3.32 GB
/srv/reproducible-results/rbuild-debian/r-b-build.30p08D3r/b1/scap-security-guide_0.1.74-1_i386.changes vs.
/srv/reproducible-results/rbuild-debian/r-b-build.30p08D3r/b2/scap-security-guide_0.1.74-1_i386.changes
824 B
Files
    
Offset 1, 6 lines modifiedOffset 1, 6 lines modified
  
1 ·74d2a1d21d01e324bb9d36e4833713af·153248·admin·optional·ssg-applications_0.1.74-1_all.deb1 ·d93e74f01251a960d60d073d4efaf811·153168·admin·optional·ssg-applications_0.1.74-1_all.deb
2 ·ac8190c89a75a5ee928afbdbfeafe241·31300·admin·optional·ssg-base_0.1.74-1_all.deb2 ·ac8190c89a75a5ee928afbdbfeafe241·31300·admin·optional·ssg-base_0.1.74-1_all.deb
3 ·2f9f18c58d3cc4ec30138ed6353ace3a·2807904·admin·optional·ssg-debderived_0.1.74-1_all.deb 
4 ·b9fe4844c9d39eba71edbdc94af39c55·1231984·admin·optional·ssg-debian_0.1.74-1_all.deb 
5 ·d61c9fc0fcf4d41f9abda986b6e42905·32360956·admin·optional·ssg-nondebian_0.1.74-1_all.deb3 ·2db0809c5958efdd2cbbf6dda67d24e3·2809432·admin·optional·ssg-debderived_0.1.74-1_all.deb
 4 ·17089fe60e4dfe518949e61653c2f7df·1232524·admin·optional·ssg-debian_0.1.74-1_all.deb
 5 ·84cfe3cd1d5d060c5937fd1dcf62830d·32375740·admin·optional·ssg-nondebian_0.1.74-1_all.deb
455 KB
ssg-applications_0.1.74-1_all.deb
452 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2024-11-02·18:39:34.000000·debian-binary1 -rw-r--r--···0········0········0········4·2024-11-02·18:39:34.000000·debian-binary
2 -rw-r--r--···0········0········0·····1728·2024-11-02·18:39:34.000000·control.tar.xz2 -rw-r--r--···0········0········0·····1724·2024-11-02·18:39:34.000000·control.tar.xz
3 -rw-r--r--···0········0········0···151328·2024-11-02·18:39:34.000000·data.tar.xz3 -rw-r--r--···0········0········0···151252·2024-11-02·18:39:34.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
454 KB
data.tar.xz
454 KB
data.tar
2.18 KB
./usr/share/doc/ssg-applications/ssg-chromium-guide-stig.html
    
Offset 14335, 15 lines modifiedOffset 14335, 15 lines modified
00037fe0:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur00037fe0:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur
00037ff0:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s00037ff0:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s
00038000:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st00038000:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st
00038010:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li00038010:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li
00038020:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</00038020:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</
00038030:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········00038030:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········
00038040:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·00038040:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·
00038050:·6f66·2032·3032·362d·3031·2d30·3829·0a20··of·2026-01-08).·00038050:·6f66·2032·3032·342d·3132·2d30·3729·0a20··of·2024-12-07).·
00038060:·2020·2020·2020·2020·2020·2020·2020·203c·················<00038060:·2020·2020·2020·2020·2020·2020·2020·203c·················<
00038070:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><00038070:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><
00038080:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont00038080:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont
00038090:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li00038090:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li
000380a0:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf000380a0:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf
000380b0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.000380b0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.
000380c0:·636f·6e74·656e·745f·6772·6f75·705f·6368··content_group_ch000380c0:·636f·6e74·656e·745f·6772·6f75·705f·6368··content_group_ch
981 B
html2text {}
    
Offset 50, 15 lines modifiedOffset 50, 15 lines modified
50 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
51 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Upstream·STIG·for·Google·Chromium51 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Upstream·STIG·for·Google·Chromium
52 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_stig52 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_stig
53 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*53 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
54 ····*·cpe:/a:google:chromium-browser54 ····*·cpe:/a:google:chromium-browser
55 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*55 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
56 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8456 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
57 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)57 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
58 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*58 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
59 ···1.·_\x8C_\x8h_\x8r_\x8o_\x8m_\x8i_\x8u_\x8m59 ···1.·_\x8C_\x8h_\x8r_\x8o_\x8m_\x8i_\x8u_\x8m
60 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*60 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*
61 Group  ·Guide·to·the·Secure·Configuration·of·Chromium·  Group·contains·1·group·and·3761 Group  ·Guide·to·the·Secure·Configuration·of·Chromium·  Group·contains·1·group·and·37
62 rules62 rules
63 Group  ·Chromium·  Group·contains·37·rules63 Group  ·Chromium·  Group·contains·37·rules
64 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Chromium·is·an·open-source·web·browser,·powered·by·WebKit·(Blink),·and64 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Chromium·is·an·open-source·web·browser,·powered·by·WebKit·(Blink),·and
2.28 KB
./usr/share/doc/ssg-applications/ssg-eks-guide-cis-node.html
    
Offset 14331, 15 lines modifiedOffset 14331, 15 lines modified
00037fa0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00037fa0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00037fb0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00037fb0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00037fc0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<00037fc0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<
00037fd0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00037fd0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00037fe0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00037fe0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00037ff0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00037ff0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00038000:·2020·2020·2020·2020·2020·2020·2020·2028·················(00038000:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00038010:·6173·206f·6620·3230·3236·2d30·312d·3038··as·of·2026-01-0800038010:·6173·206f·6620·3230·3234·2d31·322d·3037··as·of·2024-12-07
00038020:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00038020:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00038030:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00038030:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00038040:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00038040:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00038050:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00038050:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00038060:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00038060:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00038070:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00038070:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00038080:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00038080:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
1.06 KB
html2text {}
    
Offset 44, 15 lines modifiedOffset 44, 15 lines modified
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis-node44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis-node
45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
46 ····*·cpe:/a:amazon:elastic_kubernetes_service_node:1.2146 ····*·cpe:/a:amazon:elastic_kubernetes_service_node:1.21
47 ····*·cpe:/o:amazon:elastic_kubernetes_service_node:147 ····*·cpe:/o:amazon:elastic_kubernetes_service_node:1
48 ····*·cpe:/a:amazon:elastic_kubernetes_service:148 ····*·cpe:/a:amazon:elastic_kubernetes_service:1
49 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*49 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
50 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8450 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
51 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)51 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
52 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*52 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
53 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s53 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
54 ·········1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s54 ·········1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
55 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8W_\x8o_\x8r_\x8k_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s55 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8W_\x8o_\x8r_\x8k_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
56 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*56 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*
57 Group  ·Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service57 Group  ·Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service
58   Group·contains·3·groups·and·15·rules58   Group·contains·3·groups·and·15·rules
2.38 KB
./usr/share/doc/ssg-applications/ssg-eks-guide-cis.html
    
Offset 14331, 15 lines modifiedOffset 14331, 15 lines modified
00037fa0:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v00037fa0:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v
00037fb0:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>00037fb0:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>
00037fc0:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><00037fc0:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><
00037fd0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro00037fd0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro
00037fe0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong00037fe0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong
00037ff0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············00037ff0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············
00038000:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·20200038000:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202
00038010:·362d·3031·2d30·3829·0a20·2020·2020·2020··6-01-08).·······00038010:·342d·3132·2d30·3729·0a20·2020·2020·2020··4-12-07).·······
00038020:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></00038020:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></
00038030:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab00038030:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab
00038040:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</00038040:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</
00038050:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr00038050:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr
00038060:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s00038060:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s
00038070:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten00038070:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten
00038080:·745f·6772·6f75·705f·6f70·656e·7368·6966··t_group_openshif00038080:·745f·6772·6f75·705f·6f70·656e·7368·6966··t_group_openshif
1.17 KB
html2text {}
    
Offset 44, 15 lines modifiedOffset 44, 15 lines modified
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis
45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
46 ····*·cpe:/a:amazon:elastic_kubernetes_service_node:1.2146 ····*·cpe:/a:amazon:elastic_kubernetes_service_node:1.21
47 ····*·cpe:/o:amazon:elastic_kubernetes_service_node:147 ····*·cpe:/o:amazon:elastic_kubernetes_service_node:1
48 ····*·cpe:/a:amazon:elastic_kubernetes_service:148 ····*·cpe:/a:amazon:elastic_kubernetes_service:1
49 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*49 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
50 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8450 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
51 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)51 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
52 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*52 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
53 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s53 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
54 ·········1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l54 ·········1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
55 ·········2.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n55 ·········2.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n
56 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8G_\x8e_\x8n_\x8e_\x8r_\x8a_\x8l_\x8·_\x8S_\x8e_\x8c_\x8u_\x8r_\x8i_\x8t_\x8y_\x8·_\x8P_\x8r_\x8a_\x8c_\x8t_\x8i_\x8c_\x8e_\x8s56 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8G_\x8e_\x8n_\x8e_\x8r_\x8a_\x8l_\x8·_\x8S_\x8e_\x8c_\x8u_\x8r_\x8i_\x8t_\x8y_\x8·_\x8P_\x8r_\x8a_\x8c_\x8t_\x8i_\x8c_\x8e_\x8s
57 ·········4.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s57 ·········4.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
58 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8L_\x8o_\x8g_\x8g_\x8i_\x8n_\x8g_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s58 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8L_\x8o_\x8g_\x8g_\x8i_\x8n_\x8g_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
2.21 KB
./usr/share/doc/ssg-applications/ssg-firefox-guide-cusp_firefox.html
    
Offset 14284, 15 lines modifiedOffset 14284, 15 lines modified
00037cb0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00037cb0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00037cc0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00037cc0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00037cd0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<00037cd0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<
00037ce0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00037ce0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00037cf0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00037cf0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00037d00:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00037d00:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00037d10:·2020·2020·2020·2020·2020·2020·2020·2028·················(00037d10:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00037d20:·6173·206f·6620·3230·3236·2d30·312d·3038··as·of·2026-01-0800037d20:·6173·206f·6620·3230·3234·2d31·322d·3037··as·of·2024-12-07
00037d30:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00037d30:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00037d40:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00037d40:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00037d50:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00037d50:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00037d60:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00037d60:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00037d70:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00037d70:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00037d80:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00037d80:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00037d90:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00037d90:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
993 B
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CUSP·-·Common·User·Security·Profile·for·Mozilla·Firefox38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CUSP·-·Common·User·Security·Profile·for·Mozilla·Firefox
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cusp_firefox39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cusp_firefox
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/a:mozilla:firefox41 ····*·cpe:/a:mozilla:firefox
42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
43 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8443 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
46 ···1.·_\x8F_\x8i_\x8r_\x8e_\x8f_\x8o_\x8x46 ···1.·_\x8F_\x8i_\x8r_\x8e_\x8f_\x8o_\x8x
47 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*
48 Group  ·Guide·to·the·Secure·Configuration·of·Firefox·  Group·contains·1·group48 Group  ·Guide·to·the·Secure·Configuration·of·Firefox·  Group·contains·1·group
49 and·9·rules49 and·9·rules
50 Group  ·Firefox·  Group·contains·9·rules50 Group  ·Firefox·  Group·contains·9·rules
51 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Firefox·is·an·open-source·web·browser·and·developed·by·Mozilla.·Web51 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Firefox·is·an·open-source·web·browser·and·developed·by·Mozilla.·Web
2.2 KB
./usr/share/doc/ssg-applications/ssg-firefox-guide-stig.html
    
Offset 14332, 15 lines modifiedOffset 14332, 15 lines modified
00037fb0:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v00037fb0:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v
00037fc0:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>00037fc0:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>
00037fd0:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><00037fd0:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><
00037fe0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro00037fe0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro
00037ff0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong00037ff0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong
00038000:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············00038000:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············
00038010:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·20200038010:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202
00038020:·362d·3031·2d30·3829·0a20·2020·2020·2020··6-01-08).·······00038020:·342d·3132·2d30·3729·0a20·2020·2020·2020··4-12-07).·······
00038030:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></00038030:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></
00038040:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab00038040:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab
00038050:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</00038050:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</
00038060:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr00038060:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr
00038070:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s00038070:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s
00038080:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten00038080:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten
00038090:·745f·6772·6f75·705f·6669·7265·666f·7822··t_group_firefox"00038090:·745f·6772·6f75·705f·6669·7265·666f·7822··t_group_firefox"
1000 B
html2text {}
    
Offset 50, 15 lines modifiedOffset 50, 15 lines modified
50 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
51 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Mozilla·Firefox·STIG51 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Mozilla·Firefox·STIG
52 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_stig52 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_stig
53 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*53 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
54 ····*·cpe:/a:mozilla:firefox54 ····*·cpe:/a:mozilla:firefox
55 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*55 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
56 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8456 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
57 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)57 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
58 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*58 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
59 ···1.·_\x8F_\x8i_\x8r_\x8e_\x8f_\x8o_\x8x59 ···1.·_\x8F_\x8i_\x8r_\x8e_\x8f_\x8o_\x8x
60 ·········1.·_\x8T_\x8h_\x8e_\x8·_\x8D_\x8o_\x8D_\x8·_\x8R_\x8o_\x8o_\x8t_\x8·_\x8C_\x8e_\x8r_\x8t_\x8i_\x8f_\x8i_\x8c_\x8a_\x8t_\x8e_\x8·_\x8I_\x8s_\x8·_\x8R_\x8e_\x8q_\x8u_\x8i_\x8r_\x8e_\x8d60 ·········1.·_\x8T_\x8h_\x8e_\x8·_\x8D_\x8o_\x8D_\x8·_\x8R_\x8o_\x8o_\x8t_\x8·_\x8C_\x8e_\x8r_\x8t_\x8i_\x8f_\x8i_\x8c_\x8a_\x8t_\x8e_\x8·_\x8I_\x8s_\x8·_\x8R_\x8e_\x8q_\x8u_\x8i_\x8r_\x8e_\x8d
61 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*61 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*
62 Group  ·Guide·to·the·Secure·Configuration·of·Firefox·  Group·contains·2·groups62 Group  ·Guide·to·the·Secure·Configuration·of·Firefox·  Group·contains·2·groups
63 and·34·rules63 and·34·rules
64 Group  ·Firefox·  Group·contains·1·group·and·34·rules64 Group  ·Firefox·  Group·contains·1·group·and·34·rules
79.1 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ds.xml
79.0 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ds.xml
    
Offset 19, 25 lines modifiedOffset 19, 25 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-cpe-dictionary.xml"·timestamp="2024-11-02T06:39:34">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-cpe-dictionary.xml"·timestamp="2024-11-03T08:39:34">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:google:chromium-browser">28 ······<cpe-dict:cpe-item·name="cpe:/a:google:chromium-browser">
29 ········<cpe-dict:title·xml:lang="en-us">Google·Chromium·Browser</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Google·Chromium·Browser</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-chromium-cpe-oval.xml">oval:ssg-installed_app_is_chromium:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-chromium-cpe-oval.xml">oval:ssg-installed_app_is_chromium:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-xccdf.xml"·timestamp="2024-11-02T06:39:34">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-xccdf.xml"·timestamp="2024-11-03T08:39:34">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_CHROMIUM"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_CHROMIUM"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Chromium</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Chromium</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Chromium.·It·is·a·rendering·of40 configuration·settings·for·Chromium.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
42 in·order·to·support·security·automation.··The·SCAP·content·is42 in·order·to·support·security·automation.··The·SCAP·content·is
43 is·available·in·the43 is·available·in·the
Offset 1666, 15 lines modifiedOffset 1666, 15 lines modified
1666 ··········<xccdf-1.2:check·system="http://scap.nist.gov/schema/ocil/2">1666 ··········<xccdf-1.2:check·system="http://scap.nist.gov/schema/ocil/2">
1667 ············<xccdf-1.2:check-content-ref·href="ssg-chromium-ocil.xml"·name="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1"/>1667 ············<xccdf-1.2:check-content-ref·href="ssg-chromium-ocil.xml"·name="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1"/>
1668 ··········</xccdf-1.2:check>1668 ··········</xccdf-1.2:check>
1669 ········</xccdf-1.2:Rule>1669 ········</xccdf-1.2:Rule>
1670 ······</xccdf-1.2:Group>1670 ······</xccdf-1.2:Group>
1671 ····</xccdf-1.2:Benchmark>1671 ····</xccdf-1.2:Benchmark>
1672 ··</ds:component>1672 ··</ds:component>
1673 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-oval.xml"·timestamp="2024-11-02T06:39:34">1673 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-oval.xml"·timestamp="2024-11-03T08:39:34">
1674 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">1674 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
1675 ······<oval-def:generator>1675 ······<oval-def:generator>
1676 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>1676 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
1677 ········<oval:product_version>ssg:·[0,·1,·74],·python:·3.12.7</oval:product_version>1677 ········<oval:product_version>ssg:·[0,·1,·74],·python:·3.12.7</oval:product_version>
1678 ········<oval:schema_version>5.11</oval:schema_version>1678 ········<oval:schema_version>5.11</oval:schema_version>
1679 ········<oval:timestamp>2024-11-02T18:39:34</oval:timestamp>1679 ········<oval:timestamp>2024-11-02T18:39:34</oval:timestamp>
1680 ······</oval-def:generator>1680 ······</oval-def:generator>
Offset 2530, 368 lines modifiedOffset 2530, 368 lines modified
2530 ········<oval-def:external_variable·id="oval:ssg-var_enable_encrypted_searching:var:1"·version="1"·datatype="string"·comment="Expected·search·provider·name"/>2530 ········<oval-def:external_variable·id="oval:ssg-var_enable_encrypted_searching:var:1"·version="1"·datatype="string"·comment="Expected·search·provider·name"/>
2531 ········<oval-def:external_variable·id="oval:ssg-var_extension_whitelist:var:1"·version="1"·datatype="string"·comment="Expected·approved·extensions"/>2531 ········<oval-def:external_variable·id="oval:ssg-var_extension_whitelist:var:1"·version="1"·datatype="string"·comment="Expected·approved·extensions"/>
2532 ········<oval-def:external_variable·id="oval:ssg-var_auth_schema:var:1"·version="1"·datatype="string"·comment="Expected·HTTP·authentication·type"/>2532 ········<oval-def:external_variable·id="oval:ssg-var_auth_schema:var:1"·version="1"·datatype="string"·comment="Expected·HTTP·authentication·type"/>
2533 ········<oval-def:external_variable·id="oval:ssg-var_trusted_home_page:var:1"·version="1"·datatype="string"·comment="Expected·home·page"/>2533 ········<oval-def:external_variable·id="oval:ssg-var_trusted_home_page:var:1"·version="1"·datatype="string"·comment="Expected·home·page"/>
2534 ······</oval-def:variables>2534 ······</oval-def:variables>
2535 ····</oval-def:oval_definitions>2535 ····</oval-def:oval_definitions>
2536 ··</ds:component>2536 ··</ds:component>
2537 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-ocil.xml"·timestamp="2024-11-02T06:39:34">2537 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-ocil.xml"·timestamp="2024-11-03T08:39:34">
2538 ····<ocil:ocil>2538 ····<ocil:ocil>
2539 ······<ocil:generator>2539 ······<ocil:generator>
2540 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>2540 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
2541 ········<ocil:product_version>ssg:·0.1.74</ocil:product_version>2541 ········<ocil:product_version>ssg:·0.1.74</ocil:product_version>
2542 ········<ocil:schema_version>2.0</ocil:schema_version>2542 ········<ocil:schema_version>2.0</ocil:schema_version>
2543 ········<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>2543 ········<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
2544 ······</ocil:generator>2544 ······</ocil:generator>
2545 ······<ocil:questionnaires>2545 ······<ocil:questionnaires>
2546 ········<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_ocil:questionnaire:1">2546 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_thirdparty_cookies_ocil:questionnaire:1">
 2547 ··········<ocil:title>Disable·3rd·Party·Cookies</ocil:title>
2547 ··········<ocil:title>Enable·the·Default·Search·Provider</ocil:title> 
2548 ··········<ocil:actions> 
2549 ············<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_action:testaction:1</ocil:test_action_ref> 
2550 ··········</ocil:actions> 
2551 ········</ocil:questionnaire> 
2552 ········<ocil:questionnaire·id="ocil:ssg-chromium_extension_whitelist_ocil:questionnaire:1"> 
2553 ··········<ocil:title>Enable·Only·Approved·Extensions</ocil:title> 
2554 ··········<ocil:actions>2548 ··········<ocil:actions>
2555 ············<ocil:test_action_ref>ocil:ssg-chromium_extension_whitelist_action:testaction:1</ocil:test_action_ref>2549 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_thirdparty_cookies_action:testaction:1</ocil:test_action_ref>
2556 ··········</ocil:actions>2550 ··········</ocil:actions>
2557 ········</ocil:questionnaire>2551 ········</ocil:questionnaire>
2558 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1">2552 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_automatic_installation_ocil:questionnaire:1">
2559 ··········<ocil:title>Disable·Metrics·Reporting</ocil:title>2553 ··········<ocil:title>Disable·Automatic·Search·And·Installation·of·Plugins</ocil:title>
2560 ··········<ocil:actions>2554 ··········<ocil:actions>
2561 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref>2555 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_automatic_installation_action:testaction:1</ocil:test_action_ref>
2562 ··········</ocil:actions>2556 ··········</ocil:actions>
2563 ········</ocil:questionnaire>2557 ········</ocil:questionnaire>
2564 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_autocomplete_ocil:questionnaire:1">2558 ········<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_name_ocil:questionnaire:1">
2565 ··········<ocil:title>Disable·the·AutoFill·Feature</ocil:title>2559 ··········<ocil:title>Set·the·Default·Search·Provider's·URL</ocil:title>
2566 ··········<ocil:actions>2560 ··········<ocil:actions>
2567 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_autocomplete_action:testaction:1</ocil:test_action_ref>2561 ············<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_name_action:testaction:1</ocil:test_action_ref>
2568 ··········</ocil:actions>2562 ··········</ocil:actions>
2569 ········</ocil:questionnaire>2563 ········</ocil:questionnaire>
2570 ········<ocil:questionnaire·id="ocil:ssg-chromium_disallow_location_tracking_ocil:questionnaire:1">2564 ········<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_ocil:questionnaire:1">
2571 ··········<ocil:title>Disable·Location·Tracking</ocil:title>2565 ··········<ocil:title>Enable·the·Default·Search·Provider</ocil:title>
2572 ··········<ocil:actions>2566 ··········<ocil:actions>
2573 ············<ocil:test_action_ref>ocil:ssg-chromium_disallow_location_tracking_action:testaction:1</ocil:test_action_ref>2567 ············<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_action:testaction:1</ocil:test_action_ref>
2574 ··········</ocil:actions>2568 ··········</ocil:actions>
2575 ········</ocil:questionnaire>2569 ········</ocil:questionnaire>
2576 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_protocol_schemas_ocil:questionnaire:1">2570 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_approved_plugins_ocil:questionnaire:1">
2577 ··········<ocil:title>Disable·Insecure·And·Obsolete·Protocol·Schemas</ocil:title>2571 ··········<ocil:title>Enable·Only·Approved·Plugins</ocil:title>
2578 ··········<ocil:actions>2572 ··········<ocil:actions>
2579 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_protocol_schemas_action:testaction:1</ocil:test_action_ref>2573 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_approved_plugins_action:testaction:1</ocil:test_action_ref>
2580 ··········</ocil:actions>2574 ··········</ocil:actions>
2581 ········</ocil:questionnaire>2575 ········</ocil:questionnaire>
2582 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_cloud_print_sharing_ocil:questionnaire:1">2576 ········<ocil:questionnaire·id="ocil:ssg-chromium_trusted_home_page_ocil:questionnaire:1">
2583 ··········<ocil:title>Disable·Cloud·Print·Sharing</ocil:title>2577 ··········<ocil:title>Set·the·Default·Home·Page</ocil:title>
2584 ··········<ocil:actions>2578 ··········<ocil:actions>
2585 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_cloud_print_sharing_action:testaction:1</ocil:test_action_ref>2579 ············<ocil:test_action_ref>ocil:ssg-chromium_trusted_home_page_action:testaction:1</ocil:test_action_ref>
2586 ··········</ocil:actions>2580 ··········</ocil:actions>
2587 ········</ocil:questionnaire>2581 ········</ocil:questionnaire>
2588 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_search_suggestions_ocil:questionnaire:1">2582 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_saved_passwords_ocil:questionnaire:1">
2589 ··········<ocil:title>Disable·Search·Suggestion</ocil:title>2583 ··········<ocil:title>Disable·Saved·Passwords</ocil:title>
2590 ··········<ocil:actions>2584 ··········<ocil:actions>
2591 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_search_suggestions_action:testaction:1</ocil:test_action_ref>2585 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_saved_passwords_action:testaction:1</ocil:test_action_ref>
2592 ··········</ocil:actions>2586 ··········</ocil:actions>
2593 ········</ocil:questionnaire>2587 ········</ocil:questionnaire>
2594 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_browser_history_ocil:questionnaire:1">2588 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_cleartext_passwords_ocil:questionnaire:1">
2595 ··········<ocil:title>Enable·Saving·the·Browser·History</ocil:title>2589 ··········<ocil:title>Disable·Use·of·Cleartext·Passwords</ocil:title>
2596 ··········<ocil:actions>2590 ··········<ocil:actions>
2597 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_browser_history_action:testaction:1</ocil:test_action_ref>2591 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_cleartext_passwords_action:testaction:1</ocil:test_action_ref>
2598 ··········</ocil:actions>2592 ··········</ocil:actions>
2599 ········</ocil:questionnaire>2593 ········</ocil:questionnaire>
2600 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_automatic_installation_ocil:questionnaire:1">2594 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_popups_ocil:questionnaire:1">
2601 ··········<ocil:title>Disable·Automatic·Search·And·Installation·of·Plugins</ocil:title>2595 ··········<ocil:title>Disable·Popups</ocil:title>
2602 ··········<ocil:actions>2596 ··········<ocil:actions>
2603 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_automatic_installation_action:testaction:1</ocil:test_action_ref>2597 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_popups_action:testaction:1</ocil:test_action_ref>
2604 ··········</ocil:actions>2598 ··········</ocil:actions>
2605 ········</ocil:questionnaire>2599 ········</ocil:questionnaire>
2606 ········<ocil:questionnaire·id="ocil:ssg-chromium_trusted_home_page_ocil:questionnaire:1">2600 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_password_manager_ocil:questionnaire:1">
2607 ··········<ocil:title>Set·the·Default·Home·Page</ocil:title>2601 ··········<ocil:title>Disable·Chromium·Password·Manager</ocil:title>
2608 ··········<ocil:actions>2602 ··········<ocil:actions>
2609 ············<ocil:test_action_ref>ocil:ssg-chromium_trusted_home_page_action:testaction:1</ocil:test_action_ref>2603 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_password_manager_action:testaction:1</ocil:test_action_ref>
2610 ··········</ocil:actions>2604 ··········</ocil:actions>
2611 ········</ocil:questionnaire>2605 ········</ocil:questionnaire>
2612 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_encrypted_searching_ocil:questionnaire:1">2606 ········<ocil:questionnaire·id="ocil:ssg-chromium_block_desktop_notifications_ocil:questionnaire:1">
2613 ··········<ocil:title>Enable·Encrypted·Searching</ocil:title>2607 ··········<ocil:title>Prevent·Desktop·Notifications</ocil:title>
Max diff block lines reached; 68528/80743 bytes (84.87%) of diff not shown.
70.3 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ocil.xml
70.2 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ocil.xml
Ordering differences only
    
Offset 3, 359 lines modifiedOffset 3, 359 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_thirdparty_cookies_ocil:questionnaire:1">
 11 ······<ocil:title>Disable·3rd·Party·Cookies</ocil:title>
11 ······<ocil:title>Enable·the·Default·Search·Provider</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-chromium_extension_whitelist_ocil:questionnaire:1"> 
17 ······<ocil:title>Enable·Only·Approved·Extensions</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-chromium_extension_whitelist_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_thirdparty_cookies_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_automatic_installation_ocil:questionnaire:1">
23 ······<ocil:title>Disable·Metrics·Reporting</ocil:title>17 ······<ocil:title>Disable·Automatic·Search·And·Installation·of·Plugins</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_automatic_installation_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_autocomplete_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_name_ocil:questionnaire:1">
29 ······<ocil:title>Disable·the·AutoFill·Feature</ocil:title>23 ······<ocil:title>Set·the·Default·Search·Provider's·URL</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_autocomplete_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_name_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-chromium_disallow_location_tracking_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_ocil:questionnaire:1">
35 ······<ocil:title>Disable·Location·Tracking</ocil:title>29 ······<ocil:title>Enable·the·Default·Search·Provider</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-chromium_disallow_location_tracking_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_protocol_schemas_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_approved_plugins_ocil:questionnaire:1">
41 ······<ocil:title>Disable·Insecure·And·Obsolete·Protocol·Schemas</ocil:title>35 ······<ocil:title>Enable·Only·Approved·Plugins</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_protocol_schemas_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_approved_plugins_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_cloud_print_sharing_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-chromium_trusted_home_page_ocil:questionnaire:1">
47 ······<ocil:title>Disable·Cloud·Print·Sharing</ocil:title>41 ······<ocil:title>Set·the·Default·Home·Page</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_cloud_print_sharing_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-chromium_trusted_home_page_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_search_suggestions_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_saved_passwords_ocil:questionnaire:1">
53 ······<ocil:title>Disable·Search·Suggestion</ocil:title>47 ······<ocil:title>Disable·Saved·Passwords</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_search_suggestions_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_saved_passwords_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_browser_history_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_cleartext_passwords_ocil:questionnaire:1">
59 ······<ocil:title>Enable·Saving·the·Browser·History</ocil:title>53 ······<ocil:title>Disable·Use·of·Cleartext·Passwords</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_browser_history_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_cleartext_passwords_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_automatic_installation_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_popups_ocil:questionnaire:1">
65 ······<ocil:title>Disable·Automatic·Search·And·Installation·of·Plugins</ocil:title>59 ······<ocil:title>Disable·Popups</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_automatic_installation_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_popups_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-chromium_trusted_home_page_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_password_manager_ocil:questionnaire:1">
71 ······<ocil:title>Set·the·Default·Home·Page</ocil:title>65 ······<ocil:title>Disable·Chromium·Password·Manager</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-chromium_trusted_home_page_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_password_manager_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_encrypted_searching_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-chromium_block_desktop_notifications_ocil:questionnaire:1">
77 ······<ocil:title>Enable·Encrypted·Searching</ocil:title>71 ······<ocil:title>Prevent·Desktop·Notifications</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_encrypted_searching_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-chromium_block_desktop_notifications_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_outdated_plugins_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_plugin_blacklist_ocil:questionnaire:1">
83 ······<ocil:title>Disable·Outdated·Plugins</ocil:title>77 ······<ocil:title>Disable·All·Plugins·by·Default</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_outdated_plugins_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_plugin_blacklist_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-chromium_check_cert_revocation_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-chromium_plugins_require_authorization_ocil:questionnaire:1">
89 ······<ocil:title>Enable·Online·OCSP/CRL·Certificate·Checks</ocil:title>83 ······<ocil:title>Require·Outdated·Plugins·to·be·Authorized</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-chromium_check_cert_revocation_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-chromium_plugins_require_authorization_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_background_processing_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_background_processing_ocil:questionnaire:1">
95 ······<ocil:title>Disable·Background·Processing</ocil:title>89 ······<ocil:title>Disable·Background·Processing</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_background_processing_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_background_processing_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_incognito_mode_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_encrypted_searching_ocil:questionnaire:1">
101 ······<ocil:title>Disable·Incognito·Mode</ocil:title>95 ······<ocil:title>Enable·Encrypted·Searching</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_incognito_mode_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_encrypted_searching_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_session_cookies_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_google_sync_ocil:questionnaire:1">
107 ······<ocil:title>Disable·Session·Cookies</ocil:title>101 ······<ocil:title>Disable·Data·Synchronization·to·Google</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_session_cookies_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_google_sync_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_firewall_traversal_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_session_cookies_ocil:questionnaire:1">
113 ······<ocil:title>Disable·Chromium's·Ability·to·Traverse·Firewalls</ocil:title>107 ······<ocil:title>Disable·Session·Cookies</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_firewall_traversal_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_session_cookies_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_3d_graphics_api_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_3d_graphics_api_ocil:questionnaire:1">
119 ······<ocil:title>Disable·the·3D·Graphics·APIs</ocil:title>113 ······<ocil:title>Disable·the·3D·Graphics·APIs</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_3d_graphics_api_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_3d_graphics_api_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
123 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_saved_passwords_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1">
125 ······<ocil:title>Disable·Saved·Passwords</ocil:title>119 ······<ocil:title>Disable·Metrics·Reporting</ocil:title>
126 ······<ocil:actions>120 ······<ocil:actions>
127 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_saved_passwords_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref>
128 ······</ocil:actions>122 ······</ocil:actions>
Max diff block lines reached; 59807/71782 bytes (83.32%) of diff not shown.
1.17 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-xccdf.xml
1.06 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_CHROMIUM"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_CHROMIUM"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Chromium</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Chromium</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·Chromium.·It·is·a·rendering·of7 configuration·settings·for·Chromium.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
97.1 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ds.xml
97.0 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-cpe-dictionary.xml"·timestamp="2024-11-02T06:39:34">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-cpe-dictionary.xml"·timestamp="2024-11-03T08:39:34">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service:1">28 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service:1">
29 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service_node:1.21">32 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service_node:1.21">
33 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·1.21</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·1.21</cpe-dict:title>
Offset 35, 17 lines modifiedOffset 35, 17 lines modified
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ······<cpe-dict:cpe-item·name="cpe:/o:amazon:elastic_kubernetes_service_node:1">36 ······<cpe-dict:cpe-item·name="cpe:/o:amazon:elastic_kubernetes_service_node:1">
37 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·Node</cpe-dict:title>37 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·Node</cpe-dict:title>
38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks_node:def:1</cpe-dict:check>38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks_node:def:1</cpe-dict:check>
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ····</cpe-dict:cpe-list>40 ····</cpe-dict:cpe-list>
41 ··</ds:component>41 ··</ds:component>
42 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-xccdf.xml"·timestamp="2024-11-02T06:39:34">42 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-xccdf.xml"·timestamp="2024-11-03T08:39:34">
43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_EKS"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_EKS"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
44 ······<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>44 ······<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service</xccdf-1.2:title>45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service</xccdf-1.2:title>
46 ······<xccdf-1.2:description>46 ······<xccdf-1.2:description>
47 ········This·guide·presents·a·catalog·of·security-relevant47 ········This·guide·presents·a·catalog·of·security-relevant
48 configuration·settings·for·Amazon·Elastic·Kubernetes·Service.·It·is·a·rendering·of48 configuration·settings·for·Amazon·Elastic·Kubernetes·Service.·It·is·a·rendering·of
49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
50 in·order·to·support·security·automation.··The·SCAP·content·is50 in·order·to·support·security·automation.··The·SCAP·content·is
51 is·available·in·the51 is·available·in·the
Offset 113, 24 lines modifiedOffset 113, 24 lines modified
113 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>113 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
114 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>114 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
115 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>115 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
116 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>116 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
117 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>117 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
118 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>118 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
119 ······<cpe-lang:platform-specification>119 ······<cpe-lang:platform-specification>
120 ········<cpe-lang:platform·id="not_ocp4-on-hypershift"> 
121 ··········<cpe-lang:logical-test·operator="AND"·negate="true"> 
122 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift:def:1"/> 
123 ··········</cpe-lang:logical-test> 
124 ········</cpe-lang:platform> 
125 ········<cpe-lang:platform·id="eks-node">120 ········<cpe-lang:platform·id="eks-node">
126 ··········<cpe-lang:logical-test·operator="AND"·negate="false">121 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
127 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_eks_node:def:1"/>122 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_eks_node:def:1"/>
128 ··········</cpe-lang:logical-test>123 ··········</cpe-lang:logical-test>
129 ········</cpe-lang:platform>124 ········</cpe-lang:platform>
 125 ········<cpe-lang:platform·id="not_ocp4-on-hypershift">
 126 ··········<cpe-lang:logical-test·operator="AND"·negate="true">
 127 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift:def:1"/>
 128 ··········</cpe-lang:logical-test>
 129 ········</cpe-lang:platform>
130 ······</cpe-lang:platform-specification>130 ······</cpe-lang:platform-specification>
131 ······<xccdf-1.2:platform·idref="cpe:/a:amazon:elastic_kubernetes_service_node:1.21"/>131 ······<xccdf-1.2:platform·idref="cpe:/a:amazon:elastic_kubernetes_service_node:1.21"/>
132 ······<xccdf-1.2:platform·idref="cpe:/o:amazon:elastic_kubernetes_service_node:1"/>132 ······<xccdf-1.2:platform·idref="cpe:/o:amazon:elastic_kubernetes_service_node:1"/>
133 ······<xccdf-1.2:platform·idref="cpe:/a:amazon:elastic_kubernetes_service:1"/>133 ······<xccdf-1.2:platform·idref="cpe:/a:amazon:elastic_kubernetes_service:1"/>
134 ······<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.74</xccdf-1.2:version>134 ······<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.74</xccdf-1.2:version>
135 ······<xccdf-1.2:metadata>135 ······<xccdf-1.2:metadata>
136 ········<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>136 ········<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>
Offset 1490, 15 lines modifiedOffset 1490, 15 lines modified
1490 ··············<xccdf-1.2:check-content-ref·href="ssg-eks-ocil.xml"·name="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1"/>1490 ··············<xccdf-1.2:check-content-ref·href="ssg-eks-ocil.xml"·name="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1"/>
1491 ············</xccdf-1.2:check>1491 ············</xccdf-1.2:check>
1492 ··········</xccdf-1.2:Rule>1492 ··········</xccdf-1.2:Rule>
1493 ········</xccdf-1.2:Group>1493 ········</xccdf-1.2:Group>
1494 ······</xccdf-1.2:Group>1494 ······</xccdf-1.2:Group>
1495 ····</xccdf-1.2:Benchmark>1495 ····</xccdf-1.2:Benchmark>
1496 ··</ds:component>1496 ··</ds:component>
1497 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-oval.xml"·timestamp="2024-11-02T06:39:34">1497 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-oval.xml"·timestamp="2024-11-03T08:39:34">
1498 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">1498 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
1499 ······<oval-def:generator>1499 ······<oval-def:generator>
1500 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>1500 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
1501 ········<oval:product_version>ssg:·[0,·1,·74],·python:·3.12.7</oval:product_version>1501 ········<oval:product_version>ssg:·[0,·1,·74],·python:·3.12.7</oval:product_version>
1502 ········<oval:schema_version>5.11</oval:schema_version>1502 ········<oval:schema_version>5.11</oval:schema_version>
1503 ········<oval:timestamp>2024-11-02T18:39:34</oval:timestamp>1503 ········<oval:timestamp>2024-11-02T18:39:34</oval:timestamp>
1504 ······</oval-def:generator>1504 ······</oval-def:generator>
Offset 2111, 505 lines modifiedOffset 2111, 515 lines modified
2111 ········<oval-def:external_variable·id="oval:ssg-var_streaming_connection_timeouts:var:1"·version="1"·datatype="string"·comment="variable"/>2111 ········<oval-def:external_variable·id="oval:ssg-var_streaming_connection_timeouts:var:1"·version="1"·datatype="string"·comment="variable"/>
2112 ········<oval-def:local_variable·id="oval:ssg-kubelet_read_only_port_secured_file_location:var:1"·version="1"·datatype="string"·comment="The·actual·path·of·the·file·to·scan.">2112 ········<oval-def:local_variable·id="oval:ssg-kubelet_read_only_port_secured_file_location:var:1"·version="1"·datatype="string"·comment="The·actual·path·of·the·file·to·scan.">
2113 ··········<oval-def:literal_component>/etc/kubernetes/compliance-operator/kubeletconfig/openscap-kubeletconfig</oval-def:literal_component>2113 ··········<oval-def:literal_component>/etc/kubernetes/compliance-operator/kubeletconfig/openscap-kubeletconfig</oval-def:literal_component>
2114 ········</oval-def:local_variable>2114 ········</oval-def:local_variable>
2115 ······</oval-def:variables>2115 ······</oval-def:variables>
2116 ····</oval-def:oval_definitions>2116 ····</oval-def:oval_definitions>
2117 ··</ds:component>2117 ··</ds:component>
2118 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-ocil.xml"·timestamp="2024-11-02T06:39:34">2118 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-ocil.xml"·timestamp="2024-11-03T08:39:34">
2119 ····<ocil:ocil>2119 ····<ocil:ocil>
2120 ······<ocil:generator>2120 ······<ocil:generator>
2121 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>2121 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
2122 ········<ocil:product_version>ssg:·0.1.74</ocil:product_version>2122 ········<ocil:product_version>ssg:·0.1.74</ocil:product_version>
2123 ········<ocil:schema_version>2.0</ocil:schema_version>2123 ········<ocil:schema_version>2.0</ocil:schema_version>
2124 ········<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>2124 ········<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
2125 ······</ocil:generator>2125 ······</ocil:generator>
2126 ······<ocil:questionnaires>2126 ······<ocil:questionnaires>
2127 ········<ocil:questionnaire·id="ocil:ssg-kubelet_read_only_port_secured_ocil:questionnaire:1"> 
2128 ··········<ocil:title>kubelet·-·Ensure·that·the·--read-only-port·is·secured</ocil:title> 
2129 ··········<ocil:actions> 
2130 ············<ocil:test_action_ref>ocil:ssg-kubelet_read_only_port_secured_action:testaction:1</ocil:test_action_ref> 
2131 ··········</ocil:actions> 
2132 ········</ocil:questionnaire> 
2133 ········<ocil:questionnaire·id="ocil:ssg-image_scanning_ocil:questionnaire:1"> 
2134 ··········<ocil:title>Ensure·Image·Vulnerability·Scanning</ocil:title> 
2135 ··········<ocil:actions> 
2136 ············<ocil:test_action_ref>ocil:ssg-image_scanning_action:testaction:1</ocil:test_action_ref> 
2137 ··········</ocil:actions> 
2138 ········</ocil:questionnaire> 
2139 ········<ocil:questionnaire·id="ocil:ssg-dedicated_service_accounts_ocil:questionnaire:1"> 
2140 ··········<ocil:title>Use·Dedicated·Service·Accounts</ocil:title> 
2141 ··········<ocil:actions> 
2142 ············<ocil:test_action_ref>ocil:ssg-dedicated_service_accounts_action:testaction:1</ocil:test_action_ref> 
2143 ··········</ocil:actions> 
2144 ········</ocil:questionnaire> 
2145 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1"> 
2146 ··········<ocil:title>Verify·Permissions·on·the·Worker·Kubeconfig·File</ocil:title> 
2147 ··········<ocil:actions> 
2148 ············<ocil:test_action_ref>ocil:ssg-file_permissions_worker_kubeconfig_action:testaction:1</ocil:test_action_ref> 
2149 ··········</ocil:actions> 
2150 ········</ocil:questionnaire> 
2151 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_cert_rotation_ocil:questionnaire:1">2127 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_cert_rotation_ocil:questionnaire:1">
2152 ··········<ocil:title>kubelet·-·Enable·Certificate·Rotation</ocil:title>2128 ··········<ocil:title>kubelet·-·Enable·Certificate·Rotation</ocil:title>
2153 ··········<ocil:actions>2129 ··········<ocil:actions>
2154 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_cert_rotation_action:testaction:1</ocil:test_action_ref>2130 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_cert_rotation_action:testaction:1</ocil:test_action_ref>
2155 ··········</ocil:actions>2131 ··········</ocil:actions>
2156 ········</ocil:questionnaire>2132 ········</ocil:questionnaire>
2157 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_deprecated_ocil:questionnaire:1"> 
Max diff block lines reached; 89158/99234 bytes (89.85%) of diff not shown.
85.9 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ocil.xml
85.8 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ocil.xml
Ordering differences only
    
Offset 3, 496 lines modifiedOffset 3, 506 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-kubelet_read_only_port_secured_ocil:questionnaire:1"> 
11 ······<ocil:title>kubelet·-·Ensure·that·the·--read-only-port·is·secured</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-kubelet_read_only_port_secured_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-image_scanning_ocil:questionnaire:1"> 
17 ······<ocil:title>Ensure·Image·Vulnerability·Scanning</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-image_scanning_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-dedicated_service_accounts_ocil:questionnaire:1"> 
23 ······<ocil:title>Use·Dedicated·Service·Accounts</ocil:title> 
24 ······<ocil:actions> 
25 ········<ocil:test_action_ref>ocil:ssg-dedicated_service_accounts_action:testaction:1</ocil:test_action_ref> 
26 ······</ocil:actions> 
27 ····</ocil:questionnaire> 
28 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1"> 
29 ······<ocil:title>Verify·Permissions·on·the·Worker·Kubeconfig·File</ocil:title> 
30 ······<ocil:actions> 
31 ········<ocil:test_action_ref>ocil:ssg-file_permissions_worker_kubeconfig_action:testaction:1</ocil:test_action_ref> 
32 ······</ocil:actions> 
33 ····</ocil:questionnaire> 
34 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_cert_rotation_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_cert_rotation_ocil:questionnaire:1">
35 ······<ocil:title>kubelet·-·Enable·Certificate·Rotation</ocil:title>11 ······<ocil:title>kubelet·-·Enable·Certificate·Rotation</ocil:title>
36 ······<ocil:actions>12 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_cert_rotation_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_cert_rotation_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>14 ······</ocil:actions>
39 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_deprecated_ocil:questionnaire:1"> 
41 ······<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_worker_kubeconfig_ocil:questionnaire:1">
 17 ······<ocil:title>Verify·Group·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>
42 ······<ocil:actions>18 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_deprecated_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>20 ······</ocil:actions>
45 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-configure_network_policies_namespaces_ocil:questionnaire:1"> 
47 ······<ocil:title>Ensure·that·application·Namespaces·have·Network·Policies·defined.</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_deprecated_ocil:questionnaire:1">
 23 ······<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>
48 ······<ocil:actions>24 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-configure_network_policies_namespaces_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_deprecated_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>26 ······</ocil:actions>
51 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_kubelet_conf_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_kubelet_conf_ocil:questionnaire:1">
53 ······<ocil:title>Verify·Group·Who·Owns·The·Kubelet·Configuration·File</ocil:title>29 ······<ocil:title>Verify·Group·Who·Owns·The·Kubelet·Configuration·File</ocil:title>
54 ······<ocil:actions>30 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_kubelet_conf_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_kubelet_conf_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>32 ······</ocil:actions>
57 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-configure_tls_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-configure_tls_ocil:questionnaire:1">
59 ······<ocil:title>Encrypt·Traffic·to·Load·Balancers·and·Workloads</ocil:title>35 ······<ocil:title>Encrypt·Traffic·to·Load·Balancers·and·Workloads</ocil:title>
60 ······<ocil:actions>36 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-configure_tls_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-configure_tls_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>38 ······</ocil:actions>
63 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-endpoint_configuration_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_client_cert_rotation_ocil:questionnaire:1">
 41 ······<ocil:title>kubelet·-·Enable·Client·Certificate·Rotation</ocil:title>
65 ······<ocil:title>Ensure·Private·Endpoint·Access</ocil:title> 
66 ······<ocil:actions> 
67 ········<ocil:test_action_ref>ocil:ssg-endpoint_configuration_action:testaction:1</ocil:test_action_ref> 
68 ······</ocil:actions> 
69 ····</ocil:questionnaire> 
70 ····<ocil:questionnaire·id="ocil:ssg-iam_integration_ocil:questionnaire:1"> 
71 ······<ocil:title>Manage·Users·with·AWS·IAM</ocil:title> 
72 ······<ocil:actions>42 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-iam_integration_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_client_cert_rotation_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>44 ······</ocil:actions>
75 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-approved_registries_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-dedicated_service_accounts_ocil:questionnaire:1">
77 ······<ocil:title>Only·use·approved·container·registries</ocil:title>47 ······<ocil:title>Use·Dedicated·Service·Accounts</ocil:title>
78 ······<ocil:actions>48 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-approved_registries_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-dedicated_service_accounts_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>50 ······</ocil:actions>
81 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_server_cert_rotation_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_protect_kernel_defaults_ocil:questionnaire:1">
83 ······<ocil:title>kubelet·-·Enable·Server·Certificate·Rotation</ocil:title>53 ······<ocil:title>kubelet·-·Enable·Protect·Kernel·Defaults</ocil:title>
84 ······<ocil:actions>54 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_server_cert_rotation_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_protect_kernel_defaults_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>56 ······</ocil:actions>
87 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_owner_worker_kubeconfig_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-registry_access_ocil:questionnaire:1">
89 ······<ocil:title>Verify·User·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>59 ······<ocil:title>Minimize·user·access·to·Amazon·ECR</ocil:title>
90 ······<ocil:actions>60 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_owner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-registry_access_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>62 ······</ocil:actions>
93 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-read_only_registry_access_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-read_only_registry_access_ocil:questionnaire:1">
95 ······<ocil:title>Ensure·Cluster·Service·Account·with·read-only·access·to·Amazon·ECR</ocil:title>65 ······<ocil:title>Ensure·Cluster·Service·Account·with·read-only·access·to·Amazon·ECR</ocil:title>
96 ······<ocil:actions>66 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-read_only_registry_access_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-read_only_registry_access_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>68 ······</ocil:actions>
99 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-configure_network_policy_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-configure_network_policy_ocil:questionnaire:1">
101 ······<ocil:title>Ensure·Network·Policy·is·Enabled</ocil:title>71 ······<ocil:title>Ensure·Network·Policy·is·Enabled</ocil:title>
102 ······<ocil:actions>72 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-configure_network_policy_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-configure_network_policy_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>74 ······</ocil:actions>
105 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_worker_kubeconfig_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-kubelet_configure_client_ca_ocil:questionnaire:1">
107 ······<ocil:title>Verify·Group·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>77 ······<ocil:title>kubelet·-·Configure·the·Client·CA·Certificate</ocil:title>
108 ······<ocil:actions>78 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-kubelet_configure_client_ca_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>80 ······</ocil:actions>
111 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-kubelet_anonymous_auth_ocil:questionnaire:1">
113 ······<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>83 ······<ocil:title>Disable·Anonymous·Authentication·to·the·Kubelet</ocil:title>
114 ······<ocil:actions>84 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-kubelet_anonymous_auth_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>86 ······</ocil:actions>
117 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_protect_kernel_defaults_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_ocil:questionnaire:1">
119 ······<ocil:title>kubelet·-·Enable·Protect·Kernel·Defaults</ocil:title>89 ······<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>
120 ······<ocil:actions>90 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_protect_kernel_defaults_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>92 ······</ocil:actions>
123 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_kubelet_conf_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-image_scanning_ocil:questionnaire:1">
125 ······<ocil:title>Verify·Permissions·on·The·Kubelet·Configuration·File</ocil:title>95 ······<ocil:title>Ensure·Image·Vulnerability·Scanning</ocil:title>
126 ······<ocil:actions>96 ······<ocil:actions>
Max diff block lines reached; 77642/87766 bytes (88.46%) of diff not shown.
3.55 KB
./usr/share/xml/scap/ssg/content/ssg-eks-xccdf.xml
3.45 KB
./usr/share/xml/scap/ssg/content/ssg-eks-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_EKS"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_EKS"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·Amazon·Elastic·Kubernetes·Service.·It·is·a·rendering·of7 configuration·settings·for·Amazon·Elastic·Kubernetes·Service.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
Offset 72, 24 lines modifiedOffset 72, 24 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="not_ocp4-on-hypershift"> 
80 ······<cpe-lang:logical-test·operator="AND"·negate="true"> 
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift:def:1"/> 
82 ······</cpe-lang:logical-test> 
83 ····</cpe-lang:platform> 
84 ····<cpe-lang:platform·id="eks-node">79 ····<cpe-lang:platform·id="eks-node">
85 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_eks_node:def:1"/>81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_eks_node:def:1"/>
87 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
 84 ····<cpe-lang:platform·id="not_ocp4-on-hypershift">
 85 ······<cpe-lang:logical-test·operator="AND"·negate="true">
 86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift:def:1"/>
 87 ······</cpe-lang:logical-test>
 88 ····</cpe-lang:platform>
89 ··</cpe-lang:platform-specification>89 ··</cpe-lang:platform-specification>
90 ··<xccdf-1.2:platform·idref="cpe:/a:amazon:elastic_kubernetes_service_node:1.21"/>90 ··<xccdf-1.2:platform·idref="cpe:/a:amazon:elastic_kubernetes_service_node:1.21"/>
91 ··<xccdf-1.2:platform·idref="cpe:/o:amazon:elastic_kubernetes_service_node:1"/>91 ··<xccdf-1.2:platform·idref="cpe:/o:amazon:elastic_kubernetes_service_node:1"/>
92 ··<xccdf-1.2:platform·idref="cpe:/a:amazon:elastic_kubernetes_service:1"/>92 ··<xccdf-1.2:platform·idref="cpe:/a:amazon:elastic_kubernetes_service:1"/>
93 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.74</xccdf-1.2:version>93 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.74</xccdf-1.2:version>
94 ··<xccdf-1.2:metadata>94 ··<xccdf-1.2:metadata>
95 ····<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>95 ····<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>
56.0 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ds.xml
55.9 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ds.xml
    
Offset 19, 25 lines modifiedOffset 19, 25 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-cpe-dictionary.xml"·timestamp="2024-11-02T06:39:34">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-cpe-dictionary.xml"·timestamp="2024-11-03T08:39:34">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:mozilla:firefox">28 ······<cpe-dict:cpe-item·name="cpe:/a:mozilla:firefox">
29 ········<cpe-dict:title·xml:lang="en-us">Mozilla·Firefox</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Mozilla·Firefox</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-firefox-cpe-oval.xml">oval:ssg-installed_app_is_firefox:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-firefox-cpe-oval.xml">oval:ssg-installed_app_is_firefox:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-xccdf.xml"·timestamp="2024-11-02T06:39:34">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-xccdf.xml"·timestamp="2024-11-03T08:39:34">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FIREFOX"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FIREFOX"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Firefox</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Firefox</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Firefox.·It·is·a·rendering·of40 configuration·settings·for·Firefox.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
42 in·order·to·support·security·automation.··The·SCAP·content·is42 in·order·to·support·security·automation.··The·SCAP·content·is
43 is·available·in·the43 is·available·in·the
Offset 3479, 15 lines modifiedOffset 3479, 15 lines modified
3479 ··············<xccdf-1.2:check-content-ref·href="ssg-firefox-ocil.xml"·name="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1"/>3479 ··············<xccdf-1.2:check-content-ref·href="ssg-firefox-ocil.xml"·name="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1"/>
3480 ············</xccdf-1.2:check>3480 ············</xccdf-1.2:check>
3481 ··········</xccdf-1.2:Rule>3481 ··········</xccdf-1.2:Rule>
3482 ········</xccdf-1.2:Group>3482 ········</xccdf-1.2:Group>
3483 ······</xccdf-1.2:Group>3483 ······</xccdf-1.2:Group>
3484 ····</xccdf-1.2:Benchmark>3484 ····</xccdf-1.2:Benchmark>
3485 ··</ds:component>3485 ··</ds:component>
3486 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-oval.xml"·timestamp="2024-11-02T06:39:34">3486 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-oval.xml"·timestamp="2024-11-03T08:39:34">
3487 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">3487 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
3488 ······<oval-def:generator>3488 ······<oval-def:generator>
3489 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>3489 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
3490 ········<oval:product_version>ssg:·[0,·1,·74],·python:·3.12.7</oval:product_version>3490 ········<oval:product_version>ssg:·[0,·1,·74],·python:·3.12.7</oval:product_version>
3491 ········<oval:schema_version>5.11</oval:schema_version>3491 ········<oval:schema_version>5.11</oval:schema_version>
3492 ········<oval:timestamp>2024-11-02T18:39:34</oval:timestamp>3492 ········<oval:timestamp>2024-11-02T18:39:34</oval:timestamp>
3493 ······</oval-def:generator>3493 ······</oval-def:generator>
Offset 5189, 304 lines modifiedOffset 5189, 304 lines modified
5189 ··············<oval-def:literal_component>/distribution</oval-def:literal_component>5189 ··············<oval-def:literal_component>/distribution</oval-def:literal_component>
5190 ············</oval-def:concat>5190 ············</oval-def:concat>
5191 ··········</oval-def:unique>5191 ··········</oval-def:unique>
5192 ········</oval-def:local_variable>5192 ········</oval-def:local_variable>
5193 ······</oval-def:variables>5193 ······</oval-def:variables>
5194 ····</oval-def:oval_definitions>5194 ····</oval-def:oval_definitions>
5195 ··</ds:component>5195 ··</ds:component>
5196 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-ocil.xml"·timestamp="2024-11-02T06:39:34">5196 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-ocil.xml"·timestamp="2024-11-03T08:39:34">
5197 ····<ocil:ocil>5197 ····<ocil:ocil>
5198 ······<ocil:generator>5198 ······<ocil:generator>
5199 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>5199 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5200 ········<ocil:product_version>ssg:·0.1.74</ocil:product_version>5200 ········<ocil:product_version>ssg:·0.1.74</ocil:product_version>
5201 ········<ocil:schema_version>2.0</ocil:schema_version>5201 ········<ocil:schema_version>2.0</ocil:schema_version>
5202 ········<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>5202 ········<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
5203 ······</ocil:generator>5203 ······</ocil:generator>
5204 ······<ocil:questionnaires>5204 ······<ocil:questionnaires>
5205 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_studies_ocil:questionnaire:1">5205 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_suggestion_ocil:questionnaire:1">
 5206 ··········<ocil:title>Firefox·search·suggestions·must·be·disabled.</ocil:title>
5206 ··········<ocil:title>Disable·Firefox·Studies</ocil:title> 
5207 ··········<ocil:actions> 
5208 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_studies_action:testaction:1</ocil:test_action_ref> 
5209 ··········</ocil:actions> 
5210 ········</ocil:questionnaire> 
5211 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_recommendation_ocil:questionnaire:1"> 
5212 ··········<ocil:title>Disabled·Firefox·Extension·Recommendations</ocil:title> 
5213 ··········<ocil:actions> 
5214 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_recommendation_action:testaction:1</ocil:test_action_ref> 
5215 ··········</ocil:actions> 
5216 ········</ocil:questionnaire> 
5217 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1"> 
5218 ··········<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title> 
5219 ··········<ocil:actions>5207 ··········<ocil:actions>
5220 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>5208 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-search_suggestion_action:testaction:1</ocil:test_action_ref>
5221 ··········</ocil:actions>5209 ··········</ocil:actions>
5222 ········</ocil:questionnaire>5210 ········</ocil:questionnaire>
5223 ········<ocil:questionnaire·id="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1">5211 ········<ocil:questionnaire·id="ocil:ssg-installed_firefox_version_supported_ocil:questionnaire:1">
5224 ··········<ocil:title>Enable·Shared·System·Certificates</ocil:title>5212 ··········<ocil:title>Supported·Version·of·Firefox·Installed</ocil:title>
5225 ··········<ocil:actions>5213 ··········<ocil:actions>
5226 ············<ocil:test_action_ref>ocil:ssg-firefox_preferences-enable_ca_trust_action:testaction:1</ocil:test_action_ref>5214 ············<ocil:test_action_ref>ocil:ssg-installed_firefox_version_supported_action:testaction:1</ocil:test_action_ref>
5227 ··········</ocil:actions>5215 ··········</ocil:actions>
5228 ········</ocil:questionnaire>5216 ········</ocil:questionnaire>
5229 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1">5217 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-enhanced_tracking_ocil:questionnaire:1">
5230 ··········<ocil:title>Disable·Firefox·Pocket</ocil:title>5218 ··········<ocil:title>Enabled·Firefox·Enhanced·Tracking·Protection</ocil:title>
5231 ··········<ocil:actions>5219 ··········<ocil:actions>
5232 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref>5220 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-enhanced_tracking_action:testaction:1</ocil:test_action_ref>
5233 ··········</ocil:actions>5221 ··········</ocil:actions>
5234 ········</ocil:questionnaire>5222 ········</ocil:questionnaire>
5235 ········<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">5223 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-forget_button_ocil:questionnaire:1">
5236 ··········<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title>5224 ··········<ocil:title>Firefox·must·prevent·the·user·from·quickly·deleting·data.</ocil:title>
5237 ··········<ocil:actions>5225 ··········<ocil:actions>
5238 ············<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref>5226 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-forget_button_action:testaction:1</ocil:test_action_ref>
5239 ··········</ocil:actions>5227 ··········</ocil:actions>
5240 ········</ocil:questionnaire>5228 ········</ocil:questionnaire>
5241 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1">5229 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1">
5242 ··········<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title>5230 ··········<ocil:title>Enable·Firefox·Pop-up·Blocker</ocil:title>
5243 ··········<ocil:actions>5231 ··········<ocil:actions>
5244 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref>5232 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1</ocil:test_action_ref>
5245 ··········</ocil:actions>5233 ··········</ocil:actions>
5246 ········</ocil:questionnaire>5234 ········</ocil:questionnaire>
5247 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-forget_button_ocil:questionnaire:1">5235 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-network_prediction_ocil:questionnaire:1">
5248 ··········<ocil:title>Firefox·must·prevent·the·user·from·quickly·deleting·data.</ocil:title>5236 ··········<ocil:title>Disable·Firefox·network·prediction</ocil:title>
5249 ··········<ocil:actions>5237 ··········<ocil:actions>
5250 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-forget_button_action:testaction:1</ocil:test_action_ref>5238 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-network_prediction_action:testaction:1</ocil:test_action_ref>
5251 ··········</ocil:actions>5239 ··········</ocil:actions>
5252 ········</ocil:questionnaire>5240 ········</ocil:questionnaire>
5253 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_update_ocil:questionnaire:1">5241 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1">
5254 ··········<ocil:title>Firefox·must·be·configured·to·not·automatically·update·installed·add-ons·and·plugins.</ocil:title>5242 ··········<ocil:title>Disable·Firefox·Pocket</ocil:title>
5255 ··········<ocil:actions>5243 ··········<ocil:actions>
5256 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_update_action:testaction:1</ocil:test_action_ref>5244 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref>
5257 ··········</ocil:actions>5245 ··········</ocil:actions>
5258 ········</ocil:questionnaire>5246 ········</ocil:questionnaire>
5259 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1">5247 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1">
5260 ··········<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title>5248 ··········<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title>
5261 ··········<ocil:actions>5249 ··········<ocil:actions>
5262 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref>5250 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref>
5263 ··········</ocil:actions>5251 ··········</ocil:actions>
5264 ········</ocil:questionnaire>5252 ········</ocil:questionnaire>
5265 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1">5253 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1">
5266 ··········<ocil:title>Disable·Firefox·Development·Tools</ocil:title>5254 ··········<ocil:title>Disable·Firefox·Development·Tools</ocil:title>
5267 ··········<ocil:actions>5255 ··········<ocil:actions>
5268 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref>5256 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref>
5269 ··········</ocil:actions>5257 ··········</ocil:actions>
5270 ········</ocil:questionnaire>5258 ········</ocil:questionnaire>
5271 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-content_blocker_ocil:questionnaire:1">5259 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_deprecated_ciphers_ocil:questionnaire:1">
5272 ··········<ocil:title>Ensure·the·Content·Blocker·uBlock·Origin·is·Installed</ocil:title>5260 ··········<ocil:title>Disable·Firefox·deprecated·ciphers</ocil:title>
Max diff block lines reached; 46076/57143 bytes (80.63%) of diff not shown.
48.8 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ocil.xml
48.7 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ocil.xml
Ordering differences only
    
Offset 3, 295 lines modifiedOffset 3, 295 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_studies_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_suggestion_ocil:questionnaire:1">
 11 ······<ocil:title>Firefox·search·suggestions·must·be·disabled.</ocil:title>
11 ······<ocil:title>Disable·Firefox·Studies</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_studies_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_recommendation_ocil:questionnaire:1"> 
17 ······<ocil:title>Disabled·Firefox·Extension·Recommendations</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_recommendation_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1"> 
23 ······<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title> 
24 ······<ocil:actions>12 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-search_suggestion_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>14 ······</ocil:actions>
27 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1"> 
29 ······<ocil:title>Enable·Shared·System·Certificates</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-installed_firefox_version_supported_ocil:questionnaire:1">
 17 ······<ocil:title>Supported·Version·of·Firefox·Installed</ocil:title>
30 ······<ocil:actions>18 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-enable_ca_trust_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-installed_firefox_version_supported_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>20 ······</ocil:actions>
33 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-enhanced_tracking_ocil:questionnaire:1">
35 ······<ocil:title>Disable·Firefox·Pocket</ocil:title>23 ······<ocil:title>Enabled·Firefox·Enhanced·Tracking·Protection</ocil:title>
36 ······<ocil:actions>24 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-enhanced_tracking_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>26 ······</ocil:actions>
39 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-forget_button_ocil:questionnaire:1">
41 ······<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title>29 ······<ocil:title>Firefox·must·prevent·the·user·from·quickly·deleting·data.</ocil:title>
42 ······<ocil:actions>30 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-forget_button_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>32 ······</ocil:actions>
45 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1">
47 ······<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title>35 ······<ocil:title>Enable·Firefox·Pop-up·Blocker</ocil:title>
48 ······<ocil:actions>36 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>38 ······</ocil:actions>
51 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-forget_button_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-network_prediction_ocil:questionnaire:1">
53 ······<ocil:title>Firefox·must·prevent·the·user·from·quickly·deleting·data.</ocil:title>41 ······<ocil:title>Disable·Firefox·network·prediction</ocil:title>
54 ······<ocil:actions>42 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-forget_button_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-network_prediction_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>44 ······</ocil:actions>
57 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_update_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1">
59 ······<ocil:title>Firefox·must·be·configured·to·not·automatically·update·installed·add-ons·and·plugins.</ocil:title>47 ······<ocil:title>Disable·Firefox·Pocket</ocil:title>
60 ······<ocil:actions>48 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_update_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>50 ······</ocil:actions>
63 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1">
65 ······<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title>53 ······<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title>
66 ······<ocil:actions>54 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>56 ······</ocil:actions>
69 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1">
71 ······<ocil:title>Disable·Firefox·Development·Tools</ocil:title>59 ······<ocil:title>Disable·Firefox·Development·Tools</ocil:title>
72 ······<ocil:actions>60 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>62 ······</ocil:actions>
75 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-content_blocker_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_deprecated_ciphers_ocil:questionnaire:1">
77 ······<ocil:title>Ensure·the·Content·Blocker·uBlock·Origin·is·Installed</ocil:title>65 ······<ocil:title>Disable·Firefox·deprecated·ciphers</ocil:title>
78 ······<ocil:actions>66 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-content_blocker_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_deprecated_ciphers_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>68 ······</ocil:actions>
81 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-dod_root_certificate_installed_ocil:questionnaire:1"> 
83 ······<ocil:title>The·DoD·Root·Certificate·Exists</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-content_blocker_ocil:questionnaire:1">
 71 ······<ocil:title>Ensure·the·Content·Blocker·uBlock·Origin·is·Installed</ocil:title>
84 ······<ocil:actions>72 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-dod_root_certificate_installed_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-content_blocker_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>74 ······</ocil:actions>
87 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-verification_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-verification_ocil:questionnaire:1">
89 ······<ocil:title>Enable·Certificate·Verification</ocil:title>77 ······<ocil:title>Enable·Certificate·Verification</ocil:title>
90 ······<ocil:actions>78 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-verification_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-verification_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>80 ······</ocil:actions>
93 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_deprecated_ciphers_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1">
95 ······<ocil:title>Disable·Firefox·deprecated·ciphers</ocil:title>83 ······<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title>
96 ······<ocil:actions>84 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_deprecated_ciphers_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-fingerprinting_protection_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>86 ······</ocil:actions>
99 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-enhanced_tracking_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_update_ocil:questionnaire:1">
101 ······<ocil:title>Enabled·Firefox·Enhanced·Tracking·Protection</ocil:title>89 ······<ocil:title>Firefox·must·be·configured·to·not·automatically·update·installed·add-ons·and·plugins.</ocil:title>
102 ······<ocil:actions>90 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-enhanced_tracking_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_update_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>92 ······</ocil:actions>
105 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_recommendation_ocil:questionnaire:1">
107 ······<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title>95 ······<ocil:title>Disabled·Firefox·Extension·Recommendations</ocil:title>
108 ······<ocil:actions>96 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-fingerprinting_protection_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_recommendation_action:testaction:1</ocil:test_action_ref>
 98 ······</ocil:actions>
 99 ····</ocil:questionnaire>
 100 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1">
 101 ······<ocil:title>Enable·Shared·System·Certificates</ocil:title>
 102 ······<ocil:actions>
 103 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-enable_ca_trust_action:testaction:1</ocil:test_action_ref>
 104 ······</ocil:actions>
 105 ····</ocil:questionnaire>
 106 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_studies_ocil:questionnaire:1">
 107 ······<ocil:title>Disable·Firefox·Studies</ocil:title>
 108 ······<ocil:actions>
 109 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_studies_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">
113 ······<ocil:title>Disable·Firefox·Telemetry</ocil:title>113 ······<ocil:title>Disable·Firefox·Telemetry</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
Max diff block lines reached; 38851/49767 bytes (78.07%) of diff not shown.
1.16 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-xccdf.xml
1.06 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_FIREFOX"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_FIREFOX"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Firefox</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Firefox</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·Firefox.·It·is·a·rendering·of7 configuration·settings·for·Firefox.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
191 MB
ssg-debderived_0.1.74-1_all.deb
452 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2024-11-02·18:39:34.000000·debian-binary1 -rw-r--r--···0········0········0········4·2024-11-02·18:39:34.000000·debian-binary
2 -rw-r--r--···0········0········0·····2744·2024-11-02·18:39:34.000000·control.tar.xz2 -rw-r--r--···0········0········0·····2736·2024-11-02·18:39:34.000000·control.tar.xz
3 -rw-r--r--···0········0········0··2804968·2024-11-02·18:39:34.000000·data.tar.xz3 -rw-r--r--···0········0········0··2806504·2024-11-02·18:39:34.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
191 MB
data.tar.xz
191 MB
data.tar
987 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1604-guide-anssi_np_nt28_average.html
    
Offset 14287, 15 lines modifiedOffset 14287, 15 lines modified
00037ce0:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·00037ce0:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·
00037cf0:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong00037cf0:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong
00037d00:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>00037d00:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>
00037d10:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str00037d10:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str
00037d20:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron00037d20:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron
00037d30:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············00037d30:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············
00037d40:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·2000037d40:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·20
00037d50:·3236·2d30·312d·3038·290a·2020·2020·2020··26-01-08).······00037d50:·3234·2d31·322d·3037·290a·2020·2020·2020··24-12-07).······
00037d60:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><00037d60:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><
00037d70:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta00037d70:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta
00037d80:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<00037d80:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<
00037d90:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h00037d90:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h
00037da0:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.00037da0:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.
00037db0:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte00037db0:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte
00037dc0:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"00037dc0:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"
Offset 16004, 147 lines modifiedOffset 16004, 147 lines modified
0003e830:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003e830:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003e840:·743d·2223·6964·6d31·3735·3422·2074·6162··t="#idm1754"·tab0003e840:·743d·2223·6964·6d31·3735·3422·2074·6162··t="#idm1754"·tab
0003e850:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003e850:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003e860:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003e860:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003e870:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003e870:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003e880:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003e880:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003e890:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003e890:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003e8a0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
0003e8b0:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
0003e8c0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003e8d0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003e8e0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003e8f0:·6964·6d31·3735·3422·3e3c·7461·626c·6520··idm1754"><table· 
0003e900:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003e910:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003e920:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003e930:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003e940:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003e950:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003e960:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003e970:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003e980:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003e990:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003e9a0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003e9b0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003e9c0:·7465·6779·3a3c·2f74·683e·3c74·643e·7265··tegy:</th><td>re 
0003e9d0:·7374·7269·6374·3c2f·7464·3e3c·2f74·723e··strict</td></tr> 
0003e9e0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003e9f0:·6465·3e0a·666f·7220·6620·696e·202f·6574··de>.for·f·in·/et 
0003ea00:·632f·7375·646f·6572·7320·2f65·7463·2f73··c/sudoers·/etc/s 
0003ea10:·7564·6f65·7273·2e64·2f2a·203b·2064·6f0a··udoers.d/*·;·do. 
0003ea20:·2020·6966·205b·2021·202d·6520·2224·6622····if·[·!·-e·"$f" 
0003ea30:·205d·203b·2074·6865·6e0a·2020·2020·636f···]·;·then.····co 
0003ea40:·6e74·696e·7565·0a20·2066·690a·2020·6d61··ntinue.··fi.··ma 
0003ea50:·7463·6869·6e67·5f6c·6973·743d·2428·6772··tching_list=$(gr 
0003ea60:·6570·202d·5020·275e·283f·2123·292e·2a5b··ep·-P·'^(?!#).*[ 
0003ea70:·5c73·5d2b·5c21·6175·7468·656e·7469·6361··\s]+\!authentica 
0003ea80:·7465·2e2a·2427·2024·6620·7c20·756e·6971··te.*$'·$f·|·uniq 
0003ea90:·2029·0a20·2069·6620·2120·7465·7374·202d···).··if·!·test·- 
0003eaa0:·7a20·2224·6d61·7463·6869·6e67·5f6c·6973··z·"$matching_lis 
0003eab0:·7422·3b20·7468·656e·0a20·2020·2077·6869··t";·then.····whi 
0003eac0:·6c65·2049·4653·3d20·7265·6164·202d·7220··le·IFS=·read·-r· 
0003ead0:·656e·7472·793b·2064·6f0a·2020·2020·2020··entry;·do.······ 
0003eae0:·2320·636f·6d6d·656e·7420·6f75·7420·2221··#·comment·out·"! 
0003eaf0:·6175·7468·656e·7469·6361·7465·2220·6d61··authenticate"·ma 
0003eb00:·7463·6865·7320·746f·2070·7265·7365·7276··tches·to·preserv 
0003eb10:·6520·7573·6572·2064·6174·610a·2020·2020··e·user·data.···· 
0003eb20:·2020·7365·6420·2d69·2022·732f·5e24·7b65····sed·-i·"s/^${e 
0003eb30:·6e74·7279·7d24·2f23·2026·616d·703b·2f67··ntry}$/#·&amp;/g 
0003eb40:·2220·2466·0a20·2020·2064·6f6e·6520·266c··"·$f.····done·&l 
0003eb50:·743b·266c·743b·266c·743b·2022·246d·6174··t;&lt;&lt;·"$mat 
0003eb60:·6368·696e·675f·6c69·7374·220a·0a20·2020··ching_list"..··· 
0003eb70:·202f·7573·722f·7362·696e·2f76·6973·7564···/usr/sbin/visud 
0003eb80:·6f20·2d63·6620·2466·2026·616d·703b·2667··o·-cf·$f·&amp;&g 
0003eb90:·743b·202f·6465·762f·6e75·6c6c·207c·7c20··t;·/dev/null·||· 
0003eba0:·6563·686f·2022·4661·696c·2074·6f20·7661··echo·"Fail·to·va 
0003ebb0:·6c69·6461·7465·2024·6620·7769·7468·2076··lidate·$f·with·v 
0003ebc0:·6973·7564·6f22·0a20·2066·690a·646f·6e65··isudo".··fi.done 
0003ebd0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003ebe0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003ebf0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003ec00:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003ec10:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003ec20:·743d·2223·6964·6d31·3735·3522·2074·6162··t="#idm1755"·tab 
0003ec30:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003ec40:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003ec50:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003ec60:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003ec70:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003ec80:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A0003e8a0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
0003ec90:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.0003e8b0:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.
0003eca0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003e8c0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003ecb0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003e8d0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003ecc0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003e8e0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003ecd0:·643d·2269·646d·3137·3535·223e·3c74·6162··d="idm1755"><tab0003e8f0:·643d·2269·646d·3137·3534·223e·3c74·6162··d="idm1754"><tab
0003ece0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003e900:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003ecf0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003e910:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003ed00:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003e920:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003ed10:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003e930:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003ed20:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003e940:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003ed30:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003e950:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003ed40:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003e960:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
0003ed50:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003e970:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003ed60:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003e980:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003ed70:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<0003e990:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
0003ed80:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003e9a0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003ed90:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003e9b0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003eda0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003e9c0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003edb0:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></0003e9d0:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></
0003edc0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003e9e0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
0003edd0:·3c63·6f64·653e·2d20·6e61·6d65·3a20·4669··<code>-·name:·Fi0003e9f0:·3c63·6f64·653e·2d20·6e61·6d65·3a20·4669··<code>-·name:·Fi
0003ede0:·6e64·202f·6574·632f·7375·646f·6572·732e··nd·/etc/sudoers.0003ea00:·6e64·202f·6574·632f·7375·646f·6572·732e··nd·/etc/sudoers.
0003edf0:·642f·2066·696c·6573·0a20·2061·6e73·6962··d/·files.··ansib0003ea10:·642f·2066·696c·6573·0a20·2061·6e73·6962··d/·files.··ansib
0003ee00:·6c65·2e62·7569·6c74·696e·2e66·696e·643a··le.builtin.find:0003ea20:·6c65·2e62·7569·6c74·696e·2e66·696e·643a··le.builtin.find:
0003ee10:·0a20·2020·2070·6174·6873·3a0a·2020·2020··.····paths:.····0003ea30:·0a20·2020·2070·6174·6873·3a0a·2020·2020··.····paths:.····
0003ee20:·2d20·2f65·7463·2f73·7564·6f65·7273·2e64··-·/etc/sudoers.d0003ea40:·2d20·2f65·7463·2f73·7564·6f65·7273·2e64··-·/etc/sudoers.d
0003ee30:·2f0a·2020·7265·6769·7374·6572·3a20·7375··/.··register:·su0003ea50:·2f0a·2020·7265·6769·7374·6572·3a20·7375··/.··register:·su
0003ee40:·646f·6572·730a·2020·7461·6773·3a0a·2020··doers.··tags:.··0003ea60:·646f·6572·730a·2020·7461·6773·3a0a·2020··doers.··tags:.··
0003ee50:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM0003ea70:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
0003ee60:·2d36·2861·290a·2020·2d20·4e49·5354·2d38··-6(a).··-·NIST-80003ea80:·2d36·2861·290a·2020·2d20·4e49·5354·2d38··-6(a).··-·NIST-8
0003ee70:·3030·2d35·332d·4941·2d31·310a·2020·2d20··00-53-IA-11.··-·0003ea90:·3030·2d35·332d·4941·2d31·310a·2020·2d20··00-53-IA-11.··-·
0003ee80:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.·0003eaa0:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.·
0003ee90:·202d·206c·6f77·5f64·6973·7275·7074·696f···-·low_disruptio0003eab0:·202d·206c·6f77·5f64·6973·7275·7074·696f···-·low_disruptio
0003eea0:·6e0a·2020·2d20·6d65·6469·756d·5f73·6576··n.··-·medium_sev0003eac0:·6e0a·2020·2d20·6d65·6469·756d·5f73·6576··n.··-·medium_sev
0003eeb0:·6572·6974·790a·2020·2d20·6e6f·5f72·6562··erity.··-·no_reb0003ead0:·6572·6974·790a·2020·2d20·6e6f·5f72·6562··erity.··-·no_reb
0003eec0:·6f6f·745f·6e65·6564·6564·0a20·202d·2072··oot_needed.··-·r0003eae0:·6f6f·745f·6e65·6564·6564·0a20·202d·2072··oot_needed.··-·r
0003eed0:·6573·7472·6963·745f·7374·7261·7465·6779··estrict_strategy0003eaf0:·6573·7472·6963·745f·7374·7261·7465·6779··estrict_strategy
0003eee0:·0a20·202d·2073·7564·6f5f·7265·6d6f·7665··.··-·sudo_remove0003eb00:·0a20·202d·2073·7564·6f5f·7265·6d6f·7665··.··-·sudo_remove
0003eef0:·5f6e·6f5f·6175·7468·656e·7469·6361·7465··_no_authenticate0003eb10:·5f6e·6f5f·6175·7468·656e·7469·6361·7465··_no_authenticate
0003ef00:·0a0a·2d20·6e61·6d65·3a20·5265·6d6f·7665··..-·name:·Remove0003eb20:·0a0a·2d20·6e61·6d65·3a20·5265·6d6f·7665··..-·name:·Remove
0003ef10:·206c·696e·6573·2063·6f6e·7461·696e·696e···lines·containin0003eb30:·206c·696e·6573·2063·6f6e·7461·696e·696e···lines·containin
Max diff block lines reached; 877578/897642 bytes (97.76%) of diff not shown.
110 KB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Average·(Intermediate)·Level38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Average·(Intermediate)·Level
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_average39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_average
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~
42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
43 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8443 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
48 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g48 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
49 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s49 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
50 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s50 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
51 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n51 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
Offset 227, 35 lines modifiedOffset 227, 14 lines modified
227 ···························1.7,·SR·1.8,·SR·1.9227 ···························1.7,·SR·1.8,·SR·1.9
228 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,228 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
229 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3229 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
230 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)230 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
231 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7231 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
232 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,232 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
233 ···························SRG-OS-000373-GPOS-00158233 ···························SRG-OS-000373-GPOS-00158
234 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
235 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
236 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
237 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
238 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
239 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
240 ··if·[·!·-e·"$f"·]·;·then 
241 ····continue 
242 ··fi 
243 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·) 
244 ··if·!·test·-z·"$matching_list";·then 
245 ····while·IFS=·read·-r·entry;·do 
246 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data 
247 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
248 ····done·<<<·"$matching_list" 
  
249 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
250 visudo" 
251 ··fi 
252 done 
253 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8234 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
254 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low235 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
255 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low236 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
256 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false237 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
257 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict238 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
258 -·name:·Find·/etc/sudoers.d/·files239 -·name:·Find·/etc/sudoers.d/·files
259 ··ansible.builtin.find:240 ··ansible.builtin.find:
Offset 286, 14 lines modifiedOffset 265, 35 lines modified
286 ··-·NIST-800-53-IA-11265 ··-·NIST-800-53-IA-11
287 ··-·low_complexity266 ··-·low_complexity
288 ··-·low_disruption267 ··-·low_disruption
289 ··-·medium_severity268 ··-·medium_severity
290 ··-·no_reboot_needed269 ··-·no_reboot_needed
291 ··-·restrict_strategy270 ··-·restrict_strategy
292 ··-·sudo_remove_no_authenticate271 ··-·sudo_remove_no_authenticate
 272 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 273 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 274 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 275 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 276 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 277 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do
 278 ··if·[·!·-e·"$f"·]·;·then
 279 ····continue
 280 ··fi
 281 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·)
 282 ··if·!·test·-z·"$matching_list";·then
 283 ····while·IFS=·read·-r·entry;·do
 284 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data
 285 ······sed·-i·"s/^${entry}$/#·&/g"·$f
 286 ····done·<<<·"$matching_list"
  
 287 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with
 288 visudo"
 289 ··fi
 290 done
293 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o291 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o
294 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*292 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
295 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using293 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using
296 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure294 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure
297 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any295 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any
298 sudo·configuration·snippets·in·/etc/sudoers.d/.296 sudo·configuration·snippets·in·/etc/sudoers.d/.
299 ············Without·re-authentication,·users·may·access·resources·or·perform297 ············Without·re-authentication,·users·may·access·resources·or·perform
Offset 314, 35 lines modifiedOffset 314, 14 lines modified
314 ···························1.7,·SR·1.8,·SR·1.9314 ···························1.7,·SR·1.8,·SR·1.9
315 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,315 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
316 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3316 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
317 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)317 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
318 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7318 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
319 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,319 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
320 ···························SRG-OS-000373-GPOS-00158320 ···························SRG-OS-000373-GPOS-00158
321 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
322 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
323 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
324 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
325 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
326 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
327 ··if·[·!·-e·"$f"·]·;·then 
328 ····continue 
329 ··fi 
330 ··matching_list=$(grep·-P·'^(?!#).*[\s]+NOPASSWD[\s]*\:.*$'·$f·|·uniq·) 
331 ··if·!·test·-z·"$matching_list";·then 
332 ····while·IFS=·read·-r·entry;·do 
333 ······#·comment·out·"NOPASSWD"·matches·to·preserve·user·data 
334 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
335 ····done·<<<·"$matching_list" 
  
336 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
337 visudo" 
338 ··fi 
339 done 
340 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8321 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
341 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low322 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
342 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low323 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
343 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false324 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
344 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict325 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
345 -·name:·Find·/etc/sudoers.d/·files326 -·name:·Find·/etc/sudoers.d/·files
346 ··ansible.builtin.find:327 ··ansible.builtin.find:
Offset 373, 14 lines modifiedOffset 352, 35 lines modified
373 ··-·NIST-800-53-IA-11352 ··-·NIST-800-53-IA-11
374 ··-·low_complexity353 ··-·low_complexity
375 ··-·low_disruption354 ··-·low_disruption
Max diff block lines reached; 107105/112854 bytes (94.91%) of diff not shown.
1.1 MB
./usr/share/doc/ssg-debderived/ssg-ubuntu1604-guide-anssi_np_nt28_high.html
    
Offset 14288, 15 lines modifiedOffset 14288, 15 lines modified
00037cf0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00037cf0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00037d00:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00037d00:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00037d10:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s00037d10:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00037d20:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00037d20:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00037d30:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00037d30:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00037d40:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00037d40:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00037d50:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00037d50:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00037d60:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).00037d60:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
00037d70:·2020·2020·2020·2020·2020·2020·2020·2020··················00037d70:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037d80:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00037d80:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00037d90:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00037d90:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00037da0:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00037da0:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00037db0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00037db0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00037dc0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00037dc0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00037dd0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00037dd0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
Offset 16025, 146 lines modifiedOffset 16025, 146 lines modified
0003e980:·6172·6765·743d·2223·6964·6d31·3735·3422··arget="#idm1754"0003e980:·6172·6765·743d·2223·6964·6d31·3735·3422··arget="#idm1754"
0003e990:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003e990:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003e9a0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003e9a0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003e9b0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003e9b0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003e9c0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003e9c0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003e9d0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003e9d0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003e9e0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003e9e0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003e9f0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script· 
0003ea00:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003ea10:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003ea20:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003ea30:·6964·3d22·6964·6d31·3735·3422·3e3c·7461··id="idm1754"><ta 
0003ea40:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003ea50:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003ea60:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003ea70:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003ea80:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003ea90:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003eaa0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003eab0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003eac0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003ead0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003eae0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003eaf0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003eb00:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003eb10:·643e·7265·7374·7269·6374·3c2f·7464·3e3c··d>restrict</td>< 
0003eb20:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003eb30:·3e3c·636f·6465·3e0a·666f·7220·6620·696e··><code>.for·f·in 
0003eb40:·202f·6574·632f·7375·646f·6572·7320·2f65···/etc/sudoers·/e 
0003eb50:·7463·2f73·7564·6f65·7273·2e64·2f2a·203b··tc/sudoers.d/*·; 
0003eb60:·2064·6f0a·2020·6966·205b·2021·202d·6520···do.··if·[·!·-e· 
0003eb70:·2224·6622·205d·203b·2074·6865·6e0a·2020··"$f"·]·;·then.·· 
0003eb80:·2020·636f·6e74·696e·7565·0a20·2066·690a····continue.··fi. 
0003eb90:·2020·6d61·7463·6869·6e67·5f6c·6973·743d····matching_list= 
0003eba0:·2428·6772·6570·202d·5020·275e·283f·2123··$(grep·-P·'^(?!# 
0003ebb0:·292e·2a5b·5c73·5d2b·5c21·6175·7468·656e··).*[\s]+\!authen 
0003ebc0:·7469·6361·7465·2e2a·2427·2024·6620·7c20··ticate.*$'·$f·|· 
0003ebd0:·756e·6971·2029·0a20·2069·6620·2120·7465··uniq·).··if·!·te 
0003ebe0:·7374·202d·7a20·2224·6d61·7463·6869·6e67··st·-z·"$matching 
0003ebf0:·5f6c·6973·7422·3b20·7468·656e·0a20·2020··_list";·then.··· 
0003ec00:·2077·6869·6c65·2049·4653·3d20·7265·6164···while·IFS=·read 
0003ec10:·202d·7220·656e·7472·793b·2064·6f0a·2020···-r·entry;·do.·· 
0003ec20:·2020·2020·2320·636f·6d6d·656e·7420·6f75······#·comment·ou 
0003ec30:·7420·2221·6175·7468·656e·7469·6361·7465··t·"!authenticate 
0003ec40:·2220·6d61·7463·6865·7320·746f·2070·7265··"·matches·to·pre 
0003ec50:·7365·7276·6520·7573·6572·2064·6174·610a··serve·user·data. 
0003ec60:·2020·2020·2020·7365·6420·2d69·2022·732f········sed·-i·"s/ 
0003ec70:·5e24·7b65·6e74·7279·7d24·2f23·2026·616d··^${entry}$/#·&am 
0003ec80:·703b·2f67·2220·2466·0a20·2020·2064·6f6e··p;/g"·$f.····don 
0003ec90:·6520·266c·743b·266c·743b·266c·743b·2022··e·&lt;&lt;&lt;·" 
0003eca0:·246d·6174·6368·696e·675f·6c69·7374·220a··$matching_list". 
0003ecb0:·0a20·2020·202f·7573·722f·7362·696e·2f76··.····/usr/sbin/v 
0003ecc0:·6973·7564·6f20·2d63·6620·2466·2026·616d··isudo·-cf·$f·&am 
0003ecd0:·703b·2667·743b·202f·6465·762f·6e75·6c6c··p;&gt;·/dev/null 
0003ece0:·207c·7c20·6563·686f·2022·4661·696c·2074···||·echo·"Fail·t 
0003ecf0:·6f20·7661·6c69·6461·7465·2024·6620·7769··o·validate·$f·wi 
0003ed00:·7468·2076·6973·7564·6f22·0a20·2066·690a··th·visudo".··fi. 
0003ed10:·646f·6e65·0a3c·2f63·6f64·653e·3c2f·7072··done.</code></pr 
0003ed20:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003ed30:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003ed40:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003ed50:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003ed60:·6172·6765·743d·2223·6964·6d31·3735·3522··arget="#idm1755" 
0003ed70:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003ed80:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003ed90:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003eda0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003edb0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003edc0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003edd0:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp0003e9f0:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp
0003ede0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0003ea00:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
0003edf0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003ea10:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0003ee00:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003ea20:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0003ee10:·6522·2069·643d·2269·646d·3137·3535·223e··e"·id="idm1755">0003ea30:·6522·2069·643d·2269·646d·3137·3534·223e··e"·id="idm1754">
0003ee20:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003ea40:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
0003ee30:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003ea50:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
0003ee40:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003ea60:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
0003ee50:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003ea70:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
0003ee60:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003ea80:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003ee70:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003ea90:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0003ee80:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003eaa0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003ee90:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003eab0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
0003eea0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003eac0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003eeb0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo0003ead0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
0003eec0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals0003eae0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
0003eed0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><0003eaf0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
0003eee0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th0003eb00:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0003eef0:·3e3c·7464·3e72·6573·7472·6963·743c·2f74··><td>restrict</t0003eb10:·3e3c·7464·3e72·6573·7472·6963·743c·2f74··><td>restrict</t
0003ef00:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003eb20:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0003ef10:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name0003eb30:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name
0003ef20:·3a20·4669·6e64·202f·6574·632f·7375·646f··:·Find·/etc/sudo0003eb40:·3a20·4669·6e64·202f·6574·632f·7375·646f··:·Find·/etc/sudo
0003ef30:·6572·732e·642f·2066·696c·6573·0a20·2061··ers.d/·files.··a0003eb50:·6572·732e·642f·2066·696c·6573·0a20·2061··ers.d/·files.··a
0003ef40:·6e73·6962·6c65·2e62·7569·6c74·696e·2e66··nsible.builtin.f0003eb60:·6e73·6962·6c65·2e62·7569·6c74·696e·2e66··nsible.builtin.f
0003ef50:·696e·643a·0a20·2020·2070·6174·6873·3a0a··ind:.····paths:.0003eb70:·696e·643a·0a20·2020·2070·6174·6873·3a0a··ind:.····paths:.
0003ef60:·2020·2020·2d20·2f65·7463·2f73·7564·6f65······-·/etc/sudoe0003eb80:·2020·2020·2d20·2f65·7463·2f73·7564·6f65······-·/etc/sudoe
0003ef70:·7273·2e64·2f0a·2020·7265·6769·7374·6572··rs.d/.··register0003eb90:·7273·2e64·2f0a·2020·7265·6769·7374·6572··rs.d/.··register
0003ef80:·3a20·7375·646f·6572·730a·2020·7461·6773··:·sudoers.··tags0003eba0:·3a20·7375·646f·6572·730a·2020·7461·6773··:·sudoers.··tags
0003ef90:·3a0a·2020·2d20·4e49·5354·2d38·3030·2d35··:.··-·NIST-800-50003ebb0:·3a0a·2020·2d20·4e49·5354·2d38·3030·2d35··:.··-·NIST-800-5
0003efa0:·332d·434d·2d36·2861·290a·2020·2d20·4e49··3-CM-6(a).··-·NI0003ebc0:·332d·434d·2d36·2861·290a·2020·2d20·4e49··3-CM-6(a).··-·NI
0003efb0:·5354·2d38·3030·2d35·332d·4941·2d31·310a··ST-800-53-IA-11.0003ebd0:·5354·2d38·3030·2d35·332d·4941·2d31·310a··ST-800-53-IA-11.
0003efc0:·2020·2d20·6c6f·775f·636f·6d70·6c65·7869····-·low_complexi0003ebe0:·2020·2d20·6c6f·775f·636f·6d70·6c65·7869····-·low_complexi
0003efd0:·7479·0a20·202d·206c·6f77·5f64·6973·7275··ty.··-·low_disru0003ebf0:·7479·0a20·202d·206c·6f77·5f64·6973·7275··ty.··-·low_disru
0003efe0:·7074·696f·6e0a·2020·2d20·6d65·6469·756d··ption.··-·medium0003ec00:·7074·696f·6e0a·2020·2d20·6d65·6469·756d··ption.··-·medium
0003eff0:·5f73·6576·6572·6974·790a·2020·2d20·6e6f··_severity.··-·no0003ec10:·5f73·6576·6572·6974·790a·2020·2d20·6e6f··_severity.··-·no
0003f000:·5f72·6562·6f6f·745f·6e65·6564·6564·0a20··_reboot_needed.·0003ec20:·5f72·6562·6f6f·745f·6e65·6564·6564·0a20··_reboot_needed.·
0003f010:·202d·2072·6573·7472·6963·745f·7374·7261···-·restrict_stra0003ec30:·202d·2072·6573·7472·6963·745f·7374·7261···-·restrict_stra
0003f020:·7465·6779·0a20·202d·2073·7564·6f5f·7265··tegy.··-·sudo_re0003ec40:·7465·6779·0a20·202d·2073·7564·6f5f·7265··tegy.··-·sudo_re
0003f030:·6d6f·7665·5f6e·6f5f·6175·7468·656e·7469··move_no_authenti0003ec50:·6d6f·7665·5f6e·6f5f·6175·7468·656e·7469··move_no_authenti
0003f040:·6361·7465·0a0a·2d20·6e61·6d65·3a20·5265··cate..-·name:·Re0003ec60:·6361·7465·0a0a·2d20·6e61·6d65·3a20·5265··cate..-·name:·Re
0003f050:·6d6f·7665·206c·696e·6573·2063·6f6e·7461··move·lines·conta0003ec70:·6d6f·7665·206c·696e·6573·2063·6f6e·7461··move·lines·conta
0003f060:·696e·696e·6720·2161·7574·6865·6e74·6963··ining·!authentic0003ec80:·696e·696e·6720·2161·7574·6865·6e74·6963··ining·!authentic
Max diff block lines reached; 1005327/1025253 bytes (98.06%) of diff not shown.
126 KB
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·High·(Enforced)·Level39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·High·(Enforced)·Level
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_high40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_high
41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
42 ····*·cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~42 ····*·cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~
43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
44 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8444 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
49 ·········2.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n49 ·········2.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
51 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s51 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
52 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s52 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
Offset 231, 35 lines modifiedOffset 231, 14 lines modified
231 ···························1.7,·SR·1.8,·SR·1.9231 ···························1.7,·SR·1.8,·SR·1.9
232 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,232 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
233 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3233 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
234 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)234 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
235 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7235 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
236 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,236 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
237 ···························SRG-OS-000373-GPOS-00158237 ···························SRG-OS-000373-GPOS-00158
238 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
239 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
240 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
241 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
242 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
243 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
244 ··if·[·!·-e·"$f"·]·;·then 
245 ····continue 
246 ··fi 
247 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·) 
248 ··if·!·test·-z·"$matching_list";·then 
249 ····while·IFS=·read·-r·entry;·do 
250 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data 
251 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
252 ····done·<<<·"$matching_list" 
  
253 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
254 visudo" 
255 ··fi 
256 done 
257 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8238 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
258 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low239 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
259 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low240 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
260 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false241 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
261 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict242 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
262 -·name:·Find·/etc/sudoers.d/·files243 -·name:·Find·/etc/sudoers.d/·files
263 ··ansible.builtin.find:244 ··ansible.builtin.find:
Offset 290, 14 lines modifiedOffset 269, 35 lines modified
290 ··-·NIST-800-53-IA-11269 ··-·NIST-800-53-IA-11
291 ··-·low_complexity270 ··-·low_complexity
292 ··-·low_disruption271 ··-·low_disruption
293 ··-·medium_severity272 ··-·medium_severity
294 ··-·no_reboot_needed273 ··-·no_reboot_needed
295 ··-·restrict_strategy274 ··-·restrict_strategy
296 ··-·sudo_remove_no_authenticate275 ··-·sudo_remove_no_authenticate
 276 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 277 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 278 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 279 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 280 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 281 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do
 282 ··if·[·!·-e·"$f"·]·;·then
 283 ····continue
 284 ··fi
 285 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·)
 286 ··if·!·test·-z·"$matching_list";·then
 287 ····while·IFS=·read·-r·entry;·do
 288 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data
 289 ······sed·-i·"s/^${entry}$/#·&/g"·$f
 290 ····done·<<<·"$matching_list"
  
 291 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with
 292 visudo"
 293 ··fi
 294 done
297 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o295 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o
298 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*296 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
299 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using297 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using
300 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure298 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure
301 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any299 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any
302 sudo·configuration·snippets·in·/etc/sudoers.d/.300 sudo·configuration·snippets·in·/etc/sudoers.d/.
303 ············Without·re-authentication,·users·may·access·resources·or·perform301 ············Without·re-authentication,·users·may·access·resources·or·perform
Offset 318, 35 lines modifiedOffset 318, 14 lines modified
318 ···························1.7,·SR·1.8,·SR·1.9318 ···························1.7,·SR·1.8,·SR·1.9
319 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,319 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
320 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3320 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
321 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)321 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
322 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7322 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
323 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,323 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
324 ···························SRG-OS-000373-GPOS-00158324 ···························SRG-OS-000373-GPOS-00158
325 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
326 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
327 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
328 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
329 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
330 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
331 ··if·[·!·-e·"$f"·]·;·then 
332 ····continue 
333 ··fi 
334 ··matching_list=$(grep·-P·'^(?!#).*[\s]+NOPASSWD[\s]*\:.*$'·$f·|·uniq·) 
335 ··if·!·test·-z·"$matching_list";·then 
336 ····while·IFS=·read·-r·entry;·do 
337 ······#·comment·out·"NOPASSWD"·matches·to·preserve·user·data 
338 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
339 ····done·<<<·"$matching_list" 
  
340 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
341 visudo" 
342 ··fi 
343 done 
344 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8325 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
345 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low326 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
346 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low327 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
347 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false328 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
348 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict329 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
349 -·name:·Find·/etc/sudoers.d/·files330 -·name:·Find·/etc/sudoers.d/·files
350 ··ansible.builtin.find:331 ··ansible.builtin.find:
Offset 377, 14 lines modifiedOffset 356, 35 lines modified
377 ··-·NIST-800-53-IA-11356 ··-·NIST-800-53-IA-11
378 ··-·low_complexity357 ··-·low_complexity
379 ··-·low_disruption358 ··-·low_disruption
Max diff block lines reached; 122751/128505 bytes (95.52%) of diff not shown.
302 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1604-guide-anssi_np_nt28_minimal.html
    
Offset 14281, 15 lines modifiedOffset 14281, 15 lines modified
00037c80:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00037c80:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00037c90:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00037c90:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00037ca0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<00037ca0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<
00037cb0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00037cb0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00037cc0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00037cc0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00037cd0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00037cd0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00037ce0:·2020·2020·2020·2020·2020·2020·2020·2028·················(00037ce0:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00037cf0:·6173·206f·6620·3230·3236·2d30·312d·3038··as·of·2026-01-0800037cf0:·6173·206f·6620·3230·3234·2d31·322d·3037··as·of·2024-12-07
00037d00:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00037d00:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00037d10:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00037d10:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00037d20:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00037d20:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00037d30:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00037d30:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00037d40:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00037d40:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00037d50:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00037d50:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00037d60:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00037d60:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
Offset 14774, 147 lines modifiedOffset 14774, 147 lines modified
00039b50:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe00039b50:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
00039b60:·743d·2223·6964·6d31·3735·3422·2074·6162··t="#idm1754"·tab00039b60:·743d·2223·6964·6d31·3735·3422·2074·6162··t="#idm1754"·tab
00039b70:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="00039b70:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
00039b80:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp00039b80:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
00039b90:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti00039b90:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
00039ba0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to00039ba0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
00039bb0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#00039bb0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
00039bc0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
00039bd0:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
00039be0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
00039bf0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
00039c00:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
00039c10:·6964·6d31·3735·3422·3e3c·7461·626c·6520··idm1754"><table· 
00039c20:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
00039c30:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
00039c40:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
00039c50:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
00039c60:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
00039c70:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
00039c80:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
00039c90:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
00039ca0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
00039cb0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
00039cc0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
00039cd0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
00039ce0:·7465·6779·3a3c·2f74·683e·3c74·643e·7265··tegy:</th><td>re 
00039cf0:·7374·7269·6374·3c2f·7464·3e3c·2f74·723e··strict</td></tr> 
00039d00:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
00039d10:·6465·3e0a·666f·7220·6620·696e·202f·6574··de>.for·f·in·/et 
00039d20:·632f·7375·646f·6572·7320·2f65·7463·2f73··c/sudoers·/etc/s 
00039d30:·7564·6f65·7273·2e64·2f2a·203b·2064·6f0a··udoers.d/*·;·do. 
00039d40:·2020·6966·205b·2021·202d·6520·2224·6622····if·[·!·-e·"$f" 
00039d50:·205d·203b·2074·6865·6e0a·2020·2020·636f···]·;·then.····co 
00039d60:·6e74·696e·7565·0a20·2066·690a·2020·6d61··ntinue.··fi.··ma 
00039d70:·7463·6869·6e67·5f6c·6973·743d·2428·6772··tching_list=$(gr 
00039d80:·6570·202d·5020·275e·283f·2123·292e·2a5b··ep·-P·'^(?!#).*[ 
00039d90:·5c73·5d2b·5c21·6175·7468·656e·7469·6361··\s]+\!authentica 
00039da0:·7465·2e2a·2427·2024·6620·7c20·756e·6971··te.*$'·$f·|·uniq 
00039db0:·2029·0a20·2069·6620·2120·7465·7374·202d···).··if·!·test·- 
00039dc0:·7a20·2224·6d61·7463·6869·6e67·5f6c·6973··z·"$matching_lis 
00039dd0:·7422·3b20·7468·656e·0a20·2020·2077·6869··t";·then.····whi 
00039de0:·6c65·2049·4653·3d20·7265·6164·202d·7220··le·IFS=·read·-r· 
00039df0:·656e·7472·793b·2064·6f0a·2020·2020·2020··entry;·do.······ 
00039e00:·2320·636f·6d6d·656e·7420·6f75·7420·2221··#·comment·out·"! 
00039e10:·6175·7468·656e·7469·6361·7465·2220·6d61··authenticate"·ma 
00039e20:·7463·6865·7320·746f·2070·7265·7365·7276··tches·to·preserv 
00039e30:·6520·7573·6572·2064·6174·610a·2020·2020··e·user·data.···· 
00039e40:·2020·7365·6420·2d69·2022·732f·5e24·7b65····sed·-i·"s/^${e 
00039e50:·6e74·7279·7d24·2f23·2026·616d·703b·2f67··ntry}$/#·&amp;/g 
00039e60:·2220·2466·0a20·2020·2064·6f6e·6520·266c··"·$f.····done·&l 
00039e70:·743b·266c·743b·266c·743b·2022·246d·6174··t;&lt;&lt;·"$mat 
00039e80:·6368·696e·675f·6c69·7374·220a·0a20·2020··ching_list"..··· 
00039e90:·202f·7573·722f·7362·696e·2f76·6973·7564···/usr/sbin/visud 
00039ea0:·6f20·2d63·6620·2466·2026·616d·703b·2667··o·-cf·$f·&amp;&g 
00039eb0:·743b·202f·6465·762f·6e75·6c6c·207c·7c20··t;·/dev/null·||· 
00039ec0:·6563·686f·2022·4661·696c·2074·6f20·7661··echo·"Fail·to·va 
00039ed0:·6c69·6461·7465·2024·6620·7769·7468·2076··lidate·$f·with·v 
00039ee0:·6973·7564·6f22·0a20·2066·690a·646f·6e65··isudo".··fi.done 
00039ef0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
00039f00:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
00039f10:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
00039f20:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
00039f30:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
00039f40:·743d·2223·6964·6d31·3735·3522·2074·6162··t="#idm1755"·tab 
00039f50:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
00039f60:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
00039f70:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
00039f80:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
00039f90:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
00039fa0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A00039bc0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
00039fb0:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.00039bd0:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.
00039fc0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c00039be0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
00039fd0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll00039bf0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
00039fe0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i00039c00:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
00039ff0:·643d·2269·646d·3137·3535·223e·3c74·6162··d="idm1755"><tab00039c10:·643d·2269·646d·3137·3534·223e·3c74·6162··d="idm1754"><tab
0003a000:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·00039c20:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003a010:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta00039c30:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003a020:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab00039c40:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003a030:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t00039c50:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003a040:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity00039c60:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003a050:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t00039c70:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003a060:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D00039c80:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
0003a070:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><00039c90:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003a080:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>00039ca0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003a090:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<00039cb0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
0003a0a0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t00039cc0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003a0b0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S00039cd0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003a0c0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td00039ce0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003a0d0:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></00039cf0:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></
0003a0e0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>00039d00:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
0003a0f0:·3c63·6f64·653e·2d20·6e61·6d65·3a20·4669··<code>-·name:·Fi00039d10:·3c63·6f64·653e·2d20·6e61·6d65·3a20·4669··<code>-·name:·Fi
0003a100:·6e64·202f·6574·632f·7375·646f·6572·732e··nd·/etc/sudoers.00039d20:·6e64·202f·6574·632f·7375·646f·6572·732e··nd·/etc/sudoers.
0003a110:·642f·2066·696c·6573·0a20·2061·6e73·6962··d/·files.··ansib00039d30:·642f·2066·696c·6573·0a20·2061·6e73·6962··d/·files.··ansib
0003a120:·6c65·2e62·7569·6c74·696e·2e66·696e·643a··le.builtin.find:00039d40:·6c65·2e62·7569·6c74·696e·2e66·696e·643a··le.builtin.find:
0003a130:·0a20·2020·2070·6174·6873·3a0a·2020·2020··.····paths:.····00039d50:·0a20·2020·2070·6174·6873·3a0a·2020·2020··.····paths:.····
0003a140:·2d20·2f65·7463·2f73·7564·6f65·7273·2e64··-·/etc/sudoers.d00039d60:·2d20·2f65·7463·2f73·7564·6f65·7273·2e64··-·/etc/sudoers.d
0003a150:·2f0a·2020·7265·6769·7374·6572·3a20·7375··/.··register:·su00039d70:·2f0a·2020·7265·6769·7374·6572·3a20·7375··/.··register:·su
0003a160:·646f·6572·730a·2020·7461·6773·3a0a·2020··doers.··tags:.··00039d80:·646f·6572·730a·2020·7461·6773·3a0a·2020··doers.··tags:.··
0003a170:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM00039d90:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
0003a180:·2d36·2861·290a·2020·2d20·4e49·5354·2d38··-6(a).··-·NIST-800039da0:·2d36·2861·290a·2020·2d20·4e49·5354·2d38··-6(a).··-·NIST-8
0003a190:·3030·2d35·332d·4941·2d31·310a·2020·2d20··00-53-IA-11.··-·00039db0:·3030·2d35·332d·4941·2d31·310a·2020·2d20··00-53-IA-11.··-·
0003a1a0:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.·00039dc0:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.·
0003a1b0:·202d·206c·6f77·5f64·6973·7275·7074·696f···-·low_disruptio00039dd0:·202d·206c·6f77·5f64·6973·7275·7074·696f···-·low_disruptio
0003a1c0:·6e0a·2020·2d20·6d65·6469·756d·5f73·6576··n.··-·medium_sev00039de0:·6e0a·2020·2d20·6d65·6469·756d·5f73·6576··n.··-·medium_sev
0003a1d0:·6572·6974·790a·2020·2d20·6e6f·5f72·6562··erity.··-·no_reb00039df0:·6572·6974·790a·2020·2d20·6e6f·5f72·6562··erity.··-·no_reb
0003a1e0:·6f6f·745f·6e65·6564·6564·0a20·202d·2072··oot_needed.··-·r00039e00:·6f6f·745f·6e65·6564·6564·0a20·202d·2072··oot_needed.··-·r
0003a1f0:·6573·7472·6963·745f·7374·7261·7465·6779··estrict_strategy00039e10:·6573·7472·6963·745f·7374·7261·7465·6779··estrict_strategy
0003a200:·0a20·202d·2073·7564·6f5f·7265·6d6f·7665··.··-·sudo_remove00039e20:·0a20·202d·2073·7564·6f5f·7265·6d6f·7665··.··-·sudo_remove
0003a210:·5f6e·6f5f·6175·7468·656e·7469·6361·7465··_no_authenticate00039e30:·5f6e·6f5f·6175·7468·656e·7469·6361·7465··_no_authenticate
0003a220:·0a0a·2d20·6e61·6d65·3a20·5265·6d6f·7665··..-·name:·Remove00039e40:·0a0a·2d20·6e61·6d65·3a20·5265·6d6f·7665··..-·name:·Remove
0003a230:·206c·696e·6573·2063·6f6e·7461·696e·696e···lines·containin00039e50:·206c·696e·6573·2063·6f6e·7461·696e·696e···lines·containin
Max diff block lines reached; 250530/270594 bytes (92.59%) of diff not shown.
37.7 KB
html2text {}
    
Offset 36, 15 lines modifiedOffset 36, 15 lines modified
36 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*36 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
37 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Minimal·Level37 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Minimal·Level
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_minimal38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_minimal
39 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*39 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
40 ····*·cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~40 ····*·cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~
41 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*41 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
42 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8442 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
43 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)43 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
44 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*44 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
45 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s45 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
46 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e46 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
47 ·········2.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s47 ·········2.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
48 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s48 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
49 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n49 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
50 ·········2.·_\x8D_\x8e_\x8p_\x8r_\x8e_\x8c_\x8a_\x8t_\x8e_\x8d_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s50 ·········2.·_\x8D_\x8e_\x8p_\x8r_\x8e_\x8c_\x8a_\x8t_\x8e_\x8d_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
Offset 90, 35 lines modifiedOffset 90, 14 lines modified
90 ···························1.7,·SR·1.8,·SR·1.990 ···························1.7,·SR·1.8,·SR·1.9
91 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,91 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
92 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.392 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
93 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)93 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
94 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-794 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
95 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,95 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
96 ···························SRG-OS-000373-GPOS-0015896 ···························SRG-OS-000373-GPOS-00158
97 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
98 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
99 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
100 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
101 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
102 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
103 ··if·[·!·-e·"$f"·]·;·then 
104 ····continue 
105 ··fi 
106 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·) 
107 ··if·!·test·-z·"$matching_list";·then 
108 ····while·IFS=·read·-r·entry;·do 
109 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data 
110 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
111 ····done·<<<·"$matching_list" 
  
112 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
113 visudo" 
114 ··fi 
115 done 
116 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x897 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
117 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low98 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
118 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low99 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
119 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false100 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
120 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict101 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
121 -·name:·Find·/etc/sudoers.d/·files102 -·name:·Find·/etc/sudoers.d/·files
122 ··ansible.builtin.find:103 ··ansible.builtin.find:
Offset 149, 14 lines modifiedOffset 128, 35 lines modified
149 ··-·NIST-800-53-IA-11128 ··-·NIST-800-53-IA-11
150 ··-·low_complexity129 ··-·low_complexity
151 ··-·low_disruption130 ··-·low_disruption
152 ··-·medium_severity131 ··-·medium_severity
153 ··-·no_reboot_needed132 ··-·no_reboot_needed
154 ··-·restrict_strategy133 ··-·restrict_strategy
155 ··-·sudo_remove_no_authenticate134 ··-·sudo_remove_no_authenticate
 135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 140 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do
 141 ··if·[·!·-e·"$f"·]·;·then
 142 ····continue
 143 ··fi
 144 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·)
 145 ··if·!·test·-z·"$matching_list";·then
 146 ····while·IFS=·read·-r·entry;·do
 147 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data
 148 ······sed·-i·"s/^${entry}$/#·&/g"·$f
 149 ····done·<<<·"$matching_list"
  
 150 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with
 151 visudo"
 152 ··fi
 153 done
156 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o154 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o
157 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*155 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
158 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using156 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using
159 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure157 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure
160 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any158 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any
161 sudo·configuration·snippets·in·/etc/sudoers.d/.159 sudo·configuration·snippets·in·/etc/sudoers.d/.
162 ············Without·re-authentication,·users·may·access·resources·or·perform160 ············Without·re-authentication,·users·may·access·resources·or·perform
Offset 177, 35 lines modifiedOffset 177, 14 lines modified
177 ···························1.7,·SR·1.8,·SR·1.9177 ···························1.7,·SR·1.8,·SR·1.9
178 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,178 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
179 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3179 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
180 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)180 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
181 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7181 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
182 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,182 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
183 ···························SRG-OS-000373-GPOS-00158183 ···························SRG-OS-000373-GPOS-00158
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
189 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
190 ··if·[·!·-e·"$f"·]·;·then 
191 ····continue 
192 ··fi 
193 ··matching_list=$(grep·-P·'^(?!#).*[\s]+NOPASSWD[\s]*\:.*$'·$f·|·uniq·) 
194 ··if·!·test·-z·"$matching_list";·then 
195 ····while·IFS=·read·-r·entry;·do 
196 ······#·comment·out·"NOPASSWD"·matches·to·preserve·user·data 
197 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
198 ····done·<<<·"$matching_list" 
  
199 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
200 visudo" 
201 ··fi 
202 done 
203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
204 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
205 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
206 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
207 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
208 -·name:·Find·/etc/sudoers.d/·files189 -·name:·Find·/etc/sudoers.d/·files
209 ··ansible.builtin.find:190 ··ansible.builtin.find:
Offset 236, 14 lines modifiedOffset 215, 35 lines modified
236 ··-·NIST-800-53-IA-11215 ··-·NIST-800-53-IA-11
237 ··-·low_complexity216 ··-·low_complexity
238 ··-·low_disruption217 ··-·low_disruption
Max diff block lines reached; 32794/38535 bytes (85.10%) of diff not shown.
1.08 MB
./usr/share/doc/ssg-debderived/ssg-ubuntu1604-guide-anssi_np_nt28_restrictive.html
    
Offset 14285, 15 lines modifiedOffset 14285, 15 lines modified
00037cc0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00037cc0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00037cd0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00037cd0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00037ce0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<00037ce0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<
00037cf0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00037cf0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00037d00:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00037d00:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00037d10:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00037d10:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00037d20:·2020·2020·2020·2020·2020·2020·2020·2028·················(00037d20:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00037d30:·6173·206f·6620·3230·3236·2d30·312d·3038··as·of·2026-01-0800037d30:·6173·206f·6620·3230·3234·2d31·322d·3037··as·of·2024-12-07
00037d40:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00037d40:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00037d50:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00037d50:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00037d60:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00037d60:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00037d70:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00037d70:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00037d80:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00037d80:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00037d90:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00037d90:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00037da0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00037da0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
Offset 16015, 146 lines modifiedOffset 16015, 146 lines modified
0003e8e0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003e8e0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003e8f0:·6964·6d31·3735·3422·2074·6162·696e·6465··idm1754"·tabinde0003e8f0:·6964·6d31·3735·3422·2074·6162·696e·6465··idm1754"·tabinde
0003e900:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003e900:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003e910:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003e910:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003e920:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003e920:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003e930:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003e930:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003e940:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003e940:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003e950:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003e960:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003e970:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003e980:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003e990:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1 
0003e9a0:·3735·3422·3e3c·7461·626c·6520·636c·6173··754"><table·clas 
0003e9b0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003e9c0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003e9d0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003e9e0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003e9f0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003ea00:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003ea10:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003ea20:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003ea30:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003ea40:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003ea50:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003ea60:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003ea70:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri 
0003ea80:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta 
0003ea90:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>. 
0003eaa0:·666f·7220·6620·696e·202f·6574·632f·7375··for·f·in·/etc/su 
0003eab0:·646f·6572·7320·2f65·7463·2f73·7564·6f65··doers·/etc/sudoe 
0003eac0:·7273·2e64·2f2a·203b·2064·6f0a·2020·6966··rs.d/*·;·do.··if 
0003ead0:·205b·2021·202d·6520·2224·6622·205d·203b···[·!·-e·"$f"·]·; 
0003eae0:·2074·6865·6e0a·2020·2020·636f·6e74·696e···then.····contin 
0003eaf0:·7565·0a20·2066·690a·2020·6d61·7463·6869··ue.··fi.··matchi 
0003eb00:·6e67·5f6c·6973·743d·2428·6772·6570·202d··ng_list=$(grep·- 
0003eb10:·5020·275e·283f·2123·292e·2a5b·5c73·5d2b··P·'^(?!#).*[\s]+ 
0003eb20:·5c21·6175·7468·656e·7469·6361·7465·2e2a··\!authenticate.* 
0003eb30:·2427·2024·6620·7c20·756e·6971·2029·0a20··$'·$f·|·uniq·).· 
0003eb40:·2069·6620·2120·7465·7374·202d·7a20·2224···if·!·test·-z·"$ 
0003eb50:·6d61·7463·6869·6e67·5f6c·6973·7422·3b20··matching_list";· 
0003eb60:·7468·656e·0a20·2020·2077·6869·6c65·2049··then.····while·I 
0003eb70:·4653·3d20·7265·6164·202d·7220·656e·7472··FS=·read·-r·entr 
0003eb80:·793b·2064·6f0a·2020·2020·2020·2320·636f··y;·do.······#·co 
0003eb90:·6d6d·656e·7420·6f75·7420·2221·6175·7468··mment·out·"!auth 
0003eba0:·656e·7469·6361·7465·2220·6d61·7463·6865··enticate"·matche 
0003ebb0:·7320·746f·2070·7265·7365·7276·6520·7573··s·to·preserve·us 
0003ebc0:·6572·2064·6174·610a·2020·2020·2020·7365··er·data.······se 
0003ebd0:·6420·2d69·2022·732f·5e24·7b65·6e74·7279··d·-i·"s/^${entry 
0003ebe0:·7d24·2f23·2026·616d·703b·2f67·2220·2466··}$/#·&amp;/g"·$f 
0003ebf0:·0a20·2020·2064·6f6e·6520·266c·743b·266c··.····done·&lt;&l 
0003ec00:·743b·266c·743b·2022·246d·6174·6368·696e··t;&lt;·"$matchin 
0003ec10:·675f·6c69·7374·220a·0a20·2020·202f·7573··g_list"..····/us 
0003ec20:·722f·7362·696e·2f76·6973·7564·6f20·2d63··r/sbin/visudo·-c 
0003ec30:·6620·2466·2026·616d·703b·2667·743b·202f··f·$f·&amp;&gt;·/ 
0003ec40:·6465·762f·6e75·6c6c·207c·7c20·6563·686f··dev/null·||·echo 
0003ec50:·2022·4661·696c·2074·6f20·7661·6c69·6461···"Fail·to·valida 
0003ec60:·7465·2024·6620·7769·7468·2076·6973·7564··te·$f·with·visud 
0003ec70:·6f22·0a20·2066·690a·646f·6e65·0a3c·2f63··o".··fi.done.</c 
0003ec80:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003ec90:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003eca0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003ecb0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003ecc0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003ecd0:·6964·6d31·3735·3522·2074·6162·696e·6465··idm1755"·tabinde 
0003ece0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003ecf0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003ed00:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003ed10:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003ed20:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003ed30:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib0003e950:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib
0003ed40:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</0003e960:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</
0003ed50:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003e970:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003ed60:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003e980:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003ed70:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003e990:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003ed80:·646d·3137·3535·223e·3c74·6162·6c65·2063··dm1755"><table·c0003e9a0:·646d·3137·3534·223e·3c74·6162·6c65·2063··dm1754"><table·c
0003ed90:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003e9b0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003eda0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003e9c0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003edb0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003e9d0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003edc0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003e9e0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003edd0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003e9f0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003ede0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003ea00:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003edf0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru0003ea10:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003ee00:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l0003ea20:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003ee10:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003ea30:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003ee20:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>0003ea40:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
0003ee30:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></0003ea50:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
0003ee40:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0003ea60:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
0003ee50:·6567·793a·3c2f·7468·3e3c·7464·3e72·6573··egy:</th><td>res0003ea70:·6567·793a·3c2f·7468·3e3c·7464·3e72·6573··egy:</th><td>res
0003ee60:·7472·6963·743c·2f74·643e·3c2f·7472·3e3c··trict</td></tr><0003ea80:·7472·6963·743c·2f74·643e·3c2f·7472·3e3c··trict</td></tr><
0003ee70:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod0003ea90:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
0003ee80:·653e·2d20·6e61·6d65·3a20·4669·6e64·202f··e>-·name:·Find·/0003eaa0:·653e·2d20·6e61·6d65·3a20·4669·6e64·202f··e>-·name:·Find·/
0003ee90:·6574·632f·7375·646f·6572·732e·642f·2066··etc/sudoers.d/·f0003eab0:·6574·632f·7375·646f·6572·732e·642f·2066··etc/sudoers.d/·f
0003eea0:·696c·6573·0a20·2061·6e73·6962·6c65·2e62··iles.··ansible.b0003eac0:·696c·6573·0a20·2061·6e73·6962·6c65·2e62··iles.··ansible.b
0003eeb0:·7569·6c74·696e·2e66·696e·643a·0a20·2020··uiltin.find:.···0003ead0:·7569·6c74·696e·2e66·696e·643a·0a20·2020··uiltin.find:.···
0003eec0:·2070·6174·6873·3a0a·2020·2020·2d20·2f65···paths:.····-·/e0003eae0:·2070·6174·6873·3a0a·2020·2020·2d20·2f65···paths:.····-·/e
0003eed0:·7463·2f73·7564·6f65·7273·2e64·2f0a·2020··tc/sudoers.d/.··0003eaf0:·7463·2f73·7564·6f65·7273·2e64·2f0a·2020··tc/sudoers.d/.··
0003eee0:·7265·6769·7374·6572·3a20·7375·646f·6572··register:·sudoer0003eb00:·7265·6769·7374·6572·3a20·7375·646f·6572··register:·sudoer
0003eef0:·730a·2020·7461·6773·3a0a·2020·2d20·4e49··s.··tags:.··-·NI0003eb10:·730a·2020·7461·6773·3a0a·2020·2d20·4e49··s.··tags:.··-·NI
0003ef00:·5354·2d38·3030·2d35·332d·434d·2d36·2861··ST-800-53-CM-6(a0003eb20:·5354·2d38·3030·2d35·332d·434d·2d36·2861··ST-800-53-CM-6(a
0003ef10:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-50003eb30:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5
0003ef20:·332d·4941·2d31·310a·2020·2d20·6c6f·775f··3-IA-11.··-·low_0003eb40:·332d·4941·2d31·310a·2020·2d20·6c6f·775f··3-IA-11.··-·low_
0003ef30:·636f·6d70·6c65·7869·7479·0a20·202d·206c··complexity.··-·l0003eb50:·636f·6d70·6c65·7869·7479·0a20·202d·206c··complexity.··-·l
0003ef40:·6f77·5f64·6973·7275·7074·696f·6e0a·2020··ow_disruption.··0003eb60:·6f77·5f64·6973·7275·7074·696f·6e0a·2020··ow_disruption.··
0003ef50:·2d20·6d65·6469·756d·5f73·6576·6572·6974··-·medium_severit0003eb70:·2d20·6d65·6469·756d·5f73·6576·6572·6974··-·medium_severit
0003ef60:·790a·2020·2d20·6e6f·5f72·6562·6f6f·745f··y.··-·no_reboot_0003eb80:·790a·2020·2d20·6e6f·5f72·6562·6f6f·745f··y.··-·no_reboot_
0003ef70:·6e65·6564·6564·0a20·202d·2072·6573·7472··needed.··-·restr0003eb90:·6e65·6564·6564·0a20·202d·2072·6573·7472··needed.··-·restr
0003ef80:·6963·745f·7374·7261·7465·6779·0a20·202d··ict_strategy.··-0003eba0:·6963·745f·7374·7261·7465·6779·0a20·202d··ict_strategy.··-
0003ef90:·2073·7564·6f5f·7265·6d6f·7665·5f6e·6f5f···sudo_remove_no_0003ebb0:·2073·7564·6f5f·7265·6d6f·7665·5f6e·6f5f···sudo_remove_no_
0003efa0:·6175·7468·656e·7469·6361·7465·0a0a·2d20··authenticate..-·0003ebc0:·6175·7468·656e·7469·6361·7465·0a0a·2d20··authenticate..-·
0003efb0:·6e61·6d65·3a20·5265·6d6f·7665·206c·696e··name:·Remove·lin0003ebd0:·6e61·6d65·3a20·5265·6d6f·7665·206c·696e··name:·Remove·lin
0003efc0:·6573·2063·6f6e·7461·696e·696e·6720·2161··es·containing·!a0003ebe0:·6573·2063·6f6e·7461·696e·696e·6720·2161··es·containing·!a
Max diff block lines reached; 990878/1010804 bytes (98.03%) of diff not shown.
124 KB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Restrictive·Level38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Restrictive·Level
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_restrictive39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_restrictive
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~
42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
43 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8443 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
48 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g48 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
49 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s49 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
50 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s50 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
51 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n51 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
Offset 229, 35 lines modifiedOffset 229, 14 lines modified
229 ···························1.7,·SR·1.8,·SR·1.9229 ···························1.7,·SR·1.8,·SR·1.9
230 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,230 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
231 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3231 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
232 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)232 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
233 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7233 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
234 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,234 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
235 ···························SRG-OS-000373-GPOS-00158235 ···························SRG-OS-000373-GPOS-00158
236 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
237 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
238 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
239 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
240 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
241 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
242 ··if·[·!·-e·"$f"·]·;·then 
243 ····continue 
244 ··fi 
245 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·) 
246 ··if·!·test·-z·"$matching_list";·then 
247 ····while·IFS=·read·-r·entry;·do 
248 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data 
249 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
250 ····done·<<<·"$matching_list" 
  
251 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
252 visudo" 
253 ··fi 
254 done 
255 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8236 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
256 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low237 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
257 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low238 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
258 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false239 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
259 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict240 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
260 -·name:·Find·/etc/sudoers.d/·files241 -·name:·Find·/etc/sudoers.d/·files
261 ··ansible.builtin.find:242 ··ansible.builtin.find:
Offset 288, 14 lines modifiedOffset 267, 35 lines modified
288 ··-·NIST-800-53-IA-11267 ··-·NIST-800-53-IA-11
289 ··-·low_complexity268 ··-·low_complexity
290 ··-·low_disruption269 ··-·low_disruption
291 ··-·medium_severity270 ··-·medium_severity
292 ··-·no_reboot_needed271 ··-·no_reboot_needed
293 ··-·restrict_strategy272 ··-·restrict_strategy
294 ··-·sudo_remove_no_authenticate273 ··-·sudo_remove_no_authenticate
 274 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 275 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 276 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 277 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 278 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 279 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do
 280 ··if·[·!·-e·"$f"·]·;·then
 281 ····continue
 282 ··fi
 283 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·)
 284 ··if·!·test·-z·"$matching_list";·then
 285 ····while·IFS=·read·-r·entry;·do
 286 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data
 287 ······sed·-i·"s/^${entry}$/#·&/g"·$f
 288 ····done·<<<·"$matching_list"
  
 289 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with
 290 visudo"
 291 ··fi
 292 done
295 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o293 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o
296 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*294 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
297 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using295 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using
298 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure296 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure
299 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any297 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any
300 sudo·configuration·snippets·in·/etc/sudoers.d/.298 sudo·configuration·snippets·in·/etc/sudoers.d/.
301 ············Without·re-authentication,·users·may·access·resources·or·perform299 ············Without·re-authentication,·users·may·access·resources·or·perform
Offset 316, 35 lines modifiedOffset 316, 14 lines modified
316 ···························1.7,·SR·1.8,·SR·1.9316 ···························1.7,·SR·1.8,·SR·1.9
317 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,317 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
318 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3318 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
319 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)319 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
320 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7320 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
321 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,321 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
322 ···························SRG-OS-000373-GPOS-00158322 ···························SRG-OS-000373-GPOS-00158
323 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
324 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
325 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
326 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
327 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
328 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
329 ··if·[·!·-e·"$f"·]·;·then 
330 ····continue 
331 ··fi 
332 ··matching_list=$(grep·-P·'^(?!#).*[\s]+NOPASSWD[\s]*\:.*$'·$f·|·uniq·) 
333 ··if·!·test·-z·"$matching_list";·then 
334 ····while·IFS=·read·-r·entry;·do 
335 ······#·comment·out·"NOPASSWD"·matches·to·preserve·user·data 
336 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
337 ····done·<<<·"$matching_list" 
  
338 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
339 visudo" 
340 ··fi 
341 done 
342 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8323 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
343 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low324 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
344 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low325 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
345 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false326 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
346 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict327 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
347 -·name:·Find·/etc/sudoers.d/·files328 -·name:·Find·/etc/sudoers.d/·files
348 ··ansible.builtin.find:329 ··ansible.builtin.find:
Offset 375, 14 lines modifiedOffset 354, 35 lines modified
375 ··-·NIST-800-53-IA-11354 ··-·NIST-800-53-IA-11
376 ··-·low_complexity355 ··-·low_complexity
377 ··-·low_disruption356 ··-·low_disruption
Max diff block lines reached; 120862/126604 bytes (95.46%) of diff not shown.
1.1 MB
./usr/share/doc/ssg-debderived/ssg-ubuntu1604-guide-standard.html
    
Offset 14288, 15 lines modifiedOffset 14288, 15 lines modified
00037cf0:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur00037cf0:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur
00037d00:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s00037d00:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s
00037d10:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st00037d10:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st
00037d20:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li00037d20:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li
00037d30:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</00037d30:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</
00037d40:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········00037d40:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········
00037d50:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·00037d50:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·
00037d60:·6f66·2032·3032·362d·3031·2d30·3829·0a20··of·2026-01-08).·00037d60:·6f66·2032·3032·342d·3132·2d30·3729·0a20··of·2024-12-07).·
00037d70:·2020·2020·2020·2020·2020·2020·2020·203c·················<00037d70:·2020·2020·2020·2020·2020·2020·2020·203c·················<
00037d80:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><00037d80:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><
00037d90:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont00037d90:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont
00037da0:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li00037da0:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li
00037db0:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf00037db0:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf
00037dc0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.00037dc0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.
00037dd0:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy00037dd0:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy
Offset 16224, 741 lines modifiedOffset 16224, 741 lines modified
0003f5f0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003f5f0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003f600:·3d22·2369·646d·3439·3439·2220·7461·6269··="#idm4949"·tabi0003f600:·3d22·2369·646d·3439·3439·2220·7461·6269··="#idm4949"·tabi
0003f610:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003f610:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003f620:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003f620:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003f630:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003f630:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003f640:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003f640:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
Diff chunk too large, falling back to line-by-line diff (727 lines added, 727 lines removed)
0003f650:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003f650:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003f660:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh0003f660:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
0003f670:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</0003f670:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·..
0003f680:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003f680:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003f690:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003f690:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003f6a0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003f6a0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003f6b0:·646d·3439·3439·223e·3c70·7265·3e3c·636f··dm4949"><pre><co0003f6b0:·3d22·6964·6d34·3934·3922·3e3c·7461·626c··="idm4949"><tabl
0003f6c0:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation0003f6c0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0003f6d0:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o0003f6d0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0003f6e0:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p0003f6e0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0003f6f0:·6c61·7466·6f72·6d73·0a69·6620·5b20·2120··latforms.if·[·!·0003f6f0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0003f700:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·]0003f700:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003f710:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!·0003f710:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003f720:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain0003f720:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003f730:·6572·656e·7620·5d3b·2074·6865·6e0a·0a23··erenv·];·then..#0003f730:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003f740:·204c·6973·7420·6f66·206c·6f67·2066·696c···List·of·log·fil0003f740:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t
0003f750:·6520·7061·7468·7320·746f·2062·6520·696e··e·paths·to·be·in0003f750:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
0003f760:·7370·6563·7465·6420·666f·7220·636f·7272··spected·for·corr0003f760:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003f770:·6563·7420·7065·726d·6973·7369·6f6e·730a··ect·permissions.0003f770:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003f780:·2320·2a20·5072·696d·6172·696c·7920·696e··#·*·Primarily·in0003f780:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003f790:·7370·6563·7420·6c6f·6720·6669·6c65·2070··spect·log·file·p0003f790:·7464·3e63·6f6e·6669·6775·7265·3c2f·7464··td>configure</td
0003f7a0:·6174·6873·206c·6973·7465·6420·696e·202f··aths·listed·in·/0003f7a0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
0003f7b0:·6574·632f·7273·7973·6c6f·672e·636f·6e66··etc/rsyslog.conf0003f7b0:·7265·3e3c·636f·6465·3e2d·206e·616d·653a··re><code>-·name:
0003f7c0:·0a52·5359·534c·4f47·5f45·5443·5f43·4f4e··.RSYSLOG_ETC_CON0003f7c0:·2045·6e73·7572·6520·4c6f·6720·4669·6c65···Ensure·Log·File
0003f7d0:·4649·473d·222f·6574·632f·7273·7973·6c6f··FIG="/etc/rsyslo0003f7d0:·7320·4172·6520·4f77·6e65·6420·4279·2041··s·Are·Owned·By·A
0003f7e0:·672e·636f·6e66·220a·2320·2a20·416e·6420··g.conf".#·*·And·0003f7e0:·7070·726f·7072·6961·7465·2047·726f·7570··ppropriate·Group
0003f7f0:·616c·736f·2074·6865·206c·6f67·2066·696c··also·the·log·fil0003f7f0:·202d·2053·6574·2072·7379·736c·6f67·206c···-·Set·rsyslog·l
0003f800:·6520·7061·7468·7320·6c69·7374·6564·2061··e·paths·listed·a0003f800:·6f67·6669·6c65·2063·6f6e·6669·6775·7261··ogfile·configura
0003f810:·6674·6572·2072·7379·736c·6f67·2773·2024··fter·rsyslog's·$0003f810:·7469·6f6e·0a20·2020·2066·6163·7473·0a20··tion.····facts.·
0003f820:·496e·636c·7564·6543·6f6e·6669·6720·6469··IncludeConfig·di0003f820:·2061·6e73·6962·6c65·2e62·7569·6c74·696e···ansible.builtin
0003f830:·7265·6374·6976·650a·2320·2020·2873·746f··rective.#···(sto0003f830:·2e73·6574·5f66·6163·743a·0a20·2020·2072··.set_fact:.····r
0003f840:·7265·2074·6865·2072·6573·756c·7420·696e··re·the·result·in0003f840:·7379·736c·6f67·5f65·7463·5f63·6f6e·6669··syslog_etc_confi
0003f850:·746f·2061·7272·6179·2066·6f72·2074·6865··to·array·for·the0003f850:·673a·202f·6574·632f·7273·7973·6c6f·672e··g:·/etc/rsyslog.
0003f860:·2063·6173·6520·7468·6572·6527·7320·7368···case·there's·sh0003f860:·636f·6e66·0a20·2077·6865·6e3a·2061·6e73··conf.··when:·ans
0003f870:·656c·6c20·676c·6f62·2075·7365·6420·6173··ell·glob·used·as0003f870:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat
0003f880:·2076·616c·7565·206f·6620·496e·636c·7564···value·of·Includ0003f880:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in·
0003f890:·6543·6f6e·6669·6729·0a72·6561·6461·7272··eConfig).readarr0003f890:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc"
0003f8a0:·6179·202d·7420·4f4c·445f·494e·4320·266c··ay·-t·OLD_INC·&l0003f8a0:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod
0003f8b0:·743b·2026·6c74·3b28·6772·6570·202d·6520··t;·&lt;(grep·-e·0003f8b0:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container
0003f8c0:·225c·2449·6e63·6c75·6465·436f·6e66·6967··"\$IncludeConfig0003f8c0:·225d·0a20·2074·6167·733a·0a20·202d·204e··"].··tags:.··-·N
0003f8d0:·5b5b·3a73·7061·6365·3a5d·5d5c·2b5b·5e5b··[[:space:]]\+[^[0003f8d0:·4953·542d·3830·302d·3533·2d41·432d·3628··IST-800-53-AC-6(
0003f8e0:·3a73·7061·6365·3a5d·3b5d·5c2b·2220·2f65··:space:];]\+"·/e0003f8e0:·3129·0a20·202d·204e·4953·542d·3830·302d··1).··-·NIST-800-
0003f8f0:·7463·2f72·7379·736c·6f67·2e63·6f6e·6620··tc/rsyslog.conf·0003f8f0:·3533·2d43·4d2d·3628·6129·0a20·202d·2050··53-CM-6(a).··-·P
0003f900:·7c20·6375·7420·2d64·2027·2027·202d·6620··|·cut·-d·'·'·-f·0003f900:·4349·2d44·5353·2d52·6571·2d31·302e·352e··CI-DSS-Req-10.5.
0003f910:·3229·0a72·6561·6461·7272·6179·202d·7420··2).readarray·-t·0003f910:·310a·2020·2d20·5043·492d·4453·532d·5265··1.··-·PCI-DSS-Re
0003f920:·5253·5953·4c4f·475f·494e·434c·5544·455f··RSYSLOG_INCLUDE_0003f920:·712d·3130·2e35·2e32·0a20·202d·2050·4349··q-10.5.2.··-·PCI
0003f930:·434f·4e46·4947·2026·6c74·3b20·266c·743b··CONFIG·&lt;·&lt;0003f930:·2d44·5353·7634·2d31·302e·332e·320a·2020··-DSSv4-10.3.2.··
0003f940:·2866·6f72·2049·4e43·5041·5448·2069·6e20··(for·INCPATH·in·0003f940:·2d20·636f·6e66·6967·7572·655f·7374·7261··-·configure_stra
0003f950:·2224·7b4f·4c44·5f49·4e43·5b40·5d7d·223b··"${OLD_INC[@]}";0003f950:·7465·6779·0a20·202d·206c·6f77·5f63·6f6d··tegy.··-·low_com
0003f960:·2064·6f20·6576·616c·2070·7269·6e74·6620···do·eval·printf·0003f960:·706c·6578·6974·790a·2020·2d20·6d65·6469··plexity.··-·medi
0003f970:·2725·735c·5c6e·2720·2224·7b49·4e43·5041··'%s\\n'·"${INCPA0003f970:·756d·5f64·6973·7275·7074·696f·6e0a·2020··um_disruption.··
0003f980:·5448·7d22·3b20·646f·6e65·290a·7265·6164··TH}";·done).read0003f980:·2d20·6d65·6469·756d·5f73·6576·6572·6974··-·medium_severit
0003f990:·6172·7261·7920·2d74·204e·4557·5f49·4e43··array·-t·NEW_INC0003f990:·790a·2020·2d20·6e6f·5f72·6562·6f6f·745f··y.··-·no_reboot_
0003f9a0:·2026·6c74·3b20·266c·743b·2873·6564·202d···&lt;·&lt;(sed·-0003f9a0:·6e65·6564·6564·0a20·202d·2072·7379·736c··needed.··-·rsysl
0003f9b0:·6e20·272f·5e5c·732a·696e·636c·7564·6528··n·'/^\s*include(0003f9b0:·6f67·5f66·696c·6573·5f67·726f·7570·6f77··og_files_groupow
0003f9c0:·2f2c·2f29·2f49·7027·202f·6574·632f·7273··/,/)/Ip'·/etc/rs0003f9c0:·6e65·7273·6869·700a·0a2d·206e·616d·653a··nership..-·name:
0003f9d0:·7973·6c6f·672e·636f·6e66·207c·2073·6564··yslog.conf·|·sed0003f9d0:·2045·6e73·7572·6520·4c6f·6720·4669·6c65···Ensure·Log·File
0003f9e0:·202d·6e20·2773·402e·2a66·696c·655c·732a···-n·'s@.*file\s*0003f9e0:·7320·4172·6520·4f77·6e65·6420·4279·2041··s·Are·Owned·By·A
0003f9f0:·3d5c·732a·225c·285b·2f5b·3a61·6c6e·756d··=\s*"\([/[:alnum0003f9f0:·7070·726f·7072·6961·7465·2047·726f·7570··ppropriate·Group
0003fa00:·3a5d·5b3a·7075·6e63·743a·5d5d·2a5c·2922··:][:punct:]]*\)"0003fa00:·202d·2047·6574·2049·6e63·6c75·6465·436f···-·Get·IncludeCo
0003fa10:·2e2a·405c·3140·4970·2729·0a72·6561·6461··.*@\1@Ip').reada0003fa10:·6e66·6967·2064·6972·6563·7469·7665·0a20··nfig·directive.·
0003fa20:·7272·6179·202d·7420·5253·5953·4c4f·475f··rray·-t·RSYSLOG_0003fa20:·2061·6e73·6962·6c65·2e62·7569·6c74·696e···ansible.builtin
0003fa30:·494e·434c·5544·4520·266c·743b·2026·6c74··INCLUDE·&lt;·&lt0003fa30:·2e73·6865·6c6c·3a20·7c0a·2020·2020·7365··.shell:·|.····se
0003fa40:·3b28·666f·7220·494e·4350·4154·4820·696e··;(for·INCPATH·in0003fa40:·7420·2d6f·2070·6970·6566·6169·6c0a·2020··t·-o·pipefail.··
0003fa50:·2022·247b·4e45·575f·494e·435b·405d·7d22···"${NEW_INC[@]}"0003fa50:·2020·6772·6570·202d·6520·2724·496e·636c····grep·-e·'$Incl
0003fa60:·3b20·646f·2065·7661·6c20·7072·696e·7466··;·do·eval·printf0003fa60:·7564·6543·6f6e·6669·6727·207b·7b20·7273··udeConfig'·{{·rs
0003fa70:·2027·2573·5c5c·6e27·2022·247b·494e·4350···'%s\\n'·"${INCP0003fa70:·7973·6c6f·675f·6574·635f·636f·6e66·6967··yslog_etc_config
0003fa80:·4154·487d·223b·2064·6f6e·6529·0a0a·2320··ATH}";·done)..#·0003fa80:·207d·7d20·7c20·6375·7420·2d64·2027·2027···}}·|·cut·-d·'·'
0003fa90:·4465·636c·6172·6520·616e·2061·7272·6179··Declare·an·array0003fa90:·202d·6620·3220·7c7c·2074·7275·650a·2020···-f·2·||·true.··
0003faa0:·2074·6f20·686f·6c64·2074·6865·2066·696e···to·hold·the·fin0003faa0:·7265·6769·7374·6572·3a20·7273·7973·6c6f··register:·rsyslo
0003fab0:·616c·206c·6973·7420·6f66·2064·6966·6665··al·list·of·diffe0003fab0:·675f·6f6c·645f·696e·630a·2020·6368·616e··g_old_inc.··chan
0003fac0:·7265·6e74·206c·6f67·2066·696c·6520·7061··rent·log·file·pa0003fac0:·6765·645f·7768·656e·3a20·6661·6c73·650a··ged_when:·false.
0003fad0:·7468·730a·6465·636c·6172·6520·2d61·204c··ths.declare·-a·L0003fad0:·2020·7768·656e·3a20·616e·7369·626c·655f····when:·ansible_
0003fae0:·4f47·5f46·494c·455f·5041·5448·530a·0a23··OG_FILE_PATHS..#0003fae0:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t
0003faf0:·2041·7272·6179·2074·6f20·686f·6c64·2061···Array·to·hold·a0003faf0:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc
0003fb00:·6c6c·2072·7379·736c·6f67·2063·6f6e·6669··ll·rsyslog·confi0003fb00:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op
0003fb10:·6720·656e·7472·6965·730a·5253·5953·4c4f··g·entries.RSYSLO0003fb10:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman",
0003fb20:·475f·434f·4e46·4947·533d·2829·0a52·5359··G_CONFIGS=().RSY0003fb20:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].··
0003fb30:·534c·4f47·5f43·4f4e·4649·4753·3d28·2224··SLOG_CONFIGS=("$0003fb30:·7461·6773·3a0a·2020·2d20·4e49·5354·2d38··tags:.··-·NIST-8
0003fb40:·7b52·5359·534c·4f47·5f45·5443·5f43·4f4e··{RSYSLOG_ETC_CON0003fb40:·3030·2d35·332d·4143·2d36·2831·290a·2020··00-53-AC-6(1).··
0003fb50:·4649·477d·2220·2224·7b52·5359·534c·4f47··FIG}"·"${RSYSLOG0003fb50:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
0003fb60:·5f49·4e43·4c55·4445·5f43·4f4e·4649·475b··_INCLUDE_CONFIG[0003fb60:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS
0003fb70:·405d·7d22·2022·247b·5253·5953·4c4f·475f··@]}"·"${RSYSLOG_0003fb70:·532d·5265·712d·3130·2e35·2e31·0a20·202d··S-Req-10.5.1.··-
0003fb80:·494e·434c·5544·455b·405d·7d22·290a·0a23··INCLUDE[@]}")..#0003fb80:·2050·4349·2d44·5353·2d52·6571·2d31·302e···PCI-DSS-Req-10.
0003fb90:·2047·6574·2066·756c·6c20·6c69·7374·206f···Get·full·list·o0003fb90:·352e·320a·2020·2d20·5043·492d·4453·5376··5.2.··-·PCI-DSSv
0003fba0:·6620·6669·6c65·7320·746f·2062·6520·6368··f·files·to·be·ch0003fba0:·342d·3130·2e33·2e32·0a20·202d·2063·6f6e··4-10.3.2.··-·con
0003fbb0:·6563·6b65·640a·2320·5253·5953·4c4f·475f··ecked.#·RSYSLOG_0003fbb0:·6669·6775·7265·5f73·7472·6174·6567·790a··figure_strategy.
0003fbc0:·434f·4e46·4947·5320·6d61·7920·636f·6e74··CONFIGS·may·cont0003fbc0:·2020·2d20·6c6f·775f·636f·6d70·6c65·7869····-·low_complexi
0003fbd0:·6169·6e20·676c·6f62·7320·7375·6368·2061··ain·globs·such·a0003fbd0:·7479·0a20·202d·206d·6564·6975·6d5f·6469··ty.··-·medium_di
0003fbe0:·730a·2320·2f65·7463·2f72·7379·736c·6f67··s.#·/etc/rsyslog0003fbe0:·7372·7570·7469·6f6e·0a20·202d·206d·6564··sruption.··-·med
0003fbf0:·2e64·2f2a·2e63·6f6e·6620·2f65·7463·2f72··.d/*.conf·/etc/r0003fbf0:·6975·6d5f·7365·7665·7269·7479·0a20·202d··ium_severity.··-
0003fc00:·7379·736c·6f67·2e64·2f2a·2e66·7275·6c65··syslog.d/*.frule0003fc00:·206e·6f5f·7265·626f·6f74·5f6e·6565·6465···no_reboot_neede
0003fc10:·0a23·2053·6f2c·206c·6f6f·7020·6f76·6572··.#·So,·loop·over0003fc10:·640a·2020·2d20·7273·7973·6c6f·675f·6669··d.··-·rsyslog_fi
0003fc20:·2074·6865·2065·6e74·7269·6573·2069·6e20···the·entries·in·0003fc20:·6c65·735f·6772·6f75·706f·776e·6572·7368··les_groupownersh
0003fc30:·5253·5953·4c4f·475f·434f·4e46·4947·5320··RSYSLOG_CONFIGS·0003fc30:·6970·0a0a·2d20·6e61·6d65·3a20·456e·7375··ip..-·name:·Ensu
0003fc40:·616e·6420·7573·6520·6669·6e64·2074·6f20··and·use·find·to·0003fc40:·7265·204c·6f67·2046·696c·6573·2041·7265··re·Log·Files·Are
0003fc50:·6765·7420·7468·6520·6c69·7374·206f·6620··get·the·list·of·0003fc50:·204f·776e·6564·2042·7920·4170·7072·6f70···Owned·By·Approp
0003fc60:·696e·636c·7564·6564·2066·696c·6573·2e0a··included·files..0003fc60:·7269·6174·6520·4772·6f75·7020·2d20·4765··riate·Group·-·Ge
0003fc70:·5253·5953·4c4f·475f·434f·4e46·4947·5f46··RSYSLOG_CONFIG_F0003fc70:·7420·696e·636c·7564·6520·6669·6c65·7320··t·include·files·
0003fc80:·494c·4553·3d28·290a·666f·7220·454e·5452··ILES=().for·ENTR0003fc80:·6469·7265·6374·6976·6573·0a20·2061·6e73··directives.··ans
0003fc90:·5920·696e·2022·247b·5253·5953·4c4f·475f··Y·in·"${RSYSLOG_0003fc90:·6962·6c65·2e62·7569·6c74·696e·2e73·6865··ible.builtin.she
0003fca0:·434f·4e46·4947·535b·405d·7d22·0a64·6f0a··CONFIGS[@]}".do.0003fca0:·6c6c·3a20·7c0a·2020·2020·7365·7420·2d6f··ll:·|.····set·-o
0003fcb0:·0923·2049·6620·6469·7265·6374·6f72·792c··.#·If·directory,0003fcb0:·2070·6970·6566·6169·6c0a·2020·2020·6177···pipefail.····aw
0003fcc0:·2072·7379·736c·6f67·2077·696c·6c20·7365···rsyslog·will·se0003fcc0:·6b20·272f·292f·7b66·3d30·7d20·2f69·6e63··k·'/)/{f=0}·/inc
Max diff block lines reached; 926184/1028220 bytes (90.08%) of diff not shown.
125 KB
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Ubuntu·16.0439 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Ubuntu·16.04
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard
41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
42 ····*·cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~42 ····*·cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~
43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
44 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8444 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
49 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g49 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
50 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s50 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
51 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s51 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
52 ·········1.·_\x8C_\x8r_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8t_\x8·_\x8D_\x8a_\x8e_\x8m_\x8o_\x8n_\x8s52 ·········1.·_\x8C_\x8r_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8t_\x8·_\x8D_\x8a_\x8e_\x8m_\x8o_\x8n_\x8s
Offset 259, 139 lines modifiedOffset 259, 14 lines modified
259 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-007-3·R2.1,·CIP-007-3·R2.2,·CIP-007-3·R2.3,·CIP-259 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-007-3·R2.1,·CIP-007-3·R2.2,·CIP-007-3·R2.3,·CIP-
260 ···························007-3·R5.1,·CIP-007-3·R5.1.1,·CIP-007-3·R5.1.2260 ···························007-3·R5.1,·CIP-007-3·R5.1.1,·CIP-007-3·R5.1.2
261 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)261 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)
262 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5262 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5
263 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.5.1,·Req-10.5.2263 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.5.1,·Req-10.5.2
264 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71264 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71
265 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.3.2265 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.3.2
266 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
267 #·Remediation·is·applicable·only·in·certain·platforms 
268 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
269 #·List·of·log·file·paths·to·be·inspected·for·correct·permissions 
270 #·*·Primarily·inspect·log·file·paths·listed·in·/etc/rsyslog.conf 
271 RSYSLOG_ETC_CONFIG="/etc/rsyslog.conf" 
272 #·*·And·also·the·log·file·paths·listed·after·rsyslog's·$IncludeConfig·directive 
273 #···(store·the·result·into·array·for·the·case·there's·shell·glob·used·as·value 
274 of·IncludeConfig) 
275 readarray·-t·OLD_INC·<·<(grep·-e·"\$IncludeConfig[[:space:]]\+[^[:space:];]\+" 
276 /etc/rsyslog.conf·|·cut·-d·'·'·-f·2) 
277 readarray·-t·RSYSLOG_INCLUDE_CONFIG·<·<(for·INCPATH·in·"${OLD_INC[@]}";·do·eval 
278 printf·'%s\\n'·"${INCPATH}";·done) 
279 readarray·-t·NEW_INC·<·<(sed·-n·'/^\s*include(/,/)/Ip'·/etc/rsyslog.conf·|·sed 
280 -n·'s@.*file\s*=\s*"\([/[:alnum:][:punct:]]*\)".*@\1@Ip') 
281 readarray·-t·RSYSLOG_INCLUDE·<·<(for·INCPATH·in·"${NEW_INC[@]}";·do·eval·printf 
282 '%s\\n'·"${INCPATH}";·done) 
  
283 #·Declare·an·array·to·hold·the·final·list·of·different·log·file·paths 
284 declare·-a·LOG_FILE_PATHS 
  
285 #·Array·to·hold·all·rsyslog·config·entries 
286 RSYSLOG_CONFIGS=() 
287 RSYSLOG_CONFIGS=("${RSYSLOG_ETC_CONFIG}"·"${RSYSLOG_INCLUDE_CONFIG[@]}"·"$ 
288 {RSYSLOG_INCLUDE[@]}") 
  
289 #·Get·full·list·of·files·to·be·checked 
290 #·RSYSLOG_CONFIGS·may·contain·globs·such·as 
291 #·/etc/rsyslog.d/*.conf·/etc/rsyslog.d/*.frule 
292 #·So,·loop·over·the·entries·in·RSYSLOG_CONFIGS·and·use·find·to·get·the·list·of 
293 included·files. 
294 RSYSLOG_CONFIG_FILES=() 
295 for·ENTRY·in·"${RSYSLOG_CONFIGS[@]}" 
296 do 
297 »       #·If·directory,·rsyslog·will·search·for·config·files·in·recursively. 
298 »       #·However,·files·in·hidden·sub-directories·or·hidden·files·will·be·ignored. 
299 »       if·[·-d·"${ENTRY}"·] 
300 »       then 
301 »       »       readarray·-t·FINDOUT·<·<(find·"${ENTRY}"·-not·-path·'*/.*'·-type·f) 
302 »       »       RSYSLOG_CONFIG_FILES+=("${FINDOUT[@]}") 
303 »       elif·[·-f·"${ENTRY}"·] 
304 »       then 
305 »       »       RSYSLOG_CONFIG_FILES+=("${ENTRY}") 
306 »       else 
307 »       »       echo·"Invalid·include·object:·${ENTRY}" 
308 »       fi 
309 done 
  
310 #·Browse·each·file·selected·above·as·containing·paths·of·log·files 
311 #·('/etc/rsyslog.conf'·and·'/etc/rsyslog.d/*.conf'·in·the·default 
312 configuration) 
313 for·LOG_FILE·in·"${RSYSLOG_CONFIG_FILES[@]}" 
314 do 
315 »       #·From·each·of·these·files·extract·just·particular·log·file·path(s),·thus: 
316 »       #·*·Ignore·lines·starting·with·space·('·'),·comment·('#"),·or·variable·syntax 
317 ('$')·characters, 
318 »       #·*·Ignore·empty·lines, 
319 »       #·*·Strip·quotes·and·closing·brackets·from·paths. 
320 »       #·*·Ignore·paths·that·match·/dev|/etc.*\.conf,·as·those·are·paths,·but·likely 
321 not·log·files 
322 »       #·*·From·the·remaining·valid·rows·select·only·fields·constituting·a·log·file 
323 path 
324 »       #·Text·file·column·is·understood·to·represent·a·log·file·path·if·and·only·if 
325 all·of·the 
326 »       #·following·are·met: 
327 »       #·*·it·contains·at·least·one·slash·'/'·character, 
328 »       #·*·it·is·preceded·by·space 
329 »       #·*·it·doesn't·contain·space·('·'),·colon·(':'),·and·semicolon·(';') 
330 characters 
331 »       #·Search·log·file·for·path(s)·only·in·case·it·exists! 
332 »       if·[[·-f·"${LOG_FILE}"·]] 
333 »       then 
334 »       »       NORMALIZED_CONFIG_FILE_LINES=$(sed·-e·"/^[#|$]/d"·"${LOG_FILE}") 
335 »       »       LINES_WITH_PATHS=$(grep·'[^/]*\s\+\S*/\S\+$'·<<<·"$ 
336 {NORMALIZED_CONFIG_FILE_LINES}") 
337 »       »       FILTERED_PATHS=$(awk·'{if(NF>=2&&($NF~/^\//||$NF~/^-\//)){sub(/^-\//,"/ 
338 ",$NF);print·$NF}}'·<<<·"${LINES_WITH_PATHS}") 
339 »       »       CLEANED_PATHS=$(sed·-e·"s/[\"')]//g;·/\\/etc.*\.conf/d;·/\\/dev\\//d"·<<<·"$ 
340 {FILTERED_PATHS}") 
341 »       »       MATCHED_ITEMS=$(sed·-e·"/^$/d"·<<<·"${CLEANED_PATHS}") 
342 »       »       #·Since·above·sed·command·might·return·more·than·one·item·(delimited·by 
343 newline),·split 
344 »       »       #·the·particular·matches·entries·into·new·array·specific·for·this·log·file 
345 »       »       readarray·-t·ARRAY_FOR_LOG_FILE·<<<·"$MATCHED_ITEMS" 
346 »       »       #·Concatenate·the·two·arrays·-·previous·content·of·$LOG_FILE_PATHS·array·with 
347 »       »       #·items·from·newly·created·array·for·this·log·file 
348 »       »       LOG_FILE_PATHS+=("${ARRAY_FOR_LOG_FILE[@]}") 
349 »       »       #·Delete·the·temporary·array 
350 »       »       unset·ARRAY_FOR_LOG_FILE 
351 »       fi 
352 done 
  
353 #·Check·for·RainerScript·action·log·format·which·might·be·also·multiline·so 
354 grep·regex·is·a·bit 
355 #·curly: 
356 #·extract·possibly·multiline·action·omfile·expressions 
357 #·extract·File="logfile"·expression 
358 #·match·only·"logfile"·expression 
359 for·LOG_FILE·in·"${RSYSLOG_CONFIG_FILES[@]}" 
360 do 
361 »       ACTION_OMFILE_LINES=$(grep·-iozP·"action\s*\(\s*type\s*=\s*\"omfile\"[^\)]*\)" 
362 "${LOG_FILE}") 
363 »       OMFILE_LINES=$(echo·"${ACTION_OMFILE_LINES}"|·grep·-iaoP·"\bFile\s*=\s*\"([/[: 
Max diff block lines reached; 121643/128232 bytes (94.86%) of diff not shown.
987 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1804-guide-anssi_np_nt28_average.html
    
Offset 14287, 15 lines modifiedOffset 14287, 15 lines modified
00037ce0:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·00037ce0:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·
00037cf0:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong00037cf0:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong
00037d00:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>00037d00:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>
00037d10:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str00037d10:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str
00037d20:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron00037d20:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron
00037d30:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············00037d30:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············
00037d40:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·2000037d40:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·20
00037d50:·3236·2d30·312d·3038·290a·2020·2020·2020··26-01-08).······00037d50:·3234·2d31·322d·3037·290a·2020·2020·2020··24-12-07).······
00037d60:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><00037d60:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><
00037d70:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta00037d70:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta
00037d80:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<00037d80:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<
00037d90:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h00037d90:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h
00037da0:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.00037da0:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.
00037db0:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte00037db0:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte
00037dc0:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"00037dc0:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"
Offset 16036, 146 lines modifiedOffset 16036, 146 lines modified
0003ea30:·612d·7461·7267·6574·3d22·2369·646d·3139··a-target="#idm190003ea30:·612d·7461·7267·6574·3d22·2369·646d·3139··a-target="#idm19
0003ea40:·3738·2220·7461·6269·6e64·6578·3d22·3022··78"·tabindex="0"0003ea40:·3738·2220·7461·6269·6e64·6578·3d22·3022··78"·tabindex="0"
0003ea50:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003ea50:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003ea60:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003ea60:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003ea70:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003ea70:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003ea80:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003ea80:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003ea90:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003ea90:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003eaa0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
0003eab0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
0003eac0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003ead0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003eae0:·6522·2069·643d·2269·646d·3139·3738·223e··e"·id="idm1978"> 
0003eaf0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003eb00:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003eb10:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003eb20:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003eb30:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003eb40:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003eb50:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003eb60:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003eb70:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003eb80:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003eb90:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0003eba0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
0003ebb0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0003ebc0:·3e3c·7464·3e72·6573·7472·6963·743c·2f74··><td>restrict</t 
0003ebd0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003ebe0:·7072·653e·3c63·6f64·653e·0a66·6f72·2066··pre><code>.for·f 
0003ebf0:·2069·6e20·2f65·7463·2f73·7564·6f65·7273···in·/etc/sudoers 
0003ec00:·202f·6574·632f·7375·646f·6572·732e·642f···/etc/sudoers.d/ 
0003ec10:·2a20·3b20·646f·0a20·2069·6620·5b20·2120··*·;·do.··if·[·!· 
0003ec20:·2d65·2022·2466·2220·5d20·3b20·7468·656e··-e·"$f"·]·;·then 
0003ec30:·0a20·2020·2063·6f6e·7469·6e75·650a·2020··.····continue.·· 
0003ec40:·6669·0a20·206d·6174·6368·696e·675f·6c69··fi.··matching_li 
0003ec50:·7374·3d24·2867·7265·7020·2d50·2027·5e28··st=$(grep·-P·'^( 
0003ec60:·3f21·2329·2e2a·5b5c·735d·2b5c·2161·7574··?!#).*[\s]+\!aut 
0003ec70:·6865·6e74·6963·6174·652e·2a24·2720·2466··henticate.*$'·$f 
0003ec80:·207c·2075·6e69·7120·290a·2020·6966·2021···|·uniq·).··if·! 
0003ec90:·2074·6573·7420·2d7a·2022·246d·6174·6368···test·-z·"$match 
0003eca0:·696e·675f·6c69·7374·223b·2074·6865·6e0a··ing_list";·then. 
0003ecb0:·2020·2020·7768·696c·6520·4946·533d·2072······while·IFS=·r 
0003ecc0:·6561·6420·2d72·2065·6e74·7279·3b20·646f··ead·-r·entry;·do 
0003ecd0:·0a20·2020·2020·2023·2063·6f6d·6d65·6e74··.······#·comment 
0003ece0:·206f·7574·2022·2161·7574·6865·6e74·6963···out·"!authentic 
0003ecf0:·6174·6522·206d·6174·6368·6573·2074·6f20··ate"·matches·to· 
0003ed00:·7072·6573·6572·7665·2075·7365·7220·6461··preserve·user·da 
0003ed10:·7461·0a20·2020·2020·2073·6564·202d·6920··ta.······sed·-i· 
0003ed20:·2273·2f5e·247b·656e·7472·797d·242f·2320··"s/^${entry}$/#· 
0003ed30:·2661·6d70·3b2f·6722·2024·660a·2020·2020··&amp;/g"·$f.···· 
0003ed40:·646f·6e65·2026·6c74·3b26·6c74·3b26·6c74··done·&lt;&lt;&lt 
0003ed50:·3b20·2224·6d61·7463·6869·6e67·5f6c·6973··;·"$matching_lis 
0003ed60:·7422·0a0a·2020·2020·2f75·7372·2f73·6269··t"..····/usr/sbi 
0003ed70:·6e2f·7669·7375·646f·202d·6366·2024·6620··n/visudo·-cf·$f· 
0003ed80:·2661·6d70·3b26·6774·3b20·2f64·6576·2f6e··&amp;&gt;·/dev/n 
0003ed90:·756c·6c20·7c7c·2065·6368·6f20·2246·6169··ull·||·echo·"Fai 
0003eda0:·6c20·746f·2076·616c·6964·6174·6520·2466··l·to·validate·$f 
0003edb0:·2077·6974·6820·7669·7375·646f·220a·2020···with·visudo".·· 
0003edc0:·6669·0a64·6f6e·650a·3c2f·636f·6465·3e3c··fi.done.</code>< 
0003edd0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003ede0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003edf0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003ee00:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003ee10:·612d·7461·7267·6574·3d22·2369·646d·3139··a-target="#idm19 
0003ee20:·3739·2220·7461·6269·6e64·6578·3d22·3022··79"·tabindex="0" 
0003ee30:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003ee40:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003ee50:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003ee60:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003ee70:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003ee80:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn0003eaa0:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn
0003ee90:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003eab0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003eea0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003eac0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003eeb0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003ead0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003eec0:·6170·7365·2220·6964·3d22·6964·6d31·3937··apse"·id="idm1970003eae0:·6170·7365·2220·6964·3d22·6964·6d31·3937··apse"·id="idm197
0003eed0:·3922·3e3c·7461·626c·6520·636c·6173·733d··9"><table·class=0003eaf0:·3822·3e3c·7461·626c·6520·636c·6173·733d··8"><table·class=
0003eee0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003eb00:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003eef0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003eb10:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003ef00:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003eb20:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003ef10:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003eb30:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003ef20:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003eb40:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003ef30:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003eb50:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003ef40:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003eb60:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003ef50:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003eb70:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003ef60:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R0003eb80:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
0003ef70:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f0003eb90:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
0003ef80:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t0003eba0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
0003ef90:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<0003ebb0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0003efa0:·2f74·683e·3c74·643e·7265·7374·7269·6374··/th><td>restrict0003ebc0:·2f74·683e·3c74·643e·7265·7374·7269·6374··/th><td>restrict
0003efb0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003ebd0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003efc0:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n0003ebe0:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n
0003efd0:·616d·653a·2046·696e·6420·2f65·7463·2f73··ame:·Find·/etc/s0003ebf0:·616d·653a·2046·696e·6420·2f65·7463·2f73··ame:·Find·/etc/s
0003efe0:·7564·6f65·7273·2e64·2f20·6669·6c65·730a··udoers.d/·files.0003ec00:·7564·6f65·7273·2e64·2f20·6669·6c65·730a··udoers.d/·files.
0003eff0:·2020·616e·7369·626c·652e·6275·696c·7469····ansible.builti0003ec10:·2020·616e·7369·626c·652e·6275·696c·7469····ansible.builti
0003f000:·6e2e·6669·6e64·3a0a·2020·2020·7061·7468··n.find:.····path0003ec20:·6e2e·6669·6e64·3a0a·2020·2020·7061·7468··n.find:.····path
0003f010:·733a·0a20·2020·202d·202f·6574·632f·7375··s:.····-·/etc/su0003ec30:·733a·0a20·2020·202d·202f·6574·632f·7375··s:.····-·/etc/su
0003f020:·646f·6572·732e·642f·0a20·2072·6567·6973··doers.d/.··regis0003ec40:·646f·6572·732e·642f·0a20·2072·6567·6973··doers.d/.··regis
0003f030:·7465·723a·2073·7564·6f65·7273·0a20·2074··ter:·sudoers.··t0003ec50:·7465·723a·2073·7564·6f65·7273·0a20·2074··ter:·sudoers.··t
0003f040:·6167·733a·0a20·202d·204e·4953·542d·3830··ags:.··-·NIST-800003ec60:·6167·733a·0a20·202d·204e·4953·542d·3830··ags:.··-·NIST-80
0003f050:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··-0003ec70:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··-
0003f060:·204e·4953·542d·3830·302d·3533·2d49·412d···NIST-800-53-IA-0003ec80:·204e·4953·542d·3830·302d·3533·2d49·412d···NIST-800-53-IA-
0003f070:·3131·0a20·202d·206c·6f77·5f63·6f6d·706c··11.··-·low_compl0003ec90:·3131·0a20·202d·206c·6f77·5f63·6f6d·706c··11.··-·low_compl
0003f080:·6578·6974·790a·2020·2d20·6c6f·775f·6469··exity.··-·low_di0003eca0:·6578·6974·790a·2020·2d20·6c6f·775f·6469··exity.··-·low_di
0003f090:·7372·7570·7469·6f6e·0a20·202d·206d·6564··sruption.··-·med0003ecb0:·7372·7570·7469·6f6e·0a20·202d·206d·6564··sruption.··-·med
0003f0a0:·6975·6d5f·7365·7665·7269·7479·0a20·202d··ium_severity.··-0003ecc0:·6975·6d5f·7365·7665·7269·7479·0a20·202d··ium_severity.··-
0003f0b0:·206e·6f5f·7265·626f·6f74·5f6e·6565·6465···no_reboot_neede0003ecd0:·206e·6f5f·7265·626f·6f74·5f6e·6565·6465···no_reboot_neede
0003f0c0:·640a·2020·2d20·7265·7374·7269·6374·5f73··d.··-·restrict_s0003ece0:·640a·2020·2d20·7265·7374·7269·6374·5f73··d.··-·restrict_s
0003f0d0:·7472·6174·6567·790a·2020·2d20·7375·646f··trategy.··-·sudo0003ecf0:·7472·6174·6567·790a·2020·2d20·7375·646f··trategy.··-·sudo
0003f0e0:·5f72·656d·6f76·655f·6e6f·5f61·7574·6865··_remove_no_authe0003ed00:·5f72·656d·6f76·655f·6e6f·5f61·7574·6865··_remove_no_authe
0003f0f0:·6e74·6963·6174·650a·0a2d·206e·616d·653a··nticate..-·name:0003ed10:·6e74·6963·6174·650a·0a2d·206e·616d·653a··nticate..-·name:
0003f100:·2052·656d·6f76·6520·6c69·6e65·7320·636f···Remove·lines·co0003ed20:·2052·656d·6f76·6520·6c69·6e65·7320·636f···Remove·lines·co
0003f110:·6e74·6169·6e69·6e67·2021·6175·7468·656e··ntaining·!authen0003ed30:·6e74·6169·6e69·6e67·2021·6175·7468·656e··ntaining·!authen
Max diff block lines reached; 877854/897780 bytes (97.78%) of diff not shown.
110 KB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Average·(Intermediate)·Level38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Average·(Intermediate)·Level
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_average39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_average
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~
42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
43 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8443 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
48 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g48 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
49 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s49 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
50 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s50 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
51 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n51 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
Offset 232, 35 lines modifiedOffset 232, 14 lines modified
232 ···························1.7,·SR·1.8,·SR·1.9232 ···························1.7,·SR·1.8,·SR·1.9
233 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,233 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
234 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3234 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
235 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)235 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
236 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7236 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
237 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,237 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
238 ···························SRG-OS-000373-GPOS-00158238 ···························SRG-OS-000373-GPOS-00158
239 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
240 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
241 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
242 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
243 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
244 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
245 ··if·[·!·-e·"$f"·]·;·then 
246 ····continue 
247 ··fi 
248 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·) 
249 ··if·!·test·-z·"$matching_list";·then 
250 ····while·IFS=·read·-r·entry;·do 
251 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data 
252 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
253 ····done·<<<·"$matching_list" 
  
254 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
255 visudo" 
256 ··fi 
257 done 
258 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8239 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
259 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low240 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
260 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low241 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
261 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false242 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
262 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict243 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
263 -·name:·Find·/etc/sudoers.d/·files244 -·name:·Find·/etc/sudoers.d/·files
264 ··ansible.builtin.find:245 ··ansible.builtin.find:
Offset 291, 14 lines modifiedOffset 270, 35 lines modified
291 ··-·NIST-800-53-IA-11270 ··-·NIST-800-53-IA-11
292 ··-·low_complexity271 ··-·low_complexity
293 ··-·low_disruption272 ··-·low_disruption
294 ··-·medium_severity273 ··-·medium_severity
295 ··-·no_reboot_needed274 ··-·no_reboot_needed
296 ··-·restrict_strategy275 ··-·restrict_strategy
297 ··-·sudo_remove_no_authenticate276 ··-·sudo_remove_no_authenticate
 277 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 278 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 279 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 280 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 281 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 282 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do
 283 ··if·[·!·-e·"$f"·]·;·then
 284 ····continue
 285 ··fi
 286 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·)
 287 ··if·!·test·-z·"$matching_list";·then
 288 ····while·IFS=·read·-r·entry;·do
 289 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data
 290 ······sed·-i·"s/^${entry}$/#·&/g"·$f
 291 ····done·<<<·"$matching_list"
  
 292 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with
 293 visudo"
 294 ··fi
 295 done
298 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o296 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o
299 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*297 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
300 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using298 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using
301 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure299 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure
302 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any300 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any
303 sudo·configuration·snippets·in·/etc/sudoers.d/.301 sudo·configuration·snippets·in·/etc/sudoers.d/.
304 ············Without·re-authentication,·users·may·access·resources·or·perform302 ············Without·re-authentication,·users·may·access·resources·or·perform
Offset 319, 35 lines modifiedOffset 319, 14 lines modified
319 ···························1.7,·SR·1.8,·SR·1.9319 ···························1.7,·SR·1.8,·SR·1.9
320 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,320 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
321 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3321 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
322 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)322 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
323 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7323 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
324 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,324 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
325 ···························SRG-OS-000373-GPOS-00158325 ···························SRG-OS-000373-GPOS-00158
326 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
327 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
328 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
329 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
330 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
331 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
332 ··if·[·!·-e·"$f"·]·;·then 
333 ····continue 
334 ··fi 
335 ··matching_list=$(grep·-P·'^(?!#).*[\s]+NOPASSWD[\s]*\:.*$'·$f·|·uniq·) 
336 ··if·!·test·-z·"$matching_list";·then 
337 ····while·IFS=·read·-r·entry;·do 
338 ······#·comment·out·"NOPASSWD"·matches·to·preserve·user·data 
339 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
340 ····done·<<<·"$matching_list" 
  
341 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
342 visudo" 
343 ··fi 
344 done 
345 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8326 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
346 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low327 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
347 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low328 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
348 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false329 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
349 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict330 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
350 -·name:·Find·/etc/sudoers.d/·files331 -·name:·Find·/etc/sudoers.d/·files
351 ··ansible.builtin.find:332 ··ansible.builtin.find:
Offset 378, 14 lines modifiedOffset 357, 35 lines modified
378 ··-·NIST-800-53-IA-11357 ··-·NIST-800-53-IA-11
379 ··-·low_complexity358 ··-·low_complexity
380 ··-·low_disruption359 ··-·low_disruption
Max diff block lines reached; 107104/112853 bytes (94.91%) of diff not shown.
1.1 MB
./usr/share/doc/ssg-debderived/ssg-ubuntu1804-guide-anssi_np_nt28_high.html
    
Offset 14288, 15 lines modifiedOffset 14288, 15 lines modified
00037cf0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00037cf0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00037d00:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00037d00:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00037d10:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s00037d10:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00037d20:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00037d20:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00037d30:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00037d30:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00037d40:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00037d40:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00037d50:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00037d50:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00037d60:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).00037d60:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
00037d70:·2020·2020·2020·2020·2020·2020·2020·2020··················00037d70:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037d80:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00037d80:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00037d90:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00037d90:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00037da0:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00037da0:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00037db0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00037db0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00037dc0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00037dc0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00037dd0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00037dd0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
Offset 16056, 146 lines modifiedOffset 16056, 146 lines modified
0003eb70:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003eb70:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003eb80:·646d·3139·3738·2220·7461·6269·6e64·6578··dm1978"·tabindex0003eb80:·646d·3139·3738·2220·7461·6269·6e64·6578··dm1978"·tabindex
0003eb90:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003eb90:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003eba0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003eba0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003ebb0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003ebb0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003ebc0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003ebc0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003ebd0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003ebd0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003ebe0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
0003ebf0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003ec00:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003ec10:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003ec20:·6c61·7073·6522·2069·643d·2269·646d·3139··lapse"·id="idm19 
0003ec30:·3738·223e·3c74·6162·6c65·2063·6c61·7373··78"><table·class 
0003ec40:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003ec50:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003ec60:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003ec70:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003ec80:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003ec90:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003eca0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003ecb0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003ecc0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003ecd0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003ece0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
0003ecf0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003ed00:·3c2f·7468·3e3c·7464·3e72·6573·7472·6963··</th><td>restric 
0003ed10:·743c·2f74·643e·3c2f·7472·3e3c·2f74·6162··t</td></tr></tab 
0003ed20:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a66··le><pre><code>.f 
0003ed30:·6f72·2066·2069·6e20·2f65·7463·2f73·7564··or·f·in·/etc/sud 
0003ed40:·6f65·7273·202f·6574·632f·7375·646f·6572··oers·/etc/sudoer 
0003ed50:·732e·642f·2a20·3b20·646f·0a20·2069·6620··s.d/*·;·do.··if· 
0003ed60:·5b20·2120·2d65·2022·2466·2220·5d20·3b20··[·!·-e·"$f"·]·;· 
0003ed70:·7468·656e·0a20·2020·2063·6f6e·7469·6e75··then.····continu 
0003ed80:·650a·2020·6669·0a20·206d·6174·6368·696e··e.··fi.··matchin 
0003ed90:·675f·6c69·7374·3d24·2867·7265·7020·2d50··g_list=$(grep·-P 
0003eda0:·2027·5e28·3f21·2329·2e2a·5b5c·735d·2b5c···'^(?!#).*[\s]+\ 
0003edb0:·2161·7574·6865·6e74·6963·6174·652e·2a24··!authenticate.*$ 
0003edc0:·2720·2466·207c·2075·6e69·7120·290a·2020··'·$f·|·uniq·).·· 
0003edd0:·6966·2021·2074·6573·7420·2d7a·2022·246d··if·!·test·-z·"$m 
0003ede0:·6174·6368·696e·675f·6c69·7374·223b·2074··atching_list";·t 
0003edf0:·6865·6e0a·2020·2020·7768·696c·6520·4946··hen.····while·IF 
0003ee00:·533d·2072·6561·6420·2d72·2065·6e74·7279··S=·read·-r·entry 
0003ee10:·3b20·646f·0a20·2020·2020·2023·2063·6f6d··;·do.······#·com 
0003ee20:·6d65·6e74·206f·7574·2022·2161·7574·6865··ment·out·"!authe 
0003ee30:·6e74·6963·6174·6522·206d·6174·6368·6573··nticate"·matches 
0003ee40:·2074·6f20·7072·6573·6572·7665·2075·7365···to·preserve·use 
0003ee50:·7220·6461·7461·0a20·2020·2020·2073·6564··r·data.······sed 
0003ee60:·202d·6920·2273·2f5e·247b·656e·7472·797d···-i·"s/^${entry} 
0003ee70:·242f·2320·2661·6d70·3b2f·6722·2024·660a··$/#·&amp;/g"·$f. 
0003ee80:·2020·2020·646f·6e65·2026·6c74·3b26·6c74······done·&lt;&lt 
0003ee90:·3b26·6c74·3b20·2224·6d61·7463·6869·6e67··;&lt;·"$matching 
0003eea0:·5f6c·6973·7422·0a0a·2020·2020·2f75·7372··_list"..····/usr 
0003eeb0:·2f73·6269·6e2f·7669·7375·646f·202d·6366··/sbin/visudo·-cf 
0003eec0:·2024·6620·2661·6d70·3b26·6774·3b20·2f64···$f·&amp;&gt;·/d 
0003eed0:·6576·2f6e·756c·6c20·7c7c·2065·6368·6f20··ev/null·||·echo· 
0003eee0:·2246·6169·6c20·746f·2076·616c·6964·6174··"Fail·to·validat 
0003eef0:·6520·2466·2077·6974·6820·7669·7375·646f··e·$f·with·visudo 
0003ef00:·220a·2020·6669·0a64·6f6e·650a·3c2f·636f··".··fi.done.</co 
0003ef10:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003ef20:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003ef30:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003ef40:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003ef50:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003ef60:·646d·3139·3739·2220·7461·6269·6e64·6578··dm1979"·tabindex 
0003ef70:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003ef80:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003ef90:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003efa0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003efb0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003efc0:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl0003ebe0:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl
0003efd0:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a0003ebf0:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a
0003efe0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003ec00:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003eff0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003ec10:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003f000:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003ec20:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003f010:·6d31·3937·3922·3e3c·7461·626c·6520·636c··m1979"><table·cl0003ec30:·6d31·3937·3822·3e3c·7461·626c·6520·636c··m1978"><table·cl
0003f020:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003ec40:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003f030:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003ec50:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003f040:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003ec60:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003f050:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003ec70:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003f060:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003ec80:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003f070:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003ec90:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003f080:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003eca0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003f090:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003ecb0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0003f0a0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003ecc0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003f0b0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><0003ecd0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
0003f0c0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t0003ece0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
0003f0d0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate0003ecf0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003f0e0:·6779·3a3c·2f74·683e·3c74·643e·7265·7374··gy:</th><td>rest0003ed00:·6779·3a3c·2f74·683e·3c74·643e·7265·7374··gy:</th><td>rest
0003f0f0:·7269·6374·3c2f·7464·3e3c·2f74·723e·3c2f··rict</td></tr></0003ed10:·7269·6374·3c2f·7464·3e3c·2f74·723e·3c2f··rict</td></tr></
0003f100:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003ed20:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
0003f110:·3e2d·206e·616d·653a·2046·696e·6420·2f65··>-·name:·Find·/e0003ed30:·3e2d·206e·616d·653a·2046·696e·6420·2f65··>-·name:·Find·/e
0003f120:·7463·2f73·7564·6f65·7273·2e64·2f20·6669··tc/sudoers.d/·fi0003ed40:·7463·2f73·7564·6f65·7273·2e64·2f20·6669··tc/sudoers.d/·fi
0003f130:·6c65·730a·2020·616e·7369·626c·652e·6275··les.··ansible.bu0003ed50:·6c65·730a·2020·616e·7369·626c·652e·6275··les.··ansible.bu
0003f140:·696c·7469·6e2e·6669·6e64·3a0a·2020·2020··iltin.find:.····0003ed60:·696c·7469·6e2e·6669·6e64·3a0a·2020·2020··iltin.find:.····
0003f150:·7061·7468·733a·0a20·2020·202d·202f·6574··paths:.····-·/et0003ed70:·7061·7468·733a·0a20·2020·202d·202f·6574··paths:.····-·/et
0003f160:·632f·7375·646f·6572·732e·642f·0a20·2072··c/sudoers.d/.··r0003ed80:·632f·7375·646f·6572·732e·642f·0a20·2072··c/sudoers.d/.··r
0003f170:·6567·6973·7465·723a·2073·7564·6f65·7273··egister:·sudoers0003ed90:·6567·6973·7465·723a·2073·7564·6f65·7273··egister:·sudoers
0003f180:·0a20·2074·6167·733a·0a20·202d·204e·4953··.··tags:.··-·NIS0003eda0:·0a20·2074·6167·733a·0a20·202d·204e·4953··.··tags:.··-·NIS
0003f190:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a)0003edb0:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a)
0003f1a0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-530003edc0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
0003f1b0:·2d49·412d·3131·0a20·202d·206c·6f77·5f63··-IA-11.··-·low_c0003edd0:·2d49·412d·3131·0a20·202d·206c·6f77·5f63··-IA-11.··-·low_c
0003f1c0:·6f6d·706c·6578·6974·790a·2020·2d20·6c6f··omplexity.··-·lo0003ede0:·6f6d·706c·6578·6974·790a·2020·2d20·6c6f··omplexity.··-·lo
0003f1d0:·775f·6469·7372·7570·7469·6f6e·0a20·202d··w_disruption.··-0003edf0:·775f·6469·7372·7570·7469·6f6e·0a20·202d··w_disruption.··-
0003f1e0:·206d·6564·6975·6d5f·7365·7665·7269·7479···medium_severity0003ee00:·206d·6564·6975·6d5f·7365·7665·7269·7479···medium_severity
0003f1f0:·0a20·202d·206e·6f5f·7265·626f·6f74·5f6e··.··-·no_reboot_n0003ee10:·0a20·202d·206e·6f5f·7265·626f·6f74·5f6e··.··-·no_reboot_n
0003f200:·6565·6465·640a·2020·2d20·7265·7374·7269··eeded.··-·restri0003ee20:·6565·6465·640a·2020·2d20·7265·7374·7269··eeded.··-·restri
0003f210:·6374·5f73·7472·6174·6567·790a·2020·2d20··ct_strategy.··-·0003ee30:·6374·5f73·7472·6174·6567·790a·2020·2d20··ct_strategy.··-·
0003f220:·7375·646f·5f72·656d·6f76·655f·6e6f·5f61··sudo_remove_no_a0003ee40:·7375·646f·5f72·656d·6f76·655f·6e6f·5f61··sudo_remove_no_a
0003f230:·7574·6865·6e74·6963·6174·650a·0a2d·206e··uthenticate..-·n0003ee50:·7574·6865·6e74·6963·6174·650a·0a2d·206e··uthenticate..-·n
0003f240:·616d·653a·2052·656d·6f76·6520·6c69·6e65··ame:·Remove·line0003ee60:·616d·653a·2052·656d·6f76·6520·6c69·6e65··ame:·Remove·line
0003f250:·7320·636f·6e74·6169·6e69·6e67·2021·6175··s·containing·!au0003ee70:·7320·636f·6e74·6169·6e69·6e67·2021·6175··s·containing·!au
Max diff block lines reached; 1004982/1024908 bytes (98.06%) of diff not shown.
126 KB
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·High·(Enforced)·Level39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·High·(Enforced)·Level
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_high40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_high
41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
42 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~42 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~
43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
44 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8444 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
49 ·········2.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n49 ·········2.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
51 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s51 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
52 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s52 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
Offset 236, 35 lines modifiedOffset 236, 14 lines modified
236 ···························1.7,·SR·1.8,·SR·1.9236 ···························1.7,·SR·1.8,·SR·1.9
237 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,237 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
238 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3238 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
239 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)239 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
240 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7240 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
241 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,241 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
242 ···························SRG-OS-000373-GPOS-00158242 ···························SRG-OS-000373-GPOS-00158
243 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
244 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
245 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
246 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
247 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
248 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
249 ··if·[·!·-e·"$f"·]·;·then 
250 ····continue 
251 ··fi 
252 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·) 
253 ··if·!·test·-z·"$matching_list";·then 
254 ····while·IFS=·read·-r·entry;·do 
255 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data 
256 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
257 ····done·<<<·"$matching_list" 
  
258 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
259 visudo" 
260 ··fi 
261 done 
262 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8243 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
263 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low244 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
264 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low245 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
265 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false246 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
266 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict247 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
267 -·name:·Find·/etc/sudoers.d/·files248 -·name:·Find·/etc/sudoers.d/·files
268 ··ansible.builtin.find:249 ··ansible.builtin.find:
Offset 295, 14 lines modifiedOffset 274, 35 lines modified
295 ··-·NIST-800-53-IA-11274 ··-·NIST-800-53-IA-11
296 ··-·low_complexity275 ··-·low_complexity
297 ··-·low_disruption276 ··-·low_disruption
298 ··-·medium_severity277 ··-·medium_severity
299 ··-·no_reboot_needed278 ··-·no_reboot_needed
300 ··-·restrict_strategy279 ··-·restrict_strategy
301 ··-·sudo_remove_no_authenticate280 ··-·sudo_remove_no_authenticate
 281 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 282 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 283 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 284 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 285 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 286 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do
 287 ··if·[·!·-e·"$f"·]·;·then
 288 ····continue
 289 ··fi
 290 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·)
 291 ··if·!·test·-z·"$matching_list";·then
 292 ····while·IFS=·read·-r·entry;·do
 293 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data
 294 ······sed·-i·"s/^${entry}$/#·&/g"·$f
 295 ····done·<<<·"$matching_list"
  
 296 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with
 297 visudo"
 298 ··fi
 299 done
302 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o300 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o
303 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*301 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
304 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using302 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using
305 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure303 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure
306 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any304 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any
307 sudo·configuration·snippets·in·/etc/sudoers.d/.305 sudo·configuration·snippets·in·/etc/sudoers.d/.
308 ············Without·re-authentication,·users·may·access·resources·or·perform306 ············Without·re-authentication,·users·may·access·resources·or·perform
Offset 323, 35 lines modifiedOffset 323, 14 lines modified
323 ···························1.7,·SR·1.8,·SR·1.9323 ···························1.7,·SR·1.8,·SR·1.9
324 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,324 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
325 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3325 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
326 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)326 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
327 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7327 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
328 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,328 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
329 ···························SRG-OS-000373-GPOS-00158329 ···························SRG-OS-000373-GPOS-00158
330 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
331 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
332 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
333 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
334 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
335 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
336 ··if·[·!·-e·"$f"·]·;·then 
337 ····continue 
338 ··fi 
339 ··matching_list=$(grep·-P·'^(?!#).*[\s]+NOPASSWD[\s]*\:.*$'·$f·|·uniq·) 
340 ··if·!·test·-z·"$matching_list";·then 
341 ····while·IFS=·read·-r·entry;·do 
342 ······#·comment·out·"NOPASSWD"·matches·to·preserve·user·data 
343 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
344 ····done·<<<·"$matching_list" 
  
345 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
346 visudo" 
347 ··fi 
348 done 
349 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8330 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
350 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low331 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
351 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low332 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
352 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false333 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
353 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict334 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
354 -·name:·Find·/etc/sudoers.d/·files335 -·name:·Find·/etc/sudoers.d/·files
355 ··ansible.builtin.find:336 ··ansible.builtin.find:
Offset 382, 14 lines modifiedOffset 361, 35 lines modified
382 ··-·NIST-800-53-IA-11361 ··-·NIST-800-53-IA-11
383 ··-·low_complexity362 ··-·low_complexity
384 ··-·low_disruption363 ··-·low_disruption
Max diff block lines reached; 122750/128504 bytes (95.52%) of diff not shown.
302 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1804-guide-anssi_np_nt28_minimal.html
    
Offset 14281, 15 lines modifiedOffset 14281, 15 lines modified
00037c80:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00037c80:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00037c90:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00037c90:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00037ca0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<00037ca0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<
00037cb0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00037cb0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00037cc0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00037cc0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00037cd0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00037cd0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00037ce0:·2020·2020·2020·2020·2020·2020·2020·2028·················(00037ce0:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00037cf0:·6173·206f·6620·3230·3236·2d30·312d·3038··as·of·2026-01-0800037cf0:·6173·206f·6620·3230·3234·2d31·322d·3037··as·of·2024-12-07
00037d00:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00037d00:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00037d10:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00037d10:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00037d20:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00037d20:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00037d30:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00037d30:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00037d40:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00037d40:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00037d50:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00037d50:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00037d60:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00037d60:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
Offset 14774, 147 lines modifiedOffset 14774, 147 lines modified
00039b50:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe00039b50:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
00039b60:·743d·2223·6964·6d31·3937·3822·2074·6162··t="#idm1978"·tab00039b60:·743d·2223·6964·6d31·3937·3822·2074·6162··t="#idm1978"·tab
00039b70:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="00039b70:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
00039b80:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp00039b80:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
00039b90:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti00039b90:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
00039ba0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to00039ba0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
00039bb0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#00039bb0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
00039bc0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
00039bd0:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
00039be0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
00039bf0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
00039c00:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
00039c10:·6964·6d31·3937·3822·3e3c·7461·626c·6520··idm1978"><table· 
00039c20:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
00039c30:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
00039c40:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
00039c50:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
00039c60:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
00039c70:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
00039c80:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
00039c90:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
00039ca0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
00039cb0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
00039cc0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
00039cd0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
00039ce0:·7465·6779·3a3c·2f74·683e·3c74·643e·7265··tegy:</th><td>re 
00039cf0:·7374·7269·6374·3c2f·7464·3e3c·2f74·723e··strict</td></tr> 
00039d00:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
00039d10:·6465·3e0a·666f·7220·6620·696e·202f·6574··de>.for·f·in·/et 
00039d20:·632f·7375·646f·6572·7320·2f65·7463·2f73··c/sudoers·/etc/s 
00039d30:·7564·6f65·7273·2e64·2f2a·203b·2064·6f0a··udoers.d/*·;·do. 
00039d40:·2020·6966·205b·2021·202d·6520·2224·6622····if·[·!·-e·"$f" 
00039d50:·205d·203b·2074·6865·6e0a·2020·2020·636f···]·;·then.····co 
00039d60:·6e74·696e·7565·0a20·2066·690a·2020·6d61··ntinue.··fi.··ma 
00039d70:·7463·6869·6e67·5f6c·6973·743d·2428·6772··tching_list=$(gr 
00039d80:·6570·202d·5020·275e·283f·2123·292e·2a5b··ep·-P·'^(?!#).*[ 
00039d90:·5c73·5d2b·5c21·6175·7468·656e·7469·6361··\s]+\!authentica 
00039da0:·7465·2e2a·2427·2024·6620·7c20·756e·6971··te.*$'·$f·|·uniq 
00039db0:·2029·0a20·2069·6620·2120·7465·7374·202d···).··if·!·test·- 
00039dc0:·7a20·2224·6d61·7463·6869·6e67·5f6c·6973··z·"$matching_lis 
00039dd0:·7422·3b20·7468·656e·0a20·2020·2077·6869··t";·then.····whi 
00039de0:·6c65·2049·4653·3d20·7265·6164·202d·7220··le·IFS=·read·-r· 
00039df0:·656e·7472·793b·2064·6f0a·2020·2020·2020··entry;·do.······ 
00039e00:·2320·636f·6d6d·656e·7420·6f75·7420·2221··#·comment·out·"! 
00039e10:·6175·7468·656e·7469·6361·7465·2220·6d61··authenticate"·ma 
00039e20:·7463·6865·7320·746f·2070·7265·7365·7276··tches·to·preserv 
00039e30:·6520·7573·6572·2064·6174·610a·2020·2020··e·user·data.···· 
00039e40:·2020·7365·6420·2d69·2022·732f·5e24·7b65····sed·-i·"s/^${e 
00039e50:·6e74·7279·7d24·2f23·2026·616d·703b·2f67··ntry}$/#·&amp;/g 
00039e60:·2220·2466·0a20·2020·2064·6f6e·6520·266c··"·$f.····done·&l 
00039e70:·743b·266c·743b·266c·743b·2022·246d·6174··t;&lt;&lt;·"$mat 
00039e80:·6368·696e·675f·6c69·7374·220a·0a20·2020··ching_list"..··· 
00039e90:·202f·7573·722f·7362·696e·2f76·6973·7564···/usr/sbin/visud 
00039ea0:·6f20·2d63·6620·2466·2026·616d·703b·2667··o·-cf·$f·&amp;&g 
00039eb0:·743b·202f·6465·762f·6e75·6c6c·207c·7c20··t;·/dev/null·||· 
00039ec0:·6563·686f·2022·4661·696c·2074·6f20·7661··echo·"Fail·to·va 
00039ed0:·6c69·6461·7465·2024·6620·7769·7468·2076··lidate·$f·with·v 
00039ee0:·6973·7564·6f22·0a20·2066·690a·646f·6e65··isudo".··fi.done 
00039ef0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
00039f00:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
00039f10:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
00039f20:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
00039f30:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
00039f40:·743d·2223·6964·6d31·3937·3922·2074·6162··t="#idm1979"·tab 
00039f50:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
00039f60:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
00039f70:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
00039f80:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
00039f90:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
00039fa0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A00039bc0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
00039fb0:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.00039bd0:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.
00039fc0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c00039be0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
00039fd0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll00039bf0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
00039fe0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i00039c00:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
00039ff0:·643d·2269·646d·3139·3739·223e·3c74·6162··d="idm1979"><tab00039c10:·643d·2269·646d·3139·3738·223e·3c74·6162··d="idm1978"><tab
0003a000:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·00039c20:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003a010:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta00039c30:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003a020:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab00039c40:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003a030:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t00039c50:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003a040:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity00039c60:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003a050:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t00039c70:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003a060:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D00039c80:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
0003a070:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><00039c90:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003a080:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>00039ca0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003a090:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<00039cb0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
0003a0a0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t00039cc0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003a0b0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S00039cd0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003a0c0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td00039ce0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003a0d0:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></00039cf0:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></
0003a0e0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>00039d00:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
0003a0f0:·3c63·6f64·653e·2d20·6e61·6d65·3a20·4669··<code>-·name:·Fi00039d10:·3c63·6f64·653e·2d20·6e61·6d65·3a20·4669··<code>-·name:·Fi
0003a100:·6e64·202f·6574·632f·7375·646f·6572·732e··nd·/etc/sudoers.00039d20:·6e64·202f·6574·632f·7375·646f·6572·732e··nd·/etc/sudoers.
0003a110:·642f·2066·696c·6573·0a20·2061·6e73·6962··d/·files.··ansib00039d30:·642f·2066·696c·6573·0a20·2061·6e73·6962··d/·files.··ansib
0003a120:·6c65·2e62·7569·6c74·696e·2e66·696e·643a··le.builtin.find:00039d40:·6c65·2e62·7569·6c74·696e·2e66·696e·643a··le.builtin.find:
0003a130:·0a20·2020·2070·6174·6873·3a0a·2020·2020··.····paths:.····00039d50:·0a20·2020·2070·6174·6873·3a0a·2020·2020··.····paths:.····
0003a140:·2d20·2f65·7463·2f73·7564·6f65·7273·2e64··-·/etc/sudoers.d00039d60:·2d20·2f65·7463·2f73·7564·6f65·7273·2e64··-·/etc/sudoers.d
0003a150:·2f0a·2020·7265·6769·7374·6572·3a20·7375··/.··register:·su00039d70:·2f0a·2020·7265·6769·7374·6572·3a20·7375··/.··register:·su
0003a160:·646f·6572·730a·2020·7461·6773·3a0a·2020··doers.··tags:.··00039d80:·646f·6572·730a·2020·7461·6773·3a0a·2020··doers.··tags:.··
0003a170:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM00039d90:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
0003a180:·2d36·2861·290a·2020·2d20·4e49·5354·2d38··-6(a).··-·NIST-800039da0:·2d36·2861·290a·2020·2d20·4e49·5354·2d38··-6(a).··-·NIST-8
0003a190:·3030·2d35·332d·4941·2d31·310a·2020·2d20··00-53-IA-11.··-·00039db0:·3030·2d35·332d·4941·2d31·310a·2020·2d20··00-53-IA-11.··-·
0003a1a0:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.·00039dc0:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.·
0003a1b0:·202d·206c·6f77·5f64·6973·7275·7074·696f···-·low_disruptio00039dd0:·202d·206c·6f77·5f64·6973·7275·7074·696f···-·low_disruptio
0003a1c0:·6e0a·2020·2d20·6d65·6469·756d·5f73·6576··n.··-·medium_sev00039de0:·6e0a·2020·2d20·6d65·6469·756d·5f73·6576··n.··-·medium_sev
0003a1d0:·6572·6974·790a·2020·2d20·6e6f·5f72·6562··erity.··-·no_reb00039df0:·6572·6974·790a·2020·2d20·6e6f·5f72·6562··erity.··-·no_reb
0003a1e0:·6f6f·745f·6e65·6564·6564·0a20·202d·2072··oot_needed.··-·r00039e00:·6f6f·745f·6e65·6564·6564·0a20·202d·2072··oot_needed.··-·r
0003a1f0:·6573·7472·6963·745f·7374·7261·7465·6779··estrict_strategy00039e10:·6573·7472·6963·745f·7374·7261·7465·6779··estrict_strategy
0003a200:·0a20·202d·2073·7564·6f5f·7265·6d6f·7665··.··-·sudo_remove00039e20:·0a20·202d·2073·7564·6f5f·7265·6d6f·7665··.··-·sudo_remove
0003a210:·5f6e·6f5f·6175·7468·656e·7469·6361·7465··_no_authenticate00039e30:·5f6e·6f5f·6175·7468·656e·7469·6361·7465··_no_authenticate
0003a220:·0a0a·2d20·6e61·6d65·3a20·5265·6d6f·7665··..-·name:·Remove00039e40:·0a0a·2d20·6e61·6d65·3a20·5265·6d6f·7665··..-·name:·Remove
0003a230:·206c·696e·6573·2063·6f6e·7461·696e·696e···lines·containin00039e50:·206c·696e·6573·2063·6f6e·7461·696e·696e···lines·containin
Max diff block lines reached; 250530/270594 bytes (92.59%) of diff not shown.
37.7 KB
html2text {}
    
Offset 36, 15 lines modifiedOffset 36, 15 lines modified
36 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*36 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
37 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Minimal·Level37 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Minimal·Level
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_minimal38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_minimal
39 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*39 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
40 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~40 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~
41 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*41 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
42 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8442 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
43 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)43 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
44 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*44 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
45 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s45 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
46 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e46 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
47 ·········2.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s47 ·········2.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
48 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s48 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
49 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n49 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
50 ·········2.·_\x8D_\x8e_\x8p_\x8r_\x8e_\x8c_\x8a_\x8t_\x8e_\x8d_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s50 ·········2.·_\x8D_\x8e_\x8p_\x8r_\x8e_\x8c_\x8a_\x8t_\x8e_\x8d_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
Offset 90, 35 lines modifiedOffset 90, 14 lines modified
90 ···························1.7,·SR·1.8,·SR·1.990 ···························1.7,·SR·1.8,·SR·1.9
91 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,91 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
92 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.392 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
93 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)93 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
94 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-794 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
95 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,95 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
96 ···························SRG-OS-000373-GPOS-0015896 ···························SRG-OS-000373-GPOS-00158
97 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
98 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
99 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
100 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
101 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
102 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
103 ··if·[·!·-e·"$f"·]·;·then 
104 ····continue 
105 ··fi 
106 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·) 
107 ··if·!·test·-z·"$matching_list";·then 
108 ····while·IFS=·read·-r·entry;·do 
109 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data 
110 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
111 ····done·<<<·"$matching_list" 
  
112 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
113 visudo" 
114 ··fi 
115 done 
116 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x897 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
117 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low98 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
118 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low99 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
119 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false100 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
120 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict101 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
121 -·name:·Find·/etc/sudoers.d/·files102 -·name:·Find·/etc/sudoers.d/·files
122 ··ansible.builtin.find:103 ··ansible.builtin.find:
Offset 149, 14 lines modifiedOffset 128, 35 lines modified
149 ··-·NIST-800-53-IA-11128 ··-·NIST-800-53-IA-11
150 ··-·low_complexity129 ··-·low_complexity
151 ··-·low_disruption130 ··-·low_disruption
152 ··-·medium_severity131 ··-·medium_severity
153 ··-·no_reboot_needed132 ··-·no_reboot_needed
154 ··-·restrict_strategy133 ··-·restrict_strategy
155 ··-·sudo_remove_no_authenticate134 ··-·sudo_remove_no_authenticate
 135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 140 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do
 141 ··if·[·!·-e·"$f"·]·;·then
 142 ····continue
 143 ··fi
 144 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·)
 145 ··if·!·test·-z·"$matching_list";·then
 146 ····while·IFS=·read·-r·entry;·do
 147 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data
 148 ······sed·-i·"s/^${entry}$/#·&/g"·$f
 149 ····done·<<<·"$matching_list"
  
 150 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with
 151 visudo"
 152 ··fi
 153 done
156 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o154 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o
157 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*155 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
158 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using156 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using
159 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure157 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure
160 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any158 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any
161 sudo·configuration·snippets·in·/etc/sudoers.d/.159 sudo·configuration·snippets·in·/etc/sudoers.d/.
162 ············Without·re-authentication,·users·may·access·resources·or·perform160 ············Without·re-authentication,·users·may·access·resources·or·perform
Offset 177, 35 lines modifiedOffset 177, 14 lines modified
177 ···························1.7,·SR·1.8,·SR·1.9177 ···························1.7,·SR·1.8,·SR·1.9
178 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,178 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
179 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3179 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
180 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)180 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
181 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7181 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
182 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,182 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
183 ···························SRG-OS-000373-GPOS-00158183 ···························SRG-OS-000373-GPOS-00158
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
189 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
190 ··if·[·!·-e·"$f"·]·;·then 
191 ····continue 
192 ··fi 
193 ··matching_list=$(grep·-P·'^(?!#).*[\s]+NOPASSWD[\s]*\:.*$'·$f·|·uniq·) 
194 ··if·!·test·-z·"$matching_list";·then 
195 ····while·IFS=·read·-r·entry;·do 
196 ······#·comment·out·"NOPASSWD"·matches·to·preserve·user·data 
197 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
198 ····done·<<<·"$matching_list" 
  
199 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
200 visudo" 
201 ··fi 
202 done 
203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
204 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
205 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
206 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
207 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
208 -·name:·Find·/etc/sudoers.d/·files189 -·name:·Find·/etc/sudoers.d/·files
209 ··ansible.builtin.find:190 ··ansible.builtin.find:
Offset 236, 14 lines modifiedOffset 215, 35 lines modified
236 ··-·NIST-800-53-IA-11215 ··-·NIST-800-53-IA-11
237 ··-·low_complexity216 ··-·low_complexity
238 ··-·low_disruption217 ··-·low_disruption
Max diff block lines reached; 32794/38535 bytes (85.10%) of diff not shown.
1.09 MB
./usr/share/doc/ssg-debderived/ssg-ubuntu1804-guide-anssi_np_nt28_restrictive.html
    
Offset 14285, 15 lines modifiedOffset 14285, 15 lines modified
00037cc0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00037cc0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00037cd0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00037cd0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00037ce0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<00037ce0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<
00037cf0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00037cf0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00037d00:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00037d00:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00037d10:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00037d10:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00037d20:·2020·2020·2020·2020·2020·2020·2020·2028·················(00037d20:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00037d30:·6173·206f·6620·3230·3236·2d30·312d·3038··as·of·2026-01-0800037d30:·6173·206f·6620·3230·3234·2d31·322d·3037··as·of·2024-12-07
00037d40:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00037d40:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00037d50:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00037d50:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00037d60:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00037d60:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00037d70:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00037d70:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00037d80:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00037d80:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00037d90:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00037d90:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00037da0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00037da0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
Offset 16047, 146 lines modifiedOffset 16047, 146 lines modified
0003eae0:·7267·6574·3d22·2369·646d·3139·3738·2220··rget="#idm1978"·0003eae0:·7267·6574·3d22·2369·646d·3139·3738·2220··rget="#idm1978"·
0003eaf0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003eaf0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003eb00:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003eb00:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003eb10:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003eb10:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003eb20:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003eb20:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003eb30:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003eb30:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003eb40:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003eb40:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003eb50:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
0003eb60:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003eb70:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003eb80:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003eb90:·643d·2269·646d·3139·3738·223e·3c74·6162··d="idm1978"><tab 
0003eba0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003ebb0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003ebc0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003ebd0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003ebe0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003ebf0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003ec00:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003ec10:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003ec20:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003ec30:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003ec40:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003ec50:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003ec60:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003ec70:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></ 
0003ec80:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003ec90:·3c63·6f64·653e·0a66·6f72·2066·2069·6e20··<code>.for·f·in· 
0003eca0:·2f65·7463·2f73·7564·6f65·7273·202f·6574··/etc/sudoers·/et 
0003ecb0:·632f·7375·646f·6572·732e·642f·2a20·3b20··c/sudoers.d/*·;· 
0003ecc0:·646f·0a20·2069·6620·5b20·2120·2d65·2022··do.··if·[·!·-e·" 
0003ecd0:·2466·2220·5d20·3b20·7468·656e·0a20·2020··$f"·]·;·then.··· 
0003ece0:·2063·6f6e·7469·6e75·650a·2020·6669·0a20···continue.··fi.· 
0003ecf0:·206d·6174·6368·696e·675f·6c69·7374·3d24···matching_list=$ 
0003ed00:·2867·7265·7020·2d50·2027·5e28·3f21·2329··(grep·-P·'^(?!#) 
0003ed10:·2e2a·5b5c·735d·2b5c·2161·7574·6865·6e74··.*[\s]+\!authent 
0003ed20:·6963·6174·652e·2a24·2720·2466·207c·2075··icate.*$'·$f·|·u 
0003ed30:·6e69·7120·290a·2020·6966·2021·2074·6573··niq·).··if·!·tes 
0003ed40:·7420·2d7a·2022·246d·6174·6368·696e·675f··t·-z·"$matching_ 
0003ed50:·6c69·7374·223b·2074·6865·6e0a·2020·2020··list";·then.···· 
0003ed60:·7768·696c·6520·4946·533d·2072·6561·6420··while·IFS=·read· 
0003ed70:·2d72·2065·6e74·7279·3b20·646f·0a20·2020··-r·entry;·do.··· 
0003ed80:·2020·2023·2063·6f6d·6d65·6e74·206f·7574·····#·comment·out 
0003ed90:·2022·2161·7574·6865·6e74·6963·6174·6522···"!authenticate" 
0003eda0:·206d·6174·6368·6573·2074·6f20·7072·6573···matches·to·pres 
0003edb0:·6572·7665·2075·7365·7220·6461·7461·0a20··erve·user·data.· 
0003edc0:·2020·2020·2073·6564·202d·6920·2273·2f5e·······sed·-i·"s/^ 
0003edd0:·247b·656e·7472·797d·242f·2320·2661·6d70··${entry}$/#·&amp 
0003ede0:·3b2f·6722·2024·660a·2020·2020·646f·6e65··;/g"·$f.····done 
0003edf0:·2026·6c74·3b26·6c74·3b26·6c74·3b20·2224···&lt;&lt;&lt;·"$ 
0003ee00:·6d61·7463·6869·6e67·5f6c·6973·7422·0a0a··matching_list".. 
0003ee10:·2020·2020·2f75·7372·2f73·6269·6e2f·7669······/usr/sbin/vi 
0003ee20:·7375·646f·202d·6366·2024·6620·2661·6d70··sudo·-cf·$f·&amp 
0003ee30:·3b26·6774·3b20·2f64·6576·2f6e·756c·6c20··;&gt;·/dev/null· 
0003ee40:·7c7c·2065·6368·6f20·2246·6169·6c20·746f··||·echo·"Fail·to 
0003ee50:·2076·616c·6964·6174·6520·2466·2077·6974···validate·$f·wit 
0003ee60:·6820·7669·7375·646f·220a·2020·6669·0a64··h·visudo".··fi.d 
0003ee70:·6f6e·650a·3c2f·636f·6465·3e3c·2f70·7265··one.</code></pre 
0003ee80:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003ee90:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003eea0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003eeb0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003eec0:·7267·6574·3d22·2369·646d·3139·3739·2220··rget="#idm1979"· 
0003eed0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003eee0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003eef0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003ef00:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003ef10:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003ef20:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003ef30:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe0003eb50:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe
0003ef40:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003eb60:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003ef50:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003eb70:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003ef60:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003eb80:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003ef70:·2220·6964·3d22·6964·6d31·3937·3922·3e3c··"·id="idm1979"><0003eb90:·2220·6964·3d22·6964·6d31·3937·3822·3e3c··"·id="idm1978"><
0003ef80:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003eba0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003ef90:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003ebb0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003efa0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003ebc0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003efb0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003ebd0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003efc0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003ebe0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003efd0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003ebf0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003efe0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003ec00:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003eff0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003ec10:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003f000:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003ec20:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003f010:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo0003ec30:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
0003f020:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false0003ec40:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
0003f030:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003ec50:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003f040:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>0003ec60:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
0003f050:·3c74·643e·7265·7374·7269·6374·3c2f·7464··<td>restrict</td0003ec70:·3c74·643e·7265·7374·7269·6374·3c2f·7464··<td>restrict</td
0003f060:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p0003ec80:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
0003f070:·7265·3e3c·636f·6465·3e2d·206e·616d·653a··re><code>-·name:0003ec90:·7265·3e3c·636f·6465·3e2d·206e·616d·653a··re><code>-·name:
0003f080:·2046·696e·6420·2f65·7463·2f73·7564·6f65···Find·/etc/sudoe0003eca0:·2046·696e·6420·2f65·7463·2f73·7564·6f65···Find·/etc/sudoe
0003f090:·7273·2e64·2f20·6669·6c65·730a·2020·616e··rs.d/·files.··an0003ecb0:·7273·2e64·2f20·6669·6c65·730a·2020·616e··rs.d/·files.··an
0003f0a0:·7369·626c·652e·6275·696c·7469·6e2e·6669··sible.builtin.fi0003ecc0:·7369·626c·652e·6275·696c·7469·6e2e·6669··sible.builtin.fi
0003f0b0:·6e64·3a0a·2020·2020·7061·7468·733a·0a20··nd:.····paths:.·0003ecd0:·6e64·3a0a·2020·2020·7061·7468·733a·0a20··nd:.····paths:.·
0003f0c0:·2020·202d·202f·6574·632f·7375·646f·6572·····-·/etc/sudoer0003ece0:·2020·202d·202f·6574·632f·7375·646f·6572·····-·/etc/sudoer
0003f0d0:·732e·642f·0a20·2072·6567·6973·7465·723a··s.d/.··register:0003ecf0:·732e·642f·0a20·2072·6567·6973·7465·723a··s.d/.··register:
0003f0e0:·2073·7564·6f65·7273·0a20·2074·6167·733a···sudoers.··tags:0003ed00:·2073·7564·6f65·7273·0a20·2074·6167·733a···sudoers.··tags:
0003f0f0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-530003ed10:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
0003f100:·2d43·4d2d·3628·6129·0a20·202d·204e·4953··-CM-6(a).··-·NIS0003ed20:·2d43·4d2d·3628·6129·0a20·202d·204e·4953··-CM-6(a).··-·NIS
0003f110:·542d·3830·302d·3533·2d49·412d·3131·0a20··T-800-53-IA-11.·0003ed30:·542d·3830·302d·3533·2d49·412d·3131·0a20··T-800-53-IA-11.·
0003f120:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit0003ed40:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit
0003f130:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup0003ed50:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup
0003f140:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_0003ed60:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_
0003f150:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_0003ed70:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_
0003f160:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.··0003ed80:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.··
0003f170:·2d20·7265·7374·7269·6374·5f73·7472·6174··-·restrict_strat0003ed90:·2d20·7265·7374·7269·6374·5f73·7472·6174··-·restrict_strat
0003f180:·6567·790a·2020·2d20·7375·646f·5f72·656d··egy.··-·sudo_rem0003eda0:·6567·790a·2020·2d20·7375·646f·5f72·656d··egy.··-·sudo_rem
0003f190:·6f76·655f·6e6f·5f61·7574·6865·6e74·6963··ove_no_authentic0003edb0:·6f76·655f·6e6f·5f61·7574·6865·6e74·6963··ove_no_authentic
0003f1a0:·6174·650a·0a2d·206e·616d·653a·2052·656d··ate..-·name:·Rem0003edc0:·6174·650a·0a2d·206e·616d·653a·2052·656d··ate..-·name:·Rem
0003f1b0:·6f76·6520·6c69·6e65·7320·636f·6e74·6169··ove·lines·contai0003edd0:·6f76·6520·6c69·6e65·7320·636f·6e74·6169··ove·lines·contai
0003f1c0:·6e69·6e67·2021·6175·7468·656e·7469·6361··ning·!authentica0003ede0:·6e69·6e67·2021·6175·7468·656e·7469·6361··ning·!authentica
Max diff block lines reached; 991016/1010942 bytes (98.03%) of diff not shown.
124 KB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Restrictive·Level38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Restrictive·Level
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_restrictive39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_restrictive
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~
42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
43 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8443 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
48 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g48 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
49 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s49 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
50 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s50 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
51 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n51 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
Offset 234, 35 lines modifiedOffset 234, 14 lines modified
234 ···························1.7,·SR·1.8,·SR·1.9234 ···························1.7,·SR·1.8,·SR·1.9
235 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,235 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
236 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3236 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
237 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)237 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
238 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7238 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
239 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,239 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
240 ···························SRG-OS-000373-GPOS-00158240 ···························SRG-OS-000373-GPOS-00158
241 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
242 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
243 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
244 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
245 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
246 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
247 ··if·[·!·-e·"$f"·]·;·then 
248 ····continue 
249 ··fi 
250 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·) 
251 ··if·!·test·-z·"$matching_list";·then 
252 ····while·IFS=·read·-r·entry;·do 
253 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data 
254 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
255 ····done·<<<·"$matching_list" 
  
256 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
257 visudo" 
258 ··fi 
259 done 
260 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8241 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
261 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low242 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
262 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low243 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
263 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false244 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
264 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict245 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
265 -·name:·Find·/etc/sudoers.d/·files246 -·name:·Find·/etc/sudoers.d/·files
266 ··ansible.builtin.find:247 ··ansible.builtin.find:
Offset 293, 14 lines modifiedOffset 272, 35 lines modified
293 ··-·NIST-800-53-IA-11272 ··-·NIST-800-53-IA-11
294 ··-·low_complexity273 ··-·low_complexity
295 ··-·low_disruption274 ··-·low_disruption
296 ··-·medium_severity275 ··-·medium_severity
297 ··-·no_reboot_needed276 ··-·no_reboot_needed
298 ··-·restrict_strategy277 ··-·restrict_strategy
299 ··-·sudo_remove_no_authenticate278 ··-·sudo_remove_no_authenticate
 279 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 280 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 281 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 282 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 283 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 284 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do
 285 ··if·[·!·-e·"$f"·]·;·then
 286 ····continue
 287 ··fi
 288 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·)
 289 ··if·!·test·-z·"$matching_list";·then
 290 ····while·IFS=·read·-r·entry;·do
 291 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data
 292 ······sed·-i·"s/^${entry}$/#·&/g"·$f
 293 ····done·<<<·"$matching_list"
  
 294 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with
 295 visudo"
 296 ··fi
 297 done
300 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o298 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o
301 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*299 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
302 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using300 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using
303 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure301 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure
304 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any302 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any
305 sudo·configuration·snippets·in·/etc/sudoers.d/.303 sudo·configuration·snippets·in·/etc/sudoers.d/.
306 ············Without·re-authentication,·users·may·access·resources·or·perform304 ············Without·re-authentication,·users·may·access·resources·or·perform
Offset 321, 35 lines modifiedOffset 321, 14 lines modified
321 ···························1.7,·SR·1.8,·SR·1.9321 ···························1.7,·SR·1.8,·SR·1.9
322 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,322 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
323 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3323 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
324 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)324 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
325 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7325 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
326 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,326 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
327 ···························SRG-OS-000373-GPOS-00158327 ···························SRG-OS-000373-GPOS-00158
328 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
329 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
330 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
331 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
332 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
333 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
334 ··if·[·!·-e·"$f"·]·;·then 
335 ····continue 
336 ··fi 
337 ··matching_list=$(grep·-P·'^(?!#).*[\s]+NOPASSWD[\s]*\:.*$'·$f·|·uniq·) 
338 ··if·!·test·-z·"$matching_list";·then 
339 ····while·IFS=·read·-r·entry;·do 
340 ······#·comment·out·"NOPASSWD"·matches·to·preserve·user·data 
341 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
342 ····done·<<<·"$matching_list" 
  
343 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
344 visudo" 
345 ··fi 
346 done 
347 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8328 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
348 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low329 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
349 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low330 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
350 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false331 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
351 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict332 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
352 -·name:·Find·/etc/sudoers.d/·files333 -·name:·Find·/etc/sudoers.d/·files
353 ··ansible.builtin.find:334 ··ansible.builtin.find:
Offset 380, 14 lines modifiedOffset 359, 35 lines modified
380 ··-·NIST-800-53-IA-11359 ··-·NIST-800-53-IA-11
381 ··-·low_complexity360 ··-·low_complexity
382 ··-·low_disruption361 ··-·low_disruption
Max diff block lines reached; 120861/126603 bytes (95.46%) of diff not shown.
1.8 MB
./usr/share/doc/ssg-debderived/ssg-ubuntu1804-guide-cis.html
    
Offset 14282, 16 lines modifiedOffset 14282, 16 lines modified
00037c90:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><00037c90:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><
00037ca0:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio00037ca0:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio
00037cb0:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.700037cb0:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.7
00037cc0:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u00037cc0:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u
00037cd0:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr00037cd0:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr
00037ce0:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···00037ce0:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···
00037cf0:·2020·2020·2020·2020·2020·2020·2020·2020··················00037cf0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037d00:·2028·6173·206f·6620·3230·3236·2d30·312d···(as·of·2026-01-00037d00:·2028·6173·206f·6620·3230·3234·2d31·322d···(as·of·2024-12-
00037d10:·3038·290a·2020·2020·2020·2020·2020·2020··08).············00037d10:·3037·290a·2020·2020·2020·2020·2020·2020··07).············
00037d20:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></00037d20:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></
00037d30:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of00037d30:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of
00037d40:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o00037d40:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o
00037d50:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#00037d50:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#
00037d60:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro00037d60:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro
00037d70:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro00037d70:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro
00037d80:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste00037d80:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste
Offset 16680, 168 lines modifiedOffset 16680, 168 lines modified
00041270:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=00041270:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
00041280:·2223·6964·6d36·3836·3622·2074·6162·696e··"#idm6866"·tabin00041280:·2223·6964·6d36·3836·3622·2074·6162·696e··"#idm6866"·tabin
00041290:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu00041290:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
000412a0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan000412a0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
000412b0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl000412b0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
000412c0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r000412c0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
000412d0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"000412d0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
000412e0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She000412e0:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans
 000412f0:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...
 00041300:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 00041310:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 00041320:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 00041330:·2269·646d·3638·3636·223e·3c74·6162·6c65··"idm6866"><table
 00041340:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 00041350:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 00041360:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 00041370:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 00041380:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 00041390:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 000413a0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 000413b0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 000413c0:·3e6d·6564·6975·6d3c·2f74·643e·3c2f·7472··>medium</td></tr
 000413d0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 000413e0:·3c2f·7468·3e3c·7464·3e74·7275·653c·2f74··</th><td>true</t
 000413f0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 00041400:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 00041410:·3e64·6973·6162·6c65·3c2f·7464·3e3c·2f74··>disable</td></t
 00041420:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 00041430:·636f·6465·3e2d·206e·616d·653a·2045·6e73··code>-·name:·Ens
 00041440:·7572·6520·6b65·726e·656c·206d·6f64·756c··ure·kernel·modul
 00041450:·6520·2772·6473·2720·6973·2064·6973·6162··e·'rds'·is·disab
 00041460:·6c65·640a·2020·6c69·6e65·696e·6669·6c65··led.··lineinfile
 00041470:·3a0a·2020·2020·6372·6561·7465·3a20·7472··:.····create:·tr
 00041480:·7565·0a20·2020·2064·6573·743a·202f·6574··ue.····dest:·/et
 00041490:·632f·6d6f·6470·726f·6265·2e64·2f72·6473··c/modprobe.d/rds
 000414a0:·2e63·6f6e·660a·2020·2020·7265·6765·7870··.conf.····regexp
000412f0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
00041300:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
00041310:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
00041320:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
00041330:·6d36·3836·3622·3e3c·7461·626c·6520·636c··m6866"><table·cl 
00041340:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
00041350:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
00041360:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
00041370:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
00041380:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
00041390:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
000413a0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
000413b0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6d65··tion:</th><td>me 
000413c0:·6469·756d·3c2f·7464·3e3c·2f74·723e·3c74··dium</td></tr><t 
000413d0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
000413e0:·683e·3c74·643e·7472·7565·3c2f·7464·3e3c··h><td>true</td>< 
000413f0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
00041400:·7465·6779·3a3c·2f74·683e·3c74·643e·6469··tegy:</th><td>di 
00041410:·7361·626c·653c·2f74·643e·3c2f·7472·3e3c··sable</td></tr>< 
00041420:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
00041430:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation· 
00041440:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on 
00041450:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl 
00041460:·6174·666f·726d·730a·6966·205b·2021·202d··atforms.if·[·!·- 
00041470:·6620·2f2e·646f·636b·6572·656e·7620·5d20··f·/.dockerenv·]· 
00041480:·2661·6d70·3b26·616d·703b·205b·2021·202d··&amp;&amp;·[·!·- 
00041490:·6620·2f72·756e·2f2e·636f·6e74·6169·6e65··f·/run/.containe 
000414a0:·7265·6e76·205d·3b20·7468·656e·0a0a·6966··renv·];·then..if 
000414b0:·204c·435f·414c·4c3d·4320·6772·6570·202d···LC_ALL=C·grep·- 
000414c0:·7120·2d6d·2031·2022·5e69·6e73·7461·6c6c··q·-m·1·"^install 
000414d0:·2072·6473·2220·2f65·7463·2f6d·6f64·7072···rds"·/etc/modpr 
000414e0:·6f62·652e·642f·7264·732e·636f·6e66·203b··obe.d/rds.conf·; 
000414f0:·2074·6865·6e0a·090a·0973·6564·202d·6920···then....sed·-i· 
00041500:·2773·235e·696e·7374·616c·6c20·7264·732e··'s#^install·rds. 
00041510:·2a23·696e·7374·616c·6c20·7264·7320·2f62··*#install·rds·/b 
00041520:·696e·2f66·616c·7365·2367·2720·2f65·7463··in/false#g'·/etc 
00041530:·2f6d·6f64·7072·6f62·652e·642f·7264·732e··/modprobe.d/rds. 
00041540:·636f·6e66·0a65·6c73·650a·0965·6368·6f20··conf.else..echo· 
00041550:·2d65·2022·5c6e·2320·4469·7361·626c·6520··-e·"\n#·Disable· 
00041560:·7065·7220·7365·6375·7269·7479·2072·6571··per·security·req 
00041570:·7569·7265·6d65·6e74·7322·2026·6774·3b26··uirements"·&gt;& 
00041580:·6774·3b20·2f65·7463·2f6d·6f64·7072·6f62··gt;·/etc/modprob 
00041590:·652e·642f·7264·732e·636f·6e66·0a09·6563··e.d/rds.conf..ec 
000415a0:·686f·2022·696e·7374·616c·6c20·7264·7320··ho·"install·rds·000414b0:·3a20·696e·7374·616c·6c5c·732b·7264·730a··:·install\s+rds.
000415b0:·2f62·696e·2f66·616c·7365·2220·2667·743b··/bin/false"·&gt; 
000415c0:·2667·743b·202f·6574·632f·6d6f·6470·726f··&gt;·/etc/modpro 
000415d0:·6265·2e64·2f72·6473·2e63·6f6e·660a·6669··be.d/rds.conf.fi 
000415e0:·0a0a·6966·2021·204c·435f·414c·4c3d·4320··..if·!·LC_ALL=C· 
000415f0:·6772·6570·202d·7120·2d6d·2031·2022·5e62··grep·-q·-m·1·"^b 
00041600:·6c61·636b·6c69·7374·2072·6473·2422·202f··lacklist·rds$"·/000414c0:·2020·2020·6c69·6e65·3a20·696e·7374·616c······line:·instal
 000414d0:·6c20·7264·7320·2f62·696e·2f66·616c·7365··l·rds·/bin/false
 000414e0:·0a20·2077·6865·6e3a·2061·6e73·6962·6c65··.··when:·ansible
 000414f0:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_
 00041500:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do
 00041510:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o
 00041520:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman"
 00041530:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].·
 00041540:·2074·6167·733a·0a20·202d·204e·4953·542d···tags:.··-·NIST-
 00041550:·3830·302d·3533·2d43·4d2d·3628·6129·0a20··800-53-CM-6(a).·
 00041560:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C
 00041570:·4d2d·3728·6129·0a20·202d·204e·4953·542d··M-7(a).··-·NIST-
 00041580:·3830·302d·3533·2d43·4d2d·3728·6229·0a20··800-53-CM-7(b).·
 00041590:·202d·2064·6973·6162·6c65·5f73·7472·6174···-·disable_strat
 000415a0:·6567·790a·2020·2d20·6b65·726e·656c·5f6d··egy.··-·kernel_m
 000415b0:·6f64·756c·655f·7264·735f·6469·7361·626c··odule_rds_disabl
 000415c0:·6564·0a20·202d·206c·6f77·5f63·6f6d·706c··ed.··-·low_compl
 000415d0:·6578·6974·790a·2020·2d20·6c6f·775f·7365··exity.··-·low_se
 000415e0:·7665·7269·7479·0a20·202d·206d·6564·6975··verity.··-·mediu
 000415f0:·6d5f·6469·7372·7570·7469·6f6e·0a20·202d··m_disruption.··-
 00041600:·2072·6562·6f6f·745f·7265·7175·6972·6564···reboot_required
 00041610:·0a0a·2d20·6e61·6d65·3a20·456e·7375·7265··..-·name:·Ensure
 00041620:·206b·6572·6e65·6c20·6d6f·6475·6c65·2027···kernel·module·'
 00041630:·7264·7327·2069·7320·626c·6163·6b6c·6973··rds'·is·blacklis
 00041640:·7465·640a·2020·6c69·6e65·696e·6669·6c65··ted.··lineinfile
Max diff block lines reached; 1645564/1668664 bytes (98.62%) of diff not shown.
209 KB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Ubuntu·18.04·LTS·Benchmark38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Ubuntu·18.04·LTS·Benchmark
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~
42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
43 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8443 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
48 ·········2.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s48 ·········2.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
49 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s49 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
50 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s50 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
51 ·········1.·_\x8S_\x8S_\x8H_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r51 ·········1.·_\x8S_\x8S_\x8H_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r
Offset 302, 37 lines modifiedOffset 302, 14 lines modified
302 ···························SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR302 ···························SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR
303 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR303 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR
304 ···························2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·7.6304 ···························2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·7.6
305 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,305 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,
306 ···························A.9.1.2306 ···························A.9.1.2
307 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a)307 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a)
308 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3308 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3
309 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
310 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
311 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
312 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
313 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
314 #·Remediation·is·applicable·only·in·certain·platforms 
315 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
316 if·LC_ALL=C·grep·-q·-m·1·"^install·rds"·/etc/modprobe.d/rds.conf·;·then 
317 »        
318 »       sed·-i·'s#^install·rds.*#install·rds·/bin/false#g'·/etc/modprobe.d/rds.conf 
319 else 
320 »       echo·-e·"\n#·Disable·per·security·requirements"·>>·/etc/modprobe.d/rds.conf 
321 »       echo·"install·rds·/bin/false"·>>·/etc/modprobe.d/rds.conf 
322 fi 
  
323 if·!·LC_ALL=C·grep·-q·-m·1·"^blacklist·rds$"·/etc/modprobe.d/rds.conf·;·then 
324 »       echo·"blacklist·rds"·>>·/etc/modprobe.d/rds.conf 
325 fi 
  
326 else 
327 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
328 fi 
329 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8309 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
330 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low310 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
331 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium311 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
332 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true312 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
333 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable313 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
334 -·name:·Ensure·kernel·module·'rds'·is·disabled314 -·name:·Ensure·kernel·module·'rds'·is·disabled
335 ··lineinfile:315 ··lineinfile:
Offset 367, 14 lines modifiedOffset 344, 37 lines modified
367 ··-·NIST-800-53-CM-7(b)344 ··-·NIST-800-53-CM-7(b)
368 ··-·disable_strategy345 ··-·disable_strategy
369 ··-·kernel_module_rds_disabled346 ··-·kernel_module_rds_disabled
370 ··-·low_complexity347 ··-·low_complexity
371 ··-·low_severity348 ··-·low_severity
372 ··-·medium_disruption349 ··-·medium_disruption
373 ··-·reboot_required350 ··-·reboot_required
 351 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 352 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 353 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 354 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 355 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
 356 #·Remediation·is·applicable·only·in·certain·platforms
 357 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 358 if·LC_ALL=C·grep·-q·-m·1·"^install·rds"·/etc/modprobe.d/rds.conf·;·then
 359 »       
 360 »       sed·-i·'s#^install·rds.*#install·rds·/bin/false#g'·/etc/modprobe.d/rds.conf
 361 else
 362 »       echo·-e·"\n#·Disable·per·security·requirements"·>>·/etc/modprobe.d/rds.conf
 363 »       echo·"install·rds·/bin/false"·>>·/etc/modprobe.d/rds.conf
 364 fi
  
 365 if·!·LC_ALL=C·grep·-q·-m·1·"^blacklist·rds$"·/etc/modprobe.d/rds.conf·;·then
 366 »       echo·"blacklist·rds"·>>·/etc/modprobe.d/rds.conf
 367 fi
  
 368 else
 369 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 370 fi
374 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8is\x8sa\x8ab\x8bl\x8le\x8e·T\x8TI\x8IP\x8PC\x8C·S\x8Su\x8up\x8pp\x8po\x8or\x8rt\x8t·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*371 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8is\x8sa\x8ab\x8bl\x8le\x8e·T\x8TI\x8IP\x8PC\x8C·S\x8Su\x8up\x8pp\x8po\x8or\x8rt\x8t·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
375 The·Transparent·Inter-Process·Communication·(TIPC)·protocol·is·designed·to·provide372 The·Transparent·Inter-Process·Communication·(TIPC)·protocol·is·designed·to·provide
376 communications·between·nodes·in·a·cluster.·To·configure·the·system·to·prevent·the·tipc373 communications·between·nodes·in·a·cluster.·To·configure·the·system·to·prevent·the·tipc
377 kernel·module·from·being·loaded,·add·the·following·line·to·the·file·/etc/modprobe.d/374 kernel·module·from·being·loaded,·add·the·following·line·to·the·file·/etc/modprobe.d/
378 tipc.conf:375 tipc.conf:
379 install·tipc·/bin/false376 install·tipc·/bin/false
380 Warning: ·This·configuration·baseline·was·created·to·deploy·the·base·operating·system·for377 Warning: ·This·configuration·baseline·was·created·to·deploy·the·base·operating·system·for
Offset 399, 37 lines modifiedOffset 399, 14 lines modified
399 ···························2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·7.6399 ···························2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·7.6
400 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,400 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,
401 ···························A.9.1.2401 ···························A.9.1.2
402 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a)402 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a)
403 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3403 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3
404 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1404 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1
405 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000095-GPOS-00049405 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000095-GPOS-00049
406 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
407 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
408 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
409 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
410 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
411 #·Remediation·is·applicable·only·in·certain·platforms 
412 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
413 if·LC_ALL=C·grep·-q·-m·1·"^install·tipc"·/etc/modprobe.d/tipc.conf·;·then 
414 »        
415 »       sed·-i·'s#^install·tipc.*#install·tipc·/bin/false#g'·/etc/modprobe.d/tipc.conf 
416 else 
417 »       echo·-e·"\n#·Disable·per·security·requirements"·>>·/etc/modprobe.d/tipc.conf 
418 »       echo·"install·tipc·/bin/false"·>>·/etc/modprobe.d/tipc.conf 
419 fi 
  
420 if·!·LC_ALL=C·grep·-q·-m·1·"^blacklist·tipc$"·/etc/modprobe.d/tipc.conf·;·then 
421 »       echo·"blacklist·tipc"·>>·/etc/modprobe.d/tipc.conf 
422 fi 
  
423 else 
424 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
425 fi 
426 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8406 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
427 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low407 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
428 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium408 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
429 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true409 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
430 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable410 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
Max diff block lines reached; 207709/213771 bytes (97.16%) of diff not shown.
1.1 MB
./usr/share/doc/ssg-debderived/ssg-ubuntu1804-guide-standard.html
    
Offset 14288, 15 lines modifiedOffset 14288, 15 lines modified
00037cf0:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur00037cf0:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur
00037d00:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s00037d00:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s
00037d10:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st00037d10:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st
00037d20:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li00037d20:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li
00037d30:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</00037d30:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</
00037d40:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········00037d40:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········
00037d50:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·00037d50:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·
00037d60:·6f66·2032·3032·362d·3031·2d30·3829·0a20··of·2026-01-08).·00037d60:·6f66·2032·3032·342d·3132·2d30·3729·0a20··of·2024-12-07).·
00037d70:·2020·2020·2020·2020·2020·2020·2020·203c·················<00037d70:·2020·2020·2020·2020·2020·2020·2020·203c·················<
00037d80:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><00037d80:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><
00037d90:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont00037d90:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont
00037da0:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li00037da0:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li
00037db0:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf00037db0:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf
00037dc0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.00037dc0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.
00037dd0:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy00037dd0:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy
Offset 16256, 741 lines modifiedOffset 16256, 741 lines modified
0003f7f0:·2d74·6172·6765·743d·2223·6964·6d35·3137··-target="#idm5170003f7f0:·2d74·6172·6765·743d·2223·6964·6d35·3137··-target="#idm517
0003f800:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·0003f800:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·
0003f810:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003f810:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003f820:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003f820:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003f830:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003f830:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003f840:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003f840:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
Diff chunk too large, falling back to line-by-line diff (727 lines added, 727 lines removed)
0003f850:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003f850:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003f860:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip0003f860:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni
0003f870:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003f870:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003f880:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003f880:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003f890:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003f890:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003f8a0:·2220·6964·3d22·6964·6d35·3137·3222·3e3c··"·id="idm5172"><0003f8a0:·7073·6522·2069·643d·2269·646d·3531·3732··pse"·id="idm5172
0003f8b0:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme0003f8b0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003f8c0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli0003f8c0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003f8d0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce0003f8d0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003f8e0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.0003f8e0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003f8f0:·6966·205b·2021·202d·6620·2f2e·646f·636b··if·[·!·-f·/.dock0003f8f0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003f900:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am0003f900:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003f910:·703b·205b·2021·202d·6620·2f72·756e·2f2e··p;·[·!·-f·/run/.0003f910:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003f920:·636f·6e74·6169·6e65·7265·6e76·205d·3b20··containerenv·];·0003f920:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003f930:·7468·656e·0a0a·2320·4c69·7374·206f·6620··then..#·List·of·0003f930:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<
0003f940:·6c6f·6720·6669·6c65·2070·6174·6873·2074··log·file·paths·t0003f940:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003f950:·6f20·6265·2069·6e73·7065·6374·6564·2066··o·be·inspected·f0003f950:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003f960:·6f72·2063·6f72·7265·6374·2070·6572·6d69··or·correct·permi0003f960:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003f970:·7373·696f·6e73·0a23·202a·2050·7269·6d61··ssions.#·*·Prima0003f970:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003f980:·7269·6c79·2069·6e73·7065·6374·206c·6f67··rily·inspect·log0003f980:·3a3c·2f74·683e·3c74·643e·636f·6e66·6967··:</th><td>config
0003f990:·2066·696c·6520·7061·7468·7320·6c69·7374···file·paths·list0003f990:·7572·653c·2f74·643e·3c2f·7472·3e3c·2f74··ure</td></tr></t
0003f9a0:·6564·2069·6e20·2f65·7463·2f72·7379·736c··ed·in·/etc/rsysl0003f9a0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
0003f9b0:·6f67·2e63·6f6e·660a·5253·5953·4c4f·475f··og.conf.RSYSLOG_0003f9b0:·2d20·6e61·6d65·3a20·456e·7375·7265·204c··-·name:·Ensure·L
0003f9c0:·4554·435f·434f·4e46·4947·3d22·2f65·7463··ETC_CONFIG="/etc0003f9c0:·6f67·2046·696c·6573·2041·7265·204f·776e··og·Files·Are·Own
0003f9d0:·2f72·7379·736c·6f67·2e63·6f6e·6622·0a23··/rsyslog.conf".#0003f9d0:·6564·2042·7920·4170·7072·6f70·7269·6174··ed·By·Appropriat
0003f9e0:·202a·2041·6e64·2061·6c73·6f20·7468·6520···*·And·also·the·0003f9e0:·6520·4772·6f75·7020·2d20·5365·7420·7273··e·Group·-·Set·rs
0003f9f0:·6c6f·6720·6669·6c65·2070·6174·6873·206c··log·file·paths·l0003f9f0:·7973·6c6f·6720·6c6f·6766·696c·6520·636f··yslog·logfile·co
0003fa00:·6973·7465·6420·6166·7465·7220·7273·7973··isted·after·rsys0003fa00:·6e66·6967·7572·6174·696f·6e0a·2020·2020··nfiguration.····
0003fa10:·6c6f·6727·7320·2449·6e63·6c75·6465·436f··log's·$IncludeCo0003fa10:·6661·6374·730a·2020·616e·7369·626c·652e··facts.··ansible.
0003fa20:·6e66·6967·2064·6972·6563·7469·7665·0a23··nfig·directive.#0003fa20:·6275·696c·7469·6e2e·7365·745f·6661·6374··builtin.set_fact
0003fa30:·2020·2028·7374·6f72·6520·7468·6520·7265·····(store·the·re0003fa30:·3a0a·2020·2020·7273·7973·6c6f·675f·6574··:.····rsyslog_et
0003fa40:·7375·6c74·2069·6e74·6f20·6172·7261·7920··sult·into·array·0003fa40:·635f·636f·6e66·6967·3a20·2f65·7463·2f72··c_config:·/etc/r
0003fa50:·666f·7220·7468·6520·6361·7365·2074·6865··for·the·case·the0003fa50:·7379·736c·6f67·2e63·6f6e·660a·2020·7768··syslog.conf.··wh
0003fa60:·7265·2773·2073·6865·6c6c·2067·6c6f·6220··re's·shell·glob·0003fa60:·656e·3a20·616e·7369·626c·655f·7669·7274··en:·ansible_virt
0003fa70:·7573·6564·2061·7320·7661·6c75·6520·6f66··used·as·value·of0003fa70:·7561·6c69·7a61·7469·6f6e·5f74·7970·6520··ualization_type·
0003fa80:·2049·6e63·6c75·6465·436f·6e66·6967·290a···IncludeConfig).0003fa80:·6e6f·7420·696e·205b·2264·6f63·6b65·7222··not·in·["docker"
0003fa90:·7265·6164·6172·7261·7920·2d74·204f·4c44··readarray·-t·OLD0003fa90:·2c20·226c·7863·222c·2022·6f70·656e·767a··,·"lxc",·"openvz
0003faa0:·5f49·4e43·2026·6c74·3b20·266c·743b·2867··_INC·&lt;·&lt;(g0003faa0:·222c·2022·706f·646d·616e·222c·2022·636f··",·"podman",·"co
0003fab0:·7265·7020·2d65·2022·5c24·496e·636c·7564··rep·-e·"\$Includ0003fab0:·6e74·6169·6e65·7222·5d0a·2020·7461·6773··ntainer"].··tags
0003fac0:·6543·6f6e·6669·675b·5b3a·7370·6163·653a··eConfig[[:space:0003fac0:·3a0a·2020·2d20·4e49·5354·2d38·3030·2d35··:.··-·NIST-800-5
0003fad0:·5d5d·5c2b·5b5e·5b3a·7370·6163·653a·5d3b··]]\+[^[:space:];0003fad0:·332d·4143·2d36·2831·290a·2020·2d20·4e49··3-AC-6(1).··-·NI
0003fae0:·5d5c·2b22·202f·6574·632f·7273·7973·6c6f··]\+"·/etc/rsyslo0003fae0:·5354·2d38·3030·2d35·332d·434d·2d36·2861··ST-800-53-CM-6(a
0003faf0:·672e·636f·6e66·207c·2063·7574·202d·6420··g.conf·|·cut·-d·0003faf0:·290a·2020·2d20·5043·492d·4453·532d·5265··).··-·PCI-DSS-Re
0003fb00:·2720·2720·2d66·2032·290a·7265·6164·6172··'·'·-f·2).readar0003fb00:·712d·3130·2e35·2e31·0a20·202d·2050·4349··q-10.5.1.··-·PCI
0003fb10:·7261·7920·2d74·2052·5359·534c·4f47·5f49··ray·-t·RSYSLOG_I0003fb10:·2d44·5353·2d52·6571·2d31·302e·352e·320a··-DSS-Req-10.5.2.
0003fb20:·4e43·4c55·4445·5f43·4f4e·4649·4720·266c··NCLUDE_CONFIG·&l0003fb20:·2020·2d20·5043·492d·4453·5376·342d·3130····-·PCI-DSSv4-10
0003fb30:·743b·2026·6c74·3b28·666f·7220·494e·4350··t;·&lt;(for·INCP0003fb30:·2e33·2e32·0a20·202d·2063·6f6e·6669·6775··.3.2.··-·configu
0003fb40:·4154·4820·696e·2022·247b·4f4c·445f·494e··ATH·in·"${OLD_IN0003fb40:·7265·5f73·7472·6174·6567·790a·2020·2d20··re_strategy.··-·
0003fb50:·435b·405d·7d22·3b20·646f·2065·7661·6c20··C[@]}";·do·eval·0003fb50:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.·
0003fb60:·7072·696e·7466·2027·2573·5c5c·6e27·2022··printf·'%s\\n'·"0003fb60:·202d·206d·6564·6975·6d5f·6469·7372·7570···-·medium_disrup
0003fb70:·247b·494e·4350·4154·487d·223b·2064·6f6e··${INCPATH}";·don0003fb70:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_
0003fb80:·6529·0a72·6561·6461·7272·6179·202d·7420··e).readarray·-t·0003fb80:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_
0003fb90:·4e45·575f·494e·4320·266c·743b·2026·6c74··NEW_INC·&lt;·&lt0003fb90:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.··
0003fba0:·3b28·7365·6420·2d6e·2027·2f5e·5c73·2a69··;(sed·-n·'/^\s*i0003fba0:·2d20·7273·7973·6c6f·675f·6669·6c65·735f··-·rsyslog_files_
0003fbb0:·6e63·6c75·6465·282f·2c2f·292f·4970·2720··nclude(/,/)/Ip'·0003fbb0:·6772·6f75·706f·776e·6572·7368·6970·0a0a··groupownership..
0003fbc0:·2f65·7463·2f72·7379·736c·6f67·2e63·6f6e··/etc/rsyslog.con0003fbc0:·2d20·6e61·6d65·3a20·456e·7375·7265·204c··-·name:·Ensure·L
0003fbd0:·6620·7c20·7365·6420·2d6e·2027·7340·2e2a··f·|·sed·-n·'s@.*0003fbd0:·6f67·2046·696c·6573·2041·7265·204f·776e··og·Files·Are·Own
0003fbe0:·6669·6c65·5c73·2a3d·5c73·2a22·5c28·5b2f··file\s*=\s*"\([/0003fbe0:·6564·2042·7920·4170·7072·6f70·7269·6174··ed·By·Appropriat
0003fbf0:·5b3a·616c·6e75·6d3a·5d5b·3a70·756e·6374··[:alnum:][:punct0003fbf0:·6520·4772·6f75·7020·2d20·4765·7420·496e··e·Group·-·Get·In
0003fc00:·3a5d·5d2a·5c29·222e·2a40·5c31·4049·7027··:]]*\)".*@\1@Ip'0003fc00:·636c·7564·6543·6f6e·6669·6720·6469·7265··cludeConfig·dire
0003fc10:·290a·7265·6164·6172·7261·7920·2d74·2052··).readarray·-t·R0003fc10:·6374·6976·650a·2020·616e·7369·626c·652e··ctive.··ansible.
0003fc20:·5359·534c·4f47·5f49·4e43·4c55·4445·2026··SYSLOG_INCLUDE·&0003fc20:·6275·696c·7469·6e2e·7368·656c·6c3a·207c··builtin.shell:·|
0003fc30:·6c74·3b20·266c·743b·2866·6f72·2049·4e43··lt;·&lt;(for·INC0003fc30:·0a20·2020·2073·6574·202d·6f20·7069·7065··.····set·-o·pipe
0003fc40:·5041·5448·2069·6e20·2224·7b4e·4557·5f49··PATH·in·"${NEW_I0003fc40:·6661·696c·0a20·2020·2067·7265·7020·2d65··fail.····grep·-e
0003fc50:·4e43·5b40·5d7d·223b·2064·6f20·6576·616c··NC[@]}";·do·eval0003fc50:·2027·2449·6e63·6c75·6465·436f·6e66·6967···'$IncludeConfig
0003fc60:·2070·7269·6e74·6620·2725·735c·5c6e·2720···printf·'%s\\n'·0003fc60:·2720·7b7b·2072·7379·736c·6f67·5f65·7463··'·{{·rsyslog_etc
0003fc70:·2224·7b49·4e43·5041·5448·7d22·3b20·646f··"${INCPATH}";·do0003fc70:·5f63·6f6e·6669·6720·7d7d·207c·2063·7574··_config·}}·|·cut
0003fc80:·6e65·290a·0a23·2044·6563·6c61·7265·2061··ne)..#·Declare·a0003fc80:·202d·6420·2720·2720·2d66·2032·207c·7c20···-d·'·'·-f·2·||·
0003fc90:·6e20·6172·7261·7920·746f·2068·6f6c·6420··n·array·to·hold·0003fc90:·7472·7565·0a20·2072·6567·6973·7465·723a··true.··register:
0003fca0:·7468·6520·6669·6e61·6c20·6c69·7374·206f··the·final·list·o0003fca0:·2072·7379·736c·6f67·5f6f·6c64·5f69·6e63···rsyslog_old_inc
0003fcb0:·6620·6469·6666·6572·656e·7420·6c6f·6720··f·different·log·0003fcb0:·0a20·2063·6861·6e67·6564·5f77·6865·6e3a··.··changed_when:
0003fcc0:·6669·6c65·2070·6174·6873·0a64·6563·6c61··file·paths.decla0003fcc0:·2066·616c·7365·0a20·2077·6865·6e3a·2061···false.··when:·a
0003fcd0:·7265·202d·6120·4c4f·475f·4649·4c45·5f50··re·-a·LOG_FILE_P0003fcd0:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz
0003fce0:·4154·4853·0a0a·2320·4172·7261·7920·746f··ATHS..#·Array·to0003fce0:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i
0003fcf0:·2068·6f6c·6420·616c·6c20·7273·7973·6c6f···hold·all·rsyslo0003fcf0:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx
0003fd00:·6720·636f·6e66·6967·2065·6e74·7269·6573··g·config·entries0003fd00:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p
0003fd10:·0a52·5359·534c·4f47·5f43·4f4e·4649·4753··.RSYSLOG_CONFIGS0003fd10:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain
0003fd20:·3d28·290a·5253·5953·4c4f·475f·434f·4e46··=().RSYSLOG_CONF0003fd20:·6572·225d·0a20·2074·6167·733a·0a20·202d··er"].··tags:.··-
0003fd30:·4947·533d·2822·247b·5253·5953·4c4f·475f··IGS=("${RSYSLOG_0003fd30:·204e·4953·542d·3830·302d·3533·2d41·432d···NIST-800-53-AC-
0003fd40:·4554·435f·434f·4e46·4947·7d22·2022·247b··ETC_CONFIG}"·"${0003fd40:·3628·3129·0a20·202d·204e·4953·542d·3830··6(1).··-·NIST-80
0003fd50:·5253·5953·4c4f·475f·494e·434c·5544·455f··RSYSLOG_INCLUDE_0003fd50:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··-
0003fd60:·434f·4e46·4947·5b40·5d7d·2220·2224·7b52··CONFIG[@]}"·"${R0003fd60:·2050·4349·2d44·5353·2d52·6571·2d31·302e···PCI-DSS-Req-10.
0003fd70:·5359·534c·4f47·5f49·4e43·4c55·4445·5b40··SYSLOG_INCLUDE[@0003fd70:·352e·310a·2020·2d20·5043·492d·4453·532d··5.1.··-·PCI-DSS-
0003fd80:·5d7d·2229·0a0a·2320·4765·7420·6675·6c6c··]}")..#·Get·full0003fd80:·5265·712d·3130·2e35·2e32·0a20·202d·2050··Req-10.5.2.··-·P
0003fd90:·206c·6973·7420·6f66·2066·696c·6573·2074···list·of·files·t0003fd90:·4349·2d44·5353·7634·2d31·302e·332e·320a··CI-DSSv4-10.3.2.
0003fda0:·6f20·6265·2063·6865·636b·6564·0a23·2052··o·be·checked.#·R0003fda0:·2020·2d20·636f·6e66·6967·7572·655f·7374····-·configure_st
0003fdb0:·5359·534c·4f47·5f43·4f4e·4649·4753·206d··SYSLOG_CONFIGS·m0003fdb0:·7261·7465·6779·0a20·202d·206c·6f77·5f63··rategy.··-·low_c
0003fdc0:·6179·2063·6f6e·7461·696e·2067·6c6f·6273··ay·contain·globs0003fdc0:·6f6d·706c·6578·6974·790a·2020·2d20·6d65··omplexity.··-·me
0003fdd0:·2073·7563·6820·6173·0a23·202f·6574·632f···such·as.#·/etc/0003fdd0:·6469·756d·5f64·6973·7275·7074·696f·6e0a··dium_disruption.
0003fde0:·7273·7973·6c6f·672e·642f·2a2e·636f·6e66··rsyslog.d/*.conf0003fde0:·2020·2d20·6d65·6469·756d·5f73·6576·6572····-·medium_sever
0003fdf0:·202f·6574·632f·7273·7973·6c6f·672e·642f···/etc/rsyslog.d/0003fdf0:·6974·790a·2020·2d20·6e6f·5f72·6562·6f6f··ity.··-·no_reboo
0003fe00:·2a2e·6672·756c·650a·2320·536f·2c20·6c6f··*.frule.#·So,·lo0003fe00:·745f·6e65·6564·6564·0a20·202d·2072·7379··t_needed.··-·rsy
0003fe10:·6f70·206f·7665·7220·7468·6520·656e·7472··op·over·the·entr0003fe10:·736c·6f67·5f66·696c·6573·5f67·726f·7570··slog_files_group
0003fe20:·6965·7320·696e·2052·5359·534c·4f47·5f43··ies·in·RSYSLOG_C0003fe20:·6f77·6e65·7273·6869·700a·0a2d·206e·616d··ownership..-·nam
0003fe30:·4f4e·4649·4753·2061·6e64·2075·7365·2066··ONFIGS·and·use·f0003fe30:·653a·2045·6e73·7572·6520·4c6f·6720·4669··e:·Ensure·Log·Fi
0003fe40:·696e·6420·746f·2067·6574·2074·6865·206c··ind·to·get·the·l0003fe40:·6c65·7320·4172·6520·4f77·6e65·6420·4279··les·Are·Owned·By
0003fe50:·6973·7420·6f66·2069·6e63·6c75·6465·6420··ist·of·included·0003fe50:·2041·7070·726f·7072·6961·7465·2047·726f···Appropriate·Gro
0003fe60:·6669·6c65·732e·0a52·5359·534c·4f47·5f43··files..RSYSLOG_C0003fe60:·7570·202d·2047·6574·2069·6e63·6c75·6465··up·-·Get·include
0003fe70:·4f4e·4649·475f·4649·4c45·533d·2829·0a66··ONFIG_FILES=().f0003fe70:·2066·696c·6573·2064·6972·6563·7469·7665···files·directive
0003fe80:·6f72·2045·4e54·5259·2069·6e20·2224·7b52··or·ENTRY·in·"${R0003fe80:·730a·2020·616e·7369·626c·652e·6275·696c··s.··ansible.buil
0003fe90:·5359·534c·4f47·5f43·4f4e·4649·4753·5b40··SYSLOG_CONFIGS[@0003fe90:·7469·6e2e·7368·656c·6c3a·207c·0a20·2020··tin.shell:·|.···
0003fea0:·5d7d·220a·646f·0a09·2320·4966·2064·6972··]}".do..#·If·dir0003fea0:·2073·6574·202d·6f20·7069·7065·6661·696c···set·-o·pipefail
0003feb0:·6563·746f·7279·2c20·7273·7973·6c6f·6720··ectory,·rsyslog·0003feb0:·0a20·2020·2061·776b·2027·2f29·2f7b·663d··.····awk·'/)/{f=
0003fec0:·7769·6c6c·2073·6561·7263·6820·666f·7220··will·search·for·0003fec0:·307d·202f·696e·636c·7564·655c·282f·7b66··0}·/include\(/{f
Max diff block lines reached; 926115/1028151 bytes (90.08%) of diff not shown.
125 KB
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Ubuntu·18.0439 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Ubuntu·18.04
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard
41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
42 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~42 ····*·cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~
43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
44 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8444 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
49 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g49 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
50 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s50 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
51 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s51 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
52 ·········1.·_\x8C_\x8r_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8t_\x8·_\x8D_\x8a_\x8e_\x8m_\x8o_\x8n_\x8s52 ·········1.·_\x8C_\x8r_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8t_\x8·_\x8D_\x8a_\x8e_\x8m_\x8o_\x8n_\x8s
Offset 264, 139 lines modifiedOffset 264, 14 lines modified
264 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-007-3·R2.1,·CIP-007-3·R2.2,·CIP-007-3·R2.3,·CIP-264 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-007-3·R2.1,·CIP-007-3·R2.2,·CIP-007-3·R2.3,·CIP-
265 ···························007-3·R5.1,·CIP-007-3·R5.1.1,·CIP-007-3·R5.1.2265 ···························007-3·R5.1,·CIP-007-3·R5.1.1,·CIP-007-3·R5.1.2
266 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)266 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)
267 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5267 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5
268 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.5.1,·Req-10.5.2268 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.5.1,·Req-10.5.2
269 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71269 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71
270 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.3.2270 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.3.2
271 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
272 #·Remediation·is·applicable·only·in·certain·platforms 
273 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
274 #·List·of·log·file·paths·to·be·inspected·for·correct·permissions 
275 #·*·Primarily·inspect·log·file·paths·listed·in·/etc/rsyslog.conf 
276 RSYSLOG_ETC_CONFIG="/etc/rsyslog.conf" 
277 #·*·And·also·the·log·file·paths·listed·after·rsyslog's·$IncludeConfig·directive 
278 #···(store·the·result·into·array·for·the·case·there's·shell·glob·used·as·value 
279 of·IncludeConfig) 
280 readarray·-t·OLD_INC·<·<(grep·-e·"\$IncludeConfig[[:space:]]\+[^[:space:];]\+" 
281 /etc/rsyslog.conf·|·cut·-d·'·'·-f·2) 
282 readarray·-t·RSYSLOG_INCLUDE_CONFIG·<·<(for·INCPATH·in·"${OLD_INC[@]}";·do·eval 
283 printf·'%s\\n'·"${INCPATH}";·done) 
284 readarray·-t·NEW_INC·<·<(sed·-n·'/^\s*include(/,/)/Ip'·/etc/rsyslog.conf·|·sed 
285 -n·'s@.*file\s*=\s*"\([/[:alnum:][:punct:]]*\)".*@\1@Ip') 
286 readarray·-t·RSYSLOG_INCLUDE·<·<(for·INCPATH·in·"${NEW_INC[@]}";·do·eval·printf 
287 '%s\\n'·"${INCPATH}";·done) 
  
288 #·Declare·an·array·to·hold·the·final·list·of·different·log·file·paths 
289 declare·-a·LOG_FILE_PATHS 
  
290 #·Array·to·hold·all·rsyslog·config·entries 
291 RSYSLOG_CONFIGS=() 
292 RSYSLOG_CONFIGS=("${RSYSLOG_ETC_CONFIG}"·"${RSYSLOG_INCLUDE_CONFIG[@]}"·"$ 
293 {RSYSLOG_INCLUDE[@]}") 
  
294 #·Get·full·list·of·files·to·be·checked 
295 #·RSYSLOG_CONFIGS·may·contain·globs·such·as 
296 #·/etc/rsyslog.d/*.conf·/etc/rsyslog.d/*.frule 
297 #·So,·loop·over·the·entries·in·RSYSLOG_CONFIGS·and·use·find·to·get·the·list·of 
298 included·files. 
299 RSYSLOG_CONFIG_FILES=() 
300 for·ENTRY·in·"${RSYSLOG_CONFIGS[@]}" 
301 do 
302 »       #·If·directory,·rsyslog·will·search·for·config·files·in·recursively. 
303 »       #·However,·files·in·hidden·sub-directories·or·hidden·files·will·be·ignored. 
304 »       if·[·-d·"${ENTRY}"·] 
305 »       then 
306 »       »       readarray·-t·FINDOUT·<·<(find·"${ENTRY}"·-not·-path·'*/.*'·-type·f) 
307 »       »       RSYSLOG_CONFIG_FILES+=("${FINDOUT[@]}") 
308 »       elif·[·-f·"${ENTRY}"·] 
309 »       then 
310 »       »       RSYSLOG_CONFIG_FILES+=("${ENTRY}") 
311 »       else 
312 »       »       echo·"Invalid·include·object:·${ENTRY}" 
313 »       fi 
314 done 
  
315 #·Browse·each·file·selected·above·as·containing·paths·of·log·files 
316 #·('/etc/rsyslog.conf'·and·'/etc/rsyslog.d/*.conf'·in·the·default 
317 configuration) 
318 for·LOG_FILE·in·"${RSYSLOG_CONFIG_FILES[@]}" 
319 do 
320 »       #·From·each·of·these·files·extract·just·particular·log·file·path(s),·thus: 
321 »       #·*·Ignore·lines·starting·with·space·('·'),·comment·('#"),·or·variable·syntax 
322 ('$')·characters, 
323 »       #·*·Ignore·empty·lines, 
324 »       #·*·Strip·quotes·and·closing·brackets·from·paths. 
325 »       #·*·Ignore·paths·that·match·/dev|/etc.*\.conf,·as·those·are·paths,·but·likely 
326 not·log·files 
327 »       #·*·From·the·remaining·valid·rows·select·only·fields·constituting·a·log·file 
328 path 
329 »       #·Text·file·column·is·understood·to·represent·a·log·file·path·if·and·only·if 
330 all·of·the 
331 »       #·following·are·met: 
332 »       #·*·it·contains·at·least·one·slash·'/'·character, 
333 »       #·*·it·is·preceded·by·space 
334 »       #·*·it·doesn't·contain·space·('·'),·colon·(':'),·and·semicolon·(';') 
335 characters 
336 »       #·Search·log·file·for·path(s)·only·in·case·it·exists! 
337 »       if·[[·-f·"${LOG_FILE}"·]] 
338 »       then 
339 »       »       NORMALIZED_CONFIG_FILE_LINES=$(sed·-e·"/^[#|$]/d"·"${LOG_FILE}") 
340 »       »       LINES_WITH_PATHS=$(grep·'[^/]*\s\+\S*/\S\+$'·<<<·"$ 
341 {NORMALIZED_CONFIG_FILE_LINES}") 
342 »       »       FILTERED_PATHS=$(awk·'{if(NF>=2&&($NF~/^\//||$NF~/^-\//)){sub(/^-\//,"/ 
343 ",$NF);print·$NF}}'·<<<·"${LINES_WITH_PATHS}") 
344 »       »       CLEANED_PATHS=$(sed·-e·"s/[\"')]//g;·/\\/etc.*\.conf/d;·/\\/dev\\//d"·<<<·"$ 
345 {FILTERED_PATHS}") 
346 »       »       MATCHED_ITEMS=$(sed·-e·"/^$/d"·<<<·"${CLEANED_PATHS}") 
347 »       »       #·Since·above·sed·command·might·return·more·than·one·item·(delimited·by 
348 newline),·split 
349 »       »       #·the·particular·matches·entries·into·new·array·specific·for·this·log·file 
350 »       »       readarray·-t·ARRAY_FOR_LOG_FILE·<<<·"$MATCHED_ITEMS" 
351 »       »       #·Concatenate·the·two·arrays·-·previous·content·of·$LOG_FILE_PATHS·array·with 
352 »       »       #·items·from·newly·created·array·for·this·log·file 
353 »       »       LOG_FILE_PATHS+=("${ARRAY_FOR_LOG_FILE[@]}") 
354 »       »       #·Delete·the·temporary·array 
355 »       »       unset·ARRAY_FOR_LOG_FILE 
356 »       fi 
357 done 
  
358 #·Check·for·RainerScript·action·log·format·which·might·be·also·multiline·so 
359 grep·regex·is·a·bit 
360 #·curly: 
361 #·extract·possibly·multiline·action·omfile·expressions 
362 #·extract·File="logfile"·expression 
363 #·match·only·"logfile"·expression 
364 for·LOG_FILE·in·"${RSYSLOG_CONFIG_FILES[@]}" 
365 do 
366 »       ACTION_OMFILE_LINES=$(grep·-iozP·"action\s*\(\s*type\s*=\s*\"omfile\"[^\)]*\)" 
367 "${LOG_FILE}") 
368 »       OMFILE_LINES=$(echo·"${ACTION_OMFILE_LINES}"|·grep·-iaoP·"\bFile\s*=\s*\"([/[: 
Max diff block lines reached; 121642/128231 bytes (94.86%) of diff not shown.
6.31 MB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-cis_level1_server.html
    
Offset 14284, 16 lines modifiedOffset 14284, 16 lines modified
00037cb0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00037cb0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00037cc0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00037cc0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00037cd0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000037cd0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00037ce0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></00037ce0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
00037cf0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00037cf0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00037d00:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00037d00:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00037d10:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037d10:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037d20:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600037d20:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
00037d30:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········00037d30:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00037d40:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00037d40:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00037d50:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00037d50:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00037d60:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00037d60:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00037d70:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00037d70:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00037d80:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00037d80:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00037d90:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00037d90:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00037da0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00037da0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
Offset 15134, 130 lines modifiedOffset 15134, 130 lines modified
0003b1d0:·7267·6574·3d22·2369·646d·3237·3336·2220··rget="#idm2736"·0003b1d0:·7267·6574·3d22·2369·646d·3237·3336·2220··rget="#idm2736"·
0003b1e0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003b1e0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003b1f0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003b1f0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003b200:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003b200:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003b210:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003b210:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003b220:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003b220:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003b230:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003b230:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003b240:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr
 0003b250:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...<
 0003b260:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003b270:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003b280:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003b290:·6964·6d32·3733·3622·3e3c·7072·653e·3c63··idm2736"><pre><c
 0003b2a0:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages]
 0003b2b0:·5d0a·6e61·6d65·203d·2022·6169·6465·220a··].name·=·"aide".
 0003b2c0:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</
 0003b2d0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003b2e0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003b2f0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003b300:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003b310:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003b320:·2369·646d·3237·3337·2220·7461·6269·6e64··#idm2737"·tabind
 0003b330:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003b340:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003b350:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003b360:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003b370:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003b380:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi
 0003b390:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...<
 0003b3a0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003b3b0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003b3c0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003b3d0:·6964·6d32·3733·3722·3e3c·7461·626c·6520··idm2737"><table·
 0003b3e0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003b3f0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003b400:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003b410:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003b420:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003b430:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003b440:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 0003b450:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 0003b460:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003b470:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 0003b480:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
 0003b490:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003b4a0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
 0003b4b0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 0003b4c0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003b4d0:·3e2d·206e·616d·653a·2045·6e73·7572·6520··>-·name:·Ensure·
 0003b4e0:·6169·6465·2069·7320·696e·7374·616c·6c65··aide·is·installe
 0003b4f0:·640a·2020·7061·636b·6167·653a·0a20·2020··d.··package:.···
 0003b500:·206e·616d·653a·2061·6964·650a·2020·2020···name:·aide.····
 0003b510:·7374·6174·653a·2070·7265·7365·6e74·0a20··state:·present.·
 0003b520:·2077·6865·6e3a·2061·6e73·6962·6c65·5f76···when:·ansible_v
 0003b530:·6972·7475·616c·697a·6174·696f·6e5f·7479··irtualization_ty
 0003b540:·7065·206e·6f74·2069·6e20·5b22·646f·636b··pe·not·in·["dock
 0003b550:·6572·222c·2022·6c78·6322·2c20·226f·7065··er",·"lxc",·"ope
 0003b560:·6e76·7a22·2c20·2270·6f64·6d61·6e22·2c20··nvz",·"podman",·
 0003b570:·2263·6f6e·7461·696e·6572·225d·0a20·2074··"container"].··t
 0003b580:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5.
 0003b590:·3130·2e31·2e33·0a20·202d·2044·4953·412d··10.1.3.··-·DISA-
 0003b5a0:·5354·4947·2d55·4254·552d·3230·2d30·3130··STIG-UBTU-20-010
 0003b5b0:·3435·300a·2020·2d20·4e49·5354·2d38·3030··450.··-·NIST-800
 0003b5c0:·2d35·332d·434d·2d36·2861·290a·2020·2d20··-53-CM-6(a).··-·
 0003b5d0:·5043·492d·4453·532d·5265·712d·3131·2e35··PCI-DSS-Req-11.5
 0003b5e0:·0a20·202d·2050·4349·2d44·5353·7634·2d31··.··-·PCI-DSSv4-1
 0003b5f0:·312e·352e·320a·2020·2d20·656e·6162·6c65··1.5.2.··-·enable
 0003b600:·5f73·7472·6174·6567·790a·2020·2d20·6c6f··_strategy.··-·lo
 0003b610:·775f·636f·6d70·6c65·7869·7479·0a20·202d··w_complexity.··-
 0003b620:·206c·6f77·5f64·6973·7275·7074·696f·6e0a···low_disruption.
 0003b630:·2020·2d20·6d65·6469·756d·5f73·6576·6572····-·medium_sever
 0003b640:·6974·790a·2020·2d20·6e6f·5f72·6562·6f6f··ity.··-·no_reboo
 0003b650:·745f·6e65·6564·6564·0a20·202d·2070·6163··t_needed.··-·pac
 0003b660:·6b61·6765·5f61·6964·655f·696e·7374·616c··kage_aide_instal
 0003b670:·6c65·640a·3c2f·636f·6465·3e3c·2f70·7265··led.</code></pre
 0003b680:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0003b690:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0003b6a0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0003b6b0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 0003b6c0:·7267·6574·3d22·2369·646d·3237·3338·2220··rget="#idm2738"·
 0003b6d0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0003b6e0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 0003b6f0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 0003b700:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 0003b710:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 0003b720:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003b240:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.0003b730:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.
0003b250:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003b740:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003b260:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003b750:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003b270:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003b760:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003b280:·643d·2269·646d·3237·3336·223e·3c74·6162··d="idm2736"><tab0003b770:·643d·2269·646d·3237·3338·223e·3c74·6162··d="idm2738"><tab
0003b290:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003b780:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003b2a0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003b790:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003b2b0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003b7a0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003b2c0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003b7b0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003b2d0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003b7c0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003b2e0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003b7d0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003b2f0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003b7e0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
0003b300:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003b7f0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003b310:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003b800:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003b320:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<0003b810:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
0003b330:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003b820:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003b340:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003b830:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003b350:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003b840:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003b360:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr0003b850:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003b370:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003b860:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
0003b380:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio0003b870:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
0003b390:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·0003b880:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
0003b3a0:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·0003b890:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
0003b3b0:·706c·6174·666f·726d·730a·6966·205b·2021··platforms.if·[·!0003b8a0:·706c·6174·666f·726d·730a·6966·205b·2021··platforms.if·[·!
Max diff block lines reached; 5778987/5796843 bytes (99.69%) of diff not shown.
805 KB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Ubuntu·20.04·Level·1·Server·Benchmark38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Ubuntu·20.04·Level·1·Server·Benchmark
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_level1_server39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_level1_server
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~
42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
43 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8443 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
49 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r49 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
50 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n50 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
51 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g51 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 133, 27 lines modifiedOffset 133, 19 lines modified
133 include·install_aide133 include·install_aide
  
134 class·install_aide·{134 class·install_aide·{
135 ··package·{·'aide':135 ··package·{·'aide':
136 ····ensure·=>·'installed',136 ····ensure·=>·'installed',
137 ··}137 ··}
138 }138 }
 139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
144 #·Remediation·is·applicable·only·in·certain·platforms 
145 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
146 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide" 
  
147 else 
148 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
149 fi140 [[packages]]
 141 name·=·"aide"
 142 version·=·"*"
150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
151 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low144 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
152 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low145 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
153 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false146 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
154 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable147 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
155 -·name:·Ensure·aide·is·installed148 -·name:·Ensure·aide·is·installed
156 ··package:149 ··package:
Offset 168, 19 lines modifiedOffset 160, 27 lines modified
168 ··-·PCI-DSSv4-11.5.2160 ··-·PCI-DSSv4-11.5.2
169 ··-·enable_strategy161 ··-·enable_strategy
170 ··-·low_complexity162 ··-·low_complexity
171 ··-·low_disruption163 ··-·low_disruption
172 ··-·medium_severity164 ··-·medium_severity
173 ··-·no_reboot_needed165 ··-·no_reboot_needed
174 ··-·package_aide_installed166 ··-·package_aide_installed
175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 172 #·Remediation·is·applicable·only·in·certain·platforms
 173 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
176 [[packages]] 
177 name·=·"aide" 
178 version·=·"*"174 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide"
  
 175 else
 176 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 177 fi
179 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*178 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
180 Run·the·following·command·to·generate·a·new·database:179 Run·the·following·command·to·generate·a·new·database:
181 $·sudo·aideinit180 $·sudo·aideinit
182 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the181 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the
183 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide.wrapper·(or·hashes·of182 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide.wrapper·(or·hashes·of
184 these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about183 these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about
185 their·integrity.·The·newly-generated·database·can·be·installed·as·follows:184 their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 206, 40 lines modifiedOffset 206, 14 lines modified
206 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5206 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
207 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199207 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
208 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-20-010450208 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-20-010450
209 ············_\x8c_\x8i_\x8s············1.4.1209 ············_\x8c_\x8i_\x8s············1.4.1
210 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79210 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
211 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2211 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
212 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-238371r880913_rule212 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-238371r880913_rule
213 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
214 #·Remediation·is·applicable·only·in·certain·platforms 
215 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
216 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide" 
  
217 AIDE_CONFIG=/etc/aide/aide.conf 
218 DEFAULT_DB_PATH=/var/lib/aide/aide.db 
  
219 #·Fix·db·path·in·the·config·file,·if·necessary 
220 if·!·grep·-q·'^database=file:'·${AIDE_CONFIG};·then 
221 ····#·replace_or_append·gets·confused·by·'database=file'·as·a·key,·so·should·not·be·used. 
222 ····#replace_or_append·"${AIDE_CONFIG}"·'^database=file'·"${DEFAULT_DB_PATH}"·'@CCENUM@'·'%s:%s' 
223 ····echo·"database=file:${DEFAULT_DB_PATH}"·>>·${AIDE_CONFIG} 
224 fi 
  
225 #·Fix·db·out·path·in·the·config·file,·if·necessary 
226 if·!·grep·-q·'^database_out=file:'·${AIDE_CONFIG};·then 
227 ····echo·"database_out=file:${DEFAULT_DB_PATH}.new"·>>·${AIDE_CONFIG} 
228 fi 
  
229 /usr/sbin/aideinit·-y·-f 
  
230 else 
231 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
232 fi 
233 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8213 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
234 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low214 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
235 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low215 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
236 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false216 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
237 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict217 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
238 -·name:·Build·and·Test·AIDE·Database·-·Ensure·AIDE·Is·Installed218 -·name:·Build·and·Test·AIDE·Database·-·Ensure·AIDE·Is·Installed
239 ··ansible.builtin.apt:219 ··ansible.builtin.apt:
Offset 402, 14 lines modifiedOffset 376, 40 lines modified
402 ··-·PCI-DSSv4-11.5.2376 ··-·PCI-DSSv4-11.5.2
403 ··-·aide_build_database377 ··-·aide_build_database
404 ··-·low_complexity378 ··-·low_complexity
405 ··-·low_disruption379 ··-·low_disruption
406 ··-·medium_severity380 ··-·medium_severity
407 ··-·no_reboot_needed381 ··-·no_reboot_needed
408 ··-·restrict_strategy382 ··-·restrict_strategy
 383 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 384 #·Remediation·is·applicable·only·in·certain·platforms
Max diff block lines reached; 817565/824200 bytes (99.19%) of diff not shown.
6.15 MB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-cis_level1_workstation.html
    
Offset 14285, 16 lines modifiedOffset 14285, 16 lines modified
00037cc0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h00037cc0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h
00037cd0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver00037cd0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver
00037ce0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.00037ce0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.
00037cf0:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p00037cf0:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p
00037d00:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong00037d00:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong
00037d10:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.00037d10:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.
00037d20:·2020·2020·2020·2020·2020·2020·2020·2020··················00037d20:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037d30:·2020·2020·2861·7320·6f66·2032·3032·362d······(as·of·2026-00037d30:·2020·2020·2861·7320·6f66·2032·3032·342d······(as·of·2024-
00037d40:·3031·2d30·3829·0a20·2020·2020·2020·2020··01-08).·········00037d40:·3132·2d30·3729·0a20·2020·2020·2020·2020··12-07).·········
00037d50:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul00037d50:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul
00037d60:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table00037d60:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table
00037d70:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h200037d70:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2
00037d80:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href00037d80:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href
00037d90:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg00037d90:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg
00037da0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_00037da0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
00037db0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy00037db0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy
Offset 15129, 131 lines modifiedOffset 15129, 131 lines modified
0003b180:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003b180:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003b190:·743d·2223·6964·6d32·3733·3622·2074·6162··t="#idm2736"·tab0003b190:·743d·2223·6964·6d32·3733·3622·2074·6162··t="#idm2736"·tab
0003b1a0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003b1a0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003b1b0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003b1b0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003b1c0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003b1c0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003b1d0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003b1d0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003b1e0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003b1e0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003b1f0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S0003b1f0:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O
 0003b200:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint
 0003b210:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0003b220:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003b230:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003b240:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003b200:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
0003b210:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003b220:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003b230:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003b240:·6964·6d32·3733·3622·3e3c·7461·626c·6520··idm2736"><table· 
0003b250:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003b260:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003b270:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003b280:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003b290:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003b2a0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b2b0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003b2c0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003b2d0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003b2e0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003b2f0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003b300:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003b310:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
0003b320:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
0003b330:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003b250:·3237·3336·223e·3c70·7265·3e3c·636f·6465··2736"><pre><code
 0003b260:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n
 0003b270:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver
 0003b280:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod
0003b340:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i 
0003b350:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl 
0003b360:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla 
0003b370:·7466·6f72·6d73·0a69·6620·5b20·2120·2d66··tforms.if·[·!·-f 
0003b380:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·& 
0003b390:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f 
0003b3a0:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container 
0003b3b0:·656e·7620·5d3b·2074·6865·6e0a·0a44·4542··env·];·then..DEB 
0003b3c0:·4941·4e5f·4652·4f4e·5445·4e44·3d6e·6f6e··IAN_FRONTEND=non 
0003b3d0:·696e·7465·7261·6374·6976·6520·6170·742d··interactive·apt- 
0003b3e0:·6765·7420·696e·7374·616c·6c20·2d79·2022··get·install·-y·" 
0003b3f0:·6169·6465·220a·0a65·6c73·650a·2020·2020··aide"..else.···· 
0003b400:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo· 
0003b410:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is· 
0003b420:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,· 
0003b430:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done 
0003b440:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr 
0003b450:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003b460:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003b470:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003b480:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003b490:·6172·6765·743d·2223·6964·6d32·3733·3722··arget="#idm2737" 
0003b4a0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003b4b0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003b4c0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003b4d0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003b4e0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003b4f0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003b500:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp 
0003b510:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003b520:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003b530:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003b540:·6522·2069·643d·2269·646d·3237·3337·223e··e"·id="idm2737"> 
0003b550:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003b560:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003b570:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003b580:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003b590:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003b5a0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003b5b0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b5c0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003b5d0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b5e0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003b5f0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0003b600:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
0003b610:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0003b620:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0003b630:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003b640:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:· 
0003b650:·456e·7375·7265·2061·6964·6520·6973·2069··Ensure·aide·is·i 
0003b660:·6e73·7461·6c6c·6564·0a20·2070·6163·6b61··nstalled.··packa 
0003b670:·6765·3a0a·2020·2020·6e61·6d65·3a20·6169··ge:.····name:·ai 
0003b680:·6465·0a20·2020·2073·7461·7465·3a20·7072··de.····state:·pr 
0003b690:·6573·656e·740a·2020·7768·656e·3a20·616e··esent.··when:·an 
0003b6a0:·7369·626c·655f·7669·7274·7561·6c69·7a61··sible_virtualiza 
0003b6b0:·7469·6f6e·5f74·7970·6520·6e6f·7420·696e··tion_type·not·in 
0003b6c0:·205b·2264·6f63·6b65·7222·2c20·226c·7863···["docker",·"lxc 
0003b6d0:·222c·2022·6f70·656e·767a·222c·2022·706f··",·"openvz",·"po 
0003b6e0:·646d·616e·222c·2022·636f·6e74·6169·6e65··dman",·"containe 
0003b6f0:·7222·5d0a·2020·7461·6773·3a0a·2020·2d20··r"].··tags:.··-· 
0003b700:·434a·4953·2d35·2e31·302e·312e·330a·2020··CJIS-5.10.1.3.·· 
0003b710:·2d20·4449·5341·2d53·5449·472d·5542·5455··-·DISA-STIG-UBTU 
0003b720:·2d32·302d·3031·3034·3530·0a20·202d·204e··-20-010450.··-·N 
0003b730:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6( 
0003b740:·6129·0a20·202d·2050·4349·2d44·5353·2d52··a).··-·PCI-DSS-R 
0003b750:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI- 
0003b760:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··- 
0003b770:·2065·6e61·626c·655f·7374·7261·7465·6779···enable_strategy 
0003b780:·0a20·202d·206c·6f77·5f63·6f6d·706c·6578··.··-·low_complex 
0003b790:·6974·790a·2020·2d20·6c6f·775f·6469·7372··ity.··-·low_disr 
0003b7a0:·7570·7469·6f6e·0a20·202d·206d·6564·6975··uption.··-·mediu 
0003b7b0:·6d5f·7365·7665·7269·7479·0a20·202d·206e··m_severity.··-·n 
0003b7c0:·6f5f·7265·626f·6f74·5f6e·6565·6465·640a··o_reboot_needed. 
0003b7d0:·2020·2d20·7061·636b·6167·655f·6169·6465····-·package_aide 
Max diff block lines reached; 5624843/5642837 bytes (99.68%) of diff not shown.
791 KB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Ubuntu·20.04·Level·1·Workstation·Benchmark38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Ubuntu·20.04·Level·1·Workstation·Benchmark
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_level1_workstation39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_level1_workstation
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~
42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
43 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8443 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
49 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r49 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
50 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n50 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
51 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g51 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 132, 27 lines modifiedOffset 132, 19 lines modified
132 include·install_aide132 include·install_aide
  
133 class·install_aide·{133 class·install_aide·{
134 ··package·{·'aide':134 ··package·{·'aide':
135 ····ensure·=>·'installed',135 ····ensure·=>·'installed',
136 ··}136 ··}
137 }137 }
 138 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
138 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
139 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
140 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
141 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
142 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
143 #·Remediation·is·applicable·only·in·certain·platforms 
144 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
145 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide" 
  
146 else 
147 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
148 fi139 [[packages]]
 140 name·=·"aide"
 141 version·=·"*"
149 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
150 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
151 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
152 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
153 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
154 -·name:·Ensure·aide·is·installed147 -·name:·Ensure·aide·is·installed
155 ··package:148 ··package:
Offset 167, 19 lines modifiedOffset 159, 27 lines modified
167 ··-·PCI-DSSv4-11.5.2159 ··-·PCI-DSSv4-11.5.2
168 ··-·enable_strategy160 ··-·enable_strategy
169 ··-·low_complexity161 ··-·low_complexity
170 ··-·low_disruption162 ··-·low_disruption
171 ··-·medium_severity163 ··-·medium_severity
172 ··-·no_reboot_needed164 ··-·no_reboot_needed
173 ··-·package_aide_installed165 ··-·package_aide_installed
174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 171 #·Remediation·is·applicable·only·in·certain·platforms
 172 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
175 [[packages]] 
176 name·=·"aide" 
177 version·=·"*"173 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide"
  
 174 else
 175 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 176 fi
178 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*177 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
179 Run·the·following·command·to·generate·a·new·database:178 Run·the·following·command·to·generate·a·new·database:
180 $·sudo·aideinit179 $·sudo·aideinit
181 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the180 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the
182 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide.wrapper·(or·hashes·of181 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide.wrapper·(or·hashes·of
183 these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about182 these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about
184 their·integrity.·The·newly-generated·database·can·be·installed·as·follows:183 their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 205, 40 lines modifiedOffset 205, 14 lines modified
205 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5205 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
206 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199206 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
207 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-20-010450207 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-20-010450
208 ············_\x8c_\x8i_\x8s············1.4.1208 ············_\x8c_\x8i_\x8s············1.4.1
209 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79209 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
210 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2210 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
211 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-238371r880913_rule211 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-238371r880913_rule
212 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
213 #·Remediation·is·applicable·only·in·certain·platforms 
214 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
215 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide" 
  
216 AIDE_CONFIG=/etc/aide/aide.conf 
217 DEFAULT_DB_PATH=/var/lib/aide/aide.db 
  
218 #·Fix·db·path·in·the·config·file,·if·necessary 
219 if·!·grep·-q·'^database=file:'·${AIDE_CONFIG};·then 
220 ····#·replace_or_append·gets·confused·by·'database=file'·as·a·key,·so·should·not·be·used. 
221 ····#replace_or_append·"${AIDE_CONFIG}"·'^database=file'·"${DEFAULT_DB_PATH}"·'@CCENUM@'·'%s:%s' 
222 ····echo·"database=file:${DEFAULT_DB_PATH}"·>>·${AIDE_CONFIG} 
223 fi 
  
224 #·Fix·db·out·path·in·the·config·file,·if·necessary 
225 if·!·grep·-q·'^database_out=file:'·${AIDE_CONFIG};·then 
226 ····echo·"database_out=file:${DEFAULT_DB_PATH}.new"·>>·${AIDE_CONFIG} 
227 fi 
  
228 /usr/sbin/aideinit·-y·-f 
  
229 else 
230 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
231 fi 
232 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8212 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
233 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low213 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
234 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low214 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
235 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false215 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
236 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict216 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
237 -·name:·Build·and·Test·AIDE·Database·-·Ensure·AIDE·Is·Installed217 -·name:·Build·and·Test·AIDE·Database·-·Ensure·AIDE·Is·Installed
238 ··ansible.builtin.apt:218 ··ansible.builtin.apt:
Offset 401, 14 lines modifiedOffset 375, 40 lines modified
401 ··-·PCI-DSSv4-11.5.2375 ··-·PCI-DSSv4-11.5.2
402 ··-·aide_build_database376 ··-·aide_build_database
403 ··-·low_complexity377 ··-·low_complexity
404 ··-·low_disruption378 ··-·low_disruption
405 ··-·medium_severity379 ··-·medium_severity
406 ··-·no_reboot_needed380 ··-·no_reboot_needed
407 ··-·restrict_strategy381 ··-·restrict_strategy
 382 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 383 #·Remediation·is·applicable·only·in·certain·platforms
Max diff block lines reached; 803431/810076 bytes (99.18%) of diff not shown.
19.6 MB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-cis_level2_server.html
    
Offset 14284, 16 lines modifiedOffset 14284, 16 lines modified
00037cb0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00037cb0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00037cc0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00037cc0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00037cd0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000037cd0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00037ce0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></00037ce0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
00037cf0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00037cf0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00037d00:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00037d00:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00037d10:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037d10:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037d20:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600037d20:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
00037d30:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········00037d30:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00037d40:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00037d40:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00037d50:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00037d50:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00037d60:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00037d60:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00037d70:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00037d70:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00037d80:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00037d80:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00037d90:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00037d90:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00037da0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00037da0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
Offset 15156, 130 lines modifiedOffset 15156, 130 lines modified
0003b330:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003b330:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b340:·6964·6d32·3733·3622·2074·6162·696e·6465··idm2736"·tabinde0003b340:·6964·6d32·3733·3622·2074·6162·696e·6465··idm2736"·tabinde
0003b350:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b350:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003b360:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003b360:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003b370:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003b370:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003b380:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003b380:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003b390:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003b390:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003b3a0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell0003b3a0:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui
 0003b3b0:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni
 0003b3c0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0003b3d0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003b3e0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003b3f0:·7073·6522·2069·643d·2269·646d·3237·3336··pse"·id="idm2736
0003b3b0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003b3c0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b3d0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b3e0:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm2 
0003b3f0:·3733·3622·3e3c·7461·626c·6520·636c·6173··736"><table·clas 
0003b400:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b410:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b420:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b430:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b440:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b450:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b460:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b470:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b480:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b490:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b4a0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003b4b0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b4c0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b4d0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b4e0:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R0003b400:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[
 0003b410:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name·
 0003b420:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version
 0003b430:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></
0003b4f0:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003b500:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003b510:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003b520:·6d73·0a69·6620·5b20·2120·2d66·202f·2e64··ms.if·[·!·-f·/.d 
0003b530:·6f63·6b65·7265·6e76·205d·2026·616d·703b··ockerenv·]·&amp; 
0003b540:·2661·6d70·3b20·5b20·2120·2d66·202f·7275··&amp;·[·!·-f·/ru 
0003b550:·6e2f·2e63·6f6e·7461·696e·6572·656e·7620··n/.containerenv· 
0003b560:·5d3b·2074·6865·6e0a·0a44·4542·4941·4e5f··];·then..DEBIAN_ 
0003b570:·4652·4f4e·5445·4e44·3d6e·6f6e·696e·7465··FRONTEND=noninte 
0003b580:·7261·6374·6976·6520·6170·742d·6765·7420··ractive·apt-get· 
0003b590:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide 
0003b5a0:·220a·0a65·6c73·650a·2020·2020·2667·743b··"..else.····&gt; 
0003b5b0:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem 
0003b5c0:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not· 
0003b5d0:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth 
0003b5e0:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi 
0003b5f0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003b600:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b610:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b620:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b630:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b640:·743d·2223·6964·6d32·3733·3722·2074·6162··t="#idm2737"·tab 
0003b650:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b660:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b670:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b680:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b690:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b6a0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A 
0003b6b0:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
0003b6c0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b6d0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b6e0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003b6f0:·643d·2269·646d·3237·3337·223e·3c74·6162··d="idm2737"><tab 
0003b700:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003b710:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003b720:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003b730:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003b740:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003b750:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b760:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003b770:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003b780:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b790:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003b7a0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003b7b0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003b7c0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003b7d0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003b7e0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003b7f0:·6f64·653e·2d20·6e61·6d65·3a20·456e·7375··ode>-·name:·Ensu 
0003b800:·7265·2061·6964·6520·6973·2069·6e73·7461··re·aide·is·insta 
0003b810:·6c6c·6564·0a20·2070·6163·6b61·6765·3a0a··lled.··package:. 
0003b820:·2020·2020·6e61·6d65·3a20·6169·6465·0a20······name:·aide.· 
0003b830:·2020·2073·7461·7465·3a20·7072·6573·656e·····state:·presen 
0003b840:·740a·2020·7768·656e·3a20·616e·7369·626c··t.··when:·ansibl 
0003b850:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization 
0003b860:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d 
0003b870:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·" 
0003b880:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman 
0003b890:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"]. 
0003b8a0:·2020·7461·6773·3a0a·2020·2d20·434a·4953····tags:.··-·CJIS 
0003b8b0:·2d35·2e31·302e·312e·330a·2020·2d20·4449··-5.10.1.3.··-·DI 
0003b8c0:·5341·2d53·5449·472d·5542·5455·2d32·302d··SA-STIG-UBTU-20- 
0003b8d0:·3031·3034·3530·0a20·202d·204e·4953·542d··010450.··-·NIST- 
0003b8e0:·3830·302d·3533·2d43·4d2d·3628·6129·0a20··800-53-CM-6(a).· 
0003b8f0:·202d·2050·4349·2d44·5353·2d52·6571·2d31···-·PCI-DSS-Req-1 
0003b900:·312e·350a·2020·2d20·5043·492d·4453·5376··1.5.··-·PCI-DSSv 
0003b910:·342d·3131·2e35·2e32·0a20·202d·2065·6e61··4-11.5.2.··-·ena 
0003b920:·626c·655f·7374·7261·7465·6779·0a20·202d··ble_strategy.··- 
0003b930:·206c·6f77·5f63·6f6d·706c·6578·6974·790a···low_complexity. 
0003b940:·2020·2d20·6c6f·775f·6469·7372·7570·7469····-·low_disrupti 
0003b950:·6f6e·0a20·202d·206d·6564·6975·6d5f·7365··on.··-·medium_se 
0003b960:·7665·7269·7479·0a20·202d·206e·6f5f·7265··verity.··-·no_re 
0003b970:·626f·6f74·5f6e·6565·6465·640a·2020·2d20··boot_needed.··-· 
0003b980:·7061·636b·6167·655f·6169·6465·5f69·6e73··package_aide_ins 
Max diff block lines reached; 18834145/18852001 bytes (99.91%) of diff not shown.
1.66 MB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Ubuntu·20.04·Level·2·Server·Benchmark38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Ubuntu·20.04·Level·2·Server·Benchmark
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_level2_server39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_level2_server
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~
42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
43 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8443 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
49 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r49 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
50 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n50 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
51 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g51 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 136, 27 lines modifiedOffset 136, 19 lines modified
136 include·install_aide136 include·install_aide
  
137 class·install_aide·{137 class·install_aide·{
138 ··package·{·'aide':138 ··package·{·'aide':
139 ····ensure·=>·'installed',139 ····ensure·=>·'installed',
140 ··}140 ··}
141 }141 }
 142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
147 #·Remediation·is·applicable·only·in·certain·platforms 
148 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
149 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide" 
  
150 else 
151 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
152 fi143 [[packages]]
 144 name·=·"aide"
 145 version·=·"*"
153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
154 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low147 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
155 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low148 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
156 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false149 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
157 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable150 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
158 -·name:·Ensure·aide·is·installed151 -·name:·Ensure·aide·is·installed
159 ··package:152 ··package:
Offset 171, 19 lines modifiedOffset 163, 27 lines modified
171 ··-·PCI-DSSv4-11.5.2163 ··-·PCI-DSSv4-11.5.2
172 ··-·enable_strategy164 ··-·enable_strategy
173 ··-·low_complexity165 ··-·low_complexity
174 ··-·low_disruption166 ··-·low_disruption
175 ··-·medium_severity167 ··-·medium_severity
176 ··-·no_reboot_needed168 ··-·no_reboot_needed
177 ··-·package_aide_installed169 ··-·package_aide_installed
178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 175 #·Remediation·is·applicable·only·in·certain·platforms
 176 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
179 [[packages]] 
180 name·=·"aide" 
181 version·=·"*"177 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide"
  
 178 else
 179 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 180 fi
182 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*181 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
183 Run·the·following·command·to·generate·a·new·database:182 Run·the·following·command·to·generate·a·new·database:
184 $·sudo·aideinit183 $·sudo·aideinit
185 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the184 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the
186 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide.wrapper·(or·hashes·of185 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide.wrapper·(or·hashes·of
187 these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about186 these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about
188 their·integrity.·The·newly-generated·database·can·be·installed·as·follows:187 their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 209, 40 lines modifiedOffset 209, 14 lines modified
209 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5209 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
210 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199210 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
211 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-20-010450211 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-20-010450
212 ············_\x8c_\x8i_\x8s············1.4.1212 ············_\x8c_\x8i_\x8s············1.4.1
213 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79213 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
214 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2214 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
215 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-238371r880913_rule215 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-238371r880913_rule
216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
217 #·Remediation·is·applicable·only·in·certain·platforms 
218 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
219 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide" 
  
220 AIDE_CONFIG=/etc/aide/aide.conf 
221 DEFAULT_DB_PATH=/var/lib/aide/aide.db 
  
222 #·Fix·db·path·in·the·config·file,·if·necessary 
223 if·!·grep·-q·'^database=file:'·${AIDE_CONFIG};·then 
224 ····#·replace_or_append·gets·confused·by·'database=file'·as·a·key,·so·should·not·be·used. 
225 ····#replace_or_append·"${AIDE_CONFIG}"·'^database=file'·"${DEFAULT_DB_PATH}"·'@CCENUM@'·'%s:%s' 
226 ····echo·"database=file:${DEFAULT_DB_PATH}"·>>·${AIDE_CONFIG} 
227 fi 
  
228 #·Fix·db·out·path·in·the·config·file,·if·necessary 
229 if·!·grep·-q·'^database_out=file:'·${AIDE_CONFIG};·then 
230 ····echo·"database_out=file:${DEFAULT_DB_PATH}.new"·>>·${AIDE_CONFIG} 
231 fi 
  
232 /usr/sbin/aideinit·-y·-f 
  
233 else 
234 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
235 fi 
236 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
237 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low217 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
238 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low218 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
239 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false219 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
240 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict220 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
241 -·name:·Build·and·Test·AIDE·Database·-·Ensure·AIDE·Is·Installed221 -·name:·Build·and·Test·AIDE·Database·-·Ensure·AIDE·Is·Installed
242 ··ansible.builtin.apt:222 ··ansible.builtin.apt:
Offset 405, 14 lines modifiedOffset 379, 40 lines modified
405 ··-·PCI-DSSv4-11.5.2379 ··-·PCI-DSSv4-11.5.2
406 ··-·aide_build_database380 ··-·aide_build_database
407 ··-·low_complexity381 ··-·low_complexity
408 ··-·low_disruption382 ··-·low_disruption
409 ··-·medium_severity383 ··-·medium_severity
410 ··-·no_reboot_needed384 ··-·no_reboot_needed
411 ··-·restrict_strategy385 ··-·restrict_strategy
 386 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 387 #·Remediation·is·applicable·only·in·certain·platforms
Max diff block lines reached; 1729404/1736039 bytes (99.62%) of diff not shown.
19.6 MB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-cis_level2_workstation.html
    
Offset 14285, 16 lines modifiedOffset 14285, 16 lines modified
00037cc0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h00037cc0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h
00037cd0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver00037cd0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver
00037ce0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.00037ce0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.
00037cf0:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p00037cf0:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p
00037d00:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong00037d00:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong
00037d10:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.00037d10:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.
00037d20:·2020·2020·2020·2020·2020·2020·2020·2020··················00037d20:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037d30:·2020·2020·2861·7320·6f66·2032·3032·362d······(as·of·2026-00037d30:·2020·2020·2861·7320·6f66·2032·3032·342d······(as·of·2024-
00037d40:·3031·2d30·3829·0a20·2020·2020·2020·2020··01-08).·········00037d40:·3132·2d30·3729·0a20·2020·2020·2020·2020··12-07).·········
00037d50:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul00037d50:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul
00037d60:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table00037d60:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table
00037d70:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h200037d70:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2
00037d80:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href00037d80:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href
00037d90:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg00037d90:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg
00037da0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_00037da0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
00037db0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy00037db0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy
Offset 15152, 130 lines modifiedOffset 15152, 130 lines modified
0003b2f0:·7461·2d74·6172·6765·743d·2223·6964·6d32··ta-target="#idm20003b2f0:·7461·2d74·6172·6765·743d·2223·6964·6d32··ta-target="#idm2
0003b300:·3733·3622·2074·6162·696e·6465·783d·2230··736"·tabindex="00003b300:·3733·3622·2074·6162·696e·6465·783d·2230··736"·tabindex="0
0003b310:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003b310:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003b320:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003b320:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003b330:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003b330:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003b340:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003b340:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003b350:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003b350:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003b360:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr0003b360:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B
 0003b370:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet
 0003b380:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003b390:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003b3a0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003b3b0:·2069·643d·2269·646d·3237·3336·223e·3c70···id="idm2736"><p
 0003b3c0:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack
 0003b3d0:·6167·6573·5d5d·0a6e·616d·6520·3d20·2261··ages]].name·=·"a
 0003b3e0:·6964·6522·0a76·6572·7369·6f6e·203d·2022··ide".version·=·"
0003b370:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003b380:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b390:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b3a0:·7365·2220·6964·3d22·6964·6d32·3733·3622··se"·id="idm2736" 
0003b3b0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003b3c0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003b3d0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003b3e0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003b3f0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003b400:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003b410:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b420:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003b430:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b440:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003b450:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003b460:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003b470:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003b480:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003b490:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003b4a0:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed 
0003b4b0:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic 
0003b4c0:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer 
0003b4d0:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i 
0003b4e0:·6620·5b20·2120·2d66·202f·2e64·6f63·6b65··f·[·!·-f·/.docke 
0003b4f0:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp 
0003b500:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c 
0003b510:·6f6e·7461·696e·6572·656e·7620·5d3b·2074··ontainerenv·];·t 
0003b520:·6865·6e0a·0a44·4542·4941·4e5f·4652·4f4e··hen..DEBIAN_FRON 
0003b530:·5445·4e44·3d6e·6f6e·696e·7465·7261·6374··TEND=noninteract 
0003b540:·6976·6520·6170·742d·6765·7420·696e·7374··ive·apt-get·inst 
0003b550:·616c·6c20·2d79·2022·6169·6465·220a·0a65··all·-y·"aide"..e 
0003b560:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp 
0003b570:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia 
0003b580:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl 
0003b590:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing· 
0003b5a0:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c 
0003b5b0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003b5c0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003b5d0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003b5e0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003b5f0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003b600:·6964·6d32·3733·3722·2074·6162·696e·6465··idm2737"·tabinde 
0003b610:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003b620:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003b630:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003b640:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003b650:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003b660:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib 
0003b670:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</ 
0003b680:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003b690:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003b6a0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003b6b0:·646d·3237·3337·223e·3c74·6162·6c65·2063··dm2737"><table·c 
0003b6c0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003b6d0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003b6e0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003b6f0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003b700:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003b710:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b720:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003b730:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003b740:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b750:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003b760:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0003b770:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003b780:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003b790:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003b7a0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003b7b0:·2d20·6e61·6d65·3a20·456e·7375·7265·2061··-·name:·Ensure·a 
0003b7c0:·6964·6520·6973·2069·6e73·7461·6c6c·6564··ide·is·installed 
0003b7d0:·0a20·2070·6163·6b61·6765·3a0a·2020·2020··.··package:.···· 
0003b7e0:·6e61·6d65·3a20·6169·6465·0a20·2020·2073··name:·aide.····s 
0003b7f0:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.·· 
0003b800:·7768·656e·3a20·616e·7369·626c·655f·7669··when:·ansible_vi 
0003b810:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ 
0003b820:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke 
0003b830:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open 
0003b840:·767a·222c·2022·706f·646d·616e·222c·2022··vz",·"podman",·" 
0003b850:·636f·6e74·6169·6e65·7222·5d0a·2020·7461··container"].··ta 
0003b860:·6773·3a0a·2020·2d20·434a·4953·2d35·2e31··gs:.··-·CJIS-5.1 
0003b870:·302e·312e·330a·2020·2d20·4449·5341·2d53··0.1.3.··-·DISA-S 
0003b880:·5449·472d·5542·5455·2d32·302d·3031·3034··TIG-UBTU-20-0104 
0003b890:·3530·0a20·202d·204e·4953·542d·3830·302d··50.··-·NIST-800- 
0003b8a0:·3533·2d43·4d2d·3628·6129·0a20·202d·2050··53-CM-6(a).··-·P 
0003b8b0:·4349·2d44·5353·2d52·6571·2d31·312e·350a··CI-DSS-Req-11.5. 
0003b8c0:·2020·2d20·5043·492d·4453·5376·342d·3131····-·PCI-DSSv4-11 
0003b8d0:·2e35·2e32·0a20·202d·2065·6e61·626c·655f··.5.2.··-·enable_ 
0003b8e0:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low 
0003b8f0:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-· 
0003b900:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.· 
0003b910:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi 
0003b920:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot 
0003b930:·5f6e·6565·6465·640a·2020·2d20·7061·636b··_needed.··-·pack 
0003b940:·6167·655f·6169·6465·5f69·6e73·7461·6c6c··age_aide_install 
Max diff block lines reached; 18803321/18821177 bytes (99.91%) of diff not shown.
1.65 MB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Ubuntu·20.04·Level·2·Workstation·Benchmark38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Ubuntu·20.04·Level·2·Workstation·Benchmark
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_level2_workstation39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_level2_workstation
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~
42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
43 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8443 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
49 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r49 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
50 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n50 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
51 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g51 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 135, 27 lines modifiedOffset 135, 19 lines modified
135 include·install_aide135 include·install_aide
  
136 class·install_aide·{136 class·install_aide·{
137 ··package·{·'aide':137 ··package·{·'aide':
138 ····ensure·=>·'installed',138 ····ensure·=>·'installed',
139 ··}139 ··}
140 }140 }
 141 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
141 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
142 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
143 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
144 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
145 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
146 #·Remediation·is·applicable·only·in·certain·platforms 
147 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
148 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide" 
  
149 else 
150 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
151 fi142 [[packages]]
 143 name·=·"aide"
 144 version·=·"*"
152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
153 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
154 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
155 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
156 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
157 -·name:·Ensure·aide·is·installed150 -·name:·Ensure·aide·is·installed
158 ··package:151 ··package:
Offset 170, 19 lines modifiedOffset 162, 27 lines modified
170 ··-·PCI-DSSv4-11.5.2162 ··-·PCI-DSSv4-11.5.2
171 ··-·enable_strategy163 ··-·enable_strategy
172 ··-·low_complexity164 ··-·low_complexity
173 ··-·low_disruption165 ··-·low_disruption
174 ··-·medium_severity166 ··-·medium_severity
175 ··-·no_reboot_needed167 ··-·no_reboot_needed
176 ··-·package_aide_installed168 ··-·package_aide_installed
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 174 #·Remediation·is·applicable·only·in·certain·platforms
 175 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
178 [[packages]] 
179 name·=·"aide" 
180 version·=·"*"176 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide"
  
 177 else
 178 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 179 fi
181 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*180 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
182 Run·the·following·command·to·generate·a·new·database:181 Run·the·following·command·to·generate·a·new·database:
183 $·sudo·aideinit182 $·sudo·aideinit
184 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the183 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the
185 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide.wrapper·(or·hashes·of184 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide.wrapper·(or·hashes·of
186 these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about185 these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about
187 their·integrity.·The·newly-generated·database·can·be·installed·as·follows:186 their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 208, 40 lines modifiedOffset 208, 14 lines modified
208 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5208 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
209 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199209 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
210 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-20-010450210 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-20-010450
211 ············_\x8c_\x8i_\x8s············1.4.1211 ············_\x8c_\x8i_\x8s············1.4.1
212 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79212 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
213 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2213 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
214 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-238371r880913_rule214 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-238371r880913_rule
215 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
216 #·Remediation·is·applicable·only·in·certain·platforms 
217 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
218 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide" 
  
219 AIDE_CONFIG=/etc/aide/aide.conf 
220 DEFAULT_DB_PATH=/var/lib/aide/aide.db 
  
221 #·Fix·db·path·in·the·config·file,·if·necessary 
222 if·!·grep·-q·'^database=file:'·${AIDE_CONFIG};·then 
223 ····#·replace_or_append·gets·confused·by·'database=file'·as·a·key,·so·should·not·be·used. 
224 ····#replace_or_append·"${AIDE_CONFIG}"·'^database=file'·"${DEFAULT_DB_PATH}"·'@CCENUM@'·'%s:%s' 
225 ····echo·"database=file:${DEFAULT_DB_PATH}"·>>·${AIDE_CONFIG} 
226 fi 
  
227 #·Fix·db·out·path·in·the·config·file,·if·necessary 
228 if·!·grep·-q·'^database_out=file:'·${AIDE_CONFIG};·then 
229 ····echo·"database_out=file:${DEFAULT_DB_PATH}.new"·>>·${AIDE_CONFIG} 
230 fi 
  
231 /usr/sbin/aideinit·-y·-f 
  
232 else 
233 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
234 fi 
235 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8215 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
236 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low216 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
237 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low217 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
238 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false218 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
239 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict219 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
240 -·name:·Build·and·Test·AIDE·Database·-·Ensure·AIDE·Is·Installed220 -·name:·Build·and·Test·AIDE·Database·-·Ensure·AIDE·Is·Installed
241 ··ansible.builtin.apt:221 ··ansible.builtin.apt:
Offset 404, 14 lines modifiedOffset 378, 40 lines modified
404 ··-·PCI-DSSv4-11.5.2378 ··-·PCI-DSSv4-11.5.2
405 ··-·aide_build_database379 ··-·aide_build_database
406 ··-·low_complexity380 ··-·low_complexity
407 ··-·low_disruption381 ··-·low_disruption
408 ··-·medium_severity382 ··-·medium_severity
409 ··-·no_reboot_needed383 ··-·no_reboot_needed
410 ··-·restrict_strategy384 ··-·restrict_strategy
 385 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 386 #·Remediation·is·applicable·only·in·certain·platforms
Max diff block lines reached; 1726046/1732691 bytes (99.62%) of diff not shown.
1.16 MB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-standard.html
    
Offset 14288, 15 lines modifiedOffset 14288, 15 lines modified
00037cf0:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur00037cf0:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur
00037d00:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s00037d00:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s
00037d10:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st00037d10:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st
00037d20:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li00037d20:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li
00037d30:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</00037d30:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</
00037d40:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········00037d40:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········
00037d50:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·00037d50:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·
00037d60:·6f66·2032·3032·362d·3031·2d30·3829·0a20··of·2026-01-08).·00037d60:·6f66·2032·3032·342d·3132·2d30·3729·0a20··of·2024-12-07).·
00037d70:·2020·2020·2020·2020·2020·2020·2020·203c·················<00037d70:·2020·2020·2020·2020·2020·2020·2020·203c·················<
00037d80:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><00037d80:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><
00037d90:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont00037d90:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont
00037da0:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li00037da0:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li
00037db0:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf00037db0:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf
00037dc0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.00037dc0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.
00037dd0:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy00037dd0:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy
Offset 16561, 741 lines modifiedOffset 16561, 741 lines modified
00040b00:·612d·7461·7267·6574·3d22·2369·646d·3131··a-target="#idm1100040b00:·612d·7461·7267·6574·3d22·2369·646d·3131··a-target="#idm11
00040b10:·3037·3222·2074·6162·696e·6465·783d·2230··072"·tabindex="000040b10:·3037·3222·2074·6162·696e·6465·783d·2230··072"·tabindex="0
00040b20:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·00040b20:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
00040b30:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f00040b30:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
00040b40:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act00040b40:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
00040b50:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"00040b50:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
Diff chunk too large, falling back to line-by-line diff (727 lines added, 727 lines removed)
00040b60:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed00040b60:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
00040b70:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr00040b70:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s
00040b80:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><00040b80:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
00040b90:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel00040b90:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
00040ba0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap00040ba0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
00040bb0:·7365·2220·6964·3d22·6964·6d31·3130·3732··se"·id="idm1107200040bb0:·6c61·7073·6522·2069·643d·2269·646d·3131··lapse"·id="idm11
00040bc0:·223e·3c70·7265·3e3c·636f·6465·3e23·2052··"><pre><code>#·R00040bc0:·3037·3222·3e3c·7461·626c·6520·636c·6173··072"><table·clas
00040bd0:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap00040bd0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
00040be0:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in00040be0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
00040bf0:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor00040bf0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
00040c00:·6d73·0a69·6620·5b20·2120·2d66·202f·2e64··ms.if·[·!·-f·/.d00040c00:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
00040c10:·6f63·6b65·7265·6e76·205d·2026·616d·703b··ockerenv·]·&amp;00040c10:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
00040c20:·2661·6d70·3b20·5b20·2120·2d66·202f·7275··&amp;·[·!·-f·/ru00040c20:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
00040c30:·6e2f·2e63·6f6e·7461·696e·6572·656e·7620··n/.containerenv·00040c30:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
00040c40:·5d3b·2074·6865·6e0a·0a23·204c·6973·7420··];·then..#·List·00040c40:·6f6e·3a3c·2f74·683e·3c74·643e·6d65·6469··on:</th><td>medi
00040c50:·6f66·206c·6f67·2066·696c·6520·7061·7468··of·log·file·path00040c50:·756d·3c2f·7464·3e3c·2f74·723e·3c74·723e··um</td></tr><tr>
00040c60:·7320·746f·2062·6520·696e·7370·6563·7465··s·to·be·inspecte00040c60:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
00040c70:·6420·666f·7220·636f·7272·6563·7420·7065··d·for·correct·pe00040c70:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
00040c80:·726d·6973·7369·6f6e·730a·2320·2a20·5072··rmissions.#·*·Pr00040c80:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
00040c90:·696d·6172·696c·7920·696e·7370·6563·7420··imarily·inspect·00040c90:·6567·793a·3c2f·7468·3e3c·7464·3e63·6f6e··egy:</th><td>con
00040ca0:·6c6f·6720·6669·6c65·2070·6174·6873·206c··log·file·paths·l00040ca0:·6669·6775·7265·3c2f·7464·3e3c·2f74·723e··figure</td></tr>
00040cb0:·6973·7465·6420·696e·202f·6574·632f·7273··isted·in·/etc/rs00040cb0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
00040cc0:·7973·6c6f·672e·636f·6e66·0a52·5359·534c··yslog.conf.RSYSL00040cc0:·6465·3e2d·206e·616d·653a·2045·6e73·7572··de>-·name:·Ensur
00040cd0:·4f47·5f45·5443·5f43·4f4e·4649·473d·222f··OG_ETC_CONFIG="/00040cd0:·6520·4c6f·6720·4669·6c65·7320·4172·6520··e·Log·Files·Are·
00040ce0:·6574·632f·7273·7973·6c6f·672e·636f·6e66··etc/rsyslog.conf00040ce0:·4f77·6e65·6420·4279·2041·7070·726f·7072··Owned·By·Appropr
00040cf0:·220a·2320·2a20·416e·6420·616c·736f·2074··".#·*·And·also·t00040cf0:·6961·7465·2047·726f·7570·202d·2053·6574··iate·Group·-·Set
00040d00:·6865·206c·6f67·2066·696c·6520·7061·7468··he·log·file·path00040d00:·2072·7379·736c·6f67·206c·6f67·6669·6c65···rsyslog·logfile
00040d10:·7320·6c69·7374·6564·2061·6674·6572·2072··s·listed·after·r00040d10:·2063·6f6e·6669·6775·7261·7469·6f6e·0a20···configuration.·
00040d20:·7379·736c·6f67·2773·2024·496e·636c·7564··syslog's·$Includ00040d20:·2020·2066·6163·7473·0a20·2061·6e73·6962·····facts.··ansib
00040d30:·6543·6f6e·6669·6720·6469·7265·6374·6976··eConfig·directiv00040d30:·6c65·2e62·7569·6c74·696e·2e73·6574·5f66··le.builtin.set_f
00040d40:·650a·2320·2020·2873·746f·7265·2074·6865··e.#···(store·the00040d40:·6163·743a·0a20·2020·2072·7379·736c·6f67··act:.····rsyslog
00040d50:·2072·6573·756c·7420·696e·746f·2061·7272···result·into·arr00040d50:·5f65·7463·5f63·6f6e·6669·673a·202f·6574··_etc_config:·/et
00040d60:·6179·2066·6f72·2074·6865·2063·6173·6520··ay·for·the·case·00040d60:·632f·7273·7973·6c6f·672e·636f·6e66·0a20··c/rsyslog.conf.·
00040d70:·7468·6572·6527·7320·7368·656c·6c20·676c··there's·shell·gl00040d70:·2077·6865·6e3a·2061·6e73·6962·6c65·5f76···when:·ansible_v
00040d80:·6f62·2075·7365·6420·6173·2076·616c·7565··ob·used·as·value00040d80:·6972·7475·616c·697a·6174·696f·6e5f·7479··irtualization_ty
00040d90:·206f·6620·496e·636c·7564·6543·6f6e·6669···of·IncludeConfi00040d90:·7065·206e·6f74·2069·6e20·5b22·646f·636b··pe·not·in·["dock
00040da0:·6729·0a72·6561·6461·7272·6179·202d·7420··g).readarray·-t·00040da0:·6572·222c·2022·6c78·6322·2c20·226f·7065··er",·"lxc",·"ope
00040db0:·4f4c·445f·494e·4320·266c·743b·2026·6c74··OLD_INC·&lt;·&lt00040db0:·6e76·7a22·2c20·2270·6f64·6d61·6e22·2c20··nvz",·"podman",·
00040dc0:·3b28·6772·6570·202d·6520·225c·2449·6e63··;(grep·-e·"\$Inc00040dc0:·2263·6f6e·7461·696e·6572·225d·0a20·2074··"container"].··t
00040dd0:·6c75·6465·436f·6e66·6967·5b5b·3a73·7061··ludeConfig[[:spa00040dd0:·6167·733a·0a20·202d·204e·4953·542d·3830··ags:.··-·NIST-80
00040de0:·6365·3a5d·5d5c·2b5b·5e5b·3a73·7061·6365··ce:]]\+[^[:space00040de0:·302d·3533·2d41·432d·3628·3129·0a20·202d··0-53-AC-6(1).··-
00040df0:·3a5d·3b5d·5c2b·2220·2f65·7463·2f72·7379··:];]\+"·/etc/rsy00040df0:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-
00040e00:·736c·6f67·2e63·6f6e·6620·7c20·6375·7420··slog.conf·|·cut·00040e00:·3628·6129·0a20·202d·2050·4349·2d44·5353··6(a).··-·PCI-DSS
00040e10:·2d64·2027·2027·202d·6620·3229·0a72·6561··-d·'·'·-f·2).rea00040e10:·2d52·6571·2d31·302e·352e·310a·2020·2d20··-Req-10.5.1.··-·
00040e20:·6461·7272·6179·202d·7420·5253·5953·4c4f··darray·-t·RSYSLO00040e20:·5043·492d·4453·532d·5265·712d·3130·2e35··PCI-DSS-Req-10.5
00040e30:·475f·494e·434c·5544·455f·434f·4e46·4947··G_INCLUDE_CONFIG00040e30:·2e32·0a20·202d·2050·4349·2d44·5353·7634··.2.··-·PCI-DSSv4
00040e40:·2026·6c74·3b20·266c·743b·2866·6f72·2049···&lt;·&lt;(for·I00040e40:·2d31·302e·332e·320a·2020·2d20·636f·6e66··-10.3.2.··-·conf
00040e50:·4e43·5041·5448·2069·6e20·2224·7b4f·4c44··NCPATH·in·"${OLD00040e50:·6967·7572·655f·7374·7261·7465·6779·0a20··igure_strategy.·
00040e60:·5f49·4e43·5b40·5d7d·223b·2064·6f20·6576··_INC[@]}";·do·ev00040e60:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit
00040e70:·616c·2070·7269·6e74·6620·2725·735c·5c6e··al·printf·'%s\\n00040e70:·790a·2020·2d20·6d65·6469·756d·5f64·6973··y.··-·medium_dis
00040e80:·2720·2224·7b49·4e43·5041·5448·7d22·3b20··'·"${INCPATH}";·00040e80:·7275·7074·696f·6e0a·2020·2d20·6d65·6469··ruption.··-·medi
00040e90:·646f·6e65·290a·7265·6164·6172·7261·7920··done).readarray·00040e90:·756d·5f73·6576·6572·6974·790a·2020·2d20··um_severity.··-·
00040ea0:·2d74·204e·4557·5f49·4e43·2026·6c74·3b20··-t·NEW_INC·&lt;·00040ea0:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed
00040eb0:·266c·743b·2873·6564·202d·6e20·272f·5e5c··&lt;(sed·-n·'/^\00040eb0:·0a20·202d·2072·7379·736c·6f67·5f66·696c··.··-·rsyslog_fil
00040ec0:·732a·696e·636c·7564·6528·2f2c·2f29·2f49··s*include(/,/)/I00040ec0:·6573·5f67·726f·7570·6f77·6e65·7273·6869··es_groupownershi
00040ed0:·7027·202f·6574·632f·7273·7973·6c6f·672e··p'·/etc/rsyslog.00040ed0:·700a·0a2d·206e·616d·653a·2045·6e73·7572··p..-·name:·Ensur
00040ee0:·636f·6e66·207c·2073·6564·202d·6e20·2773··conf·|·sed·-n·'s00040ee0:·6520·4c6f·6720·4669·6c65·7320·4172·6520··e·Log·Files·Are·
00040ef0:·402e·2a66·696c·655c·732a·3d5c·732a·225c··@.*file\s*=\s*"\00040ef0:·4f77·6e65·6420·4279·2041·7070·726f·7072··Owned·By·Appropr
00040f00:·285b·2f5b·3a61·6c6e·756d·3a5d·5b3a·7075··([/[:alnum:][:pu00040f00:·6961·7465·2047·726f·7570·202d·2047·6574··iate·Group·-·Get
00040f10:·6e63·743a·5d5d·2a5c·2922·2e2a·405c·3140··nct:]]*\)".*@\1@00040f10:·2049·6e63·6c75·6465·436f·6e66·6967·2064···IncludeConfig·d
00040f20:·4970·2729·0a72·6561·6461·7272·6179·202d··Ip').readarray·-00040f20:·6972·6563·7469·7665·0a20·2061·6e73·6962··irective.··ansib
00040f30:·7420·5253·5953·4c4f·475f·494e·434c·5544··t·RSYSLOG_INCLUD00040f30:·6c65·2e62·7569·6c74·696e·2e73·6865·6c6c··le.builtin.shell
00040f40:·4520·266c·743b·2026·6c74·3b28·666f·7220··E·&lt;·&lt;(for·00040f40:·3a20·7c0a·2020·2020·7365·7420·2d6f·2070··:·|.····set·-o·p
00040f50:·494e·4350·4154·4820·696e·2022·247b·4e45··INCPATH·in·"${NE00040f50:·6970·6566·6169·6c0a·2020·2020·6772·6570··ipefail.····grep
00040f60:·575f·494e·435b·405d·7d22·3b20·646f·2065··W_INC[@]}";·do·e00040f60:·202d·6520·2724·496e·636c·7564·6543·6f6e···-e·'$IncludeCon
00040f70:·7661·6c20·7072·696e·7466·2027·2573·5c5c··val·printf·'%s\\00040f70:·6669·6727·207b·7b20·7273·7973·6c6f·675f··fig'·{{·rsyslog_
00040f80:·6e27·2022·247b·494e·4350·4154·487d·223b··n'·"${INCPATH}";00040f80:·6574·635f·636f·6e66·6967·207d·7d20·7c20··etc_config·}}·|·
00040f90:·2064·6f6e·6529·0a0a·2320·4465·636c·6172···done)..#·Declar00040f90:·6375·7420·2d64·2027·2027·202d·6620·3220··cut·-d·'·'·-f·2·
00040fa0:·6520·616e·2061·7272·6179·2074·6f20·686f··e·an·array·to·ho00040fa0:·7c7c·2074·7275·650a·2020·7265·6769·7374··||·true.··regist
00040fb0:·6c64·2074·6865·2066·696e·616c·206c·6973··ld·the·final·lis00040fb0:·6572·3a20·7273·7973·6c6f·675f·6f6c·645f··er:·rsyslog_old_
00040fc0:·7420·6f66·2064·6966·6665·7265·6e74·206c··t·of·different·l00040fc0:·696e·630a·2020·6368·616e·6765·645f·7768··inc.··changed_wh
00040fd0:·6f67·2066·696c·6520·7061·7468·730a·6465··og·file·paths.de00040fd0:·656e·3a20·6661·6c73·650a·2020·7768·656e··en:·false.··when
00040fe0:·636c·6172·6520·2d61·204c·4f47·5f46·494c··clare·-a·LOG_FIL00040fe0:·3a20·616e·7369·626c·655f·7669·7274·7561··:·ansible_virtua
00040ff0:·455f·5041·5448·530a·0a23·2041·7272·6179··E_PATHS..#·Array00040ff0:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no
00041000:·2074·6f20·686f·6c64·2061·6c6c·2072·7379···to·hold·all·rsy00041000:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",·
00041010:·736c·6f67·2063·6f6e·6669·6720·656e·7472··slog·config·entr00041010:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz",
00041020:·6965·730a·5253·5953·4c4f·475f·434f·4e46··ies.RSYSLOG_CONF00041020:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont
00041030:·4947·533d·2829·0a52·5359·534c·4f47·5f43··IGS=().RSYSLOG_C00041030:·6169·6e65·7222·5d0a·2020·7461·6773·3a0a··ainer"].··tags:.
00041040:·4f4e·4649·4753·3d28·2224·7b52·5359·534c··ONFIGS=("${RSYSL00041040:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
00041050:·4f47·5f45·5443·5f43·4f4e·4649·477d·2220··OG_ETC_CONFIG}"·00041050:·4143·2d36·2831·290a·2020·2d20·4e49·5354··AC-6(1).··-·NIST
00041060:·2224·7b52·5359·534c·4f47·5f49·4e43·4c55··"${RSYSLOG_INCLU00041060:·2d38·3030·2d35·332d·434d·2d36·2861·290a··-800-53-CM-6(a).
00041070:·4445·5f43·4f4e·4649·475b·405d·7d22·2022··DE_CONFIG[@]}"·"00041070:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req-
00041080:·247b·5253·5953·4c4f·475f·494e·434c·5544··${RSYSLOG_INCLUD00041080:·3130·2e35·2e31·0a20·202d·2050·4349·2d44··10.5.1.··-·PCI-D
00041090:·455b·405d·7d22·290a·0a23·2047·6574·2066··E[@]}")..#·Get·f00041090:·5353·2d52·6571·2d31·302e·352e·320a·2020··SS-Req-10.5.2.··
000410a0:·756c·6c20·6c69·7374·206f·6620·6669·6c65··ull·list·of·file000410a0:·2d20·5043·492d·4453·5376·342d·3130·2e33··-·PCI-DSSv4-10.3
000410b0:·7320·746f·2062·6520·6368·6563·6b65·640a··s·to·be·checked.000410b0:·2e32·0a20·202d·2063·6f6e·6669·6775·7265··.2.··-·configure
000410c0:·2320·5253·5953·4c4f·475f·434f·4e46·4947··#·RSYSLOG_CONFIG000410c0:·5f73·7472·6174·6567·790a·2020·2d20·6c6f··_strategy.··-·lo
000410d0:·5320·6d61·7920·636f·6e74·6169·6e20·676c··S·may·contain·gl000410d0:·775f·636f·6d70·6c65·7869·7479·0a20·202d··w_complexity.··-
000410e0:·6f62·7320·7375·6368·2061·730a·2320·2f65··obs·such·as.#·/e000410e0:·206d·6564·6975·6d5f·6469·7372·7570·7469···medium_disrupti
000410f0:·7463·2f72·7379·736c·6f67·2e64·2f2a·2e63··tc/rsyslog.d/*.c000410f0:·6f6e·0a20·202d·206d·6564·6975·6d5f·7365··on.··-·medium_se
00041100:·6f6e·6620·2f65·7463·2f72·7379·736c·6f67··onf·/etc/rsyslog00041100:·7665·7269·7479·0a20·202d·206e·6f5f·7265··verity.··-·no_re
00041110:·2e64·2f2a·2e66·7275·6c65·0a23·2053·6f2c··.d/*.frule.#·So,00041110:·626f·6f74·5f6e·6565·6465·640a·2020·2d20··boot_needed.··-·
00041120:·206c·6f6f·7020·6f76·6572·2074·6865·2065···loop·over·the·e00041120:·7273·7973·6c6f·675f·6669·6c65·735f·6772··rsyslog_files_gr
00041130:·6e74·7269·6573·2069·6e20·5253·5953·4c4f··ntries·in·RSYSLO00041130:·6f75·706f·776e·6572·7368·6970·0a0a·2d20··oupownership..-·
00041140:·475f·434f·4e46·4947·5320·616e·6420·7573··G_CONFIGS·and·us00041140:·6e61·6d65·3a20·456e·7375·7265·204c·6f67··name:·Ensure·Log
00041150:·6520·6669·6e64·2074·6f20·6765·7420·7468··e·find·to·get·th00041150:·2046·696c·6573·2041·7265·204f·776e·6564···Files·Are·Owned
00041160:·6520·6c69·7374·206f·6620·696e·636c·7564··e·list·of·includ00041160:·2042·7920·4170·7072·6f70·7269·6174·6520···By·Appropriate·
00041170:·6564·2066·696c·6573·2e0a·5253·5953·4c4f··ed·files..RSYSLO00041170:·4772·6f75·7020·2d20·4765·7420·696e·636c··Group·-·Get·incl
00041180:·475f·434f·4e46·4947·5f46·494c·4553·3d28··G_CONFIG_FILES=(00041180:·7564·6520·6669·6c65·7320·6469·7265·6374··ude·files·direct
00041190:·290a·666f·7220·454e·5452·5920·696e·2022··).for·ENTRY·in·"00041190:·6976·6573·0a20·2061·6e73·6962·6c65·2e62··ives.··ansible.b
000411a0:·247b·5253·5953·4c4f·475f·434f·4e46·4947··${RSYSLOG_CONFIG000411a0:·7569·6c74·696e·2e73·6865·6c6c·3a20·7c0a··uiltin.shell:·|.
000411b0:·535b·405d·7d22·0a64·6f0a·0923·2049·6620··S[@]}".do..#·If·000411b0:·2020·2020·7365·7420·2d6f·2070·6970·6566······set·-o·pipef
000411c0:·6469·7265·6374·6f72·792c·2072·7379·736c··directory,·rsysl000411c0:·6169·6c0a·2020·2020·6177·6b20·272f·292f··ail.····awk·'/)/
000411d0:·6f67·2077·696c·6c20·7365·6172·6368·2066··og·will·search·f000411d0:·7b66·3d30·7d20·2f69·6e63·6c75·6465·5c28··{f=0}·/include\(
Max diff block lines reached; 978210/1080246 bytes (90.55%) of diff not shown.
130 KB
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Ubuntu·20.0439 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Ubuntu·20.04
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard
41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
42 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~42 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~
43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
44 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8444 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
49 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l49 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
51 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s51 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
52 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s52 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
Offset 289, 137 lines modifiedOffset 289, 14 lines modified
289 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······007-3·R2.1,·CIP-007-3·R2.2,·CIP-007-3·R2.3,·CIP-007-289 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······007-3·R2.1,·CIP-007-3·R2.2,·CIP-007-3·R2.3,·CIP-007-
290 ···························3·R5.1,·CIP-007-3·R5.1.1,·CIP-007-3·R5.1.2290 ···························3·R5.1,·CIP-007-3·R5.1.1,·CIP-007-3·R5.1.2
291 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)291 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)
292 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5292 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5
293 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.5.1,·Req-10.5.2293 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.5.1,·Req-10.5.2
294 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71294 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71
295 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.3.2295 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.3.2
296 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
297 #·Remediation·is·applicable·only·in·certain·platforms 
298 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
299 #·List·of·log·file·paths·to·be·inspected·for·correct·permissions 
300 #·*·Primarily·inspect·log·file·paths·listed·in·/etc/rsyslog.conf 
301 RSYSLOG_ETC_CONFIG="/etc/rsyslog.conf" 
302 #·*·And·also·the·log·file·paths·listed·after·rsyslog's·$IncludeConfig·directive 
303 #···(store·the·result·into·array·for·the·case·there's·shell·glob·used·as·value·of 
304 IncludeConfig) 
305 readarray·-t·OLD_INC·<·<(grep·-e·"\$IncludeConfig[[:space:]]\+[^[:space:];]\+"·/ 
306 etc/rsyslog.conf·|·cut·-d·'·'·-f·2) 
307 readarray·-t·RSYSLOG_INCLUDE_CONFIG·<·<(for·INCPATH·in·"${OLD_INC[@]}";·do·eval 
308 printf·'%s\\n'·"${INCPATH}";·done) 
309 readarray·-t·NEW_INC·<·<(sed·-n·'/^\s*include(/,/)/Ip'·/etc/rsyslog.conf·|·sed·- 
310 n·'s@.*file\s*=\s*"\([/[:alnum:][:punct:]]*\)".*@\1@Ip') 
311 readarray·-t·RSYSLOG_INCLUDE·<·<(for·INCPATH·in·"${NEW_INC[@]}";·do·eval·printf 
312 '%s\\n'·"${INCPATH}";·done) 
  
313 #·Declare·an·array·to·hold·the·final·list·of·different·log·file·paths 
314 declare·-a·LOG_FILE_PATHS 
  
315 #·Array·to·hold·all·rsyslog·config·entries 
316 RSYSLOG_CONFIGS=() 
317 RSYSLOG_CONFIGS=("${RSYSLOG_ETC_CONFIG}"·"${RSYSLOG_INCLUDE_CONFIG[@]}"·"$ 
318 {RSYSLOG_INCLUDE[@]}") 
  
319 #·Get·full·list·of·files·to·be·checked 
320 #·RSYSLOG_CONFIGS·may·contain·globs·such·as 
321 #·/etc/rsyslog.d/*.conf·/etc/rsyslog.d/*.frule 
322 #·So,·loop·over·the·entries·in·RSYSLOG_CONFIGS·and·use·find·to·get·the·list·of 
323 included·files. 
324 RSYSLOG_CONFIG_FILES=() 
325 for·ENTRY·in·"${RSYSLOG_CONFIGS[@]}" 
326 do 
327 »       #·If·directory,·rsyslog·will·search·for·config·files·in·recursively. 
328 »       #·However,·files·in·hidden·sub-directories·or·hidden·files·will·be·ignored. 
329 »       if·[·-d·"${ENTRY}"·] 
330 »       then 
331 »       »       readarray·-t·FINDOUT·<·<(find·"${ENTRY}"·-not·-path·'*/.*'·-type·f) 
332 »       »       RSYSLOG_CONFIG_FILES+=("${FINDOUT[@]}") 
333 »       elif·[·-f·"${ENTRY}"·] 
334 »       then 
335 »       »       RSYSLOG_CONFIG_FILES+=("${ENTRY}") 
336 »       else 
337 »       »       echo·"Invalid·include·object:·${ENTRY}" 
338 »       fi 
339 done 
  
340 #·Browse·each·file·selected·above·as·containing·paths·of·log·files 
341 #·('/etc/rsyslog.conf'·and·'/etc/rsyslog.d/*.conf'·in·the·default·configuration) 
342 for·LOG_FILE·in·"${RSYSLOG_CONFIG_FILES[@]}" 
343 do 
344 »       #·From·each·of·these·files·extract·just·particular·log·file·path(s),·thus: 
345 »       #·*·Ignore·lines·starting·with·space·('·'),·comment·('#"),·or·variable·syntax 
346 ('$')·characters, 
347 »       #·*·Ignore·empty·lines, 
348 »       #·*·Strip·quotes·and·closing·brackets·from·paths. 
349 »       #·*·Ignore·paths·that·match·/dev|/etc.*\.conf,·as·those·are·paths,·but·likely 
350 not·log·files 
351 »       #·*·From·the·remaining·valid·rows·select·only·fields·constituting·a·log·file 
352 path 
353 »       #·Text·file·column·is·understood·to·represent·a·log·file·path·if·and·only·if·all 
354 of·the 
355 »       #·following·are·met: 
356 »       #·*·it·contains·at·least·one·slash·'/'·character, 
357 »       #·*·it·is·preceded·by·space 
358 »       #·*·it·doesn't·contain·space·('·'),·colon·(':'),·and·semicolon·(';')·characters 
359 »       #·Search·log·file·for·path(s)·only·in·case·it·exists! 
360 »       if·[[·-f·"${LOG_FILE}"·]] 
361 »       then 
362 »       »       NORMALIZED_CONFIG_FILE_LINES=$(sed·-e·"/^[#|$]/d"·"${LOG_FILE}") 
363 »       »       LINES_WITH_PATHS=$(grep·'[^/]*\s\+\S*/\S\+$'·<<<·"$ 
364 {NORMALIZED_CONFIG_FILE_LINES}") 
365 »       »       FILTERED_PATHS=$(awk·'{if(NF>=2&&($NF~/^\//||$NF~/^-\//)){sub(/^-\//,"/ 
366 ",$NF);print·$NF}}'·<<<·"${LINES_WITH_PATHS}") 
367 »       »       CLEANED_PATHS=$(sed·-e·"s/[\"')]//g;·/\\/etc.*\.conf/d;·/\\/dev\\//d"·<<<·"$ 
368 {FILTERED_PATHS}") 
369 »       »       MATCHED_ITEMS=$(sed·-e·"/^$/d"·<<<·"${CLEANED_PATHS}") 
370 »       »       #·Since·above·sed·command·might·return·more·than·one·item·(delimited·by 
371 newline),·split 
372 »       »       #·the·particular·matches·entries·into·new·array·specific·for·this·log·file 
373 »       »       readarray·-t·ARRAY_FOR_LOG_FILE·<<<·"$MATCHED_ITEMS" 
374 »       »       #·Concatenate·the·two·arrays·-·previous·content·of·$LOG_FILE_PATHS·array·with 
375 »       »       #·items·from·newly·created·array·for·this·log·file 
376 »       »       LOG_FILE_PATHS+=("${ARRAY_FOR_LOG_FILE[@]}") 
377 »       »       #·Delete·the·temporary·array 
378 »       »       unset·ARRAY_FOR_LOG_FILE 
379 »       fi 
380 done 
  
381 #·Check·for·RainerScript·action·log·format·which·might·be·also·multiline·so·grep 
382 regex·is·a·bit 
383 #·curly: 
384 #·extract·possibly·multiline·action·omfile·expressions 
385 #·extract·File="logfile"·expression 
386 #·match·only·"logfile"·expression 
387 for·LOG_FILE·in·"${RSYSLOG_CONFIG_FILES[@]}" 
388 do 
389 »       ACTION_OMFILE_LINES=$(grep·-iozP·"action\s*\(\s*type\s*=\s*\"omfile\"[^\)]*\)" 
390 "${LOG_FILE}") 
391 »       OMFILE_LINES=$(echo·"${ACTION_OMFILE_LINES}"|·grep·-iaoP·"\bFile\s*=\s*\"([/[: 
392 alnum:][:punct:]]*)\"\s*\)") 
393 »       LOG_FILE_PATHS+=("$(echo·"${OMFILE_LINES}"|·grep·-oE·"\"([/[:alnum:][:punct: 
Max diff block lines reached; 126531/133137 bytes (95.04%) of diff not shown.
17.4 MB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-stig.html
    
Offset 14298, 15 lines modifiedOffset 14298, 15 lines modified
00037d90:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur00037d90:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur
00037da0:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s00037da0:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s
00037db0:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st00037db0:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st
00037dc0:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li00037dc0:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li
00037dd0:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</00037dd0:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</
00037de0:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········00037de0:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········
00037df0:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·00037df0:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·
00037e00:·6f66·2032·3032·362d·3031·2d30·3829·0a20··of·2026-01-08).·00037e00:·6f66·2032·3032·342d·3132·2d30·3729·0a20··of·2024-12-07).·
00037e10:·2020·2020·2020·2020·2020·2020·2020·203c·················<00037e10:·2020·2020·2020·2020·2020·2020·2020·203c·················<
00037e20:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><00037e20:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><
00037e30:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont00037e30:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont
00037e40:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li00037e40:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li
00037e50:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf00037e50:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf
00037e60:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.00037e60:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.
00037e70:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy00037e70:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy
Offset 15111, 130 lines modifiedOffset 15111, 130 lines modified
0003b060:·612d·7461·7267·6574·3d22·2369·646d·3237··a-target="#idm270003b060:·612d·7461·7267·6574·3d22·2369·646d·3237··a-target="#idm27
0003b070:·3336·2220·7461·6269·6e64·6578·3d22·3022··36"·tabindex="0"0003b070:·3336·2220·7461·6269·6e64·6578·3d22·3022··36"·tabindex="0"
0003b080:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003b080:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003b090:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003b090:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003b0a0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003b0a0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003b0b0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003b0b0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003b0c0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003b0c0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003b0d0:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl
 0003b0e0:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet·
 0003b0f0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003b100:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003b110:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003b120:·6964·3d22·6964·6d32·3733·3622·3e3c·7072··id="idm2736"><pr
 0003b130:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa
 0003b140:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai
 0003b150:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"*
 0003b160:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre><
 0003b170:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0003b180:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0003b190:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0003b1a0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0003b1b0:·6574·3d22·2369·646d·3237·3337·2220·7461··et="#idm2737"·ta
 0003b1c0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 0003b1d0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 0003b1e0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 0003b1f0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 0003b200:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 0003b210:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003b220:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet·
 0003b230:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003b240:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003b250:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003b260:·6964·3d22·6964·6d32·3733·3722·3e3c·7461··id="idm2737"><ta
 0003b270:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0003b280:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0003b290:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0003b2a0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0003b2b0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0003b2c0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0003b2d0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b2e0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003b2f0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003b300:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 0003b310:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 0003b320:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b330:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0003b340:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0003b350:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003b360:·636f·6465·3e2d·206e·616d·653a·2045·6e73··code>-·name:·Ens
 0003b370:·7572·6520·6169·6465·2069·7320·696e·7374··ure·aide·is·inst
 0003b380:·616c·6c65·640a·2020·7061·636b·6167·653a··alled.··package:
 0003b390:·0a20·2020·206e·616d·653a·2061·6964·650a··.····name:·aide.
 0003b3a0:·2020·2020·7374·6174·653a·2070·7265·7365······state:·prese
 0003b3b0:·6e74·0a20·2077·6865·6e3a·2061·6e73·6962··nt.··when:·ansib
 0003b3c0:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio
 0003b3d0:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·["
 0003b3e0:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",·
 0003b3f0:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma
 0003b400:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"]
 0003b410:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI
 0003b420:·532d·352e·3130·2e31·2e33·0a20·202d·2044··S-5.10.1.3.··-·D
 0003b430:·4953·412d·5354·4947·2d55·4254·552d·3230··ISA-STIG-UBTU-20
 0003b440:·2d30·3130·3435·300a·2020·2d20·4e49·5354··-010450.··-·NIST
 0003b450:·2d38·3030·2d35·332d·434d·2d36·2861·290a··-800-53-CM-6(a).
 0003b460:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req-
 0003b470:·3131·2e35·0a20·202d·2050·4349·2d44·5353··11.5.··-·PCI-DSS
 0003b480:·7634·2d31·312e·352e·320a·2020·2d20·656e··v4-11.5.2.··-·en
 0003b490:·6162·6c65·5f73·7472·6174·6567·790a·2020··able_strategy.··
 0003b4a0:·2d20·6c6f·775f·636f·6d70·6c65·7869·7479··-·low_complexity
 0003b4b0:·0a20·202d·206c·6f77·5f64·6973·7275·7074··.··-·low_disrupt
 0003b4c0:·696f·6e0a·2020·2d20·6d65·6469·756d·5f73··ion.··-·medium_s
 0003b4d0:·6576·6572·6974·790a·2020·2d20·6e6f·5f72··everity.··-·no_r
 0003b4e0:·6562·6f6f·745f·6e65·6564·6564·0a20·202d··eboot_needed.··-
 0003b4f0:·2070·6163·6b61·6765·5f61·6964·655f·696e···package_aide_in
 0003b500:·7374·616c·6c65·640a·3c2f·636f·6465·3e3c··stalled.</code><
 0003b510:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003b520:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003b530:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003b540:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003b550:·612d·7461·7267·6574·3d22·2369·646d·3237··a-target="#idm27
 0003b560:·3338·2220·7461·6269·6e64·6578·3d22·3022··38"·tabindex="0"
 0003b570:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003b580:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003b590:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003b5a0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003b5b0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003b0d0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri0003b5c0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
0003b0e0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d0003b5d0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
0003b0f0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003b5e0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0003b100:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003b5f0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0003b110:·6522·2069·643d·2269·646d·3237·3336·223e··e"·id="idm2736">0003b600:·6522·2069·643d·2269·646d·3237·3338·223e··e"·id="idm2738">
0003b120:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003b610:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
0003b130:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003b620:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
0003b140:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003b630:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
0003b150:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003b640:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
0003b160:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003b650:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003b170:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003b660:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0003b180:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003b670:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003b190:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003b680:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
0003b1a0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003b690:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003b1b0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo0003b6a0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
0003b1c0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals0003b6b0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
0003b1d0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><0003b6c0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
0003b1e0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th0003b6d0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0003b1f0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>0003b6e0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
0003b200:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003b6f0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
0003b210:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi0003b700:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
0003b220:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica0003b710:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
0003b230:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert0003b720:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
0003b240:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if0003b730:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
0003b250:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker0003b740:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker
Max diff block lines reached; 17020122/17037840 bytes (99.90%) of diff not shown.
1.14 MB
html2text {}
    
Offset 41, 15 lines modifiedOffset 41, 15 lines modified
41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Canonical·Ubuntu·20.04·LTS·Security·Technical·Implementation41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Canonical·Ubuntu·20.04·LTS·Security·Technical·Implementation
42 ··············Guide·(STIG)·V1R1142 ··············Guide·(STIG)·V1R11
43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_stig43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_stig
44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
45 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~45 ····*·cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~
46 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
47 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8447 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
48 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)48 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
49 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*49 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
50 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s50 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
51 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e51 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
52 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l52 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
53 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r53 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
54 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n54 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
55 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g55 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 126, 27 lines modifiedOffset 126, 19 lines modified
126 include·install_aide126 include·install_aide
  
127 class·install_aide·{127 class·install_aide·{
128 ··package·{·'aide':128 ··package·{·'aide':
129 ····ensure·=>·'installed',129 ····ensure·=>·'installed',
130 ··}130 ··}
131 }131 }
 132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
137 #·Remediation·is·applicable·only·in·certain·platforms 
138 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
139 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide" 
  
140 else 
141 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
142 fi133 [[packages]]
 134 name·=·"aide"
 135 version·=·"*"
143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
144 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
145 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
146 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
147 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
148 -·name:·Ensure·aide·is·installed141 -·name:·Ensure·aide·is·installed
149 ··package:142 ··package:
Offset 161, 19 lines modifiedOffset 153, 27 lines modified
161 ··-·PCI-DSSv4-11.5.2153 ··-·PCI-DSSv4-11.5.2
162 ··-·enable_strategy154 ··-·enable_strategy
163 ··-·low_complexity155 ··-·low_complexity
164 ··-·low_disruption156 ··-·low_disruption
165 ··-·medium_severity157 ··-·medium_severity
166 ··-·no_reboot_needed158 ··-·no_reboot_needed
167 ··-·package_aide_installed159 ··-·package_aide_installed
168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 161 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 162 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 163 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 164 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 165 #·Remediation·is·applicable·only·in·certain·platforms
 166 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
169 [[packages]] 
170 name·=·"aide" 
171 version·=·"*"167 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide"
  
 168 else
 169 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 170 fi
172 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*171 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
173 Run·the·following·command·to·generate·a·new·database:172 Run·the·following·command·to·generate·a·new·database:
174 $·sudo·aideinit173 $·sudo·aideinit
175 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the174 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the
176 configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide.wrapper·(or·hashes·of·these·files),·in·a175 configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide.wrapper·(or·hashes·of·these·files),·in·a
177 secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The176 secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The
178 newly-generated·database·can·be·installed·as·follows:177 newly-generated·database·can·be·installed·as·follows:
Offset 199, 40 lines modifiedOffset 199, 14 lines modified
199 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5199 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
200 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199200 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
201 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-20-010450201 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-20-010450
202 ············_\x8c_\x8i_\x8s············1.4.1202 ············_\x8c_\x8i_\x8s············1.4.1
203 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79203 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
204 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2204 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
205 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-238371r880913_rule205 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-238371r880913_rule
206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
207 #·Remediation·is·applicable·only·in·certain·platforms 
208 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
209 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide" 
  
210 AIDE_CONFIG=/etc/aide/aide.conf 
211 DEFAULT_DB_PATH=/var/lib/aide/aide.db 
  
212 #·Fix·db·path·in·the·config·file,·if·necessary 
213 if·!·grep·-q·'^database=file:'·${AIDE_CONFIG};·then 
214 ····#·replace_or_append·gets·confused·by·'database=file'·as·a·key,·so·should·not·be·used. 
215 ····#replace_or_append·"${AIDE_CONFIG}"·'^database=file'·"${DEFAULT_DB_PATH}"·'@CCENUM@'·'%s:%s' 
216 ····echo·"database=file:${DEFAULT_DB_PATH}"·>>·${AIDE_CONFIG} 
217 fi 
  
218 #·Fix·db·out·path·in·the·config·file,·if·necessary 
219 if·!·grep·-q·'^database_out=file:'·${AIDE_CONFIG};·then 
220 ····echo·"database_out=file:${DEFAULT_DB_PATH}.new"·>>·${AIDE_CONFIG} 
221 fi 
  
222 /usr/sbin/aideinit·-y·-f 
  
223 else 
224 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
225 fi 
226 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
227 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low207 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
228 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low208 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
229 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false209 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
230 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict210 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
231 -·name:·Build·and·Test·AIDE·Database·-·Ensure·AIDE·Is·Installed211 -·name:·Build·and·Test·AIDE·Database·-·Ensure·AIDE·Is·Installed
232 ··ansible.builtin.apt:212 ··ansible.builtin.apt:
Offset 395, 14 lines modifiedOffset 369, 40 lines modified
395 ··-·PCI-DSSv4-11.5.2369 ··-·PCI-DSSv4-11.5.2
396 ··-·aide_build_database370 ··-·aide_build_database
397 ··-·low_complexity371 ··-·low_complexity
398 ··-·low_disruption372 ··-·low_disruption
399 ··-·medium_severity373 ··-·medium_severity
400 ··-·no_reboot_needed374 ··-·no_reboot_needed
401 ··-·restrict_strategy375 ··-·restrict_strategy
 376 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 377 #·Remediation·is·applicable·only·in·certain·platforms
Max diff block lines reached; 1187259/1193853 bytes (99.45%) of diff not shown.
7.95 MB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-cis_level1_server.html
    
Offset 14284, 16 lines modifiedOffset 14284, 16 lines modified
00037cb0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00037cb0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00037cc0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00037cc0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00037cd0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000037cd0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00037ce0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></00037ce0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
00037cf0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00037cf0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00037d00:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00037d00:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00037d10:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037d10:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037d20:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600037d20:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
00037d30:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········00037d30:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00037d40:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00037d40:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00037d50:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00037d50:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00037d60:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00037d60:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00037d70:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00037d70:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00037d80:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00037d80:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00037d90:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00037d90:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00037da0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00037da0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
Offset 15146, 131 lines modifiedOffset 15146, 131 lines modified
0003b290:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b290:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003b2a0:·2223·6964·6d32·3930·3322·2074·6162·696e··"#idm2903"·tabin0003b2a0:·2223·6964·6d32·3930·3322·2074·6162·696e··"#idm2903"·tabin
0003b2b0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b2b0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b2c0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b2c0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b2d0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b2d0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b2e0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b2e0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b2f0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b2f0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b300:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She0003b300:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB
 0003b310:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s
 0003b320:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0003b330:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003b340:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003b350:·6c61·7073·6522·2069·643d·2269·646d·3239··lapse"·id="idm29
0003b310:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
0003b320:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b330:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b340:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b350:·6d32·3930·3322·3e3c·7461·626c·6520·636c··m2903"><table·cl 
0003b360:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003b370:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003b380:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0003b390:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0003b3a0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0003b3b0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003b3c0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003b3d0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
0003b3e0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b3f0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
0003b400:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
0003b410:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
0003b420:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
0003b430:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
0003b440:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#0003b360:·3033·223e·3c70·7265·3e3c·636f·6465·3e0a··03"><pre><code>.
 0003b370:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam
 0003b380:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi
 0003b390:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code>
0003b450:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is· 
0003b460:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only· 
0003b470:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf 
0003b480:·6f72·6d73·0a69·6620·5b20·2120·2d66·202f··orms.if·[·!·-f·/ 
0003b490:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am 
0003b4a0:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/ 
0003b4b0:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren 
0003b4c0:·7620·5d3b·2074·6865·6e0a·0a44·4542·4941··v·];·then..DEBIA 
0003b4d0:·4e5f·4652·4f4e·5445·4e44·3d6e·6f6e·696e··N_FRONTEND=nonin 
0003b4e0:·7465·7261·6374·6976·6520·6170·742d·6765··teractive·apt-ge 
0003b4f0:·7420·696e·7374·616c·6c20·2d79·2022·6169··t·install·-y·"ai 
0003b500:·6465·220a·0a65·6c73·650a·2020·2020·2667··de"..else.····&g 
0003b510:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R 
0003b520:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no 
0003b530:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no 
0003b540:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'. 
0003b550:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre> 
0003b560:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003b570:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003b580:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003b590:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003b5a0:·6765·743d·2223·6964·6d32·3930·3422·2074··get="#idm2904"·t 
0003b5b0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003b5c0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003b5d0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003b5e0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003b5f0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003b600:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003b610:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet 
0003b620:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003b630:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003b640:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003b650:·2069·643d·2269·646d·3239·3034·223e·3c74···id="idm2904"><t 
0003b660:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003b670:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003b680:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003b690:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003b6a0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003b6b0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003b6c0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b6d0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003b6e0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003b6f0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003b700:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003b710:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b720:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0003b730:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003b740:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003b750:·3c63·6f64·653e·2d20·6e61·6d65·3a20·456e··<code>-·name:·En 
0003b760:·7375·7265·2061·6964·6520·6973·2069·6e73··sure·aide·is·ins 
0003b770:·7461·6c6c·6564·0a20·2070·6163·6b61·6765··talled.··package 
0003b780:·3a0a·2020·2020·6e61·6d65·3a20·6169·6465··:.····name:·aide 
0003b790:·0a20·2020·2073·7461·7465·3a20·7072·6573··.····state:·pres 
0003b7a0:·656e·740a·2020·7768·656e·3a20·616e·7369··ent.··when:·ansi 
0003b7b0:·626c·655f·7669·7274·7561·6c69·7a61·7469··ble_virtualizati 
0003b7c0:·6f6e·5f74·7970·6520·6e6f·7420·696e·205b··on_type·not·in·[ 
0003b7d0:·2264·6f63·6b65·7222·2c20·226c·7863·222c··"docker",·"lxc", 
0003b7e0:·2022·6f70·656e·767a·222c·2022·706f·646d···"openvz",·"podm 
0003b7f0:·616e·222c·2022·636f·6e74·6169·6e65·7222··an",·"container" 
0003b800:·5d0a·2020·7461·6773·3a0a·2020·2d20·434a··].··tags:.··-·CJ 
0003b810:·4953·2d35·2e31·302e·312e·330a·2020·2d20··IS-5.10.1.3.··-· 
0003b820:·4449·5341·2d53·5449·472d·5542·5455·2d32··DISA-STIG-UBTU-2 
0003b830:·322d·3635·3130·3130·0a20·202d·204e·4953··2-651010.··-·NIS 
0003b840:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a) 
0003b850:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req 
0003b860:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS 
0003b870:·5376·342d·3131·2e35·2e32·0a20·202d·2065··Sv4-11.5.2.··-·e 
0003b880:·6e61·626c·655f·7374·7261·7465·6779·0a20··nable_strategy.· 
0003b890:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit 
0003b8a0:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup 
0003b8b0:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_ 
0003b8c0:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_ 
0003b8d0:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.·· 
0003b8e0:·2d20·7061·636b·6167·655f·6169·6465·5f69··-·package_aide_i 
Max diff block lines reached; 7382360/7400354 bytes (99.76%) of diff not shown.
912 KB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Ubuntu·22.04·Level·1·Server·Benchmark38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Ubuntu·22.04·Level·1·Server·Benchmark
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_level1_server39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_level1_server
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~
42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
43 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8443 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
49 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r49 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
50 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n50 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
51 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g51 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 135, 27 lines modifiedOffset 135, 19 lines modified
135 include·install_aide135 include·install_aide
  
136 class·install_aide·{136 class·install_aide·{
137 ··package·{·'aide':137 ··package·{·'aide':
138 ····ensure·=>·'installed',138 ····ensure·=>·'installed',
139 ··}139 ··}
140 }140 }
 141 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
141 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
142 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
143 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
144 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
145 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
146 #·Remediation·is·applicable·only·in·certain·platforms 
147 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
148 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide" 
  
149 else 
150 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
151 fi142 [[packages]]
 143 name·=·"aide"
 144 version·=·"*"
152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
153 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
154 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
155 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
156 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
157 -·name:·Ensure·aide·is·installed150 -·name:·Ensure·aide·is·installed
158 ··package:151 ··package:
Offset 170, 19 lines modifiedOffset 162, 27 lines modified
170 ··-·PCI-DSSv4-11.5.2162 ··-·PCI-DSSv4-11.5.2
171 ··-·enable_strategy163 ··-·enable_strategy
172 ··-·low_complexity164 ··-·low_complexity
173 ··-·low_disruption165 ··-·low_disruption
174 ··-·medium_severity166 ··-·medium_severity
175 ··-·no_reboot_needed167 ··-·no_reboot_needed
176 ··-·package_aide_installed168 ··-·package_aide_installed
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 174 #·Remediation·is·applicable·only·in·certain·platforms
 175 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
178 [[packages]] 
179 name·=·"aide" 
180 version·=·"*"176 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide"
  
 177 else
 178 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 179 fi
181 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*180 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
182 Run·the·following·command·to·generate·a·new·database:181 Run·the·following·command·to·generate·a·new·database:
183 $·sudo·aideinit182 $·sudo·aideinit
184 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the183 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the
185 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these184 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these
186 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their185 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
187 integrity.·The·newly-generated·database·can·be·installed·as·follows:186 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 207, 40 lines modifiedOffset 207, 14 lines modified
207 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3207 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
208 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5208 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
209 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199209 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
210 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-22-651015210 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-22-651015
211 ············_\x8c_\x8i_\x8s············1.3.1211 ············_\x8c_\x8i_\x8s············1.3.1
212 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79212 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
213 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2213 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
214 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
215 #·Remediation·is·applicable·only·in·certain·platforms 
216 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
217 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide" 
  
218 AIDE_CONFIG=/etc/aide/aide.conf 
219 DEFAULT_DB_PATH=/var/lib/aide/aide.db 
  
220 #·Fix·db·path·in·the·config·file,·if·necessary 
221 if·!·grep·-q·'^database=file:'·${AIDE_CONFIG};·then 
222 ····#·replace_or_append·gets·confused·by·'database=file'·as·a·key,·so·should·not·be·used. 
223 ····#replace_or_append·"${AIDE_CONFIG}"·'^database=file'·"${DEFAULT_DB_PATH}"·'@CCENUM@'·'%s:%s' 
224 ····echo·"database=file:${DEFAULT_DB_PATH}"·>>·${AIDE_CONFIG} 
225 fi 
  
226 #·Fix·db·out·path·in·the·config·file,·if·necessary 
227 if·!·grep·-q·'^database_out=file:'·${AIDE_CONFIG};·then 
228 ····echo·"database_out=file:${DEFAULT_DB_PATH}.new"·>>·${AIDE_CONFIG} 
229 fi 
  
230 /usr/sbin/aideinit·-y·-f 
  
231 else 
232 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
233 fi 
234 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8214 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
235 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low215 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
236 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low216 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
237 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false217 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
238 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict218 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
239 -·name:·Build·and·Test·AIDE·Database·-·Ensure·AIDE·Is·Installed219 -·name:·Build·and·Test·AIDE·Database·-·Ensure·AIDE·Is·Installed
240 ··ansible.builtin.apt:220 ··ansible.builtin.apt:
Offset 403, 14 lines modifiedOffset 377, 40 lines modified
403 ··-·PCI-DSSv4-11.5.2377 ··-·PCI-DSSv4-11.5.2
404 ··-·aide_build_database378 ··-·aide_build_database
405 ··-·low_complexity379 ··-·low_complexity
406 ··-·low_disruption380 ··-·low_disruption
407 ··-·medium_severity381 ··-·medium_severity
408 ··-·no_reboot_needed382 ··-·no_reboot_needed
409 ··-·restrict_strategy383 ··-·restrict_strategy
 384 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 385 #·Remediation·is·applicable·only·in·certain·platforms
Max diff block lines reached; 927654/934331 bytes (99.29%) of diff not shown.
7.79 MB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-cis_level1_workstation.html
    
Offset 14285, 16 lines modifiedOffset 14285, 16 lines modified
00037cc0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h00037cc0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h
00037cd0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver00037cd0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver
00037ce0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.00037ce0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.
00037cf0:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p00037cf0:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p
00037d00:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong00037d00:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong
00037d10:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.00037d10:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.
00037d20:·2020·2020·2020·2020·2020·2020·2020·2020··················00037d20:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037d30:·2020·2020·2861·7320·6f66·2032·3032·362d······(as·of·2026-00037d30:·2020·2020·2861·7320·6f66·2032·3032·342d······(as·of·2024-
00037d40:·3031·2d30·3829·0a20·2020·2020·2020·2020··01-08).·········00037d40:·3132·2d30·3729·0a20·2020·2020·2020·2020··12-07).·········
00037d50:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul00037d50:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul
00037d60:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table00037d60:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table
00037d70:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h200037d70:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2
00037d80:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href00037d80:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href
00037d90:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg00037d90:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg
00037da0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_00037da0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
00037db0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy00037db0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy
Offset 15137, 130 lines modifiedOffset 15137, 130 lines modified
0003b200:·7461·2d74·6172·6765·743d·2223·6964·6d32··ta-target="#idm20003b200:·7461·2d74·6172·6765·743d·2223·6964·6d32··ta-target="#idm2
0003b210:·3930·3322·2074·6162·696e·6465·783d·2230··903"·tabindex="00003b210:·3930·3322·2074·6162·696e·6465·783d·2230··903"·tabindex="0
0003b220:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003b220:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003b230:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003b230:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003b240:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003b240:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003b250:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003b250:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003b260:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003b260:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003b270:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr0003b270:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B
 0003b280:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet
 0003b290:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003b2a0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003b2b0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003b2c0:·2069·643d·2269·646d·3239·3033·223e·3c70···id="idm2903"><p
 0003b2d0:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack
 0003b2e0:·6167·6573·5d5d·0a6e·616d·6520·3d20·2261··ages]].name·=·"a
 0003b2f0:·6964·6522·0a76·6572·7369·6f6e·203d·2022··ide".version·=·"
0003b280:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003b290:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b2a0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b2b0:·7365·2220·6964·3d22·6964·6d32·3930·3322··se"·id="idm2903" 
0003b2c0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003b2d0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003b2e0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003b2f0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003b300:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003b310:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003b320:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b330:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003b340:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b350:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003b360:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003b370:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003b380:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003b390:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003b3a0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003b3b0:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed 
0003b3c0:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic 
0003b3d0:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer 
0003b3e0:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i 
0003b3f0:·6620·5b20·2120·2d66·202f·2e64·6f63·6b65··f·[·!·-f·/.docke 
0003b400:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp 
0003b410:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c 
0003b420:·6f6e·7461·696e·6572·656e·7620·5d3b·2074··ontainerenv·];·t 
0003b430:·6865·6e0a·0a44·4542·4941·4e5f·4652·4f4e··hen..DEBIAN_FRON 
0003b440:·5445·4e44·3d6e·6f6e·696e·7465·7261·6374··TEND=noninteract 
0003b450:·6976·6520·6170·742d·6765·7420·696e·7374··ive·apt-get·inst 
0003b460:·616c·6c20·2d79·2022·6169·6465·220a·0a65··all·-y·"aide"..e 
0003b470:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp 
0003b480:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia 
0003b490:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl 
0003b4a0:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing· 
0003b4b0:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c 
0003b4c0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003b4d0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003b4e0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003b4f0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003b500:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003b510:·6964·6d32·3930·3422·2074·6162·696e·6465··idm2904"·tabinde 
0003b520:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003b530:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003b540:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003b550:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003b560:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003b570:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib 
0003b580:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</ 
0003b590:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003b5a0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003b5b0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003b5c0:·646d·3239·3034·223e·3c74·6162·6c65·2063··dm2904"><table·c 
0003b5d0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003b5e0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003b5f0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003b600:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003b610:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003b620:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b630:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003b640:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003b650:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b660:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003b670:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0003b680:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003b690:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003b6a0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003b6b0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003b6c0:·2d20·6e61·6d65·3a20·456e·7375·7265·2061··-·name:·Ensure·a 
0003b6d0:·6964·6520·6973·2069·6e73·7461·6c6c·6564··ide·is·installed 
0003b6e0:·0a20·2070·6163·6b61·6765·3a0a·2020·2020··.··package:.···· 
0003b6f0:·6e61·6d65·3a20·6169·6465·0a20·2020·2073··name:·aide.····s 
0003b700:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.·· 
0003b710:·7768·656e·3a20·616e·7369·626c·655f·7669··when:·ansible_vi 
0003b720:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ 
0003b730:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke 
0003b740:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open 
0003b750:·767a·222c·2022·706f·646d·616e·222c·2022··vz",·"podman",·" 
0003b760:·636f·6e74·6169·6e65·7222·5d0a·2020·7461··container"].··ta 
0003b770:·6773·3a0a·2020·2d20·434a·4953·2d35·2e31··gs:.··-·CJIS-5.1 
0003b780:·302e·312e·330a·2020·2d20·4449·5341·2d53··0.1.3.··-·DISA-S 
0003b790:·5449·472d·5542·5455·2d32·322d·3635·3130··TIG-UBTU-22-6510 
0003b7a0:·3130·0a20·202d·204e·4953·542d·3830·302d··10.··-·NIST-800- 
0003b7b0:·3533·2d43·4d2d·3628·6129·0a20·202d·2050··53-CM-6(a).··-·P 
0003b7c0:·4349·2d44·5353·2d52·6571·2d31·312e·350a··CI-DSS-Req-11.5. 
0003b7d0:·2020·2d20·5043·492d·4453·5376·342d·3131····-·PCI-DSSv4-11 
0003b7e0:·2e35·2e32·0a20·202d·2065·6e61·626c·655f··.5.2.··-·enable_ 
0003b7f0:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low 
0003b800:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-· 
0003b810:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.· 
0003b820:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi 
0003b830:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot 
0003b840:·5f6e·6565·6465·640a·2020·2d20·7061·636b··_needed.··-·pack 
0003b850:·6167·655f·6169·6465·5f69·6e73·7461·6c6c··age_aide_install 
Max diff block lines reached; 7232062/7249918 bytes (99.75%) of diff not shown.
899 KB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Ubuntu·22.04·Level·1·Workstation·Benchmark38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Ubuntu·22.04·Level·1·Workstation·Benchmark
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_level1_workstation39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_level1_workstation
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~41 ····*·cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~
42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
43 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8443 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
49 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r49 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
50 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n50 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
51 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g51 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 133, 27 lines modifiedOffset 133, 19 lines modified
133 include·install_aide133 include·install_aide
  
134 class·install_aide·{134 class·install_aide·{
135 ··package·{·'aide':135 ··package·{·'aide':
136 ····ensure·=>·'installed',136 ····ensure·=>·'installed',
137 ··}137 ··}
138 }138 }
 139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
144 #·Remediation·is·applicable·only·in·certain·platforms 
145 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
146 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide" 
  
147 else 
148 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
149 fi140 [[packages]]
 141 name·=·"aide"
 142 version·=·"*"
150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
151 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low144 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
152 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low145 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
153 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false146 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
154 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable147 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
155 -·name:·Ensure·aide·is·installed148 -·name:·Ensure·aide·is·installed
156 ··package:149 ··package:
Offset 168, 19 lines modifiedOffset 160, 27 lines modified
168 ··-·PCI-DSSv4-11.5.2160 ··-·PCI-DSSv4-11.5.2
169 ··-·enable_strategy161 ··-·enable_strategy
170 ··-·low_complexity162 ··-·low_complexity
171 ··-·low_disruption163 ··-·low_disruption
172 ··-·medium_severity164 ··-·medium_severity
173 ··-·no_reboot_needed165 ··-·no_reboot_needed
174 ··-·package_aide_installed166 ··-·package_aide_installed
175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 172 #·Remediation·is·applicable·only·in·certain·platforms
 173 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
176 [[packages]] 
177 name·=·"aide" 
178 version·=·"*"174 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide"
  
 175 else
 176 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 177 fi
179 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*178 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
180 Run·the·following·command·to·generate·a·new·database:179 Run·the·following·command·to·generate·a·new·database:
181 $·sudo·aideinit180 $·sudo·aideinit
182 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the181 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the
183 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these182 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these
184 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their183 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
185 integrity.·The·newly-generated·database·can·be·installed·as·follows:184 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 205, 40 lines modifiedOffset 205, 14 lines modified
205 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3205 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
206 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5206 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
207 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199207 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
208 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-22-651015208 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-22-651015
209 ············_\x8c_\x8i_\x8s············1.3.1209 ············_\x8c_\x8i_\x8s············1.3.1
210 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79210 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
211 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2211 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
212 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
213 #·Remediation·is·applicable·only·in·certain·platforms 
214 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
215 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide" 
  
216 AIDE_CONFIG=/etc/aide/aide.conf 
217 DEFAULT_DB_PATH=/var/lib/aide/aide.db 
  
218 #·Fix·db·path·in·the·config·file,·if·necessary 
219 if·!·grep·-q·'^database=file:'·${AIDE_CONFIG};·then 
220 ····#·replace_or_append·gets·confused·by·'database=file'·as·a·key,·so·should·not·be·used. 
221 ····#replace_or_append·"${AIDE_CONFIG}"·'^database=file'·"${DEFAULT_DB_PATH}"·'@CCENUM@'·'%s:%s' 
222 ····echo·"database=file:${DEFAULT_DB_PATH}"·>>·${AIDE_CONFIG} 
223 fi 
  
224 #·Fix·db·out·path·in·the·config·file,·if·necessary 
225 if·!·grep·-q·'^database_out=file:'·${AIDE_CONFIG};·then 
226 ····echo·"database_out=file:${DEFAULT_DB_PATH}.new"·>>·${AIDE_CONFIG} 
227 fi 
  
228 /usr/sbin/aideinit·-y·-f 
  
229 else 
230 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
231 fi 
232 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8212 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
233 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low213 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
234 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low214 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
235 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false215 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
236 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict216 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
237 -·name:·Build·and·Test·AIDE·Database·-·Ensure·AIDE·Is·Installed217 -·name:·Build·and·Test·AIDE·Database·-·Ensure·AIDE·Is·Installed
238 ··ansible.builtin.apt:218 ··ansible.builtin.apt:
Offset 401, 14 lines modifiedOffset 375, 40 lines modified
401 ··-·PCI-DSSv4-11.5.2375 ··-·PCI-DSSv4-11.5.2
402 ··-·aide_build_database376 ··-·aide_build_database
403 ··-·low_complexity377 ··-·low_complexity
404 ··-·low_disruption378 ··-·low_disruption
405 ··-·medium_severity379 ··-·medium_severity
406 ··-·no_reboot_needed380 ··-·no_reboot_needed
407 ··-·restrict_strategy381 ··-·restrict_strategy
 382 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 383 #·Remediation·is·applicable·only·in·certain·platforms
Max diff block lines reached; 913462/920149 bytes (99.27%) of diff not shown.
22.3 MB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-cis_level2_server.html
    
Offset 14284, 16 lines modifiedOffset 14284, 16 lines modified
00037cb0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00037cb0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00037cc0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00037cc0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00037cd0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000037cd0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00037ce0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></00037ce0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
00037cf0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00037cf0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00037d00:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00037d00:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00037d10:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037d10:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037d20:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600037d20:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
00037d30:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········00037d30:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00037d40:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00037d40:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00037d50:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00037d50:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00037d60:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00037d60:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00037d70:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00037d70:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00037d80:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00037d80:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00037d90:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00037d90:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00037da0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00037da0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
Offset 15154, 130 lines modifiedOffset 15154, 130 lines modified
0003b310:·7461·2d74·6172·6765·743d·2223·6964·6d32··ta-target="#idm20003b310:·7461·2d74·6172·6765·743d·2223·6964·6d32··ta-target="#idm2
0003b320:·3930·3322·2074·6162·696e·6465·783d·2230··903"·tabindex="00003b320:·3930·3322·2074·6162·696e·6465·783d·2230··903"·tabindex="0
0003b330:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003b330:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003b340:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003b340:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003b350:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003b350:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003b360:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003b360:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003b370:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003b370:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003b380:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr0003b380:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B
 0003b390:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet
 0003b3a0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003b3b0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003b3c0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003b3d0:·2069·643d·2269·646d·3239·3033·223e·3c70···id="idm2903"><p
 0003b3e0:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack
 0003b3f0:·6167·6573·5d5d·0a6e·616d·6520·3d20·2261··ages]].name·=·"a
 0003b400:·6964·6522·0a76·6572·7369·6f6e·203d·2022··ide".version·=·"
0003b390:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003b3a0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b3b0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b3c0:·7365·2220·6964·3d22·6964·6d32·3930·3322··se"·id="idm2903" 
0003b3d0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003b3e0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003b3f0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003b400:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003b410:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003b420:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003b430:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b440:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003b450:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b460:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003b470:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003b480:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003b490:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003b4a0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003b4b0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003b4c0:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed 
0003b4d0:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic 
0003b4e0:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer 
0003b4f0:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i 
0003b500:·6620·5b20·2120·2d66·202f·2e64·6f63·6b65··f·[·!·-f·/.docke 
0003b510:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp 
0003b520:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c 
0003b530:·6f6e·7461·696e·6572·656e·7620·5d3b·2074··ontainerenv·];·t 
0003b540:·6865·6e0a·0a44·4542·4941·4e5f·4652·4f4e··hen..DEBIAN_FRON 
0003b550:·5445·4e44·3d6e·6f6e·696e·7465·7261·6374··TEND=noninteract 
0003b560:·6976·6520·6170·742d·6765·7420·696e·7374··ive·apt-get·inst 
0003b570:·616c·6c20·2d79·2022·6169·6465·220a·0a65··all·-y·"aide"..e 
0003b580:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp 
0003b590:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia 
0003b5a0:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl 
0003b5b0:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing· 
0003b5c0:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c 
0003b5d0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003b5e0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003b5f0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003b600:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003b610:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003b620:·6964·6d32·3930·3422·2074·6162·696e·6465··idm2904"·tabinde 
0003b630:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003b640:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003b650:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003b660:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003b670:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003b680:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib 
0003b690:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</ 
0003b6a0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003b6b0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003b6c0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003b6d0:·646d·3239·3034·223e·3c74·6162·6c65·2063··dm2904"><table·c 
0003b6e0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003b6f0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003b700:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003b710:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003b720:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003b730:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b740:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003b750:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003b760:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b770:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003b780:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0003b790:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003b7a0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003b7b0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003b7c0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003b7d0:·2d20·6e61·6d65·3a20·456e·7375·7265·2061··-·name:·Ensure·a 
0003b7e0:·6964·6520·6973·2069·6e73·7461·6c6c·6564··ide·is·installed 
0003b7f0:·0a20·2070·6163·6b61·6765·3a0a·2020·2020··.··package:.···· 
0003b800:·6e61·6d65·3a20·6169·6465·0a20·2020·2073··name:·aide.····s 
0003b810:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.·· 
0003b820:·7768·656e·3a20·616e·7369·626c·655f·7669··when:·ansible_vi 
0003b830:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ 
0003b840:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke 
0003b850:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open 
0003b860:·767a·222c·2022·706f·646d·616e·222c·2022··vz",·"podman",·" 
0003b870:·636f·6e74·6169·6e65·7222·5d0a·2020·7461··container"].··ta 
0003b880:·6773·3a0a·2020·2d20·434a·4953·2d35·2e31··gs:.··-·CJIS-5.1 
0003b890:·302e·312e·330a·2020·2d20·4449·5341·2d53··0.1.3.··-·DISA-S 
0003b8a0:·5449·472d·5542·5455·2d32·322d·3635·3130··TIG-UBTU-22-6510 
0003b8b0:·3130·0a20·202d·204e·4953·542d·3830·302d··10.··-·NIST-800- 
0003b8c0:·3533·2d43·4d2d·3628·6129·0a20·202d·2050··53-CM-6(a).··-·P 
0003b8d0:·4349·2d44·5353·2d52·6571·2d31·312e·350a··CI-DSS-Req-11.5. 
0003b8e0:·2020·2d20·5043·492d·4453·5376·342d·3131····-·PCI-DSSv4-11 
0003b8f0:·2e35·2e32·0a20·202d·2065·6e61·626c·655f··.5.2.··-·enable_ 
0003b900:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low 
0003b910:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-· 
0003b920:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.· 
0003b930:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi 
0003b940:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot 
0003b950:·5f6e·6565·6465·640a·2020·2d20·7061·636b··_needed.··-·pack 
0003b960:·6167·655f·6169·6465·5f69·6e73·7461·6c6c··age_aide_install 
Max diff block lines reached; 21416616/21434472 bytes (99.92%) of diff not shown.
1.85 MB
html2text {}
Max HTML report size reached
22.3 MB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-cis_level2_workstation.html
    
Offset 14285, 16 lines modifiedOffset 14285, 16 lines modified
00037cc0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h00037cc0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h
00037cd0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver00037cd0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver
00037ce0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.00037ce0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.
00037cf0:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p00037cf0:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p
00037d00:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong00037d00:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong
00037d10:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.00037d10:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.
00037d20:·2020·2020·2020·2020·2020·2020·2020·2020··················00037d20:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037d30:·2020·2020·2861·7320·6f66·2032·3032·362d······(as·of·2026-00037d30:·2020·2020·2861·7320·6f66·2032·3032·342d······(as·of·2024-
00037d40:·3031·2d30·3829·0a20·2020·2020·2020·2020··01-08).·········00037d40:·3132·2d30·3729·0a20·2020·2020·2020·2020··12-07).·········
00037d50:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul00037d50:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul
00037d60:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table00037d60:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table
00037d70:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h200037d70:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2
00037d80:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href00037d80:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href
00037d90:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg00037d90:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg
00037da0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_00037da0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
00037db0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy00037db0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy
Offset 15150, 130 lines modifiedOffset 15150, 130 lines modified
0003b2d0:·6172·6765·743d·2223·6964·6d32·3930·3322··arget="#idm2903"0003b2d0:·6172·6765·743d·2223·6964·6d32·3930·3322··arget="#idm2903"
0003b2e0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003b2e0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003b2f0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003b2f0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003b300:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003b300:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003b310:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003b310:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003b320:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003b320:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003b330:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003b330:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003b340:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep
 0003b350:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·...
 0003b360:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003b370:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003b380:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003b390:·2269·646d·3239·3033·223e·3c70·7265·3e3c··"idm2903"><pre><
 0003b3a0:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages
 0003b3b0:·5d5d·0a6e·616d·6520·3d20·2261·6964·6522··]].name·=·"aide"
 0003b3c0:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".<
0003b340:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script· 
0003b350:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003b360:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003b370:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003b380:·6964·3d22·6964·6d32·3930·3322·3e3c·7461··id="idm2903"><ta 
0003b390:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003b3a0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003b3b0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003b3c0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003b3d0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003b3e0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003b3f0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b400:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003b410:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b420:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003b430:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003b440:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b450:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003b460:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0003b470:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003b480:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati 
0003b490:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable 
0003b4a0:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain 
0003b4b0:·2070·6c61·7466·6f72·6d73·0a69·6620·5b20···platforms.if·[· 
0003b4c0:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv 
0003b4d0:·205d·2026·616d·703b·2661·6d70·3b20·5b20···]·&amp;&amp;·[· 
0003b4e0:·2120·2d66·202f·7275·6e2f·2e63·6f6e·7461··!·-f·/run/.conta 
0003b4f0:·696e·6572·656e·7620·5d3b·2074·6865·6e0a··inerenv·];·then. 
0003b500:·0a44·4542·4941·4e5f·4652·4f4e·5445·4e44··.DEBIAN_FRONTEND 
0003b510:·3d6e·6f6e·696e·7465·7261·6374·6976·6520··=noninteractive· 
0003b520:·6170·742d·6765·7420·696e·7374·616c·6c20··apt-get·install· 
0003b530:·2d79·2022·6169·6465·220a·0a65·6c73·650a··-y·"aide"..else. 
0003b540:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e 
0003b550:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation 
0003b560:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab 
0003b570:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was· 
0003b580:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code> 
0003b590:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003b5a0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003b5b0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003b5c0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003b5d0:·7461·2d74·6172·6765·743d·2223·6964·6d32··ta-target="#idm2 
0003b5e0:·3930·3422·2074·6162·696e·6465·783d·2230··904"·tabindex="0 
0003b5f0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003b600:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003b610:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003b620:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003b630:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003b640:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s 
0003b650:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003b660:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003b670:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003b680:·6c61·7073·6522·2069·643d·2269·646d·3239··lapse"·id="idm29 
0003b690:·3034·223e·3c74·6162·6c65·2063·6c61·7373··04"><table·class 
0003b6a0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003b6b0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003b6c0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003b6d0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003b6e0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003b6f0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b700:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003b710:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003b720:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b730:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003b740:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
0003b750:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003b760:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003b770:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003b780:·3e3c·7072·653e·3c63·6f64·653e·2d20·6e61··><pre><code>-·na 
0003b790:·6d65·3a20·456e·7375·7265·2061·6964·6520··me:·Ensure·aide· 
0003b7a0:·6973·2069·6e73·7461·6c6c·6564·0a20·2070··is·installed.··p 
0003b7b0:·6163·6b61·6765·3a0a·2020·2020·6e61·6d65··ackage:.····name 
0003b7c0:·3a20·6169·6465·0a20·2020·2073·7461·7465··:·aide.····state 
0003b7d0:·3a20·7072·6573·656e·740a·2020·7768·656e··:·present.··when 
0003b7e0:·3a20·616e·7369·626c·655f·7669·7274·7561··:·ansible_virtua 
0003b7f0:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no 
0003b800:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",· 
0003b810:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz", 
0003b820:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont 
0003b830:·6169·6e65·7222·5d0a·2020·7461·6773·3a0a··ainer"].··tags:. 
0003b840:·2020·2d20·434a·4953·2d35·2e31·302e·312e····-·CJIS-5.10.1. 
0003b850:·330a·2020·2d20·4449·5341·2d53·5449·472d··3.··-·DISA-STIG- 
0003b860:·5542·5455·2d32·322d·3635·3130·3130·0a20··UBTU-22-651010.· 
0003b870:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C 
0003b880:·4d2d·3628·6129·0a20·202d·2050·4349·2d44··M-6(a).··-·PCI-D 
0003b890:·5353·2d52·6571·2d31·312e·350a·2020·2d20··SS-Req-11.5.··-· 
0003b8a0:·5043·492d·4453·5376·342d·3131·2e35·2e32··PCI-DSSv4-11.5.2 
0003b8b0:·0a20·202d·2065·6e61·626c·655f·7374·7261··.··-·enable_stra 
0003b8c0:·7465·6779·0a20·202d·206c·6f77·5f63·6f6d··tegy.··-·low_com 
0003b8d0:·706c·6578·6974·790a·2020·2d20·6c6f·775f··plexity.··-·low_ 
0003b8e0:·6469·7372·7570·7469·6f6e·0a20·202d·206d··disruption.··-·m 
0003b8f0:·6564·6975·6d5f·7365·7665·7269·7479·0a20··edium_severity.· 
0003b900:·202d·206e·6f5f·7265·626f·6f74·5f6e·6565···-·no_reboot_nee 
0003b910:·6465·640a·2020·2d20·7061·636b·6167·655f··ded.··-·package_ 
Max diff block lines reached; 21386683/21404539 bytes (99.92%) of diff not shown.
1.84 MB
html2text {}
Max HTML report size reached
1.16 MB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-standard.html
    
Offset 14288, 15 lines modifiedOffset 14288, 15 lines modified
00037cf0:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur00037cf0:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur
00037d00:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s00037d00:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s
00037d10:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st00037d10:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st
00037d20:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li00037d20:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li
00037d30:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</00037d30:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</
00037d40:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········00037d40:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········
00037d50:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·00037d50:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·
00037d60:·6f66·2032·3032·362d·3031·2d30·3829·0a20··of·2026-01-08).·00037d60:·6f66·2032·3032·342d·3132·2d30·3729·0a20··of·2024-12-07).·
00037d70:·2020·2020·2020·2020·2020·2020·2020·203c·················<00037d70:·2020·2020·2020·2020·2020·2020·2020·203c·················<
00037d80:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><00037d80:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><
00037d90:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont00037d90:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont
00037da0:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li00037da0:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li
00037db0:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf00037db0:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf
00037dc0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.00037dc0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.
00037dd0:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy00037dd0:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy
Offset 16538, 741 lines modifiedOffset 16538, 741 lines modified
00040990:·743d·2223·6964·6d31·3135·3337·2220·7461··t="#idm11537"·ta00040990:·743d·2223·6964·6d31·3135·3337·2220·7461··t="#idm11537"·ta
000409a0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=000409a0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
000409b0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex000409b0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
000409c0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t000409c0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
000409d0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t000409d0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
000409e0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="000409e0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
Diff chunk too large, falling back to line-by-line diff (727 lines added, 727 lines removed)
000409f0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·000409f0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
00040a00:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...00040a00:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet·
00040a10:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla00040a10:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
00040a20:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap00040a20:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
00040a30:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=00040a30:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
00040a40:·2269·646d·3131·3533·3722·3e3c·7072·653e··"idm11537"><pre>00040a40:·6964·3d22·6964·6d31·3135·3337·223e·3c74··id="idm11537"><t
00040a50:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat00040a50:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
00040a60:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl00040a60:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
00040a70:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai00040a70:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
00040a80:·6e20·706c·6174·666f·726d·730a·6966·205b··n·platforms.if·[00040a80:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
00040a90:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren00040a90:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
00040aa0:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[00040aa0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
00040ab0:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont00040ab0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
00040ac0:·6169·6e65·7265·6e76·205d·3b20·7468·656e··ainerenv·];·then00040ac0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
00040ad0:·0a0a·2320·4c69·7374·206f·6620·6c6f·6720··..#·List·of·log·00040ad0:·3e3c·7464·3e6d·6564·6975·6d3c·2f74·643e··><td>medium</td>
00040ae0:·6669·6c65·2070·6174·6873·2074·6f20·6265··file·paths·to·be00040ae0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
00040af0:·2069·6e73·7065·6374·6564·2066·6f72·2063···inspected·for·c00040af0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
00040b00:·6f72·7265·6374·2070·6572·6d69·7373·696f··orrect·permissio00040b00:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
00040b10:·6e73·0a23·202a·2050·7269·6d61·7269·6c79··ns.#·*·Primarily00040b10:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
00040b20:·2069·6e73·7065·6374·206c·6f67·2066·696c···inspect·log·fil00040b20:·683e·3c74·643e·636f·6e66·6967·7572·653c··h><td>configure<
00040b30:·6520·7061·7468·7320·6c69·7374·6564·2069··e·paths·listed·i00040b30:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
00040b40:·6e20·2f65·7463·2f72·7379·736c·6f67·2e63··n·/etc/rsyslog.c00040b40:·3e3c·7072·653e·3c63·6f64·653e·2d20·6e61··><pre><code>-·na
00040b50:·6f6e·660a·5253·5953·4c4f·475f·4554·435f··onf.RSYSLOG_ETC_00040b50:·6d65·3a20·456e·7375·7265·204c·6f67·2046··me:·Ensure·Log·F
00040b60:·434f·4e46·4947·3d22·2f65·7463·2f72·7379··CONFIG="/etc/rsy00040b60:·696c·6573·2041·7265·204f·776e·6564·2042··iles·Are·Owned·B
00040b70:·736c·6f67·2e63·6f6e·6622·0a23·202a·2041··slog.conf".#·*·A00040b70:·7920·4170·7072·6f70·7269·6174·6520·4772··y·Appropriate·Gr
00040b80:·6e64·2061·6c73·6f20·7468·6520·6c6f·6720··nd·also·the·log·00040b80:·6f75·7020·2d20·5365·7420·7273·7973·6c6f··oup·-·Set·rsyslo
00040b90:·6669·6c65·2070·6174·6873·206c·6973·7465··file·paths·liste00040b90:·6720·6c6f·6766·696c·6520·636f·6e66·6967··g·logfile·config
00040ba0:·6420·6166·7465·7220·7273·7973·6c6f·6727··d·after·rsyslog'00040ba0:·7572·6174·696f·6e0a·2020·2020·6661·6374··uration.····fact
00040bb0:·7320·2449·6e63·6c75·6465·436f·6e66·6967··s·$IncludeConfig00040bb0:·730a·2020·616e·7369·626c·652e·6275·696c··s.··ansible.buil
00040bc0:·2064·6972·6563·7469·7665·0a23·2020·2028···directive.#···(00040bc0:·7469·6e2e·7365·745f·6661·6374·3a0a·2020··tin.set_fact:.··
00040bd0:·7374·6f72·6520·7468·6520·7265·7375·6c74··store·the·result00040bd0:·2020·7273·7973·6c6f·675f·6574·635f·636f····rsyslog_etc_co
00040be0:·2069·6e74·6f20·6172·7261·7920·666f·7220···into·array·for·00040be0:·6e66·6967·3a20·2f65·7463·2f72·7379·736c··nfig:·/etc/rsysl
00040bf0:·7468·6520·6361·7365·2074·6865·7265·2773··the·case·there's00040bf0:·6f67·2e63·6f6e·660a·2020·7768·656e·3a20··og.conf.··when:·
00040c00:·2073·6865·6c6c·2067·6c6f·6220·7573·6564···shell·glob·used00040c00:·616e·7369·626c·655f·7669·7274·7561·6c69··ansible_virtuali
00040c10:·2061·7320·7661·6c75·6520·6f66·2049·6e63···as·value·of·Inc00040c10:·7a61·7469·6f6e·5f74·7970·6520·6e6f·7420··zation_type·not·
00040c20:·6c75·6465·436f·6e66·6967·290a·7265·6164··ludeConfig).read00040c20:·696e·205b·2264·6f63·6b65·7222·2c20·226c··in·["docker",·"l
00040c30:·6172·7261·7920·2d74·204f·4c44·5f49·4e43··array·-t·OLD_INC00040c30:·7863·222c·2022·6f70·656e·767a·222c·2022··xc",·"openvz",·"
00040c40:·2026·6c74·3b20·266c·743b·2867·7265·7020···&lt;·&lt;(grep·00040c40:·706f·646d·616e·222c·2022·636f·6e74·6169··podman",·"contai
00040c50:·2d65·2022·5c24·496e·636c·7564·6543·6f6e··-e·"\$IncludeCon00040c50:·6e65·7222·5d0a·2020·7461·6773·3a0a·2020··ner"].··tags:.··
00040c60:·6669·675b·5b3a·7370·6163·653a·5d5d·5c2b··fig[[:space:]]\+00040c60:·2d20·4e49·5354·2d38·3030·2d35·332d·4143··-·NIST-800-53-AC
00040c70:·5b5e·5b3a·7370·6163·653a·5d3b·5d5c·2b22··[^[:space:];]\+"00040c70:·2d36·2831·290a·2020·2d20·4e49·5354·2d38··-6(1).··-·NIST-8
00040c80:·202f·6574·632f·7273·7973·6c6f·672e·636f···/etc/rsyslog.co00040c80:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).··
00040c90:·6e66·207c·2063·7574·202d·6420·2720·2720··nf·|·cut·-d·'·'·00040c90:·2d20·5043·492d·4453·532d·5265·712d·3130··-·PCI-DSS-Req-10
00040ca0:·2d66·2032·290a·7265·6164·6172·7261·7920··-f·2).readarray·00040ca0:·2e35·2e31·0a20·202d·2050·4349·2d44·5353··.5.1.··-·PCI-DSS
00040cb0:·2d74·2052·5359·534c·4f47·5f49·4e43·4c55··-t·RSYSLOG_INCLU00040cb0:·2d52·6571·2d31·302e·352e·320a·2020·2d20··-Req-10.5.2.··-·
00040cc0:·4445·5f43·4f4e·4649·4720·266c·743b·2026··DE_CONFIG·&lt;·&00040cc0:·5043·492d·4453·5376·342d·3130·2e33·2e32··PCI-DSSv4-10.3.2
00040cd0:·6c74·3b28·666f·7220·494e·4350·4154·4820··lt;(for·INCPATH·00040cd0:·0a20·202d·2063·6f6e·6669·6775·7265·5f73··.··-·configure_s
00040ce0:·696e·2022·247b·4f4c·445f·494e·435b·405d··in·"${OLD_INC[@]00040ce0:·7472·6174·6567·790a·2020·2d20·6c6f·775f··trategy.··-·low_
00040cf0:·7d22·3b20·646f·2065·7661·6c20·7072·696e··}";·do·eval·prin00040cf0:·636f·6d70·6c65·7869·7479·0a20·202d·206d··complexity.··-·m
00040d00:·7466·2027·2573·5c5c·6e27·2022·247b·494e··tf·'%s\\n'·"${IN00040d00:·6564·6975·6d5f·6469·7372·7570·7469·6f6e··edium_disruption
00040d10:·4350·4154·487d·223b·2064·6f6e·6529·0a72··CPATH}";·done).r00040d10:·0a20·202d·206d·6564·6975·6d5f·7365·7665··.··-·medium_seve
00040d20:·6561·6461·7272·6179·202d·7420·4e45·575f··eadarray·-t·NEW_00040d20:·7269·7479·0a20·202d·206e·6f5f·7265·626f··rity.··-·no_rebo
00040d30:·494e·4320·266c·743b·2026·6c74·3b28·7365··INC·&lt;·&lt;(se00040d30:·6f74·5f6e·6565·6465·640a·2020·2d20·7273··ot_needed.··-·rs
00040d40:·6420·2d6e·2027·2f5e·5c73·2a69·6e63·6c75··d·-n·'/^\s*inclu00040d40:·7973·6c6f·675f·6669·6c65·735f·6772·6f75··yslog_files_grou
00040d50:·6465·282f·2c2f·292f·4970·2720·2f65·7463··de(/,/)/Ip'·/etc00040d50:·706f·776e·6572·7368·6970·0a0a·2d20·6e61··pownership..-·na
00040d60:·2f72·7379·736c·6f67·2e63·6f6e·6620·7c20··/rsyslog.conf·|·00040d60:·6d65·3a20·456e·7375·7265·204c·6f67·2046··me:·Ensure·Log·F
00040d70:·7365·6420·2d6e·2027·7340·2e2a·6669·6c65··sed·-n·'s@.*file00040d70:·696c·6573·2041·7265·204f·776e·6564·2042··iles·Are·Owned·B
00040d80:·5c73·2a3d·5c73·2a22·5c28·5b2f·5b3a·616c··\s*=\s*"\([/[:al00040d80:·7920·4170·7072·6f70·7269·6174·6520·4772··y·Appropriate·Gr
00040d90:·6e75·6d3a·5d5b·3a70·756e·6374·3a5d·5d2a··num:][:punct:]]*00040d90:·6f75·7020·2d20·4765·7420·496e·636c·7564··oup·-·Get·Includ
00040da0:·5c29·222e·2a40·5c31·4049·7027·290a·7265··\)".*@\1@Ip').re00040da0:·6543·6f6e·6669·6720·6469·7265·6374·6976··eConfig·directiv
00040db0:·6164·6172·7261·7920·2d74·2052·5359·534c··adarray·-t·RSYSL00040db0:·650a·2020·616e·7369·626c·652e·6275·696c··e.··ansible.buil
00040dc0:·4f47·5f49·4e43·4c55·4445·2026·6c74·3b20··OG_INCLUDE·&lt;·00040dc0:·7469·6e2e·7368·656c·6c3a·207c·0a20·2020··tin.shell:·|.···
00040dd0:·266c·743b·2866·6f72·2049·4e43·5041·5448··&lt;(for·INCPATH00040dd0:·2073·6574·202d·6f20·7069·7065·6661·696c···set·-o·pipefail
00040de0:·2069·6e20·2224·7b4e·4557·5f49·4e43·5b40···in·"${NEW_INC[@00040de0:·0a20·2020·2067·7265·7020·2d65·2027·2449··.····grep·-e·'$I
00040df0:·5d7d·223b·2064·6f20·6576·616c·2070·7269··]}";·do·eval·pri00040df0:·6e63·6c75·6465·436f·6e66·6967·2720·7b7b··ncludeConfig'·{{
00040e00:·6e74·6620·2725·735c·5c6e·2720·2224·7b49··ntf·'%s\\n'·"${I00040e00:·2072·7379·736c·6f67·5f65·7463·5f63·6f6e···rsyslog_etc_con
00040e10:·4e43·5041·5448·7d22·3b20·646f·6e65·290a··NCPATH}";·done).00040e10:·6669·6720·7d7d·207c·2063·7574·202d·6420··fig·}}·|·cut·-d·
00040e20:·0a23·2044·6563·6c61·7265·2061·6e20·6172··.#·Declare·an·ar00040e20:·2720·2720·2d66·2032·207c·7c20·7472·7565··'·'·-f·2·||·true
00040e30:·7261·7920·746f·2068·6f6c·6420·7468·6520··ray·to·hold·the·00040e30:·0a20·2072·6567·6973·7465·723a·2072·7379··.··register:·rsy
00040e40:·6669·6e61·6c20·6c69·7374·206f·6620·6469··final·list·of·di00040e40:·736c·6f67·5f6f·6c64·5f69·6e63·0a20·2063··slog_old_inc.··c
00040e50:·6666·6572·656e·7420·6c6f·6720·6669·6c65··fferent·log·file00040e50:·6861·6e67·6564·5f77·6865·6e3a·2066·616c··hanged_when:·fal
00040e60:·2070·6174·6873·0a64·6563·6c61·7265·202d···paths.declare·-00040e60:·7365·0a20·2077·6865·6e3a·2061·6e73·6962··se.··when:·ansib
00040e70:·6120·4c4f·475f·4649·4c45·5f50·4154·4853··a·LOG_FILE_PATHS00040e70:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio
00040e80:·0a0a·2320·4172·7261·7920·746f·2068·6f6c··..#·Array·to·hol00040e80:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·["
00040e90:·6420·616c·6c20·7273·7973·6c6f·6720·636f··d·all·rsyslog·co00040e90:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",·
00040ea0:·6e66·6967·2065·6e74·7269·6573·0a52·5359··nfig·entries.RSY00040ea0:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma
00040eb0:·534c·4f47·5f43·4f4e·4649·4753·3d28·290a··SLOG_CONFIGS=().00040eb0:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"]
00040ec0:·5253·5953·4c4f·475f·434f·4e46·4947·533d··RSYSLOG_CONFIGS=00040ec0:·0a20·2074·6167·733a·0a20·202d·204e·4953··.··tags:.··-·NIS
00040ed0:·2822·247b·5253·5953·4c4f·475f·4554·435f··("${RSYSLOG_ETC_00040ed0:·542d·3830·302d·3533·2d41·432d·3628·3129··T-800-53-AC-6(1)
00040ee0:·434f·4e46·4947·7d22·2022·247b·5253·5953··CONFIG}"·"${RSYS00040ee0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
00040ef0:·4c4f·475f·494e·434c·5544·455f·434f·4e46··LOG_INCLUDE_CONF00040ef0:·2d43·4d2d·3628·6129·0a20·202d·2050·4349··-CM-6(a).··-·PCI
00040f00:·4947·5b40·5d7d·2220·2224·7b52·5359·534c··IG[@]}"·"${RSYSL00040f00:·2d44·5353·2d52·6571·2d31·302e·352e·310a··-DSS-Req-10.5.1.
00040f10:·4f47·5f49·4e43·4c55·4445·5b40·5d7d·2229··OG_INCLUDE[@]}")00040f10:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req-
00040f20:·0a0a·2320·4765·7420·6675·6c6c·206c·6973··..#·Get·full·lis00040f20:·3130·2e35·2e32·0a20·202d·2050·4349·2d44··10.5.2.··-·PCI-D
00040f30:·7420·6f66·2066·696c·6573·2074·6f20·6265··t·of·files·to·be00040f30:·5353·7634·2d31·302e·332e·320a·2020·2d20··SSv4-10.3.2.··-·
00040f40:·2063·6865·636b·6564·0a23·2052·5359·534c···checked.#·RSYSL00040f40:·636f·6e66·6967·7572·655f·7374·7261·7465··configure_strate
00040f50:·4f47·5f43·4f4e·4649·4753·206d·6179·2063··OG_CONFIGS·may·c00040f50:·6779·0a20·202d·206c·6f77·5f63·6f6d·706c··gy.··-·low_compl
00040f60:·6f6e·7461·696e·2067·6c6f·6273·2073·7563··ontain·globs·suc00040f60:·6578·6974·790a·2020·2d20·6d65·6469·756d··exity.··-·medium
00040f70:·6820·6173·0a23·202f·6574·632f·7273·7973··h·as.#·/etc/rsys00040f70:·5f64·6973·7275·7074·696f·6e0a·2020·2d20··_disruption.··-·
00040f80:·6c6f·672e·642f·2a2e·636f·6e66·202f·6574··log.d/*.conf·/et00040f80:·6d65·6469·756d·5f73·6576·6572·6974·790a··medium_severity.
00040f90:·632f·7273·7973·6c6f·672e·642f·2a2e·6672··c/rsyslog.d/*.fr00040f90:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne
00040fa0:·756c·650a·2320·536f·2c20·6c6f·6f70·206f··ule.#·So,·loop·o00040fa0:·6564·6564·0a20·202d·2072·7379·736c·6f67··eded.··-·rsyslog
00040fb0:·7665·7220·7468·6520·656e·7472·6965·7320··ver·the·entries·00040fb0:·5f66·696c·6573·5f67·726f·7570·6f77·6e65··_files_groupowne
00040fc0:·696e·2052·5359·534c·4f47·5f43·4f4e·4649··in·RSYSLOG_CONFI00040fc0:·7273·6869·700a·0a2d·206e·616d·653a·2045··rship..-·name:·E
00040fd0:·4753·2061·6e64·2075·7365·2066·696e·6420··GS·and·use·find·00040fd0:·6e73·7572·6520·4c6f·6720·4669·6c65·7320··nsure·Log·Files·
00040fe0:·746f·2067·6574·2074·6865·206c·6973·7420··to·get·the·list·00040fe0:·4172·6520·4f77·6e65·6420·4279·2041·7070··Are·Owned·By·App
00040ff0:·6f66·2069·6e63·6c75·6465·6420·6669·6c65··of·included·file00040ff0:·726f·7072·6961·7465·2047·726f·7570·202d··ropriate·Group·-
00041000:·732e·0a52·5359·534c·4f47·5f43·4f4e·4649··s..RSYSLOG_CONFI00041000:·2047·6574·2069·6e63·6c75·6465·2066·696c···Get·include·fil
00041010:·475f·4649·4c45·533d·2829·0a66·6f72·2045··G_FILES=().for·E00041010:·6573·2064·6972·6563·7469·7665·730a·2020··es·directives.··
00041020:·4e54·5259·2069·6e20·2224·7b52·5359·534c··NTRY·in·"${RSYSL00041020:·616e·7369·626c·652e·6275·696c·7469·6e2e··ansible.builtin.
00041030:·4f47·5f43·4f4e·4649·4753·5b40·5d7d·220a··OG_CONFIGS[@]}".00041030:·7368·656c·6c3a·207c·0a20·2020·2073·6574··shell:·|.····set
00041040:·646f·0a09·2320·4966·2064·6972·6563·746f··do..#·If·directo00041040:·202d·6f20·7069·7065·6661·696c·0a20·2020···-o·pipefail.···
00041050:·7279·2c20·7273·7973·6c6f·6720·7769·6c6c··ry,·rsyslog·will00041050:·2061·776b·2027·2f29·2f7b·663d·307d·202f···awk·'/)/{f=0}·/
00041060:·2073·6561·7263·6820·666f·7220·636f·6e66···search·for·conf00041060:·696e·636c·7564·655c·282f·7b66·3d31·7d20··include\(/{f=1}·
Max diff block lines reached; 978624/1080660 bytes (90.56%) of diff not shown.
133 KB
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Ubuntu·22.0439 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Ubuntu·22.04
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard
41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
42 ····*·cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~42 ····*·cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~
43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
44 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8444 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
49 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l49 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
51 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s51 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
52 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s52 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
Offset 289, 137 lines modifiedOffset 289, 14 lines modified
289 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-007-3·R2.1,·CIP-007-3·R2.2,·CIP-007-3·R2.3,·CIP-289 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-007-3·R2.1,·CIP-007-3·R2.2,·CIP-007-3·R2.3,·CIP-
290 ···························007-3·R5.1,·CIP-007-3·R5.1.1,·CIP-007-3·R5.1.2290 ···························007-3·R5.1,·CIP-007-3·R5.1.1,·CIP-007-3·R5.1.2
291 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)291 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)
292 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5292 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5
293 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.5.1,·Req-10.5.2293 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.5.1,·Req-10.5.2
294 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71294 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71
295 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.3.2295 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.3.2
296 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
297 #·Remediation·is·applicable·only·in·certain·platforms 
298 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
299 #·List·of·log·file·paths·to·be·inspected·for·correct·permissions 
300 #·*·Primarily·inspect·log·file·paths·listed·in·/etc/rsyslog.conf 
301 RSYSLOG_ETC_CONFIG="/etc/rsyslog.conf" 
302 #·*·And·also·the·log·file·paths·listed·after·rsyslog's·$IncludeConfig·directive 
303 #···(store·the·result·into·array·for·the·case·there's·shell·glob·used·as·value 
304 of·IncludeConfig) 
305 readarray·-t·OLD_INC·<·<(grep·-e·"\$IncludeConfig[[:space:]]\+[^[:space:];]\+"·/ 
306 etc/rsyslog.conf·|·cut·-d·'·'·-f·2) 
307 readarray·-t·RSYSLOG_INCLUDE_CONFIG·<·<(for·INCPATH·in·"${OLD_INC[@]}";·do·eval 
308 printf·'%s\\n'·"${INCPATH}";·done) 
309 readarray·-t·NEW_INC·<·<(sed·-n·'/^\s*include(/,/)/Ip'·/etc/rsyslog.conf·|·sed·- 
310 n·'s@.*file\s*=\s*"\([/[:alnum:][:punct:]]*\)".*@\1@Ip') 
311 readarray·-t·RSYSLOG_INCLUDE·<·<(for·INCPATH·in·"${NEW_INC[@]}";·do·eval·printf 
312 '%s\\n'·"${INCPATH}";·done) 
  
313 #·Declare·an·array·to·hold·the·final·list·of·different·log·file·paths 
314 declare·-a·LOG_FILE_PATHS 
  
315 #·Array·to·hold·all·rsyslog·config·entries 
316 RSYSLOG_CONFIGS=() 
317 RSYSLOG_CONFIGS=("${RSYSLOG_ETC_CONFIG}"·"${RSYSLOG_INCLUDE_CONFIG[@]}"·"$ 
318 {RSYSLOG_INCLUDE[@]}") 
  
319 #·Get·full·list·of·files·to·be·checked 
320 #·RSYSLOG_CONFIGS·may·contain·globs·such·as 
321 #·/etc/rsyslog.d/*.conf·/etc/rsyslog.d/*.frule 
322 #·So,·loop·over·the·entries·in·RSYSLOG_CONFIGS·and·use·find·to·get·the·list·of 
323 included·files. 
324 RSYSLOG_CONFIG_FILES=() 
325 for·ENTRY·in·"${RSYSLOG_CONFIGS[@]}" 
326 do 
327 »       #·If·directory,·rsyslog·will·search·for·config·files·in·recursively. 
328 »       #·However,·files·in·hidden·sub-directories·or·hidden·files·will·be·ignored. 
329 »       if·[·-d·"${ENTRY}"·] 
330 »       then 
331 »       »       readarray·-t·FINDOUT·<·<(find·"${ENTRY}"·-not·-path·'*/.*'·-type·f) 
332 »       »       RSYSLOG_CONFIG_FILES+=("${FINDOUT[@]}") 
333 »       elif·[·-f·"${ENTRY}"·] 
334 »       then 
335 »       »       RSYSLOG_CONFIG_FILES+=("${ENTRY}") 
336 »       else 
337 »       »       echo·"Invalid·include·object:·${ENTRY}" 
338 »       fi 
339 done 
  
340 #·Browse·each·file·selected·above·as·containing·paths·of·log·files 
341 #·('/etc/rsyslog.conf'·and·'/etc/rsyslog.d/*.conf'·in·the·default·configuration) 
342 for·LOG_FILE·in·"${RSYSLOG_CONFIG_FILES[@]}" 
343 do 
344 »       #·From·each·of·these·files·extract·just·particular·log·file·path(s),·thus: 
345 »       #·*·Ignore·lines·starting·with·space·('·'),·comment·('#"),·or·variable·syntax 
346 ('$')·characters, 
347 »       #·*·Ignore·empty·lines, 
348 »       #·*·Strip·quotes·and·closing·brackets·from·paths. 
349 »       #·*·Ignore·paths·that·match·/dev|/etc.*\.conf,·as·those·are·paths,·but·likely 
350 not·log·files 
351 »       #·*·From·the·remaining·valid·rows·select·only·fields·constituting·a·log·file 
352 path 
353 »       #·Text·file·column·is·understood·to·represent·a·log·file·path·if·and·only·if 
354 all·of·the 
355 »       #·following·are·met: 
356 »       #·*·it·contains·at·least·one·slash·'/'·character, 
357 »       #·*·it·is·preceded·by·space 
358 »       #·*·it·doesn't·contain·space·('·'),·colon·(':'),·and·semicolon·(';')·characters 
359 »       #·Search·log·file·for·path(s)·only·in·case·it·exists! 
360 »       if·[[·-f·"${LOG_FILE}"·]] 
361 »       then 
362 »       »       NORMALIZED_CONFIG_FILE_LINES=$(sed·-e·"/^[#|$]/d"·"${LOG_FILE}") 
363 »       »       LINES_WITH_PATHS=$(grep·'[^/]*\s\+\S*/\S\+$'·<<<·"$ 
364 {NORMALIZED_CONFIG_FILE_LINES}") 
365 »       »       FILTERED_PATHS=$(awk·'{if(NF>=2&&($NF~/^\//||$NF~/^-\//)){sub(/^-\//,"/ 
366 ",$NF);print·$NF}}'·<<<·"${LINES_WITH_PATHS}") 
367 »       »       CLEANED_PATHS=$(sed·-e·"s/[\"')]//g;·/\\/etc.*\.conf/d;·/\\/dev\\//d"·<<<·"$ 
368 {FILTERED_PATHS}") 
369 »       »       MATCHED_ITEMS=$(sed·-e·"/^$/d"·<<<·"${CLEANED_PATHS}") 
370 »       »       #·Since·above·sed·command·might·return·more·than·one·item·(delimited·by 
371 newline),·split 
372 »       »       #·the·particular·matches·entries·into·new·array·specific·for·this·log·file 
373 »       »       readarray·-t·ARRAY_FOR_LOG_FILE·<<<·"$MATCHED_ITEMS" 
374 »       »       #·Concatenate·the·two·arrays·-·previous·content·of·$LOG_FILE_PATHS·array·with 
375 »       »       #·items·from·newly·created·array·for·this·log·file 
376 »       »       LOG_FILE_PATHS+=("${ARRAY_FOR_LOG_FILE[@]}") 
377 »       »       #·Delete·the·temporary·array 
378 »       »       unset·ARRAY_FOR_LOG_FILE 
379 »       fi 
380 done 
  
381 #·Check·for·RainerScript·action·log·format·which·might·be·also·multiline·so·grep 
382 regex·is·a·bit 
383 #·curly: 
384 #·extract·possibly·multiline·action·omfile·expressions 
385 #·extract·File="logfile"·expression 
386 #·match·only·"logfile"·expression 
387 for·LOG_FILE·in·"${RSYSLOG_CONFIG_FILES[@]}" 
388 do 
389 »       ACTION_OMFILE_LINES=$(grep·-iozP·"action\s*\(\s*type\s*=\s*\"omfile\"[^\)]*\)" 
390 "${LOG_FILE}") 
391 »       OMFILE_LINES=$(echo·"${ACTION_OMFILE_LINES}"|·grep·-iaoP·"\bFile\s*=\s*\"([/[: 
392 alnum:][:punct:]]*)\"\s*\)") 
393 »       LOG_FILE_PATHS+=("$(echo·"${OMFILE_LINES}"|·grep·-oE·"\"([/[:alnum:][:punct: 
Max diff block lines reached; 129828/136438 bytes (95.16%) of diff not shown.
17.9 MB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-stig.html
    
Offset 14298, 15 lines modifiedOffset 14298, 15 lines modified
00037d90:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre00037d90:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre
00037da0:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str00037da0:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str
00037db0:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro00037db0:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro
00037dc0:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><00037dc0:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><
00037dd0:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st00037dd0:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st
00037de0:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········00037de0:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········
00037df0:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of00037df0:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of
00037e00:·2032·3032·362d·3031·2d30·3829·0a20·2020···2026-01-08).···00037e00:·2032·3032·342d·3132·2d30·3729·0a20·2020···2024-12-07).···
00037e10:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l00037e10:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l
00037e20:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h200037e20:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h2
00037e30:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten00037e30:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten
00037e40:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><00037e40:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><
00037e50:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o00037e50:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o
00037e60:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co00037e60:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co
00037e70:·6e74·656e·745f·6772·6f75·705f·7379·7374··ntent_group_syst00037e70:·6e74·656e·745f·6772·6f75·705f·7379·7374··ntent_group_syst
Offset 15104, 130 lines modifiedOffset 15104, 130 lines modified
0003aff0:·6574·3d22·2369·646d·3239·3033·2220·7461··et="#idm2903"·ta0003aff0:·6574·3d22·2369·646d·3239·3033·2220·7461··et="#idm2903"·ta
0003b000:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003b000:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003b010:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003b010:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003b020:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003b020:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003b030:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003b030:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003b040:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003b040:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003b050:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003b050:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003b060:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin
 0003b070:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 0003b080:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003b090:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003b0a0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003b0b0:·6d32·3930·3322·3e3c·7072·653e·3c63·6f64··m2903"><pre><cod
 0003b0c0:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]].
 0003b0d0:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve
 0003b0e0:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co
0003b060:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
0003b070:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b080:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b090:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b0a0:·2269·646d·3239·3033·223e·3c74·6162·6c65··"idm2903"><table 
0003b0b0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003b0c0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003b0d0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003b0e0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003b0f0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003b100:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b110:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003b120:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003b130:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b140:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003b150:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003b160:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003b170:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0003b180:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0003b190:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003b1a0:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation· 
0003b1b0:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on 
0003b1c0:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl 
0003b1d0:·6174·666f·726d·730a·6966·205b·2021·202d··atforms.if·[·!·- 
0003b1e0:·6620·2f2e·646f·636b·6572·656e·7620·5d20··f·/.dockerenv·]· 
0003b1f0:·2661·6d70·3b26·616d·703b·205b·2021·202d··&amp;&amp;·[·!·- 
0003b200:·6620·2f72·756e·2f2e·636f·6e74·6169·6e65··f·/run/.containe 
0003b210:·7265·6e76·205d·3b20·7468·656e·0a0a·4445··renv·];·then..DE 
0003b220:·4249·414e·5f46·524f·4e54·454e·443d·6e6f··BIAN_FRONTEND=no 
0003b230:·6e69·6e74·6572·6163·7469·7665·2061·7074··ninteractive·apt 
0003b240:·2d67·6574·2069·6e73·7461·6c6c·202d·7920··-get·install·-y· 
0003b250:·2261·6964·6522·0a0a·656c·7365·0a20·2020··"aide"..else.··· 
0003b260:·2026·6774·3b26·616d·703b·3220·6563·686f···&gt;&amp;2·echo 
0003b270:·2027·5265·6d65·6469·6174·696f·6e20·6973···'Remediation·is 
0003b280:·206e·6f74·2061·7070·6c69·6361·626c·652c···not·applicable, 
0003b290:·206e·6f74·6869·6e67·2077·6173·2064·6f6e···nothing·was·don 
0003b2a0:·6527·0a66·690a·3c2f·636f·6465·3e3c·2f70··e'.fi.</code></p 
0003b2b0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003b2c0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003b2d0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003b2e0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003b2f0:·7461·7267·6574·3d22·2369·646d·3239·3034··target="#idm2904 
0003b300:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003b310:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003b320:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003b330:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003b340:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003b350:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003b360:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip 
0003b370:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003b380:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b390:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b3a0:·7365·2220·6964·3d22·6964·6d32·3930·3422··se"·id="idm2904" 
0003b3b0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003b3c0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003b3d0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003b3e0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003b3f0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003b400:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003b410:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b420:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003b430:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b440:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003b450:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003b460:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003b470:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003b480:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003b490:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003b4a0:·7265·3e3c·636f·6465·3e2d·206e·616d·653a··re><code>-·name: 
0003b4b0:·2045·6e73·7572·6520·6169·6465·2069·7320···Ensure·aide·is· 
0003b4c0:·696e·7374·616c·6c65·640a·2020·7061·636b··installed.··pack 
0003b4d0:·6167·653a·0a20·2020·206e·616d·653a·2061··age:.····name:·a 
0003b4e0:·6964·650a·2020·2020·7374·6174·653a·2070··ide.····state:·p 
0003b4f0:·7265·7365·6e74·0a20·2077·6865·6e3a·2061··resent.··when:·a 
0003b500:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz 
0003b510:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i 
0003b520:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx 
0003b530:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p 
0003b540:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain 
0003b550:·6572·225d·0a20·2074·6167·733a·0a20·202d··er"].··tags:.··- 
0003b560:·2043·4a49·532d·352e·3130·2e31·2e33·0a20···CJIS-5.10.1.3.· 
0003b570:·202d·2044·4953·412d·5354·4947·2d55·4254···-·DISA-STIG-UBT 
0003b580:·552d·3232·2d36·3531·3031·300a·2020·2d20··U-22-651010.··-· 
0003b590:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6 
0003b5a0:·2861·290a·2020·2d20·5043·492d·4453·532d··(a).··-·PCI-DSS- 
0003b5b0:·5265·712d·3131·2e35·0a20·202d·2050·4349··Req-11.5.··-·PCI 
0003b5c0:·2d44·5353·7634·2d31·312e·352e·320a·2020··-DSSv4-11.5.2.·· 
0003b5d0:·2d20·656e·6162·6c65·5f73·7472·6174·6567··-·enable_strateg 
0003b5e0:·790a·2020·2d20·6c6f·775f·636f·6d70·6c65··y.··-·low_comple 
0003b5f0:·7869·7479·0a20·202d·206c·6f77·5f64·6973··xity.··-·low_dis 
0003b600:·7275·7074·696f·6e0a·2020·2d20·6d65·6469··ruption.··-·medi 
0003b610:·756d·5f73·6576·6572·6974·790a·2020·2d20··um_severity.··-· 
0003b620:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed 
0003b630:·0a20·202d·2070·6163·6b61·6765·5f61·6964··.··-·package_aid 
0003b640:·655f·696e·7374·616c·6c65·640a·3c2f·636f··e_installed.</co 
Max diff block lines reached; 17506334/17524052 bytes (99.90%) of diff not shown.
1.16 MB
html2text {}
    
Offset 41, 15 lines modifiedOffset 41, 15 lines modified
41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Canonical·Ubuntu·22.04·LTS·Security·Technical·Implementation41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Canonical·Ubuntu·22.04·LTS·Security·Technical·Implementation
42 ··············Guide·(STIG)·V1R142 ··············Guide·(STIG)·V1R1
43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_stig43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_stig
44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
45 ····*·cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~45 ····*·cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~
46 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
47 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8447 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
48 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)48 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
49 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*49 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
50 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s50 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
51 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e51 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
52 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l52 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
53 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r53 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
54 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n54 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
55 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g55 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 125, 27 lines modifiedOffset 125, 19 lines modified
125 include·install_aide125 include·install_aide
  
126 class·install_aide·{126 class·install_aide·{
127 ··package·{·'aide':127 ··package·{·'aide':
128 ····ensure·=>·'installed',128 ····ensure·=>·'installed',
129 ··}129 ··}
130 }130 }
 131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
136 #·Remediation·is·applicable·only·in·certain·platforms 
137 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
138 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide" 
  
139 else 
140 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
141 fi132 [[packages]]
 133 name·=·"aide"
 134 version·=·"*"
142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
147 -·name:·Ensure·aide·is·installed140 -·name:·Ensure·aide·is·installed
148 ··package:141 ··package:
Offset 160, 19 lines modifiedOffset 152, 27 lines modified
160 ··-·PCI-DSSv4-11.5.2152 ··-·PCI-DSSv4-11.5.2
161 ··-·enable_strategy153 ··-·enable_strategy
162 ··-·low_complexity154 ··-·low_complexity
163 ··-·low_disruption155 ··-·low_disruption
164 ··-·medium_severity156 ··-·medium_severity
165 ··-·no_reboot_needed157 ··-·no_reboot_needed
166 ··-·package_aide_installed158 ··-·package_aide_installed
167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 160 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 161 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 162 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 163 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 164 #·Remediation·is·applicable·only·in·certain·platforms
 165 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
168 [[packages]] 
169 name·=·"aide" 
170 version·=·"*"166 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide"
  
 167 else
 168 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 169 fi
171 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*170 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
172 Run·the·following·command·to·generate·a·new·database:171 Run·the·following·command·to·generate·a·new·database:
173 $·sudo·aideinit172 $·sudo·aideinit
174 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the173 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the
175 configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these·files),·in·a·secure174 configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these·files),·in·a·secure
176 location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-175 location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-
177 generated·database·can·be·installed·as·follows:176 generated·database·can·be·installed·as·follows:
Offset 197, 40 lines modifiedOffset 197, 14 lines modified
197 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3197 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
198 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5198 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
199 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199199 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
200 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-22-651015200 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-22-651015
201 ············_\x8c_\x8i_\x8s············1.3.1201 ············_\x8c_\x8i_\x8s············1.3.1
202 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79202 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
203 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2203 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
205 #·Remediation·is·applicable·only·in·certain·platforms 
206 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
207 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide" 
  
208 AIDE_CONFIG=/etc/aide/aide.conf 
209 DEFAULT_DB_PATH=/var/lib/aide/aide.db 
  
210 #·Fix·db·path·in·the·config·file,·if·necessary 
211 if·!·grep·-q·'^database=file:'·${AIDE_CONFIG};·then 
212 ····#·replace_or_append·gets·confused·by·'database=file'·as·a·key,·so·should·not·be·used. 
213 ····#replace_or_append·"${AIDE_CONFIG}"·'^database=file'·"${DEFAULT_DB_PATH}"·'@CCENUM@'·'%s:%s' 
214 ····echo·"database=file:${DEFAULT_DB_PATH}"·>>·${AIDE_CONFIG} 
215 fi 
  
216 #·Fix·db·out·path·in·the·config·file,·if·necessary 
217 if·!·grep·-q·'^database_out=file:'·${AIDE_CONFIG};·then 
218 ····echo·"database_out=file:${DEFAULT_DB_PATH}.new"·>>·${AIDE_CONFIG} 
219 fi 
  
220 /usr/sbin/aideinit·-y·-f 
  
221 else 
222 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
223 fi 
224 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
225 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
226 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
227 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
228 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
229 -·name:·Build·and·Test·AIDE·Database·-·Ensure·AIDE·Is·Installed209 -·name:·Build·and·Test·AIDE·Database·-·Ensure·AIDE·Is·Installed
230 ··ansible.builtin.apt:210 ··ansible.builtin.apt:
Offset 393, 14 lines modifiedOffset 367, 40 lines modified
393 ··-·PCI-DSSv4-11.5.2367 ··-·PCI-DSSv4-11.5.2
394 ··-·aide_build_database368 ··-·aide_build_database
395 ··-·low_complexity369 ··-·low_complexity
396 ··-·low_disruption370 ··-·low_disruption
397 ··-·medium_severity371 ··-·medium_severity
398 ··-·no_reboot_needed372 ··-·no_reboot_needed
399 ··-·restrict_strategy373 ··-·restrict_strategy
 374 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 375 #·Remediation·is·applicable·only·in·certain·platforms
Max diff block lines reached; 1208701/1215329 bytes (99.45%) of diff not shown.
2.38 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ds.xml
2.38 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ds.xml
Max HTML report size reached
667 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ocil.xml
667 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ocil.xml
Ordering differences only
    
Offset 3, 5591 lines modifiedOffset 3, 5781 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-package_rsyslog_installed_ocil:questionnaire:1">
 11 ······<ocil:title>Ensure·rsyslog·is·Installed</ocil:title>
11 ······<ocil:title>Disable·SSH·Root·Login</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1"> 
17 ······<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-package_rsyslog_installed_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_ipv6_option_disabled_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-service_timesyncd_enabled_ocil:questionnaire:1">
23 ······<ocil:title>Disable·IPv6·Networking·Support·Automatic·Loading</ocil:title>17 ······<ocil:title>Enable·systemd_timesyncd·Service</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-kernel_module_ipv6_option_disabled_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-service_timesyncd_enabled_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_memory_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-service_iptables_enabled_ocil:questionnaire:1">
29 ······<ocil:title>Randomize·the·kernel·memory·sections</ocil:title>23 ······<ocil:title>Verify·iptables·Enabled</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_randomize_memory_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-service_iptables_enabled_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_bug_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-no_direct_root_logins_ocil:questionnaire:1">
35 ······<ocil:title>Enable·support·for·BUG()</ocil:title>29 ······<ocil:title>Direct·root·Logins·Not·Allowed</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-kernel_config_bug_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-no_direct_root_logins_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_base_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_audit_configuration_ocil:questionnaire:1">
41 ······<ocil:title>Randomize·the·address·of·the·kernel·image·(KASLR)</ocil:title>35 ······<ocil:title>Audit·Configuration·Files·Must·Be·Owned·By·Root</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-kernel_config_randomize_base_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_ownership_audit_configuration_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-prefer_64bit_os_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_syslog_ocil:questionnaire:1">
47 ······<ocil:title>Prefer·to·use·a·64-bit·Operating·System·when·supported</ocil:title>41 ······<ocil:title>Verify·User·Who·Owns·/var/log/syslog·File</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-prefer_64bit_os_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_syslog_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_shadow_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-grub2_mce_argument_ocil:questionnaire:1">
53 ······<ocil:title>Verify·Permissions·on·shadow·File</ocil:title>47 ······<ocil:title>Force·kernel·panic·on·uncorrected·MCEs</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_shadow_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-grub2_mce_argument_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_shadow_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_home_dirs_ocil:questionnaire:1">
59 ······<ocil:title>Verify·Group·Who·Owns·shadow·File</ocil:title>53 ······<ocil:title>Ensure·that·User·Home·Directories·are·not·Group-Writable·or·World-Readable</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_shadow_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-file_permissions_home_dirs_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_passwd_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_password_login_ocil:questionnaire:1">
65 ······<ocil:title>Verify·User·Who·Owns·passwd·File</ocil:title>59 ······<ocil:title>Disable·SSH·root·Login·with·a·Password·(Insecure)</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_passwd_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_password_login_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_priv_separation_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-auditd_freq_ocil:questionnaire:1">
71 ······<ocil:title>Enable·Use·of·Privilege·Separation</ocil:title>65 ······<ocil:title>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sshd_use_priv_separation_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-auditd_freq_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-dir_ownership_binary_dirs_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_ocil:questionnaire:1">
77 ······<ocil:title>Verify·that·System·Executable·Have·Root·Ownership</ocil:title>71 ······<ocil:title>Ensure·/var·Located·On·Separate·Partition</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-dir_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_gshadow_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_profile_ocil:questionnaire:1">
83 ······<ocil:title>Verify·Permissions·on·Backup·gshadow·File</ocil:title>77 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·/etc/profile</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_profile_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmodat_ocil:questionnaire:1"> 
89 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmodat</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_all_shadowed_ocil:questionnaire:1">
 83 ······<ocil:title>Verify·All·Account·Password·Hashes·are·Shadowed</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmodat_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-accounts_password_all_shadowed_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-partition_for_tmp_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-accounts_minimum_age_login_defs_ocil:questionnaire:1">
95 ······<ocil:title>Ensure·/tmp·Located·On·Separate·Partition</ocil:title>89 ······<ocil:title>Set·Password·Minimum·Age</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-partition_for_tmp_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-accounts_minimum_age_login_defs_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_net_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-harden_ssh_client_crypto_policy_ocil:questionnaire:1">
101 ······<ocil:title>Enable·SSH·Warning·Banner</ocil:title>95 ······<ocil:title>Harden·SSH·client·Crypto·Policy</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_net_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-harden_ssh_client_crypto_policy_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-chronyd_specify_remote_server_ocil:questionnaire:1"> 
107 ······<ocil:title>A·remote·time·server·for·Chrony·is·configured</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_syslog_ocil:questionnaire:1">
 101 ······<ocil:title>Verify·Permissions·on·/var/log/syslog·File</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-chronyd_specify_remote_server_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_syslog_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_rename_ocil:questionnaire:1"> 
113 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·rename</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-package_openssh-server_installed_ocil:questionnaire:1">
 107 ······<ocil:title>Install·the·OpenSSH·Server·Package</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rename_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-package_openssh-server_installed_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_messages_ocil:questionnaire:1"> 
119 ······<ocil:title>Verify·Permissions·on·/var/log/messages·File</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_net_ocil:questionnaire:1">
 113 ······<ocil:title>Enable·SSH·Warning·Banner</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_messages_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_net_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
123 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_on_oops_ocil:questionnaire:1">
Max diff block lines reached; 671025/683178 bytes (98.22%) of diff not shown.
1.65 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-xccdf.xml
1.65 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-XENIAL"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-XENIAL"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·16.04</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·16.04</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·Ubuntu·16.04.·It·is·a·rendering·of7 configuration·settings·for·Ubuntu·16.04.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
Offset 72, 157 lines modifiedOffset 72, 157 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="package_shadow-utils">79 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
 80 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 82 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
 83 ······</cpe-lang:logical-test>
 84 ····</cpe-lang:platform>
 85 ····<cpe-lang:platform·id="grub2">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">86 ······<cpe-lang:logical-test·operator="AND"·negate="false">
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
82 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
83 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
84 ····<cpe-lang:platform·id="package_ntp">90 ····<cpe-lang:platform·id="machine">
85 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
87 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="aarch64_arch">95 ····<cpe-lang:platform·id="package_iptables">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
92 ······</cpe-lang:logical-test>98 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>99 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="machine">100 ····<cpe-lang:platform·id="machine_and_package_ufw">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">101 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
 103 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
97 ······</cpe-lang:logical-test>104 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>105 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="x86_64_arch">106 ····<cpe-lang:platform·id="not_aarch64_arch">
 107 ······<cpe-lang:logical-test·operator="AND"·negate="true">
 108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 109 ······</cpe-lang:logical-test>
 110 ····</cpe-lang:platform>
 111 ····<cpe-lang:platform·id="package_ntp">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">112 ······<cpe-lang:logical-test·operator="AND"·negate="false">
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
102 ······</cpe-lang:logical-test>114 ······</cpe-lang:logical-test>
103 ····</cpe-lang:platform>115 ····</cpe-lang:platform>
104 ····<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">116 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
105 ······<cpe-lang:logical-test·operator="AND"·negate="false">117 ······<cpe-lang:logical-test·operator="AND"·negate="false">
106 ········<cpe-lang:logical-test·operator="AND"·negate="true">118 ········<cpe-lang:logical-test·operator="AND"·negate="true">
107 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>119 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
108 ········</cpe-lang:logical-test>120 ········</cpe-lang:logical-test>
109 ········<cpe-lang:logical-test·operator="AND"·negate="true">121 ········<cpe-lang:logical-test·operator="AND"·negate="true">
110 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>122 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
111 ········</cpe-lang:logical-test>123 ········</cpe-lang:logical-test>
 124 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
 125 ······</cpe-lang:logical-test>
 126 ····</cpe-lang:platform>
 127 ····<cpe-lang:platform·id="package_pam">
 128 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 129 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
112 ······</cpe-lang:logical-test>130 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>131 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="package_logrotate">132 ····<cpe-lang:platform·id="package_logrotate">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">133 ······<cpe-lang:logical-test·operator="AND"·negate="false">
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>134 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
117 ······</cpe-lang:logical-test>135 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>136 ····</cpe-lang:platform>
 137 ····<cpe-lang:platform·id="package_audit">
 138 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 139 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>
 140 ······</cpe-lang:logical-test>
 141 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="package_sudo">142 ····<cpe-lang:platform·id="package_sudo">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">143 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>144 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
122 ······</cpe-lang:logical-test>145 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>146 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="machine_and_package_ufw">147 ····<cpe-lang:platform·id="package_postfix">
 148 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
 150 ······</cpe-lang:logical-test>
 151 ····</cpe-lang:platform>
 152 ····<cpe-lang:platform·id="machine_and_package_iptables_and_service_disabled_firewalld">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">153 ······<cpe-lang:logical-test·operator="AND"·negate="false">
126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
 156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
128 ······</cpe-lang:logical-test>157 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>158 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="not_aarch64_arch">159 ····<cpe-lang:platform·id="package_chrony">
131 ······<cpe-lang:logical-test·operator="AND"·negate="true">160 ······<cpe-lang:logical-test·operator="AND"·negate="false">
132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
133 ······</cpe-lang:logical-test>162 ······</cpe-lang:logical-test>
134 ····</cpe-lang:platform>163 ····</cpe-lang:platform>
135 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">164 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">
136 ······<cpe-lang:logical-test·operator="AND"·negate="false">165 ······<cpe-lang:logical-test·operator="AND"·negate="false">
137 ········<cpe-lang:logical-test·operator="AND"·negate="true">166 ········<cpe-lang:logical-test·operator="AND"·negate="true">
138 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>167 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
139 ········</cpe-lang:logical-test>168 ········</cpe-lang:logical-test>
140 ········<cpe-lang:logical-test·operator="AND"·negate="true">169 ········<cpe-lang:logical-test·operator="AND"·negate="true">
141 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>170 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
142 ········</cpe-lang:logical-test>171 ········</cpe-lang:logical-test>
143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
144 ······</cpe-lang:logical-test> 
145 ····</cpe-lang:platform> 
146 ····<cpe-lang:platform·id="package_systemd"> 
147 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/> 
149 ······</cpe-lang:logical-test> 
150 ····</cpe-lang:platform> 
151 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch"> 
152 ······<cpe-lang:logical-test·operator="OR"·negate="false"> 
153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/> 
155 ······</cpe-lang:logical-test>172 ······</cpe-lang:logical-test>
156 ····</cpe-lang:platform>173 ····</cpe-lang:platform>
157 ····<cpe-lang:platform·id="package_gdm">174 ····<cpe-lang:platform·id="package_gdm">
158 ······<cpe-lang:logical-test·operator="AND"·negate="false">175 ······<cpe-lang:logical-test·operator="AND"·negate="false">
Max diff block lines reached; 1721530/1733900 bytes (99.29%) of diff not shown.
2.54 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ds.xml
2.54 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ds.xml
Max HTML report size reached
699 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ocil.xml
699 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ocil.xml
Ordering differences only
    
Offset 3, 5478 lines modifiedOffset 3, 5577 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_settimeofday_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1">
11 ······<ocil:title>Record·attempts·to·alter·time·through·settimeofday</ocil:title>11 ······<ocil:title>Limit·Users'·SSH·Access</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_settimeofday_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-sshd_limit_user_access_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_login_defs_ocil:questionnaire:1"> 
17 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·login.defs</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_ocil:questionnaire:1">
 17 ······<ocil:title>Disable·IPv6·Addressing·on·IPv6·Interfaces·by·Default</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_login_defs_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-mount_option_home_nodev_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-mount_option_tmp_nosuid_ocil:questionnaire:1">
23 ······<ocil:title>Add·nodev·Option·to·/home</ocil:title>23 ······<ocil:title>Add·nosuid·Option·to·/tmp</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-mount_option_home_nodev_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-mount_option_tmp_nosuid_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-package_nss-tools_installed_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_maxstartups_ocil:questionnaire:1">
29 ······<ocil:title>Ensure·nss-tools·is·installed</ocil:title>29 ······<ocil:title>Ensure·SSH·MaxStartups·is·configured</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-package_nss-tools_installed_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sshd_set_maxstartups_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-installed_OS_is_FIPS_certified_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_shadow_ocil:questionnaire:1">
35 ······<ocil:title>The·Installed·Operating·System·Is·FIPS·140-2·Certified</ocil:title>35 ······<ocil:title>Verify·User·Who·Owns·shadow·File</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-installed_OS_is_FIPS_certified_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_shadow_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_library_dirs_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-package_openssh-server_removed_ocil:questionnaire:1">
41 ······<ocil:title>Verify·that·Shared·Library·Files·Have·Restrictive·Permissions</ocil:title>41 ······<ocil:title>Remove·the·OpenSSH·Server·Package</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-file_permissions_library_dirs_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-package_openssh-server_removed_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_relayhost_ocil:questionnaire:1">
47 ······<ocil:title>Configure·ARP·filtering·for·All·IPv4·Interfaces</ocil:title>47 ······<ocil:title>Configure·System·to·Forward·All·Mail·through·a·specific·host</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_relayhost_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-partition_for_tmp_ocil:questionnaire:1">
53 ······<ocil:title>Disable·SSH·Root·Login</ocil:title>53 ······<ocil:title>Ensure·/tmp·Located·On·Separate·Partition</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-partition_for_tmp_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_gshadow_ocil:questionnaire:1"> 
59 ······<ocil:title>Verify·Permissions·on·Backup·gshadow·File</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_reboot_ocil:questionnaire:1">
 59 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·reboot</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_reboot_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1"> 
65 ······<ocil:title>Disable·X11·Forwarding</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_credentials_ocil:questionnaire:1">
 65 ······<ocil:title>Enable·checks·on·credential·management</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_credentials_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_group_ocil:questionnaire:1"> 
71 ······<ocil:title>Verify·User·Who·Owns·Backup·group·File</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-securetty_root_login_console_only_ocil:questionnaire:1">
 71 ······<ocil:title>Restrict·Virtual·Console·Root·Logins</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_group_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-securetty_root_login_console_only_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-mount_option_tmp_nosuid_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-package_audit_installed_ocil:questionnaire:1">
77 ······<ocil:title>Add·nosuid·Option·to·/tmp</ocil:title>77 ······<ocil:title>Ensure·the·audit·Subsystem·is·Installed</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-mount_option_tmp_nosuid_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-package_audit_installed_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_acpi_custom_method_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_shadow_ocil:questionnaire:1">
83 ······<ocil:title>Do·not·allow·ACPI·methods·to·be·inserted/replaced·at·run·time</ocil:title>83 ······<ocil:title>Verify·User·Who·Owns·Backup·shadow·File</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_acpi_custom_method_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-selinux_state_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-account_passwords_pam_faillock_dir_ocil:questionnaire:1">
89 ······<ocil:title>Ensure·SELinux·State·is·Enforcing</ocil:title>89 ······<ocil:title>Account·Lockouts·Must·Persist</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_dir_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-service_chronyd_enabled_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_rsa_ocil:questionnaire:1">
95 ······<ocil:title>The·Chronyd·service·is·enabled</ocil:title>95 ······<ocil:title>Disable·SSH·Support·for·Rhosts·RSA·Authentication</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-service_chronyd_enabled_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_rsa_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sudoers_no_command_negation_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_ocil:questionnaire:1">
101 ······<ocil:title>Don't·define·allowed·commands·in·sudoers·by·means·of·exclusion</ocil:title>101 ······<ocil:title>Set·SSH·Client·Alive·Count·Max</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sudoers_no_command_negation_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_tcp_forwarding_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-grub2_mce_argument_ocil:questionnaire:1">
107 ······<ocil:title>Disable·SSH·TCP·Forwarding</ocil:title>107 ······<ocil:title>Force·kernel·panic·on·uncorrected·MCEs</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_tcp_forwarding_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-grub2_mce_argument_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-no_netrc_files_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_hibernation_ocil:questionnaire:1">
113 ······<ocil:title>Verify·No·netrc·Files·Exist</ocil:title>113 ······<ocil:title>Disable·hibernation</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-no_netrc_files_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-kernel_config_hibernation_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-partition_for_home_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_home_dirs_ocil:questionnaire:1">
119 ······<ocil:title>Ensure·/home·Located·On·Separate·Partition</ocil:title>119 ······<ocil:title>Ensure·that·User·Home·Directories·are·not·Group-Writable·or·World-Readable</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-partition_for_home_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-file_permissions_home_dirs_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_group_ocil:questionnaire:1">124 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_shadow_ocil:questionnaire:1">
125 ······<ocil:title>Verify·Group·Who·Owns·group·File</ocil:title>125 ······<ocil:title>Verify·Permissions·on·shadow·File</ocil:title>
Max diff block lines reached; 702840/715198 bytes (98.27%) of diff not shown.
1.76 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-xccdf.xml
1.76 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-BIONIC"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_UBUNTU-BIONIC"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·18.04</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Ubuntu·18.04</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·Ubuntu·18.04.·It·is·a·rendering·of7 configuration·settings·for·Ubuntu·18.04.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
Offset 72, 181 lines modifiedOffset 72, 181 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="package_shadow-utils">79 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="OR"·negate="false">
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/> 
82 ······</cpe-lang:logical-test> 
83 ····</cpe-lang:platform> 
84 ····<cpe-lang:platform·id="package_ntp"> 
85 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/> 
87 ······</cpe-lang:logical-test> 
88 ····</cpe-lang:platform> 
89 ····<cpe-lang:platform·id="aarch64_arch"> 
90 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
92 ······</cpe-lang:logical-test> 
93 ····</cpe-lang:platform> 
94 ····<cpe-lang:platform·id="machine"> 
95 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
97 ······</cpe-lang:logical-test> 
98 ····</cpe-lang:platform> 
99 ····<cpe-lang:platform·id="x86_64_arch"> 
100 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>82 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
102 ······</cpe-lang:logical-test>83 ······</cpe-lang:logical-test>
103 ····</cpe-lang:platform>84 ····</cpe-lang:platform>
104 ····<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">85 ····<cpe-lang:platform·id="grub2">
105 ······<cpe-lang:logical-test·operator="AND"·negate="false">86 ······<cpe-lang:logical-test·operator="AND"·negate="false">
106 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
107 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/> 
108 ········</cpe-lang:logical-test> 
109 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
110 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
111 ········</cpe-lang:logical-test> 
112 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="package_logrotate">90 ····<cpe-lang:platform·id="machine">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
117 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="machine_and_mount_home">95 ····<cpe-lang:platform·id="machine_and_mount_tmp">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_home:def:1"/>98 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
123 ······</cpe-lang:logical-test>99 ······</cpe-lang:logical-test>
124 ····</cpe-lang:platform>100 ····</cpe-lang:platform>
125 ····<cpe-lang:platform·id="package_sudo">101 ····<cpe-lang:platform·id="package_iptables">
126 ······<cpe-lang:logical-test·operator="AND"·negate="false">102 ······<cpe-lang:logical-test·operator="AND"·negate="false">
127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>103 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
128 ······</cpe-lang:logical-test>104 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>105 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="machine_and_package_ufw">106 ····<cpe-lang:platform·id="machine_and_package_ufw">
131 ······<cpe-lang:logical-test·operator="AND"·negate="false">107 ······<cpe-lang:logical-test·operator="AND"·negate="false">
132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>109 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
134 ······</cpe-lang:logical-test>110 ······</cpe-lang:logical-test>
135 ····</cpe-lang:platform>111 ····</cpe-lang:platform>
136 ····<cpe-lang:platform·id="not_aarch64_arch">112 ····<cpe-lang:platform·id="not_aarch64_arch">
137 ······<cpe-lang:logical-test·operator="AND"·negate="true">113 ······<cpe-lang:logical-test·operator="AND"·negate="true">
138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>114 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
139 ······</cpe-lang:logical-test>115 ······</cpe-lang:logical-test>
140 ····</cpe-lang:platform>116 ····</cpe-lang:platform>
 117 ····<cpe-lang:platform·id="package_ntp">
 118 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
 120 ······</cpe-lang:logical-test>
 121 ····</cpe-lang:platform>
141 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">122 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
142 ······<cpe-lang:logical-test·operator="AND"·negate="false">123 ······<cpe-lang:logical-test·operator="AND"·negate="false">
143 ········<cpe-lang:logical-test·operator="AND"·negate="true">124 ········<cpe-lang:logical-test·operator="AND"·negate="true">
144 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>125 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
145 ········</cpe-lang:logical-test>126 ········</cpe-lang:logical-test>
146 ········<cpe-lang:logical-test·operator="AND"·negate="true">127 ········<cpe-lang:logical-test·operator="AND"·negate="true">
147 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>128 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
148 ········</cpe-lang:logical-test>129 ········</cpe-lang:logical-test>
149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>130 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
150 ······</cpe-lang:logical-test>131 ······</cpe-lang:logical-test>
151 ····</cpe-lang:platform>132 ····</cpe-lang:platform>
152 ····<cpe-lang:platform·id="package_systemd">133 ····<cpe-lang:platform·id="package_pam">
153 ······<cpe-lang:logical-test·operator="AND"·negate="false">134 ······<cpe-lang:logical-test·operator="AND"·negate="false">
154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>135 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
155 ······</cpe-lang:logical-test>136 ······</cpe-lang:logical-test>
156 ····</cpe-lang:platform>137 ····</cpe-lang:platform>
157 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">138 ····<cpe-lang:platform·id="package_logrotate">
158 ······<cpe-lang:logical-test·operator="OR"·negate="false">139 ······<cpe-lang:logical-test·operator="AND"·negate="false">
159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>140 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
161 ······</cpe-lang:logical-test>141 ······</cpe-lang:logical-test>
162 ····</cpe-lang:platform>142 ····</cpe-lang:platform>
163 ····<cpe-lang:platform·id="package_gdm">143 ····<cpe-lang:platform·id="package_audit">
164 ······<cpe-lang:logical-test·operator="AND"·negate="false">144 ······<cpe-lang:logical-test·operator="AND"·negate="false">
165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>
166 ······</cpe-lang:logical-test>146 ······</cpe-lang:logical-test>
167 ····</cpe-lang:platform>147 ····</cpe-lang:platform>
168 ····<cpe-lang:platform·id="package_postfix">148 ····<cpe-lang:platform·id="machine_and_mount_var-tmp">
169 ······<cpe-lang:logical-test·operator="AND"·negate="false">149 ······<cpe-lang:logical-test·operator="AND"·negate="false">
170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
 151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
171 ······</cpe-lang:logical-test>152 ······</cpe-lang:logical-test>
172 ····</cpe-lang:platform>153 ····</cpe-lang:platform>
173 ····<cpe-lang:platform·id="grub2">154 ····<cpe-lang:platform·id="package_sudo">
174 ······<cpe-lang:logical-test·operator="AND"·negate="false">155 ······<cpe-lang:logical-test·operator="AND"·negate="false">
175 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
176 ······</cpe-lang:logical-test>157 ······</cpe-lang:logical-test>
177 ····</cpe-lang:platform>158 ····</cpe-lang:platform>
178 ····<cpe-lang:platform·id="machine_and_mount_var-tmp">159 ····<cpe-lang:platform·id="machine_and_package_autofs">
179 ······<cpe-lang:logical-test·operator="AND"·negate="false">160 ······<cpe-lang:logical-test·operator="AND"·negate="false">
180 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
181 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>162 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
Max diff block lines reached; 1833395/1846043 bytes (99.31%) of diff not shown.
5.18 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ds.xml
5.18 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ds.xml
Max HTML report size reached
1.32 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ocil.xml
1.32 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ocil.xml
Ordering differences only
    
Offset 3, 4484 lines modifiedOffset 3, 4484 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sshd_use_approved_macs_ordered_stig_ocil:questionnaire:1"> 
11 ······<ocil:title>Use·Only·FIPS·140-2·Validated·MACs</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-sshd_use_approved_macs_ordered_stig_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_bug_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-sssd_offline_cred_expiration_ocil:questionnaire:1">
 11 ······<ocil:title>Configure·SSSD·to·Expire·Offline·Credentials</ocil:title>
17 ······<ocil:title>Enable·support·for·BUG()</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-kernel_config_bug_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-package_ntp_installed_ocil:questionnaire:1"> 
23 ······<ocil:title>Install·the·ntp·service</ocil:title> 
24 ······<ocil:actions>12 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-package_ntp_installed_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-sssd_offline_cred_expiration_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>14 ······</ocil:actions>
27 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_gshadow_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-package_xinetd_removed_ocil:questionnaire:1">
29 ······<ocil:title>Verify·User·Who·Owns·gshadow·File</ocil:title>17 ······<ocil:title>Uninstall·xinetd·Package</ocil:title>
30 ······<ocil:actions>18 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_gshadow_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-package_xinetd_removed_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>20 ······</ocil:actions>
33 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_hash_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_ocil:questionnaire:1">
35 ······<ocil:title>Specify·the·hash·to·use·when·signing·modules</ocil:title>23 ······<ocil:title>Enable·different·security·models</ocil:title>
36 ······<ocil:actions>24 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_hash_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>26 ······</ocil:actions>
39 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1"> 
41 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fremovexattr</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1">
 29 ······<ocil:title>Configure·Speculative·Store·Bypass·Mitigation</ocil:title>
42 ······<ocil:actions>30 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>32 ······</ocil:actions>
45 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_compat_brk_ocil:questionnaire:1"> 
47 ······<ocil:title>Disable·compatibility·with·brk()</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-ufw_only_required_services_ocil:questionnaire:1">
 35 ······<ocil:title>Only·Allow·Authorized·Network·Services·in·ufw</ocil:title>
48 ······<ocil:actions>36 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-kernel_config_compat_brk_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-ufw_only_required_services_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>38 ······</ocil:actions>
51 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_strictmodes_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_retry_ocil:questionnaire:1">
53 ······<ocil:title>Enable·Use·of·Strict·Mode·Checking</ocil:title>41 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Authentication·Retry·Prompts·Permitted·Per-Session</ocil:title>
54 ······<ocil:actions>42 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_strictmodes_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_retry_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>44 ······</ocil:actions>
57 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-clean_components_post_updating_ocil:questionnaire:1"> 
59 ······<ocil:title>Ensure·apt_get·Removes·Previous·Package·Versions</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_pubkey_auth_ocil:questionnaire:1">
 47 ······<ocil:title>Disable·PubkeyAuthentication·Authentication</ocil:title>
60 ······<ocil:actions>48 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-clean_components_post_updating_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_pubkey_auth_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>50 ······</ocil:actions>
63 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_library_dirs_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_x11_forwarding_ocil:questionnaire:1">
65 ······<ocil:title>Verify·that·Shared·Library·Files·Have·Restrictive·Permissions</ocil:title>53 ······<ocil:title>Enable·Encrypted·X11·Forwarding</ocil:title>
66 ······<ocil:actions>54 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_permissions_library_dirs_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>56 ······</ocil:actions>
69 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-display_login_attempts_ocil:questionnaire:1">
71 ······<ocil:title>Enable·Kernel·Parameter·to·Log·Martian·Packets·on·all·IPv4·Interfaces</ocil:title>59 ······<ocil:title>Ensure·PAM·Displays·Last·Logon/Access·Notification</ocil:title>
72 ······<ocil:actions>60 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-display_login_attempts_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>62 ······</ocil:actions>
75 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-package_rsync_removed_ocil:questionnaire:1">
77 ······<ocil:title>Ensure·the·Default·Bash·Umask·is·Set·Correctly</ocil:title>65 ······<ocil:title>Uninstall·rsync·Package</ocil:title>
78 ······<ocil:actions>66 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-package_rsync_removed_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>68 ······</ocil:actions>
81 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_gpasswd_ocil:questionnaire:1"> 
83 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·gpasswd</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_syslog_ocil:questionnaire:1">
 71 ······<ocil:title>Verify·User·Who·Owns·/var/log/syslog·File</ocil:title>
84 ······<ocil:actions>72 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_gpasswd_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_syslog_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>74 ······</ocil:actions>
87 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-encrypt_partitions_ocil:questionnaire:1">
89 ······<ocil:title>Ensure·/var·Located·On·Separate·Partition</ocil:title>77 ······<ocil:title>Encrypt·Partitions</ocil:title>
90 ······<ocil:actions>78 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-encrypt_partitions_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>80 ······</ocil:actions>
93 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-service_auditd_enabled_ocil:questionnaire:1"> 
95 ······<ocil:title>Enable·auditd·Service</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-policy_temp_passwords_immediate_change_ocil:questionnaire:1">
 83 ······<ocil:title>Policy·Requires·Immediate·Change·of·Temporary·Passwords</ocil:title>
96 ······<ocil:actions>84 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-service_auditd_enabled_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-policy_temp_passwords_immediate_change_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>86 ······</ocil:actions>
99 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-chronyd_sync_clock_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_login_grace_time_ocil:questionnaire:1">
101 ······<ocil:title>Synchronize·internal·information·system·clocks</ocil:title>89 ······<ocil:title>Ensure·SSH·LoginGraceTime·is·configured</ocil:title>
102 ······<ocil:actions>90 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-chronyd_sync_clock_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sshd_set_login_grace_time_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>92 ······</ocil:actions>
105 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-package_pam_pwquality_installed_ocil:questionnaire:1"> 
107 ······<ocil:title>Install·pam_pwquality·Package</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-sudoers_no_root_target_ocil:questionnaire:1">
 95 ······<ocil:title>Don't·target·root·user·in·the·sudoers·file</ocil:title>
108 ······<ocil:actions>96 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-package_pam_pwquality_installed_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sudoers_no_root_target_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>98 ······</ocil:actions>
111 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-service_cups_disabled_ocil:questionnaire:1"> 
113 ······<ocil:title>Disable·the·CUPS·Service</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_ocil:questionnaire:1">
 101 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·open_by_handle_at</ocil:title>
114 ······<ocil:actions>102 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-service_cups_disabled_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>104 ······</ocil:actions>
117 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_compression_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-chronyd_specify_remote_server_ocil:questionnaire:1">
119 ······<ocil:title>Disable·Compression·Or·Set·Compression·to·delayed</ocil:title>107 ······<ocil:title>A·remote·time·server·for·Chrony·is·configured</ocil:title>
120 ······<ocil:actions>108 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_compression_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-chronyd_specify_remote_server_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 1367710/1379357 bytes (99.16%) of diff not shown.
3.73 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-xccdf.xml
3.73 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-xccdf.xml
Max HTML report size reached
5.42 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ds.xml
5.42 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ds.xml
Max HTML report size reached
1.37 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ocil.xml
1.37 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ocil.xml
Ordering differences only
    
Offset 3, 6672 lines modifiedOffset 3, 6672 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_issue_ocil:questionnaire:1">
11 ······<ocil:title>Ensure·the·Default·Bash·Umask·is·Set·Correctly</ocil:title>11 ······<ocil:title>Verify·permissions·on·System·Login·Banner</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_issue_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_audit_configuration_ocil:questionnaire:1">
17 ······<ocil:title>Record·Events·that·Modify·the·System's·Network·Environment</ocil:title>17 ······<ocil:title>Audit·Configuration·Files·Must·Be·Owned·By·Root</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_networkconfig_modification_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_ownership_audit_configuration_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_owner_grub2_cfg_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_devkmem_ocil:questionnaire:1">
23 ······<ocil:title>Verify·/boot/grub/grub.cfg·User·Ownership</ocil:title>23 ······<ocil:title>Disable·/dev/kmem·virtual·device·support</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_owner_grub2_cfg_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-kernel_config_devkmem_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_zero_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-accounts_minimum_age_login_defs_ocil:questionnaire:1">
29 ······<ocil:title>Use·zero·for·poisoning·instead·of·debugging·value</ocil:title>29 ······<ocil:title>Set·Password·Minimum·Age</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_zero_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-accounts_minimum_age_login_defs_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-chronyd_sync_clock_ocil:questionnaire:1"> 
35 ······<ocil:title>Synchronize·internal·information·system·clocks</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1">
 35 ······<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-chronyd_sync_clock_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_deny_ocil:questionnaire:1"> 
41 ······<ocil:title>Lock·Accounts·After·Failed·Password·Attempts</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-grub2_nosmap_argument_absent_ocil:questionnaire:1">
 41 ······<ocil:title>Ensure·SMAP·is·not·disabled·during·boot</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_deny_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-grub2_nosmap_argument_absent_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-grub2_disable_recovery_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_shutdown_ocil:questionnaire:1">
47 ······<ocil:title>Disable·Recovery·Booting</ocil:title>47 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·shutdown</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-grub2_disable_recovery_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_shutdown_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_weekly_ocil:questionnaire:1"> 
53 ······<ocil:title>Verify·Group·Who·Owns·cron.weekly</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_postdrop_ocil:questionnaire:1">
 53 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·postdrop</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_weekly_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_postdrop_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_hourly_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_hardlinks_ocil:questionnaire:1">
59 ······<ocil:title>Verify·Owner·on·cron.hourly</ocil:title>59 ······<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Hardlinks</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_hourly_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_hardlinks_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_usermod_ocil:questionnaire:1"> 
65 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·usermod</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_ocil:questionnaire:1">
 65 ······<ocil:title>Disable·Accepting·Router·Advertisements·on·all·IPv6·Interfaces·by·Default</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_usermod_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_keepalive_0_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_net_ocil:questionnaire:1">
71 ······<ocil:title>Set·SSH·Client·Alive·Count·Max·to·zero</ocil:title>71 ······<ocil:title>Enable·SSH·Warning·Banner</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_0_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_net_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-package_ufw_removed_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_ungroupowned_ocil:questionnaire:1">
77 ······<ocil:title>Remove·ufw·Package</ocil:title>77 ······<ocil:title>Ensure·All·Files·Are·Owned·by·a·Group</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-package_ufw_removed_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_permissions_ungroupowned_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-banner_etc_issue_ocil:questionnaire:1"> 
83 ······<ocil:title>Modify·the·System·Login·Banner</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_relayhost_ocil:questionnaire:1">
 83 ······<ocil:title>Configure·System·to·Forward·All·Mail·through·a·specific·host</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-banner_etc_issue_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_relayhost_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_unix_update_ocil:questionnaire:1"> 
89 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·unix_update</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_audit_binaries_ocil:questionnaire:1">
 89 ······<ocil:title>Verify·that·audit·tools·Have·Mode·0755·or·less</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_unix_update_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_permissions_audit_binaries_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-package_openldap-clients_removed_ocil:questionnaire:1">
95 ······<ocil:title>Enable·different·security·models</ocil:title>95 ······<ocil:title>Ensure·LDAP·client·is·not·installed</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-package_openldap-clients_removed_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_num_logs_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1">
101 ······<ocil:title>Configure·auditd·Number·of·Logs·Retained</ocil:title>101 ······<ocil:title>Ensure·syslog-ng·is·Installed</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_num_logs_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_ocredit_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_unix_update_ocil:questionnaire:1">
107 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Special·Characters</ocil:title>107 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·unix_update</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_ocredit_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_unix_update_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_noexec_ocil:questionnaire:1"> 
113 ······<ocil:title>Add·noexec·Option·to·/var/log</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_newgidmap_ocil:questionnaire:1">
 113 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·newgidmap</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_log_noexec_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_newgidmap_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_no_sanity_ocil:questionnaire:1"> 
119 ······<ocil:title>Enable·poison·without·sanity·check</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-aide_build_database_ocil:questionnaire:1">
 119 ······<ocil:title>Build·and·Test·AIDE·Database</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_no_sanity_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-aide_build_database_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 1424316/1436806 bytes (99.13%) of diff not shown.
3.9 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-xccdf.xml
3.9 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-xccdf.xml
Max HTML report size reached
68.8 MB
ssg-debian_0.1.74-1_all.deb
452 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2024-11-02·18:39:34.000000·debian-binary1 -rw-r--r--···0········0········0········4·2024-11-02·18:39:34.000000·debian-binary
2 -rw-r--r--···0········0········0·····1980·2024-11-02·18:39:34.000000·control.tar.xz2 -rw-r--r--···0········0········0·····1976·2024-11-02·18:39:34.000000·control.tar.xz
3 -rw-r--r--···0········0········0··1229812·2024-11-02·18:39:34.000000·data.tar.xz3 -rw-r--r--···0········0········0··1230356·2024-11-02·18:39:34.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
68.8 MB
data.tar.xz
68.8 MB
data.tar
1.02 MB
./usr/share/doc/ssg-debian/ssg-debian11-guide-anssi_np_nt28_average.html
    
Offset 14284, 15 lines modifiedOffset 14284, 15 lines modified
00037cb0:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00037cb0:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00037cc0:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00037cc0:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00037cd0:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</00037cd0:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
00037ce0:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00037ce0:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
00037cf0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft00037cf0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
00037d00:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······00037d00:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
00037d10:·2020·2020·2020·2020·2020·2020·2020·2861················(a00037d10:·2020·2020·2020·2020·2020·2020·2020·2861················(a
00037d20:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)00037d20:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
00037d30:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037d30:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037d40:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div00037d40:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
00037d50:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co00037d50:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
00037d60:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><00037d60:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
00037d70:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc00037d70:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
00037d80:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec00037d80:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00037d90:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00037d90:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 16001, 146 lines modifiedOffset 16001, 146 lines modified
0003e800:·6172·6765·743d·2223·6964·6d31·3934·3022··arget="#idm1940"0003e800:·6172·6765·743d·2223·6964·6d31·3934·3022··arget="#idm1940"
0003e810:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003e810:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003e820:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003e820:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003e830:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003e830:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003e840:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003e840:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003e850:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003e850:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003e860:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003e860:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003e870:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script· 
0003e880:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003e890:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003e8a0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003e8b0:·6964·3d22·6964·6d31·3934·3022·3e3c·7461··id="idm1940"><ta 
0003e8c0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003e8d0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003e8e0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003e8f0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003e900:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003e910:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003e920:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003e930:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003e940:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003e950:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003e960:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003e970:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003e980:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003e990:·643e·7265·7374·7269·6374·3c2f·7464·3e3c··d>restrict</td>< 
0003e9a0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003e9b0:·3e3c·636f·6465·3e0a·666f·7220·6620·696e··><code>.for·f·in 
0003e9c0:·202f·6574·632f·7375·646f·6572·7320·2f65···/etc/sudoers·/e 
0003e9d0:·7463·2f73·7564·6f65·7273·2e64·2f2a·203b··tc/sudoers.d/*·; 
0003e9e0:·2064·6f0a·2020·6966·205b·2021·202d·6520···do.··if·[·!·-e· 
0003e9f0:·2224·6622·205d·203b·2074·6865·6e0a·2020··"$f"·]·;·then.·· 
0003ea00:·2020·636f·6e74·696e·7565·0a20·2066·690a····continue.··fi. 
0003ea10:·2020·6d61·7463·6869·6e67·5f6c·6973·743d····matching_list= 
0003ea20:·2428·6772·6570·202d·5020·275e·283f·2123··$(grep·-P·'^(?!# 
0003ea30:·292e·2a5b·5c73·5d2b·5c21·6175·7468·656e··).*[\s]+\!authen 
0003ea40:·7469·6361·7465·2e2a·2427·2024·6620·7c20··ticate.*$'·$f·|· 
0003ea50:·756e·6971·2029·0a20·2069·6620·2120·7465··uniq·).··if·!·te 
0003ea60:·7374·202d·7a20·2224·6d61·7463·6869·6e67··st·-z·"$matching 
0003ea70:·5f6c·6973·7422·3b20·7468·656e·0a20·2020··_list";·then.··· 
0003ea80:·2077·6869·6c65·2049·4653·3d20·7265·6164···while·IFS=·read 
0003ea90:·202d·7220·656e·7472·793b·2064·6f0a·2020···-r·entry;·do.·· 
0003eaa0:·2020·2020·2320·636f·6d6d·656e·7420·6f75······#·comment·ou 
0003eab0:·7420·2221·6175·7468·656e·7469·6361·7465··t·"!authenticate 
0003eac0:·2220·6d61·7463·6865·7320·746f·2070·7265··"·matches·to·pre 
0003ead0:·7365·7276·6520·7573·6572·2064·6174·610a··serve·user·data. 
0003eae0:·2020·2020·2020·7365·6420·2d69·2022·732f········sed·-i·"s/ 
0003eaf0:·5e24·7b65·6e74·7279·7d24·2f23·2026·616d··^${entry}$/#·&am 
0003eb00:·703b·2f67·2220·2466·0a20·2020·2064·6f6e··p;/g"·$f.····don 
0003eb10:·6520·266c·743b·266c·743b·266c·743b·2022··e·&lt;&lt;&lt;·" 
0003eb20:·246d·6174·6368·696e·675f·6c69·7374·220a··$matching_list". 
0003eb30:·0a20·2020·202f·7573·722f·7362·696e·2f76··.····/usr/sbin/v 
0003eb40:·6973·7564·6f20·2d63·6620·2466·2026·616d··isudo·-cf·$f·&am 
0003eb50:·703b·2667·743b·202f·6465·762f·6e75·6c6c··p;&gt;·/dev/null 
0003eb60:·207c·7c20·6563·686f·2022·4661·696c·2074···||·echo·"Fail·t 
0003eb70:·6f20·7661·6c69·6461·7465·2024·6620·7769··o·validate·$f·wi 
0003eb80:·7468·2076·6973·7564·6f22·0a20·2066·690a··th·visudo".··fi. 
0003eb90:·646f·6e65·0a3c·2f63·6f64·653e·3c2f·7072··done.</code></pr 
0003eba0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003ebb0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003ebc0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003ebd0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003ebe0:·6172·6765·743d·2223·6964·6d31·3934·3122··arget="#idm1941" 
0003ebf0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003ec00:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003ec10:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003ec20:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003ec30:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003ec40:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003ec50:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp0003e870:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp
0003ec60:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0003e880:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
0003ec70:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003e890:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0003ec80:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003e8a0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0003ec90:·6522·2069·643d·2269·646d·3139·3431·223e··e"·id="idm1941">0003e8b0:·6522·2069·643d·2269·646d·3139·3430·223e··e"·id="idm1940">
0003eca0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003e8c0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
0003ecb0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003e8d0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
0003ecc0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003e8e0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
0003ecd0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003e8f0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
0003ece0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003e900:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003ecf0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003e910:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0003ed00:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003e920:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003ed10:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003e930:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
0003ed20:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003e940:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003ed30:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo0003e950:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
0003ed40:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals0003e960:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
0003ed50:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><0003e970:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
0003ed60:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th0003e980:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0003ed70:·3e3c·7464·3e72·6573·7472·6963·743c·2f74··><td>restrict</t0003e990:·3e3c·7464·3e72·6573·7472·6963·743c·2f74··><td>restrict</t
0003ed80:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003e9a0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0003ed90:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name0003e9b0:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name
0003eda0:·3a20·4669·6e64·202f·6574·632f·7375·646f··:·Find·/etc/sudo0003e9c0:·3a20·4669·6e64·202f·6574·632f·7375·646f··:·Find·/etc/sudo
0003edb0:·6572·732e·642f·2066·696c·6573·0a20·2061··ers.d/·files.··a0003e9d0:·6572·732e·642f·2066·696c·6573·0a20·2061··ers.d/·files.··a
0003edc0:·6e73·6962·6c65·2e62·7569·6c74·696e·2e66··nsible.builtin.f0003e9e0:·6e73·6962·6c65·2e62·7569·6c74·696e·2e66··nsible.builtin.f
0003edd0:·696e·643a·0a20·2020·2070·6174·6873·3a0a··ind:.····paths:.0003e9f0:·696e·643a·0a20·2020·2070·6174·6873·3a0a··ind:.····paths:.
0003ede0:·2020·2020·2d20·2f65·7463·2f73·7564·6f65······-·/etc/sudoe0003ea00:·2020·2020·2d20·2f65·7463·2f73·7564·6f65······-·/etc/sudoe
0003edf0:·7273·2e64·2f0a·2020·7265·6769·7374·6572··rs.d/.··register0003ea10:·7273·2e64·2f0a·2020·7265·6769·7374·6572··rs.d/.··register
0003ee00:·3a20·7375·646f·6572·730a·2020·7461·6773··:·sudoers.··tags0003ea20:·3a20·7375·646f·6572·730a·2020·7461·6773··:·sudoers.··tags
0003ee10:·3a0a·2020·2d20·4e49·5354·2d38·3030·2d35··:.··-·NIST-800-50003ea30:·3a0a·2020·2d20·4e49·5354·2d38·3030·2d35··:.··-·NIST-800-5
0003ee20:·332d·434d·2d36·2861·290a·2020·2d20·4e49··3-CM-6(a).··-·NI0003ea40:·332d·434d·2d36·2861·290a·2020·2d20·4e49··3-CM-6(a).··-·NI
0003ee30:·5354·2d38·3030·2d35·332d·4941·2d31·310a··ST-800-53-IA-11.0003ea50:·5354·2d38·3030·2d35·332d·4941·2d31·310a··ST-800-53-IA-11.
0003ee40:·2020·2d20·6c6f·775f·636f·6d70·6c65·7869····-·low_complexi0003ea60:·2020·2d20·6c6f·775f·636f·6d70·6c65·7869····-·low_complexi
0003ee50:·7479·0a20·202d·206c·6f77·5f64·6973·7275··ty.··-·low_disru0003ea70:·7479·0a20·202d·206c·6f77·5f64·6973·7275··ty.··-·low_disru
0003ee60:·7074·696f·6e0a·2020·2d20·6d65·6469·756d··ption.··-·medium0003ea80:·7074·696f·6e0a·2020·2d20·6d65·6469·756d··ption.··-·medium
0003ee70:·5f73·6576·6572·6974·790a·2020·2d20·6e6f··_severity.··-·no0003ea90:·5f73·6576·6572·6974·790a·2020·2d20·6e6f··_severity.··-·no
0003ee80:·5f72·6562·6f6f·745f·6e65·6564·6564·0a20··_reboot_needed.·0003eaa0:·5f72·6562·6f6f·745f·6e65·6564·6564·0a20··_reboot_needed.·
0003ee90:·202d·2072·6573·7472·6963·745f·7374·7261···-·restrict_stra0003eab0:·202d·2072·6573·7472·6963·745f·7374·7261···-·restrict_stra
0003eea0:·7465·6779·0a20·202d·2073·7564·6f5f·7265··tegy.··-·sudo_re0003eac0:·7465·6779·0a20·202d·2073·7564·6f5f·7265··tegy.··-·sudo_re
0003eeb0:·6d6f·7665·5f6e·6f5f·6175·7468·656e·7469··move_no_authenti0003ead0:·6d6f·7665·5f6e·6f5f·6175·7468·656e·7469··move_no_authenti
0003eec0:·6361·7465·0a0a·2d20·6e61·6d65·3a20·5265··cate..-·name:·Re0003eae0:·6361·7465·0a0a·2d20·6e61·6d65·3a20·5265··cate..-·name:·Re
0003eed0:·6d6f·7665·206c·696e·6573·2063·6f6e·7461··move·lines·conta0003eaf0:·6d6f·7665·206c·696e·6573·2063·6f6e·7461··move·lines·conta
0003eee0:·696e·696e·6720·2161·7574·6865·6e74·6963··ining·!authentic0003eb00:·696e·696e·6720·2161·7574·6865·6e74·6963··ining·!authentic
Max diff block lines reached; 933024/952950 bytes (97.91%) of diff not shown.
118 KB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Average·(Intermediate)·Level38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Average·(Intermediate)·Level
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_average39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_average
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:debian:debian_linux:1141 ····*·cpe:/o:debian:debian_linux:11
42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
43 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8443 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
48 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g48 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
49 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s49 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
50 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s50 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
51 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n51 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
Offset 227, 35 lines modifiedOffset 227, 14 lines modified
227 ···························1.7,·SR·1.8,·SR·1.9227 ···························1.7,·SR·1.8,·SR·1.9
228 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,228 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
229 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3229 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
230 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)230 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
231 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7231 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
232 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,232 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
233 ···························SRG-OS-000373-GPOS-00158233 ···························SRG-OS-000373-GPOS-00158
234 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
235 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
236 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
237 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
238 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
239 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
240 ··if·[·!·-e·"$f"·]·;·then 
241 ····continue 
242 ··fi 
243 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·) 
244 ··if·!·test·-z·"$matching_list";·then 
245 ····while·IFS=·read·-r·entry;·do 
246 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data 
247 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
248 ····done·<<<·"$matching_list" 
  
249 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
250 visudo" 
251 ··fi 
252 done 
253 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8234 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
254 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low235 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
255 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low236 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
256 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false237 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
257 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict238 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
258 -·name:·Find·/etc/sudoers.d/·files239 -·name:·Find·/etc/sudoers.d/·files
259 ··ansible.builtin.find:240 ··ansible.builtin.find:
Offset 286, 14 lines modifiedOffset 265, 35 lines modified
286 ··-·NIST-800-53-IA-11265 ··-·NIST-800-53-IA-11
287 ··-·low_complexity266 ··-·low_complexity
288 ··-·low_disruption267 ··-·low_disruption
289 ··-·medium_severity268 ··-·medium_severity
290 ··-·no_reboot_needed269 ··-·no_reboot_needed
291 ··-·restrict_strategy270 ··-·restrict_strategy
292 ··-·sudo_remove_no_authenticate271 ··-·sudo_remove_no_authenticate
 272 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 273 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 274 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 275 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 276 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 277 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do
 278 ··if·[·!·-e·"$f"·]·;·then
 279 ····continue
 280 ··fi
 281 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·)
 282 ··if·!·test·-z·"$matching_list";·then
 283 ····while·IFS=·read·-r·entry;·do
 284 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data
 285 ······sed·-i·"s/^${entry}$/#·&/g"·$f
 286 ····done·<<<·"$matching_list"
  
 287 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with
 288 visudo"
 289 ··fi
 290 done
293 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o291 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o
294 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*292 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
295 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using293 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using
296 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure294 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure
297 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any295 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any
298 sudo·configuration·snippets·in·/etc/sudoers.d/.296 sudo·configuration·snippets·in·/etc/sudoers.d/.
299 ············Without·re-authentication,·users·may·access·resources·or·perform297 ············Without·re-authentication,·users·may·access·resources·or·perform
Offset 314, 35 lines modifiedOffset 314, 14 lines modified
314 ···························1.7,·SR·1.8,·SR·1.9314 ···························1.7,·SR·1.8,·SR·1.9
315 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,315 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
316 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3316 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
317 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)317 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
318 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7318 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
319 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,319 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
320 ···························SRG-OS-000373-GPOS-00158320 ···························SRG-OS-000373-GPOS-00158
321 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
322 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
323 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
324 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
325 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
326 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
327 ··if·[·!·-e·"$f"·]·;·then 
328 ····continue 
329 ··fi 
330 ··matching_list=$(grep·-P·'^(?!#).*[\s]+NOPASSWD[\s]*\:.*$'·$f·|·uniq·) 
331 ··if·!·test·-z·"$matching_list";·then 
332 ····while·IFS=·read·-r·entry;·do 
333 ······#·comment·out·"NOPASSWD"·matches·to·preserve·user·data 
334 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
335 ····done·<<<·"$matching_list" 
  
336 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
337 visudo" 
338 ··fi 
339 done 
340 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8321 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
341 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low322 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
342 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low323 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
343 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false324 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
344 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict325 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
345 -·name:·Find·/etc/sudoers.d/·files326 -·name:·Find·/etc/sudoers.d/·files
346 ··ansible.builtin.find:327 ··ansible.builtin.find:
Offset 373, 14 lines modifiedOffset 352, 35 lines modified
373 ··-·NIST-800-53-IA-11352 ··-·NIST-800-53-IA-11
374 ··-·low_complexity353 ··-·low_complexity
375 ··-·low_disruption354 ··-·low_disruption
Max diff block lines reached; 114704/120437 bytes (95.24%) of diff not shown.
1.14 MB
./usr/share/doc/ssg-debian/ssg-debian11-guide-anssi_np_nt28_high.html
    
Offset 14285, 16 lines modifiedOffset 14285, 16 lines modified
00037cc0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h00037cc0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h
00037cd0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver00037cd0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver
00037ce0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.00037ce0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.
00037cf0:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p00037cf0:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p
00037d00:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong00037d00:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong
00037d10:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.00037d10:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.
00037d20:·2020·2020·2020·2020·2020·2020·2020·2020··················00037d20:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037d30:·2020·2020·2861·7320·6f66·2032·3032·362d······(as·of·2026-00037d30:·2020·2020·2861·7320·6f66·2032·3032·342d······(as·of·2024-
00037d40:·3031·2d30·3829·0a20·2020·2020·2020·2020··01-08).·········00037d40:·3132·2d30·3729·0a20·2020·2020·2020·2020··12-07).·········
00037d50:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul00037d50:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul
00037d60:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table00037d60:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table
00037d70:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h200037d70:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2
00037d80:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href00037d80:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href
00037d90:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg00037d90:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg
00037da0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_00037da0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
00037db0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy00037db0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy
Offset 16021, 146 lines modifiedOffset 16021, 146 lines modified
0003e940:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm10003e940:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
0003e950:·3934·3022·2074·6162·696e·6465·783d·2230··940"·tabindex="00003e950:·3934·3022·2074·6162·696e·6465·783d·2230··940"·tabindex="0
0003e960:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003e960:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003e970:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003e970:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003e980:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003e980:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003e990:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003e990:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003e9a0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003e9a0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003e9b0:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
0003e9c0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003e9d0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003e9e0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003e9f0:·7365·2220·6964·3d22·6964·6d31·3934·3022··se"·id="idm1940" 
0003ea00:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003ea10:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003ea20:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003ea30:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003ea40:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003ea50:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003ea60:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003ea70:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003ea80:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003ea90:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003eaa0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003eab0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003eac0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003ead0:·683e·3c74·643e·7265·7374·7269·6374·3c2f··h><td>restrict</ 
0003eae0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003eaf0:·3c70·7265·3e3c·636f·6465·3e0a·666f·7220··<pre><code>.for· 
0003eb00:·6620·696e·202f·6574·632f·7375·646f·6572··f·in·/etc/sudoer 
0003eb10:·7320·2f65·7463·2f73·7564·6f65·7273·2e64··s·/etc/sudoers.d 
0003eb20:·2f2a·203b·2064·6f0a·2020·6966·205b·2021··/*·;·do.··if·[·! 
0003eb30:·202d·6520·2224·6622·205d·203b·2074·6865···-e·"$f"·]·;·the 
0003eb40:·6e0a·2020·2020·636f·6e74·696e·7565·0a20··n.····continue.· 
0003eb50:·2066·690a·2020·6d61·7463·6869·6e67·5f6c···fi.··matching_l 
0003eb60:·6973·743d·2428·6772·6570·202d·5020·275e··ist=$(grep·-P·'^ 
0003eb70:·283f·2123·292e·2a5b·5c73·5d2b·5c21·6175··(?!#).*[\s]+\!au 
0003eb80:·7468·656e·7469·6361·7465·2e2a·2427·2024··thenticate.*$'·$ 
0003eb90:·6620·7c20·756e·6971·2029·0a20·2069·6620··f·|·uniq·).··if· 
0003eba0:·2120·7465·7374·202d·7a20·2224·6d61·7463··!·test·-z·"$matc 
0003ebb0:·6869·6e67·5f6c·6973·7422·3b20·7468·656e··hing_list";·then 
0003ebc0:·0a20·2020·2077·6869·6c65·2049·4653·3d20··.····while·IFS=· 
0003ebd0:·7265·6164·202d·7220·656e·7472·793b·2064··read·-r·entry;·d 
0003ebe0:·6f0a·2020·2020·2020·2320·636f·6d6d·656e··o.······#·commen 
0003ebf0:·7420·6f75·7420·2221·6175·7468·656e·7469··t·out·"!authenti 
0003ec00:·6361·7465·2220·6d61·7463·6865·7320·746f··cate"·matches·to 
0003ec10:·2070·7265·7365·7276·6520·7573·6572·2064···preserve·user·d 
0003ec20:·6174·610a·2020·2020·2020·7365·6420·2d69··ata.······sed·-i 
0003ec30:·2022·732f·5e24·7b65·6e74·7279·7d24·2f23···"s/^${entry}$/# 
0003ec40:·2026·616d·703b·2f67·2220·2466·0a20·2020···&amp;/g"·$f.··· 
0003ec50:·2064·6f6e·6520·266c·743b·266c·743b·266c···done·&lt;&lt;&l 
0003ec60:·743b·2022·246d·6174·6368·696e·675f·6c69··t;·"$matching_li 
0003ec70:·7374·220a·0a20·2020·202f·7573·722f·7362··st"..····/usr/sb 
0003ec80:·696e·2f76·6973·7564·6f20·2d63·6620·2466··in/visudo·-cf·$f 
0003ec90:·2026·616d·703b·2667·743b·202f·6465·762f···&amp;&gt;·/dev/ 
0003eca0:·6e75·6c6c·207c·7c20·6563·686f·2022·4661··null·||·echo·"Fa 
0003ecb0:·696c·2074·6f20·7661·6c69·6461·7465·2024··il·to·validate·$ 
0003ecc0:·6620·7769·7468·2076·6973·7564·6f22·0a20··f·with·visudo".· 
0003ecd0:·2066·690a·646f·6e65·0a3c·2f63·6f64·653e···fi.done.</code> 
0003ece0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003ecf0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003ed00:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003ed10:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003ed20:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1 
0003ed30:·3934·3122·2074·6162·696e·6465·783d·2230··941"·tabindex="0 
0003ed40:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003ed50:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003ed60:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003ed70:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003ed80:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003ed90:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s0003e9b0:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s
0003eda0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003e9c0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003edb0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003e9d0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003edc0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003e9e0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003edd0:·6c61·7073·6522·2069·643d·2269·646d·3139··lapse"·id="idm190003e9f0:·6c61·7073·6522·2069·643d·2269·646d·3139··lapse"·id="idm19
0003ede0:·3431·223e·3c74·6162·6c65·2063·6c61·7373··41"><table·class0003ea00:·3430·223e·3c74·6162·6c65·2063·6c61·7373··40"><table·class
0003edf0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003ea10:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003ee00:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003ea20:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003ee10:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003ea30:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003ee20:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003ea40:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003ee30:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003ea50:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003ee40:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003ea60:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003ee50:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003ea70:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003ee60:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003ea80:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003ee70:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003ea90:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003ee80:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>0003eaa0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0003ee90:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><0003eab0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
0003eea0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003eac0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003eeb0:·3c2f·7468·3e3c·7464·3e72·6573·7472·6963··</th><td>restric0003ead0:·3c2f·7468·3e3c·7464·3e72·6573·7472·6963··</th><td>restric
0003eec0:·743c·2f74·643e·3c2f·7472·3e3c·2f74·6162··t</td></tr></tab0003eae0:·743c·2f74·643e·3c2f·7472·3e3c·2f74·6162··t</td></tr></tab
0003eed0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-·0003eaf0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-·
0003eee0:·6e61·6d65·3a20·4669·6e64·202f·6574·632f··name:·Find·/etc/0003eb00:·6e61·6d65·3a20·4669·6e64·202f·6574·632f··name:·Find·/etc/
0003eef0:·7375·646f·6572·732e·642f·2066·696c·6573··sudoers.d/·files0003eb10:·7375·646f·6572·732e·642f·2066·696c·6573··sudoers.d/·files
0003ef00:·0a20·2061·6e73·6962·6c65·2e62·7569·6c74··.··ansible.built0003eb20:·0a20·2061·6e73·6962·6c65·2e62·7569·6c74··.··ansible.built
0003ef10:·696e·2e66·696e·643a·0a20·2020·2070·6174··in.find:.····pat0003eb30:·696e·2e66·696e·643a·0a20·2020·2070·6174··in.find:.····pat
0003ef20:·6873·3a0a·2020·2020·2d20·2f65·7463·2f73··hs:.····-·/etc/s0003eb40:·6873·3a0a·2020·2020·2d20·2f65·7463·2f73··hs:.····-·/etc/s
0003ef30:·7564·6f65·7273·2e64·2f0a·2020·7265·6769··udoers.d/.··regi0003eb50:·7564·6f65·7273·2e64·2f0a·2020·7265·6769··udoers.d/.··regi
0003ef40:·7374·6572·3a20·7375·646f·6572·730a·2020··ster:·sudoers.··0003eb60:·7374·6572·3a20·7375·646f·6572·730a·2020··ster:·sudoers.··
0003ef50:·7461·6773·3a0a·2020·2d20·4e49·5354·2d38··tags:.··-·NIST-80003eb70:·7461·6773·3a0a·2020·2d20·4e49·5354·2d38··tags:.··-·NIST-8
0003ef60:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).··0003eb80:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).··
0003ef70:·2d20·4e49·5354·2d38·3030·2d35·332d·4941··-·NIST-800-53-IA0003eb90:·2d20·4e49·5354·2d38·3030·2d35·332d·4941··-·NIST-800-53-IA
0003ef80:·2d31·310a·2020·2d20·6c6f·775f·636f·6d70··-11.··-·low_comp0003eba0:·2d31·310a·2020·2d20·6c6f·775f·636f·6d70··-11.··-·low_comp
0003ef90:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d0003ebb0:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d
0003efa0:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me0003ebc0:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me
0003efb0:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.··0003ebd0:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.··
0003efc0:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need0003ebe0:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need
0003efd0:·6564·0a20·202d·2072·6573·7472·6963·745f··ed.··-·restrict_0003ebf0:·6564·0a20·202d·2072·6573·7472·6963·745f··ed.··-·restrict_
0003efe0:·7374·7261·7465·6779·0a20·202d·2073·7564··strategy.··-·sud0003ec00:·7374·7261·7465·6779·0a20·202d·2073·7564··strategy.··-·sud
0003eff0:·6f5f·7265·6d6f·7665·5f6e·6f5f·6175·7468··o_remove_no_auth0003ec10:·6f5f·7265·6d6f·7665·5f6e·6f5f·6175·7468··o_remove_no_auth
0003f000:·656e·7469·6361·7465·0a0a·2d20·6e61·6d65··enticate..-·name0003ec20:·656e·7469·6361·7465·0a0a·2d20·6e61·6d65··enticate..-·name
0003f010:·3a20·5265·6d6f·7665·206c·696e·6573·2063··:·Remove·lines·c0003ec30:·3a20·5265·6d6f·7665·206c·696e·6573·2063··:·Remove·lines·c
Max diff block lines reached; 1044530/1064594 bytes (98.12%) of diff not shown.
129 KB
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·High·(Enforced)·Level39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·High·(Enforced)·Level
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_high40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_high
41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
42 ····*·cpe:/o:debian:debian_linux:1142 ····*·cpe:/o:debian:debian_linux:11
43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
44 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8444 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
49 ·········2.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n49 ·········2.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
51 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s51 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
52 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s52 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
Offset 231, 35 lines modifiedOffset 231, 14 lines modified
231 ···························1.7,·SR·1.8,·SR·1.9231 ···························1.7,·SR·1.8,·SR·1.9
232 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,232 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
233 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3233 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
234 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)234 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
235 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7235 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
236 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,236 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
237 ···························SRG-OS-000373-GPOS-00158237 ···························SRG-OS-000373-GPOS-00158
238 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
239 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
240 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
241 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
242 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
243 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
244 ··if·[·!·-e·"$f"·]·;·then 
245 ····continue 
246 ··fi 
247 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·) 
248 ··if·!·test·-z·"$matching_list";·then 
249 ····while·IFS=·read·-r·entry;·do 
250 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data 
251 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
252 ····done·<<<·"$matching_list" 
  
253 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
254 visudo" 
255 ··fi 
256 done 
257 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8238 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
258 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low239 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
259 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low240 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
260 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false241 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
261 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict242 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
262 -·name:·Find·/etc/sudoers.d/·files243 -·name:·Find·/etc/sudoers.d/·files
263 ··ansible.builtin.find:244 ··ansible.builtin.find:
Offset 290, 14 lines modifiedOffset 269, 35 lines modified
290 ··-·NIST-800-53-IA-11269 ··-·NIST-800-53-IA-11
291 ··-·low_complexity270 ··-·low_complexity
292 ··-·low_disruption271 ··-·low_disruption
293 ··-·medium_severity272 ··-·medium_severity
294 ··-·no_reboot_needed273 ··-·no_reboot_needed
295 ··-·restrict_strategy274 ··-·restrict_strategy
296 ··-·sudo_remove_no_authenticate275 ··-·sudo_remove_no_authenticate
 276 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 277 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 278 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 279 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 280 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 281 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do
 282 ··if·[·!·-e·"$f"·]·;·then
 283 ····continue
 284 ··fi
 285 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·)
 286 ··if·!·test·-z·"$matching_list";·then
 287 ····while·IFS=·read·-r·entry;·do
 288 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data
 289 ······sed·-i·"s/^${entry}$/#·&/g"·$f
 290 ····done·<<<·"$matching_list"
  
 291 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with
 292 visudo"
 293 ··fi
 294 done
297 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o295 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o
298 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*296 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
299 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using297 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using
300 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure298 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure
301 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any299 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any
302 sudo·configuration·snippets·in·/etc/sudoers.d/.300 sudo·configuration·snippets·in·/etc/sudoers.d/.
303 ············Without·re-authentication,·users·may·access·resources·or·perform301 ············Without·re-authentication,·users·may·access·resources·or·perform
Offset 318, 35 lines modifiedOffset 318, 14 lines modified
318 ···························1.7,·SR·1.8,·SR·1.9318 ···························1.7,·SR·1.8,·SR·1.9
319 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,319 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
320 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3320 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
321 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)321 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
322 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7322 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
323 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,323 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
324 ···························SRG-OS-000373-GPOS-00158324 ···························SRG-OS-000373-GPOS-00158
325 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
326 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
327 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
328 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
329 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
330 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
331 ··if·[·!·-e·"$f"·]·;·then 
332 ····continue 
333 ··fi 
334 ··matching_list=$(grep·-P·'^(?!#).*[\s]+NOPASSWD[\s]*\:.*$'·$f·|·uniq·) 
335 ··if·!·test·-z·"$matching_list";·then 
336 ····while·IFS=·read·-r·entry;·do 
337 ······#·comment·out·"NOPASSWD"·matches·to·preserve·user·data 
338 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
339 ····done·<<<·"$matching_list" 
  
340 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
341 visudo" 
342 ··fi 
343 done 
344 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8325 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
345 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low326 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
346 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low327 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
347 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false328 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
348 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict329 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
349 -·name:·Find·/etc/sudoers.d/·files330 -·name:·Find·/etc/sudoers.d/·files
350 ··ansible.builtin.find:331 ··ansible.builtin.find:
Offset 377, 14 lines modifiedOffset 356, 35 lines modified
377 ··-·NIST-800-53-IA-11356 ··-·NIST-800-53-IA-11
378 ··-·low_complexity357 ··-·low_complexity
379 ··-·low_disruption358 ··-·low_disruption
Max diff block lines reached; 126140/131878 bytes (95.65%) of diff not shown.
365 KB
./usr/share/doc/ssg-debian/ssg-debian11-guide-anssi_np_nt28_minimal.html
    
Offset 14279, 15 lines modifiedOffset 14279, 15 lines modified
00037c60:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v00037c60:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v
00037c70:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>00037c70:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>
00037c80:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><00037c80:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><
00037c90:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro00037c90:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro
00037ca0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong00037ca0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong
00037cb0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············00037cb0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············
00037cc0:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·20200037cc0:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202
00037cd0:·362d·3031·2d30·3829·0a20·2020·2020·2020··6-01-08).·······00037cd0:·342d·3132·2d30·3729·0a20·2020·2020·2020··4-12-07).·······
00037ce0:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></00037ce0:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></
00037cf0:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab00037cf0:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab
00037d00:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</00037d00:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</
00037d10:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr00037d10:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr
00037d20:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s00037d20:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s
00037d30:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten00037d30:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten
00037d40:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">00037d40:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">
Offset 14776, 146 lines modifiedOffset 14776, 146 lines modified
00039b70:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm100039b70:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
00039b80:·3934·3022·2074·6162·696e·6465·783d·2230··940"·tabindex="000039b80:·3934·3022·2074·6162·696e·6465·783d·2230··940"·tabindex="0
00039b90:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·00039b90:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
00039ba0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f00039ba0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
00039bb0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act00039bb0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
00039bc0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"00039bc0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
00039bd0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed00039bd0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
00039be0:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
00039bf0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
00039c00:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
00039c10:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
00039c20:·7365·2220·6964·3d22·6964·6d31·3934·3022··se"·id="idm1940" 
00039c30:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
00039c40:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
00039c50:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
00039c60:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
00039c70:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
00039c80:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
00039c90:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
00039ca0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
00039cb0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
00039cc0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
00039cd0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
00039ce0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
00039cf0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
00039d00:·683e·3c74·643e·7265·7374·7269·6374·3c2f··h><td>restrict</ 
00039d10:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
00039d20:·3c70·7265·3e3c·636f·6465·3e0a·666f·7220··<pre><code>.for· 
00039d30:·6620·696e·202f·6574·632f·7375·646f·6572··f·in·/etc/sudoer 
00039d40:·7320·2f65·7463·2f73·7564·6f65·7273·2e64··s·/etc/sudoers.d 
00039d50:·2f2a·203b·2064·6f0a·2020·6966·205b·2021··/*·;·do.··if·[·! 
00039d60:·202d·6520·2224·6622·205d·203b·2074·6865···-e·"$f"·]·;·the 
00039d70:·6e0a·2020·2020·636f·6e74·696e·7565·0a20··n.····continue.· 
00039d80:·2066·690a·2020·6d61·7463·6869·6e67·5f6c···fi.··matching_l 
00039d90:·6973·743d·2428·6772·6570·202d·5020·275e··ist=$(grep·-P·'^ 
00039da0:·283f·2123·292e·2a5b·5c73·5d2b·5c21·6175··(?!#).*[\s]+\!au 
00039db0:·7468·656e·7469·6361·7465·2e2a·2427·2024··thenticate.*$'·$ 
00039dc0:·6620·7c20·756e·6971·2029·0a20·2069·6620··f·|·uniq·).··if· 
00039dd0:·2120·7465·7374·202d·7a20·2224·6d61·7463··!·test·-z·"$matc 
00039de0:·6869·6e67·5f6c·6973·7422·3b20·7468·656e··hing_list";·then 
00039df0:·0a20·2020·2077·6869·6c65·2049·4653·3d20··.····while·IFS=· 
00039e00:·7265·6164·202d·7220·656e·7472·793b·2064··read·-r·entry;·d 
00039e10:·6f0a·2020·2020·2020·2320·636f·6d6d·656e··o.······#·commen 
00039e20:·7420·6f75·7420·2221·6175·7468·656e·7469··t·out·"!authenti 
00039e30:·6361·7465·2220·6d61·7463·6865·7320·746f··cate"·matches·to 
00039e40:·2070·7265·7365·7276·6520·7573·6572·2064···preserve·user·d 
00039e50:·6174·610a·2020·2020·2020·7365·6420·2d69··ata.······sed·-i 
00039e60:·2022·732f·5e24·7b65·6e74·7279·7d24·2f23···"s/^${entry}$/# 
00039e70:·2026·616d·703b·2f67·2220·2466·0a20·2020···&amp;/g"·$f.··· 
00039e80:·2064·6f6e·6520·266c·743b·266c·743b·266c···done·&lt;&lt;&l 
00039e90:·743b·2022·246d·6174·6368·696e·675f·6c69··t;·"$matching_li 
00039ea0:·7374·220a·0a20·2020·202f·7573·722f·7362··st"..····/usr/sb 
00039eb0:·696e·2f76·6973·7564·6f20·2d63·6620·2466··in/visudo·-cf·$f 
00039ec0:·2026·616d·703b·2667·743b·202f·6465·762f···&amp;&gt;·/dev/ 
00039ed0:·6e75·6c6c·207c·7c20·6563·686f·2022·4661··null·||·echo·"Fa 
00039ee0:·696c·2074·6f20·7661·6c69·6461·7465·2024··il·to·validate·$ 
00039ef0:·6620·7769·7468·2076·6973·7564·6f22·0a20··f·with·visudo".· 
00039f00:·2066·690a·646f·6e65·0a3c·2f63·6f64·653e···fi.done.</code> 
00039f10:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
00039f20:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
00039f30:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
00039f40:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
00039f50:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1 
00039f60:·3934·3122·2074·6162·696e·6465·783d·2230··941"·tabindex="0 
00039f70:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
00039f80:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
00039f90:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
00039fa0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
00039fb0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
00039fc0:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s00039be0:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s
00039fd0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b00039bf0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
00039fe0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa00039c00:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
00039ff0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col00039c10:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003a000:·6c61·7073·6522·2069·643d·2269·646d·3139··lapse"·id="idm1900039c20:·6c61·7073·6522·2069·643d·2269·646d·3139··lapse"·id="idm19
0003a010:·3431·223e·3c74·6162·6c65·2063·6c61·7373··41"><table·class00039c30:·3430·223e·3c74·6162·6c65·2063·6c61·7373··40"><table·class
0003a020:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st00039c40:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003a030:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord00039c50:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003a040:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde00039c60:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003a050:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co00039c70:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003a060:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t00039c80:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003a070:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><00039c90:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003a080:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio00039ca0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003a090:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</00039cb0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003a0a0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>00039cc0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003a0b0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>00039cd0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0003a0c0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><00039ce0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
0003a0d0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:00039cf0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003a0e0:·3c2f·7468·3e3c·7464·3e72·6573·7472·6963··</th><td>restric00039d00:·3c2f·7468·3e3c·7464·3e72·6573·7472·6963··</th><td>restric
0003a0f0:·743c·2f74·643e·3c2f·7472·3e3c·2f74·6162··t</td></tr></tab00039d10:·743c·2f74·643e·3c2f·7472·3e3c·2f74·6162··t</td></tr></tab
0003a100:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-·00039d20:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-·
0003a110:·6e61·6d65·3a20·4669·6e64·202f·6574·632f··name:·Find·/etc/00039d30:·6e61·6d65·3a20·4669·6e64·202f·6574·632f··name:·Find·/etc/
0003a120:·7375·646f·6572·732e·642f·2066·696c·6573··sudoers.d/·files00039d40:·7375·646f·6572·732e·642f·2066·696c·6573··sudoers.d/·files
0003a130:·0a20·2061·6e73·6962·6c65·2e62·7569·6c74··.··ansible.built00039d50:·0a20·2061·6e73·6962·6c65·2e62·7569·6c74··.··ansible.built
0003a140:·696e·2e66·696e·643a·0a20·2020·2070·6174··in.find:.····pat00039d60:·696e·2e66·696e·643a·0a20·2020·2070·6174··in.find:.····pat
0003a150:·6873·3a0a·2020·2020·2d20·2f65·7463·2f73··hs:.····-·/etc/s00039d70:·6873·3a0a·2020·2020·2d20·2f65·7463·2f73··hs:.····-·/etc/s
0003a160:·7564·6f65·7273·2e64·2f0a·2020·7265·6769··udoers.d/.··regi00039d80:·7564·6f65·7273·2e64·2f0a·2020·7265·6769··udoers.d/.··regi
0003a170:·7374·6572·3a20·7375·646f·6572·730a·2020··ster:·sudoers.··00039d90:·7374·6572·3a20·7375·646f·6572·730a·2020··ster:·sudoers.··
0003a180:·7461·6773·3a0a·2020·2d20·4e49·5354·2d38··tags:.··-·NIST-800039da0:·7461·6773·3a0a·2020·2d20·4e49·5354·2d38··tags:.··-·NIST-8
0003a190:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).··00039db0:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).··
0003a1a0:·2d20·4e49·5354·2d38·3030·2d35·332d·4941··-·NIST-800-53-IA00039dc0:·2d20·4e49·5354·2d38·3030·2d35·332d·4941··-·NIST-800-53-IA
0003a1b0:·2d31·310a·2020·2d20·6c6f·775f·636f·6d70··-11.··-·low_comp00039dd0:·2d31·310a·2020·2d20·6c6f·775f·636f·6d70··-11.··-·low_comp
0003a1c0:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d00039de0:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d
0003a1d0:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me00039df0:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me
0003a1e0:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.··00039e00:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.··
0003a1f0:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need00039e10:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need
0003a200:·6564·0a20·202d·2072·6573·7472·6963·745f··ed.··-·restrict_00039e20:·6564·0a20·202d·2072·6573·7472·6963·745f··ed.··-·restrict_
0003a210:·7374·7261·7465·6779·0a20·202d·2073·7564··strategy.··-·sud00039e30:·7374·7261·7465·6779·0a20·202d·2073·7564··strategy.··-·sud
0003a220:·6f5f·7265·6d6f·7665·5f6e·6f5f·6175·7468··o_remove_no_auth00039e40:·6f5f·7265·6d6f·7665·5f6e·6f5f·6175·7468··o_remove_no_auth
0003a230:·656e·7469·6361·7465·0a0a·2d20·6e61·6d65··enticate..-·name00039e50:·656e·7469·6361·7465·0a0a·2d20·6e61·6d65··enticate..-·name
0003a240:·3a20·5265·6d6f·7665·206c·696e·6573·2063··:·Remove·lines·c00039e60:·3a20·5265·6d6f·7665·206c·696e·6573·2063··:·Remove·lines·c
0003a250:·6f6e·7461·696e·696e·6720·2161·7574·6865··ontaining·!authe00039e70:·6f6e·7461·696e·696e·6720·2161·7574·6865··ontaining·!authe
Max diff block lines reached; 307356/327282 bytes (93.91%) of diff not shown.
45.1 KB
html2text {}
    
Offset 36, 15 lines modifiedOffset 36, 15 lines modified
36 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*36 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
37 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Minimal·Level37 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Minimal·Level
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_minimal38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_minimal
39 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*39 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
40 ····*·cpe:/o:debian:debian_linux:1140 ····*·cpe:/o:debian:debian_linux:11
41 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*41 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
42 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8442 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
43 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)43 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
44 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*44 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
45 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s45 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
46 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e46 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
47 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g47 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
48 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s48 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
49 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s49 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
50 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n50 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
Offset 91, 35 lines modifiedOffset 91, 14 lines modified
91 ···························1.7,·SR·1.8,·SR·1.991 ···························1.7,·SR·1.8,·SR·1.9
92 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,92 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
93 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.393 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
94 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)94 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
95 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-795 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
96 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,96 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
97 ···························SRG-OS-000373-GPOS-0015897 ···························SRG-OS-000373-GPOS-00158
98 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
99 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
100 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
101 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
102 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
103 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
104 ··if·[·!·-e·"$f"·]·;·then 
105 ····continue 
106 ··fi 
107 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·) 
108 ··if·!·test·-z·"$matching_list";·then 
109 ····while·IFS=·read·-r·entry;·do 
110 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data 
111 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
112 ····done·<<<·"$matching_list" 
  
113 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
114 visudo" 
115 ··fi 
116 done 
117 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x898 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
118 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low99 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
119 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low100 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
120 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false101 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
121 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict102 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
122 -·name:·Find·/etc/sudoers.d/·files103 -·name:·Find·/etc/sudoers.d/·files
123 ··ansible.builtin.find:104 ··ansible.builtin.find:
Offset 150, 14 lines modifiedOffset 129, 35 lines modified
150 ··-·NIST-800-53-IA-11129 ··-·NIST-800-53-IA-11
151 ··-·low_complexity130 ··-·low_complexity
152 ··-·low_disruption131 ··-·low_disruption
153 ··-·medium_severity132 ··-·medium_severity
154 ··-·no_reboot_needed133 ··-·no_reboot_needed
155 ··-·restrict_strategy134 ··-·restrict_strategy
156 ··-·sudo_remove_no_authenticate135 ··-·sudo_remove_no_authenticate
 136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 141 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do
 142 ··if·[·!·-e·"$f"·]·;·then
 143 ····continue
 144 ··fi
 145 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·)
 146 ··if·!·test·-z·"$matching_list";·then
 147 ····while·IFS=·read·-r·entry;·do
 148 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data
 149 ······sed·-i·"s/^${entry}$/#·&/g"·$f
 150 ····done·<<<·"$matching_list"
  
 151 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with
 152 visudo"
 153 ··fi
 154 done
157 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o155 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o
158 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*156 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
159 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using157 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using
160 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure158 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure
161 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any159 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any
162 sudo·configuration·snippets·in·/etc/sudoers.d/.160 sudo·configuration·snippets·in·/etc/sudoers.d/.
163 ············Without·re-authentication,·users·may·access·resources·or·perform161 ············Without·re-authentication,·users·may·access·resources·or·perform
Offset 178, 35 lines modifiedOffset 178, 14 lines modified
178 ···························1.7,·SR·1.8,·SR·1.9178 ···························1.7,·SR·1.8,·SR·1.9
179 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,179 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
180 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3180 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
181 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)181 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
182 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7182 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
183 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,183 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
184 ···························SRG-OS-000373-GPOS-00158184 ···························SRG-OS-000373-GPOS-00158
185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
190 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
191 ··if·[·!·-e·"$f"·]·;·then 
192 ····continue 
193 ··fi 
194 ··matching_list=$(grep·-P·'^(?!#).*[\s]+NOPASSWD[\s]*\:.*$'·$f·|·uniq·) 
195 ··if·!·test·-z·"$matching_list";·then 
196 ····while·IFS=·read·-r·entry;·do 
197 ······#·comment·out·"NOPASSWD"·matches·to·preserve·user·data 
198 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
199 ····done·<<<·"$matching_list" 
  
200 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
201 visudo" 
202 ··fi 
203 done 
204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
209 -·name:·Find·/etc/sudoers.d/·files190 -·name:·Find·/etc/sudoers.d/·files
210 ··ansible.builtin.find:191 ··ansible.builtin.find:
Offset 237, 14 lines modifiedOffset 216, 35 lines modified
237 ··-·NIST-800-53-IA-11216 ··-·NIST-800-53-IA-11
238 ··-·low_complexity217 ··-·low_complexity
239 ··-·low_disruption218 ··-·low_disruption
Max diff block lines reached; 40434/46150 bytes (87.61%) of diff not shown.
1.1 MB
./usr/share/doc/ssg-debian/ssg-debian11-guide-anssi_np_nt28_restrictive.html
    
Offset 14283, 15 lines modifiedOffset 14283, 15 lines modified
00037ca0:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v00037ca0:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v
00037cb0:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>00037cb0:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>
00037cc0:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><00037cc0:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><
00037cd0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro00037cd0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro
00037ce0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong00037ce0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong
00037cf0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············00037cf0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············
00037d00:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·20200037d00:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202
00037d10:·362d·3031·2d30·3829·0a20·2020·2020·2020··6-01-08).·······00037d10:·342d·3132·2d30·3729·0a20·2020·2020·2020··4-12-07).·······
00037d20:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></00037d20:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></
00037d30:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab00037d30:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab
00037d40:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</00037d40:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</
00037d50:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr00037d50:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr
00037d60:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s00037d60:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s
00037d70:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten00037d70:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten
00037d80:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">00037d80:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">
Offset 16011, 147 lines modifiedOffset 16011, 147 lines modified
0003e8a0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003e8a0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003e8b0:·743d·2223·6964·6d31·3934·3022·2074·6162··t="#idm1940"·tab0003e8b0:·743d·2223·6964·6d31·3934·3022·2074·6162··t="#idm1940"·tab
0003e8c0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003e8c0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003e8d0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003e8d0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003e8e0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003e8e0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003e8f0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003e8f0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003e900:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003e900:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003e910:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
0003e920:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
0003e930:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003e940:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003e950:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003e960:·6964·6d31·3934·3022·3e3c·7461·626c·6520··idm1940"><table· 
0003e970:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003e980:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003e990:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003e9a0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003e9b0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003e9c0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003e9d0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003e9e0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003e9f0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003ea00:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003ea10:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003ea20:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003ea30:·7465·6779·3a3c·2f74·683e·3c74·643e·7265··tegy:</th><td>re 
0003ea40:·7374·7269·6374·3c2f·7464·3e3c·2f74·723e··strict</td></tr> 
0003ea50:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003ea60:·6465·3e0a·666f·7220·6620·696e·202f·6574··de>.for·f·in·/et 
0003ea70:·632f·7375·646f·6572·7320·2f65·7463·2f73··c/sudoers·/etc/s 
0003ea80:·7564·6f65·7273·2e64·2f2a·203b·2064·6f0a··udoers.d/*·;·do. 
0003ea90:·2020·6966·205b·2021·202d·6520·2224·6622····if·[·!·-e·"$f" 
0003eaa0:·205d·203b·2074·6865·6e0a·2020·2020·636f···]·;·then.····co 
0003eab0:·6e74·696e·7565·0a20·2066·690a·2020·6d61··ntinue.··fi.··ma 
0003eac0:·7463·6869·6e67·5f6c·6973·743d·2428·6772··tching_list=$(gr 
0003ead0:·6570·202d·5020·275e·283f·2123·292e·2a5b··ep·-P·'^(?!#).*[ 
0003eae0:·5c73·5d2b·5c21·6175·7468·656e·7469·6361··\s]+\!authentica 
0003eaf0:·7465·2e2a·2427·2024·6620·7c20·756e·6971··te.*$'·$f·|·uniq 
0003eb00:·2029·0a20·2069·6620·2120·7465·7374·202d···).··if·!·test·- 
0003eb10:·7a20·2224·6d61·7463·6869·6e67·5f6c·6973··z·"$matching_lis 
0003eb20:·7422·3b20·7468·656e·0a20·2020·2077·6869··t";·then.····whi 
0003eb30:·6c65·2049·4653·3d20·7265·6164·202d·7220··le·IFS=·read·-r· 
0003eb40:·656e·7472·793b·2064·6f0a·2020·2020·2020··entry;·do.······ 
0003eb50:·2320·636f·6d6d·656e·7420·6f75·7420·2221··#·comment·out·"! 
0003eb60:·6175·7468·656e·7469·6361·7465·2220·6d61··authenticate"·ma 
0003eb70:·7463·6865·7320·746f·2070·7265·7365·7276··tches·to·preserv 
0003eb80:·6520·7573·6572·2064·6174·610a·2020·2020··e·user·data.···· 
0003eb90:·2020·7365·6420·2d69·2022·732f·5e24·7b65····sed·-i·"s/^${e 
0003eba0:·6e74·7279·7d24·2f23·2026·616d·703b·2f67··ntry}$/#·&amp;/g 
0003ebb0:·2220·2466·0a20·2020·2064·6f6e·6520·266c··"·$f.····done·&l 
0003ebc0:·743b·266c·743b·266c·743b·2022·246d·6174··t;&lt;&lt;·"$mat 
0003ebd0:·6368·696e·675f·6c69·7374·220a·0a20·2020··ching_list"..··· 
0003ebe0:·202f·7573·722f·7362·696e·2f76·6973·7564···/usr/sbin/visud 
0003ebf0:·6f20·2d63·6620·2466·2026·616d·703b·2667··o·-cf·$f·&amp;&g 
0003ec00:·743b·202f·6465·762f·6e75·6c6c·207c·7c20··t;·/dev/null·||· 
0003ec10:·6563·686f·2022·4661·696c·2074·6f20·7661··echo·"Fail·to·va 
0003ec20:·6c69·6461·7465·2024·6620·7769·7468·2076··lidate·$f·with·v 
0003ec30:·6973·7564·6f22·0a20·2066·690a·646f·6e65··isudo".··fi.done 
0003ec40:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003ec50:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003ec60:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003ec70:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003ec80:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003ec90:·743d·2223·6964·6d31·3934·3122·2074·6162··t="#idm1941"·tab 
0003eca0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003ecb0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003ecc0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003ecd0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003ece0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003ecf0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A0003e910:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
0003ed00:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.0003e920:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.
0003ed10:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003e930:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003ed20:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003e940:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003ed30:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003e950:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003ed40:·643d·2269·646d·3139·3431·223e·3c74·6162··d="idm1941"><tab0003e960:·643d·2269·646d·3139·3430·223e·3c74·6162··d="idm1940"><tab
0003ed50:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003e970:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003ed60:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003e980:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003ed70:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003e990:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003ed80:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003e9a0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003ed90:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003e9b0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003eda0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003e9c0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003edb0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003e9d0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
0003edc0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003e9e0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003edd0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003e9f0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003ede0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<0003ea00:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
0003edf0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003ea10:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003ee00:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003ea20:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003ee10:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003ea30:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003ee20:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></0003ea40:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></
0003ee30:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003ea50:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
0003ee40:·3c63·6f64·653e·2d20·6e61·6d65·3a20·4669··<code>-·name:·Fi0003ea60:·3c63·6f64·653e·2d20·6e61·6d65·3a20·4669··<code>-·name:·Fi
0003ee50:·6e64·202f·6574·632f·7375·646f·6572·732e··nd·/etc/sudoers.0003ea70:·6e64·202f·6574·632f·7375·646f·6572·732e··nd·/etc/sudoers.
0003ee60:·642f·2066·696c·6573·0a20·2061·6e73·6962··d/·files.··ansib0003ea80:·642f·2066·696c·6573·0a20·2061·6e73·6962··d/·files.··ansib
0003ee70:·6c65·2e62·7569·6c74·696e·2e66·696e·643a··le.builtin.find:0003ea90:·6c65·2e62·7569·6c74·696e·2e66·696e·643a··le.builtin.find:
0003ee80:·0a20·2020·2070·6174·6873·3a0a·2020·2020··.····paths:.····0003eaa0:·0a20·2020·2070·6174·6873·3a0a·2020·2020··.····paths:.····
0003ee90:·2d20·2f65·7463·2f73·7564·6f65·7273·2e64··-·/etc/sudoers.d0003eab0:·2d20·2f65·7463·2f73·7564·6f65·7273·2e64··-·/etc/sudoers.d
0003eea0:·2f0a·2020·7265·6769·7374·6572·3a20·7375··/.··register:·su0003eac0:·2f0a·2020·7265·6769·7374·6572·3a20·7375··/.··register:·su
0003eeb0:·646f·6572·730a·2020·7461·6773·3a0a·2020··doers.··tags:.··0003ead0:·646f·6572·730a·2020·7461·6773·3a0a·2020··doers.··tags:.··
0003eec0:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM0003eae0:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
0003eed0:·2d36·2861·290a·2020·2d20·4e49·5354·2d38··-6(a).··-·NIST-80003eaf0:·2d36·2861·290a·2020·2d20·4e49·5354·2d38··-6(a).··-·NIST-8
0003eee0:·3030·2d35·332d·4941·2d31·310a·2020·2d20··00-53-IA-11.··-·0003eb00:·3030·2d35·332d·4941·2d31·310a·2020·2d20··00-53-IA-11.··-·
0003eef0:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.·0003eb10:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.·
0003ef00:·202d·206c·6f77·5f64·6973·7275·7074·696f···-·low_disruptio0003eb20:·202d·206c·6f77·5f64·6973·7275·7074·696f···-·low_disruptio
0003ef10:·6e0a·2020·2d20·6d65·6469·756d·5f73·6576··n.··-·medium_sev0003eb30:·6e0a·2020·2d20·6d65·6469·756d·5f73·6576··n.··-·medium_sev
0003ef20:·6572·6974·790a·2020·2d20·6e6f·5f72·6562··erity.··-·no_reb0003eb40:·6572·6974·790a·2020·2d20·6e6f·5f72·6562··erity.··-·no_reb
0003ef30:·6f6f·745f·6e65·6564·6564·0a20·202d·2072··oot_needed.··-·r0003eb50:·6f6f·745f·6e65·6564·6564·0a20·202d·2072··oot_needed.··-·r
0003ef40:·6573·7472·6963·745f·7374·7261·7465·6779··estrict_strategy0003eb60:·6573·7472·6963·745f·7374·7261·7465·6779··estrict_strategy
0003ef50:·0a20·202d·2073·7564·6f5f·7265·6d6f·7665··.··-·sudo_remove0003eb70:·0a20·202d·2073·7564·6f5f·7265·6d6f·7665··.··-·sudo_remove
0003ef60:·5f6e·6f5f·6175·7468·656e·7469·6361·7465··_no_authenticate0003eb80:·5f6e·6f5f·6175·7468·656e·7469·6361·7465··_no_authenticate
0003ef70:·0a0a·2d20·6e61·6d65·3a20·5265·6d6f·7665··..-·name:·Remove0003eb90:·0a0a·2d20·6e61·6d65·3a20·5265·6d6f·7665··..-·name:·Remove
0003ef80:·206c·696e·6573·2063·6f6e·7461·696e·696e···lines·containin0003eba0:·206c·696e·6573·2063·6f6e·7461·696e·696e···lines·containin
Max diff block lines reached; 1002550/1022614 bytes (98.04%) of diff not shown.
125 KB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Restrictive·Level38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Restrictive·Level
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_restrictive39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_restrictive
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:debian:debian_linux:1141 ····*·cpe:/o:debian:debian_linux:11
42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
43 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8443 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
48 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g48 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
49 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s49 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
50 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s50 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
51 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n51 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
Offset 229, 35 lines modifiedOffset 229, 14 lines modified
229 ···························1.7,·SR·1.8,·SR·1.9229 ···························1.7,·SR·1.8,·SR·1.9
230 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,230 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
231 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3231 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
232 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)232 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
233 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7233 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
234 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,234 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
235 ···························SRG-OS-000373-GPOS-00158235 ···························SRG-OS-000373-GPOS-00158
236 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
237 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
238 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
239 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
240 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
241 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
242 ··if·[·!·-e·"$f"·]·;·then 
243 ····continue 
244 ··fi 
245 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·) 
246 ··if·!·test·-z·"$matching_list";·then 
247 ····while·IFS=·read·-r·entry;·do 
248 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data 
249 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
250 ····done·<<<·"$matching_list" 
  
251 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
252 visudo" 
253 ··fi 
254 done 
255 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8236 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
256 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low237 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
257 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low238 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
258 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false239 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
259 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict240 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
260 -·name:·Find·/etc/sudoers.d/·files241 -·name:·Find·/etc/sudoers.d/·files
261 ··ansible.builtin.find:242 ··ansible.builtin.find:
Offset 288, 14 lines modifiedOffset 267, 35 lines modified
288 ··-·NIST-800-53-IA-11267 ··-·NIST-800-53-IA-11
289 ··-·low_complexity268 ··-·low_complexity
290 ··-·low_disruption269 ··-·low_disruption
291 ··-·medium_severity270 ··-·medium_severity
292 ··-·no_reboot_needed271 ··-·no_reboot_needed
293 ··-·restrict_strategy272 ··-·restrict_strategy
294 ··-·sudo_remove_no_authenticate273 ··-·sudo_remove_no_authenticate
 274 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 275 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 276 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 277 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 278 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 279 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do
 280 ··if·[·!·-e·"$f"·]·;·then
 281 ····continue
 282 ··fi
 283 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·)
 284 ··if·!·test·-z·"$matching_list";·then
 285 ····while·IFS=·read·-r·entry;·do
 286 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data
 287 ······sed·-i·"s/^${entry}$/#·&/g"·$f
 288 ····done·<<<·"$matching_list"
  
 289 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with
 290 visudo"
 291 ··fi
 292 done
295 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o293 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o
296 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*294 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
297 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using295 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using
298 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure296 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure
299 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any297 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any
300 sudo·configuration·snippets·in·/etc/sudoers.d/.298 sudo·configuration·snippets·in·/etc/sudoers.d/.
301 ············Without·re-authentication,·users·may·access·resources·or·perform299 ············Without·re-authentication,·users·may·access·resources·or·perform
Offset 316, 35 lines modifiedOffset 316, 14 lines modified
316 ···························1.7,·SR·1.8,·SR·1.9316 ···························1.7,·SR·1.8,·SR·1.9
317 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,317 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
318 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3318 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
319 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)319 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
320 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7320 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
321 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,321 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
322 ···························SRG-OS-000373-GPOS-00158322 ···························SRG-OS-000373-GPOS-00158
323 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
324 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
325 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
326 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
327 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
328 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
329 ··if·[·!·-e·"$f"·]·;·then 
330 ····continue 
331 ··fi 
332 ··matching_list=$(grep·-P·'^(?!#).*[\s]+NOPASSWD[\s]*\:.*$'·$f·|·uniq·) 
333 ··if·!·test·-z·"$matching_list";·then 
334 ····while·IFS=·read·-r·entry;·do 
335 ······#·comment·out·"NOPASSWD"·matches·to·preserve·user·data 
336 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
337 ····done·<<<·"$matching_list" 
  
338 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
339 visudo" 
340 ··fi 
341 done 
342 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8323 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
343 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low324 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
344 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low325 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
345 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false326 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
346 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict327 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
347 -·name:·Find·/etc/sudoers.d/·files328 -·name:·Find·/etc/sudoers.d/·files
348 ··ansible.builtin.find:329 ··ansible.builtin.find:
Offset 375, 14 lines modifiedOffset 354, 35 lines modified
375 ··-·NIST-800-53-IA-11354 ··-·NIST-800-53-IA-11
376 ··-·low_complexity355 ··-·low_complexity
377 ··-·low_disruption356 ··-·low_disruption
Max diff block lines reached; 122451/128177 bytes (95.53%) of diff not shown.
1.04 MB
./usr/share/doc/ssg-debian/ssg-debian11-guide-standard.html
    
Offset 14285, 15 lines modifiedOffset 14285, 15 lines modified
00037cc0:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren00037cc0:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren
00037cd0:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro00037cd0:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro
00037ce0:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron00037ce0:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron
00037cf0:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s00037cf0:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s
00037d00:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str00037d00:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str
00037d10:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········00037d10:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········
00037d20:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·00037d20:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·
00037d30:·3230·3236·2d30·312d·3038·290a·2020·2020··2026-01-08).····00037d30:·3230·3234·2d31·322d·3037·290a·2020·2020··2024-12-07).····
00037d40:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li00037d40:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li
00037d50:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>00037d50:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>
00037d60:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content00037d60:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content
00037d70:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a00037d70:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a
00037d80:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or00037d80:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or
00037d90:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con00037d90:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con
00037da0:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste00037da0:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste
Offset 16220, 736 lines modifiedOffset 16220, 736 lines modified
0003f5b0:·7267·6574·3d22·2369·646d·3530·3437·2220··rget="#idm5047"·0003f5b0:·7267·6574·3d22·2369·646d·3530·3437·2220··rget="#idm5047"·
0003f5c0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003f5c0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003f5d0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003f5d0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003f5e0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003f5e0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003f5f0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003f5f0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003f600:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003f600:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
Diff chunk too large, falling back to line-by-line diff (722 lines added, 722 lines removed)
0003f610:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003f610:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003f620:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.0003f620:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe
0003f630:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003f630:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003f640:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003f640:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003f650:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003f650:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003f660:·643d·2269·646d·3530·3437·223e·3c70·7265··d="idm5047"><pre0003f660:·2220·6964·3d22·6964·6d35·3034·3722·3e3c··"·id="idm5047"><
0003f670:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia0003f670:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003f680:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab0003f680:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003f690:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa0003f690:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003f6a0:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if·0003f6a0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003f6b0:·5b20·2120·2d66·202f·2e64·6f63·6b65·7265··[·!·-f·/.dockere0003f6b0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003f6c0:·6e76·205d·2026·616d·703b·2661·6d70·3b20··nv·]·&amp;&amp;·0003f6c0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003f6d0:·5b20·2120·2d66·202f·7275·6e2f·2e63·6f6e··[·!·-f·/run/.con0003f6d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003f6e0:·7461·696e·6572·656e·7620·5d3b·2074·6865··tainerenv·];·the0003f6e0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003f6f0:·6e0a·0a23·204c·6973·7420·6f66·206c·6f67··n..#·List·of·log0003f6f0:·683e·3c74·643e·6d65·6469·756d·3c2f·7464··h><td>medium</td
0003f700:·2066·696c·6520·7061·7468·7320·746f·2062···file·paths·to·b0003f700:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003f710:·6520·696e·7370·6563·7465·6420·666f·7220··e·inspected·for·0003f710:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003f720:·636f·7272·6563·7420·7065·726d·6973·7369··correct·permissi0003f720:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003f730:·6f6e·730a·2320·2a20·5072·696d·6172·696c··ons.#·*·Primaril0003f730:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003f740:·7920·696e·7370·6563·7420·6c6f·6720·6669··y·inspect·log·fi0003f740:·7468·3e3c·7464·3e63·6f6e·6669·6775·7265··th><td>configure
0003f750:·6c65·2070·6174·6873·206c·6973·7465·6420··le·paths·listed·0003f750:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003f760:·696e·202f·6574·632f·7273·7973·6c6f·672e··in·/etc/rsyslog.0003f760:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n
0003f770:·636f·6e66·0a52·5359·534c·4f47·5f45·5443··conf.RSYSLOG_ETC0003f770:·616d·653a·2045·6e73·7572·6520·4c6f·6720··ame:·Ensure·Log·
0003f780:·5f43·4f4e·4649·473d·222f·6574·632f·7273··_CONFIG="/etc/rs0003f780:·4669·6c65·7320·4172·6520·4f77·6e65·6420··Files·Are·Owned·
0003f790:·7973·6c6f·672e·636f·6e66·220a·2320·2a20··yslog.conf".#·*·0003f790:·4279·2041·7070·726f·7072·6961·7465·2047··By·Appropriate·G
0003f7a0:·416e·6420·616c·736f·2074·6865·206c·6f67··And·also·the·log0003f7a0:·726f·7570·202d·2053·6574·2072·7379·736c··roup·-·Set·rsysl
0003f7b0:·2066·696c·6520·7061·7468·7320·6c69·7374···file·paths·list0003f7b0:·6f67·206c·6f67·6669·6c65·2063·6f6e·6669··og·logfile·confi
0003f7c0:·6564·2061·6674·6572·2072·7379·736c·6f67··ed·after·rsyslog0003f7c0:·6775·7261·7469·6f6e·0a20·2020·2066·6163··guration.····fac
0003f7d0:·2773·2024·496e·636c·7564·6543·6f6e·6669··'s·$IncludeConfi0003f7d0:·7473·0a20·2061·6e73·6962·6c65·2e62·7569··ts.··ansible.bui
0003f7e0:·6720·6469·7265·6374·6976·650a·2320·2020··g·directive.#···0003f7e0:·6c74·696e·2e73·6574·5f66·6163·743a·0a20··ltin.set_fact:.·
0003f7f0:·2873·746f·7265·2074·6865·2072·6573·756c··(store·the·resul0003f7f0:·2020·2072·7379·736c·6f67·5f65·7463·5f63·····rsyslog_etc_c
0003f800:·7420·696e·746f·2061·7272·6179·2066·6f72··t·into·array·for0003f800:·6f6e·6669·673a·202f·6574·632f·7273·7973··onfig:·/etc/rsys
0003f810:·2074·6865·2063·6173·6520·7468·6572·6527···the·case·there'0003f810:·6c6f·672e·636f·6e66·0a20·2077·6865·6e3a··log.conf.··when:
0003f820:·7320·7368·656c·6c20·676c·6f62·2075·7365··s·shell·glob·use0003f820:·2061·6e73·6962·6c65·5f76·6972·7475·616c···ansible_virtual
0003f830:·6420·6173·2076·616c·7565·206f·6620·496e··d·as·value·of·In0003f830:·697a·6174·696f·6e5f·7479·7065·206e·6f74··ization_type·not
0003f840:·636c·7564·6543·6f6e·6669·6729·0a72·6561··cludeConfig).rea0003f840:·2069·6e20·5b22·646f·636b·6572·222c·2022···in·["docker",·"
0003f850:·6461·7272·6179·202d·7420·4f4c·445f·494e··darray·-t·OLD_IN0003f850:·6c78·6322·2c20·226f·7065·6e76·7a22·2c20··lxc",·"openvz",·
0003f860:·4320·266c·743b·2026·6c74·3b28·6772·6570··C·&lt;·&lt;(grep0003f860:·2270·6f64·6d61·6e22·2c20·2263·6f6e·7461··"podman",·"conta
0003f870:·202d·6520·225c·2449·6e63·6c75·6465·436f···-e·"\$IncludeCo0003f870:·696e·6572·225d·0a20·2074·6167·733a·0a20··iner"].··tags:.·
0003f880:·6e66·6967·5b5b·3a73·7061·6365·3a5d·5d5c··nfig[[:space:]]\0003f880:·202d·204e·4953·542d·3830·302d·3533·2d41···-·NIST-800-53-A
0003f890:·2b5b·5e5b·3a73·7061·6365·3a5d·3b5d·5c2b··+[^[:space:];]\+0003f890:·432d·3628·3129·0a20·202d·204e·4953·542d··C-6(1).··-·NIST-
0003f8a0:·2220·2f65·7463·2f72·7379·736c·6f67·2e63··"·/etc/rsyslog.c0003f8a0:·3830·302d·3533·2d43·4d2d·3628·6129·0a20··800-53-CM-6(a).·
0003f8b0:·6f6e·6620·7c20·6375·7420·2d64·2027·2027··onf·|·cut·-d·'·'0003f8b0:·202d·2050·4349·2d44·5353·2d52·6571·2d31···-·PCI-DSS-Req-1
0003f8c0:·202d·6620·3229·0a72·6561·6461·7272·6179···-f·2).readarray0003f8c0:·302e·352e·310a·2020·2d20·5043·492d·4453··0.5.1.··-·PCI-DS
0003f8d0:·202d·7420·5253·5953·4c4f·475f·494e·434c···-t·RSYSLOG_INCL0003f8d0:·532d·5265·712d·3130·2e35·2e32·0a20·202d··S-Req-10.5.2.··-
0003f8e0:·5544·455f·434f·4e46·4947·2026·6c74·3b20··UDE_CONFIG·&lt;·0003f8e0:·2050·4349·2d44·5353·7634·2d31·302e·332e···PCI-DSSv4-10.3.
0003f8f0:·266c·743b·2866·6f72·2049·4e43·5041·5448··&lt;(for·INCPATH0003f8f0:·320a·2020·2d20·636f·6e66·6967·7572·655f··2.··-·configure_
0003f900:·2069·6e20·2224·7b4f·4c44·5f49·4e43·5b40···in·"${OLD_INC[@0003f900:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low
0003f910:·5d7d·223b·2064·6f20·6576·616c·2070·7269··]}";·do·eval·pri0003f910:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-·
0003f920:·6e74·6620·2725·735c·5c6e·2720·2224·7b49··ntf·'%s\\n'·"${I0003f920:·6d65·6469·756d·5f64·6973·7275·7074·696f··medium_disruptio
0003f930:·4e43·5041·5448·7d22·3b20·646f·6e65·290a··NCPATH}";·done).0003f930:·6e0a·2020·2d20·6d65·6469·756d·5f73·6576··n.··-·medium_sev
0003f940:·7265·6164·6172·7261·7920·2d74·204e·4557··readarray·-t·NEW0003f940:·6572·6974·790a·2020·2d20·6e6f·5f72·6562··erity.··-·no_reb
0003f950:·5f49·4e43·2026·6c74·3b20·266c·743b·2873··_INC·&lt;·&lt;(s0003f950:·6f6f·745f·6e65·6564·6564·0a20·202d·2072··oot_needed.··-·r
0003f960:·6564·202d·6e20·272f·5e5c·732a·696e·636c··ed·-n·'/^\s*incl0003f960:·7379·736c·6f67·5f66·696c·6573·5f67·726f··syslog_files_gro
0003f970:·7564·6528·2f2c·2f29·2f49·7027·202f·6574··ude(/,/)/Ip'·/et0003f970:·7570·6f77·6e65·7273·6869·700a·0a2d·206e··upownership..-·n
0003f980:·632f·7273·7973·6c6f·672e·636f·6e66·207c··c/rsyslog.conf·|0003f980:·616d·653a·2045·6e73·7572·6520·4c6f·6720··ame:·Ensure·Log·
0003f990:·2073·6564·202d·6e20·2773·402e·2a66·696c···sed·-n·'s@.*fil0003f990:·4669·6c65·7320·4172·6520·4f77·6e65·6420··Files·Are·Owned·
0003f9a0:·655c·732a·3d5c·732a·225c·285b·2f5b·3a61··e\s*=\s*"\([/[:a0003f9a0:·4279·2041·7070·726f·7072·6961·7465·2047··By·Appropriate·G
0003f9b0:·6c6e·756d·3a5d·5b3a·7075·6e63·743a·5d5d··lnum:][:punct:]]0003f9b0:·726f·7570·202d·2047·6574·2049·6e63·6c75··roup·-·Get·Inclu
0003f9c0:·2a5c·2922·2e2a·405c·3140·4970·2729·0a72··*\)".*@\1@Ip').r0003f9c0:·6465·436f·6e66·6967·2064·6972·6563·7469··deConfig·directi
0003f9d0:·6561·6461·7272·6179·202d·7420·5253·5953··eadarray·-t·RSYS0003f9d0:·7665·0a20·2061·6e73·6962·6c65·2e62·7569··ve.··ansible.bui
0003f9e0:·4c4f·475f·494e·434c·5544·4520·266c·743b··LOG_INCLUDE·&lt;0003f9e0:·6c74·696e·2e73·6865·6c6c·3a20·7c0a·2020··ltin.shell:·|.··
0003f9f0:·2026·6c74·3b28·666f·7220·494e·4350·4154···&lt;(for·INCPAT0003f9f0:·2020·6772·6570·202d·6520·2724·496e·636c····grep·-e·'$Incl
0003fa00:·4820·696e·2022·247b·4e45·575f·494e·435b··H·in·"${NEW_INC[0003fa00:·7564·6543·6f6e·6669·6727·207b·7b20·7273··udeConfig'·{{·rs
0003fa10:·405d·7d22·3b20·646f·2065·7661·6c20·7072··@]}";·do·eval·pr0003fa10:·7973·6c6f·675f·6574·635f·636f·6e66·6967··yslog_etc_config
0003fa20:·696e·7466·2027·2573·5c5c·6e27·2022·247b··intf·'%s\\n'·"${0003fa20:·207d·7d20·7c20·6375·7420·2d64·2027·2027···}}·|·cut·-d·'·'
0003fa30:·494e·4350·4154·487d·223b·2064·6f6e·6529··INCPATH}";·done)0003fa30:·202d·6620·3220·7c7c·2074·7275·650a·2020···-f·2·||·true.··
0003fa40:·0a0a·2320·4465·636c·6172·6520·616e·2061··..#·Declare·an·a0003fa40:·7265·6769·7374·6572·3a20·7273·7973·6c6f··register:·rsyslo
0003fa50:·7272·6179·2074·6f20·686f·6c64·2074·6865··rray·to·hold·the0003fa50:·675f·6f6c·645f·696e·630a·2020·6368·616e··g_old_inc.··chan
0003fa60:·2066·696e·616c·206c·6973·7420·6f66·2064···final·list·of·d0003fa60:·6765·645f·7768·656e·3a20·6661·6c73·650a··ged_when:·false.
0003fa70:·6966·6665·7265·6e74·206c·6f67·2066·696c··ifferent·log·fil0003fa70:·2020·7768·656e·3a20·616e·7369·626c·655f····when:·ansible_
0003fa80:·6520·7061·7468·730a·6465·636c·6172·6520··e·paths.declare·0003fa80:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t
0003fa90:·2d61·204c·4f47·5f46·494c·455f·5041·5448··-a·LOG_FILE_PATH0003fa90:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc
0003faa0:·530a·0a23·2041·7272·6179·2074·6f20·686f··S..#·Array·to·ho0003faa0:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op
0003fab0:·6c64·2061·6c6c·2072·7379·736c·6f67·2063··ld·all·rsyslog·c0003fab0:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman",
0003fac0:·6f6e·6669·6720·656e·7472·6965·730a·5253··onfig·entries.RS0003fac0:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].··
0003fad0:·5953·4c4f·475f·434f·4e46·4947·533d·2829··YSLOG_CONFIGS=()0003fad0:·7461·6773·3a0a·2020·2d20·4e49·5354·2d38··tags:.··-·NIST-8
0003fae0:·0a52·5359·534c·4f47·5f43·4f4e·4649·4753··.RSYSLOG_CONFIGS0003fae0:·3030·2d35·332d·4143·2d36·2831·290a·2020··00-53-AC-6(1).··
0003faf0:·3d28·2224·7b52·5359·534c·4f47·5f45·5443··=("${RSYSLOG_ETC0003faf0:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
0003fb00:·5f43·4f4e·4649·477d·2220·2224·7b52·5359··_CONFIG}"·"${RSY0003fb00:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS
0003fb10:·534c·4f47·5f49·4e43·4c55·4445·5f43·4f4e··SLOG_INCLUDE_CON0003fb10:·532d·5265·712d·3130·2e35·2e31·0a20·202d··S-Req-10.5.1.··-
0003fb20:·4649·475b·405d·7d22·2022·247b·5253·5953··FIG[@]}"·"${RSYS0003fb20:·2050·4349·2d44·5353·2d52·6571·2d31·302e···PCI-DSS-Req-10.
0003fb30:·4c4f·475f·494e·434c·5544·455b·405d·7d22··LOG_INCLUDE[@]}"0003fb30:·352e·320a·2020·2d20·5043·492d·4453·5376··5.2.··-·PCI-DSSv
0003fb40:·290a·0a23·2047·6574·2066·756c·6c20·6c69··)..#·Get·full·li0003fb40:·342d·3130·2e33·2e32·0a20·202d·2063·6f6e··4-10.3.2.··-·con
0003fb50:·7374·206f·6620·6669·6c65·7320·746f·2062··st·of·files·to·b0003fb50:·6669·6775·7265·5f73·7472·6174·6567·790a··figure_strategy.
0003fb60:·6520·6368·6563·6b65·640a·2320·5253·5953··e·checked.#·RSYS0003fb60:·2020·2d20·6c6f·775f·636f·6d70·6c65·7869····-·low_complexi
0003fb70:·4c4f·475f·434f·4e46·4947·5320·6d61·7920··LOG_CONFIGS·may·0003fb70:·7479·0a20·202d·206d·6564·6975·6d5f·6469··ty.··-·medium_di
0003fb80:·636f·6e74·6169·6e20·676c·6f62·7320·7375··contain·globs·su0003fb80:·7372·7570·7469·6f6e·0a20·202d·206d·6564··sruption.··-·med
0003fb90:·6368·2061·730a·2320·2f65·7463·2f72·7379··ch·as.#·/etc/rsy0003fb90:·6975·6d5f·7365·7665·7269·7479·0a20·202d··ium_severity.··-
0003fba0:·736c·6f67·2e64·2f2a·2e63·6f6e·6620·2f65··slog.d/*.conf·/e0003fba0:·206e·6f5f·7265·626f·6f74·5f6e·6565·6465···no_reboot_neede
0003fbb0:·7463·2f72·7379·736c·6f67·2e64·2f2a·2e66··tc/rsyslog.d/*.f0003fbb0:·640a·2020·2d20·7273·7973·6c6f·675f·6669··d.··-·rsyslog_fi
0003fbc0:·7275·6c65·0a23·2053·6f2c·206c·6f6f·7020··rule.#·So,·loop·0003fbc0:·6c65·735f·6772·6f75·706f·776e·6572·7368··les_groupownersh
0003fbd0:·6f76·6572·2074·6865·2065·6e74·7269·6573··over·the·entries0003fbd0:·6970·0a0a·2d20·6e61·6d65·3a20·456e·7375··ip..-·name:·Ensu
0003fbe0:·2069·6e20·5253·5953·4c4f·475f·434f·4e46···in·RSYSLOG_CONF0003fbe0:·7265·204c·6f67·2046·696c·6573·2041·7265··re·Log·Files·Are
0003fbf0:·4947·5320·616e·6420·7573·6520·6669·6e64··IGS·and·use·find0003fbf0:·204f·776e·6564·2042·7920·4170·7072·6f70···Owned·By·Approp
0003fc00:·2074·6f20·6765·7420·7468·6520·6c69·7374···to·get·the·list0003fc00:·7269·6174·6520·4772·6f75·7020·2d20·4765··riate·Group·-·Ge
0003fc10:·206f·6620·696e·636c·7564·6564·2066·696c···of·included·fil0003fc10:·7420·696e·636c·7564·6520·6669·6c65·7320··t·include·files·
0003fc20:·6573·2e0a·5253·5953·4c4f·475f·434f·4e46··es..RSYSLOG_CONF0003fc20:·6469·7265·6374·6976·6573·0a20·2061·6e73··directives.··ans
0003fc30:·4947·5f46·494c·4553·3d28·290a·666f·7220··IG_FILES=().for·0003fc30:·6962·6c65·2e62·7569·6c74·696e·2e73·6865··ible.builtin.she
0003fc40:·454e·5452·5920·696e·2022·247b·5253·5953··ENTRY·in·"${RSYS0003fc40:·6c6c·3a20·7c0a·2020·2020·6177·6b20·272f··ll:·|.····awk·'/
0003fc50:·4c4f·475f·434f·4e46·4947·535b·405d·7d22··LOG_CONFIGS[@]}"0003fc50:·292f·7b66·3d30·7d20·2f69·6e63·6c75·6465··)/{f=0}·/include
0003fc60:·0a64·6f0a·0923·2049·6620·6469·7265·6374··.do..#·If·direct0003fc60:·5c28·2f7b·663d·317d·2066·7b20·6e66·3d67··\(/{f=1}·f{·nf=g
0003fc70:·6f72·792c·2072·7379·736c·6f67·2077·696c··ory,·rsyslog·wil0003fc70:·656e·7375·6228·225e·2869·6e63·6c75·6465··ensub("^(include
0003fc80:·6c20·7365·6172·6368·2066·6f72·2063·6f6e··l·search·for·con0003fc80:·5c5c·287c·5c5c·732a·2966·696c·653d·5c22··\\(|\\s*)file=\"
Max diff block lines reached; 865846/967192 bytes (89.52%) of diff not shown.
117 KB
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Debian·1139 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Debian·11
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard
41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
42 ····*·cpe:/o:debian:debian_linux:1142 ····*·cpe:/o:debian:debian_linux:11
43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
44 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8444 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
49 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g49 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
50 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s50 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
51 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s51 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
52 ·········1.·_\x8C_\x8r_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8t_\x8·_\x8D_\x8a_\x8e_\x8m_\x8o_\x8n_\x8s52 ·········1.·_\x8C_\x8r_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8t_\x8·_\x8D_\x8a_\x8e_\x8m_\x8o_\x8n_\x8s
Offset 258, 139 lines modifiedOffset 258, 14 lines modified
258 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-007-3·R2.1,·CIP-007-3·R2.2,·CIP-007-3·R2.3,·CIP-258 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-007-3·R2.1,·CIP-007-3·R2.2,·CIP-007-3·R2.3,·CIP-
259 ···························007-3·R5.1,·CIP-007-3·R5.1.1,·CIP-007-3·R5.1.2259 ···························007-3·R5.1,·CIP-007-3·R5.1.1,·CIP-007-3·R5.1.2
260 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)260 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)
261 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5261 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5
262 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.5.1,·Req-10.5.2262 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.5.1,·Req-10.5.2
263 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71263 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71
264 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.3.2264 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.3.2
265 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
266 #·Remediation·is·applicable·only·in·certain·platforms 
267 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
268 #·List·of·log·file·paths·to·be·inspected·for·correct·permissions 
269 #·*·Primarily·inspect·log·file·paths·listed·in·/etc/rsyslog.conf 
270 RSYSLOG_ETC_CONFIG="/etc/rsyslog.conf" 
271 #·*·And·also·the·log·file·paths·listed·after·rsyslog's·$IncludeConfig·directive 
272 #···(store·the·result·into·array·for·the·case·there's·shell·glob·used·as·value 
273 of·IncludeConfig) 
274 readarray·-t·OLD_INC·<·<(grep·-e·"\$IncludeConfig[[:space:]]\+[^[:space:];]\+" 
275 /etc/rsyslog.conf·|·cut·-d·'·'·-f·2) 
276 readarray·-t·RSYSLOG_INCLUDE_CONFIG·<·<(for·INCPATH·in·"${OLD_INC[@]}";·do·eval 
277 printf·'%s\\n'·"${INCPATH}";·done) 
278 readarray·-t·NEW_INC·<·<(sed·-n·'/^\s*include(/,/)/Ip'·/etc/rsyslog.conf·|·sed 
279 -n·'s@.*file\s*=\s*"\([/[:alnum:][:punct:]]*\)".*@\1@Ip') 
280 readarray·-t·RSYSLOG_INCLUDE·<·<(for·INCPATH·in·"${NEW_INC[@]}";·do·eval·printf 
281 '%s\\n'·"${INCPATH}";·done) 
  
282 #·Declare·an·array·to·hold·the·final·list·of·different·log·file·paths 
283 declare·-a·LOG_FILE_PATHS 
  
284 #·Array·to·hold·all·rsyslog·config·entries 
285 RSYSLOG_CONFIGS=() 
286 RSYSLOG_CONFIGS=("${RSYSLOG_ETC_CONFIG}"·"${RSYSLOG_INCLUDE_CONFIG[@]}"·"$ 
287 {RSYSLOG_INCLUDE[@]}") 
  
288 #·Get·full·list·of·files·to·be·checked 
289 #·RSYSLOG_CONFIGS·may·contain·globs·such·as 
290 #·/etc/rsyslog.d/*.conf·/etc/rsyslog.d/*.frule 
291 #·So,·loop·over·the·entries·in·RSYSLOG_CONFIGS·and·use·find·to·get·the·list·of 
292 included·files. 
293 RSYSLOG_CONFIG_FILES=() 
294 for·ENTRY·in·"${RSYSLOG_CONFIGS[@]}" 
295 do 
296 »       #·If·directory,·rsyslog·will·search·for·config·files·in·recursively. 
297 »       #·However,·files·in·hidden·sub-directories·or·hidden·files·will·be·ignored. 
298 »       if·[·-d·"${ENTRY}"·] 
299 »       then 
300 »       »       readarray·-t·FINDOUT·<·<(find·"${ENTRY}"·-not·-path·'*/.*'·-type·f) 
301 »       »       RSYSLOG_CONFIG_FILES+=("${FINDOUT[@]}") 
302 »       elif·[·-f·"${ENTRY}"·] 
303 »       then 
304 »       »       RSYSLOG_CONFIG_FILES+=("${ENTRY}") 
305 »       else 
306 »       »       echo·"Invalid·include·object:·${ENTRY}" 
307 »       fi 
308 done 
  
309 #·Browse·each·file·selected·above·as·containing·paths·of·log·files 
310 #·('/etc/rsyslog.conf'·and·'/etc/rsyslog.d/*.conf'·in·the·default 
311 configuration) 
312 for·LOG_FILE·in·"${RSYSLOG_CONFIG_FILES[@]}" 
313 do 
314 »       #·From·each·of·these·files·extract·just·particular·log·file·path(s),·thus: 
315 »       #·*·Ignore·lines·starting·with·space·('·'),·comment·('#"),·or·variable·syntax 
316 ('$')·characters, 
317 »       #·*·Ignore·empty·lines, 
318 »       #·*·Strip·quotes·and·closing·brackets·from·paths. 
319 »       #·*·Ignore·paths·that·match·/dev|/etc.*\.conf,·as·those·are·paths,·but·likely 
320 not·log·files 
321 »       #·*·From·the·remaining·valid·rows·select·only·fields·constituting·a·log·file 
322 path 
323 »       #·Text·file·column·is·understood·to·represent·a·log·file·path·if·and·only·if 
324 all·of·the 
325 »       #·following·are·met: 
326 »       #·*·it·contains·at·least·one·slash·'/'·character, 
327 »       #·*·it·is·preceded·by·space 
328 »       #·*·it·doesn't·contain·space·('·'),·colon·(':'),·and·semicolon·(';') 
329 characters 
330 »       #·Search·log·file·for·path(s)·only·in·case·it·exists! 
331 »       if·[[·-f·"${LOG_FILE}"·]] 
332 »       then 
333 »       »       NORMALIZED_CONFIG_FILE_LINES=$(sed·-e·"/^[#|$]/d"·"${LOG_FILE}") 
334 »       »       LINES_WITH_PATHS=$(grep·'[^/]*\s\+\S*/\S\+$'·<<<·"$ 
335 {NORMALIZED_CONFIG_FILE_LINES}") 
336 »       »       FILTERED_PATHS=$(awk·'{if(NF>=2&&($NF~/^\//||$NF~/^-\//)){sub(/^-\//,"/ 
337 ",$NF);print·$NF}}'·<<<·"${LINES_WITH_PATHS}") 
338 »       »       CLEANED_PATHS=$(sed·-e·"s/[\"')]//g;·/\\/etc.*\.conf/d;·/\\/dev\\//d"·<<<·"$ 
339 {FILTERED_PATHS}") 
340 »       »       MATCHED_ITEMS=$(sed·-e·"/^$/d"·<<<·"${CLEANED_PATHS}") 
341 »       »       #·Since·above·sed·command·might·return·more·than·one·item·(delimited·by 
342 newline),·split 
343 »       »       #·the·particular·matches·entries·into·new·array·specific·for·this·log·file 
344 »       »       readarray·-t·ARRAY_FOR_LOG_FILE·<<<·"$MATCHED_ITEMS" 
345 »       »       #·Concatenate·the·two·arrays·-·previous·content·of·$LOG_FILE_PATHS·array·with 
346 »       »       #·items·from·newly·created·array·for·this·log·file 
347 »       »       LOG_FILE_PATHS+=("${ARRAY_FOR_LOG_FILE[@]}") 
348 »       »       #·Delete·the·temporary·array 
349 »       »       unset·ARRAY_FOR_LOG_FILE 
350 »       fi 
351 done 
  
352 #·Check·for·RainerScript·action·log·format·which·might·be·also·multiline·so 
353 grep·regex·is·a·bit 
354 #·curly: 
355 #·extract·possibly·multiline·action·omfile·expressions 
356 #·extract·File="logfile"·expression 
357 #·match·only·"logfile"·expression 
358 for·LOG_FILE·in·"${RSYSLOG_CONFIG_FILES[@]}" 
359 do 
360 »       ACTION_OMFILE_LINES=$(grep·-iozP·"action\s*\(\s*type\s*=\s*\"omfile\"[^\)]*\)" 
361 "${LOG_FILE}") 
362 »       OMFILE_LINES=$(echo·"${ACTION_OMFILE_LINES}"|·grep·-iaoP·"\bFile\s*=\s*\"([/[: 
Max diff block lines reached; 113281/119851 bytes (94.52%) of diff not shown.
18.1 MB
./usr/share/doc/ssg-debian/ssg-debian12-guide-anssi_bp28_enhanced.html
    
Offset 14303, 15 lines modifiedOffset 14303, 15 lines modified
00037de0:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current00037de0:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current
00037df0:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron00037df0:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron
00037e00:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong00037e00:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong
00037e10:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st00037e10:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st
00037e20:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro00037e20:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro
00037e30:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············00037e30:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············
00037e40:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·200037e40:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·2
00037e50:·3032·362d·3031·2d30·3829·0a20·2020·2020··026-01-08).·····00037e50:·3032·342d·3132·2d30·3729·0a20·2020·2020··024-12-07).·····
00037e60:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>00037e60:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>
00037e70:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T00037e70:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T
00037e80:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents00037e80:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents
00037e90:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·00037e90:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·
00037ea0:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org00037ea0:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org
00037eb0:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont00037eb0:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont
00037ec0:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system00037ec0:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system
Offset 15076, 129 lines modifiedOffset 15076, 129 lines modified
0003ae30:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003ae30:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003ae40:·743d·2223·6964·6d32·3636·3322·2074·6162··t="#idm2663"·tab0003ae40:·743d·2223·6964·6d32·3636·3322·2074·6162··t="#idm2663"·tab
0003ae50:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003ae50:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003ae60:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003ae60:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003ae70:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003ae70:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003ae80:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003ae80:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003ae90:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003ae90:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003aea0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S0003aea0:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O
 0003aeb0:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint
 0003aec0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0003aed0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003aee0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003aef0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003aeb0:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
0003aec0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003aed0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003aee0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003aef0:·6964·6d32·3636·3322·3e3c·7461·626c·6520··idm2663"><table· 
0003af00:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003af10:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003af20:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003af30:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003af40:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003af50:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003af60:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003af70:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003af80:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003af90:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003afa0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003afb0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003afc0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
0003afd0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
0003afe0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003af00:·3236·3633·223e·3c70·7265·3e3c·636f·6465··2663"><pre><code
 0003af10:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n
 0003af20:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver
 0003af30:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod
 0003af40:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003af50:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003af60:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003af70:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003af80:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003af90:·6d32·3636·3422·2074·6162·696e·6465·783d··m2664"·tabindex=
 0003afa0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003afb0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003afc0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003afd0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003afe0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003aff0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible
 0003b000:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0003b010:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003b020:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003b030:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003b040:·3236·3634·223e·3c74·6162·6c65·2063·6c61··2664"><table·cla
 0003b050:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0003b060:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0003b070:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003b080:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003b090:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003b0a0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003b0b0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0003b0c0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003b0d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b0e0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
 0003b0f0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 0003b100:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003b110:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003aff0:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i 
0003b000:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl 
0003b010:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla 
0003b020:·7466·6f72·6d73·0a69·6620·5b20·2120·2d66··tforms.if·[·!·-f 
0003b030:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·& 
0003b040:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f 
0003b050:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container 
0003b060:·656e·7620·5d3b·2074·6865·6e0a·0a44·4542··env·];·then..DEB 
0003b070:·4941·4e5f·4652·4f4e·5445·4e44·3d6e·6f6e··IAN_FRONTEND=non 
0003b080:·696e·7465·7261·6374·6976·6520·6170·742d··interactive·apt- 
0003b090:·6765·7420·696e·7374·616c·6c20·2d79·2022··get·install·-y·" 
0003b0a0:·6169·6465·220a·0a65·6c73·650a·2020·2020··aide"..else.···· 
0003b0b0:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo· 
0003b0c0:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is· 
0003b0d0:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,· 
0003b0e0:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done 
0003b0f0:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr 
0003b100:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003b110:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003b120:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003b130:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003b140:·6172·6765·743d·2223·6964·6d32·3636·3422··arget="#idm2664" 
0003b150:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003b160:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003b170:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003b180:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003b190:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003b1a0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003b1b0:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp 
0003b1c0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003b1d0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003b1e0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003b1f0:·6522·2069·643d·2269·646d·3236·3634·223e··e"·id="idm2664"> 
0003b200:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003b210:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003b220:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003b230:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003b240:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003b250:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003b260:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b270:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003b280:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b290:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003b2a0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0003b2b0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><0003b120:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
Max diff block lines reached; 17372620/17390200 bytes (99.90%) of diff not shown.
1.52 MB
html2text {}
    
Offset 43, 15 lines modifiedOffset 43, 15 lines modified
43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(enhanced)44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(enhanced)
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_enhanced45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_enhanced
46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
47 ····*·cpe:/o:debian:debian_linux:1247 ····*·cpe:/o:debian:debian_linux:12
48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
49 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8449 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
55 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r55 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
56 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n56 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
57 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g57 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 125, 27 lines modifiedOffset 125, 19 lines modified
125 include·install_aide125 include·install_aide
  
126 class·install_aide·{126 class·install_aide·{
127 ··package·{·'aide':127 ··package·{·'aide':
128 ····ensure·=>·'installed',128 ····ensure·=>·'installed',
129 ··}129 ··}
130 }130 }
 131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
136 #·Remediation·is·applicable·only·in·certain·platforms 
137 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
138 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide" 
  
139 else 
140 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
141 fi132 [[packages]]
 133 name·=·"aide"
 134 version·=·"*"
142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
147 -·name:·Ensure·aide·is·installed140 -·name:·Ensure·aide·is·installed
148 ··package:141 ··package:
Offset 159, 19 lines modifiedOffset 151, 27 lines modified
159 ··-·PCI-DSSv4-11.5.2151 ··-·PCI-DSSv4-11.5.2
160 ··-·enable_strategy152 ··-·enable_strategy
161 ··-·low_complexity153 ··-·low_complexity
162 ··-·low_disruption154 ··-·low_disruption
163 ··-·medium_severity155 ··-·medium_severity
164 ··-·no_reboot_needed156 ··-·no_reboot_needed
165 ··-·package_aide_installed157 ··-·package_aide_installed
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 159 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 160 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 161 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 162 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 163 #·Remediation·is·applicable·only·in·certain·platforms
 164 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
167 [[packages]] 
168 name·=·"aide" 
169 version·=·"*"165 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide"
  
 166 else
 167 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 168 fi
170 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*169 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
171 Run·the·following·command·to·generate·a·new·database:170 Run·the·following·command·to·generate·a·new·database:
172 $·sudo·aideinit171 $·sudo·aideinit
173 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the172 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the
174 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these173 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
175 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their174 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
176 integrity.·The·newly-generated·database·can·be·installed·as·follows:175 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 194, 40 lines modifiedOffset 194, 14 lines modified
194 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3194 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
195 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)195 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
196 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3196 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
197 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5197 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
198 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199198 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
199 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79199 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
200 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2200 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
202 #·Remediation·is·applicable·only·in·certain·platforms 
203 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
204 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide" 
  
205 AIDE_CONFIG=/etc/aide/aide.conf 
206 DEFAULT_DB_PATH=/var/lib/aide/aide.db 
  
207 #·Fix·db·path·in·the·config·file,·if·necessary 
208 if·!·grep·-q·'^database=file:'·${AIDE_CONFIG};·then 
209 ····#·replace_or_append·gets·confused·by·'database=file'·as·a·key,·so·should·not·be·used. 
210 ····#replace_or_append·"${AIDE_CONFIG}"·'^database=file'·"${DEFAULT_DB_PATH}"·'@CCENUM@'·'%s:%s' 
211 ····echo·"database=file:${DEFAULT_DB_PATH}"·>>·${AIDE_CONFIG} 
212 fi 
  
213 #·Fix·db·out·path·in·the·config·file,·if·necessary 
214 if·!·grep·-q·'^database_out=file:'·${AIDE_CONFIG};·then 
215 ····echo·"database_out=file:${DEFAULT_DB_PATH}.new"·>>·${AIDE_CONFIG} 
216 fi 
  
217 /usr/sbin/aideinit·-y·-f 
  
218 else 
219 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
220 fi 
221 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
222 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
223 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
224 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
225 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
226 -·name:·Build·and·Test·AIDE·Database·-·Ensure·AIDE·Is·Installed206 -·name:·Build·and·Test·AIDE·Database·-·Ensure·AIDE·Is·Installed
227 ··ansible.builtin.apt:207 ··ansible.builtin.apt:
Offset 382, 14 lines modifiedOffset 356, 40 lines modified
382 ··-·PCI-DSSv4-11.5.2356 ··-·PCI-DSSv4-11.5.2
383 ··-·aide_build_database357 ··-·aide_build_database
384 ··-·low_complexity358 ··-·low_complexity
385 ··-·low_disruption359 ··-·low_disruption
386 ··-·medium_severity360 ··-·medium_severity
387 ··-·no_reboot_needed361 ··-·no_reboot_needed
388 ··-·restrict_strategy362 ··-·restrict_strategy
 363 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 364 #·Remediation·is·applicable·only·in·certain·platforms
Max diff block lines reached; 1589590/1596153 bytes (99.59%) of diff not shown.
18.3 MB
./usr/share/doc/ssg-debian/ssg-debian12-guide-anssi_bp28_high.html
    
Offset 14302, 15 lines modifiedOffset 14302, 15 lines modified
00037dd0:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v00037dd0:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v
00037de0:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>00037de0:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>
00037df0:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><00037df0:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><
00037e00:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro00037e00:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro
00037e10:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong00037e10:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong
00037e20:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············00037e20:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············
00037e30:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·20200037e30:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202
00037e40:·362d·3031·2d30·3829·0a20·2020·2020·2020··6-01-08).·······00037e40:·342d·3132·2d30·3729·0a20·2020·2020·2020··4-12-07).·······
00037e50:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></00037e50:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></
00037e60:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab00037e60:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab
00037e70:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</00037e70:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</
00037e80:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr00037e80:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr
00037e90:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s00037e90:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s
00037ea0:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten00037ea0:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten
00037eb0:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">00037eb0:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">
Offset 15082, 128 lines modifiedOffset 15082, 128 lines modified
0003ae90:·6574·3d22·2369·646d·3236·3633·2220·7461··et="#idm2663"·ta0003ae90:·6574·3d22·2369·646d·3236·3633·2220·7461··et="#idm2663"·ta
0003aea0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003aea0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003aeb0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003aeb0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003aec0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003aec0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003aed0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003aed0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003aee0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003aee0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003aef0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003aef0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003af00:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
0003af10:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003af20:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003af30:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003af40:·2269·646d·3236·3633·223e·3c74·6162·6c65··"idm2663"><table 
0003af50:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003af60:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003af70:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003af80:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003af90:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003afa0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003afb0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003afc0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003af00:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin
 0003af10:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 0003af20:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003af30:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003af40:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003af50:·6d32·3636·3322·3e3c·7072·653e·3c63·6f64··m2663"><pre><cod
 0003af60:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]].
 0003af70:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve
 0003af80:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co
 0003af90:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0003afa0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 0003afb0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 0003afc0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 0003afd0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 0003afe0:·646d·3236·3634·2220·7461·6269·6e64·6578··dm2664"·tabindex
 0003aff0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 0003b000:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 0003b010:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 0003b020:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 0003b030:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 0003b040:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl
 0003b050:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a
 0003b060:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003b070:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003b080:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003b090:·6d32·3636·3422·3e3c·7461·626c·6520·636c··m2664"><table·cl
 0003b0a0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003b0b0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003b0c0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003b0d0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003b0e0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003b0f0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b100:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003b110:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003b120:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b130:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 0003b140:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0003b150:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003b160:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003afd0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003b170:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003afe0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003aff0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003b000:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003b010:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0003b020:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0003b030:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003b040:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation· 
0003b050:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on 
0003b060:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl 
0003b070:·6174·666f·726d·730a·6966·205b·2021·202d··atforms.if·[·!·- 
0003b080:·6620·2f2e·646f·636b·6572·656e·7620·5d20··f·/.dockerenv·]· 
0003b090:·2661·6d70·3b26·616d·703b·205b·2021·202d··&amp;&amp;·[·!·- 
0003b0a0:·6620·2f72·756e·2f2e·636f·6e74·6169·6e65··f·/run/.containe 
0003b0b0:·7265·6e76·205d·3b20·7468·656e·0a0a·4445··renv·];·then..DE 
0003b0c0:·4249·414e·5f46·524f·4e54·454e·443d·6e6f··BIAN_FRONTEND=no 
0003b0d0:·6e69·6e74·6572·6163·7469·7665·2061·7074··ninteractive·apt 
0003b0e0:·2d67·6574·2069·6e73·7461·6c6c·202d·7920··-get·install·-y· 
0003b0f0:·2261·6964·6522·0a0a·656c·7365·0a20·2020··"aide"..else.··· 
0003b100:·2026·6774·3b26·616d·703b·3220·6563·686f···&gt;&amp;2·echo 
0003b110:·2027·5265·6d65·6469·6174·696f·6e20·6973···'Remediation·is 
0003b120:·206e·6f74·2061·7070·6c69·6361·626c·652c···not·applicable, 
0003b130:·206e·6f74·6869·6e67·2077·6173·2064·6f6e···nothing·was·don 
0003b140:·6527·0a66·690a·3c2f·636f·6465·3e3c·2f70··e'.fi.</code></p 
0003b150:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003b160:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003b170:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003b180:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003b190:·7461·7267·6574·3d22·2369·646d·3236·3634··target="#idm2664 
0003b1a0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003b1b0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003b1c0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003b1d0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003b1e0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003b1f0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003b200:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip 
0003b210:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003b220:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b230:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b240:·7365·2220·6964·3d22·6964·6d32·3636·3422··se"·id="idm2664" 
0003b250:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003b260:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003b270:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003b280:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003b290:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003b2a0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003b2b0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b2c0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003b2d0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b2e0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003b2f0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003b300:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003b310:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
Max diff block lines reached; 17542283/17559725 bytes (99.90%) of diff not shown.
1.54 MB
html2text {}
    
Offset 43, 15 lines modifiedOffset 43, 15 lines modified
43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(high)44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(high)
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_high45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_high
46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
47 ····*·cpe:/o:debian:debian_linux:1247 ····*·cpe:/o:debian:debian_linux:12
48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
49 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8449 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
55 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r55 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
56 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n56 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
57 ·········5.·_\x8K_\x8e_\x8r_\x8n_\x8e_\x8l_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n57 ·········5.·_\x8K_\x8e_\x8r_\x8n_\x8e_\x8l_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
Offset 126, 27 lines modifiedOffset 126, 19 lines modified
126 include·install_aide126 include·install_aide
  
127 class·install_aide·{127 class·install_aide·{
128 ··package·{·'aide':128 ··package·{·'aide':
129 ····ensure·=>·'installed',129 ····ensure·=>·'installed',
130 ··}130 ··}
131 }131 }
 132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
137 #·Remediation·is·applicable·only·in·certain·platforms 
138 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
139 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide" 
  
140 else 
141 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
142 fi133 [[packages]]
 134 name·=·"aide"
 135 version·=·"*"
143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
144 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
145 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
146 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
147 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
148 -·name:·Ensure·aide·is·installed141 -·name:·Ensure·aide·is·installed
149 ··package:142 ··package:
Offset 160, 19 lines modifiedOffset 152, 27 lines modified
160 ··-·PCI-DSSv4-11.5.2152 ··-·PCI-DSSv4-11.5.2
161 ··-·enable_strategy153 ··-·enable_strategy
162 ··-·low_complexity154 ··-·low_complexity
163 ··-·low_disruption155 ··-·low_disruption
164 ··-·medium_severity156 ··-·medium_severity
165 ··-·no_reboot_needed157 ··-·no_reboot_needed
166 ··-·package_aide_installed158 ··-·package_aide_installed
167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 160 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 161 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 162 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 163 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 164 #·Remediation·is·applicable·only·in·certain·platforms
 165 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
168 [[packages]] 
169 name·=·"aide" 
170 version·=·"*"166 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide"
  
 167 else
 168 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 169 fi
171 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*170 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
172 Run·the·following·command·to·generate·a·new·database:171 Run·the·following·command·to·generate·a·new·database:
173 $·sudo·aideinit172 $·sudo·aideinit
174 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the173 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the
175 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these174 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
176 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their175 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
177 integrity.·The·newly-generated·database·can·be·installed·as·follows:176 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 195, 40 lines modifiedOffset 195, 14 lines modified
195 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3195 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
196 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)196 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
197 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3197 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
198 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5198 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
199 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199199 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
200 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79200 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
201 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2201 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
203 #·Remediation·is·applicable·only·in·certain·platforms 
204 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
205 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide" 
  
206 AIDE_CONFIG=/etc/aide/aide.conf 
207 DEFAULT_DB_PATH=/var/lib/aide/aide.db 
  
208 #·Fix·db·path·in·the·config·file,·if·necessary 
209 if·!·grep·-q·'^database=file:'·${AIDE_CONFIG};·then 
210 ····#·replace_or_append·gets·confused·by·'database=file'·as·a·key,·so·should·not·be·used. 
211 ····#replace_or_append·"${AIDE_CONFIG}"·'^database=file'·"${DEFAULT_DB_PATH}"·'@CCENUM@'·'%s:%s' 
212 ····echo·"database=file:${DEFAULT_DB_PATH}"·>>·${AIDE_CONFIG} 
213 fi 
  
214 #·Fix·db·out·path·in·the·config·file,·if·necessary 
215 if·!·grep·-q·'^database_out=file:'·${AIDE_CONFIG};·then 
216 ····echo·"database_out=file:${DEFAULT_DB_PATH}.new"·>>·${AIDE_CONFIG} 
217 fi 
  
218 /usr/sbin/aideinit·-y·-f 
  
219 else 
220 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
221 fi 
222 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
223 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low203 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
224 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low204 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
225 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false205 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
226 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict206 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
227 -·name:·Build·and·Test·AIDE·Database·-·Ensure·AIDE·Is·Installed207 -·name:·Build·and·Test·AIDE·Database·-·Ensure·AIDE·Is·Installed
228 ··ansible.builtin.apt:208 ··ansible.builtin.apt:
Offset 383, 14 lines modifiedOffset 357, 40 lines modified
383 ··-·PCI-DSSv4-11.5.2357 ··-·PCI-DSSv4-11.5.2
384 ··-·aide_build_database358 ··-·aide_build_database
385 ··-·low_complexity359 ··-·low_complexity
386 ··-·low_disruption360 ··-·low_disruption
387 ··-·medium_severity361 ··-·medium_severity
388 ··-·no_reboot_needed362 ··-·no_reboot_needed
389 ··-·restrict_strategy363 ··-·restrict_strategy
 364 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 365 #·Remediation·is·applicable·only·in·certain·platforms
Max diff block lines reached; 1613167/1619867 bytes (99.59%) of diff not shown.
7.35 MB
./usr/share/doc/ssg-debian/ssg-debian12-guide-anssi_bp28_intermediary.html
    
Offset 14304, 15 lines modifiedOffset 14304, 15 lines modified
00037df0:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v00037df0:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v
00037e00:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>00037e00:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>
00037e10:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><00037e10:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><
00037e20:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro00037e20:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro
00037e30:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong00037e30:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong
00037e40:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············00037e40:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············
00037e50:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·20200037e50:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202
00037e60:·362d·3031·2d30·3829·0a20·2020·2020·2020··6-01-08).·······00037e60:·342d·3132·2d30·3729·0a20·2020·2020·2020··4-12-07).·······
00037e70:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></00037e70:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></
00037e80:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab00037e80:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab
00037e90:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</00037e90:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</
00037ea0:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr00037ea0:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr
00037eb0:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s00037eb0:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s
00037ec0:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten00037ec0:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten
00037ed0:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">00037ed0:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">
Offset 15067, 129 lines modifiedOffset 15067, 129 lines modified
0003ada0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003ada0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003adb0:·3d22·2369·646d·3236·3633·2220·7461·6269··="#idm2663"·tabi0003adb0:·3d22·2369·646d·3236·3633·2220·7461·6269··="#idm2663"·tabi
0003adc0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003adc0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003add0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003add0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003ade0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003ade0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003adf0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003adf0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003ae00:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003ae00:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003ae10:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh0003ae10:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
 0003ae20:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
 0003ae30:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003ae40:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003ae50:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003ae60:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm2
0003ae20:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</ 
0003ae30:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003ae40:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003ae50:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003ae60:·646d·3236·3633·223e·3c74·6162·6c65·2063··dm2663"><table·c 
0003ae70:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003ae80:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003ae90:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003aea0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003aeb0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003aec0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003aed0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003aee0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003aef0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003af00:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003af10:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0003af20:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003af30:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003af40:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003af50:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003ae70:·3636·3322·3e3c·7072·653e·3c63·6f64·653e··663"><pre><code>
 0003ae80:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 0003ae90:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers
 0003aea0:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code
 0003aeb0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 0003aec0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 0003aed0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 0003aee0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 0003aef0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 0003af00:·3236·3634·2220·7461·6269·6e64·6578·3d22··2664"·tabindex="
 0003af10:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 0003af20:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 0003af30:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 0003af40:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 0003af50:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0003af60:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible·
 0003af70:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003af80:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003af90:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003afa0:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm2
 0003afb0:·3636·3422·3e3c·7461·626c·6520·636c·6173··664"><table·clas
 0003afc0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003afd0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003afe0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003aff0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003b000:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003b010:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003b020:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003b030:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0003b040:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b050:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 0003b060:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003b070:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003b080:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
0003af60:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is 
0003af70:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only 
0003af80:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat 
0003af90:·666f·726d·730a·6966·205b·2021·202d·6620··forms.if·[·!·-f· 
0003afa0:·2f2e·646f·636b·6572·656e·7620·5d20·2661··/.dockerenv·]·&a 
0003afb0:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f· 
0003afc0:·2f72·756e·2f2e·636f·6e74·6169·6e65·7265··/run/.containere 
0003afd0:·6e76·205d·3b20·7468·656e·0a0a·4445·4249··nv·];·then..DEBI 
0003afe0:·414e·5f46·524f·4e54·454e·443d·6e6f·6e69··AN_FRONTEND=noni 
0003aff0:·6e74·6572·6163·7469·7665·2061·7074·2d67··nteractive·apt-g 
0003b000:·6574·2069·6e73·7461·6c6c·202d·7920·2261··et·install·-y·"a 
0003b010:·6964·6522·0a0a·656c·7365·0a20·2020·2026··ide"..else.····& 
0003b020:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·' 
0003b030:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n 
0003b040:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n 
0003b050:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done' 
0003b060:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre 
0003b070:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003b080:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003b090:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003b0a0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003b0b0:·7267·6574·3d22·2369·646d·3236·3634·2220··rget="#idm2664"· 
0003b0c0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003b0d0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003b0e0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003b0f0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003b100:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003b110:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003b120:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe 
0003b130:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003b140:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003b150:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003b160:·2220·6964·3d22·6964·6d32·3636·3422·3e3c··"·id="idm2664">< 
0003b170:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003b180:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003b190:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003b1a0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003b1b0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003b1c0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003b1d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003b090:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003b1e0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003b1f0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b200:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003b210:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003b220:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
Max diff block lines reached; 6809450/6827030 bytes (99.74%) of diff not shown.
856 KB
html2text {}
    
Offset 43, 15 lines modifiedOffset 43, 15 lines modified
43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(intermediary)44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(intermediary)
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_intermediary45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_intermediary
46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
47 ····*·cpe:/o:debian:debian_linux:1247 ····*·cpe:/o:debian:debian_linux:12
48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
49 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8449 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
55 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n55 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
56 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s56 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
57 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s57 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 123, 27 lines modifiedOffset 123, 19 lines modified
123 include·install_aide123 include·install_aide
  
124 class·install_aide·{124 class·install_aide·{
125 ··package·{·'aide':125 ··package·{·'aide':
126 ····ensure·=>·'installed',126 ····ensure·=>·'installed',
127 ··}127 ··}
128 }128 }
 129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
134 #·Remediation·is·applicable·only·in·certain·platforms 
135 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
136 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide" 
  
137 else 
138 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
139 fi130 [[packages]]
 131 name·=·"aide"
 132 version·=·"*"
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
145 -·name:·Ensure·aide·is·installed138 -·name:·Ensure·aide·is·installed
146 ··package:139 ··package:
Offset 157, 19 lines modifiedOffset 149, 27 lines modified
157 ··-·PCI-DSSv4-11.5.2149 ··-·PCI-DSSv4-11.5.2
158 ··-·enable_strategy150 ··-·enable_strategy
159 ··-·low_complexity151 ··-·low_complexity
160 ··-·low_disruption152 ··-·low_disruption
161 ··-·medium_severity153 ··-·medium_severity
162 ··-·no_reboot_needed154 ··-·no_reboot_needed
163 ··-·package_aide_installed155 ··-·package_aide_installed
164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 157 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 158 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 159 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 160 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 161 #·Remediation·is·applicable·only·in·certain·platforms
 162 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
165 [[packages]] 
166 name·=·"aide" 
167 version·=·"*"163 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide"
  
 164 else
 165 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 166 fi
168 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*167 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
169 Run·the·following·command·to·generate·a·new·database:168 Run·the·following·command·to·generate·a·new·database:
170 $·sudo·aideinit169 $·sudo·aideinit
171 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the170 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the
172 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these171 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
173 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their172 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
174 integrity.·The·newly-generated·database·can·be·installed·as·follows:173 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 192, 40 lines modifiedOffset 192, 14 lines modified
192 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3192 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
193 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)193 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
194 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3194 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
195 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5195 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
196 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199196 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
197 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79197 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
198 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2198 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
200 #·Remediation·is·applicable·only·in·certain·platforms 
201 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
202 DEBIAN_FRONTEND=noninteractive·apt-get·install·-y·"aide" 
  
203 AIDE_CONFIG=/etc/aide/aide.conf 
204 DEFAULT_DB_PATH=/var/lib/aide/aide.db 
  
205 #·Fix·db·path·in·the·config·file,·if·necessary 
206 if·!·grep·-q·'^database=file:'·${AIDE_CONFIG};·then 
207 ····#·replace_or_append·gets·confused·by·'database=file'·as·a·key,·so·should·not·be·used. 
208 ····#replace_or_append·"${AIDE_CONFIG}"·'^database=file'·"${DEFAULT_DB_PATH}"·'@CCENUM@'·'%s:%s' 
209 ····echo·"database=file:${DEFAULT_DB_PATH}"·>>·${AIDE_CONFIG} 
210 fi 
  
211 #·Fix·db·out·path·in·the·config·file,·if·necessary 
212 if·!·grep·-q·'^database_out=file:'·${AIDE_CONFIG};·then 
213 ····echo·"database_out=file:${DEFAULT_DB_PATH}.new"·>>·${AIDE_CONFIG} 
214 fi 
  
215 /usr/sbin/aideinit·-y·-f 
  
216 else 
217 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
218 fi 
219 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
220 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
221 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
222 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
223 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
224 -·name:·Build·and·Test·AIDE·Database·-·Ensure·AIDE·Is·Installed204 -·name:·Build·and·Test·AIDE·Database·-·Ensure·AIDE·Is·Installed
225 ··ansible.builtin.apt:205 ··ansible.builtin.apt:
Offset 380, 14 lines modifiedOffset 354, 40 lines modified
380 ··-·PCI-DSSv4-11.5.2354 ··-·PCI-DSSv4-11.5.2
381 ··-·aide_build_database355 ··-·aide_build_database
382 ··-·low_complexity356 ··-·low_complexity
383 ··-·low_disruption357 ··-·low_disruption
384 ··-·medium_severity358 ··-·medium_severity
385 ··-·no_reboot_needed359 ··-·no_reboot_needed
386 ··-·restrict_strategy360 ··-·restrict_strategy
 361 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 362 #·Remediation·is·applicable·only·in·certain·platforms
Max diff block lines reached; 869776/876457 bytes (99.24%) of diff not shown.
1.39 MB
./usr/share/doc/ssg-debian/ssg-debian12-guide-anssi_bp28_minimal.html
    
Offset 14302, 16 lines modifiedOffset 14302, 16 lines modified
00037dd0:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>00037dd0:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>
00037de0:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi00037de0:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi
00037df0:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.00037df0:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.
00037e00:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><00037e00:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><
00037e10:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d00037e10:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d
00037e20:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··00037e20:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··
00037e30:·2020·2020·2020·2020·2020·2020·2020·2020··················00037e30:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037e40:·2020·2861·7320·6f66·2032·3032·362d·3031····(as·of·2026-0100037e40:·2020·2861·7320·6f66·2032·3032·342d·3132····(as·of·2024-12
00037e50:·2d30·3829·0a20·2020·2020·2020·2020·2020··-08).···········00037e50:·2d30·3729·0a20·2020·2020·2020·2020·2020··-07).···········
00037e60:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><00037e60:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><
00037e70:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o00037e70:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o
00037e80:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><00037e80:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><
00037e90:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="00037e90:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="
00037ea0:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr00037ea0:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr
00037eb0:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr00037eb0:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr
00037ec0:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst00037ec0:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst
Offset 15543, 412 lines modifiedOffset 15543, 412 lines modified
0003cb60:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003cb60:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003cb70:·6d34·3631·3922·2074·6162·696e·6465·783d··m4619"·tabindex=0003cb70:·6d34·3631·3922·2074·6162·696e·6465·783d··m4619"·tabindex=
0003cb80:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003cb80:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003cb90:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003cb90:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003cba0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003cba0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003cbb0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003cbb0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
Diff chunk too large, falling back to line-by-line diff (398 lines added, 398 lines removed)
0003cbc0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003cbc0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003cbd0:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s0003cbd0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible
0003cbe0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br0003cbe0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003cbf0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003cbf0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003cc00:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003cc00:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003cc10:·6170·7365·2220·6964·3d22·6964·6d34·3631··apse"·id="idm4610003cc10:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003cc20:·3922·3e3c·7072·653e·3c63·6f64·653e·2320··9"><pre><code>#·0003cc20:·3436·3139·223e·3c74·6162·6c65·2063·6c61··4619"><table·cla
0003cc30:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a0003cc30:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003cc40:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i0003cc40:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003cc50:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo0003cc50:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003cc60:·726d·730a·6966·2064·706b·672d·7175·6572··rms.if·dpkg-quer0003cc60:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003cc70:·7920·2d2d·7368·6f77·202d·2d73·686f·7766··y·--show·--showf0003cc70:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003cc80:·6f72·6d61·743d·2724·7b64·623a·5374·6174··ormat='${db:Stat0003cc80:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003cc90:·7573·2d53·7461·7475·737d·5c6e·2720·276c··us-Status}\n'·'l0003cc90:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003cca0:·6962·7061·6d2d·7275·6e74·696d·6527·2032··ibpam-runtime'·20003cca0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6d·6564··ion:</th><td>med
0003ccb0:·2667·743b·2f64·6576·2f6e·756c·6c20·7c20··&gt;/dev/null·|·0003ccb0:·6975·6d3c·2f74·643e·3c2f·7472·3e3c·7472··ium</td></tr><tr
0003ccc0:·6772·6570·202d·7120·696e·7374·616c·6c65··grep·-q·installe0003ccc0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
0003ccd0:·643b·2074·6865·6e0a·0a76·6172·5f70·6173··d;·then..var_pas0003ccd0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
0003cce0:·7377·6f72·645f·7061·6d5f·756e·6978·5f72··sword_pam_unix_r0003cce0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
0003ccf0:·656d·656d·6265·723d·273c·6162·6272·2074··emember='<abbr·t0003ccf0:·7465·6779·3a3c·2f74·683e·3c74·643e·636f··tegy:</th><td>co
0003cd00:·6974·6c65·3d22·6672·6f6d·2050·726f·6669··itle="from·Profi0003cd00:·6e66·6967·7572·653c·2f74·643e·3c2f·7472··nfigure</td></tr
0003cd10:·6c65·2f72·6566·696e·652d·7661·6c75·653a··le/refine-value:0003cd10:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
0003cd20:·2078·6363·6466·5f6f·7267·2e73·7367·7072···xccdf_org.ssgpr0003cd20:·6f64·653e·2d20·6e61·6d65·3a20·4761·7468··ode>-·name:·Gath
0003cd30:·6f6a·6563·742e·636f·6e74·656e·745f·7661··oject.content_va0003cd30:·6572·2074·6865·2070·6163·6b61·6765·2066··er·the·package·f
0003cd40:·6c75·655f·7661·725f·7061·7373·776f·7264··lue_var_password0003cd40:·6163·7473·0a20·2070·6163·6b61·6765·5f66··acts.··package_f
0003cd50:·5f70·616d·5f75·6e69·785f·7265·6d65·6d62··_pam_unix_rememb0003cd50:·6163·7473·3a0a·2020·2020·6d61·6e61·6765··acts:.····manage
0003cd60:·6572·223e·323c·2f61·6262·723e·270a·0a0a··er">2</abbr>'...0003cd60:·723a·2061·7574·6f0a·2020·7461·6773·3a0a··r:·auto.··tags:.
0003cd70:·0a0a·0a0a·6966·205b·202d·6520·222f·6574··....if·[·-e·"/et0003cd70:·2020·2d20·434a·4953·2d35·2e36·2e32·2e31····-·CJIS-5.6.2.1
0003cd80:·632f·7061·6d2e·642f·636f·6d6d·6f6e·2d70··c/pam.d/common-p0003cd80:·2e31·0a20·202d·204e·4953·542d·3830·302d··.1.··-·NIST-800-
0003cd90:·6173·7377·6f72·6422·205d·203b·2074·6865··assword"·]·;·the0003cd90:·3137·312d·332e·352e·380a·2020·2d20·4e49··171-3.5.8.··-·NI
0003cda0:·6e0a·2020·2020·7661·6c75·6552·6567·6578··n.····valueRegex0003cda0:·5354·2d38·3030·2d35·332d·4941·2d35·2831··ST-800-53-IA-5(1
0003cdb0:·3d22·2476·6172·5f70·6173·7377·6f72·645f··="$var_password_0003cdb0:·2928·6529·0a20·202d·204e·4953·542d·3830··)(e).··-·NIST-80
0003cdc0:·7061·6d5f·756e·6978·5f72·656d·656d·6265··pam_unix_remembe0003cdc0:·302d·3533·2d49·412d·3528·6629·0a20·202d··0-53-IA-5(f).··-
0003cdd0:·7222·2064·6566·6175·6c74·5661·6c75·653d··r"·defaultValue=0003cdd0:·2050·4349·2d44·5353·2d52·6571·2d38·2e32···PCI-DSS-Req-8.2
0003cde0:·2224·7661·725f·7061·7373·776f·7264·5f70··"$var_password_p0003cde0:·2e35·0a20·202d·2050·4349·2d44·5353·7634··.5.··-·PCI-DSSv4
0003cdf0:·616d·5f75·6e69·785f·7265·6d65·6d62·6572··am_unix_remember0003cdf0:·2d38·2e33·2e37·0a20·202d·2061·6363·6f75··-8.3.7.··-·accou
0003ce00:·220a·2020·2020·2320·6e6f·6e2d·656d·7074··".····#·non-empt0003ce00:·6e74·735f·7061·7373·776f·7264·5f70·616d··nts_password_pam
0003ce10:·7920·7661·6c75·6573·206e·6565·6420·746f··y·values·need·to0003ce10:·5f75·6e69·785f·7265·6d65·6d62·6572·0a20··_unix_remember.·
0003ce20:·2062·6520·7072·6563·6564·6564·2062·7920···be·preceded·by·0003ce20:·202d·2063·6f6e·6669·6775·7265·5f73·7472···-·configure_str
0003ce30:·616e·2065·7175·616c·7320·7369·676e·0a20··an·equals·sign.·0003ce30:·6174·6567·790a·2020·2d20·6c6f·775f·636f··ategy.··-·low_co
0003ce40:·2020·205b·202d·6e20·2224·7b76·616c·7565·····[·-n·"${value0003ce40:·6d70·6c65·7869·7479·0a20·202d·206d·6564··mplexity.··-·med
0003ce50:·5265·6765·787d·2220·5d20·2661·6d70·3b26··Regex}"·]·&amp;&0003ce50:·6975·6d5f·6469·7372·7570·7469·6f6e·0a20··ium_disruption.·
0003ce60:·616d·703b·2076·616c·7565·5265·6765·783d··amp;·valueRegex=0003ce60:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi
0003ce70:·223d·247b·7661·6c75·6552·6567·6578·7d22··"=${valueRegex}"0003ce70:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot
0003ce80:·0a20·2020·2023·2061·6464·2061·6e20·6571··.····#·add·an·eq0003ce80:·5f6e·6565·6465·640a·2d20·6e61·6d65·3a20··_needed.-·name:·
0003ce90:·7561·6c73·2073·6967·6e20·746f·206e·6f6e··uals·sign·to·non0003ce90:·5843·4344·4620·5661·6c75·6520·7661·725f··XCCDF·Value·var_
0003cea0:·2d65·6d70·7479·2076·616c·7565·730a·2020··-empty·values.··0003cea0:·7061·7373·776f·7264·5f70·616d·5f75·6e69··password_pam_uni
0003ceb0:·2020·5b20·2d6e·2022·247b·6465·6661·756c····[·-n·"${defaul0003ceb0:·785f·7265·6d65·6d62·6572·2023·2070·726f··x_remember·#·pro
0003cec0:·7456·616c·7565·7d22·205d·2026·616d·703b··tValue}"·]·&amp;0003cec0:·6d6f·7465·2074·6f20·7661·7269·6162·6c65··mote·to·variable
0003ced0:·2661·6d70·3b20·6465·6661·756c·7456·616c··&amp;·defaultVal0003ced0:·0a20·2073·6574·5f66·6163·743a·0a20·2020··.··set_fact:.···
0003cee0:·7565·3d22·3d24·7b64·6566·6175·6c74·5661··ue="=${defaultVa0003cee0:·2076·6172·5f70·6173·7377·6f72·645f·7061···var_password_pa
0003cef0:·6c75·657d·220a·0a20·2020·2023·2066·6978··lue}"..····#·fix0003cef0:·6d5f·756e·6978·5f72·656d·656d·6265·723a··m_unix_remember:
0003cf00:·2027·7479·7065·2720·6966·2069·7427·7320···'type'·if·it's·0003cf00:·2021·2173·7472·203c·6162·6272·2074·6974···!!str·<abbr·tit
0003cf10:·7772·6f6e·670a·2020·2020·6966·2067·7265··wrong.····if·gre0003cf10:·6c65·3d22·6672·6f6d·2050·726f·6669·6c65··le="from·Profile
0003cf20:·7020·2d71·202d·5020·225e·5c5c·732a·283f··p·-q·-P·"^\\s*(?0003cf20:·2f72·6566·696e·652d·7661·6c75·653a·2078··/refine-value:·x
0003cf30:·2227·2127·2270·6173·7377·6f72·645c·5c73··"'!'"password\\s0003cf30:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj
0003cf40:·295b·5b3a·616c·6e75·6d3a·5d5d·2b5c·5c73··)[[:alnum:]]+\\s0003cf40:·6563·742e·636f·6e74·656e·745f·7661·6c75··ect.content_valu
0003cf50:·2b5b·5b3a·616c·6e75·6d3a·5d5d·2b5c·5c73··+[[:alnum:]]+\\s0003cf50:·655f·7661·725f·7061·7373·776f·7264·5f70··e_var_password_p
0003cf60:·2b70·616d·5f75·6e69·782e·736f·2220·266c··+pam_unix.so"·&l0003cf60:·616d·5f75·6e69·785f·7265·6d65·6d62·6572··am_unix_remember
0003cf70:·743b·2022·2f65·7463·2f70·616d·2e64·2f63··t;·"/etc/pam.d/c0003cf70:·223e·323c·2f61·6262·723e·0a20·2074·6167··">2</abbr>.··tag
0003cf80:·6f6d·6d6f·6e2d·7061·7373·776f·7264·2220··ommon-password"·0003cf80:·733a·0a20·2020·202d·2061·6c77·6179·730a··s:.····-·always.
0003cf90:·3b20·7468·656e·0a20·2020·2020·2020·2073··;·then.········s0003cf90:·0a2d·206e·616d·653a·204c·696d·6974·2050··.-·name:·Limit·P
0003cfa0:·6564·202d·2d66·6f6c·6c6f·772d·7379·6d6c··ed·--follow-syml0003cfa0:·6173·7377·6f72·6420·5265·7573·6520·2d20··assword·Reuse·-·
0003cfb0:·696e·6b73·202d·6920·2d45·202d·6520·2273··inks·-i·-E·-e·"s0003cfb0:·4368·6563·6b20·6966·2074·6865·2072·6571··Check·if·the·req
0003cfc0:·2f5e·285c·5c73·2a29·5b5b·3a61·6c6e·756d··/^(\\s*)[[:alnum0003cfc0:·7569·7265·6420·5041·4d20·6d6f·6475·6c65··uired·PAM·module
0003cfd0:·3a5d·5d2b·285c·5c73·2b5b·5b3a·616c·6e75··:]]+(\\s+[[:alnu0003cfd0:·206f·7074·696f·6e20·6973·2070·7265·7365···option·is·prese
0003cfe0:·6d3a·5d5d·2b5c·5c73·2b70·616d·5f75·6e69··m:]]+\\s+pam_uni0003cfe0:·6e74·0a20·2020·2069·6e20·2f65·7463·2f70··nt.····in·/etc/p
0003cff0:·782e·736f·292f·5c5c·3170·6173·7377·6f72··x.so)/\\1passwor0003cff0:·616d·2e64·2f63·6f6d·6d6f·6e2d·7061·7373··am.d/common-pass
0003d000:·645c·5c32·2f22·2022·2f65·7463·2f70·616d··d\\2/"·"/etc/pam0003d000:·776f·7264·0a20·2061·6e73·6962·6c65·2e62··word.··ansible.b
0003d010:·2e64·2f63·6f6d·6d6f·6e2d·7061·7373·776f··.d/common-passwo0003d010:·7569·6c74·696e·2e6c·696e·6569·6e66·696c··uiltin.lineinfil
0003d020:·7264·220a·2020·2020·6669·0a0a·2020·2020··rd".····fi..····0003d020:·653a·0a20·2020·2070·6174·683a·202f·6574··e:.····path:·/et
0003d030:·2320·6669·7820·2763·6f6e·7472·6f6c·2720··#·fix·'control'·0003d030:·632f·7061·6d2e·642f·636f·6d6d·6f6e·2d70··c/pam.d/common-p
0003d040:·6966·2069·7427·7320·7772·6f6e·670a·2020··if·it's·wrong.··0003d040:·6173·7377·6f72·640a·2020·2020·7265·6765··assword.····rege
0003d050:·2020·6966·2067·7265·7020·2d71·202d·5020····if·grep·-q·-P·0003d050:·7870·3a20·5e5c·732a·7061·7373·776f·7264··xp:·^\s*password
0003d060:·225e·5c5c·732a·7061·7373·776f·7264·5c5c··"^\\s*password\\0003d060:·5c73·2b5c·5b73·7563·6365·7373·3d5b·412d··\s+\[success=[A-
0003d070:·732b·283f·2227·2127·225c·5b73·7563·6365··s+(?"'!'"\[succe0003d070:·5a61·2d7a·302d·395d·2e2a·5c5d·5c73·2b70··Za-z0-9].*\]\s+p
0003d080:·7373·3d5b·5b3a·616c·6e75·6d3a·5d5d·2e2a··ss=[[:alnum:]].*0003d080:·616d·5f75·6e69·782e·736f·5c73·2a2e·2a5c··am_unix.so\s*.*\
0003d090:·5c5d·295b·5b3a·616c·6e75·6d3a·5d5d·2b5c··\])[[:alnum:]]+\0003d090:·7372·656d·656d·6265·725c·620a·2020·2020··sremember\b.····
0003d0a0:·5c73·2b70·616d·5f75·6e69·782e·736f·2220··\s+pam_unix.so"·0003d0a0:·7374·6174·653a·2061·6273·656e·740a·2020··state:·absent.··
0003d0b0:·266c·743b·2022·2f65·7463·2f70·616d·2e64··&lt;·"/etc/pam.d0003d0b0:·6368·6563·6b5f·6d6f·6465·3a20·7472·7565··check_mode:·true
0003d0c0:·2f63·6f6d·6d6f·6e2d·7061·7373·776f·7264··/common-password0003d0c0:·0a20·2063·6861·6e67·6564·5f77·6865·6e3a··.··changed_when:
0003d0d0:·2220·3b20·7468·656e·0a20·2020·2020·2020··"·;·then.·······0003d0d0:·2066·616c·7365·0a20·2072·6567·6973·7465···false.··registe
0003d0e0:·2073·6564·202d·2d66·6f6c·6c6f·772d·7379···sed·--follow-sy0003d0e0:·723a·2072·6573·756c·745f·7061·6d5f·6d6f··r:·result_pam_mo
0003d0f0:·6d6c·696e·6b73·202d·6920·2d45·202d·6520··mlinks·-i·-E·-e·0003d0f0:·6475·6c65·5f72·656d·656d·6265·725f·6f70··dule_remember_op
0003d100:·2273·2f5e·285c·5c73·2a70·6173·7377·6f72··"s/^(\\s*passwor0003d100:·7469·6f6e·5f70·7265·7365·6e74·0a20·2077··tion_present.··w
0003d110:·645c·5c73·2b29·5b5b·3a61·6c6e·756d·3a5d··d\\s+)[[:alnum:]0003d110:·6865·6e3a·2027·226c·6962·7061·6d2d·7275··hen:·'"libpam-ru
0003d120:·5d2b·285c·5c73·2b70·616d·5f75·6e69·782e··]+(\\s+pam_unix.0003d120:·6e74·696d·6522·2069·6e20·616e·7369·626c··ntime"·in·ansibl
0003d130:·736f·292f·5c5c·315c·5b73·7563·6365·7373··so)/\\1\[success0003d130:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages
0003d140:·3d5b·5b3a·616c·6e75·6d3a·5d5d·2e2a·5c5d··=[[:alnum:]].*\]0003d140:·270a·2020·7461·6773·3a0a·2020·2d20·434a··'.··tags:.··-·CJ
0003d150:·5c5c·322f·2220·222f·6574·632f·7061·6d2e··\\2/"·"/etc/pam.0003d150:·4953·2d35·2e36·2e32·2e31·2e31·0a20·202d··IS-5.6.2.1.1.··-
0003d160:·642f·636f·6d6d·6f6e·2d70·6173·7377·6f72··d/common-passwor0003d160:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.
0003d170:·6422·0a20·2020·2066·690a·0a20·2020·2023··d".····fi..····#0003d170:·352e·380a·2020·2d20·4e49·5354·2d38·3030··5.8.··-·NIST-800
0003d180:·2066·6978·2074·6865·2076·616c·7565·2066···fix·the·value·f0003d180:·2d35·332d·4941·2d35·2831·2928·6529·0a20··-53-IA-5(1)(e).·
0003d190:·6f72·2027·6f70·7469·6f6e·2720·6966·206f··or·'option'·if·o0003d190:·202d·204e·4953·542d·3830·302d·3533·2d49···-·NIST-800-53-I
0003d1a0:·6e65·2065·7869·7374·7320·6275·7420·646f··ne·exists·but·do0003d1a0:·412d·3528·6629·0a20·202d·2050·4349·2d44··A-5(f).··-·PCI-D
0003d1b0:·6573·206e·6f74·206d·6174·6368·2027·7661··es·not·match·'va0003d1b0:·5353·2d52·6571·2d38·2e32·2e35·0a20·202d··SS-Req-8.2.5.··-
0003d1c0:·6c75·6552·6567·6578·270a·2020·2020·6966··lueRegex'.····if0003d1c0:·2050·4349·2d44·5353·7634·2d38·2e33·2e37···PCI-DSSv4-8.3.7
0003d1d0:·2067·7265·7020·2d71·202d·5020·225e·5c5c···grep·-q·-P·"^\\0003d1d0:·0a20·202d·2061·6363·6f75·6e74·735f·7061··.··-·accounts_pa
0003d1e0:·732a·7061·7373·776f·7264·5c5c·732b·5c5b··s*password\\s+\[0003d1e0:·7373·776f·7264·5f70·616d·5f75·6e69·785f··ssword_pam_unix_
0003d1f0:·7375·6363·6573·733d·5b5b·3a61·6c6e·756d··success=[[:alnum0003d1f0:·7265·6d65·6d62·6572·0a20·202d·2063·6f6e··remember.··-·con
0003d200:·3a5d·5d2e·2a5c·5d5c·5c73·2b70·616d·5f75··:]].*\]\\s+pam_u0003d200:·6669·6775·7265·5f73·7472·6174·6567·790a··figure_strategy.
0003d210:·6e69·782e·736f·285c·5c73·2e2b·293f·5c5c··nix.so(\\s.+)?\\0003d210:·2020·2d20·6c6f·775f·636f·6d70·6c65·7869····-·low_complexi
0003d220:·732b·7265·6d65·6d62·6572·283f·2227·2127··s+remember(?"'!'0003d220:·7479·0a20·202d·206d·6564·6975·6d5f·6469··ty.··-·medium_di
Max diff block lines reached; 1291386/1348158 bytes (95.79%) of diff not shown.
110 KB
html2text {}
    
Offset 43, 15 lines modifiedOffset 43, 15 lines modified
43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(minimal)44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(minimal)
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_minimal45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_minimal
46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
47 ····*·cpe:/o:debian:debian_linux:1247 ····*·cpe:/o:debian:debian_linux:12
48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
49 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8449 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
55 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s55 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
56 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s56 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
57 ·········1.·_\x8D_\x8H_\x8C_\x8P57 ·········1.·_\x8D_\x8H_\x8C_\x8P
Offset 177, 76 lines modifiedOffset 177, 14 lines modified
177 ···························A.9.3.1,·A.9.4.2,·A.9.4.3177 ···························A.9.3.1,·A.9.4.2,·A.9.4.3
178 ············_\x8n_\x8i_\x8s_\x8t···········IA-5(f),·IA-5(1)(e)178 ············_\x8n_\x8i_\x8s_\x8t···········IA-5(f),·IA-5(1)(e)
179 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-6,·PR.AC-7179 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-6,·PR.AC-7
180 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-8.2.5180 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-8.2.5
181 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000077-GPOS-00045181 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000077-GPOS-00045
182 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R31182 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R31
183 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········8.3.7183 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········8.3.7
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
185 #·Remediation·is·applicable·only·in·certain·platforms 
186 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·| 
187 grep·-q·installed;·then 
  
188 var_password_pam_unix_remember='2' 
  
  
  
  
  
  
189 if·[·-e·"/etc/pam.d/common-password"·]·;·then 
190 ····valueRegex="$var_password_pam_unix_remember" 
191 defaultValue="$var_password_pam_unix_remember" 
192 ····#·non-empty·values·need·to·be·preceded·by·an·equals·sign 
193 ····[·-n·"${valueRegex}"·]·&&·valueRegex="=${valueRegex}" 
194 ····#·add·an·equals·sign·to·non-empty·values 
195 ····[·-n·"${defaultValue}"·]·&&·defaultValue="=${defaultValue}" 
  
196 ····#·fix·'type'·if·it's·wrong 
197 ····if·grep·-q·-P·"^\\s*(?"'!'"password\\s)[[:alnum:]]+\\s+[[:alnum:]]+\\s+pam_unix.so"·<·"/ 
198 etc/pam.d/common-password"·;·then 
199 ········sed·--follow-symlinks·-i·-E·-e·"s/^(\\s*)[[:alnum:]]+(\\s+[[:alnum: 
200 ]]+\\s+pam_unix.so)/\\1password\\2/"·"/etc/pam.d/common-password" 
201 ····fi 
  
202 ····#·fix·'control'·if·it's·wrong 
203 ····if·grep·-q·-P·"^\\s*password\\s+(?"'!'"\[success=[[:alnum:]].*\])[[:alnum: 
204 ]]+\\s+pam_unix.so"·<·"/etc/pam.d/common-password"·;·then 
205 ········sed·--follow-symlinks·-i·-E·-e·"s/^(\\s*password\\s+)[[:alnum:]]+(\\s+pam_unix.so)/ 
206 \\1\[success=[[:alnum:]].*\]\\2/"·"/etc/pam.d/common-password" 
207 ····fi 
  
208 ····#·fix·the·value·for·'option'·if·one·exists·but·does·not·match·'valueRegex' 
209 ····if·grep·-q·-P·"^\\s*password\\s+\[success=[[:alnum:]].*\]\\s+pam_unix.so 
210 (\\s.+)?\\s+remember(?"'!'"${valueRegex}(\\s|\$))"·<·"/etc/pam.d/common-password"·;·then 
211 ········sed·--follow-symlinks·-i·-E·-e·"s/^(\\s*password\\s+\[success=[[:alnum: 
212 ]].*\]\\s+pam_unix.so(\\s.+)?\\s)remember=[^[:space:]]*/\\1remember${defaultValue}/"·"/etc/ 
213 pam.d/common-password" 
  
214 ····#·add·'option=default'·if·option·is·not·set 
215 ····elif·grep·-q·-E·"^\\s*password\\s+\[success=[[:alnum:]].*\]\\s+pam_unix.so"·<·"/etc/ 
216 pam.d/common-password"·&& 
217 ············grep····-E·"^\\s*password\\s+\[success=[[:alnum:]].*\]\\s+pam_unix.so"·<·"/etc/ 
218 pam.d/common-password"·|·grep·-q·-E·-v·"\\sremember(=|\\s|\$)"·;·then 
  
219 ········sed·--follow-symlinks·-i·-E·-e·"s/^(\\s*password\\s+\[success=[[:alnum: 
220 ]].*\]\\s+pam_unix.so[^\\n]*)/\\1·remember${defaultValue}/"·"/etc/pam.d/common-password" 
221 ····#·add·a·new·entry·if·none·exists 
222 ····elif·!·grep·-q·-P·"^\\s*password\\s+\[success=[[:alnum:]].*\]\\s+pam_unix.so 
223 (\\s.+)?\\s+remember${valueRegex}(\\s|\$)"·<·"/etc/pam.d/common-password"·;·then 
224 ········echo·"password·\[success=[[:alnum:]].*\]·pam_unix.so·remember${defaultValue}"·>>·"/ 
225 etc/pam.d/common-password" 
226 ····fi 
227 else 
228 ····echo·"/etc/pam.d/common-password·doesn't·exist"·>&2 
229 fi 
  
230 else 
231 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
232 fi 
233 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
234 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
235 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
236 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
237 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
238 -·name:·Gather·the·package·facts189 -·name:·Gather·the·package·facts
239 ··package_facts:190 ··package_facts:
Offset 341, 14 lines modifiedOffset 279, 76 lines modified
341 ··-·PCI-DSSv4-8.3.7279 ··-·PCI-DSSv4-8.3.7
342 ··-·accounts_password_pam_unix_remember280 ··-·accounts_password_pam_unix_remember
343 ··-·configure_strategy281 ··-·configure_strategy
344 ··-·low_complexity282 ··-·low_complexity
345 ··-·medium_disruption283 ··-·medium_disruption
346 ··-·medium_severity284 ··-·medium_severity
347 ··-·no_reboot_needed285 ··-·no_reboot_needed
 286 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 287 #·Remediation·is·applicable·only·in·certain·platforms
 288 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|
 289 grep·-q·installed;·then
  
 290 var_password_pam_unix_remember='2'
  
  
  
  
  
  
 291 if·[·-e·"/etc/pam.d/common-password"·]·;·then
 292 ····valueRegex="$var_password_pam_unix_remember"
 293 defaultValue="$var_password_pam_unix_remember"
 294 ····#·non-empty·values·need·to·be·preceded·by·an·equals·sign
 295 ····[·-n·"${valueRegex}"·]·&&·valueRegex="=${valueRegex}"
 296 ····#·add·an·equals·sign·to·non-empty·values
 297 ····[·-n·"${defaultValue}"·]·&&·defaultValue="=${defaultValue}"
  
 298 ····#·fix·'type'·if·it's·wrong
 299 ····if·grep·-q·-P·"^\\s*(?"'!'"password\\s)[[:alnum:]]+\\s+[[:alnum:]]+\\s+pam_unix.so"·<·"/
 300 etc/pam.d/common-password"·;·then
 301 ········sed·--follow-symlinks·-i·-E·-e·"s/^(\\s*)[[:alnum:]]+(\\s+[[:alnum:
 302 ]]+\\s+pam_unix.so)/\\1password\\2/"·"/etc/pam.d/common-password"
 303 ····fi
  
Max diff block lines reached; 105210/112874 bytes (93.21%) of diff not shown.
1.02 MB
./usr/share/doc/ssg-debian/ssg-debian12-guide-anssi_np_nt28_average.html
    
Offset 14284, 15 lines modifiedOffset 14284, 15 lines modified
00037cb0:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00037cb0:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00037cc0:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00037cc0:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00037cd0:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</00037cd0:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
00037ce0:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00037ce0:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
00037cf0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft00037cf0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
00037d00:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······00037d00:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
00037d10:·2020·2020·2020·2020·2020·2020·2020·2861················(a00037d10:·2020·2020·2020·2020·2020·2020·2020·2861················(a
00037d20:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)00037d20:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
00037d30:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037d30:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037d40:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div00037d40:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
00037d50:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co00037d50:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
00037d60:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><00037d60:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
00037d70:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc00037d70:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
00037d80:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec00037d80:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00037d90:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00037d90:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 16001, 146 lines modifiedOffset 16001, 146 lines modified
0003e800:·6172·6765·743d·2223·6964·6d34·3033·3422··arget="#idm4034"0003e800:·6172·6765·743d·2223·6964·6d34·3033·3422··arget="#idm4034"
0003e810:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003e810:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003e820:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003e820:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003e830:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003e830:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003e840:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003e840:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003e850:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003e850:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003e860:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003e860:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003e870:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script· 
0003e880:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003e890:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003e8a0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003e8b0:·6964·3d22·6964·6d34·3033·3422·3e3c·7461··id="idm4034"><ta 
0003e8c0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003e8d0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003e8e0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003e8f0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003e900:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003e910:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003e920:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003e930:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003e940:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003e950:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003e960:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003e970:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003e980:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003e990:·643e·7265·7374·7269·6374·3c2f·7464·3e3c··d>restrict</td>< 
0003e9a0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003e9b0:·3e3c·636f·6465·3e0a·666f·7220·6620·696e··><code>.for·f·in 
0003e9c0:·202f·6574·632f·7375·646f·6572·7320·2f65···/etc/sudoers·/e 
0003e9d0:·7463·2f73·7564·6f65·7273·2e64·2f2a·203b··tc/sudoers.d/*·; 
0003e9e0:·2064·6f0a·2020·6966·205b·2021·202d·6520···do.··if·[·!·-e· 
0003e9f0:·2224·6622·205d·203b·2074·6865·6e0a·2020··"$f"·]·;·then.·· 
0003ea00:·2020·636f·6e74·696e·7565·0a20·2066·690a····continue.··fi. 
0003ea10:·2020·6d61·7463·6869·6e67·5f6c·6973·743d····matching_list= 
0003ea20:·2428·6772·6570·202d·5020·275e·283f·2123··$(grep·-P·'^(?!# 
0003ea30:·292e·2a5b·5c73·5d2b·5c21·6175·7468·656e··).*[\s]+\!authen 
0003ea40:·7469·6361·7465·2e2a·2427·2024·6620·7c20··ticate.*$'·$f·|· 
0003ea50:·756e·6971·2029·0a20·2069·6620·2120·7465··uniq·).··if·!·te 
0003ea60:·7374·202d·7a20·2224·6d61·7463·6869·6e67··st·-z·"$matching 
0003ea70:·5f6c·6973·7422·3b20·7468·656e·0a20·2020··_list";·then.··· 
0003ea80:·2077·6869·6c65·2049·4653·3d20·7265·6164···while·IFS=·read 
0003ea90:·202d·7220·656e·7472·793b·2064·6f0a·2020···-r·entry;·do.·· 
0003eaa0:·2020·2020·2320·636f·6d6d·656e·7420·6f75······#·comment·ou 
0003eab0:·7420·2221·6175·7468·656e·7469·6361·7465··t·"!authenticate 
0003eac0:·2220·6d61·7463·6865·7320·746f·2070·7265··"·matches·to·pre 
0003ead0:·7365·7276·6520·7573·6572·2064·6174·610a··serve·user·data. 
0003eae0:·2020·2020·2020·7365·6420·2d69·2022·732f········sed·-i·"s/ 
0003eaf0:·5e24·7b65·6e74·7279·7d24·2f23·2026·616d··^${entry}$/#·&am 
0003eb00:·703b·2f67·2220·2466·0a20·2020·2064·6f6e··p;/g"·$f.····don 
0003eb10:·6520·266c·743b·266c·743b·266c·743b·2022··e·&lt;&lt;&lt;·" 
0003eb20:·246d·6174·6368·696e·675f·6c69·7374·220a··$matching_list". 
0003eb30:·0a20·2020·202f·7573·722f·7362·696e·2f76··.····/usr/sbin/v 
0003eb40:·6973·7564·6f20·2d63·6620·2466·2026·616d··isudo·-cf·$f·&am 
0003eb50:·703b·2667·743b·202f·6465·762f·6e75·6c6c··p;&gt;·/dev/null 
0003eb60:·207c·7c20·6563·686f·2022·4661·696c·2074···||·echo·"Fail·t 
0003eb70:·6f20·7661·6c69·6461·7465·2024·6620·7769··o·validate·$f·wi 
0003eb80:·7468·2076·6973·7564·6f22·0a20·2066·690a··th·visudo".··fi. 
0003eb90:·646f·6e65·0a3c·2f63·6f64·653e·3c2f·7072··done.</code></pr 
0003eba0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003ebb0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003ebc0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003ebd0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003ebe0:·6172·6765·743d·2223·6964·6d34·3033·3522··arget="#idm4035" 
0003ebf0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003ec00:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003ec10:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003ec20:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003ec30:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003ec40:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003ec50:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp0003e870:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp
0003ec60:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0003e880:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
0003ec70:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003e890:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0003ec80:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003e8a0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0003ec90:·6522·2069·643d·2269·646d·3430·3335·223e··e"·id="idm4035">0003e8b0:·6522·2069·643d·2269·646d·3430·3334·223e··e"·id="idm4034">
0003eca0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003e8c0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
0003ecb0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003e8d0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
0003ecc0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003e8e0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
0003ecd0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003e8f0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
0003ece0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003e900:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003ecf0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003e910:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0003ed00:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003e920:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003ed10:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003e930:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
0003ed20:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003e940:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003ed30:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo0003e950:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
0003ed40:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals0003e960:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
0003ed50:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><0003e970:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
0003ed60:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th0003e980:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0003ed70:·3e3c·7464·3e72·6573·7472·6963·743c·2f74··><td>restrict</t0003e990:·3e3c·7464·3e72·6573·7472·6963·743c·2f74··><td>restrict</t
0003ed80:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003e9a0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0003ed90:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name0003e9b0:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name
0003eda0:·3a20·4669·6e64·202f·6574·632f·7375·646f··:·Find·/etc/sudo0003e9c0:·3a20·4669·6e64·202f·6574·632f·7375·646f··:·Find·/etc/sudo
0003edb0:·6572·732e·642f·2066·696c·6573·0a20·2061··ers.d/·files.··a0003e9d0:·6572·732e·642f·2066·696c·6573·0a20·2061··ers.d/·files.··a
0003edc0:·6e73·6962·6c65·2e62·7569·6c74·696e·2e66··nsible.builtin.f0003e9e0:·6e73·6962·6c65·2e62·7569·6c74·696e·2e66··nsible.builtin.f
0003edd0:·696e·643a·0a20·2020·2070·6174·6873·3a0a··ind:.····paths:.0003e9f0:·696e·643a·0a20·2020·2070·6174·6873·3a0a··ind:.····paths:.
0003ede0:·2020·2020·2d20·2f65·7463·2f73·7564·6f65······-·/etc/sudoe0003ea00:·2020·2020·2d20·2f65·7463·2f73·7564·6f65······-·/etc/sudoe
0003edf0:·7273·2e64·2f0a·2020·7265·6769·7374·6572··rs.d/.··register0003ea10:·7273·2e64·2f0a·2020·7265·6769·7374·6572··rs.d/.··register
0003ee00:·3a20·7375·646f·6572·730a·2020·7461·6773··:·sudoers.··tags0003ea20:·3a20·7375·646f·6572·730a·2020·7461·6773··:·sudoers.··tags
0003ee10:·3a0a·2020·2d20·4e49·5354·2d38·3030·2d35··:.··-·NIST-800-50003ea30:·3a0a·2020·2d20·4e49·5354·2d38·3030·2d35··:.··-·NIST-800-5
0003ee20:·332d·434d·2d36·2861·290a·2020·2d20·4e49··3-CM-6(a).··-·NI0003ea40:·332d·434d·2d36·2861·290a·2020·2d20·4e49··3-CM-6(a).··-·NI
0003ee30:·5354·2d38·3030·2d35·332d·4941·2d31·310a··ST-800-53-IA-11.0003ea50:·5354·2d38·3030·2d35·332d·4941·2d31·310a··ST-800-53-IA-11.
0003ee40:·2020·2d20·6c6f·775f·636f·6d70·6c65·7869····-·low_complexi0003ea60:·2020·2d20·6c6f·775f·636f·6d70·6c65·7869····-·low_complexi
0003ee50:·7479·0a20·202d·206c·6f77·5f64·6973·7275··ty.··-·low_disru0003ea70:·7479·0a20·202d·206c·6f77·5f64·6973·7275··ty.··-·low_disru
0003ee60:·7074·696f·6e0a·2020·2d20·6d65·6469·756d··ption.··-·medium0003ea80:·7074·696f·6e0a·2020·2d20·6d65·6469·756d··ption.··-·medium
0003ee70:·5f73·6576·6572·6974·790a·2020·2d20·6e6f··_severity.··-·no0003ea90:·5f73·6576·6572·6974·790a·2020·2d20·6e6f··_severity.··-·no
0003ee80:·5f72·6562·6f6f·745f·6e65·6564·6564·0a20··_reboot_needed.·0003eaa0:·5f72·6562·6f6f·745f·6e65·6564·6564·0a20··_reboot_needed.·
0003ee90:·202d·2072·6573·7472·6963·745f·7374·7261···-·restrict_stra0003eab0:·202d·2072·6573·7472·6963·745f·7374·7261···-·restrict_stra
0003eea0:·7465·6779·0a20·202d·2073·7564·6f5f·7265··tegy.··-·sudo_re0003eac0:·7465·6779·0a20·202d·2073·7564·6f5f·7265··tegy.··-·sudo_re
0003eeb0:·6d6f·7665·5f6e·6f5f·6175·7468·656e·7469··move_no_authenti0003ead0:·6d6f·7665·5f6e·6f5f·6175·7468·656e·7469··move_no_authenti
0003eec0:·6361·7465·0a0a·2d20·6e61·6d65·3a20·5265··cate..-·name:·Re0003eae0:·6361·7465·0a0a·2d20·6e61·6d65·3a20·5265··cate..-·name:·Re
0003eed0:·6d6f·7665·206c·696e·6573·2063·6f6e·7461··move·lines·conta0003eaf0:·6d6f·7665·206c·696e·6573·2063·6f6e·7461··move·lines·conta
0003eee0:·696e·696e·6720·2161·7574·6865·6e74·6963··ining·!authentic0003eb00:·696e·696e·6720·2161·7574·6865·6e74·6963··ining·!authentic
Max diff block lines reached; 934128/954054 bytes (97.91%) of diff not shown.
118 KB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Average·(Intermediate)·Level38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Average·(Intermediate)·Level
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_average39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_average
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:debian:debian_linux:1241 ····*·cpe:/o:debian:debian_linux:12
42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
43 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8443 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
48 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g48 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
49 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s49 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
50 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s50 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
51 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n51 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
Offset 227, 35 lines modifiedOffset 227, 14 lines modified
227 ···························1.7,·SR·1.8,·SR·1.9227 ···························1.7,·SR·1.8,·SR·1.9
228 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,228 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
229 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3229 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
230 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)230 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
231 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7231 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
232 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,232 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
233 ···························SRG-OS-000373-GPOS-00158233 ···························SRG-OS-000373-GPOS-00158
234 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
235 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
236 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
237 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
238 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
239 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
240 ··if·[·!·-e·"$f"·]·;·then 
241 ····continue 
242 ··fi 
243 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·) 
244 ··if·!·test·-z·"$matching_list";·then 
245 ····while·IFS=·read·-r·entry;·do 
246 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data 
247 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
248 ····done·<<<·"$matching_list" 
  
249 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
250 visudo" 
251 ··fi 
252 done 
253 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8234 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
254 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low235 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
255 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low236 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
256 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false237 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
257 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict238 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
258 -·name:·Find·/etc/sudoers.d/·files239 -·name:·Find·/etc/sudoers.d/·files
259 ··ansible.builtin.find:240 ··ansible.builtin.find:
Offset 286, 14 lines modifiedOffset 265, 35 lines modified
286 ··-·NIST-800-53-IA-11265 ··-·NIST-800-53-IA-11
287 ··-·low_complexity266 ··-·low_complexity
288 ··-·low_disruption267 ··-·low_disruption
289 ··-·medium_severity268 ··-·medium_severity
290 ··-·no_reboot_needed269 ··-·no_reboot_needed
291 ··-·restrict_strategy270 ··-·restrict_strategy
292 ··-·sudo_remove_no_authenticate271 ··-·sudo_remove_no_authenticate
 272 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 273 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 274 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 275 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 276 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 277 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do
 278 ··if·[·!·-e·"$f"·]·;·then
 279 ····continue
 280 ··fi
 281 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·)
 282 ··if·!·test·-z·"$matching_list";·then
 283 ····while·IFS=·read·-r·entry;·do
 284 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data
 285 ······sed·-i·"s/^${entry}$/#·&/g"·$f
 286 ····done·<<<·"$matching_list"
  
 287 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with
 288 visudo"
 289 ··fi
 290 done
293 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o291 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o
294 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*292 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
295 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using293 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using
296 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure294 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure
297 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any295 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any
298 sudo·configuration·snippets·in·/etc/sudoers.d/.296 sudo·configuration·snippets·in·/etc/sudoers.d/.
299 ············Without·re-authentication,·users·may·access·resources·or·perform297 ············Without·re-authentication,·users·may·access·resources·or·perform
Offset 314, 35 lines modifiedOffset 314, 14 lines modified
314 ···························1.7,·SR·1.8,·SR·1.9314 ···························1.7,·SR·1.8,·SR·1.9
315 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,315 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
316 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3316 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
317 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)317 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
318 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7318 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
319 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,319 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
320 ···························SRG-OS-000373-GPOS-00158320 ···························SRG-OS-000373-GPOS-00158
321 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
322 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
323 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
324 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
325 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
326 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
327 ··if·[·!·-e·"$f"·]·;·then 
328 ····continue 
329 ··fi 
330 ··matching_list=$(grep·-P·'^(?!#).*[\s]+NOPASSWD[\s]*\:.*$'·$f·|·uniq·) 
331 ··if·!·test·-z·"$matching_list";·then 
332 ····while·IFS=·read·-r·entry;·do 
333 ······#·comment·out·"NOPASSWD"·matches·to·preserve·user·data 
334 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
335 ····done·<<<·"$matching_list" 
  
336 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
337 visudo" 
338 ··fi 
339 done 
340 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8321 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
341 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low322 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
342 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low323 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
343 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false324 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
344 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict325 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
345 -·name:·Find·/etc/sudoers.d/·files326 -·name:·Find·/etc/sudoers.d/·files
346 ··ansible.builtin.find:327 ··ansible.builtin.find:
Offset 373, 14 lines modifiedOffset 352, 35 lines modified
373 ··-·NIST-800-53-IA-11352 ··-·NIST-800-53-IA-11
374 ··-·low_complexity353 ··-·low_complexity
375 ··-·low_disruption354 ··-·low_disruption
Max diff block lines reached; 114704/120437 bytes (95.24%) of diff not shown.
1.14 MB
./usr/share/doc/ssg-debian/ssg-debian12-guide-anssi_np_nt28_high.html
    
Offset 14285, 16 lines modifiedOffset 14285, 16 lines modified
00037cc0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h00037cc0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h
00037cd0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver00037cd0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver
00037ce0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.00037ce0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.
00037cf0:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p00037cf0:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p
00037d00:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong00037d00:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong
00037d10:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.00037d10:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.
00037d20:·2020·2020·2020·2020·2020·2020·2020·2020··················00037d20:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037d30:·2020·2020·2861·7320·6f66·2032·3032·362d······(as·of·2026-00037d30:·2020·2020·2861·7320·6f66·2032·3032·342d······(as·of·2024-
00037d40:·3031·2d30·3829·0a20·2020·2020·2020·2020··01-08).·········00037d40:·3132·2d30·3729·0a20·2020·2020·2020·2020··12-07).·········
00037d50:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul00037d50:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul
00037d60:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table00037d60:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table
00037d70:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h200037d70:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2
00037d80:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href00037d80:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href
00037d90:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg00037d90:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg
00037da0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_00037da0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
00037db0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy00037db0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy
Offset 16021, 146 lines modifiedOffset 16021, 146 lines modified
0003e940:·7461·2d74·6172·6765·743d·2223·6964·6d34··ta-target="#idm40003e940:·7461·2d74·6172·6765·743d·2223·6964·6d34··ta-target="#idm4
0003e950:·3033·3422·2074·6162·696e·6465·783d·2230··034"·tabindex="00003e950:·3033·3422·2074·6162·696e·6465·783d·2230··034"·tabindex="0
0003e960:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003e960:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003e970:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003e970:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003e980:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003e980:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003e990:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003e990:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003e9a0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003e9a0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003e9b0:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
0003e9c0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003e9d0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003e9e0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003e9f0:·7365·2220·6964·3d22·6964·6d34·3033·3422··se"·id="idm4034" 
0003ea00:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003ea10:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003ea20:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003ea30:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003ea40:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003ea50:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003ea60:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003ea70:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003ea80:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003ea90:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003eaa0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003eab0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003eac0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003ead0:·683e·3c74·643e·7265·7374·7269·6374·3c2f··h><td>restrict</ 
0003eae0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003eaf0:·3c70·7265·3e3c·636f·6465·3e0a·666f·7220··<pre><code>.for· 
0003eb00:·6620·696e·202f·6574·632f·7375·646f·6572··f·in·/etc/sudoer 
0003eb10:·7320·2f65·7463·2f73·7564·6f65·7273·2e64··s·/etc/sudoers.d 
0003eb20:·2f2a·203b·2064·6f0a·2020·6966·205b·2021··/*·;·do.··if·[·! 
0003eb30:·202d·6520·2224·6622·205d·203b·2074·6865···-e·"$f"·]·;·the 
0003eb40:·6e0a·2020·2020·636f·6e74·696e·7565·0a20··n.····continue.· 
0003eb50:·2066·690a·2020·6d61·7463·6869·6e67·5f6c···fi.··matching_l 
0003eb60:·6973·743d·2428·6772·6570·202d·5020·275e··ist=$(grep·-P·'^ 
0003eb70:·283f·2123·292e·2a5b·5c73·5d2b·5c21·6175··(?!#).*[\s]+\!au 
0003eb80:·7468·656e·7469·6361·7465·2e2a·2427·2024··thenticate.*$'·$ 
0003eb90:·6620·7c20·756e·6971·2029·0a20·2069·6620··f·|·uniq·).··if· 
0003eba0:·2120·7465·7374·202d·7a20·2224·6d61·7463··!·test·-z·"$matc 
0003ebb0:·6869·6e67·5f6c·6973·7422·3b20·7468·656e··hing_list";·then 
0003ebc0:·0a20·2020·2077·6869·6c65·2049·4653·3d20··.····while·IFS=· 
0003ebd0:·7265·6164·202d·7220·656e·7472·793b·2064··read·-r·entry;·d 
0003ebe0:·6f0a·2020·2020·2020·2320·636f·6d6d·656e··o.······#·commen 
0003ebf0:·7420·6f75·7420·2221·6175·7468·656e·7469··t·out·"!authenti 
0003ec00:·6361·7465·2220·6d61·7463·6865·7320·746f··cate"·matches·to 
0003ec10:·2070·7265·7365·7276·6520·7573·6572·2064···preserve·user·d 
0003ec20:·6174·610a·2020·2020·2020·7365·6420·2d69··ata.······sed·-i 
0003ec30:·2022·732f·5e24·7b65·6e74·7279·7d24·2f23···"s/^${entry}$/# 
0003ec40:·2026·616d·703b·2f67·2220·2466·0a20·2020···&amp;/g"·$f.··· 
0003ec50:·2064·6f6e·6520·266c·743b·266c·743b·266c···done·&lt;&lt;&l 
0003ec60:·743b·2022·246d·6174·6368·696e·675f·6c69··t;·"$matching_li 
0003ec70:·7374·220a·0a20·2020·202f·7573·722f·7362··st"..····/usr/sb 
0003ec80:·696e·2f76·6973·7564·6f20·2d63·6620·2466··in/visudo·-cf·$f 
0003ec90:·2026·616d·703b·2667·743b·202f·6465·762f···&amp;&gt;·/dev/ 
0003eca0:·6e75·6c6c·207c·7c20·6563·686f·2022·4661··null·||·echo·"Fa 
0003ecb0:·696c·2074·6f20·7661·6c69·6461·7465·2024··il·to·validate·$ 
0003ecc0:·6620·7769·7468·2076·6973·7564·6f22·0a20··f·with·visudo".· 
0003ecd0:·2066·690a·646f·6e65·0a3c·2f63·6f64·653e···fi.done.</code> 
0003ece0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003ecf0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003ed00:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003ed10:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003ed20:·7461·2d74·6172·6765·743d·2223·6964·6d34··ta-target="#idm4 
0003ed30:·3033·3522·2074·6162·696e·6465·783d·2230··035"·tabindex="0 
0003ed40:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003ed50:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003ed60:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003ed70:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003ed80:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003ed90:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s0003e9b0:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s
0003eda0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003e9c0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003edb0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003e9d0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003edc0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003e9e0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003edd0:·6c61·7073·6522·2069·643d·2269·646d·3430··lapse"·id="idm400003e9f0:·6c61·7073·6522·2069·643d·2269·646d·3430··lapse"·id="idm40
0003ede0:·3335·223e·3c74·6162·6c65·2063·6c61·7373··35"><table·class0003ea00:·3334·223e·3c74·6162·6c65·2063·6c61·7373··34"><table·class
0003edf0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003ea10:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003ee00:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003ea20:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003ee10:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003ea30:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003ee20:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003ea40:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003ee30:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003ea50:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003ee40:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003ea60:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003ee50:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003ea70:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003ee60:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003ea80:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003ee70:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003ea90:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003ee80:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>0003eaa0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0003ee90:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><0003eab0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
0003eea0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003eac0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003eeb0:·3c2f·7468·3e3c·7464·3e72·6573·7472·6963··</th><td>restric0003ead0:·3c2f·7468·3e3c·7464·3e72·6573·7472·6963··</th><td>restric
0003eec0:·743c·2f74·643e·3c2f·7472·3e3c·2f74·6162··t</td></tr></tab0003eae0:·743c·2f74·643e·3c2f·7472·3e3c·2f74·6162··t</td></tr></tab
0003eed0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-·0003eaf0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-·
0003eee0:·6e61·6d65·3a20·4669·6e64·202f·6574·632f··name:·Find·/etc/0003eb00:·6e61·6d65·3a20·4669·6e64·202f·6574·632f··name:·Find·/etc/
0003eef0:·7375·646f·6572·732e·642f·2066·696c·6573··sudoers.d/·files0003eb10:·7375·646f·6572·732e·642f·2066·696c·6573··sudoers.d/·files
0003ef00:·0a20·2061·6e73·6962·6c65·2e62·7569·6c74··.··ansible.built0003eb20:·0a20·2061·6e73·6962·6c65·2e62·7569·6c74··.··ansible.built
0003ef10:·696e·2e66·696e·643a·0a20·2020·2070·6174··in.find:.····pat0003eb30:·696e·2e66·696e·643a·0a20·2020·2070·6174··in.find:.····pat
0003ef20:·6873·3a0a·2020·2020·2d20·2f65·7463·2f73··hs:.····-·/etc/s0003eb40:·6873·3a0a·2020·2020·2d20·2f65·7463·2f73··hs:.····-·/etc/s
0003ef30:·7564·6f65·7273·2e64·2f0a·2020·7265·6769··udoers.d/.··regi0003eb50:·7564·6f65·7273·2e64·2f0a·2020·7265·6769··udoers.d/.··regi
0003ef40:·7374·6572·3a20·7375·646f·6572·730a·2020··ster:·sudoers.··0003eb60:·7374·6572·3a20·7375·646f·6572·730a·2020··ster:·sudoers.··
0003ef50:·7461·6773·3a0a·2020·2d20·4e49·5354·2d38··tags:.··-·NIST-80003eb70:·7461·6773·3a0a·2020·2d20·4e49·5354·2d38··tags:.··-·NIST-8
0003ef60:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).··0003eb80:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).··
0003ef70:·2d20·4e49·5354·2d38·3030·2d35·332d·4941··-·NIST-800-53-IA0003eb90:·2d20·4e49·5354·2d38·3030·2d35·332d·4941··-·NIST-800-53-IA
0003ef80:·2d31·310a·2020·2d20·6c6f·775f·636f·6d70··-11.··-·low_comp0003eba0:·2d31·310a·2020·2d20·6c6f·775f·636f·6d70··-11.··-·low_comp
0003ef90:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d0003ebb0:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d
0003efa0:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me0003ebc0:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me
0003efb0:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.··0003ebd0:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.··
0003efc0:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need0003ebe0:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need
0003efd0:·6564·0a20·202d·2072·6573·7472·6963·745f··ed.··-·restrict_0003ebf0:·6564·0a20·202d·2072·6573·7472·6963·745f··ed.··-·restrict_
0003efe0:·7374·7261·7465·6779·0a20·202d·2073·7564··strategy.··-·sud0003ec00:·7374·7261·7465·6779·0a20·202d·2073·7564··strategy.··-·sud
0003eff0:·6f5f·7265·6d6f·7665·5f6e·6f5f·6175·7468··o_remove_no_auth0003ec10:·6f5f·7265·6d6f·7665·5f6e·6f5f·6175·7468··o_remove_no_auth
0003f000:·656e·7469·6361·7465·0a0a·2d20·6e61·6d65··enticate..-·name0003ec20:·656e·7469·6361·7465·0a0a·2d20·6e61·6d65··enticate..-·name
0003f010:·3a20·5265·6d6f·7665·206c·696e·6573·2063··:·Remove·lines·c0003ec30:·3a20·5265·6d6f·7665·206c·696e·6573·2063··:·Remove·lines·c
Max diff block lines reached; 1045634/1065698 bytes (98.12%) of diff not shown.
129 KB
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·High·(Enforced)·Level39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·High·(Enforced)·Level
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_high40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_high
41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
42 ····*·cpe:/o:debian:debian_linux:1242 ····*·cpe:/o:debian:debian_linux:12
43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
44 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8444 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
49 ·········2.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n49 ·········2.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
51 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s51 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
52 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s52 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
Offset 231, 35 lines modifiedOffset 231, 14 lines modified
231 ···························1.7,·SR·1.8,·SR·1.9231 ···························1.7,·SR·1.8,·SR·1.9
232 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,232 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
233 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3233 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
234 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)234 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
235 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7235 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
236 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,236 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
237 ···························SRG-OS-000373-GPOS-00158237 ···························SRG-OS-000373-GPOS-00158
238 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
239 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
240 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
241 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
242 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
243 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
244 ··if·[·!·-e·"$f"·]·;·then 
245 ····continue 
246 ··fi 
247 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·) 
248 ··if·!·test·-z·"$matching_list";·then 
249 ····while·IFS=·read·-r·entry;·do 
250 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data 
251 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
252 ····done·<<<·"$matching_list" 
  
253 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
254 visudo" 
255 ··fi 
256 done 
257 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8238 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
258 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low239 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
259 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low240 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
260 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false241 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
261 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict242 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
262 -·name:·Find·/etc/sudoers.d/·files243 -·name:·Find·/etc/sudoers.d/·files
263 ··ansible.builtin.find:244 ··ansible.builtin.find:
Offset 290, 14 lines modifiedOffset 269, 35 lines modified
290 ··-·NIST-800-53-IA-11269 ··-·NIST-800-53-IA-11
291 ··-·low_complexity270 ··-·low_complexity
292 ··-·low_disruption271 ··-·low_disruption
293 ··-·medium_severity272 ··-·medium_severity
294 ··-·no_reboot_needed273 ··-·no_reboot_needed
295 ··-·restrict_strategy274 ··-·restrict_strategy
296 ··-·sudo_remove_no_authenticate275 ··-·sudo_remove_no_authenticate
 276 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 277 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 278 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 279 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 280 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 281 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do
 282 ··if·[·!·-e·"$f"·]·;·then
 283 ····continue
 284 ··fi
 285 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·)
 286 ··if·!·test·-z·"$matching_list";·then
 287 ····while·IFS=·read·-r·entry;·do
 288 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data
 289 ······sed·-i·"s/^${entry}$/#·&/g"·$f
 290 ····done·<<<·"$matching_list"
  
 291 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with
 292 visudo"
 293 ··fi
 294 done
297 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o295 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o
298 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*296 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
299 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using297 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using
300 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure298 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure
301 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any299 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any
302 sudo·configuration·snippets·in·/etc/sudoers.d/.300 sudo·configuration·snippets·in·/etc/sudoers.d/.
303 ············Without·re-authentication,·users·may·access·resources·or·perform301 ············Without·re-authentication,·users·may·access·resources·or·perform
Offset 318, 35 lines modifiedOffset 318, 14 lines modified
318 ···························1.7,·SR·1.8,·SR·1.9318 ···························1.7,·SR·1.8,·SR·1.9
319 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,319 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
320 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3320 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
321 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)321 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
322 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7322 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
323 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,323 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
324 ···························SRG-OS-000373-GPOS-00158324 ···························SRG-OS-000373-GPOS-00158
325 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
326 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
327 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
328 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
329 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
330 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
331 ··if·[·!·-e·"$f"·]·;·then 
332 ····continue 
333 ··fi 
334 ··matching_list=$(grep·-P·'^(?!#).*[\s]+NOPASSWD[\s]*\:.*$'·$f·|·uniq·) 
335 ··if·!·test·-z·"$matching_list";·then 
336 ····while·IFS=·read·-r·entry;·do 
337 ······#·comment·out·"NOPASSWD"·matches·to·preserve·user·data 
338 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
339 ····done·<<<·"$matching_list" 
  
340 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
341 visudo" 
342 ··fi 
343 done 
344 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8325 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
345 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low326 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
346 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low327 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
347 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false328 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
348 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict329 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
349 -·name:·Find·/etc/sudoers.d/·files330 -·name:·Find·/etc/sudoers.d/·files
350 ··ansible.builtin.find:331 ··ansible.builtin.find:
Offset 377, 14 lines modifiedOffset 356, 35 lines modified
377 ··-·NIST-800-53-IA-11356 ··-·NIST-800-53-IA-11
378 ··-·low_complexity357 ··-·low_complexity
379 ··-·low_disruption358 ··-·low_disruption
Max diff block lines reached; 126140/131878 bytes (95.65%) of diff not shown.
366 KB
./usr/share/doc/ssg-debian/ssg-debian12-guide-anssi_np_nt28_minimal.html
    
Offset 14279, 15 lines modifiedOffset 14279, 15 lines modified
00037c60:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v00037c60:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v
00037c70:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>00037c70:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>
00037c80:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><00037c80:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><
00037c90:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro00037c90:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro
00037ca0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong00037ca0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong
00037cb0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············00037cb0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············
00037cc0:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·20200037cc0:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202
00037cd0:·362d·3031·2d30·3829·0a20·2020·2020·2020··6-01-08).·······00037cd0:·342d·3132·2d30·3729·0a20·2020·2020·2020··4-12-07).·······
00037ce0:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></00037ce0:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></
00037cf0:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab00037cf0:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab
00037d00:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</00037d00:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</
00037d10:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr00037d10:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr
00037d20:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s00037d20:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s
00037d30:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten00037d30:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten
00037d40:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">00037d40:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">
Offset 14776, 146 lines modifiedOffset 14776, 146 lines modified
00039b70:·7461·2d74·6172·6765·743d·2223·6964·6d34··ta-target="#idm400039b70:·7461·2d74·6172·6765·743d·2223·6964·6d34··ta-target="#idm4
00039b80:·3033·3422·2074·6162·696e·6465·783d·2230··034"·tabindex="000039b80:·3033·3422·2074·6162·696e·6465·783d·2230··034"·tabindex="0
00039b90:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·00039b90:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
00039ba0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f00039ba0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
00039bb0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act00039bb0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
00039bc0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"00039bc0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
00039bd0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed00039bd0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
00039be0:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
00039bf0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
00039c00:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
00039c10:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
00039c20:·7365·2220·6964·3d22·6964·6d34·3033·3422··se"·id="idm4034" 
00039c30:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
00039c40:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
00039c50:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
00039c60:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
00039c70:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
00039c80:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
00039c90:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
00039ca0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
00039cb0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
00039cc0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
00039cd0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
00039ce0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
00039cf0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
00039d00:·683e·3c74·643e·7265·7374·7269·6374·3c2f··h><td>restrict</ 
00039d10:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
00039d20:·3c70·7265·3e3c·636f·6465·3e0a·666f·7220··<pre><code>.for· 
00039d30:·6620·696e·202f·6574·632f·7375·646f·6572··f·in·/etc/sudoer 
00039d40:·7320·2f65·7463·2f73·7564·6f65·7273·2e64··s·/etc/sudoers.d 
00039d50:·2f2a·203b·2064·6f0a·2020·6966·205b·2021··/*·;·do.··if·[·! 
00039d60:·202d·6520·2224·6622·205d·203b·2074·6865···-e·"$f"·]·;·the 
00039d70:·6e0a·2020·2020·636f·6e74·696e·7565·0a20··n.····continue.· 
00039d80:·2066·690a·2020·6d61·7463·6869·6e67·5f6c···fi.··matching_l 
00039d90:·6973·743d·2428·6772·6570·202d·5020·275e··ist=$(grep·-P·'^ 
00039da0:·283f·2123·292e·2a5b·5c73·5d2b·5c21·6175··(?!#).*[\s]+\!au 
00039db0:·7468·656e·7469·6361·7465·2e2a·2427·2024··thenticate.*$'·$ 
00039dc0:·6620·7c20·756e·6971·2029·0a20·2069·6620··f·|·uniq·).··if· 
00039dd0:·2120·7465·7374·202d·7a20·2224·6d61·7463··!·test·-z·"$matc 
00039de0:·6869·6e67·5f6c·6973·7422·3b20·7468·656e··hing_list";·then 
00039df0:·0a20·2020·2077·6869·6c65·2049·4653·3d20··.····while·IFS=· 
00039e00:·7265·6164·202d·7220·656e·7472·793b·2064··read·-r·entry;·d 
00039e10:·6f0a·2020·2020·2020·2320·636f·6d6d·656e··o.······#·commen 
00039e20:·7420·6f75·7420·2221·6175·7468·656e·7469··t·out·"!authenti 
00039e30:·6361·7465·2220·6d61·7463·6865·7320·746f··cate"·matches·to 
00039e40:·2070·7265·7365·7276·6520·7573·6572·2064···preserve·user·d 
00039e50:·6174·610a·2020·2020·2020·7365·6420·2d69··ata.······sed·-i 
00039e60:·2022·732f·5e24·7b65·6e74·7279·7d24·2f23···"s/^${entry}$/# 
00039e70:·2026·616d·703b·2f67·2220·2466·0a20·2020···&amp;/g"·$f.··· 
00039e80:·2064·6f6e·6520·266c·743b·266c·743b·266c···done·&lt;&lt;&l 
00039e90:·743b·2022·246d·6174·6368·696e·675f·6c69··t;·"$matching_li 
00039ea0:·7374·220a·0a20·2020·202f·7573·722f·7362··st"..····/usr/sb 
00039eb0:·696e·2f76·6973·7564·6f20·2d63·6620·2466··in/visudo·-cf·$f 
00039ec0:·2026·616d·703b·2667·743b·202f·6465·762f···&amp;&gt;·/dev/ 
00039ed0:·6e75·6c6c·207c·7c20·6563·686f·2022·4661··null·||·echo·"Fa 
00039ee0:·696c·2074·6f20·7661·6c69·6461·7465·2024··il·to·validate·$ 
00039ef0:·6620·7769·7468·2076·6973·7564·6f22·0a20··f·with·visudo".· 
00039f00:·2066·690a·646f·6e65·0a3c·2f63·6f64·653e···fi.done.</code> 
00039f10:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
00039f20:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
00039f30:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
00039f40:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
00039f50:·7461·2d74·6172·6765·743d·2223·6964·6d34··ta-target="#idm4 
00039f60:·3033·3522·2074·6162·696e·6465·783d·2230··035"·tabindex="0 
00039f70:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
00039f80:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
00039f90:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
00039fa0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
00039fb0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
00039fc0:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s00039be0:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s
00039fd0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b00039bf0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
00039fe0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa00039c00:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
00039ff0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col00039c10:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003a000:·6c61·7073·6522·2069·643d·2269·646d·3430··lapse"·id="idm4000039c20:·6c61·7073·6522·2069·643d·2269·646d·3430··lapse"·id="idm40
0003a010:·3335·223e·3c74·6162·6c65·2063·6c61·7373··35"><table·class00039c30:·3334·223e·3c74·6162·6c65·2063·6c61·7373··34"><table·class
0003a020:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st00039c40:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003a030:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord00039c50:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003a040:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde00039c60:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003a050:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co00039c70:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003a060:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t00039c80:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003a070:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><00039c90:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003a080:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio00039ca0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003a090:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</00039cb0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003a0a0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>00039cc0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003a0b0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>00039cd0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0003a0c0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><00039ce0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
0003a0d0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:00039cf0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003a0e0:·3c2f·7468·3e3c·7464·3e72·6573·7472·6963··</th><td>restric00039d00:·3c2f·7468·3e3c·7464·3e72·6573·7472·6963··</th><td>restric
0003a0f0:·743c·2f74·643e·3c2f·7472·3e3c·2f74·6162··t</td></tr></tab00039d10:·743c·2f74·643e·3c2f·7472·3e3c·2f74·6162··t</td></tr></tab
0003a100:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-·00039d20:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-·
0003a110:·6e61·6d65·3a20·4669·6e64·202f·6574·632f··name:·Find·/etc/00039d30:·6e61·6d65·3a20·4669·6e64·202f·6574·632f··name:·Find·/etc/
0003a120:·7375·646f·6572·732e·642f·2066·696c·6573··sudoers.d/·files00039d40:·7375·646f·6572·732e·642f·2066·696c·6573··sudoers.d/·files
0003a130:·0a20·2061·6e73·6962·6c65·2e62·7569·6c74··.··ansible.built00039d50:·0a20·2061·6e73·6962·6c65·2e62·7569·6c74··.··ansible.built
0003a140:·696e·2e66·696e·643a·0a20·2020·2070·6174··in.find:.····pat00039d60:·696e·2e66·696e·643a·0a20·2020·2070·6174··in.find:.····pat
0003a150:·6873·3a0a·2020·2020·2d20·2f65·7463·2f73··hs:.····-·/etc/s00039d70:·6873·3a0a·2020·2020·2d20·2f65·7463·2f73··hs:.····-·/etc/s
0003a160:·7564·6f65·7273·2e64·2f0a·2020·7265·6769··udoers.d/.··regi00039d80:·7564·6f65·7273·2e64·2f0a·2020·7265·6769··udoers.d/.··regi
0003a170:·7374·6572·3a20·7375·646f·6572·730a·2020··ster:·sudoers.··00039d90:·7374·6572·3a20·7375·646f·6572·730a·2020··ster:·sudoers.··
0003a180:·7461·6773·3a0a·2020·2d20·4e49·5354·2d38··tags:.··-·NIST-800039da0:·7461·6773·3a0a·2020·2d20·4e49·5354·2d38··tags:.··-·NIST-8
0003a190:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).··00039db0:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).··
0003a1a0:·2d20·4e49·5354·2d38·3030·2d35·332d·4941··-·NIST-800-53-IA00039dc0:·2d20·4e49·5354·2d38·3030·2d35·332d·4941··-·NIST-800-53-IA
0003a1b0:·2d31·310a·2020·2d20·6c6f·775f·636f·6d70··-11.··-·low_comp00039dd0:·2d31·310a·2020·2d20·6c6f·775f·636f·6d70··-11.··-·low_comp
0003a1c0:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d00039de0:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d
0003a1d0:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me00039df0:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me
0003a1e0:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.··00039e00:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.··
0003a1f0:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need00039e10:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need
0003a200:·6564·0a20·202d·2072·6573·7472·6963·745f··ed.··-·restrict_00039e20:·6564·0a20·202d·2072·6573·7472·6963·745f··ed.··-·restrict_
0003a210:·7374·7261·7465·6779·0a20·202d·2073·7564··strategy.··-·sud00039e30:·7374·7261·7465·6779·0a20·202d·2073·7564··strategy.··-·sud
0003a220:·6f5f·7265·6d6f·7665·5f6e·6f5f·6175·7468··o_remove_no_auth00039e40:·6f5f·7265·6d6f·7665·5f6e·6f5f·6175·7468··o_remove_no_auth
0003a230:·656e·7469·6361·7465·0a0a·2d20·6e61·6d65··enticate..-·name00039e50:·656e·7469·6361·7465·0a0a·2d20·6e61·6d65··enticate..-·name
0003a240:·3a20·5265·6d6f·7665·206c·696e·6573·2063··:·Remove·lines·c00039e60:·3a20·5265·6d6f·7665·206c·696e·6573·2063··:·Remove·lines·c
0003a250:·6f6e·7461·696e·696e·6720·2161·7574·6865··ontaining·!authe00039e70:·6f6e·7461·696e·696e·6720·2161·7574·6865··ontaining·!authe
Max diff block lines reached; 308046/327972 bytes (93.92%) of diff not shown.
45.1 KB
html2text {}
    
Offset 36, 15 lines modifiedOffset 36, 15 lines modified
36 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*36 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
37 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Minimal·Level37 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Minimal·Level
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_minimal38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_minimal
39 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*39 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
40 ····*·cpe:/o:debian:debian_linux:1240 ····*·cpe:/o:debian:debian_linux:12
41 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*41 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
42 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8442 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
43 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)43 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
44 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*44 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
45 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s45 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
46 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e46 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
47 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g47 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
48 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s48 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
49 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s49 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
50 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n50 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
Offset 91, 35 lines modifiedOffset 91, 14 lines modified
91 ···························1.7,·SR·1.8,·SR·1.991 ···························1.7,·SR·1.8,·SR·1.9
92 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,92 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
93 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.393 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
94 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)94 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
95 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-795 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
96 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,96 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
97 ···························SRG-OS-000373-GPOS-0015897 ···························SRG-OS-000373-GPOS-00158
98 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
99 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
100 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
101 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
102 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
103 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
104 ··if·[·!·-e·"$f"·]·;·then 
105 ····continue 
106 ··fi 
107 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·) 
108 ··if·!·test·-z·"$matching_list";·then 
109 ····while·IFS=·read·-r·entry;·do 
110 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data 
111 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
112 ····done·<<<·"$matching_list" 
  
113 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
114 visudo" 
115 ··fi 
116 done 
117 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x898 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
118 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low99 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
119 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low100 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
120 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false101 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
121 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict102 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
122 -·name:·Find·/etc/sudoers.d/·files103 -·name:·Find·/etc/sudoers.d/·files
123 ··ansible.builtin.find:104 ··ansible.builtin.find:
Offset 150, 14 lines modifiedOffset 129, 35 lines modified
150 ··-·NIST-800-53-IA-11129 ··-·NIST-800-53-IA-11
151 ··-·low_complexity130 ··-·low_complexity
152 ··-·low_disruption131 ··-·low_disruption
153 ··-·medium_severity132 ··-·medium_severity
154 ··-·no_reboot_needed133 ··-·no_reboot_needed
155 ··-·restrict_strategy134 ··-·restrict_strategy
156 ··-·sudo_remove_no_authenticate135 ··-·sudo_remove_no_authenticate
 136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 141 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do
 142 ··if·[·!·-e·"$f"·]·;·then
 143 ····continue
 144 ··fi
 145 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·)
 146 ··if·!·test·-z·"$matching_list";·then
 147 ····while·IFS=·read·-r·entry;·do
 148 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data
 149 ······sed·-i·"s/^${entry}$/#·&/g"·$f
 150 ····done·<<<·"$matching_list"
  
 151 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with
 152 visudo"
 153 ··fi
 154 done
157 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o155 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o
158 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*156 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
159 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using157 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using
160 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure158 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure
161 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any159 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any
162 sudo·configuration·snippets·in·/etc/sudoers.d/.160 sudo·configuration·snippets·in·/etc/sudoers.d/.
163 ············Without·re-authentication,·users·may·access·resources·or·perform161 ············Without·re-authentication,·users·may·access·resources·or·perform
Offset 178, 35 lines modifiedOffset 178, 14 lines modified
178 ···························1.7,·SR·1.8,·SR·1.9178 ···························1.7,·SR·1.8,·SR·1.9
179 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,179 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
180 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3180 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
181 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)181 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
182 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7182 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
183 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,183 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
184 ···························SRG-OS-000373-GPOS-00158184 ···························SRG-OS-000373-GPOS-00158
185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
190 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
191 ··if·[·!·-e·"$f"·]·;·then 
192 ····continue 
193 ··fi 
194 ··matching_list=$(grep·-P·'^(?!#).*[\s]+NOPASSWD[\s]*\:.*$'·$f·|·uniq·) 
195 ··if·!·test·-z·"$matching_list";·then 
196 ····while·IFS=·read·-r·entry;·do 
197 ······#·comment·out·"NOPASSWD"·matches·to·preserve·user·data 
198 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
199 ····done·<<<·"$matching_list" 
  
200 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
201 visudo" 
202 ··fi 
203 done 
204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
209 -·name:·Find·/etc/sudoers.d/·files190 -·name:·Find·/etc/sudoers.d/·files
210 ··ansible.builtin.find:191 ··ansible.builtin.find:
Offset 237, 14 lines modifiedOffset 216, 35 lines modified
237 ··-·NIST-800-53-IA-11216 ··-·NIST-800-53-IA-11
238 ··-·low_complexity217 ··-·low_complexity
239 ··-·low_disruption218 ··-·low_disruption
Max diff block lines reached; 40434/46150 bytes (87.61%) of diff not shown.
1.1 MB
./usr/share/doc/ssg-debian/ssg-debian12-guide-anssi_np_nt28_restrictive.html
    
Offset 14283, 15 lines modifiedOffset 14283, 15 lines modified
00037ca0:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v00037ca0:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v
00037cb0:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>00037cb0:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>
00037cc0:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><00037cc0:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><
00037cd0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro00037cd0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro
00037ce0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong00037ce0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong
00037cf0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············00037cf0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············
00037d00:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·20200037d00:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202
00037d10:·362d·3031·2d30·3829·0a20·2020·2020·2020··6-01-08).·······00037d10:·342d·3132·2d30·3729·0a20·2020·2020·2020··4-12-07).·······
00037d20:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></00037d20:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></
00037d30:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab00037d30:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab
00037d40:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</00037d40:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</
00037d50:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr00037d50:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr
00037d60:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s00037d60:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s
00037d70:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten00037d70:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten
00037d80:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">00037d80:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">
Offset 16011, 147 lines modifiedOffset 16011, 147 lines modified
0003e8a0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003e8a0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003e8b0:·743d·2223·6964·6d34·3033·3422·2074·6162··t="#idm4034"·tab0003e8b0:·743d·2223·6964·6d34·3033·3422·2074·6162··t="#idm4034"·tab
0003e8c0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003e8c0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003e8d0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003e8d0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003e8e0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003e8e0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003e8f0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003e8f0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003e900:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003e900:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003e910:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
0003e920:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
0003e930:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003e940:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003e950:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003e960:·6964·6d34·3033·3422·3e3c·7461·626c·6520··idm4034"><table· 
0003e970:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003e980:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003e990:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003e9a0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003e9b0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003e9c0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003e9d0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003e9e0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003e9f0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003ea00:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003ea10:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003ea20:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003ea30:·7465·6779·3a3c·2f74·683e·3c74·643e·7265··tegy:</th><td>re 
0003ea40:·7374·7269·6374·3c2f·7464·3e3c·2f74·723e··strict</td></tr> 
0003ea50:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003ea60:·6465·3e0a·666f·7220·6620·696e·202f·6574··de>.for·f·in·/et 
0003ea70:·632f·7375·646f·6572·7320·2f65·7463·2f73··c/sudoers·/etc/s 
0003ea80:·7564·6f65·7273·2e64·2f2a·203b·2064·6f0a··udoers.d/*·;·do. 
0003ea90:·2020·6966·205b·2021·202d·6520·2224·6622····if·[·!·-e·"$f" 
0003eaa0:·205d·203b·2074·6865·6e0a·2020·2020·636f···]·;·then.····co 
0003eab0:·6e74·696e·7565·0a20·2066·690a·2020·6d61··ntinue.··fi.··ma 
0003eac0:·7463·6869·6e67·5f6c·6973·743d·2428·6772··tching_list=$(gr 
0003ead0:·6570·202d·5020·275e·283f·2123·292e·2a5b··ep·-P·'^(?!#).*[ 
0003eae0:·5c73·5d2b·5c21·6175·7468·656e·7469·6361··\s]+\!authentica 
0003eaf0:·7465·2e2a·2427·2024·6620·7c20·756e·6971··te.*$'·$f·|·uniq 
0003eb00:·2029·0a20·2069·6620·2120·7465·7374·202d···).··if·!·test·- 
0003eb10:·7a20·2224·6d61·7463·6869·6e67·5f6c·6973··z·"$matching_lis 
0003eb20:·7422·3b20·7468·656e·0a20·2020·2077·6869··t";·then.····whi 
0003eb30:·6c65·2049·4653·3d20·7265·6164·202d·7220··le·IFS=·read·-r· 
0003eb40:·656e·7472·793b·2064·6f0a·2020·2020·2020··entry;·do.······ 
0003eb50:·2320·636f·6d6d·656e·7420·6f75·7420·2221··#·comment·out·"! 
0003eb60:·6175·7468·656e·7469·6361·7465·2220·6d61··authenticate"·ma 
0003eb70:·7463·6865·7320·746f·2070·7265·7365·7276··tches·to·preserv 
0003eb80:·6520·7573·6572·2064·6174·610a·2020·2020··e·user·data.···· 
0003eb90:·2020·7365·6420·2d69·2022·732f·5e24·7b65····sed·-i·"s/^${e 
0003eba0:·6e74·7279·7d24·2f23·2026·616d·703b·2f67··ntry}$/#·&amp;/g 
0003ebb0:·2220·2466·0a20·2020·2064·6f6e·6520·266c··"·$f.····done·&l 
0003ebc0:·743b·266c·743b·266c·743b·2022·246d·6174··t;&lt;&lt;·"$mat 
0003ebd0:·6368·696e·675f·6c69·7374·220a·0a20·2020··ching_list"..··· 
0003ebe0:·202f·7573·722f·7362·696e·2f76·6973·7564···/usr/sbin/visud 
0003ebf0:·6f20·2d63·6620·2466·2026·616d·703b·2667··o·-cf·$f·&amp;&g 
0003ec00:·743b·202f·6465·762f·6e75·6c6c·207c·7c20··t;·/dev/null·||· 
0003ec10:·6563·686f·2022·4661·696c·2074·6f20·7661··echo·"Fail·to·va 
0003ec20:·6c69·6461·7465·2024·6620·7769·7468·2076··lidate·$f·with·v 
0003ec30:·6973·7564·6f22·0a20·2066·690a·646f·6e65··isudo".··fi.done 
0003ec40:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003ec50:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003ec60:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003ec70:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003ec80:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003ec90:·743d·2223·6964·6d34·3033·3522·2074·6162··t="#idm4035"·tab 
0003eca0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003ecb0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003ecc0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003ecd0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003ece0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003ecf0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A0003e910:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
0003ed00:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.0003e920:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.
0003ed10:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003e930:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003ed20:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003e940:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003ed30:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003e950:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003ed40:·643d·2269·646d·3430·3335·223e·3c74·6162··d="idm4035"><tab0003e960:·643d·2269·646d·3430·3334·223e·3c74·6162··d="idm4034"><tab
0003ed50:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003e970:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003ed60:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003e980:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003ed70:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003e990:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003ed80:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003e9a0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003ed90:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003e9b0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003eda0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003e9c0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003edb0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003e9d0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
0003edc0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003e9e0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003edd0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003e9f0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003ede0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<0003ea00:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
0003edf0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003ea10:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003ee00:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003ea20:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003ee10:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003ea30:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003ee20:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></0003ea40:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></
0003ee30:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003ea50:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
0003ee40:·3c63·6f64·653e·2d20·6e61·6d65·3a20·4669··<code>-·name:·Fi0003ea60:·3c63·6f64·653e·2d20·6e61·6d65·3a20·4669··<code>-·name:·Fi
0003ee50:·6e64·202f·6574·632f·7375·646f·6572·732e··nd·/etc/sudoers.0003ea70:·6e64·202f·6574·632f·7375·646f·6572·732e··nd·/etc/sudoers.
0003ee60:·642f·2066·696c·6573·0a20·2061·6e73·6962··d/·files.··ansib0003ea80:·642f·2066·696c·6573·0a20·2061·6e73·6962··d/·files.··ansib
0003ee70:·6c65·2e62·7569·6c74·696e·2e66·696e·643a··le.builtin.find:0003ea90:·6c65·2e62·7569·6c74·696e·2e66·696e·643a··le.builtin.find:
0003ee80:·0a20·2020·2070·6174·6873·3a0a·2020·2020··.····paths:.····0003eaa0:·0a20·2020·2070·6174·6873·3a0a·2020·2020··.····paths:.····
0003ee90:·2d20·2f65·7463·2f73·7564·6f65·7273·2e64··-·/etc/sudoers.d0003eab0:·2d20·2f65·7463·2f73·7564·6f65·7273·2e64··-·/etc/sudoers.d
0003eea0:·2f0a·2020·7265·6769·7374·6572·3a20·7375··/.··register:·su0003eac0:·2f0a·2020·7265·6769·7374·6572·3a20·7375··/.··register:·su
0003eeb0:·646f·6572·730a·2020·7461·6773·3a0a·2020··doers.··tags:.··0003ead0:·646f·6572·730a·2020·7461·6773·3a0a·2020··doers.··tags:.··
0003eec0:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM0003eae0:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
0003eed0:·2d36·2861·290a·2020·2d20·4e49·5354·2d38··-6(a).··-·NIST-80003eaf0:·2d36·2861·290a·2020·2d20·4e49·5354·2d38··-6(a).··-·NIST-8
0003eee0:·3030·2d35·332d·4941·2d31·310a·2020·2d20··00-53-IA-11.··-·0003eb00:·3030·2d35·332d·4941·2d31·310a·2020·2d20··00-53-IA-11.··-·
0003eef0:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.·0003eb10:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.·
0003ef00:·202d·206c·6f77·5f64·6973·7275·7074·696f···-·low_disruptio0003eb20:·202d·206c·6f77·5f64·6973·7275·7074·696f···-·low_disruptio
0003ef10:·6e0a·2020·2d20·6d65·6469·756d·5f73·6576··n.··-·medium_sev0003eb30:·6e0a·2020·2d20·6d65·6469·756d·5f73·6576··n.··-·medium_sev
0003ef20:·6572·6974·790a·2020·2d20·6e6f·5f72·6562··erity.··-·no_reb0003eb40:·6572·6974·790a·2020·2d20·6e6f·5f72·6562··erity.··-·no_reb
0003ef30:·6f6f·745f·6e65·6564·6564·0a20·202d·2072··oot_needed.··-·r0003eb50:·6f6f·745f·6e65·6564·6564·0a20·202d·2072··oot_needed.··-·r
0003ef40:·6573·7472·6963·745f·7374·7261·7465·6779··estrict_strategy0003eb60:·6573·7472·6963·745f·7374·7261·7465·6779··estrict_strategy
0003ef50:·0a20·202d·2073·7564·6f5f·7265·6d6f·7665··.··-·sudo_remove0003eb70:·0a20·202d·2073·7564·6f5f·7265·6d6f·7665··.··-·sudo_remove
0003ef60:·5f6e·6f5f·6175·7468·656e·7469·6361·7465··_no_authenticate0003eb80:·5f6e·6f5f·6175·7468·656e·7469·6361·7465··_no_authenticate
0003ef70:·0a0a·2d20·6e61·6d65·3a20·5265·6d6f·7665··..-·name:·Remove0003eb90:·0a0a·2d20·6e61·6d65·3a20·5265·6d6f·7665··..-·name:·Remove
0003ef80:·206c·696e·6573·2063·6f6e·7461·696e·696e···lines·containin0003eba0:·206c·696e·6573·2063·6f6e·7461·696e·696e···lines·containin
Max diff block lines reached; 1003654/1023718 bytes (98.04%) of diff not shown.
125 KB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Restrictive·Level38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Profile·for·ANSSI·DAT-NT28·Restrictive·Level
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_restrictive39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_np_nt28_restrictive
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:debian:debian_linux:1241 ····*·cpe:/o:debian:debian_linux:12
42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
43 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8443 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
48 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g48 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
49 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s49 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
50 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s50 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
51 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n51 ·········1.·_\x8A_\x8P_\x8T_\x8·_\x8s_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
Offset 229, 35 lines modifiedOffset 229, 14 lines modified
229 ···························1.7,·SR·1.8,·SR·1.9229 ···························1.7,·SR·1.8,·SR·1.9
230 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,230 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
231 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3231 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
232 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)232 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
233 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7233 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
234 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,234 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
235 ···························SRG-OS-000373-GPOS-00158235 ···························SRG-OS-000373-GPOS-00158
236 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
237 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
238 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
239 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
240 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
241 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
242 ··if·[·!·-e·"$f"·]·;·then 
243 ····continue 
244 ··fi 
245 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·) 
246 ··if·!·test·-z·"$matching_list";·then 
247 ····while·IFS=·read·-r·entry;·do 
248 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data 
249 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
250 ····done·<<<·"$matching_list" 
  
251 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
252 visudo" 
253 ··fi 
254 done 
255 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8236 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
256 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low237 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
257 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low238 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
258 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false239 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
259 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict240 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
260 -·name:·Find·/etc/sudoers.d/·files241 -·name:·Find·/etc/sudoers.d/·files
261 ··ansible.builtin.find:242 ··ansible.builtin.find:
Offset 288, 14 lines modifiedOffset 267, 35 lines modified
288 ··-·NIST-800-53-IA-11267 ··-·NIST-800-53-IA-11
289 ··-·low_complexity268 ··-·low_complexity
290 ··-·low_disruption269 ··-·low_disruption
291 ··-·medium_severity270 ··-·medium_severity
292 ··-·no_reboot_needed271 ··-·no_reboot_needed
293 ··-·restrict_strategy272 ··-·restrict_strategy
294 ··-·sudo_remove_no_authenticate273 ··-·sudo_remove_no_authenticate
 274 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 275 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 276 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 277 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 278 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 279 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do
 280 ··if·[·!·-e·"$f"·]·;·then
 281 ····continue
 282 ··fi
 283 ··matching_list=$(grep·-P·'^(?!#).*[\s]+\!authenticate.*$'·$f·|·uniq·)
 284 ··if·!·test·-z·"$matching_list";·then
 285 ····while·IFS=·read·-r·entry;·do
 286 ······#·comment·out·"!authenticate"·matches·to·preserve·user·data
 287 ······sed·-i·"s/^${entry}$/#·&/g"·$f
 288 ····done·<<<·"$matching_list"
  
 289 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with
 290 visudo"
 291 ··fi
 292 done
295 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o293 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·U\x8Us\x8se\x8er\x8rs\x8s·R\x8Re\x8e-\x8-A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8te\x8e·f\x8fo\x8or\x8r·P\x8Pr\x8ri\x8iv\x8vi\x8il\x8le\x8eg\x8ge\x8e·E\x8Es\x8sc\x8ca\x8al\x8la\x8at\x8ti\x8io\x8on\x8n·-\x8-·s\x8su\x8ud\x8do\x8o
296 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*294 N\x8NO\x8OP\x8PA\x8AS\x8SS\x8SW\x8WD\x8D·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
297 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using295 The·sudo·NOPASSWD·tag,·when·specified,·allows·a·user·to·execute·commands·using
298 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure296 sudo·without·having·to·authenticate.·This·should·be·disabled·by·making·sure
299 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any297 that·the·NOPASSWD·tag·does·not·exist·in·/etc/sudoers·configuration·file·or·any
300 sudo·configuration·snippets·in·/etc/sudoers.d/.298 sudo·configuration·snippets·in·/etc/sudoers.d/.
301 ············Without·re-authentication,·users·may·access·resources·or·perform299 ············Without·re-authentication,·users·may·access·resources·or·perform
Offset 316, 35 lines modifiedOffset 316, 14 lines modified
316 ···························1.7,·SR·1.8,·SR·1.9316 ···························1.7,·SR·1.8,·SR·1.9
317 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,317 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,
318 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3318 ···························A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
319 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)319 ············_\x8n_\x8i_\x8s_\x8t···········IA-11,·CM-6(a)
320 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7320 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-7
321 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,321 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000373-GPOS-00156,·SRG-OS-000373-GPOS-00157,
322 ···························SRG-OS-000373-GPOS-00158322 ···························SRG-OS-000373-GPOS-00158
323 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
324 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
325 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
326 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
327 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
328 for·f·in·/etc/sudoers·/etc/sudoers.d/*·;·do 
329 ··if·[·!·-e·"$f"·]·;·then 
330 ····continue 
331 ··fi 
332 ··matching_list=$(grep·-P·'^(?!#).*[\s]+NOPASSWD[\s]*\:.*$'·$f·|·uniq·) 
333 ··if·!·test·-z·"$matching_list";·then 
334 ····while·IFS=·read·-r·entry;·do 
335 ······#·comment·out·"NOPASSWD"·matches·to·preserve·user·data 
336 ······sed·-i·"s/^${entry}$/#·&/g"·$f 
337 ····done·<<<·"$matching_list" 
  
338 ····/usr/sbin/visudo·-cf·$f·&>·/dev/null·||·echo·"Fail·to·validate·$f·with 
339 visudo" 
340 ··fi 
341 done 
342 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8323 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
343 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low324 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
344 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low325 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
345 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false326 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
346 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict327 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
347 -·name:·Find·/etc/sudoers.d/·files328 -·name:·Find·/etc/sudoers.d/·files
348 ··ansible.builtin.find:329 ··ansible.builtin.find:
Offset 375, 14 lines modifiedOffset 354, 35 lines modified
375 ··-·NIST-800-53-IA-11354 ··-·NIST-800-53-IA-11
376 ··-·low_complexity355 ··-·low_complexity
377 ··-·low_disruption356 ··-·low_disruption
Max diff block lines reached; 122451/128177 bytes (95.53%) of diff not shown.
1.04 MB
./usr/share/doc/ssg-debian/ssg-debian12-guide-standard.html
    
Offset 14285, 15 lines modifiedOffset 14285, 15 lines modified
00037cc0:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren00037cc0:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren
00037cd0:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro00037cd0:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro
00037ce0:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron00037ce0:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron
00037cf0:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s00037cf0:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s
00037d00:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str00037d00:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str
00037d10:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········00037d10:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········
00037d20:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·00037d20:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·
00037d30:·3230·3236·2d30·312d·3038·290a·2020·2020··2026-01-08).····00037d30:·3230·3234·2d31·322d·3037·290a·2020·2020··2024-12-07).····
00037d40:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li00037d40:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li
00037d50:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>00037d50:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>
00037d60:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content00037d60:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content
00037d70:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a00037d70:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a
00037d80:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or00037d80:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or
00037d90:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con00037d90:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con
00037da0:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste00037da0:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste
Offset 16220, 736 lines modifiedOffset 16220, 736 lines modified
0003f5b0:·6172·6765·743d·2223·6964·6d31·3033·3533··arget="#idm103530003f5b0:·6172·6765·743d·2223·6964·6d31·3033·3533··arget="#idm10353
0003f5c0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003f5c0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003f5d0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003f5d0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003f5e0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003f5e0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003f5f0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003f5f0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003f600:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003f600:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
Diff chunk too large, falling back to line-by-line diff (722 lines added, 722 lines removed)
0003f610:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003f610:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003f620:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script0003f620:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip
0003f630:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003f630:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003f640:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003f640:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003f650:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003f650:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003f660:·2069·643d·2269·646d·3130·3335·3322·3e3c···id="idm10353"><0003f660:·7365·2220·6964·3d22·6964·6d31·3033·3533··se"·id="idm10353
0003f670:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme0003f670:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003f680:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli0003f680:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003f690:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce0003f690:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003f6a0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.0003f6a0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003f6b0:·6966·205b·2021·202d·6620·2f2e·646f·636b··if·[·!·-f·/.dock0003f6b0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003f6c0:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am0003f6c0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003f6d0:·703b·205b·2021·202d·6620·2f72·756e·2f2e··p;·[·!·-f·/run/.0003f6d0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003f6e0:·636f·6e74·6169·6e65·7265·6e76·205d·3b20··containerenv·];·0003f6e0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003f6f0:·7468·656e·0a0a·2320·4c69·7374·206f·6620··then..#·List·of·0003f6f0:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<
0003f700:·6c6f·6720·6669·6c65·2070·6174·6873·2074··log·file·paths·t0003f700:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003f710:·6f20·6265·2069·6e73·7065·6374·6564·2066··o·be·inspected·f0003f710:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003f720:·6f72·2063·6f72·7265·6374·2070·6572·6d69··or·correct·permi0003f720:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003f730:·7373·696f·6e73·0a23·202a·2050·7269·6d61··ssions.#·*·Prima0003f730:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003f740:·7269·6c79·2069·6e73·7065·6374·206c·6f67··rily·inspect·log0003f740:·3a3c·2f74·683e·3c74·643e·636f·6e66·6967··:</th><td>config
0003f750:·2066·696c·6520·7061·7468·7320·6c69·7374···file·paths·list0003f750:·7572·653c·2f74·643e·3c2f·7472·3e3c·2f74··ure</td></tr></t
0003f760:·6564·2069·6e20·2f65·7463·2f72·7379·736c··ed·in·/etc/rsysl0003f760:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
0003f770:·6f67·2e63·6f6e·660a·5253·5953·4c4f·475f··og.conf.RSYSLOG_0003f770:·2d20·6e61·6d65·3a20·456e·7375·7265·204c··-·name:·Ensure·L
0003f780:·4554·435f·434f·4e46·4947·3d22·2f65·7463··ETC_CONFIG="/etc0003f780:·6f67·2046·696c·6573·2041·7265·204f·776e··og·Files·Are·Own
0003f790:·2f72·7379·736c·6f67·2e63·6f6e·6622·0a23··/rsyslog.conf".#0003f790:·6564·2042·7920·4170·7072·6f70·7269·6174··ed·By·Appropriat
0003f7a0:·202a·2041·6e64·2061·6c73·6f20·7468·6520···*·And·also·the·0003f7a0:·6520·4772·6f75·7020·2d20·5365·7420·7273··e·Group·-·Set·rs
0003f7b0:·6c6f·6720·6669·6c65·2070·6174·6873·206c··log·file·paths·l0003f7b0:·7973·6c6f·6720·6c6f·6766·696c·6520·636f··yslog·logfile·co
0003f7c0:·6973·7465·6420·6166·7465·7220·7273·7973··isted·after·rsys0003f7c0:·6e66·6967·7572·6174·696f·6e0a·2020·2020··nfiguration.····
0003f7d0:·6c6f·6727·7320·2449·6e63·6c75·6465·436f··log's·$IncludeCo0003f7d0:·6661·6374·730a·2020·616e·7369·626c·652e··facts.··ansible.
0003f7e0:·6e66·6967·2064·6972·6563·7469·7665·0a23··nfig·directive.#0003f7e0:·6275·696c·7469·6e2e·7365·745f·6661·6374··builtin.set_fact
0003f7f0:·2020·2028·7374·6f72·6520·7468·6520·7265·····(store·the·re0003f7f0:·3a0a·2020·2020·7273·7973·6c6f·675f·6574··:.····rsyslog_et
0003f800:·7375·6c74·2069·6e74·6f20·6172·7261·7920··sult·into·array·0003f800:·635f·636f·6e66·6967·3a20·2f65·7463·2f72··c_config:·/etc/r
0003f810:·666f·7220·7468·6520·6361·7365·2074·6865··for·the·case·the0003f810:·7379·736c·6f67·2e63·6f6e·660a·2020·7768··syslog.conf.··wh
0003f820:·7265·2773·2073·6865·6c6c·2067·6c6f·6220··re's·shell·glob·0003f820:·656e·3a20·616e·7369·626c·655f·7669·7274··en:·ansible_virt
0003f830:·7573·6564·2061·7320·7661·6c75·6520·6f66··used·as·value·of0003f830:·7561·6c69·7a61·7469·6f6e·5f74·7970·6520··ualization_type·
0003f840:·2049·6e63·6c75·6465·436f·6e66·6967·290a···IncludeConfig).0003f840:·6e6f·7420·696e·205b·2264·6f63·6b65·7222··not·in·["docker"
0003f850:·7265·6164·6172·7261·7920·2d74·204f·4c44··readarray·-t·OLD0003f850:·2c20·226c·7863·222c·2022·6f70·656e·767a··,·"lxc",·"openvz
0003f860:·5f49·4e43·2026·6c74·3b20·266c·743b·2867··_INC·&lt;·&lt;(g0003f860:·222c·2022·706f·646d·616e·222c·2022·636f··",·"podman",·"co
0003f870:·7265·7020·2d65·2022·5c24·496e·636c·7564··rep·-e·"\$Includ0003f870:·6e74·6169·6e65·7222·5d0a·2020·7461·6773··ntainer"].··tags
0003f880:·6543·6f6e·6669·675b·5b3a·7370·6163·653a··eConfig[[:space:0003f880:·3a0a·2020·2d20·4e49·5354·2d38·3030·2d35··:.··-·NIST-800-5
0003f890:·5d5d·5c2b·5b5e·5b3a·7370·6163·653a·5d3b··]]\+[^[:space:];0003f890:·332d·4143·2d36·2831·290a·2020·2d20·4e49··3-AC-6(1).··-·NI
0003f8a0:·5d5c·2b22·202f·6574·632f·7273·7973·6c6f··]\+"·/etc/rsyslo0003f8a0:·5354·2d38·3030·2d35·332d·434d·2d36·2861··ST-800-53-CM-6(a
0003f8b0:·672e·636f·6e66·207c·2063·7574·202d·6420··g.conf·|·cut·-d·0003f8b0:·290a·2020·2d20·5043·492d·4453·532d·5265··).··-·PCI-DSS-Re
0003f8c0:·2720·2720·2d66·2032·290a·7265·6164·6172··'·'·-f·2).readar0003f8c0:·712d·3130·2e35·2e31·0a20·202d·2050·4349··q-10.5.1.··-·PCI
0003f8d0:·7261·7920·2d74·2052·5359·534c·4f47·5f49··ray·-t·RSYSLOG_I0003f8d0:·2d44·5353·2d52·6571·2d31·302e·352e·320a··-DSS-Req-10.5.2.
0003f8e0:·4e43·4c55·4445·5f43·4f4e·4649·4720·266c··NCLUDE_CONFIG·&l0003f8e0:·2020·2d20·5043·492d·4453·5376·342d·3130····-·PCI-DSSv4-10
0003f8f0:·743b·2026·6c74·3b28·666f·7220·494e·4350··t;·&lt;(for·INCP0003f8f0:·2e33·2e32·0a20·202d·2063·6f6e·6669·6775··.3.2.··-·configu
0003f900:·4154·4820·696e·2022·247b·4f4c·445f·494e··ATH·in·"${OLD_IN0003f900:·7265·5f73·7472·6174·6567·790a·2020·2d20··re_strategy.··-·
0003f910:·435b·405d·7d22·3b20·646f·2065·7661·6c20··C[@]}";·do·eval·0003f910:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.·
0003f920:·7072·696e·7466·2027·2573·5c5c·6e27·2022··printf·'%s\\n'·"0003f920:·202d·206d·6564·6975·6d5f·6469·7372·7570···-·medium_disrup
0003f930:·247b·494e·4350·4154·487d·223b·2064·6f6e··${INCPATH}";·don0003f930:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_
0003f940:·6529·0a72·6561·6461·7272·6179·202d·7420··e).readarray·-t·0003f940:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_
0003f950:·4e45·575f·494e·4320·266c·743b·2026·6c74··NEW_INC·&lt;·&lt0003f950:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.··
0003f960:·3b28·7365·6420·2d6e·2027·2f5e·5c73·2a69··;(sed·-n·'/^\s*i0003f960:·2d20·7273·7973·6c6f·675f·6669·6c65·735f··-·rsyslog_files_
0003f970:·6e63·6c75·6465·282f·2c2f·292f·4970·2720··nclude(/,/)/Ip'·0003f970:·6772·6f75·706f·776e·6572·7368·6970·0a0a··groupownership..
0003f980:·2f65·7463·2f72·7379·736c·6f67·2e63·6f6e··/etc/rsyslog.con0003f980:·2d20·6e61·6d65·3a20·456e·7375·7265·204c··-·name:·Ensure·L
0003f990:·6620·7c20·7365·6420·2d6e·2027·7340·2e2a··f·|·sed·-n·'s@.*0003f990:·6f67·2046·696c·6573·2041·7265·204f·776e··og·Files·Are·Own
0003f9a0:·6669·6c65·5c73·2a3d·5c73·2a22·5c28·5b2f··file\s*=\s*"\([/0003f9a0:·6564·2042·7920·4170·7072·6f70·7269·6174··ed·By·Appropriat
0003f9b0:·5b3a·616c·6e75·6d3a·5d5b·3a70·756e·6374··[:alnum:][:punct0003f9b0:·6520·4772·6f75·7020·2d20·4765·7420·496e··e·Group·-·Get·In
0003f9c0:·3a5d·5d2a·5c29·222e·2a40·5c31·4049·7027··:]]*\)".*@\1@Ip'0003f9c0:·636c·7564·6543·6f6e·6669·6720·6469·7265··cludeConfig·dire
0003f9d0:·290a·7265·6164·6172·7261·7920·2d74·2052··).readarray·-t·R0003f9d0:·6374·6976·650a·2020·616e·7369·626c·652e··ctive.··ansible.
0003f9e0:·5359·534c·4f47·5f49·4e43·4c55·4445·2026··SYSLOG_INCLUDE·&0003f9e0:·6275·696c·7469·6e2e·7368·656c·6c3a·207c··builtin.shell:·|
0003f9f0:·6c74·3b20·266c·743b·2866·6f72·2049·4e43··lt;·&lt;(for·INC0003f9f0:·0a20·2020·2067·7265·7020·2d65·2027·2449··.····grep·-e·'$I
0003fa00:·5041·5448·2069·6e20·2224·7b4e·4557·5f49··PATH·in·"${NEW_I0003fa00:·6e63·6c75·6465·436f·6e66·6967·2720·7b7b··ncludeConfig'·{{
0003fa10:·4e43·5b40·5d7d·223b·2064·6f20·6576·616c··NC[@]}";·do·eval0003fa10:·2072·7379·736c·6f67·5f65·7463·5f63·6f6e···rsyslog_etc_con
0003fa20:·2070·7269·6e74·6620·2725·735c·5c6e·2720···printf·'%s\\n'·0003fa20:·6669·6720·7d7d·207c·2063·7574·202d·6420··fig·}}·|·cut·-d·
0003fa30:·2224·7b49·4e43·5041·5448·7d22·3b20·646f··"${INCPATH}";·do0003fa30:·2720·2720·2d66·2032·207c·7c20·7472·7565··'·'·-f·2·||·true
0003fa40:·6e65·290a·0a23·2044·6563·6c61·7265·2061··ne)..#·Declare·a0003fa40:·0a20·2072·6567·6973·7465·723a·2072·7379··.··register:·rsy
0003fa50:·6e20·6172·7261·7920·746f·2068·6f6c·6420··n·array·to·hold·0003fa50:·736c·6f67·5f6f·6c64·5f69·6e63·0a20·2063··slog_old_inc.··c
0003fa60:·7468·6520·6669·6e61·6c20·6c69·7374·206f··the·final·list·o0003fa60:·6861·6e67·6564·5f77·6865·6e3a·2066·616c··hanged_when:·fal
0003fa70:·6620·6469·6666·6572·656e·7420·6c6f·6720··f·different·log·0003fa70:·7365·0a20·2077·6865·6e3a·2061·6e73·6962··se.··when:·ansib
0003fa80:·6669·6c65·2070·6174·6873·0a64·6563·6c61··file·paths.decla0003fa80:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio
0003fa90:·7265·202d·6120·4c4f·475f·4649·4c45·5f50··re·-a·LOG_FILE_P0003fa90:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·["
0003faa0:·4154·4853·0a0a·2320·4172·7261·7920·746f··ATHS..#·Array·to0003faa0:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",·
0003fab0:·2068·6f6c·6420·616c·6c20·7273·7973·6c6f···hold·all·rsyslo0003fab0:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma
0003fac0:·6720·636f·6e66·6967·2065·6e74·7269·6573··g·config·entries0003fac0:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"]
0003fad0:·0a52·5359·534c·4f47·5f43·4f4e·4649·4753··.RSYSLOG_CONFIGS0003fad0:·0a20·2074·6167·733a·0a20·202d·204e·4953··.··tags:.··-·NIS
0003fae0:·3d28·290a·5253·5953·4c4f·475f·434f·4e46··=().RSYSLOG_CONF0003fae0:·542d·3830·302d·3533·2d41·432d·3628·3129··T-800-53-AC-6(1)
0003faf0:·4947·533d·2822·247b·5253·5953·4c4f·475f··IGS=("${RSYSLOG_0003faf0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
0003fb00:·4554·435f·434f·4e46·4947·7d22·2022·247b··ETC_CONFIG}"·"${0003fb00:·2d43·4d2d·3628·6129·0a20·202d·2050·4349··-CM-6(a).··-·PCI
0003fb10:·5253·5953·4c4f·475f·494e·434c·5544·455f··RSYSLOG_INCLUDE_0003fb10:·2d44·5353·2d52·6571·2d31·302e·352e·310a··-DSS-Req-10.5.1.
0003fb20:·434f·4e46·4947·5b40·5d7d·2220·2224·7b52··CONFIG[@]}"·"${R0003fb20:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req-
0003fb30:·5359·534c·4f47·5f49·4e43·4c55·4445·5b40··SYSLOG_INCLUDE[@0003fb30:·3130·2e35·2e32·0a20·202d·2050·4349·2d44··10.5.2.··-·PCI-D
0003fb40:·5d7d·2229·0a0a·2320·4765·7420·6675·6c6c··]}")..#·Get·full0003fb40:·5353·7634·2d31·302e·332e·320a·2020·2d20··SSv4-10.3.2.··-·
0003fb50:·206c·6973·7420·6f66·2066·696c·6573·2074···list·of·files·t0003fb50:·636f·6e66·6967·7572·655f·7374·7261·7465··configure_strate
0003fb60:·6f20·6265·2063·6865·636b·6564·0a23·2052··o·be·checked.#·R0003fb60:·6779·0a20·202d·206c·6f77·5f63·6f6d·706c··gy.··-·low_compl
0003fb70:·5359·534c·4f47·5f43·4f4e·4649·4753·206d··SYSLOG_CONFIGS·m0003fb70:·6578·6974·790a·2020·2d20·6d65·6469·756d··exity.··-·medium
0003fb80:·6179·2063·6f6e·7461·696e·2067·6c6f·6273··ay·contain·globs0003fb80:·5f64·6973·7275·7074·696f·6e0a·2020·2d20··_disruption.··-·
0003fb90:·2073·7563·6820·6173·0a23·202f·6574·632f···such·as.#·/etc/0003fb90:·6d65·6469·756d·5f73·6576·6572·6974·790a··medium_severity.
0003fba0:·7273·7973·6c6f·672e·642f·2a2e·636f·6e66··rsyslog.d/*.conf0003fba0:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne
0003fbb0:·202f·6574·632f·7273·7973·6c6f·672e·642f···/etc/rsyslog.d/0003fbb0:·6564·6564·0a20·202d·2072·7379·736c·6f67··eded.··-·rsyslog
0003fbc0:·2a2e·6672·756c·650a·2320·536f·2c20·6c6f··*.frule.#·So,·lo0003fbc0:·5f66·696c·6573·5f67·726f·7570·6f77·6e65··_files_groupowne
0003fbd0:·6f70·206f·7665·7220·7468·6520·656e·7472··op·over·the·entr0003fbd0:·7273·6869·700a·0a2d·206e·616d·653a·2045··rship..-·name:·E
0003fbe0:·6965·7320·696e·2052·5359·534c·4f47·5f43··ies·in·RSYSLOG_C0003fbe0:·6e73·7572·6520·4c6f·6720·4669·6c65·7320··nsure·Log·Files·
0003fbf0:·4f4e·4649·4753·2061·6e64·2075·7365·2066··ONFIGS·and·use·f0003fbf0:·4172·6520·4f77·6e65·6420·4279·2041·7070··Are·Owned·By·App
0003fc00:·696e·6420·746f·2067·6574·2074·6865·206c··ind·to·get·the·l0003fc00:·726f·7072·6961·7465·2047·726f·7570·202d··ropriate·Group·-
0003fc10:·6973·7420·6f66·2069·6e63·6c75·6465·6420··ist·of·included·0003fc10:·2047·6574·2069·6e63·6c75·6465·2066·696c···Get·include·fil
0003fc20:·6669·6c65·732e·0a52·5359·534c·4f47·5f43··files..RSYSLOG_C0003fc20:·6573·2064·6972·6563·7469·7665·730a·2020··es·directives.··
0003fc30:·4f4e·4649·475f·4649·4c45·533d·2829·0a66··ONFIG_FILES=().f0003fc30:·616e·7369·626c·652e·6275·696c·7469·6e2e··ansible.builtin.
0003fc40:·6f72·2045·4e54·5259·2069·6e20·2224·7b52··or·ENTRY·in·"${R0003fc40:·7368·656c·6c3a·207c·0a20·2020·2061·776b··shell:·|.····awk
0003fc50:·5359·534c·4f47·5f43·4f4e·4649·4753·5b40··SYSLOG_CONFIGS[@0003fc50:·2027·2f29·2f7b·663d·307d·202f·696e·636c···'/)/{f=0}·/incl
0003fc60:·5d7d·220a·646f·0a09·2320·4966·2064·6972··]}".do..#·If·dir0003fc60:·7564·655c·282f·7b66·3d31·7d20·667b·206e··ude\(/{f=1}·f{·n
0003fc70:·6563·746f·7279·2c20·7273·7973·6c6f·6720··ectory,·rsyslog·0003fc70:·663d·6765·6e73·7562·2822·5e28·696e·636c··f=gensub("^(incl
0003fc80:·7769·6c6c·2073·6561·7263·6820·666f·7220··will·search·for·0003fc80:·7564·655c·5c28·7c5c·5c73·2a29·6669·6c65··ude\\(|\\s*)file
Max diff block lines reached; 867640/968986 bytes (89.54%) of diff not shown.
117 KB
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Debian·1239 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Debian·12
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard
41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
42 ····*·cpe:/o:debian:debian_linux:1242 ····*·cpe:/o:debian:debian_linux:12
43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
44 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8444 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
49 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g49 ·········2.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
50 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s50 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
51 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s51 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
52 ·········1.·_\x8C_\x8r_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8t_\x8·_\x8D_\x8a_\x8e_\x8m_\x8o_\x8n_\x8s52 ·········1.·_\x8C_\x8r_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8t_\x8·_\x8D_\x8a_\x8e_\x8m_\x8o_\x8n_\x8s
Offset 258, 139 lines modifiedOffset 258, 14 lines modified
258 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-007-3·R2.1,·CIP-007-3·R2.2,·CIP-007-3·R2.3,·CIP-258 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-007-3·R2.1,·CIP-007-3·R2.2,·CIP-007-3·R2.3,·CIP-
259 ···························007-3·R5.1,·CIP-007-3·R5.1.1,·CIP-007-3·R5.1.2259 ···························007-3·R5.1,·CIP-007-3·R5.1.1,·CIP-007-3·R5.1.2
260 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)260 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)
261 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5261 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5
262 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.5.1,·Req-10.5.2262 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.5.1,·Req-10.5.2
263 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71263 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71
264 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.3.2264 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.3.2
265 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
266 #·Remediation·is·applicable·only·in·certain·platforms 
267 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
268 #·List·of·log·file·paths·to·be·inspected·for·correct·permissions 
269 #·*·Primarily·inspect·log·file·paths·listed·in·/etc/rsyslog.conf 
270 RSYSLOG_ETC_CONFIG="/etc/rsyslog.conf" 
271 #·*·And·also·the·log·file·paths·listed·after·rsyslog's·$IncludeConfig·directive 
272 #···(store·the·result·into·array·for·the·case·there's·shell·glob·used·as·value 
273 of·IncludeConfig) 
274 readarray·-t·OLD_INC·<·<(grep·-e·"\$IncludeConfig[[:space:]]\+[^[:space:];]\+" 
275 /etc/rsyslog.conf·|·cut·-d·'·'·-f·2) 
276 readarray·-t·RSYSLOG_INCLUDE_CONFIG·<·<(for·INCPATH·in·"${OLD_INC[@]}";·do·eval 
277 printf·'%s\\n'·"${INCPATH}";·done) 
278 readarray·-t·NEW_INC·<·<(sed·-n·'/^\s*include(/,/)/Ip'·/etc/rsyslog.conf·|·sed 
279 -n·'s@.*file\s*=\s*"\([/[:alnum:][:punct:]]*\)".*@\1@Ip') 
280 readarray·-t·RSYSLOG_INCLUDE·<·<(for·INCPATH·in·"${NEW_INC[@]}";·do·eval·printf 
281 '%s\\n'·"${INCPATH}";·done) 
  
282 #·Declare·an·array·to·hold·the·final·list·of·different·log·file·paths 
283 declare·-a·LOG_FILE_PATHS 
  
284 #·Array·to·hold·all·rsyslog·config·entries 
285 RSYSLOG_CONFIGS=() 
286 RSYSLOG_CONFIGS=("${RSYSLOG_ETC_CONFIG}"·"${RSYSLOG_INCLUDE_CONFIG[@]}"·"$ 
287 {RSYSLOG_INCLUDE[@]}") 
  
288 #·Get·full·list·of·files·to·be·checked 
289 #·RSYSLOG_CONFIGS·may·contain·globs·such·as 
290 #·/etc/rsyslog.d/*.conf·/etc/rsyslog.d/*.frule 
291 #·So,·loop·over·the·entries·in·RSYSLOG_CONFIGS·and·use·find·to·get·the·list·of 
292 included·files. 
293 RSYSLOG_CONFIG_FILES=() 
294 for·ENTRY·in·"${RSYSLOG_CONFIGS[@]}" 
295 do 
296 »       #·If·directory,·rsyslog·will·search·for·config·files·in·recursively. 
297 »       #·However,·files·in·hidden·sub-directories·or·hidden·files·will·be·ignored. 
298 »       if·[·-d·"${ENTRY}"·] 
299 »       then 
300 »       »       readarray·-t·FINDOUT·<·<(find·"${ENTRY}"·-not·-path·'*/.*'·-type·f) 
301 »       »       RSYSLOG_CONFIG_FILES+=("${FINDOUT[@]}") 
302 »       elif·[·-f·"${ENTRY}"·] 
303 »       then 
304 »       »       RSYSLOG_CONFIG_FILES+=("${ENTRY}") 
305 »       else 
306 »       »       echo·"Invalid·include·object:·${ENTRY}" 
307 »       fi 
308 done 
  
309 #·Browse·each·file·selected·above·as·containing·paths·of·log·files 
310 #·('/etc/rsyslog.conf'·and·'/etc/rsyslog.d/*.conf'·in·the·default 
311 configuration) 
312 for·LOG_FILE·in·"${RSYSLOG_CONFIG_FILES[@]}" 
313 do 
314 »       #·From·each·of·these·files·extract·just·particular·log·file·path(s),·thus: 
315 »       #·*·Ignore·lines·starting·with·space·('·'),·comment·('#"),·or·variable·syntax 
316 ('$')·characters, 
317 »       #·*·Ignore·empty·lines, 
318 »       #·*·Strip·quotes·and·closing·brackets·from·paths. 
319 »       #·*·Ignore·paths·that·match·/dev|/etc.*\.conf,·as·those·are·paths,·but·likely 
320 not·log·files 
321 »       #·*·From·the·remaining·valid·rows·select·only·fields·constituting·a·log·file 
322 path 
323 »       #·Text·file·column·is·understood·to·represent·a·log·file·path·if·and·only·if 
324 all·of·the 
325 »       #·following·are·met: 
326 »       #·*·it·contains·at·least·one·slash·'/'·character, 
327 »       #·*·it·is·preceded·by·space 
328 »       #·*·it·doesn't·contain·space·('·'),·colon·(':'),·and·semicolon·(';') 
329 characters 
330 »       #·Search·log·file·for·path(s)·only·in·case·it·exists! 
331 »       if·[[·-f·"${LOG_FILE}"·]] 
332 »       then 
333 »       »       NORMALIZED_CONFIG_FILE_LINES=$(sed·-e·"/^[#|$]/d"·"${LOG_FILE}") 
334 »       »       LINES_WITH_PATHS=$(grep·'[^/]*\s\+\S*/\S\+$'·<<<·"$ 
335 {NORMALIZED_CONFIG_FILE_LINES}") 
336 »       »       FILTERED_PATHS=$(awk·'{if(NF>=2&&($NF~/^\//||$NF~/^-\//)){sub(/^-\//,"/ 
337 ",$NF);print·$NF}}'·<<<·"${LINES_WITH_PATHS}") 
338 »       »       CLEANED_PATHS=$(sed·-e·"s/[\"')]//g;·/\\/etc.*\.conf/d;·/\\/dev\\//d"·<<<·"$ 
339 {FILTERED_PATHS}") 
340 »       »       MATCHED_ITEMS=$(sed·-e·"/^$/d"·<<<·"${CLEANED_PATHS}") 
341 »       »       #·Since·above·sed·command·might·return·more·than·one·item·(delimited·by 
342 newline),·split 
343 »       »       #·the·particular·matches·entries·into·new·array·specific·for·this·log·file 
344 »       »       readarray·-t·ARRAY_FOR_LOG_FILE·<<<·"$MATCHED_ITEMS" 
345 »       »       #·Concatenate·the·two·arrays·-·previous·content·of·$LOG_FILE_PATHS·array·with 
346 »       »       #·items·from·newly·created·array·for·this·log·file 
347 »       »       LOG_FILE_PATHS+=("${ARRAY_FOR_LOG_FILE[@]}") 
348 »       »       #·Delete·the·temporary·array 
349 »       »       unset·ARRAY_FOR_LOG_FILE 
350 »       fi 
351 done 
  
352 #·Check·for·RainerScript·action·log·format·which·might·be·also·multiline·so 
353 grep·regex·is·a·bit 
354 #·curly: 
355 #·extract·possibly·multiline·action·omfile·expressions 
356 #·extract·File="logfile"·expression 
357 #·match·only·"logfile"·expression 
358 for·LOG_FILE·in·"${RSYSLOG_CONFIG_FILES[@]}" 
359 do 
360 »       ACTION_OMFILE_LINES=$(grep·-iozP·"action\s*\(\s*type\s*=\s*\"omfile\"[^\)]*\)" 
361 "${LOG_FILE}") 
362 »       OMFILE_LINES=$(echo·"${ACTION_OMFILE_LINES}"|·grep·-iaoP·"\bFile\s*=\s*\"([/[: 
Max diff block lines reached; 113281/119851 bytes (94.52%) of diff not shown.
2.98 MB
./usr/share/xml/scap/ssg/content/ssg-debian11-ds.xml
2.98 MB
./usr/share/xml/scap/ssg/content/ssg-debian11-ds.xml
Max HTML report size reached
702 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ocil.xml
702 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ocil.xml
Ordering differences only
    
Offset 3, 2603 lines modifiedOffset 3, 2603 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
 10 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1">
 11 ······<ocil:title>Configure·auditd·space_left·Action·on·Low·Disk·Space</ocil:title>
10 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_syslog_ocil:questionnaire:1"> 
11 ······<ocil:title>Verify·Group·Who·Owns·/var/log/syslog·File</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_syslog_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_ocil:questionnaire:1"> 
17 ······<ocil:title>Configure·Sending·and·Accepting·Shared·Media·Redirects·for·All·IPv4·Interfaces</ocil:title> 
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-grub2_slab_nomerge_argument_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-snmpd_not_default_password_ocil:questionnaire:1">
23 ······<ocil:title>Disable·merging·of·slabs·with·similar·size</ocil:title>17 ······<ocil:title>Ensure·Default·SNMP·Password·Is·Not·Used</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-grub2_slab_nomerge_argument_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-snmpd_not_default_password_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-package_postfix_installed_ocil:questionnaire:1"> 
29 ······<ocil:title>The·Postfix·package·is·installed</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-dir_perms_world_writable_sticky_bits_ocil:questionnaire:1">
 23 ······<ocil:title>Verify·that·All·World-Writable·Directories·Have·Sticky·Bits·Set</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-package_postfix_installed_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-dir_perms_world_writable_sticky_bits_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-directory_permissions_var_log_audit_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1">
35 ······<ocil:title>System·Audit·Logs·Must·Have·Mode·0750·or·Less·Permissive</ocil:title>29 ······<ocil:title>Configure·Speculative·Store·Bypass·Mitigation</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-directory_permissions_var_log_audit_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-auditd_log_format_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_login_events_faillock_ocil:questionnaire:1">
41 ······<ocil:title>Resolve·information·before·writing·to·audit·logs</ocil:title>35 ······<ocil:title>Record·Attempts·to·Alter·Logon·and·Logout·Events·-·faillock</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-auditd_log_format_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_login_events_faillock_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_init_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-package_cron_installed_ocil:questionnaire:1">
47 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·init</ocil:title>41 ······<ocil:title>Install·the·cron·service</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_init_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-package_cron_installed_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_ocil:questionnaire:1"> 
53 ······<ocil:title>Verify·Group·Who·Owns·/var/log·Directory</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_ocil:questionnaire:1">
 47 ······<ocil:title>Ensure·Rsyslog·Encrypts·Off-Loaded·Audit·Records</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sudo_custom_logfile_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_default_mmap_min_addr_ocil:questionnaire:1">
59 ······<ocil:title>Ensure·Sudo·Logfile·Exists·-·sudo·logfile</ocil:title>53 ······<ocil:title>Configure·Low·Address·Space·To·Protect·From·User·Allocation</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sudo_custom_logfile_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-kernel_config_default_mmap_min_addr_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_ocil:questionnaire:1">
65 ······<ocil:title>Disable·XDMCP·in·GDM</ocil:title>59 ······<ocil:title>Configure·auditd·Max·Log·File·Size</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_relayhost_ocil:questionnaire:1"> 
71 ······<ocil:title>Configure·System·to·Forward·All·Mail·through·a·specific·host</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-account_passwords_pam_faillock_audit_ocil:questionnaire:1">
 65 ······<ocil:title>Account·Lockouts·Must·Be·Logged</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_relayhost_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_audit_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_private_key_ocil:questionnaire:1"> 
77 ······<ocil:title>Verify·Ownership·on·SSH·Server·Private·*_key·Key·Files</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_dmesg_restrict_ocil:questionnaire:1">
 71 ······<ocil:title>Restrict·unprivileged·access·to·the·kernel·syslog</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_private_key_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_dmesg_restrict_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_action_mail_acct_ocil:questionnaire:1"> 
83 ······<ocil:title>Configure·auditd·mail_acct·Action·on·Low·Disk·Space</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">
 77 ······<ocil:title>Disable·XDMCP·in·GDM</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_action_mail_acct_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_compression_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ocil:questionnaire:1">
89 ······<ocil:title>Disable·Compression·Or·Set·Compression·to·delayed</ocil:title>83 ······<ocil:title>Ensure·auditd·Collects·Unauthorized·Access·Attempts·to·Files·(unsuccessful)</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_compression_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-service_syslogng_enabled_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-service_iptables_enabled_ocil:questionnaire:1">
95 ······<ocil:title>Enable·syslog-ng·Service</ocil:title>89 ······<ocil:title>Verify·iptables·Enabled</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-service_syslogng_enabled_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-service_iptables_enabled_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmodat_ocil:questionnaire:1"> 
101 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmodat</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_binfmt_misc_ocil:questionnaire:1">
 95 ······<ocil:title>Disable·kernel·support·for·MISC·binaries</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmodat_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-kernel_config_binfmt_misc_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_postmaster_ocil:questionnaire:1"> 
107 ······<ocil:title>Configure·System·to·Forward·All·Mail·From·Postmaster·to·The·Root·Account</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdrivermode_ocil:questionnaire:1">
 101 ······<ocil:title>Ensure·Rsyslog·Encrypts·Off-Loaded·Audit·Records</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_postmaster_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdrivermode_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_creat_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_full_action_ocil:questionnaire:1">
113 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·creat</ocil:title>107 ······<ocil:title>Configure·auditd·Disk·Full·Action·when·Disk·Space·Is·Full</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_creat_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_full_action_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-service_snmpd_disabled_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_pam_ocil:questionnaire:1">
119 ······<ocil:title>Disable·snmpd·Service</ocil:title>113 ······<ocil:title>Enable·PAM</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
Max diff block lines reached; 705996/718343 bytes (98.28%) of diff not shown.
2.19 MB
./usr/share/xml/scap/ssg/content/ssg-debian11-xccdf.xml
2.19 MB
./usr/share/xml/scap/ssg/content/ssg-debian11-xccdf.xml
Max HTML report size reached
4.32 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ds.xml
4.32 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ds.xml
Max HTML report size reached
1.14 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ocil.xml
1.14 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ocil.xml
Ordering differences only
    
Offset 3, 7121 lines modifiedOffset 3, 7121 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-directory_owner_etc_iptables_ocil:questionnaire:1"> 
11 ······<ocil:title>Verify·User·Who·Owns·/etc/iptables·Directory</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-directory_owner_etc_iptables_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_grub2_cfg_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-file_owner_systemmap_ocil:questionnaire:1">
 11 ······<ocil:title>Verify·User·Who·Owns·System.map·Files</ocil:title>
17 ······<ocil:title>Verify·/boot/grub/grub.cfg·Group·Ownership</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_grub2_cfg_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_efi_user_cfg_ocil:questionnaire:1"> 
23 ······<ocil:title>Verify·/boot/grub2/user.cfg·Group·Ownership</ocil:title> 
24 ······<ocil:actions>12 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_efi_user_cfg_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_owner_systemmap_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>14 ······</ocil:actions>
27 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_logindefs_ocil:questionnaire:1"> 
29 ······<ocil:title>Set·Password·Hashing·Algorithm·in·/etc/login.defs</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_syslog_ocil:questionnaire:1">
 17 ······<ocil:title>Verify·Group·Who·Owns·/var/log/syslog·File</ocil:title>
30 ······<ocil:actions>18 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_logindefs_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_syslog_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>20 ······</ocil:actions>
33 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_sysadmin_actions_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-grub2_page_poison_argument_ocil:questionnaire:1">
35 ······<ocil:title>Ensure·auditd·Collects·System·Administrator·Actions</ocil:title>23 ······<ocil:title>Enable·page·allocator·poisoning</ocil:title>
36 ······<ocil:actions>24 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_sysadmin_actions_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-grub2_page_poison_argument_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>26 ······</ocil:actions>
39 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1"> 
41 ······<ocil:title>Disallow·Configuration·to·Bypass·Password·Requirements·for·Privilege·Escalation</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_audit_configuration_ocil:questionnaire:1">
 29 ······<ocil:title>Audit·Configuration·Files·Permissions·are·640·or·More·Restrictive</ocil:title>
42 ······<ocil:actions>30 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-disallow_bypass_password_sudo_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_permissions_audit_configuration_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>32 ······</ocil:actions>
45 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minlen_ocil:questionnaire:1"> 
47 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Length</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_ocil:questionnaire:1">
 35 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·open_by_handle_at</ocil:title>
48 ······<ocil:actions>36 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minlen_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>38 ······</ocil:actions>
51 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_var_tmp_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_rsa_ocil:questionnaire:1">
53 ······<ocil:title>Configure·Polyinstantiation·of·/var/tmp·Directories</ocil:title>41 ······<ocil:title>Disable·SSH·Support·for·Rhosts·RSA·Authentication</ocil:title>
54 ······<ocil:actions>42 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_var_tmp_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_rsa_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>44 ······</ocil:actions>
57 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-no_rsh_trust_files_ocil:questionnaire:1"> 
59 ······<ocil:title>Remove·Rsh·Trust·Files</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_ocil:questionnaire:1">
 47 ······<ocil:title>Configure·Accepting·Prefix·Information·in·Router·Advertisements·on·All·IPv6·Interfaces·By·Default</ocil:title>
60 ······<ocil:actions>48 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-no_rsh_trust_files_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>50 ······</ocil:actions>
63 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_set_max_life_root_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-accounts_users_home_files_groupownership_ocil:questionnaire:1">
65 ······<ocil:title>Set·Root·Account·Password·Maximum·Age</ocil:title>53 ······<ocil:title>All·User·Files·and·Directories·In·The·Home·Directory·Must·Be·Group-Owned·By·The·Primary·Group</ocil:title>
66 ······<ocil:actions>54 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-accounts_password_set_max_life_root_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-accounts_users_home_files_groupownership_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>56 ······</ocil:actions>
69 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_var_log_audit_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">
71 ······<ocil:title>System·Audit·Logs·Must·Be·Owned·By·Root</ocil:title>59 ······<ocil:title>Disable·XDMCP·in·GDM</ocil:title>
72 ······<ocil:actions>60 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>62 ······</ocil:actions>
75 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-account_passwords_pam_faillock_dir_ocil:questionnaire:1">
77 ······<ocil:title>Verify·Group·Who·Owns·passwd·File</ocil:title>65 ······<ocil:title>Account·Lockouts·Must·Persist</ocil:title>
78 ······<ocil:actions>66 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_dir_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>68 ······</ocil:actions>
81 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_stackprotector_strong_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_ocil:questionnaire:1">
83 ······<ocil:title>Strong·Stack·Protector</ocil:title>71 ······<ocil:title>Enable·poison·of·pages·after·freeing</ocil:title>
84 ······<ocil:actions>72 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_stackprotector_strong_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>74 ······</ocil:actions>
87 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-mount_option_tmp_nosuid_ocil:questionnaire:1"> 
89 ······<ocil:title>Add·nosuid·Option·to·/tmp</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-package_rsyslog-gnutls_installed_ocil:questionnaire:1">
 77 ······<ocil:title>Ensure·rsyslog-gnutls·is·installed</ocil:title>
90 ······<ocil:actions>78 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-mount_option_tmp_nosuid_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-package_rsyslog-gnutls_installed_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>80 ······</ocil:actions>
93 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-dir_permissions_library_dirs_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
95 ······<ocil:title>Verify·that·Shared·Library·Directories·Have·Restrictive·Permissions</ocil:title>83 ······<ocil:title>Enable·systemd-journald·Service</ocil:title>
96 ······<ocil:actions>84 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-dir_permissions_library_dirs_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>86 ······</ocil:actions>
99 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_systemmap_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_unmap_kernel_at_el0_ocil:questionnaire:1">
101 ······<ocil:title>Verify·Group·Who·Owns·System.map·Files</ocil:title>89 ······<ocil:title>Unmap·kernel·when·running·in·userspace·(aka·KAISER)</ocil:title>
102 ······<ocil:actions>90 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_systemmap_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-kernel_config_unmap_kernel_at_el0_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>92 ······</ocil:actions>
105 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_umount2_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-grub2_enable_iommu_force_ocil:questionnaire:1">
107 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·umount2</ocil:title>95 ······<ocil:title>IOMMU·configuration·directive</ocil:title>
108 ······<ocil:actions>96 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_umount2_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-grub2_enable_iommu_force_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>98 ······</ocil:actions>
111 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-aide_verify_ext_attributes_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_noexec_ocil:questionnaire:1">
113 ······<ocil:title>Configure·AIDE·to·Verify·Extended·Attributes</ocil:title>101 ······<ocil:title>Add·noexec·Option·to·/var</ocil:title>
114 ······<ocil:actions>102 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-aide_verify_ext_attributes_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_noexec_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>104 ······</ocil:actions>
117 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_gssapi_auth_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_ocil:questionnaire:1">
119 ······<ocil:title>Enable·GSSAPI·Authentication</ocil:title>107 ······<ocil:title>Disable·IPv6·Addressing·on·All·IPv6·Interfaces</ocil:title>
120 ······<ocil:actions>108 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_gssapi_auth_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>110 ······</ocil:actions>
123 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
Max diff block lines reached; 1184030/1196344 bytes (98.97%) of diff not shown.
3.08 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-xccdf.xml
3.08 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-xccdf.xml
Max HTML report size reached
3.06 GB
ssg-nondebian_0.1.74-1_all.deb
452 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2024-11-02·18:39:34.000000·debian-binary1 -rw-r--r--···0········0········0········4·2024-11-02·18:39:34.000000·debian-binary
2 -rw-r--r--···0········0········0····16508·2024-11-02·18:39:34.000000·control.tar.xz2 -rw-r--r--···0········0········0····16516·2024-11-02·18:39:34.000000·control.tar.xz
3 -rw-r--r--···0········0········0·32344256·2024-11-02·18:39:34.000000·data.tar.xz3 -rw-r--r--···0········0········0·32359032·2024-11-02·18:39:34.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
3.06 GB
data.tar.xz
3.06 GB
data.tar
6.84 MB
./usr/share/doc/ssg-nondebian/ssg-al2023-guide-cis.html
    
Offset 14295, 15 lines modifiedOffset 14295, 15 lines modified
00037d60:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre00037d60:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre
00037d70:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str00037d70:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str
00037d80:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro00037d80:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro
00037d90:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><00037d90:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><
00037da0:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st00037da0:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st
00037db0:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········00037db0:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········
00037dc0:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of00037dc0:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of
00037dd0:·2032·3032·362d·3031·2d30·3829·0a20·2020···2026-01-08).···00037dd0:·2032·3032·342d·3132·2d30·3729·0a20·2020···2024-12-07).···
00037de0:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l00037de0:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l
00037df0:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h200037df0:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h2
00037e00:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten00037e00:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten
00037e10:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><00037e10:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><
00037e20:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o00037e20:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o
00037e30:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co00037e30:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co
00037e40:·6e74·656e·745f·6772·6f75·705f·7379·7374··ntent_group_syst00037e40:·6e74·656e·745f·6772·6f75·705f·7379·7374··ntent_group_syst
Offset 15143, 81 lines modifiedOffset 15143, 81 lines modified
0003b260:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b260:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003b270:·2223·6964·6d31·3332·3222·2074·6162·696e··"#idm1322"·tabin0003b270:·2223·6964·6d31·3332·3222·2074·6162·696e··"#idm1322"·tabin
0003b280:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b280:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b290:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b290:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b2a0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b2a0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b2b0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b2b0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b2c0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b2c0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b2d0:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans0003b2d0:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB
0003b2e0:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·... 
0003b2f0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b300:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b310:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b320:·2269·646d·3133·3232·223e·3c74·6162·6c65··"idm1322"><table 
0003b330:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003b340:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003b350:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003b360:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003b370:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003b380:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b390:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003b3a0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003b3b0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b3c0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003b3d0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003b3e0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003b3f0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003b2e0:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s
 0003b2f0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0003b300:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003b310:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003b320:·6c61·7073·6522·2069·643d·2269·646d·3133··lapse"·id="idm13
 0003b330:·3232·223e·3c70·7265·3e3c·636f·6465·3e0a··22"><pre><code>.
 0003b340:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam
 0003b350:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi
 0003b360:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code>
 0003b370:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003b380:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003b390:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003b3a0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0003b3b0:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
 0003b3c0:·3332·3322·2074·6162·696e·6465·783d·2230··323"·tabindex="0
 0003b3d0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0003b3e0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0003b3f0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0003b400:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0003b410:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003b420:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s
 0003b430:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0003b440:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003b450:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003b460:·6c61·7073·6522·2069·643d·2269·646d·3133··lapse"·id="idm13
 0003b470:·3233·223e·3c74·6162·6c65·2063·6c61·7373··23"><table·class
 0003b480:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003b490:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0003b4a0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003b4b0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003b4c0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003b4d0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b4e0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003b4f0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003b500:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b510:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0003b400:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003b520:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003b530:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003b540:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003b550:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 0003b560:·3e3c·7072·653e·3c63·6f64·653e·2d20·6e61··><pre><code>-·na
 0003b570:·6d65·3a20·456e·7375·7265·2061·6964·6520··me:·Ensure·aide·
 0003b580:·6973·2069·6e73·7461·6c6c·6564·0a20·2070··is·installed.··p
 0003b590:·6163·6b61·6765·3a0a·2020·2020·6e61·6d65··ackage:.····name
 0003b5a0:·3a20·6169·6465·0a20·2020·2073·7461·7465··:·aide.····state
 0003b5b0:·3a20·7072·6573·656e·740a·2020·7768·656e··:·present.··when
 0003b5c0:·3a20·616e·7369·626c·655f·7669·7274·7561··:·ansible_virtua
 0003b5d0:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no
 0003b5e0:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",·
 0003b5f0:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz",
 0003b600:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont
 0003b610:·6169·6e65·7222·5d0a·2020·7461·6773·3a0a··ainer"].··tags:.
 0003b620:·2020·2d20·434a·4953·2d35·2e31·302e·312e····-·CJIS-5.10.1.
 0003b630:·330a·2020·2d20·4e49·5354·2d38·3030·2d35··3.··-·NIST-800-5
 0003b640:·332d·434d·2d36·2861·290a·2020·2d20·5043··3-CM-6(a).··-·PC
 0003b650:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·
 0003b660:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.
 0003b670:·352e·320a·2020·2d20·656e·6162·6c65·5f73··5.2.··-·enable_s
 0003b680:·7472·6174·6567·790a·2020·2d20·6c6f·775f··trategy.··-·low_
 0003b690:·636f·6d70·6c65·7869·7479·0a20·202d·206c··complexity.··-·l
 0003b6a0:·6f77·5f64·6973·7275·7074·696f·6e0a·2020··ow_disruption.··
 0003b6b0:·2d20·6d65·6469·756d·5f73·6576·6572·6974··-·medium_severit
 0003b6c0:·790a·2020·2d20·6e6f·5f72·6562·6f6f·745f··y.··-·no_reboot_
 0003b6d0:·6e65·6564·6564·0a20·202d·2070·6163·6b61··needed.··-·packa
 0003b6e0:·6765·5f61·6964·655f·696e·7374·616c·6c65··ge_aide_installe
0003b410:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003b420:·653e·2d20·6e61·6d65·3a20·456e·7375·7265··e>-·name:·Ensure 
0003b430:·2061·6964·6520·6973·2069·6e73·7461·6c6c···aide·is·install 
0003b440:·6564·0a20·2070·6163·6b61·6765·3a0a·2020··ed.··package:.·· 
0003b450:·2020·6e61·6d65·3a20·6169·6465·0a20·2020····name:·aide.··· 
0003b460:·2073·7461·7465·3a20·7072·6573·656e·740a···state:·present. 
0003b470:·2020·7768·656e·3a20·616e·7369·626c·655f····when:·ansible_ 
0003b480:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t 
0003b490:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc 
0003b4a0:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op 
0003b4b0:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman", 
0003b4c0:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].·· 
0003b4d0:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-5 
0003b4e0:·2e31·302e·312e·330a·2020·2d20·4e49·5354··.10.1.3.··-·NIST 
0003b4f0:·2d38·3030·2d35·332d·434d·2d36·2861·290a··-800-53-CM-6(a). 
0003b500:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req- 
0003b510:·3131·2e35·0a20·202d·2050·4349·2d44·5353··11.5.··-·PCI-DSS 
0003b520:·7634·2d31·312e·352e·320a·2020·2d20·656e··v4-11.5.2.··-·en 
0003b530:·6162·6c65·5f73·7472·6174·6567·790a·2020··able_strategy.·· 
0003b540:·2d20·6c6f·775f·636f·6d70·6c65·7869·7479··-·low_complexity 
0003b550:·0a20·202d·206c·6f77·5f64·6973·7275·7074··.··-·low_disrupt 
Max diff block lines reached; 6449453/6460407 bytes (99.83%) of diff not shown.
696 KB
html2text {}
    
Offset 40, 15 lines modifiedOffset 40, 15 lines modified
40 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*40 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Amazon·Linux·2023·Benchmark·for·Level·2·-·Server41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Amazon·Linux·2023·Benchmark·for·Level·2·-·Server
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis
43 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*43 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
44 ····*·cpe:/o:amazon:amazon_linux:202344 ····*·cpe:/o:amazon:amazon_linux:2023
45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
46 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8446 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
50 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e50 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
51 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l51 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
52 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n52 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
53 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g53 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
54 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s54 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 134, 14 lines modifiedOffset 134, 19 lines modified
134 include·install_aide134 include·install_aide
  
135 class·install_aide·{135 class·install_aide·{
136 ··package·{·'aide':136 ··package·{·'aide':
137 ····ensure·=>·'installed',137 ····ensure·=>·'installed',
138 ··}138 ··}
139 }139 }
 140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 141 [[packages]]
 142 name·=·"aide"
 143 version·=·"*"
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low145 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low146 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false147 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable148 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
145 -·name:·Ensure·aide·is·installed149 -·name:·Ensure·aide·is·installed
146 ··package:150 ··package:
Offset 155, 19 lines modifiedOffset 160, 14 lines modified
155 ··-·PCI-DSSv4-11.5.2160 ··-·PCI-DSSv4-11.5.2
156 ··-·enable_strategy161 ··-·enable_strategy
157 ··-·low_complexity162 ··-·low_complexity
158 ··-·low_disruption163 ··-·low_disruption
159 ··-·medium_severity164 ··-·medium_severity
160 ··-·no_reboot_needed165 ··-·no_reboot_needed
161 ··-·package_aide_installed166 ··-·package_aide_installed
162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
163 [[packages]] 
164 name·=·"aide" 
165 version·=·"*" 
166 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*167 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
167 Run·the·following·command·to·generate·a·new·database:168 Run·the·following·command·to·generate·a·new·database:
168 $·sudo·/usr/sbin/aide·--init169 $·sudo·/usr/sbin/aide·--init
169 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,170 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,
170 the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a171 the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a
171 secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The172 secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The
172 newly-generated·database·can·be·installed·as·follows:173 newly-generated·database·can·be·installed·as·follows:
Offset 482, 33 lines modifiedOffset 482, 14 lines modified
482 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1482 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1
483 ············_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)483 ············_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)
484 References:·_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,484 References:·_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,
485 ·····················FCS_TLSC_EXT.1485 ·····················FCS_TLSC_EXT.1
486 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174486 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
487 ············_\x8c_\x8i_\x8s······1.9487 ············_\x8c_\x8i_\x8s······1.9
488 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7488 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7
489 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
490 var_system_crypto_policy='DEFAULT' 
  
  
491 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
492 rc=$? 
  
493 if·test·"$rc"·=·127;·then 
494 »       echo·"$stderr_of_call"·>&2 
495 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
496 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
497 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
498 »       false··#·end·with·an·error·code 
499 elif·test·"$rc"·!=·0;·then 
500 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
501 »       false··#·end·with·an·error·code 
502 fi 
503 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8489 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
504 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low490 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
505 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low491 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
506 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false492 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
507 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict493 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
508 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable494 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
509 ··set_fact:495 ··set_fact:
Offset 551, 14 lines modifiedOffset 532, 33 lines modified
551 ··-·PCI-DSSv4-2.2.7532 ··-·PCI-DSSv4-2.2.7
552 ··-·configure_crypto_policy533 ··-·configure_crypto_policy
553 ··-·high_severity534 ··-·high_severity
554 ··-·low_complexity535 ··-·low_complexity
555 ··-·low_disruption536 ··-·low_disruption
556 ··-·no_reboot_needed537 ··-·no_reboot_needed
557 ··-·restrict_strategy538 ··-·restrict_strategy
 539 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 540 var_system_crypto_policy='DEFAULT'
  
  
 541 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null)
 542 rc=$?
  
 543 if·test·"$rc"·=·127;·then
 544 »       echo·"$stderr_of_call"·>&2
 545 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2
 546 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2
 547 »       echo·"to·see·what·package·to·(re)install"·>&2
  
 548 »       false··#·end·with·an·error·code
 549 elif·test·"$rc"·!=·0;·then
 550 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
 551 »       false··#·end·with·an·error·code
 552 fi
558 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*553 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
559 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is554 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is
560 supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto555 supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto
561 Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or556 Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or
562 not·set·at·all·in·the·/etc/sysconfig/sshd.557 not·set·at·all·in·the·/etc/sysconfig/sshd.
563 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,558 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,
564 ············and·makes·system·configuration·more·fragmented.559 ············and·makes·system·configuration·more·fragmented.
Offset 569, 19 lines modifiedOffset 569, 14 lines modified
569 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1569 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1
570 ············_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13570 ············_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13
571 References:·_\x8o_\x8s_\x8p_\x8p·····FCS_SSH_EXT.1,·FCS_SSHS_EXT.1,·FCS_SSHC_EXT.1571 References:·_\x8o_\x8s_\x8p_\x8p·····FCS_SSH_EXT.1,·FCS_SSHS_EXT.1,·FCS_SSHC_EXT.1
Max diff block lines reached; 707049/713134 bytes (99.15%) of diff not shown.
5.71 MB
./usr/share/doc/ssg-nondebian/ssg-al2023-guide-cis_server_l1.html
    
Offset 14295, 16 lines modifiedOffset 14295, 16 lines modified
00037d60:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h00037d60:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h
00037d70:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver00037d70:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver
00037d80:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.00037d80:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.
00037d90:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p00037d90:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p
00037da0:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong00037da0:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong
00037db0:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.00037db0:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.
00037dc0:·2020·2020·2020·2020·2020·2020·2020·2020··················00037dc0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037dd0:·2020·2020·2861·7320·6f66·2032·3032·362d······(as·of·2026-00037dd0:·2020·2020·2861·7320·6f66·2032·3032·342d······(as·of·2024-
00037de0:·3031·2d30·3829·0a20·2020·2020·2020·2020··01-08).·········00037de0:·3132·2d30·3729·0a20·2020·2020·2020·2020··12-07).·········
00037df0:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul00037df0:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul
00037e00:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table00037e00:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table
00037e10:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h200037e10:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2
00037e20:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href00037e20:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href
00037e30:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg00037e30:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg
00037e40:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_00037e40:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
00037e50:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy00037e50:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy
Offset 15116, 80 lines modifiedOffset 15116, 80 lines modified
0003b0b0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b0b0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b0c0:·2369·646d·3133·3232·2220·7461·6269·6e64··#idm1322"·tabind0003b0c0:·2369·646d·3133·3232·2220·7461·6269·6e64··#idm1322"·tabind
0003b0d0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b0d0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b0e0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b0e0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b0f0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b0f0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b100:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b100:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b110:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b110:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b120:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi0003b120:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu
0003b130:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...< 
0003b140:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003b150:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003b160:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003b170:·6964·6d31·3332·3222·3e3c·7461·626c·6520··idm1322"><table· 
0003b180:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003b190:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003b1a0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003b1b0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003b1c0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003b1d0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b1e0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003b1f0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003b200:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003b210:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003b220:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003b230:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003b240:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003b130:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn
 0003b140:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0003b150:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003b160:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003b170:·6170·7365·2220·6964·3d22·6964·6d31·3332··apse"·id="idm132
 0003b180:·3222·3e3c·7072·653e·3c63·6f64·653e·0a5b··2"><pre><code>.[
 0003b190:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name
 0003b1a0:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio
 0003b1b0:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code><
 0003b1c0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003b1d0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003b1e0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003b1f0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003b200:·612d·7461·7267·6574·3d22·2369·646d·3133··a-target="#idm13
 0003b210:·3233·2220·7461·6269·6e64·6578·3d22·3022··23"·tabindex="0"
 0003b220:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003b230:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003b240:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003b250:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003b260:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003b270:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn
 0003b280:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0003b290:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003b2a0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003b2b0:·6170·7365·2220·6964·3d22·6964·6d31·3332··apse"·id="idm132
 0003b2c0:·3322·3e3c·7461·626c·6520·636c·6173·733d··3"><table·class=
 0003b2d0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003b2e0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0003b2f0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0003b300:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0003b310:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0003b320:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003b330:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003b340:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003b350:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
 0003b360:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
0003b250:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003b370:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 0003b380:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003b390:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003b3a0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003b3b0:·3c70·7265·3e3c·636f·6465·3e2d·206e·616d··<pre><code>-·nam
 0003b3c0:·653a·2045·6e73·7572·6520·6169·6465·2069··e:·Ensure·aide·i
 0003b3d0:·7320·696e·7374·616c·6c65·640a·2020·7061··s·installed.··pa
 0003b3e0:·636b·6167·653a·0a20·2020·206e·616d·653a··ckage:.····name:
 0003b3f0:·2061·6964·650a·2020·2020·7374·6174·653a···aide.····state:
 0003b400:·2070·7265·7365·6e74·0a20·2077·6865·6e3a···present.··when:
 0003b410:·2061·6e73·6962·6c65·5f76·6972·7475·616c···ansible_virtual
 0003b420:·697a·6174·696f·6e5f·7479·7065·206e·6f74··ization_type·not
 0003b430:·2069·6e20·5b22·646f·636b·6572·222c·2022···in·["docker",·"
 0003b440:·6c78·6322·2c20·226f·7065·6e76·7a22·2c20··lxc",·"openvz",·
 0003b450:·2270·6f64·6d61·6e22·2c20·2263·6f6e·7461··"podman",·"conta
 0003b460:·696e·6572·225d·0a20·2074·6167·733a·0a20··iner"].··tags:.·
 0003b470:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3
 0003b480:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
 0003b490:·2d43·4d2d·3628·6129·0a20·202d·2050·4349··-CM-6(a).··-·PCI
 0003b4a0:·2d44·5353·2d52·6571·2d31·312e·350a·2020··-DSS-Req-11.5.··
 0003b4b0:·2d20·5043·492d·4453·5376·342d·3131·2e35··-·PCI-DSSv4-11.5
 0003b4c0:·2e32·0a20·202d·2065·6e61·626c·655f·7374··.2.··-·enable_st
 0003b4d0:·7261·7465·6779·0a20·202d·206c·6f77·5f63··rategy.··-·low_c
 0003b4e0:·6f6d·706c·6578·6974·790a·2020·2d20·6c6f··omplexity.··-·lo
 0003b4f0:·775f·6469·7372·7570·7469·6f6e·0a20·202d··w_disruption.··-
 0003b500:·206d·6564·6975·6d5f·7365·7665·7269·7479···medium_severity
 0003b510:·0a20·202d·206e·6f5f·7265·626f·6f74·5f6e··.··-·no_reboot_n
 0003b520:·6565·6465·640a·2020·2d20·7061·636b·6167··eeded.··-·packag
 0003b530:·655f·6169·6465·5f69·6e73·7461·6c6c·6564··e_aide_installed
0003b260:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
0003b270:·3e2d·206e·616d·653a·2045·6e73·7572·6520··>-·name:·Ensure· 
0003b280:·6169·6465·2069·7320·696e·7374·616c·6c65··aide·is·installe 
0003b290:·640a·2020·7061·636b·6167·653a·0a20·2020··d.··package:.··· 
0003b2a0:·206e·616d·653a·2061·6964·650a·2020·2020···name:·aide.···· 
0003b2b0:·7374·6174·653a·2070·7265·7365·6e74·0a20··state:·present.· 
0003b2c0:·2077·6865·6e3a·2061·6e73·6962·6c65·5f76···when:·ansible_v 
0003b2d0:·6972·7475·616c·697a·6174·696f·6e5f·7479··irtualization_ty 
0003b2e0:·7065·206e·6f74·2069·6e20·5b22·646f·636b··pe·not·in·["dock 
0003b2f0:·6572·222c·2022·6c78·6322·2c20·226f·7065··er",·"lxc",·"ope 
0003b300:·6e76·7a22·2c20·2270·6f64·6d61·6e22·2c20··nvz",·"podman",· 
0003b310:·2263·6f6e·7461·696e·6572·225d·0a20·2074··"container"].··t 
0003b320:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5. 
0003b330:·3130·2e31·2e33·0a20·202d·204e·4953·542d··10.1.3.··-·NIST- 
0003b340:·3830·302d·3533·2d43·4d2d·3628·6129·0a20··800-53-CM-6(a).· 
0003b350:·202d·2050·4349·2d44·5353·2d52·6571·2d31···-·PCI-DSS-Req-1 
0003b360:·312e·350a·2020·2d20·5043·492d·4453·5376··1.5.··-·PCI-DSSv 
0003b370:·342d·3131·2e35·2e32·0a20·202d·2065·6e61··4-11.5.2.··-·ena 
0003b380:·626c·655f·7374·7261·7465·6779·0a20·202d··ble_strategy.··- 
0003b390:·206c·6f77·5f63·6f6d·706c·6578·6974·790a···low_complexity. 
Max diff block lines reached; 5385931/5396885 bytes (99.80%) of diff not shown.
579 KB
html2text {}
    
Offset 40, 15 lines modifiedOffset 40, 15 lines modified
40 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*40 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Amazon·Linux·2023·Benchmark·for·Level·1·-·Server41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Amazon·Linux·2023·Benchmark·for·Level·1·-·Server
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_server_l142 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_server_l1
43 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*43 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
44 ····*·cpe:/o:amazon:amazon_linux:202344 ····*·cpe:/o:amazon:amazon_linux:2023
45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
46 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8446 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
50 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e50 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
51 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l51 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
52 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n52 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
53 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g53 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
54 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s54 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 130, 14 lines modifiedOffset 130, 19 lines modified
130 include·install_aide130 include·install_aide
  
131 class·install_aide·{131 class·install_aide·{
132 ··package·{·'aide':132 ··package·{·'aide':
133 ····ensure·=>·'installed',133 ····ensure·=>·'installed',
134 ··}134 ··}
135 }135 }
 136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 137 [[packages]]
 138 name·=·"aide"
 139 version·=·"*"
136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
141 -·name:·Ensure·aide·is·installed145 -·name:·Ensure·aide·is·installed
142 ··package:146 ··package:
Offset 151, 19 lines modifiedOffset 156, 14 lines modified
151 ··-·PCI-DSSv4-11.5.2156 ··-·PCI-DSSv4-11.5.2
152 ··-·enable_strategy157 ··-·enable_strategy
153 ··-·low_complexity158 ··-·low_complexity
154 ··-·low_disruption159 ··-·low_disruption
155 ··-·medium_severity160 ··-·medium_severity
156 ··-·no_reboot_needed161 ··-·no_reboot_needed
157 ··-·package_aide_installed162 ··-·package_aide_installed
158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
159 [[packages]] 
160 name·=·"aide" 
161 version·=·"*" 
162 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*163 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
163 Run·the·following·command·to·generate·a·new·database:164 Run·the·following·command·to·generate·a·new·database:
164 $·sudo·/usr/sbin/aide·--init165 $·sudo·/usr/sbin/aide·--init
165 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,166 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,
166 the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a167 the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a
167 secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The168 secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The
168 newly-generated·database·can·be·installed·as·follows:169 newly-generated·database·can·be·installed·as·follows:
Offset 478, 33 lines modifiedOffset 478, 14 lines modified
478 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1478 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1
479 ············_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)479 ············_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)
480 References:·_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,480 References:·_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,
481 ·····················FCS_TLSC_EXT.1481 ·····················FCS_TLSC_EXT.1
482 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174482 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
483 ············_\x8c_\x8i_\x8s······1.9483 ············_\x8c_\x8i_\x8s······1.9
484 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7484 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7
485 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
486 var_system_crypto_policy='DEFAULT' 
  
  
487 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
488 rc=$? 
  
489 if·test·"$rc"·=·127;·then 
490 »       echo·"$stderr_of_call"·>&2 
491 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
492 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
493 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
494 »       false··#·end·with·an·error·code 
495 elif·test·"$rc"·!=·0;·then 
496 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
497 »       false··#·end·with·an·error·code 
498 fi 
499 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8485 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
500 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low486 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
501 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low487 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
502 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false488 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
503 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict489 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
504 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable490 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
505 ··set_fact:491 ··set_fact:
Offset 547, 14 lines modifiedOffset 528, 33 lines modified
547 ··-·PCI-DSSv4-2.2.7528 ··-·PCI-DSSv4-2.2.7
548 ··-·configure_crypto_policy529 ··-·configure_crypto_policy
549 ··-·high_severity530 ··-·high_severity
550 ··-·low_complexity531 ··-·low_complexity
551 ··-·low_disruption532 ··-·low_disruption
552 ··-·no_reboot_needed533 ··-·no_reboot_needed
553 ··-·restrict_strategy534 ··-·restrict_strategy
 535 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 536 var_system_crypto_policy='DEFAULT'
  
  
 537 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null)
 538 rc=$?
  
 539 if·test·"$rc"·=·127;·then
 540 »       echo·"$stderr_of_call"·>&2
 541 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2
 542 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2
 543 »       echo·"to·see·what·package·to·(re)install"·>&2
  
 544 »       false··#·end·with·an·error·code
 545 elif·test·"$rc"·!=·0;·then
 546 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
 547 »       false··#·end·with·an·error·code
 548 fi
554 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*549 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
555 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is550 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is
556 supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto551 supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto
557 Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or552 Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or
558 not·set·at·all·in·the·/etc/sysconfig/sshd.553 not·set·at·all·in·the·/etc/sysconfig/sshd.
559 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,554 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,
560 ············and·makes·system·configuration·more·fragmented.555 ············and·makes·system·configuration·more·fragmented.
Offset 565, 19 lines modifiedOffset 565, 14 lines modified
565 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1565 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1
566 ············_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13566 ············_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13
567 References:·_\x8o_\x8s_\x8p_\x8p·····FCS_SSH_EXT.1,·FCS_SSHS_EXT.1,·FCS_SSHC_EXT.1567 References:·_\x8o_\x8s_\x8p_\x8p·····FCS_SSH_EXT.1,·FCS_SSHS_EXT.1,·FCS_SSHC_EXT.1
Max diff block lines reached; 586787/592882 bytes (98.97%) of diff not shown.
2.54 MB
./usr/share/doc/ssg-nondebian/ssg-alinux2-guide-pci-dss.html
    
Offset 14294, 15 lines modifiedOffset 14294, 15 lines modified
00037d50:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr00037d50:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr
00037d60:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st00037d60:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st
00037d70:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str00037d70:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str
00037d80:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>00037d80:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>
00037d90:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s00037d90:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s
00037da0:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········00037da0:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········
00037db0:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o00037db0:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o
00037dc0:·6620·3230·3236·2d30·312d·3038·290a·2020··f·2026-01-08).··00037dc0:·6620·3230·3234·2d31·322d·3037·290a·2020··f·2024-12-07).··
00037dd0:·2020·2020·2020·2020·2020·2020·2020·3c2f················</00037dd0:·2020·2020·2020·2020·2020·2020·2020·3c2f················</
00037de0:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h00037de0:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h
00037df0:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte00037df0:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte
00037e00:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>00037e00:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>
00037e10:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_00037e10:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_
00037e20:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c00037e20:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c
00037e30:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys00037e30:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys
Offset 15506, 80 lines modifiedOffset 15506, 80 lines modified
0003c910:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm10003c910:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
0003c920:·3138·3722·2074·6162·696e·6465·783d·2230··187"·tabindex="00003c920:·3138·3722·2074·6162·696e·6465·783d·2230··187"·tabindex="0
0003c930:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003c930:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003c940:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003c940:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003c950:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003c950:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003c960:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003c960:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003c970:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003c970:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003c980:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s0003c980:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B
0003c990:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003c9a0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003c9b0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003c9c0:·6c61·7073·6522·2069·643d·2269·646d·3131··lapse"·id="idm11 
0003c9d0:·3837·223e·3c74·6162·6c65·2063·6c61·7373··87"><table·class 
0003c9e0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003c9f0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003ca00:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003ca10:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003ca20:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003ca30:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003ca40:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003ca50:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003ca60:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003ca70:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003ca80:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
0003ca90:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003caa0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0003c990:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet
 0003c9a0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003c9b0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003c9c0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003c9d0:·2069·643d·2269·646d·3131·3837·223e·3c70···id="idm1187"><p
 0003c9e0:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack
 0003c9f0:·6167·6573·5d5d·0a6e·616d·6520·3d20·2261··ages]].name·=·"a
 0003ca00:·6964·6522·0a76·6572·7369·6f6e·203d·2022··ide".version·=·"
 0003ca10:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre>
 0003ca20:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0003ca30:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0003ca40:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0003ca50:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 0003ca60:·6765·743d·2223·6964·6d31·3138·3822·2074··get="#idm1188"·t
 0003ca70:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 0003ca80:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 0003ca90:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 0003caa0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 0003cab0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 0003cac0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003cad0:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet
 0003cae0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003caf0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003cb00:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003cb10:·2069·643d·2269·646d·3131·3838·223e·3c74···id="idm1188"><t
 0003cb20:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003cb30:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0003cb40:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0003cb50:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003cb60:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0003cb70:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003cab0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003cb80:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003cb90:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0003cba0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003cbb0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0003cbc0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 0003cbd0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003cbe0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003cbf0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0003cc00:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003cc10:·3c63·6f64·653e·2d20·6e61·6d65·3a20·456e··<code>-·name:·En
 0003cc20:·7375·7265·2061·6964·6520·6973·2069·6e73··sure·aide·is·ins
0003cac0:·3e3c·7072·653e·3c63·6f64·653e·2d20·6e61··><pre><code>-·na 
0003cad0:·6d65·3a20·456e·7375·7265·2061·6964·6520··me:·Ensure·aide· 
0003cae0:·6973·2069·6e73·7461·6c6c·6564·0a20·2070··is·installed.··p 
0003caf0:·6163·6b61·6765·3a0a·2020·2020·6e61·6d65··ackage:.····name 
0003cb00:·3a20·6169·6465·0a20·2020·2073·7461·7465··:·aide.····state 
0003cb10:·3a20·7072·6573·656e·740a·2020·7768·656e··:·present.··when 
0003cb20:·3a20·616e·7369·626c·655f·7669·7274·7561··:·ansible_virtua 
0003cb30:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no 
0003cb40:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",· 
0003cb50:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz", 
0003cb60:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont 
0003cb70:·6169·6e65·7222·5d0a·2020·7461·6773·3a0a··ainer"].··tags:. 
0003cb80:·2020·2d20·434a·4953·2d35·2e31·302e·312e····-·CJIS-5.10.1. 
0003cb90:·330a·2020·2d20·4e49·5354·2d38·3030·2d35··3.··-·NIST-800-5 
0003cba0:·332d·434d·2d36·2861·290a·2020·2d20·5043··3-CM-6(a).··-·PC 
0003cbb0:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.· 
0003cbc0:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11. 
0003cbd0:·352e·320a·2020·2d20·656e·6162·6c65·5f73··5.2.··-·enable_s 
0003cbe0:·7472·6174·6567·790a·2020·2d20·6c6f·775f··trategy.··-·low_ 
0003cbf0:·636f·6d70·6c65·7869·7479·0a20·202d·206c··complexity.··-·l 
0003cc00:·6f77·5f64·6973·7275·7074·696f·6e0a·2020··ow_disruption.·· 
0003cc10:·2d20·6d65·6469·756d·5f73·6576·6572·6974··-·medium_severit 
0003cc20:·790a·2020·2d20·6e6f·5f72·6562·6f6f·745f··y.··-·no_reboot_ 
0003cc30:·6e65·6564·6564·0a20·202d·2070·6163·6b61··needed.··-·packa0003cc30:·7461·6c6c·6564·0a20·2070·6163·6b61·6765··talled.··package
0003cc40:·6765·5f61·6964·655f·696e·7374·616c·6c65··ge_aide_installe 
0003cc50:·640a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··d.</code></pre>< 
0003cc60:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003cc70:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003cc80:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003cc90:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003cca0:·6574·3d22·2369·646d·3131·3838·2220·7461··et="#idm1188"·ta 
0003ccb0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003ccc0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003ccd0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003cce0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003ccf0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003cd00:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003cd10:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
0003cd20:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
0003cd30:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003cd40:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003cd50:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003cd60:·6d31·3138·3822·3e3c·7072·653e·3c63·6f64··m1188"><pre><cod 
0003cd70:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]]. 
Max diff block lines reached; 2353137/2363953 bytes (99.54%) of diff not shown.
289 KB
html2text {}
    
Offset 39, 15 lines modifiedOffset 39, 15 lines modified
39 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*39 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v4.0·Control·Baseline·for·Alibaba·Cloud·Linux·240 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v4.0·Control·Baseline·for·Alibaba·Cloud·Linux·2
41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss
42 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*42 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
43 ····*·cpe:/o:alinux:alibaba_cloud_linux:243 ····*·cpe:/o:alinux:alibaba_cloud_linux:2
44 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*44 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
45 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8445 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
46 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)46 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
47 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
48 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s48 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
49 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e49 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
50 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l50 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
51 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n51 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
52 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g52 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
53 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s53 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 172, 14 lines modifiedOffset 172, 19 lines modified
172 include·install_aide172 include·install_aide
  
173 class·install_aide·{173 class·install_aide·{
174 ··package·{·'aide':174 ··package·{·'aide':
175 ····ensure·=>·'installed',175 ····ensure·=>·'installed',
176 ··}176 ··}
177 }177 }
 178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 179 [[packages]]
 180 name·=·"aide"
 181 version·=·"*"
178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
183 -·name:·Ensure·aide·is·installed187 -·name:·Ensure·aide·is·installed
184 ··package:188 ··package:
Offset 193, 19 lines modifiedOffset 198, 14 lines modified
193 ··-·PCI-DSSv4-11.5.2198 ··-·PCI-DSSv4-11.5.2
194 ··-·enable_strategy199 ··-·enable_strategy
195 ··-·low_complexity200 ··-·low_complexity
196 ··-·low_disruption201 ··-·low_disruption
197 ··-·medium_severity202 ··-·medium_severity
198 ··-·no_reboot_needed203 ··-·no_reboot_needed
199 ··-·package_aide_installed204 ··-·package_aide_installed
200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
201 [[packages]] 
202 name·=·"aide" 
203 version·=·"*" 
204 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*205 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
205 Run·the·following·command·to·generate·a·new·database:206 Run·the·following·command·to·generate·a·new·database:
206 $·sudo·/usr/sbin/aide·--init207 $·sudo·/usr/sbin/aide·--init
207 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the208 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
208 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these209 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
209 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their210 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
210 integrity.·The·newly-generated·database·can·be·installed·as·follows:211 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 506, 33 lines modifiedOffset 506, 14 lines modified
506 ············_\x8i_\x8s_\x8m······1446506 ············_\x8i_\x8s_\x8m······1446
507 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1507 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1
508 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)508 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)
509 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,509 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,
510 ·····················FCS_TLSC_EXT.1510 ·····················FCS_TLSC_EXT.1
511 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174511 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
512 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7512 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7
513 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
514 var_system_crypto_policy='DEFAULT' 
  
  
515 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
516 rc=$? 
  
517 if·test·"$rc"·=·127;·then 
518 »       echo·"$stderr_of_call"·>&2 
519 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
520 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
521 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
522 »       false··#·end·with·an·error·code 
523 elif·test·"$rc"·!=·0;·then 
524 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
525 »       false··#·end·with·an·error·code 
526 fi 
527 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8513 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
528 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low514 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
529 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low515 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
530 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false516 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
531 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict517 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
532 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable518 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
533 ··set_fact:519 ··set_fact:
Offset 575, 14 lines modifiedOffset 556, 33 lines modified
575 ··-·PCI-DSSv4-2.2.7556 ··-·PCI-DSSv4-2.2.7
576 ··-·configure_crypto_policy557 ··-·configure_crypto_policy
577 ··-·high_severity558 ··-·high_severity
578 ··-·low_complexity559 ··-·low_complexity
579 ··-·low_disruption560 ··-·low_disruption
580 ··-·no_reboot_needed561 ··-·no_reboot_needed
581 ··-·restrict_strategy562 ··-·restrict_strategy
 563 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 564 var_system_crypto_policy='DEFAULT'
  
  
 565 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null)
 566 rc=$?
  
 567 if·test·"$rc"·=·127;·then
 568 »       echo·"$stderr_of_call"·>&2
 569 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2
 570 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2
 571 »       echo·"to·see·what·package·to·(re)install"·>&2
  
 572 »       false··#·end·with·an·error·code
 573 elif·test·"$rc"·!=·0;·then
 574 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
 575 »       false··#·end·with·an·error·code
 576 fi
582 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*577 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
583 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is578 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is
584 supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that579 supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that
585 Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either580 Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either
586 commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.581 commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
587 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate582 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate
588 ············expectations,·and·makes·system·configuration·more·fragmented.583 ············expectations,·and·makes·system·configuration·more·fragmented.
Offset 593, 19 lines modifiedOffset 593, 14 lines modified
593 ·····················(ii)593 ·····················(ii)
594 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1594 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1
595 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13595 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13
Max diff block lines reached; 289379/295461 bytes (97.94%) of diff not shown.
341 KB
./usr/share/doc/ssg-nondebian/ssg-alinux2-guide-standard.html
    
Offset 14290, 15 lines modifiedOffset 14290, 15 lines modified
00037d10:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00037d10:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00037d20:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00037d20:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00037d30:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s00037d30:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00037d40:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00037d40:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00037d50:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00037d50:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00037d60:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00037d60:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00037d70:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00037d70:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00037d80:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).00037d80:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
00037d90:·2020·2020·2020·2020·2020·2020·2020·2020··················00037d90:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037da0:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00037da0:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00037db0:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00037db0:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00037dc0:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00037dc0:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00037dd0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00037dd0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00037de0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00037de0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00037df0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00037df0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
Offset 16651, 173 lines modifiedOffset 16651, 173 lines modified
000410a0:·6172·6765·743d·2223·6964·6d31·3435·3522··arget="#idm1455"000410a0:·6172·6765·743d·2223·6964·6d31·3435·3522··arget="#idm1455"
000410b0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro000410b0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
000410c0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria000410c0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
000410d0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false000410d0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
000410e0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat000410e0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
000410f0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre000410f0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
00041100:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati00041100:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 00041110:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp
 00041120:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 00041130:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 00041140:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 00041150:·6522·2069·643d·2269·646d·3134·3535·223e··e"·id="idm1455">
 00041160:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 00041170:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 00041180:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 00041190:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 000411a0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 000411b0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 000411c0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 000411d0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
00041110:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script· 
00041120:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
00041130:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
00041140:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
00041150:·6964·3d22·6964·6d31·3435·3522·3e3c·7072··id="idm1455"><pr 
00041160:·653e·3c63·6f64·653e·0a76·6172·5f73·7973··e><code>.var_sys 
00041170:·7465·6d5f·6372·7970·746f·5f70·6f6c·6963··tem_crypto_polic 
00041180:·793d·273c·6162·6272·2074·6974·6c65·3d22··y='<abbr·title=" 
00041190:·6672·6f6d·2042·656e·6368·6d61·726b·2f56··from·Benchmark/V 
000411a0:·616c·7565·3a20·7863·6364·665f·6f72·672e··alue:·xccdf_org. 
000411b0:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte 
000411c0:·6e74·5f76·616c·7565·5f76·6172·5f73·7973··nt_value_var_sys 
000411d0:·7465·6d5f·6372·7970·746f·5f70·6f6c·6963··tem_crypto_polic 
000411e0:·7922·3e44·4546·4155·4c54·3c2f·6162·6272··y">DEFAULT</abbr 
000411f0:·3e27·0a0a·0a73·7464·6572·725f·6f66·5f63··>'...stderr_of_c 
00041200:·616c·6c3d·2428·7570·6461·7465·2d63·7279··all=$(update-cry 
00041210:·7074·6f2d·706f·6c69·6369·6573·202d·2d73··pto-policies·--s 
00041220:·6574·2024·7b76·6172·5f73·7973·7465·6d5f··et·${var_system_ 
00041230:·6372·7970·746f·5f70·6f6c·6963·797d·2032··crypto_policy}·2 
00041240:·2667·743b·2661·6d70·3b31·2026·6774·3b20··&gt;&amp;1·&gt;· 
00041250:·2f64·6576·2f6e·756c·6c29·0a72·633d·243f··/dev/null).rc=$? 
00041260:·0a0a·6966·2074·6573·7420·2224·7263·2220··..if·test·"$rc"· 
00041270:·3d20·3132·373b·2074·6865·6e0a·0965·6368··=·127;·then..ech 
00041280:·6f20·2224·7374·6465·7272·5f6f·665f·6361··o·"$stderr_of_ca 
00041290:·6c6c·2220·2667·743b·2661·6d70·3b32·0a09··ll"·&gt;&amp;2.. 
000412a0:·6563·686f·2022·4d61·6b65·2073·7572·6520··echo·"Make·sure· 
000412b0:·7468·6174·2074·6865·2073·6372·6970·7420··that·the·script· 
000412c0:·6973·2069·6e73·7461·6c6c·6564·206f·6e20··is·installed·on· 
000412d0:·7468·6520·7265·6d65·6469·6174·6564·2073··the·remediated·s 
000412e0:·7973·7465·6d2e·2220·2667·743b·2661·6d70··ystem."·&gt;&amp 
000412f0:·3b32·0a09·6563·686f·2022·5365·6520·6f75··;2..echo·"See·ou 
00041300:·7470·7574·206f·6620·7468·6520·2764·6e66··tput·of·the·'dnf 
00041310:·2070·726f·7669·6465·7320·7570·6461·7465···provides·update 
00041320:·2d63·7279·7074·6f2d·706f·6c69·6369·6573··-crypto-policies 
00041330:·2720·636f·6d6d·616e·6422·2026·6774·3b26··'·command"·&gt;& 
00041340:·616d·703b·320a·0965·6368·6f20·2274·6f20··amp;2..echo·"to· 
00041350:·7365·6520·7768·6174·2070·6163·6b61·6765··see·what·package 
00041360:·2074·6f20·2872·6529·696e·7374·616c·6c22···to·(re)install" 
00041370:·2026·6774·3b26·616d·703b·320a·0a09·6661···&gt;&amp;2...fa 
00041380:·6c73·6520·2023·2065·6e64·2077·6974·6820··lse··#·end·with· 
00041390:·616e·2065·7272·6f72·2063·6f64·650a·656c··an·error·code.el 
000413a0:·6966·2074·6573·7420·2224·7263·2220·213d··if·test·"$rc"·!= 
000413b0:·2030·3b20·7468·656e·0a09·6563·686f·2022···0;·then..echo·" 
000413c0:·4572·726f·7220·696e·766f·6b69·6e67·2074··Error·invoking·t 
000413d0:·6865·2075·7064·6174·652d·6372·7970·746f··he·update-crypto 
000413e0:·2d70·6f6c·6963·6965·7320·7363·7269·7074··-policies·script 
000413f0:·3a20·2473·7464·6572·725f·6f66·5f63·616c··:·$stderr_of_cal 
00041400:·6c22·2026·6774·3b26·616d·703b·320a·0966··l"·&gt;&amp;2..f 
00041410:·616c·7365·2020·2320·656e·6420·7769·7468··alse··#·end·with 
00041420:·2061·6e20·6572·726f·7220·636f·6465·0a66···an·error·code.f 
00041430:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre>< 
00041440:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
00041450:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
00041460:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
00041470:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
00041480:·6574·3d22·2369·646d·3134·3537·2220·7461··et="#idm1457"·ta 
00041490:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
000414a0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
000414b0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
000414c0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
000414d0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
000414e0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
000414f0:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet· 
00041500:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
00041510:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
00041520:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
00041530:·6964·3d22·6964·6d31·3435·3722·3e3c·7461··id="idm1457"><ta 
00041540:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
00041550:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
00041560:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
00041570:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
00041580:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
00041590:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</000411e0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
000415a0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
000415b0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
000415c0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
000415d0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
000415e0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
000415f0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>000411f0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
00041600:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
00041610:·643e·7265·7374·7269·6374·3c2f·7464·3e3c··d>restrict</td>< 
00041620:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
00041630:·3e3c·636f·6465·3e2d·206e·616d·653a·2058··><code>-·name:·X 
00041640:·4343·4446·2056·616c·7565·2076·6172·5f73··CCDF·Value·var_s00041200:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
 00041210:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 00041220:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 00041230:·3e3c·7464·3e72·6573·7472·6963·743c·2f74··><td>restrict</t
 00041240:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 00041250:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name
 00041260:·3a20·5843·4344·4620·5661·6c75·6520·7661··:·XCCDF·Value·va
 00041270:·725f·7379·7374·656d·5f63·7279·7074·6f5f··r_system_crypto_
Max diff block lines reached; 295680/319332 bytes (92.59%) of diff not shown.
28.7 KB
html2text {}
    
Offset 39, 15 lines modifiedOffset 39, 15 lines modified
39 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*39 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Alibaba·Cloud·Linux·240 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Alibaba·Cloud·Linux·2
41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard
42 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*42 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
43 ····*·cpe:/o:alinux:alibaba_cloud_linux:243 ····*·cpe:/o:alinux:alibaba_cloud_linux:2
44 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*44 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
45 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8445 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
46 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)46 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
47 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
48 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s48 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
49 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e49 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
50 ·········2.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s50 ·········2.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
51 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s51 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
52 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s52 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
53 ·········1.·_\x8B_\x8a_\x8s_\x8e_\x8·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s53 ·········1.·_\x8B_\x8a_\x8s_\x8e_\x8·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
Offset 389, 34 lines modifiedOffset 389, 14 lines modified
389 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1389 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1
390 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)390 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)
391 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,391 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,
392 ·····················FCS_CKM.2,·FCS_TLSC_EXT.1392 ·····················FCS_CKM.2,·FCS_TLSC_EXT.1
393 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-393 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-
394 ·····················GPOS-00174394 ·····················GPOS-00174
395 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7395 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7
396 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
397 var_system_crypto_policy='DEFAULT' 
  
  
398 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/ 
399 null) 
400 rc=$? 
  
401 if·test·"$rc"·=·127;·then 
402 »       echo·"$stderr_of_call"·>&2 
403 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
404 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
405 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
406 »       false··#·end·with·an·error·code 
407 elif·test·"$rc"·!=·0;·then 
408 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
409 »       false··#·end·with·an·error·code 
410 fi 
411 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8396 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
412 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low397 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
413 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low398 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
414 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false399 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
415 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict400 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
416 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable401 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
417 ··set_fact:402 ··set_fact:
Offset 459, 14 lines modifiedOffset 439, 34 lines modified
459 ··-·PCI-DSSv4-2.2.7439 ··-·PCI-DSSv4-2.2.7
460 ··-·configure_crypto_policy440 ··-·configure_crypto_policy
461 ··-·high_severity441 ··-·high_severity
462 ··-·low_complexity442 ··-·low_complexity
463 ··-·low_disruption443 ··-·low_disruption
464 ··-·no_reboot_needed444 ··-·no_reboot_needed
465 ··-·restrict_strategy445 ··-·restrict_strategy
 446 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 447 var_system_crypto_policy='DEFAULT'
  
  
 448 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/
 449 null)
 450 rc=$?
  
 451 if·test·"$rc"·=·127;·then
 452 »       echo·"$stderr_of_call"·>&2
 453 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2
 454 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2
 455 »       echo·"to·see·what·package·to·(re)install"·>&2
  
 456 »       false··#·end·with·an·error·code
 457 elif·test·"$rc"·!=·0;·then
 458 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
 459 »       false··#·end·with·an·error·code
 460 fi
466 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·K\x8Ke\x8er\x8rb\x8be\x8er\x8ro\x8os\x8s·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*461 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·K\x8Ke\x8er\x8rb\x8be\x8er\x8ro\x8os\x8s·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
467 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many462 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many
468 packages.·Kerberos·is·supported·by·crypto·policy,·but·it's·configuration·may·be·set·up463 packages.·Kerberos·is·supported·by·crypto·policy,·but·it's·configuration·may·be·set·up
469 to·ignore·it.·To·check·that·Crypto·Policies·settings·for·Kerberos·are·configured464 to·ignore·it.·To·check·that·Crypto·Policies·settings·for·Kerberos·are·configured
470 correctly,·examine·that·there·is·a·symlink·at·/etc/krb5.conf.d/crypto-policies465 correctly,·examine·that·there·is·a·symlink·at·/etc/krb5.conf.d/crypto-policies
471 targeting·/etc/cypto-policies/back-ends/krb5.config.·If·the·symlink·exists,·Kerberos·is466 targeting·/etc/cypto-policies/back-ends/krb5.config.·If·the·symlink·exists,·Kerberos·is
472 configured·to·use·the·system-wide·crypto·policy·settings.467 configured·to·use·the·system-wide·crypto·policy·settings.
Offset 474, 22 lines modifiedOffset 474, 14 lines modified
474 ············expectations,·and·makes·system·configuration·more·fragmented.474 ············expectations,·and·makes·system·configuration·more·fragmented.
475 Severity: ··high475 Severity: ··high
476 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_kerberos_crypto_policy476 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_kerberos_crypto_policy
477 ············_\x8i_\x8s_\x8m······0418,·1055,·1402477 ············_\x8i_\x8s_\x8m······0418,·1055,·1402
478 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1478 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
479 ············_\x8n_\x8i_\x8s_\x8t·····SC-13,·SC-12(2),·SC-12(3)479 ············_\x8n_\x8i_\x8s_\x8t·····SC-13,·SC-12(2),·SC-12(3)
480 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000120-GPOS-00061480 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000120-GPOS-00061
481 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
482 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
483 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
484 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
485 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure 
  
486 rm·-f·/etc/krb5.conf.d/crypto-policies 
487 ln·-s·/etc/crypto-policies/back-ends/krb5.config·/etc/krb5.conf.d/crypto-policies 
488 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8481 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
489 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low482 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
490 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low483 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
491 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true484 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
492 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure485 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
493 -·name:·Configure·Kerberos·to·use·System·Crypto·Policy486 -·name:·Configure·Kerberos·to·use·System·Crypto·Policy
494 ··file:487 ··file:
Offset 502, 14 lines modifiedOffset 494, 22 lines modified
502 ··-·NIST-800-53-SC-13494 ··-·NIST-800-53-SC-13
503 ··-·configure_kerberos_crypto_policy495 ··-·configure_kerberos_crypto_policy
504 ··-·configure_strategy496 ··-·configure_strategy
505 ··-·high_severity497 ··-·high_severity
506 ··-·low_complexity498 ··-·low_complexity
507 ··-·low_disruption499 ··-·low_disruption
508 ··-·reboot_required500 ··-·reboot_required
 501 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 502 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 503 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 504 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 505 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
  
 506 rm·-f·/etc/krb5.conf.d/crypto-policies
 507 ln·-s·/etc/crypto-policies/back-ends/krb5.config·/etc/krb5.conf.d/crypto-policies
509 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·L\x8Li\x8ib\x8br\x8re\x8es\x8sw\x8wa\x8an\x8n·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*508 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·L\x8Li\x8ib\x8br\x8re\x8es\x8sw\x8wa\x8an\x8n·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
510 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many509 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many
511 packages.·Libreswan·is·supported·by·system·crypto·policy,·but·the·Libreswan510 packages.·Libreswan·is·supported·by·system·crypto·policy,·but·the·Libreswan
Max diff block lines reached; 23085/29332 bytes (78.70%) of diff not shown.
2.45 MB
./usr/share/doc/ssg-nondebian/ssg-alinux3-guide-pci-dss.html
    
Offset 14294, 15 lines modifiedOffset 14294, 15 lines modified
00037d50:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr00037d50:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr
00037d60:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st00037d60:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st
00037d70:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str00037d70:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str
00037d80:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>00037d80:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>
00037d90:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s00037d90:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s
00037da0:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········00037da0:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········
00037db0:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o00037db0:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o
00037dc0:·6620·3230·3236·2d30·312d·3038·290a·2020··f·2026-01-08).··00037dc0:·6620·3230·3234·2d31·322d·3037·290a·2020··f·2024-12-07).··
00037dd0:·2020·2020·2020·2020·2020·2020·2020·3c2f················</00037dd0:·2020·2020·2020·2020·2020·2020·2020·3c2f················</
00037de0:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h00037de0:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h
00037df0:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte00037df0:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte
00037e00:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>00037e00:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>
00037e10:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_00037e10:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_
00037e20:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c00037e20:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c
00037e30:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys00037e30:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys
Offset 15865, 80 lines modifiedOffset 15865, 80 lines modified
0003df80:·6574·3d22·2369·646d·3132·3739·2220·7461··et="#idm1279"·ta0003df80:·6574·3d22·2369·646d·3132·3739·2220·7461··et="#idm1279"·ta
0003df90:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003df90:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003dfa0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003dfa0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003dfb0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003dfb0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003dfc0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003dfc0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003dfd0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003dfd0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003dfe0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003dfe0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003dff0:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet· 
0003e000:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003e010:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003e020:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003e030:·6964·3d22·6964·6d31·3237·3922·3e3c·7461··id="idm1279"><ta 
0003e040:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003e050:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003e060:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003e070:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003e080:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003e090:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003e0a0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003e0b0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003e0c0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003e0d0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003e0e0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003e0f0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003e100:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003dff0:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin
 0003e000:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 0003e010:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003e020:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003e030:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003e040:·6d31·3237·3922·3e3c·7072·653e·3c63·6f64··m1279"><pre><cod
 0003e050:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]].
 0003e060:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve
 0003e070:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co
 0003e080:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0003e090:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 0003e0a0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 0003e0b0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 0003e0c0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 0003e0d0:·646d·3132·3830·2220·7461·6269·6e64·6578··dm1280"·tabindex
 0003e0e0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 0003e0f0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 0003e100:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 0003e110:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 0003e120:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 0003e130:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl
 0003e140:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a
 0003e150:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003e160:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003e170:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003e180:·6d31·3238·3022·3e3c·7461·626c·6520·636c··m1280"><table·cl
 0003e190:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003e1a0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003e1b0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003e1c0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003e1d0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003e1e0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003e1f0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003e200:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003e210:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003e220:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
0003e110:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t0003e230:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0003e240:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003e250:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 0003e260:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 0003e270:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-
 0003e280:·206e·616d·653a·2045·6e73·7572·6520·6169···name:·Ensure·ai
 0003e290:·6465·2069·7320·696e·7374·616c·6c65·640a··de·is·installed.
 0003e2a0:·2020·7061·636b·6167·653a·0a20·2020·206e····package:.····n
 0003e2b0:·616d·653a·2061·6964·650a·2020·2020·7374··ame:·aide.····st
 0003e2c0:·6174·653a·2070·7265·7365·6e74·0a20·2077··ate:·present.··w
 0003e2d0:·6865·6e3a·2061·6e73·6962·6c65·5f76·6972··hen:·ansible_vir
 0003e2e0:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type
 0003e2f0:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker
 0003e300:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv
 0003e310:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c
 0003e320:·6f6e·7461·696e·6572·225d·0a20·2074·6167··ontainer"].··tag
 0003e330:·733a·0a20·202d·2043·4a49·532d·352e·3130··s:.··-·CJIS-5.10
 0003e340:·2e31·2e33·0a20·202d·204e·4953·542d·3830··.1.3.··-·NIST-80
 0003e350:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··-
 0003e360:·2050·4349·2d44·5353·2d52·6571·2d31·312e···PCI-DSS-Req-11.
 0003e370:·350a·2020·2d20·5043·492d·4453·5376·342d··5.··-·PCI-DSSv4-
 0003e380:·3131·2e35·2e32·0a20·202d·2065·6e61·626c··11.5.2.··-·enabl
 0003e390:·655f·7374·7261·7465·6779·0a20·202d·206c··e_strategy.··-·l
 0003e3a0:·6f77·5f63·6f6d·706c·6578·6974·790a·2020··ow_complexity.··
 0003e3b0:·2d20·6c6f·775f·6469·7372·7570·7469·6f6e··-·low_disruption
 0003e3c0:·0a20·202d·206d·6564·6975·6d5f·7365·7665··.··-·medium_seve
 0003e3d0:·7269·7479·0a20·202d·206e·6f5f·7265·626f··rity.··-·no_rebo
 0003e3e0:·6f74·5f6e·6565·6465·640a·2020·2d20·7061··ot_needed.··-·pa
 0003e3f0:·636b·6167·655f·6169·6465·5f69·6e73·7461··ckage_aide_insta
0003e120:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003e130:·636f·6465·3e2d·206e·616d·653a·2045·6e73··code>-·name:·Ens 
0003e140:·7572·6520·6169·6465·2069·7320·696e·7374··ure·aide·is·inst 
0003e150:·616c·6c65·640a·2020·7061·636b·6167·653a··alled.··package: 
0003e160:·0a20·2020·206e·616d·653a·2061·6964·650a··.····name:·aide. 
0003e170:·2020·2020·7374·6174·653a·2070·7265·7365······state:·prese 
0003e180:·6e74·0a20·2077·6865·6e3a·2061·6e73·6962··nt.··when:·ansib 
0003e190:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio 
0003e1a0:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·[" 
0003e1b0:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",· 
0003e1c0:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma 
0003e1d0:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"] 
0003e1e0:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI 
0003e1f0:·532d·352e·3130·2e31·2e33·0a20·202d·204e··S-5.10.1.3.··-·N 
0003e200:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6( 
0003e210:·6129·0a20·202d·2050·4349·2d44·5353·2d52··a).··-·PCI-DSS-R 
0003e220:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI- 
0003e230:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··- 
0003e240:·2065·6e61·626c·655f·7374·7261·7465·6779···enable_strategy 
0003e250:·0a20·202d·206c·6f77·5f63·6f6d·706c·6578··.··-·low_complex 
0003e260:·6974·790a·2020·2d20·6c6f·775f·6469·7372··ity.··-·low_disr 
0003e270:·7570·7469·6f6e·0a20·202d·206d·6564·6975··uption.··-·mediu 
Max diff block lines reached; 2286669/2297485 bytes (99.53%) of diff not shown.
270 KB
html2text {}
    
Offset 39, 15 lines modifiedOffset 39, 15 lines modified
39 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*39 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v4.0·Control·Baseline·for·Alibaba·Cloud·Linux·340 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v4.0·Control·Baseline·for·Alibaba·Cloud·Linux·3
41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss
42 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*42 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
43 ····*·cpe:/o:alinux:alibaba_cloud_linux:343 ····*·cpe:/o:alinux:alibaba_cloud_linux:3
44 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*44 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
45 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8445 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
46 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)46 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
47 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
48 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s48 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
49 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e49 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
50 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l50 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
51 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n51 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
52 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g52 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
53 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s53 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 214, 14 lines modifiedOffset 214, 19 lines modified
214 include·install_aide214 include·install_aide
  
215 class·install_aide·{215 class·install_aide·{
216 ··package·{·'aide':216 ··package·{·'aide':
217 ····ensure·=>·'installed',217 ····ensure·=>·'installed',
218 ··}218 ··}
219 }219 }
 220 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 221 [[packages]]
 222 name·=·"aide"
 223 version·=·"*"
220 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8224 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
221 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low225 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
222 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low226 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
223 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false227 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
224 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable228 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
225 -·name:·Ensure·aide·is·installed229 -·name:·Ensure·aide·is·installed
226 ··package:230 ··package:
Offset 235, 19 lines modifiedOffset 240, 14 lines modified
235 ··-·PCI-DSSv4-11.5.2240 ··-·PCI-DSSv4-11.5.2
236 ··-·enable_strategy241 ··-·enable_strategy
237 ··-·low_complexity242 ··-·low_complexity
238 ··-·low_disruption243 ··-·low_disruption
239 ··-·medium_severity244 ··-·medium_severity
240 ··-·no_reboot_needed245 ··-·no_reboot_needed
241 ··-·package_aide_installed246 ··-·package_aide_installed
242 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
243 [[packages]] 
244 name·=·"aide" 
245 version·=·"*" 
246 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·P\x8Pe\x8er\x8ri\x8io\x8od\x8di\x8ic\x8c·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8ti\x8io\x8on\x8n·o\x8of\x8f·A\x8AI\x8ID\x8DE\x8E·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*247 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·P\x8Pe\x8er\x8ri\x8io\x8od\x8di\x8ic\x8c·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8ti\x8io\x8on\x8n·o\x8of\x8f·A\x8AI\x8ID\x8DE\x8E·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
247 At·a·minimum,·AIDE·should·be·configured·to·run·a·weekly·scan.·To·implement·a·daily·execution·of248 At·a·minimum,·AIDE·should·be·configured·to·run·a·weekly·scan.·To·implement·a·daily·execution·of
248 AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/crontab:249 AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/crontab:
249 05·4·*·*·*·root·/usr/sbin/aide·--check250 05·4·*·*·*·root·/usr/sbin/aide·--check
250 To·implement·a·weekly·execution·of·AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/251 To·implement·a·weekly·execution·of·AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/
251 crontab:252 crontab:
252 05·4·*·*·0·root·/usr/sbin/aide·--check253 05·4·*·*·0·root·/usr/sbin/aide·--check
Offset 441, 33 lines modifiedOffset 441, 14 lines modified
441 ············_\x8i_\x8s_\x8m······1446441 ············_\x8i_\x8s_\x8m······1446
442 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1442 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1
443 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)443 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)
444 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,444 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,
445 ·····················FCS_TLSC_EXT.1445 ·····················FCS_TLSC_EXT.1
446 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174446 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
447 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7447 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7
448 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
449 var_system_crypto_policy='DEFAULT' 
  
  
450 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
451 rc=$? 
  
452 if·test·"$rc"·=·127;·then 
453 »       echo·"$stderr_of_call"·>&2 
454 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
455 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
456 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
457 »       false··#·end·with·an·error·code 
458 elif·test·"$rc"·!=·0;·then 
459 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
460 »       false··#·end·with·an·error·code 
461 fi 
462 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8448 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
463 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low449 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
464 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low450 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
465 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false451 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
466 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict452 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
467 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable453 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
468 ··set_fact:454 ··set_fact:
Offset 510, 14 lines modifiedOffset 491, 33 lines modified
510 ··-·PCI-DSSv4-2.2.7491 ··-·PCI-DSSv4-2.2.7
511 ··-·configure_crypto_policy492 ··-·configure_crypto_policy
512 ··-·high_severity493 ··-·high_severity
513 ··-·low_complexity494 ··-·low_complexity
514 ··-·low_disruption495 ··-·low_disruption
515 ··-·no_reboot_needed496 ··-·no_reboot_needed
516 ··-·restrict_strategy497 ··-·restrict_strategy
 498 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 499 var_system_crypto_policy='DEFAULT'
  
  
 500 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null)
 501 rc=$?
  
 502 if·test·"$rc"·=·127;·then
 503 »       echo·"$stderr_of_call"·>&2
 504 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2
 505 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2
 506 »       echo·"to·see·what·package·to·(re)install"·>&2
  
 507 »       false··#·end·with·an·error·code
 508 elif·test·"$rc"·!=·0;·then
 509 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
 510 »       false··#·end·with·an·error·code
 511 fi
517 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*512 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
518 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is513 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is
519 supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that514 supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that
520 Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either515 Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either
521 commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.516 commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
522 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate517 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate
523 ············expectations,·and·makes·system·configuration·more·fragmented.518 ············expectations,·and·makes·system·configuration·more·fragmented.
Offset 528, 19 lines modifiedOffset 528, 14 lines modified
528 ·····················(ii)528 ·····················(ii)
529 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1529 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1
530 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13530 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13
Max diff block lines reached; 269947/275951 bytes (97.82%) of diff not shown.
307 KB
./usr/share/doc/ssg-nondebian/ssg-alinux3-guide-standard.html
    
Offset 14290, 15 lines modifiedOffset 14290, 15 lines modified
00037d10:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00037d10:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00037d20:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00037d20:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00037d30:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s00037d30:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00037d40:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00037d40:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00037d50:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00037d50:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00037d60:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00037d60:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00037d70:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00037d70:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00037d80:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).00037d80:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
00037d90:·2020·2020·2020·2020·2020·2020·2020·2020··················00037d90:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037da0:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00037da0:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00037db0:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00037db0:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00037dc0:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00037dc0:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00037dd0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00037dd0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00037de0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00037de0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00037df0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00037df0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
Offset 16133, 173 lines modifiedOffset 16133, 173 lines modified
0003f040:·6172·6765·743d·2223·6964·6d31·3436·3322··arget="#idm1463"0003f040:·6172·6765·743d·2223·6964·6d31·3436·3322··arget="#idm1463"
0003f050:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003f050:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003f060:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003f060:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003f070:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003f070:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003f080:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003f080:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003f090:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003f090:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003f0a0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003f0a0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003f0b0:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp
 0003f0c0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0003f0d0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003f0e0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003f0f0:·6522·2069·643d·2269·646d·3134·3633·223e··e"·id="idm1463">
 0003f100:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003f110:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003f120:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003f130:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003f140:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 0003f150:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 0003f160:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003f170:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
0003f0b0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script· 
0003f0c0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003f0d0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003f0e0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003f0f0:·6964·3d22·6964·6d31·3436·3322·3e3c·7072··id="idm1463"><pr 
0003f100:·653e·3c63·6f64·653e·0a76·6172·5f73·7973··e><code>.var_sys 
0003f110:·7465·6d5f·6372·7970·746f·5f70·6f6c·6963··tem_crypto_polic 
0003f120:·793d·273c·6162·6272·2074·6974·6c65·3d22··y='<abbr·title=" 
0003f130:·6672·6f6d·2042·656e·6368·6d61·726b·2f56··from·Benchmark/V 
0003f140:·616c·7565·3a20·7863·6364·665f·6f72·672e··alue:·xccdf_org. 
0003f150:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte 
0003f160:·6e74·5f76·616c·7565·5f76·6172·5f73·7973··nt_value_var_sys 
0003f170:·7465·6d5f·6372·7970·746f·5f70·6f6c·6963··tem_crypto_polic 
0003f180:·7922·3e44·4546·4155·4c54·3c2f·6162·6272··y">DEFAULT</abbr 
0003f190:·3e27·0a0a·0a73·7464·6572·725f·6f66·5f63··>'...stderr_of_c 
0003f1a0:·616c·6c3d·2428·7570·6461·7465·2d63·7279··all=$(update-cry 
0003f1b0:·7074·6f2d·706f·6c69·6369·6573·202d·2d73··pto-policies·--s 
0003f1c0:·6574·2024·7b76·6172·5f73·7973·7465·6d5f··et·${var_system_ 
0003f1d0:·6372·7970·746f·5f70·6f6c·6963·797d·2032··crypto_policy}·2 
0003f1e0:·2667·743b·2661·6d70·3b31·2026·6774·3b20··&gt;&amp;1·&gt;· 
0003f1f0:·2f64·6576·2f6e·756c·6c29·0a72·633d·243f··/dev/null).rc=$? 
0003f200:·0a0a·6966·2074·6573·7420·2224·7263·2220··..if·test·"$rc"· 
0003f210:·3d20·3132·373b·2074·6865·6e0a·0965·6368··=·127;·then..ech 
0003f220:·6f20·2224·7374·6465·7272·5f6f·665f·6361··o·"$stderr_of_ca 
0003f230:·6c6c·2220·2667·743b·2661·6d70·3b32·0a09··ll"·&gt;&amp;2.. 
0003f240:·6563·686f·2022·4d61·6b65·2073·7572·6520··echo·"Make·sure· 
0003f250:·7468·6174·2074·6865·2073·6372·6970·7420··that·the·script· 
0003f260:·6973·2069·6e73·7461·6c6c·6564·206f·6e20··is·installed·on· 
0003f270:·7468·6520·7265·6d65·6469·6174·6564·2073··the·remediated·s 
0003f280:·7973·7465·6d2e·2220·2667·743b·2661·6d70··ystem."·&gt;&amp 
0003f290:·3b32·0a09·6563·686f·2022·5365·6520·6f75··;2..echo·"See·ou 
0003f2a0:·7470·7574·206f·6620·7468·6520·2764·6e66··tput·of·the·'dnf 
0003f2b0:·2070·726f·7669·6465·7320·7570·6461·7465···provides·update 
0003f2c0:·2d63·7279·7074·6f2d·706f·6c69·6369·6573··-crypto-policies 
0003f2d0:·2720·636f·6d6d·616e·6422·2026·6774·3b26··'·command"·&gt;& 
0003f2e0:·616d·703b·320a·0965·6368·6f20·2274·6f20··amp;2..echo·"to· 
0003f2f0:·7365·6520·7768·6174·2070·6163·6b61·6765··see·what·package 
0003f300:·2074·6f20·2872·6529·696e·7374·616c·6c22···to·(re)install" 
0003f310:·2026·6774·3b26·616d·703b·320a·0a09·6661···&gt;&amp;2...fa 
0003f320:·6c73·6520·2023·2065·6e64·2077·6974·6820··lse··#·end·with· 
0003f330:·616e·2065·7272·6f72·2063·6f64·650a·656c··an·error·code.el 
0003f340:·6966·2074·6573·7420·2224·7263·2220·213d··if·test·"$rc"·!= 
0003f350:·2030·3b20·7468·656e·0a09·6563·686f·2022···0;·then..echo·" 
0003f360:·4572·726f·7220·696e·766f·6b69·6e67·2074··Error·invoking·t 
0003f370:·6865·2075·7064·6174·652d·6372·7970·746f··he·update-crypto 
0003f380:·2d70·6f6c·6963·6965·7320·7363·7269·7074··-policies·script 
0003f390:·3a20·2473·7464·6572·725f·6f66·5f63·616c··:·$stderr_of_cal 
0003f3a0:·6c22·2026·6774·3b26·616d·703b·320a·0966··l"·&gt;&amp;2..f 
0003f3b0:·616c·7365·2020·2320·656e·6420·7769·7468··alse··#·end·with 
0003f3c0:·2061·6e20·6572·726f·7220·636f·6465·0a66···an·error·code.f 
0003f3d0:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre>< 
0003f3e0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003f3f0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003f400:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003f410:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003f420:·6574·3d22·2369·646d·3134·3635·2220·7461··et="#idm1465"·ta 
0003f430:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003f440:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003f450:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003f460:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003f470:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003f480:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003f490:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet· 
0003f4a0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003f4b0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003f4c0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003f4d0:·6964·3d22·6964·6d31·3436·3522·3e3c·7461··id="idm1465"><ta 
0003f4e0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003f4f0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003f500:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003f510:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003f520:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003f530:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003f180:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003f540:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003f550:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003f560:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003f570:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003f580:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003f590:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003f190:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
0003f5a0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003f5b0:·643e·7265·7374·7269·6374·3c2f·7464·3e3c··d>restrict</td>< 
0003f5c0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003f5d0:·3e3c·636f·6465·3e2d·206e·616d·653a·2058··><code>-·name:·X 
0003f5e0:·4343·4446·2056·616c·7565·2076·6172·5f73··CCDF·Value·var_s0003f1a0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
 0003f1b0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 0003f1c0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003f1d0:·3e3c·7464·3e72·6573·7472·6963·743c·2f74··><td>restrict</t
 0003f1e0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003f1f0:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name
 0003f200:·3a20·5843·4344·4620·5661·6c75·6520·7661··:·XCCDF·Value·va
 0003f210:·725f·7379·7374·656d·5f63·7279·7074·6f5f··r_system_crypto_
Max diff block lines reached; 265126/288778 bytes (91.81%) of diff not shown.
25.0 KB
html2text {}
    
Offset 39, 15 lines modifiedOffset 39, 15 lines modified
39 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*39 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Alibaba·Cloud·Linux·340 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Alibaba·Cloud·Linux·3
41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard
42 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*42 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
43 ····*·cpe:/o:alinux:alibaba_cloud_linux:343 ····*·cpe:/o:alinux:alibaba_cloud_linux:3
44 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*44 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
45 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8445 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
46 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)46 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
47 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
48 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s48 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
49 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e49 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
50 ·········2.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s50 ·········2.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
51 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s51 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
52 ·········1.·_\x8B_\x8a_\x8s_\x8e_\x8·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s52 ·········1.·_\x8B_\x8a_\x8s_\x8e_\x8·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
53 ·········2.·_\x8C_\x8r_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8t_\x8·_\x8D_\x8a_\x8e_\x8m_\x8o_\x8n_\x8s53 ·········2.·_\x8C_\x8r_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8t_\x8·_\x8D_\x8a_\x8e_\x8m_\x8o_\x8n_\x8s
Offset 266, 34 lines modifiedOffset 266, 14 lines modified
266 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1266 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1
267 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)267 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)
268 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,268 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,
269 ·····················FCS_CKM.2,·FCS_TLSC_EXT.1269 ·····················FCS_CKM.2,·FCS_TLSC_EXT.1
270 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-270 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-
271 ·····················GPOS-00174271 ·····················GPOS-00174
272 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7272 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7
273 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
274 var_system_crypto_policy='DEFAULT' 
  
  
275 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/ 
276 null) 
277 rc=$? 
  
278 if·test·"$rc"·=·127;·then 
279 »       echo·"$stderr_of_call"·>&2 
280 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
281 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
282 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
283 »       false··#·end·with·an·error·code 
284 elif·test·"$rc"·!=·0;·then 
285 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
286 »       false··#·end·with·an·error·code 
287 fi 
288 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8273 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
289 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low274 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
290 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low275 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
291 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false276 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
292 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict277 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
293 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable278 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
294 ··set_fact:279 ··set_fact:
Offset 336, 14 lines modifiedOffset 316, 34 lines modified
336 ··-·PCI-DSSv4-2.2.7316 ··-·PCI-DSSv4-2.2.7
337 ··-·configure_crypto_policy317 ··-·configure_crypto_policy
338 ··-·high_severity318 ··-·high_severity
339 ··-·low_complexity319 ··-·low_complexity
340 ··-·low_disruption320 ··-·low_disruption
341 ··-·no_reboot_needed321 ··-·no_reboot_needed
342 ··-·restrict_strategy322 ··-·restrict_strategy
 323 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 324 var_system_crypto_policy='DEFAULT'
  
  
 325 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/
 326 null)
 327 rc=$?
  
 328 if·test·"$rc"·=·127;·then
 329 »       echo·"$stderr_of_call"·>&2
 330 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2
 331 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2
 332 »       echo·"to·see·what·package·to·(re)install"·>&2
  
 333 »       false··#·end·with·an·error·code
 334 elif·test·"$rc"·!=·0;·then
 335 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
 336 »       false··#·end·with·an·error·code
 337 fi
343 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·K\x8Ke\x8er\x8rb\x8be\x8er\x8ro\x8os\x8s·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*338 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·K\x8Ke\x8er\x8rb\x8be\x8er\x8ro\x8os\x8s·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
344 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many339 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many
345 packages.·Kerberos·is·supported·by·crypto·policy,·but·it's·configuration·may·be·set·up340 packages.·Kerberos·is·supported·by·crypto·policy,·but·it's·configuration·may·be·set·up
346 to·ignore·it.·To·check·that·Crypto·Policies·settings·for·Kerberos·are·configured341 to·ignore·it.·To·check·that·Crypto·Policies·settings·for·Kerberos·are·configured
347 correctly,·examine·that·there·is·a·symlink·at·/etc/krb5.conf.d/crypto-policies342 correctly,·examine·that·there·is·a·symlink·at·/etc/krb5.conf.d/crypto-policies
348 targeting·/etc/cypto-policies/back-ends/krb5.config.·If·the·symlink·exists,·Kerberos·is343 targeting·/etc/cypto-policies/back-ends/krb5.config.·If·the·symlink·exists,·Kerberos·is
349 configured·to·use·the·system-wide·crypto·policy·settings.344 configured·to·use·the·system-wide·crypto·policy·settings.
Offset 351, 22 lines modifiedOffset 351, 14 lines modified
351 ············expectations,·and·makes·system·configuration·more·fragmented.351 ············expectations,·and·makes·system·configuration·more·fragmented.
352 Severity: ··high352 Severity: ··high
353 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_kerberos_crypto_policy353 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_kerberos_crypto_policy
354 ············_\x8i_\x8s_\x8m······0418,·1055,·1402354 ············_\x8i_\x8s_\x8m······0418,·1055,·1402
355 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1355 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
356 ············_\x8n_\x8i_\x8s_\x8t·····SC-13,·SC-12(2),·SC-12(3)356 ············_\x8n_\x8i_\x8s_\x8t·····SC-13,·SC-12(2),·SC-12(3)
357 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000120-GPOS-00061357 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000120-GPOS-00061
358 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
359 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
360 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
361 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
362 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure 
  
363 rm·-f·/etc/krb5.conf.d/crypto-policies 
364 ln·-s·/etc/crypto-policies/back-ends/krb5.config·/etc/krb5.conf.d/crypto-policies 
365 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8358 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
366 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low359 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
367 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low360 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
368 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true361 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
369 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure362 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
370 -·name:·Configure·Kerberos·to·use·System·Crypto·Policy363 -·name:·Configure·Kerberos·to·use·System·Crypto·Policy
371 ··file:364 ··file:
Offset 379, 14 lines modifiedOffset 371, 22 lines modified
379 ··-·NIST-800-53-SC-13371 ··-·NIST-800-53-SC-13
380 ··-·configure_kerberos_crypto_policy372 ··-·configure_kerberos_crypto_policy
381 ··-·configure_strategy373 ··-·configure_strategy
382 ··-·high_severity374 ··-·high_severity
383 ··-·low_complexity375 ··-·low_complexity
384 ··-·low_disruption376 ··-·low_disruption
385 ··-·reboot_required377 ··-·reboot_required
 378 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 379 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 380 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 381 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 382 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
  
 383 rm·-f·/etc/krb5.conf.d/crypto-policies
 384 ln·-s·/etc/crypto-policies/back-ends/krb5.config·/etc/krb5.conf.d/crypto-policies
386 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·L\x8Li\x8ib\x8br\x8re\x8es\x8sw\x8wa\x8an\x8n·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*385 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·L\x8Li\x8ib\x8br\x8re\x8es\x8sw\x8wa\x8an\x8n·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
387 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many386 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many
388 packages.·Libreswan·is·supported·by·system·crypto·policy,·but·the·Libreswan387 packages.·Libreswan·is·supported·by·system·crypto·policy,·but·the·Libreswan
Max diff block lines reached; 19374/25573 bytes (75.76%) of diff not shown.
2.45 MB
./usr/share/doc/ssg-nondebian/ssg-anolis23-guide-pci-dss.html
    
Offset 14290, 15 lines modifiedOffset 14290, 15 lines modified
00037d10:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur00037d10:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur
00037d20:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s00037d20:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s
00037d30:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st00037d30:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st
00037d40:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li00037d40:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li
00037d50:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</00037d50:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</
00037d60:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········00037d60:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········
00037d70:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·00037d70:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·
00037d80:·6f66·2032·3032·362d·3031·2d30·3829·0a20··of·2026-01-08).·00037d80:·6f66·2032·3032·342d·3132·2d30·3729·0a20··of·2024-12-07).·
00037d90:·2020·2020·2020·2020·2020·2020·2020·203c·················<00037d90:·2020·2020·2020·2020·2020·2020·2020·203c·················<
00037da0:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><00037da0:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><
00037db0:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont00037db0:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont
00037dc0:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li00037dc0:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li
00037dd0:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf00037dd0:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf
00037de0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.00037de0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.
00037df0:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy00037df0:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy
Offset 15497, 80 lines modifiedOffset 15497, 80 lines modified
0003c880:·6574·3d22·2369·646d·3133·3339·2220·7461··et="#idm1339"·ta0003c880:·6574·3d22·2369·646d·3133·3339·2220·7461··et="#idm1339"·ta
0003c890:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003c890:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003c8a0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003c8a0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003c8b0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003c8b0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003c8c0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003c8c0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003c8d0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003c8d0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003c8e0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003c8e0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003c8f0:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet· 
0003c900:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003c910:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003c920:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003c930:·6964·3d22·6964·6d31·3333·3922·3e3c·7461··id="idm1339"><ta 
0003c940:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003c950:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003c960:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003c970:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003c980:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003c990:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003c9a0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003c9b0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003c9c0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003c9d0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003c9e0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003c9f0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003ca00:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003c8f0:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin
 0003c900:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 0003c910:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003c920:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003c930:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003c940:·6d31·3333·3922·3e3c·7072·653e·3c63·6f64··m1339"><pre><cod
 0003c950:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]].
 0003c960:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve
 0003c970:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co
 0003c980:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0003c990:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 0003c9a0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 0003c9b0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 0003c9c0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 0003c9d0:·646d·3133·3430·2220·7461·6269·6e64·6578··dm1340"·tabindex
 0003c9e0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 0003c9f0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 0003ca00:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 0003ca10:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 0003ca20:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 0003ca30:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl
 0003ca40:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a
 0003ca50:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003ca60:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003ca70:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003ca80:·6d31·3334·3022·3e3c·7461·626c·6520·636c··m1340"><table·cl
 0003ca90:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003caa0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003cab0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003cac0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003cad0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003cae0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003caf0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003cb00:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003cb10:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003cb20:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
0003ca10:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t0003cb30:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0003cb40:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003cb50:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 0003cb60:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 0003cb70:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-
 0003cb80:·206e·616d·653a·2045·6e73·7572·6520·6169···name:·Ensure·ai
 0003cb90:·6465·2069·7320·696e·7374·616c·6c65·640a··de·is·installed.
 0003cba0:·2020·7061·636b·6167·653a·0a20·2020·206e····package:.····n
 0003cbb0:·616d·653a·2061·6964·650a·2020·2020·7374··ame:·aide.····st
 0003cbc0:·6174·653a·2070·7265·7365·6e74·0a20·2077··ate:·present.··w
 0003cbd0:·6865·6e3a·2061·6e73·6962·6c65·5f76·6972··hen:·ansible_vir
 0003cbe0:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type
 0003cbf0:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker
 0003cc00:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv
 0003cc10:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c
 0003cc20:·6f6e·7461·696e·6572·225d·0a20·2074·6167··ontainer"].··tag
 0003cc30:·733a·0a20·202d·2043·4a49·532d·352e·3130··s:.··-·CJIS-5.10
 0003cc40:·2e31·2e33·0a20·202d·204e·4953·542d·3830··.1.3.··-·NIST-80
 0003cc50:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··-
 0003cc60:·2050·4349·2d44·5353·2d52·6571·2d31·312e···PCI-DSS-Req-11.
 0003cc70:·350a·2020·2d20·5043·492d·4453·5376·342d··5.··-·PCI-DSSv4-
 0003cc80:·3131·2e35·2e32·0a20·202d·2065·6e61·626c··11.5.2.··-·enabl
 0003cc90:·655f·7374·7261·7465·6779·0a20·202d·206c··e_strategy.··-·l
 0003cca0:·6f77·5f63·6f6d·706c·6578·6974·790a·2020··ow_complexity.··
 0003ccb0:·2d20·6c6f·775f·6469·7372·7570·7469·6f6e··-·low_disruption
 0003ccc0:·0a20·202d·206d·6564·6975·6d5f·7365·7665··.··-·medium_seve
 0003ccd0:·7269·7479·0a20·202d·206e·6f5f·7265·626f··rity.··-·no_rebo
 0003cce0:·6f74·5f6e·6565·6465·640a·2020·2d20·7061··ot_needed.··-·pa
 0003ccf0:·636b·6167·655f·6169·6465·5f69·6e73·7461··ckage_aide_insta
0003ca20:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003ca30:·636f·6465·3e2d·206e·616d·653a·2045·6e73··code>-·name:·Ens 
0003ca40:·7572·6520·6169·6465·2069·7320·696e·7374··ure·aide·is·inst 
0003ca50:·616c·6c65·640a·2020·7061·636b·6167·653a··alled.··package: 
0003ca60:·0a20·2020·206e·616d·653a·2061·6964·650a··.····name:·aide. 
0003ca70:·2020·2020·7374·6174·653a·2070·7265·7365······state:·prese 
0003ca80:·6e74·0a20·2077·6865·6e3a·2061·6e73·6962··nt.··when:·ansib 
0003ca90:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio 
0003caa0:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·[" 
0003cab0:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",· 
0003cac0:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma 
0003cad0:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"] 
0003cae0:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI 
0003caf0:·532d·352e·3130·2e31·2e33·0a20·202d·204e··S-5.10.1.3.··-·N 
0003cb00:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6( 
0003cb10:·6129·0a20·202d·2050·4349·2d44·5353·2d52··a).··-·PCI-DSS-R 
0003cb20:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI- 
0003cb30:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··- 
0003cb40:·2065·6e61·626c·655f·7374·7261·7465·6779···enable_strategy 
0003cb50:·0a20·202d·206c·6f77·5f63·6f6d·706c·6578··.··-·low_complex 
0003cb60:·6974·790a·2020·2d20·6c6f·775f·6469·7372··ity.··-·low_disr 
0003cb70:·7570·7469·6f6e·0a20·202d·206d·6564·6975··uption.··-·mediu 
Max diff block lines reached; 2285472/2296288 bytes (99.53%) of diff not shown.
265 KB
html2text {}
    
Offset 39, 15 lines modifiedOffset 39, 15 lines modified
39 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*39 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v4.0·Control·Baseline·for·Anolis·OS·2340 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v4.0·Control·Baseline·for·Anolis·OS·23
41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss
42 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*42 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
43 ····*·cpe:/o:anolis:anolis_os:2343 ····*·cpe:/o:anolis:anolis_os:23
44 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*44 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
45 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8445 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
46 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)46 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
47 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
48 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s48 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
49 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e49 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
50 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l50 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
51 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n51 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
52 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g52 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
53 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s53 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 170, 14 lines modifiedOffset 170, 19 lines modified
170 include·install_aide170 include·install_aide
  
171 class·install_aide·{171 class·install_aide·{
172 ··package·{·'aide':172 ··package·{·'aide':
173 ····ensure·=>·'installed',173 ····ensure·=>·'installed',
174 ··}174 ··}
175 }175 }
 176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 177 [[packages]]
 178 name·=·"aide"
 179 version·=·"*"
176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
177 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
178 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
179 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
180 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
181 -·name:·Ensure·aide·is·installed185 -·name:·Ensure·aide·is·installed
182 ··package:186 ··package:
Offset 191, 19 lines modifiedOffset 196, 14 lines modified
191 ··-·PCI-DSSv4-11.5.2196 ··-·PCI-DSSv4-11.5.2
192 ··-·enable_strategy197 ··-·enable_strategy
193 ··-·low_complexity198 ··-·low_complexity
194 ··-·low_disruption199 ··-·low_disruption
195 ··-·medium_severity200 ··-·medium_severity
196 ··-·no_reboot_needed201 ··-·no_reboot_needed
197 ··-·package_aide_installed202 ··-·package_aide_installed
198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
199 [[packages]] 
200 name·=·"aide" 
201 version·=·"*" 
202 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·P\x8Pe\x8er\x8ri\x8io\x8od\x8di\x8ic\x8c·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8ti\x8io\x8on\x8n·o\x8of\x8f·A\x8AI\x8ID\x8DE\x8E·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*203 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·P\x8Pe\x8er\x8ri\x8io\x8od\x8di\x8ic\x8c·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8ti\x8io\x8on\x8n·o\x8of\x8f·A\x8AI\x8ID\x8DE\x8E·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
203 At·a·minimum,·AIDE·should·be·configured·to·run·a·weekly·scan.·To·implement·a·daily·execution·of204 At·a·minimum,·AIDE·should·be·configured·to·run·a·weekly·scan.·To·implement·a·daily·execution·of
204 AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/crontab:205 AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/crontab:
205 05·4·*·*·*·root·/usr/sbin/aide·--check206 05·4·*·*·*·root·/usr/sbin/aide·--check
206 To·implement·a·weekly·execution·of·AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/207 To·implement·a·weekly·execution·of·AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/
207 crontab:208 crontab:
208 05·4·*·*·0·root·/usr/sbin/aide·--check209 05·4·*·*·0·root·/usr/sbin/aide·--check
Offset 397, 33 lines modifiedOffset 397, 14 lines modified
397 ············_\x8i_\x8s_\x8m······1446397 ············_\x8i_\x8s_\x8m······1446
398 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1398 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1
399 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)399 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)
400 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,400 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,
401 ·····················FCS_TLSC_EXT.1401 ·····················FCS_TLSC_EXT.1
402 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174402 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
403 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7403 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7
404 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
405 var_system_crypto_policy='DEFAULT' 
  
  
406 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
407 rc=$? 
  
408 if·test·"$rc"·=·127;·then 
409 »       echo·"$stderr_of_call"·>&2 
410 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
411 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
412 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
413 »       false··#·end·with·an·error·code 
414 elif·test·"$rc"·!=·0;·then 
415 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
416 »       false··#·end·with·an·error·code 
417 fi 
418 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8404 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
419 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low405 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
420 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low406 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
421 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false407 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
422 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict408 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
423 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable409 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
424 ··set_fact:410 ··set_fact:
Offset 466, 14 lines modifiedOffset 447, 33 lines modified
466 ··-·PCI-DSSv4-2.2.7447 ··-·PCI-DSSv4-2.2.7
467 ··-·configure_crypto_policy448 ··-·configure_crypto_policy
468 ··-·high_severity449 ··-·high_severity
469 ··-·low_complexity450 ··-·low_complexity
470 ··-·low_disruption451 ··-·low_disruption
471 ··-·no_reboot_needed452 ··-·no_reboot_needed
472 ··-·restrict_strategy453 ··-·restrict_strategy
 454 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 455 var_system_crypto_policy='DEFAULT'
  
  
 456 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null)
 457 rc=$?
  
 458 if·test·"$rc"·=·127;·then
 459 »       echo·"$stderr_of_call"·>&2
 460 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2
 461 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2
 462 »       echo·"to·see·what·package·to·(re)install"·>&2
  
 463 »       false··#·end·with·an·error·code
 464 elif·test·"$rc"·!=·0;·then
 465 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
 466 »       false··#·end·with·an·error·code
 467 fi
473 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*468 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
474 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is469 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is
475 supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that470 supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that
476 Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either471 Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either
477 commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.472 commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
478 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate473 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate
479 ············expectations,·and·makes·system·configuration·more·fragmented.474 ············expectations,·and·makes·system·configuration·more·fragmented.
Offset 484, 19 lines modifiedOffset 484, 14 lines modified
484 ·····················(ii)484 ·····················(ii)
485 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1485 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1
486 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13486 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13
Max diff block lines reached; 265289/271275 bytes (97.79%) of diff not shown.
2.88 MB
./usr/share/doc/ssg-nondebian/ssg-anolis23-guide-standard.html
    
Offset 14281, 15 lines modifiedOffset 14281, 15 lines modified
00037c80:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00037c80:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00037c90:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00037c90:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00037ca0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<00037ca0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<
00037cb0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00037cb0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00037cc0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00037cc0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00037cd0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00037cd0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00037ce0:·2020·2020·2020·2020·2020·2020·2020·2028·················(00037ce0:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00037cf0:·6173·206f·6620·3230·3236·2d30·312d·3038··as·of·2026-01-0800037cf0:·6173·206f·6620·3230·3234·2d31·322d·3037··as·of·2024-12-07
00037d00:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00037d00:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00037d10:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00037d10:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00037d20:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00037d20:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00037d30:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00037d30:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00037d40:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00037d40:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00037d50:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00037d50:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00037d60:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00037d60:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
Offset 15087, 81 lines modifiedOffset 15087, 81 lines modified
0003aee0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003aee0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003aef0:·2223·6964·6d31·3333·3922·2074·6162·696e··"#idm1339"·tabin0003aef0:·2223·6964·6d31·3333·3922·2074·6162·696e··"#idm1339"·tabin
0003af00:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003af00:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003af10:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003af10:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003af20:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003af20:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003af30:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003af30:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003af40:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003af40:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003af50:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans0003af50:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB
0003af60:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·... 
0003af70:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003af80:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003af90:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003afa0:·2269·646d·3133·3339·223e·3c74·6162·6c65··"idm1339"><table 
0003afb0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003afc0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003afd0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003afe0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003aff0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003b000:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b010:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003b020:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003b030:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b040:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003b050:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003b060:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003b070:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003af60:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s
 0003af70:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0003af80:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003af90:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003afa0:·6c61·7073·6522·2069·643d·2269·646d·3133··lapse"·id="idm13
 0003afb0:·3339·223e·3c70·7265·3e3c·636f·6465·3e0a··39"><pre><code>.
 0003afc0:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam
 0003afd0:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi
 0003afe0:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code>
 0003aff0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003b000:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003b010:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003b020:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0003b030:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
 0003b040:·3334·3022·2074·6162·696e·6465·783d·2230··340"·tabindex="0
 0003b050:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0003b060:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0003b070:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0003b080:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0003b090:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003b0a0:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s
 0003b0b0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0003b0c0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003b0d0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003b0e0:·6c61·7073·6522·2069·643d·2269·646d·3133··lapse"·id="idm13
 0003b0f0:·3430·223e·3c74·6162·6c65·2063·6c61·7373··40"><table·class
 0003b100:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003b110:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0003b120:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003b130:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003b140:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003b150:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b160:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003b170:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003b180:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b190:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0003b080:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003b1a0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003b1b0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003b1c0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003b1d0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 0003b1e0:·3e3c·7072·653e·3c63·6f64·653e·2d20·6e61··><pre><code>-·na
 0003b1f0:·6d65·3a20·456e·7375·7265·2061·6964·6520··me:·Ensure·aide·
 0003b200:·6973·2069·6e73·7461·6c6c·6564·0a20·2070··is·installed.··p
 0003b210:·6163·6b61·6765·3a0a·2020·2020·6e61·6d65··ackage:.····name
 0003b220:·3a20·6169·6465·0a20·2020·2073·7461·7465··:·aide.····state
 0003b230:·3a20·7072·6573·656e·740a·2020·7768·656e··:·present.··when
 0003b240:·3a20·616e·7369·626c·655f·7669·7274·7561··:·ansible_virtua
 0003b250:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no
 0003b260:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",·
 0003b270:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz",
 0003b280:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont
 0003b290:·6169·6e65·7222·5d0a·2020·7461·6773·3a0a··ainer"].··tags:.
 0003b2a0:·2020·2d20·434a·4953·2d35·2e31·302e·312e····-·CJIS-5.10.1.
 0003b2b0:·330a·2020·2d20·4e49·5354·2d38·3030·2d35··3.··-·NIST-800-5
 0003b2c0:·332d·434d·2d36·2861·290a·2020·2d20·5043··3-CM-6(a).··-·PC
 0003b2d0:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·
 0003b2e0:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.
 0003b2f0:·352e·320a·2020·2d20·656e·6162·6c65·5f73··5.2.··-·enable_s
 0003b300:·7472·6174·6567·790a·2020·2d20·6c6f·775f··trategy.··-·low_
 0003b310:·636f·6d70·6c65·7869·7479·0a20·202d·206c··complexity.··-·l
 0003b320:·6f77·5f64·6973·7275·7074·696f·6e0a·2020··ow_disruption.··
 0003b330:·2d20·6d65·6469·756d·5f73·6576·6572·6974··-·medium_severit
 0003b340:·790a·2020·2d20·6e6f·5f72·6562·6f6f·745f··y.··-·no_reboot_
 0003b350:·6e65·6564·6564·0a20·202d·2070·6163·6b61··needed.··-·packa
 0003b360:·6765·5f61·6964·655f·696e·7374·616c·6c65··ge_aide_installe
0003b090:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003b0a0:·653e·2d20·6e61·6d65·3a20·456e·7375·7265··e>-·name:·Ensure 
0003b0b0:·2061·6964·6520·6973·2069·6e73·7461·6c6c···aide·is·install 
0003b0c0:·6564·0a20·2070·6163·6b61·6765·3a0a·2020··ed.··package:.·· 
0003b0d0:·2020·6e61·6d65·3a20·6169·6465·0a20·2020····name:·aide.··· 
0003b0e0:·2073·7461·7465·3a20·7072·6573·656e·740a···state:·present. 
0003b0f0:·2020·7768·656e·3a20·616e·7369·626c·655f····when:·ansible_ 
0003b100:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t 
0003b110:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc 
0003b120:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op 
0003b130:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman", 
0003b140:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].·· 
0003b150:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-5 
0003b160:·2e31·302e·312e·330a·2020·2d20·4e49·5354··.10.1.3.··-·NIST 
0003b170:·2d38·3030·2d35·332d·434d·2d36·2861·290a··-800-53-CM-6(a). 
0003b180:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req- 
0003b190:·3131·2e35·0a20·202d·2050·4349·2d44·5353··11.5.··-·PCI-DSS 
0003b1a0:·7634·2d31·312e·352e·320a·2020·2d20·656e··v4-11.5.2.··-·en 
0003b1b0:·6162·6c65·5f73·7472·6174·6567·790a·2020··able_strategy.·· 
0003b1c0:·2d20·6c6f·775f·636f·6d70·6c65·7869·7479··-·low_complexity 
0003b1d0:·0a20·202d·206c·6f77·5f64·6973·7275·7074··.··-·low_disrupt 
Max diff block lines reached; 2695329/2706283 bytes (99.60%) of diff not shown.
302 KB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Anolis·OS·2338 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Anolis·OS·23
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:anolis:anolis_os:2341 ····*·cpe:/o:anolis:anolis_os:23
42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
43 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8443 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
49 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n49 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
50 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g50 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
51 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s51 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 126, 14 lines modifiedOffset 126, 19 lines modified
126 include·install_aide126 include·install_aide
  
127 class·install_aide·{127 class·install_aide·{
128 ··package·{·'aide':128 ··package·{·'aide':
129 ····ensure·=>·'installed',129 ····ensure·=>·'installed',
130 ··}130 ··}
131 }131 }
 132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 133 [[packages]]
 134 name·=·"aide"
 135 version·=·"*"
132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
137 -·name:·Ensure·aide·is·installed141 -·name:·Ensure·aide·is·installed
138 ··package:142 ··package:
Offset 147, 19 lines modifiedOffset 152, 14 lines modified
147 ··-·PCI-DSSv4-11.5.2152 ··-·PCI-DSSv4-11.5.2
148 ··-·enable_strategy153 ··-·enable_strategy
149 ··-·low_complexity154 ··-·low_complexity
150 ··-·low_disruption155 ··-·low_disruption
151 ··-·medium_severity156 ··-·medium_severity
152 ··-·no_reboot_needed157 ··-·no_reboot_needed
153 ··-·package_aide_installed158 ··-·package_aide_installed
154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
155 [[packages]] 
156 name·=·"aide" 
157 version·=·"*" 
158 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·P\x8Pe\x8er\x8ri\x8io\x8od\x8di\x8ic\x8c·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8ti\x8io\x8on\x8n·o\x8of\x8f·A\x8AI\x8ID\x8DE\x8E·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*159 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·P\x8Pe\x8er\x8ri\x8io\x8od\x8di\x8ic\x8c·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8ti\x8io\x8on\x8n·o\x8of\x8f·A\x8AI\x8ID\x8DE\x8E·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
159 At·a·minimum,·AIDE·should·be·configured·to·run·a·weekly·scan.·To·implement·a·daily·execution·of160 At·a·minimum,·AIDE·should·be·configured·to·run·a·weekly·scan.·To·implement·a·daily·execution·of
160 AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/crontab:161 AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/crontab:
161 05·4·*·*·*·root·/usr/sbin/aide·--check162 05·4·*·*·*·root·/usr/sbin/aide·--check
162 To·implement·a·weekly·execution·of·AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/163 To·implement·a·weekly·execution·of·AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/
163 crontab:164 crontab:
164 05·4·*·*·0·root·/usr/sbin/aide·--check165 05·4·*·*·0·root·/usr/sbin/aide·--check
Offset 353, 33 lines modifiedOffset 353, 14 lines modified
353 ············_\x8i_\x8s_\x8m······1446353 ············_\x8i_\x8s_\x8m······1446
354 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1354 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1
355 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)355 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)
356 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,356 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,
357 ·····················FCS_TLSC_EXT.1357 ·····················FCS_TLSC_EXT.1
358 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174358 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
359 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7359 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7
360 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
361 var_system_crypto_policy='DEFAULT' 
  
  
362 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
363 rc=$? 
  
364 if·test·"$rc"·=·127;·then 
365 »       echo·"$stderr_of_call"·>&2 
366 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
367 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
368 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
369 »       false··#·end·with·an·error·code 
370 elif·test·"$rc"·!=·0;·then 
371 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
372 »       false··#·end·with·an·error·code 
373 fi 
374 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8360 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
375 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low361 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
376 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low362 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
377 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false363 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
378 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict364 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
379 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable365 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
380 ··set_fact:366 ··set_fact:
Offset 422, 14 lines modifiedOffset 403, 33 lines modified
422 ··-·PCI-DSSv4-2.2.7403 ··-·PCI-DSSv4-2.2.7
423 ··-·configure_crypto_policy404 ··-·configure_crypto_policy
424 ··-·high_severity405 ··-·high_severity
425 ··-·low_complexity406 ··-·low_complexity
426 ··-·low_disruption407 ··-·low_disruption
427 ··-·no_reboot_needed408 ··-·no_reboot_needed
428 ··-·restrict_strategy409 ··-·restrict_strategy
 410 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 411 var_system_crypto_policy='DEFAULT'
  
  
 412 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null)
 413 rc=$?
  
 414 if·test·"$rc"·=·127;·then
 415 »       echo·"$stderr_of_call"·>&2
 416 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2
 417 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2
 418 »       echo·"to·see·what·package·to·(re)install"·>&2
  
 419 »       false··#·end·with·an·error·code
 420 elif·test·"$rc"·!=·0;·then
 421 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
 422 »       false··#·end·with·an·error·code
 423 fi
429 Group  ·Updating·Software·  Group·contains·1·rule424 Group  ·Updating·Software·  Group·contains·1·rule
430 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also425 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also
431 provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called426 provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called
432 S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.427 S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.
  
433 Anolis·OS·23·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records428 Anolis·OS·23·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records
434 metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all429 metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all
Offset 634, 20 lines modifiedOffset 634, 14 lines modified
634 ···········Display·of·a·standardized·and·approved·use·notification·before·granting·access·to·the634 ···········Display·of·a·standardized·and·approved·use·notification·before·granting·access·to·the
635 ···········operating·system·ensures·privacy·and·security·notification·verbiage·used·is·consistent635 ···········operating·system·ensures·privacy·and·security·notification·verbiage·used·is·consistent
636 Rationale:·with·applicable·federal·laws,·Executive·Orders,·directives,·policies,·regulations,636 Rationale:·with·applicable·federal·laws,·Executive·Orders,·directives,·policies,·regulations,
Max diff block lines reached; 303171/309092 bytes (98.08%) of diff not shown.
2.45 MB
./usr/share/doc/ssg-nondebian/ssg-anolis8-guide-pci-dss.html
    
Offset 14289, 16 lines modifiedOffset 14289, 16 lines modified
00037d00:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00037d00:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00037d10:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00037d10:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00037d20:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000037d20:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00037d30:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></00037d30:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
00037d40:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00037d40:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00037d50:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00037d50:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00037d60:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037d60:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037d70:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600037d70:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
00037d80:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········00037d80:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00037d90:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00037d90:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00037da0:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00037da0:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00037db0:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00037db0:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00037dc0:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00037dc0:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00037dd0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00037dd0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00037de0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00037de0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00037df0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00037df0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
Offset 15496, 80 lines modifiedOffset 15496, 80 lines modified
0003c870:·7461·7267·6574·3d22·2369·646d·3133·3339··target="#idm13390003c870:·7461·7267·6574·3d22·2369·646d·3133·3339··target="#idm1339
0003c880:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003c880:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003c890:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003c890:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003c8a0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003c8a0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003c8b0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003c8b0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003c8c0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003c8c0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003c8d0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003c8d0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003c8e0:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip 
0003c8f0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003c900:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003c910:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003c920:·7365·2220·6964·3d22·6964·6d31·3333·3922··se"·id="idm1339"0003c8e0:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue
 0003c8f0:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·..
 0003c900:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003c910:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003c920:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003c930:·3d22·6964·6d31·3333·3922·3e3c·7072·653e··="idm1339"><pre>
 0003c940:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package
 0003c950:·735d·5d0a·6e61·6d65·203d·2022·6169·6465··s]].name·=·"aide
 0003c960:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*".
 0003c970:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003c930:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003c980:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0003c990:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0003c9a0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 0003c9b0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0003c9c0:·3d22·2369·646d·3133·3430·2220·7461·6269··="#idm1340"·tabi
 0003c9d0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 0003c9e0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 0003c9f0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 0003ca00:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 0003ca10:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 0003ca20:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
 0003ca30:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·..
 0003ca40:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003ca50:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003ca60:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003ca70:·3d22·6964·6d31·3334·3022·3e3c·7461·626c··="idm1340"><tabl
 0003ca80:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003ca90:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003caa0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003cab0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003cac0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 0003cad0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003cae0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0003caf0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0003cb00:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003cb10:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 0003cb20:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 0003cb30:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0003cb40:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 0003cb50:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 0003cb60:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003cb70:·6465·3e2d·206e·616d·653a·2045·6e73·7572··de>-·name:·Ensur
 0003cb80:·6520·6169·6465·2069·7320·696e·7374·616c··e·aide·is·instal
0003c940:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003c950:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003c960:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003c970:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003c980:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003c990:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003c9a0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003c9b0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003c9c0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003c9d0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003c9e0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003c9f0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003ca00:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003ca10:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003ca20:·7265·3e3c·636f·6465·3e2d·206e·616d·653a··re><code>-·name: 
0003ca30:·2045·6e73·7572·6520·6169·6465·2069·7320···Ensure·aide·is· 
0003ca40:·696e·7374·616c·6c65·640a·2020·7061·636b··installed.··pack 
0003ca50:·6167·653a·0a20·2020·206e·616d·653a·2061··age:.····name:·a 
0003ca60:·6964·650a·2020·2020·7374·6174·653a·2070··ide.····state:·p 
0003ca70:·7265·7365·6e74·0a20·2077·6865·6e3a·2061··resent.··when:·a 
0003ca80:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz 
0003ca90:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i 
0003caa0:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx 
0003cab0:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p 
0003cac0:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain 
0003cad0:·6572·225d·0a20·2074·6167·733a·0a20·202d··er"].··tags:.··- 
0003cae0:·2043·4a49·532d·352e·3130·2e31·2e33·0a20···CJIS-5.10.1.3.· 
0003caf0:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C 
0003cb00:·4d2d·3628·6129·0a20·202d·2050·4349·2d44··M-6(a).··-·PCI-D 
0003cb10:·5353·2d52·6571·2d31·312e·350a·2020·2d20··SS-Req-11.5.··-· 
0003cb20:·5043·492d·4453·5376·342d·3131·2e35·2e32··PCI-DSSv4-11.5.2 
0003cb30:·0a20·202d·2065·6e61·626c·655f·7374·7261··.··-·enable_stra 
0003cb40:·7465·6779·0a20·202d·206c·6f77·5f63·6f6d··tegy.··-·low_com 
0003cb50:·706c·6578·6974·790a·2020·2d20·6c6f·775f··plexity.··-·low_ 
0003cb60:·6469·7372·7570·7469·6f6e·0a20·202d·206d··disruption.··-·m 
0003cb70:·6564·6975·6d5f·7365·7665·7269·7479·0a20··edium_severity.· 
0003cb80:·202d·206e·6f5f·7265·626f·6f74·5f6e·6565···-·no_reboot_nee 
0003cb90:·6465·640a·2020·2d20·7061·636b·6167·655f··ded.··-·package_0003cb90:·6c65·640a·2020·7061·636b·6167·653a·0a20··led.··package:.·
0003cba0:·6169·6465·5f69·6e73·7461·6c6c·6564·0a3c··aide_installed.< 
0003cbb0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003cbc0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003cbd0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003cbe0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003cbf0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003cc00:·2223·6964·6d31·3334·3022·2074·6162·696e··"#idm1340"·tabin 
0003cc10:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003cc20:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003cc30:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003cc40:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003cc50:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003cc60:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB 
0003cc70:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
0003cc80:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003cc90:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003cca0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003ccb0:·6c61·7073·6522·2069·643d·2269·646d·3133··lapse"·id="idm13 
Max diff block lines reached; 2285541/2296495 bytes (99.52%) of diff not shown.
265 KB
html2text {}
    
Offset 39, 15 lines modifiedOffset 39, 15 lines modified
39 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*39 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v4.0·Control·Baseline·for·Anolis·OS·840 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v4.0·Control·Baseline·for·Anolis·OS·8
41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss
42 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*42 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
43 ····*·cpe:/o:anolis:anolis_os:843 ····*·cpe:/o:anolis:anolis_os:8
44 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*44 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
45 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8445 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
46 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)46 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
47 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
48 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s48 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
49 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e49 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
50 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l50 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
51 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n51 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
52 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g52 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
53 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s53 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 170, 14 lines modifiedOffset 170, 19 lines modified
170 include·install_aide170 include·install_aide
  
171 class·install_aide·{171 class·install_aide·{
172 ··package·{·'aide':172 ··package·{·'aide':
173 ····ensure·=>·'installed',173 ····ensure·=>·'installed',
174 ··}174 ··}
175 }175 }
 176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 177 [[packages]]
 178 name·=·"aide"
 179 version·=·"*"
176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
177 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
178 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
179 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
180 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
181 -·name:·Ensure·aide·is·installed185 -·name:·Ensure·aide·is·installed
182 ··package:186 ··package:
Offset 191, 19 lines modifiedOffset 196, 14 lines modified
191 ··-·PCI-DSSv4-11.5.2196 ··-·PCI-DSSv4-11.5.2
192 ··-·enable_strategy197 ··-·enable_strategy
193 ··-·low_complexity198 ··-·low_complexity
194 ··-·low_disruption199 ··-·low_disruption
195 ··-·medium_severity200 ··-·medium_severity
196 ··-·no_reboot_needed201 ··-·no_reboot_needed
197 ··-·package_aide_installed202 ··-·package_aide_installed
198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
199 [[packages]] 
200 name·=·"aide" 
201 version·=·"*" 
202 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·P\x8Pe\x8er\x8ri\x8io\x8od\x8di\x8ic\x8c·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8ti\x8io\x8on\x8n·o\x8of\x8f·A\x8AI\x8ID\x8DE\x8E·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*203 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·P\x8Pe\x8er\x8ri\x8io\x8od\x8di\x8ic\x8c·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8ti\x8io\x8on\x8n·o\x8of\x8f·A\x8AI\x8ID\x8DE\x8E·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
203 At·a·minimum,·AIDE·should·be·configured·to·run·a·weekly·scan.·To·implement·a·daily·execution·of204 At·a·minimum,·AIDE·should·be·configured·to·run·a·weekly·scan.·To·implement·a·daily·execution·of
204 AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/crontab:205 AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/crontab:
205 05·4·*·*·*·root·/usr/sbin/aide·--check206 05·4·*·*·*·root·/usr/sbin/aide·--check
206 To·implement·a·weekly·execution·of·AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/207 To·implement·a·weekly·execution·of·AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/
207 crontab:208 crontab:
208 05·4·*·*·0·root·/usr/sbin/aide·--check209 05·4·*·*·0·root·/usr/sbin/aide·--check
Offset 397, 33 lines modifiedOffset 397, 14 lines modified
397 ············_\x8i_\x8s_\x8m······1446397 ············_\x8i_\x8s_\x8m······1446
398 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1398 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1
399 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)399 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)
400 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,400 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,
401 ·····················FCS_TLSC_EXT.1401 ·····················FCS_TLSC_EXT.1
402 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174402 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
403 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7403 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7
404 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
405 var_system_crypto_policy='DEFAULT' 
  
  
406 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
407 rc=$? 
  
408 if·test·"$rc"·=·127;·then 
409 »       echo·"$stderr_of_call"·>&2 
410 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
411 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
412 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
413 »       false··#·end·with·an·error·code 
414 elif·test·"$rc"·!=·0;·then 
415 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
416 »       false··#·end·with·an·error·code 
417 fi 
418 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8404 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
419 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low405 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
420 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low406 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
421 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false407 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
422 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict408 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
423 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable409 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
424 ··set_fact:410 ··set_fact:
Offset 466, 14 lines modifiedOffset 447, 33 lines modified
466 ··-·PCI-DSSv4-2.2.7447 ··-·PCI-DSSv4-2.2.7
467 ··-·configure_crypto_policy448 ··-·configure_crypto_policy
468 ··-·high_severity449 ··-·high_severity
469 ··-·low_complexity450 ··-·low_complexity
470 ··-·low_disruption451 ··-·low_disruption
471 ··-·no_reboot_needed452 ··-·no_reboot_needed
472 ··-·restrict_strategy453 ··-·restrict_strategy
 454 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 455 var_system_crypto_policy='DEFAULT'
  
  
 456 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null)
 457 rc=$?
  
 458 if·test·"$rc"·=·127;·then
 459 »       echo·"$stderr_of_call"·>&2
 460 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2
 461 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2
 462 »       echo·"to·see·what·package·to·(re)install"·>&2
  
 463 »       false··#·end·with·an·error·code
 464 elif·test·"$rc"·!=·0;·then
 465 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
 466 »       false··#·end·with·an·error·code
 467 fi
473 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*468 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
474 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is469 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is
475 supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that470 supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that
476 Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either471 Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either
477 commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.472 commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
478 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate473 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate
479 ············expectations,·and·makes·system·configuration·more·fragmented.474 ············expectations,·and·makes·system·configuration·more·fragmented.
Offset 484, 19 lines modifiedOffset 484, 14 lines modified
484 ·····················(ii)484 ·····················(ii)
485 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1485 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1
486 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13486 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13
Max diff block lines reached; 265286/271270 bytes (97.79%) of diff not shown.
2.88 MB
./usr/share/doc/ssg-nondebian/ssg-anolis8-guide-standard.html
    
Offset 14281, 15 lines modifiedOffset 14281, 15 lines modified
00037c80:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·00037c80:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·
00037c90:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong00037c90:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong
00037ca0:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>00037ca0:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>
00037cb0:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str00037cb0:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str
00037cc0:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron00037cc0:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron
00037cd0:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············00037cd0:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············
00037ce0:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·2000037ce0:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·20
00037cf0:·3236·2d30·312d·3038·290a·2020·2020·2020··26-01-08).······00037cf0:·3234·2d31·322d·3037·290a·2020·2020·2020··24-12-07).······
00037d00:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><00037d00:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><
00037d10:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta00037d10:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta
00037d20:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<00037d20:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<
00037d30:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h00037d30:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h
00037d40:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.00037d40:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.
00037d50:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte00037d50:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte
00037d60:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"00037d60:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"
Offset 15087, 80 lines modifiedOffset 15087, 80 lines modified
0003aee0:·6574·3d22·2369·646d·3133·3339·2220·7461··et="#idm1339"·ta0003aee0:·6574·3d22·2369·646d·3133·3339·2220·7461··et="#idm1339"·ta
0003aef0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003aef0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003af00:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003af00:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003af10:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003af10:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003af20:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003af20:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003af30:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003af30:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003af40:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003af40:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003af50:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet· 
0003af60:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003af70:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003af80:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003af90:·6964·3d22·6964·6d31·3333·3922·3e3c·7461··id="idm1339"><ta 
0003afa0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003afb0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003afc0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003afd0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003afe0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003aff0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003b000:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b010:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003b020:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b030:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003b040:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003b050:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b060:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003af50:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin
 0003af60:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 0003af70:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003af80:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003af90:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003afa0:·6d31·3333·3922·3e3c·7072·653e·3c63·6f64··m1339"><pre><cod
 0003afb0:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]].
 0003afc0:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve
 0003afd0:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co
 0003afe0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0003aff0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 0003b000:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 0003b010:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 0003b020:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 0003b030:·646d·3133·3430·2220·7461·6269·6e64·6578··dm1340"·tabindex
 0003b040:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 0003b050:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 0003b060:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 0003b070:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 0003b080:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 0003b090:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl
 0003b0a0:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a
 0003b0b0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003b0c0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003b0d0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003b0e0:·6d31·3334·3022·3e3c·7461·626c·6520·636c··m1340"><table·cl
 0003b0f0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003b100:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003b110:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003b120:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003b130:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003b140:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b150:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003b160:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003b170:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b180:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
0003b070:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t0003b190:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0003b1a0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003b1b0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 0003b1c0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 0003b1d0:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-
 0003b1e0:·206e·616d·653a·2045·6e73·7572·6520·6169···name:·Ensure·ai
 0003b1f0:·6465·2069·7320·696e·7374·616c·6c65·640a··de·is·installed.
 0003b200:·2020·7061·636b·6167·653a·0a20·2020·206e····package:.····n
 0003b210:·616d·653a·2061·6964·650a·2020·2020·7374··ame:·aide.····st
 0003b220:·6174·653a·2070·7265·7365·6e74·0a20·2077··ate:·present.··w
 0003b230:·6865·6e3a·2061·6e73·6962·6c65·5f76·6972··hen:·ansible_vir
 0003b240:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type
 0003b250:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker
 0003b260:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv
 0003b270:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c
 0003b280:·6f6e·7461·696e·6572·225d·0a20·2074·6167··ontainer"].··tag
 0003b290:·733a·0a20·202d·2043·4a49·532d·352e·3130··s:.··-·CJIS-5.10
 0003b2a0:·2e31·2e33·0a20·202d·204e·4953·542d·3830··.1.3.··-·NIST-80
 0003b2b0:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··-
 0003b2c0:·2050·4349·2d44·5353·2d52·6571·2d31·312e···PCI-DSS-Req-11.
 0003b2d0:·350a·2020·2d20·5043·492d·4453·5376·342d··5.··-·PCI-DSSv4-
 0003b2e0:·3131·2e35·2e32·0a20·202d·2065·6e61·626c··11.5.2.··-·enabl
 0003b2f0:·655f·7374·7261·7465·6779·0a20·202d·206c··e_strategy.··-·l
 0003b300:·6f77·5f63·6f6d·706c·6578·6974·790a·2020··ow_complexity.··
 0003b310:·2d20·6c6f·775f·6469·7372·7570·7469·6f6e··-·low_disruption
 0003b320:·0a20·202d·206d·6564·6975·6d5f·7365·7665··.··-·medium_seve
 0003b330:·7269·7479·0a20·202d·206e·6f5f·7265·626f··rity.··-·no_rebo
 0003b340:·6f74·5f6e·6565·6465·640a·2020·2d20·7061··ot_needed.··-·pa
 0003b350:·636b·6167·655f·6169·6465·5f69·6e73·7461··ckage_aide_insta
0003b080:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003b090:·636f·6465·3e2d·206e·616d·653a·2045·6e73··code>-·name:·Ens 
0003b0a0:·7572·6520·6169·6465·2069·7320·696e·7374··ure·aide·is·inst 
0003b0b0:·616c·6c65·640a·2020·7061·636b·6167·653a··alled.··package: 
0003b0c0:·0a20·2020·206e·616d·653a·2061·6964·650a··.····name:·aide. 
0003b0d0:·2020·2020·7374·6174·653a·2070·7265·7365······state:·prese 
0003b0e0:·6e74·0a20·2077·6865·6e3a·2061·6e73·6962··nt.··when:·ansib 
0003b0f0:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio 
0003b100:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·[" 
0003b110:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",· 
0003b120:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma 
0003b130:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"] 
0003b140:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI 
0003b150:·532d·352e·3130·2e31·2e33·0a20·202d·204e··S-5.10.1.3.··-·N 
0003b160:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6( 
0003b170:·6129·0a20·202d·2050·4349·2d44·5353·2d52··a).··-·PCI-DSS-R 
0003b180:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI- 
0003b190:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··- 
0003b1a0:·2065·6e61·626c·655f·7374·7261·7465·6779···enable_strategy 
0003b1b0:·0a20·202d·206c·6f77·5f63·6f6d·706c·6578··.··-·low_complex 
0003b1c0:·6974·790a·2020·2d20·6c6f·775f·6469·7372··ity.··-·low_disr 
0003b1d0:·7570·7469·6f6e·0a20·202d·206d·6564·6975··uption.··-·mediu 
Max diff block lines reached; 2696088/2706904 bytes (99.60%) of diff not shown.
302 KB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Anolis·OS·838 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Anolis·OS·8
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:anolis:anolis_os:841 ····*·cpe:/o:anolis:anolis_os:8
42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
43 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8443 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
49 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n49 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
50 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g50 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
51 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s51 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 126, 14 lines modifiedOffset 126, 19 lines modified
126 include·install_aide126 include·install_aide
  
127 class·install_aide·{127 class·install_aide·{
128 ··package·{·'aide':128 ··package·{·'aide':
129 ····ensure·=>·'installed',129 ····ensure·=>·'installed',
130 ··}130 ··}
131 }131 }
 132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 133 [[packages]]
 134 name·=·"aide"
 135 version·=·"*"
132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
137 -·name:·Ensure·aide·is·installed141 -·name:·Ensure·aide·is·installed
138 ··package:142 ··package:
Offset 147, 19 lines modifiedOffset 152, 14 lines modified
147 ··-·PCI-DSSv4-11.5.2152 ··-·PCI-DSSv4-11.5.2
148 ··-·enable_strategy153 ··-·enable_strategy
149 ··-·low_complexity154 ··-·low_complexity
150 ··-·low_disruption155 ··-·low_disruption
151 ··-·medium_severity156 ··-·medium_severity
152 ··-·no_reboot_needed157 ··-·no_reboot_needed
153 ··-·package_aide_installed158 ··-·package_aide_installed
154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
155 [[packages]] 
156 name·=·"aide" 
157 version·=·"*" 
158 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·P\x8Pe\x8er\x8ri\x8io\x8od\x8di\x8ic\x8c·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8ti\x8io\x8on\x8n·o\x8of\x8f·A\x8AI\x8ID\x8DE\x8E·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*159 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·P\x8Pe\x8er\x8ri\x8io\x8od\x8di\x8ic\x8c·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8ti\x8io\x8on\x8n·o\x8of\x8f·A\x8AI\x8ID\x8DE\x8E·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
159 At·a·minimum,·AIDE·should·be·configured·to·run·a·weekly·scan.·To·implement·a·daily·execution·of160 At·a·minimum,·AIDE·should·be·configured·to·run·a·weekly·scan.·To·implement·a·daily·execution·of
160 AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/crontab:161 AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/crontab:
161 05·4·*·*·*·root·/usr/sbin/aide·--check162 05·4·*·*·*·root·/usr/sbin/aide·--check
162 To·implement·a·weekly·execution·of·AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/163 To·implement·a·weekly·execution·of·AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/
163 crontab:164 crontab:
164 05·4·*·*·0·root·/usr/sbin/aide·--check165 05·4·*·*·0·root·/usr/sbin/aide·--check
Offset 353, 33 lines modifiedOffset 353, 14 lines modified
353 ············_\x8i_\x8s_\x8m······1446353 ············_\x8i_\x8s_\x8m······1446
354 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1354 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1
355 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)355 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)
356 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,356 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,
357 ·····················FCS_TLSC_EXT.1357 ·····················FCS_TLSC_EXT.1
358 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174358 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
359 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7359 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7
360 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
361 var_system_crypto_policy='DEFAULT' 
  
  
362 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
363 rc=$? 
  
364 if·test·"$rc"·=·127;·then 
365 »       echo·"$stderr_of_call"·>&2 
366 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
367 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
368 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
369 »       false··#·end·with·an·error·code 
370 elif·test·"$rc"·!=·0;·then 
371 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
372 »       false··#·end·with·an·error·code 
373 fi 
374 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8360 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
375 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low361 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
376 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low362 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
377 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false363 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
378 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict364 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
379 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable365 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
380 ··set_fact:366 ··set_fact:
Offset 422, 14 lines modifiedOffset 403, 33 lines modified
422 ··-·PCI-DSSv4-2.2.7403 ··-·PCI-DSSv4-2.2.7
423 ··-·configure_crypto_policy404 ··-·configure_crypto_policy
424 ··-·high_severity405 ··-·high_severity
425 ··-·low_complexity406 ··-·low_complexity
426 ··-·low_disruption407 ··-·low_disruption
427 ··-·no_reboot_needed408 ··-·no_reboot_needed
428 ··-·restrict_strategy409 ··-·restrict_strategy
 410 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 411 var_system_crypto_policy='DEFAULT'
  
  
 412 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null)
 413 rc=$?
  
 414 if·test·"$rc"·=·127;·then
 415 »       echo·"$stderr_of_call"·>&2
 416 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2
 417 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2
 418 »       echo·"to·see·what·package·to·(re)install"·>&2
  
 419 »       false··#·end·with·an·error·code
 420 elif·test·"$rc"·!=·0;·then
 421 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
 422 »       false··#·end·with·an·error·code
 423 fi
429 Group  ·Updating·Software·  Group·contains·1·rule424 Group  ·Updating·Software·  Group·contains·1·rule
430 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also425 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also
431 provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called426 provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called
432 S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.427 S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.
  
433 Anolis·OS·8·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records428 Anolis·OS·8·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records
434 metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all429 metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all
Offset 634, 20 lines modifiedOffset 634, 14 lines modified
634 ···········Display·of·a·standardized·and·approved·use·notification·before·granting·access·to·the634 ···········Display·of·a·standardized·and·approved·use·notification·before·granting·access·to·the
635 ···········operating·system·ensures·privacy·and·security·notification·verbiage·used·is·consistent635 ···········operating·system·ensures·privacy·and·security·notification·verbiage·used·is·consistent
636 Rationale:·with·applicable·federal·laws,·Executive·Orders,·directives,·policies,·regulations,636 Rationale:·with·applicable·federal·laws,·Executive·Orders,·directives,·policies,·regulations,
Max diff block lines reached; 303166/309084 bytes (98.09%) of diff not shown.
23.1 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-anssi_bp28_enhanced.html
    
Offset 14565, 15 lines modifiedOffset 14565, 15 lines modified
00038e40:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren00038e40:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren
00038e50:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro00038e50:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro
00038e60:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron00038e60:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron
00038e70:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s00038e70:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s
00038e80:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str00038e80:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str
00038e90:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········00038e90:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········
00038ea0:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·00038ea0:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·
00038eb0:·3230·3236·2d30·312d·3038·290a·2020·2020··2026-01-08).····00038eb0:·3230·3234·2d31·322d·3037·290a·2020·2020··2024-12-07).····
00038ec0:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li00038ec0:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li
00038ed0:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>00038ed0:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>
00038ee0:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content00038ee0:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content
00038ef0:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a00038ef0:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a
00038f00:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or00038f00:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or
00038f10:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con00038f10:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con
00038f20:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste00038f20:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste
Offset 15321, 236 lines modifiedOffset 15321, 236 lines modified
0003bd80:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003bd80:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003bd90:·6964·6d38·3030·3222·2074·6162·696e·6465··idm8002"·tabinde0003bd90:·6964·6d38·3030·3222·2074·6162·696e·6465··idm8002"·tabinde
0003bda0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003bda0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003bdb0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003bdb0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003bdc0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003bdc0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003bdd0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003bdd0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003bde0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003bde0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003bdf0:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe0003bdf0:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco
0003be00:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a0003be00:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...<
0003be10:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003be10:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003be20:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003be20:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003be30:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003be30:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
0003be40:·6d38·3030·3222·3e3c·7461·626c·6520·636c··m8002"><table·cl0003be40:·6964·6d38·3030·3222·3e3c·7461·626c·6520··idm8002"><table·
0003be50:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003be50:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003be60:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003be60:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003be70:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003be70:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003be80:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003be80:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0003be90:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003be90:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0003bea0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003bea0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003beb0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003beb0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003bec0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003bec0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003bed0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003bed0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003bee0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><0003bee0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
0003bef0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t0003bef0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
0003bf00:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate0003bf00:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
0003bf10:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab0003bf10:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
0003bf20:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta0003bf20:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
0003bf30:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i0003bf30:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003bf40:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add=
 0003bf50:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr
 0003bf60:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 0003bf70:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 0003bf80:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 0003bf90:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 0003bfa0:·6172·6765·743d·2223·6964·6d38·3030·3322··arget="#idm8003"
 0003bfb0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 0003bfc0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 0003bfd0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 0003bfe0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 0003bff0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 0003c000:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003c010:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe
 0003c020:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003c030:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003c040:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003c050:·2220·6964·3d22·6964·6d38·3030·3322·3e3c··"·id="idm8003"><
 0003c060:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003c070:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003c080:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003c090:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003c0a0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003bf40:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a 
0003bf50:·6964·650a·0a63·6c61·7373·2069·6e73·7461··ide..class·insta 
0003bf60:·6c6c·5f61·6964·6520·7b0a·2020·7061·636b··ll_aide·{.··pack 
0003bf70:·6167·6520·7b20·2761·6964·6527·3a0a·2020··age·{·'aide':.·· 
0003bf80:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·' 
0003bf90:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}. 
0003bfa0:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre>< 
0003bfb0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003bfc0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003bfd0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003bfe0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003bff0:·6574·3d22·2369·646d·3830·3033·2220·7461··et="#idm8003"·ta 
0003c000:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003c010:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003c020:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003c030:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003c040:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003c050:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003c060:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
0003c070:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003c080:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003c090:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003c0a0:·2269·646d·3830·3033·223e·3c74·6162·6c65··"idm8003"><table 
0003c0b0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003c0c0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003c0d0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003c0e0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003c0f0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003c100:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003c110:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003c120:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003c130:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003c140:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003c150:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003c160:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003c170:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003c0b0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003c180:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0003c190:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003c1a0:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation· 
0003c1b0:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on 
0003c1c0:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl 
0003c1d0:·6174·666f·726d·730a·6966·205b·2021·202d··atforms.if·[·!·- 
0003c1e0:·6620·2f2e·646f·636b·6572·656e·7620·5d20··f·/.dockerenv·]· 
0003c1f0:·2661·6d70·3b26·616d·703b·205b·2021·202d··&amp;&amp;·[·!·- 
0003c200:·6620·2f72·756e·2f2e·636f·6e74·6169·6e65··f·/run/.containe 
0003c210:·7265·6e76·205d·3b20·7468·656e·0a0a·6966··renv·];·then..if 
0003c220:·2021·2072·706d·202d·7120·2d2d·7175·6965···!·rpm·-q·--quie 
0003c230:·7420·2261·6964·6522·203b·2074·6865·6e0a··t·"aide"·;·then. 
0003c240:·2020·2020·7975·6d20·696e·7374·616c·6c20······yum·install· 
0003c250:·2d79·2022·6169·6465·220a·6669·0a0a·656c··-y·"aide".fi..el 
0003c260:·7365·0a20·2020·2026·6774·3b26·616d·703b··se.····&gt;&amp; 
0003c270:·3220·6563·686f·2027·5265·6d65·6469·6174··2·echo·'Remediat 
0003c280:·696f·6e20·6973·206e·6f74·2061·7070·6c69··ion·is·not·appli 
0003c290:·6361·626c·652c·206e·6f74·6869·6e67·2077··cable,·nothing·w 
0003c2a0:·6173·2064·6f6e·6527·0a66·690a·3c2f·636f··as·done'.fi.</co 
0003c2b0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003c2c0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003c2d0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003c2e0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003c2f0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
Max diff block lines reached; 22148641/22180987 bytes (99.85%) of diff not shown.
1.94 MB
html2text {}
Max HTML report size reached
23.4 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-anssi_bp28_high.html
    
Offset 14564, 15 lines modifiedOffset 14564, 15 lines modified
00038e30:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren00038e30:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren
00038e40:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro00038e40:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro
00038e50:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron00038e50:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron
00038e60:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s00038e60:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s
00038e70:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str00038e70:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str
00038e80:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········00038e80:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········
00038e90:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·00038e90:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·
00038ea0:·3230·3236·2d30·312d·3038·290a·2020·2020··2026-01-08).····00038ea0:·3230·3234·2d31·322d·3037·290a·2020·2020··2024-12-07).····
00038eb0:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li00038eb0:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li
00038ec0:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>00038ec0:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>
00038ed0:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content00038ed0:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content
00038ee0:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a00038ee0:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a
00038ef0:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or00038ef0:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or
00038f00:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con00038f00:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con
00038f10:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste00038f10:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste
Offset 15326, 236 lines modifiedOffset 15326, 236 lines modified
0003bdd0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003bdd0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003bde0:·3d22·2369·646d·3830·3032·2220·7461·6269··="#idm8002"·tabi0003bde0:·3d22·2369·646d·3830·3032·2220·7461·6269··="#idm8002"·tabi
0003bdf0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003bdf0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003be00:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003be00:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003be10:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003be10:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003be20:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003be20:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003be30:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003be30:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003be40:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu0003be40:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
0003be50:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...0003be50:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
0003be60:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003be60:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003be70:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003be70:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003be80:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003be80:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003be90:·2269·646d·3830·3032·223e·3c74·6162·6c65··"idm8002"><table0003be90:·643d·2269·646d·3830·3032·223e·3c74·6162··d="idm8002"><tab
0003bea0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003bea0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003beb0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003beb0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003bec0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003bec0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003bed0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003bed0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003bee0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003bee0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003bef0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003bef0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003bf00:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003bf00:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
0003bf10:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003bf10:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003bf20:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003bf20:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003bf30:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t0003bf30:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
0003bf40:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>0003bf40:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003bf50:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003bf50:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003bf60:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003bf60:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003bf70:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003bf70:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003bf80:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod0003bf80:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003bf90:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a
 0003bfa0:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code><
 0003bfb0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003bfc0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003bfd0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003bfe0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003bff0:·612d·7461·7267·6574·3d22·2369·646d·3830··a-target="#idm80
 0003c000:·3033·2220·7461·6269·6e64·6578·3d22·3022··03"·tabindex="0"
 0003c010:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003c020:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003c030:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003c040:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003c050:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003c060:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
 0003c070:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0003c080:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003c090:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003c0a0:·7073·6522·2069·643d·2269·646d·3830·3033··pse"·id="idm8003
 0003c0b0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003c0c0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0003c0d0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0003c0e0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003c0f0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003c100:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003c110:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003c120:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003bf90:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal 
0003bfa0:·6c5f·6169·6465·0a0a·636c·6173·7320·696e··l_aide..class·in 
0003bfb0:·7374·616c·6c5f·6169·6465·207b·0a20·2070··stall_aide·{.··p 
0003bfc0:·6163·6b61·6765·207b·2027·6169·6465·273a··ackage·{·'aide': 
0003bfd0:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt 
0003bfe0:·3b20·2769·6e73·7461·6c6c·6564·272c·0a20··;·'installed',.· 
0003bff0:·207d·0a7d·0a3c·2f63·6f64·653e·3c2f·7072···}.}.</code></pr 
0003c000:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003c010:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003c020:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003c030:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003c040:·6172·6765·743d·2223·6964·6d38·3030·3322··arget="#idm8003" 
0003c050:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003c060:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003c070:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003c080:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003c090:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003c0a0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003c0b0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script· 
0003c0c0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003c0d0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003c0e0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003c0f0:·6964·3d22·6964·6d38·3030·3322·3e3c·7461··id="idm8003"><ta 
0003c100:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003c110:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003c120:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003c130:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003c140:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003c150:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003c130:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003c160:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003c140:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 0003c150:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003c170:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003c180:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003c190:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003c1a0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003c1b0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003c1c0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003c1d0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0003c1e0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003c1f0:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati 
0003c200:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable 
0003c210:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain 
0003c220:·2070·6c61·7466·6f72·6d73·0a69·6620·5b20···platforms.if·[· 
0003c230:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv 
0003c240:·205d·2026·616d·703b·2661·6d70·3b20·5b20···]·&amp;&amp;·[· 
0003c250:·2120·2d66·202f·7275·6e2f·2e63·6f6e·7461··!·-f·/run/.conta 
0003c260:·696e·6572·656e·7620·5d3b·2074·6865·6e0a··inerenv·];·then. 
0003c270:·0a69·6620·2120·7270·6d20·2d71·202d·2d71··.if·!·rpm·-q·--q 
0003c280:·7569·6574·2022·6169·6465·2220·3b20·7468··uiet·"aide"·;·th 
0003c290:·656e·0a20·2020·2079·756d·2069·6e73·7461··en.····yum·insta 
0003c2a0:·6c6c·202d·7920·2261·6964·6522·0a66·690a··ll·-y·"aide".fi. 
0003c2b0:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a 
0003c2c0:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed 
0003c2d0:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap 
0003c2e0:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin 
0003c2f0:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.< 
0003c300:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
Max diff block lines reached; 22421935/22454281 bytes (99.86%) of diff not shown.
1.97 MB
html2text {}
Max HTML report size reached
9.85 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-anssi_bp28_intermediary.html
    
Offset 14566, 15 lines modifiedOffset 14566, 15 lines modified
00038e50:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren00038e50:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren
00038e60:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro00038e60:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro
00038e70:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron00038e70:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron
00038e80:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s00038e80:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s
00038e90:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str00038e90:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str
00038ea0:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········00038ea0:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········
00038eb0:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·00038eb0:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·
00038ec0:·3230·3236·2d30·312d·3038·290a·2020·2020··2026-01-08).····00038ec0:·3230·3234·2d31·322d·3037·290a·2020·2020··2024-12-07).····
00038ed0:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li00038ed0:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li
00038ee0:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>00038ee0:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>
00038ef0:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content00038ef0:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content
00038f00:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a00038f00:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a
00038f10:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or00038f10:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or
00038f20:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con00038f20:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con
00038f30:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste00038f30:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste
Offset 15317, 235 lines modifiedOffset 15317, 235 lines modified
0003bd40:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003bd40:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003bd50:·3830·3032·2220·7461·6269·6e64·6578·3d22··8002"·tabindex="0003bd50:·3830·3032·2220·7461·6269·6e64·6578·3d22··8002"·tabindex="
0003bd60:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003bd60:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003bd70:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003bd70:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003bd80:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003bd80:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003bd90:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003bd90:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003bda0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003bda0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003bdb0:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s0003bdb0:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
0003bdc0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003bdc0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003bdd0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003bdd0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003bde0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003bde0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003bdf0:·6c61·7073·6522·2069·643d·2269·646d·3830··lapse"·id="idm800003bdf0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003be00:·3032·223e·3c74·6162·6c65·2063·6c61·7373··02"><table·class0003be00:·3830·3032·223e·3c74·6162·6c65·2063·6c61··8002"><table·cla
0003be10:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003be10:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003be20:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003be20:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003be30:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003be30:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003be40:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003be40:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003be50:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003be50:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003be60:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003be60:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003be70:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003be70:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003be80:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003be80:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
0003be90:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003be90:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003bea0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>0003bea0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
0003beb0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><0003beb0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
0003bec0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003bec0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
0003bed0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0003bed0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003bee0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003bee0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0003bef0:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl0003bef0:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p
 0003bf00:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid
 0003bf10:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><
 0003bf20:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0003bf30:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0003bf40:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0003bf50:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0003bf60:·6574·3d22·2369·646d·3830·3033·2220·7461··et="#idm8003"·ta
 0003bf70:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 0003bf80:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 0003bf90:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 0003bfa0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 0003bfb0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 0003bfc0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003bfd0:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.
 0003bfe0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003bff0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003bf00:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide 
0003bf10:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_ 
0003bf20:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package 
0003bf30:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e 
0003bf40:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins 
0003bf50:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.< 
0003bf60:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003bf70:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003bf80:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003bf90:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003bfa0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003bfb0:·2223·6964·6d38·3030·3322·2074·6162·696e··"#idm8003"·tabin 
0003bfc0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003bfd0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003bfe0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003bff0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003c000:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003c010:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
0003c020:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
0003c030:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003c040:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003c000:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003c010:·643d·2269·646d·3830·3033·223e·3c74·6162··d="idm8003"><tab
 0003c020:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0003c030:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0003c040:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 0003c050:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 0003c060:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003c050:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003c060:·6d38·3030·3322·3e3c·7461·626c·6520·636c··m8003"><table·cl 
0003c070:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003c080:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003c090:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0003c0a0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0003c0b0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0003c0c0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003c0d0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003c0e0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003c070:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003c0f0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003c080:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0003c090:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003c100:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
0003c110:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
0003c120:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
0003c130:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
0003c140:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
0003c150:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code># 
0003c160:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is· 
0003c170:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only· 
0003c180:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf 
0003c190:·6f72·6d73·0a69·6620·5b20·2120·2d66·202f··orms.if·[·!·-f·/ 
0003c1a0:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am 
0003c1b0:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/ 
0003c1c0:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren 
0003c1d0:·7620·5d3b·2074·6865·6e0a·0a69·6620·2120··v·];·then..if·!· 
0003c1e0:·7270·6d20·2d71·202d·2d71·7569·6574·2022··rpm·-q·--quiet·" 
0003c1f0:·6169·6465·2220·3b20·7468·656e·0a20·2020··aide"·;·then.··· 
0003c200:·2079·756d·2069·6e73·7461·6c6c·202d·7920···yum·install·-y· 
0003c210:·2261·6964·6522·0a66·690a·0a65·6c73·650a··"aide".fi..else. 
0003c220:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e 
0003c230:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation 
0003c240:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab 
0003c250:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was· 
0003c260:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code> 
0003c270:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003c280:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003c290:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003c2a0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003c2b0:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8 
Max diff block lines reached; 9199974/9232182 bytes (99.65%) of diff not shown.
1.04 MB
html2text {}
    
Offset 74, 15 lines modifiedOffset 74, 15 lines modified
74 ····*·cpe:/o:redhat:enterprise_linux:8.774 ····*·cpe:/o:redhat:enterprise_linux:8.7
75 ····*·cpe:/o:redhat:enterprise_linux:8.875 ····*·cpe:/o:redhat:enterprise_linux:8.8
76 ····*·cpe:/o:redhat:enterprise_linux:8.976 ····*·cpe:/o:redhat:enterprise_linux:8.9
77 ····*·cpe:/o:redhat:enterprise_linux:877 ····*·cpe:/o:redhat:enterprise_linux:8
78 ····*·cpe:/o:centos:centos:878 ····*·cpe:/o:centos:centos:8
79 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*79 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
80 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8480 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
81 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)81 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
82 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*82 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
83 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s83 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
84 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e84 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
85 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l85 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
86 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n86 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
87 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s87 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
88 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s88 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 147, 41 lines modifiedOffset 147, 45 lines modified
147 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3147 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
148 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5148 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
149 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199149 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
150 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79150 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
151 ············_\x8c_\x8i_\x8s············5.3.1151 ············_\x8c_\x8i_\x8s············5.3.1
152 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2152 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
153 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule153 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule
 154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 159 package·--add=aide
154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low161 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low162 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false163 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable164 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
159 include·install_aide165 include·install_aide
  
160 class·install_aide·{166 class·install_aide·{
161 ··package·{·'aide':167 ··package·{·'aide':
162 ····ensure·=>·'installed',168 ····ensure·=>·'installed',
163 ··}169 ··}
164 }170 }
 171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 172 [[packages]]
 173 name·=·"aide"
 174 version·=·"*"
165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low176 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low177 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false178 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable179 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
170 #·Remediation·is·applicable·only·in·certain·platforms 
171 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
 180 package·install·aide
172 if·!·rpm·-q·--quiet·"aide"·;·then 
173 ····yum·install·-y·"aide" 
174 fi 
  
175 else 
176 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
177 fi 
178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
183 -·name:·Ensure·aide·is·installed186 -·name:·Ensure·aide·is·installed
184 ··package:187 ··package:
Offset 196, 33 lines modifiedOffset 200, 29 lines modified
196 ··-·PCI-DSSv4-11.5.2200 ··-·PCI-DSSv4-11.5.2
197 ··-·enable_strategy201 ··-·enable_strategy
198 ··-·low_complexity202 ··-·low_complexity
199 ··-·low_disruption203 ··-·low_disruption
200 ··-·medium_severity204 ··-·medium_severity
201 ··-·no_reboot_needed205 ··-·no_reboot_needed
202 ··-·package_aide_installed206 ··-·package_aide_installed
203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
204 [[packages]] 
205 name·=·"aide" 
206 version·=·"*" 
207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 212 #·Remediation·is·applicable·only·in·certain·platforms
 213 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 214 if·!·rpm·-q·--quiet·"aide"·;·then
 215 ····yum·install·-y·"aide"
 216 fi
212 package·install·aide 
213 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
214 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
215 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
216 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
217 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
218 package·--add=aide217 else
 218 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 219 fi
219 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*220 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
220 Run·the·following·command·to·generate·a·new·database:221 Run·the·following·command·to·generate·a·new·database:
221 $·sudo·/usr/sbin/aide·--init222 $·sudo·/usr/sbin/aide·--init
222 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the223 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
223 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these224 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
224 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their225 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
225 integrity.·The·newly-generated·database·can·be·installed·as·follows:226 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 247, 28 lines modifiedOffset 247, 14 lines modified
247 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3247 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
248 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5248 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
249 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199249 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
250 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79250 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
251 ············_\x8c_\x8i_\x8s············5.3.1251 ············_\x8c_\x8i_\x8s············5.3.1
252 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2252 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
253 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule253 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule
254 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
255 #·Remediation·is·applicable·only·in·certain·platforms 
256 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
257 if·!·rpm·-q·--quiet·"aide"·;·then 
258 ····yum·install·-y·"aide" 
259 fi 
  
Max diff block lines reached; 1087627/1093510 bytes (99.46%) of diff not shown.
3.21 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-anssi_bp28_minimal.html
    
Offset 14564, 16 lines modifiedOffset 14564, 16 lines modified
00038e30:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00038e30:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00038e40:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00038e40:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00038e50:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000038e50:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00038e60:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></00038e60:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
00038e70:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00038e70:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00038e80:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00038e80:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00038e90:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00038e90:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00038ea0:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600038ea0:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
00038eb0:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········00038eb0:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00038ec0:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00038ec0:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00038ed0:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00038ed0:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00038ee0:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00038ee0:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00038ef0:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00038ef0:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00038f00:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00038f00:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00038f10:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00038f10:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00038f20:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00038f20:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
Offset 14984, 217 lines modifiedOffset 14984, 217 lines modified
0003a870:·612d·7461·7267·6574·3d22·2369·646d·3133··a-target="#idm130003a870:·612d·7461·7267·6574·3d22·2369·646d·3133··a-target="#idm13
0003a880:·3231·3822·2074·6162·696e·6465·783d·2230··218"·tabindex="00003a880:·3231·3822·2074·6162·696e·6465·783d·2230··218"·tabindex="0
0003a890:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003a890:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003a8a0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003a8a0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003a8b0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003a8b0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003a8c0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003a8c0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003a8d0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003a8d0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003a8e0:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn0003a8e0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·
 0003a8f0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003a900:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003a910:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003a920:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1
 0003a930:·3332·3138·223e·3c74·6162·6c65·2063·6c61··3218"><table·cla
 0003a940:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0003a950:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0003a960:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003a970:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003a980:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003a990:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003a9a0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0003a9b0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003a9c0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003a9d0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
 0003a9e0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 0003a9f0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003aa00:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 0003aa10:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 0003aa20:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p
 0003aa30:·6163·6b61·6765·202d·2d61·6464·3d64·6e66··ackage·--add=dnf
 0003aa40:·2d61·7574·6f6d·6174·6963·0a3c·2f63·6f64··-automatic.</cod
 0003aa50:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003aa60:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003aa70:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003aa80:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003aa90:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003aaa0:·6d31·3332·3139·2220·7461·6269·6e64·6578··m13219"·tabindex
 0003aab0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 0003aac0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 0003aad0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 0003aae0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 0003aaf0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 0003ab00:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet
 0003ab10:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0003ab20:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003ab30:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003ab40:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003ab50:·3133·3231·3922·3e3c·7461·626c·6520·636c··13219"><table·cl
 0003ab60:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003ab70:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003ab80:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003ab90:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003aba0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003abb0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003abc0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003abd0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003abe0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003abf0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 0003ac00:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0003ac10:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003ac20:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 0003ac30:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 0003ac40:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i
 0003ac50:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f64··nclude·install_d
 0003ac60:·6e66·2d61·7574·6f6d·6174·6963·0a0a·636c··nf-automatic..cl
 0003ac70:·6173·7320·696e·7374·616c·6c5f·646e·662d··ass·install_dnf-
 0003ac80:·6175·746f·6d61·7469·6320·7b0a·2020·7061··automatic·{.··pa
 0003ac90:·636b·6167·6520·7b20·2764·6e66·2d61·7574··ckage·{·'dnf-aut
 0003aca0:·6f6d·6174·6963·273a·0a20·2020·2065·6e73··omatic':.····ens
 0003acb0:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta
 0003acc0:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c
 0003acd0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003ace0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003acf0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003ad00:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 0003ad10:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0003ad20:·6964·6d31·3332·3230·2220·7461·6269·6e64··idm13220"·tabind
 0003ad30:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003ad40:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003ad50:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003ad60:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003ad70:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003ad80:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu
 0003ad90:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn
0003a8f0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003ada0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003a900:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003a910:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003a920:·6170·7365·2220·6964·3d22·6964·6d31·3332··apse"·id="idm132 
0003a930:·3138·223e·3c74·6162·6c65·2063·6c61·7373··18"><table·class 
0003a940:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003a950:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003a960:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003a970:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003a980:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003a990:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003a9a0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003a9b0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003a9c0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003a9d0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003a9e0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
0003a9f0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003aa00:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003aa10:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003aa20:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl 
0003aa30:·7564·6520·696e·7374·616c·6c5f·646e·662d··ude·install_dnf- 
0003aa40:·6175·746f·6d61·7469·630a·0a63·6c61·7373··automatic..class 
0003aa50:·2069·6e73·7461·6c6c·5f64·6e66·2d61·7574···install_dnf-aut 
0003aa60:·6f6d·6174·6963·207b·0a20·2070·6163·6b61··omatic·{.··packa 
0003aa70:·6765·207b·2027·646e·662d·6175·746f·6d61··ge·{·'dnf-automa 
0003aa80:·7469·6327·3a0a·2020·2020·656e·7375·7265··tic':.····ensure 
0003aa90:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe 
Max diff block lines reached; 3111865/3141727 bytes (99.05%) of diff not shown.
224 KB
html2text {}
    
Offset 74, 15 lines modifiedOffset 74, 15 lines modified
74 ····*·cpe:/o:redhat:enterprise_linux:8.774 ····*·cpe:/o:redhat:enterprise_linux:8.7
75 ····*·cpe:/o:redhat:enterprise_linux:8.875 ····*·cpe:/o:redhat:enterprise_linux:8.8
76 ····*·cpe:/o:redhat:enterprise_linux:8.976 ····*·cpe:/o:redhat:enterprise_linux:8.9
77 ····*·cpe:/o:redhat:enterprise_linux:877 ····*·cpe:/o:redhat:enterprise_linux:8
78 ····*·cpe:/o:centos:centos:878 ····*·cpe:/o:centos:centos:8
79 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*79 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
80 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8480 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
81 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)81 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
82 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*82 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
83 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s83 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
84 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e84 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
85 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l85 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
86 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s86 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
87 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s87 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
88 ·········1.·_\x8D_\x8H_\x8C_\x8P88 ·········1.·_\x8D_\x8H_\x8C_\x8P
Offset 111, 35 lines modifiedOffset 111, 45 lines modified
111 $·sudo·yum·install·dnf-automatic111 $·sudo·yum·install·dnf-automatic
112 Rationale:··dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade112 Rationale:··dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade
113 ············suitable·for·automatic,·regular·execution.113 ············suitable·for·automatic,·regular·execution.
114 Severity: ··medium114 Severity: ··medium
115 Rule·ID:····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed115 Rule·ID:····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
116 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080116 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
117 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61117 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
 118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 123 package·--add=dnf-automatic
118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low126 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false127 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable128 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
123 include·install_dnf-automatic129 include·install_dnf-automatic
  
124 class·install_dnf-automatic·{130 class·install_dnf-automatic·{
125 ··package·{·'dnf-automatic':131 ··package·{·'dnf-automatic':
126 ····ensure·=>·'installed',132 ····ensure·=>·'installed',
127 ··}133 ··}
128 }134 }
 135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 136 [[packages]]
 137 name·=·"dnf-automatic"
 138 version·=·"*"
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 144 package·install·dnf-automatic
134 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then 
135 ····yum·install·-y·"dnf-automatic" 
136 fi 
137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
142 -·name:·Ensure·dnf-automatic·is·installed150 -·name:·Ensure·dnf-automatic·is·installed
143 ··package:151 ··package:
Offset 148, 33 lines modifiedOffset 158, 23 lines modified
148 ··tags:158 ··tags:
149 ··-·enable_strategy159 ··-·enable_strategy
150 ··-·low_complexity160 ··-·low_complexity
151 ··-·low_disruption161 ··-·low_disruption
152 ··-·medium_severity162 ··-·medium_severity
153 ··-·no_reboot_needed163 ··-·no_reboot_needed
154 ··-·package_dnf-automatic_installed164 ··-·package_dnf-automatic_installed
155 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
156 [[packages]] 
157 name·=·"dnf-automatic" 
158 version·=·"*" 
159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
160 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
161 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
162 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
163 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
164 package·install·dnf-automatic 
165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
170 package·--add=dnf-automatic170 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
 171 ····yum·install·-y·"dnf-automatic"
 172 fi
171 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*173 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
172 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed174 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
173 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/175 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
174 automatic.conf.176 automatic.conf.
175 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation177 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
176 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and178 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
177 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in179 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 184, 14 lines modifiedOffset 184, 36 lines modified
184 Severity: ··medium184 Severity: ··medium
185 Rule·ID:····xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates185 Rule·ID:····xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates
186 ············_\x8i_\x8s_\x8m····0940,·1144,·1467,·1472,·1483,·1493,·1494,·1495186 ············_\x8i_\x8s_\x8m····0940,·1144,·1467,·1472,·1483,·1493,·1494,·1495
187 ············_\x8n_\x8i_\x8s_\x8t···SI-2(5),·CM-6(a),·SI-2(c)187 ············_\x8n_\x8i_\x8s_\x8t···SI-2(5),·CM-6(a),·SI-2(c)
188 References:·_\x8o_\x8s_\x8p_\x8p···FMT_SMF_EXT.1188 References:·_\x8o_\x8s_\x8p_\x8p···FMT_SMF_EXT.1
189 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080189 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
190 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61190 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
 191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···unknown
 196 -·name:·Configure·dnf-automatic·to·Install·Available·Updates·Automatically
 197 ··ini_file:
 198 ····dest:·/etc/dnf/automatic.conf
 199 ····section:·commands
 200 ····option:·apply_updates
 201 ····value:·'yes'
 202 ····create:·true
 203 ··tags:
 204 ··-·NIST-800-53-CM-6(a)
 205 ··-·NIST-800-53-SI-2(5)
 206 ··-·NIST-800-53-SI-2(c)
 207 ··-·dnf-automatic_apply_updates
 208 ··-·low_complexity
 209 ··-·medium_disruption
Max diff block lines reached; 223420/229124 bytes (97.51%) of diff not shown.
26.5 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cis.html
    
Offset 14547, 16 lines modifiedOffset 14547, 16 lines modified
00038d20:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h00038d20:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h
00038d30:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver00038d30:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver
00038d40:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.00038d40:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.
00038d50:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p00038d50:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p
00038d60:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong00038d60:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong
00038d70:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.00038d70:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.
00038d80:·2020·2020·2020·2020·2020·2020·2020·2020··················00038d80:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038d90:·2020·2020·2861·7320·6f66·2032·3032·362d······(as·of·2026-00038d90:·2020·2020·2861·7320·6f66·2032·3032·342d······(as·of·2024-
00038da0:·3031·2d30·3829·0a20·2020·2020·2020·2020··01-08).·········00038da0:·3132·2d30·3729·0a20·2020·2020·2020·2020··12-07).·········
00038db0:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul00038db0:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul
00038dc0:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table00038dc0:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table
00038dd0:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h200038dd0:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2
00038de0:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href00038de0:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href
00038df0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg00038df0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg
00038e00:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_00038e00:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
00038e10:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy00038e10:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy
Offset 15367, 235 lines modifiedOffset 15367, 235 lines modified
0003c060:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm80003c060:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8
0003c070:·3030·3222·2074·6162·696e·6465·783d·2230··002"·tabindex="00003c070:·3030·3222·2074·6162·696e·6465·783d·2230··002"·tabindex="0
0003c080:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003c080:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003c090:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003c090:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003c0a0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003c0a0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003c0b0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003c0b0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003c0c0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003c0c0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003c0d0:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn0003c0d0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·
0003c0e0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003c0e0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003c0f0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003c0f0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003c100:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003c100:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003c110:·6170·7365·2220·6964·3d22·6964·6d38·3030··apse"·id="idm8000003c110:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
0003c120:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class=0003c120:·3030·3222·3e3c·7461·626c·6520·636c·6173··002"><table·clas
0003c130:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003c130:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003c140:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003c140:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003c150:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003c150:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003c160:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003c160:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003c170:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003c170:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003c180:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003c180:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003c190:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003c190:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003c1a0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003c1a0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003c1b0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R0003c1b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c1c0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f0003c1c0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003c1d0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t0003c1d0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003c1e0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<0003c1e0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003c1f0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</0003c1f0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
0003c200:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>0003c200:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003c210:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu 
0003c220:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide. 
0003c230:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a 
0003c240:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package· 
0003c250:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en 
0003c260:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst 
0003c270:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</ 
0003c280:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003c290:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003c2a0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003c2b0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003c2c0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003c2d0:·2369·646d·3830·3033·2220·7461·6269·6e64··#idm8003"·tabind 
0003c2e0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003c2f0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003c300:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003c310:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003c320:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003c330:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel 
0003c340:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a> 
0003c350:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003c360:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003c370:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003c380:·3830·3033·223e·3c74·6162·6c65·2063·6c61··8003"><table·cla 
0003c390:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003c3a0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003c3b0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003c3c0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003c3d0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003c3e0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003c3f0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003c400:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003c410:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003c420:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003c430:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003c440:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003c450:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003c460:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003c470:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#· 
0003c480:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a 
0003c490:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i 
0003c4a0:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo 
0003c4b0:·726d·730a·6966·205b·2021·202d·6620·2f2e··rms.if·[·!·-f·/. 
0003c4c0:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp 
0003c4d0:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r 
0003c4e0:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv 
0003c4f0:·205d·3b20·7468·656e·0a0a·6966·2021·2072···];·then..if·!·r 
0003c500:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a 
0003c510:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.···· 
0003c520:·7975·6d20·696e·7374·616c·6c20·2d79·2022··yum·install·-y·" 
0003c530:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.· 
0003c540:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec 
0003c550:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation· 
0003c560:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl 
0003c570:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d 
0003c580:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code>< 
0003c590:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003c5a0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003c5b0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003c5c0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003c5d0:·612d·7461·7267·6574·3d22·2369·646d·3830··a-target="#idm80 
0003c5e0:·3034·2220·7461·6269·6e64·6578·3d22·3022··04"·tabindex="0" 
0003c5f0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003c600:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003c610:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003c620:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003c630:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003c640:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn 
0003c650:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003c660:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003c670:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003c680:·6170·7365·2220·6964·3d22·6964·6d38·3030··apse"·id="idm800 
0003c690:·3422·3e3c·7461·626c·6520·636c·6173·733d··4"><table·class= 
0003c6a0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003c6b0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003c6c0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003c6d0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003c6e0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003c6f0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003c700:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003c710:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003c720:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003c730:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
Max diff block lines reached; 25352179/25384525 bytes (99.87%) of diff not shown.
2.33 MB
html2text {}
Max HTML report size reached
11.6 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cis_server_l1.html
    
Offset 14548, 15 lines modifiedOffset 14548, 15 lines modified
00038d30:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00038d30:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00038d40:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00038d40:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00038d50:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</00038d50:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
00038d60:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00038d60:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
00038d70:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft00038d70:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
00038d80:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······00038d80:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
00038d90:·2020·2020·2020·2020·2020·2020·2020·2861················(a00038d90:·2020·2020·2020·2020·2020·2020·2020·2861················(a
00038da0:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)00038da0:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
00038db0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00038db0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00038dc0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div00038dc0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
00038dd0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co00038dd0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
00038de0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><00038de0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
00038df0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc00038df0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
00038e00:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec00038e00:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00038e10:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00038e10:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 15336, 235 lines modifiedOffset 15336, 235 lines modified
0003be70:·7267·6574·3d22·2369·646d·3830·3032·2220··rget="#idm8002"·0003be70:·7267·6574·3d22·2369·646d·3830·3032·2220··rget="#idm8002"·
0003be80:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003be80:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003be90:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003be90:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003bea0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003bea0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003beb0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003beb0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003bec0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003bec0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003bed0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003bed0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003bee0:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet0003bee0:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp
0003bef0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003bef0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
0003bf00:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003bf00:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0003bf10:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003bf10:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0003bf20:·2069·643d·2269·646d·3830·3032·223e·3c74···id="idm8002"><t0003bf20:·6522·2069·643d·2269·646d·3830·3032·223e··e"·id="idm8002">
0003bf30:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl0003bf30:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
0003bf40:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·0003bf40:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
0003bf50:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0003bf50:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
0003bf60:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">0003bf60:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
0003bf70:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi0003bf70:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003bf80:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<0003bf80:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0003bf90:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003bf90:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003bfa0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th0003bfa0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
0003bfb0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003bfb0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003bfc0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot0003bfc0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
0003bfd0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<0003bfd0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
0003bfe0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003bfe0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
0003bff0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003bff0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0003c000:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003c000:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
0003c010:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003c010:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003c020:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package
 0003c030:·202d·2d61·6464·3d61·6964·650a·3c2f·636f···--add=aide.</co
 0003c040:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0003c050:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 0003c060:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
0003c020:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in 
0003c030:·7374·616c·6c5f·6169·6465·0a0a·636c·6173··stall_aide..clas 
0003c040:·7320·696e·7374·616c·6c5f·6169·6465·207b··s·install_aide·{ 
0003c050:·0a20·2070·6163·6b61·6765·207b·2027·6169··.··package·{·'ai 
0003c060:·6465·273a·0a20·2020·2065·6e73·7572·6520··de':.····ensure· 
0003c070:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed 
0003c080:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code> 
0003c090:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003c0a0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003c0b0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003c0c0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003c0d0:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8 
0003c0e0:·3030·3322·2074·6162·696e·6465·783d·2230··003"·tabindex="0 
0003c0f0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003c100:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003c110:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003c120:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003c130:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003c140:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
0003c150:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003c160:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003c170:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003c180:·7365·2220·6964·3d22·6964·6d38·3030·3322··se"·id="idm8003" 
0003c190:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003c1a0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003c1b0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003c1c0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003c1d0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003c1e0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003c1f0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003c200:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003c210:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003c220:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003c230:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003c240:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003c250:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003c260:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003c270:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003c280:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed 
0003c290:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic 
0003c2a0:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer 
0003c2b0:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i 
0003c2c0:·6620·5b20·2120·2d66·202f·2e64·6f63·6b65··f·[·!·-f·/.docke 
0003c2d0:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp 
0003c2e0:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c 
0003c2f0:·6f6e·7461·696e·6572·656e·7620·5d3b·2074··ontainerenv·];·t 
0003c300:·6865·6e0a·0a69·6620·2120·7270·6d20·2d71··hen..if·!·rpm·-q 
0003c310:·202d·2d71·7569·6574·2022·6169·6465·2220···--quiet·"aide"· 
0003c320:·3b20·7468·656e·0a20·2020·2079·756d·2069··;·then.····yum·i 
0003c330:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide" 
0003c340:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g 
0003c350:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R 
0003c360:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no 
0003c370:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no 
0003c380:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'. 
0003c390:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre> 
0003c3a0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003c3b0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003c3c0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003c3d0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003c3e0:·6765·743d·2223·6964·6d38·3030·3422·2074··get="#idm8004"·t 
0003c3f0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003c400:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003c410:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003c420:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003c430:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003c440:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003c450:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet 
0003c460:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003c470:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003c480:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003c070:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
0003c490:·2069·643d·2269·646d·3830·3034·223e·3c74···id="idm8004"><t 
0003c4a0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003c4b0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003c4c0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003c4d0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003c4e0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003c4f0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003c500:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
Max diff block lines reached; 10764863/10797071 bytes (99.70%) of diff not shown.
1.28 MB
html2text {}
    
Offset 70, 15 lines modifiedOffset 70, 15 lines modified
70 ····*·cpe:/o:redhat:enterprise_linux:8.770 ····*·cpe:/o:redhat:enterprise_linux:8.7
71 ····*·cpe:/o:redhat:enterprise_linux:8.871 ····*·cpe:/o:redhat:enterprise_linux:8.8
72 ····*·cpe:/o:redhat:enterprise_linux:8.972 ····*·cpe:/o:redhat:enterprise_linux:8.9
73 ····*·cpe:/o:redhat:enterprise_linux:873 ····*·cpe:/o:redhat:enterprise_linux:8
74 ····*·cpe:/o:centos:centos:874 ····*·cpe:/o:centos:centos:8
75 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*75 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
76 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8476 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
77 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)77 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
78 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*78 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
79 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s79 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
80 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e80 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
81 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l81 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
82 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n82 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
83 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g83 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
84 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s84 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 133, 41 lines modifiedOffset 133, 45 lines modified
133 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3133 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
134 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5134 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
135 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199135 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
136 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79136 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
137 ············_\x8c_\x8i_\x8s············5.3.1137 ············_\x8c_\x8i_\x8s············5.3.1
138 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2138 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
139 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule139 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule
 140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 145 package·--add=aide
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low147 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low148 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false149 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable150 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
145 include·install_aide151 include·install_aide
  
146 class·install_aide·{152 class·install_aide·{
147 ··package·{·'aide':153 ··package·{·'aide':
148 ····ensure·=>·'installed',154 ····ensure·=>·'installed',
149 ··}155 ··}
150 }156 }
 157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 158 [[packages]]
 159 name·=·"aide"
 160 version·=·"*"
151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
156 #·Remediation·is·applicable·only·in·certain·platforms 
157 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
 166 package·install·aide
158 if·!·rpm·-q·--quiet·"aide"·;·then 
159 ····yum·install·-y·"aide" 
160 fi 
  
161 else 
162 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
163 fi 
164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
165 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
166 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
167 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
168 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
169 -·name:·Ensure·aide·is·installed172 -·name:·Ensure·aide·is·installed
170 ··package:173 ··package:
Offset 182, 33 lines modifiedOffset 186, 29 lines modified
182 ··-·PCI-DSSv4-11.5.2186 ··-·PCI-DSSv4-11.5.2
183 ··-·enable_strategy187 ··-·enable_strategy
184 ··-·low_complexity188 ··-·low_complexity
185 ··-·low_disruption189 ··-·low_disruption
186 ··-·medium_severity190 ··-·medium_severity
187 ··-·no_reboot_needed191 ··-·no_reboot_needed
188 ··-·package_aide_installed192 ··-·package_aide_installed
189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
190 [[packages]] 
191 name·=·"aide" 
192 version·=·"*" 
193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 198 #·Remediation·is·applicable·only·in·certain·platforms
 199 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 200 if·!·rpm·-q·--quiet·"aide"·;·then
 201 ····yum·install·-y·"aide"
 202 fi
198 package·install·aide 
199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
204 package·--add=aide203 else
 204 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 205 fi
205 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*206 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
206 Run·the·following·command·to·generate·a·new·database:207 Run·the·following·command·to·generate·a·new·database:
207 $·sudo·/usr/sbin/aide·--init208 $·sudo·/usr/sbin/aide·--init
208 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:209 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
209 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz210 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
210 To·initiate·a·manual·check,·run·the·following·command:211 To·initiate·a·manual·check,·run·the·following·command:
211 $·sudo·/usr/sbin/aide·--check212 $·sudo·/usr/sbin/aide·--check
Offset 226, 28 lines modifiedOffset 226, 14 lines modified
226 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3226 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
227 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5227 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
228 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199228 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
229 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79229 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
230 ············_\x8c_\x8i_\x8s············5.3.1230 ············_\x8c_\x8i_\x8s············5.3.1
231 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2231 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
232 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule232 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule
233 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
234 #·Remediation·is·applicable·only·in·certain·platforms 
235 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
236 if·!·rpm·-q·--quiet·"aide"·;·then 
237 ····yum·install·-y·"aide" 
238 fi 
  
Max diff block lines reached; 1335341/1341343 bytes (99.55%) of diff not shown.
11.3 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cis_workstation_l1.html
    
Offset 14549, 16 lines modifiedOffset 14549, 16 lines modified
00038d40:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>00038d40:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>
00038d50:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi00038d50:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi
00038d60:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.00038d60:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.
00038d70:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><00038d70:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><
00038d80:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d00038d80:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d
00038d90:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··00038d90:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··
00038da0:·2020·2020·2020·2020·2020·2020·2020·2020··················00038da0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038db0:·2020·2861·7320·6f66·2032·3032·362d·3031····(as·of·2026-0100038db0:·2020·2861·7320·6f66·2032·3032·342d·3132····(as·of·2024-12
00038dc0:·2d30·3829·0a20·2020·2020·2020·2020·2020··-08).···········00038dc0:·2d30·3729·0a20·2020·2020·2020·2020·2020··-07).···········
00038dd0:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><00038dd0:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><
00038de0:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o00038de0:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o
00038df0:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><00038df0:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><
00038e00:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="00038e00:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="
00038e10:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr00038e10:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr
00038e20:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr00038e20:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr
00038e30:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst00038e30:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst
Offset 15327, 235 lines modifiedOffset 15327, 235 lines modified
0003bde0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003bde0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003bdf0:·3830·3032·2220·7461·6269·6e64·6578·3d22··8002"·tabindex="0003bdf0:·3830·3032·2220·7461·6269·6e64·6578·3d22··8002"·tabindex="
0003be00:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003be00:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003be10:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003be10:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003be20:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003be20:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003be30:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003be30:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003be40:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003be40:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003be50:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s0003be50:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
0003be60:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003be60:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003be70:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003be70:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003be80:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003be80:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003be90:·6c61·7073·6522·2069·643d·2269·646d·3830··lapse"·id="idm800003be90:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003bea0:·3032·223e·3c74·6162·6c65·2063·6c61·7373··02"><table·class0003bea0:·3830·3032·223e·3c74·6162·6c65·2063·6c61··8002"><table·cla
0003beb0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003beb0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003bec0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003bec0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003bed0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003bed0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003bee0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003bee0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003bef0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003bef0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003bf00:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003bf00:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003bf10:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003bf10:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003bf20:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003bf20:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
0003bf30:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003bf30:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003bf40:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>0003bf40:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
0003bf50:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><0003bf50:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
0003bf60:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003bf60:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
0003bf70:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0003bf70:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003bf80:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003bf80:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0003bf90:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl0003bf90:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p
 0003bfa0:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid
 0003bfb0:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><
 0003bfc0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0003bfd0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0003bfe0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0003bff0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0003c000:·6574·3d22·2369·646d·3830·3033·2220·7461··et="#idm8003"·ta
 0003c010:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 0003c020:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 0003c030:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 0003c040:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 0003c050:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 0003c060:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003c070:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.
 0003c080:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003c090:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003bfa0:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide 
0003bfb0:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_ 
0003bfc0:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package 
0003bfd0:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e 
0003bfe0:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins 
0003bff0:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.< 
0003c000:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003c010:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003c020:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003c030:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003c040:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003c050:·2223·6964·6d38·3030·3322·2074·6162·696e··"#idm8003"·tabin 
0003c060:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003c070:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003c080:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003c090:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003c0a0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003c0b0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
0003c0c0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
0003c0d0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003c0e0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003c0a0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003c0f0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003c100:·6d38·3030·3322·3e3c·7461·626c·6520·636c··m8003"><table·cl 
0003c110:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003c120:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003c130:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0003c140:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0003c150:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003c0b0:·643d·2269·646d·3830·3033·223e·3c74·6162··d="idm8003"><tab
 0003c0c0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0003c0d0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0003c0e0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 0003c0f0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 0003c100:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 0003c110:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003c120:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0003c130:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003c160:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003c140:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003c170:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003c180:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003c150:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 0003c160:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003c190:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003c170:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 0003c180:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 0003c190:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 0003c1a0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003c1b0:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst
 0003c1c0:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class·
 0003c1d0:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.·
 0003c1e0:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide
 0003c1f0:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=&
 0003c200:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed',
 0003c210:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></
0003c1a0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
0003c1b0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
0003c1c0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
0003c1d0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
0003c1e0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
0003c1f0:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code># 
0003c200:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is· 
0003c210:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only· 
0003c220:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf 
0003c230:·6f72·6d73·0a69·6620·5b20·2120·2d66·202f··orms.if·[·!·-f·/ 
0003c240:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am 
0003c250:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/ 
0003c260:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren 
0003c270:·7620·5d3b·2074·6865·6e0a·0a69·6620·2120··v·];·then..if·!· 
0003c280:·7270·6d20·2d71·202d·2d71·7569·6574·2022··rpm·-q·--quiet·" 
Max diff block lines reached; 10468052/10500398 bytes (99.69%) of diff not shown.
1.25 MB
html2text {}
    
Offset 71, 15 lines modifiedOffset 71, 15 lines modified
71 ····*·cpe:/o:redhat:enterprise_linux:8.771 ····*·cpe:/o:redhat:enterprise_linux:8.7
72 ····*·cpe:/o:redhat:enterprise_linux:8.872 ····*·cpe:/o:redhat:enterprise_linux:8.8
73 ····*·cpe:/o:redhat:enterprise_linux:8.973 ····*·cpe:/o:redhat:enterprise_linux:8.9
74 ····*·cpe:/o:redhat:enterprise_linux:874 ····*·cpe:/o:redhat:enterprise_linux:8
75 ····*·cpe:/o:centos:centos:875 ····*·cpe:/o:centos:centos:8
76 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*76 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
77 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8477 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
78 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)78 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
79 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*79 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
80 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s80 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
81 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e81 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
82 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l82 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
83 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n83 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
84 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g84 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
85 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s85 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 132, 41 lines modifiedOffset 132, 45 lines modified
132 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3132 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
133 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5133 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
134 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199134 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
135 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79135 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
136 ············_\x8c_\x8i_\x8s············5.3.1136 ············_\x8c_\x8i_\x8s············5.3.1
137 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2137 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
138 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule138 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule
 139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 144 package·--add=aide
139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
144 include·install_aide150 include·install_aide
  
145 class·install_aide·{151 class·install_aide·{
146 ··package·{·'aide':152 ··package·{·'aide':
147 ····ensure·=>·'installed',153 ····ensure·=>·'installed',
148 ··}154 ··}
149 }155 }
 156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 157 [[packages]]
 158 name·=·"aide"
 159 version·=·"*"
150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
151 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low161 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
152 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low162 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
153 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false163 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
154 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable164 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
155 #·Remediation·is·applicable·only·in·certain·platforms 
156 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
 165 package·install·aide
157 if·!·rpm·-q·--quiet·"aide"·;·then 
158 ····yum·install·-y·"aide" 
159 fi 
  
160 else 
161 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
162 fi 
163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
168 -·name:·Ensure·aide·is·installed171 -·name:·Ensure·aide·is·installed
169 ··package:172 ··package:
Offset 181, 33 lines modifiedOffset 185, 29 lines modified
181 ··-·PCI-DSSv4-11.5.2185 ··-·PCI-DSSv4-11.5.2
182 ··-·enable_strategy186 ··-·enable_strategy
183 ··-·low_complexity187 ··-·low_complexity
184 ··-·low_disruption188 ··-·low_disruption
185 ··-·medium_severity189 ··-·medium_severity
186 ··-·no_reboot_needed190 ··-·no_reboot_needed
187 ··-·package_aide_installed191 ··-·package_aide_installed
188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
189 [[packages]] 
190 name·=·"aide" 
191 version·=·"*" 
192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 197 #·Remediation·is·applicable·only·in·certain·platforms
 198 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 199 if·!·rpm·-q·--quiet·"aide"·;·then
 200 ····yum·install·-y·"aide"
 201 fi
197 package·install·aide 
198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
203 package·--add=aide202 else
 203 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 204 fi
204 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*205 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
205 Run·the·following·command·to·generate·a·new·database:206 Run·the·following·command·to·generate·a·new·database:
206 $·sudo·/usr/sbin/aide·--init207 $·sudo·/usr/sbin/aide·--init
207 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:208 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
208 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz209 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
209 To·initiate·a·manual·check,·run·the·following·command:210 To·initiate·a·manual·check,·run·the·following·command:
210 $·sudo·/usr/sbin/aide·--check211 $·sudo·/usr/sbin/aide·--check
Offset 225, 28 lines modifiedOffset 225, 14 lines modified
225 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3225 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
226 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5226 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
227 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199227 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
228 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79228 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
229 ············_\x8c_\x8i_\x8s············5.3.1229 ············_\x8c_\x8i_\x8s············5.3.1
230 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2230 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
231 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule231 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule
232 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
233 #·Remediation·is·applicable·only·in·certain·platforms 
234 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
235 if·!·rpm·-q·--quiet·"aide"·;·then 
236 ····yum·install·-y·"aide" 
237 fi 
  
Max diff block lines reached; 1301440/1307442 bytes (99.54%) of diff not shown.
26.3 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cis_workstation_l2.html
    
Offset 14549, 16 lines modifiedOffset 14549, 16 lines modified
00038d40:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>00038d40:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>
00038d50:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi00038d50:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi
00038d60:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.00038d60:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.
00038d70:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><00038d70:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><
00038d80:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d00038d80:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d
00038d90:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··00038d90:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··
00038da0:·2020·2020·2020·2020·2020·2020·2020·2020··················00038da0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038db0:·2020·2861·7320·6f66·2032·3032·362d·3031····(as·of·2026-0100038db0:·2020·2861·7320·6f66·2032·3032·342d·3132····(as·of·2024-12
00038dc0:·2d30·3829·0a20·2020·2020·2020·2020·2020··-08).···········00038dc0:·2d30·3729·0a20·2020·2020·2020·2020·2020··-07).···········
00038dd0:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><00038dd0:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><
00038de0:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o00038de0:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o
00038df0:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><00038df0:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><
00038e00:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="00038e00:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="
00038e10:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr00038e10:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr
00038e20:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr00038e20:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr
00038e30:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst00038e30:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst
Offset 15359, 235 lines modifiedOffset 15359, 235 lines modified
0003bfe0:·6765·743d·2223·6964·6d38·3030·3222·2074··get="#idm8002"·t0003bfe0:·6765·743d·2223·6964·6d38·3030·3222·2074··get="#idm8002"·t
0003bff0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003bff0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003c000:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003c000:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003c010:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003c010:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003c020:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003c020:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003c030:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003c030:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003c040:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003c040:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003c050:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·0003c050:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe
0003c060:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003c060:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003c070:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003c070:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003c080:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003c080:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003c090:·6964·3d22·6964·6d38·3030·3222·3e3c·7461··id="idm8002"><ta0003c090:·2220·6964·3d22·6964·6d38·3030·3222·3e3c··"·id="idm8002"><
0003c0a0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0003c0a0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003c0b0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0003c0b0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003c0c0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0003c0c0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003c0d0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0003c0d0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003c0e0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003c0e0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003c0f0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003c0f0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003c100:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003c100:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003c110:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>0003c110:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003c120:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003c120:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003c130:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:0003c130:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
0003c140:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</0003c140:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
0003c150:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003c150:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003c160:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003c160:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
0003c170:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t0003c170:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
0003c180:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003c180:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003c190:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 0003c1a0:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod
 0003c1b0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003c1c0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003c1d0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
0003c190:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins 
0003c1a0:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class 
0003c1b0:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{. 
0003c1c0:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid 
0003c1d0:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·= 
0003c1e0:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed' 
0003c1f0:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code>< 
0003c200:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003c210:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003c220:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003c230:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003c240:·612d·7461·7267·6574·3d22·2369·646d·3830··a-target="#idm80 
0003c250:·3033·2220·7461·6269·6e64·6578·3d22·3022··03"·tabindex="0" 
0003c260:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003c270:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003c280:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003c290:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003c2a0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003c2b0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
0003c2c0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
0003c2d0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003c2e0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003c2f0:·6522·2069·643d·2269·646d·3830·3033·223e··e"·id="idm8003"> 
0003c300:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003c310:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003c320:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003c330:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003c340:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003c350:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003c360:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003c370:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003c380:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003c390:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003c3a0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0003c3b0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
0003c3c0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0003c3d0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0003c3e0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003c3f0:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi 
0003c400:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica 
0003c410:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert 
0003c420:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if 
0003c430:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker 
0003c440:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp; 
0003c450:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co 
0003c460:·6e74·6169·6e65·7265·6e76·205d·3b20·7468··ntainerenv·];·th 
0003c470:·656e·0a0a·6966·2021·2072·706d·202d·7120··en..if·!·rpm·-q· 
0003c480:·2d2d·7175·6965·7420·2261·6964·6522·203b··--quiet·"aide"·; 
0003c490:·2074·6865·6e0a·2020·2020·7975·6d20·696e···then.····yum·in 
0003c4a0:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide". 
0003c4b0:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt 
0003c4c0:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re 
0003c4d0:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not 
0003c4e0:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not 
0003c4f0:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f 
0003c500:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre>< 
0003c510:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003c520:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003c530:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003c540:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003c550:·6574·3d22·2369·646d·3830·3034·2220·7461··et="#idm8004"·ta 
0003c560:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003c570:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003c580:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003c590:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003c5a0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003c5b0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003c5c0:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet· 
0003c5d0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003c5e0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003c5f0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003c1e0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
0003c600:·6964·3d22·6964·6d38·3030·3422·3e3c·7461··id="idm8004"><ta 
0003c610:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003c620:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003c630:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003c640:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003c650:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003c660:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
Max diff block lines reached; 25160731/25193077 bytes (99.87%) of diff not shown.
2.31 MB
html2text {}
Max HTML report size reached
9.99 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cui.html
    
Offset 14583, 15 lines modifiedOffset 14583, 15 lines modified
00038f60:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v00038f60:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v
00038f70:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>00038f70:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>
00038f80:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><00038f80:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><
00038f90:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro00038f90:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro
00038fa0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong00038fa0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong
00038fb0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············00038fb0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············
00038fc0:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·20200038fc0:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202
00038fd0:·362d·3031·2d30·3829·0a20·2020·2020·2020··6-01-08).·······00038fd0:·342d·3132·2d30·3729·0a20·2020·2020·2020··4-12-07).·······
00038fe0:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></00038fe0:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></
00038ff0:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab00038ff0:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab
00039000:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</00039000:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</
00039010:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr00039010:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr
00039020:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s00039020:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s
00039030:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten00039030:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten
00039040:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">00039040:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">
Offset 15358, 235 lines modifiedOffset 15358, 235 lines modified
0003bfd0:·6172·6765·743d·2223·6964·6d38·3030·3222··arget="#idm8002"0003bfd0:·6172·6765·743d·2223·6964·6d38·3030·3222··arget="#idm8002"
0003bfe0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003bfe0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003bff0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003bff0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003c000:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003c000:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003c010:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003c010:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003c020:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003c020:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003c030:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003c030:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003c040:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe0003c040:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip
0003c050:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003c050:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003c060:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003c060:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003c070:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003c070:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003c080:·2220·6964·3d22·6964·6d38·3030·3222·3e3c··"·id="idm8002"><0003c080:·7365·2220·6964·3d22·6964·6d38·3030·3222··se"·id="idm8002"
0003c090:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003c090:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003c0a0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003c0a0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003c0b0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003c0b0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003c0c0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003c0c0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003c0d0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003c0d0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003c0e0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003c0e0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003c0f0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003c0f0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003c100:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003c100:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003c110:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003c110:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003c120:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo0003c120:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
0003c130:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false0003c130:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
0003c140:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003c140:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
0003c150:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>0003c150:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0003c160:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><0003c160:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
0003c170:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0003c170:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003c180:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag
 0003c190:·6520·2d2d·6164·643d·6169·6465·0a3c·2f63··e·--add=aide.</c
 0003c1a0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003c1b0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003c1c0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
0003c180:·3e3c·636f·6465·3e69·6e63·6c75·6465·2069··><code>include·i 
0003c190:·6e73·7461·6c6c·5f61·6964·650a·0a63·6c61··nstall_aide..cla 
0003c1a0:·7373·2069·6e73·7461·6c6c·5f61·6964·6520··ss·install_aide· 
0003c1b0:·7b0a·2020·7061·636b·6167·6520·7b20·2761··{.··package·{·'a 
0003c1c0:·6964·6527·3a0a·2020·2020·656e·7375·7265··ide':.····ensure 
0003c1d0:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe 
0003c1e0:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code 
0003c1f0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003c200:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003c210:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003c220:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003c230:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003c240:·3830·3033·2220·7461·6269·6e64·6578·3d22··8003"·tabindex=" 
0003c250:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003c260:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003c270:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003c280:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003c290:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003c2a0:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003c2b0:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003c2c0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003c2d0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003c2e0:·7073·6522·2069·643d·2269·646d·3830·3033··pse"·id="idm8003 
0003c2f0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003c300:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003c310:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003c320:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003c330:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003c340:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003c350:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003c360:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003c370:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003c380:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003c390:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0003c3a0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
0003c3b0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003c3c0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003c3d0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003c3e0:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme 
0003c3f0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
0003c400:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
0003c410:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
0003c420:·6966·205b·2021·202d·6620·2f2e·646f·636b··if·[·!·-f·/.dock 
0003c430:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am 
0003c440:·703b·205b·2021·202d·6620·2f72·756e·2f2e··p;·[·!·-f·/run/. 
0003c450:·636f·6e74·6169·6e65·7265·6e76·205d·3b20··containerenv·];· 
0003c460:·7468·656e·0a0a·6966·2021·2072·706d·202d··then..if·!·rpm·- 
0003c470:·7120·2d2d·7175·6965·7420·2261·6964·6522··q·--quiet·"aide" 
0003c480:·203b·2074·6865·6e0a·2020·2020·7975·6d20···;·then.····yum· 
0003c490:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide 
0003c4a0:·220a·6669·0a0a·656c·7365·0a20·2020·2026··".fi..else.····& 
0003c4b0:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·' 
0003c4c0:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n 
0003c4d0:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n 
0003c4e0:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done' 
0003c4f0:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre 
0003c500:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003c510:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003c520:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003c530:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003c540:·7267·6574·3d22·2369·646d·3830·3034·2220··rget="#idm8004"· 
0003c550:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003c560:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003c570:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003c580:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003c590:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003c5a0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003c5b0:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe 
0003c5c0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003c5d0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003c5e0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003c1d0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
0003c5f0:·2220·6964·3d22·6964·6d38·3030·3422·3e3c··"·id="idm8004">< 
0003c600:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003c610:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003c620:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003c630:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003c640:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003c650:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003c660:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
Max diff block lines reached; 9159300/9191508 bytes (99.65%) of diff not shown.
1.23 MB
html2text {}
    
Offset 79, 15 lines modifiedOffset 79, 15 lines modified
79 ····*·cpe:/o:redhat:enterprise_linux:8.779 ····*·cpe:/o:redhat:enterprise_linux:8.7
80 ····*·cpe:/o:redhat:enterprise_linux:8.880 ····*·cpe:/o:redhat:enterprise_linux:8.8
81 ····*·cpe:/o:redhat:enterprise_linux:8.981 ····*·cpe:/o:redhat:enterprise_linux:8.9
82 ····*·cpe:/o:redhat:enterprise_linux:882 ····*·cpe:/o:redhat:enterprise_linux:8
83 ····*·cpe:/o:centos:centos:883 ····*·cpe:/o:centos:centos:8
84 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*84 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
85 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8485 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
86 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)86 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
87 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*87 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
88 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s88 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
89 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e89 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
90 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l90 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
91 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n91 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
92 ·········4.·_\x8z_\x8I_\x8P_\x8L_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n92 ·········4.·_\x8z_\x8I_\x8P_\x8L_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
93 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g93 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 138, 41 lines modifiedOffset 138, 45 lines modified
138 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3138 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
139 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5139 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
140 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199140 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
141 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79141 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
142 ············_\x8c_\x8i_\x8s············5.3.1142 ············_\x8c_\x8i_\x8s············5.3.1
143 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2143 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
144 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule144 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule
 145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 150 package·--add=aide
145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
150 include·install_aide156 include·install_aide
  
151 class·install_aide·{157 class·install_aide·{
152 ··package·{·'aide':158 ··package·{·'aide':
153 ····ensure·=>·'installed',159 ····ensure·=>·'installed',
154 ··}160 ··}
155 }161 }
 162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 163 [[packages]]
 164 name·=·"aide"
 165 version·=·"*"
156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
157 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
158 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
159 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
160 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
161 #·Remediation·is·applicable·only·in·certain·platforms 
162 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
 171 package·install·aide
163 if·!·rpm·-q·--quiet·"aide"·;·then 
164 ····yum·install·-y·"aide" 
165 fi 
  
166 else 
167 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
168 fi 
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
174 -·name:·Ensure·aide·is·installed177 -·name:·Ensure·aide·is·installed
175 ··package:178 ··package:
Offset 187, 33 lines modifiedOffset 191, 29 lines modified
187 ··-·PCI-DSSv4-11.5.2191 ··-·PCI-DSSv4-11.5.2
188 ··-·enable_strategy192 ··-·enable_strategy
189 ··-·low_complexity193 ··-·low_complexity
190 ··-·low_disruption194 ··-·low_disruption
191 ··-·medium_severity195 ··-·medium_severity
192 ··-·no_reboot_needed196 ··-·no_reboot_needed
193 ··-·package_aide_installed197 ··-·package_aide_installed
194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
195 [[packages]] 
196 name·=·"aide" 
197 version·=·"*" 
198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 203 #·Remediation·is·applicable·only·in·certain·platforms
 204 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 205 if·!·rpm·-q·--quiet·"aide"·;·then
 206 ····yum·install·-y·"aide"
 207 fi
203 package·install·aide 
204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
209 package·--add=aide208 else
 209 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 210 fi
210 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules211 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
211 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.212 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
212 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.213 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.
  
213 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.214 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
214 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*215 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 228, 27 lines modifiedOffset 228, 14 lines modified
228 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000068,·CCI-000803,·CCI-002450228 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000068,·CCI-000803,·CCI-002450
229 ············_\x8i_\x8s_\x8m······1446229 ············_\x8i_\x8s_\x8m······1446
230 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1230 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
231 References:·_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12231 References:·_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
232 ············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.1232 ············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.1
233 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223233 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223
234 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r928585_rule234 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r928585_rule
235 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
236 #·Remediation·is·applicable·only·in·certain·platforms 
237 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·);·then 
  
238 fips-mode-setup·--enable 
239 FIPS_CONF="/etc/dracut.conf.d/40-fips.conf" 
240 if·!·grep·"^add_dracutmodules+=\"·fips·\""·$FIPS_CONF;·then 
241 ····echo·"add_dracutmodules+=\"·fips·\""·>>·$FIPS_CONF 
Max diff block lines reached; 1281145/1287631 bytes (99.50%) of diff not shown.
6.97 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-e8.html
    
Offset 14549, 16 lines modifiedOffset 14549, 16 lines modified
00038d40:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><00038d40:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><
00038d50:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio00038d50:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio
00038d60:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.700038d60:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.7
00038d70:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u00038d70:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u
00038d80:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr00038d80:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr
00038d90:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···00038d90:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···
00038da0:·2020·2020·2020·2020·2020·2020·2020·2020··················00038da0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038db0:·2028·6173·206f·6620·3230·3236·2d30·312d···(as·of·2026-01-00038db0:·2028·6173·206f·6620·3230·3234·2d31·322d···(as·of·2024-12-
00038dc0:·3038·290a·2020·2020·2020·2020·2020·2020··08).············00038dc0:·3037·290a·2020·2020·2020·2020·2020·2020··07).············
00038dd0:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></00038dd0:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></
00038de0:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of00038de0:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of
00038df0:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o00038df0:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o
00038e00:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#00038e00:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#
00038e10:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro00038e10:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro
00038e20:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro00038e20:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro
00038e30:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste00038e30:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste
Offset 15402, 301 lines modifiedOffset 15402, 301 lines modified
0003c290:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003c290:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003c2a0:·6964·6d37·3636·3222·2074·6162·696e·6465··idm7662"·tabinde0003c2a0:·6964·6d37·3636·3222·2074·6162·696e·6465··idm7662"·tabinde
0003c2b0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003c2b0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003c2c0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003c2c0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003c2d0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003c2d0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003c2e0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003c2e0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003c2f0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003c2f0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003c300:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003c310:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003c320:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003c330:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003c340:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7 
0003c350:·3636·3222·3e3c·7072·653e·3c63·6f64·653e··662"><pre><code> 
0003c360:·0a23·2046·696e·6420·7768·6963·6820·6669··.#·Find·which·fi 
0003c370:·6c65·7320·6861·7665·2069·6e63·6f72·7265··les·have·incorre 
0003c380:·6374·2068·6173·6820·286e·6f74·2069·6e20··ct·hash·(not·in· 
0003c390:·2f65·7463·2c20·6265·6361·7573·6520·6f66··/etc,·because·of 
0003c3a0:·2074·6865·2073·7973·7465·6d20·7265·6c61···the·system·rela 
0003c3b0:·7465·6420·636f·6e66·6967·2066·696c·6573··ted·config·files 
0003c3c0:·2920·616e·6420·7468·656e·2067·6574·2066··)·and·then·get·f 
0003c3d0:·696c·6573·206e·616d·6573·0a66·696c·6573··iles·names.files 
0003c3e0:·5f77·6974·685f·696e·636f·7272·6563·745f··_with_incorrect_ 
0003c3f0:·6861·7368·3d22·2428·7270·6d20·2d56·6120··hash="$(rpm·-Va· 
0003c400:·2d2d·6e6f·636f·6e66·6967·207c·2067·7265··--noconfig·|·gre 
0003c410:·7020·2d45·2027·5e2e·2e35·2720·7c20·6177··p·-E·'^..5'·|·aw 
0003c420:·6b20·277b·7072·696e·7420·244e·467d·2720··k·'{print·$NF}'· 
0003c430:·2922·0a0a·6966·205b·202d·6e20·2224·6669··)"..if·[·-n·"$fi 
0003c440:·6c65·735f·7769·7468·5f69·6e63·6f72·7265··les_with_incorre 
0003c450:·6374·5f68·6173·6822·205d·3b20·7468·656e··ct_hash"·];·then 
0003c460:·0a20·2020·2023·2046·726f·6d20·6669·6c65··.····#·From·file 
0003c470:·7320·6e61·6d65·7320·6765·7420·7061·636b··s·names·get·pack 
0003c480:·6167·6520·6e61·6d65·7320·616e·6420·6368··age·names·and·ch 
0003c490:·616e·6765·206e·6577·6c69·6e65·2074·6f20··ange·newline·to· 
0003c4a0:·7370·6163·652c·2062·6563·6175·7365·2072··space,·because·r 
0003c4b0:·706d·2077·7269·7465·7320·6561·6368·2070··pm·writes·each·p 
0003c4c0:·6163·6b61·6765·2074·6f20·6e65·7720·6c69··ackage·to·new·li 
0003c4d0:·6e65·0a20·2020·2070·6163·6b61·6765·735f··ne.····packages_ 
0003c4e0:·746f·5f72·6569·6e73·7461·6c6c·3d22·2428··to_reinstall="$( 
0003c4f0:·7270·6d20·2d71·6620·2466·696c·6573·5f77··rpm·-qf·$files_w 
0003c500:·6974·685f·696e·636f·7272·6563·745f·6861··ith_incorrect_ha 
0003c510:·7368·207c·2074·7220·275c·6e27·2027·2027··sh·|·tr·'\n'·'·' 
0003c520:·2922·0a0a·2020·2020·0a20·2020·2079·756d··)"..····.····yum 
0003c530:·2072·6569·6e73·7461·6c6c·202d·7920·2470···reinstall·-y·$p 
0003c540:·6163·6b61·6765·735f·746f·5f72·6569·6e73··ackages_to_reins 
0003c550:·7461·6c6c·0a20·2020·200a·6669·0a3c·2f63··tall.····.fi.</c 
0003c560:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003c570:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003c580:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003c590:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003c5a0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003c5b0:·6964·6d37·3636·3322·2074·6162·696e·6465··idm7663"·tabinde 
0003c5c0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003c5d0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003c5e0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003c5f0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003c600:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003c610:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib0003c300:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib
0003c620:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</0003c310:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</
0003c630:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003c320:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003c640:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003c330:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003c650:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003c340:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003c660:·646d·3736·3633·223e·3c74·6162·6c65·2063··dm7663"><table·c0003c350:·646d·3736·3632·223e·3c74·6162·6c65·2063··dm7662"><table·c
0003c670:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003c360:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003c680:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003c370:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003c690:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003c380:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003c6a0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003c390:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003c6b0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003c3a0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003c6c0:·683e·3c74·643e·6869·6768·3c2f·7464·3e3c··h><td>high</td><0003c3b0:·683e·3c74·643e·6869·6768·3c2f·7464·3e3c··h><td>high</td><
0003c6d0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003c3c0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003c6e0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003c3d0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003c6f0:·6d65·6469·756d·3c2f·7464·3e3c·2f74·723e··medium</td></tr>0003c3e0:·6d65·6469·756d·3c2f·7464·3e3c·2f74·723e··medium</td></tr>
0003c700:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<0003c3f0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
0003c710:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003c400:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003c720:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003c410:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003c730:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003c420:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003c740:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></0003c430:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></
0003c750:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003c440:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
0003c760:·3c63·6f64·653e·2d20·6e61·6d65·3a20·2753··<code>-·name:·'S0003c450:·3c63·6f64·653e·2d20·6e61·6d65·3a20·2753··<code>-·name:·'S
0003c770:·6574·2066·6163·743a·2050·6163·6b61·6765··et·fact:·Package0003c460:·6574·2066·6163·743a·2050·6163·6b61·6765··et·fact:·Package
0003c780:·206d·616e·6167·6572·2072·6569·6e73·7461···manager·reinsta0003c470:·206d·616e·6167·6572·2072·6569·6e73·7461···manager·reinsta
0003c790:·6c6c·2063·6f6d·6d61·6e64·270a·2020·7365··ll·command'.··se0003c480:·6c6c·2063·6f6d·6d61·6e64·270a·2020·7365··ll·command'.··se
0003c7a0:·745f·6661·6374·3a0a·2020·2020·7061·636b··t_fact:.····pack0003c490:·745f·6661·6374·3a0a·2020·2020·7061·636b··t_fact:.····pack
0003c7b0:·6167·655f·6d61·6e61·6765·725f·7265·696e··age_manager_rein0003c4a0:·6167·655f·6d61·6e61·6765·725f·7265·696e··age_manager_rein
0003c7c0:·7374·616c·6c5f·636d·643a·2079·756d·2072··stall_cmd:·yum·r0003c4b0:·7374·616c·6c5f·636d·643a·2079·756d·2072··stall_cmd:·yum·r
0003c7d0:·6569·6e73·7461·6c6c·202d·790a·2020·7768··einstall·-y.··wh0003c4c0:·6569·6e73·7461·6c6c·202d·790a·2020·7768··einstall·-y.··wh
0003c7e0:·656e·3a20·616e·7369·626c·655f·6469·7374··en:·ansible_dist0003c4d0:·656e·3a20·616e·7369·626c·655f·6469·7374··en:·ansible_dist
0003c7f0:·7269·6275·7469·6f6e·2069·6e20·5b20·2246··ribution·in·[·"F0003c4e0:·7269·6275·7469·6f6e·2069·6e20·5b20·2246··ribution·in·[·"F
0003c800:·6564·6f72·6122·2c20·2252·6564·4861·7422··edora",·"RedHat"0003c4f0:·6564·6f72·6122·2c20·2252·6564·4861·7422··edora",·"RedHat"
0003c810:·2c20·2243·656e·744f·5322·2c20·224f·7261··,·"CentOS",·"Ora0003c500:·2c20·2243·656e·744f·5322·2c20·224f·7261··,·"CentOS",·"Ora
0003c820:·636c·654c·696e·7578·2220·5d0a·2020·7461··cleLinux"·].··ta0003c510:·636c·654c·696e·7578·2220·5d0a·2020·7461··cleLinux"·].··ta
0003c830:·6773·3a0a·2020·2d20·434a·4953·2d35·2e31··gs:.··-·CJIS-5.10003c520:·6773·3a0a·2020·2d20·434a·4953·2d35·2e31··gs:.··-·CJIS-5.1
0003c840:·302e·342e·310a·2020·2d20·4e49·5354·2d38··0.4.1.··-·NIST-80003c530:·302e·342e·310a·2020·2d20·4e49·5354·2d38··0.4.1.··-·NIST-8
0003c850:·3030·2d31·3731·2d33·2e33·2e38·0a20·202d··00-171-3.3.8.··-0003c540:·3030·2d31·3731·2d33·2e33·2e38·0a20·202d··00-171-3.3.8.··-
0003c860:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.0003c550:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.
0003c870:·342e·310a·2020·2d20·4e49·5354·2d38·3030··4.1.··-·NIST-8000003c560:·342e·310a·2020·2d20·4e49·5354·2d38·3030··4.1.··-·NIST-800
0003c880:·2d35·332d·4155·2d39·2833·290a·2020·2d20··-53-AU-9(3).··-·0003c570:·2d35·332d·4155·2d39·2833·290a·2020·2d20··-53-AU-9(3).··-·
0003c890:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-60003c580:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6
0003c8a0:·2863·290a·2020·2d20·4e49·5354·2d38·3030··(c).··-·NIST-8000003c590:·2863·290a·2020·2d20·4e49·5354·2d38·3030··(c).··-·NIST-800
0003c8b0:·2d35·332d·434d·2d36·2864·290a·2020·2d20··-53-CM-6(d).··-·0003c5a0:·2d35·332d·434d·2d36·2864·290a·2020·2d20··-53-CM-6(d).··-·
0003c8c0:·4e49·5354·2d38·3030·2d35·332d·5349·2d37··NIST-800-53-SI-70003c5b0:·4e49·5354·2d38·3030·2d35·332d·5349·2d37··NIST-800-53-SI-7
0003c8d0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-530003c5c0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
0003c8e0:·2d53·492d·3728·3129·0a20·202d·204e·4953··-SI-7(1).··-·NIS0003c5d0:·2d53·492d·3728·3129·0a20·202d·204e·4953··-SI-7(1).··-·NIS
0003c8f0:·542d·3830·302d·3533·2d53·492d·3728·3629··T-800-53-SI-7(6)0003c5e0:·542d·3830·302d·3533·2d53·492d·3728·3629··T-800-53-SI-7(6)
0003c900:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req0003c5f0:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req
0003c910:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS0003c600:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS
0003c920:·5376·342d·3131·2e35·2e32·0a20·202d·2068··Sv4-11.5.2.··-·h0003c610:·5376·342d·3131·2e35·2e32·0a20·202d·2068··Sv4-11.5.2.··-·h
0003c930:·6967·685f·636f·6d70·6c65·7869·7479·0a20··igh_complexity.·0003c620:·6967·685f·636f·6d70·6c65·7869·7479·0a20··igh_complexity.·
0003c940:·202d·2068·6967·685f·7365·7665·7269·7479···-·high_severity0003c630:·202d·2068·6967·685f·7365·7665·7269·7479···-·high_severity
0003c950:·0a20·202d·206d·6564·6975·6d5f·6469·7372··.··-·medium_disr0003c640:·0a20·202d·206d·6564·6975·6d5f·6469·7372··.··-·medium_disr
0003c960:·7570·7469·6f6e·0a20·202d·206e·6f5f·7265··uption.··-·no_re0003c650:·7570·7469·6f6e·0a20·202d·206e·6f5f·7265··uption.··-·no_re
Max diff block lines reached; 6538049/6579503 bytes (99.37%) of diff not shown.
710 KB
html2text {}
    
Offset 70, 15 lines modifiedOffset 70, 15 lines modified
70 ····*·cpe:/o:redhat:enterprise_linux:8.770 ····*·cpe:/o:redhat:enterprise_linux:8.7
71 ····*·cpe:/o:redhat:enterprise_linux:8.871 ····*·cpe:/o:redhat:enterprise_linux:8.8
72 ····*·cpe:/o:redhat:enterprise_linux:8.972 ····*·cpe:/o:redhat:enterprise_linux:8.9
73 ····*·cpe:/o:redhat:enterprise_linux:873 ····*·cpe:/o:redhat:enterprise_linux:8
74 ····*·cpe:/o:centos:centos:874 ····*·cpe:/o:centos:centos:8
75 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*75 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
76 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8476 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
77 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)77 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
78 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*78 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
79 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s79 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
80 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e80 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
81 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l81 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
82 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g82 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
83 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s83 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
84 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s84 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 132, 27 lines modifiedOffset 132, 14 lines modified
132 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6132 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
133 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4133 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
134 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)134 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
135 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1135 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
136 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5136 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
137 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227137 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
138 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2138 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
140 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
141 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
142 if·[·-n·"$files_with_incorrect_hash"·];·then 
143 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
144 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
145 ····yum·reinstall·-y·$packages_to_reinstall 
  
146 fi 
147 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
148 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
149 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
150 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
151 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
152 -·name:·'Set·fact:·Package·manager·reinstall·command'144 -·name:·'Set·fact:·Package·manager·reinstall·command'
153 ··set_fact:145 ··set_fact:
Offset 279, 14 lines modifiedOffset 266, 27 lines modified
279 ··-·PCI-DSSv4-11.5.2266 ··-·PCI-DSSv4-11.5.2
280 ··-·high_complexity267 ··-·high_complexity
281 ··-·high_severity268 ··-·high_severity
282 ··-·medium_disruption269 ··-·medium_disruption
283 ··-·no_reboot_needed270 ··-·no_reboot_needed
284 ··-·restrict_strategy271 ··-·restrict_strategy
285 ··-·rpm_verify_hashes272 ··-·rpm_verify_hashes
 273 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 274 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 275 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 276 if·[·-n·"$files_with_incorrect_hash"·];·then
 277 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 278 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 279 ····yum·reinstall·-y·$packages_to_reinstall
  
 280 fi
286 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*281 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
287 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:282 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
288 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'283 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
289 run·the·following·command·to·determine·which·package·owns·it:284 run·the·following·command·to·determine·which·package·owns·it:
290 $·rpm·-qf·FILENAME285 $·rpm·-qf·FILENAME
291 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:286 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
292 $·sudo·rpm·--setugids·PACKAGENAME287 $·sudo·rpm·--setugids·PACKAGENAME
Offset 305, 40 lines modifiedOffset 305, 14 lines modified
305 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5305 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
306 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2306 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
307 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)307 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
308 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1308 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
309 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5309 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
310 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108310 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
311 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2311 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
312 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
313 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
314 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
315 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
316 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
317 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
318 declare·-A·SETPERMS_RPM_DICT 
  
319 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
320 #·is·expected·by·the·RPM·database 
321 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
322 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
323 do 
324 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
325 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
326 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
327 done 
  
328 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
329 #·correct·values 
330 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
331 do 
332 ········rpm·--setugids·"${RPM_PACKAGE}" 
333 done 
334 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8312 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
335 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high313 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
336 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium314 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
337 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false315 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
338 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict316 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
339 -·name:·Read·list·of·files·with·incorrect·ownership317 -·name:·Read·list·of·files·with·incorrect·ownership
340 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev318 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 413, 14 lines modifiedOffset 387, 40 lines modified
413 ··-·PCI-DSSv4-11.5.2387 ··-·PCI-DSSv4-11.5.2
414 ··-·high_complexity388 ··-·high_complexity
415 ··-·high_severity389 ··-·high_severity
416 ··-·medium_disruption390 ··-·medium_disruption
417 ··-·no_reboot_needed391 ··-·no_reboot_needed
418 ··-·restrict_strategy392 ··-·restrict_strategy
419 ··-·rpm_verify_ownership393 ··-·rpm_verify_ownership
 394 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 395 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 396 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 397 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 398 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 399 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 719024/726756 bytes (98.94%) of diff not shown.
17.8 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-hipaa.html
    
Offset 14569, 15 lines modifiedOffset 14569, 15 lines modified
00038e80:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00038e80:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00038e90:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00038e90:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00038ea0:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s00038ea0:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00038eb0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00038eb0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00038ec0:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00038ec0:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00038ed0:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00038ed0:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00038ee0:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00038ee0:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00038ef0:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).00038ef0:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
00038f00:·2020·2020·2020·2020·2020·2020·2020·2020··················00038f00:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038f10:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00038f10:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00038f20:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00038f20:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00038f30:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00038f30:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00038f40:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00038f40:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00038f50:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00038f50:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00038f60:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00038f60:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
Offset 15428, 301 lines modifiedOffset 15428, 301 lines modified
0003c430:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003c430:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003c440:·2223·6964·6d37·3636·3222·2074·6162·696e··"#idm7662"·tabin0003c440:·2223·6964·6d37·3636·3222·2074·6162·696e··"#idm7662"·tabin
0003c450:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003c450:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003c460:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003c460:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003c470:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003c470:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003c480:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003c480:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003c490:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003c490:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003c4a0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
0003c4b0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
0003c4c0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003c4d0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003c4e0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003c4f0:·6d37·3636·3222·3e3c·7072·653e·3c63·6f64··m7662"><pre><cod 
0003c500:·653e·0a23·2046·696e·6420·7768·6963·6820··e>.#·Find·which· 
0003c510:·6669·6c65·7320·6861·7665·2069·6e63·6f72··files·have·incor 
0003c520:·7265·6374·2068·6173·6820·286e·6f74·2069··rect·hash·(not·i 
0003c530:·6e20·2f65·7463·2c20·6265·6361·7573·6520··n·/etc,·because· 
0003c540:·6f66·2074·6865·2073·7973·7465·6d20·7265··of·the·system·re 
0003c550:·6c61·7465·6420·636f·6e66·6967·2066·696c··lated·config·fil 
0003c560:·6573·2920·616e·6420·7468·656e·2067·6574··es)·and·then·get 
0003c570:·2066·696c·6573·206e·616d·6573·0a66·696c···files·names.fil 
0003c580:·6573·5f77·6974·685f·696e·636f·7272·6563··es_with_incorrec 
0003c590:·745f·6861·7368·3d22·2428·7270·6d20·2d56··t_hash="$(rpm·-V 
0003c5a0:·6120·2d2d·6e6f·636f·6e66·6967·207c·2067··a·--noconfig·|·g 
0003c5b0:·7265·7020·2d45·2027·5e2e·2e35·2720·7c20··rep·-E·'^..5'·|· 
0003c5c0:·6177·6b20·277b·7072·696e·7420·244e·467d··awk·'{print·$NF} 
0003c5d0:·2720·2922·0a0a·6966·205b·202d·6e20·2224··'·)"..if·[·-n·"$ 
0003c5e0:·6669·6c65·735f·7769·7468·5f69·6e63·6f72··files_with_incor 
0003c5f0:·7265·6374·5f68·6173·6822·205d·3b20·7468··rect_hash"·];·th 
0003c600:·656e·0a20·2020·2023·2046·726f·6d20·6669··en.····#·From·fi 
0003c610:·6c65·7320·6e61·6d65·7320·6765·7420·7061··les·names·get·pa 
0003c620:·636b·6167·6520·6e61·6d65·7320·616e·6420··ckage·names·and· 
0003c630:·6368·616e·6765·206e·6577·6c69·6e65·2074··change·newline·t 
0003c640:·6f20·7370·6163·652c·2062·6563·6175·7365··o·space,·because 
0003c650:·2072·706d·2077·7269·7465·7320·6561·6368···rpm·writes·each 
0003c660:·2070·6163·6b61·6765·2074·6f20·6e65·7720···package·to·new· 
0003c670:·6c69·6e65·0a20·2020·2070·6163·6b61·6765··line.····package 
0003c680:·735f·746f·5f72·6569·6e73·7461·6c6c·3d22··s_to_reinstall=" 
0003c690:·2428·7270·6d20·2d71·6620·2466·696c·6573··$(rpm·-qf·$files 
0003c6a0:·5f77·6974·685f·696e·636f·7272·6563·745f··_with_incorrect_ 
0003c6b0:·6861·7368·207c·2074·7220·275c·6e27·2027··hash·|·tr·'\n'·' 
0003c6c0:·2027·2922·0a0a·2020·2020·0a20·2020·2079···')"..····.····y 
0003c6d0:·756d·2072·6569·6e73·7461·6c6c·202d·7920··um·reinstall·-y· 
0003c6e0:·2470·6163·6b61·6765·735f·746f·5f72·6569··$packages_to_rei 
0003c6f0:·6e73·7461·6c6c·0a20·2020·200a·6669·0a3c··nstall.····.fi.< 
0003c700:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003c710:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003c720:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003c730:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003c740:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003c750:·2223·6964·6d37·3636·3322·2074·6162·696e··"#idm7663"·tabin 
0003c760:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003c770:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003c780:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003c790:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003c7a0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003c7b0:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans0003c4a0:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans
0003c7c0:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...0003c4b0:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...
0003c7d0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003c4c0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003c7e0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003c4d0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003c7f0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003c4e0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003c800:·2269·646d·3736·3633·223e·3c74·6162·6c65··"idm7663"><table0003c4f0:·2269·646d·3736·3632·223e·3c74·6162·6c65··"idm7662"><table
0003c810:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003c500:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003c820:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003c510:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003c830:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003c520:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003c840:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003c530:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003c850:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003c540:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003c860:·2f74·683e·3c74·643e·6869·6768·3c2f·7464··/th><td>high</td0003c550:·2f74·683e·3c74·643e·6869·6768·3c2f·7464··/th><td>high</td
0003c870:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003c560:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003c880:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003c570:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003c890:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t0003c580:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t
0003c8a0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot0003c590:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
0003c8b0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<0003c5a0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003c8c0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003c5b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c8d0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003c5c0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003c8e0:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>0003c5d0:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>
0003c8f0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003c5e0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
0003c900:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·0003c5f0:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·
0003c910:·2753·6574·2066·6163·743a·2050·6163·6b61··'Set·fact:·Packa0003c600:·2753·6574·2066·6163·743a·2050·6163·6b61··'Set·fact:·Packa
0003c920:·6765·206d·616e·6167·6572·2072·6569·6e73··ge·manager·reins0003c610:·6765·206d·616e·6167·6572·2072·6569·6e73··ge·manager·reins
0003c930:·7461·6c6c·2063·6f6d·6d61·6e64·270a·2020··tall·command'.··0003c620:·7461·6c6c·2063·6f6d·6d61·6e64·270a·2020··tall·command'.··
0003c940:·7365·745f·6661·6374·3a0a·2020·2020·7061··set_fact:.····pa0003c630:·7365·745f·6661·6374·3a0a·2020·2020·7061··set_fact:.····pa
0003c950:·636b·6167·655f·6d61·6e61·6765·725f·7265··ckage_manager_re0003c640:·636b·6167·655f·6d61·6e61·6765·725f·7265··ckage_manager_re
0003c960:·696e·7374·616c·6c5f·636d·643a·2079·756d··install_cmd:·yum0003c650:·696e·7374·616c·6c5f·636d·643a·2079·756d··install_cmd:·yum
0003c970:·2072·6569·6e73·7461·6c6c·202d·790a·2020···reinstall·-y.··0003c660:·2072·6569·6e73·7461·6c6c·202d·790a·2020···reinstall·-y.··
0003c980:·7768·656e·3a20·616e·7369·626c·655f·6469··when:·ansible_di0003c670:·7768·656e·3a20·616e·7369·626c·655f·6469··when:·ansible_di
0003c990:·7374·7269·6275·7469·6f6e·2069·6e20·5b20··stribution·in·[·0003c680:·7374·7269·6275·7469·6f6e·2069·6e20·5b20··stribution·in·[·
0003c9a0:·2246·6564·6f72·6122·2c20·2252·6564·4861··"Fedora",·"RedHa0003c690:·2246·6564·6f72·6122·2c20·2252·6564·4861··"Fedora",·"RedHa
0003c9b0:·7422·2c20·2243·656e·744f·5322·2c20·224f··t",·"CentOS",·"O0003c6a0:·7422·2c20·2243·656e·744f·5322·2c20·224f··t",·"CentOS",·"O
0003c9c0:·7261·636c·654c·696e·7578·2220·5d0a·2020··racleLinux"·].··0003c6b0:·7261·636c·654c·696e·7578·2220·5d0a·2020··racleLinux"·].··
0003c9d0:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-50003c6c0:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-5
0003c9e0:·2e31·302e·342e·310a·2020·2d20·4e49·5354··.10.4.1.··-·NIST0003c6d0:·2e31·302e·342e·310a·2020·2d20·4e49·5354··.10.4.1.··-·NIST
0003c9f0:·2d38·3030·2d31·3731·2d33·2e33·2e38·0a20··-800-171-3.3.8.·0003c6e0:·2d38·3030·2d31·3731·2d33·2e33·2e38·0a20··-800-171-3.3.8.·
0003ca00:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-0003c6f0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
0003ca10:·332e·342e·310a·2020·2d20·4e49·5354·2d38··3.4.1.··-·NIST-80003c700:·332e·342e·310a·2020·2d20·4e49·5354·2d38··3.4.1.··-·NIST-8
0003ca20:·3030·2d35·332d·4155·2d39·2833·290a·2020··00-53-AU-9(3).··0003c710:·3030·2d35·332d·4155·2d39·2833·290a·2020··00-53-AU-9(3).··
0003ca30:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM0003c720:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
0003ca40:·2d36·2863·290a·2020·2d20·4e49·5354·2d38··-6(c).··-·NIST-80003c730:·2d36·2863·290a·2020·2d20·4e49·5354·2d38··-6(c).··-·NIST-8
0003ca50:·3030·2d35·332d·434d·2d36·2864·290a·2020··00-53-CM-6(d).··0003c740:·3030·2d35·332d·434d·2d36·2864·290a·2020··00-53-CM-6(d).··
0003ca60:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI0003c750:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI
0003ca70:·2d37·0a20·202d·204e·4953·542d·3830·302d··-7.··-·NIST-800-0003c760:·2d37·0a20·202d·204e·4953·542d·3830·302d··-7.··-·NIST-800-
0003ca80:·3533·2d53·492d·3728·3129·0a20·202d·204e··53-SI-7(1).··-·N0003c770:·3533·2d53·492d·3728·3129·0a20·202d·204e··53-SI-7(1).··-·N
0003ca90:·4953·542d·3830·302d·3533·2d53·492d·3728··IST-800-53-SI-7(0003c780:·4953·542d·3830·302d·3533·2d53·492d·3728··IST-800-53-SI-7(
0003caa0:·3629·0a20·202d·2050·4349·2d44·5353·2d52··6).··-·PCI-DSS-R0003c790:·3629·0a20·202d·2050·4349·2d44·5353·2d52··6).··-·PCI-DSS-R
0003cab0:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI-0003c7a0:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI-
0003cac0:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··-0003c7b0:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··-
0003cad0:·2068·6967·685f·636f·6d70·6c65·7869·7479···high_complexity0003c7c0:·2068·6967·685f·636f·6d70·6c65·7869·7479···high_complexity
0003cae0:·0a20·202d·2068·6967·685f·7365·7665·7269··.··-·high_severi0003c7d0:·0a20·202d·2068·6967·685f·7365·7665·7269··.··-·high_severi
0003caf0:·7479·0a20·202d·206d·6564·6975·6d5f·6469··ty.··-·medium_di0003c7e0:·7479·0a20·202d·206d·6564·6975·6d5f·6469··ty.··-·medium_di
0003cb00:·7372·7570·7469·6f6e·0a20·202d·206e·6f5f··sruption.··-·no_0003c7f0:·7372·7570·7469·6f6e·0a20·202d·206e·6f5f··sruption.··-·no_
0003cb10:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.··0003c800:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.··
Max diff block lines reached; 17269050/17294634 bytes (99.85%) of diff not shown.
1.3 MB
html2text {}
    
Offset 75, 15 lines modifiedOffset 75, 15 lines modified
75 ····*·cpe:/o:redhat:enterprise_linux:8.775 ····*·cpe:/o:redhat:enterprise_linux:8.7
76 ····*·cpe:/o:redhat:enterprise_linux:8.876 ····*·cpe:/o:redhat:enterprise_linux:8.8
77 ····*·cpe:/o:redhat:enterprise_linux:8.977 ····*·cpe:/o:redhat:enterprise_linux:8.9
78 ····*·cpe:/o:redhat:enterprise_linux:878 ····*·cpe:/o:redhat:enterprise_linux:8
79 ····*·cpe:/o:centos:centos:879 ····*·cpe:/o:centos:centos:8
80 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*80 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
81 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8481 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
82 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)82 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
83 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*83 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
84 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s84 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
85 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e85 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
86 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l86 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
87 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n87 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
88 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g88 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
89 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s89 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 138, 27 lines modifiedOffset 138, 14 lines modified
138 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6138 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
139 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4139 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
140 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)140 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
141 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1141 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
142 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5142 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
143 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227143 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
144 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2144 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
146 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
147 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
148 if·[·-n·"$files_with_incorrect_hash"·];·then 
149 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
150 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
151 ····yum·reinstall·-y·$packages_to_reinstall 
  
152 fi 
153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
154 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
155 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
156 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
157 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
158 -·name:·'Set·fact:·Package·manager·reinstall·command'150 -·name:·'Set·fact:·Package·manager·reinstall·command'
159 ··set_fact:151 ··set_fact:
Offset 285, 14 lines modifiedOffset 272, 27 lines modified
285 ··-·PCI-DSSv4-11.5.2272 ··-·PCI-DSSv4-11.5.2
286 ··-·high_complexity273 ··-·high_complexity
287 ··-·high_severity274 ··-·high_severity
288 ··-·medium_disruption275 ··-·medium_disruption
289 ··-·no_reboot_needed276 ··-·no_reboot_needed
290 ··-·restrict_strategy277 ··-·restrict_strategy
291 ··-·rpm_verify_hashes278 ··-·rpm_verify_hashes
 279 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 280 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 281 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 282 if·[·-n·"$files_with_incorrect_hash"·];·then
 283 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 284 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 285 ····yum·reinstall·-y·$packages_to_reinstall
  
 286 fi
292 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*287 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
293 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:288 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:
294 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'289 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'
295 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:290 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:
296 $·rpm·-qf·FILENAME291 $·rpm·-qf·FILENAME
  
297 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:292 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
Offset 313, 44 lines modifiedOffset 313, 14 lines modified
313 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5313 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
314 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2314 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
315 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)315 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)
316 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1316 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
317 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5317 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
318 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108318 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108
319 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2319 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
320 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
321 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
322 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
323 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
324 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
325 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
326 declare·-A·SETPERMS_RPM_DICT 
  
327 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
328 #·is·expected·by·the·RPM·database 
329 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}') 
  
330 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
331 do 
332 ········#·NOTE:·some·files·maybe·controlled·by·more·then·one·package 
333 ········readarray·-t·RPM_PACKAGES·<·<(rpm·-qf·"${FILE_PATH}") 
334 ········for·RPM_PACKAGE·in·"${RPM_PACKAGES[@]}" 
335 ········do 
336 ················#·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
337 ················SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
338 ········done 
339 done 
  
340 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
341 #·correct·values 
342 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
343 do 
344 »       rpm·--restore·"${RPM_PACKAGE}" 
345 done 
346 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8320 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
347 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high321 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
348 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium322 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
349 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false323 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
350 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict324 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
351 -·name:·Read·list·of·files·with·incorrect·permissions325 -·name:·Read·list·of·files·with·incorrect·permissions
352 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev326 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 428, 14 lines modifiedOffset 398, 44 lines modified
428 ··-·PCI-DSSv4-11.5.2398 ··-·PCI-DSSv4-11.5.2
429 ··-·high_complexity399 ··-·high_complexity
430 ··-·high_severity400 ··-·high_severity
431 ··-·medium_disruption401 ··-·medium_disruption
432 ··-·no_reboot_needed402 ··-·no_reboot_needed
433 ··-·restrict_strategy403 ··-·restrict_strategy
434 ··-·rpm_verify_permissions404 ··-·rpm_verify_permissions
 405 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 406 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 407 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
Max diff block lines reached; 1351913/1360029 bytes (99.40%) of diff not shown.
10.6 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-ism_o.html
    
Offset 14562, 15 lines modifiedOffset 14562, 15 lines modified
00038e10:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00038e10:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00038e20:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00038e20:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00038e30:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s00038e30:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00038e40:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00038e40:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00038e50:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00038e50:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00038e60:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00038e60:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00038e70:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00038e70:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00038e80:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).00038e80:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
00038e90:·2020·2020·2020·2020·2020·2020·2020·2020··················00038e90:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038ea0:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00038ea0:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00038eb0:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00038eb0:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00038ec0:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00038ec0:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00038ed0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00038ed0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00038ee0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00038ee0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00038ef0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00038ef0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
Offset 15437, 300 lines modifiedOffset 15437, 300 lines modified
0003c4c0:·6574·3d22·2369·646d·3736·3632·2220·7461··et="#idm7662"·ta0003c4c0:·6574·3d22·2369·646d·3736·3632·2220·7461··et="#idm7662"·ta
0003c4d0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003c4d0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003c4e0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003c4e0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003c4f0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003c4f0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003c500:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003c500:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003c510:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003c510:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003c520:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003c520:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003c530:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
0003c540:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003c550:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003c560:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003c570:·2269·646d·3736·3632·223e·3c70·7265·3e3c··"idm7662"><pre>< 
0003c580:·636f·6465·3e0a·2320·4669·6e64·2077·6869··code>.#·Find·whi 
0003c590:·6368·2066·696c·6573·2068·6176·6520·696e··ch·files·have·in 
0003c5a0:·636f·7272·6563·7420·6861·7368·2028·6e6f··correct·hash·(no 
0003c5b0:·7420·696e·202f·6574·632c·2062·6563·6175··t·in·/etc,·becau 
0003c5c0:·7365·206f·6620·7468·6520·7379·7374·656d··se·of·the·system 
0003c5d0:·2072·656c·6174·6564·2063·6f6e·6669·6720···related·config· 
0003c5e0:·6669·6c65·7329·2061·6e64·2074·6865·6e20··files)·and·then· 
0003c5f0:·6765·7420·6669·6c65·7320·6e61·6d65·730a··get·files·names. 
0003c600:·6669·6c65·735f·7769·7468·5f69·6e63·6f72··files_with_incor 
0003c610:·7265·6374·5f68·6173·683d·2224·2872·706d··rect_hash="$(rpm 
0003c620:·202d·5661·202d·2d6e·6f63·6f6e·6669·6720···-Va·--noconfig· 
0003c630:·7c20·6772·6570·202d·4520·275e·2e2e·3527··|·grep·-E·'^..5' 
0003c640:·207c·2061·776b·2027·7b70·7269·6e74·2024···|·awk·'{print·$ 
0003c650:·4e46·7d27·2029·220a·0a69·6620·5b20·2d6e··NF}'·)"..if·[·-n 
0003c660:·2022·2466·696c·6573·5f77·6974·685f·696e···"$files_with_in 
0003c670:·636f·7272·6563·745f·6861·7368·2220·5d3b··correct_hash"·]; 
0003c680:·2074·6865·6e0a·2020·2020·2320·4672·6f6d···then.····#·From 
0003c690:·2066·696c·6573·206e·616d·6573·2067·6574···files·names·get 
0003c6a0:·2070·6163·6b61·6765·206e·616d·6573·2061···package·names·a 
0003c6b0:·6e64·2063·6861·6e67·6520·6e65·776c·696e··nd·change·newlin 
0003c6c0:·6520·746f·2073·7061·6365·2c20·6265·6361··e·to·space,·beca 
0003c6d0:·7573·6520·7270·6d20·7772·6974·6573·2065··use·rpm·writes·e 
0003c6e0:·6163·6820·7061·636b·6167·6520·746f·206e··ach·package·to·n 
0003c6f0:·6577·206c·696e·650a·2020·2020·7061·636b··ew·line.····pack 
0003c700:·6167·6573·5f74·6f5f·7265·696e·7374·616c··ages_to_reinstal 
0003c710:·6c3d·2224·2872·706d·202d·7166·2024·6669··l="$(rpm·-qf·$fi 
0003c720:·6c65·735f·7769·7468·5f69·6e63·6f72·7265··les_with_incorre 
0003c730:·6374·5f68·6173·6820·7c20·7472·2027·5c6e··ct_hash·|·tr·'\n 
0003c740:·2720·2720·2729·220a·0a20·2020·200a·2020··'·'·')"..····.·· 
0003c750:·2020·7975·6d20·7265·696e·7374·616c·6c20····yum·reinstall· 
0003c760:·2d79·2024·7061·636b·6167·6573·5f74·6f5f··-y·$packages_to_ 
0003c770:·7265·696e·7374·616c·6c0a·2020·2020·0a66··reinstall.····.f 
0003c780:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre>< 
0003c790:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003c7a0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003c7b0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003c7c0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003c7d0:·6574·3d22·2369·646d·3736·3633·2220·7461··et="#idm7663"·ta 
0003c7e0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003c7f0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003c800:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003c810:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003c820:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003c830:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003c840:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet·0003c530:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet·
0003c850:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003c540:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003c860:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003c550:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003c870:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003c560:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003c880:·6964·3d22·6964·6d37·3636·3322·3e3c·7461··id="idm7663"><ta0003c570:·6964·3d22·6964·6d37·3636·3222·3e3c·7461··id="idm7662"><ta
0003c890:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0003c580:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003c8a0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0003c590:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003c8b0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0003c5a0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003c8c0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0003c5b0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003c8d0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003c5c0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003c8e0:·793a·3c2f·7468·3e3c·7464·3e68·6967·683c··y:</th><td>high<0003c5d0:·793a·3c2f·7468·3e3c·7464·3e68·6967·683c··y:</th><td>high<
0003c8f0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003c5e0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c900:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th0003c5f0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003c910:·3e3c·7464·3e6d·6564·6975·6d3c·2f74·643e··><td>medium</td>0003c600:·3e3c·7464·3e6d·6564·6975·6d3c·2f74·643e··><td>medium</td>
0003c920:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb0003c610:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
0003c930:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal0003c620:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
0003c940:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>0003c630:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
0003c950:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t0003c640:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0003c960:·683e·3c74·643e·7265·7374·7269·6374·3c2f··h><td>restrict</0003c650:·683e·3c74·643e·7265·7374·7269·6374·3c2f··h><td>restrict</
0003c970:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>0003c660:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
0003c980:·3c70·7265·3e3c·636f·6465·3e2d·206e·616d··<pre><code>-·nam0003c670:·3c70·7265·3e3c·636f·6465·3e2d·206e·616d··<pre><code>-·nam
0003c990:·653a·2027·5365·7420·6661·6374·3a20·5061··e:·'Set·fact:·Pa0003c680:·653a·2027·5365·7420·6661·6374·3a20·5061··e:·'Set·fact:·Pa
0003c9a0:·636b·6167·6520·6d61·6e61·6765·7220·7265··ckage·manager·re0003c690:·636b·6167·6520·6d61·6e61·6765·7220·7265··ckage·manager·re
0003c9b0:·696e·7374·616c·6c20·636f·6d6d·616e·6427··install·command'0003c6a0:·696e·7374·616c·6c20·636f·6d6d·616e·6427··install·command'
0003c9c0:·0a20·2073·6574·5f66·6163·743a·0a20·2020··.··set_fact:.···0003c6b0:·0a20·2073·6574·5f66·6163·743a·0a20·2020··.··set_fact:.···
0003c9d0:·2070·6163·6b61·6765·5f6d·616e·6167·6572···package_manager0003c6c0:·2070·6163·6b61·6765·5f6d·616e·6167·6572···package_manager
0003c9e0:·5f72·6569·6e73·7461·6c6c·5f63·6d64·3a20··_reinstall_cmd:·0003c6d0:·5f72·6569·6e73·7461·6c6c·5f63·6d64·3a20··_reinstall_cmd:·
0003c9f0:·7975·6d20·7265·696e·7374·616c·6c20·2d79··yum·reinstall·-y0003c6e0:·7975·6d20·7265·696e·7374·616c·6c20·2d79··yum·reinstall·-y
0003ca00:·0a20·2077·6865·6e3a·2061·6e73·6962·6c65··.··when:·ansible0003c6f0:·0a20·2077·6865·6e3a·2061·6e73·6962·6c65··.··when:·ansible
0003ca10:·5f64·6973·7472·6962·7574·696f·6e20·696e··_distribution·in0003c700:·5f64·6973·7472·6962·7574·696f·6e20·696e··_distribution·in
0003ca20:·205b·2022·4665·646f·7261·222c·2022·5265···[·"Fedora",·"Re0003c710:·205b·2022·4665·646f·7261·222c·2022·5265···[·"Fedora",·"Re
0003ca30:·6448·6174·222c·2022·4365·6e74·4f53·222c··dHat",·"CentOS",0003c720:·6448·6174·222c·2022·4365·6e74·4f53·222c··dHat",·"CentOS",
0003ca40:·2022·4f72·6163·6c65·4c69·6e75·7822·205d···"OracleLinux"·]0003c730:·2022·4f72·6163·6c65·4c69·6e75·7822·205d···"OracleLinux"·]
0003ca50:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI0003c740:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI
0003ca60:·532d·352e·3130·2e34·2e31·0a20·202d·204e··S-5.10.4.1.··-·N0003c750:·532d·352e·3130·2e34·2e31·0a20·202d·204e··S-5.10.4.1.··-·N
0003ca70:·4953·542d·3830·302d·3137·312d·332e·332e··IST-800-171-3.3.0003c760:·4953·542d·3830·302d·3137·312d·332e·332e··IST-800-171-3.3.
0003ca80:·380a·2020·2d20·4e49·5354·2d38·3030·2d31··8.··-·NIST-800-10003c770:·380a·2020·2d20·4e49·5354·2d38·3030·2d31··8.··-·NIST-800-1
0003ca90:·3731·2d33·2e34·2e31·0a20·202d·204e·4953··71-3.4.1.··-·NIS0003c780:·3731·2d33·2e34·2e31·0a20·202d·204e·4953··71-3.4.1.··-·NIS
0003caa0:·542d·3830·302d·3533·2d41·552d·3928·3329··T-800-53-AU-9(3)0003c790:·542d·3830·302d·3533·2d41·552d·3928·3329··T-800-53-AU-9(3)
0003cab0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-530003c7a0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
0003cac0:·2d43·4d2d·3628·6329·0a20·202d·204e·4953··-CM-6(c).··-·NIS0003c7b0:·2d43·4d2d·3628·6329·0a20·202d·204e·4953··-CM-6(c).··-·NIS
0003cad0:·542d·3830·302d·3533·2d43·4d2d·3628·6429··T-800-53-CM-6(d)0003c7c0:·542d·3830·302d·3533·2d43·4d2d·3628·6429··T-800-53-CM-6(d)
0003cae0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-530003c7d0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
0003caf0:·2d53·492d·370a·2020·2d20·4e49·5354·2d38··-SI-7.··-·NIST-80003c7e0:·2d53·492d·370a·2020·2d20·4e49·5354·2d38··-SI-7.··-·NIST-8
0003cb00:·3030·2d35·332d·5349·2d37·2831·290a·2020··00-53-SI-7(1).··0003c7f0:·3030·2d35·332d·5349·2d37·2831·290a·2020··00-53-SI-7(1).··
0003cb10:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI0003c800:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI
0003cb20:·2d37·2836·290a·2020·2d20·5043·492d·4453··-7(6).··-·PCI-DS0003c810:·2d37·2836·290a·2020·2d20·5043·492d·4453··-7(6).··-·PCI-DS
0003cb30:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P0003c820:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P
0003cb40:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2.0003c830:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2.
0003cb50:·2020·2d20·6869·6768·5f63·6f6d·706c·6578····-·high_complex0003c840:·2020·2d20·6869·6768·5f63·6f6d·706c·6578····-·high_complex
0003cb60:·6974·790a·2020·2d20·6869·6768·5f73·6576··ity.··-·high_sev0003c850:·6974·790a·2020·2d20·6869·6768·5f73·6576··ity.··-·high_sev
0003cb70:·6572·6974·790a·2020·2d20·6d65·6469·756d··erity.··-·medium0003c860:·6572·6974·790a·2020·2d20·6d65·6469·756d··erity.··-·medium
0003cb80:·5f64·6973·7275·7074·696f·6e0a·2020·2d20··_disruption.··-·0003c870:·5f64·6973·7275·7074·696f·6e0a·2020·2d20··_disruption.··-·
0003cb90:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed0003c880:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed
0003cba0:·0a20·202d·2072·6573·7472·6963·745f·7374··.··-·restrict_st0003c890:·0a20·202d·2072·6573·7472·6963·745f·7374··.··-·restrict_st
Max diff block lines reached; 10000094/10041272 bytes (99.59%) of diff not shown.
1.03 MB
html2text {}
    
Offset 73, 15 lines modifiedOffset 73, 15 lines modified
73 ····*·cpe:/o:redhat:enterprise_linux:8.773 ····*·cpe:/o:redhat:enterprise_linux:8.7
74 ····*·cpe:/o:redhat:enterprise_linux:8.874 ····*·cpe:/o:redhat:enterprise_linux:8.8
75 ····*·cpe:/o:redhat:enterprise_linux:8.975 ····*·cpe:/o:redhat:enterprise_linux:8.9
76 ····*·cpe:/o:redhat:enterprise_linux:876 ····*·cpe:/o:redhat:enterprise_linux:8
77 ····*·cpe:/o:centos:centos:877 ····*·cpe:/o:centos:centos:8
78 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*78 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
79 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8479 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
80 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)80 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
81 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*81 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
82 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s82 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
83 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e83 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
84 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l84 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
85 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g85 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
86 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s86 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
87 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s87 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 139, 27 lines modifiedOffset 139, 14 lines modified
139 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6139 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
140 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4140 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
141 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)141 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
142 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1142 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
143 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5143 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
144 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227144 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
145 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2145 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
147 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
148 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
149 if·[·-n·"$files_with_incorrect_hash"·];·then 
150 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
151 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
152 ····yum·reinstall·-y·$packages_to_reinstall 
  
153 fi 
154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high147 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium148 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false149 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict150 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
159 -·name:·'Set·fact:·Package·manager·reinstall·command'151 -·name:·'Set·fact:·Package·manager·reinstall·command'
160 ··set_fact:152 ··set_fact:
Offset 286, 14 lines modifiedOffset 273, 27 lines modified
286 ··-·PCI-DSSv4-11.5.2273 ··-·PCI-DSSv4-11.5.2
287 ··-·high_complexity274 ··-·high_complexity
288 ··-·high_severity275 ··-·high_severity
289 ··-·medium_disruption276 ··-·medium_disruption
290 ··-·no_reboot_needed277 ··-·no_reboot_needed
291 ··-·restrict_strategy278 ··-·restrict_strategy
292 ··-·rpm_verify_hashes279 ··-·rpm_verify_hashes
 280 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 281 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 282 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 283 if·[·-n·"$files_with_incorrect_hash"·];·then
 284 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 285 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 286 ····yum·reinstall·-y·$packages_to_reinstall
  
 287 fi
293 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*288 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
294 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:289 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
295 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'290 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
296 run·the·following·command·to·determine·which·package·owns·it:291 run·the·following·command·to·determine·which·package·owns·it:
297 $·rpm·-qf·FILENAME292 $·rpm·-qf·FILENAME
298 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:293 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
299 $·sudo·rpm·--setugids·PACKAGENAME294 $·sudo·rpm·--setugids·PACKAGENAME
Offset 312, 40 lines modifiedOffset 312, 14 lines modified
312 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5312 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
313 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2313 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
314 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)314 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
315 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1315 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
316 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5316 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
317 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108317 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
318 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2318 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
319 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
320 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
321 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
322 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
323 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
324 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
325 declare·-A·SETPERMS_RPM_DICT 
  
326 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
327 #·is·expected·by·the·RPM·database 
328 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
329 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
330 do 
331 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
332 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
333 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
334 done 
  
335 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
336 #·correct·values 
337 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
338 do 
339 ········rpm·--setugids·"${RPM_PACKAGE}" 
340 done 
341 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8319 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
342 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high320 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
343 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium321 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
344 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false322 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
345 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict323 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
346 -·name:·Read·list·of·files·with·incorrect·ownership324 -·name:·Read·list·of·files·with·incorrect·ownership
347 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev325 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 420, 14 lines modifiedOffset 394, 40 lines modified
420 ··-·PCI-DSSv4-11.5.2394 ··-·PCI-DSSv4-11.5.2
421 ··-·high_complexity395 ··-·high_complexity
422 ··-·high_severity396 ··-·high_severity
423 ··-·medium_disruption397 ··-·medium_disruption
424 ··-·no_reboot_needed398 ··-·no_reboot_needed
425 ··-·restrict_strategy399 ··-·restrict_strategy
426 ··-·rpm_verify_ownership400 ··-·rpm_verify_ownership
 401 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 402 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 403 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 404 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 405 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 406 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 1077104/1084836 bytes (99.29%) of diff not shown.
9.99 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-ospp.html
    
Offset 14556, 15 lines modifiedOffset 14556, 15 lines modified
00038db0:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre00038db0:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre
00038dc0:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str00038dc0:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str
00038dd0:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro00038dd0:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro
00038de0:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><00038de0:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><
00038df0:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st00038df0:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st
00038e00:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········00038e00:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········
00038e10:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of00038e10:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of
00038e20:·2032·3032·362d·3031·2d30·3829·0a20·2020···2026-01-08).···00038e20:·2032·3032·342d·3132·2d30·3729·0a20·2020···2024-12-07).···
00038e30:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l00038e30:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l
00038e40:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h200038e40:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h2
00038e50:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten00038e50:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten
00038e60:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><00038e60:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><
00038e70:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o00038e70:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o
00038e80:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co00038e80:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co
00038e90:·6e74·656e·745f·6772·6f75·705f·7379·7374··ntent_group_syst00038e90:·6e74·656e·745f·6772·6f75·705f·7379·7374··ntent_group_syst
Offset 15331, 235 lines modifiedOffset 15331, 235 lines modified
0003be20:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm80003be20:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8
0003be30:·3030·3222·2074·6162·696e·6465·783d·2230··002"·tabindex="00003be30:·3030·3222·2074·6162·696e·6465·783d·2230··002"·tabindex="0
0003be40:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003be40:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003be50:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003be50:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003be60:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003be60:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003be70:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003be70:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003be80:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003be80:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003be90:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn0003be90:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·
0003bea0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003bea0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003beb0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003beb0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003bec0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003bec0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003bed0:·6170·7365·2220·6964·3d22·6964·6d38·3030··apse"·id="idm8000003bed0:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
0003bee0:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class=0003bee0:·3030·3222·3e3c·7461·626c·6520·636c·6173··002"><table·clas
0003bef0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003bef0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003bf00:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003bf00:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003bf10:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003bf10:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003bf20:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003bf20:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003bf30:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003bf30:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003bf40:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003bf40:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003bf50:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003bf50:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003bf60:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003bf60:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003bf70:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R0003bf70:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003bf80:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f0003bf80:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003bf90:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t0003bf90:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003bfa0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<0003bfa0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003bfb0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</0003bfb0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
0003bfc0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>0003bfc0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003bfd0:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu 
0003bfe0:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide. 
0003bff0:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a 
0003c000:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package· 
0003c010:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en 
0003c020:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst 
0003c030:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</ 
0003c040:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003c050:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003c060:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003c070:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003c080:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003c090:·2369·646d·3830·3033·2220·7461·6269·6e64··#idm8003"·tabind 
0003c0a0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003c0b0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003c0c0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003c0d0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003c0e0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003c0f0:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel 
0003c100:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a> 
0003c110:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003c120:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003c130:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003c140:·3830·3033·223e·3c74·6162·6c65·2063·6c61··8003"><table·cla 
0003c150:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003c160:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003c170:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003c180:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003c190:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003c1a0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003c1b0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003c1c0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003c1d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003c1e0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003c1f0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003c200:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003c210:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003c220:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003c230:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#· 
0003c240:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a 
0003c250:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i 
0003c260:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo 
0003c270:·726d·730a·6966·205b·2021·202d·6620·2f2e··rms.if·[·!·-f·/. 
0003c280:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp 
0003c290:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r 
0003c2a0:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv 
0003c2b0:·205d·3b20·7468·656e·0a0a·6966·2021·2072···];·then..if·!·r 
0003c2c0:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a 
0003c2d0:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.···· 
0003c2e0:·7975·6d20·696e·7374·616c·6c20·2d79·2022··yum·install·-y·" 
0003c2f0:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.· 
0003c300:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec 
0003c310:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation· 
0003c320:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl 
0003c330:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d 
0003c340:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code>< 
0003c350:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003c360:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003c370:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003c380:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003c390:·612d·7461·7267·6574·3d22·2369·646d·3830··a-target="#idm80 
0003c3a0:·3034·2220·7461·6269·6e64·6578·3d22·3022··04"·tabindex="0" 
0003c3b0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003c3c0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003c3d0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003c3e0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003c3f0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003c400:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn 
0003c410:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003c420:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003c430:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003c440:·6170·7365·2220·6964·3d22·6964·6d38·3030··apse"·id="idm800 
0003c450:·3422·3e3c·7461·626c·6520·636c·6173·733d··4"><table·class= 
0003c460:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003c470:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003c480:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003c490:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003c4a0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003c4b0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003c4c0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003c4d0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003c4e0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003c4f0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003c500:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
Max diff block lines reached; 9157851/9190059 bytes (99.65%) of diff not shown.
1.23 MB
html2text {}
    
Offset 71, 15 lines modifiedOffset 71, 15 lines modified
71 ····*·cpe:/o:redhat:enterprise_linux:8.771 ····*·cpe:/o:redhat:enterprise_linux:8.7
72 ····*·cpe:/o:redhat:enterprise_linux:8.872 ····*·cpe:/o:redhat:enterprise_linux:8.8
73 ····*·cpe:/o:redhat:enterprise_linux:8.973 ····*·cpe:/o:redhat:enterprise_linux:8.9
74 ····*·cpe:/o:redhat:enterprise_linux:874 ····*·cpe:/o:redhat:enterprise_linux:8
75 ····*·cpe:/o:centos:centos:875 ····*·cpe:/o:centos:centos:8
76 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*76 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
77 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8477 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
78 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)78 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
79 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*79 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
80 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s80 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
81 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e81 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
82 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l82 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
83 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n83 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
84 ·········4.·_\x8z_\x8I_\x8P_\x8L_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n84 ·········4.·_\x8z_\x8I_\x8P_\x8L_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
85 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g85 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 130, 41 lines modifiedOffset 130, 45 lines modified
130 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3130 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
131 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5131 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
132 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199132 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
133 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79133 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
134 ············_\x8c_\x8i_\x8s············5.3.1134 ············_\x8c_\x8i_\x8s············5.3.1
135 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2135 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
136 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule136 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule
 137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 142 package·--add=aide
137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low144 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low145 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false146 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable147 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
142 include·install_aide148 include·install_aide
  
143 class·install_aide·{149 class·install_aide·{
144 ··package·{·'aide':150 ··package·{·'aide':
145 ····ensure·=>·'installed',151 ····ensure·=>·'installed',
146 ··}152 ··}
147 }153 }
 154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 155 [[packages]]
 156 name·=·"aide"
 157 version·=·"*"
148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
149 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low159 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
150 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low160 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
151 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false161 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
152 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable162 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
153 #·Remediation·is·applicable·only·in·certain·platforms 
154 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
 163 package·install·aide
155 if·!·rpm·-q·--quiet·"aide"·;·then 
156 ····yum·install·-y·"aide" 
157 fi 
  
158 else 
159 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
160 fi 
161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low165 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low166 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false167 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable168 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
166 -·name:·Ensure·aide·is·installed169 -·name:·Ensure·aide·is·installed
167 ··package:170 ··package:
Offset 179, 33 lines modifiedOffset 183, 29 lines modified
179 ··-·PCI-DSSv4-11.5.2183 ··-·PCI-DSSv4-11.5.2
180 ··-·enable_strategy184 ··-·enable_strategy
181 ··-·low_complexity185 ··-·low_complexity
182 ··-·low_disruption186 ··-·low_disruption
183 ··-·medium_severity187 ··-·medium_severity
184 ··-·no_reboot_needed188 ··-·no_reboot_needed
185 ··-·package_aide_installed189 ··-·package_aide_installed
186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
187 [[packages]] 
188 name·=·"aide" 
189 version·=·"*" 
190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 195 #·Remediation·is·applicable·only·in·certain·platforms
 196 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 197 if·!·rpm·-q·--quiet·"aide"·;·then
 198 ····yum·install·-y·"aide"
 199 fi
195 package·install·aide 
196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
201 package·--add=aide200 else
 201 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 202 fi
202 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules203 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
203 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.204 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
204 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.205 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.
  
205 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.206 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
206 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*207 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 220, 27 lines modifiedOffset 220, 14 lines modified
220 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000068,·CCI-000803,·CCI-002450220 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000068,·CCI-000803,·CCI-002450
221 ············_\x8i_\x8s_\x8m······1446221 ············_\x8i_\x8s_\x8m······1446
222 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1222 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
223 References:·_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12223 References:·_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
224 ············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.1224 ············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.1
225 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223225 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223
226 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r928585_rule226 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r928585_rule
227 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
228 #·Remediation·is·applicable·only·in·certain·platforms 
229 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·);·then 
  
230 fips-mode-setup·--enable 
231 FIPS_CONF="/etc/dracut.conf.d/40-fips.conf" 
232 if·!·grep·"^add_dracutmodules+=\"·fips·\""·$FIPS_CONF;·then 
233 ····echo·"add_dracutmodules+=\"·fips·\""·>>·$FIPS_CONF 
Max diff block lines reached; 1281163/1287649 bytes (99.50%) of diff not shown.
18.0 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-pci-dss.html
    
Offset 14550, 16 lines modifiedOffset 14550, 16 lines modified
00038d50:·7369·6f6e·2048·6973·746f·7279·3c2f·6832··sion·History</h200038d50:·7369·6f6e·2048·6973·746f·7279·3c2f·6832··sion·History</h2
00038d60:·3e3c·703e·4375·7272·656e·7420·7665·7273··><p>Current·vers00038d60:·3e3c·703e·4375·7272·656e·7420·7665·7273··><p>Current·vers
00038d70:·696f·6e3a·203c·7374·726f·6e67·3e30·2e31··ion:·<strong>0.100038d70:·696f·6e3a·203c·7374·726f·6e67·3e30·2e31··ion:·<strong>0.1
00038d80:·2e37·343c·2f73·7472·6f6e·673e·3c2f·703e··.74</strong></p>00038d80:·2e37·343c·2f73·7472·6f6e·673e·3c2f·703e··.74</strong></p>
00038d90:·3c75·6c3e·3c6c·693e·3c73·7472·6f6e·673e··<ul><li><strong>00038d90:·3c75·6c3e·3c6c·693e·3c73·7472·6f6e·673e··<ul><li><strong>
00038da0:·6472·6166·743c·2f73·7472·6f6e·673e·0a20··draft</strong>.·00038da0:·6472·6166·743c·2f73·7472·6f6e·673e·0a20··draft</strong>.·
00038db0:·2020·2020·2020·2020·2020·2020·2020·2020··················00038db0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038dc0:·2020·2028·6173·206f·6620·3230·3236·2d30·····(as·of·2026-000038dc0:·2020·2028·6173·206f·6620·3230·3234·2d31·····(as·of·2024-1
00038dd0:·312d·3038·290a·2020·2020·2020·2020·2020··1-08).··········00038dd0:·322d·3037·290a·2020·2020·2020·2020·2020··2-07).··········
00038de0:·2020·2020·2020·3c2f·6c69·3e3c·2f75·6c3e········</li></ul>00038de0:·2020·2020·2020·3c2f·6c69·3e3c·2f75·6c3e········</li></ul>
00038df0:·3c2f·6469·763e·3c68·323e·5461·626c·6520··</div><h2>Table·00038df0:·3c2f·6469·763e·3c68·323e·5461·626c·6520··</div><h2>Table·
00038e00:·6f66·2043·6f6e·7465·6e74·733c·2f68·323e··of·Contents</h2>00038e00:·6f66·2043·6f6e·7465·6e74·733c·2f68·323e··of·Contents</h2>
00038e10:·3c6f·6c3e·3c6c·693e·3c61·2068·7265·663d··<ol><li><a·href=00038e10:·3c6f·6c3e·3c6c·693e·3c61·2068·7265·663d··<ol><li><a·href=
00038e20:·2223·7863·6364·665f·6f72·672e·7373·6770··"#xccdf_org.ssgp00038e20:·2223·7863·6364·665f·6f72·672e·7373·6770··"#xccdf_org.ssgp
00038e30:·726f·6a65·6374·2e63·6f6e·7465·6e74·5f67··roject.content_g00038e30:·726f·6a65·6374·2e63·6f6e·7465·6e74·5f67··roject.content_g
00038e40:·726f·7570·5f73·7973·7465·6d22·3e53·7973··roup_system">Sys00038e40:·726f·7570·5f73·7973·7465·6d22·3e53·7973··roup_system">Sys
Offset 15429, 301 lines modifiedOffset 15429, 301 lines modified
0003c440:·7461·7267·6574·3d22·2369·646d·3736·3632··target="#idm76620003c440:·7461·7267·6574·3d22·2369·646d·3736·3632··target="#idm7662
0003c450:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003c450:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003c460:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003c460:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003c470:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003c470:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003c480:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003c480:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003c490:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003c490:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003c4a0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003c4a0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003c4b0:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003c4c0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003c4d0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003c4e0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003c4f0:·2069·643d·2269·646d·3736·3632·223e·3c70···id="idm7662"><p 
0003c500:·7265·3e3c·636f·6465·3e0a·2320·4669·6e64··re><code>.#·Find 
0003c510:·2077·6869·6368·2066·696c·6573·2068·6176···which·files·hav 
0003c520:·6520·696e·636f·7272·6563·7420·6861·7368··e·incorrect·hash 
0003c530:·2028·6e6f·7420·696e·202f·6574·632c·2062···(not·in·/etc,·b 
0003c540:·6563·6175·7365·206f·6620·7468·6520·7379··ecause·of·the·sy 
0003c550:·7374·656d·2072·656c·6174·6564·2063·6f6e··stem·related·con 
0003c560:·6669·6720·6669·6c65·7329·2061·6e64·2074··fig·files)·and·t 
0003c570:·6865·6e20·6765·7420·6669·6c65·7320·6e61··hen·get·files·na 
0003c580:·6d65·730a·6669·6c65·735f·7769·7468·5f69··mes.files_with_i 
0003c590:·6e63·6f72·7265·6374·5f68·6173·683d·2224··ncorrect_hash="$ 
0003c5a0:·2872·706d·202d·5661·202d·2d6e·6f63·6f6e··(rpm·-Va·--nocon 
0003c5b0:·6669·6720·7c20·6772·6570·202d·4520·275e··fig·|·grep·-E·'^ 
0003c5c0:·2e2e·3527·207c·2061·776b·2027·7b70·7269··..5'·|·awk·'{pri 
0003c5d0:·6e74·2024·4e46·7d27·2029·220a·0a69·6620··nt·$NF}'·)"..if· 
0003c5e0:·5b20·2d6e·2022·2466·696c·6573·5f77·6974··[·-n·"$files_wit 
0003c5f0:·685f·696e·636f·7272·6563·745f·6861·7368··h_incorrect_hash 
0003c600:·2220·5d3b·2074·6865·6e0a·2020·2020·2320··"·];·then.····#· 
0003c610:·4672·6f6d·2066·696c·6573·206e·616d·6573··From·files·names 
0003c620:·2067·6574·2070·6163·6b61·6765·206e·616d···get·package·nam 
0003c630:·6573·2061·6e64·2063·6861·6e67·6520·6e65··es·and·change·ne 
0003c640:·776c·696e·6520·746f·2073·7061·6365·2c20··wline·to·space,· 
0003c650:·6265·6361·7573·6520·7270·6d20·7772·6974··because·rpm·writ 
0003c660:·6573·2065·6163·6820·7061·636b·6167·6520··es·each·package· 
0003c670:·746f·206e·6577·206c·696e·650a·2020·2020··to·new·line.···· 
0003c680:·7061·636b·6167·6573·5f74·6f5f·7265·696e··packages_to_rein 
0003c690:·7374·616c·6c3d·2224·2872·706d·202d·7166··stall="$(rpm·-qf 
0003c6a0:·2024·6669·6c65·735f·7769·7468·5f69·6e63···$files_with_inc 
0003c6b0:·6f72·7265·6374·5f68·6173·6820·7c20·7472··orrect_hash·|·tr 
0003c6c0:·2027·5c6e·2720·2720·2729·220a·0a20·2020···'\n'·'·')"..··· 
0003c6d0:·200a·2020·2020·7975·6d20·7265·696e·7374···.····yum·reinst 
0003c6e0:·616c·6c20·2d79·2024·7061·636b·6167·6573··all·-y·$packages 
0003c6f0:·5f74·6f5f·7265·696e·7374·616c·6c0a·2020··_to_reinstall.·· 
0003c700:·2020·0a66·690a·3c2f·636f·6465·3e3c·2f70····.fi.</code></p 
0003c710:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003c720:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003c730:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003c740:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003c750:·7461·7267·6574·3d22·2369·646d·3736·3633··target="#idm7663 
0003c760:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003c770:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003c780:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003c790:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003c7a0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003c7b0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003c7c0:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip0003c4b0:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip
0003c7d0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003c4c0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003c7e0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003c4d0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003c7f0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003c4e0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003c800:·7365·2220·6964·3d22·6964·6d37·3636·3322··se"·id="idm7663"0003c4f0:·7365·2220·6964·3d22·6964·6d37·3636·3222··se"·id="idm7662"
0003c810:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003c500:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003c820:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003c510:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003c830:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003c520:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003c840:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003c530:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003c850:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003c540:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003c860:·6578·6974·793a·3c2f·7468·3e3c·7464·3e68··exity:</th><td>h0003c550:·6578·6974·793a·3c2f·7468·3e3c·7464·3e68··exity:</th><td>h
0003c870:·6967·683c·2f74·643e·3c2f·7472·3e3c·7472··igh</td></tr><tr0003c560:·6967·683c·2f74·643e·3c2f·7472·3e3c·7472··igh</td></tr><tr
0003c880:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003c570:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003c890:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<0003c580:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<
0003c8a0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003c590:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c8b0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003c5a0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003c8c0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003c5b0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003c8d0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003c5c0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003c8e0:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri0003c5d0:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri
0003c8f0:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta0003c5e0:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta
0003c900:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-0003c5f0:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-
0003c910:·206e·616d·653a·2027·5365·7420·6661·6374···name:·'Set·fact0003c600:·206e·616d·653a·2027·5365·7420·6661·6374···name:·'Set·fact
0003c920:·3a20·5061·636b·6167·6520·6d61·6e61·6765··:·Package·manage0003c610:·3a20·5061·636b·6167·6520·6d61·6e61·6765··:·Package·manage
0003c930:·7220·7265·696e·7374·616c·6c20·636f·6d6d··r·reinstall·comm0003c620:·7220·7265·696e·7374·616c·6c20·636f·6d6d··r·reinstall·comm
0003c940:·616e·6427·0a20·2073·6574·5f66·6163·743a··and'.··set_fact:0003c630:·616e·6427·0a20·2073·6574·5f66·6163·743a··and'.··set_fact:
0003c950:·0a20·2020·2070·6163·6b61·6765·5f6d·616e··.····package_man0003c640:·0a20·2020·2070·6163·6b61·6765·5f6d·616e··.····package_man
0003c960:·6167·6572·5f72·6569·6e73·7461·6c6c·5f63··ager_reinstall_c0003c650:·6167·6572·5f72·6569·6e73·7461·6c6c·5f63··ager_reinstall_c
0003c970:·6d64·3a20·7975·6d20·7265·696e·7374·616c··md:·yum·reinstal0003c660:·6d64·3a20·7975·6d20·7265·696e·7374·616c··md:·yum·reinstal
0003c980:·6c20·2d79·0a20·2077·6865·6e3a·2061·6e73··l·-y.··when:·ans0003c670:·6c20·2d79·0a20·2077·6865·6e3a·2061·6e73··l·-y.··when:·ans
0003c990:·6962·6c65·5f64·6973·7472·6962·7574·696f··ible_distributio0003c680:·6962·6c65·5f64·6973·7472·6962·7574·696f··ible_distributio
0003c9a0:·6e20·696e·205b·2022·4665·646f·7261·222c··n·in·[·"Fedora",0003c690:·6e20·696e·205b·2022·4665·646f·7261·222c··n·in·[·"Fedora",
0003c9b0:·2022·5265·6448·6174·222c·2022·4365·6e74···"RedHat",·"Cent0003c6a0:·2022·5265·6448·6174·222c·2022·4365·6e74···"RedHat",·"Cent
0003c9c0:·4f53·222c·2022·4f72·6163·6c65·4c69·6e75··OS",·"OracleLinu0003c6b0:·4f53·222c·2022·4f72·6163·6c65·4c69·6e75··OS",·"OracleLinu
0003c9d0:·7822·205d·0a20·2074·6167·733a·0a20·202d··x"·].··tags:.··-0003c6c0:·7822·205d·0a20·2074·6167·733a·0a20·202d··x"·].··tags:.··-
0003c9e0:·2043·4a49·532d·352e·3130·2e34·2e31·0a20···CJIS-5.10.4.1.·0003c6d0:·2043·4a49·532d·352e·3130·2e34·2e31·0a20···CJIS-5.10.4.1.·
0003c9f0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-0003c6e0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
0003ca00:·332e·332e·380a·2020·2d20·4e49·5354·2d38··3.3.8.··-·NIST-80003c6f0:·332e·332e·380a·2020·2d20·4e49·5354·2d38··3.3.8.··-·NIST-8
0003ca10:·3030·2d31·3731·2d33·2e34·2e31·0a20·202d··00-171-3.4.1.··-0003c700:·3030·2d31·3731·2d33·2e34·2e31·0a20·202d··00-171-3.4.1.··-
0003ca20:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-0003c710:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-
0003ca30:·3928·3329·0a20·202d·204e·4953·542d·3830··9(3).··-·NIST-800003c720:·3928·3329·0a20·202d·204e·4953·542d·3830··9(3).··-·NIST-80
0003ca40:·302d·3533·2d43·4d2d·3628·6329·0a20·202d··0-53-CM-6(c).··-0003c730:·302d·3533·2d43·4d2d·3628·6329·0a20·202d··0-53-CM-6(c).··-
0003ca50:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-0003c740:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-
0003ca60:·3628·6429·0a20·202d·204e·4953·542d·3830··6(d).··-·NIST-800003c750:·3628·6429·0a20·202d·204e·4953·542d·3830··6(d).··-·NIST-80
0003ca70:·302d·3533·2d53·492d·370a·2020·2d20·4e49··0-53-SI-7.··-·NI0003c760:·302d·3533·2d53·492d·370a·2020·2d20·4e49··0-53-SI-7.··-·NI
0003ca80:·5354·2d38·3030·2d35·332d·5349·2d37·2831··ST-800-53-SI-7(10003c770:·5354·2d38·3030·2d35·332d·5349·2d37·2831··ST-800-53-SI-7(1
0003ca90:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-50003c780:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5
0003caa0:·332d·5349·2d37·2836·290a·2020·2d20·5043··3-SI-7(6).··-·PC0003c790:·332d·5349·2d37·2836·290a·2020·2d20·5043··3-SI-7(6).··-·PC
0003cab0:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·0003c7a0:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·
0003cac0:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.0003c7b0:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.
0003cad0:·352e·320a·2020·2d20·6869·6768·5f63·6f6d··5.2.··-·high_com0003c7c0:·352e·320a·2020·2d20·6869·6768·5f63·6f6d··5.2.··-·high_com
0003cae0:·706c·6578·6974·790a·2020·2d20·6869·6768··plexity.··-·high0003c7d0:·706c·6578·6974·790a·2020·2d20·6869·6768··plexity.··-·high
0003caf0:·5f73·6576·6572·6974·790a·2020·2d20·6d65··_severity.··-·me0003c7e0:·5f73·6576·6572·6974·790a·2020·2d20·6d65··_severity.··-·me
0003cb00:·6469·756d·5f64·6973·7275·7074·696f·6e0a··dium_disruption.0003c7f0:·6469·756d·5f64·6973·7275·7074·696f·6e0a··dium_disruption.
0003cb10:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne0003c800:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne
Max diff block lines reached; 17167847/17193707 bytes (99.85%) of diff not shown.
1.61 MB
html2text {}
    
Offset 71, 15 lines modifiedOffset 71, 15 lines modified
71 ····*·cpe:/o:redhat:enterprise_linux:8.771 ····*·cpe:/o:redhat:enterprise_linux:8.7
72 ····*·cpe:/o:redhat:enterprise_linux:8.872 ····*·cpe:/o:redhat:enterprise_linux:8.8
73 ····*·cpe:/o:redhat:enterprise_linux:8.973 ····*·cpe:/o:redhat:enterprise_linux:8.9
74 ····*·cpe:/o:redhat:enterprise_linux:874 ····*·cpe:/o:redhat:enterprise_linux:8
75 ····*·cpe:/o:centos:centos:875 ····*·cpe:/o:centos:centos:8
76 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*76 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
77 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8477 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
78 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)78 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
79 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*79 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
80 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s80 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
81 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e81 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
82 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l82 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
83 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n83 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
84 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g84 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
85 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s85 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 138, 27 lines modifiedOffset 138, 14 lines modified
138 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6138 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
139 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4139 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
140 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)140 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
141 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1141 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
142 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5142 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
143 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227143 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
144 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2144 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
146 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
147 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
148 if·[·-n·"$files_with_incorrect_hash"·];·then 
149 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
150 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
151 ····yum·reinstall·-y·$packages_to_reinstall 
  
152 fi 
153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
154 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
155 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
156 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
157 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
158 -·name:·'Set·fact:·Package·manager·reinstall·command'150 -·name:·'Set·fact:·Package·manager·reinstall·command'
159 ··set_fact:151 ··set_fact:
Offset 285, 14 lines modifiedOffset 272, 27 lines modified
285 ··-·PCI-DSSv4-11.5.2272 ··-·PCI-DSSv4-11.5.2
286 ··-·high_complexity273 ··-·high_complexity
287 ··-·high_severity274 ··-·high_severity
288 ··-·medium_disruption275 ··-·medium_disruption
289 ··-·no_reboot_needed276 ··-·no_reboot_needed
290 ··-·restrict_strategy277 ··-·restrict_strategy
291 ··-·rpm_verify_hashes278 ··-·rpm_verify_hashes
 279 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 280 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 281 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 282 if·[·-n·"$files_with_incorrect_hash"·];·then
 283 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 284 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 285 ····yum·reinstall·-y·$packages_to_reinstall
  
 286 fi
292 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*287 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
293 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:288 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
294 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'289 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
295 run·the·following·command·to·determine·which·package·owns·it:290 run·the·following·command·to·determine·which·package·owns·it:
296 $·rpm·-qf·FILENAME291 $·rpm·-qf·FILENAME
297 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:292 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
298 $·sudo·rpm·--setugids·PACKAGENAME293 $·sudo·rpm·--setugids·PACKAGENAME
Offset 311, 40 lines modifiedOffset 311, 14 lines modified
311 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5311 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
312 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2312 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
313 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)313 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
314 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1314 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
315 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5315 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
316 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108316 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
317 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2317 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
318 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
319 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
320 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
321 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
322 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
323 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
324 declare·-A·SETPERMS_RPM_DICT 
  
325 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
326 #·is·expected·by·the·RPM·database 
327 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
328 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
329 do 
330 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
331 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
332 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
333 done 
  
334 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
335 #·correct·values 
336 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
337 do 
338 ········rpm·--setugids·"${RPM_PACKAGE}" 
339 done 
340 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8318 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
341 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high319 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
342 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium320 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
343 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false321 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
344 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict322 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
345 -·name:·Read·list·of·files·with·incorrect·ownership323 -·name:·Read·list·of·files·with·incorrect·ownership
346 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev324 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 419, 14 lines modifiedOffset 393, 40 lines modified
419 ··-·PCI-DSSv4-11.5.2393 ··-·PCI-DSSv4-11.5.2
420 ··-·high_complexity394 ··-·high_complexity
421 ··-·high_severity395 ··-·high_severity
422 ··-·medium_disruption396 ··-·medium_disruption
423 ··-·no_reboot_needed397 ··-·no_reboot_needed
424 ··-·restrict_strategy398 ··-·restrict_strategy
425 ··-·rpm_verify_ownership399 ··-·rpm_verify_ownership
 400 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 401 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 402 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 403 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 404 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 405 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 1679922/1687534 bytes (99.55%) of diff not shown.
29.9 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-stig.html
    
Offset 14560, 15 lines modifiedOffset 14560, 15 lines modified
00038df0:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current00038df0:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current
00038e00:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron00038e00:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron
00038e10:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong00038e10:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong
00038e20:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st00038e20:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st
00038e30:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro00038e30:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro
00038e40:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············00038e40:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············
00038e50:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·200038e50:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·2
00038e60:·3032·362d·3031·2d30·3829·0a20·2020·2020··026-01-08).·····00038e60:·3032·342d·3132·2d30·3729·0a20·2020·2020··024-12-07).·····
00038e70:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>00038e70:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>
00038e80:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T00038e80:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T
00038e90:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents00038e90:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents
00038ea0:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·00038ea0:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·
00038eb0:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org00038eb0:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org
00038ec0:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont00038ec0:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont
00038ed0:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system00038ed0:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system
Offset 15358, 235 lines modifiedOffset 15358, 235 lines modified
0003bfd0:·6574·3d22·2369·646d·3830·3032·2220·7461··et="#idm8002"·ta0003bfd0:·6574·3d22·2369·646d·3830·3032·2220·7461··et="#idm8002"·ta
0003bfe0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003bfe0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003bff0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003bff0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003c000:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003c000:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003c010:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003c010:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003c020:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003c020:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003c030:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003c030:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003c040:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.0003c040:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet
0003c050:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003c050:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003c060:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003c060:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003c070:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003c070:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003c080:·643d·2269·646d·3830·3032·223e·3c74·6162··d="idm8002"><tab0003c080:·2069·643d·2269·646d·3830·3032·223e·3c74···id="idm8002"><t
0003c090:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003c090:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003c0a0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003c0a0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003c0b0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003c0b0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003c0c0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003c0c0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003c0d0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003c0d0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003c0e0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003c0e0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003c0f0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003c0f0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c100:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003c100:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003c110:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003c110:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003c120:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<0003c120:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
0003c130:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003c130:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003c140:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003c140:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c150:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003c150:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003c160:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr0003c160:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
0003c170:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003c170:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003c180:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·-
 0003c190:·2d61·6464·3d61·6964·650a·3c2f·636f·6465··-add=aide.</code
 0003c1a0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 0003c1b0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 0003c1c0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0003c180:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst 
0003c190:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class· 
0003c1a0:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.· 
0003c1b0:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide 
0003c1c0:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=& 
0003c1d0:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed', 
0003c1e0:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></ 
0003c1f0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003c200:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003c210:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003c220:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003c230:·2d74·6172·6765·743d·2223·6964·6d38·3030··-target="#idm800 
0003c240:·3322·2074·6162·696e·6465·783d·2230·2220··3"·tabindex="0"· 
0003c250:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003c260:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003c270:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003c280:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003c290:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003c2a0:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
0003c2b0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003c2c0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003c2d0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003c2e0:·2220·6964·3d22·6964·6d38·3030·3322·3e3c··"·id="idm8003">< 
0003c2f0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003c300:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003c310:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003c320:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003c330:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003c340:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003c350:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003c360:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003c370:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003c380:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003c390:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003c3a0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003c3b0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003c3c0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003c3d0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003c3e0:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia 
0003c3f0:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab 
0003c400:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa 
0003c410:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if· 
0003c420:·5b20·2120·2d66·202f·2e64·6f63·6b65·7265··[·!·-f·/.dockere 
0003c430:·6e76·205d·2026·616d·703b·2661·6d70·3b20··nv·]·&amp;&amp;· 
0003c440:·5b20·2120·2d66·202f·7275·6e2f·2e63·6f6e··[·!·-f·/run/.con 
0003c450:·7461·696e·6572·656e·7620·5d3b·2074·6865··tainerenv·];·the 
0003c460:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·- 
0003c470:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;· 
0003c480:·7468·656e·0a20·2020·2079·756d·2069·6e73··then.····yum·ins 
0003c490:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f 
0003c4a0:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt; 
0003c4b0:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem 
0003c4c0:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not· 
0003c4d0:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth 
0003c4e0:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi 
0003c4f0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003c500:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003c510:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003c520:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003c530:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003c540:·743d·2223·6964·6d38·3030·3422·2074·6162··t="#idm8004"·tab 
0003c550:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003c560:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003c570:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003c580:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003c590:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003c5a0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A 
0003c5b0:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
0003c5c0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003c5d0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003c5e0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003c1d0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
0003c5f0:·643d·2269·646d·3830·3034·223e·3c74·6162··d="idm8004"><tab 
0003c600:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003c610:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003c620:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003c630:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003c640:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003c650:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003c660:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
Max diff block lines reached; 28776007/28808215 bytes (99.89%) of diff not shown.
2.41 MB
html2text {}
Max HTML report size reached
29.7 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-stig_gui.html
    
Offset 14584, 15 lines modifiedOffset 14584, 15 lines modified
00038f70:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur00038f70:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur
00038f80:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s00038f80:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s
00038f90:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st00038f90:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st
00038fa0:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li00038fa0:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li
00038fb0:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</00038fb0:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</
00038fc0:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········00038fc0:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········
00038fd0:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·00038fd0:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·
00038fe0:·6f66·2032·3032·362d·3031·2d30·3829·0a20··of·2026-01-08).·00038fe0:·6f66·2032·3032·342d·3132·2d30·3729·0a20··of·2024-12-07).·
00038ff0:·2020·2020·2020·2020·2020·2020·2020·203c·················<00038ff0:·2020·2020·2020·2020·2020·2020·2020·203c·················<
00039000:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><00039000:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><
00039010:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont00039010:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont
00039020:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li00039020:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li
00039030:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf00039030:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf
00039040:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.00039040:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.
00039050:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy00039050:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy
Offset 15377, 235 lines modifiedOffset 15377, 235 lines modified
0003c100:·6765·743d·2223·6964·6d38·3030·3222·2074··get="#idm8002"·t0003c100:·6765·743d·2223·6964·6d38·3030·3222·2074··get="#idm8002"·t
0003c110:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003c110:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003c120:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003c120:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003c130:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003c130:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003c140:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003c140:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003c150:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003c150:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003c160:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003c160:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003c170:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·0003c170:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe
0003c180:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003c180:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003c190:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003c190:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003c1a0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003c1a0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003c1b0:·6964·3d22·6964·6d38·3030·3222·3e3c·7461··id="idm8002"><ta0003c1b0:·2220·6964·3d22·6964·6d38·3030·3222·3e3c··"·id="idm8002"><
0003c1c0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0003c1c0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003c1d0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0003c1d0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003c1e0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0003c1e0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003c1f0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0003c1f0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003c200:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003c200:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003c210:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003c210:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003c220:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003c220:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003c230:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>0003c230:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003c240:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003c240:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003c250:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:0003c250:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
0003c260:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</0003c260:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
0003c270:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003c270:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003c280:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003c280:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
0003c290:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t0003c290:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
0003c2a0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003c2a0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003c2b0:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 0003c2c0:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod
 0003c2d0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003c2e0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003c2f0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
0003c2b0:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins 
0003c2c0:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class 
0003c2d0:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{. 
0003c2e0:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid 
0003c2f0:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·= 
0003c300:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed' 
0003c310:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code>< 
0003c320:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003c330:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003c340:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003c350:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003c360:·612d·7461·7267·6574·3d22·2369·646d·3830··a-target="#idm80 
0003c370:·3033·2220·7461·6269·6e64·6578·3d22·3022··03"·tabindex="0" 
0003c380:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003c390:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003c3a0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003c3b0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003c3c0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003c3d0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
0003c3e0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
0003c3f0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003c400:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003c410:·6522·2069·643d·2269·646d·3830·3033·223e··e"·id="idm8003"> 
0003c420:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003c430:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003c440:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003c450:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003c460:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003c470:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003c480:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003c490:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003c4a0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003c4b0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003c4c0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0003c4d0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
0003c4e0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0003c4f0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0003c500:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003c510:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi 
0003c520:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica 
0003c530:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert 
0003c540:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if 
0003c550:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker 
0003c560:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp; 
0003c570:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co 
0003c580:·6e74·6169·6e65·7265·6e76·205d·3b20·7468··ntainerenv·];·th 
0003c590:·656e·0a0a·6966·2021·2072·706d·202d·7120··en..if·!·rpm·-q· 
0003c5a0:·2d2d·7175·6965·7420·2261·6964·6522·203b··--quiet·"aide"·; 
0003c5b0:·2074·6865·6e0a·2020·2020·7975·6d20·696e···then.····yum·in 
0003c5c0:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide". 
0003c5d0:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt 
0003c5e0:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re 
0003c5f0:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not 
0003c600:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not 
0003c610:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f 
0003c620:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre>< 
0003c630:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003c640:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003c650:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003c660:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003c670:·6574·3d22·2369·646d·3830·3034·2220·7461··et="#idm8004"·ta 
0003c680:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003c690:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003c6a0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003c6b0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003c6c0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003c6d0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003c6e0:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet· 
0003c6f0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003c700:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003c710:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003c300:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
0003c720:·6964·3d22·6964·6d38·3030·3422·3e3c·7461··id="idm8004"><ta 
0003c730:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003c740:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003c750:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003c760:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003c770:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003c780:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003c790:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
Max diff block lines reached; 28628335/28660543 bytes (99.89%) of diff not shown.
2.39 MB
html2text {}
Max HTML report size reached
21.5 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-anssi_bp28_enhanced.html
    
Offset 14435, 15 lines modifiedOffset 14435, 15 lines modified
00038620:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr00038620:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr
00038630:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st00038630:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st
00038640:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str00038640:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str
00038650:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>00038650:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>
00038660:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s00038660:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s
00038670:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········00038670:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········
00038680:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o00038680:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o
00038690:·6620·3230·3236·2d30·312d·3038·290a·2020··f·2026-01-08).··00038690:·6620·3230·3234·2d31·322d·3037·290a·2020··f·2024-12-07).··
000386a0:·2020·2020·2020·2020·2020·2020·2020·3c2f················</000386a0:·2020·2020·2020·2020·2020·2020·2020·3c2f················</
000386b0:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h000386b0:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h
000386c0:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte000386c0:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte
000386d0:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>000386d0:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>
000386e0:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_000386e0:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_
000386f0:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c000386f0:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c
00038700:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys00038700:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys
Offset 15180, 234 lines modifiedOffset 15180, 234 lines modified
0003b4b0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b4b0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003b4c0:·646d·3732·3733·2220·7461·6269·6e64·6578··dm7273"·tabindex0003b4c0:·646d·3732·3733·2220·7461·6269·6e64·6578··dm7273"·tabindex
0003b4d0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b4d0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b4e0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b4e0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b4f0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b4f0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b500:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b500:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b510:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b510:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003b520:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet0003b520:·6d65·6469·6174·696f·6e20·416e·6163·6f6e··mediation·Anacon
0003b530:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003b530:·6461·2073·6e69·7070·6574·20e2·87b2·3c2f··da·snippet·...</
0003b540:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003b540:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003b550:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003b550:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003b560:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003b560:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003b570:·3732·3733·223e·3c74·6162·6c65·2063·6c61··7273"><table·cla0003b570:·646d·3732·3733·223e·3c74·6162·6c65·2063··dm7273"><table·c
0003b580:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003b580:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003b590:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003b590:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003b5a0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003b5a0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003b5b0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003b5b0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003b5c0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003b5c0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003b5d0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003b5d0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003b5e0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003b5e0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003b5f0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003b5f0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003b600:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003b600:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003b610:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t0003b610:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
0003b620:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr0003b620:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
0003b630:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0003b630:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
0003b640:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl0003b640:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003b650:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0003b650:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
0003b660:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in0003b660:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003b670:·0a70·6163·6b61·6765·202d·2d61·6464·3d61··.package·--add=a
0003b670:·636c·7564·6520·696e·7374·616c·6c5f·6169··clude·install_ai 
0003b680:·6465·0a0a·636c·6173·7320·696e·7374·616c··de..class·instal 
0003b690:·6c5f·6169·6465·207b·0a20·2070·6163·6b61··l_aide·{.··packa 
0003b6a0:·6765·207b·2027·6169·6465·273a·0a20·2020··ge·{·'aide':.··· 
0003b6b0:·2065·6e73·7572·6520·3d26·6774·3b20·2769···ensure·=&gt;·'i 
0003b6c0:·6e73·7461·6c6c·6564·272c·0a20·207d·0a7d··nstalled',.··}.} 
0003b6d0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003b6e0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b6f0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b700:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b710:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b720:·743d·2223·6964·6d37·3237·3422·2074·6162··t="#idm7274"·tab 
0003b730:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b740:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b750:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b760:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b770:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b780:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
0003b790:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
0003b7a0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003b7b0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003b7c0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003b7d0:·6964·6d37·3237·3422·3e3c·7461·626c·6520··idm7274"><table· 
0003b7e0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003b7f0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003b800:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003b810:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003b820:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003b830:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b840:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003b850:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003b860:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003b870:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003b880:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003b890:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003b8a0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
0003b8b0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
0003b8c0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
0003b8d0:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i 
0003b8e0:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl 
0003b8f0:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla 
0003b900:·7466·6f72·6d73·0a69·6620·5b20·2120·2d66··tforms.if·[·!·-f 
0003b910:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·& 
0003b920:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f 
0003b930:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container 
0003b940:·656e·7620·5d3b·2074·6865·6e0a·0a69·6620··env·];·then..if· 
0003b950:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet 
0003b960:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.· 
0003b970:·2020·2064·6e66·2069·6e73·7461·6c6c·202d·····dnf·install·- 
0003b980:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els 
0003b990:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2 
0003b9a0:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati 
0003b9b0:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic 
0003b9c0:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa 
0003b9d0:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod 
0003b9e0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003b9f0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003ba00:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003ba10:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003ba20:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003ba30:·6d37·3237·3522·2074·6162·696e·6465·783d··m7275"·tabindex= 
0003ba40:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003ba50:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003ba60:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003ba70:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003ba80:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003ba90:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible 
0003baa0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003bab0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003bac0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003bad0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003bae0:·3732·3735·223e·3c74·6162·6c65·2063·6c61··7275"><table·cla 
0003baf0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003bb00:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003bb10:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003bb20:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003bb30:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003bb40:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003bb50:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003bb60:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003bb70:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003bb80:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
Max diff block lines reached; 20625649/20657719 bytes (99.84%) of diff not shown.
1.85 MB
html2text {}
Max HTML report size reached
22.0 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-anssi_bp28_high.html
    
Offset 14434, 15 lines modifiedOffset 14434, 15 lines modified
00038610:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr00038610:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr
00038620:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st00038620:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st
00038630:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str00038630:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str
00038640:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>00038640:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>
00038650:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s00038650:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s
00038660:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········00038660:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········
00038670:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o00038670:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o
00038680:·6620·3230·3236·2d30·312d·3038·290a·2020··f·2026-01-08).··00038680:·6620·3230·3234·2d31·322d·3037·290a·2020··f·2024-12-07).··
00038690:·2020·2020·2020·2020·2020·2020·2020·3c2f················</00038690:·2020·2020·2020·2020·2020·2020·2020·3c2f················</
000386a0:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h000386a0:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h
000386b0:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte000386b0:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte
000386c0:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>000386c0:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>
000386d0:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_000386d0:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_
000386e0:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c000386e0:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c
000386f0:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys000386f0:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys
Offset 15185, 234 lines modifiedOffset 15185, 234 lines modified
0003b500:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b500:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003b510:·2223·6964·6d37·3237·3322·2074·6162·696e··"#idm7273"·tabin0003b510:·2223·6964·6d37·3237·3322·2074·6162·696e··"#idm7273"·tabin
0003b520:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b520:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b530:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b530:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b540:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b540:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b550:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b550:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b560:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b560:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b570:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup0003b570:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana
0003b580:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<0003b580:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..
0003b590:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003b590:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003b5a0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003b5a0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003b5b0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003b5b0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003b5c0:·6964·6d37·3237·3322·3e3c·7461·626c·6520··idm7273"><table·0003b5c0:·3d22·6964·6d37·3237·3322·3e3c·7461·626c··="idm7273"><tabl
0003b5d0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003b5d0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0003b5e0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003b5e0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0003b5f0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003b5f0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0003b600:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003b600:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0003b610:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003b610:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003b620:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003b620:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003b630:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003b630:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003b640:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003b640:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003b650:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003b650:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003b660:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th0003b660:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
0003b670:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><0003b670:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
0003b680:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003b680:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
0003b690:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003b690:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0003b6a0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003b6a0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
0003b6b0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003b6b0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003b6c0:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad
0003b6c0:·3e69·6e63·6c75·6465·2069·6e73·7461·6c6c··>include·install 
0003b6d0:·5f61·6964·650a·0a63·6c61·7373·2069·6e73··_aide..class·ins 
0003b6e0:·7461·6c6c·5f61·6964·6520·7b0a·2020·7061··tall_aide·{.··pa 
0003b6f0:·636b·6167·6520·7b20·2761·6964·6527·3a0a··ckage·{·'aide':. 
0003b700:·2020·2020·656e·7375·7265·203d·2667·743b······ensure·=&gt; 
0003b710:·2027·696e·7374·616c·6c65·6427·2c0a·2020···'installed',.·· 
0003b720:·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70·7265··}.}.</code></pre 
0003b730:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003b740:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003b750:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003b760:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003b770:·7267·6574·3d22·2369·646d·3732·3734·2220··rget="#idm7274"· 
0003b780:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003b790:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003b7a0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003b7b0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003b7c0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003b7d0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003b7e0:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
0003b7f0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b800:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b810:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003b820:·643d·2269·646d·3732·3734·223e·3c74·6162··d="idm7274"><tab 
0003b830:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003b840:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003b850:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003b860:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003b870:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003b880:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b890:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003b8a0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003b8b0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b8c0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003b8d0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003b8e0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003b8f0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003b900:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003b910:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003b920:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio 
0003b930:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable· 
0003b940:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain· 
0003b950:·706c·6174·666f·726d·730a·6966·205b·2021··platforms.if·[·! 
0003b960:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv· 
0003b970:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·! 
0003b980:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai 
0003b990:·6e65·7265·6e76·205d·3b20·7468·656e·0a0a··nerenv·];·then.. 
0003b9a0:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu 
0003b9b0:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the 
0003b9c0:·6e0a·2020·2020·646e·6620·696e·7374·616c··n.····dnf·instal 
0003b9d0:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi.. 
0003b9e0:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am 
0003b9f0:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi 
0003ba00:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app 
0003ba10:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing 
0003ba20:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</ 
0003ba30:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003ba40:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003ba50:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003ba60:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003ba70:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003ba80:·2369·646d·3732·3735·2220·7461·6269·6e64··#idm7275"·tabind 
0003ba90:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003baa0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003bab0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003bac0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003bad0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003bae0:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi 
0003baf0:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...< 
0003bb00:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003bb10:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003bb20:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003bb30:·6964·6d37·3237·3522·3e3c·7461·626c·6520··idm7275"><table· 
0003bb40:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003bb50:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003bb60:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003bb70:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003bb80:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003bb90:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003bba0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003bbb0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003bbc0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003bbd0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
Max diff block lines reached; 21042235/21074305 bytes (99.85%) of diff not shown.
1.92 MB
html2text {}
Max HTML report size reached
9.64 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-anssi_bp28_intermediary.html
    
Offset 14436, 15 lines modifiedOffset 14436, 15 lines modified
00038630:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr00038630:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr
00038640:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st00038640:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st
00038650:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str00038650:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str
00038660:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>00038660:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>
00038670:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s00038670:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s
00038680:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········00038680:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········
00038690:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o00038690:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o
000386a0:·6620·3230·3236·2d30·312d·3038·290a·2020··f·2026-01-08).··000386a0:·6620·3230·3234·2d31·322d·3037·290a·2020··f·2024-12-07).··
000386b0:·2020·2020·2020·2020·2020·2020·2020·3c2f················</000386b0:·2020·2020·2020·2020·2020·2020·2020·3c2f················</
000386c0:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h000386c0:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h
000386d0:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte000386d0:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte
000386e0:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>000386e0:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>
000386f0:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_000386f0:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_
00038700:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c00038700:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c
00038710:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys00038710:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys
Offset 15176, 234 lines modifiedOffset 15176, 234 lines modified
0003b470:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm70003b470:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7
0003b480:·3237·3322·2074·6162·696e·6465·783d·2230··273"·tabindex="00003b480:·3237·3322·2074·6162·696e·6465·783d·2230··273"·tabindex="0
0003b490:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003b490:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003b4a0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003b4a0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003b4b0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003b4b0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003b4c0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003b4c0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003b4d0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003b4d0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003b4e0:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn0003b4e0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·
0003b4f0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003b4f0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003b500:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003b500:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003b510:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003b510:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003b520:·6170·7365·2220·6964·3d22·6964·6d37·3237··apse"·id="idm7270003b520:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7
0003b530:·3322·3e3c·7461·626c·6520·636c·6173·733d··3"><table·class=0003b530:·3237·3322·3e3c·7461·626c·6520·636c·6173··273"><table·clas
0003b540:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003b540:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003b550:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003b550:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003b560:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003b560:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003b570:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003b570:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003b580:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003b580:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003b590:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003b590:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003b5a0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003b5a0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003b5b0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003b5b0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003b5c0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R0003b5c0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b5d0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f0003b5d0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003b5e0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t0003b5e0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003b5f0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<0003b5f0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003b600:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</0003b600:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
0003b610:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>0003b610:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003b620:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu 
0003b630:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide. 
0003b640:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a 
0003b650:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package· 
0003b660:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en 
0003b670:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst 
0003b680:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</ 
0003b690:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003b6a0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003b6b0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003b6c0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003b6d0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003b6e0:·2369·646d·3732·3734·2220·7461·6269·6e64··#idm7274"·tabind 
0003b6f0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003b700:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003b710:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003b720:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003b730:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003b740:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel 
0003b750:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a> 
0003b760:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b770:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b780:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b790:·3732·3734·223e·3c74·6162·6c65·2063·6c61··7274"><table·cla 
0003b7a0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003b7b0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003b7c0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003b7d0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003b7e0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003b7f0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b800:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003b810:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003b820:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b830:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003b840:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003b850:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003b860:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003b870:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003b880:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#· 
0003b890:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a 
0003b8a0:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i 
0003b8b0:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo 
0003b8c0:·726d·730a·6966·205b·2021·202d·6620·2f2e··rms.if·[·!·-f·/. 
0003b8d0:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp 
0003b8e0:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r 
0003b8f0:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv 
0003b900:·205d·3b20·7468·656e·0a0a·6966·2021·2072···];·then..if·!·r 
0003b910:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a 
0003b920:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.···· 
0003b930:·646e·6620·696e·7374·616c·6c20·2d79·2022··dnf·install·-y·" 
0003b940:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.· 
0003b950:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec 
0003b960:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation· 
0003b970:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl 
0003b980:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d 
0003b990:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code>< 
0003b9a0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003b9b0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003b9c0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003b9d0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003b9e0:·612d·7461·7267·6574·3d22·2369·646d·3732··a-target="#idm72 
0003b9f0:·3735·2220·7461·6269·6e64·6578·3d22·3022··75"·tabindex="0" 
0003ba00:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003ba10:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003ba20:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003ba30:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003ba40:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003ba50:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn 
0003ba60:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003ba70:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003ba80:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003ba90:·6170·7365·2220·6964·3d22·6964·6d37·3237··apse"·id="idm727 
0003baa0:·3522·3e3c·7461·626c·6520·636c·6173·733d··5"><table·class= 
0003bab0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003bac0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003bad0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003bae0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003baf0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003bb00:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003bb10:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003bb20:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003bb30:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003bb40:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003bb50:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
Max diff block lines reached; 9021978/9054048 bytes (99.65%) of diff not shown.
1.01 MB
html2text {}
    
Offset 64, 15 lines modifiedOffset 64, 15 lines modified
64 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·ANSSI-BP-028·(intermediary)64 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·ANSSI-BP-028·(intermediary)
65 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_intermediary65 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_intermediary
66 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*66 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
67 ····*·cpe:/o:redhat:enterprise_linux:1067 ····*·cpe:/o:redhat:enterprise_linux:10
68 ····*·cpe:/o:centos:centos:1068 ····*·cpe:/o:centos:centos:10
69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
70 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8470 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
73 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s73 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
74 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e74 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
75 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l75 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
76 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n76 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
77 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s77 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
78 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s78 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 135, 41 lines modifiedOffset 135, 45 lines modified
135 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)135 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
136 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3136 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
137 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5137 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
138 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199138 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
139 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79139 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
140 ············_\x8c_\x8i_\x8s············6.1.1140 ············_\x8c_\x8i_\x8s············6.1.1
141 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2141 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
 142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 147 package·--add=aide
142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low149 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low150 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false151 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable152 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
147 include·install_aide153 include·install_aide
  
148 class·install_aide·{154 class·install_aide·{
149 ··package·{·'aide':155 ··package·{·'aide':
150 ····ensure·=>·'installed',156 ····ensure·=>·'installed',
151 ··}157 ··}
152 }158 }
 159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 160 [[packages]]
 161 name·=·"aide"
 162 version·=·"*"
153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
154 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
155 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
156 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
157 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
158 #·Remediation·is·applicable·only·in·certain·platforms 
159 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
 168 package·install·aide
160 if·!·rpm·-q·--quiet·"aide"·;·then 
161 ····dnf·install·-y·"aide" 
162 fi 
  
163 else 
164 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
165 fi 
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
171 -·name:·Ensure·aide·is·installed174 -·name:·Ensure·aide·is·installed
172 ··package:175 ··package:
Offset 183, 33 lines modifiedOffset 187, 29 lines modified
183 ··-·PCI-DSSv4-11.5.2187 ··-·PCI-DSSv4-11.5.2
184 ··-·enable_strategy188 ··-·enable_strategy
185 ··-·low_complexity189 ··-·low_complexity
186 ··-·low_disruption190 ··-·low_disruption
187 ··-·medium_severity191 ··-·medium_severity
188 ··-·no_reboot_needed192 ··-·no_reboot_needed
189 ··-·package_aide_installed193 ··-·package_aide_installed
190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
191 [[packages]] 
192 name·=·"aide" 
193 version·=·"*" 
194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 199 #·Remediation·is·applicable·only·in·certain·platforms
 200 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 201 if·!·rpm·-q·--quiet·"aide"·;·then
 202 ····dnf·install·-y·"aide"
 203 fi
199 package·install·aide 
200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
205 package·--add=aide204 else
 205 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 206 fi
206 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*207 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
207 Run·the·following·command·to·generate·a·new·database:208 Run·the·following·command·to·generate·a·new·database:
208 $·sudo·/usr/sbin/aide·--init209 $·sudo·/usr/sbin/aide·--init
209 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the210 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
210 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these211 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
211 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their212 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
212 integrity.·The·newly-generated·database·can·be·installed·as·follows:213 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 233, 28 lines modifiedOffset 233, 14 lines modified
233 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)233 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
234 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3234 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
235 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5235 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
236 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199236 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
237 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79237 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
238 ············_\x8c_\x8i_\x8s············6.1.1238 ············_\x8c_\x8i_\x8s············6.1.1
239 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2239 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
240 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
241 #·Remediation·is·applicable·only·in·certain·platforms 
242 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
243 if·!·rpm·-q·--quiet·"aide"·;·then 
244 ····dnf·install·-y·"aide" 
245 fi 
  
Max diff block lines reached; 1050530/1056477 bytes (99.44%) of diff not shown.
3.04 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-anssi_bp28_minimal.html
    
Offset 14435, 15 lines modifiedOffset 14435, 15 lines modified
00038620:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·00038620:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·
00038630:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong00038630:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong
00038640:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>00038640:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>
00038650:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str00038650:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str
00038660:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron00038660:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron
00038670:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············00038670:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············
00038680:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·2000038680:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·20
00038690:·3236·2d30·312d·3038·290a·2020·2020·2020··26-01-08).······00038690:·3234·2d31·322d·3037·290a·2020·2020·2020··24-12-07).······
000386a0:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><000386a0:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><
000386b0:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta000386b0:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta
000386c0:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<000386c0:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<
000386d0:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h000386d0:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h
000386e0:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.000386e0:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.
000386f0:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte000386f0:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte
00038700:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"00038700:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"
Offset 14854, 217 lines modifiedOffset 14854, 217 lines modified
0003a050:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003a050:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003a060:·3d22·2369·646d·3130·3632·3222·2074·6162··="#idm10622"·tab0003a060:·3d22·2369·646d·3130·3632·3222·2074·6162··="#idm10622"·tab
0003a070:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003a070:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003a080:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003a080:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003a090:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003a090:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003a0a0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003a0a0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003a0b0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003a0b0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003a0c0:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P0003a0c0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
0003a0d0:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..0003a0d0:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·
0003a0e0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003a0e0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003a0f0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003a0f0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003a100:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003a100:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003a110:·3d22·6964·6d31·3036·3232·223e·3c74·6162··="idm10622"><tab0003a110:·6964·3d22·6964·6d31·3036·3232·223e·3c74··id="idm10622"><t
0003a120:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003a120:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003a130:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003a130:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003a140:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003a140:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003a150:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003a150:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003a160:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003a160:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003a170:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003a170:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003a180:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003a180:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003a190:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003a190:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003a1a0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003a1a0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003a1b0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<0003a1b0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
0003a1c0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003a1c0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003a1d0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003a1d0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003a1e0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003a1e0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003a1f0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr0003a1f0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
0003a200:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003a200:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003a210:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·-
 0003a220:·2d61·6464·3d64·6e66·2d61·7574·6f6d·6174··-add=dnf-automat
 0003a230:·6963·0a3c·2f63·6f64·653e·3c2f·7072·653e··ic.</code></pre>
 0003a240:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0003a250:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0003a260:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0003a270:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 0003a280:·6765·743d·2223·6964·6d31·3036·3233·2220··get="#idm10623"·
 0003a290:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0003a2a0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 0003a2b0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 0003a2c0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 0003a2d0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 0003a2e0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003a2f0:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
0003a210:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst 
0003a220:·616c·6c5f·646e·662d·6175·746f·6d61·7469··all_dnf-automati 
0003a230:·630a·0a63·6c61·7373·2069·6e73·7461·6c6c··c..class·install 
0003a240:·5f64·6e66·2d61·7574·6f6d·6174·6963·207b··_dnf-automatic·{ 
0003a250:·0a20·2070·6163·6b61·6765·207b·2027·646e··.··package·{·'dn 
0003a260:·662d·6175·746f·6d61·7469·6327·3a0a·2020··f-automatic':.·· 
0003a270:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·' 
0003a280:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}. 
0003a290:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre>< 
0003a2a0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003a2b0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003a2c0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003a2d0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003a2e0:·6574·3d22·2369·646d·3130·3632·3322·2074··et="#idm10623"·t 
0003a2f0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003a300:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003a310:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003a320:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003a330:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003a340:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003a350:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
0003a360:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003a370:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003a380:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003a390:·3d22·6964·6d31·3036·3233·223e·3c74·6162··="idm10623"><tab 
0003a3a0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003a3b0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003a3c0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003a3d0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003a3e0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003a3f0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003a400:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003a410:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003a420:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003a430:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003a440:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003a450:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003a460:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003a470:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003a480:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003a490:·6f64·653e·0a69·6620·2120·7270·6d20·2d71··ode>.if·!·rpm·-q 
0003a4a0:·202d·2d71·7569·6574·2022·646e·662d·6175···--quiet·"dnf-au 
0003a4b0:·746f·6d61·7469·6322·203b·2074·6865·6e0a··tomatic"·;·then. 
0003a4c0:·2020·2020·646e·6620·696e·7374·616c·6c20······dnf·install· 
0003a4d0:·2d79·2022·646e·662d·6175·746f·6d61·7469··-y·"dnf-automati 
0003a4e0:·6322·0a66·690a·3c2f·636f·6465·3e3c·2f70··c".fi.</code></p 
0003a4f0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003a500:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003a510:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003a520:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003a530:·7461·7267·6574·3d22·2369·646d·3130·3632··target="#idm1062 
0003a540:·3422·2074·6162·696e·6465·783d·2230·2220··4"·tabindex="0"· 
0003a550:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003a560:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003a570:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003a580:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003a590:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003a5a0:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni 
0003a5b0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003a5c0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003a5d0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003a5e0:·7073·6522·2069·643d·2269·646d·3130·3632··pse"·id="idm1062 
0003a5f0:·3422·3e3c·7461·626c·6520·636c·6173·733d··4"><table·class= 
0003a600:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003a610:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003a620:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003a630:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003a640:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
Max diff block lines reached; 2931952/2961676 bytes (99.00%) of diff not shown.
218 KB
html2text {}
    
Offset 64, 15 lines modifiedOffset 64, 15 lines modified
64 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·ANSSI-BP-028·(minimal)64 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·ANSSI-BP-028·(minimal)
65 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_minimal65 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_minimal
66 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*66 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
67 ····*·cpe:/o:redhat:enterprise_linux:1067 ····*·cpe:/o:redhat:enterprise_linux:10
68 ····*·cpe:/o:centos:centos:1068 ····*·cpe:/o:centos:centos:10
69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
70 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8470 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
73 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s73 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
74 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e74 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
75 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l75 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
76 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s76 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
77 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s77 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
78 ·········1.·_\x8D_\x8H_\x8C_\x8P78 ·········1.·_\x8D_\x8H_\x8C_\x8P
Offset 101, 35 lines modifiedOffset 101, 45 lines modified
101 $·sudo·dnf·install·dnf-automatic101 $·sudo·dnf·install·dnf-automatic
102 Rationale:··dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade102 Rationale:··dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade
103 ············suitable·for·automatic,·regular·execution.103 ············suitable·for·automatic,·regular·execution.
104 Severity: ··medium104 Severity: ··medium
105 Rule·ID:····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed105 Rule·ID:····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
106 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080106 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
107 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61107 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
 108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 109 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 110 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 111 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 112 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 113 package·--add=dnf-automatic
108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
109 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low115 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
110 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low116 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
111 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false117 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
112 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable118 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
113 include·install_dnf-automatic119 include·install_dnf-automatic
  
114 class·install_dnf-automatic·{120 class·install_dnf-automatic·{
115 ··package·{·'dnf-automatic':121 ··package·{·'dnf-automatic':
116 ····ensure·=>·'installed',122 ····ensure·=>·'installed',
117 ··}123 ··}
118 }124 }
 125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 126 [[packages]]
 127 name·=·"dnf-automatic"
 128 version·=·"*"
119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
120 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
121 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
122 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
123 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 134 package·install·dnf-automatic
124 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then 
125 ····dnf·install·-y·"dnf-automatic" 
126 fi 
127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
132 -·name:·Ensure·dnf-automatic·is·installed140 -·name:·Ensure·dnf-automatic·is·installed
133 ··package:141 ··package:
Offset 138, 33 lines modifiedOffset 148, 23 lines modified
138 ··tags:148 ··tags:
139 ··-·enable_strategy149 ··-·enable_strategy
140 ··-·low_complexity150 ··-·low_complexity
141 ··-·low_disruption151 ··-·low_disruption
142 ··-·medium_severity152 ··-·medium_severity
143 ··-·no_reboot_needed153 ··-·no_reboot_needed
144 ··-·package_dnf-automatic_installed154 ··-·package_dnf-automatic_installed
145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
146 [[packages]] 
147 name·=·"dnf-automatic" 
148 version·=·"*" 
149 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8155 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
150 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
151 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
152 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
153 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
154 package·install·dnf-automatic 
155 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
156 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low156 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
157 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low157 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
158 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false158 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
159 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable159 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
160 package·--add=dnf-automatic160 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
 161 ····dnf·install·-y·"dnf-automatic"
 162 fi
161 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*163 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
162 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed164 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
163 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/165 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
164 automatic.conf.166 automatic.conf.
165 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation167 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
166 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and168 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
167 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in169 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 174, 14 lines modifiedOffset 174, 36 lines modified
174 Severity: ··medium174 Severity: ··medium
175 Rule·ID:····xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates175 Rule·ID:····xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates
176 ············_\x8i_\x8s_\x8m····0940,·1144,·1467,·1472,·1483,·1493,·1494,·1495176 ············_\x8i_\x8s_\x8m····0940,·1144,·1467,·1472,·1483,·1493,·1494,·1495
177 ············_\x8n_\x8i_\x8s_\x8t···SI-2(5),·CM-6(a),·SI-2(c)177 ············_\x8n_\x8i_\x8s_\x8t···SI-2(5),·CM-6(a),·SI-2(c)
178 References:·_\x8o_\x8s_\x8p_\x8p···FMT_SMF_EXT.1178 References:·_\x8o_\x8s_\x8p_\x8p···FMT_SMF_EXT.1
179 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080179 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
180 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61180 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
 181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···unknown
 186 -·name:·Configure·dnf-automatic·to·Install·Available·Updates·Automatically
 187 ··ini_file:
 188 ····dest:·/etc/dnf/automatic.conf
 189 ····section:·commands
 190 ····option:·apply_updates
 191 ····value:·'yes'
 192 ····create:·true
 193 ··tags:
 194 ··-·NIST-800-53-CM-6(a)
 195 ··-·NIST-800-53-SI-2(5)
 196 ··-·NIST-800-53-SI-2(c)
 197 ··-·dnf-automatic_apply_updates
 198 ··-·low_complexity
 199 ··-·medium_disruption
Max diff block lines reached; 217652/223450 bytes (97.41%) of diff not shown.
24.8 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-cis.html
    
Offset 14406, 15 lines modifiedOffset 14406, 15 lines modified
00038450:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00038450:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00038460:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00038460:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00038470:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s00038470:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00038480:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00038480:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00038490:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00038490:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
000384a0:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······000384a0:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
000384b0:·2020·2020·2020·2020·2020·2020·2028·6173···············(as000384b0:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
000384c0:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).000384c0:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
000384d0:·2020·2020·2020·2020·2020·2020·2020·2020··················000384d0:·2020·2020·2020·2020·2020·2020·2020·2020··················
000384e0:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>000384e0:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
000384f0:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con000384f0:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00038500:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00038500:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00038510:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00038510:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00038520:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00038520:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00038530:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00038530:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
Offset 15219, 233 lines modifiedOffset 15219, 233 lines modified
0003b720:·6765·743d·2223·6964·6d37·3237·3322·2074··get="#idm7273"·t0003b720:·6765·743d·2223·6964·6d37·3237·3322·2074··get="#idm7273"·t
0003b730:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003b730:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003b740:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003b740:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003b750:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003b750:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003b760:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003b760:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003b770:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003b770:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003b780:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003b780:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003b790:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·0003b790:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe
0003b7a0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003b7a0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003b7b0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003b7b0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003b7c0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003b7c0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003b7d0:·6964·3d22·6964·6d37·3237·3322·3e3c·7461··id="idm7273"><ta0003b7d0:·2220·6964·3d22·6964·6d37·3237·3322·3e3c··"·id="idm7273"><
0003b7e0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0003b7e0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003b7f0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0003b7f0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003b800:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0003b800:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003b810:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0003b810:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003b820:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003b820:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003b830:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003b830:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003b840:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003b840:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003b850:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>0003b850:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003b860:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003b860:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003b870:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:0003b870:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
0003b880:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</0003b880:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
0003b890:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003b890:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003b8a0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003b8a0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
0003b8b0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t0003b8b0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
0003b8c0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003b8c0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003b8d0:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 0003b8e0:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod
0003b8d0:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins 
0003b8e0:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class 
0003b8f0:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{. 
0003b900:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid 
0003b910:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·= 
0003b920:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed' 
0003b930:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code>< 
0003b940:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003b950:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003b960:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003b970:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003b980:·612d·7461·7267·6574·3d22·2369·646d·3732··a-target="#idm72 
0003b990:·3734·2220·7461·6269·6e64·6578·3d22·3022··74"·tabindex="0" 
0003b9a0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003b9b0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003b9c0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003b9d0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003b9e0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003b9f0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
0003ba00:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
0003ba10:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003ba20:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003ba30:·6522·2069·643d·2269·646d·3732·3734·223e··e"·id="idm7274"> 
0003ba40:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003ba50:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003ba60:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003ba70:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003ba80:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003ba90:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003baa0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003bab0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003bac0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003bad0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003bae0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0003baf0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
0003bb00:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0003bb10:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0003bb20:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003bb30:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi 
0003bb40:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica 
0003bb50:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert 
0003bb60:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if 
0003bb70:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker 
0003bb80:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp; 
0003bb90:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co 
0003bba0:·6e74·6169·6e65·7265·6e76·205d·3b20·7468··ntainerenv·];·th 
0003bbb0:·656e·0a0a·6966·2021·2072·706d·202d·7120··en..if·!·rpm·-q· 
0003bbc0:·2d2d·7175·6965·7420·2261·6964·6522·203b··--quiet·"aide"·; 
0003bbd0:·2074·6865·6e0a·2020·2020·646e·6620·696e···then.····dnf·in 
0003bbe0:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide". 
0003bbf0:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt 
0003bc00:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re 
0003bc10:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not 
0003bc20:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not 
0003bc30:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f 
0003bc40:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre>< 
0003bc50:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003bc60:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003bc70:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003bc80:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003bc90:·6574·3d22·2369·646d·3732·3735·2220·7461··et="#idm7275"·ta 
0003bca0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003bcb0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003bcc0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003bcd0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003bce0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003bcf0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003bd00:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet· 
0003bd10:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003bd20:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003bd30:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003bd40:·6964·3d22·6964·6d37·3237·3522·3e3c·7461··id="idm7275"><ta 
0003bd50:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003bd60:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003bd70:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003bd80:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003bd90:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003bda0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003bdb0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003bdc0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003bdd0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003bde0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
Max diff block lines reached; 23675901/23707833 bytes (99.87%) of diff not shown.
2.24 MB
html2text {}
Max HTML report size reached
11.3 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-cis_server_l1.html
    
Offset 14407, 15 lines modifiedOffset 14407, 15 lines modified
00038460:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·00038460:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·
00038470:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong00038470:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong
00038480:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>00038480:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>
00038490:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str00038490:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str
000384a0:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron000384a0:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron
000384b0:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············000384b0:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············
000384c0:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·20000384c0:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·20
000384d0:·3236·2d30·312d·3038·290a·2020·2020·2020··26-01-08).······000384d0:·3234·2d31·322d·3037·290a·2020·2020·2020··24-12-07).······
000384e0:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><000384e0:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><
000384f0:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta000384f0:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta
00038500:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<00038500:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<
00038510:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h00038510:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h
00038520:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.00038520:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.
00038530:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte00038530:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte
00038540:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"00038540:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"
Offset 15187, 234 lines modifiedOffset 15187, 234 lines modified
0003b520:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b520:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b530:·2369·646d·3732·3733·2220·7461·6269·6e64··#idm7273"·tabind0003b530:·2369·646d·3732·3733·2220·7461·6269·6e64··#idm7273"·tabind
0003b540:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b540:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b550:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b550:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b560:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b560:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b570:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b570:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b580:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b580:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b590:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp0003b590:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac
0003b5a0:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</0003b5a0:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...
0003b5b0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003b5b0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003b5c0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003b5c0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003b5d0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003b5d0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003b5e0:·646d·3732·3733·223e·3c74·6162·6c65·2063··dm7273"><table·c0003b5e0:·2269·646d·3732·3733·223e·3c74·6162·6c65··"idm7273"><table
0003b5f0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003b5f0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003b600:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003b600:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003b610:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003b610:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003b620:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003b620:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003b630:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003b630:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003b640:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003b640:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003b650:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru0003b650:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003b660:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l0003b660:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003b670:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003b670:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003b680:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>0003b680:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
0003b690:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></0003b690:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
0003b6a0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0003b6a0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003b6b0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena0003b6b0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003b6c0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t0003b6c0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003b6d0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003b6d0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003b6e0:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add
0003b6e0:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_ 
0003b6f0:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst 
0003b700:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac 
0003b710:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.· 
0003b720:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;· 
0003b730:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··} 
0003b740:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre> 
0003b750:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003b760:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003b770:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003b780:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003b790:·6765·743d·2223·6964·6d37·3237·3422·2074··get="#idm7274"·t 
0003b7a0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003b7b0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003b7c0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003b7d0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003b7e0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003b7f0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003b800:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
0003b810:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b820:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b830:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b840:·3d22·6964·6d37·3237·3422·3e3c·7461·626c··="idm7274"><tabl 
0003b850:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003b860:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003b870:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003b880:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003b890:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003b8a0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b8b0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003b8c0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003b8d0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b8e0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003b8f0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003b900:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003b910:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003b920:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003b930:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003b940:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation 
0003b950:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o 
0003b960:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p 
0003b970:·6c61·7466·6f72·6d73·0a69·6620·5b20·2120··latforms.if·[·!· 
0003b980:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·] 
0003b990:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!· 
0003b9a0:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain 
0003b9b0:·6572·656e·7620·5d3b·2074·6865·6e0a·0a69··erenv·];·then..i 
0003b9c0:·6620·2120·7270·6d20·2d71·202d·2d71·7569··f·!·rpm·-q·--qui 
0003b9d0:·6574·2022·6169·6465·2220·3b20·7468·656e··et·"aide"·;·then 
0003b9e0:·0a20·2020·2064·6e66·2069·6e73·7461·6c6c··.····dnf·install 
0003b9f0:·202d·7920·2261·6964·6522·0a66·690a·0a65···-y·"aide".fi..e 
0003ba00:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp 
0003ba10:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia 
0003ba20:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl 
0003ba30:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing· 
0003ba40:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c 
0003ba50:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003ba60:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003ba70:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003ba80:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003ba90:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003baa0:·6964·6d37·3237·3522·2074·6162·696e·6465··idm7275"·tabinde 
0003bab0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003bac0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003bad0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003bae0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003baf0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003bb00:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib 
0003bb10:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</ 
0003bb20:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003bb30:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003bb40:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003bb50:·646d·3732·3735·223e·3c74·6162·6c65·2063··dm7275"><table·c 
0003bb60:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003bb70:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003bb80:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003bb90:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003bba0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003bbb0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003bbc0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003bbd0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003bbe0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003bbf0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
Max diff block lines reached; 10472611/10504681 bytes (99.69%) of diff not shown.
1.26 MB
html2text {}
    
Offset 58, 15 lines modifiedOffset 58, 15 lines modified
58 ··············Server58 ··············Server
59 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_server_l159 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_server_l1
60 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*60 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
61 ····*·cpe:/o:redhat:enterprise_linux:1061 ····*·cpe:/o:redhat:enterprise_linux:10
62 ····*·cpe:/o:centos:centos:1062 ····*·cpe:/o:centos:centos:10
63 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*63 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
64 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8464 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
65 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)65 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
66 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*66 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
67 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s67 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
68 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e68 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
69 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l69 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
70 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n70 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
71 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g71 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
72 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s72 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 120, 41 lines modifiedOffset 120, 45 lines modified
120 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)120 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
121 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3121 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
122 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5122 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
123 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199123 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
124 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79124 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
125 ············_\x8c_\x8i_\x8s············6.1.1125 ············_\x8c_\x8i_\x8s············6.1.1
126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
 127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 132 package·--add=aide
127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
132 include·install_aide138 include·install_aide
  
133 class·install_aide·{139 class·install_aide·{
134 ··package·{·'aide':140 ··package·{·'aide':
135 ····ensure·=>·'installed',141 ····ensure·=>·'installed',
136 ··}142 ··}
137 }143 }
 144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 145 [[packages]]
 146 name·=·"aide"
 147 version·=·"*"
138 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
139 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low149 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
140 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low150 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
141 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false151 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
142 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable152 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
143 #·Remediation·is·applicable·only·in·certain·platforms 
144 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
 153 package·install·aide
145 if·!·rpm·-q·--quiet·"aide"·;·then 
146 ····dnf·install·-y·"aide" 
147 fi 
  
148 else 
149 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
150 fi 
151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
156 -·name:·Ensure·aide·is·installed159 -·name:·Ensure·aide·is·installed
157 ··package:160 ··package:
Offset 168, 33 lines modifiedOffset 172, 29 lines modified
168 ··-·PCI-DSSv4-11.5.2172 ··-·PCI-DSSv4-11.5.2
169 ··-·enable_strategy173 ··-·enable_strategy
170 ··-·low_complexity174 ··-·low_complexity
171 ··-·low_disruption175 ··-·low_disruption
172 ··-·medium_severity176 ··-·medium_severity
173 ··-·no_reboot_needed177 ··-·no_reboot_needed
174 ··-·package_aide_installed178 ··-·package_aide_installed
175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
176 [[packages]] 
177 name·=·"aide" 
178 version·=·"*" 
179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 184 #·Remediation·is·applicable·only·in·certain·platforms
 185 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 186 if·!·rpm·-q·--quiet·"aide"·;·then
 187 ····dnf·install·-y·"aide"
 188 fi
184 package·install·aide 
185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
190 package·--add=aide189 else
 190 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 191 fi
191 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*192 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
192 Run·the·following·command·to·generate·a·new·database:193 Run·the·following·command·to·generate·a·new·database:
193 $·sudo·/usr/sbin/aide·--init194 $·sudo·/usr/sbin/aide·--init
194 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:195 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
195 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz196 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
196 To·initiate·a·manual·check,·run·the·following·command:197 To·initiate·a·manual·check,·run·the·following·command:
197 $·sudo·/usr/sbin/aide·--check198 $·sudo·/usr/sbin/aide·--check
Offset 211, 28 lines modifiedOffset 211, 14 lines modified
211 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a)211 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
212 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3212 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
213 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5213 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
214 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199214 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
215 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79215 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
216 ············_\x8c_\x8i_\x8s············6.1.1216 ············_\x8c_\x8i_\x8s············6.1.1
217 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2217 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
218 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
219 #·Remediation·is·applicable·only·in·certain·platforms 
220 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
221 if·!·rpm·-q·--quiet·"aide"·;·then 
222 ····dnf·install·-y·"aide" 
223 fi 
  
Max diff block lines reached; 1313854/1319857 bytes (99.55%) of diff not shown.
10.9 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-cis_workstation_l1.html
    
Offset 14408, 15 lines modifiedOffset 14408, 15 lines modified
00038470:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v00038470:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v
00038480:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>00038480:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>
00038490:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><00038490:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><
000384a0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro000384a0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro
000384b0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong000384b0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong
000384c0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············000384c0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············
000384d0:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202000384d0:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202
000384e0:·362d·3031·2d30·3829·0a20·2020·2020·2020··6-01-08).·······000384e0:·342d·3132·2d30·3729·0a20·2020·2020·2020··4-12-07).·······
000384f0:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></000384f0:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></
00038500:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab00038500:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab
00038510:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</00038510:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</
00038520:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr00038520:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr
00038530:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s00038530:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s
00038540:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten00038540:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten
00038550:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">00038550:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">
Offset 15178, 234 lines modifiedOffset 15178, 234 lines modified
0003b490:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b490:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003b4a0:·2223·6964·6d37·3237·3322·2074·6162·696e··"#idm7273"·tabin0003b4a0:·2223·6964·6d37·3237·3322·2074·6162·696e··"#idm7273"·tabin
0003b4b0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b4b0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b4c0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b4c0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b4d0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b4d0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b4e0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b4e0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b4f0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b4f0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b500:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup0003b500:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana
0003b510:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<0003b510:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..
0003b520:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003b520:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003b530:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003b530:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003b540:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003b540:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003b550:·6964·6d37·3237·3322·3e3c·7461·626c·6520··idm7273"><table·0003b550:·3d22·6964·6d37·3237·3322·3e3c·7461·626c··="idm7273"><tabl
0003b560:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003b560:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0003b570:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003b570:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0003b580:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003b580:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0003b590:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003b590:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0003b5a0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003b5a0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003b5b0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003b5b0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003b5c0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003b5c0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003b5d0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003b5d0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003b5e0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003b5e0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003b5f0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th0003b5f0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
0003b600:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><0003b600:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
0003b610:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003b610:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
0003b620:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003b620:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0003b630:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003b630:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
0003b640:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003b640:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003b650:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad
 0003b660:·643d·6169·6465·0a3c·2f63·6f64·653e·3c2f··d=aide.</code></
0003b650:·3e69·6e63·6c75·6465·2069·6e73·7461·6c6c··>include·install 
0003b660:·5f61·6964·650a·0a63·6c61·7373·2069·6e73··_aide..class·ins 
0003b670:·7461·6c6c·5f61·6964·6520·7b0a·2020·7061··tall_aide·{.··pa 
0003b680:·636b·6167·6520·7b20·2761·6964·6527·3a0a··ckage·{·'aide':. 
0003b690:·2020·2020·656e·7375·7265·203d·2667·743b······ensure·=&gt; 
0003b6a0:·2027·696e·7374·616c·6c65·6427·2c0a·2020···'installed',.·· 
0003b6b0:·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70·7265··}.}.</code></pre 
0003b6c0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003b6d0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003b6e0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003b6f0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003b700:·7267·6574·3d22·2369·646d·3732·3734·2220··rget="#idm7274"· 
0003b710:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003b720:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003b730:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003b740:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003b750:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003b760:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003b770:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
0003b780:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b790:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b7a0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003b7b0:·643d·2269·646d·3732·3734·223e·3c74·6162··d="idm7274"><tab 
0003b7c0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003b7d0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003b7e0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003b7f0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003b800:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003b810:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b820:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003b830:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003b840:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b850:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003b860:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003b870:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003b880:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003b890:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003b8a0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003b8b0:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio 
0003b8c0:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable· 
0003b8d0:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain· 
0003b8e0:·706c·6174·666f·726d·730a·6966·205b·2021··platforms.if·[·! 
0003b8f0:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv· 
0003b900:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·! 
0003b910:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai 
0003b920:·6e65·7265·6e76·205d·3b20·7468·656e·0a0a··nerenv·];·then.. 
0003b930:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu 
0003b940:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the 
0003b950:·6e0a·2020·2020·646e·6620·696e·7374·616c··n.····dnf·instal 
0003b960:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi.. 
0003b970:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am 
0003b980:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi 
0003b990:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app 
0003b9a0:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing 
0003b9b0:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</ 
0003b9c0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003b9d0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003b9e0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003b9f0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003ba00:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003ba10:·2369·646d·3732·3735·2220·7461·6269·6e64··#idm7275"·tabind 
0003ba20:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003ba30:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003ba40:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003ba50:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003ba60:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003ba70:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi 
0003ba80:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...< 
0003ba90:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003baa0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003bab0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003bac0:·6964·6d37·3237·3522·3e3c·7461·626c·6520··idm7275"><table· 
0003bad0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003bae0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003baf0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003bb00:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003bb10:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003bb20:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003bb30:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003bb40:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003bb50:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
Max diff block lines reached; 10097003/10129073 bytes (99.68%) of diff not shown.
1.22 MB
html2text {}
    
Offset 58, 15 lines modifiedOffset 58, 15 lines modified
58 ··············Workstation58 ··············Workstation
59 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_workstation_l159 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_workstation_l1
60 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*60 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
61 ····*·cpe:/o:redhat:enterprise_linux:1061 ····*·cpe:/o:redhat:enterprise_linux:10
62 ····*·cpe:/o:centos:centos:1062 ····*·cpe:/o:centos:centos:10
63 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*63 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
64 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8464 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
65 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)65 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
66 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*66 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
67 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s67 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
68 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e68 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
69 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l69 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
70 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n70 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
71 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g71 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
72 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s72 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 118, 41 lines modifiedOffset 118, 45 lines modified
118 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)118 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
119 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3119 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
121 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199121 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
122 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79122 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
123 ············_\x8c_\x8i_\x8s············6.1.1123 ············_\x8c_\x8i_\x8s············6.1.1
124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
 125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 130 package·--add=aide
125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
130 include·install_aide136 include·install_aide
  
131 class·install_aide·{137 class·install_aide·{
132 ··package·{·'aide':138 ··package·{·'aide':
133 ····ensure·=>·'installed',139 ····ensure·=>·'installed',
134 ··}140 ··}
135 }141 }
 142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 143 [[packages]]
 144 name·=·"aide"
 145 version·=·"*"
136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low147 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low148 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false149 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable150 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
141 #·Remediation·is·applicable·only·in·certain·platforms 
142 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
 151 package·install·aide
143 if·!·rpm·-q·--quiet·"aide"·;·then 
144 ····dnf·install·-y·"aide" 
145 fi 
  
146 else 
147 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
148 fi 
149 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
150 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low153 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
151 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low154 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
152 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false155 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
153 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable156 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
154 -·name:·Ensure·aide·is·installed157 -·name:·Ensure·aide·is·installed
155 ··package:158 ··package:
Offset 166, 33 lines modifiedOffset 170, 29 lines modified
166 ··-·PCI-DSSv4-11.5.2170 ··-·PCI-DSSv4-11.5.2
167 ··-·enable_strategy171 ··-·enable_strategy
168 ··-·low_complexity172 ··-·low_complexity
169 ··-·low_disruption173 ··-·low_disruption
170 ··-·medium_severity174 ··-·medium_severity
171 ··-·no_reboot_needed175 ··-·no_reboot_needed
172 ··-·package_aide_installed176 ··-·package_aide_installed
173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
174 [[packages]] 
175 name·=·"aide" 
176 version·=·"*" 
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 182 #·Remediation·is·applicable·only·in·certain·platforms
 183 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 184 if·!·rpm·-q·--quiet·"aide"·;·then
 185 ····dnf·install·-y·"aide"
 186 fi
182 package·install·aide 
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
188 package·--add=aide187 else
 188 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 189 fi
189 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*190 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
190 Run·the·following·command·to·generate·a·new·database:191 Run·the·following·command·to·generate·a·new·database:
191 $·sudo·/usr/sbin/aide·--init192 $·sudo·/usr/sbin/aide·--init
192 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:193 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
193 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz194 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
194 To·initiate·a·manual·check,·run·the·following·command:195 To·initiate·a·manual·check,·run·the·following·command:
195 $·sudo·/usr/sbin/aide·--check196 $·sudo·/usr/sbin/aide·--check
Offset 209, 28 lines modifiedOffset 209, 14 lines modified
209 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a)209 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
210 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3210 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
211 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5211 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
212 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199212 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
213 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79213 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
214 ············_\x8c_\x8i_\x8s············6.1.1214 ············_\x8c_\x8i_\x8s············6.1.1
215 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2215 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
217 #·Remediation·is·applicable·only·in·certain·platforms 
218 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
219 if·!·rpm·-q·--quiet·"aide"·;·then 
220 ····dnf·install·-y·"aide" 
221 fi 
  
Max diff block lines reached; 1268040/1274053 bytes (99.53%) of diff not shown.
24.6 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-cis_workstation_l2.html
    
Offset 14408, 15 lines modifiedOffset 14408, 15 lines modified
00038470:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v00038470:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v
00038480:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>00038480:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>
00038490:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><00038490:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><
000384a0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro000384a0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro
000384b0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong000384b0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong
000384c0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············000384c0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············
000384d0:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202000384d0:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202
000384e0:·362d·3031·2d30·3829·0a20·2020·2020·2020··6-01-08).·······000384e0:·342d·3132·2d30·3729·0a20·2020·2020·2020··4-12-07).·······
000384f0:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></000384f0:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></
00038500:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab00038500:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab
00038510:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</00038510:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</
00038520:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr00038520:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr
00038530:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s00038530:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s
00038540:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten00038540:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten
00038550:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">00038550:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">
Offset 15210, 234 lines modifiedOffset 15210, 234 lines modified
0003b690:·612d·7461·7267·6574·3d22·2369·646d·3732··a-target="#idm720003b690:·612d·7461·7267·6574·3d22·2369·646d·3732··a-target="#idm72
0003b6a0:·3733·2220·7461·6269·6e64·6578·3d22·3022··73"·tabindex="0"0003b6a0:·3733·2220·7461·6269·6e64·6578·3d22·3022··73"·tabindex="0"
0003b6b0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003b6b0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003b6c0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003b6c0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003b6d0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003b6d0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003b6e0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003b6e0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003b6f0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003b6f0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003b700:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni0003b700:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s
0003b710:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003b710:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003b720:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003b720:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003b730:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003b730:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003b740:·7073·6522·2069·643d·2269·646d·3732·3733··pse"·id="idm72730003b740:·6c61·7073·6522·2069·643d·2269·646d·3732··lapse"·id="idm72
0003b750:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003b750:·3733·223e·3c74·6162·6c65·2063·6c61·7373··73"><table·class
0003b760:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003b760:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003b770:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003b770:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003b780:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003b780:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003b790:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003b790:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003b7a0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003b7a0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003b7b0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003b7b0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003b7c0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003b7c0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003b7d0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003b7d0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003b7e0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003b7e0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b7f0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003b7f0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0003b800:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003b800:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
0003b810:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003b810:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003b820:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003b820:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0003b830:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003b830:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003b840:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ0003b840:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 0003b850:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide.
0003b850:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide.. 
0003b860:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai 
0003b870:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{ 
0003b880:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens 
0003b890:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta 
0003b8a0:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c 
0003b8b0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003b8c0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003b8d0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003b8e0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003b8f0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003b900:·6964·6d37·3237·3422·2074·6162·696e·6465··idm7274"·tabinde 
0003b910:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003b920:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003b930:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003b940:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003b950:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003b960:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003b970:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003b980:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b990:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b9a0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7 
0003b9b0:·3237·3422·3e3c·7461·626c·6520·636c·6173··274"><table·clas 
0003b9c0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b9d0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b9e0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b9f0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003ba00:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003ba10:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003ba20:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003ba30:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003ba40:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003ba50:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003ba60:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003ba70:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003ba80:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003ba90:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003baa0:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R 
0003bab0:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003bac0:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003bad0:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003bae0:·6d73·0a69·6620·5b20·2120·2d66·202f·2e64··ms.if·[·!·-f·/.d 
0003baf0:·6f63·6b65·7265·6e76·205d·2026·616d·703b··ockerenv·]·&amp; 
0003bb00:·2661·6d70·3b20·5b20·2120·2d66·202f·7275··&amp;·[·!·-f·/ru 
0003bb10:·6e2f·2e63·6f6e·7461·696e·6572·656e·7620··n/.containerenv· 
0003bb20:·5d3b·2074·6865·6e0a·0a69·6620·2120·7270··];·then..if·!·rp 
0003bb30:·6d20·2d71·202d·2d71·7569·6574·2022·6169··m·-q·--quiet·"ai 
0003bb40:·6465·2220·3b20·7468·656e·0a20·2020·2064··de"·;·then.····d 
0003bb50:·6e66·2069·6e73·7461·6c6c·202d·7920·2261··nf·install·-y·"a 
0003bb60:·6964·6522·0a66·690a·0a65·6c73·650a·2020··ide".fi..else.·· 
0003bb70:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech 
0003bb80:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i 
0003bb90:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable 
0003bba0:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do 
0003bbb0:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></ 
0003bbc0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003bbd0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003bbe0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003bbf0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003bc00:·2d74·6172·6765·743d·2223·6964·6d37·3237··-target="#idm727 
0003bc10:·3522·2074·6162·696e·6465·783d·2230·2220··5"·tabindex="0"· 
0003bc20:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003bc30:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003bc40:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003bc50:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003bc60:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003bc70:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni 
0003bc80:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003bc90:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003bca0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003bcb0:·7073·6522·2069·643d·2269·646d·3732·3735··pse"·id="idm7275 
0003bcc0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003bcd0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003bce0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003bcf0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003bd00:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003bd10:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003bd20:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003bd30:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003bd40:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003bd50:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003bd60:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
Max diff block lines reached; 23486730/23518800 bytes (99.86%) of diff not shown.
2.21 MB
html2text {}
Max HTML report size reached
6.67 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-e8.html
    
Offset 14419, 16 lines modifiedOffset 14419, 16 lines modified
00038520:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00038520:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00038530:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00038530:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00038540:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000038540:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00038550:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></00038550:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
00038560:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00038560:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00038570:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00038570:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00038580:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00038580:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00038590:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600038590:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
000385a0:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········000385a0:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
000385b0:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u000385b0:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
000385c0:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl000385c0:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
000385d0:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h000385d0:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
000385e0:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre000385e0:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
000385f0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss000385f0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00038600:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00038600:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00038610:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00038610:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
Offset 15273, 301 lines modifiedOffset 15273, 301 lines modified
0003ba80:·7461·7267·6574·3d22·2369·646d·3639·3334··target="#idm69340003ba80:·7461·7267·6574·3d22·2369·646d·3639·3334··target="#idm6934
0003ba90:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003ba90:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003baa0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003baa0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003bab0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003bab0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003bac0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003bac0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003bad0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003bad0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003bae0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003bae0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003baf0:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003bb00:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003bb10:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003bb20:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003bb30:·2069·643d·2269·646d·3639·3334·223e·3c70···id="idm6934"><p 
0003bb40:·7265·3e3c·636f·6465·3e0a·2320·4669·6e64··re><code>.#·Find 
0003bb50:·2077·6869·6368·2066·696c·6573·2068·6176···which·files·hav 
0003bb60:·6520·696e·636f·7272·6563·7420·6861·7368··e·incorrect·hash 
0003bb70:·2028·6e6f·7420·696e·202f·6574·632c·2062···(not·in·/etc,·b 
0003bb80:·6563·6175·7365·206f·6620·7468·6520·7379··ecause·of·the·sy 
0003bb90:·7374·656d·2072·656c·6174·6564·2063·6f6e··stem·related·con 
0003bba0:·6669·6720·6669·6c65·7329·2061·6e64·2074··fig·files)·and·t 
0003bbb0:·6865·6e20·6765·7420·6669·6c65·7320·6e61··hen·get·files·na 
0003bbc0:·6d65·730a·6669·6c65·735f·7769·7468·5f69··mes.files_with_i 
0003bbd0:·6e63·6f72·7265·6374·5f68·6173·683d·2224··ncorrect_hash="$ 
0003bbe0:·2872·706d·202d·5661·202d·2d6e·6f63·6f6e··(rpm·-Va·--nocon 
0003bbf0:·6669·6720·7c20·6772·6570·202d·4520·275e··fig·|·grep·-E·'^ 
0003bc00:·2e2e·3527·207c·2061·776b·2027·7b70·7269··..5'·|·awk·'{pri 
0003bc10:·6e74·2024·4e46·7d27·2029·220a·0a69·6620··nt·$NF}'·)"..if· 
0003bc20:·5b20·2d6e·2022·2466·696c·6573·5f77·6974··[·-n·"$files_wit 
0003bc30:·685f·696e·636f·7272·6563·745f·6861·7368··h_incorrect_hash 
0003bc40:·2220·5d3b·2074·6865·6e0a·2020·2020·2320··"·];·then.····#· 
0003bc50:·4672·6f6d·2066·696c·6573·206e·616d·6573··From·files·names 
0003bc60:·2067·6574·2070·6163·6b61·6765·206e·616d···get·package·nam 
0003bc70:·6573·2061·6e64·2063·6861·6e67·6520·6e65··es·and·change·ne 
0003bc80:·776c·696e·6520·746f·2073·7061·6365·2c20··wline·to·space,· 
0003bc90:·6265·6361·7573·6520·7270·6d20·7772·6974··because·rpm·writ 
0003bca0:·6573·2065·6163·6820·7061·636b·6167·6520··es·each·package· 
0003bcb0:·746f·206e·6577·206c·696e·650a·2020·2020··to·new·line.···· 
0003bcc0:·7061·636b·6167·6573·5f74·6f5f·7265·696e··packages_to_rein 
0003bcd0:·7374·616c·6c3d·2224·2872·706d·202d·7166··stall="$(rpm·-qf 
0003bce0:·2024·6669·6c65·735f·7769·7468·5f69·6e63···$files_with_inc 
0003bcf0:·6f72·7265·6374·5f68·6173·6820·7c20·7472··orrect_hash·|·tr 
0003bd00:·2027·5c6e·2720·2720·2729·220a·0a20·2020···'\n'·'·')"..··· 
0003bd10:·200a·2020·2020·646e·6620·7265·696e·7374···.····dnf·reinst 
0003bd20:·616c·6c20·2d79·2024·7061·636b·6167·6573··all·-y·$packages 
0003bd30:·5f74·6f5f·7265·696e·7374·616c·6c0a·2020··_to_reinstall.·· 
0003bd40:·2020·0a66·690a·3c2f·636f·6465·3e3c·2f70····.fi.</code></p 
0003bd50:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003bd60:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003bd70:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003bd80:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003bd90:·7461·7267·6574·3d22·2369·646d·3639·3335··target="#idm6935 
0003bda0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003bdb0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003bdc0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003bdd0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003bde0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003bdf0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003be00:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip0003baf0:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip
0003be10:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003bb00:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003be20:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003bb10:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003be30:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003bb20:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003be40:·7365·2220·6964·3d22·6964·6d36·3933·3522··se"·id="idm6935"0003bb30:·7365·2220·6964·3d22·6964·6d36·3933·3422··se"·id="idm6934"
0003be50:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003bb40:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003be60:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003bb50:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003be70:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003bb60:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003be80:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003bb70:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003be90:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003bb80:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003bea0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e68··exity:</th><td>h0003bb90:·6578·6974·793a·3c2f·7468·3e3c·7464·3e68··exity:</th><td>h
0003beb0:·6967·683c·2f74·643e·3c2f·7472·3e3c·7472··igh</td></tr><tr0003bba0:·6967·683c·2f74·643e·3c2f·7472·3e3c·7472··igh</td></tr><tr
0003bec0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003bbb0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003bed0:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<0003bbc0:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<
0003bee0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003bbd0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003bef0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003bbe0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003bf00:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003bbf0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003bf10:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003bc00:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003bf20:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri0003bc10:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri
0003bf30:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta0003bc20:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta
0003bf40:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-0003bc30:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-
0003bf50:·206e·616d·653a·2027·5365·7420·6661·6374···name:·'Set·fact0003bc40:·206e·616d·653a·2027·5365·7420·6661·6374···name:·'Set·fact
0003bf60:·3a20·5061·636b·6167·6520·6d61·6e61·6765··:·Package·manage0003bc50:·3a20·5061·636b·6167·6520·6d61·6e61·6765··:·Package·manage
0003bf70:·7220·7265·696e·7374·616c·6c20·636f·6d6d··r·reinstall·comm0003bc60:·7220·7265·696e·7374·616c·6c20·636f·6d6d··r·reinstall·comm
0003bf80:·616e·6427·0a20·2073·6574·5f66·6163·743a··and'.··set_fact:0003bc70:·616e·6427·0a20·2073·6574·5f66·6163·743a··and'.··set_fact:
0003bf90:·0a20·2020·2070·6163·6b61·6765·5f6d·616e··.····package_man0003bc80:·0a20·2020·2070·6163·6b61·6765·5f6d·616e··.····package_man
0003bfa0:·6167·6572·5f72·6569·6e73·7461·6c6c·5f63··ager_reinstall_c0003bc90:·6167·6572·5f72·6569·6e73·7461·6c6c·5f63··ager_reinstall_c
0003bfb0:·6d64·3a20·646e·6620·7265·696e·7374·616c··md:·dnf·reinstal0003bca0:·6d64·3a20·646e·6620·7265·696e·7374·616c··md:·dnf·reinstal
0003bfc0:·6c20·2d79·0a20·2077·6865·6e3a·2061·6e73··l·-y.··when:·ans0003bcb0:·6c20·2d79·0a20·2077·6865·6e3a·2061·6e73··l·-y.··when:·ans
0003bfd0:·6962·6c65·5f64·6973·7472·6962·7574·696f··ible_distributio0003bcc0:·6962·6c65·5f64·6973·7472·6962·7574·696f··ible_distributio
0003bfe0:·6e20·696e·205b·2022·4665·646f·7261·222c··n·in·[·"Fedora",0003bcd0:·6e20·696e·205b·2022·4665·646f·7261·222c··n·in·[·"Fedora",
0003bff0:·2022·5265·6448·6174·222c·2022·4365·6e74···"RedHat",·"Cent0003bce0:·2022·5265·6448·6174·222c·2022·4365·6e74···"RedHat",·"Cent
0003c000:·4f53·222c·2022·4f72·6163·6c65·4c69·6e75··OS",·"OracleLinu0003bcf0:·4f53·222c·2022·4f72·6163·6c65·4c69·6e75··OS",·"OracleLinu
0003c010:·7822·205d·0a20·2074·6167·733a·0a20·202d··x"·].··tags:.··-0003bd00:·7822·205d·0a20·2074·6167·733a·0a20·202d··x"·].··tags:.··-
0003c020:·2043·4a49·532d·352e·3130·2e34·2e31·0a20···CJIS-5.10.4.1.·0003bd10:·2043·4a49·532d·352e·3130·2e34·2e31·0a20···CJIS-5.10.4.1.·
0003c030:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-0003bd20:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
0003c040:·332e·332e·380a·2020·2d20·4e49·5354·2d38··3.3.8.··-·NIST-80003bd30:·332e·332e·380a·2020·2d20·4e49·5354·2d38··3.3.8.··-·NIST-8
0003c050:·3030·2d31·3731·2d33·2e34·2e31·0a20·202d··00-171-3.4.1.··-0003bd40:·3030·2d31·3731·2d33·2e34·2e31·0a20·202d··00-171-3.4.1.··-
0003c060:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-0003bd50:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-
0003c070:·3928·3329·0a20·202d·204e·4953·542d·3830··9(3).··-·NIST-800003bd60:·3928·3329·0a20·202d·204e·4953·542d·3830··9(3).··-·NIST-80
0003c080:·302d·3533·2d43·4d2d·3628·6329·0a20·202d··0-53-CM-6(c).··-0003bd70:·302d·3533·2d43·4d2d·3628·6329·0a20·202d··0-53-CM-6(c).··-
0003c090:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-0003bd80:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-
0003c0a0:·3628·6429·0a20·202d·204e·4953·542d·3830··6(d).··-·NIST-800003bd90:·3628·6429·0a20·202d·204e·4953·542d·3830··6(d).··-·NIST-80
0003c0b0:·302d·3533·2d53·492d·370a·2020·2d20·4e49··0-53-SI-7.··-·NI0003bda0:·302d·3533·2d53·492d·370a·2020·2d20·4e49··0-53-SI-7.··-·NI
0003c0c0:·5354·2d38·3030·2d35·332d·5349·2d37·2831··ST-800-53-SI-7(10003bdb0:·5354·2d38·3030·2d35·332d·5349·2d37·2831··ST-800-53-SI-7(1
0003c0d0:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-50003bdc0:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5
0003c0e0:·332d·5349·2d37·2836·290a·2020·2d20·5043··3-SI-7(6).··-·PC0003bdd0:·332d·5349·2d37·2836·290a·2020·2d20·5043··3-SI-7(6).··-·PC
0003c0f0:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·0003bde0:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·
0003c100:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.0003bdf0:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.
0003c110:·352e·320a·2020·2d20·6869·6768·5f63·6f6d··5.2.··-·high_com0003be00:·352e·320a·2020·2d20·6869·6768·5f63·6f6d··5.2.··-·high_com
0003c120:·706c·6578·6974·790a·2020·2d20·6869·6768··plexity.··-·high0003be10:·706c·6578·6974·790a·2020·2d20·6869·6768··plexity.··-·high
0003c130:·5f73·6576·6572·6974·790a·2020·2d20·6d65··_severity.··-·me0003be20:·5f73·6576·6572·6974·790a·2020·2d20·6d65··_severity.··-·me
0003c140:·6469·756d·5f64·6973·7275·7074·696f·6e0a··dium_disruption.0003be30:·6469·756d·5f64·6973·7275·7074·696f·6e0a··dium_disruption.
0003c150:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne0003be40:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne
Max diff block lines reached; 6275707/6301567 bytes (99.59%) of diff not shown.
674 KB
html2text {}
    
Offset 60, 15 lines modifiedOffset 60, 15 lines modified
60 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Australian·Cyber·Security·Centre·(ACSC)·Essential·Eight60 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Australian·Cyber·Security·Centre·(ACSC)·Essential·Eight
61 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_e861 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_e8
62 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*62 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
63 ····*·cpe:/o:redhat:enterprise_linux:1063 ····*·cpe:/o:redhat:enterprise_linux:10
64 ····*·cpe:/o:centos:centos:1064 ····*·cpe:/o:centos:centos:10
65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
66 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8466 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
69 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s69 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
70 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e70 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
71 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l71 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
72 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g72 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
73 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s73 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
74 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s74 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 122, 27 lines modifiedOffset 122, 14 lines modified
122 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6122 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
123 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4123 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
124 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)124 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
125 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1125 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
127 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227127 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
128 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2128 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
130 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
131 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
132 if·[·-n·"$files_with_incorrect_hash"·];·then 
133 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
134 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
135 ····dnf·reinstall·-y·$packages_to_reinstall 
  
136 fi 
137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
142 -·name:·'Set·fact:·Package·manager·reinstall·command'134 -·name:·'Set·fact:·Package·manager·reinstall·command'
143 ··set_fact:135 ··set_fact:
Offset 269, 14 lines modifiedOffset 256, 27 lines modified
269 ··-·PCI-DSSv4-11.5.2256 ··-·PCI-DSSv4-11.5.2
270 ··-·high_complexity257 ··-·high_complexity
271 ··-·high_severity258 ··-·high_severity
272 ··-·medium_disruption259 ··-·medium_disruption
273 ··-·no_reboot_needed260 ··-·no_reboot_needed
274 ··-·restrict_strategy261 ··-·restrict_strategy
275 ··-·rpm_verify_hashes262 ··-·rpm_verify_hashes
 263 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 264 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 265 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 266 if·[·-n·"$files_with_incorrect_hash"·];·then
 267 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 268 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 269 ····dnf·reinstall·-y·$packages_to_reinstall
  
 270 fi
276 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*271 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
277 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:272 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
278 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'273 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
279 run·the·following·command·to·determine·which·package·owns·it:274 run·the·following·command·to·determine·which·package·owns·it:
280 $·rpm·-qf·FILENAME275 $·rpm·-qf·FILENAME
281 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:276 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
282 $·sudo·rpm·--setugids·PACKAGENAME277 $·sudo·rpm·--setugids·PACKAGENAME
Offset 295, 40 lines modifiedOffset 295, 14 lines modified
295 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5295 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
296 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2296 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
297 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)297 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
298 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1298 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
299 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5299 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
300 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108300 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
301 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2301 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
302 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
303 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
304 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
305 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
306 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
307 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
308 declare·-A·SETPERMS_RPM_DICT 
  
309 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
310 #·is·expected·by·the·RPM·database 
311 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
312 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
313 do 
314 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
315 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
316 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
317 done 
  
318 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
319 #·correct·values 
320 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
321 do 
322 ········rpm·--setugids·"${RPM_PACKAGE}" 
323 done 
324 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8302 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
325 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high303 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
326 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium304 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
327 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false305 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
328 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict306 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
329 -·name:·Read·list·of·files·with·incorrect·ownership307 -·name:·Read·list·of·files·with·incorrect·ownership
330 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev308 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 403, 14 lines modifiedOffset 377, 40 lines modified
403 ··-·PCI-DSSv4-11.5.2377 ··-·PCI-DSSv4-11.5.2
404 ··-·high_complexity378 ··-·high_complexity
405 ··-·high_severity379 ··-·high_severity
406 ··-·medium_disruption380 ··-·medium_disruption
407 ··-·no_reboot_needed381 ··-·no_reboot_needed
408 ··-·restrict_strategy382 ··-·restrict_strategy
409 ··-·rpm_verify_ownership383 ··-·rpm_verify_ownership
 384 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 385 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 386 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 387 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 388 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 389 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 682024/689738 bytes (98.88%) of diff not shown.
20.2 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-hipaa.html
    
Offset 14439, 15 lines modifiedOffset 14439, 15 lines modified
00038660:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00038660:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00038670:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00038670:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00038680:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</00038680:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
00038690:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00038690:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
000386a0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft000386a0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
000386b0:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······000386b0:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
000386c0:·2020·2020·2020·2020·2020·2020·2020·2861················(a000386c0:·2020·2020·2020·2020·2020·2020·2020·2861················(a
000386d0:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)000386d0:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
000386e0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············000386e0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
000386f0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div000386f0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
00038700:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co00038700:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
00038710:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><00038710:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
00038720:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc00038720:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
00038730:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec00038730:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00038740:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00038740:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 15294, 300 lines modifiedOffset 15294, 300 lines modified
0003bbd0:·6765·743d·2223·6964·6d36·3933·3422·2074··get="#idm6934"·t0003bbd0:·6765·743d·2223·6964·6d36·3933·3422·2074··get="#idm6934"·t
0003bbe0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003bbe0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003bbf0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003bbf0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003bc00:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003bc00:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003bc10:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003bc10:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003bc20:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003bc20:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003bc30:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003bc30:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003bc40:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
0003bc50:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003bc60:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003bc70:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003bc80:·3d22·6964·6d36·3933·3422·3e3c·7072·653e··="idm6934"><pre> 
0003bc90:·3c63·6f64·653e·0a23·2046·696e·6420·7768··<code>.#·Find·wh 
0003bca0:·6963·6820·6669·6c65·7320·6861·7665·2069··ich·files·have·i 
0003bcb0:·6e63·6f72·7265·6374·2068·6173·6820·286e··ncorrect·hash·(n 
0003bcc0:·6f74·2069·6e20·2f65·7463·2c20·6265·6361··ot·in·/etc,·beca 
0003bcd0:·7573·6520·6f66·2074·6865·2073·7973·7465··use·of·the·syste 
0003bce0:·6d20·7265·6c61·7465·6420·636f·6e66·6967··m·related·config 
0003bcf0:·2066·696c·6573·2920·616e·6420·7468·656e···files)·and·then 
0003bd00:·2067·6574·2066·696c·6573·206e·616d·6573···get·files·names 
0003bd10:·0a66·696c·6573·5f77·6974·685f·696e·636f··.files_with_inco 
0003bd20:·7272·6563·745f·6861·7368·3d22·2428·7270··rrect_hash="$(rp 
0003bd30:·6d20·2d56·6120·2d2d·6e6f·636f·6e66·6967··m·-Va·--noconfig 
0003bd40:·207c·2067·7265·7020·2d45·2027·5e2e·2e35···|·grep·-E·'^..5 
0003bd50:·2720·7c20·6177·6b20·277b·7072·696e·7420··'·|·awk·'{print· 
0003bd60:·244e·467d·2720·2922·0a0a·6966·205b·202d··$NF}'·)"..if·[·- 
0003bd70:·6e20·2224·6669·6c65·735f·7769·7468·5f69··n·"$files_with_i 
0003bd80:·6e63·6f72·7265·6374·5f68·6173·6822·205d··ncorrect_hash"·] 
0003bd90:·3b20·7468·656e·0a20·2020·2023·2046·726f··;·then.····#·Fro 
0003bda0:·6d20·6669·6c65·7320·6e61·6d65·7320·6765··m·files·names·ge 
0003bdb0:·7420·7061·636b·6167·6520·6e61·6d65·7320··t·package·names· 
0003bdc0:·616e·6420·6368·616e·6765·206e·6577·6c69··and·change·newli 
0003bdd0:·6e65·2074·6f20·7370·6163·652c·2062·6563··ne·to·space,·bec 
0003bde0:·6175·7365·2072·706d·2077·7269·7465·7320··ause·rpm·writes· 
0003bdf0:·6561·6368·2070·6163·6b61·6765·2074·6f20··each·package·to· 
0003be00:·6e65·7720·6c69·6e65·0a20·2020·2070·6163··new·line.····pac 
0003be10:·6b61·6765·735f·746f·5f72·6569·6e73·7461··kages_to_reinsta 
0003be20:·6c6c·3d22·2428·7270·6d20·2d71·6620·2466··ll="$(rpm·-qf·$f 
0003be30:·696c·6573·5f77·6974·685f·696e·636f·7272··iles_with_incorr 
0003be40:·6563·745f·6861·7368·207c·2074·7220·275c··ect_hash·|·tr·'\ 
0003be50:·6e27·2027·2027·2922·0a0a·2020·2020·0a20··n'·'·')"..····.· 
0003be60:·2020·2064·6e66·2072·6569·6e73·7461·6c6c·····dnf·reinstall 
0003be70:·202d·7920·2470·6163·6b61·6765·735f·746f···-y·$packages_to 
0003be80:·5f72·6569·6e73·7461·6c6c·0a20·2020·200a··_reinstall.····. 
0003be90:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre> 
0003bea0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003beb0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003bec0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003bed0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003bee0:·6765·743d·2223·6964·6d36·3933·3522·2074··get="#idm6935"·t 
0003bef0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003bf00:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003bf10:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003bf20:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003bf30:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003bf40:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003bf50:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet0003bc40:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet
0003bf60:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003bc50:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003bf70:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003bc60:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003bf80:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003bc70:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003bf90:·2069·643d·2269·646d·3639·3335·223e·3c74···id="idm6935"><t0003bc80:·2069·643d·2269·646d·3639·3334·223e·3c74···id="idm6934"><t
0003bfa0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl0003bc90:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003bfb0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·0003bca0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003bfc0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0003bcb0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003bfd0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">0003bcc0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003bfe0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi0003bcd0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003bff0:·7479·3a3c·2f74·683e·3c74·643e·6869·6768··ty:</th><td>high0003bce0:·7479·3a3c·2f74·683e·3c74·643e·6869·6768··ty:</th><td>high
0003c000:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003bcf0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003c010:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003bd00:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003c020:·683e·3c74·643e·6d65·6469·756d·3c2f·7464··h><td>medium</td0003bd10:·683e·3c74·643e·6d65·6469·756d·3c2f·7464··h><td>medium</td
0003c030:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003bd20:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003c040:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003bd30:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003c050:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003bd40:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003c060:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003bd50:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003c070:·7468·3e3c·7464·3e72·6573·7472·6963·743c··th><td>restrict<0003bd60:·7468·3e3c·7464·3e72·6573·7472·6963·743c··th><td>restrict<
0003c080:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003bd70:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003c090:·3e3c·7072·653e·3c63·6f64·653e·2d20·6e61··><pre><code>-·na0003bd80:·3e3c·7072·653e·3c63·6f64·653e·2d20·6e61··><pre><code>-·na
0003c0a0:·6d65·3a20·2753·6574·2066·6163·743a·2050··me:·'Set·fact:·P0003bd90:·6d65·3a20·2753·6574·2066·6163·743a·2050··me:·'Set·fact:·P
0003c0b0:·6163·6b61·6765·206d·616e·6167·6572·2072··ackage·manager·r0003bda0:·6163·6b61·6765·206d·616e·6167·6572·2072··ackage·manager·r
0003c0c0:·6569·6e73·7461·6c6c·2063·6f6d·6d61·6e64··einstall·command0003bdb0:·6569·6e73·7461·6c6c·2063·6f6d·6d61·6e64··einstall·command
0003c0d0:·270a·2020·7365·745f·6661·6374·3a0a·2020··'.··set_fact:.··0003bdc0:·270a·2020·7365·745f·6661·6374·3a0a·2020··'.··set_fact:.··
0003c0e0:·2020·7061·636b·6167·655f·6d61·6e61·6765····package_manage0003bdd0:·2020·7061·636b·6167·655f·6d61·6e61·6765····package_manage
0003c0f0:·725f·7265·696e·7374·616c·6c5f·636d·643a··r_reinstall_cmd:0003bde0:·725f·7265·696e·7374·616c·6c5f·636d·643a··r_reinstall_cmd:
0003c100:·2064·6e66·2072·6569·6e73·7461·6c6c·202d···dnf·reinstall·-0003bdf0:·2064·6e66·2072·6569·6e73·7461·6c6c·202d···dnf·reinstall·-
0003c110:·790a·2020·7768·656e·3a20·616e·7369·626c··y.··when:·ansibl0003be00:·790a·2020·7768·656e·3a20·616e·7369·626c··y.··when:·ansibl
0003c120:·655f·6469·7374·7269·6275·7469·6f6e·2069··e_distribution·i0003be10:·655f·6469·7374·7269·6275·7469·6f6e·2069··e_distribution·i
0003c130:·6e20·5b20·2246·6564·6f72·6122·2c20·2252··n·[·"Fedora",·"R0003be20:·6e20·5b20·2246·6564·6f72·6122·2c20·2252··n·[·"Fedora",·"R
0003c140:·6564·4861·7422·2c20·2243·656e·744f·5322··edHat",·"CentOS"0003be30:·6564·4861·7422·2c20·2243·656e·744f·5322··edHat",·"CentOS"
0003c150:·2c20·224f·7261·636c·654c·696e·7578·2220··,·"OracleLinux"·0003be40:·2c20·224f·7261·636c·654c·696e·7578·2220··,·"OracleLinux"·
0003c160:·5d0a·2020·7461·6773·3a0a·2020·2d20·434a··].··tags:.··-·CJ0003be50:·5d0a·2020·7461·6773·3a0a·2020·2d20·434a··].··tags:.··-·CJ
0003c170:·4953·2d35·2e31·302e·342e·310a·2020·2d20··IS-5.10.4.1.··-·0003be60:·4953·2d35·2e31·302e·342e·310a·2020·2d20··IS-5.10.4.1.··-·
0003c180:·4e49·5354·2d38·3030·2d31·3731·2d33·2e33··NIST-800-171-3.30003be70:·4e49·5354·2d38·3030·2d31·3731·2d33·2e33··NIST-800-171-3.3
0003c190:·2e38·0a20·202d·204e·4953·542d·3830·302d··.8.··-·NIST-800-0003be80:·2e38·0a20·202d·204e·4953·542d·3830·302d··.8.··-·NIST-800-
0003c1a0:·3137·312d·332e·342e·310a·2020·2d20·4e49··171-3.4.1.··-·NI0003be90:·3137·312d·332e·342e·310a·2020·2d20·4e49··171-3.4.1.··-·NI
0003c1b0:·5354·2d38·3030·2d35·332d·4155·2d39·2833··ST-800-53-AU-9(30003bea0:·5354·2d38·3030·2d35·332d·4155·2d39·2833··ST-800-53-AU-9(3
0003c1c0:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-50003beb0:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5
0003c1d0:·332d·434d·2d36·2863·290a·2020·2d20·4e49··3-CM-6(c).··-·NI0003bec0:·332d·434d·2d36·2863·290a·2020·2d20·4e49··3-CM-6(c).··-·NI
0003c1e0:·5354·2d38·3030·2d35·332d·434d·2d36·2864··ST-800-53-CM-6(d0003bed0:·5354·2d38·3030·2d35·332d·434d·2d36·2864··ST-800-53-CM-6(d
0003c1f0:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-50003bee0:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5
0003c200:·332d·5349·2d37·0a20·202d·204e·4953·542d··3-SI-7.··-·NIST-0003bef0:·332d·5349·2d37·0a20·202d·204e·4953·542d··3-SI-7.··-·NIST-
0003c210:·3830·302d·3533·2d53·492d·3728·3129·0a20··800-53-SI-7(1).·0003bf00:·3830·302d·3533·2d53·492d·3728·3129·0a20··800-53-SI-7(1).·
0003c220:·202d·204e·4953·542d·3830·302d·3533·2d53···-·NIST-800-53-S0003bf10:·202d·204e·4953·542d·3830·302d·3533·2d53···-·NIST-800-53-S
0003c230:·492d·3728·3629·0a20·202d·2050·4349·2d44··I-7(6).··-·PCI-D0003bf20:·492d·3728·3629·0a20·202d·2050·4349·2d44··I-7(6).··-·PCI-D
0003c240:·5353·2d52·6571·2d31·312e·350a·2020·2d20··SS-Req-11.5.··-·0003bf30:·5353·2d52·6571·2d31·312e·350a·2020·2d20··SS-Req-11.5.··-·
0003c250:·5043·492d·4453·5376·342d·3131·2e35·2e32··PCI-DSSv4-11.5.20003bf40:·5043·492d·4453·5376·342d·3131·2e35·2e32··PCI-DSSv4-11.5.2
0003c260:·0a20·202d·2068·6967·685f·636f·6d70·6c65··.··-·high_comple0003bf50:·0a20·202d·2068·6967·685f·636f·6d70·6c65··.··-·high_comple
0003c270:·7869·7479·0a20·202d·2068·6967·685f·7365··xity.··-·high_se0003bf60:·7869·7479·0a20·202d·2068·6967·685f·7365··xity.··-·high_se
0003c280:·7665·7269·7479·0a20·202d·206d·6564·6975··verity.··-·mediu0003bf70:·7665·7269·7479·0a20·202d·206d·6564·6975··verity.··-·mediu
0003c290:·6d5f·6469·7372·7570·7469·6f6e·0a20·202d··m_disruption.··-0003bf80:·6d5f·6469·7372·7570·7469·6f6e·0a20·202d··m_disruption.··-
0003c2a0:·206e·6f5f·7265·626f·6f74·5f6e·6565·6465···no_reboot_neede0003bf90:·206e·6f5f·7265·626f·6f74·5f6e·6565·6465···no_reboot_neede
0003c2b0:·640a·2020·2d20·7265·7374·7269·6374·5f73··d.··-·restrict_s0003bfa0:·640a·2020·2d20·7265·7374·7269·6374·5f73··d.··-·restrict_s
Max diff block lines reached; 19552829/19578551 bytes (99.87%) of diff not shown.
1.54 MB
html2text {}
    
Offset 66, 15 lines modifiedOffset 66, 15 lines modified
66 ··············(HIPAA)66 ··············(HIPAA)
67 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_hipaa67 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_hipaa
68 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*68 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
69 ····*·cpe:/o:redhat:enterprise_linux:1069 ····*·cpe:/o:redhat:enterprise_linux:10
70 ····*·cpe:/o:centos:centos:1070 ····*·cpe:/o:centos:centos:10
71 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*71 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
72 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8472 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
73 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)73 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
74 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*74 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
75 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s75 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
76 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e76 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
77 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l77 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
78 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n78 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
79 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g79 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
80 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s80 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 128, 27 lines modifiedOffset 128, 14 lines modified
128 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6128 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
129 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4129 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
130 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)130 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
131 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1131 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
132 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5132 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
133 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227133 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
134 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2134 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
136 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
137 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
138 if·[·-n·"$files_with_incorrect_hash"·];·then 
139 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
140 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
141 ····dnf·reinstall·-y·$packages_to_reinstall 
  
142 fi 
143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
144 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
145 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
146 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
147 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
148 -·name:·'Set·fact:·Package·manager·reinstall·command'140 -·name:·'Set·fact:·Package·manager·reinstall·command'
149 ··set_fact:141 ··set_fact:
Offset 275, 14 lines modifiedOffset 262, 27 lines modified
275 ··-·PCI-DSSv4-11.5.2262 ··-·PCI-DSSv4-11.5.2
276 ··-·high_complexity263 ··-·high_complexity
277 ··-·high_severity264 ··-·high_severity
278 ··-·medium_disruption265 ··-·medium_disruption
279 ··-·no_reboot_needed266 ··-·no_reboot_needed
280 ··-·restrict_strategy267 ··-·restrict_strategy
281 ··-·rpm_verify_hashes268 ··-·rpm_verify_hashes
 269 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 270 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 271 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 272 if·[·-n·"$files_with_incorrect_hash"·];·then
 273 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 274 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 275 ····dnf·reinstall·-y·$packages_to_reinstall
  
 276 fi
282 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*277 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
283 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:278 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:
284 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'279 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'
285 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:280 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:
286 $·rpm·-qf·FILENAME281 $·rpm·-qf·FILENAME
  
287 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:282 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
Offset 303, 44 lines modifiedOffset 303, 14 lines modified
303 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5303 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
304 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2304 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
305 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)305 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)
306 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1306 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
307 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5307 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
308 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108308 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108
309 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2309 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
310 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
311 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
312 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
313 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
314 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
315 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
316 declare·-A·SETPERMS_RPM_DICT 
  
317 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
318 #·is·expected·by·the·RPM·database 
319 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}') 
  
320 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
321 do 
322 ········#·NOTE:·some·files·maybe·controlled·by·more·then·one·package 
323 ········readarray·-t·RPM_PACKAGES·<·<(rpm·-qf·"${FILE_PATH}") 
324 ········for·RPM_PACKAGE·in·"${RPM_PACKAGES[@]}" 
325 ········do 
326 ················#·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
327 ················SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
328 ········done 
329 done 
  
330 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
331 #·correct·values 
332 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
333 do 
334 »       rpm·--restore·"${RPM_PACKAGE}" 
335 done 
336 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8310 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
337 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high311 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
338 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium312 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
339 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false313 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
340 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict314 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
341 -·name:·Read·list·of·files·with·incorrect·permissions315 -·name:·Read·list·of·files·with·incorrect·permissions
342 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev316 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 418, 14 lines modifiedOffset 388, 44 lines modified
418 ··-·PCI-DSSv4-11.5.2388 ··-·PCI-DSSv4-11.5.2
419 ··-·high_complexity389 ··-·high_complexity
420 ··-·high_severity390 ··-·high_severity
421 ··-·medium_disruption391 ··-·medium_disruption
422 ··-·no_reboot_needed392 ··-·no_reboot_needed
423 ··-·restrict_strategy393 ··-·restrict_strategy
424 ··-·rpm_verify_permissions394 ··-·rpm_verify_permissions
 395 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 396 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 397 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
Max diff block lines reached; 1603491/1611641 bytes (99.49%) of diff not shown.
11.5 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-ism_o.html
    
Offset 14427, 15 lines modifiedOffset 14427, 15 lines modified
000385a0:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C000385a0:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
000385b0:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·000385b0:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
000385c0:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</000385c0:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
000385d0:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><000385d0:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
000385e0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft000385e0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
000385f0:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······000385f0:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
00038600:·2020·2020·2020·2020·2020·2020·2020·2861················(a00038600:·2020·2020·2020·2020·2020·2020·2020·2861················(a
00038610:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)00038610:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
00038620:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00038620:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00038630:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div00038630:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
00038640:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co00038640:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
00038650:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><00038650:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
00038660:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc00038660:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
00038670:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec00038670:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00038680:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00038680:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 15317, 301 lines modifiedOffset 15317, 301 lines modified
0003bd40:·2d74·6172·6765·743d·2223·6964·6d36·3933··-target="#idm6930003bd40:·2d74·6172·6765·743d·2223·6964·6d36·3933··-target="#idm693
0003bd50:·3422·2074·6162·696e·6465·783d·2230·2220··4"·tabindex="0"·0003bd50:·3422·2074·6162·696e·6465·783d·2230·2220··4"·tabindex="0"·
0003bd60:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003bd60:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003bd70:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003bd70:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003bd80:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003bd80:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003bd90:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003bd90:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003bda0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003bda0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003bdb0:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
0003bdc0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003bdd0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003bde0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003bdf0:·2220·6964·3d22·6964·6d36·3933·3422·3e3c··"·id="idm6934">< 
0003be00:·7072·653e·3c63·6f64·653e·0a23·2046·696e··pre><code>.#·Fin 
0003be10:·6420·7768·6963·6820·6669·6c65·7320·6861··d·which·files·ha 
0003be20:·7665·2069·6e63·6f72·7265·6374·2068·6173··ve·incorrect·has 
0003be30:·6820·286e·6f74·2069·6e20·2f65·7463·2c20··h·(not·in·/etc,· 
0003be40:·6265·6361·7573·6520·6f66·2074·6865·2073··because·of·the·s 
0003be50:·7973·7465·6d20·7265·6c61·7465·6420·636f··ystem·related·co 
0003be60:·6e66·6967·2066·696c·6573·2920·616e·6420··nfig·files)·and· 
0003be70:·7468·656e·2067·6574·2066·696c·6573·206e··then·get·files·n 
0003be80:·616d·6573·0a66·696c·6573·5f77·6974·685f··ames.files_with_ 
0003be90:·696e·636f·7272·6563·745f·6861·7368·3d22··incorrect_hash=" 
0003bea0:·2428·7270·6d20·2d56·6120·2d2d·6e6f·636f··$(rpm·-Va·--noco 
0003beb0:·6e66·6967·207c·2067·7265·7020·2d45·2027··nfig·|·grep·-E·' 
0003bec0:·5e2e·2e35·2720·7c20·6177·6b20·277b·7072··^..5'·|·awk·'{pr 
0003bed0:·696e·7420·244e·467d·2720·2922·0a0a·6966··int·$NF}'·)"..if 
0003bee0:·205b·202d·6e20·2224·6669·6c65·735f·7769···[·-n·"$files_wi 
0003bef0:·7468·5f69·6e63·6f72·7265·6374·5f68·6173··th_incorrect_has 
0003bf00:·6822·205d·3b20·7468·656e·0a20·2020·2023··h"·];·then.····# 
0003bf10:·2046·726f·6d20·6669·6c65·7320·6e61·6d65···From·files·name 
0003bf20:·7320·6765·7420·7061·636b·6167·6520·6e61··s·get·package·na 
0003bf30:·6d65·7320·616e·6420·6368·616e·6765·206e··mes·and·change·n 
0003bf40:·6577·6c69·6e65·2074·6f20·7370·6163·652c··ewline·to·space, 
0003bf50:·2062·6563·6175·7365·2072·706d·2077·7269···because·rpm·wri 
0003bf60:·7465·7320·6561·6368·2070·6163·6b61·6765··tes·each·package 
0003bf70:·2074·6f20·6e65·7720·6c69·6e65·0a20·2020···to·new·line.··· 
0003bf80:·2070·6163·6b61·6765·735f·746f·5f72·6569···packages_to_rei 
0003bf90:·6e73·7461·6c6c·3d22·2428·7270·6d20·2d71··nstall="$(rpm·-q 
0003bfa0:·6620·2466·696c·6573·5f77·6974·685f·696e··f·$files_with_in 
0003bfb0:·636f·7272·6563·745f·6861·7368·207c·2074··correct_hash·|·t 
0003bfc0:·7220·275c·6e27·2027·2027·2922·0a0a·2020··r·'\n'·'·')"..·· 
0003bfd0:·2020·0a20·2020·2064·6e66·2072·6569·6e73····.····dnf·reins 
0003bfe0:·7461·6c6c·202d·7920·2470·6163·6b61·6765··tall·-y·$package 
0003bff0:·735f·746f·5f72·6569·6e73·7461·6c6c·0a20··s_to_reinstall.· 
0003c000:·2020·200a·6669·0a3c·2f63·6f64·653e·3c2f·····.fi.</code></ 
0003c010:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003c020:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003c030:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003c040:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003c050:·2d74·6172·6765·743d·2223·6964·6d36·3933··-target="#idm693 
0003c060:·3522·2074·6162·696e·6465·783d·2230·2220··5"·tabindex="0"· 
0003c070:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003c080:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003c090:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003c0a0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003c0b0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003c0c0:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni0003bdb0:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni
0003c0d0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003bdc0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003c0e0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003bdd0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003c0f0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003bde0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003c100:·7073·6522·2069·643d·2269·646d·3639·3335··pse"·id="idm69350003bdf0:·7073·6522·2069·643d·2269·646d·3639·3334··pse"·id="idm6934
0003c110:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003be00:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003c120:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003be10:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003c130:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003be20:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003c140:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003be30:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003c150:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003be40:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003c160:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003be50:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003c170:·6869·6768·3c2f·7464·3e3c·2f74·723e·3c74··high</td></tr><t0003be60:·6869·6768·3c2f·7464·3e3c·2f74·723e·3c74··high</td></tr><t
0003c180:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003be70:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003c190:·3a3c·2f74·683e·3c74·643e·6d65·6469·756d··:</th><td>medium0003be80:·3a3c·2f74·683e·3c74·643e·6d65·6469·756d··:</th><td>medium
0003c1a0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003be90:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003c1b0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t0003bea0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
0003c1c0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr0003beb0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
0003c1d0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0003bec0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
0003c1e0:·793a·3c2f·7468·3e3c·7464·3e72·6573·7472··y:</th><td>restr0003bed0:·793a·3c2f·7468·3e3c·7464·3e72·6573·7472··y:</th><td>restr
0003c1f0:·6963·743c·2f74·643e·3c2f·7472·3e3c·2f74··ict</td></tr></t0003bee0:·6963·743c·2f74·643e·3c2f·7472·3e3c·2f74··ict</td></tr></t
0003c200:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003bef0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
0003c210:·2d20·6e61·6d65·3a20·2753·6574·2066·6163··-·name:·'Set·fac0003bf00:·2d20·6e61·6d65·3a20·2753·6574·2066·6163··-·name:·'Set·fac
0003c220:·743a·2050·6163·6b61·6765·206d·616e·6167··t:·Package·manag0003bf10:·743a·2050·6163·6b61·6765·206d·616e·6167··t:·Package·manag
0003c230:·6572·2072·6569·6e73·7461·6c6c·2063·6f6d··er·reinstall·com0003bf20:·6572·2072·6569·6e73·7461·6c6c·2063·6f6d··er·reinstall·com
0003c240:·6d61·6e64·270a·2020·7365·745f·6661·6374··mand'.··set_fact0003bf30:·6d61·6e64·270a·2020·7365·745f·6661·6374··mand'.··set_fact
0003c250:·3a0a·2020·2020·7061·636b·6167·655f·6d61··:.····package_ma0003bf40:·3a0a·2020·2020·7061·636b·6167·655f·6d61··:.····package_ma
0003c260:·6e61·6765·725f·7265·696e·7374·616c·6c5f··nager_reinstall_0003bf50:·6e61·6765·725f·7265·696e·7374·616c·6c5f··nager_reinstall_
0003c270:·636d·643a·2064·6e66·2072·6569·6e73·7461··cmd:·dnf·reinsta0003bf60:·636d·643a·2064·6e66·2072·6569·6e73·7461··cmd:·dnf·reinsta
0003c280:·6c6c·202d·790a·2020·7768·656e·3a20·616e··ll·-y.··when:·an0003bf70:·6c6c·202d·790a·2020·7768·656e·3a20·616e··ll·-y.··when:·an
0003c290:·7369·626c·655f·6469·7374·7269·6275·7469··sible_distributi0003bf80:·7369·626c·655f·6469·7374·7269·6275·7469··sible_distributi
0003c2a0:·6f6e·2069·6e20·5b20·2246·6564·6f72·6122··on·in·[·"Fedora"0003bf90:·6f6e·2069·6e20·5b20·2246·6564·6f72·6122··on·in·[·"Fedora"
0003c2b0:·2c20·2252·6564·4861·7422·2c20·2243·656e··,·"RedHat",·"Cen0003bfa0:·2c20·2252·6564·4861·7422·2c20·2243·656e··,·"RedHat",·"Cen
0003c2c0:·744f·5322·2c20·224f·7261·636c·654c·696e··tOS",·"OracleLin0003bfb0:·744f·5322·2c20·224f·7261·636c·654c·696e··tOS",·"OracleLin
0003c2d0:·7578·2220·5d0a·2020·7461·6773·3a0a·2020··ux"·].··tags:.··0003bfc0:·7578·2220·5d0a·2020·7461·6773·3a0a·2020··ux"·].··tags:.··
0003c2e0:·2d20·434a·4953·2d35·2e31·302e·342e·310a··-·CJIS-5.10.4.1.0003bfd0:·2d20·434a·4953·2d35·2e31·302e·342e·310a··-·CJIS-5.10.4.1.
0003c2f0:·2020·2d20·4e49·5354·2d38·3030·2d31·3731····-·NIST-800-1710003bfe0:·2020·2d20·4e49·5354·2d38·3030·2d31·3731····-·NIST-800-171
0003c300:·2d33·2e33·2e38·0a20·202d·204e·4953·542d··-3.3.8.··-·NIST-0003bff0:·2d33·2e33·2e38·0a20·202d·204e·4953·542d··-3.3.8.··-·NIST-
0003c310:·3830·302d·3137·312d·332e·342e·310a·2020··800-171-3.4.1.··0003c000:·3830·302d·3137·312d·332e·342e·310a·2020··800-171-3.4.1.··
0003c320:·2d20·4e49·5354·2d38·3030·2d35·332d·4155··-·NIST-800-53-AU0003c010:·2d20·4e49·5354·2d38·3030·2d35·332d·4155··-·NIST-800-53-AU
0003c330:·2d39·2833·290a·2020·2d20·4e49·5354·2d38··-9(3).··-·NIST-80003c020:·2d39·2833·290a·2020·2d20·4e49·5354·2d38··-9(3).··-·NIST-8
0003c340:·3030·2d35·332d·434d·2d36·2863·290a·2020··00-53-CM-6(c).··0003c030:·3030·2d35·332d·434d·2d36·2863·290a·2020··00-53-CM-6(c).··
0003c350:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM0003c040:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
0003c360:·2d36·2864·290a·2020·2d20·4e49·5354·2d38··-6(d).··-·NIST-80003c050:·2d36·2864·290a·2020·2d20·4e49·5354·2d38··-6(d).··-·NIST-8
0003c370:·3030·2d35·332d·5349·2d37·0a20·202d·204e··00-53-SI-7.··-·N0003c060:·3030·2d35·332d·5349·2d37·0a20·202d·204e··00-53-SI-7.··-·N
0003c380:·4953·542d·3830·302d·3533·2d53·492d·3728··IST-800-53-SI-7(0003c070:·4953·542d·3830·302d·3533·2d53·492d·3728··IST-800-53-SI-7(
0003c390:·3129·0a20·202d·204e·4953·542d·3830·302d··1).··-·NIST-800-0003c080:·3129·0a20·202d·204e·4953·542d·3830·302d··1).··-·NIST-800-
0003c3a0:·3533·2d53·492d·3728·3629·0a20·202d·2050··53-SI-7(6).··-·P0003c090:·3533·2d53·492d·3728·3629·0a20·202d·2050··53-SI-7(6).··-·P
0003c3b0:·4349·2d44·5353·2d52·6571·2d31·312e·350a··CI-DSS-Req-11.5.0003c0a0:·4349·2d44·5353·2d52·6571·2d31·312e·350a··CI-DSS-Req-11.5.
0003c3c0:·2020·2d20·5043·492d·4453·5376·342d·3131····-·PCI-DSSv4-110003c0b0:·2020·2d20·5043·492d·4453·5376·342d·3131····-·PCI-DSSv4-11
0003c3d0:·2e35·2e32·0a20·202d·2068·6967·685f·636f··.5.2.··-·high_co0003c0c0:·2e35·2e32·0a20·202d·2068·6967·685f·636f··.5.2.··-·high_co
0003c3e0:·6d70·6c65·7869·7479·0a20·202d·2068·6967··mplexity.··-·hig0003c0d0:·6d70·6c65·7869·7479·0a20·202d·2068·6967··mplexity.··-·hig
0003c3f0:·685f·7365·7665·7269·7479·0a20·202d·206d··h_severity.··-·m0003c0e0:·685f·7365·7665·7269·7479·0a20·202d·206d··h_severity.··-·m
0003c400:·6564·6975·6d5f·6469·7372·7570·7469·6f6e··edium_disruption0003c0f0:·6564·6975·6d5f·6469·7372·7570·7469·6f6e··edium_disruption
0003c410:·0a20·202d·206e·6f5f·7265·626f·6f74·5f6e··.··-·no_reboot_n0003c100:·0a20·202d·206e·6f5f·7265·626f·6f74·5f6e··.··-·no_reboot_n
0003c420:·6565·6465·640a·2020·2d20·7265·7374·7269··eeded.··-·restri0003c110:·6565·6465·640a·2020·2d20·7265·7374·7269··eeded.··-·restri
Max diff block lines reached; 10830895/10856617 bytes (99.76%) of diff not shown.
1.15 MB
html2text {}
    
Offset 63, 15 lines modifiedOffset 63, 15 lines modified
63 ··············Base63 ··············Base
64 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ism_o64 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ism_o
65 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*65 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
66 ····*·cpe:/o:redhat:enterprise_linux:1066 ····*·cpe:/o:redhat:enterprise_linux:10
67 ····*·cpe:/o:centos:centos:1067 ····*·cpe:/o:centos:centos:10
68 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*68 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
69 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8469 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
70 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)70 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
71 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*71 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
72 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s72 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
73 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e73 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
74 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l74 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
75 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g75 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
76 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s76 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
77 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s77 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 132, 27 lines modifiedOffset 132, 14 lines modified
132 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6132 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
133 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4133 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
134 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)134 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
135 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1135 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
136 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5136 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
137 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227137 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
138 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2138 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
140 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
141 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
142 if·[·-n·"$files_with_incorrect_hash"·];·then 
143 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
144 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
145 ····dnf·reinstall·-y·$packages_to_reinstall 
  
146 fi 
147 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
148 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
149 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
150 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
151 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
152 -·name:·'Set·fact:·Package·manager·reinstall·command'144 -·name:·'Set·fact:·Package·manager·reinstall·command'
153 ··set_fact:145 ··set_fact:
Offset 279, 14 lines modifiedOffset 266, 27 lines modified
279 ··-·PCI-DSSv4-11.5.2266 ··-·PCI-DSSv4-11.5.2
280 ··-·high_complexity267 ··-·high_complexity
281 ··-·high_severity268 ··-·high_severity
282 ··-·medium_disruption269 ··-·medium_disruption
283 ··-·no_reboot_needed270 ··-·no_reboot_needed
284 ··-·restrict_strategy271 ··-·restrict_strategy
285 ··-·rpm_verify_hashes272 ··-·rpm_verify_hashes
 273 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 274 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 275 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 276 if·[·-n·"$files_with_incorrect_hash"·];·then
 277 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 278 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 279 ····dnf·reinstall·-y·$packages_to_reinstall
  
 280 fi
286 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*281 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
287 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:282 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
288 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'283 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
289 run·the·following·command·to·determine·which·package·owns·it:284 run·the·following·command·to·determine·which·package·owns·it:
290 $·rpm·-qf·FILENAME285 $·rpm·-qf·FILENAME
291 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:286 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
292 $·sudo·rpm·--setugids·PACKAGENAME287 $·sudo·rpm·--setugids·PACKAGENAME
Offset 305, 40 lines modifiedOffset 305, 14 lines modified
305 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5305 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
306 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2306 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
307 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)307 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
308 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1308 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
309 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5309 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
310 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108310 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
311 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2311 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
312 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
313 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
314 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
315 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
316 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
317 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
318 declare·-A·SETPERMS_RPM_DICT 
  
319 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
320 #·is·expected·by·the·RPM·database 
321 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
322 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
323 do 
324 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
325 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
326 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
327 done 
  
328 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
329 #·correct·values 
330 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
331 do 
332 ········rpm·--setugids·"${RPM_PACKAGE}" 
333 done 
334 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8312 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
335 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high313 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
336 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium314 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
337 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false315 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
338 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict316 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
339 -·name:·Read·list·of·files·with·incorrect·ownership317 -·name:·Read·list·of·files·with·incorrect·ownership
340 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev318 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 413, 14 lines modifiedOffset 387, 40 lines modified
413 ··-·PCI-DSSv4-11.5.2387 ··-·PCI-DSSv4-11.5.2
414 ··-·high_complexity388 ··-·high_complexity
415 ··-·high_severity389 ··-·high_severity
416 ··-·medium_disruption390 ··-·medium_disruption
417 ··-·no_reboot_needed391 ··-·no_reboot_needed
418 ··-·restrict_strategy392 ··-·restrict_strategy
419 ··-·rpm_verify_ownership393 ··-·rpm_verify_ownership
 394 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 395 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 396 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 397 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 398 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 399 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 1193872/1201502 bytes (99.36%) of diff not shown.
11.5 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-ism_o_secret.html
    
Offset 14431, 15 lines modifiedOffset 14431, 15 lines modified
000385e0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu000385e0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
000385f0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<000385f0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00038600:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s00038600:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00038610:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00038610:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00038620:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00038620:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00038630:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00038630:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00038640:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00038640:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00038650:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).00038650:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
00038660:·2020·2020·2020·2020·2020·2020·2020·2020··················00038660:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038670:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00038670:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00038680:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00038680:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00038690:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00038690:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
000386a0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd000386a0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
000386b0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject000386b0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
000386c0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s000386c0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
Offset 15321, 301 lines modifiedOffset 15321, 301 lines modified
0003bd80:·7461·7267·6574·3d22·2369·646d·3639·3334··target="#idm69340003bd80:·7461·7267·6574·3d22·2369·646d·3639·3334··target="#idm6934
0003bd90:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003bd90:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003bda0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003bda0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003bdb0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003bdb0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003bdc0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003bdc0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003bdd0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003bdd0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003bde0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003bde0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003bdf0:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003be00:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003be10:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003be20:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003be30:·2069·643d·2269·646d·3639·3334·223e·3c70···id="idm6934"><p 
0003be40:·7265·3e3c·636f·6465·3e0a·2320·4669·6e64··re><code>.#·Find 
0003be50:·2077·6869·6368·2066·696c·6573·2068·6176···which·files·hav 
0003be60:·6520·696e·636f·7272·6563·7420·6861·7368··e·incorrect·hash 
0003be70:·2028·6e6f·7420·696e·202f·6574·632c·2062···(not·in·/etc,·b 
0003be80:·6563·6175·7365·206f·6620·7468·6520·7379··ecause·of·the·sy 
0003be90:·7374·656d·2072·656c·6174·6564·2063·6f6e··stem·related·con 
0003bea0:·6669·6720·6669·6c65·7329·2061·6e64·2074··fig·files)·and·t 
0003beb0:·6865·6e20·6765·7420·6669·6c65·7320·6e61··hen·get·files·na 
0003bec0:·6d65·730a·6669·6c65·735f·7769·7468·5f69··mes.files_with_i 
0003bed0:·6e63·6f72·7265·6374·5f68·6173·683d·2224··ncorrect_hash="$ 
0003bee0:·2872·706d·202d·5661·202d·2d6e·6f63·6f6e··(rpm·-Va·--nocon 
0003bef0:·6669·6720·7c20·6772·6570·202d·4520·275e··fig·|·grep·-E·'^ 
0003bf00:·2e2e·3527·207c·2061·776b·2027·7b70·7269··..5'·|·awk·'{pri 
0003bf10:·6e74·2024·4e46·7d27·2029·220a·0a69·6620··nt·$NF}'·)"..if· 
0003bf20:·5b20·2d6e·2022·2466·696c·6573·5f77·6974··[·-n·"$files_wit 
0003bf30:·685f·696e·636f·7272·6563·745f·6861·7368··h_incorrect_hash 
0003bf40:·2220·5d3b·2074·6865·6e0a·2020·2020·2320··"·];·then.····#· 
0003bf50:·4672·6f6d·2066·696c·6573·206e·616d·6573··From·files·names 
0003bf60:·2067·6574·2070·6163·6b61·6765·206e·616d···get·package·nam 
0003bf70:·6573·2061·6e64·2063·6861·6e67·6520·6e65··es·and·change·ne 
0003bf80:·776c·696e·6520·746f·2073·7061·6365·2c20··wline·to·space,· 
0003bf90:·6265·6361·7573·6520·7270·6d20·7772·6974··because·rpm·writ 
0003bfa0:·6573·2065·6163·6820·7061·636b·6167·6520··es·each·package· 
0003bfb0:·746f·206e·6577·206c·696e·650a·2020·2020··to·new·line.···· 
0003bfc0:·7061·636b·6167·6573·5f74·6f5f·7265·696e··packages_to_rein 
0003bfd0:·7374·616c·6c3d·2224·2872·706d·202d·7166··stall="$(rpm·-qf 
0003bfe0:·2024·6669·6c65·735f·7769·7468·5f69·6e63···$files_with_inc 
0003bff0:·6f72·7265·6374·5f68·6173·6820·7c20·7472··orrect_hash·|·tr 
0003c000:·2027·5c6e·2720·2720·2729·220a·0a20·2020···'\n'·'·')"..··· 
0003c010:·200a·2020·2020·646e·6620·7265·696e·7374···.····dnf·reinst 
0003c020:·616c·6c20·2d79·2024·7061·636b·6167·6573··all·-y·$packages 
0003c030:·5f74·6f5f·7265·696e·7374·616c·6c0a·2020··_to_reinstall.·· 
0003c040:·2020·0a66·690a·3c2f·636f·6465·3e3c·2f70····.fi.</code></p 
0003c050:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003c060:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003c070:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003c080:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003c090:·7461·7267·6574·3d22·2369·646d·3639·3335··target="#idm6935 
0003c0a0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003c0b0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003c0c0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003c0d0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003c0e0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003c0f0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003c100:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip0003bdf0:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip
0003c110:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003be00:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003c120:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003be10:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003c130:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003be20:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003c140:·7365·2220·6964·3d22·6964·6d36·3933·3522··se"·id="idm6935"0003be30:·7365·2220·6964·3d22·6964·6d36·3933·3422··se"·id="idm6934"
0003c150:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003be40:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003c160:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003be50:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003c170:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003be60:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003c180:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003be70:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003c190:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003be80:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003c1a0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e68··exity:</th><td>h0003be90:·6578·6974·793a·3c2f·7468·3e3c·7464·3e68··exity:</th><td>h
0003c1b0:·6967·683c·2f74·643e·3c2f·7472·3e3c·7472··igh</td></tr><tr0003bea0:·6967·683c·2f74·643e·3c2f·7472·3e3c·7472··igh</td></tr><tr
0003c1c0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003beb0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003c1d0:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<0003bec0:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<
0003c1e0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003bed0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c1f0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003bee0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003c200:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003bef0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003c210:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003bf00:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003c220:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri0003bf10:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri
0003c230:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta0003bf20:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta
0003c240:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-0003bf30:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-
0003c250:·206e·616d·653a·2027·5365·7420·6661·6374···name:·'Set·fact0003bf40:·206e·616d·653a·2027·5365·7420·6661·6374···name:·'Set·fact
0003c260:·3a20·5061·636b·6167·6520·6d61·6e61·6765··:·Package·manage0003bf50:·3a20·5061·636b·6167·6520·6d61·6e61·6765··:·Package·manage
0003c270:·7220·7265·696e·7374·616c·6c20·636f·6d6d··r·reinstall·comm0003bf60:·7220·7265·696e·7374·616c·6c20·636f·6d6d··r·reinstall·comm
0003c280:·616e·6427·0a20·2073·6574·5f66·6163·743a··and'.··set_fact:0003bf70:·616e·6427·0a20·2073·6574·5f66·6163·743a··and'.··set_fact:
0003c290:·0a20·2020·2070·6163·6b61·6765·5f6d·616e··.····package_man0003bf80:·0a20·2020·2070·6163·6b61·6765·5f6d·616e··.····package_man
0003c2a0:·6167·6572·5f72·6569·6e73·7461·6c6c·5f63··ager_reinstall_c0003bf90:·6167·6572·5f72·6569·6e73·7461·6c6c·5f63··ager_reinstall_c
0003c2b0:·6d64·3a20·646e·6620·7265·696e·7374·616c··md:·dnf·reinstal0003bfa0:·6d64·3a20·646e·6620·7265·696e·7374·616c··md:·dnf·reinstal
0003c2c0:·6c20·2d79·0a20·2077·6865·6e3a·2061·6e73··l·-y.··when:·ans0003bfb0:·6c20·2d79·0a20·2077·6865·6e3a·2061·6e73··l·-y.··when:·ans
0003c2d0:·6962·6c65·5f64·6973·7472·6962·7574·696f··ible_distributio0003bfc0:·6962·6c65·5f64·6973·7472·6962·7574·696f··ible_distributio
0003c2e0:·6e20·696e·205b·2022·4665·646f·7261·222c··n·in·[·"Fedora",0003bfd0:·6e20·696e·205b·2022·4665·646f·7261·222c··n·in·[·"Fedora",
0003c2f0:·2022·5265·6448·6174·222c·2022·4365·6e74···"RedHat",·"Cent0003bfe0:·2022·5265·6448·6174·222c·2022·4365·6e74···"RedHat",·"Cent
0003c300:·4f53·222c·2022·4f72·6163·6c65·4c69·6e75··OS",·"OracleLinu0003bff0:·4f53·222c·2022·4f72·6163·6c65·4c69·6e75··OS",·"OracleLinu
0003c310:·7822·205d·0a20·2074·6167·733a·0a20·202d··x"·].··tags:.··-0003c000:·7822·205d·0a20·2074·6167·733a·0a20·202d··x"·].··tags:.··-
0003c320:·2043·4a49·532d·352e·3130·2e34·2e31·0a20···CJIS-5.10.4.1.·0003c010:·2043·4a49·532d·352e·3130·2e34·2e31·0a20···CJIS-5.10.4.1.·
0003c330:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-0003c020:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
0003c340:·332e·332e·380a·2020·2d20·4e49·5354·2d38··3.3.8.··-·NIST-80003c030:·332e·332e·380a·2020·2d20·4e49·5354·2d38··3.3.8.··-·NIST-8
0003c350:·3030·2d31·3731·2d33·2e34·2e31·0a20·202d··00-171-3.4.1.··-0003c040:·3030·2d31·3731·2d33·2e34·2e31·0a20·202d··00-171-3.4.1.··-
0003c360:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-0003c050:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-
0003c370:·3928·3329·0a20·202d·204e·4953·542d·3830··9(3).··-·NIST-800003c060:·3928·3329·0a20·202d·204e·4953·542d·3830··9(3).··-·NIST-80
0003c380:·302d·3533·2d43·4d2d·3628·6329·0a20·202d··0-53-CM-6(c).··-0003c070:·302d·3533·2d43·4d2d·3628·6329·0a20·202d··0-53-CM-6(c).··-
0003c390:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-0003c080:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-
0003c3a0:·3628·6429·0a20·202d·204e·4953·542d·3830··6(d).··-·NIST-800003c090:·3628·6429·0a20·202d·204e·4953·542d·3830··6(d).··-·NIST-80
0003c3b0:·302d·3533·2d53·492d·370a·2020·2d20·4e49··0-53-SI-7.··-·NI0003c0a0:·302d·3533·2d53·492d·370a·2020·2d20·4e49··0-53-SI-7.··-·NI
0003c3c0:·5354·2d38·3030·2d35·332d·5349·2d37·2831··ST-800-53-SI-7(10003c0b0:·5354·2d38·3030·2d35·332d·5349·2d37·2831··ST-800-53-SI-7(1
0003c3d0:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-50003c0c0:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5
0003c3e0:·332d·5349·2d37·2836·290a·2020·2d20·5043··3-SI-7(6).··-·PC0003c0d0:·332d·5349·2d37·2836·290a·2020·2d20·5043··3-SI-7(6).··-·PC
0003c3f0:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·0003c0e0:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·
0003c400:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.0003c0f0:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.
0003c410:·352e·320a·2020·2d20·6869·6768·5f63·6f6d··5.2.··-·high_com0003c100:·352e·320a·2020·2d20·6869·6768·5f63·6f6d··5.2.··-·high_com
0003c420:·706c·6578·6974·790a·2020·2d20·6869·6768··plexity.··-·high0003c110:·706c·6578·6974·790a·2020·2d20·6869·6768··plexity.··-·high
0003c430:·5f73·6576·6572·6974·790a·2020·2d20·6d65··_severity.··-·me0003c120:·5f73·6576·6572·6974·790a·2020·2d20·6d65··_severity.··-·me
0003c440:·6469·756d·5f64·6973·7275·7074·696f·6e0a··dium_disruption.0003c130:·6469·756d·5f64·6973·7275·7074·696f·6e0a··dium_disruption.
0003c450:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne0003c140:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne
0003c460:·6564·6564·0a20·202d·2072·6573·7472·6963··eded.··-·restric0003c150:·6564·6564·0a20·202d·2072·6573·7472·6963··eded.··-·restric
Max diff block lines reached; 10830964/10856686 bytes (99.76%) of diff not shown.
1.15 MB
html2text {}
    
Offset 64, 15 lines modifiedOffset 64, 15 lines modified
64 ··············Secret64 ··············Secret
65 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ism_o_secret65 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ism_o_secret
66 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*66 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
67 ····*·cpe:/o:redhat:enterprise_linux:1067 ····*·cpe:/o:redhat:enterprise_linux:10
68 ····*·cpe:/o:centos:centos:1068 ····*·cpe:/o:centos:centos:10
69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
70 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8470 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
73 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s73 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
74 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e74 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
75 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l75 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
76 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g76 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
77 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s77 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
78 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s78 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 133, 27 lines modifiedOffset 133, 14 lines modified
133 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6133 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
134 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4134 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
135 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)135 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
136 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1136 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
137 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5137 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
138 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227138 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
139 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2139 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
141 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
142 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
143 if·[·-n·"$files_with_incorrect_hash"·];·then 
144 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
145 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
146 ····dnf·reinstall·-y·$packages_to_reinstall 
  
147 fi 
148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
149 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
150 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
151 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
152 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
153 -·name:·'Set·fact:·Package·manager·reinstall·command'145 -·name:·'Set·fact:·Package·manager·reinstall·command'
154 ··set_fact:146 ··set_fact:
Offset 280, 14 lines modifiedOffset 267, 27 lines modified
280 ··-·PCI-DSSv4-11.5.2267 ··-·PCI-DSSv4-11.5.2
281 ··-·high_complexity268 ··-·high_complexity
282 ··-·high_severity269 ··-·high_severity
283 ··-·medium_disruption270 ··-·medium_disruption
284 ··-·no_reboot_needed271 ··-·no_reboot_needed
285 ··-·restrict_strategy272 ··-·restrict_strategy
286 ··-·rpm_verify_hashes273 ··-·rpm_verify_hashes
 274 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 275 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 276 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 277 if·[·-n·"$files_with_incorrect_hash"·];·then
 278 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 279 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 280 ····dnf·reinstall·-y·$packages_to_reinstall
  
 281 fi
287 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*282 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
288 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:283 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
289 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'284 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
290 run·the·following·command·to·determine·which·package·owns·it:285 run·the·following·command·to·determine·which·package·owns·it:
291 $·rpm·-qf·FILENAME286 $·rpm·-qf·FILENAME
292 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:287 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
293 $·sudo·rpm·--setugids·PACKAGENAME288 $·sudo·rpm·--setugids·PACKAGENAME
Offset 306, 40 lines modifiedOffset 306, 14 lines modified
306 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5306 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
307 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2307 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
308 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)308 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
309 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1309 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
310 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5310 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
311 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108311 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
312 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2312 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
313 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
314 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
315 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
316 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
317 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
318 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
319 declare·-A·SETPERMS_RPM_DICT 
  
320 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
321 #·is·expected·by·the·RPM·database 
322 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
323 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
324 do 
325 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
326 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
327 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
328 done 
  
329 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
330 #·correct·values 
331 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
332 do 
333 ········rpm·--setugids·"${RPM_PACKAGE}" 
334 done 
335 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8313 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
336 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high314 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
337 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium315 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
338 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false316 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
339 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict317 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
340 -·name:·Read·list·of·files·with·incorrect·ownership318 -·name:·Read·list·of·files·with·incorrect·ownership
341 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev319 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 414, 14 lines modifiedOffset 388, 40 lines modified
414 ··-·PCI-DSSv4-11.5.2388 ··-·PCI-DSSv4-11.5.2
415 ··-·high_complexity389 ··-·high_complexity
416 ··-·high_severity390 ··-·high_severity
417 ··-·medium_disruption391 ··-·medium_disruption
418 ··-·no_reboot_needed392 ··-·no_reboot_needed
419 ··-·restrict_strategy393 ··-·restrict_strategy
420 ··-·rpm_verify_ownership394 ··-·rpm_verify_ownership
 395 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 396 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 397 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 398 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 399 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 400 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 1193872/1201511 bytes (99.36%) of diff not shown.
11.5 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-ism_o_top_secret.html
    
Offset 14428, 16 lines modifiedOffset 14428, 16 lines modified
000385b0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</000385b0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
000385c0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve000385c0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
000385d0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0000385d0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
000385e0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></000385e0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
000385f0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron000385f0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00038600:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00038600:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00038610:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00038610:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00038620:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600038620:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
00038630:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········00038630:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00038640:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00038640:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00038650:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00038650:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00038660:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00038660:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00038670:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00038670:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00038680:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00038680:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00038690:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00038690:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
000386a0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S000386a0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
Offset 15318, 301 lines modifiedOffset 15318, 301 lines modified
0003bd50:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003bd50:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003bd60:·2369·646d·3639·3334·2220·7461·6269·6e64··#idm6934"·tabind0003bd60:·2369·646d·3639·3334·2220·7461·6269·6e64··#idm6934"·tabind
0003bd70:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003bd70:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003bd80:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003bd80:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003bd90:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003bd90:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003bda0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003bda0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003bdb0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003bdb0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003bdc0:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel 
0003bdd0:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a> 
0003bde0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003bdf0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003be00:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003be10:·3639·3334·223e·3c70·7265·3e3c·636f·6465··6934"><pre><code 
0003be20:·3e0a·2320·4669·6e64·2077·6869·6368·2066··>.#·Find·which·f 
0003be30:·696c·6573·2068·6176·6520·696e·636f·7272··iles·have·incorr 
0003be40:·6563·7420·6861·7368·2028·6e6f·7420·696e··ect·hash·(not·in 
0003be50:·202f·6574·632c·2062·6563·6175·7365·206f···/etc,·because·o 
0003be60:·6620·7468·6520·7379·7374·656d·2072·656c··f·the·system·rel 
0003be70:·6174·6564·2063·6f6e·6669·6720·6669·6c65··ated·config·file 
0003be80:·7329·2061·6e64·2074·6865·6e20·6765·7420··s)·and·then·get· 
0003be90:·6669·6c65·7320·6e61·6d65·730a·6669·6c65··files·names.file 
0003bea0:·735f·7769·7468·5f69·6e63·6f72·7265·6374··s_with_incorrect 
0003beb0:·5f68·6173·683d·2224·2872·706d·202d·5661··_hash="$(rpm·-Va 
0003bec0:·202d·2d6e·6f63·6f6e·6669·6720·7c20·6772···--noconfig·|·gr 
0003bed0:·6570·202d·4520·275e·2e2e·3527·207c·2061··ep·-E·'^..5'·|·a 
0003bee0:·776b·2027·7b70·7269·6e74·2024·4e46·7d27··wk·'{print·$NF}' 
0003bef0:·2029·220a·0a69·6620·5b20·2d6e·2022·2466···)"..if·[·-n·"$f 
0003bf00:·696c·6573·5f77·6974·685f·696e·636f·7272··iles_with_incorr 
0003bf10:·6563·745f·6861·7368·2220·5d3b·2074·6865··ect_hash"·];·the 
0003bf20:·6e0a·2020·2020·2320·4672·6f6d·2066·696c··n.····#·From·fil 
0003bf30:·6573·206e·616d·6573·2067·6574·2070·6163··es·names·get·pac 
0003bf40:·6b61·6765·206e·616d·6573·2061·6e64·2063··kage·names·and·c 
0003bf50:·6861·6e67·6520·6e65·776c·696e·6520·746f··hange·newline·to 
0003bf60:·2073·7061·6365·2c20·6265·6361·7573·6520···space,·because· 
0003bf70:·7270·6d20·7772·6974·6573·2065·6163·6820··rpm·writes·each· 
0003bf80:·7061·636b·6167·6520·746f·206e·6577·206c··package·to·new·l 
0003bf90:·696e·650a·2020·2020·7061·636b·6167·6573··ine.····packages 
0003bfa0:·5f74·6f5f·7265·696e·7374·616c·6c3d·2224··_to_reinstall="$ 
0003bfb0:·2872·706d·202d·7166·2024·6669·6c65·735f··(rpm·-qf·$files_ 
0003bfc0:·7769·7468·5f69·6e63·6f72·7265·6374·5f68··with_incorrect_h 
0003bfd0:·6173·6820·7c20·7472·2027·5c6e·2720·2720··ash·|·tr·'\n'·'· 
0003bfe0:·2729·220a·0a20·2020·200a·2020·2020·646e··')"..····.····dn 
0003bff0:·6620·7265·696e·7374·616c·6c20·2d79·2024··f·reinstall·-y·$ 
0003c000:·7061·636b·6167·6573·5f74·6f5f·7265·696e··packages_to_rein 
0003c010:·7374·616c·6c0a·2020·2020·0a66·690a·3c2f··stall.····.fi.</ 
0003c020:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003c030:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003c040:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003c050:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003c060:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003c070:·2369·646d·3639·3335·2220·7461·6269·6e64··#idm6935"·tabind 
0003c080:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003c090:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003c0a0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003c0b0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003c0c0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003c0d0:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi0003bdc0:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi
0003c0e0:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...<0003bdd0:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...<
0003c0f0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003bde0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003c100:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003bdf0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003c110:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003be00:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
0003c120:·6964·6d36·3933·3522·3e3c·7461·626c·6520··idm6935"><table·0003be10:·6964·6d36·3933·3422·3e3c·7461·626c·6520··idm6934"><table·
0003c130:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003be20:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003c140:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003be30:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003c150:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003be40:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003c160:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003be50:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0003c170:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003be60:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0003c180:·7468·3e3c·7464·3e68·6967·683c·2f74·643e··th><td>high</td>0003be70:·7468·3e3c·7464·3e68·6967·683c·2f74·643e··th><td>high</td>
0003c190:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003be80:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003c1a0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003be90:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003c1b0:·3e6d·6564·6975·6d3c·2f74·643e·3c2f·7472··>medium</td></tr0003bea0:·3e6d·6564·6975·6d3c·2f74·643e·3c2f·7472··>medium</td></tr
0003c1c0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:0003beb0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
0003c1d0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</0003bec0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
0003c1e0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003bed0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003c1f0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003bee0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003c200:·643e·7265·7374·7269·6374·3c2f·7464·3e3c··d>restrict</td><0003bef0:·643e·7265·7374·7269·6374·3c2f·7464·3e3c··d>restrict</td><
0003c210:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0003bf00:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
0003c220:·3e3c·636f·6465·3e2d·206e·616d·653a·2027··><code>-·name:·'0003bf10:·3e3c·636f·6465·3e2d·206e·616d·653a·2027··><code>-·name:·'
0003c230:·5365·7420·6661·6374·3a20·5061·636b·6167··Set·fact:·Packag0003bf20:·5365·7420·6661·6374·3a20·5061·636b·6167··Set·fact:·Packag
0003c240:·6520·6d61·6e61·6765·7220·7265·696e·7374··e·manager·reinst0003bf30:·6520·6d61·6e61·6765·7220·7265·696e·7374··e·manager·reinst
0003c250:·616c·6c20·636f·6d6d·616e·6427·0a20·2073··all·command'.··s0003bf40:·616c·6c20·636f·6d6d·616e·6427·0a20·2073··all·command'.··s
0003c260:·6574·5f66·6163·743a·0a20·2020·2070·6163··et_fact:.····pac0003bf50:·6574·5f66·6163·743a·0a20·2020·2070·6163··et_fact:.····pac
0003c270:·6b61·6765·5f6d·616e·6167·6572·5f72·6569··kage_manager_rei0003bf60:·6b61·6765·5f6d·616e·6167·6572·5f72·6569··kage_manager_rei
0003c280:·6e73·7461·6c6c·5f63·6d64·3a20·646e·6620··nstall_cmd:·dnf·0003bf70:·6e73·7461·6c6c·5f63·6d64·3a20·646e·6620··nstall_cmd:·dnf·
0003c290:·7265·696e·7374·616c·6c20·2d79·0a20·2077··reinstall·-y.··w0003bf80:·7265·696e·7374·616c·6c20·2d79·0a20·2077··reinstall·-y.··w
0003c2a0:·6865·6e3a·2061·6e73·6962·6c65·5f64·6973··hen:·ansible_dis0003bf90:·6865·6e3a·2061·6e73·6962·6c65·5f64·6973··hen:·ansible_dis
0003c2b0:·7472·6962·7574·696f·6e20·696e·205b·2022··tribution·in·[·"0003bfa0:·7472·6962·7574·696f·6e20·696e·205b·2022··tribution·in·[·"
0003c2c0:·4665·646f·7261·222c·2022·5265·6448·6174··Fedora",·"RedHat0003bfb0:·4665·646f·7261·222c·2022·5265·6448·6174··Fedora",·"RedHat
0003c2d0:·222c·2022·4365·6e74·4f53·222c·2022·4f72··",·"CentOS",·"Or0003bfc0:·222c·2022·4365·6e74·4f53·222c·2022·4f72··",·"CentOS",·"Or
0003c2e0:·6163·6c65·4c69·6e75·7822·205d·0a20·2074··acleLinux"·].··t0003bfd0:·6163·6c65·4c69·6e75·7822·205d·0a20·2074··acleLinux"·].··t
0003c2f0:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5.0003bfe0:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5.
0003c300:·3130·2e34·2e31·0a20·202d·204e·4953·542d··10.4.1.··-·NIST-0003bff0:·3130·2e34·2e31·0a20·202d·204e·4953·542d··10.4.1.··-·NIST-
0003c310:·3830·302d·3137·312d·332e·332e·380a·2020··800-171-3.3.8.··0003c000:·3830·302d·3137·312d·332e·332e·380a·2020··800-171-3.3.8.··
0003c320:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-30003c010:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-3
0003c330:·2e34·2e31·0a20·202d·204e·4953·542d·3830··.4.1.··-·NIST-800003c020:·2e34·2e31·0a20·202d·204e·4953·542d·3830··.4.1.··-·NIST-80
0003c340:·302d·3533·2d41·552d·3928·3329·0a20·202d··0-53-AU-9(3).··-0003c030:·302d·3533·2d41·552d·3928·3329·0a20·202d··0-53-AU-9(3).··-
0003c350:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-0003c040:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-
0003c360:·3628·6329·0a20·202d·204e·4953·542d·3830··6(c).··-·NIST-800003c050:·3628·6329·0a20·202d·204e·4953·542d·3830··6(c).··-·NIST-80
0003c370:·302d·3533·2d43·4d2d·3628·6429·0a20·202d··0-53-CM-6(d).··-0003c060:·302d·3533·2d43·4d2d·3628·6429·0a20·202d··0-53-CM-6(d).··-
0003c380:·204e·4953·542d·3830·302d·3533·2d53·492d···NIST-800-53-SI-0003c070:·204e·4953·542d·3830·302d·3533·2d53·492d···NIST-800-53-SI-
0003c390:·370a·2020·2d20·4e49·5354·2d38·3030·2d35··7.··-·NIST-800-50003c080:·370a·2020·2d20·4e49·5354·2d38·3030·2d35··7.··-·NIST-800-5
0003c3a0:·332d·5349·2d37·2831·290a·2020·2d20·4e49··3-SI-7(1).··-·NI0003c090:·332d·5349·2d37·2831·290a·2020·2d20·4e49··3-SI-7(1).··-·NI
0003c3b0:·5354·2d38·3030·2d35·332d·5349·2d37·2836··ST-800-53-SI-7(60003c0a0:·5354·2d38·3030·2d35·332d·5349·2d37·2836··ST-800-53-SI-7(6
0003c3c0:·290a·2020·2d20·5043·492d·4453·532d·5265··).··-·PCI-DSS-Re0003c0b0:·290a·2020·2d20·5043·492d·4453·532d·5265··).··-·PCI-DSS-Re
0003c3d0:·712d·3131·2e35·0a20·202d·2050·4349·2d44··q-11.5.··-·PCI-D0003c0c0:·712d·3131·2e35·0a20·202d·2050·4349·2d44··q-11.5.··-·PCI-D
0003c3e0:·5353·7634·2d31·312e·352e·320a·2020·2d20··SSv4-11.5.2.··-·0003c0d0:·5353·7634·2d31·312e·352e·320a·2020·2d20··SSv4-11.5.2.··-·
0003c3f0:·6869·6768·5f63·6f6d·706c·6578·6974·790a··high_complexity.0003c0e0:·6869·6768·5f63·6f6d·706c·6578·6974·790a··high_complexity.
0003c400:·2020·2d20·6869·6768·5f73·6576·6572·6974····-·high_severit0003c0f0:·2020·2d20·6869·6768·5f73·6576·6572·6974····-·high_severit
0003c410:·790a·2020·2d20·6d65·6469·756d·5f64·6973··y.··-·medium_dis0003c100:·790a·2020·2d20·6d65·6469·756d·5f64·6973··y.··-·medium_dis
0003c420:·7275·7074·696f·6e0a·2020·2d20·6e6f·5f72··ruption.··-·no_r0003c110:·7275·7074·696f·6e0a·2020·2d20·6e6f·5f72··ruption.··-·no_r
Max diff block lines reached; 10813850/10855304 bytes (99.62%) of diff not shown.
1.15 MB
html2text {}
    
Offset 63, 15 lines modifiedOffset 63, 15 lines modified
63 ··············Top·Secret63 ··············Top·Secret
64 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ism_o_top_secret64 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ism_o_top_secret
65 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*65 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
66 ····*·cpe:/o:redhat:enterprise_linux:1066 ····*·cpe:/o:redhat:enterprise_linux:10
67 ····*·cpe:/o:centos:centos:1067 ····*·cpe:/o:centos:centos:10
68 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*68 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
69 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8469 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
70 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)70 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
71 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*71 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
72 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s72 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
73 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e73 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
74 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l74 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
75 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g75 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
76 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s76 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
77 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s77 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 132, 27 lines modifiedOffset 132, 14 lines modified
132 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6132 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
133 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4133 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
134 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)134 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
135 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1135 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
136 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5136 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
137 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227137 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
138 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2138 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
140 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
141 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
142 if·[·-n·"$files_with_incorrect_hash"·];·then 
143 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
144 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
145 ····dnf·reinstall·-y·$packages_to_reinstall 
  
146 fi 
147 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
148 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
149 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
150 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
151 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
152 -·name:·'Set·fact:·Package·manager·reinstall·command'144 -·name:·'Set·fact:·Package·manager·reinstall·command'
153 ··set_fact:145 ··set_fact:
Offset 279, 14 lines modifiedOffset 266, 27 lines modified
279 ··-·PCI-DSSv4-11.5.2266 ··-·PCI-DSSv4-11.5.2
280 ··-·high_complexity267 ··-·high_complexity
281 ··-·high_severity268 ··-·high_severity
282 ··-·medium_disruption269 ··-·medium_disruption
283 ··-·no_reboot_needed270 ··-·no_reboot_needed
284 ··-·restrict_strategy271 ··-·restrict_strategy
285 ··-·rpm_verify_hashes272 ··-·rpm_verify_hashes
 273 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 274 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 275 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 276 if·[·-n·"$files_with_incorrect_hash"·];·then
 277 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 278 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 279 ····dnf·reinstall·-y·$packages_to_reinstall
  
 280 fi
286 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*281 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
287 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:282 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
288 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'283 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
289 run·the·following·command·to·determine·which·package·owns·it:284 run·the·following·command·to·determine·which·package·owns·it:
290 $·rpm·-qf·FILENAME285 $·rpm·-qf·FILENAME
291 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:286 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
292 $·sudo·rpm·--setugids·PACKAGENAME287 $·sudo·rpm·--setugids·PACKAGENAME
Offset 305, 40 lines modifiedOffset 305, 14 lines modified
305 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5305 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
306 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2306 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
307 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)307 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
308 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1308 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
309 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5309 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
310 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108310 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
311 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2311 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
312 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
313 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
314 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
315 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
316 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
317 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
318 declare·-A·SETPERMS_RPM_DICT 
  
319 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
320 #·is·expected·by·the·RPM·database 
321 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
322 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
323 do 
324 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
325 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
326 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
327 done 
  
328 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
329 #·correct·values 
330 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
331 do 
332 ········rpm·--setugids·"${RPM_PACKAGE}" 
333 done 
334 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8312 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
335 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high313 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
336 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium314 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
337 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false315 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
338 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict316 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
339 -·name:·Read·list·of·files·with·incorrect·ownership317 -·name:·Read·list·of·files·with·incorrect·ownership
340 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev318 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 413, 14 lines modifiedOffset 387, 40 lines modified
413 ··-·PCI-DSSv4-11.5.2387 ··-·PCI-DSSv4-11.5.2
414 ··-·high_complexity388 ··-·high_complexity
415 ··-·high_severity389 ··-·high_severity
416 ··-·medium_disruption390 ··-·medium_disruption
417 ··-·no_reboot_needed391 ··-·no_reboot_needed
418 ··-·restrict_strategy392 ··-·restrict_strategy
419 ··-·rpm_verify_ownership393 ··-·rpm_verify_ownership
 394 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 395 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 396 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 397 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 398 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 399 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 1193872/1201519 bytes (99.36%) of diff not shown.
16.7 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-pci-dss.html
    
Offset 14421, 15 lines modifiedOffset 14421, 15 lines modified
00038540:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren00038540:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren
00038550:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro00038550:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro
00038560:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron00038560:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron
00038570:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s00038570:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s
00038580:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str00038580:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str
00038590:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········00038590:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········
000385a0:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·000385a0:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·
000385b0:·3230·3236·2d30·312d·3038·290a·2020·2020··2026-01-08).····000385b0:·3230·3234·2d31·322d·3037·290a·2020·2020··2024-12-07).····
000385c0:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li000385c0:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li
000385d0:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>000385d0:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>
000385e0:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content000385e0:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content
000385f0:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a000385f0:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a
00038600:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or00038600:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or
00038610:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con00038610:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con
00038620:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste00038620:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste
Offset 15299, 301 lines modifiedOffset 15299, 301 lines modified
0003bc20:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003bc20:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003bc30:·743d·2223·6964·6d36·3933·3422·2074·6162··t="#idm6934"·tab0003bc30:·743d·2223·6964·6d36·3933·3422·2074·6162··t="#idm6934"·tab
0003bc40:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003bc40:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003bc50:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003bc50:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003bc60:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003bc60:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003bc70:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003bc70:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003bc80:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003bc80:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003bc90:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
0003bca0:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
0003bcb0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003bcc0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003bcd0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003bce0:·6964·6d36·3933·3422·3e3c·7072·653e·3c63··idm6934"><pre><c 
0003bcf0:·6f64·653e·0a23·2046·696e·6420·7768·6963··ode>.#·Find·whic 
0003bd00:·6820·6669·6c65·7320·6861·7665·2069·6e63··h·files·have·inc 
0003bd10:·6f72·7265·6374·2068·6173·6820·286e·6f74··orrect·hash·(not 
0003bd20:·2069·6e20·2f65·7463·2c20·6265·6361·7573···in·/etc,·becaus 
0003bd30:·6520·6f66·2074·6865·2073·7973·7465·6d20··e·of·the·system· 
0003bd40:·7265·6c61·7465·6420·636f·6e66·6967·2066··related·config·f 
0003bd50:·696c·6573·2920·616e·6420·7468·656e·2067··iles)·and·then·g 
0003bd60:·6574·2066·696c·6573·206e·616d·6573·0a66··et·files·names.f 
0003bd70:·696c·6573·5f77·6974·685f·696e·636f·7272··iles_with_incorr 
0003bd80:·6563·745f·6861·7368·3d22·2428·7270·6d20··ect_hash="$(rpm· 
0003bd90:·2d56·6120·2d2d·6e6f·636f·6e66·6967·207c··-Va·--noconfig·| 
0003bda0:·2067·7265·7020·2d45·2027·5e2e·2e35·2720···grep·-E·'^..5'· 
0003bdb0:·7c20·6177·6b20·277b·7072·696e·7420·244e··|·awk·'{print·$N 
0003bdc0:·467d·2720·2922·0a0a·6966·205b·202d·6e20··F}'·)"..if·[·-n· 
0003bdd0:·2224·6669·6c65·735f·7769·7468·5f69·6e63··"$files_with_inc 
0003bde0:·6f72·7265·6374·5f68·6173·6822·205d·3b20··orrect_hash"·];· 
0003bdf0:·7468·656e·0a20·2020·2023·2046·726f·6d20··then.····#·From· 
0003be00:·6669·6c65·7320·6e61·6d65·7320·6765·7420··files·names·get· 
0003be10:·7061·636b·6167·6520·6e61·6d65·7320·616e··package·names·an 
0003be20:·6420·6368·616e·6765·206e·6577·6c69·6e65··d·change·newline 
0003be30:·2074·6f20·7370·6163·652c·2062·6563·6175···to·space,·becau 
0003be40:·7365·2072·706d·2077·7269·7465·7320·6561··se·rpm·writes·ea 
0003be50:·6368·2070·6163·6b61·6765·2074·6f20·6e65··ch·package·to·ne 
0003be60:·7720·6c69·6e65·0a20·2020·2070·6163·6b61··w·line.····packa 
0003be70:·6765·735f·746f·5f72·6569·6e73·7461·6c6c··ges_to_reinstall 
0003be80:·3d22·2428·7270·6d20·2d71·6620·2466·696c··="$(rpm·-qf·$fil 
0003be90:·6573·5f77·6974·685f·696e·636f·7272·6563··es_with_incorrec 
0003bea0:·745f·6861·7368·207c·2074·7220·275c·6e27··t_hash·|·tr·'\n' 
0003beb0:·2027·2027·2922·0a0a·2020·2020·0a20·2020···'·')"..····.··· 
0003bec0:·2064·6e66·2072·6569·6e73·7461·6c6c·202d···dnf·reinstall·- 
0003bed0:·7920·2470·6163·6b61·6765·735f·746f·5f72··y·$packages_to_r 
0003bee0:·6569·6e73·7461·6c6c·0a20·2020·200a·6669··einstall.····.fi 
0003bef0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003bf00:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003bf10:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003bf20:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003bf30:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003bf40:·743d·2223·6964·6d36·3933·3522·2074·6162··t="#idm6935"·tab 
0003bf50:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003bf60:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003bf70:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003bf80:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003bf90:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003bfa0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A0003bc90:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
0003bfb0:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.0003bca0:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.
0003bfc0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003bcb0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003bfd0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003bcc0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003bfe0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003bcd0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003bff0:·643d·2269·646d·3639·3335·223e·3c74·6162··d="idm6935"><tab0003bce0:·643d·2269·646d·3639·3334·223e·3c74·6162··d="idm6934"><tab
0003c000:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003bcf0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003c010:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003bd00:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003c020:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003bd10:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003c030:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003bd20:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003c040:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003bd30:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003c050:·3a3c·2f74·683e·3c74·643e·6869·6768·3c2f··:</th><td>high</0003bd40:·3a3c·2f74·683e·3c74·643e·6869·6768·3c2f··:</th><td>high</
0003c060:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003bd50:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003c070:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>0003bd60:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
0003c080:·3c74·643e·6d65·6469·756d·3c2f·7464·3e3c··<td>medium</td><0003bd70:·3c74·643e·6d65·6469·756d·3c2f·7464·3e3c··<td>medium</td><
0003c090:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo0003bd80:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
0003c0a0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals0003bd90:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
0003c0b0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><0003bda0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
0003c0c0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th0003bdb0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0003c0d0:·3e3c·7464·3e72·6573·7472·6963·743c·2f74··><td>restrict</t0003bdc0:·3e3c·7464·3e72·6573·7472·6963·743c·2f74··><td>restrict</t
0003c0e0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003bdd0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0003c0f0:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name0003bde0:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name
0003c100:·3a20·2753·6574·2066·6163·743a·2050·6163··:·'Set·fact:·Pac0003bdf0:·3a20·2753·6574·2066·6163·743a·2050·6163··:·'Set·fact:·Pac
0003c110:·6b61·6765·206d·616e·6167·6572·2072·6569··kage·manager·rei0003be00:·6b61·6765·206d·616e·6167·6572·2072·6569··kage·manager·rei
0003c120:·6e73·7461·6c6c·2063·6f6d·6d61·6e64·270a··nstall·command'.0003be10:·6e73·7461·6c6c·2063·6f6d·6d61·6e64·270a··nstall·command'.
0003c130:·2020·7365·745f·6661·6374·3a0a·2020·2020····set_fact:.····0003be20:·2020·7365·745f·6661·6374·3a0a·2020·2020····set_fact:.····
0003c140:·7061·636b·6167·655f·6d61·6e61·6765·725f··package_manager_0003be30:·7061·636b·6167·655f·6d61·6e61·6765·725f··package_manager_
0003c150:·7265·696e·7374·616c·6c5f·636d·643a·2064··reinstall_cmd:·d0003be40:·7265·696e·7374·616c·6c5f·636d·643a·2064··reinstall_cmd:·d
0003c160:·6e66·2072·6569·6e73·7461·6c6c·202d·790a··nf·reinstall·-y.0003be50:·6e66·2072·6569·6e73·7461·6c6c·202d·790a··nf·reinstall·-y.
0003c170:·2020·7768·656e·3a20·616e·7369·626c·655f····when:·ansible_0003be60:·2020·7768·656e·3a20·616e·7369·626c·655f····when:·ansible_
0003c180:·6469·7374·7269·6275·7469·6f6e·2069·6e20··distribution·in·0003be70:·6469·7374·7269·6275·7469·6f6e·2069·6e20··distribution·in·
0003c190:·5b20·2246·6564·6f72·6122·2c20·2252·6564··[·"Fedora",·"Red0003be80:·5b20·2246·6564·6f72·6122·2c20·2252·6564··[·"Fedora",·"Red
0003c1a0:·4861·7422·2c20·2243·656e·744f·5322·2c20··Hat",·"CentOS",·0003be90:·4861·7422·2c20·2243·656e·744f·5322·2c20··Hat",·"CentOS",·
0003c1b0:·224f·7261·636c·654c·696e·7578·2220·5d0a··"OracleLinux"·].0003bea0:·224f·7261·636c·654c·696e·7578·2220·5d0a··"OracleLinux"·].
0003c1c0:·2020·7461·6773·3a0a·2020·2d20·434a·4953····tags:.··-·CJIS0003beb0:·2020·7461·6773·3a0a·2020·2d20·434a·4953····tags:.··-·CJIS
0003c1d0:·2d35·2e31·302e·342e·310a·2020·2d20·4e49··-5.10.4.1.··-·NI0003bec0:·2d35·2e31·302e·342e·310a·2020·2d20·4e49··-5.10.4.1.··-·NI
0003c1e0:·5354·2d38·3030·2d31·3731·2d33·2e33·2e38··ST-800-171-3.3.80003bed0:·5354·2d38·3030·2d31·3731·2d33·2e33·2e38··ST-800-171-3.3.8
0003c1f0:·0a20·202d·204e·4953·542d·3830·302d·3137··.··-·NIST-800-170003bee0:·0a20·202d·204e·4953·542d·3830·302d·3137··.··-·NIST-800-17
0003c200:·312d·332e·342e·310a·2020·2d20·4e49·5354··1-3.4.1.··-·NIST0003bef0:·312d·332e·342e·310a·2020·2d20·4e49·5354··1-3.4.1.··-·NIST
0003c210:·2d38·3030·2d35·332d·4155·2d39·2833·290a··-800-53-AU-9(3).0003bf00:·2d38·3030·2d35·332d·4155·2d39·2833·290a··-800-53-AU-9(3).
0003c220:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-0003bf10:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
0003c230:·434d·2d36·2863·290a·2020·2d20·4e49·5354··CM-6(c).··-·NIST0003bf20:·434d·2d36·2863·290a·2020·2d20·4e49·5354··CM-6(c).··-·NIST
0003c240:·2d38·3030·2d35·332d·434d·2d36·2864·290a··-800-53-CM-6(d).0003bf30:·2d38·3030·2d35·332d·434d·2d36·2864·290a··-800-53-CM-6(d).
0003c250:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-0003bf40:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
0003c260:·5349·2d37·0a20·202d·204e·4953·542d·3830··SI-7.··-·NIST-800003bf50:·5349·2d37·0a20·202d·204e·4953·542d·3830··SI-7.··-·NIST-80
0003c270:·302d·3533·2d53·492d·3728·3129·0a20·202d··0-53-SI-7(1).··-0003bf60:·302d·3533·2d53·492d·3728·3129·0a20·202d··0-53-SI-7(1).··-
0003c280:·204e·4953·542d·3830·302d·3533·2d53·492d···NIST-800-53-SI-0003bf70:·204e·4953·542d·3830·302d·3533·2d53·492d···NIST-800-53-SI-
0003c290:·3728·3629·0a20·202d·2050·4349·2d44·5353··7(6).··-·PCI-DSS0003bf80:·3728·3629·0a20·202d·2050·4349·2d44·5353··7(6).··-·PCI-DSS
0003c2a0:·2d52·6571·2d31·312e·350a·2020·2d20·5043··-Req-11.5.··-·PC0003bf90:·2d52·6571·2d31·312e·350a·2020·2d20·5043··-Req-11.5.··-·PC
0003c2b0:·492d·4453·5376·342d·3131·2e35·2e32·0a20··I-DSSv4-11.5.2.·0003bfa0:·492d·4453·5376·342d·3131·2e35·2e32·0a20··I-DSSv4-11.5.2.·
0003c2c0:·202d·2068·6967·685f·636f·6d70·6c65·7869···-·high_complexi0003bfb0:·202d·2068·6967·685f·636f·6d70·6c65·7869···-·high_complexi
0003c2d0:·7479·0a20·202d·2068·6967·685f·7365·7665··ty.··-·high_seve0003bfc0:·7479·0a20·202d·2068·6967·685f·7365·7665··ty.··-·high_seve
0003c2e0:·7269·7479·0a20·202d·206d·6564·6975·6d5f··rity.··-·medium_0003bfd0:·7269·7479·0a20·202d·206d·6564·6975·6d5f··rity.··-·medium_
0003c2f0:·6469·7372·7570·7469·6f6e·0a20·202d·206e··disruption.··-·n0003bfe0:·6469·7372·7570·7469·6f6e·0a20·202d·206e··disruption.··-·n
0003c300:·6f5f·7265·626f·6f74·5f6e·6565·6465·640a··o_reboot_needed.0003bff0:·6f5f·7265·626f·6f74·5f6e·6565·6465·640a··o_reboot_needed.
Max diff block lines reached; 15819884/15861200 bytes (99.74%) of diff not shown.
1.53 MB
html2text {}
    
Offset 62, 15 lines modifiedOffset 62, 15 lines modified
62 ··············Linux·1062 ··············Linux·10
63 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss63 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss
64 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*64 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
65 ····*·cpe:/o:redhat:enterprise_linux:1065 ····*·cpe:/o:redhat:enterprise_linux:10
66 ····*·cpe:/o:centos:centos:1066 ····*·cpe:/o:centos:centos:10
67 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*67 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
68 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8468 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
69 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)69 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
70 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*70 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
71 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s71 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
72 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e72 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
73 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l73 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
74 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n74 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
75 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g75 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
76 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s76 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 129, 27 lines modifiedOffset 129, 14 lines modified
129 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6129 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
130 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4130 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
131 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)131 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
132 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1132 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
133 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5133 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
134 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227134 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
135 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2135 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
137 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
138 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
139 if·[·-n·"$files_with_incorrect_hash"·];·then 
140 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
141 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
142 ····dnf·reinstall·-y·$packages_to_reinstall 
  
143 fi 
144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
145 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
146 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
147 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
148 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
149 -·name:·'Set·fact:·Package·manager·reinstall·command'141 -·name:·'Set·fact:·Package·manager·reinstall·command'
150 ··set_fact:142 ··set_fact:
Offset 276, 14 lines modifiedOffset 263, 27 lines modified
276 ··-·PCI-DSSv4-11.5.2263 ··-·PCI-DSSv4-11.5.2
277 ··-·high_complexity264 ··-·high_complexity
278 ··-·high_severity265 ··-·high_severity
279 ··-·medium_disruption266 ··-·medium_disruption
280 ··-·no_reboot_needed267 ··-·no_reboot_needed
281 ··-·restrict_strategy268 ··-·restrict_strategy
282 ··-·rpm_verify_hashes269 ··-·rpm_verify_hashes
 270 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 271 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 272 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 273 if·[·-n·"$files_with_incorrect_hash"·];·then
 274 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 275 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 276 ····dnf·reinstall·-y·$packages_to_reinstall
  
 277 fi
283 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*278 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
284 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:279 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
285 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'280 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
286 run·the·following·command·to·determine·which·package·owns·it:281 run·the·following·command·to·determine·which·package·owns·it:
287 $·rpm·-qf·FILENAME282 $·rpm·-qf·FILENAME
288 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:283 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
289 $·sudo·rpm·--setugids·PACKAGENAME284 $·sudo·rpm·--setugids·PACKAGENAME
Offset 302, 40 lines modifiedOffset 302, 14 lines modified
302 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5302 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
303 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2303 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
304 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)304 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
305 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1305 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
306 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5306 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
307 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108307 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
308 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2308 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
309 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
310 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
311 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
312 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
313 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
314 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
315 declare·-A·SETPERMS_RPM_DICT 
  
316 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
317 #·is·expected·by·the·RPM·database 
318 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
319 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
320 do 
321 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
322 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
323 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
324 done 
  
325 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
326 #·correct·values 
327 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
328 do 
329 ········rpm·--setugids·"${RPM_PACKAGE}" 
330 done 
331 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8309 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
332 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high310 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
333 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium311 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
334 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false312 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
335 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict313 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
336 -·name:·Read·list·of·files·with·incorrect·ownership314 -·name:·Read·list·of·files·with·incorrect·ownership
337 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev315 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 410, 14 lines modifiedOffset 384, 40 lines modified
410 ··-·PCI-DSSv4-11.5.2384 ··-·PCI-DSSv4-11.5.2
411 ··-·high_complexity385 ··-·high_complexity
412 ··-·high_severity386 ··-·high_severity
413 ··-·medium_disruption387 ··-·medium_disruption
414 ··-·no_reboot_needed388 ··-·no_reboot_needed
415 ··-·restrict_strategy389 ··-·restrict_strategy
416 ··-·rpm_verify_ownership390 ··-·rpm_verify_ownership
 391 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 392 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 393 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 394 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 395 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 396 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 1592680/1600329 bytes (99.52%) of diff not shown.
34.0 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-stig.html
    
Offset 14416, 15 lines modifiedOffset 14416, 15 lines modified
000384f0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu000384f0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00038500:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00038500:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00038510:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s00038510:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00038520:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00038520:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00038530:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00038530:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00038540:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00038540:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00038550:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00038550:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00038560:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).00038560:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
00038570:·2020·2020·2020·2020·2020·2020·2020·2020··················00038570:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038580:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00038580:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00038590:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00038590:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
000385a0:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l000385a0:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
000385b0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd000385b0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
000385c0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject000385c0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
000385d0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s000385d0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
Offset 15213, 234 lines modifiedOffset 15213, 234 lines modified
0003b6c0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b6c0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003b6d0:·3732·3733·2220·7461·6269·6e64·6578·3d22··7273"·tabindex="0003b6d0:·3732·3733·2220·7461·6269·6e64·6578·3d22··7273"·tabindex="
0003b6e0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b6e0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003b6f0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b6f0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003b700:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003b700:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003b710:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003b710:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003b720:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003b720:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003b730:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s0003b730:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
0003b740:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003b740:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003b750:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003b750:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003b760:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003b760:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003b770:·6c61·7073·6522·2069·643d·2269·646d·3732··lapse"·id="idm720003b770:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003b780:·3733·223e·3c74·6162·6c65·2063·6c61·7373··73"><table·class0003b780:·3732·3733·223e·3c74·6162·6c65·2063·6c61··7273"><table·cla
0003b790:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003b790:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003b7a0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003b7a0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003b7b0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003b7b0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003b7c0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003b7c0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003b7d0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003b7d0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003b7e0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003b7e0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003b7f0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003b7f0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003b800:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003b800:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
0003b810:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003b810:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003b820:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>0003b820:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
0003b830:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><0003b830:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
0003b840:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003b840:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
0003b850:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0003b850:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003b860:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003b860:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0003b870:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl0003b870:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p
 0003b880:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid
0003b880:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide 
0003b890:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_ 
0003b8a0:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package 
0003b8b0:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e 
0003b8c0:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins 
0003b8d0:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.< 
0003b8e0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003b8f0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003b900:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003b910:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003b920:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003b930:·2223·6964·6d37·3237·3422·2074·6162·696e··"#idm7274"·tabin 
0003b940:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003b950:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003b960:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003b970:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003b980:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003b990:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
0003b9a0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
0003b9b0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b9c0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b9d0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b9e0:·6d37·3237·3422·3e3c·7461·626c·6520·636c··m7274"><table·cl 
0003b9f0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003ba00:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003ba10:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0003ba20:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0003ba30:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0003ba40:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003ba50:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003ba60:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
0003ba70:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003ba80:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
0003ba90:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
0003baa0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
0003bab0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
0003bac0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
0003bad0:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code># 
0003bae0:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is· 
0003baf0:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only· 
0003bb00:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf 
0003bb10:·6f72·6d73·0a69·6620·5b20·2120·2d66·202f··orms.if·[·!·-f·/ 
0003bb20:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am 
0003bb30:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/ 
0003bb40:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren 
0003bb50:·7620·5d3b·2074·6865·6e0a·0a69·6620·2120··v·];·then..if·!· 
0003bb60:·7270·6d20·2d71·202d·2d71·7569·6574·2022··rpm·-q·--quiet·" 
0003bb70:·6169·6465·2220·3b20·7468·656e·0a20·2020··aide"·;·then.··· 
0003bb80:·2064·6e66·2069·6e73·7461·6c6c·202d·7920···dnf·install·-y· 
0003bb90:·2261·6964·6522·0a66·690a·0a65·6c73·650a··"aide".fi..else. 
0003bba0:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e 
0003bbb0:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation 
0003bbc0:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab 
0003bbd0:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was· 
0003bbe0:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code> 
0003bbf0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003bc00:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003bc10:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003bc20:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003bc30:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7 
0003bc40:·3237·3522·2074·6162·696e·6465·783d·2230··275"·tabindex="0 
0003bc50:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003bc60:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003bc70:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003bc80:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003bc90:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003bca0:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s 
0003bcb0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003bcc0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003bcd0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003bce0:·6c61·7073·6522·2069·643d·2269·646d·3732··lapse"·id="idm72 
0003bcf0:·3735·223e·3c74·6162·6c65·2063·6c61·7373··75"><table·class 
0003bd00:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003bd10:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003bd20:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003bd30:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003bd40:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003bd50:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003bd60:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003bd70:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003bd80:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003bd90:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
Max diff block lines reached; 32773254/32805324 bytes (99.90%) of diff not shown.
2.74 MB
html2text {}
Max HTML report size reached
33.9 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-stig_gui.html
    
Offset 14416, 16 lines modifiedOffset 14416, 16 lines modified
000384f0:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><000384f0:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><
00038500:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio00038500:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio
00038510:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.700038510:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.7
00038520:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u00038520:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u
00038530:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr00038530:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr
00038540:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···00038540:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···
00038550:·2020·2020·2020·2020·2020·2020·2020·2020··················00038550:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038560:·2028·6173·206f·6620·3230·3236·2d30·312d···(as·of·2026-01-00038560:·2028·6173·206f·6620·3230·3234·2d31·322d···(as·of·2024-12-
00038570:·3038·290a·2020·2020·2020·2020·2020·2020··08).············00038570:·3037·290a·2020·2020·2020·2020·2020·2020··07).············
00038580:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></00038580:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></
00038590:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of00038590:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of
000385a0:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o000385a0:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o
000385b0:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#000385b0:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#
000385c0:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro000385c0:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro
000385d0:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro000385d0:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro
000385e0:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste000385e0:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste
Offset 15213, 234 lines modifiedOffset 15213, 234 lines modified
0003b6c0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b6c0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b6d0:·2369·646d·3732·3733·2220·7461·6269·6e64··#idm7273"·tabind0003b6d0:·2369·646d·3732·3733·2220·7461·6269·6e64··#idm7273"·tabind
0003b6e0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b6e0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b6f0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b6f0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b700:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b700:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b710:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b710:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b720:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b720:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b730:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp0003b730:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac
0003b740:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</0003b740:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...
0003b750:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003b750:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003b760:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003b760:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003b770:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003b770:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003b780:·646d·3732·3733·223e·3c74·6162·6c65·2063··dm7273"><table·c0003b780:·2269·646d·3732·3733·223e·3c74·6162·6c65··"idm7273"><table
0003b790:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003b790:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003b7a0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003b7a0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003b7b0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003b7b0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003b7c0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003b7c0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003b7d0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003b7d0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003b7e0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003b7e0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003b7f0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru0003b7f0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003b800:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l0003b800:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003b810:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003b810:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003b820:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>0003b820:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
0003b830:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></0003b830:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
0003b840:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0003b840:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003b850:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena0003b850:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003b860:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t0003b860:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003b870:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003b870:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003b880:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add
0003b880:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_ 
0003b890:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst 
0003b8a0:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac 
0003b8b0:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.· 
0003b8c0:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;· 
0003b8d0:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··} 
0003b8e0:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre> 
0003b8f0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003b900:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003b910:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003b920:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003b930:·6765·743d·2223·6964·6d37·3237·3422·2074··get="#idm7274"·t 
0003b940:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003b950:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003b960:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003b970:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003b980:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003b990:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003b9a0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
0003b9b0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b9c0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b9d0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b9e0:·3d22·6964·6d37·3237·3422·3e3c·7461·626c··="idm7274"><tabl 
0003b9f0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003ba00:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003ba10:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003ba20:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003ba30:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003ba40:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003ba50:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003ba60:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003ba70:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003ba80:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003ba90:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003baa0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003bab0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003bac0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003bad0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003bae0:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation 
0003baf0:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o 
0003bb00:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p 
0003bb10:·6c61·7466·6f72·6d73·0a69·6620·5b20·2120··latforms.if·[·!· 
0003bb20:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·] 
0003bb30:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!· 
0003bb40:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain 
0003bb50:·6572·656e·7620·5d3b·2074·6865·6e0a·0a69··erenv·];·then..i 
0003bb60:·6620·2120·7270·6d20·2d71·202d·2d71·7569··f·!·rpm·-q·--qui 
0003bb70:·6574·2022·6169·6465·2220·3b20·7468·656e··et·"aide"·;·then 
0003bb80:·0a20·2020·2064·6e66·2069·6e73·7461·6c6c··.····dnf·install 
0003bb90:·202d·7920·2261·6964·6522·0a66·690a·0a65···-y·"aide".fi..e 
0003bba0:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp 
0003bbb0:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia 
0003bbc0:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl 
0003bbd0:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing· 
0003bbe0:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c 
0003bbf0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003bc00:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003bc10:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003bc20:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003bc30:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003bc40:·6964·6d37·3237·3522·2074·6162·696e·6465··idm7275"·tabinde 
0003bc50:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003bc60:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003bc70:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003bc80:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003bc90:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003bca0:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib 
0003bcb0:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</ 
0003bcc0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003bcd0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003bce0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003bcf0:·646d·3732·3735·223e·3c74·6162·6c65·2063··dm7275"><table·c 
0003bd00:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003bd10:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003bd20:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003bd30:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003bd40:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003bd50:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003bd60:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003bd70:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003bd80:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
Max diff block lines reached; 32682498/32714706 bytes (99.90%) of diff not shown.
2.73 MB
html2text {}
Max HTML report size reached
23.0 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-anssi_bp28_enhanced.html
    
Offset 14430, 15 lines modifiedOffset 14430, 15 lines modified
000385d0:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr000385d0:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr
000385e0:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st000385e0:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st
000385f0:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str000385f0:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str
00038600:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>00038600:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>
00038610:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s00038610:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s
00038620:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········00038620:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········
00038630:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o00038630:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o
00038640:·6620·3230·3236·2d30·312d·3038·290a·2020··f·2026-01-08).··00038640:·6620·3230·3234·2d31·322d·3037·290a·2020··f·2024-12-07).··
00038650:·2020·2020·2020·2020·2020·2020·2020·3c2f················</00038650:·2020·2020·2020·2020·2020·2020·2020·3c2f················</
00038660:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h00038660:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h
00038670:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte00038670:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte
00038680:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>00038680:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>
00038690:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_00038690:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_
000386a0:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c000386a0:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c
000386b0:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys000386b0:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys
Offset 15182, 236 lines modifiedOffset 15182, 236 lines modified
0003b4d0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003b4d0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003b4e0:·6d38·3432·3822·2074·6162·696e·6465·783d··m8428"·tabindex=0003b4e0:·6d38·3432·3822·2074·6162·696e·6465·783d··m8428"·tabindex=
0003b4f0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003b4f0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003b500:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003b500:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003b510:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003b510:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003b520:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003b520:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003b530:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003b530:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003b540:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·0003b540:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond
0003b550:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003b550:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a
0003b560:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003b560:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003b570:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003b570:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003b580:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm80003b580:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003b590:·3432·3822·3e3c·7461·626c·6520·636c·6173··428"><table·clas0003b590:·6d38·3432·3822·3e3c·7461·626c·6520·636c··m8428"><table·cl
0003b5a0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003b5a0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003b5b0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003b5b0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003b5c0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003b5c0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003b5d0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003b5d0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003b5e0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003b5e0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003b5f0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003b5f0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003b600:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003b600:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003b610:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003b610:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0003b620:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b620:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003b630:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003b630:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
0003b640:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003b640:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
0003b650:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003b650:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003b660:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003b660:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003b670:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003b670:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003b680:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc0003b680:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.
 0003b690:·7061·636b·6167·6520·2d2d·6164·643d·6169··package·--add=ai
 0003b6a0:·6465·0a3c·2f63·6f64·653e·3c2f·7072·653e··de.</code></pre>
0003b690:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid 
0003b6a0:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install 
0003b6b0:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag 
0003b6c0:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.···· 
0003b6d0:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in 
0003b6e0:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}. 
0003b6f0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003b700:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003b710:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003b720:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003b730:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003b740:·3d22·2369·646d·3834·3239·2220·7461·6269··="#idm8429"·tabi 
0003b750:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003b760:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003b770:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003b780:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003b790:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003b7a0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
0003b7b0:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</ 
0003b7c0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003b7d0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003b7e0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003b7f0:·646d·3834·3239·223e·3c74·6162·6c65·2063··dm8429"><table·c 
0003b800:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003b810:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003b820:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003b830:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003b840:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003b850:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b860:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003b870:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003b880:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b890:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003b8a0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0003b8b0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003b8c0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003b8d0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003b8e0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003b8f0:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is 
0003b900:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only 
0003b910:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat 
0003b920:·666f·726d·730a·6966·205b·2021·202d·6620··forms.if·[·!·-f· 
0003b930:·2f2e·646f·636b·6572·656e·7620·5d20·2661··/.dockerenv·]·&a 
0003b940:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f· 
0003b950:·2f72·756e·2f2e·636f·6e74·6169·6e65·7265··/run/.containere 
0003b960:·6e76·205d·3b20·7468·656e·0a0a·6966·2021··nv·];·then..if·! 
0003b970:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet· 
0003b980:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.·· 
0003b990:·2020·646e·6620·696e·7374·616c·6c20·2d79····dnf·install·-y 
0003b9a0:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else 
0003b9b0:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2· 
0003b9c0:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio 
0003b9d0:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica 
0003b9e0:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was 
0003b9f0:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code 
0003ba00:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003ba10:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003ba20:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003ba30:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003ba40:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003ba50:·3834·3330·2220·7461·6269·6e64·6578·3d22··8430"·tabindex=" 
0003ba60:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003ba70:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003ba80:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003ba90:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003baa0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003bab0:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible· 
0003bac0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003bad0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003bae0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003baf0:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8 
0003bb00:·3433·3022·3e3c·7461·626c·6520·636c·6173··430"><table·clas 
0003bb10:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003bb20:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003bb30:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003bb40:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003bb50:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003bb60:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003bb70:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003bb80:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003bb90:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
Max diff block lines reached; 22033634/22065980 bytes (99.85%) of diff not shown.
1.92 MB
html2text {}
Max HTML report size reached
23.4 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-anssi_bp28_high.html
    
Offset 14429, 15 lines modifiedOffset 14429, 15 lines modified
000385c0:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr000385c0:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr
000385d0:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st000385d0:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st
000385e0:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str000385e0:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str
000385f0:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>000385f0:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>
00038600:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s00038600:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s
00038610:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········00038610:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········
00038620:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o00038620:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o
00038630:·6620·3230·3236·2d30·312d·3038·290a·2020··f·2026-01-08).··00038630:·6620·3230·3234·2d31·322d·3037·290a·2020··f·2024-12-07).··
00038640:·2020·2020·2020·2020·2020·2020·2020·3c2f················</00038640:·2020·2020·2020·2020·2020·2020·2020·3c2f················</
00038650:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h00038650:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h
00038660:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte00038660:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte
00038670:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>00038670:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>
00038680:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_00038680:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_
00038690:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c00038690:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c
000386a0:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys000386a0:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys
Offset 15187, 236 lines modifiedOffset 15187, 236 lines modified
0003b520:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b520:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b530:·2369·646d·3834·3238·2220·7461·6269·6e64··#idm8428"·tabind0003b530:·2369·646d·3834·3238·2220·7461·6269·6e64··#idm8428"·tabind
0003b540:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b540:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b550:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b550:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b560:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b560:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b570:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b570:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b580:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b580:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b590:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp0003b590:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac
0003b5a0:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</0003b5a0:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...
0003b5b0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003b5b0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003b5c0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003b5c0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003b5d0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003b5d0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003b5e0:·646d·3834·3238·223e·3c74·6162·6c65·2063··dm8428"><table·c0003b5e0:·2269·646d·3834·3238·223e·3c74·6162·6c65··"idm8428"><table
0003b5f0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003b5f0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003b600:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003b600:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003b610:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003b610:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003b620:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003b620:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003b630:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003b630:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003b640:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003b640:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003b650:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru0003b650:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003b660:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l0003b660:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003b670:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003b670:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003b680:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>0003b680:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
0003b690:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></0003b690:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
0003b6a0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0003b6a0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003b6b0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena0003b6b0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003b6c0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t0003b6c0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003b6d0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003b6d0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003b6e0:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add
 0003b6f0:·3d61·6964·650a·3c2f·636f·6465·3e3c·2f70··=aide.</code></p
 0003b700:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
 0003b710:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
 0003b720:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
 0003b730:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
 0003b740:·7461·7267·6574·3d22·2369·646d·3834·3239··target="#idm8429
 0003b750:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 0003b760:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 0003b770:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 0003b780:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 0003b790:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 0003b7a0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0003b7b0:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp
 0003b7c0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0003b7d0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003b7e0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003b7f0:·6522·2069·643d·2269·646d·3834·3239·223e··e"·id="idm8429">
 0003b800:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003b810:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003b820:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003b830:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003b840:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003b6e0:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_ 
0003b6f0:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst 
0003b700:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac 
0003b710:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.· 
0003b720:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;· 
0003b730:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··} 
0003b740:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre> 
0003b750:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003b760:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003b770:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003b780:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003b790:·6765·743d·2223·6964·6d38·3432·3922·2074··get="#idm8429"·t 
0003b7a0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003b7b0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003b7c0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003b7d0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003b7e0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003b7f0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003b800:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
0003b810:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b820:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b830:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b840:·3d22·6964·6d38·3432·3922·3e3c·7461·626c··="idm8429"><tabl 
0003b850:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003b860:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003b870:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003b880:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003b890:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003b8a0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b8b0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003b8c0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003b8d0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b8e0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003b8f0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003b900:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003b910:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003b850:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0003b920:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003b930:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003b940:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation 
0003b950:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o 
0003b960:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p 
0003b970:·6c61·7466·6f72·6d73·0a69·6620·5b20·2120··latforms.if·[·!· 
0003b980:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·] 
0003b990:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!· 
0003b9a0:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain 
0003b9b0:·6572·656e·7620·5d3b·2074·6865·6e0a·0a69··erenv·];·then..i 
0003b9c0:·6620·2120·7270·6d20·2d71·202d·2d71·7569··f·!·rpm·-q·--qui 
0003b9d0:·6574·2022·6169·6465·2220·3b20·7468·656e··et·"aide"·;·then 
0003b9e0:·0a20·2020·2064·6e66·2069·6e73·7461·6c6c··.····dnf·install 
0003b9f0:·202d·7920·2261·6964·6522·0a66·690a·0a65···-y·"aide".fi..e 
0003ba00:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp 
0003ba10:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia 
0003ba20:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl 
0003ba30:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing· 
0003ba40:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c 
0003ba50:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003ba60:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003ba70:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003ba80:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003ba90:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
Max diff block lines reached; 22452148/22484494 bytes (99.86%) of diff not shown.
1.97 MB
html2text {}
Max HTML report size reached
9.89 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-anssi_bp28_intermediary.html
    
Offset 14431, 15 lines modifiedOffset 14431, 15 lines modified
000385e0:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr000385e0:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr
000385f0:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st000385f0:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st
00038600:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str00038600:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str
00038610:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>00038610:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>
00038620:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s00038620:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s
00038630:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········00038630:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········
00038640:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o00038640:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o
00038650:·6620·3230·3236·2d30·312d·3038·290a·2020··f·2026-01-08).··00038650:·6620·3230·3234·2d31·322d·3037·290a·2020··f·2024-12-07).··
00038660:·2020·2020·2020·2020·2020·2020·2020·3c2f················</00038660:·2020·2020·2020·2020·2020·2020·2020·3c2f················</
00038670:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h00038670:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h
00038680:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte00038680:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte
00038690:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>00038690:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>
000386a0:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_000386a0:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_
000386b0:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c000386b0:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c
000386c0:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys000386c0:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys
Offset 15178, 235 lines modifiedOffset 15178, 235 lines modified
0003b490:·612d·7461·7267·6574·3d22·2369·646d·3834··a-target="#idm840003b490:·612d·7461·7267·6574·3d22·2369·646d·3834··a-target="#idm84
0003b4a0:·3238·2220·7461·6269·6e64·6578·3d22·3022··28"·tabindex="0"0003b4a0:·3238·2220·7461·6269·6e64·6578·3d22·3022··28"·tabindex="0"
0003b4b0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003b4b0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003b4c0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003b4c0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003b4d0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003b4d0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003b4e0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003b4e0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003b4f0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003b4f0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003b500:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni0003b500:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s
0003b510:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003b510:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003b520:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003b520:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003b530:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003b530:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003b540:·7073·6522·2069·643d·2269·646d·3834·3238··pse"·id="idm84280003b540:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm84
0003b550:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003b550:·3238·223e·3c74·6162·6c65·2063·6c61·7373··28"><table·class
0003b560:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003b560:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003b570:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003b570:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003b580:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003b580:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003b590:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003b590:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003b5a0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003b5a0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003b5b0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003b5b0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003b5c0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003b5c0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003b5d0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003b5d0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003b5e0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003b5e0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b5f0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003b5f0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0003b600:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003b600:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
0003b610:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003b610:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003b620:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003b620:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0003b630:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003b630:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003b640:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ0003b640:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 0003b650:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide.
 0003b660:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003b650:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide.. 
0003b660:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai 
0003b670:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{ 
0003b680:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens 
0003b690:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta 
0003b6a0:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c 
0003b6b0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003b6c0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003b6d0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003b6e0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003b6f0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003b700:·6964·6d38·3432·3922·2074·6162·696e·6465··idm8429"·tabinde 
0003b710:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003b720:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003b730:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003b740:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003b750:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003b760:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003b770:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003b780:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003b670:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0003b680:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0003b690:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0003b790:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b7a0:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8 
0003b7b0:·3432·3922·3e3c·7461·626c·6520·636c·6173··429"><table·clas 
0003b7c0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b7d0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b7e0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b7f0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b800:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b810:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b820:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b830:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b840:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b850:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b860:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003b870:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b880:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b890:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b8a0:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R 
0003b8b0:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003b8c0:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003b8d0:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003b8e0:·6d73·0a69·6620·5b20·2120·2d66·202f·2e64··ms.if·[·!·-f·/.d 
0003b8f0:·6f63·6b65·7265·6e76·205d·2026·616d·703b··ockerenv·]·&amp; 
0003b900:·2661·6d70·3b20·5b20·2120·2d66·202f·7275··&amp;·[·!·-f·/ru 
0003b910:·6e2f·2e63·6f6e·7461·696e·6572·656e·7620··n/.containerenv· 
0003b920:·5d3b·2074·6865·6e0a·0a69·6620·2120·7270··];·then..if·!·rp 
0003b930:·6d20·2d71·202d·2d71·7569·6574·2022·6169··m·-q·--quiet·"ai 
0003b940:·6465·2220·3b20·7468·656e·0a20·2020·2064··de"·;·then.····d 
0003b950:·6e66·2069·6e73·7461·6c6c·202d·7920·2261··nf·install·-y·"a 
0003b960:·6964·6522·0a66·690a·0a65·6c73·650a·2020··ide".fi..else.·· 
0003b970:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech 
0003b980:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i 
0003b990:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable 
0003b9a0:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do 
0003b9b0:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></ 
0003b9c0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003b9d0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003b9e0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle0003b6a0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0003b6b0:·3d22·2369·646d·3834·3239·2220·7461·6269··="#idm8429"·tabi
 0003b6c0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 0003b6d0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 0003b6e0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 0003b6f0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 0003b700:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 0003b710:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu
 0003b720:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...
 0003b730:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003b740:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003b750:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003b760:·2269·646d·3834·3239·223e·3c74·6162·6c65··"idm8429"><table
 0003b770:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003b780:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003b790:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003b7a0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003b7b0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 0003b7c0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003b7d0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003b7e0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003b9f0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
Max diff block lines reached; 9245020/9277228 bytes (99.65%) of diff not shown.
1.04 MB
html2text {}
    
Offset 63, 15 lines modifiedOffset 63, 15 lines modified
63 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(intermediary)63 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(intermediary)
64 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_intermediary64 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_intermediary
65 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*65 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
66 ····*·cpe:/o:redhat:enterprise_linux:966 ····*·cpe:/o:redhat:enterprise_linux:9
67 ····*·cpe:/o:centos:centos:967 ····*·cpe:/o:centos:centos:9
68 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*68 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
69 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8469 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
70 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)70 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
71 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*71 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
72 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s72 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
73 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e73 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
74 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l74 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
75 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n75 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
76 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s76 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
77 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s77 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 135, 41 lines modifiedOffset 135, 45 lines modified
135 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3135 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
136 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5136 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
137 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199137 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
138 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79138 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
139 ············_\x8c_\x8i_\x8s············6.1.1139 ············_\x8c_\x8i_\x8s············6.1.1
140 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2140 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
141 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule141 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule
 142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 147 package·--add=aide
142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low149 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low150 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false151 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable152 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
147 include·install_aide153 include·install_aide
  
148 class·install_aide·{154 class·install_aide·{
149 ··package·{·'aide':155 ··package·{·'aide':
150 ····ensure·=>·'installed',156 ····ensure·=>·'installed',
151 ··}157 ··}
152 }158 }
 159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 160 [[packages]]
 161 name·=·"aide"
 162 version·=·"*"
153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
154 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
155 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
156 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
157 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
158 #·Remediation·is·applicable·only·in·certain·platforms 
159 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
 168 package·install·aide
160 if·!·rpm·-q·--quiet·"aide"·;·then 
161 ····dnf·install·-y·"aide" 
162 fi 
  
163 else 
164 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
165 fi 
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
171 -·name:·Ensure·aide·is·installed174 -·name:·Ensure·aide·is·installed
172 ··package:175 ··package:
Offset 184, 33 lines modifiedOffset 188, 29 lines modified
184 ··-·PCI-DSSv4-11.5.2188 ··-·PCI-DSSv4-11.5.2
185 ··-·enable_strategy189 ··-·enable_strategy
186 ··-·low_complexity190 ··-·low_complexity
187 ··-·low_disruption191 ··-·low_disruption
188 ··-·medium_severity192 ··-·medium_severity
189 ··-·no_reboot_needed193 ··-·no_reboot_needed
190 ··-·package_aide_installed194 ··-·package_aide_installed
191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
192 [[packages]] 
193 name·=·"aide" 
194 version·=·"*" 
195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 200 #·Remediation·is·applicable·only·in·certain·platforms
 201 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 202 if·!·rpm·-q·--quiet·"aide"·;·then
 203 ····dnf·install·-y·"aide"
 204 fi
200 package·install·aide 
201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
206 package·--add=aide205 else
 206 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 207 fi
207 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*208 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
208 Run·the·following·command·to·generate·a·new·database:209 Run·the·following·command·to·generate·a·new·database:
209 $·sudo·/usr/sbin/aide·--init210 $·sudo·/usr/sbin/aide·--init
210 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the211 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
211 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these212 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
212 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their213 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
213 integrity.·The·newly-generated·database·can·be·installed·as·follows:214 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 235, 28 lines modifiedOffset 235, 14 lines modified
235 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3235 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
236 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5236 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
237 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199237 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
238 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79238 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
239 ············_\x8c_\x8i_\x8s············6.1.1239 ············_\x8c_\x8i_\x8s············6.1.1
240 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2240 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
241 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule241 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule
242 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
243 #·Remediation·is·applicable·only·in·certain·platforms 
244 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
245 if·!·rpm·-q·--quiet·"aide"·;·then 
246 ····dnf·install·-y·"aide" 
247 fi 
  
Max diff block lines reached; 1082481/1088458 bytes (99.45%) of diff not shown.
3.22 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-anssi_bp28_minimal.html
    
Offset 14430, 15 lines modifiedOffset 14430, 15 lines modified
000385d0:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·000385d0:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·
000385e0:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong000385e0:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong
000385f0:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>000385f0:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>
00038600:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str00038600:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str
00038610:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron00038610:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron
00038620:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············00038620:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············
00038630:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·2000038630:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·20
00038640:·3236·2d30·312d·3038·290a·2020·2020·2020··26-01-08).······00038640:·3234·2d31·322d·3037·290a·2020·2020·2020··24-12-07).······
00038650:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><00038650:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><
00038660:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta00038660:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta
00038670:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<00038670:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<
00038680:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h00038680:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h
00038690:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.00038690:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.
000386a0:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte000386a0:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte
000386b0:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"000386b0:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"
Offset 14849, 217 lines modifiedOffset 14849, 217 lines modified
0003a000:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003a000:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003a010:·3132·3538·3922·2074·6162·696e·6465·783d··12589"·tabindex=0003a010:·3132·3538·3922·2074·6162·696e·6465·783d··12589"·tabindex=
0003a020:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003a020:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003a030:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003a030:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003a040:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003a040:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003a050:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003a050:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003a060:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003a060:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003a070:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·0003a070:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond
 0003a080:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a
 0003a090:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003a0a0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003a0b0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003a0c0:·6d31·3235·3839·223e·3c74·6162·6c65·2063··m12589"><table·c
 0003a0d0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003a0e0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003a0f0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003a100:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003a110:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003a120:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003a130:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0003a140:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0003a150:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003a160:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003a170:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003a180:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003a190:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003a1a0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003a1b0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003a1c0:·0a70·6163·6b61·6765·202d·2d61·6464·3d64··.package·--add=d
 0003a1d0:·6e66·2d61·7574·6f6d·6174·6963·0a3c·2f63··nf-automatic.</c
 0003a1e0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003a1f0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003a200:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003a210:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 0003a220:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0003a230:·6964·6d31·3235·3930·2220·7461·6269·6e64··idm12590"·tabind
 0003a240:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003a250:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003a260:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003a270:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003a280:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003a290:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp
 0003a2a0:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</
 0003a2b0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003a2c0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003a2d0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003a2e0:·646d·3132·3539·3022·3e3c·7461·626c·6520··dm12590"><table·
 0003a2f0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003a300:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003a310:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003a320:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003a330:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003a340:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003a350:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 0003a360:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 0003a370:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003a380:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 0003a390:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
 0003a3a0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003a3b0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
 0003a3c0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 0003a3d0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003a3e0:·3e69·6e63·6c75·6465·2069·6e73·7461·6c6c··>include·install
 0003a3f0:·5f64·6e66·2d61·7574·6f6d·6174·6963·0a0a··_dnf-automatic..
 0003a400:·636c·6173·7320·696e·7374·616c·6c5f·646e··class·install_dn
 0003a410:·662d·6175·746f·6d61·7469·6320·7b0a·2020··f-automatic·{.··
 0003a420:·7061·636b·6167·6520·7b20·2764·6e66·2d61··package·{·'dnf-a
 0003a430:·7574·6f6d·6174·6963·273a·0a20·2020·2065··utomatic':.····e
 0003a440:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 0003a450:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 0003a460:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003a470:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003a480:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003a490:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0003a4a0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003a4b0:·2223·6964·6d31·3235·3931·2220·7461·6269··"#idm12591"·tabi
 0003a4c0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 0003a4d0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 0003a4e0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 0003a4f0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 0003a500:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 0003a510:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
 0003a520:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
0003a080:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003a530:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003a090:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003a540:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003a0a0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003a550:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003a0b0:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm10003a560:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1
 0003a570:·3235·3931·223e·3c70·7265·3e3c·636f·6465··2591"><pre><code
 0003a580:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n
 0003a590:·616d·6520·3d20·2264·6e66·2d61·7574·6f6d··ame·=·"dnf-autom
 0003a5a0:·6174·6963·220a·7665·7273·696f·6e20·3d20··atic".version·=·
0003a0c0:·3235·3839·223e·3c74·6162·6c65·2063·6c61··2589"><table·cla 
0003a0d0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003a0e0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003a0f0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003a100:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003a110:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003a120:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003a130:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003a140:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003a150:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003a160:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003a170:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003a180:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003a190:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003a1a0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003a1b0:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in 
0003a1c0:·636c·7564·6520·696e·7374·616c·6c5f·646e··clude·install_dn 
0003a1d0:·662d·6175·746f·6d61·7469·630a·0a63·6c61··f-automatic..cla 
0003a1e0:·7373·2069·6e73·7461·6c6c·5f64·6e66·2d61··ss·install_dnf-a 
0003a1f0:·7574·6f6d·6174·6963·207b·0a20·2070·6163··utomatic·{.··pac 
Max diff block lines reached; 3110347/3140071 bytes (99.05%) of diff not shown.
226 KB
html2text {}
    
Offset 63, 15 lines modifiedOffset 63, 15 lines modified
63 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(minimal)63 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(minimal)
64 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_minimal64 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_minimal
65 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*65 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
66 ····*·cpe:/o:redhat:enterprise_linux:966 ····*·cpe:/o:redhat:enterprise_linux:9
67 ····*·cpe:/o:centos:centos:967 ····*·cpe:/o:centos:centos:9
68 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*68 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
69 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8469 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
70 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)70 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
71 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*71 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
72 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s72 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
73 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e73 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
74 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l74 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
75 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s75 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
76 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s76 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
77 ·········1.·_\x8D_\x8H_\x8C_\x8P77 ·········1.·_\x8D_\x8H_\x8C_\x8P
Offset 100, 35 lines modifiedOffset 100, 45 lines modified
100 $·sudo·dnf·install·dnf-automatic100 $·sudo·dnf·install·dnf-automatic
101 Rationale:··dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade101 Rationale:··dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade
102 ············suitable·for·automatic,·regular·execution.102 ············suitable·for·automatic,·regular·execution.
103 Severity: ··medium103 Severity: ··medium
104 Rule·ID:····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed104 Rule·ID:····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
105 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080105 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
106 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61106 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
 107 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 108 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 109 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 110 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 111 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 112 package·--add=dnf-automatic
107 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8113 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
108 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low114 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
109 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low115 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
110 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false116 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
111 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable117 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
112 include·install_dnf-automatic118 include·install_dnf-automatic
  
113 class·install_dnf-automatic·{119 class·install_dnf-automatic·{
114 ··package·{·'dnf-automatic':120 ··package·{·'dnf-automatic':
115 ····ensure·=>·'installed',121 ····ensure·=>·'installed',
116 ··}122 ··}
117 }123 }
 124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 125 [[packages]]
 126 name·=·"dnf-automatic"
 127 version·=·"*"
118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 133 package·install·dnf-automatic
123 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then 
124 ····dnf·install·-y·"dnf-automatic" 
125 fi 
126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low135 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low136 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false137 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable138 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
131 -·name:·Ensure·dnf-automatic·is·installed139 -·name:·Ensure·dnf-automatic·is·installed
132 ··package:140 ··package:
Offset 137, 33 lines modifiedOffset 147, 23 lines modified
137 ··tags:147 ··tags:
138 ··-·enable_strategy148 ··-·enable_strategy
139 ··-·low_complexity149 ··-·low_complexity
140 ··-·low_disruption150 ··-·low_disruption
141 ··-·medium_severity151 ··-·medium_severity
142 ··-·no_reboot_needed152 ··-·no_reboot_needed
143 ··-·package_dnf-automatic_installed153 ··-·package_dnf-automatic_installed
144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
145 [[packages]] 
146 name·=·"dnf-automatic" 
147 version·=·"*" 
148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
149 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
150 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
151 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
152 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
153 package·install·dnf-automatic 
154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
159 package·--add=dnf-automatic159 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
 160 ····dnf·install·-y·"dnf-automatic"
 161 fi
160 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*162 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
161 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed163 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
162 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/164 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
163 automatic.conf.165 automatic.conf.
164 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation166 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
165 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and167 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
166 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in168 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 173, 14 lines modifiedOffset 173, 36 lines modified
173 Severity: ··medium173 Severity: ··medium
174 Rule·ID:····xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates174 Rule·ID:····xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates
175 ············_\x8i_\x8s_\x8m····0940,·1144,·1467,·1472,·1483,·1493,·1494,·1495175 ············_\x8i_\x8s_\x8m····0940,·1144,·1467,·1472,·1483,·1493,·1494,·1495
176 ············_\x8n_\x8i_\x8s_\x8t···SI-2(5),·CM-6(a),·SI-2(c)176 ············_\x8n_\x8i_\x8s_\x8t···SI-2(5),·CM-6(a),·SI-2(c)
177 References:·_\x8o_\x8s_\x8p_\x8p···FMT_SMF_EXT.1177 References:·_\x8o_\x8s_\x8p_\x8p···FMT_SMF_EXT.1
178 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080178 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
179 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61179 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
 180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···unknown
 185 -·name:·Configure·dnf-automatic·to·Install·Available·Updates·Automatically
 186 ··ini_file:
 187 ····dest:·/etc/dnf/automatic.conf
 188 ····section:·commands
 189 ····option:·apply_updates
 190 ····value:·'yes'
 191 ····create:·true
 192 ··tags:
 193 ··-·NIST-800-53-CM-6(a)
 194 ··-·NIST-800-53-SI-2(5)
 195 ··-·NIST-800-53-SI-2(c)
 196 ··-·dnf-automatic_apply_updates
 197 ··-·low_complexity
 198 ··-·medium_disruption
Max diff block lines reached; 225258/231046 bytes (97.49%) of diff not shown.
13.4 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-ccn_advanced.html
    
Offset 14416, 15 lines modifiedOffset 14416, 15 lines modified
000384f0:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C000384f0:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00038500:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00038500:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00038510:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</00038510:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
00038520:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00038520:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
00038530:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft00038530:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
00038540:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······00038540:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
00038550:·2020·2020·2020·2020·2020·2020·2020·2861················(a00038550:·2020·2020·2020·2020·2020·2020·2020·2861················(a
00038560:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)00038560:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
00038570:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00038570:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00038580:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div00038580:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
00038590:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co00038590:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
000385a0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><000385a0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
000385b0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc000385b0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
000385c0:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec000385c0:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
000385d0:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_000385d0:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 15226, 249 lines modifiedOffset 15226, 249 lines modified
0003b790:·7461·2d74·6172·6765·743d·2223·6964·6d39··ta-target="#idm90003b790:·7461·2d74·6172·6765·743d·2223·6964·6d39··ta-target="#idm9
0003b7a0:·3138·3722·2074·6162·696e·6465·783d·2230··187"·tabindex="00003b7a0:·3138·3722·2074·6162·696e·6465·783d·2230··187"·tabindex="0
0003b7b0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003b7b0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003b7c0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003b7c0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003b7d0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003b7d0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003b7e0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003b7e0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003b7f0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003b7f0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003b800:·6961·7469·6f6e·204b·7562·6572·6e65·7465··iation·Kubernete
 0003b810:·7320·736e·6970·7065·7420·e287·b23c·2f61··s·snippet·...</a
 0003b820:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003b830:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003b840:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003b850:·6d39·3138·3722·3e3c·7461·626c·6520·636c··m9187"><table·cl
 0003b860:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003b870:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003b800:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
0003b810:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003b820:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b830:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b840:·7365·2220·6964·3d22·6964·6d39·3138·3722··se"·id="idm9187" 
0003b850:·3e3c·7072·653e·3c63·6f64·653e·0a76·6172··><pre><code>.var 
0003b860:·5f73·7973·7465·6d5f·6372·7970·746f·5f70··_system_crypto_p 
0003b870:·6f6c·6963·793d·273c·6162·6272·2074·6974··olicy='<abbr·tit 
0003b880:·6c65·3d22·6672·6f6d·2050·726f·6669·6c65··le="from·Profile 
0003b890:·2f72·6566·696e·652d·7661·6c75·653a·2078··/refine-value:·x 
0003b8a0:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj 
0003b8b0:·6563·742e·636f·6e74·656e·745f·7661·6c75··ect.content_valu 
0003b8c0:·655f·7661·725f·7379·7374·656d·5f63·7279··e_var_system_cry 
0003b8d0:·7074·6f5f·706f·6c69·6379·223e·4445·4641··pto_policy">DEFA 
0003b8e0:·554c·543c·2f61·6262·723e·270a·0a0a·7374··ULT</abbr>'...st 
0003b8f0:·6465·7272·5f6f·665f·6361·6c6c·3d24·2875··derr_of_call=$(u 
0003b900:·7064·6174·652d·6372·7970·746f·2d70·6f6c··pdate-crypto-pol 
0003b910:·6963·6965·7320·2d2d·7365·7420·247b·7661··icies·--set·${va 
0003b920:·725f·7379·7374·656d·5f63·7279·7074·6f5f··r_system_crypto_ 
0003b930:·706f·6c69·6379·7d20·3226·6774·3b26·616d··policy}·2&gt;&am 
0003b940:·703b·3120·2667·743b·202f·6465·762f·6e75··p;1·&gt;·/dev/nu 
0003b950:·6c6c·290a·7263·3d24·3f0a·0a69·6620·7465··ll).rc=$?..if·te 
0003b960:·7374·2022·2472·6322·203d·2031·3237·3b20··st·"$rc"·=·127;· 
0003b970:·7468·656e·0a09·6563·686f·2022·2473·7464··then..echo·"$std 
0003b980:·6572·725f·6f66·5f63·616c·6c22·2026·6774··err_of_call"·&gt 
0003b990:·3b26·616d·703b·320a·0965·6368·6f20·224d··;&amp;2..echo·"M 
0003b9a0:·616b·6520·7375·7265·2074·6861·7420·7468··ake·sure·that·th 
0003b9b0:·6520·7363·7269·7074·2069·7320·696e·7374··e·script·is·inst 
0003b9c0:·616c·6c65·6420·6f6e·2074·6865·2072·656d··alled·on·the·rem 
0003b9d0:·6564·6961·7465·6420·7379·7374·656d·2e22··ediated·system." 
0003b9e0:·2026·6774·3b26·616d·703b·320a·0965·6368···&gt;&amp;2..ech 
0003b9f0:·6f20·2253·6565·206f·7574·7075·7420·6f66··o·"See·output·of 
0003ba00:·2074·6865·2027·646e·6620·7072·6f76·6964···the·'dnf·provid 
0003ba10:·6573·2075·7064·6174·652d·6372·7970·746f··es·update-crypto 
0003ba20:·2d70·6f6c·6963·6965·7327·2063·6f6d·6d61··-policies'·comma 
0003ba30:·6e64·2220·2667·743b·2661·6d70·3b32·0a09··nd"·&gt;&amp;2.. 
0003ba40:·6563·686f·2022·746f·2073·6565·2077·6861··echo·"to·see·wha 
0003ba50:·7420·7061·636b·6167·6520·746f·2028·7265··t·package·to·(re 
0003ba60:·2969·6e73·7461·6c6c·2220·2667·743b·2661··)install"·&gt;&a 
0003ba70:·6d70·3b32·0a0a·0966·616c·7365·2020·2320··mp;2...false··#· 
0003ba80:·656e·6420·7769·7468·2061·6e20·6572·726f··end·with·an·erro 
0003ba90:·7220·636f·6465·0a65·6c69·6620·7465·7374··r·code.elif·test 
0003baa0:·2022·2472·6322·2021·3d20·303b·2074·6865···"$rc"·!=·0;·the 
0003bab0:·6e0a·0965·6368·6f20·2245·7272·6f72·2069··n..echo·"Error·i 
0003bac0:·6e76·6f6b·696e·6720·7468·6520·7570·6461··nvoking·the·upda 
0003bad0:·7465·2d63·7279·7074·6f2d·706f·6c69·6369··te-crypto-polici 
0003bae0:·6573·2073·6372·6970·743a·2024·7374·6465··es·script:·$stde 
0003baf0:·7272·5f6f·665f·6361·6c6c·2220·2667·743b··rr_of_call"·&gt; 
0003bb00:·2661·6d70·3b32·0a09·6661·6c73·6520·2023··&amp;2..false··# 
0003bb10:·2065·6e64·2077·6974·6820·616e·2065·7272···end·with·an·err 
0003bb20:·6f72·2063·6f64·650a·6669·0a3c·2f63·6f64··or·code.fi.</cod 
0003bb30:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003bb40:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003bb50:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003bb60:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003bb70:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003bb80:·6d39·3138·3922·2074·6162·696e·6465·783d··m9189"·tabindex= 
0003bb90:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003bba0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003bbb0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003bbc0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003bbd0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003bbe0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible 
0003bbf0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003bc00:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003bc10:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003bc20:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003bc30:·3931·3839·223e·3c74·6162·6c65·2063·6c61··9189"><table·cla 
0003bc40:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003bc50:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003b880:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003b890:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003b8a0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003b8b0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b8c0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003b8d0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003b8e0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b8f0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
0003bc60:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003bc70:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003bc80:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003bc90:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003bca0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003bcb0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003bcc0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003bcd0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003bce0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr0003b900:·7464·3e74·7275·653c·2f74·643e·3c2f·7472··td>true</td></tr
0003bcf0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0003b910:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
0003bd00:·793a·3c2f·7468·3e3c·7464·3e72·6573·7472··y:</th><td>restr0003b920:·793a·3c2f·7468·3e3c·7464·3e72·6573·7472··y:</th><td>restr
0003bd10:·6963·743c·2f74·643e·3c2f·7472·3e3c·2f74··ict</td></tr></t0003b930:·6963·743c·2f74·643e·3c2f·7472·3e3c·2f74··ict</td></tr></t
0003bd20:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003b940:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003b950:·2d2d·2d0a·6170·6956·6572·7369·6f6e·3a20··---.apiVersion:·
 0003b960:·6d61·6368·696e·6563·6f6e·6669·6775·7261··machineconfigura
 0003b970:·7469·6f6e·2e6f·7065·6e73·6869·6674·2e69··tion.openshift.i
 0003b980:·6f2f·7631·0a6b·696e·643a·204d·6163·6869··o/v1.kind:·Machi
 0003b990:·6e65·436f·6e66·6967·0a73·7065·633a·0a20··neConfig.spec:.·
 0003b9a0:·2063·6f6e·6669·673a·0a20·2020·2069·676e···config:.····ign
Max diff block lines reached; 12808404/12842544 bytes (99.73%) of diff not shown.
1.1 MB
html2text {}
    
Offset 60, 15 lines modifiedOffset 60, 15 lines modified
60 ··············Linux·9·-·Advanced60 ··············Linux·9·-·Advanced
61 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ccn_advanced61 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ccn_advanced
62 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*62 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
63 ····*·cpe:/o:redhat:enterprise_linux:963 ····*·cpe:/o:redhat:enterprise_linux:9
64 ····*·cpe:/o:centos:centos:964 ····*·cpe:/o:centos:centos:9
65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
66 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8466 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
69 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s69 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
70 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e70 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
71 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l71 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
72 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n72 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
73 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s73 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
74 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s74 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 119, 33 lines modifiedOffset 119, 39 lines modified
119 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1119 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1
120 ············_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)120 ············_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)
121 References:·_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1121 References:·_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
122 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174122 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
123 ············_\x8c_\x8i_\x8s······1.6.1123 ············_\x8c_\x8i_\x8s······1.6.1
124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7
125 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule,·SV-258238r926701_rule,·SV-258241r926710_rule125 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule,·SV-258238r926701_rule,·SV-258241r926710_rule
126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
  
127 var_system_crypto_policy='DEFAULT' 
  
  
128 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
129 rc=$? 
  
130 if·test·"$rc"·=·127;·then 
131 »       echo·"$stderr_of_call"·>&2 
132 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
133 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
134 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
135 »       false··#·end·with·an·error·code 
136 elif·test·"$rc"·!=·0;·then 
137 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
138 »       false··#·end·with·an·error·code 
139 fi127 C.Co.om.mp.pl.le.ex.xi.it.ty.y:.:·low
 128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 131 ---
 132 apiVersion:·machineconfiguration.openshift.io/v1
 133 kind:·MachineConfig
 134 spec:
 135 ··config:
 136 ····ignition:
 137 ······version:·3.1.0
 138 ····systemd:
 139 ······units:
 140 ········-·name:·configure-crypto-policy.service
 141 ··········enabled:·true
 142 ··········contents:·|
 143 ············[Unit]
 144 ············Before=kubelet.service
 145 ············[Service]
 146 ············Type=oneshot
 147 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 148 ············RemainAfterExit=yes
 149 ············[Install]
 150 ············WantedBy=multi-user.target
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
145 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable156 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
146 ··set_fact:157 ··set_fact:
Offset 194, 39 lines modifiedOffset 200, 33 lines modified
194 ··-·PCI-DSSv4-2.2.7200 ··-·PCI-DSSv4-2.2.7
195 ··-·configure_crypto_policy201 ··-·configure_crypto_policy
196 ··-·high_severity202 ··-·high_severity
197 ··-·low_complexity203 ··-·low_complexity
198 ··-·low_disruption204 ··-·low_disruption
199 ··-·no_reboot_needed205 ··-·no_reboot_needed
200 ··-·restrict_strategy206 ··-·restrict_strategy
201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
  
 208 var_system_crypto_policy='DEFAULT'
  
  
 209 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null)
 210 rc=$?
  
 211 if·test·"$rc"·=·127;·then
 212 »       echo·"$stderr_of_call"·>&2
 213 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2
 214 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2
 215 »       echo·"to·see·what·package·to·(re)install"·>&2
  
 216 »       false··#·end·with·an·error·code
 217 elif·test·"$rc"·!=·0;·then
 218 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
 219 »       false··#·end·with·an·error·code
 220 fi
202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
206 --- 
207 apiVersion:·machineconfiguration.openshift.io/v1 
208 kind:·MachineConfig 
209 spec: 
210 ··config: 
211 ····ignition: 
212 ······version:·3.1.0 
213 ····systemd: 
214 ······units: 
215 ········-·name:·configure-crypto-policy.service 
216 ··········enabled:·true 
217 ··········contents:·| 
218 ············[Unit] 
219 ············Before=kubelet.service 
220 ············[Service] 
221 ············Type=oneshot 
222 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
223 ············RemainAfterExit=yes 
224 ············[Install] 
225 ············WantedBy=multi-user.target 
226 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*221 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
227 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.222 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
228 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.223 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
229 Severity: ··medium224 Severity: ··medium
Max diff block lines reached; 1152262/1158192 bytes (99.49%) of diff not shown.
9.19 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-ccn_basic.html
    
Offset 14415, 16 lines modifiedOffset 14415, 16 lines modified
000384e0:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>000384e0:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>
000384f0:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi000384f0:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi
00038500:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.00038500:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.
00038510:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><00038510:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><
00038520:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d00038520:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d
00038530:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··00038530:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··
00038540:·2020·2020·2020·2020·2020·2020·2020·2020··················00038540:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038550:·2020·2861·7320·6f66·2032·3032·362d·3031····(as·of·2026-0100038550:·2020·2861·7320·6f66·2032·3032·342d·3132····(as·of·2024-12
00038560:·2d30·3829·0a20·2020·2020·2020·2020·2020··-08).···········00038560:·2d30·3729·0a20·2020·2020·2020·2020·2020··-07).···········
00038570:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><00038570:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><
00038580:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o00038580:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o
00038590:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><00038590:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><
000385a0:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="000385a0:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="
000385b0:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr000385b0:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr
000385c0:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr000385c0:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr
000385d0:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst000385d0:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst
Offset 15186, 249 lines modifiedOffset 15186, 249 lines modified
0003b510:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b510:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003b520:·3931·3837·2220·7461·6269·6e64·6578·3d22··9187"·tabindex="0003b520:·3931·3837·2220·7461·6269·6e64·6578·3d22··9187"·tabindex="
0003b530:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b530:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003b540:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b540:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003b550:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003b550:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003b560:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003b560:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003b570:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003b570:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0003b580:·6469·6174·696f·6e20·4b75·6265·726e·6574··diation·Kubernet
0003b580:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003b590:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003b5a0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003b5b0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003b5c0:·7073·6522·2069·643d·2269·646d·3931·3837··pse"·id="idm9187 
0003b5d0:·223e·3c70·7265·3e3c·636f·6465·3e0a·7661··"><pre><code>.va 
0003b5e0:·725f·7379·7374·656d·5f63·7279·7074·6f5f··r_system_crypto_ 
0003b5f0:·706f·6c69·6379·3d27·3c61·6262·7220·7469··policy='<abbr·ti 
0003b600:·746c·653d·2266·726f·6d20·5072·6f66·696c··tle="from·Profil 
0003b610:·652f·7265·6669·6e65·2d76·616c·7565·3a20··e/refine-value:· 
0003b620:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro 
0003b630:·6a65·6374·2e63·6f6e·7465·6e74·5f76·616c··ject.content_val 
0003b640:·7565·5f76·6172·5f73·7973·7465·6d5f·6372··ue_var_system_cr 
0003b650:·7970·746f·5f70·6f6c·6963·7922·3e44·4546··ypto_policy">DEF 
0003b660:·4155·4c54·3c2f·6162·6272·3e27·0a0a·0a73··AULT</abbr>'...s 
0003b670:·7464·6572·725f·6f66·5f63·616c·6c3d·2428··tderr_of_call=$( 
0003b680:·7570·6461·7465·2d63·7279·7074·6f2d·706f··update-crypto-po 
0003b690:·6c69·6369·6573·202d·2d73·6574·2024·7b76··licies·--set·${v 
0003b6a0:·6172·5f73·7973·7465·6d5f·6372·7970·746f··ar_system_crypto 
0003b6b0:·5f70·6f6c·6963·797d·2032·2667·743b·2661··_policy}·2&gt;&a 
0003b6c0:·6d70·3b31·2026·6774·3b20·2f64·6576·2f6e··mp;1·&gt;·/dev/n 
0003b6d0:·756c·6c29·0a72·633d·243f·0a0a·6966·2074··ull).rc=$?..if·t 
0003b6e0:·6573·7420·2224·7263·2220·3d20·3132·373b··est·"$rc"·=·127; 
0003b6f0:·2074·6865·6e0a·0965·6368·6f20·2224·7374···then..echo·"$st 
0003b700:·6465·7272·5f6f·665f·6361·6c6c·2220·2667··derr_of_call"·&g 
0003b710:·743b·2661·6d70·3b32·0a09·6563·686f·2022··t;&amp;2..echo·" 
0003b720:·4d61·6b65·2073·7572·6520·7468·6174·2074··Make·sure·that·t 
0003b730:·6865·2073·6372·6970·7420·6973·2069·6e73··he·script·is·ins 
0003b740:·7461·6c6c·6564·206f·6e20·7468·6520·7265··talled·on·the·re 
0003b750:·6d65·6469·6174·6564·2073·7973·7465·6d2e··mediated·system. 
0003b760:·2220·2667·743b·2661·6d70·3b32·0a09·6563··"·&gt;&amp;2..ec 
0003b770:·686f·2022·5365·6520·6f75·7470·7574·206f··ho·"See·output·o 
0003b780:·6620·7468·6520·2764·6e66·2070·726f·7669··f·the·'dnf·provi 
0003b790:·6465·7320·7570·6461·7465·2d63·7279·7074··des·update-crypt 
0003b7a0:·6f2d·706f·6c69·6369·6573·2720·636f·6d6d··o-policies'·comm 
0003b7b0:·616e·6422·2026·6774·3b26·616d·703b·320a··and"·&gt;&amp;2. 
0003b7c0:·0965·6368·6f20·2274·6f20·7365·6520·7768··.echo·"to·see·wh 
0003b7d0:·6174·2070·6163·6b61·6765·2074·6f20·2872··at·package·to·(r 
0003b7e0:·6529·696e·7374·616c·6c22·2026·6774·3b26··e)install"·&gt;& 
0003b7f0:·616d·703b·320a·0a09·6661·6c73·6520·2023··amp;2...false··# 
0003b800:·2065·6e64·2077·6974·6820·616e·2065·7272···end·with·an·err 
0003b810:·6f72·2063·6f64·650a·656c·6966·2074·6573··or·code.elif·tes 
0003b820:·7420·2224·7263·2220·213d·2030·3b20·7468··t·"$rc"·!=·0;·th 
0003b830:·656e·0a09·6563·686f·2022·4572·726f·7220··en..echo·"Error· 
0003b840:·696e·766f·6b69·6e67·2074·6865·2075·7064··invoking·the·upd 
0003b850:·6174·652d·6372·7970·746f·2d70·6f6c·6963··ate-crypto-polic 
0003b860:·6965·7320·7363·7269·7074·3a20·2473·7464··ies·script:·$std 
0003b870:·6572·725f·6f66·5f63·616c·6c22·2026·6774··err_of_call"·&gt 
0003b880:·3b26·616d·703b·320a·0966·616c·7365·2020··;&amp;2..false·· 
0003b890:·2320·656e·6420·7769·7468·2061·6e20·6572··#·end·with·an·er 
0003b8a0:·726f·7220·636f·6465·0a66·690a·3c2f·636f··ror·code.fi.</co 
0003b8b0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003b8c0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003b8d0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003b8e0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003b8f0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003b900:·646d·3931·3839·2220·7461·6269·6e64·6578··dm9189"·tabindex 
0003b910:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003b920:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003b930:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003b940:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003b950:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003b960:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl 
0003b970:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a0003b590:·6573·2073·6e69·7070·6574·20e2·87b2·3c2f··es·snippet·...</
0003b980:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b990:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b9a0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b9b0:·6d39·3138·3922·3e3c·7461·626c·6520·636c··m9189"><table·cl 
0003b9c0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003b9d0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003b9e0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0003b9f0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0003ba00:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0003ba10:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003ba20:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003ba30:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
0003ba40:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003ba50:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><0003b5a0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003b5b0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003b5c0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003b5d0:·646d·3931·3837·223e·3c74·6162·6c65·2063··dm9187"><table·c
 0003b5e0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003b5f0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003b600:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003b610:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003b620:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003b630:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003b640:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0003b650:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0003b660:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003b670:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
0003ba60:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t0003b680:·3c74·643e·7472·7565·3c2f·7464·3e3c·2f74··<td>true</td></t
0003ba70:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate0003b690:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003ba80:·6779·3a3c·2f74·683e·3c74·643e·7265·7374··gy:</th><td>rest0003b6a0:·6779·3a3c·2f74·683e·3c74·643e·7265·7374··gy:</th><td>rest
0003ba90:·7269·6374·3c2f·7464·3e3c·2f74·723e·3c2f··rict</td></tr></0003b6b0:·7269·6374·3c2f·7464·3e3c·2f74·723e·3c2f··rict</td></tr></
0003baa0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003b6c0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003b6d0:·3e2d·2d2d·0a61·7069·5665·7273·696f·6e3a··>---.apiVersion:
 0003b6e0:·206d·6163·6869·6e65·636f·6e66·6967·7572···machineconfigur
 0003b6f0:·6174·696f·6e2e·6f70·656e·7368·6966·742e··ation.openshift.
 0003b700:·696f·2f76·310a·6b69·6e64·3a20·4d61·6368··io/v1.kind:·Mach
 0003b710:·696e·6543·6f6e·6669·670a·7370·6563·3a0a··ineConfig.spec:.
 0003b720:·2020·636f·6e66·6967·3a0a·2020·2020·6967····config:.····ig
Max diff block lines reached; 8737582/8771860 bytes (99.61%) of diff not shown.
843 KB
html2text {}
    
Offset 60, 15 lines modifiedOffset 60, 15 lines modified
60 ··············Linux·9·-·Basic60 ··············Linux·9·-·Basic
61 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ccn_basic61 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ccn_basic
62 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*62 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
63 ····*·cpe:/o:redhat:enterprise_linux:963 ····*·cpe:/o:redhat:enterprise_linux:9
64 ····*·cpe:/o:centos:centos:964 ····*·cpe:/o:centos:centos:9
65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
66 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8466 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
69 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s69 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
70 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e70 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
71 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l71 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
72 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n72 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
73 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s73 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
74 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s74 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 111, 33 lines modifiedOffset 111, 39 lines modified
111 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1111 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1
112 ············_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)112 ············_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)
113 References:·_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1113 References:·_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
114 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174114 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
115 ············_\x8c_\x8i_\x8s······1.6.1115 ············_\x8c_\x8i_\x8s······1.6.1
116 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7116 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7
117 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule,·SV-258238r926701_rule,·SV-258241r926710_rule117 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule,·SV-258238r926701_rule,·SV-258241r926710_rule
118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
  
119 var_system_crypto_policy='DEFAULT' 
  
  
120 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
121 rc=$? 
  
122 if·test·"$rc"·=·127;·then 
123 »       echo·"$stderr_of_call"·>&2 
124 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
125 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
126 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
127 »       false··#·end·with·an·error·code 
128 elif·test·"$rc"·!=·0;·then 
129 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
130 »       false··#·end·with·an·error·code 
131 fi119 C.Co.om.mp.pl.le.ex.xi.it.ty.y:.:·low
 120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 123 ---
 124 apiVersion:·machineconfiguration.openshift.io/v1
 125 kind:·MachineConfig
 126 spec:
 127 ··config:
 128 ····ignition:
 129 ······version:·3.1.0
 130 ····systemd:
 131 ······units:
 132 ········-·name:·configure-crypto-policy.service
 133 ··········enabled:·true
 134 ··········contents:·|
 135 ············[Unit]
 136 ············Before=kubelet.service
 137 ············[Service]
 138 ············Type=oneshot
 139 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 140 ············RemainAfterExit=yes
 141 ············[Install]
 142 ············WantedBy=multi-user.target
132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low144 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low145 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false146 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict147 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
137 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable148 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
138 ··set_fact:149 ··set_fact:
Offset 186, 39 lines modifiedOffset 192, 33 lines modified
186 ··-·PCI-DSSv4-2.2.7192 ··-·PCI-DSSv4-2.2.7
187 ··-·configure_crypto_policy193 ··-·configure_crypto_policy
188 ··-·high_severity194 ··-·high_severity
189 ··-·low_complexity195 ··-·low_complexity
190 ··-·low_disruption196 ··-·low_disruption
191 ··-·no_reboot_needed197 ··-·no_reboot_needed
192 ··-·restrict_strategy198 ··-·restrict_strategy
193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
  
 200 var_system_crypto_policy='DEFAULT'
  
  
 201 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null)
 202 rc=$?
  
 203 if·test·"$rc"·=·127;·then
 204 »       echo·"$stderr_of_call"·>&2
 205 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2
 206 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2
 207 »       echo·"to·see·what·package·to·(re)install"·>&2
  
 208 »       false··#·end·with·an·error·code
 209 elif·test·"$rc"·!=·0;·then
 210 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
 211 »       false··#·end·with·an·error·code
 212 fi
194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
198 --- 
199 apiVersion:·machineconfiguration.openshift.io/v1 
200 kind:·MachineConfig 
201 spec: 
202 ··config: 
203 ····ignition: 
204 ······version:·3.1.0 
205 ····systemd: 
206 ······units: 
207 ········-·name:·configure-crypto-policy.service 
208 ··········enabled:·true 
209 ··········contents:·| 
210 ············[Unit] 
211 ············Before=kubelet.service 
212 ············[Service] 
213 ············Type=oneshot 
214 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
215 ············RemainAfterExit=yes 
216 ············[Install] 
217 ············WantedBy=multi-user.target 
218 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*213 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
219 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.214 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
220 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.215 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
221 Severity: ··medium216 Severity: ··medium
Max diff block lines reached; 857746/863670 bytes (99.31%) of diff not shown.
10.6 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-ccn_intermediate.html
    
Offset 14417, 15 lines modifiedOffset 14417, 15 lines modified
00038500:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00038500:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00038510:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00038510:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00038520:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</00038520:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
00038530:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00038530:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
00038540:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft00038540:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
00038550:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······00038550:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
00038560:·2020·2020·2020·2020·2020·2020·2020·2861················(a00038560:·2020·2020·2020·2020·2020·2020·2020·2861················(a
00038570:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)00038570:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
00038580:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00038580:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00038590:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div00038590:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
000385a0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co000385a0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
000385b0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><000385b0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
000385c0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc000385c0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
000385d0:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec000385d0:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
000385e0:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_000385e0:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 15227, 249 lines modifiedOffset 15227, 249 lines modified
0003b7a0:·7461·2d74·6172·6765·743d·2223·6964·6d39··ta-target="#idm90003b7a0:·7461·2d74·6172·6765·743d·2223·6964·6d39··ta-target="#idm9
0003b7b0:·3138·3722·2074·6162·696e·6465·783d·2230··187"·tabindex="00003b7b0:·3138·3722·2074·6162·696e·6465·783d·2230··187"·tabindex="0
0003b7c0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003b7c0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003b7d0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003b7d0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003b7e0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003b7e0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003b7f0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003b7f0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003b800:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003b800:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003b810:·6961·7469·6f6e·204b·7562·6572·6e65·7465··iation·Kubernete
 0003b820:·7320·736e·6970·7065·7420·e287·b23c·2f61··s·snippet·...</a
 0003b830:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003b840:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003b850:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003b860:·6d39·3138·3722·3e3c·7461·626c·6520·636c··m9187"><table·cl
 0003b870:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003b880:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003b810:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
0003b820:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003b830:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b840:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b850:·7365·2220·6964·3d22·6964·6d39·3138·3722··se"·id="idm9187" 
0003b860:·3e3c·7072·653e·3c63·6f64·653e·0a76·6172··><pre><code>.var 
0003b870:·5f73·7973·7465·6d5f·6372·7970·746f·5f70··_system_crypto_p 
0003b880:·6f6c·6963·793d·273c·6162·6272·2074·6974··olicy='<abbr·tit 
0003b890:·6c65·3d22·6672·6f6d·2050·726f·6669·6c65··le="from·Profile 
0003b8a0:·2f72·6566·696e·652d·7661·6c75·653a·2078··/refine-value:·x 
0003b8b0:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj 
0003b8c0:·6563·742e·636f·6e74·656e·745f·7661·6c75··ect.content_valu 
0003b8d0:·655f·7661·725f·7379·7374·656d·5f63·7279··e_var_system_cry 
0003b8e0:·7074·6f5f·706f·6c69·6379·223e·4445·4641··pto_policy">DEFA 
0003b8f0:·554c·543c·2f61·6262·723e·270a·0a0a·7374··ULT</abbr>'...st 
0003b900:·6465·7272·5f6f·665f·6361·6c6c·3d24·2875··derr_of_call=$(u 
0003b910:·7064·6174·652d·6372·7970·746f·2d70·6f6c··pdate-crypto-pol 
0003b920:·6963·6965·7320·2d2d·7365·7420·247b·7661··icies·--set·${va 
0003b930:·725f·7379·7374·656d·5f63·7279·7074·6f5f··r_system_crypto_ 
0003b940:·706f·6c69·6379·7d20·3226·6774·3b26·616d··policy}·2&gt;&am 
0003b950:·703b·3120·2667·743b·202f·6465·762f·6e75··p;1·&gt;·/dev/nu 
0003b960:·6c6c·290a·7263·3d24·3f0a·0a69·6620·7465··ll).rc=$?..if·te 
0003b970:·7374·2022·2472·6322·203d·2031·3237·3b20··st·"$rc"·=·127;· 
0003b980:·7468·656e·0a09·6563·686f·2022·2473·7464··then..echo·"$std 
0003b990:·6572·725f·6f66·5f63·616c·6c22·2026·6774··err_of_call"·&gt 
0003b9a0:·3b26·616d·703b·320a·0965·6368·6f20·224d··;&amp;2..echo·"M 
0003b9b0:·616b·6520·7375·7265·2074·6861·7420·7468··ake·sure·that·th 
0003b9c0:·6520·7363·7269·7074·2069·7320·696e·7374··e·script·is·inst 
0003b9d0:·616c·6c65·6420·6f6e·2074·6865·2072·656d··alled·on·the·rem 
0003b9e0:·6564·6961·7465·6420·7379·7374·656d·2e22··ediated·system." 
0003b9f0:·2026·6774·3b26·616d·703b·320a·0965·6368···&gt;&amp;2..ech 
0003ba00:·6f20·2253·6565·206f·7574·7075·7420·6f66··o·"See·output·of 
0003ba10:·2074·6865·2027·646e·6620·7072·6f76·6964···the·'dnf·provid 
0003ba20:·6573·2075·7064·6174·652d·6372·7970·746f··es·update-crypto 
0003ba30:·2d70·6f6c·6963·6965·7327·2063·6f6d·6d61··-policies'·comma 
0003ba40:·6e64·2220·2667·743b·2661·6d70·3b32·0a09··nd"·&gt;&amp;2.. 
0003ba50:·6563·686f·2022·746f·2073·6565·2077·6861··echo·"to·see·wha 
0003ba60:·7420·7061·636b·6167·6520·746f·2028·7265··t·package·to·(re 
0003ba70:·2969·6e73·7461·6c6c·2220·2667·743b·2661··)install"·&gt;&a 
0003ba80:·6d70·3b32·0a0a·0966·616c·7365·2020·2320··mp;2...false··#· 
0003ba90:·656e·6420·7769·7468·2061·6e20·6572·726f··end·with·an·erro 
0003baa0:·7220·636f·6465·0a65·6c69·6620·7465·7374··r·code.elif·test 
0003bab0:·2022·2472·6322·2021·3d20·303b·2074·6865···"$rc"·!=·0;·the 
0003bac0:·6e0a·0965·6368·6f20·2245·7272·6f72·2069··n..echo·"Error·i 
0003bad0:·6e76·6f6b·696e·6720·7468·6520·7570·6461··nvoking·the·upda 
0003bae0:·7465·2d63·7279·7074·6f2d·706f·6c69·6369··te-crypto-polici 
0003baf0:·6573·2073·6372·6970·743a·2024·7374·6465··es·script:·$stde 
0003bb00:·7272·5f6f·665f·6361·6c6c·2220·2667·743b··rr_of_call"·&gt; 
0003bb10:·2661·6d70·3b32·0a09·6661·6c73·6520·2023··&amp;2..false··# 
0003bb20:·2065·6e64·2077·6974·6820·616e·2065·7272···end·with·an·err 
0003bb30:·6f72·2063·6f64·650a·6669·0a3c·2f63·6f64··or·code.fi.</cod 
0003bb40:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003bb50:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003bb60:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003bb70:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003bb80:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003bb90:·6d39·3138·3922·2074·6162·696e·6465·783d··m9189"·tabindex= 
0003bba0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003bbb0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003bbc0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003bbd0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003bbe0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003bbf0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible 
0003bc00:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003bc10:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003bc20:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003bc30:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003bc40:·3931·3839·223e·3c74·6162·6c65·2063·6c61··9189"><table·cla 
0003bc50:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003bc60:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003b890:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003b8a0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003b8b0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003b8c0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b8d0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003b8e0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003b8f0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b900:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
0003bc70:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003bc80:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003bc90:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003bca0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003bcb0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003bcc0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003bcd0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003bce0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003bcf0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr0003b910:·7464·3e74·7275·653c·2f74·643e·3c2f·7472··td>true</td></tr
0003bd00:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0003b920:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
0003bd10:·793a·3c2f·7468·3e3c·7464·3e72·6573·7472··y:</th><td>restr0003b930:·793a·3c2f·7468·3e3c·7464·3e72·6573·7472··y:</th><td>restr
0003bd20:·6963·743c·2f74·643e·3c2f·7472·3e3c·2f74··ict</td></tr></t0003b940:·6963·743c·2f74·643e·3c2f·7472·3e3c·2f74··ict</td></tr></t
0003bd30:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003b950:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003b960:·2d2d·2d0a·6170·6956·6572·7369·6f6e·3a20··---.apiVersion:·
 0003b970:·6d61·6368·696e·6563·6f6e·6669·6775·7261··machineconfigura
 0003b980:·7469·6f6e·2e6f·7065·6e73·6869·6674·2e69··tion.openshift.i
 0003b990:·6f2f·7631·0a6b·696e·643a·204d·6163·6869··o/v1.kind:·Machi
 0003b9a0:·6e65·436f·6e66·6967·0a73·7065·633a·0a20··neConfig.spec:.·
 0003b9b0:·2063·6f6e·6669·673a·0a20·2020·2069·676e···config:.····ign
Max diff block lines reached; 9980420/10014560 bytes (99.66%) of diff not shown.
1.01 MB
html2text {}
    
Offset 60, 15 lines modifiedOffset 60, 15 lines modified
60 ··············Linux·9·-·Intermediate60 ··············Linux·9·-·Intermediate
61 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ccn_intermediate61 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ccn_intermediate
62 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*62 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
63 ····*·cpe:/o:redhat:enterprise_linux:963 ····*·cpe:/o:redhat:enterprise_linux:9
64 ····*·cpe:/o:centos:centos:964 ····*·cpe:/o:centos:centos:9
65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
66 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8466 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
69 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s69 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
70 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e70 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
71 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l71 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
72 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n72 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
73 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s73 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
74 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s74 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 119, 33 lines modifiedOffset 119, 39 lines modified
119 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1119 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1
120 ············_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)120 ············_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)
121 References:·_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1121 References:·_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
122 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174122 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
123 ············_\x8c_\x8i_\x8s······1.6.1123 ············_\x8c_\x8i_\x8s······1.6.1
124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7
125 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule,·SV-258238r926701_rule,·SV-258241r926710_rule125 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule,·SV-258238r926701_rule,·SV-258241r926710_rule
126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
  
127 var_system_crypto_policy='DEFAULT' 
  
  
128 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
129 rc=$? 
  
130 if·test·"$rc"·=·127;·then 
131 »       echo·"$stderr_of_call"·>&2 
132 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
133 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
134 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
135 »       false··#·end·with·an·error·code 
136 elif·test·"$rc"·!=·0;·then 
137 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
138 »       false··#·end·with·an·error·code 
139 fi127 C.Co.om.mp.pl.le.ex.xi.it.ty.y:.:·low
 128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 131 ---
 132 apiVersion:·machineconfiguration.openshift.io/v1
 133 kind:·MachineConfig
 134 spec:
 135 ··config:
 136 ····ignition:
 137 ······version:·3.1.0
 138 ····systemd:
 139 ······units:
 140 ········-·name:·configure-crypto-policy.service
 141 ··········enabled:·true
 142 ··········contents:·|
 143 ············[Unit]
 144 ············Before=kubelet.service
 145 ············[Service]
 146 ············Type=oneshot
 147 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 148 ············RemainAfterExit=yes
 149 ············[Install]
 150 ············WantedBy=multi-user.target
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
145 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable156 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
146 ··set_fact:157 ··set_fact:
Offset 194, 39 lines modifiedOffset 200, 33 lines modified
194 ··-·PCI-DSSv4-2.2.7200 ··-·PCI-DSSv4-2.2.7
195 ··-·configure_crypto_policy201 ··-·configure_crypto_policy
196 ··-·high_severity202 ··-·high_severity
197 ··-·low_complexity203 ··-·low_complexity
198 ··-·low_disruption204 ··-·low_disruption
199 ··-·no_reboot_needed205 ··-·no_reboot_needed
200 ··-·restrict_strategy206 ··-·restrict_strategy
201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
  
 208 var_system_crypto_policy='DEFAULT'
  
  
 209 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null)
 210 rc=$?
  
 211 if·test·"$rc"·=·127;·then
 212 »       echo·"$stderr_of_call"·>&2
 213 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2
 214 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2
 215 »       echo·"to·see·what·package·to·(re)install"·>&2
  
 216 »       false··#·end·with·an·error·code
 217 elif·test·"$rc"·!=·0;·then
 218 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
 219 »       false··#·end·with·an·error·code
 220 fi
202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
206 --- 
207 apiVersion:·machineconfiguration.openshift.io/v1 
208 kind:·MachineConfig 
209 spec: 
210 ··config: 
211 ····ignition: 
212 ······version:·3.1.0 
213 ····systemd: 
214 ······units: 
215 ········-·name:·configure-crypto-policy.service 
216 ··········enabled:·true 
217 ··········contents:·| 
218 ············[Unit] 
219 ············Before=kubelet.service 
220 ············[Service] 
221 ············Type=oneshot 
222 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
223 ············RemainAfterExit=yes 
224 ············[Install] 
225 ············WantedBy=multi-user.target 
226 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*221 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
227 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.222 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
228 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.223 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
229 Severity: ··medium224 Severity: ··medium
Max diff block lines reached; 1053040/1058978 bytes (99.44%) of diff not shown.
26.2 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-cis.html
    
Offset 14413, 15 lines modifiedOffset 14413, 15 lines modified
000384c0:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v000384c0:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v
000384d0:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>000384d0:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>
000384e0:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><000384e0:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><
000384f0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro000384f0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro
00038500:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong00038500:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong
00038510:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············00038510:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············
00038520:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·20200038520:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202
00038530:·362d·3031·2d30·3829·0a20·2020·2020·2020··6-01-08).·······00038530:·342d·3132·2d30·3729·0a20·2020·2020·2020··4-12-07).·······
00038540:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></00038540:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></
00038550:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab00038550:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab
00038560:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</00038560:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</
00038570:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr00038570:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr
00038580:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s00038580:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s
00038590:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten00038590:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten
000385a0:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">000385a0:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">
Offset 15232, 236 lines modifiedOffset 15232, 236 lines modified
0003b7f0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003b7f0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003b800:·6d38·3432·3822·2074·6162·696e·6465·783d··m8428"·tabindex=0003b800:·6d38·3432·3822·2074·6162·696e·6465·783d··m8428"·tabindex=
0003b810:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003b810:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003b820:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003b820:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003b830:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003b830:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003b840:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003b840:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003b850:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003b850:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003b860:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·0003b860:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond
0003b870:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003b870:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a
0003b880:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003b880:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003b890:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003b890:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003b8a0:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm80003b8a0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003b8b0:·3432·3822·3e3c·7461·626c·6520·636c·6173··428"><table·clas0003b8b0:·6d38·3432·3822·3e3c·7461·626c·6520·636c··m8428"><table·cl
0003b8c0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003b8c0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003b8d0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003b8d0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003b8e0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003b8e0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003b8f0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003b8f0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003b900:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003b900:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003b910:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003b910:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003b920:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003b920:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003b930:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003b930:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0003b940:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b940:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003b950:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003b950:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
0003b960:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003b960:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
0003b970:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003b970:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003b980:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003b980:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003b990:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003b990:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003b9a0:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc0003b9a0:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.
 0003b9b0:·7061·636b·6167·6520·2d2d·6164·643d·6169··package·--add=ai
 0003b9c0:·6465·0a3c·2f63·6f64·653e·3c2f·7072·653e··de.</code></pre>
0003b9b0:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid 
0003b9c0:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install 
0003b9d0:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag 
0003b9e0:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.···· 
0003b9f0:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in 
0003ba00:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}. 
0003ba10:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003ba20:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003ba30:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003ba40:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003ba50:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003ba60:·3d22·2369·646d·3834·3239·2220·7461·6269··="#idm8429"·tabi 
0003ba70:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003ba80:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003ba90:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003baa0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003bab0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003bac0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
0003bad0:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</ 
0003bae0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003baf0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003bb00:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003bb10:·646d·3834·3239·223e·3c74·6162·6c65·2063··dm8429"><table·c 
0003bb20:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003bb30:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003bb40:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003bb50:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003bb60:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003bb70:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003bb80:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003bb90:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003bba0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003bbb0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003bbc0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0003bbd0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003bbe0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003bbf0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003bc00:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003bc10:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is 
0003bc20:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only 
0003bc30:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat 
0003bc40:·666f·726d·730a·6966·205b·2021·202d·6620··forms.if·[·!·-f· 
0003bc50:·2f2e·646f·636b·6572·656e·7620·5d20·2661··/.dockerenv·]·&a 
0003bc60:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f· 
0003bc70:·2f72·756e·2f2e·636f·6e74·6169·6e65·7265··/run/.containere 
0003bc80:·6e76·205d·3b20·7468·656e·0a0a·6966·2021··nv·];·then..if·! 
0003bc90:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet· 
0003bca0:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.·· 
0003bcb0:·2020·646e·6620·696e·7374·616c·6c20·2d79····dnf·install·-y 
0003bcc0:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else 
0003bcd0:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2· 
0003bce0:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio 
0003bcf0:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica 
0003bd00:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was 
0003bd10:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code 
0003bd20:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003bd30:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003bd40:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003bd50:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003bd60:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003bd70:·3834·3330·2220·7461·6269·6e64·6578·3d22··8430"·tabindex=" 
0003bd80:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003bd90:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003bda0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003bdb0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003bdc0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003bdd0:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible· 
0003bde0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003bdf0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003be00:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003be10:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8 
0003be20:·3433·3022·3e3c·7461·626c·6520·636c·6173··430"><table·clas 
0003be30:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003be40:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003be50:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003be60:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003be70:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003be80:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003be90:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003bea0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003beb0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
Max diff block lines reached; 25004054/25036400 bytes (99.87%) of diff not shown.
2.3 MB
html2text {}
Max HTML report size reached
11.4 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-cis_server_l1.html
    
Offset 14413, 16 lines modifiedOffset 14413, 16 lines modified
000384c0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p000384c0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p
000384d0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version000384d0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version
000384e0:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.74000384e0:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.74
000384f0:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul000384f0:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul
00038500:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra00038500:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra
00038510:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····00038510:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····
00038520:·2020·2020·2020·2020·2020·2020·2020·2020··················00038520:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038530:·2861·7320·6f66·2032·3032·362d·3031·2d30··(as·of·2026-01-000038530:·2861·7320·6f66·2032·3032·342d·3132·2d30··(as·of·2024-12-0
00038540:·3829·0a20·2020·2020·2020·2020·2020·2020··8).·············00038540:·3729·0a20·2020·2020·2020·2020·2020·2020··7).·············
00038550:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d00038550:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d
00038560:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·00038560:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·
00038570:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol00038570:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol
00038580:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x00038580:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x
00038590:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj00038590:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj
000385a0:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou000385a0:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou
000385b0:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System000385b0:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System
Offset 15201, 235 lines modifiedOffset 15201, 235 lines modified
0003b600:·7461·7267·6574·3d22·2369·646d·3834·3238··target="#idm84280003b600:·7461·7267·6574·3d22·2369·646d·3834·3238··target="#idm8428
0003b610:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003b610:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003b620:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003b620:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003b630:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003b630:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003b640:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003b640:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003b650:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003b650:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003b660:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003b660:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003b670:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp0003b670:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni
0003b680:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0003b680:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003b690:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003b690:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003b6a0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003b6a0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003b6b0:·6522·2069·643d·2269·646d·3834·3238·223e··e"·id="idm8428">0003b6b0:·7073·6522·2069·643d·2269·646d·3834·3238··pse"·id="idm8428
0003b6c0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003b6c0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003b6d0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003b6d0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003b6e0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003b6e0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003b6f0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003b6f0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003b700:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003b700:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003b710:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003b710:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003b720:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003b720:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003b730:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003b730:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003b740:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003b740:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003b750:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo0003b750:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003b760:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals0003b760:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003b770:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><0003b770:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003b780:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th0003b780:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003b790:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>0003b790:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0003b7a0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003b7a0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003b7b0:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa
 0003b7c0:·6765·202d·2d61·6464·3d61·6964·650a·3c2f··ge·--add=aide.</
 0003b7d0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003b7e0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003b7f0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003b800:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
0003b7b0:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include· 
0003b7c0:·696e·7374·616c·6c5f·6169·6465·0a0a·636c··install_aide..cl 
0003b7d0:·6173·7320·696e·7374·616c·6c5f·6169·6465··ass·install_aide 
0003b7e0:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·' 
0003b7f0:·6169·6465·273a·0a20·2020·2065·6e73·7572··aide':.····ensur 
0003b800:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install 
0003b810:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod 
0003b820:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003b830:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003b840:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003b850:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003b860:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003b870:·6d38·3432·3922·2074·6162·696e·6465·783d··m8429"·tabindex= 
0003b880:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003b890:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003b8a0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003b8b0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003b8c0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003b8d0:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s 
0003b8e0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003b8f0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003b900:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003b910:·6170·7365·2220·6964·3d22·6964·6d38·3432··apse"·id="idm842 
0003b920:·3922·3e3c·7461·626c·6520·636c·6173·733d··9"><table·class= 
0003b930:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003b940:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003b950:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003b960:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003b970:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003b980:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b990:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003b9a0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b9b0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003b9c0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003b9d0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
0003b9e0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003b9f0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003ba00:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003ba10:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem 
0003ba20:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl 
0003ba30:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c 
0003ba40:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms 
0003ba50:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc 
0003ba60:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a 
0003ba70:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/ 
0003ba80:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·]; 
0003ba90:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm· 
0003baa0:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide 
0003bab0:·2220·3b20·7468·656e·0a20·2020·2064·6e66··"·;·then.····dnf 
0003bac0:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid 
0003bad0:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.···· 
0003bae0:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo· 
0003baf0:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is· 
0003bb00:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,· 
0003bb10:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done 
0003bb20:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr 
0003bb30:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003bb40:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003bb50:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="0003b810:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003b820:·2369·646d·3834·3239·2220·7461·6269·6e64··#idm8429"·tabind
 0003b830:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003b840:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003b850:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003b860:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003b870:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003b880:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp
 0003b890:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</
 0003b8a0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003b8b0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003b8c0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003b8d0:·646d·3834·3239·223e·3c74·6162·6c65·2063··dm8429"><table·c
 0003b8e0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003b8f0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003b900:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003b910:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003b920:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003b930:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
Max diff block lines reached; 10615904/10648250 bytes (99.70%) of diff not shown.
1.26 MB
html2text {}
    
Offset 59, 15 lines modifiedOffset 59, 15 lines modified
59 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Red·Hat·Enterprise·Linux·9·Benchmark·for·Level·1·-·Server59 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Red·Hat·Enterprise·Linux·9·Benchmark·for·Level·1·-·Server
60 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_server_l160 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_server_l1
61 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*61 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
62 ····*·cpe:/o:redhat:enterprise_linux:962 ····*·cpe:/o:redhat:enterprise_linux:9
63 ····*·cpe:/o:centos:centos:963 ····*·cpe:/o:centos:centos:9
64 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*64 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
65 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8465 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
66 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)66 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
67 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*67 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
68 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s68 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
69 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e69 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
70 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l70 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
71 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n71 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
72 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g72 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
73 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s73 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 122, 41 lines modifiedOffset 122, 45 lines modified
122 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3122 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
123 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5123 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
124 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199124 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
125 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79125 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
126 ············_\x8c_\x8i_\x8s············6.1.1126 ············_\x8c_\x8i_\x8s············6.1.1
127 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2127 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
128 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule128 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule
 129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 134 package·--add=aide
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
134 include·install_aide140 include·install_aide
  
135 class·install_aide·{141 class·install_aide·{
136 ··package·{·'aide':142 ··package·{·'aide':
137 ····ensure·=>·'installed',143 ····ensure·=>·'installed',
138 ··}144 ··}
139 }145 }
 146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 147 [[packages]]
 148 name·=·"aide"
 149 version·=·"*"
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low151 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low152 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false153 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable154 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
145 #·Remediation·is·applicable·only·in·certain·platforms 
146 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
 155 package·install·aide
147 if·!·rpm·-q·--quiet·"aide"·;·then 
148 ····dnf·install·-y·"aide" 
149 fi 
  
150 else 
151 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
152 fi 
153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
154 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low157 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
155 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low158 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
156 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false159 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
157 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable160 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
158 -·name:·Ensure·aide·is·installed161 -·name:·Ensure·aide·is·installed
159 ··package:162 ··package:
Offset 171, 33 lines modifiedOffset 175, 29 lines modified
171 ··-·PCI-DSSv4-11.5.2175 ··-·PCI-DSSv4-11.5.2
172 ··-·enable_strategy176 ··-·enable_strategy
173 ··-·low_complexity177 ··-·low_complexity
174 ··-·low_disruption178 ··-·low_disruption
175 ··-·medium_severity179 ··-·medium_severity
176 ··-·no_reboot_needed180 ··-·no_reboot_needed
177 ··-·package_aide_installed181 ··-·package_aide_installed
178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
179 [[packages]] 
180 name·=·"aide" 
181 version·=·"*" 
182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 187 #·Remediation·is·applicable·only·in·certain·platforms
 188 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 189 if·!·rpm·-q·--quiet·"aide"·;·then
 190 ····dnf·install·-y·"aide"
 191 fi
187 package·install·aide 
188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
193 package·--add=aide192 else
 193 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 194 fi
194 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*195 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
195 Run·the·following·command·to·generate·a·new·database:196 Run·the·following·command·to·generate·a·new·database:
196 $·sudo·/usr/sbin/aide·--init197 $·sudo·/usr/sbin/aide·--init
197 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:198 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
198 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz199 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
199 To·initiate·a·manual·check,·run·the·following·command:200 To·initiate·a·manual·check,·run·the·following·command:
200 $·sudo·/usr/sbin/aide·--check201 $·sudo·/usr/sbin/aide·--check
Offset 215, 28 lines modifiedOffset 215, 14 lines modified
215 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3215 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
216 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5216 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
217 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199217 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
218 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79218 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
219 ············_\x8c_\x8i_\x8s············6.1.1219 ············_\x8c_\x8i_\x8s············6.1.1
220 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2220 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
221 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule221 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule
222 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
223 #·Remediation·is·applicable·only·in·certain·platforms 
224 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
225 if·!·rpm·-q·--quiet·"aide"·;·then 
226 ····dnf·install·-y·"aide" 
227 fi 
  
Max diff block lines reached; 1317218/1323338 bytes (99.54%) of diff not shown.
11.0 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-cis_workstation_l1.html
    
Offset 14414, 16 lines modifiedOffset 14414, 16 lines modified
000384d0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h000384d0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h
000384e0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver000384e0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver
000384f0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.000384f0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.
00038500:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p00038500:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p
00038510:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong00038510:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong
00038520:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.00038520:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.
00038530:·2020·2020·2020·2020·2020·2020·2020·2020··················00038530:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038540:·2020·2020·2861·7320·6f66·2032·3032·362d······(as·of·2026-00038540:·2020·2020·2861·7320·6f66·2032·3032·342d······(as·of·2024-
00038550:·3031·2d30·3829·0a20·2020·2020·2020·2020··01-08).·········00038550:·3132·2d30·3729·0a20·2020·2020·2020·2020··12-07).·········
00038560:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul00038560:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul
00038570:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table00038570:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table
00038580:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h200038580:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2
00038590:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href00038590:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href
000385a0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg000385a0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg
000385b0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_000385b0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
000385c0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy000385c0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy
Offset 15192, 236 lines modifiedOffset 15192, 236 lines modified
0003b570:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b570:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003b580:·646d·3834·3238·2220·7461·6269·6e64·6578··dm8428"·tabindex0003b580:·646d·3834·3238·2220·7461·6269·6e64·6578··dm8428"·tabindex
0003b590:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b590:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b5a0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b5a0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b5b0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b5b0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b5c0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b5c0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b5d0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b5d0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003b5e0:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet0003b5e0:·6d65·6469·6174·696f·6e20·416e·6163·6f6e··mediation·Anacon
0003b5f0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003b5f0:·6461·2073·6e69·7070·6574·20e2·87b2·3c2f··da·snippet·...</
0003b600:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003b600:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003b610:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003b610:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003b620:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003b620:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003b630:·3834·3238·223e·3c74·6162·6c65·2063·6c61··8428"><table·cla0003b630:·646d·3834·3238·223e·3c74·6162·6c65·2063··dm8428"><table·c
0003b640:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003b640:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003b650:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003b650:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003b660:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003b660:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003b670:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003b670:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003b680:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003b680:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003b690:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003b690:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003b6a0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003b6a0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003b6b0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003b6b0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003b6c0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003b6c0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003b6d0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t0003b6d0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
0003b6e0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr0003b6e0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
0003b6f0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0003b6f0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
0003b700:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl0003b700:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003b710:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0003b710:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
0003b720:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in0003b720:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003b730:·0a70·6163·6b61·6765·202d·2d61·6464·3d61··.package·--add=a
 0003b740:·6964·650a·3c2f·636f·6465·3e3c·2f70·7265··ide.</code></pre
 0003b750:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0003b760:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0003b770:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0003b780:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 0003b790:·7267·6574·3d22·2369·646d·3834·3239·2220··rget="#idm8429"·
 0003b7a0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0003b7b0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 0003b7c0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 0003b7d0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 0003b7e0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 0003b7f0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003b800:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
 0003b810:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003b820:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003b830:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003b840:·2069·643d·2269·646d·3834·3239·223e·3c74···id="idm8429"><t
 0003b850:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003b860:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0003b870:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0003b880:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003b890:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003b730:·636c·7564·6520·696e·7374·616c·6c5f·6169··clude·install_ai 
0003b740:·6465·0a0a·636c·6173·7320·696e·7374·616c··de..class·instal 
0003b750:·6c5f·6169·6465·207b·0a20·2070·6163·6b61··l_aide·{.··packa 
0003b760:·6765·207b·2027·6169·6465·273a·0a20·2020··ge·{·'aide':.··· 
0003b770:·2065·6e73·7572·6520·3d26·6774·3b20·2769···ensure·=&gt;·'i 
0003b780:·6e73·7461·6c6c·6564·272c·0a20·207d·0a7d··nstalled',.··}.} 
0003b790:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003b7a0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b7b0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b7c0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b7d0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b7e0:·743d·2223·6964·6d38·3432·3922·2074·6162··t="#idm8429"·tab 
0003b7f0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b800:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b810:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b820:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b830:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b840:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
0003b850:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
0003b860:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003b870:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003b880:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003b890:·6964·6d38·3432·3922·3e3c·7461·626c·6520··idm8429"><table· 
0003b8a0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003b8b0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003b8c0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003b8d0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003b8e0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003b8f0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b900:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003b910:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003b920:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003b930:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003b940:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003b950:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003b960:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003b8a0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003b8b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b8c0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003b970:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
0003b980:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
0003b990:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i 
0003b9a0:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl 
0003b9b0:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla 
0003b9c0:·7466·6f72·6d73·0a69·6620·5b20·2120·2d66··tforms.if·[·!·-f 
0003b9d0:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·& 
0003b9e0:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f 
0003b9f0:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container 
0003ba00:·656e·7620·5d3b·2074·6865·6e0a·0a69·6620··env·];·then..if· 
0003ba10:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet 
0003ba20:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.· 
0003ba30:·2020·2064·6e66·2069·6e73·7461·6c6c·202d·····dnf·install·- 
0003ba40:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els 
0003ba50:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2 
0003ba60:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati 
0003ba70:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic 
0003ba80:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa 
0003ba90:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod 
0003baa0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003bab0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
Max diff block lines reached; 10234843/10267327 bytes (99.68%) of diff not shown.
1.22 MB
html2text {}
    
Offset 60, 15 lines modifiedOffset 60, 15 lines modified
60 ··············Workstation60 ··············Workstation
61 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_workstation_l161 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_workstation_l1
62 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*62 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
63 ····*·cpe:/o:redhat:enterprise_linux:963 ····*·cpe:/o:redhat:enterprise_linux:9
64 ····*·cpe:/o:centos:centos:964 ····*·cpe:/o:centos:centos:9
65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
66 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8466 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
69 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s69 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
70 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e70 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
71 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l71 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
72 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n72 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
73 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g73 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
74 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s74 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 121, 41 lines modifiedOffset 121, 45 lines modified
121 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3121 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
122 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5122 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
123 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199123 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
124 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79124 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
125 ············_\x8c_\x8i_\x8s············6.1.1125 ············_\x8c_\x8i_\x8s············6.1.1
126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
127 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule127 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule
 128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 133 package·--add=aide
128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low135 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low136 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false137 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable138 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
133 include·install_aide139 include·install_aide
  
134 class·install_aide·{140 class·install_aide·{
135 ··package·{·'aide':141 ··package·{·'aide':
136 ····ensure·=>·'installed',142 ····ensure·=>·'installed',
137 ··}143 ··}
138 }144 }
 145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 146 [[packages]]
 147 name·=·"aide"
 148 version·=·"*"
139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8149 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low150 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low151 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false152 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable153 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
144 #·Remediation·is·applicable·only·in·certain·platforms 
145 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
 154 package·install·aide
146 if·!·rpm·-q·--quiet·"aide"·;·then 
147 ····dnf·install·-y·"aide" 
148 fi 
  
149 else 
150 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
151 fi 
152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8155 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
153 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low156 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
154 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low157 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
155 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false158 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
156 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable159 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
157 -·name:·Ensure·aide·is·installed160 -·name:·Ensure·aide·is·installed
158 ··package:161 ··package:
Offset 170, 33 lines modifiedOffset 174, 29 lines modified
170 ··-·PCI-DSSv4-11.5.2174 ··-·PCI-DSSv4-11.5.2
171 ··-·enable_strategy175 ··-·enable_strategy
172 ··-·low_complexity176 ··-·low_complexity
173 ··-·low_disruption177 ··-·low_disruption
174 ··-·medium_severity178 ··-·medium_severity
175 ··-·no_reboot_needed179 ··-·no_reboot_needed
176 ··-·package_aide_installed180 ··-·package_aide_installed
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
178 [[packages]] 
179 name·=·"aide" 
180 version·=·"*" 
181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 186 #·Remediation·is·applicable·only·in·certain·platforms
 187 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 188 if·!·rpm·-q·--quiet·"aide"·;·then
 189 ····dnf·install·-y·"aide"
 190 fi
186 package·install·aide 
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
192 package·--add=aide191 else
 192 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 193 fi
193 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*194 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
194 Run·the·following·command·to·generate·a·new·database:195 Run·the·following·command·to·generate·a·new·database:
195 $·sudo·/usr/sbin/aide·--init196 $·sudo·/usr/sbin/aide·--init
196 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:197 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
197 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz198 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
198 To·initiate·a·manual·check,·run·the·following·command:199 To·initiate·a·manual·check,·run·the·following·command:
199 $·sudo·/usr/sbin/aide·--check200 $·sudo·/usr/sbin/aide·--check
Offset 214, 28 lines modifiedOffset 214, 14 lines modified
214 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3214 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
215 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5215 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
216 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199216 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
217 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79217 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
218 ············_\x8c_\x8i_\x8s············6.1.1218 ············_\x8c_\x8i_\x8s············6.1.1
219 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2219 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
220 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule220 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule
221 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
222 #·Remediation·is·applicable·only·in·certain·platforms 
223 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
224 if·!·rpm·-q·--quiet·"aide"·;·then 
225 ····dnf·install·-y·"aide" 
226 fi 
  
Max diff block lines reached; 1269095/1275146 bytes (99.53%) of diff not shown.
26.0 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-cis_workstation_l2.html
    
Offset 14414, 16 lines modifiedOffset 14414, 16 lines modified
000384d0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h000384d0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h
000384e0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver000384e0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver
000384f0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.000384f0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.
00038500:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p00038500:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p
00038510:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong00038510:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong
00038520:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.00038520:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.
00038530:·2020·2020·2020·2020·2020·2020·2020·2020··················00038530:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038540:·2020·2020·2861·7320·6f66·2032·3032·362d······(as·of·2026-00038540:·2020·2020·2861·7320·6f66·2032·3032·342d······(as·of·2024-
00038550:·3031·2d30·3829·0a20·2020·2020·2020·2020··01-08).·········00038550:·3132·2d30·3729·0a20·2020·2020·2020·2020··12-07).·········
00038560:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul00038560:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul
00038570:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table00038570:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table
00038580:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h200038580:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2
00038590:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href00038590:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href
000385a0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg000385a0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg
000385b0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_000385b0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
000385c0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy000385c0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy
Offset 15224, 235 lines modifiedOffset 15224, 235 lines modified
0003b770:·6172·6765·743d·2223·6964·6d38·3432·3822··arget="#idm8428"0003b770:·6172·6765·743d·2223·6964·6d38·3432·3822··arget="#idm8428"
0003b780:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003b780:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003b790:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003b790:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003b7a0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003b7a0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003b7b0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003b7b0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003b7c0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003b7c0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003b7d0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003b7d0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003b7e0:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe0003b7e0:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip
0003b7f0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003b7f0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003b800:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003b800:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003b810:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003b810:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003b820:·2220·6964·3d22·6964·6d38·3432·3822·3e3c··"·id="idm8428"><0003b820:·7365·2220·6964·3d22·6964·6d38·3432·3822··se"·id="idm8428"
0003b830:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003b830:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003b840:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003b840:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003b850:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003b850:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003b860:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003b860:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003b870:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003b870:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003b880:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003b880:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003b890:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003b890:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003b8a0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003b8a0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003b8b0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003b8b0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003b8c0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo0003b8c0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
0003b8d0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false0003b8d0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
0003b8e0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003b8e0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
0003b8f0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>0003b8f0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0003b900:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><0003b900:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
0003b910:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0003b910:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003b920:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag
 0003b930:·6520·2d2d·6164·643d·6169·6465·0a3c·2f63··e·--add=aide.</c
 0003b940:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003b950:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003b960:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003b970:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 0003b980:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0003b990:·6964·6d38·3432·3922·2074·6162·696e·6465··idm8429"·tabinde
 0003b9a0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 0003b9b0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 0003b9c0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 0003b9d0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 0003b9e0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 0003b9f0:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
 0003ba00:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 0003ba10:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003ba20:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003ba30:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003ba40:·6d38·3432·3922·3e3c·7461·626c·6520·636c··m8429"><table·cl
 0003ba50:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003ba60:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003ba70:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003ba80:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003ba90:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003baa0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003bab0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003b920:·3e3c·636f·6465·3e69·6e63·6c75·6465·2069··><code>include·i 
0003b930:·6e73·7461·6c6c·5f61·6964·650a·0a63·6c61··nstall_aide..cla 
0003b940:·7373·2069·6e73·7461·6c6c·5f61·6964·6520··ss·install_aide· 
0003b950:·7b0a·2020·7061·636b·6167·6520·7b20·2761··{.··package·{·'a 
0003b960:·6964·6527·3a0a·2020·2020·656e·7375·7265··ide':.····ensure 
0003b970:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe 
0003b980:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code 
0003b990:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003b9a0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003b9b0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003b9c0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003b9d0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003b9e0:·3834·3239·2220·7461·6269·6e64·6578·3d22··8429"·tabindex=" 
0003b9f0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003ba00:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003ba10:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003ba20:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003ba30:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003ba40:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003ba50:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003ba60:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003ba70:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003ba80:·7073·6522·2069·643d·2269·646d·3834·3239··pse"·id="idm8429 
0003ba90:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003baa0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003bab0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003bac0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003bad0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003bae0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003bac0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0003baf0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003bad0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003bb00:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003bb10:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003bae0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 0003baf0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
0003bb20:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003bb00:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003bb30:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003bb10:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 0003bb20:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 0003bb30:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i
 0003bb40:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a
 0003bb50:·6964·650a·0a63·6c61·7373·2069·6e73·7461··ide..class·insta
 0003bb60:·6c6c·5f61·6964·6520·7b0a·2020·7061·636b··ll_aide·{.··pack
 0003bb70:·6167·6520·7b20·2761·6964·6527·3a0a·2020··age·{·'aide':.··
 0003bb80:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·'
 0003bb90:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}.
0003bb40:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
0003bb50:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003bb60:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003bb70:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003bb80:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme 
0003bb90:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
0003bba0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
0003bbb0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
0003bbc0:·6966·205b·2021·202d·6620·2f2e·646f·636b··if·[·!·-f·/.dock 
0003bbd0:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am 
0003bbe0:·703b·205b·2021·202d·6620·2f72·756e·2f2e··p;·[·!·-f·/run/. 
0003bbf0:·636f·6e74·6169·6e65·7265·6e76·205d·3b20··containerenv·];· 
0003bc00:·7468·656e·0a0a·6966·2021·2072·706d·202d··then..if·!·rpm·- 
0003bc10:·7120·2d2d·7175·6965·7420·2261·6964·6522··q·--quiet·"aide" 
Max diff block lines reached; 24815851/24848197 bytes (99.87%) of diff not shown.
2.27 MB
html2text {}
Max HTML report size reached
6.81 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-cui.html
    
Offset 14449, 15 lines modifiedOffset 14449, 15 lines modified
00038700:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current00038700:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current
00038710:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron00038710:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron
00038720:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong00038720:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong
00038730:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st00038730:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st
00038740:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro00038740:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro
00038750:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············00038750:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············
00038760:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·200038760:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·2
00038770:·3032·362d·3031·2d30·3829·0a20·2020·2020··026-01-08).·····00038770:·3032·342d·3132·2d30·3729·0a20·2020·2020··024-12-07).·····
00038780:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>00038780:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>
00038790:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T00038790:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T
000387a0:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents000387a0:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents
000387b0:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·000387b0:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·
000387c0:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org000387c0:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org
000387d0:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont000387d0:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont
000387e0:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system000387e0:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system
Offset 15177, 196 lines modifiedOffset 15177, 196 lines modified
0003b480:·6765·743d·2223·6964·6d38·3933·3122·2074··get="#idm8931"·t0003b480:·6765·743d·2223·6964·6d38·3933·3122·2074··get="#idm8931"·t
0003b490:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003b490:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003b4a0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003b4a0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003b4b0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003b4b0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003b4c0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003b4c0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003b4d0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003b4d0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003b4e0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003b4e0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003b4f0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
0003b500:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b510:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b520:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b530:·3d22·6964·6d38·3933·3122·3e3c·7072·653e··="idm8931"><pre> 
0003b540:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat 
0003b550:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl 
0003b560:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai 
0003b570:·6e20·706c·6174·666f·726d·730a·6966·2028··n·platforms.if·( 
0003b580:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker 
0003b590:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp; 
0003b5a0:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co 
0003b5b0:·6e74·6169·6e65·7265·6e76·205d·2026·616d··ntainerenv·]·&am 
0003b5c0:·703b·2661·6d70·3b20·2120·2820·5b20·2224··p;&amp;·!·(·[·"$ 
0003b5d0:·7b63·6f6e·7461·696e·6572·3a2d·7d22·203d··{container:-}"·= 
0003b5e0:·3d20·2262·7772·6170·2d6f·7362·7569·6c64··=·"bwrap-osbuild 
0003b5f0:·2220·5d20·2920·293b·2074·6865·6e0a·0a66··"·]·)·);·then..f 
0003b600:·6970·732d·6d6f·6465·2d73·6574·7570·202d··ips-mode-setup·- 
0003b610:·2d65·6e61·626c·650a·4649·5053·5f43·4f4e··-enable.FIPS_CON 
0003b620:·463d·222f·6574·632f·6472·6163·7574·2e63··F="/etc/dracut.c 
0003b630:·6f6e·662e·642f·3430·2d66·6970·732e·636f··onf.d/40-fips.co 
0003b640:·6e66·220a·6966·2021·2067·7265·7020·225e··nf".if·!·grep·"^ 
0003b650:·6164·645f·6472·6163·7574·6d6f·6475·6c65··add_dracutmodule 
0003b660:·732b·3d5c·2220·6669·7073·205c·2222·2024··s+=\"·fips·\""·$ 
0003b670:·4649·5053·5f43·4f4e·463b·2074·6865·6e0a··FIPS_CONF;·then. 
0003b680:·2020·2020·6563·686f·2022·6164·645f·6472······echo·"add_dr 
0003b690:·6163·7574·6d6f·6475·6c65·732b·3d5c·2220··acutmodules+=\"· 
0003b6a0:·6669·7073·205c·2222·2026·6774·3b26·6774··fips·\""·&gt;&gt 
0003b6b0:·3b20·2446·4950·535f·434f·4e46·0a66·690a··;·$FIPS_CONF.fi. 
0003b6c0:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a 
0003b6d0:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed 
0003b6e0:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap 
0003b6f0:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin 
0003b700:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.< 
0003b710:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003b720:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003b730:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003b740:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003b750:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003b760:·2223·6964·6d38·3933·3222·2074·6162·696e··"#idm8932"·tabin 
0003b770:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003b780:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003b790:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003b7a0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003b7b0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003b7c0:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans 
0003b7d0:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...0003b4f0:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet
0003b7e0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003b500:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003b7f0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003b510:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003b800:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003b520:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003b810:·2269·646d·3839·3332·223e·3c74·6162·6c65··"idm8932"><table0003b530:·2069·643d·2269·646d·3839·3331·223e·3c74···id="idm8931"><t
0003b820:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003b540:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003b830:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003b550:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003b840:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003b560:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003b850:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003b570:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003b860:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003b580:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0003b590:·7479·3a3c·2f74·683e·3c74·643e·6d65·6469··ty:</th><td>medi
 0003b5a0:·756d·3c2f·7464·3e3c·2f74·723e·3c74·723e··um</td></tr><tr>
 0003b5b0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003b870:·2f74·683e·3c74·643e·6d65·6469·756d·3c2f··/th><td>medium</0003b5c0:·2f74·683e·3c74·643e·6d65·6469·756d·3c2f··/th><td>medium</
0003b880:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003b5d0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b890:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003b8a0:·3c74·643e·6d65·6469·756d·3c2f·7464·3e3c··<td>medium</td>< 
0003b8b0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003b8c0:·6f74·3a3c·2f74·683e·3c74·643e·7472·7565··ot:</th><td>true0003b5e0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003b5f0:·7472·7565·3c2f·7464·3e3c·2f74·723e·3c74··true</td></tr><t
 0003b600:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003b610:·2f74·683e·3c74·643e·7265·7374·7269·6374··/th><td>restrict
0003b8d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003b620:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003b8e0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003b8f0:·3c74·643e·7265·7374·7269·6374·3c2f·7464··<td>restrict</td 
0003b900:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003b910:·7265·3e3c·636f·6465·3e2d·206e·616d·653a··re><code>-·name:0003b630:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n
0003b920:·2043·6865·636b·2074·6f20·7365·6520·7468···Check·to·see·th0003b640:·616d·653a·2043·6865·636b·2074·6f20·7365··ame:·Check·to·se
0003b930:·6520·6375·7272·656e·7420·7374·6174·7573··e·current·status0003b650:·6520·7468·6520·6375·7272·656e·7420·7374··e·the·current·st
0003b940:·206f·6620·4649·5053·206d·6f64·650a·2020···of·FIPS·mode.··0003b660:·6174·7573·206f·6620·4649·5053·206d·6f64··atus·of·FIPS·mod
0003b950:·636f·6d6d·616e·643a·202f·7573·722f·6269··command:·/usr/bi0003b670:·650a·2020·636f·6d6d·616e·643a·202f·7573··e.··command:·/us
0003b960:·6e2f·6669·7073·2d6d·6f64·652d·7365·7475··n/fips-mode-setu0003b680:·722f·6269·6e2f·6669·7073·2d6d·6f64·652d··r/bin/fips-mode-
0003b970:·7020·2d2d·6368·6563·6b0a·2020·7265·6769··p·--check.··regi0003b690:·7365·7475·7020·2d2d·6368·6563·6b0a·2020··setup·--check.··
0003b980:·7374·6572·3a20·6973·5f66·6970·735f·656e··ster:·is_fips_en0003b6a0:·7265·6769·7374·6572·3a20·6973·5f66·6970··register:·is_fip
0003b990:·6162·6c65·640a·2020·6368·616e·6765·645f··abled.··changed_0003b6b0:·735f·656e·6162·6c65·640a·2020·6368·616e··s_enabled.··chan
0003b9a0:·7768·656e·3a20·6661·6c73·650a·2020·6661··when:·false.··fa0003b6c0:·6765·645f·7768·656e·3a20·6661·6c73·650a··ged_when:·false.
0003b9b0:·696c·6564·5f77·6865·6e3a·2066·616c·7365··iled_when:·false0003b6d0:·2020·6661·696c·6564·5f77·6865·6e3a·2066····failed_when:·f
0003b9c0:·0a20·2077·6865·6e3a·2028·2061·6e73·6962··.··when:·(·ansib0003b6e0:·616c·7365·0a20·2077·6865·6e3a·2028·2061··alse.··when:·(·a
0003b9d0:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio0003b6f0:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz
0003b9e0:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·["0003b700:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i
0003b9f0:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",·0003b710:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx
0003ba00:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma0003b720:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p
0003ba10:·6e22·2c0a·2020·2020·2263·6f6e·7461·696e··n",.····"contain0003b730:·6f64·6d61·6e22·2c0a·2020·2020·2263·6f6e··odman",.····"con
0003ba20:·6572·225d·2061·6e64·206e·6f74·2028·206c··er"]·and·not·(·l0003b740:·7461·696e·6572·225d·2061·6e64·206e·6f74··tainer"]·and·not
0003ba30:·6f6f·6b75·7028·2265·6e76·222c·2022·636f··ookup("env",·"co0003b750:·2028·206c·6f6f·6b75·7028·2265·6e76·222c···(·lookup("env",
0003ba40:·6e74·6169·6e65·7222·2920·3d3d·2022·6277··ntainer")·==·"bw0003b760:·2022·636f·6e74·6169·6e65·7222·2920·3d3d···"container")·==
0003ba50:·7261·702d·6f73·6275·696c·6422·2029·2029··rap-osbuild"·)·)0003b770:·2022·6277·7261·702d·6f73·6275·696c·6422···"bwrap-osbuild"
0003ba60:·0a20·2074·6167·733a·0a20·202d·2044·4953··.··tags:.··-·DIS0003b780:·2029·2029·0a20·2074·6167·733a·0a20·202d···)·).··tags:.··-
0003ba70:·412d·5354·4947·2d52·4845·4c2d·3039·2d36··A-STIG-RHEL-09-60003b790:·2044·4953·412d·5354·4947·2d52·4845·4c2d···DISA-STIG-RHEL-
 0003b7a0:·3039·2d36·3731·3031·300a·2020·2d20·4e49··09-671010.··-·NI
 0003b7b0:·5354·2d38·3030·2d35·332d·434d·2d36·2861··ST-800-53-CM-6(a
 0003b7c0:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5
 0003b7d0:·332d·4941·2d37·0a20·202d·204e·4953·542d··3-IA-7.··-·NIST-
 0003b7e0:·3830·302d·3533·2d53·432d·3132·0a20·202d··800-53-SC-12.··-
 0003b7f0:·204e·4953·542d·3830·302d·3533·2d53·432d···NIST-800-53-SC-
0003ba80:·3731·3031·300a·2020·2d20·4e49·5354·2d38··71010.··-·NIST-80003b800:·3132·2832·290a·2020·2d20·4e49·5354·2d38··12(2).··-·NIST-8
0003ba90:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).··0003b810:·3030·2d35·332d·5343·2d31·3228·3329·0a20··00-53-SC-12(3).·
0003baa0:·2d20·4e49·5354·2d38·3030·2d35·332d·4941··-·NIST-800-53-IA 
Max diff block lines reached; 6223959/6250785 bytes (99.57%) of diff not shown.
874 KB
html2text {}
    
Offset 68, 15 lines modifiedOffset 68, 15 lines modified
68 ··············Systems·and·Organizations·(NIST·800-171)68 ··············Systems·and·Organizations·(NIST·800-171)
69 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cui69 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cui
70 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*70 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
71 ····*·cpe:/o:redhat:enterprise_linux:971 ····*·cpe:/o:redhat:enterprise_linux:9
72 ····*·cpe:/o:centos:centos:972 ····*·cpe:/o:centos:centos:9
73 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*73 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
74 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8474 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
75 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)75 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
76 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*76 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
77 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s77 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
78 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e78 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
79 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l79 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
80 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n80 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
81 ·········4.·_\x8z_\x8I_\x8P_\x8L_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n81 ·········4.·_\x8z_\x8I_\x8P_\x8L_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
82 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s82 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 117, 27 lines modifiedOffset 117, 14 lines modified
117 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000068,·CCI-000803,·CCI-002450117 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000068,·CCI-000803,·CCI-002450
118 ············_\x8i_\x8s_\x8m······1446118 ············_\x8i_\x8s_\x8m······1446
119 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1119 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
120 References:·_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12120 References:·_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
121 ············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.1121 ············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.1
122 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223122 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223
123 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule123 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule
124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
125 #·Remediation·is·applicable·only·in·certain·platforms 
126 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·);·then 
  
127 fips-mode-setup·--enable 
128 FIPS_CONF="/etc/dracut.conf.d/40-fips.conf" 
129 if·!·grep·"^add_dracutmodules+=\"·fips·\""·$FIPS_CONF;·then 
130 ····echo·"add_dracutmodules+=\"·fips·\""·>>·$FIPS_CONF 
131 fi 
  
132 else 
133 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
134 fi 
135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium
137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium126 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true127 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict128 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
140 -·name:·Check·to·see·the·current·status·of·FIPS·mode129 -·name:·Check·to·see·the·current·status·of·FIPS·mode
141 ··command:·/usr/bin/fips-mode-setup·--check130 ··command:·/usr/bin/fips-mode-setup·--check
Offset 198, 14 lines modifiedOffset 185, 27 lines modified
198 ··-·NIST-800-53-SC-13185 ··-·NIST-800-53-SC-13
199 ··-·enable_dracut_fips_module186 ··-·enable_dracut_fips_module
200 ··-·high_severity187 ··-·high_severity
201 ··-·medium_complexity188 ··-·medium_complexity
202 ··-·medium_disruption189 ··-·medium_disruption
203 ··-·reboot_required190 ··-·reboot_required
204 ··-·restrict_strategy191 ··-·restrict_strategy
 192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 193 #·Remediation·is·applicable·only·in·certain·platforms
 194 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·);·then
  
 195 fips-mode-setup·--enable
 196 FIPS_CONF="/etc/dracut.conf.d/40-fips.conf"
 197 if·!·grep·"^add_dracutmodules+=\"·fips·\""·$FIPS_CONF;·then
 198 ····echo·"add_dracutmodules+=\"·fips·\""·>>·$FIPS_CONF
 199 fi
  
 200 else
 201 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 202 fi
205 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*203 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
206 To·enable·FIPS·mode,·run·the·following·command:204 To·enable·FIPS·mode,·run·the·following·command:
207 fips-mode-setup·--enable205 fips-mode-setup·--enable
  
208 The·fips-mode-setup·command·will·configure·the·system·in·FIPS·mode·by·automatically·configuring·the·following:206 The·fips-mode-setup·command·will·configure·the·system·in·FIPS·mode·by·automatically·configuring·the·following:
209 ····*·Setting·the·kernel·FIPS·mode·flag·(/proc/sys/crypto/fips_enabled)·to·1207 ····*·Setting·the·kernel·FIPS·mode·flag·(/proc/sys/crypto/fips_enabled)·to·1
210 ····*·Creating·/etc/system-fips208 ····*·Creating·/etc/system-fips
Offset 219, 41 lines modifiedOffset 219, 18 lines modified
219 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000068,·CCI-000803,·CCI-002450219 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000068,·CCI-000803,·CCI-002450
220 ············_\x8i_\x8s_\x8m······1446220 ············_\x8i_\x8s_\x8m······1446
221 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1221 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
222 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12222 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
223 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1223 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
224 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176224 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
225 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule225 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule
 226 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
226 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
227 #·Remediation·is·applicable·only·in·certain·platforms 
228 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·)·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then 
  
229 var_system_crypto_policy='FIPS' 
  
  
230 fips-mode-setup·--enable 
  
231 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
232 rc=$? 
  
233 if·test·"$rc"·=·127;·then 
234 »       echo·"$stderr_of_call"·>&2 
235 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
236 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
237 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
238 »       false··#·end·with·an·error·code 
239 elif·test·"$rc"·!=·0;·then 
240 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
241 »       false··#·end·with·an·error·code 
242 fi 
  
 227 [customizations]
 228 fips·=·true
243 else 
244 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
245 fi 
246 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8229 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
247 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium230 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium
248 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium231 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
249 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true232 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
250 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict233 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
251 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable234 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
252 ··set_fact:235 ··set_fact:
Offset 353, 18 lines modifiedOffset 330, 41 lines modified
353 ··-·NIST-800-53-SC-13330 ··-·NIST-800-53-SC-13
354 ··-·enable_fips_mode331 ··-·enable_fips_mode
355 ··-·high_severity332 ··-·high_severity
356 ··-·medium_complexity333 ··-·medium_complexity
357 ··-·medium_disruption334 ··-·medium_disruption
358 ··-·reboot_required335 ··-·reboot_required
359 ··-·restrict_strategy336 ··-·restrict_strategy
360 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8337 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 338 #·Remediation·is·applicable·only·in·certain·platforms
 339 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·)·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
Max diff block lines reached; 888431/894629 bytes (99.31%) of diff not shown.
6.95 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-e8.html
    
Offset 14414, 16 lines modifiedOffset 14414, 16 lines modified
000384d0:·7369·6f6e·2048·6973·746f·7279·3c2f·6832··sion·History</h2000384d0:·7369·6f6e·2048·6973·746f·7279·3c2f·6832··sion·History</h2
000384e0:·3e3c·703e·4375·7272·656e·7420·7665·7273··><p>Current·vers000384e0:·3e3c·703e·4375·7272·656e·7420·7665·7273··><p>Current·vers
000384f0:·696f·6e3a·203c·7374·726f·6e67·3e30·2e31··ion:·<strong>0.1000384f0:·696f·6e3a·203c·7374·726f·6e67·3e30·2e31··ion:·<strong>0.1
00038500:·2e37·343c·2f73·7472·6f6e·673e·3c2f·703e··.74</strong></p>00038500:·2e37·343c·2f73·7472·6f6e·673e·3c2f·703e··.74</strong></p>
00038510:·3c75·6c3e·3c6c·693e·3c73·7472·6f6e·673e··<ul><li><strong>00038510:·3c75·6c3e·3c6c·693e·3c73·7472·6f6e·673e··<ul><li><strong>
00038520:·6472·6166·743c·2f73·7472·6f6e·673e·0a20··draft</strong>.·00038520:·6472·6166·743c·2f73·7472·6f6e·673e·0a20··draft</strong>.·
00038530:·2020·2020·2020·2020·2020·2020·2020·2020··················00038530:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038540:·2020·2028·6173·206f·6620·3230·3236·2d30·····(as·of·2026-000038540:·2020·2028·6173·206f·6620·3230·3234·2d31·····(as·of·2024-1
00038550:·312d·3038·290a·2020·2020·2020·2020·2020··1-08).··········00038550:·322d·3037·290a·2020·2020·2020·2020·2020··2-07).··········
00038560:·2020·2020·2020·3c2f·6c69·3e3c·2f75·6c3e········</li></ul>00038560:·2020·2020·2020·3c2f·6c69·3e3c·2f75·6c3e········</li></ul>
00038570:·3c2f·6469·763e·3c68·323e·5461·626c·6520··</div><h2>Table·00038570:·3c2f·6469·763e·3c68·323e·5461·626c·6520··</div><h2>Table·
00038580:·6f66·2043·6f6e·7465·6e74·733c·2f68·323e··of·Contents</h2>00038580:·6f66·2043·6f6e·7465·6e74·733c·2f68·323e··of·Contents</h2>
00038590:·3c6f·6c3e·3c6c·693e·3c61·2068·7265·663d··<ol><li><a·href=00038590:·3c6f·6c3e·3c6c·693e·3c61·2068·7265·663d··<ol><li><a·href=
000385a0:·2223·7863·6364·665f·6f72·672e·7373·6770··"#xccdf_org.ssgp000385a0:·2223·7863·6364·665f·6f72·672e·7373·6770··"#xccdf_org.ssgp
000385b0:·726f·6a65·6374·2e63·6f6e·7465·6e74·5f67··roject.content_g000385b0:·726f·6a65·6374·2e63·6f6e·7465·6e74·5f67··roject.content_g
000385c0:·726f·7570·5f73·7973·7465·6d22·3e53·7973··roup_system">Sys000385c0:·726f·7570·5f73·7973·7465·6d22·3e53·7973··roup_system">Sys
Offset 15267, 301 lines modifiedOffset 15267, 301 lines modified
0003ba20:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003ba20:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003ba30:·2223·6964·6d38·3038·3822·2074·6162·696e··"#idm8088"·tabin0003ba30:·2223·6964·6d38·3038·3822·2074·6162·696e··"#idm8088"·tabin
0003ba40:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003ba40:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003ba50:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003ba50:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003ba60:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003ba60:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003ba70:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003ba70:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003ba80:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003ba80:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003ba90:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
0003baa0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
0003bab0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003bac0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003bad0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003bae0:·6d38·3038·3822·3e3c·7072·653e·3c63·6f64··m8088"><pre><cod 
0003baf0:·653e·0a23·2046·696e·6420·7768·6963·6820··e>.#·Find·which· 
0003bb00:·6669·6c65·7320·6861·7665·2069·6e63·6f72··files·have·incor 
0003bb10:·7265·6374·2068·6173·6820·286e·6f74·2069··rect·hash·(not·i 
0003bb20:·6e20·2f65·7463·2c20·6265·6361·7573·6520··n·/etc,·because· 
0003bb30:·6f66·2074·6865·2073·7973·7465·6d20·7265··of·the·system·re 
0003bb40:·6c61·7465·6420·636f·6e66·6967·2066·696c··lated·config·fil 
0003bb50:·6573·2920·616e·6420·7468·656e·2067·6574··es)·and·then·get 
0003bb60:·2066·696c·6573·206e·616d·6573·0a66·696c···files·names.fil 
0003bb70:·6573·5f77·6974·685f·696e·636f·7272·6563··es_with_incorrec 
0003bb80:·745f·6861·7368·3d22·2428·7270·6d20·2d56··t_hash="$(rpm·-V 
0003bb90:·6120·2d2d·6e6f·636f·6e66·6967·207c·2067··a·--noconfig·|·g 
0003bba0:·7265·7020·2d45·2027·5e2e·2e35·2720·7c20··rep·-E·'^..5'·|· 
0003bbb0:·6177·6b20·277b·7072·696e·7420·244e·467d··awk·'{print·$NF} 
0003bbc0:·2720·2922·0a0a·6966·205b·202d·6e20·2224··'·)"..if·[·-n·"$ 
0003bbd0:·6669·6c65·735f·7769·7468·5f69·6e63·6f72··files_with_incor 
0003bbe0:·7265·6374·5f68·6173·6822·205d·3b20·7468··rect_hash"·];·th 
0003bbf0:·656e·0a20·2020·2023·2046·726f·6d20·6669··en.····#·From·fi 
0003bc00:·6c65·7320·6e61·6d65·7320·6765·7420·7061··les·names·get·pa 
0003bc10:·636b·6167·6520·6e61·6d65·7320·616e·6420··ckage·names·and· 
0003bc20:·6368·616e·6765·206e·6577·6c69·6e65·2074··change·newline·t 
0003bc30:·6f20·7370·6163·652c·2062·6563·6175·7365··o·space,·because 
0003bc40:·2072·706d·2077·7269·7465·7320·6561·6368···rpm·writes·each 
0003bc50:·2070·6163·6b61·6765·2074·6f20·6e65·7720···package·to·new· 
0003bc60:·6c69·6e65·0a20·2020·2070·6163·6b61·6765··line.····package 
0003bc70:·735f·746f·5f72·6569·6e73·7461·6c6c·3d22··s_to_reinstall=" 
0003bc80:·2428·7270·6d20·2d71·6620·2466·696c·6573··$(rpm·-qf·$files 
0003bc90:·5f77·6974·685f·696e·636f·7272·6563·745f··_with_incorrect_ 
0003bca0:·6861·7368·207c·2074·7220·275c·6e27·2027··hash·|·tr·'\n'·' 
0003bcb0:·2027·2922·0a0a·2020·2020·0a20·2020·2064···')"..····.····d 
0003bcc0:·6e66·2072·6569·6e73·7461·6c6c·202d·7920··nf·reinstall·-y· 
0003bcd0:·2470·6163·6b61·6765·735f·746f·5f72·6569··$packages_to_rei 
0003bce0:·6e73·7461·6c6c·0a20·2020·200a·6669·0a3c··nstall.····.fi.< 
0003bcf0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003bd00:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003bd10:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003bd20:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003bd30:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003bd40:·2223·6964·6d38·3038·3922·2074·6162·696e··"#idm8089"·tabin 
0003bd50:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003bd60:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003bd70:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003bd80:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003bd90:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003bda0:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans0003ba90:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans
0003bdb0:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...0003baa0:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...
0003bdc0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003bab0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003bdd0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003bac0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003bde0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003bad0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003bdf0:·2269·646d·3830·3839·223e·3c74·6162·6c65··"idm8089"><table0003bae0:·2269·646d·3830·3838·223e·3c74·6162·6c65··"idm8088"><table
0003be00:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003baf0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003be10:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003bb00:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003be20:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003bb10:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003be30:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003bb20:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003be40:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003bb30:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003be50:·2f74·683e·3c74·643e·6869·6768·3c2f·7464··/th><td>high</td0003bb40:·2f74·683e·3c74·643e·6869·6768·3c2f·7464··/th><td>high</td
0003be60:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003bb50:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003be70:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003bb60:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003be80:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t0003bb70:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t
0003be90:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot0003bb80:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
0003bea0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<0003bb90:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003beb0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003bba0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003bec0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003bbb0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003bed0:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>0003bbc0:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>
0003bee0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003bbd0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
0003bef0:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·0003bbe0:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·
0003bf00:·2753·6574·2066·6163·743a·2050·6163·6b61··'Set·fact:·Packa0003bbf0:·2753·6574·2066·6163·743a·2050·6163·6b61··'Set·fact:·Packa
0003bf10:·6765·206d·616e·6167·6572·2072·6569·6e73··ge·manager·reins0003bc00:·6765·206d·616e·6167·6572·2072·6569·6e73··ge·manager·reins
0003bf20:·7461·6c6c·2063·6f6d·6d61·6e64·270a·2020··tall·command'.··0003bc10:·7461·6c6c·2063·6f6d·6d61·6e64·270a·2020··tall·command'.··
0003bf30:·7365·745f·6661·6374·3a0a·2020·2020·7061··set_fact:.····pa0003bc20:·7365·745f·6661·6374·3a0a·2020·2020·7061··set_fact:.····pa
0003bf40:·636b·6167·655f·6d61·6e61·6765·725f·7265··ckage_manager_re0003bc30:·636b·6167·655f·6d61·6e61·6765·725f·7265··ckage_manager_re
0003bf50:·696e·7374·616c·6c5f·636d·643a·2064·6e66··install_cmd:·dnf0003bc40:·696e·7374·616c·6c5f·636d·643a·2064·6e66··install_cmd:·dnf
0003bf60:·2072·6569·6e73·7461·6c6c·202d·790a·2020···reinstall·-y.··0003bc50:·2072·6569·6e73·7461·6c6c·202d·790a·2020···reinstall·-y.··
0003bf70:·7768·656e·3a20·616e·7369·626c·655f·6469··when:·ansible_di0003bc60:·7768·656e·3a20·616e·7369·626c·655f·6469··when:·ansible_di
0003bf80:·7374·7269·6275·7469·6f6e·2069·6e20·5b20··stribution·in·[·0003bc70:·7374·7269·6275·7469·6f6e·2069·6e20·5b20··stribution·in·[·
0003bf90:·2246·6564·6f72·6122·2c20·2252·6564·4861··"Fedora",·"RedHa0003bc80:·2246·6564·6f72·6122·2c20·2252·6564·4861··"Fedora",·"RedHa
0003bfa0:·7422·2c20·2243·656e·744f·5322·2c20·224f··t",·"CentOS",·"O0003bc90:·7422·2c20·2243·656e·744f·5322·2c20·224f··t",·"CentOS",·"O
0003bfb0:·7261·636c·654c·696e·7578·2220·5d0a·2020··racleLinux"·].··0003bca0:·7261·636c·654c·696e·7578·2220·5d0a·2020··racleLinux"·].··
0003bfc0:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-50003bcb0:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-5
0003bfd0:·2e31·302e·342e·310a·2020·2d20·4e49·5354··.10.4.1.··-·NIST0003bcc0:·2e31·302e·342e·310a·2020·2d20·4e49·5354··.10.4.1.··-·NIST
0003bfe0:·2d38·3030·2d31·3731·2d33·2e33·2e38·0a20··-800-171-3.3.8.·0003bcd0:·2d38·3030·2d31·3731·2d33·2e33·2e38·0a20··-800-171-3.3.8.·
0003bff0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-0003bce0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
0003c000:·332e·342e·310a·2020·2d20·4e49·5354·2d38··3.4.1.··-·NIST-80003bcf0:·332e·342e·310a·2020·2d20·4e49·5354·2d38··3.4.1.··-·NIST-8
0003c010:·3030·2d35·332d·4155·2d39·2833·290a·2020··00-53-AU-9(3).··0003bd00:·3030·2d35·332d·4155·2d39·2833·290a·2020··00-53-AU-9(3).··
0003c020:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM0003bd10:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
0003c030:·2d36·2863·290a·2020·2d20·4e49·5354·2d38··-6(c).··-·NIST-80003bd20:·2d36·2863·290a·2020·2d20·4e49·5354·2d38··-6(c).··-·NIST-8
0003c040:·3030·2d35·332d·434d·2d36·2864·290a·2020··00-53-CM-6(d).··0003bd30:·3030·2d35·332d·434d·2d36·2864·290a·2020··00-53-CM-6(d).··
0003c050:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI0003bd40:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI
0003c060:·2d37·0a20·202d·204e·4953·542d·3830·302d··-7.··-·NIST-800-0003bd50:·2d37·0a20·202d·204e·4953·542d·3830·302d··-7.··-·NIST-800-
0003c070:·3533·2d53·492d·3728·3129·0a20·202d·204e··53-SI-7(1).··-·N0003bd60:·3533·2d53·492d·3728·3129·0a20·202d·204e··53-SI-7(1).··-·N
0003c080:·4953·542d·3830·302d·3533·2d53·492d·3728··IST-800-53-SI-7(0003bd70:·4953·542d·3830·302d·3533·2d53·492d·3728··IST-800-53-SI-7(
0003c090:·3629·0a20·202d·2050·4349·2d44·5353·2d52··6).··-·PCI-DSS-R0003bd80:·3629·0a20·202d·2050·4349·2d44·5353·2d52··6).··-·PCI-DSS-R
0003c0a0:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI-0003bd90:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI-
0003c0b0:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··-0003bda0:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··-
0003c0c0:·2068·6967·685f·636f·6d70·6c65·7869·7479···high_complexity0003bdb0:·2068·6967·685f·636f·6d70·6c65·7869·7479···high_complexity
0003c0d0:·0a20·202d·2068·6967·685f·7365·7665·7269··.··-·high_severi0003bdc0:·0a20·202d·2068·6967·685f·7365·7665·7269··.··-·high_severi
0003c0e0:·7479·0a20·202d·206d·6564·6975·6d5f·6469··ty.··-·medium_di0003bdd0:·7479·0a20·202d·206d·6564·6975·6d5f·6469··ty.··-·medium_di
0003c0f0:·7372·7570·7469·6f6e·0a20·202d·206e·6f5f··sruption.··-·no_0003bde0:·7372·7570·7469·6f6e·0a20·202d·206e·6f5f··sruption.··-·no_
Max diff block lines reached; 6529409/6555131 bytes (99.61%) of diff not shown.
711 KB
html2text {}
    
Offset 59, 15 lines modifiedOffset 59, 15 lines modified
59 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Australian·Cyber·Security·Centre·(ACSC)·Essential·Eight59 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Australian·Cyber·Security·Centre·(ACSC)·Essential·Eight
60 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_e860 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_e8
61 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*61 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
62 ····*·cpe:/o:redhat:enterprise_linux:962 ····*·cpe:/o:redhat:enterprise_linux:9
63 ····*·cpe:/o:centos:centos:963 ····*·cpe:/o:centos:centos:9
64 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*64 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
65 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8465 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
66 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)66 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
67 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*67 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
68 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s68 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
69 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e69 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
70 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l70 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
71 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g71 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
72 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s72 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
73 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s73 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 121, 27 lines modifiedOffset 121, 14 lines modified
121 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6121 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
122 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4122 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
123 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)123 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
124 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1124 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
125 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5125 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
126 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227126 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
127 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2127 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
129 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
130 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
131 if·[·-n·"$files_with_incorrect_hash"·];·then 
132 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
133 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
134 ····dnf·reinstall·-y·$packages_to_reinstall 
  
135 fi 
136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
141 -·name:·'Set·fact:·Package·manager·reinstall·command'133 -·name:·'Set·fact:·Package·manager·reinstall·command'
142 ··set_fact:134 ··set_fact:
Offset 268, 14 lines modifiedOffset 255, 27 lines modified
268 ··-·PCI-DSSv4-11.5.2255 ··-·PCI-DSSv4-11.5.2
269 ··-·high_complexity256 ··-·high_complexity
270 ··-·high_severity257 ··-·high_severity
271 ··-·medium_disruption258 ··-·medium_disruption
272 ··-·no_reboot_needed259 ··-·no_reboot_needed
273 ··-·restrict_strategy260 ··-·restrict_strategy
274 ··-·rpm_verify_hashes261 ··-·rpm_verify_hashes
 262 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 263 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 264 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 265 if·[·-n·"$files_with_incorrect_hash"·];·then
 266 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 267 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 268 ····dnf·reinstall·-y·$packages_to_reinstall
  
 269 fi
275 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*270 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
276 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:271 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
277 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'272 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
278 run·the·following·command·to·determine·which·package·owns·it:273 run·the·following·command·to·determine·which·package·owns·it:
279 $·rpm·-qf·FILENAME274 $·rpm·-qf·FILENAME
280 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:275 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
281 $·sudo·rpm·--setugids·PACKAGENAME276 $·sudo·rpm·--setugids·PACKAGENAME
Offset 294, 40 lines modifiedOffset 294, 14 lines modified
294 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5294 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
295 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2295 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
296 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)296 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
297 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1297 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
298 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5298 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
299 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108299 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
300 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2300 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
301 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
302 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
303 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
304 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
305 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
306 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
307 declare·-A·SETPERMS_RPM_DICT 
  
308 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
309 #·is·expected·by·the·RPM·database 
310 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
311 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
312 do 
313 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
314 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
315 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
316 done 
  
317 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
318 #·correct·values 
319 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
320 do 
321 ········rpm·--setugids·"${RPM_PACKAGE}" 
322 done 
323 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8301 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
324 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high302 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
325 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium303 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
326 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false304 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
327 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict305 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
328 -·name:·Read·list·of·files·with·incorrect·ownership306 -·name:·Read·list·of·files·with·incorrect·ownership
329 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev307 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 402, 14 lines modifiedOffset 376, 40 lines modified
402 ··-·PCI-DSSv4-11.5.2376 ··-·PCI-DSSv4-11.5.2
403 ··-·high_complexity377 ··-·high_complexity
404 ··-·high_severity378 ··-·high_severity
405 ··-·medium_disruption379 ··-·medium_disruption
406 ··-·no_reboot_needed380 ··-·no_reboot_needed
407 ··-·restrict_strategy381 ··-·restrict_strategy
408 ··-·rpm_verify_ownership382 ··-·rpm_verify_ownership
 383 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 384 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 385 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 386 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 387 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 388 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 720035/727868 bytes (98.92%) of diff not shown.
17.5 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-hipaa.html
    
Offset 14434, 15 lines modifiedOffset 14434, 15 lines modified
00038610:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00038610:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00038620:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00038620:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00038630:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<00038630:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<
00038640:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00038640:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00038650:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00038650:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00038660:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00038660:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00038670:·2020·2020·2020·2020·2020·2020·2020·2028·················(00038670:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00038680:·6173·206f·6620·3230·3236·2d30·312d·3038··as·of·2026-01-0800038680:·6173·206f·6620·3230·3234·2d31·322d·3037··as·of·2024-12-07
00038690:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00038690:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
000386a0:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di000386a0:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
000386b0:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C000386b0:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
000386c0:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>000386c0:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
000386d0:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc000386d0:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
000386e0:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje000386e0:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
000386f0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group000386f0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
Offset 15288, 301 lines modifiedOffset 15288, 301 lines modified
0003bb70:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003bb70:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003bb80:·2223·6964·6d38·3038·3822·2074·6162·696e··"#idm8088"·tabin0003bb80:·2223·6964·6d38·3038·3822·2074·6162·696e··"#idm8088"·tabin
0003bb90:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003bb90:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003bba0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003bba0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003bbb0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003bbb0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003bbc0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003bbc0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003bbd0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003bbd0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003bbe0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
0003bbf0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
0003bc00:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003bc10:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003bc20:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003bc30:·6d38·3038·3822·3e3c·7072·653e·3c63·6f64··m8088"><pre><cod 
0003bc40:·653e·0a23·2046·696e·6420·7768·6963·6820··e>.#·Find·which· 
0003bc50:·6669·6c65·7320·6861·7665·2069·6e63·6f72··files·have·incor 
0003bc60:·7265·6374·2068·6173·6820·286e·6f74·2069··rect·hash·(not·i 
0003bc70:·6e20·2f65·7463·2c20·6265·6361·7573·6520··n·/etc,·because· 
0003bc80:·6f66·2074·6865·2073·7973·7465·6d20·7265··of·the·system·re 
0003bc90:·6c61·7465·6420·636f·6e66·6967·2066·696c··lated·config·fil 
0003bca0:·6573·2920·616e·6420·7468·656e·2067·6574··es)·and·then·get 
0003bcb0:·2066·696c·6573·206e·616d·6573·0a66·696c···files·names.fil 
0003bcc0:·6573·5f77·6974·685f·696e·636f·7272·6563··es_with_incorrec 
0003bcd0:·745f·6861·7368·3d22·2428·7270·6d20·2d56··t_hash="$(rpm·-V 
0003bce0:·6120·2d2d·6e6f·636f·6e66·6967·207c·2067··a·--noconfig·|·g 
0003bcf0:·7265·7020·2d45·2027·5e2e·2e35·2720·7c20··rep·-E·'^..5'·|· 
0003bd00:·6177·6b20·277b·7072·696e·7420·244e·467d··awk·'{print·$NF} 
0003bd10:·2720·2922·0a0a·6966·205b·202d·6e20·2224··'·)"..if·[·-n·"$ 
0003bd20:·6669·6c65·735f·7769·7468·5f69·6e63·6f72··files_with_incor 
0003bd30:·7265·6374·5f68·6173·6822·205d·3b20·7468··rect_hash"·];·th 
0003bd40:·656e·0a20·2020·2023·2046·726f·6d20·6669··en.····#·From·fi 
0003bd50:·6c65·7320·6e61·6d65·7320·6765·7420·7061··les·names·get·pa 
0003bd60:·636b·6167·6520·6e61·6d65·7320·616e·6420··ckage·names·and· 
0003bd70:·6368·616e·6765·206e·6577·6c69·6e65·2074··change·newline·t 
0003bd80:·6f20·7370·6163·652c·2062·6563·6175·7365··o·space,·because 
0003bd90:·2072·706d·2077·7269·7465·7320·6561·6368···rpm·writes·each 
0003bda0:·2070·6163·6b61·6765·2074·6f20·6e65·7720···package·to·new· 
0003bdb0:·6c69·6e65·0a20·2020·2070·6163·6b61·6765··line.····package 
0003bdc0:·735f·746f·5f72·6569·6e73·7461·6c6c·3d22··s_to_reinstall=" 
0003bdd0:·2428·7270·6d20·2d71·6620·2466·696c·6573··$(rpm·-qf·$files 
0003bde0:·5f77·6974·685f·696e·636f·7272·6563·745f··_with_incorrect_ 
0003bdf0:·6861·7368·207c·2074·7220·275c·6e27·2027··hash·|·tr·'\n'·' 
0003be00:·2027·2922·0a0a·2020·2020·0a20·2020·2064···')"..····.····d 
0003be10:·6e66·2072·6569·6e73·7461·6c6c·202d·7920··nf·reinstall·-y· 
0003be20:·2470·6163·6b61·6765·735f·746f·5f72·6569··$packages_to_rei 
0003be30:·6e73·7461·6c6c·0a20·2020·200a·6669·0a3c··nstall.····.fi.< 
0003be40:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003be50:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003be60:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003be70:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003be80:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003be90:·2223·6964·6d38·3038·3922·2074·6162·696e··"#idm8089"·tabin 
0003bea0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003beb0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003bec0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003bed0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003bee0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003bef0:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans0003bbe0:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans
0003bf00:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...0003bbf0:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...
0003bf10:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003bc00:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003bf20:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003bc10:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003bf30:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003bc20:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003bf40:·2269·646d·3830·3839·223e·3c74·6162·6c65··"idm8089"><table0003bc30:·2269·646d·3830·3838·223e·3c74·6162·6c65··"idm8088"><table
0003bf50:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003bc40:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003bf60:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003bc50:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003bf70:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003bc60:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003bf80:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003bc70:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003bf90:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003bc80:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003bfa0:·2f74·683e·3c74·643e·6869·6768·3c2f·7464··/th><td>high</td0003bc90:·2f74·683e·3c74·643e·6869·6768·3c2f·7464··/th><td>high</td
0003bfb0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003bca0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003bfc0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003bcb0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003bfd0:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t0003bcc0:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t
0003bfe0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot0003bcd0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
0003bff0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<0003bce0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003c000:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003bcf0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c010:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003bd00:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003c020:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>0003bd10:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>
0003c030:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003bd20:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
0003c040:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·0003bd30:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·
0003c050:·2753·6574·2066·6163·743a·2050·6163·6b61··'Set·fact:·Packa0003bd40:·2753·6574·2066·6163·743a·2050·6163·6b61··'Set·fact:·Packa
0003c060:·6765·206d·616e·6167·6572·2072·6569·6e73··ge·manager·reins0003bd50:·6765·206d·616e·6167·6572·2072·6569·6e73··ge·manager·reins
0003c070:·7461·6c6c·2063·6f6d·6d61·6e64·270a·2020··tall·command'.··0003bd60:·7461·6c6c·2063·6f6d·6d61·6e64·270a·2020··tall·command'.··
0003c080:·7365·745f·6661·6374·3a0a·2020·2020·7061··set_fact:.····pa0003bd70:·7365·745f·6661·6374·3a0a·2020·2020·7061··set_fact:.····pa
0003c090:·636b·6167·655f·6d61·6e61·6765·725f·7265··ckage_manager_re0003bd80:·636b·6167·655f·6d61·6e61·6765·725f·7265··ckage_manager_re
0003c0a0:·696e·7374·616c·6c5f·636d·643a·2064·6e66··install_cmd:·dnf0003bd90:·696e·7374·616c·6c5f·636d·643a·2064·6e66··install_cmd:·dnf
0003c0b0:·2072·6569·6e73·7461·6c6c·202d·790a·2020···reinstall·-y.··0003bda0:·2072·6569·6e73·7461·6c6c·202d·790a·2020···reinstall·-y.··
0003c0c0:·7768·656e·3a20·616e·7369·626c·655f·6469··when:·ansible_di0003bdb0:·7768·656e·3a20·616e·7369·626c·655f·6469··when:·ansible_di
0003c0d0:·7374·7269·6275·7469·6f6e·2069·6e20·5b20··stribution·in·[·0003bdc0:·7374·7269·6275·7469·6f6e·2069·6e20·5b20··stribution·in·[·
0003c0e0:·2246·6564·6f72·6122·2c20·2252·6564·4861··"Fedora",·"RedHa0003bdd0:·2246·6564·6f72·6122·2c20·2252·6564·4861··"Fedora",·"RedHa
0003c0f0:·7422·2c20·2243·656e·744f·5322·2c20·224f··t",·"CentOS",·"O0003bde0:·7422·2c20·2243·656e·744f·5322·2c20·224f··t",·"CentOS",·"O
0003c100:·7261·636c·654c·696e·7578·2220·5d0a·2020··racleLinux"·].··0003bdf0:·7261·636c·654c·696e·7578·2220·5d0a·2020··racleLinux"·].··
0003c110:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-50003be00:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-5
0003c120:·2e31·302e·342e·310a·2020·2d20·4e49·5354··.10.4.1.··-·NIST0003be10:·2e31·302e·342e·310a·2020·2d20·4e49·5354··.10.4.1.··-·NIST
0003c130:·2d38·3030·2d31·3731·2d33·2e33·2e38·0a20··-800-171-3.3.8.·0003be20:·2d38·3030·2d31·3731·2d33·2e33·2e38·0a20··-800-171-3.3.8.·
0003c140:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-0003be30:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
0003c150:·332e·342e·310a·2020·2d20·4e49·5354·2d38··3.4.1.··-·NIST-80003be40:·332e·342e·310a·2020·2d20·4e49·5354·2d38··3.4.1.··-·NIST-8
0003c160:·3030·2d35·332d·4155·2d39·2833·290a·2020··00-53-AU-9(3).··0003be50:·3030·2d35·332d·4155·2d39·2833·290a·2020··00-53-AU-9(3).··
0003c170:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM0003be60:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
0003c180:·2d36·2863·290a·2020·2d20·4e49·5354·2d38··-6(c).··-·NIST-80003be70:·2d36·2863·290a·2020·2d20·4e49·5354·2d38··-6(c).··-·NIST-8
0003c190:·3030·2d35·332d·434d·2d36·2864·290a·2020··00-53-CM-6(d).··0003be80:·3030·2d35·332d·434d·2d36·2864·290a·2020··00-53-CM-6(d).··
0003c1a0:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI0003be90:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI
0003c1b0:·2d37·0a20·202d·204e·4953·542d·3830·302d··-7.··-·NIST-800-0003bea0:·2d37·0a20·202d·204e·4953·542d·3830·302d··-7.··-·NIST-800-
0003c1c0:·3533·2d53·492d·3728·3129·0a20·202d·204e··53-SI-7(1).··-·N0003beb0:·3533·2d53·492d·3728·3129·0a20·202d·204e··53-SI-7(1).··-·N
0003c1d0:·4953·542d·3830·302d·3533·2d53·492d·3728··IST-800-53-SI-7(0003bec0:·4953·542d·3830·302d·3533·2d53·492d·3728··IST-800-53-SI-7(
0003c1e0:·3629·0a20·202d·2050·4349·2d44·5353·2d52··6).··-·PCI-DSS-R0003bed0:·3629·0a20·202d·2050·4349·2d44·5353·2d52··6).··-·PCI-DSS-R
0003c1f0:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI-0003bee0:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI-
0003c200:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··-0003bef0:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··-
0003c210:·2068·6967·685f·636f·6d70·6c65·7869·7479···high_complexity0003bf00:·2068·6967·685f·636f·6d70·6c65·7869·7479···high_complexity
0003c220:·0a20·202d·2068·6967·685f·7365·7665·7269··.··-·high_severi0003bf10:·0a20·202d·2068·6967·685f·7365·7665·7269··.··-·high_severi
0003c230:·7479·0a20·202d·206d·6564·6975·6d5f·6469··ty.··-·medium_di0003bf20:·7479·0a20·202d·206d·6564·6975·6d5f·6469··ty.··-·medium_di
0003c240:·7372·7570·7469·6f6e·0a20·202d·206e·6f5f··sruption.··-·no_0003bf30:·7372·7570·7469·6f6e·0a20·202d·206e·6f5f··sruption.··-·no_
0003c250:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.··0003bf40:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.··
Max diff block lines reached; 17069785/17095369 bytes (99.85%) of diff not shown.
1.22 MB
html2text {}
    
Offset 64, 15 lines modifiedOffset 64, 15 lines modified
64 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Health·Insurance·Portability·and·Accountability·Act·(HIPAA)64 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Health·Insurance·Portability·and·Accountability·Act·(HIPAA)
65 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_hipaa65 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_hipaa
66 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*66 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
67 ····*·cpe:/o:redhat:enterprise_linux:967 ····*·cpe:/o:redhat:enterprise_linux:9
68 ····*·cpe:/o:centos:centos:968 ····*·cpe:/o:centos:centos:9
69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
70 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8470 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
73 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s73 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
74 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e74 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
75 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l75 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
76 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n76 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
77 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g77 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
78 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s78 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 126, 27 lines modifiedOffset 126, 14 lines modified
126 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6126 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
127 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4127 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
128 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)128 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
129 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1129 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
130 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5130 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
131 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227131 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
132 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2132 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
134 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
135 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
136 if·[·-n·"$files_with_incorrect_hash"·];·then 
137 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
138 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
139 ····dnf·reinstall·-y·$packages_to_reinstall 
  
140 fi 
141 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
142 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
143 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
144 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
145 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
146 -·name:·'Set·fact:·Package·manager·reinstall·command'138 -·name:·'Set·fact:·Package·manager·reinstall·command'
147 ··set_fact:139 ··set_fact:
Offset 273, 14 lines modifiedOffset 260, 27 lines modified
273 ··-·PCI-DSSv4-11.5.2260 ··-·PCI-DSSv4-11.5.2
274 ··-·high_complexity261 ··-·high_complexity
275 ··-·high_severity262 ··-·high_severity
276 ··-·medium_disruption263 ··-·medium_disruption
277 ··-·no_reboot_needed264 ··-·no_reboot_needed
278 ··-·restrict_strategy265 ··-·restrict_strategy
279 ··-·rpm_verify_hashes266 ··-·rpm_verify_hashes
 267 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 268 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 269 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 270 if·[·-n·"$files_with_incorrect_hash"·];·then
 271 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 272 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 273 ····dnf·reinstall·-y·$packages_to_reinstall
  
 274 fi
280 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*275 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
281 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:276 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:
282 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'277 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'
283 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:278 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:
284 $·rpm·-qf·FILENAME279 $·rpm·-qf·FILENAME
  
285 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:280 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
Offset 301, 44 lines modifiedOffset 301, 14 lines modified
301 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5301 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
302 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2302 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
303 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)303 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)
304 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1304 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
305 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5305 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
306 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108306 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108
307 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2307 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
308 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
309 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
310 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
311 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
312 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
313 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
314 declare·-A·SETPERMS_RPM_DICT 
  
315 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
316 #·is·expected·by·the·RPM·database 
317 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}') 
  
318 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
319 do 
320 ········#·NOTE:·some·files·maybe·controlled·by·more·then·one·package 
321 ········readarray·-t·RPM_PACKAGES·<·<(rpm·-qf·"${FILE_PATH}") 
322 ········for·RPM_PACKAGE·in·"${RPM_PACKAGES[@]}" 
323 ········do 
324 ················#·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
325 ················SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
326 ········done 
327 done 
  
328 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
329 #·correct·values 
330 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
331 do 
332 »       rpm·--restore·"${RPM_PACKAGE}" 
333 done 
334 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8308 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
335 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high309 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
336 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium310 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
337 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false311 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
338 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict312 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
339 -·name:·Read·list·of·files·with·incorrect·permissions313 -·name:·Read·list·of·files·with·incorrect·permissions
340 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev314 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 416, 14 lines modifiedOffset 386, 44 lines modified
416 ··-·PCI-DSSv4-11.5.2386 ··-·PCI-DSSv4-11.5.2
417 ··-·high_complexity387 ··-·high_complexity
418 ··-·high_severity388 ··-·high_severity
419 ··-·medium_disruption389 ··-·medium_disruption
420 ··-·no_reboot_needed390 ··-·no_reboot_needed
421 ··-·restrict_strategy391 ··-·restrict_strategy
422 ··-·rpm_verify_permissions392 ··-·rpm_verify_permissions
 393 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 394 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 395 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
Max diff block lines reached; 1272617/1280841 bytes (99.36%) of diff not shown.
10.5 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-ism_o.html
    
Offset 14427, 15 lines modifiedOffset 14427, 15 lines modified
000385a0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>000385a0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
000385b0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:000385b0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
000385c0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<000385c0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<
000385d0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>000385d0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
000385e0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf000385e0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
000385f0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····000385f0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00038600:·2020·2020·2020·2020·2020·2020·2020·2028·················(00038600:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00038610:·6173·206f·6620·3230·3236·2d30·312d·3038··as·of·2026-01-0800038610:·6173·206f·6620·3230·3234·2d31·322d·3037··as·of·2024-12-07
00038620:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00038620:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00038630:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00038630:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00038640:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00038640:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00038650:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00038650:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00038660:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00038660:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00038670:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00038670:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00038680:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00038680:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
Offset 15302, 300 lines modifiedOffset 15302, 300 lines modified
0003bc50:·7267·6574·3d22·2369·646d·3830·3838·2220··rget="#idm8088"·0003bc50:·7267·6574·3d22·2369·646d·3830·3838·2220··rget="#idm8088"·
0003bc60:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003bc60:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003bc70:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003bc70:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003bc80:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003bc80:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003bc90:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003bc90:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003bca0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003bca0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003bcb0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003bcb0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003bcc0:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
0003bcd0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003bce0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003bcf0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003bd00:·643d·2269·646d·3830·3838·223e·3c70·7265··d="idm8088"><pre 
0003bd10:·3e3c·636f·6465·3e0a·2320·4669·6e64·2077··><code>.#·Find·w 
0003bd20:·6869·6368·2066·696c·6573·2068·6176·6520··hich·files·have· 
0003bd30:·696e·636f·7272·6563·7420·6861·7368·2028··incorrect·hash·( 
0003bd40:·6e6f·7420·696e·202f·6574·632c·2062·6563··not·in·/etc,·bec 
0003bd50:·6175·7365·206f·6620·7468·6520·7379·7374··ause·of·the·syst 
0003bd60:·656d·2072·656c·6174·6564·2063·6f6e·6669··em·related·confi 
0003bd70:·6720·6669·6c65·7329·2061·6e64·2074·6865··g·files)·and·the 
0003bd80:·6e20·6765·7420·6669·6c65·7320·6e61·6d65··n·get·files·name 
0003bd90:·730a·6669·6c65·735f·7769·7468·5f69·6e63··s.files_with_inc 
0003bda0:·6f72·7265·6374·5f68·6173·683d·2224·2872··orrect_hash="$(r 
0003bdb0:·706d·202d·5661·202d·2d6e·6f63·6f6e·6669··pm·-Va·--noconfi 
0003bdc0:·6720·7c20·6772·6570·202d·4520·275e·2e2e··g·|·grep·-E·'^.. 
0003bdd0:·3527·207c·2061·776b·2027·7b70·7269·6e74··5'·|·awk·'{print 
0003bde0:·2024·4e46·7d27·2029·220a·0a69·6620·5b20···$NF}'·)"..if·[· 
0003bdf0:·2d6e·2022·2466·696c·6573·5f77·6974·685f··-n·"$files_with_ 
0003be00:·696e·636f·7272·6563·745f·6861·7368·2220··incorrect_hash"· 
0003be10:·5d3b·2074·6865·6e0a·2020·2020·2320·4672··];·then.····#·Fr 
0003be20:·6f6d·2066·696c·6573·206e·616d·6573·2067··om·files·names·g 
0003be30:·6574·2070·6163·6b61·6765·206e·616d·6573··et·package·names 
0003be40:·2061·6e64·2063·6861·6e67·6520·6e65·776c···and·change·newl 
0003be50:·696e·6520·746f·2073·7061·6365·2c20·6265··ine·to·space,·be 
0003be60:·6361·7573·6520·7270·6d20·7772·6974·6573··cause·rpm·writes 
0003be70:·2065·6163·6820·7061·636b·6167·6520·746f···each·package·to 
0003be80:·206e·6577·206c·696e·650a·2020·2020·7061···new·line.····pa 
0003be90:·636b·6167·6573·5f74·6f5f·7265·696e·7374··ckages_to_reinst 
0003bea0:·616c·6c3d·2224·2872·706d·202d·7166·2024··all="$(rpm·-qf·$ 
0003beb0:·6669·6c65·735f·7769·7468·5f69·6e63·6f72··files_with_incor 
0003bec0:·7265·6374·5f68·6173·6820·7c20·7472·2027··rect_hash·|·tr·' 
0003bed0:·5c6e·2720·2720·2729·220a·0a20·2020·200a··\n'·'·')"..····. 
0003bee0:·2020·2020·646e·6620·7265·696e·7374·616c······dnf·reinstal 
0003bef0:·6c20·2d79·2024·7061·636b·6167·6573·5f74··l·-y·$packages_t 
0003bf00:·6f5f·7265·696e·7374·616c·6c0a·2020·2020··o_reinstall.···· 
0003bf10:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre 
0003bf20:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003bf30:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003bf40:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003bf50:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003bf60:·7267·6574·3d22·2369·646d·3830·3839·2220··rget="#idm8089"· 
0003bf70:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003bf80:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003bf90:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003bfa0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003bfb0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003bfc0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003bfd0:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe0003bcc0:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe
0003bfe0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003bcd0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003bff0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003bce0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003c000:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003bcf0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003c010:·2220·6964·3d22·6964·6d38·3038·3922·3e3c··"·id="idm8089"><0003bd00:·2220·6964·3d22·6964·6d38·3038·3822·3e3c··"·id="idm8088"><
0003c020:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003bd10:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003c030:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003bd20:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003c040:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003bd30:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003c050:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003bd40:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003c060:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003bd50:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003c070:·6974·793a·3c2f·7468·3e3c·7464·3e68·6967··ity:</th><td>hig0003bd60:·6974·793a·3c2f·7468·3e3c·7464·3e68·6967··ity:</th><td>hig
0003c080:·683c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··h</td></tr><tr><0003bd70:·683c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··h</td></tr><tr><
0003c090:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003bd80:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
0003c0a0:·7468·3e3c·7464·3e6d·6564·6975·6d3c·2f74··th><td>medium</t0003bd90:·7468·3e3c·7464·3e6d·6564·6975·6d3c·2f74··th><td>medium</t
0003c0b0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R0003bda0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
0003c0c0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f0003bdb0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
0003c0d0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t0003bdc0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
0003c0e0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<0003bdd0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0003c0f0:·2f74·683e·3c74·643e·7265·7374·7269·6374··/th><td>restrict0003bde0:·2f74·683e·3c74·643e·7265·7374·7269·6374··/th><td>restrict
0003c100:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003bdf0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003c110:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n0003be00:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n
0003c120:·616d·653a·2027·5365·7420·6661·6374·3a20··ame:·'Set·fact:·0003be10:·616d·653a·2027·5365·7420·6661·6374·3a20··ame:·'Set·fact:·
0003c130:·5061·636b·6167·6520·6d61·6e61·6765·7220··Package·manager·0003be20:·5061·636b·6167·6520·6d61·6e61·6765·7220··Package·manager·
0003c140:·7265·696e·7374·616c·6c20·636f·6d6d·616e··reinstall·comman0003be30:·7265·696e·7374·616c·6c20·636f·6d6d·616e··reinstall·comman
0003c150:·6427·0a20·2073·6574·5f66·6163·743a·0a20··d'.··set_fact:.·0003be40:·6427·0a20·2073·6574·5f66·6163·743a·0a20··d'.··set_fact:.·
0003c160:·2020·2070·6163·6b61·6765·5f6d·616e·6167·····package_manag0003be50:·2020·2070·6163·6b61·6765·5f6d·616e·6167·····package_manag
0003c170:·6572·5f72·6569·6e73·7461·6c6c·5f63·6d64··er_reinstall_cmd0003be60:·6572·5f72·6569·6e73·7461·6c6c·5f63·6d64··er_reinstall_cmd
0003c180:·3a20·646e·6620·7265·696e·7374·616c·6c20··:·dnf·reinstall·0003be70:·3a20·646e·6620·7265·696e·7374·616c·6c20··:·dnf·reinstall·
0003c190:·2d79·0a20·2077·6865·6e3a·2061·6e73·6962··-y.··when:·ansib0003be80:·2d79·0a20·2077·6865·6e3a·2061·6e73·6962··-y.··when:·ansib
0003c1a0:·6c65·5f64·6973·7472·6962·7574·696f·6e20··le_distribution·0003be90:·6c65·5f64·6973·7472·6962·7574·696f·6e20··le_distribution·
0003c1b0:·696e·205b·2022·4665·646f·7261·222c·2022··in·[·"Fedora",·"0003bea0:·696e·205b·2022·4665·646f·7261·222c·2022··in·[·"Fedora",·"
0003c1c0:·5265·6448·6174·222c·2022·4365·6e74·4f53··RedHat",·"CentOS0003beb0:·5265·6448·6174·222c·2022·4365·6e74·4f53··RedHat",·"CentOS
0003c1d0:·222c·2022·4f72·6163·6c65·4c69·6e75·7822··",·"OracleLinux"0003bec0:·222c·2022·4f72·6163·6c65·4c69·6e75·7822··",·"OracleLinux"
0003c1e0:·205d·0a20·2074·6167·733a·0a20·202d·2043···].··tags:.··-·C0003bed0:·205d·0a20·2074·6167·733a·0a20·202d·2043···].··tags:.··-·C
0003c1f0:·4a49·532d·352e·3130·2e34·2e31·0a20·202d··JIS-5.10.4.1.··-0003bee0:·4a49·532d·352e·3130·2e34·2e31·0a20·202d··JIS-5.10.4.1.··-
0003c200:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.0003bef0:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.
0003c210:·332e·380a·2020·2d20·4e49·5354·2d38·3030··3.8.··-·NIST-8000003bf00:·332e·380a·2020·2d20·4e49·5354·2d38·3030··3.8.··-·NIST-800
0003c220:·2d31·3731·2d33·2e34·2e31·0a20·202d·204e··-171-3.4.1.··-·N0003bf10:·2d31·3731·2d33·2e34·2e31·0a20·202d·204e··-171-3.4.1.··-·N
0003c230:·4953·542d·3830·302d·3533·2d41·552d·3928··IST-800-53-AU-9(0003bf20:·4953·542d·3830·302d·3533·2d41·552d·3928··IST-800-53-AU-9(
0003c240:·3329·0a20·202d·204e·4953·542d·3830·302d··3).··-·NIST-800-0003bf30:·3329·0a20·202d·204e·4953·542d·3830·302d··3).··-·NIST-800-
0003c250:·3533·2d43·4d2d·3628·6329·0a20·202d·204e··53-CM-6(c).··-·N0003bf40:·3533·2d43·4d2d·3628·6329·0a20·202d·204e··53-CM-6(c).··-·N
0003c260:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6(0003bf50:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6(
0003c270:·6429·0a20·202d·204e·4953·542d·3830·302d··d).··-·NIST-800-0003bf60:·6429·0a20·202d·204e·4953·542d·3830·302d··d).··-·NIST-800-
0003c280:·3533·2d53·492d·370a·2020·2d20·4e49·5354··53-SI-7.··-·NIST0003bf70:·3533·2d53·492d·370a·2020·2d20·4e49·5354··53-SI-7.··-·NIST
0003c290:·2d38·3030·2d35·332d·5349·2d37·2831·290a··-800-53-SI-7(1).0003bf80:·2d38·3030·2d35·332d·5349·2d37·2831·290a··-800-53-SI-7(1).
0003c2a0:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-0003bf90:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
0003c2b0:·5349·2d37·2836·290a·2020·2d20·5043·492d··SI-7(6).··-·PCI-0003bfa0:·5349·2d37·2836·290a·2020·2d20·5043·492d··SI-7(6).··-·PCI-
0003c2c0:·4453·532d·5265·712d·3131·2e35·0a20·202d··DSS-Req-11.5.··-0003bfb0:·4453·532d·5265·712d·3131·2e35·0a20·202d··DSS-Req-11.5.··-
0003c2d0:·2050·4349·2d44·5353·7634·2d31·312e·352e···PCI-DSSv4-11.5.0003bfc0:·2050·4349·2d44·5353·7634·2d31·312e·352e···PCI-DSSv4-11.5.
0003c2e0:·320a·2020·2d20·6869·6768·5f63·6f6d·706c··2.··-·high_compl0003bfd0:·320a·2020·2d20·6869·6768·5f63·6f6d·706c··2.··-·high_compl
0003c2f0:·6578·6974·790a·2020·2d20·6869·6768·5f73··exity.··-·high_s0003bfe0:·6578·6974·790a·2020·2d20·6869·6768·5f73··exity.··-·high_s
0003c300:·6576·6572·6974·790a·2020·2d20·6d65·6469··everity.··-·medi0003bff0:·6576·6572·6974·790a·2020·2d20·6d65·6469··everity.··-·medi
0003c310:·756d·5f64·6973·7275·7074·696f·6e0a·2020··um_disruption.··0003c000:·756d·5f64·6973·7275·7074·696f·6e0a·2020··um_disruption.··
0003c320:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need0003c010:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need
0003c330:·6564·0a20·202d·2072·6573·7472·6963·745f··ed.··-·restrict_0003c020:·6564·0a20·202d·2072·6573·7472·6963·745f··ed.··-·restrict_
Max diff block lines reached; 9901500/9927222 bytes (99.74%) of diff not shown.
1020 KB
html2text {}
    
Offset 62, 15 lines modifiedOffset 62, 15 lines modified
62 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Australian·Cyber·Security·Centre·(ACSC)·ISM·Official62 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Australian·Cyber·Security·Centre·(ACSC)·ISM·Official
63 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ism_o63 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ism_o
64 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*64 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
65 ····*·cpe:/o:redhat:enterprise_linux:965 ····*·cpe:/o:redhat:enterprise_linux:9
66 ····*·cpe:/o:centos:centos:966 ····*·cpe:/o:centos:centos:9
67 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*67 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
68 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8468 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
69 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)69 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
70 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*70 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
71 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s71 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
72 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e72 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
73 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l73 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
74 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g74 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
75 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s75 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
76 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s76 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 128, 27 lines modifiedOffset 128, 14 lines modified
128 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6128 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
129 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4129 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
130 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)130 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
131 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1131 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
132 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5132 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
133 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227133 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
134 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2134 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
136 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
137 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
138 if·[·-n·"$files_with_incorrect_hash"·];·then 
139 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
140 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
141 ····dnf·reinstall·-y·$packages_to_reinstall 
  
142 fi 
143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
144 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
145 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
146 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
147 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
148 -·name:·'Set·fact:·Package·manager·reinstall·command'140 -·name:·'Set·fact:·Package·manager·reinstall·command'
149 ··set_fact:141 ··set_fact:
Offset 275, 14 lines modifiedOffset 262, 27 lines modified
275 ··-·PCI-DSSv4-11.5.2262 ··-·PCI-DSSv4-11.5.2
276 ··-·high_complexity263 ··-·high_complexity
277 ··-·high_severity264 ··-·high_severity
278 ··-·medium_disruption265 ··-·medium_disruption
279 ··-·no_reboot_needed266 ··-·no_reboot_needed
280 ··-·restrict_strategy267 ··-·restrict_strategy
281 ··-·rpm_verify_hashes268 ··-·rpm_verify_hashes
 269 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 270 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 271 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 272 if·[·-n·"$files_with_incorrect_hash"·];·then
 273 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 274 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 275 ····dnf·reinstall·-y·$packages_to_reinstall
  
 276 fi
282 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*277 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
283 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:278 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
284 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'279 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
285 run·the·following·command·to·determine·which·package·owns·it:280 run·the·following·command·to·determine·which·package·owns·it:
286 $·rpm·-qf·FILENAME281 $·rpm·-qf·FILENAME
287 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:282 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
288 $·sudo·rpm·--setugids·PACKAGENAME283 $·sudo·rpm·--setugids·PACKAGENAME
Offset 301, 40 lines modifiedOffset 301, 14 lines modified
301 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5301 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
302 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2302 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
303 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)303 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
304 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1304 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
305 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5305 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
306 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108306 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
307 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2307 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
308 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
309 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
310 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
311 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
312 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
313 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
314 declare·-A·SETPERMS_RPM_DICT 
  
315 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
316 #·is·expected·by·the·RPM·database 
317 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
318 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
319 do 
320 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
321 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
322 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
323 done 
  
324 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
325 #·correct·values 
326 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
327 do 
328 ········rpm·--setugids·"${RPM_PACKAGE}" 
329 done 
330 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8308 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
331 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high309 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
332 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium310 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
333 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false311 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
334 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict312 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
335 -·name:·Read·list·of·files·with·incorrect·ownership313 -·name:·Read·list·of·files·with·incorrect·ownership
336 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev314 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 409, 14 lines modifiedOffset 383, 40 lines modified
409 ··-·PCI-DSSv4-11.5.2383 ··-·PCI-DSSv4-11.5.2
410 ··-·high_complexity384 ··-·high_complexity
411 ··-·high_severity385 ··-·high_severity
412 ··-·medium_disruption386 ··-·medium_disruption
413 ··-·no_reboot_needed387 ··-·no_reboot_needed
414 ··-·restrict_strategy388 ··-·restrict_strategy
415 ··-·rpm_verify_ownership389 ··-·rpm_verify_ownership
 390 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 391 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 392 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 393 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 394 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 395 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 1038060/1045893 bytes (99.25%) of diff not shown.
6.81 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-ospp.html
    
Offset 14416, 15 lines modifiedOffset 14416, 15 lines modified
000384f0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>000384f0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00038500:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00038500:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00038510:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<00038510:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<
00038520:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00038520:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00038530:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00038530:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00038540:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00038540:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00038550:·2020·2020·2020·2020·2020·2020·2020·2028·················(00038550:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00038560:·6173·206f·6620·3230·3236·2d30·312d·3038··as·of·2026-01-0800038560:·6173·206f·6620·3230·3234·2d31·322d·3037··as·of·2024-12-07
00038570:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00038570:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00038580:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00038580:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00038590:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00038590:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
000385a0:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>000385a0:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
000385b0:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc000385b0:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
000385c0:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje000385c0:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
000385d0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group000385d0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
Offset 15144, 197 lines modifiedOffset 15144, 197 lines modified
0003b270:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b270:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003b280:·3839·3331·2220·7461·6269·6e64·6578·3d22··8931"·tabindex="0003b280:·3839·3331·2220·7461·6269·6e64·6578·3d22··8931"·tabindex="
0003b290:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b290:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003b2a0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b2a0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003b2b0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003b2b0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003b2c0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003b2c0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003b2d0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003b2d0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003b2e0:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc0003b2e0:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible·
0003b2f0:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003b300:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003b310:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003b320:·7073·6522·2069·643d·2269·646d·3839·3331··pse"·id="idm8931 
0003b330:·223e·3c70·7265·3e3c·636f·6465·3e23·2052··"><pre><code>#·R 
0003b340:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003b350:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003b360:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003b370:·6d73·0a69·6620·2820·5b20·2120·2d66·202f··ms.if·(·[·!·-f·/ 
0003b380:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am 
0003b390:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/ 
0003b3a0:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren 
0003b3b0:·7620·5d20·2661·6d70·3b26·616d·703b·2021··v·]·&amp;&amp;·!0003b2f0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003b300:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003b310:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b320:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
 0003b330:·3933·3122·3e3c·7461·626c·6520·636c·6173··931"><table·clas
 0003b340:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003b350:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003b360:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003b370:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003b380:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003b390:·7464·3e6d·6564·6975·6d3c·2f74·643e·3c2f··td>medium</td></
 0003b3a0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0003b3b0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6d··ption:</th><td>m
 0003b3c0:·6564·6975·6d3c·2f74·643e·3c2f·7472·3e3c··edium</td></tr><
 0003b3d0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 0003b3e0:·7468·3e3c·7464·3e74·7275·653c·2f74·643e··th><td>true</td>
 0003b3f0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 0003b400:·6174·6567·793a·3c2f·7468·3e3c·7464·3e72··ategy:</th><td>r
 0003b410:·6573·7472·6963·743c·2f74·643e·3c2f·7472··estrict</td></tr
 0003b420:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003b430:·6f64·653e·2d20·6e61·6d65·3a20·4368·6563··ode>-·name:·Chec
 0003b440:·6b20·746f·2073·6565·2074·6865·2063·7572··k·to·see·the·cur
 0003b450:·7265·6e74·2073·7461·7475·7320·6f66·2046··rent·status·of·F
 0003b460:·4950·5320·6d6f·6465·0a20·2063·6f6d·6d61··IPS·mode.··comma
 0003b470:·6e64·3a20·2f75·7372·2f62·696e·2f66·6970··nd:·/usr/bin/fip
 0003b480:·732d·6d6f·6465·2d73·6574·7570·202d·2d63··s-mode-setup·--c
 0003b490:·6865·636b·0a20·2072·6567·6973·7465·723a··heck.··register:
 0003b4a0:·2069·735f·6669·7073·5f65·6e61·626c·6564···is_fips_enabled
 0003b4b0:·0a20·2063·6861·6e67·6564·5f77·6865·6e3a··.··changed_when:
 0003b4c0:·2066·616c·7365·0a20·2066·6169·6c65·645f···false.··failed_
 0003b4d0:·7768·656e·3a20·6661·6c73·650a·2020·7768··when:·false.··wh
 0003b4e0:·656e·3a20·2820·616e·7369·626c·655f·7669··en:·(·ansible_vi
 0003b4f0:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ
 0003b500:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke
 0003b510:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open
 0003b520:·767a·222c·2022·706f·646d·616e·222c·0a20··vz",·"podman",.·
0003b3c0:·2028·205b·2022·247b·636f·6e74·6169·6e65···(·[·"${containe0003b530:·2020·2022·636f·6e74·6169·6e65·7222·5d20·····"container"]·
 0003b540:·616e·6420·6e6f·7420·2820·6c6f·6f6b·7570··and·not·(·lookup
 0003b550:·2822·656e·7622·2c20·2263·6f6e·7461·696e··("env",·"contain
 0003b560:·6572·2229·203d·3d20·2262·7772·6170·2d6f··er")·==·"bwrap-o
 0003b570:·7362·7569·6c64·2220·2920·290a·2020·7461··sbuild"·)·).··ta
 0003b580:·6773·3a0a·2020·2d20·4449·5341·2d53·5449··gs:.··-·DISA-STI
 0003b590:·472d·5248·454c·2d30·392d·3637·3130·3130··G-RHEL-09-671010
 0003b5a0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
 0003b5b0:·2d43·4d2d·3628·6129·0a20·202d·204e·4953··-CM-6(a).··-·NIS
 0003b5c0:·542d·3830·302d·3533·2d49·412d·370a·2020··T-800-53-IA-7.··
 0003b5d0:·2d20·4e49·5354·2d38·3030·2d35·332d·5343··-·NIST-800-53-SC
 0003b5e0:·2d31·320a·2020·2d20·4e49·5354·2d38·3030··-12.··-·NIST-800
 0003b5f0:·2d35·332d·5343·2d31·3228·3229·0a20·202d··-53-SC-12(2).··-
 0003b600:·204e·4953·542d·3830·302d·3533·2d53·432d···NIST-800-53-SC-
 0003b610:·3132·2833·290a·2020·2d20·4e49·5354·2d38··12(3).··-·NIST-8
 0003b620:·3030·2d35·332d·5343·2d31·330a·2020·2d20··00-53-SC-13.··-·
 0003b630:·656e·6162·6c65·5f64·7261·6375·745f·6669··enable_dracut_fi
 0003b640:·7073·5f6d·6f64·756c·650a·2020·2d20·6869··ps_module.··-·hi
 0003b650:·6768·5f73·6576·6572·6974·790a·2020·2d20··gh_severity.··-·
 0003b660:·6d65·6469·756d·5f63·6f6d·706c·6578·6974··medium_complexit
 0003b670:·790a·2020·2d20·6d65·6469·756d·5f64·6973··y.··-·medium_dis
 0003b680:·7275·7074·696f·6e0a·2020·2d20·7265·626f··ruption.··-·rebo
 0003b690:·6f74·5f72·6571·7569·7265·640a·2020·2d20··ot_required.··-·
 0003b6a0:·7265·7374·7269·6374·5f73·7472·6174·6567··restrict_strateg
 0003b6b0:·790a·0a2d·206e·616d·653a·2045·6e61·626c··y..-·name:·Enabl
 0003b6c0:·6520·4649·5053·206d·6f64·650a·2020·636f··e·FIPS·mode.··co
 0003b6d0:·6d6d·616e·643a·202f·7573·722f·6269·6e2f··mmand:·/usr/bin/
 0003b6e0:·6669·7073·2d6d·6f64·652d·7365·7475·7020··fips-mode-setup·
 0003b6f0:·2d2d·656e·6162·6c65·0a20·2077·6865·6e3a··--enable.··when:
 0003b700:·0a20·202d·2028·2061·6e73·6962·6c65·5f76··.··-·(·ansible_v
 0003b710:·6972·7475·616c·697a·6174·696f·6e5f·7479··irtualization_ty
 0003b720:·7065·206e·6f74·2069·6e20·5b22·646f·636b··pe·not·in·["dock
 0003b730:·6572·222c·2022·6c78·6322·2c20·226f·7065··er",·"lxc",·"ope
 0003b740:·6e76·7a22·2c20·2270·6f64·6d61·6e22·2c20··nvz",·"podman",·
 0003b750:·2263·6f6e·7461·696e·6572·225d·0a20·2020··"container"].···
 0003b760:·2061·6e64·206e·6f74·2028·206c·6f6f·6b75···and·not·(·looku
 0003b770:·7028·2265·6e76·222c·2022·636f·6e74·6169··p("env",·"contai
0003b3d0:·723a·2d7d·2220·3d3d·2022·6277·7261·702d··r:-}"·==·"bwrap-0003b780:·6e65·7222·2920·3d3d·2022·6277·7261·702d··ner")·==·"bwrap-
0003b3e0:·6f73·6275·696c·6422·205d·2029·2029·3b20··osbuild"·]·)·);·0003b790:·6f73·6275·696c·6422·2029·2029·0a20·202d··osbuild"·)·).··-
0003b3f0:·7468·656e·0a0a·6669·7073·2d6d·6f64·652d··then..fips-mode- 
0003b400:·7365·7475·7020·2d2d·656e·6162·6c65·0a46··setup·--enable.F 
0003b410:·4950·535f·434f·4e46·3d22·2f65·7463·2f64··IPS_CONF="/etc/d 
0003b420:·7261·6375·742e·636f·6e66·2e64·2f34·302d··racut.conf.d/40- 
0003b430:·6669·7073·2e63·6f6e·6622·0a69·6620·2120··fips.conf".if·!· 
0003b440:·6772·6570·2022·5e61·6464·5f64·7261·6375··grep·"^add_dracu0003b7a0:·2069·735f·6669·7073·5f65·6e61·626c·6564···is_fips_enabled
 0003b7b0:·2e73·7464·6f75·742e·6669·6e64·2827·4649··.stdout.find('FI
 0003b7c0:·5053·206d·6f64·6520·6973·2065·6e61·626c··PS·mode·is·enabl
 0003b7d0:·6564·2e27·2920·3d3d·202d·310a·2020·7461··ed.')·==·-1.··ta
 0003b7e0:·6773·3a0a·2020·2d20·4449·5341·2d53·5449··gs:.··-·DISA-STI
 0003b7f0:·472d·5248·454c·2d30·392d·3637·3130·3130··G-RHEL-09-671010
 0003b800:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
 0003b810:·2d43·4d2d·3628·6129·0a20·202d·204e·4953··-CM-6(a).··-·NIS
 0003b820:·542d·3830·302d·3533·2d49·412d·370a·2020··T-800-53-IA-7.··
 0003b830:·2d20·4e49·5354·2d38·3030·2d35·332d·5343··-·NIST-800-53-SC
 0003b840:·2d31·320a·2020·2d20·4e49·5354·2d38·3030··-12.··-·NIST-800
Max diff block lines reached; 6223683/6250647 bytes (99.57%) of diff not shown.
874 KB
html2text {}
    
Offset 59, 15 lines modifiedOffset 59, 15 lines modified
59 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Protection·Profile·for·General·Purpose·Operating·Systems59 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Protection·Profile·for·General·Purpose·Operating·Systems
60 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ospp60 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ospp
61 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*61 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
62 ····*·cpe:/o:redhat:enterprise_linux:962 ····*·cpe:/o:redhat:enterprise_linux:9
63 ····*·cpe:/o:centos:centos:963 ····*·cpe:/o:centos:centos:9
64 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*64 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
65 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8465 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
66 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)66 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
67 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*67 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
68 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s68 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
69 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e69 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
70 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l70 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
71 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n71 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
72 ·········4.·_\x8z_\x8I_\x8P_\x8L_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n72 ·········4.·_\x8z_\x8I_\x8P_\x8L_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
73 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s73 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 108, 27 lines modifiedOffset 108, 14 lines modified
108 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000068,·CCI-000803,·CCI-002450108 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000068,·CCI-000803,·CCI-002450
109 ············_\x8i_\x8s_\x8m······1446109 ············_\x8i_\x8s_\x8m······1446
110 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1110 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
111 References:·_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12111 References:·_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
112 ············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.1112 ············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.1
113 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223113 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223
114 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule114 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule
115 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
116 #·Remediation·is·applicable·only·in·certain·platforms 
117 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·);·then 
  
118 fips-mode-setup·--enable 
119 FIPS_CONF="/etc/dracut.conf.d/40-fips.conf" 
120 if·!·grep·"^add_dracutmodules+=\"·fips·\""·$FIPS_CONF;·then 
121 ····echo·"add_dracutmodules+=\"·fips·\""·>>·$FIPS_CONF 
122 fi 
  
123 else 
124 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
125 fi 
126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8115 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium116 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium
128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium117 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true118 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict119 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
131 -·name:·Check·to·see·the·current·status·of·FIPS·mode120 -·name:·Check·to·see·the·current·status·of·FIPS·mode
132 ··command:·/usr/bin/fips-mode-setup·--check121 ··command:·/usr/bin/fips-mode-setup·--check
Offset 189, 14 lines modifiedOffset 176, 27 lines modified
189 ··-·NIST-800-53-SC-13176 ··-·NIST-800-53-SC-13
190 ··-·enable_dracut_fips_module177 ··-·enable_dracut_fips_module
191 ··-·high_severity178 ··-·high_severity
192 ··-·medium_complexity179 ··-·medium_complexity
193 ··-·medium_disruption180 ··-·medium_disruption
194 ··-·reboot_required181 ··-·reboot_required
195 ··-·restrict_strategy182 ··-·restrict_strategy
 183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 184 #·Remediation·is·applicable·only·in·certain·platforms
 185 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·);·then
  
 186 fips-mode-setup·--enable
 187 FIPS_CONF="/etc/dracut.conf.d/40-fips.conf"
 188 if·!·grep·"^add_dracutmodules+=\"·fips·\""·$FIPS_CONF;·then
 189 ····echo·"add_dracutmodules+=\"·fips·\""·>>·$FIPS_CONF
 190 fi
  
 191 else
 192 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 193 fi
196 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*194 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
197 To·enable·FIPS·mode,·run·the·following·command:195 To·enable·FIPS·mode,·run·the·following·command:
198 fips-mode-setup·--enable196 fips-mode-setup·--enable
  
199 The·fips-mode-setup·command·will·configure·the·system·in·FIPS·mode·by·automatically·configuring·the·following:197 The·fips-mode-setup·command·will·configure·the·system·in·FIPS·mode·by·automatically·configuring·the·following:
200 ····*·Setting·the·kernel·FIPS·mode·flag·(/proc/sys/crypto/fips_enabled)·to·1198 ····*·Setting·the·kernel·FIPS·mode·flag·(/proc/sys/crypto/fips_enabled)·to·1
201 ····*·Creating·/etc/system-fips199 ····*·Creating·/etc/system-fips
Offset 210, 41 lines modifiedOffset 210, 18 lines modified
210 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000068,·CCI-000803,·CCI-002450210 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000068,·CCI-000803,·CCI-002450
211 ············_\x8i_\x8s_\x8m······1446211 ············_\x8i_\x8s_\x8m······1446
212 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1212 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
213 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12213 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
214 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1214 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
215 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176215 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
216 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule216 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule
 217 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
217 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
218 #·Remediation·is·applicable·only·in·certain·platforms 
219 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·)·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then 
  
220 var_system_crypto_policy='FIPS:OSPP' 
  
  
221 fips-mode-setup·--enable 
  
222 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
223 rc=$? 
  
224 if·test·"$rc"·=·127;·then 
225 »       echo·"$stderr_of_call"·>&2 
226 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
227 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
228 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
229 »       false··#·end·with·an·error·code 
230 elif·test·"$rc"·!=·0;·then 
231 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
232 »       false··#·end·with·an·error·code 
233 fi 
  
 218 [customizations]
 219 fips·=·true
234 else 
235 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
236 fi 
237 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8220 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
238 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium221 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium
239 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium222 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
240 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true223 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
241 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict224 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
242 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable225 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
243 ··set_fact:226 ··set_fact:
Offset 344, 18 lines modifiedOffset 321, 41 lines modified
344 ··-·NIST-800-53-SC-13321 ··-·NIST-800-53-SC-13
345 ··-·enable_fips_mode322 ··-·enable_fips_mode
346 ··-·high_severity323 ··-·high_severity
347 ··-·medium_complexity324 ··-·medium_complexity
348 ··-·medium_disruption325 ··-·medium_disruption
349 ··-·reboot_required326 ··-·reboot_required
350 ··-·restrict_strategy327 ··-·restrict_strategy
351 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8328 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 329 #·Remediation·is·applicable·only·in·certain·platforms
 330 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·)·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
Max diff block lines reached; 888456/894700 bytes (99.30%) of diff not shown.
17.9 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-pci-dss.html
    
Offset 14415, 16 lines modifiedOffset 14415, 16 lines modified
000384e0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</000384e0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
000384f0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve000384f0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00038500:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000038500:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00038510:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></00038510:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
00038520:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00038520:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00038530:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00038530:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00038540:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00038540:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00038550:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600038550:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
00038560:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········00038560:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00038570:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00038570:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00038580:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00038580:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00038590:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00038590:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
000385a0:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre000385a0:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
000385b0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss000385b0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
000385c0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content000385c0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
000385d0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S000385d0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
Offset 15294, 301 lines modifiedOffset 15294, 301 lines modified
0003bbd0:·612d·7461·7267·6574·3d22·2369·646d·3830··a-target="#idm800003bbd0:·612d·7461·7267·6574·3d22·2369·646d·3830··a-target="#idm80
0003bbe0:·3838·2220·7461·6269·6e64·6578·3d22·3022··88"·tabindex="0"0003bbe0:·3838·2220·7461·6269·6e64·6578·3d22·3022··88"·tabindex="0"
0003bbf0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003bbf0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003bc00:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003bc00:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003bc10:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003bc10:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003bc20:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003bc20:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003bc30:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003bc30:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003bc40:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
0003bc50:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
0003bc60:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003bc70:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003bc80:·6522·2069·643d·2269·646d·3830·3838·223e··e"·id="idm8088"> 
0003bc90:·3c70·7265·3e3c·636f·6465·3e0a·2320·4669··<pre><code>.#·Fi 
0003bca0:·6e64·2077·6869·6368·2066·696c·6573·2068··nd·which·files·h 
0003bcb0:·6176·6520·696e·636f·7272·6563·7420·6861··ave·incorrect·ha 
0003bcc0:·7368·2028·6e6f·7420·696e·202f·6574·632c··sh·(not·in·/etc, 
0003bcd0:·2062·6563·6175·7365·206f·6620·7468·6520···because·of·the· 
0003bce0:·7379·7374·656d·2072·656c·6174·6564·2063··system·related·c 
0003bcf0:·6f6e·6669·6720·6669·6c65·7329·2061·6e64··onfig·files)·and 
0003bd00:·2074·6865·6e20·6765·7420·6669·6c65·7320···then·get·files· 
0003bd10:·6e61·6d65·730a·6669·6c65·735f·7769·7468··names.files_with 
0003bd20:·5f69·6e63·6f72·7265·6374·5f68·6173·683d··_incorrect_hash= 
0003bd30:·2224·2872·706d·202d·5661·202d·2d6e·6f63··"$(rpm·-Va·--noc 
0003bd40:·6f6e·6669·6720·7c20·6772·6570·202d·4520··onfig·|·grep·-E· 
0003bd50:·275e·2e2e·3527·207c·2061·776b·2027·7b70··'^..5'·|·awk·'{p 
0003bd60:·7269·6e74·2024·4e46·7d27·2029·220a·0a69··rint·$NF}'·)"..i 
0003bd70:·6620·5b20·2d6e·2022·2466·696c·6573·5f77··f·[·-n·"$files_w 
0003bd80:·6974·685f·696e·636f·7272·6563·745f·6861··ith_incorrect_ha 
0003bd90:·7368·2220·5d3b·2074·6865·6e0a·2020·2020··sh"·];·then.···· 
0003bda0:·2320·4672·6f6d·2066·696c·6573·206e·616d··#·From·files·nam 
0003bdb0:·6573·2067·6574·2070·6163·6b61·6765·206e··es·get·package·n 
0003bdc0:·616d·6573·2061·6e64·2063·6861·6e67·6520··ames·and·change· 
0003bdd0:·6e65·776c·696e·6520·746f·2073·7061·6365··newline·to·space 
0003bde0:·2c20·6265·6361·7573·6520·7270·6d20·7772··,·because·rpm·wr 
0003bdf0:·6974·6573·2065·6163·6820·7061·636b·6167··ites·each·packag 
0003be00:·6520·746f·206e·6577·206c·696e·650a·2020··e·to·new·line.·· 
0003be10:·2020·7061·636b·6167·6573·5f74·6f5f·7265····packages_to_re 
0003be20:·696e·7374·616c·6c3d·2224·2872·706d·202d··install="$(rpm·- 
0003be30:·7166·2024·6669·6c65·735f·7769·7468·5f69··qf·$files_with_i 
0003be40:·6e63·6f72·7265·6374·5f68·6173·6820·7c20··ncorrect_hash·|· 
0003be50:·7472·2027·5c6e·2720·2720·2729·220a·0a20··tr·'\n'·'·')"..· 
0003be60:·2020·200a·2020·2020·646e·6620·7265·696e·····.····dnf·rein 
0003be70:·7374·616c·6c20·2d79·2024·7061·636b·6167··stall·-y·$packag 
0003be80:·6573·5f74·6f5f·7265·696e·7374·616c·6c0a··es_to_reinstall. 
0003be90:·2020·2020·0a66·690a·3c2f·636f·6465·3e3c······.fi.</code>< 
0003bea0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003beb0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003bec0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003bed0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003bee0:·612d·7461·7267·6574·3d22·2369·646d·3830··a-target="#idm80 
0003bef0:·3839·2220·7461·6269·6e64·6578·3d22·3022··89"·tabindex="0" 
0003bf00:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003bf10:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003bf20:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003bf30:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003bf40:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003bf50:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn0003bc40:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn
0003bf60:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003bc50:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003bf70:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003bc60:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003bf80:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003bc70:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003bf90:·6170·7365·2220·6964·3d22·6964·6d38·3038··apse"·id="idm8080003bc80:·6170·7365·2220·6964·3d22·6964·6d38·3038··apse"·id="idm808
0003bfa0:·3922·3e3c·7461·626c·6520·636c·6173·733d··9"><table·class=0003bc90:·3822·3e3c·7461·626c·6520·636c·6173·733d··8"><table·class=
0003bfb0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003bca0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003bfc0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003bcb0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003bfd0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003bcc0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003bfe0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003bcd0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003bff0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003bce0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003c000:·3e68·6967·683c·2f74·643e·3c2f·7472·3e3c··>high</td></tr><0003bcf0:·3e68·6967·683c·2f74·643e·3c2f·7472·3e3c··>high</td></tr><
0003c010:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003bd00:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003c020:·6e3a·3c2f·7468·3e3c·7464·3e6d·6564·6975··n:</th><td>mediu0003bd10:·6e3a·3c2f·7468·3e3c·7464·3e6d·6564·6975··n:</th><td>mediu
0003c030:·6d3c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··m</td></tr><tr><0003bd20:·6d3c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··m</td></tr><tr><
0003c040:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><0003bd30:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
0003c050:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t0003bd40:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
0003c060:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate0003bd50:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003c070:·6779·3a3c·2f74·683e·3c74·643e·7265·7374··gy:</th><td>rest0003bd60:·6779·3a3c·2f74·683e·3c74·643e·7265·7374··gy:</th><td>rest
0003c080:·7269·6374·3c2f·7464·3e3c·2f74·723e·3c2f··rict</td></tr></0003bd70:·7269·6374·3c2f·7464·3e3c·2f74·723e·3c2f··rict</td></tr></
0003c090:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003bd80:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
0003c0a0:·3e2d·206e·616d·653a·2027·5365·7420·6661··>-·name:·'Set·fa0003bd90:·3e2d·206e·616d·653a·2027·5365·7420·6661··>-·name:·'Set·fa
0003c0b0:·6374·3a20·5061·636b·6167·6520·6d61·6e61··ct:·Package·mana0003bda0:·6374·3a20·5061·636b·6167·6520·6d61·6e61··ct:·Package·mana
0003c0c0:·6765·7220·7265·696e·7374·616c·6c20·636f··ger·reinstall·co0003bdb0:·6765·7220·7265·696e·7374·616c·6c20·636f··ger·reinstall·co
0003c0d0:·6d6d·616e·6427·0a20·2073·6574·5f66·6163··mmand'.··set_fac0003bdc0:·6d6d·616e·6427·0a20·2073·6574·5f66·6163··mmand'.··set_fac
0003c0e0:·743a·0a20·2020·2070·6163·6b61·6765·5f6d··t:.····package_m0003bdd0:·743a·0a20·2020·2070·6163·6b61·6765·5f6d··t:.····package_m
0003c0f0:·616e·6167·6572·5f72·6569·6e73·7461·6c6c··anager_reinstall0003bde0:·616e·6167·6572·5f72·6569·6e73·7461·6c6c··anager_reinstall
0003c100:·5f63·6d64·3a20·646e·6620·7265·696e·7374··_cmd:·dnf·reinst0003bdf0:·5f63·6d64·3a20·646e·6620·7265·696e·7374··_cmd:·dnf·reinst
0003c110:·616c·6c20·2d79·0a20·2077·6865·6e3a·2061··all·-y.··when:·a0003be00:·616c·6c20·2d79·0a20·2077·6865·6e3a·2061··all·-y.··when:·a
0003c120:·6e73·6962·6c65·5f64·6973·7472·6962·7574··nsible_distribut0003be10:·6e73·6962·6c65·5f64·6973·7472·6962·7574··nsible_distribut
0003c130:·696f·6e20·696e·205b·2022·4665·646f·7261··ion·in·[·"Fedora0003be20:·696f·6e20·696e·205b·2022·4665·646f·7261··ion·in·[·"Fedora
0003c140:·222c·2022·5265·6448·6174·222c·2022·4365··",·"RedHat",·"Ce0003be30:·222c·2022·5265·6448·6174·222c·2022·4365··",·"RedHat",·"Ce
0003c150:·6e74·4f53·222c·2022·4f72·6163·6c65·4c69··ntOS",·"OracleLi0003be40:·6e74·4f53·222c·2022·4f72·6163·6c65·4c69··ntOS",·"OracleLi
0003c160:·6e75·7822·205d·0a20·2074·6167·733a·0a20··nux"·].··tags:.·0003be50:·6e75·7822·205d·0a20·2074·6167·733a·0a20··nux"·].··tags:.·
0003c170:·202d·2043·4a49·532d·352e·3130·2e34·2e31···-·CJIS-5.10.4.10003be60:·202d·2043·4a49·532d·352e·3130·2e34·2e31···-·CJIS-5.10.4.1
0003c180:·0a20·202d·204e·4953·542d·3830·302d·3137··.··-·NIST-800-170003be70:·0a20·202d·204e·4953·542d·3830·302d·3137··.··-·NIST-800-17
0003c190:·312d·332e·332e·380a·2020·2d20·4e49·5354··1-3.3.8.··-·NIST0003be80:·312d·332e·332e·380a·2020·2d20·4e49·5354··1-3.3.8.··-·NIST
0003c1a0:·2d38·3030·2d31·3731·2d33·2e34·2e31·0a20··-800-171-3.4.1.·0003be90:·2d38·3030·2d31·3731·2d33·2e34·2e31·0a20··-800-171-3.4.1.·
0003c1b0:·202d·204e·4953·542d·3830·302d·3533·2d41···-·NIST-800-53-A0003bea0:·202d·204e·4953·542d·3830·302d·3533·2d41···-·NIST-800-53-A
0003c1c0:·552d·3928·3329·0a20·202d·204e·4953·542d··U-9(3).··-·NIST-0003beb0:·552d·3928·3329·0a20·202d·204e·4953·542d··U-9(3).··-·NIST-
0003c1d0:·3830·302d·3533·2d43·4d2d·3628·6329·0a20··800-53-CM-6(c).·0003bec0:·3830·302d·3533·2d43·4d2d·3628·6329·0a20··800-53-CM-6(c).·
0003c1e0:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C0003bed0:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C
0003c1f0:·4d2d·3628·6429·0a20·202d·204e·4953·542d··M-6(d).··-·NIST-0003bee0:·4d2d·3628·6429·0a20·202d·204e·4953·542d··M-6(d).··-·NIST-
0003c200:·3830·302d·3533·2d53·492d·370a·2020·2d20··800-53-SI-7.··-·0003bef0:·3830·302d·3533·2d53·492d·370a·2020·2d20··800-53-SI-7.··-·
0003c210:·4e49·5354·2d38·3030·2d35·332d·5349·2d37··NIST-800-53-SI-70003bf00:·4e49·5354·2d38·3030·2d35·332d·5349·2d37··NIST-800-53-SI-7
0003c220:·2831·290a·2020·2d20·4e49·5354·2d38·3030··(1).··-·NIST-8000003bf10:·2831·290a·2020·2d20·4e49·5354·2d38·3030··(1).··-·NIST-800
0003c230:·2d35·332d·5349·2d37·2836·290a·2020·2d20··-53-SI-7(6).··-·0003bf20:·2d35·332d·5349·2d37·2836·290a·2020·2d20··-53-SI-7(6).··-·
0003c240:·5043·492d·4453·532d·5265·712d·3131·2e35··PCI-DSS-Req-11.50003bf30:·5043·492d·4453·532d·5265·712d·3131·2e35··PCI-DSS-Req-11.5
0003c250:·0a20·202d·2050·4349·2d44·5353·7634·2d31··.··-·PCI-DSSv4-10003bf40:·0a20·202d·2050·4349·2d44·5353·7634·2d31··.··-·PCI-DSSv4-1
0003c260:·312e·352e·320a·2020·2d20·6869·6768·5f63··1.5.2.··-·high_c0003bf50:·312e·352e·320a·2020·2d20·6869·6768·5f63··1.5.2.··-·high_c
0003c270:·6f6d·706c·6578·6974·790a·2020·2d20·6869··omplexity.··-·hi0003bf60:·6f6d·706c·6578·6974·790a·2020·2d20·6869··omplexity.··-·hi
0003c280:·6768·5f73·6576·6572·6974·790a·2020·2d20··gh_severity.··-·0003bf70:·6768·5f73·6576·6572·6974·790a·2020·2d20··gh_severity.··-·
0003c290:·6d65·6469·756d·5f64·6973·7275·7074·696f··medium_disruptio0003bf80:·6d65·6469·756d·5f64·6973·7275·7074·696f··medium_disruptio
0003c2a0:·6e0a·2020·2d20·6e6f·5f72·6562·6f6f·745f··n.··-·no_reboot_0003bf90:·6e0a·2020·2d20·6e6f·5f72·6562·6f6f·745f··n.··-·no_reboot_
Max diff block lines reached; 17124956/17150816 bytes (99.85%) of diff not shown.
1.59 MB
html2text {}
    
Offset 60, 15 lines modifiedOffset 60, 15 lines modified
60 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v4.0·Control·Baseline·for·Red·Hat·Enterprise·Linux·960 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v4.0·Control·Baseline·for·Red·Hat·Enterprise·Linux·9
61 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss61 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss
62 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*62 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
63 ····*·cpe:/o:redhat:enterprise_linux:963 ····*·cpe:/o:redhat:enterprise_linux:9
64 ····*·cpe:/o:centos:centos:964 ····*·cpe:/o:centos:centos:9
65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
66 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8466 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
69 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s69 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
70 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e70 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
71 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l71 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
72 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n72 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
73 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g73 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
74 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s74 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 127, 27 lines modifiedOffset 127, 14 lines modified
127 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6127 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
128 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4128 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
129 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)129 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
130 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1130 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
131 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5131 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
132 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227132 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
133 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2133 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
135 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
136 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
137 if·[·-n·"$files_with_incorrect_hash"·];·then 
138 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
139 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
140 ····dnf·reinstall·-y·$packages_to_reinstall 
  
141 fi 
142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high135 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium136 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false137 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict138 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
147 -·name:·'Set·fact:·Package·manager·reinstall·command'139 -·name:·'Set·fact:·Package·manager·reinstall·command'
148 ··set_fact:140 ··set_fact:
Offset 274, 14 lines modifiedOffset 261, 27 lines modified
274 ··-·PCI-DSSv4-11.5.2261 ··-·PCI-DSSv4-11.5.2
275 ··-·high_complexity262 ··-·high_complexity
276 ··-·high_severity263 ··-·high_severity
277 ··-·medium_disruption264 ··-·medium_disruption
278 ··-·no_reboot_needed265 ··-·no_reboot_needed
279 ··-·restrict_strategy266 ··-·restrict_strategy
280 ··-·rpm_verify_hashes267 ··-·rpm_verify_hashes
 268 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 269 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 270 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 271 if·[·-n·"$files_with_incorrect_hash"·];·then
 272 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 273 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 274 ····dnf·reinstall·-y·$packages_to_reinstall
  
 275 fi
281 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*276 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
282 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:277 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
283 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'278 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
284 run·the·following·command·to·determine·which·package·owns·it:279 run·the·following·command·to·determine·which·package·owns·it:
285 $·rpm·-qf·FILENAME280 $·rpm·-qf·FILENAME
286 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:281 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
287 $·sudo·rpm·--setugids·PACKAGENAME282 $·sudo·rpm·--setugids·PACKAGENAME
Offset 300, 40 lines modifiedOffset 300, 14 lines modified
300 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5300 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
301 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2301 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
302 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)302 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
303 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1303 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
304 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5304 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
305 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108305 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
306 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2306 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
307 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
308 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
309 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
310 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
311 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
312 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
313 declare·-A·SETPERMS_RPM_DICT 
  
314 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
315 #·is·expected·by·the·RPM·database 
316 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
317 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
318 do 
319 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
320 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
321 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
322 done 
  
323 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
324 #·correct·values 
325 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
326 do 
327 ········rpm·--setugids·"${RPM_PACKAGE}" 
328 done 
329 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8307 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
330 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high308 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
331 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium309 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
332 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false310 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
333 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict311 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
334 -·name:·Read·list·of·files·with·incorrect·ownership312 -·name:·Read·list·of·files·with·incorrect·ownership
335 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev313 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 408, 14 lines modifiedOffset 382, 40 lines modified
408 ··-·PCI-DSSv4-11.5.2382 ··-·PCI-DSSv4-11.5.2
409 ··-·high_complexity383 ··-·high_complexity
410 ··-·high_severity384 ··-·high_severity
411 ··-·medium_disruption385 ··-·medium_disruption
412 ··-·no_reboot_needed386 ··-·no_reboot_needed
413 ··-·restrict_strategy387 ··-·restrict_strategy
414 ··-·rpm_verify_ownership388 ··-·rpm_verify_ownership
 389 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 390 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 391 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 392 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 393 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 394 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 1659294/1667017 bytes (99.54%) of diff not shown.
33.5 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-stig.html
    
Offset 14425, 15 lines modifiedOffset 14425, 15 lines modified
00038580:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren00038580:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren
00038590:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro00038590:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro
000385a0:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron000385a0:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron
000385b0:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s000385b0:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s
000385c0:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str000385c0:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str
000385d0:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········000385d0:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········
000385e0:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·000385e0:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·
000385f0:·3230·3236·2d30·312d·3038·290a·2020·2020··2026-01-08).····000385f0:·3230·3234·2d31·322d·3037·290a·2020·2020··2024-12-07).····
00038600:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li00038600:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li
00038610:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>00038610:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>
00038620:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content00038620:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content
00038630:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a00038630:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a
00038640:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or00038640:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or
00038650:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con00038650:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con
00038660:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste00038660:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste
Offset 15227, 236 lines modifiedOffset 15227, 236 lines modified
0003b7a0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b7a0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b7b0:·2369·646d·3834·3238·2220·7461·6269·6e64··#idm8428"·tabind0003b7b0:·2369·646d·3834·3238·2220·7461·6269·6e64··#idm8428"·tabind
0003b7c0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b7c0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b7d0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b7d0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b7e0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b7e0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b7f0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b7f0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b800:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b800:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b810:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp0003b810:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac
0003b820:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</0003b820:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...
0003b830:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003b830:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003b840:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003b840:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003b850:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003b850:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003b860:·646d·3834·3238·223e·3c74·6162·6c65·2063··dm8428"><table·c0003b860:·2269·646d·3834·3238·223e·3c74·6162·6c65··"idm8428"><table
0003b870:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003b870:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003b880:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003b880:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003b890:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003b890:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003b8a0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003b8a0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003b8b0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003b8b0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003b8c0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003b8c0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003b8d0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru0003b8d0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003b8e0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l0003b8e0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003b8f0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003b8f0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003b900:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>0003b900:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
0003b910:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></0003b910:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
0003b920:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0003b920:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003b930:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena0003b930:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003b940:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t0003b940:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003b950:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003b950:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003b960:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add
 0003b970:·3d61·6964·650a·3c2f·636f·6465·3e3c·2f70··=aide.</code></p
 0003b980:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
 0003b990:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
 0003b9a0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
 0003b9b0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
 0003b9c0:·7461·7267·6574·3d22·2369·646d·3834·3239··target="#idm8429
 0003b9d0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 0003b9e0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 0003b9f0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 0003ba00:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 0003ba10:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 0003ba20:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0003ba30:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp
 0003ba40:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0003ba50:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003ba60:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003ba70:·6522·2069·643d·2269·646d·3834·3239·223e··e"·id="idm8429">
 0003ba80:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003ba90:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003baa0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003bab0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003bac0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 0003bad0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 0003bae0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003baf0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
0003b960:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_ 
0003b970:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst 
0003b980:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac 
0003b990:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.· 
0003b9a0:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;· 
0003b9b0:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··} 
0003b9c0:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre> 
0003b9d0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003b9e0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003b9f0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003ba00:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003ba10:·6765·743d·2223·6964·6d38·3432·3922·2074··get="#idm8429"·t 
0003ba20:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003ba30:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003ba40:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003ba50:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003ba60:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003ba70:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003ba80:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
0003ba90:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003baa0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003bab0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003bac0:·3d22·6964·6d38·3432·3922·3e3c·7461·626c··="idm8429"><tabl 
0003bad0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003bae0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003baf0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003bb00:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003bb10:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003bb20:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003bb00:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003bb30:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003bb10:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
0003bb40:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003bb50:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003bb60:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</0003bb20:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
 0003bb30:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 0003bb40:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0003bb70:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td0003bb50:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003bb60:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003bb70:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include·
 0003bb80:·696e·7374·616c·6c5f·6169·6465·0a0a·636c··install_aide..cl
 0003bb90:·6173·7320·696e·7374·616c·6c5f·6169·6465··ass·install_aide
 0003bba0:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·'
 0003bbb0:·6169·6465·273a·0a20·2020·2065·6e73·7572··aide':.····ensur
 0003bbc0:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install
 0003bbd0:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod
0003bb80:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003bb90:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003bba0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003bbb0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003bbc0:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation 
0003bbd0:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o 
0003bbe0:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p 
0003bbf0:·6c61·7466·6f72·6d73·0a69·6620·5b20·2120··latforms.if·[·!· 
0003bc00:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·] 
0003bc10:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!· 
0003bc20:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain 
0003bc30:·6572·656e·7620·5d3b·2074·6865·6e0a·0a69··erenv·];·then..i 
0003bc40:·6620·2120·7270·6d20·2d71·202d·2d71·7569··f·!·rpm·-q·--qui 
Max diff block lines reached; 32182774/32215120 bytes (99.90%) of diff not shown.
2.74 MB
html2text {}
Max HTML report size reached
33.3 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-stig_gui.html
    
Offset 14448, 16 lines modifiedOffset 14448, 16 lines modified
000386f0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</000386f0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00038700:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00038700:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00038710:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000038710:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00038720:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></00038720:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
00038730:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00038730:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00038740:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00038740:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00038750:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00038750:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00038760:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600038760:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
00038770:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········00038770:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00038780:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00038780:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00038790:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00038790:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
000387a0:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h000387a0:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
000387b0:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre000387b0:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
000387c0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss000387c0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
000387d0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content000387d0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
000387e0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S000387e0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
Offset 15246, 235 lines modifiedOffset 15246, 235 lines modified
0003b8d0:·2d74·6172·6765·743d·2223·6964·6d38·3432··-target="#idm8420003b8d0:·2d74·6172·6765·743d·2223·6964·6d38·3432··-target="#idm842
0003b8e0:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·0003b8e0:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·
0003b8f0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003b8f0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003b900:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003b900:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003b910:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003b910:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003b920:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003b920:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003b930:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003b930:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003b940:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip0003b940:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn
0003b950:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003b950:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003b960:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003b960:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003b970:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003b970:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003b980:·7365·2220·6964·3d22·6964·6d38·3432·3822··se"·id="idm8428"0003b980:·6170·7365·2220·6964·3d22·6964·6d38·3432··apse"·id="idm842
0003b990:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003b990:·3822·3e3c·7461·626c·6520·636c·6173·733d··8"><table·class=
0003b9a0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003b9a0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003b9b0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003b9b0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003b9c0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003b9c0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003b9d0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003b9d0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003b9e0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l0003b9e0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003b9f0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003b9f0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003ba00:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<0003ba00:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003ba10:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003ba10:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003ba20:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb0003ba20:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
0003ba30:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal0003ba30:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
0003ba40:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>0003ba40:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
0003ba50:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t0003ba50:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0003ba60:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td0003ba60:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
0003ba70:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p0003ba70:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003ba80:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack
 0003ba90:·6167·6520·2d2d·6164·643d·6169·6465·0a3c··age·--add=aide.<
 0003baa0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
0003ba80:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include 
0003ba90:·2069·6e73·7461·6c6c·5f61·6964·650a·0a63···install_aide..c 
0003baa0:·6c61·7373·2069·6e73·7461·6c6c·5f61·6964··lass·install_aid 
0003bab0:·6520·7b0a·2020·7061·636b·6167·6520·7b20··e·{.··package·{· 
0003bac0:·2761·6964·6527·3a0a·2020·2020·656e·7375··'aide':.····ensu 
0003bad0:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal 
0003bae0:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co 
0003baf0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003bb00:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003bb10:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003bb20:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003bb30:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003bb40:·646d·3834·3239·2220·7461·6269·6e64·6578··dm8429"·tabindex 
0003bb50:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003bb60:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003bb70:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003bb80:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003bb90:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003bba0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
0003bbb0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003bbc0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003bab0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003bac0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003bad0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
0003bbd0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003bbe0:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm84 
0003bbf0:·3239·223e·3c74·6162·6c65·2063·6c61·7373··29"><table·class 
0003bc00:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003bc10:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003bc20:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003bc30:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003bc40:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003bc50:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003bc60:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003bc70:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003bc80:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003bc90:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003bca0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
0003bcb0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003bcc0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003bcd0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003bce0:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re 
0003bcf0:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app 
0003bd00:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in· 
0003bd10:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform 
0003bd20:·730a·6966·205b·2021·202d·6620·2f2e·646f··s.if·[·!·-f·/.do 
0003bd30:·636b·6572·656e·7620·5d20·2661·6d70·3b26··ckerenv·]·&amp;& 
0003bd40:·616d·703b·205b·2021·202d·6620·2f72·756e··amp;·[·!·-f·/run 
0003bd50:·2f2e·636f·6e74·6169·6e65·7265·6e76·205d··/.containerenv·] 
0003bd60:·3b20·7468·656e·0a0a·6966·2021·2072·706d··;·then..if·!·rpm 
0003bd70:·202d·7120·2d2d·7175·6965·7420·2261·6964···-q·--quiet·"aid 
0003bd80:·6522·203b·2074·6865·6e0a·2020·2020·646e··e"·;·then.····dn 
0003bd90:·6620·696e·7374·616c·6c20·2d79·2022·6169··f·install·-y·"ai 
0003bda0:·6465·220a·6669·0a0a·656c·7365·0a20·2020··de".fi..else.··· 
0003bdb0:·2026·6774·3b26·616d·703b·3220·6563·686f···&gt;&amp;2·echo 
0003bdc0:·2027·5265·6d65·6469·6174·696f·6e20·6973···'Remediation·is 
0003bdd0:·206e·6f74·2061·7070·6c69·6361·626c·652c···not·applicable, 
0003bde0:·206e·6f74·6869·6e67·2077·6173·2064·6f6e···nothing·was·don 
0003bdf0:·6527·0a66·690a·3c2f·636f·6465·3e3c·2f70··e'.fi.</code></p 
0003be00:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003be10:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003be20:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=0003bae0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003baf0:·2223·6964·6d38·3432·3922·2074·6162·696e··"#idm8429"·tabin
 0003bb00:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003bb10:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003bb20:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003bb30:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003bb40:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003bb50:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
 0003bb60:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
 0003bb70:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003bb80:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003bb90:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003bba0:·6964·6d38·3432·3922·3e3c·7461·626c·6520··idm8429"><table·
 0003bbb0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003bbc0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003bbd0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003bbe0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003bbf0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003bc00:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003bc10:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
Max diff block lines reached; 32044488/32076834 bytes (99.90%) of diff not shown.
2.72 MB
html2text {}
Max HTML report size reached
19.0 MB
./usr/share/doc/ssg-nondebian/ssg-fedora-guide-cusp_fedora.html
    
Offset 14354, 15 lines modifiedOffset 14354, 15 lines modified
00038110:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00038110:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00038120:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00038120:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00038130:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</00038130:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
00038140:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00038140:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
00038150:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft00038150:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
00038160:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······00038160:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
00038170:·2020·2020·2020·2020·2020·2020·2020·2861················(a00038170:·2020·2020·2020·2020·2020·2020·2020·2861················(a
00038180:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)00038180:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
00038190:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00038190:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
000381a0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div000381a0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
000381b0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co000381b0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
000381c0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><000381c0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
000381d0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc000381d0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
000381e0:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec000381e0:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
000381f0:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_000381f0:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 15399, 239 lines modifiedOffset 15399, 239 lines modified
0003c260:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003c260:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003c270:·743d·2223·6964·6d32·3533·3222·2074·6162··t="#idm2532"·tab0003c270:·743d·2223·6964·6d32·3533·3222·2074·6162··t="#idm2532"·tab
0003c280:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003c280:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003c290:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003c290:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003c2a0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003c2a0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003c2b0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003c2b0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003c2c0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003c2c0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003c2d0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S0003c2d0:·2122·3e52·656d·6564·6961·7469·6f6e·204b··!">Remediation·K
 0003c2e0:·7562·6572·6e65·7465·7320·736e·6970·7065··ubernetes·snippe
 0003c2f0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003c300:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003c310:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003c320:·2220·6964·3d22·6964·6d32·3533·3222·3e3c··"·id="idm2532"><
 0003c330:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003c340:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003c350:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003c2e0:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
0003c2f0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003c300:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003c310:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003c320:·6964·6d32·3533·3222·3e3c·7072·653e·3c63··idm2532"><pre><c 
0003c330:·6f64·653e·0a76·6172·5f73·7973·7465·6d5f··ode>.var_system_ 
0003c340:·6372·7970·746f·5f70·6f6c·6963·793d·273c··crypto_policy='< 
0003c350:·6162·6272·2074·6974·6c65·3d22·6672·6f6d··abbr·title="from 
0003c360:·2050·726f·6669·6c65·2f72·6566·696e·652d···Profile/refine- 
0003c370:·7661·6c75·653a·2078·6363·6466·5f6f·7267··value:·xccdf_org 
0003c380:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont 
0003c390:·656e·745f·7661·6c75·655f·7661·725f·7379··ent_value_var_sy 
0003c3a0:·7374·656d·5f63·7279·7074·6f5f·706f·6c69··stem_crypto_poli 
0003c3b0:·6379·223e·4445·4641·554c·543c·2f61·6262··cy">DEFAULT</abb 
0003c3c0:·723e·270a·0a0a·7374·6465·7272·5f6f·665f··r>'...stderr_of_ 
0003c3d0:·6361·6c6c·3d24·2875·7064·6174·652d·6372··call=$(update-cr 
0003c3e0:·7970·746f·2d70·6f6c·6963·6965·7320·2d2d··ypto-policies·-- 
0003c3f0:·7365·7420·247b·7661·725f·7379·7374·656d··set·${var_system 
0003c400:·5f63·7279·7074·6f5f·706f·6c69·6379·7d20··_crypto_policy}· 
0003c410:·3226·6774·3b26·616d·703b·3120·2667·743b··2&gt;&amp;1·&gt; 
0003c420:·202f·6465·762f·6e75·6c6c·290a·7263·3d24···/dev/null).rc=$ 
0003c430:·3f0a·0a69·6620·7465·7374·2022·2472·6322··?..if·test·"$rc" 
0003c440:·203d·2031·3237·3b20·7468·656e·0a09·6563···=·127;·then..ec 
0003c450:·686f·2022·2473·7464·6572·725f·6f66·5f63··ho·"$stderr_of_c 
0003c460:·616c·6c22·2026·6774·3b26·616d·703b·320a··all"·&gt;&amp;2. 
0003c470:·0965·6368·6f20·224d·616b·6520·7375·7265··.echo·"Make·sure 
0003c480:·2074·6861·7420·7468·6520·7363·7269·7074···that·the·script 
0003c490:·2069·7320·696e·7374·616c·6c65·6420·6f6e···is·installed·on 
0003c4a0:·2074·6865·2072·656d·6564·6961·7465·6420···the·remediated· 
0003c4b0:·7379·7374·656d·2e22·2026·6774·3b26·616d··system."·&gt;&am 
0003c4c0:·703b·320a·0965·6368·6f20·2253·6565·206f··p;2..echo·"See·o 
0003c4d0:·7574·7075·7420·6f66·2074·6865·2027·646e··utput·of·the·'dn 
0003c4e0:·6620·7072·6f76·6964·6573·2075·7064·6174··f·provides·updat 
0003c4f0:·652d·6372·7970·746f·2d70·6f6c·6963·6965··e-crypto-policie 
0003c500:·7327·2063·6f6d·6d61·6e64·2220·2667·743b··s'·command"·&gt; 
0003c510:·2661·6d70·3b32·0a09·6563·686f·2022·746f··&amp;2..echo·"to 
0003c520:·2073·6565·2077·6861·7420·7061·636b·6167···see·what·packag 
0003c530:·6520·746f·2028·7265·2969·6e73·7461·6c6c··e·to·(re)install 
0003c540:·2220·2667·743b·2661·6d70·3b32·0a0a·0966··"·&gt;&amp;2...f 
0003c550:·616c·7365·2020·2320·656e·6420·7769·7468··alse··#·end·with 
0003c560:·2061·6e20·6572·726f·7220·636f·6465·0a65···an·error·code.e 
0003c570:·6c69·6620·7465·7374·2022·2472·6322·2021··lif·test·"$rc"·! 
0003c580:·3d20·303b·2074·6865·6e0a·0965·6368·6f20··=·0;·then..echo· 
0003c590:·2245·7272·6f72·2069·6e76·6f6b·696e·6720··"Error·invoking· 
0003c5a0:·7468·6520·7570·6461·7465·2d63·7279·7074··the·update-crypt 
0003c5b0:·6f2d·706f·6c69·6369·6573·2073·6372·6970··o-policies·scrip 
0003c5c0:·743a·2024·7374·6465·7272·5f6f·665f·6361··t:·$stderr_of_ca 
0003c5d0:·6c6c·2220·2667·743b·2661·6d70·3b32·0a09··ll"·&gt;&amp;2.. 
0003c5e0:·6661·6c73·6520·2023·2065·6e64·2077·6974··false··#·end·wit 
0003c5f0:·6820·616e·2065·7272·6f72·2063·6f64·650a··h·an·error·code. 
0003c600:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre> 
0003c610:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003c620:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003c630:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003c640:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003c650:·6765·743d·2223·6964·6d32·3533·3422·2074··get="#idm2534"·t 
0003c660:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003c670:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003c680:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003c690:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003c6a0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003c6b0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003c6c0:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet 
0003c6d0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003c6e0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003c6f0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003c700:·2069·643d·2269·646d·3235·3334·223e·3c74···id="idm2534"><t 
0003c710:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003c720:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003c730:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0003c360:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003c740:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003c750:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003c760:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<0003c370:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0003c380:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0003c390:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003c3a0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0003c3b0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003c3c0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
 0003c3d0:·743a·3c2f·7468·3e3c·7464·3e74·7275·653c··t:</th><td>true<
0003c770:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003c3e0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c780:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003c790:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003c7a0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003c7b0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003c7c0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003c7d0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003c3f0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003c7e0:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>0003c400:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>
0003c7f0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003c410:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003c420:·653e·3c63·6f64·653e·2d2d·2d0a·6170·6956··e><code>---.apiV
 0003c430:·6572·7369·6f6e·3a20·6d61·6368·696e·6563··ersion:·machinec
 0003c440:·6f6e·6669·6775·7261·7469·6f6e·2e6f·7065··onfiguration.ope
 0003c450:·6e73·6869·6674·2e69·6f2f·7631·0a6b·696e··nshift.io/v1.kin
 0003c460:·643a·204d·6163·6869·6e65·436f·6e66·6967··d:·MachineConfig
 0003c470:·0a73·7065·633a·0a20·2063·6f6e·6669·673a··.spec:.··config:
 0003c480:·0a20·2020·2069·676e·6974·696f·6e3a·0a20··.····ignition:.·
Max diff block lines reached; 18066420/18099180 bytes (99.82%) of diff not shown.
1.69 MB
html2text {}
    
Offset 43, 15 lines modifiedOffset 43, 15 lines modified
43 ····*·cpe:/o:fedoraproject:fedora:4143 ····*·cpe:/o:fedoraproject:fedora:41
44 ····*·cpe:/o:fedoraproject:fedora:4244 ····*·cpe:/o:fedoraproject:fedora:42
45 ····*·cpe:/o:fedoraproject:fedora:4345 ····*·cpe:/o:fedoraproject:fedora:43
46 ····*·cpe:/o:fedoraproject:fedora:4446 ····*·cpe:/o:fedoraproject:fedora:44
47 ····*·cpe:/o:fedoraproject:fedora:4547 ····*·cpe:/o:fedoraproject:fedora:45
48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
49 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8449 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
55 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n55 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
56 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g56 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
57 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s57 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 133, 33 lines modifiedOffset 133, 39 lines modified
133 ············_\x8h_\x8i_\x8p_\x8a_\x8a····164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.312(e)(1),·164.312(e)(2)(ii)133 ············_\x8h_\x8i_\x8p_\x8a_\x8a····164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.312(e)(1),·164.312(e)(2)(ii)
134 ············_\x8i_\x8s_\x8m······1446134 ············_\x8i_\x8s_\x8m······1446
135 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1135 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1
136 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)136 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)
137 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1137 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
138 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174138 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
139 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7139 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
  
141 var_system_crypto_policy='DEFAULT' 
  
  
142 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
143 rc=$? 
  
144 if·test·"$rc"·=·127;·then 
145 »       echo·"$stderr_of_call"·>&2 
146 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
147 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
148 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
149 »       false··#·end·with·an·error·code 
150 elif·test·"$rc"·!=·0;·then 
151 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
152 »       false··#·end·with·an·error·code 
153 fi141 C.Co.om.mp.pl.le.ex.xi.it.ty.y:.:·low
 142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 145 ---
 146 apiVersion:·machineconfiguration.openshift.io/v1
 147 kind:·MachineConfig
 148 spec:
 149 ··config:
 150 ····ignition:
 151 ······version:·3.1.0
 152 ····systemd:
 153 ······units:
 154 ········-·name:·configure-crypto-policy.service
 155 ··········enabled:·true
 156 ··········contents:·|
 157 ············[Unit]
 158 ············Before=kubelet.service
 159 ············[Service]
 160 ············Type=oneshot
 161 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 162 ············RemainAfterExit=yes
 163 ············[Install]
 164 ············WantedBy=multi-user.target
154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
159 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable170 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
160 ··set_fact:171 ··set_fact:
Offset 202, 74 lines modifiedOffset 208, 41 lines modified
202 ··-·PCI-DSSv4-2.2.7208 ··-·PCI-DSSv4-2.2.7
203 ··-·configure_crypto_policy209 ··-·configure_crypto_policy
204 ··-·high_severity210 ··-·high_severity
205 ··-·low_complexity211 ··-·low_complexity
206 ··-·low_disruption212 ··-·low_disruption
207 ··-·no_reboot_needed213 ··-·no_reboot_needed
208 ··-·restrict_strategy214 ··-·restrict_strategy
209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8215 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
  
 216 var_system_crypto_policy='DEFAULT'
  
  
 217 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null)
 218 rc=$?
  
 219 if·test·"$rc"·=·127;·then
 220 »       echo·"$stderr_of_call"·>&2
 221 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2
 222 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2
 223 »       echo·"to·see·what·package·to·(re)install"·>&2
  
 224 »       false··#·end·with·an·error·code
 225 elif·test·"$rc"·!=·0;·then
 226 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
 227 »       false··#·end·with·an·error·code
 228 fi
210 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
211 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
212 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
213 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
214 --- 
215 apiVersion:·machineconfiguration.openshift.io/v1 
216 kind:·MachineConfig 
217 spec: 
218 ··config: 
219 ····ignition: 
220 ······version:·3.1.0 
221 ····systemd: 
222 ······units: 
223 ········-·name:·configure-crypto-policy.service 
224 ··········enabled:·true 
225 ··········contents:·| 
226 ············[Unit] 
227 ············Before=kubelet.service 
228 ············[Service] 
229 ············Type=oneshot 
230 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
231 ············RemainAfterExit=yes 
232 ············[Install] 
233 ············WantedBy=multi-user.target 
234 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·G\x8Gn\x8nu\x8uT\x8TL\x8LS\x8S·l\x8li\x8ib\x8br\x8ra\x8ar\x8ry\x8y·t\x8to\x8o·u\x8us\x8se\x8e·D\x8Do\x8oD\x8D-\x8-a\x8ap\x8pp\x8pr\x8ro\x8ov\x8ve\x8ed\x8d·T\x8TL\x8LS\x8S·E\x8En\x8nc\x8cr\x8ry\x8yp\x8pt\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*229 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·G\x8Gn\x8nu\x8uT\x8TL\x8LS\x8S·l\x8li\x8ib\x8br\x8ra\x8ar\x8ry\x8y·t\x8to\x8o·u\x8us\x8se\x8e·D\x8Do\x8oD\x8D-\x8-a\x8ap\x8pp\x8pr\x8ro\x8ov\x8ve\x8ed\x8d·T\x8TL\x8LS\x8S·E\x8En\x8nc\x8cr\x8ry\x8yp\x8pt\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
235 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·GnuTLS·is·supported·by·system·crypto·policy,·but·the·GnuTLS·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·/etc/crypto-policies/back-ends/gnutls.config·contains·the·following·line·and·is·not·commented·out:·+VERS-ALL:-VERS-DTLS0.9:-VERS-SSL3.0:-VERS-TLS1.0:-VERS-TLS1.1:-VERS-DTLS1.0230 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·GnuTLS·is·supported·by·system·crypto·policy,·but·the·GnuTLS·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·/etc/crypto-policies/back-ends/gnutls.config·contains·the·following·line·and·is·not·commented·out:·+VERS-ALL:-VERS-DTLS0.9:-VERS-SSL3.0:-VERS-TLS1.0:-VERS-TLS1.1:-VERS-DTLS1.0
236 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·GnuTLS·library·violate·expectations,·and·makes·system·configuration·more·fragmented.231 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·GnuTLS·library·violate·expectations,·and·makes·system·configuration·more·fragmented.
237 Severity: ··medium232 Severity: ··medium
Max diff block lines reached; 1767044/1773054 bytes (99.66%) of diff not shown.
26.9 MB
./usr/share/doc/ssg-nondebian/ssg-fedora-guide-ospp.html
    
Offset 14376, 16 lines modifiedOffset 14376, 16 lines modified
00038270:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00038270:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00038280:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00038280:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00038290:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000038290:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
000382a0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></000382a0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
000382b0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron000382b0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
000382c0:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>000382c0:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
000382d0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············000382d0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
000382e0:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·2026000382e0:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
000382f0:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········000382f0:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00038300:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00038300:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00038310:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00038310:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00038320:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00038320:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00038330:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00038330:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00038340:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00038340:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00038350:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00038350:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00038360:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00038360:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
Offset 15236, 300 lines modifiedOffset 15236, 300 lines modified
0003b830:·6574·3d22·2369·646d·3138·3632·2220·7461··et="#idm1862"·ta0003b830:·6574·3d22·2369·646d·3138·3632·2220·7461··et="#idm1862"·ta
0003b840:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003b840:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003b850:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003b850:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003b860:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003b860:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003b870:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003b870:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003b880:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003b880:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003b890:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003b890:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003b8a0:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
0003b8b0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b8c0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b8d0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b8e0:·2269·646d·3138·3632·223e·3c70·7265·3e3c··"idm1862"><pre>< 
0003b8f0:·636f·6465·3e0a·2320·4669·6e64·2077·6869··code>.#·Find·whi 
0003b900:·6368·2066·696c·6573·2068·6176·6520·696e··ch·files·have·in 
0003b910:·636f·7272·6563·7420·6861·7368·2028·6e6f··correct·hash·(no 
0003b920:·7420·696e·202f·6574·632c·2062·6563·6175··t·in·/etc,·becau 
0003b930:·7365·206f·6620·7468·6520·7379·7374·656d··se·of·the·system 
0003b940:·2072·656c·6174·6564·2063·6f6e·6669·6720···related·config· 
0003b950:·6669·6c65·7329·2061·6e64·2074·6865·6e20··files)·and·then· 
0003b960:·6765·7420·6669·6c65·7320·6e61·6d65·730a··get·files·names. 
0003b970:·6669·6c65·735f·7769·7468·5f69·6e63·6f72··files_with_incor 
0003b980:·7265·6374·5f68·6173·683d·2224·2872·706d··rect_hash="$(rpm 
0003b990:·202d·5661·202d·2d6e·6f63·6f6e·6669·6720···-Va·--noconfig· 
0003b9a0:·7c20·6772·6570·202d·4520·275e·2e2e·3527··|·grep·-E·'^..5' 
0003b9b0:·207c·2061·776b·2027·7b70·7269·6e74·2024···|·awk·'{print·$ 
0003b9c0:·4e46·7d27·2029·220a·0a69·6620·5b20·2d6e··NF}'·)"..if·[·-n 
0003b9d0:·2022·2466·696c·6573·5f77·6974·685f·696e···"$files_with_in 
0003b9e0:·636f·7272·6563·745f·6861·7368·2220·5d3b··correct_hash"·]; 
0003b9f0:·2074·6865·6e0a·2020·2020·2320·4672·6f6d···then.····#·From 
0003ba00:·2066·696c·6573·206e·616d·6573·2067·6574···files·names·get 
0003ba10:·2070·6163·6b61·6765·206e·616d·6573·2061···package·names·a 
0003ba20:·6e64·2063·6861·6e67·6520·6e65·776c·696e··nd·change·newlin 
0003ba30:·6520·746f·2073·7061·6365·2c20·6265·6361··e·to·space,·beca 
0003ba40:·7573·6520·7270·6d20·7772·6974·6573·2065··use·rpm·writes·e 
0003ba50:·6163·6820·7061·636b·6167·6520·746f·206e··ach·package·to·n 
0003ba60:·6577·206c·696e·650a·2020·2020·7061·636b··ew·line.····pack 
0003ba70:·6167·6573·5f74·6f5f·7265·696e·7374·616c··ages_to_reinstal 
0003ba80:·6c3d·2224·2872·706d·202d·7166·2024·6669··l="$(rpm·-qf·$fi 
0003ba90:·6c65·735f·7769·7468·5f69·6e63·6f72·7265··les_with_incorre 
0003baa0:·6374·5f68·6173·6820·7c20·7472·2027·5c6e··ct_hash·|·tr·'\n 
0003bab0:·2720·2720·2729·220a·0a20·2020·200a·2020··'·'·')"..····.·· 
0003bac0:·2020·646e·6620·7265·696e·7374·616c·6c20····dnf·reinstall· 
0003bad0:·2d79·2024·7061·636b·6167·6573·5f74·6f5f··-y·$packages_to_ 
0003bae0:·7265·696e·7374·616c·6c0a·2020·2020·0a66··reinstall.····.f 
0003baf0:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre>< 
0003bb00:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003bb10:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003bb20:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003bb30:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003bb40:·6574·3d22·2369·646d·3138·3633·2220·7461··et="#idm1863"·ta 
0003bb50:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003bb60:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003bb70:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003bb80:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003bb90:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003bba0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003bbb0:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet·0003b8a0:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet·
0003bbc0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003b8b0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003bbd0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003b8c0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003bbe0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003b8d0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003bbf0:·6964·3d22·6964·6d31·3836·3322·3e3c·7461··id="idm1863"><ta0003b8e0:·6964·3d22·6964·6d31·3836·3222·3e3c·7461··id="idm1862"><ta
0003bc00:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0003b8f0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003bc10:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0003b900:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003bc20:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0003b910:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003bc30:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0003b920:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003bc40:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003b930:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003bc50:·793a·3c2f·7468·3e3c·7464·3e68·6967·683c··y:</th><td>high<0003b940:·793a·3c2f·7468·3e3c·7464·3e68·6967·683c··y:</th><td>high<
0003bc60:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b950:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003bc70:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th0003b960:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003bc80:·3e3c·7464·3e6d·6564·6975·6d3c·2f74·643e··><td>medium</td>0003b970:·3e3c·7464·3e6d·6564·6975·6d3c·2f74·643e··><td>medium</td>
0003bc90:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb0003b980:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
0003bca0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal0003b990:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
0003bcb0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>0003b9a0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
0003bcc0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t0003b9b0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0003bcd0:·683e·3c74·643e·7265·7374·7269·6374·3c2f··h><td>restrict</0003b9c0:·683e·3c74·643e·7265·7374·7269·6374·3c2f··h><td>restrict</
0003bce0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>0003b9d0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
0003bcf0:·3c70·7265·3e3c·636f·6465·3e2d·206e·616d··<pre><code>-·nam0003b9e0:·3c70·7265·3e3c·636f·6465·3e2d·206e·616d··<pre><code>-·nam
0003bd00:·653a·2027·5365·7420·6661·6374·3a20·5061··e:·'Set·fact:·Pa0003b9f0:·653a·2027·5365·7420·6661·6374·3a20·5061··e:·'Set·fact:·Pa
0003bd10:·636b·6167·6520·6d61·6e61·6765·7220·7265··ckage·manager·re0003ba00:·636b·6167·6520·6d61·6e61·6765·7220·7265··ckage·manager·re
0003bd20:·696e·7374·616c·6c20·636f·6d6d·616e·6427··install·command'0003ba10:·696e·7374·616c·6c20·636f·6d6d·616e·6427··install·command'
0003bd30:·0a20·2073·6574·5f66·6163·743a·0a20·2020··.··set_fact:.···0003ba20:·0a20·2073·6574·5f66·6163·743a·0a20·2020··.··set_fact:.···
0003bd40:·2070·6163·6b61·6765·5f6d·616e·6167·6572···package_manager0003ba30:·2070·6163·6b61·6765·5f6d·616e·6167·6572···package_manager
0003bd50:·5f72·6569·6e73·7461·6c6c·5f63·6d64·3a20··_reinstall_cmd:·0003ba40:·5f72·6569·6e73·7461·6c6c·5f63·6d64·3a20··_reinstall_cmd:·
0003bd60:·646e·6620·7265·696e·7374·616c·6c20·2d79··dnf·reinstall·-y0003ba50:·646e·6620·7265·696e·7374·616c·6c20·2d79··dnf·reinstall·-y
0003bd70:·0a20·2077·6865·6e3a·2061·6e73·6962·6c65··.··when:·ansible0003ba60:·0a20·2077·6865·6e3a·2061·6e73·6962·6c65··.··when:·ansible
0003bd80:·5f64·6973·7472·6962·7574·696f·6e20·696e··_distribution·in0003ba70:·5f64·6973·7472·6962·7574·696f·6e20·696e··_distribution·in
0003bd90:·205b·2022·4665·646f·7261·222c·2022·5265···[·"Fedora",·"Re0003ba80:·205b·2022·4665·646f·7261·222c·2022·5265···[·"Fedora",·"Re
0003bda0:·6448·6174·222c·2022·4365·6e74·4f53·222c··dHat",·"CentOS",0003ba90:·6448·6174·222c·2022·4365·6e74·4f53·222c··dHat",·"CentOS",
0003bdb0:·2022·4f72·6163·6c65·4c69·6e75·7822·205d···"OracleLinux"·]0003baa0:·2022·4f72·6163·6c65·4c69·6e75·7822·205d···"OracleLinux"·]
0003bdc0:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI0003bab0:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI
0003bdd0:·532d·352e·3130·2e34·2e31·0a20·202d·204e··S-5.10.4.1.··-·N0003bac0:·532d·352e·3130·2e34·2e31·0a20·202d·204e··S-5.10.4.1.··-·N
0003bde0:·4953·542d·3830·302d·3137·312d·332e·332e··IST-800-171-3.3.0003bad0:·4953·542d·3830·302d·3137·312d·332e·332e··IST-800-171-3.3.
0003bdf0:·380a·2020·2d20·4e49·5354·2d38·3030·2d31··8.··-·NIST-800-10003bae0:·380a·2020·2d20·4e49·5354·2d38·3030·2d31··8.··-·NIST-800-1
0003be00:·3731·2d33·2e34·2e31·0a20·202d·204e·4953··71-3.4.1.··-·NIS0003baf0:·3731·2d33·2e34·2e31·0a20·202d·204e·4953··71-3.4.1.··-·NIS
0003be10:·542d·3830·302d·3533·2d41·552d·3928·3329··T-800-53-AU-9(3)0003bb00:·542d·3830·302d·3533·2d41·552d·3928·3329··T-800-53-AU-9(3)
0003be20:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-530003bb10:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
0003be30:·2d43·4d2d·3628·6329·0a20·202d·204e·4953··-CM-6(c).··-·NIS0003bb20:·2d43·4d2d·3628·6329·0a20·202d·204e·4953··-CM-6(c).··-·NIS
0003be40:·542d·3830·302d·3533·2d43·4d2d·3628·6429··T-800-53-CM-6(d)0003bb30:·542d·3830·302d·3533·2d43·4d2d·3628·6429··T-800-53-CM-6(d)
0003be50:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-530003bb40:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
0003be60:·2d53·492d·370a·2020·2d20·4e49·5354·2d38··-SI-7.··-·NIST-80003bb50:·2d53·492d·370a·2020·2d20·4e49·5354·2d38··-SI-7.··-·NIST-8
0003be70:·3030·2d35·332d·5349·2d37·2831·290a·2020··00-53-SI-7(1).··0003bb60:·3030·2d35·332d·5349·2d37·2831·290a·2020··00-53-SI-7(1).··
0003be80:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI0003bb70:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI
0003be90:·2d37·2836·290a·2020·2d20·5043·492d·4453··-7(6).··-·PCI-DS0003bb80:·2d37·2836·290a·2020·2d20·5043·492d·4453··-7(6).··-·PCI-DS
0003bea0:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P0003bb90:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P
0003beb0:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2.0003bba0:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2.
0003bec0:·2020·2d20·6869·6768·5f63·6f6d·706c·6578····-·high_complex0003bbb0:·2020·2d20·6869·6768·5f63·6f6d·706c·6578····-·high_complex
0003bed0:·6974·790a·2020·2d20·6869·6768·5f73·6576··ity.··-·high_sev0003bbc0:·6974·790a·2020·2d20·6869·6768·5f73·6576··ity.··-·high_sev
0003bee0:·6572·6974·790a·2020·2d20·6d65·6469·756d··erity.··-·medium0003bbd0:·6572·6974·790a·2020·2d20·6d65·6469·756d··erity.··-·medium
0003bef0:·5f64·6973·7275·7074·696f·6e0a·2020·2d20··_disruption.··-·0003bbe0:·5f64·6973·7275·7074·696f·6e0a·2020·2d20··_disruption.··-·
0003bf00:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed0003bbf0:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed
Max diff block lines reached; 26573817/26615133 bytes (99.84%) of diff not shown.
1.56 MB
html2text {}
    
Offset 49, 15 lines modifiedOffset 49, 15 lines modified
49 ····*·cpe:/o:fedoraproject:fedora:4149 ····*·cpe:/o:fedoraproject:fedora:41
50 ····*·cpe:/o:fedoraproject:fedora:4250 ····*·cpe:/o:fedoraproject:fedora:42
51 ····*·cpe:/o:fedoraproject:fedora:4351 ····*·cpe:/o:fedoraproject:fedora:43
52 ····*·cpe:/o:fedoraproject:fedora:4452 ····*·cpe:/o:fedoraproject:fedora:44
53 ····*·cpe:/o:fedoraproject:fedora:4553 ····*·cpe:/o:fedoraproject:fedora:45
54 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*54 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
55 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8455 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
56 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)56 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
57 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*57 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
58 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s58 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
59 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e59 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
60 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l60 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
61 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n61 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
62 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g62 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
63 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s63 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 113, 27 lines modifiedOffset 113, 14 lines modified
113 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6113 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
114 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4114 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
115 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)115 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
116 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1116 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
117 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5117 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
118 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227118 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
119 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2119 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
121 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
122 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
123 if·[·-n·"$files_with_incorrect_hash"·];·then 
124 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
125 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
126 ····dnf·reinstall·-y·$packages_to_reinstall 
  
127 fi 
128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high121 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium122 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false123 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict124 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
133 -·name:·'Set·fact:·Package·manager·reinstall·command'125 -·name:·'Set·fact:·Package·manager·reinstall·command'
134 ··set_fact:126 ··set_fact:
Offset 260, 14 lines modifiedOffset 247, 27 lines modified
260 ··-·PCI-DSSv4-11.5.2247 ··-·PCI-DSSv4-11.5.2
261 ··-·high_complexity248 ··-·high_complexity
262 ··-·high_severity249 ··-·high_severity
263 ··-·medium_disruption250 ··-·medium_disruption
264 ··-·no_reboot_needed251 ··-·no_reboot_needed
265 ··-·restrict_strategy252 ··-·restrict_strategy
266 ··-·rpm_verify_hashes253 ··-·rpm_verify_hashes
 254 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 255 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 256 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 257 if·[·-n·"$files_with_incorrect_hash"·];·then
 258 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 259 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 260 ····dnf·reinstall·-y·$packages_to_reinstall
  
 261 fi
267 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·1·rule262 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·1·rule
268 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.263 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
269 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Fedora.264 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Fedora.
  
270 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.265 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
271 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*266 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 286, 41 lines modifiedOffset 286, 18 lines modified
286 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode286 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode
287 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000068,·CCI-000803,·CCI-002450287 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000068,·CCI-000803,·CCI-002450
288 ············_\x8i_\x8s_\x8m······1446288 ············_\x8i_\x8s_\x8m······1446
289 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1289 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
290 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12290 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
291 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1291 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
292 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176292 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
 293 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
293 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
294 #·Remediation·is·applicable·only·in·certain·platforms 
295 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·)·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then 
  
296 var_system_crypto_policy='FIPS' 
  
  
297 fips-mode-setup·--enable 
  
298 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
299 rc=$? 
  
300 if·test·"$rc"·=·127;·then 
301 »       echo·"$stderr_of_call"·>&2 
302 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
303 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
304 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
305 »       false··#·end·with·an·error·code 
306 elif·test·"$rc"·!=·0;·then 
307 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
308 »       false··#·end·with·an·error·code 
309 fi 
  
 294 [customizations]
 295 fips·=·true
310 else 
311 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
312 fi 
313 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8296 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
314 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium297 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium
315 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium298 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
316 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true299 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
317 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict300 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
318 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable301 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
319 ··set_fact:302 ··set_fact:
Offset 416, 18 lines modifiedOffset 393, 41 lines modified
416 ··-·NIST-800-53-SC-13393 ··-·NIST-800-53-SC-13
417 ··-·enable_fips_mode394 ··-·enable_fips_mode
418 ··-·high_severity395 ··-·high_severity
419 ··-·medium_complexity396 ··-·medium_complexity
420 ··-·medium_disruption397 ··-·medium_disruption
421 ··-·reboot_required398 ··-·reboot_required
422 ··-·restrict_strategy399 ··-·restrict_strategy
423 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8400 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 401 #·Remediation·is·applicable·only·in·certain·platforms
 402 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·)·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
Max diff block lines reached; 1630062/1637138 bytes (99.57%) of diff not shown.
14.5 MB
./usr/share/doc/ssg-nondebian/ssg-fedora-guide-pci-dss.html
    
Offset 14349, 15 lines modifiedOffset 14349, 15 lines modified
000380c0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>000380c0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
000380d0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:000380d0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
000380e0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<000380e0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<
000380f0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>000380f0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00038100:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00038100:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00038110:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00038110:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00038120:·2020·2020·2020·2020·2020·2020·2020·2028·················(00038120:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00038130:·6173·206f·6620·3230·3236·2d30·312d·3038··as·of·2026-01-0800038130:·6173·206f·6620·3230·3234·2d31·322d·3037··as·of·2024-12-07
00038140:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00038140:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00038150:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00038150:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00038160:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00038160:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00038170:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00038170:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00038180:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00038180:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00038190:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00038190:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
000381a0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group000381a0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
Offset 15177, 300 lines modifiedOffset 15177, 300 lines modified
0003b480:·6574·3d22·2369·646d·3138·3632·2220·7461··et="#idm1862"·ta0003b480:·6574·3d22·2369·646d·3138·3632·2220·7461··et="#idm1862"·ta
0003b490:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003b490:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003b4a0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003b4a0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003b4b0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003b4b0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003b4c0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003b4c0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003b4d0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003b4d0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003b4e0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003b4e0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003b4f0:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
0003b500:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b510:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b520:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b530:·2269·646d·3138·3632·223e·3c70·7265·3e3c··"idm1862"><pre>< 
0003b540:·636f·6465·3e0a·2320·4669·6e64·2077·6869··code>.#·Find·whi 
0003b550:·6368·2066·696c·6573·2068·6176·6520·696e··ch·files·have·in 
0003b560:·636f·7272·6563·7420·6861·7368·2028·6e6f··correct·hash·(no 
0003b570:·7420·696e·202f·6574·632c·2062·6563·6175··t·in·/etc,·becau 
0003b580:·7365·206f·6620·7468·6520·7379·7374·656d··se·of·the·system 
0003b590:·2072·656c·6174·6564·2063·6f6e·6669·6720···related·config· 
0003b5a0:·6669·6c65·7329·2061·6e64·2074·6865·6e20··files)·and·then· 
0003b5b0:·6765·7420·6669·6c65·7320·6e61·6d65·730a··get·files·names. 
0003b5c0:·6669·6c65·735f·7769·7468·5f69·6e63·6f72··files_with_incor 
0003b5d0:·7265·6374·5f68·6173·683d·2224·2872·706d··rect_hash="$(rpm 
0003b5e0:·202d·5661·202d·2d6e·6f63·6f6e·6669·6720···-Va·--noconfig· 
0003b5f0:·7c20·6772·6570·202d·4520·275e·2e2e·3527··|·grep·-E·'^..5' 
0003b600:·207c·2061·776b·2027·7b70·7269·6e74·2024···|·awk·'{print·$ 
0003b610:·4e46·7d27·2029·220a·0a69·6620·5b20·2d6e··NF}'·)"..if·[·-n 
0003b620:·2022·2466·696c·6573·5f77·6974·685f·696e···"$files_with_in 
0003b630:·636f·7272·6563·745f·6861·7368·2220·5d3b··correct_hash"·]; 
0003b640:·2074·6865·6e0a·2020·2020·2320·4672·6f6d···then.····#·From 
0003b650:·2066·696c·6573·206e·616d·6573·2067·6574···files·names·get 
0003b660:·2070·6163·6b61·6765·206e·616d·6573·2061···package·names·a 
0003b670:·6e64·2063·6861·6e67·6520·6e65·776c·696e··nd·change·newlin 
0003b680:·6520·746f·2073·7061·6365·2c20·6265·6361··e·to·space,·beca 
0003b690:·7573·6520·7270·6d20·7772·6974·6573·2065··use·rpm·writes·e 
0003b6a0:·6163·6820·7061·636b·6167·6520·746f·206e··ach·package·to·n 
0003b6b0:·6577·206c·696e·650a·2020·2020·7061·636b··ew·line.····pack 
0003b6c0:·6167·6573·5f74·6f5f·7265·696e·7374·616c··ages_to_reinstal 
0003b6d0:·6c3d·2224·2872·706d·202d·7166·2024·6669··l="$(rpm·-qf·$fi 
0003b6e0:·6c65·735f·7769·7468·5f69·6e63·6f72·7265··les_with_incorre 
0003b6f0:·6374·5f68·6173·6820·7c20·7472·2027·5c6e··ct_hash·|·tr·'\n 
0003b700:·2720·2720·2729·220a·0a20·2020·200a·2020··'·'·')"..····.·· 
0003b710:·2020·646e·6620·7265·696e·7374·616c·6c20····dnf·reinstall· 
0003b720:·2d79·2024·7061·636b·6167·6573·5f74·6f5f··-y·$packages_to_ 
0003b730:·7265·696e·7374·616c·6c0a·2020·2020·0a66··reinstall.····.f 
0003b740:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre>< 
0003b750:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003b760:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003b770:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003b780:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003b790:·6574·3d22·2369·646d·3138·3633·2220·7461··et="#idm1863"·ta 
0003b7a0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003b7b0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003b7c0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003b7d0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003b7e0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003b7f0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003b800:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet·0003b4f0:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet·
0003b810:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003b500:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003b820:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003b510:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003b830:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003b520:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003b840:·6964·3d22·6964·6d31·3836·3322·3e3c·7461··id="idm1863"><ta0003b530:·6964·3d22·6964·6d31·3836·3222·3e3c·7461··id="idm1862"><ta
0003b850:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0003b540:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003b860:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0003b550:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003b870:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0003b560:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003b880:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0003b570:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003b890:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003b580:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003b8a0:·793a·3c2f·7468·3e3c·7464·3e68·6967·683c··y:</th><td>high<0003b590:·793a·3c2f·7468·3e3c·7464·3e68·6967·683c··y:</th><td>high<
0003b8b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b5a0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b8c0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th0003b5b0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003b8d0:·3e3c·7464·3e6d·6564·6975·6d3c·2f74·643e··><td>medium</td>0003b5c0:·3e3c·7464·3e6d·6564·6975·6d3c·2f74·643e··><td>medium</td>
0003b8e0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb0003b5d0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
0003b8f0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal0003b5e0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
0003b900:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>0003b5f0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
0003b910:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t0003b600:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0003b920:·683e·3c74·643e·7265·7374·7269·6374·3c2f··h><td>restrict</0003b610:·683e·3c74·643e·7265·7374·7269·6374·3c2f··h><td>restrict</
0003b930:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>0003b620:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
0003b940:·3c70·7265·3e3c·636f·6465·3e2d·206e·616d··<pre><code>-·nam0003b630:·3c70·7265·3e3c·636f·6465·3e2d·206e·616d··<pre><code>-·nam
0003b950:·653a·2027·5365·7420·6661·6374·3a20·5061··e:·'Set·fact:·Pa0003b640:·653a·2027·5365·7420·6661·6374·3a20·5061··e:·'Set·fact:·Pa
0003b960:·636b·6167·6520·6d61·6e61·6765·7220·7265··ckage·manager·re0003b650:·636b·6167·6520·6d61·6e61·6765·7220·7265··ckage·manager·re
0003b970:·696e·7374·616c·6c20·636f·6d6d·616e·6427··install·command'0003b660:·696e·7374·616c·6c20·636f·6d6d·616e·6427··install·command'
0003b980:·0a20·2073·6574·5f66·6163·743a·0a20·2020··.··set_fact:.···0003b670:·0a20·2073·6574·5f66·6163·743a·0a20·2020··.··set_fact:.···
0003b990:·2070·6163·6b61·6765·5f6d·616e·6167·6572···package_manager0003b680:·2070·6163·6b61·6765·5f6d·616e·6167·6572···package_manager
0003b9a0:·5f72·6569·6e73·7461·6c6c·5f63·6d64·3a20··_reinstall_cmd:·0003b690:·5f72·6569·6e73·7461·6c6c·5f63·6d64·3a20··_reinstall_cmd:·
0003b9b0:·646e·6620·7265·696e·7374·616c·6c20·2d79··dnf·reinstall·-y0003b6a0:·646e·6620·7265·696e·7374·616c·6c20·2d79··dnf·reinstall·-y
0003b9c0:·0a20·2077·6865·6e3a·2061·6e73·6962·6c65··.··when:·ansible0003b6b0:·0a20·2077·6865·6e3a·2061·6e73·6962·6c65··.··when:·ansible
0003b9d0:·5f64·6973·7472·6962·7574·696f·6e20·696e··_distribution·in0003b6c0:·5f64·6973·7472·6962·7574·696f·6e20·696e··_distribution·in
0003b9e0:·205b·2022·4665·646f·7261·222c·2022·5265···[·"Fedora",·"Re0003b6d0:·205b·2022·4665·646f·7261·222c·2022·5265···[·"Fedora",·"Re
0003b9f0:·6448·6174·222c·2022·4365·6e74·4f53·222c··dHat",·"CentOS",0003b6e0:·6448·6174·222c·2022·4365·6e74·4f53·222c··dHat",·"CentOS",
0003ba00:·2022·4f72·6163·6c65·4c69·6e75·7822·205d···"OracleLinux"·]0003b6f0:·2022·4f72·6163·6c65·4c69·6e75·7822·205d···"OracleLinux"·]
0003ba10:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI0003b700:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI
0003ba20:·532d·352e·3130·2e34·2e31·0a20·202d·204e··S-5.10.4.1.··-·N0003b710:·532d·352e·3130·2e34·2e31·0a20·202d·204e··S-5.10.4.1.··-·N
0003ba30:·4953·542d·3830·302d·3137·312d·332e·332e··IST-800-171-3.3.0003b720:·4953·542d·3830·302d·3137·312d·332e·332e··IST-800-171-3.3.
0003ba40:·380a·2020·2d20·4e49·5354·2d38·3030·2d31··8.··-·NIST-800-10003b730:·380a·2020·2d20·4e49·5354·2d38·3030·2d31··8.··-·NIST-800-1
0003ba50:·3731·2d33·2e34·2e31·0a20·202d·204e·4953··71-3.4.1.··-·NIS0003b740:·3731·2d33·2e34·2e31·0a20·202d·204e·4953··71-3.4.1.··-·NIS
0003ba60:·542d·3830·302d·3533·2d41·552d·3928·3329··T-800-53-AU-9(3)0003b750:·542d·3830·302d·3533·2d41·552d·3928·3329··T-800-53-AU-9(3)
0003ba70:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-530003b760:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
0003ba80:·2d43·4d2d·3628·6329·0a20·202d·204e·4953··-CM-6(c).··-·NIS0003b770:·2d43·4d2d·3628·6329·0a20·202d·204e·4953··-CM-6(c).··-·NIS
0003ba90:·542d·3830·302d·3533·2d43·4d2d·3628·6429··T-800-53-CM-6(d)0003b780:·542d·3830·302d·3533·2d43·4d2d·3628·6429··T-800-53-CM-6(d)
0003baa0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-530003b790:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
0003bab0:·2d53·492d·370a·2020·2d20·4e49·5354·2d38··-SI-7.··-·NIST-80003b7a0:·2d53·492d·370a·2020·2d20·4e49·5354·2d38··-SI-7.··-·NIST-8
0003bac0:·3030·2d35·332d·5349·2d37·2831·290a·2020··00-53-SI-7(1).··0003b7b0:·3030·2d35·332d·5349·2d37·2831·290a·2020··00-53-SI-7(1).··
0003bad0:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI0003b7c0:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI
0003bae0:·2d37·2836·290a·2020·2d20·5043·492d·4453··-7(6).··-·PCI-DS0003b7d0:·2d37·2836·290a·2020·2d20·5043·492d·4453··-7(6).··-·PCI-DS
0003baf0:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P0003b7e0:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P
0003bb00:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2.0003b7f0:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2.
0003bb10:·2020·2d20·6869·6768·5f63·6f6d·706c·6578····-·high_complex0003b800:·2020·2d20·6869·6768·5f63·6f6d·706c·6578····-·high_complex
0003bb20:·6974·790a·2020·2d20·6869·6768·5f73·6576··ity.··-·high_sev0003b810:·6974·790a·2020·2d20·6869·6768·5f73·6576··ity.··-·high_sev
0003bb30:·6572·6974·790a·2020·2d20·6d65·6469·756d··erity.··-·medium0003b820:·6572·6974·790a·2020·2d20·6d65·6469·756d··erity.··-·medium
0003bb40:·5f64·6973·7275·7074·696f·6e0a·2020·2d20··_disruption.··-·0003b830:·5f64·6973·7275·7074·696f·6e0a·2020·2d20··_disruption.··-·
0003bb50:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed0003b840:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed
0003bb60:·0a20·202d·2072·6573·7472·6963·745f·7374··.··-·restrict_st0003b850:·0a20·202d·2072·6573·7472·6963·745f·7374··.··-·restrict_st
Max diff block lines reached; 14008764/14049942 bytes (99.71%) of diff not shown.
1.06 MB
html2text {}
    
Offset 42, 15 lines modifiedOffset 42, 15 lines modified
42 ····*·cpe:/o:fedoraproject:fedora:4142 ····*·cpe:/o:fedoraproject:fedora:41
43 ····*·cpe:/o:fedoraproject:fedora:4243 ····*·cpe:/o:fedoraproject:fedora:42
44 ····*·cpe:/o:fedoraproject:fedora:4344 ····*·cpe:/o:fedoraproject:fedora:43
45 ····*·cpe:/o:fedoraproject:fedora:4445 ····*·cpe:/o:fedoraproject:fedora:44
46 ····*·cpe:/o:fedoraproject:fedora:4546 ····*·cpe:/o:fedoraproject:fedora:45
47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
48 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8448 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
54 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n54 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
55 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g55 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
56 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s56 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 100, 27 lines modifiedOffset 100, 14 lines modified
100 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6100 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
101 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4101 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
102 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)102 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
103 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1103 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
104 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5104 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
105 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227105 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
106 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2106 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
107 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
108 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
109 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
110 if·[·-n·"$files_with_incorrect_hash"·];·then 
111 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
112 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
113 ····dnf·reinstall·-y·$packages_to_reinstall 
  
114 fi 
115 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8107 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
116 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high108 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
117 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium109 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
118 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false110 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
119 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict111 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
120 -·name:·'Set·fact:·Package·manager·reinstall·command'112 -·name:·'Set·fact:·Package·manager·reinstall·command'
121 ··set_fact:113 ··set_fact:
Offset 247, 14 lines modifiedOffset 234, 27 lines modified
247 ··-·PCI-DSSv4-11.5.2234 ··-·PCI-DSSv4-11.5.2
248 ··-·high_complexity235 ··-·high_complexity
249 ··-·high_severity236 ··-·high_severity
250 ··-·medium_disruption237 ··-·medium_disruption
251 ··-·no_reboot_needed238 ··-·no_reboot_needed
252 ··-·restrict_strategy239 ··-·restrict_strategy
253 ··-·rpm_verify_hashes240 ··-·rpm_verify_hashes
 241 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 242 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 243 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 244 if·[·-n·"$files_with_incorrect_hash"·];·then
 245 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 246 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 247 ····dnf·reinstall·-y·$packages_to_reinstall
  
 248 fi
254 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*249 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
255 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:250 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:
256 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'251 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'
257 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:252 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:
258 $·rpm·-qf·FILENAME253 $·rpm·-qf·FILENAME
  
259 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:254 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
Offset 275, 44 lines modifiedOffset 275, 14 lines modified
275 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5275 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
276 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2276 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
277 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)277 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)
278 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1278 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
279 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5279 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
280 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108280 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108
281 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2281 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
282 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
283 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
284 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
285 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
286 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
287 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
288 declare·-A·SETPERMS_RPM_DICT 
  
289 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
290 #·is·expected·by·the·RPM·database 
291 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}') 
  
292 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
293 do 
294 ········#·NOTE:·some·files·maybe·controlled·by·more·then·one·package 
295 ········readarray·-t·RPM_PACKAGES·<·<(rpm·-qf·"${FILE_PATH}") 
296 ········for·RPM_PACKAGE·in·"${RPM_PACKAGES[@]}" 
297 ········do 
298 ················#·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
299 ················SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
300 ········done 
301 done 
  
302 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
303 #·correct·values 
304 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
305 do 
306 »       rpm·--restore·"${RPM_PACKAGE}" 
307 done 
308 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8282 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
309 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high283 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
310 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium284 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
311 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false285 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
312 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict286 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
313 -·name:·Read·list·of·files·with·incorrect·permissions287 -·name:·Read·list·of·files·with·incorrect·permissions
314 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev288 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 390, 14 lines modifiedOffset 360, 44 lines modified
390 ··-·PCI-DSSv4-11.5.2360 ··-·PCI-DSSv4-11.5.2
391 ··-·high_complexity361 ··-·high_complexity
392 ··-·high_severity362 ··-·high_severity
393 ··-·medium_disruption363 ··-·medium_disruption
394 ··-·no_reboot_needed364 ··-·no_reboot_needed
395 ··-·restrict_strategy365 ··-·restrict_strategy
396 ··-·rpm_verify_permissions366 ··-·rpm_verify_permissions
 367 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 368 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 369 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
Max diff block lines reached; 1105311/1113418 bytes (99.27%) of diff not shown.
7.6 MB
./usr/share/doc/ssg-nondebian/ssg-fedora-guide-standard.html
    
Offset 14354, 16 lines modifiedOffset 14354, 16 lines modified
00038110:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><00038110:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><
00038120:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio00038120:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio
00038130:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.700038130:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.7
00038140:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u00038140:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u
00038150:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr00038150:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr
00038160:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···00038160:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···
00038170:·2020·2020·2020·2020·2020·2020·2020·2020··················00038170:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038180:·2028·6173·206f·6620·3230·3236·2d30·312d···(as·of·2026-01-00038180:·2028·6173·206f·6620·3230·3234·2d31·322d···(as·of·2024-12-
00038190:·3038·290a·2020·2020·2020·2020·2020·2020··08).············00038190:·3037·290a·2020·2020·2020·2020·2020·2020··07).············
000381a0:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></000381a0:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></
000381b0:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of000381b0:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of
000381c0:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o000381c0:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o
000381d0:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#000381d0:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#
000381e0:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro000381e0:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro
000381f0:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro000381f0:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro
00038200:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste00038200:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste
Offset 15168, 301 lines modifiedOffset 15168, 301 lines modified
0003b3f0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b3f0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003b400:·2223·6964·6d31·3836·3222·2074·6162·696e··"#idm1862"·tabin0003b400:·2223·6964·6d31·3836·3222·2074·6162·696e··"#idm1862"·tabin
0003b410:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b410:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b420:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b420:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b430:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b430:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b440:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b440:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b450:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b450:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b460:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
0003b470:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
0003b480:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b490:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b4a0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b4b0:·6d31·3836·3222·3e3c·7072·653e·3c63·6f64··m1862"><pre><cod 
0003b4c0:·653e·0a23·2046·696e·6420·7768·6963·6820··e>.#·Find·which· 
0003b4d0:·6669·6c65·7320·6861·7665·2069·6e63·6f72··files·have·incor 
0003b4e0:·7265·6374·2068·6173·6820·286e·6f74·2069··rect·hash·(not·i 
0003b4f0:·6e20·2f65·7463·2c20·6265·6361·7573·6520··n·/etc,·because· 
0003b500:·6f66·2074·6865·2073·7973·7465·6d20·7265··of·the·system·re 
0003b510:·6c61·7465·6420·636f·6e66·6967·2066·696c··lated·config·fil 
0003b520:·6573·2920·616e·6420·7468·656e·2067·6574··es)·and·then·get 
0003b530:·2066·696c·6573·206e·616d·6573·0a66·696c···files·names.fil 
0003b540:·6573·5f77·6974·685f·696e·636f·7272·6563··es_with_incorrec 
0003b550:·745f·6861·7368·3d22·2428·7270·6d20·2d56··t_hash="$(rpm·-V 
0003b560:·6120·2d2d·6e6f·636f·6e66·6967·207c·2067··a·--noconfig·|·g 
0003b570:·7265·7020·2d45·2027·5e2e·2e35·2720·7c20··rep·-E·'^..5'·|· 
0003b580:·6177·6b20·277b·7072·696e·7420·244e·467d··awk·'{print·$NF} 
0003b590:·2720·2922·0a0a·6966·205b·202d·6e20·2224··'·)"..if·[·-n·"$ 
0003b5a0:·6669·6c65·735f·7769·7468·5f69·6e63·6f72··files_with_incor 
0003b5b0:·7265·6374·5f68·6173·6822·205d·3b20·7468··rect_hash"·];·th 
0003b5c0:·656e·0a20·2020·2023·2046·726f·6d20·6669··en.····#·From·fi 
0003b5d0:·6c65·7320·6e61·6d65·7320·6765·7420·7061··les·names·get·pa 
0003b5e0:·636b·6167·6520·6e61·6d65·7320·616e·6420··ckage·names·and· 
0003b5f0:·6368·616e·6765·206e·6577·6c69·6e65·2074··change·newline·t 
0003b600:·6f20·7370·6163·652c·2062·6563·6175·7365··o·space,·because 
0003b610:·2072·706d·2077·7269·7465·7320·6561·6368···rpm·writes·each 
0003b620:·2070·6163·6b61·6765·2074·6f20·6e65·7720···package·to·new· 
0003b630:·6c69·6e65·0a20·2020·2070·6163·6b61·6765··line.····package 
0003b640:·735f·746f·5f72·6569·6e73·7461·6c6c·3d22··s_to_reinstall=" 
0003b650:·2428·7270·6d20·2d71·6620·2466·696c·6573··$(rpm·-qf·$files 
0003b660:·5f77·6974·685f·696e·636f·7272·6563·745f··_with_incorrect_ 
0003b670:·6861·7368·207c·2074·7220·275c·6e27·2027··hash·|·tr·'\n'·' 
0003b680:·2027·2922·0a0a·2020·2020·0a20·2020·2064···')"..····.····d 
0003b690:·6e66·2072·6569·6e73·7461·6c6c·202d·7920··nf·reinstall·-y· 
0003b6a0:·2470·6163·6b61·6765·735f·746f·5f72·6569··$packages_to_rei 
0003b6b0:·6e73·7461·6c6c·0a20·2020·200a·6669·0a3c··nstall.····.fi.< 
0003b6c0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003b6d0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003b6e0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003b6f0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003b700:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003b710:·2223·6964·6d31·3836·3322·2074·6162·696e··"#idm1863"·tabin 
0003b720:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003b730:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003b740:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003b750:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003b760:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003b770:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans0003b460:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans
0003b780:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...0003b470:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...
0003b790:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003b480:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003b7a0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003b490:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003b7b0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003b4a0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003b7c0:·2269·646d·3138·3633·223e·3c74·6162·6c65··"idm1863"><table0003b4b0:·2269·646d·3138·3632·223e·3c74·6162·6c65··"idm1862"><table
0003b7d0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003b4c0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003b7e0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003b4d0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003b7f0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003b4e0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003b800:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003b4f0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003b810:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003b500:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003b820:·2f74·683e·3c74·643e·6869·6768·3c2f·7464··/th><td>high</td0003b510:·2f74·683e·3c74·643e·6869·6768·3c2f·7464··/th><td>high</td
0003b830:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003b520:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003b840:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003b530:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003b850:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t0003b540:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t
0003b860:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot0003b550:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
0003b870:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<0003b560:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003b880:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b570:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b890:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003b580:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003b8a0:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>0003b590:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>
0003b8b0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003b5a0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
0003b8c0:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·0003b5b0:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·
0003b8d0:·2753·6574·2066·6163·743a·2050·6163·6b61··'Set·fact:·Packa0003b5c0:·2753·6574·2066·6163·743a·2050·6163·6b61··'Set·fact:·Packa
0003b8e0:·6765·206d·616e·6167·6572·2072·6569·6e73··ge·manager·reins0003b5d0:·6765·206d·616e·6167·6572·2072·6569·6e73··ge·manager·reins
0003b8f0:·7461·6c6c·2063·6f6d·6d61·6e64·270a·2020··tall·command'.··0003b5e0:·7461·6c6c·2063·6f6d·6d61·6e64·270a·2020··tall·command'.··
0003b900:·7365·745f·6661·6374·3a0a·2020·2020·7061··set_fact:.····pa0003b5f0:·7365·745f·6661·6374·3a0a·2020·2020·7061··set_fact:.····pa
0003b910:·636b·6167·655f·6d61·6e61·6765·725f·7265··ckage_manager_re0003b600:·636b·6167·655f·6d61·6e61·6765·725f·7265··ckage_manager_re
0003b920:·696e·7374·616c·6c5f·636d·643a·2064·6e66··install_cmd:·dnf0003b610:·696e·7374·616c·6c5f·636d·643a·2064·6e66··install_cmd:·dnf
0003b930:·2072·6569·6e73·7461·6c6c·202d·790a·2020···reinstall·-y.··0003b620:·2072·6569·6e73·7461·6c6c·202d·790a·2020···reinstall·-y.··
0003b940:·7768·656e·3a20·616e·7369·626c·655f·6469··when:·ansible_di0003b630:·7768·656e·3a20·616e·7369·626c·655f·6469··when:·ansible_di
0003b950:·7374·7269·6275·7469·6f6e·2069·6e20·5b20··stribution·in·[·0003b640:·7374·7269·6275·7469·6f6e·2069·6e20·5b20··stribution·in·[·
0003b960:·2246·6564·6f72·6122·2c20·2252·6564·4861··"Fedora",·"RedHa0003b650:·2246·6564·6f72·6122·2c20·2252·6564·4861··"Fedora",·"RedHa
0003b970:·7422·2c20·2243·656e·744f·5322·2c20·224f··t",·"CentOS",·"O0003b660:·7422·2c20·2243·656e·744f·5322·2c20·224f··t",·"CentOS",·"O
0003b980:·7261·636c·654c·696e·7578·2220·5d0a·2020··racleLinux"·].··0003b670:·7261·636c·654c·696e·7578·2220·5d0a·2020··racleLinux"·].··
0003b990:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-50003b680:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-5
0003b9a0:·2e31·302e·342e·310a·2020·2d20·4e49·5354··.10.4.1.··-·NIST0003b690:·2e31·302e·342e·310a·2020·2d20·4e49·5354··.10.4.1.··-·NIST
0003b9b0:·2d38·3030·2d31·3731·2d33·2e33·2e38·0a20··-800-171-3.3.8.·0003b6a0:·2d38·3030·2d31·3731·2d33·2e33·2e38·0a20··-800-171-3.3.8.·
0003b9c0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-0003b6b0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
0003b9d0:·332e·342e·310a·2020·2d20·4e49·5354·2d38··3.4.1.··-·NIST-80003b6c0:·332e·342e·310a·2020·2d20·4e49·5354·2d38··3.4.1.··-·NIST-8
0003b9e0:·3030·2d35·332d·4155·2d39·2833·290a·2020··00-53-AU-9(3).··0003b6d0:·3030·2d35·332d·4155·2d39·2833·290a·2020··00-53-AU-9(3).··
0003b9f0:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM0003b6e0:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
0003ba00:·2d36·2863·290a·2020·2d20·4e49·5354·2d38··-6(c).··-·NIST-80003b6f0:·2d36·2863·290a·2020·2d20·4e49·5354·2d38··-6(c).··-·NIST-8
0003ba10:·3030·2d35·332d·434d·2d36·2864·290a·2020··00-53-CM-6(d).··0003b700:·3030·2d35·332d·434d·2d36·2864·290a·2020··00-53-CM-6(d).··
0003ba20:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI0003b710:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI
0003ba30:·2d37·0a20·202d·204e·4953·542d·3830·302d··-7.··-·NIST-800-0003b720:·2d37·0a20·202d·204e·4953·542d·3830·302d··-7.··-·NIST-800-
0003ba40:·3533·2d53·492d·3728·3129·0a20·202d·204e··53-SI-7(1).··-·N0003b730:·3533·2d53·492d·3728·3129·0a20·202d·204e··53-SI-7(1).··-·N
0003ba50:·4953·542d·3830·302d·3533·2d53·492d·3728··IST-800-53-SI-7(0003b740:·4953·542d·3830·302d·3533·2d53·492d·3728··IST-800-53-SI-7(
0003ba60:·3629·0a20·202d·2050·4349·2d44·5353·2d52··6).··-·PCI-DSS-R0003b750:·3629·0a20·202d·2050·4349·2d44·5353·2d52··6).··-·PCI-DSS-R
0003ba70:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI-0003b760:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI-
0003ba80:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··-0003b770:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··-
0003ba90:·2068·6967·685f·636f·6d70·6c65·7869·7479···high_complexity0003b780:·2068·6967·685f·636f·6d70·6c65·7869·7479···high_complexity
0003baa0:·0a20·202d·2068·6967·685f·7365·7665·7269··.··-·high_severi0003b790:·0a20·202d·2068·6967·685f·7365·7665·7269··.··-·high_severi
0003bab0:·7479·0a20·202d·206d·6564·6975·6d5f·6469··ty.··-·medium_di0003b7a0:·7479·0a20·202d·206d·6564·6975·6d5f·6469··ty.··-·medium_di
0003bac0:·7372·7570·7469·6f6e·0a20·202d·206e·6f5f··sruption.··-·no_0003b7b0:·7372·7570·7469·6f6e·0a20·202d·206e·6f5f··sruption.··-·no_
Max diff block lines reached; 7253277/7278999 bytes (99.65%) of diff not shown.
674 KB
html2text {}
    
Offset 43, 15 lines modifiedOffset 43, 15 lines modified
43 ····*·cpe:/o:fedoraproject:fedora:4143 ····*·cpe:/o:fedoraproject:fedora:41
44 ····*·cpe:/o:fedoraproject:fedora:4244 ····*·cpe:/o:fedoraproject:fedora:42
45 ····*·cpe:/o:fedoraproject:fedora:4345 ····*·cpe:/o:fedoraproject:fedora:43
46 ····*·cpe:/o:fedoraproject:fedora:4446 ····*·cpe:/o:fedoraproject:fedora:44
47 ····*·cpe:/o:fedoraproject:fedora:4547 ····*·cpe:/o:fedoraproject:fedora:45
48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
49 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8449 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
55 ·········3.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s55 ·········3.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
56 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s56 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
57 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s57 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
Offset 99, 27 lines modifiedOffset 99, 14 lines modified
99 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.699 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
100 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4100 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
101 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)101 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
102 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1102 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
103 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5103 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
104 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227104 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
105 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2105 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
106 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
107 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
108 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
109 if·[·-n·"$files_with_incorrect_hash"·];·then 
110 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
111 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
112 ····dnf·reinstall·-y·$packages_to_reinstall 
  
113 fi 
114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8106 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
115 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high107 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
116 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium108 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
117 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false109 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
118 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict110 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
119 -·name:·'Set·fact:·Package·manager·reinstall·command'111 -·name:·'Set·fact:·Package·manager·reinstall·command'
120 ··set_fact:112 ··set_fact:
Offset 246, 14 lines modifiedOffset 233, 27 lines modified
246 ··-·PCI-DSSv4-11.5.2233 ··-·PCI-DSSv4-11.5.2
247 ··-·high_complexity234 ··-·high_complexity
248 ··-·high_severity235 ··-·high_severity
249 ··-·medium_disruption236 ··-·medium_disruption
250 ··-·no_reboot_needed237 ··-·no_reboot_needed
251 ··-·restrict_strategy238 ··-·restrict_strategy
252 ··-·rpm_verify_hashes239 ··-·rpm_verify_hashes
 240 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 241 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 242 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 243 if·[·-n·"$files_with_incorrect_hash"·];·then
 244 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 245 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 246 ····dnf·reinstall·-y·$packages_to_reinstall
  
 247 fi
253 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*248 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
254 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:249 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:
255 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'250 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'
256 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:251 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:
257 $·rpm·-qf·FILENAME252 $·rpm·-qf·FILENAME
  
258 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:253 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
Offset 274, 44 lines modifiedOffset 274, 14 lines modified
274 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5274 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
275 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2275 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
276 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)276 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)
277 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1277 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
278 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5278 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
279 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108279 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108
280 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2280 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
281 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
282 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
283 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
284 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
285 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
286 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
287 declare·-A·SETPERMS_RPM_DICT 
  
288 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
289 #·is·expected·by·the·RPM·database 
290 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}') 
  
291 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
292 do 
293 ········#·NOTE:·some·files·maybe·controlled·by·more·then·one·package 
294 ········readarray·-t·RPM_PACKAGES·<·<(rpm·-qf·"${FILE_PATH}") 
295 ········for·RPM_PACKAGE·in·"${RPM_PACKAGES[@]}" 
296 ········do 
297 ················#·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
298 ················SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
299 ········done 
300 done 
  
301 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
302 #·correct·values 
303 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
304 do 
305 »       rpm·--restore·"${RPM_PACKAGE}" 
306 done 
307 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8281 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
308 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high282 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
309 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium283 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
310 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false284 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
311 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict285 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
312 -·name:·Read·list·of·files·with·incorrect·permissions286 -·name:·Read·list·of·files·with·incorrect·permissions
313 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev287 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 389, 14 lines modifiedOffset 359, 44 lines modified
389 ··-·PCI-DSSv4-11.5.2359 ··-·PCI-DSSv4-11.5.2
390 ··-·high_complexity360 ··-·high_complexity
391 ··-·high_severity361 ··-·high_severity
392 ··-·medium_disruption362 ··-·medium_disruption
393 ··-·no_reboot_needed363 ··-·no_reboot_needed
394 ··-·restrict_strategy364 ··-·restrict_strategy
395 ··-·rpm_verify_permissions365 ··-·rpm_verify_permissions
 366 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 367 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 368 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
Max diff block lines reached; 681870/689932 bytes (98.83%) of diff not shown.
2.35 KB
./usr/share/doc/ssg-nondebian/ssg-macos1015-guide-moderate.html
    
Offset 14332, 16 lines modifiedOffset 14332, 16 lines modified
00037fb0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00037fb0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00037fc0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00037fc0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00037fd0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000037fd0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00037fe0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></00037fe0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
00037ff0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00037ff0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00038000:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00038000:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00038010:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00038010:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00038020:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600038020:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
00038030:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········00038030:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00038040:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00038040:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00038050:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00038050:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00038060:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00038060:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00038070:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00038070:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00038080:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00038080:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00038090:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00038090:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
000380a0:·5f67·726f·7570·5f61·7564·6974·696e·6722··_group_auditing"000380a0:·5f67·726f·7570·5f61·7564·6974·696e·6722··_group_auditing"
1010 B
html2text {}
    
Offset 53, 15 lines modifiedOffset 53, 15 lines modified
53 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·NIST·800-53·Moderate-Impact·Baseline·for·Apple·macOS·10.1553 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·NIST·800-53·Moderate-Impact·Baseline·for·Apple·macOS·10.15
54 ··············Catalina54 ··············Catalina
55 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_moderate55 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_moderate
56 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*56 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
57 ····*·cpe:/o:apple:macos:10.1557 ····*·cpe:/o:apple:macos:10.15
58 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*58 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
59 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8459 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
60 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)60 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
61 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*61 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
62 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8i_\x8n_\x8g_\x8·_\x8w_\x8i_\x8t_\x8h_\x8·_\x8a_\x8u_\x8d_\x8i_\x8t62 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8i_\x8n_\x8g_\x8·_\x8w_\x8i_\x8t_\x8h_\x8·_\x8a_\x8u_\x8d_\x8i_\x8t
63 ·········1.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8a_\x8u_\x8d_\x8i_\x8t_\x8d63 ·········1.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8a_\x8u_\x8d_\x8i_\x8t_\x8d
64 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*64 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*
65 Group  ·Guide·to·the·Secure·Configuration·of·Apple·macOS·10.15·  Group·contains65 Group  ·Guide·to·the·Secure·Configuration·of·Apple·macOS·10.15·  Group·contains
66 2·groups·and·2·rules66 2·groups·and·2·rules
67 Group  ·System·Accounting·with·audit·  Group·contains·1·group·and·2·rules67 Group  ·System·Accounting·with·audit·  Group·contains·1·group·and·2·rules
2.58 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-bsi-2022.html
    
Offset 14601, 16 lines modifiedOffset 14601, 16 lines modified
00039080:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><00039080:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><
00039090:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio00039090:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio
000390a0:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.7000390a0:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.7
000390b0:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u000390b0:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u
000390c0:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr000390c0:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr
000390d0:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···000390d0:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···
000390e0:·2020·2020·2020·2020·2020·2020·2020·2020··················000390e0:·2020·2020·2020·2020·2020·2020·2020·2020··················
000390f0:·2028·6173·206f·6620·3230·3236·2d30·312d···(as·of·2026-01-000390f0:·2028·6173·206f·6620·3230·3234·2d31·322d···(as·of·2024-12-
00039100:·3038·290a·2020·2020·2020·2020·2020·2020··08).············00039100:·3037·290a·2020·2020·2020·2020·2020·2020··07).············
00039110:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></00039110:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></
00039120:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of00039120:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of
00039130:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o00039130:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o
00039140:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#00039140:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#
00039150:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro00039150:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro
00039160:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro00039160:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro
00039170:·7570·5f6f·7065·6e73·6869·6674·223e·4b75··up_openshift">Ku00039170:·7570·5f6f·7065·6e73·6869·6674·223e·4b75··up_openshift">Ku
1.22 KB
html2text {}
    
Offset 64, 15 lines modifiedOffset 64, 15 lines modified
64 ····*·cpe:/a:redhat:openshift_container_platform:4.664 ····*·cpe:/a:redhat:openshift_container_platform:4.6
65 ····*·cpe:/a:redhat:openshift_container_platform:4.765 ····*·cpe:/a:redhat:openshift_container_platform:4.7
66 ····*·cpe:/a:redhat:openshift_container_platform:4.866 ····*·cpe:/a:redhat:openshift_container_platform:4.8
67 ····*·cpe:/a:redhat:openshift_container_platform:4.967 ····*·cpe:/a:redhat:openshift_container_platform:4.9
68 ····*·cpe:/a:redhat:openshift_container_platform:4.168 ····*·cpe:/a:redhat:openshift_container_platform:4.1
69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
70 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8470 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
73 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s73 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
74 ·········1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l74 ·········1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
75 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r75 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r
76 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s76 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
77 ·········4.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8G_\x8e_\x8n_\x8e_\x8r_\x8a_\x8l_\x8·_\x8S_\x8e_\x8c_\x8u_\x8r_\x8i_\x8t_\x8y_\x8·_\x8P_\x8r_\x8a_\x8c_\x8t_\x8i_\x8c_\x8e_\x8s77 ·········4.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8G_\x8e_\x8n_\x8e_\x8r_\x8a_\x8l_\x8·_\x8S_\x8e_\x8c_\x8u_\x8r_\x8i_\x8t_\x8y_\x8·_\x8P_\x8r_\x8a_\x8c_\x8t_\x8i_\x8c_\x8e_\x8s
78 ·········5.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s78 ·········5.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
2.21 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-bsi-node-2022.html
    
Offset 14602, 15 lines modifiedOffset 14602, 15 lines modified
00039090:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v00039090:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v
000390a0:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>000390a0:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>
000390b0:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><000390b0:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><
000390c0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro000390c0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro
000390d0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong000390d0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong
000390e0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············000390e0:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············
000390f0:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202000390f0:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202
00039100:·362d·3031·2d30·3829·0a20·2020·2020·2020··6-01-08).·······00039100:·342d·3132·2d30·3729·0a20·2020·2020·2020··4-12-07).·······
00039110:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></00039110:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></
00039120:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab00039120:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab
00039130:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</00039130:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</
00039140:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr00039140:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr
00039150:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s00039150:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s
00039160:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten00039160:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten
00039170:·745f·6772·6f75·705f·6f70·656e·7368·6966··t_group_openshif00039170:·745f·6772·6f75·705f·6f70·656e·7368·6966··t_group_openshif
1000 B
html2text {}
    
Offset 64, 15 lines modifiedOffset 64, 15 lines modified
64 ····*·cpe:/a:redhat:openshift_container_platform:4.664 ····*·cpe:/a:redhat:openshift_container_platform:4.6
65 ····*·cpe:/a:redhat:openshift_container_platform:4.765 ····*·cpe:/a:redhat:openshift_container_platform:4.7
66 ····*·cpe:/a:redhat:openshift_container_platform:4.866 ····*·cpe:/a:redhat:openshift_container_platform:4.8
67 ····*·cpe:/a:redhat:openshift_container_platform:4.967 ····*·cpe:/a:redhat:openshift_container_platform:4.9
68 ····*·cpe:/a:redhat:openshift_container_platform:4.168 ····*·cpe:/a:redhat:openshift_container_platform:4.1
69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
70 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8470 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
73 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s73 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
74 ·········1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s74 ·········1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
75 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*75 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*
76 Group  ·Guide·to·the·Secure·Configuration·of·Red·Hat·OpenShift·Container76 Group  ·Guide·to·the·Secure·Configuration·of·Red·Hat·OpenShift·Container
77 Platform·4·  Group·contains·2·groups·and·1·rule77 Platform·4·  Group·contains·2·groups·and·1·rule
78 Group  ·Kubernetes·Settings·  Group·contains·1·group·and·1·rule78 Group  ·Kubernetes·Settings·  Group·contains·1·group·and·1·rule
2.33 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-bsi-node.html
    
Offset 14601, 16 lines modifiedOffset 14601, 16 lines modified
00039080:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><00039080:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><
00039090:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio00039090:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio
000390a0:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.7000390a0:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.7
000390b0:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u000390b0:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u
000390c0:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr000390c0:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr
000390d0:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···000390d0:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···
000390e0:·2020·2020·2020·2020·2020·2020·2020·2020··················000390e0:·2020·2020·2020·2020·2020·2020·2020·2020··················
000390f0:·2028·6173·206f·6620·3230·3236·2d30·312d···(as·of·2026-01-000390f0:·2028·6173·206f·6620·3230·3234·2d31·322d···(as·of·2024-12-
00039100:·3038·290a·2020·2020·2020·2020·2020·2020··08).············00039100:·3037·290a·2020·2020·2020·2020·2020·2020··07).············
00039110:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></00039110:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></
00039120:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of00039120:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of
00039130:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o00039130:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o
00039140:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#00039140:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#
00039150:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro00039150:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro
00039160:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro00039160:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro
00039170:·7570·5f6f·7065·6e73·6869·6674·223e·4b75··up_openshift">Ku00039170:·7570·5f6f·7065·6e73·6869·6674·223e·4b75··up_openshift">Ku
1000 B
html2text {}
    
Offset 64, 15 lines modifiedOffset 64, 15 lines modified
64 ····*·cpe:/a:redhat:openshift_container_platform:4.664 ····*·cpe:/a:redhat:openshift_container_platform:4.6
65 ····*·cpe:/a:redhat:openshift_container_platform:4.765 ····*·cpe:/a:redhat:openshift_container_platform:4.7
66 ····*·cpe:/a:redhat:openshift_container_platform:4.866 ····*·cpe:/a:redhat:openshift_container_platform:4.8
67 ····*·cpe:/a:redhat:openshift_container_platform:4.967 ····*·cpe:/a:redhat:openshift_container_platform:4.9
68 ····*·cpe:/a:redhat:openshift_container_platform:4.168 ····*·cpe:/a:redhat:openshift_container_platform:4.1
69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
70 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8470 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
73 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s73 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
74 ·········1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s74 ·········1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
75 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*75 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*
76 Group  ·Guide·to·the·Secure·Configuration·of·Red·Hat·OpenShift·Container76 Group  ·Guide·to·the·Secure·Configuration·of·Red·Hat·OpenShift·Container
77 Platform·4·  Group·contains·2·groups·and·1·rule77 Platform·4·  Group·contains·2·groups·and·1·rule
78 Group  ·Kubernetes·Settings·  Group·contains·1·group·and·1·rule78 Group  ·Kubernetes·Settings·  Group·contains·1·group·and·1·rule
2.43 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-bsi.html
    
Offset 14601, 15 lines modifiedOffset 14601, 15 lines modified
00039080:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur00039080:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur
00039090:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s00039090:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s
000390a0:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st000390a0:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st
000390b0:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li000390b0:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li
000390c0:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</000390c0:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</
000390d0:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········000390d0:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········
000390e0:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·000390e0:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·
000390f0:·6f66·2032·3032·362d·3031·2d30·3829·0a20··of·2026-01-08).·000390f0:·6f66·2032·3032·342d·3132·2d30·3729·0a20··of·2024-12-07).·
00039100:·2020·2020·2020·2020·2020·2020·2020·203c·················<00039100:·2020·2020·2020·2020·2020·2020·2020·203c·················<
00039110:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><00039110:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><
00039120:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont00039120:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont
00039130:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li00039130:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li
00039140:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf00039140:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf
00039150:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.00039150:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.
00039160:·636f·6e74·656e·745f·6772·6f75·705f·6f70··content_group_op00039160:·636f·6e74·656e·745f·6772·6f75·705f·6f70··content_group_op
1.22 KB
html2text {}
    
Offset 64, 15 lines modifiedOffset 64, 15 lines modified
64 ····*·cpe:/a:redhat:openshift_container_platform:4.664 ····*·cpe:/a:redhat:openshift_container_platform:4.6
65 ····*·cpe:/a:redhat:openshift_container_platform:4.765 ····*·cpe:/a:redhat:openshift_container_platform:4.7
66 ····*·cpe:/a:redhat:openshift_container_platform:4.866 ····*·cpe:/a:redhat:openshift_container_platform:4.8
67 ····*·cpe:/a:redhat:openshift_container_platform:4.967 ····*·cpe:/a:redhat:openshift_container_platform:4.9
68 ····*·cpe:/a:redhat:openshift_container_platform:4.168 ····*·cpe:/a:redhat:openshift_container_platform:4.1
69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
70 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8470 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
73 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s73 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
74 ·········1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l74 ·········1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
75 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r75 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r
76 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s76 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
77 ·········4.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8G_\x8e_\x8n_\x8e_\x8r_\x8a_\x8l_\x8·_\x8S_\x8e_\x8c_\x8u_\x8r_\x8i_\x8t_\x8y_\x8·_\x8P_\x8r_\x8a_\x8c_\x8t_\x8i_\x8c_\x8e_\x8s77 ·········4.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8G_\x8e_\x8n_\x8e_\x8r_\x8a_\x8l_\x8·_\x8S_\x8e_\x8c_\x8u_\x8r_\x8i_\x8t_\x8y_\x8·_\x8P_\x8r_\x8a_\x8c_\x8t_\x8i_\x8c_\x8e_\x8s
78 ·········5.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s78 ·········5.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
2.31 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-cis-1-4.html
    
Offset 14609, 15 lines modifiedOffset 14609, 15 lines modified
00039100:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00039100:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00039110:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00039110:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00039120:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<00039120:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<
00039130:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00039130:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00039140:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00039140:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00039150:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00039150:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00039160:·2020·2020·2020·2020·2020·2020·2020·2028·················(00039160:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00039170:·6173·206f·6620·3230·3236·2d30·312d·3038··as·of·2026-01-0800039170:·6173·206f·6620·3230·3234·2d31·322d·3037··as·of·2024-12-07
00039180:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00039180:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00039190:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00039190:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
000391a0:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C000391a0:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
000391b0:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>000391b0:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
000391c0:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc000391c0:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
000391d0:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje000391d0:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
000391e0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group000391e0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
1.09 KB
html2text {}
    
Offset 64, 15 lines modifiedOffset 64, 15 lines modified
64 ····*·cpe:/a:redhat:openshift_container_platform:4.664 ····*·cpe:/a:redhat:openshift_container_platform:4.6
65 ····*·cpe:/a:redhat:openshift_container_platform:4.765 ····*·cpe:/a:redhat:openshift_container_platform:4.7
66 ····*·cpe:/a:redhat:openshift_container_platform:4.866 ····*·cpe:/a:redhat:openshift_container_platform:4.8
67 ····*·cpe:/a:redhat:openshift_container_platform:4.967 ····*·cpe:/a:redhat:openshift_container_platform:4.9
68 ····*·cpe:/a:redhat:openshift_container_platform:4.168 ····*·cpe:/a:redhat:openshift_container_platform:4.1
69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
70 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8470 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
73 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s73 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
74 ·········1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l74 ·········1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
75 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r75 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r
76 ·········3.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n76 ·········3.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n
77 ·········4.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s77 ·········4.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
78 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s78 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
2.31 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-cis-1-5.html
    
Offset 14609, 15 lines modifiedOffset 14609, 15 lines modified
00039100:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00039100:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00039110:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00039110:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00039120:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<00039120:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<
00039130:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00039130:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00039140:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00039140:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00039150:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00039150:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00039160:·2020·2020·2020·2020·2020·2020·2020·2028·················(00039160:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00039170:·6173·206f·6620·3230·3236·2d30·312d·3038··as·of·2026-01-0800039170:·6173·206f·6620·3230·3234·2d31·322d·3037··as·of·2024-12-07
00039180:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00039180:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00039190:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00039190:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
000391a0:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C000391a0:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
000391b0:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>000391b0:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
000391c0:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc000391c0:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
000391d0:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje000391d0:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
000391e0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group000391e0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
1.09 KB
html2text {}
    
Offset 64, 15 lines modifiedOffset 64, 15 lines modified
64 ····*·cpe:/a:redhat:openshift_container_platform:4.664 ····*·cpe:/a:redhat:openshift_container_platform:4.6
65 ····*·cpe:/a:redhat:openshift_container_platform:4.765 ····*·cpe:/a:redhat:openshift_container_platform:4.7
66 ····*·cpe:/a:redhat:openshift_container_platform:4.866 ····*·cpe:/a:redhat:openshift_container_platform:4.8
67 ····*·cpe:/a:redhat:openshift_container_platform:4.967 ····*·cpe:/a:redhat:openshift_container_platform:4.9
68 ····*·cpe:/a:redhat:openshift_container_platform:4.168 ····*·cpe:/a:redhat:openshift_container_platform:4.1
69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
70 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8470 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
73 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s73 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
74 ·········1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l74 ·········1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
75 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r75 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r
76 ·········3.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n76 ·········3.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n
77 ·········4.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s77 ·········4.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
78 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s78 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
2.32 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-cis-node-1-4.html
    
Offset 14610, 15 lines modifiedOffset 14610, 15 lines modified
00039110:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur00039110:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur
00039120:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s00039120:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s
00039130:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st00039130:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st
00039140:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li00039140:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li
00039150:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</00039150:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</
00039160:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········00039160:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········
00039170:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·00039170:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·
00039180:·6f66·2032·3032·362d·3031·2d30·3829·0a20··of·2026-01-08).·00039180:·6f66·2032·3032·342d·3132·2d30·3729·0a20··of·2024-12-07).·
00039190:·2020·2020·2020·2020·2020·2020·2020·203c·················<00039190:·2020·2020·2020·2020·2020·2020·2020·203c·················<
000391a0:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><000391a0:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><
000391b0:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont000391b0:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont
000391c0:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li000391c0:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li
000391d0:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf000391d0:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf
000391e0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.000391e0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.
000391f0:·636f·6e74·656e·745f·6772·6f75·705f·6f70··content_group_op000391f0:·636f·6e74·656e·745f·6772·6f75·705f·6f70··content_group_op
1.1 KB
html2text {}
    
Offset 64, 15 lines modifiedOffset 64, 15 lines modified
64 ····*·cpe:/a:redhat:openshift_container_platform:4.664 ····*·cpe:/a:redhat:openshift_container_platform:4.6
65 ····*·cpe:/a:redhat:openshift_container_platform:4.765 ····*·cpe:/a:redhat:openshift_container_platform:4.7
66 ····*·cpe:/a:redhat:openshift_container_platform:4.866 ····*·cpe:/a:redhat:openshift_container_platform:4.8
67 ····*·cpe:/a:redhat:openshift_container_platform:4.967 ····*·cpe:/a:redhat:openshift_container_platform:4.9
68 ····*·cpe:/a:redhat:openshift_container_platform:4.168 ····*·cpe:/a:redhat:openshift_container_platform:4.1
69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
70 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8470 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
73 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s73 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
74 ·········1.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s74 ·········1.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
75 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s75 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
76 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s76 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
77 ·········4.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8W_\x8o_\x8r_\x8k_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s77 ·········4.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8W_\x8o_\x8r_\x8k_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
78 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*78 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*
2.32 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-cis-node-1-5.html
    
Offset 14610, 15 lines modifiedOffset 14610, 15 lines modified
00039110:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur00039110:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur
00039120:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s00039120:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s
00039130:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st00039130:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st
00039140:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li00039140:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li
00039150:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</00039150:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</
00039160:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········00039160:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········
00039170:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·00039170:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·
00039180:·6f66·2032·3032·362d·3031·2d30·3829·0a20··of·2026-01-08).·00039180:·6f66·2032·3032·342d·3132·2d30·3729·0a20··of·2024-12-07).·
00039190:·2020·2020·2020·2020·2020·2020·2020·203c·················<00039190:·2020·2020·2020·2020·2020·2020·2020·203c·················<
000391a0:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><000391a0:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><
000391b0:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont000391b0:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont
000391c0:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li000391c0:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li
000391d0:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf000391d0:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf
000391e0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.000391e0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.
000391f0:·636f·6e74·656e·745f·6772·6f75·705f·6f70··content_group_op000391f0:·636f·6e74·656e·745f·6772·6f75·705f·6f70··content_group_op
1.1 KB
html2text {}
    
Offset 64, 15 lines modifiedOffset 64, 15 lines modified
64 ····*·cpe:/a:redhat:openshift_container_platform:4.664 ····*·cpe:/a:redhat:openshift_container_platform:4.6
65 ····*·cpe:/a:redhat:openshift_container_platform:4.765 ····*·cpe:/a:redhat:openshift_container_platform:4.7
66 ····*·cpe:/a:redhat:openshift_container_platform:4.866 ····*·cpe:/a:redhat:openshift_container_platform:4.8
67 ····*·cpe:/a:redhat:openshift_container_platform:4.967 ····*·cpe:/a:redhat:openshift_container_platform:4.9
68 ····*·cpe:/a:redhat:openshift_container_platform:4.168 ····*·cpe:/a:redhat:openshift_container_platform:4.1
69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
70 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8470 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
73 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s73 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
74 ·········1.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s74 ·········1.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
75 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s75 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
76 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s76 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
77 ·········4.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8W_\x8o_\x8r_\x8k_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s77 ·········4.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8W_\x8o_\x8r_\x8k_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
78 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*78 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*
2.31 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-cis-node.html
    
Offset 14610, 15 lines modifiedOffset 14610, 15 lines modified
00039110:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current00039110:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current
00039120:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron00039120:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron
00039130:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong00039130:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong
00039140:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st00039140:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st
00039150:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro00039150:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro
00039160:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············00039160:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············
00039170:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·200039170:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·2
00039180:·3032·362d·3031·2d30·3829·0a20·2020·2020··026-01-08).·····00039180:·3032·342d·3132·2d30·3729·0a20·2020·2020··024-12-07).·····
00039190:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>00039190:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>
000391a0:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T000391a0:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T
000391b0:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents000391b0:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents
000391c0:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·000391c0:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·
000391d0:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org000391d0:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org
000391e0:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont000391e0:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont
000391f0:·656e·745f·6772·6f75·705f·6f70·656e·7368··ent_group_opensh000391f0:·656e·745f·6772·6f75·705f·6f70·656e·7368··ent_group_opensh
1.1 KB
html2text {}
    
Offset 64, 15 lines modifiedOffset 64, 15 lines modified
64 ····*·cpe:/a:redhat:openshift_container_platform:4.664 ····*·cpe:/a:redhat:openshift_container_platform:4.6
65 ····*·cpe:/a:redhat:openshift_container_platform:4.765 ····*·cpe:/a:redhat:openshift_container_platform:4.7
66 ····*·cpe:/a:redhat:openshift_container_platform:4.866 ····*·cpe:/a:redhat:openshift_container_platform:4.8
67 ····*·cpe:/a:redhat:openshift_container_platform:4.967 ····*·cpe:/a:redhat:openshift_container_platform:4.9
68 ····*·cpe:/a:redhat:openshift_container_platform:4.168 ····*·cpe:/a:redhat:openshift_container_platform:4.1
69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
70 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8470 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
73 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s73 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
74 ·········1.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s74 ·········1.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
75 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s75 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
76 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s76 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
77 ·········4.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8W_\x8o_\x8r_\x8k_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s77 ·········4.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8W_\x8o_\x8r_\x8k_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
78 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*78 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*
2.3 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-cis.html
    
Offset 14609, 15 lines modifiedOffset 14609, 15 lines modified
00039100:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr00039100:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr
00039110:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st00039110:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st
00039120:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str00039120:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str
00039130:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>00039130:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>
00039140:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s00039140:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s
00039150:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········00039150:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········
00039160:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o00039160:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o
00039170:·6620·3230·3236·2d30·312d·3038·290a·2020··f·2026-01-08).··00039170:·6620·3230·3234·2d31·322d·3037·290a·2020··f·2024-12-07).··
00039180:·2020·2020·2020·2020·2020·2020·2020·3c2f················</00039180:·2020·2020·2020·2020·2020·2020·2020·3c2f················</
00039190:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h00039190:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h
000391a0:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte000391a0:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte
000391b0:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>000391b0:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>
000391c0:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_000391c0:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_
000391d0:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c000391d0:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c
000391e0:·6f6e·7465·6e74·5f67·726f·7570·5f6f·7065··ontent_group_ope000391e0:·6f6e·7465·6e74·5f67·726f·7570·5f6f·7065··ontent_group_ope
1.09 KB
html2text {}
    
Offset 64, 15 lines modifiedOffset 64, 15 lines modified
64 ····*·cpe:/a:redhat:openshift_container_platform:4.664 ····*·cpe:/a:redhat:openshift_container_platform:4.6
65 ····*·cpe:/a:redhat:openshift_container_platform:4.765 ····*·cpe:/a:redhat:openshift_container_platform:4.7
66 ····*·cpe:/a:redhat:openshift_container_platform:4.866 ····*·cpe:/a:redhat:openshift_container_platform:4.8
67 ····*·cpe:/a:redhat:openshift_container_platform:4.967 ····*·cpe:/a:redhat:openshift_container_platform:4.9
68 ····*·cpe:/a:redhat:openshift_container_platform:4.168 ····*·cpe:/a:redhat:openshift_container_platform:4.1
69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*69 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
70 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8470 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)71 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*72 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
73 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s73 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
74 ·········1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l74 ·········1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
75 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r75 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r
76 ·········3.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n76 ·········3.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n
77 ·········4.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s77 ·········4.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
78 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s78 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
2.34 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-e8.html
    
Offset 14603, 15 lines modifiedOffset 14603, 15 lines modified
000390a0:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren000390a0:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren
000390b0:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro000390b0:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro
000390c0:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron000390c0:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron
000390d0:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s000390d0:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s
000390e0:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str000390e0:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str
000390f0:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········000390f0:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········
00039100:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·00039100:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·
00039110:·3230·3236·2d30·312d·3038·290a·2020·2020··2026-01-08).····00039110:·3230·3234·2d31·322d·3037·290a·2020·2020··2024-12-07).····
00039120:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li00039120:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li
00039130:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>00039130:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>
00039140:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content00039140:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content
00039150:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a00039150:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a
00039160:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or00039160:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or
00039170:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con00039170:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con
00039180:·7465·6e74·5f67·726f·7570·5f6f·7065·6e73··tent_group_opens00039180:·7465·6e74·5f67·726f·7570·5f6f·7065·6e73··tent_group_opens
1.13 KB
html2text {}
    
Offset 63, 15 lines modifiedOffset 63, 15 lines modified
63 ····*·cpe:/a:redhat:openshift_container_platform:4.663 ····*·cpe:/a:redhat:openshift_container_platform:4.6
64 ····*·cpe:/a:redhat:openshift_container_platform:4.764 ····*·cpe:/a:redhat:openshift_container_platform:4.7
65 ····*·cpe:/a:redhat:openshift_container_platform:4.865 ····*·cpe:/a:redhat:openshift_container_platform:4.8
66 ····*·cpe:/a:redhat:openshift_container_platform:4.966 ····*·cpe:/a:redhat:openshift_container_platform:4.9
67 ····*·cpe:/a:redhat:openshift_container_platform:4.167 ····*·cpe:/a:redhat:openshift_container_platform:4.1
68 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*68 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
69 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8469 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
70 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)70 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
71 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*71 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
72 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s72 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
73 ·········1.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r73 ·········1.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r
74 ·········2.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n74 ·········2.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n
75 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8G_\x8e_\x8n_\x8e_\x8r_\x8a_\x8l_\x8·_\x8S_\x8e_\x8c_\x8u_\x8r_\x8i_\x8t_\x8y_\x8·_\x8P_\x8r_\x8a_\x8c_\x8t_\x8i_\x8c_\x8e_\x8s75 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8G_\x8e_\x8n_\x8e_\x8r_\x8a_\x8l_\x8·_\x8S_\x8e_\x8c_\x8u_\x8r_\x8i_\x8t_\x8y_\x8·_\x8P_\x8r_\x8a_\x8c_\x8t_\x8i_\x8c_\x8e_\x8s
76 ·········4.·_\x8R_\x8o_\x8l_\x8e_\x8-_\x8b_\x8a_\x8s_\x8e_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l76 ·········4.·_\x8R_\x8o_\x8l_\x8e_\x8-_\x8b_\x8a_\x8s_\x8e_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
77 ·········5.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8R_\x8e_\x8g_\x8i_\x8s_\x8t_\x8r_\x8y_\x8·_\x8S_\x8e_\x8c_\x8u_\x8r_\x8i_\x8t_\x8y_\x8·_\x8P_\x8r_\x8a_\x8c_\x8t_\x8i_\x8c_\x8e_\x8s77 ·········5.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8R_\x8e_\x8g_\x8i_\x8s_\x8t_\x8r_\x8y_\x8·_\x8S_\x8e_\x8c_\x8u_\x8r_\x8i_\x8t_\x8y_\x8·_\x8P_\x8r_\x8a_\x8c_\x8t_\x8i_\x8c_\x8e_\x8s
2.35 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-high-node-rev-4.html
    
Offset 14656, 15 lines modifiedOffset 14656, 15 lines modified
000393f0:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre000393f0:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre
00039400:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str00039400:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str
00039410:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro00039410:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro
00039420:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><00039420:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><
00039430:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st00039430:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st
00039440:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········00039440:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········
00039450:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of00039450:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of
00039460:·2032·3032·362d·3031·2d30·3829·0a20·2020···2026-01-08).···00039460:·2032·3032·342d·3132·2d30·3729·0a20·2020···2024-12-07).···
00039470:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l00039470:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l
00039480:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h200039480:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h2
00039490:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten00039490:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten
000394a0:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><000394a0:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><
000394b0:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o000394b0:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o
000394c0:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co000394c0:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co
000394d0:·6e74·656e·745f·6772·6f75·705f·6f70·656e··ntent_group_open000394d0:·6e74·656e·745f·6772·6f75·705f·6f70·656e··ntent_group_open
1.12 KB
html2text {}
    
Offset 77, 15 lines modifiedOffset 77, 15 lines modified
77 ····*·cpe:/a:redhat:openshift_container_platform:4.677 ····*·cpe:/a:redhat:openshift_container_platform:4.6
78 ····*·cpe:/a:redhat:openshift_container_platform:4.778 ····*·cpe:/a:redhat:openshift_container_platform:4.7
79 ····*·cpe:/a:redhat:openshift_container_platform:4.879 ····*·cpe:/a:redhat:openshift_container_platform:4.8
80 ····*·cpe:/a:redhat:openshift_container_platform:4.980 ····*·cpe:/a:redhat:openshift_container_platform:4.9
81 ····*·cpe:/a:redhat:openshift_container_platform:4.181 ····*·cpe:/a:redhat:openshift_container_platform:4.1
82 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*82 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
83 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8483 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
84 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)84 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
85 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*85 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
86 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s86 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
87 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y87 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y
88 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s88 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
89 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s89 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
90 ·········4.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8L_\x8o_\x8g_\x8g_\x8i_\x8n_\x8g_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s90 ·········4.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8L_\x8o_\x8g_\x8g_\x8i_\x8n_\x8g_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
91 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s91 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
2.47 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-high-node.html
    
Offset 14655, 16 lines modifiedOffset 14655, 16 lines modified
000393e0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h000393e0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h
000393f0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver000393f0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver
00039400:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.00039400:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.
00039410:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p00039410:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p
00039420:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong00039420:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong
00039430:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.00039430:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.
00039440:·2020·2020·2020·2020·2020·2020·2020·2020··················00039440:·2020·2020·2020·2020·2020·2020·2020·2020··················
00039450:·2020·2020·2861·7320·6f66·2032·3032·362d······(as·of·2026-00039450:·2020·2020·2861·7320·6f66·2032·3032·342d······(as·of·2024-
00039460:·3031·2d30·3829·0a20·2020·2020·2020·2020··01-08).·········00039460:·3132·2d30·3729·0a20·2020·2020·2020·2020··12-07).·········
00039470:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul00039470:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul
00039480:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table00039480:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table
00039490:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h200039490:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2
000394a0:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href000394a0:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href
000394b0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg000394b0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg
000394c0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_000394c0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
000394d0:·6772·6f75·705f·6f70·656e·7368·6966·7422··group_openshift"000394d0:·6772·6f75·705f·6f70·656e·7368·6966·7422··group_openshift"
1.12 KB
html2text {}
    
Offset 77, 15 lines modifiedOffset 77, 15 lines modified
77 ····*·cpe:/a:redhat:openshift_container_platform:4.677 ····*·cpe:/a:redhat:openshift_container_platform:4.6
78 ····*·cpe:/a:redhat:openshift_container_platform:4.778 ····*·cpe:/a:redhat:openshift_container_platform:4.7
79 ····*·cpe:/a:redhat:openshift_container_platform:4.879 ····*·cpe:/a:redhat:openshift_container_platform:4.8
80 ····*·cpe:/a:redhat:openshift_container_platform:4.980 ····*·cpe:/a:redhat:openshift_container_platform:4.9
81 ····*·cpe:/a:redhat:openshift_container_platform:4.181 ····*·cpe:/a:redhat:openshift_container_platform:4.1
82 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*82 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
83 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8483 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
84 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)84 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
85 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*85 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
86 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s86 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
87 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y87 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y
88 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s88 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
89 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s89 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
90 ·········4.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8L_\x8o_\x8g_\x8g_\x8i_\x8n_\x8g_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s90 ·········4.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8L_\x8o_\x8g_\x8g_\x8i_\x8n_\x8g_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
91 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s91 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
2.33 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-high-rev-4.html
    
Offset 14656, 15 lines modifiedOffset 14656, 15 lines modified
000393f0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu000393f0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00039400:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00039400:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00039410:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s00039410:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00039420:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00039420:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00039430:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00039430:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00039440:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00039440:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00039450:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00039450:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00039460:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).00039460:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
00039470:·2020·2020·2020·2020·2020·2020·2020·2020··················00039470:·2020·2020·2020·2020·2020·2020·2020·2020··················
00039480:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00039480:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00039490:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00039490:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
000394a0:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l000394a0:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
000394b0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd000394b0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
000394c0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject000394c0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
000394d0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f6f··.content_group_o000394d0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f6f··.content_group_o
1.11 KB
html2text {}
    
Offset 77, 15 lines modifiedOffset 77, 15 lines modified
77 ····*·cpe:/a:redhat:openshift_container_platform:4.677 ····*·cpe:/a:redhat:openshift_container_platform:4.6
78 ····*·cpe:/a:redhat:openshift_container_platform:4.778 ····*·cpe:/a:redhat:openshift_container_platform:4.7
79 ····*·cpe:/a:redhat:openshift_container_platform:4.879 ····*·cpe:/a:redhat:openshift_container_platform:4.8
80 ····*·cpe:/a:redhat:openshift_container_platform:4.980 ····*·cpe:/a:redhat:openshift_container_platform:4.9
81 ····*·cpe:/a:redhat:openshift_container_platform:4.181 ····*·cpe:/a:redhat:openshift_container_platform:4.1
82 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*82 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
83 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8483 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
84 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)84 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
85 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*85 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
86 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s86 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
87 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y87 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y
88 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l88 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
89 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r89 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r
90 ·········4.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n90 ·········4.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n
91 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s91 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
2.32 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-high.html
    
Offset 14656, 15 lines modifiedOffset 14656, 15 lines modified
000393f0:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·000393f0:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·
00039400:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong00039400:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong
00039410:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>00039410:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>
00039420:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str00039420:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str
00039430:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron00039430:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron
00039440:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············00039440:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············
00039450:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·2000039450:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·20
00039460:·3236·2d30·312d·3038·290a·2020·2020·2020··26-01-08).······00039460:·3234·2d31·322d·3037·290a·2020·2020·2020··24-12-07).······
00039470:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><00039470:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><
00039480:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta00039480:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta
00039490:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<00039490:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<
000394a0:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h000394a0:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h
000394b0:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.000394b0:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.
000394c0:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte000394c0:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte
000394d0:·6e74·5f67·726f·7570·5f6f·7065·6e73·6869··nt_group_openshi000394d0:·6e74·5f67·726f·7570·5f6f·7065·6e73·6869··nt_group_openshi
1.11 KB
html2text {}
    
Offset 77, 15 lines modifiedOffset 77, 15 lines modified
77 ····*·cpe:/a:redhat:openshift_container_platform:4.677 ····*·cpe:/a:redhat:openshift_container_platform:4.6
78 ····*·cpe:/a:redhat:openshift_container_platform:4.778 ····*·cpe:/a:redhat:openshift_container_platform:4.7
79 ····*·cpe:/a:redhat:openshift_container_platform:4.879 ····*·cpe:/a:redhat:openshift_container_platform:4.8
80 ····*·cpe:/a:redhat:openshift_container_platform:4.980 ····*·cpe:/a:redhat:openshift_container_platform:4.9
81 ····*·cpe:/a:redhat:openshift_container_platform:4.181 ····*·cpe:/a:redhat:openshift_container_platform:4.1
82 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*82 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
83 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8483 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
84 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)84 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
85 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*85 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
86 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s86 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
87 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y87 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y
88 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l88 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
89 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r89 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r
90 ·········4.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n90 ·········4.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n
91 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s91 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
2.36 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-moderate-node-rev-4.html
    
Offset 14657, 15 lines modifiedOffset 14657, 15 lines modified
00039400:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00039400:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00039410:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00039410:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00039420:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</00039420:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
00039430:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00039430:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
00039440:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft00039440:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
00039450:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······00039450:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
00039460:·2020·2020·2020·2020·2020·2020·2020·2861················(a00039460:·2020·2020·2020·2020·2020·2020·2020·2861················(a
00039470:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)00039470:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
00039480:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00039480:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00039490:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div00039490:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
000394a0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co000394a0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
000394b0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><000394b0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
000394c0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc000394c0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
000394d0:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec000394d0:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
000394e0:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_000394e0:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
1.12 KB
html2text {}
    
Offset 77, 15 lines modifiedOffset 77, 15 lines modified
77 ····*·cpe:/a:redhat:openshift_container_platform:4.677 ····*·cpe:/a:redhat:openshift_container_platform:4.6
78 ····*·cpe:/a:redhat:openshift_container_platform:4.778 ····*·cpe:/a:redhat:openshift_container_platform:4.7
79 ····*·cpe:/a:redhat:openshift_container_platform:4.879 ····*·cpe:/a:redhat:openshift_container_platform:4.8
80 ····*·cpe:/a:redhat:openshift_container_platform:4.980 ····*·cpe:/a:redhat:openshift_container_platform:4.9
81 ····*·cpe:/a:redhat:openshift_container_platform:4.181 ····*·cpe:/a:redhat:openshift_container_platform:4.1
82 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*82 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
83 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8483 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
84 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)84 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
85 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*85 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
86 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s86 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
87 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y87 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y
88 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s88 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
89 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s89 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
90 ·········4.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8L_\x8o_\x8g_\x8g_\x8i_\x8n_\x8g_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s90 ·········4.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8L_\x8o_\x8g_\x8g_\x8i_\x8n_\x8g_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
91 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s91 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
2.35 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-moderate-node.html
    
Offset 14657, 15 lines modifiedOffset 14657, 15 lines modified
00039400:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current00039400:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current
00039410:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron00039410:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron
00039420:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong00039420:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong
00039430:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st00039430:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st
00039440:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro00039440:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro
00039450:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············00039450:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············
00039460:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·200039460:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·2
00039470:·3032·362d·3031·2d30·3829·0a20·2020·2020··026-01-08).·····00039470:·3032·342d·3132·2d30·3729·0a20·2020·2020··024-12-07).·····
00039480:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>00039480:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>
00039490:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T00039490:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T
000394a0:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents000394a0:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents
000394b0:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·000394b0:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·
000394c0:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org000394c0:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org
000394d0:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont000394d0:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont
000394e0:·656e·745f·6772·6f75·705f·6f70·656e·7368··ent_group_opensh000394e0:·656e·745f·6772·6f75·705f·6f70·656e·7368··ent_group_opensh
1.12 KB
html2text {}
    
Offset 77, 15 lines modifiedOffset 77, 15 lines modified
77 ····*·cpe:/a:redhat:openshift_container_platform:4.677 ····*·cpe:/a:redhat:openshift_container_platform:4.6
78 ····*·cpe:/a:redhat:openshift_container_platform:4.778 ····*·cpe:/a:redhat:openshift_container_platform:4.7
79 ····*·cpe:/a:redhat:openshift_container_platform:4.879 ····*·cpe:/a:redhat:openshift_container_platform:4.8
80 ····*·cpe:/a:redhat:openshift_container_platform:4.980 ····*·cpe:/a:redhat:openshift_container_platform:4.9
81 ····*·cpe:/a:redhat:openshift_container_platform:4.181 ····*·cpe:/a:redhat:openshift_container_platform:4.1
82 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*82 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
83 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8483 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
84 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)84 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
85 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*85 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
86 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s86 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
87 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y87 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y
88 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s88 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
89 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s89 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
90 ·········4.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8L_\x8o_\x8g_\x8g_\x8i_\x8n_\x8g_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s90 ·········4.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8L_\x8o_\x8g_\x8g_\x8i_\x8n_\x8g_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
91 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s91 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
2.48 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-moderate-rev-4.html
    
Offset 14657, 16 lines modifiedOffset 14657, 16 lines modified
00039400:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><00039400:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><
00039410:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio00039410:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio
00039420:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.700039420:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.7
00039430:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u00039430:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u
00039440:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr00039440:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr
00039450:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···00039450:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···
00039460:·2020·2020·2020·2020·2020·2020·2020·2020··················00039460:·2020·2020·2020·2020·2020·2020·2020·2020··················
00039470:·2028·6173·206f·6620·3230·3236·2d30·312d···(as·of·2026-01-00039470:·2028·6173·206f·6620·3230·3234·2d31·322d···(as·of·2024-12-
00039480:·3038·290a·2020·2020·2020·2020·2020·2020··08).············00039480:·3037·290a·2020·2020·2020·2020·2020·2020··07).············
00039490:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></00039490:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></
000394a0:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of000394a0:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of
000394b0:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o000394b0:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o
000394c0:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#000394c0:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#
000394d0:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro000394d0:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro
000394e0:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro000394e0:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro
000394f0:·7570·5f6f·7065·6e73·6869·6674·223e·4b75··up_openshift">Ku000394f0:·7570·5f6f·7065·6e73·6869·6674·223e·4b75··up_openshift">Ku
1.11 KB
html2text {}
    
Offset 77, 15 lines modifiedOffset 77, 15 lines modified
77 ····*·cpe:/a:redhat:openshift_container_platform:4.677 ····*·cpe:/a:redhat:openshift_container_platform:4.6
78 ····*·cpe:/a:redhat:openshift_container_platform:4.778 ····*·cpe:/a:redhat:openshift_container_platform:4.7
79 ····*·cpe:/a:redhat:openshift_container_platform:4.879 ····*·cpe:/a:redhat:openshift_container_platform:4.8
80 ····*·cpe:/a:redhat:openshift_container_platform:4.980 ····*·cpe:/a:redhat:openshift_container_platform:4.9
81 ····*·cpe:/a:redhat:openshift_container_platform:4.181 ····*·cpe:/a:redhat:openshift_container_platform:4.1
82 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*82 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
83 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8483 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
84 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)84 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
85 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*85 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
86 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s86 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
87 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y87 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y
88 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l88 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
89 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r89 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r
90 ·········4.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n90 ·········4.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n
91 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s91 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
2.33 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-moderate.html
    
Offset 14657, 15 lines modifiedOffset 14657, 15 lines modified
00039400:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr00039400:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr
00039410:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st00039410:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st
00039420:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str00039420:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str
00039430:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>00039430:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>
00039440:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s00039440:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s
00039450:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········00039450:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········
00039460:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o00039460:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o
00039470:·6620·3230·3236·2d30·312d·3038·290a·2020··f·2026-01-08).··00039470:·6620·3230·3234·2d31·322d·3037·290a·2020··f·2024-12-07).··
00039480:·2020·2020·2020·2020·2020·2020·2020·3c2f················</00039480:·2020·2020·2020·2020·2020·2020·2020·3c2f················</
00039490:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h00039490:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h
000394a0:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte000394a0:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte
000394b0:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>000394b0:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>
000394c0:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_000394c0:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_
000394d0:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c000394d0:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c
000394e0:·6f6e·7465·6e74·5f67·726f·7570·5f6f·7065··ontent_group_ope000394e0:·6f6e·7465·6e74·5f67·726f·7570·5f6f·7065··ontent_group_ope
1.11 KB
html2text {}
    
Offset 77, 15 lines modifiedOffset 77, 15 lines modified
77 ····*·cpe:/a:redhat:openshift_container_platform:4.677 ····*·cpe:/a:redhat:openshift_container_platform:4.6
78 ····*·cpe:/a:redhat:openshift_container_platform:4.778 ····*·cpe:/a:redhat:openshift_container_platform:4.7
79 ····*·cpe:/a:redhat:openshift_container_platform:4.879 ····*·cpe:/a:redhat:openshift_container_platform:4.8
80 ····*·cpe:/a:redhat:openshift_container_platform:4.980 ····*·cpe:/a:redhat:openshift_container_platform:4.9
81 ····*·cpe:/a:redhat:openshift_container_platform:4.181 ····*·cpe:/a:redhat:openshift_container_platform:4.1
82 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*82 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
83 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8483 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
84 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)84 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
85 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*85 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
86 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s86 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
87 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y87 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y
88 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l88 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
89 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r89 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r
90 ·········4.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n90 ·········4.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n
91 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s91 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
2.48 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-nerc-cip-node.html
    
Offset 14618, 16 lines modifiedOffset 14618, 16 lines modified
00039190:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><00039190:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><
000391a0:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio000391a0:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio
000391b0:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.7000391b0:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.7
000391c0:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u000391c0:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u
000391d0:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr000391d0:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr
000391e0:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···000391e0:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···
000391f0:·2020·2020·2020·2020·2020·2020·2020·2020··················000391f0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00039200:·2028·6173·206f·6620·3230·3236·2d30·312d···(as·of·2026-01-00039200:·2028·6173·206f·6620·3230·3234·2d31·322d···(as·of·2024-12-
00039210:·3038·290a·2020·2020·2020·2020·2020·2020··08).············00039210:·3037·290a·2020·2020·2020·2020·2020·2020··07).············
00039220:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></00039220:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></
00039230:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of00039230:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of
00039240:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o00039240:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o
00039250:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#00039250:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#
00039260:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro00039260:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro
00039270:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro00039270:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro
00039280:·7570·5f6f·7065·6e73·6869·6674·223e·4b75··up_openshift">Ku00039280:·7570·5f6f·7065·6e73·6869·6674·223e·4b75··up_openshift">Ku
1.12 KB
html2text {}
    
Offset 66, 15 lines modifiedOffset 66, 15 lines modified
66 ····*·cpe:/a:redhat:openshift_container_platform:4.666 ····*·cpe:/a:redhat:openshift_container_platform:4.6
67 ····*·cpe:/a:redhat:openshift_container_platform:4.767 ····*·cpe:/a:redhat:openshift_container_platform:4.7
68 ····*·cpe:/a:redhat:openshift_container_platform:4.868 ····*·cpe:/a:redhat:openshift_container_platform:4.8
69 ····*·cpe:/a:redhat:openshift_container_platform:4.969 ····*·cpe:/a:redhat:openshift_container_platform:4.9
70 ····*·cpe:/a:redhat:openshift_container_platform:4.170 ····*·cpe:/a:redhat:openshift_container_platform:4.1
71 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*71 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
72 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8472 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
73 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)73 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
74 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*74 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
75 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s75 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
76 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y76 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y
77 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s77 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
78 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s78 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
79 ·········4.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8L_\x8o_\x8g_\x8g_\x8i_\x8n_\x8g_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s79 ·········4.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8L_\x8o_\x8g_\x8g_\x8i_\x8n_\x8g_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
80 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s80 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
2.46 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-nerc-cip.html
    
Offset 14618, 16 lines modifiedOffset 14618, 16 lines modified
00039190:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h00039190:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h
000391a0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver000391a0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver
000391b0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.000391b0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.
000391c0:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p000391c0:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p
000391d0:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong000391d0:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong
000391e0:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.000391e0:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.
000391f0:·2020·2020·2020·2020·2020·2020·2020·2020··················000391f0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00039200:·2020·2020·2861·7320·6f66·2032·3032·362d······(as·of·2026-00039200:·2020·2020·2861·7320·6f66·2032·3032·342d······(as·of·2024-
00039210:·3031·2d30·3829·0a20·2020·2020·2020·2020··01-08).·········00039210:·3132·2d30·3729·0a20·2020·2020·2020·2020··12-07).·········
00039220:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul00039220:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul
00039230:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table00039230:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table
00039240:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h200039240:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2
00039250:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href00039250:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href
00039260:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg00039260:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg
00039270:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_00039270:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
00039280:·6772·6f75·705f·6f70·656e·7368·6966·7422··group_openshift"00039280:·6772·6f75·705f·6f70·656e·7368·6966·7422··group_openshift"
1.11 KB
html2text {}
    
Offset 66, 15 lines modifiedOffset 66, 15 lines modified
66 ····*·cpe:/a:redhat:openshift_container_platform:4.666 ····*·cpe:/a:redhat:openshift_container_platform:4.6
67 ····*·cpe:/a:redhat:openshift_container_platform:4.767 ····*·cpe:/a:redhat:openshift_container_platform:4.7
68 ····*·cpe:/a:redhat:openshift_container_platform:4.868 ····*·cpe:/a:redhat:openshift_container_platform:4.8
69 ····*·cpe:/a:redhat:openshift_container_platform:4.969 ····*·cpe:/a:redhat:openshift_container_platform:4.9
70 ····*·cpe:/a:redhat:openshift_container_platform:4.170 ····*·cpe:/a:redhat:openshift_container_platform:4.1
71 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*71 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
72 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8472 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
73 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)73 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
74 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*74 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
75 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s75 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
76 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y76 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y
77 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l77 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
78 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r78 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r
79 ·········4.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n79 ·········4.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n
80 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s80 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
2.33 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-pci-dss-3-2.html
    
Offset 14588, 15 lines modifiedOffset 14588, 15 lines modified
00038fb0:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre00038fb0:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre
00038fc0:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str00038fc0:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str
00038fd0:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro00038fd0:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro
00038fe0:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><00038fe0:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><
00038ff0:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st00038ff0:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st
00039000:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········00039000:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········
00039010:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of00039010:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of
00039020:·2032·3032·362d·3031·2d30·3829·0a20·2020···2026-01-08).···00039020:·2032·3032·342d·3132·2d30·3729·0a20·2020···2024-12-07).···
00039030:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l00039030:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l
00039040:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h200039040:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h2
00039050:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten00039050:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten
00039060:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><00039060:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><
00039070:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o00039070:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o
00039080:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co00039080:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co
00039090:·6e74·656e·745f·6772·6f75·705f·6f70·656e··ntent_group_open00039090:·6e74·656e·745f·6772·6f75·705f·6f70·656e··ntent_group_open
1.11 KB
html2text {}
    
Offset 60, 15 lines modifiedOffset 60, 15 lines modified
60 ····*·cpe:/a:redhat:openshift_container_platform:4.660 ····*·cpe:/a:redhat:openshift_container_platform:4.6
61 ····*·cpe:/a:redhat:openshift_container_platform:4.761 ····*·cpe:/a:redhat:openshift_container_platform:4.7
62 ····*·cpe:/a:redhat:openshift_container_platform:4.862 ····*·cpe:/a:redhat:openshift_container_platform:4.8
63 ····*·cpe:/a:redhat:openshift_container_platform:4.963 ····*·cpe:/a:redhat:openshift_container_platform:4.9
64 ····*·cpe:/a:redhat:openshift_container_platform:4.164 ····*·cpe:/a:redhat:openshift_container_platform:4.1
65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
66 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8466 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
69 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s69 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
70 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y70 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y
71 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l71 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
72 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r72 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r
73 ·········4.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n73 ·········4.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n
74 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s74 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
2.32 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-pci-dss-4-0.html
    
Offset 14588, 15 lines modifiedOffset 14588, 15 lines modified
00038fb0:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre00038fb0:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre
00038fc0:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str00038fc0:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str
00038fd0:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro00038fd0:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro
00038fe0:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><00038fe0:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><
00038ff0:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st00038ff0:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st
00039000:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········00039000:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········
00039010:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of00039010:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of
00039020:·2032·3032·362d·3031·2d30·3829·0a20·2020···2026-01-08).···00039020:·2032·3032·342d·3132·2d30·3729·0a20·2020···2024-12-07).···
00039030:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l00039030:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l
00039040:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h200039040:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h2
00039050:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten00039050:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten
00039060:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><00039060:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><
00039070:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o00039070:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o
00039080:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co00039080:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co
00039090:·6e74·656e·745f·6772·6f75·705f·6f70·656e··ntent_group_open00039090:·6e74·656e·745f·6772·6f75·705f·6f70·656e··ntent_group_open
1.09 KB
html2text {}
    
Offset 60, 15 lines modifiedOffset 60, 15 lines modified
60 ····*·cpe:/a:redhat:openshift_container_platform:4.660 ····*·cpe:/a:redhat:openshift_container_platform:4.6
61 ····*·cpe:/a:redhat:openshift_container_platform:4.761 ····*·cpe:/a:redhat:openshift_container_platform:4.7
62 ····*·cpe:/a:redhat:openshift_container_platform:4.862 ····*·cpe:/a:redhat:openshift_container_platform:4.8
63 ····*·cpe:/a:redhat:openshift_container_platform:4.963 ····*·cpe:/a:redhat:openshift_container_platform:4.9
64 ····*·cpe:/a:redhat:openshift_container_platform:4.164 ····*·cpe:/a:redhat:openshift_container_platform:4.1
65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
66 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8466 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
69 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s69 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
70 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y70 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y
71 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l71 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
72 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r72 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r
73 ·········4.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n73 ·········4.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n
74 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8n_\x8e_\x8m_\x8e_\x8n_\x8t74 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8n_\x8e_\x8m_\x8e_\x8n_\x8t
2.38 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-pci-dss-node-3-2.html
    
Offset 14588, 15 lines modifiedOffset 14588, 15 lines modified
00038fb0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00038fb0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00038fc0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00038fc0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00038fd0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<00038fd0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<
00038fe0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00038fe0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00038ff0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00038ff0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00039000:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00039000:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00039010:·2020·2020·2020·2020·2020·2020·2020·2028·················(00039010:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00039020:·6173·206f·6620·3230·3236·2d30·312d·3038··as·of·2026-01-0800039020:·6173·206f·6620·3230·3234·2d31·322d·3037··as·of·2024-12-07
00039030:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00039030:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00039040:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00039040:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00039050:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00039050:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00039060:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00039060:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00039070:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00039070:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00039080:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00039080:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00039090:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00039090:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
1.15 KB
html2text {}
    
Offset 60, 15 lines modifiedOffset 60, 15 lines modified
60 ····*·cpe:/a:redhat:openshift_container_platform:4.660 ····*·cpe:/a:redhat:openshift_container_platform:4.6
61 ····*·cpe:/a:redhat:openshift_container_platform:4.761 ····*·cpe:/a:redhat:openshift_container_platform:4.7
62 ····*·cpe:/a:redhat:openshift_container_platform:4.862 ····*·cpe:/a:redhat:openshift_container_platform:4.8
63 ····*·cpe:/a:redhat:openshift_container_platform:4.963 ····*·cpe:/a:redhat:openshift_container_platform:4.9
64 ····*·cpe:/a:redhat:openshift_container_platform:4.164 ····*·cpe:/a:redhat:openshift_container_platform:4.1
65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
66 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8466 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
69 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s69 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
70 ·········1.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s70 ·········1.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
71 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8G_\x8e_\x8n_\x8e_\x8r_\x8a_\x8l_\x8·_\x8S_\x8e_\x8c_\x8u_\x8r_\x8i_\x8t_\x8y_\x8·_\x8P_\x8r_\x8a_\x8c_\x8t_\x8i_\x8c_\x8e_\x8s71 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8G_\x8e_\x8n_\x8e_\x8r_\x8a_\x8l_\x8·_\x8S_\x8e_\x8c_\x8u_\x8r_\x8i_\x8t_\x8y_\x8·_\x8P_\x8r_\x8a_\x8c_\x8t_\x8i_\x8c_\x8e_\x8s
72 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s72 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
73 ·········4.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8L_\x8o_\x8g_\x8g_\x8i_\x8n_\x8g_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s73 ·········4.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8L_\x8o_\x8g_\x8g_\x8i_\x8n_\x8g_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
74 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s74 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
2.4 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-pci-dss-node-4-0.html
    
Offset 14588, 15 lines modifiedOffset 14588, 15 lines modified
00038fb0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00038fb0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00038fc0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00038fc0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00038fd0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<00038fd0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<
00038fe0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00038fe0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00038ff0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00038ff0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00039000:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00039000:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00039010:·2020·2020·2020·2020·2020·2020·2020·2028·················(00039010:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00039020:·6173·206f·6620·3230·3236·2d30·312d·3038··as·of·2026-01-0800039020:·6173·206f·6620·3230·3234·2d31·322d·3037··as·of·2024-12-07
00039030:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00039030:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00039040:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00039040:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00039050:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00039050:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00039060:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00039060:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00039070:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00039070:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00039080:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00039080:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00039090:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00039090:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
1.17 KB
html2text {}
    
Offset 60, 15 lines modifiedOffset 60, 15 lines modified
60 ····*·cpe:/a:redhat:openshift_container_platform:4.660 ····*·cpe:/a:redhat:openshift_container_platform:4.6
61 ····*·cpe:/a:redhat:openshift_container_platform:4.761 ····*·cpe:/a:redhat:openshift_container_platform:4.7
62 ····*·cpe:/a:redhat:openshift_container_platform:4.862 ····*·cpe:/a:redhat:openshift_container_platform:4.8
63 ····*·cpe:/a:redhat:openshift_container_platform:4.963 ····*·cpe:/a:redhat:openshift_container_platform:4.9
64 ····*·cpe:/a:redhat:openshift_container_platform:4.164 ····*·cpe:/a:redhat:openshift_container_platform:4.1
65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
66 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8466 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
69 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s69 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
70 ·········1.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s70 ·········1.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
71 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8G_\x8e_\x8n_\x8e_\x8r_\x8a_\x8l_\x8·_\x8S_\x8e_\x8c_\x8u_\x8r_\x8i_\x8t_\x8y_\x8·_\x8P_\x8r_\x8a_\x8c_\x8t_\x8i_\x8c_\x8e_\x8s71 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8G_\x8e_\x8n_\x8e_\x8r_\x8a_\x8l_\x8·_\x8S_\x8e_\x8c_\x8u_\x8r_\x8i_\x8t_\x8y_\x8·_\x8P_\x8r_\x8a_\x8c_\x8t_\x8i_\x8c_\x8e_\x8s
72 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s72 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
73 ·········4.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s73 ·········4.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
74 ·········5.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8W_\x8o_\x8r_\x8k_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s74 ·········5.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8W_\x8o_\x8r_\x8k_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
2.38 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-pci-dss-node.html
    
Offset 14588, 15 lines modifiedOffset 14588, 15 lines modified
00038fb0:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr00038fb0:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr
00038fc0:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st00038fc0:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st
00038fd0:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str00038fd0:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str
00038fe0:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>00038fe0:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>
00038ff0:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s00038ff0:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s
00039000:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········00039000:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········
00039010:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o00039010:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o
00039020:·6620·3230·3236·2d30·312d·3038·290a·2020··f·2026-01-08).··00039020:·6620·3230·3234·2d31·322d·3037·290a·2020··f·2024-12-07).··
00039030:·2020·2020·2020·2020·2020·2020·2020·3c2f················</00039030:·2020·2020·2020·2020·2020·2020·2020·3c2f················</
00039040:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h00039040:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h
00039050:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte00039050:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte
00039060:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>00039060:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>
00039070:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_00039070:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_
00039080:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c00039080:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c
00039090:·6f6e·7465·6e74·5f67·726f·7570·5f6f·7065··ontent_group_ope00039090:·6f6e·7465·6e74·5f67·726f·7570·5f6f·7065··ontent_group_ope
1.15 KB
html2text {}
    
Offset 60, 15 lines modifiedOffset 60, 15 lines modified
60 ····*·cpe:/a:redhat:openshift_container_platform:4.660 ····*·cpe:/a:redhat:openshift_container_platform:4.6
61 ····*·cpe:/a:redhat:openshift_container_platform:4.761 ····*·cpe:/a:redhat:openshift_container_platform:4.7
62 ····*·cpe:/a:redhat:openshift_container_platform:4.862 ····*·cpe:/a:redhat:openshift_container_platform:4.8
63 ····*·cpe:/a:redhat:openshift_container_platform:4.963 ····*·cpe:/a:redhat:openshift_container_platform:4.9
64 ····*·cpe:/a:redhat:openshift_container_platform:4.164 ····*·cpe:/a:redhat:openshift_container_platform:4.1
65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
66 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8466 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
69 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s69 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
70 ·········1.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s70 ·········1.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
71 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8G_\x8e_\x8n_\x8e_\x8r_\x8a_\x8l_\x8·_\x8S_\x8e_\x8c_\x8u_\x8r_\x8i_\x8t_\x8y_\x8·_\x8P_\x8r_\x8a_\x8c_\x8t_\x8i_\x8c_\x8e_\x8s71 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8G_\x8e_\x8n_\x8e_\x8r_\x8a_\x8l_\x8·_\x8S_\x8e_\x8c_\x8u_\x8r_\x8i_\x8t_\x8y_\x8·_\x8P_\x8r_\x8a_\x8c_\x8t_\x8i_\x8c_\x8e_\x8s
72 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s72 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
73 ·········4.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8L_\x8o_\x8g_\x8g_\x8i_\x8n_\x8g_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s73 ·········4.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8L_\x8o_\x8g_\x8g_\x8i_\x8n_\x8g_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
74 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s74 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
2.33 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-pci-dss.html
    
Offset 14588, 15 lines modifiedOffset 14588, 15 lines modified
00038fb0:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v00038fb0:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v
00038fc0:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>00038fc0:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>
00038fd0:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><00038fd0:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><
00038fe0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro00038fe0:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro
00038ff0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong00038ff0:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong
00039000:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············00039000:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············
00039010:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·20200039010:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202
00039020:·362d·3031·2d30·3829·0a20·2020·2020·2020··6-01-08).·······00039020:·342d·3132·2d30·3729·0a20·2020·2020·2020··4-12-07).·······
00039030:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></00039030:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></
00039040:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab00039040:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab
00039050:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</00039050:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</
00039060:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr00039060:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr
00039070:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s00039070:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s
00039080:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten00039080:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten
00039090:·745f·6772·6f75·705f·6f70·656e·7368·6966··t_group_openshif00039090:·745f·6772·6f75·705f·6f70·656e·7368·6966··t_group_openshif
1.11 KB
html2text {}
    
Offset 60, 15 lines modifiedOffset 60, 15 lines modified
60 ····*·cpe:/a:redhat:openshift_container_platform:4.660 ····*·cpe:/a:redhat:openshift_container_platform:4.6
61 ····*·cpe:/a:redhat:openshift_container_platform:4.761 ····*·cpe:/a:redhat:openshift_container_platform:4.7
62 ····*·cpe:/a:redhat:openshift_container_platform:4.862 ····*·cpe:/a:redhat:openshift_container_platform:4.8
63 ····*·cpe:/a:redhat:openshift_container_platform:4.963 ····*·cpe:/a:redhat:openshift_container_platform:4.9
64 ····*·cpe:/a:redhat:openshift_container_platform:4.164 ····*·cpe:/a:redhat:openshift_container_platform:4.1
65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
66 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8466 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
69 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s69 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
70 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y70 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y
71 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l71 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
72 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r72 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r
73 ·········4.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n73 ·········4.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n
74 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s74 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
2.38 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-stig-node-v1r1.html
    
Offset 14590, 15 lines modifiedOffset 14590, 15 lines modified
00038fd0:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre00038fd0:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre
00038fe0:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str00038fe0:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str
00038ff0:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro00038ff0:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro
00039000:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><00039000:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><
00039010:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st00039010:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st
00039020:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········00039020:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········
00039030:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of00039030:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of
00039040:·2032·3032·362d·3031·2d30·3829·0a20·2020···2026-01-08).···00039040:·2032·3032·342d·3132·2d30·3729·0a20·2020···2024-12-07).···
00039050:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l00039050:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l
00039060:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h200039060:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h2
00039070:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten00039070:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten
00039080:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><00039080:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><
00039090:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o00039090:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o
000390a0:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co000390a0:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co
000390b0:·6e74·656e·745f·6772·6f75·705f·6f70·656e··ntent_group_open000390b0:·6e74·656e·745f·6772·6f75·705f·6f70·656e··ntent_group_open
1.15 KB
html2text {}
    
Offset 60, 15 lines modifiedOffset 60, 15 lines modified
60 ····*·cpe:/a:redhat:openshift_container_platform:4.660 ····*·cpe:/a:redhat:openshift_container_platform:4.6
61 ····*·cpe:/a:redhat:openshift_container_platform:4.761 ····*·cpe:/a:redhat:openshift_container_platform:4.7
62 ····*·cpe:/a:redhat:openshift_container_platform:4.862 ····*·cpe:/a:redhat:openshift_container_platform:4.8
63 ····*·cpe:/a:redhat:openshift_container_platform:4.963 ····*·cpe:/a:redhat:openshift_container_platform:4.9
64 ····*·cpe:/a:redhat:openshift_container_platform:4.164 ····*·cpe:/a:redhat:openshift_container_platform:4.1
65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
66 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8466 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
69 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s69 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
70 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y70 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y
71 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s71 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
72 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8G_\x8e_\x8n_\x8e_\x8r_\x8a_\x8l_\x8·_\x8S_\x8e_\x8c_\x8u_\x8r_\x8i_\x8t_\x8y_\x8·_\x8P_\x8r_\x8a_\x8c_\x8t_\x8i_\x8c_\x8e_\x8s72 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8G_\x8e_\x8n_\x8e_\x8r_\x8a_\x8l_\x8·_\x8S_\x8e_\x8c_\x8u_\x8r_\x8i_\x8t_\x8y_\x8·_\x8P_\x8r_\x8a_\x8c_\x8t_\x8i_\x8c_\x8e_\x8s
73 ·········4.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s73 ·········4.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
74 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s74 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
2.51 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-stig-node.html
    
Offset 14589, 16 lines modifiedOffset 14589, 16 lines modified
00038fc0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00038fc0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00038fd0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00038fd0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00038fe0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000038fe0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00038ff0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></00038ff0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
00039000:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00039000:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00039010:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00039010:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00039020:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00039020:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00039030:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600039030:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
00039040:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········00039040:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00039050:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00039050:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00039060:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00039060:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00039070:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00039070:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00039080:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00039080:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00039090:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00039090:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
000390a0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content000390a0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
000390b0:·5f67·726f·7570·5f6f·7065·6e73·6869·6674··_group_openshift000390b0:·5f67·726f·7570·5f6f·7065·6e73·6869·6674··_group_openshift
1.15 KB
html2text {}
    
Offset 60, 15 lines modifiedOffset 60, 15 lines modified
60 ····*·cpe:/a:redhat:openshift_container_platform:4.660 ····*·cpe:/a:redhat:openshift_container_platform:4.6
61 ····*·cpe:/a:redhat:openshift_container_platform:4.761 ····*·cpe:/a:redhat:openshift_container_platform:4.7
62 ····*·cpe:/a:redhat:openshift_container_platform:4.862 ····*·cpe:/a:redhat:openshift_container_platform:4.8
63 ····*·cpe:/a:redhat:openshift_container_platform:4.963 ····*·cpe:/a:redhat:openshift_container_platform:4.9
64 ····*·cpe:/a:redhat:openshift_container_platform:4.164 ····*·cpe:/a:redhat:openshift_container_platform:4.1
65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*65 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
66 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8466 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)67 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*68 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
69 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s69 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
70 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y70 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y
71 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s71 ·········2.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8e_\x8t_\x8c_\x8d_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
72 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8G_\x8e_\x8n_\x8e_\x8r_\x8a_\x8l_\x8·_\x8S_\x8e_\x8c_\x8u_\x8r_\x8i_\x8t_\x8y_\x8·_\x8P_\x8r_\x8a_\x8c_\x8t_\x8i_\x8c_\x8e_\x8s72 ·········3.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8G_\x8e_\x8n_\x8e_\x8r_\x8a_\x8l_\x8·_\x8S_\x8e_\x8c_\x8u_\x8r_\x8i_\x8t_\x8y_\x8·_\x8P_\x8r_\x8a_\x8c_\x8t_\x8i_\x8c_\x8e_\x8s
73 ·········4.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s73 ·········4.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8K_\x8u_\x8b_\x8e_\x8l_\x8e_\x8t_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
74 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s74 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8-_\x8·_\x8M_\x8a_\x8s_\x8t_\x8e_\x8r_\x8·_\x8N_\x8o_\x8d_\x8e_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
2.33 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-stig-v1r1.html
    
Offset 14590, 15 lines modifiedOffset 14590, 15 lines modified
00038fd0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00038fd0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00038fe0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00038fe0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00038ff0:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s00038ff0:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00039000:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00039000:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00039010:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00039010:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00039020:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00039020:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00039030:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00039030:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00039040:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).00039040:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
00039050:·2020·2020·2020·2020·2020·2020·2020·2020··················00039050:·2020·2020·2020·2020·2020·2020·2020·2020··················
00039060:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00039060:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00039070:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00039070:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00039080:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00039080:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00039090:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00039090:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
000390a0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject000390a0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
000390b0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f6f··.content_group_o000390b0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f6f··.content_group_o
1.11 KB
html2text {}
    
Offset 61, 15 lines modifiedOffset 61, 15 lines modified
61 ····*·cpe:/a:redhat:openshift_container_platform:4.661 ····*·cpe:/a:redhat:openshift_container_platform:4.6
62 ····*·cpe:/a:redhat:openshift_container_platform:4.762 ····*·cpe:/a:redhat:openshift_container_platform:4.7
63 ····*·cpe:/a:redhat:openshift_container_platform:4.863 ····*·cpe:/a:redhat:openshift_container_platform:4.8
64 ····*·cpe:/a:redhat:openshift_container_platform:4.964 ····*·cpe:/a:redhat:openshift_container_platform:4.9
65 ····*·cpe:/a:redhat:openshift_container_platform:4.165 ····*·cpe:/a:redhat:openshift_container_platform:4.1
66 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*66 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
67 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8467 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
68 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)68 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
69 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*69 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
70 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s70 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
71 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y71 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y
72 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l72 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
73 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r73 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r
74 ·········4.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n74 ·········4.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n
75 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s75 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
2.32 KB
./usr/share/doc/ssg-nondebian/ssg-ocp4-guide-stig.html
    
Offset 14590, 15 lines modifiedOffset 14590, 15 lines modified
00038fd0:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current00038fd0:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current
00038fe0:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron00038fe0:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron
00038ff0:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong00038ff0:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong
00039000:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st00039000:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st
00039010:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro00039010:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro
00039020:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············00039020:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············
00039030:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·200039030:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·2
00039040:·3032·362d·3031·2d30·3829·0a20·2020·2020··026-01-08).·····00039040:·3032·342d·3132·2d30·3729·0a20·2020·2020··024-12-07).·····
00039050:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>00039050:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>
00039060:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T00039060:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T
00039070:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents00039070:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents
00039080:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·00039080:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·
00039090:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org00039090:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org
000390a0:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont000390a0:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont
000390b0:·656e·745f·6772·6f75·705f·6f70·656e·7368··ent_group_opensh000390b0:·656e·745f·6772·6f75·705f·6f70·656e·7368··ent_group_opensh
1.11 KB
html2text {}
    
Offset 61, 15 lines modifiedOffset 61, 15 lines modified
61 ····*·cpe:/a:redhat:openshift_container_platform:4.661 ····*·cpe:/a:redhat:openshift_container_platform:4.6
62 ····*·cpe:/a:redhat:openshift_container_platform:4.762 ····*·cpe:/a:redhat:openshift_container_platform:4.7
63 ····*·cpe:/a:redhat:openshift_container_platform:4.863 ····*·cpe:/a:redhat:openshift_container_platform:4.8
64 ····*·cpe:/a:redhat:openshift_container_platform:4.964 ····*·cpe:/a:redhat:openshift_container_platform:4.9
65 ····*·cpe:/a:redhat:openshift_container_platform:4.165 ····*·cpe:/a:redhat:openshift_container_platform:4.1
66 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*66 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
67 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8467 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
68 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)68 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
69 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*69 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
70 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s70 ···1.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
71 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y71 ·········1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8a_\x8n_\x8d_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e_\x8·_\x8I_\x8n_\x8t_\x8e_\x8g_\x8r_\x8i_\x8t_\x8y
72 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l72 ·········2.·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8-_\x8·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
73 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r73 ·········3.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8K_\x8u_\x8b_\x8e_\x8·_\x8A_\x8P_\x8I_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r
74 ·········4.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n74 ·········4.·_\x8A_\x8u_\x8t_\x8h_\x8e_\x8n_\x8t_\x8i_\x8c_\x8a_\x8t_\x8i_\x8o_\x8n
75 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s75 ·········5.·_\x8O_\x8p_\x8e_\x8n_\x8S_\x8h_\x8i_\x8f_\x8t_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l_\x8l_\x8e_\x8r_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
21.1 MB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-anssi_nt28_enhanced.html
    
Offset 14302, 16 lines modifiedOffset 14302, 16 lines modified
00037dd0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p00037dd0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p
00037de0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version00037de0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version
00037df0:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.7400037df0:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.74
00037e00:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul00037e00:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul
00037e10:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra00037e10:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra
00037e20:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····00037e20:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····
00037e30:·2020·2020·2020·2020·2020·2020·2020·2020··················00037e30:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037e40:·2861·7320·6f66·2032·3032·362d·3031·2d30··(as·of·2026-01-000037e40:·2861·7320·6f66·2032·3032·342d·3132·2d30··(as·of·2024-12-0
00037e50:·3829·0a20·2020·2020·2020·2020·2020·2020··8).·············00037e50:·3729·0a20·2020·2020·2020·2020·2020·2020··7).·············
00037e60:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d00037e60:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d
00037e70:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·00037e70:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·
00037e80:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol00037e80:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol
00037e90:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x00037e90:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x
00037ea0:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj00037ea0:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj
00037eb0:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou00037eb0:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou
00037ec0:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System00037ec0:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System
Offset 15053, 203 lines modifiedOffset 15053, 203 lines modified
0003acc0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003acc0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003acd0:·3d22·2369·646d·3536·3431·2220·7461·6269··="#idm5641"·tabi0003acd0:·3d22·2369·646d·3536·3431·2220·7461·6269··="#idm5641"·tabi
0003ace0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003ace0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003acf0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003acf0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003ad00:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003ad00:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003ad10:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003ad10:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003ad20:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003ad20:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003ad30:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu0003ad30:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
0003ad40:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...0003ad40:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
0003ad50:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003ad50:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003ad60:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003ad60:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003ad70:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003ad70:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003ad80:·2269·646d·3536·3431·223e·3c74·6162·6c65··"idm5641"><table0003ad80:·643d·2269·646d·3536·3431·223e·3c74·6162··d="idm5641"><tab
0003ad90:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003ad90:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003ada0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003ada0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003adb0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003adb0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003adc0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003adc0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003add0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003add0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003ade0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003ade0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003adf0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003adf0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
0003ae00:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003ae00:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003ae10:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003ae10:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003ae20:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t0003ae20:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
0003ae30:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>0003ae30:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003ae40:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003ae40:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003ae50:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003ae50:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003ae60:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003ae60:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003ae70:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod0003ae70:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003ae80:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a
 0003ae90:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code><
 0003aea0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003aeb0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003aec0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
0003ae80:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal 
0003ae90:·6c5f·6169·6465·0a0a·636c·6173·7320·696e··l_aide..class·in 
0003aea0:·7374·616c·6c5f·6169·6465·207b·0a20·2070··stall_aide·{.··p 
0003aeb0:·6163·6b61·6765·207b·2027·6169·6465·273a··ackage·{·'aide': 
0003aec0:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt 
0003aed0:·3b20·2769·6e73·7461·6c6c·6564·272c·0a20··;·'installed',.· 
0003aee0:·207d·0a7d·0a3c·2f63·6f64·653e·3c2f·7072···}.}.</code></pr 
0003aef0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003af00:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003af10:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003af20:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003af30:·6172·6765·743d·2223·6964·6d35·3634·3222··arget="#idm5642" 
0003af40:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003af50:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003af60:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003af70:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003af80:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003af90:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003afa0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script· 
0003afb0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003afc0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003afd0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003afe0:·6964·3d22·6964·6d35·3634·3222·3e3c·7461··id="idm5642"><ta 
0003aff0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003b000:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003b010:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003b020:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003b030:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003b040:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003b050:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b060:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003b070:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b080:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003b090:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003b0a0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b0b0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003b0c0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0003b0d0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003b0e0:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati 
0003b0f0:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable 
0003b100:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain 
0003b110:·2070·6c61·7466·6f72·6d73·0a69·6620·5b20···platforms.if·[· 
0003b120:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv 
0003b130:·205d·2026·616d·703b·2661·6d70·3b20·5b20···]·&amp;&amp;·[· 
0003b140:·2120·2d66·202f·7275·6e2f·2e63·6f6e·7461··!·-f·/run/.conta 
0003b150:·696e·6572·656e·7620·5d3b·2074·6865·6e0a··inerenv·];·then. 
0003b160:·0a69·6620·2120·7270·6d20·2d71·202d·2d71··.if·!·rpm·-q·--q 
0003b170:·7569·6574·2022·6169·6465·2220·3b20·7468··uiet·"aide"·;·th 
0003b180:·656e·0a20·2020·2079·756d·2069·6e73·7461··en.····yum·insta 
0003b190:·6c6c·202d·7920·2261·6964·6522·0a66·690a··ll·-y·"aide".fi. 
0003b1a0:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a 
0003b1b0:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed 
0003b1c0:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap 
0003b1d0:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin 
0003b1e0:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.< 
0003b1f0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003b200:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003b210:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003b220:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003b230:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003b240:·2223·6964·6d35·3634·3322·2074·6162·696e··"#idm5643"·tabin 
0003b250:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003b260:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003b270:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003b280:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003b290:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003b2a0:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans 
0003b2b0:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·... 
0003b2c0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b2d0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b2e0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003aed0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
0003b2f0:·2269·646d·3536·3433·223e·3c74·6162·6c65··"idm5643"><table 
0003b300:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003b310:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003b320:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003b330:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003b340:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
Max diff block lines reached; 20282514/20310444 bytes (99.86%) of diff not shown.
1.74 MB
html2text {}
    
Offset 43, 15 lines modifiedOffset 43, 15 lines modified
43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(enhanced)44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(enhanced)
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_nt28_enhanced45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_nt28_enhanced
46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
47 ····*·cpe:/o:oracle:linux:747 ····*·cpe:/o:oracle:linux:7
48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
49 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8449 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
55 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r55 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
56 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n56 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
57 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g57 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 115, 41 lines modifiedOffset 115, 38 lines modified
115 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3115 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
116 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5116 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
117 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199117 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
118 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029118 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029
119 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79119 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
121 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r880693_rule121 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r880693_rule
 122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 123 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 124 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 125 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 126 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 127 package·--add=aide
122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
123 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
124 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
125 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
126 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
127 include·install_aide133 include·install_aide
  
128 class·install_aide·{134 class·install_aide·{
129 ··package·{·'aide':135 ··package·{·'aide':
130 ····ensure·=>·'installed',136 ····ensure·=>·'installed',
131 ··}137 ··}
132 }138 }
 139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
138 #·Remediation·is·applicable·only·in·certain·platforms 
139 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
140 if·!·rpm·-q·--quiet·"aide"·;·then 
141 ····yum·install·-y·"aide" 
142 fi 
  
143 else 
144 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
145 fi140 [[packages]]
 141 name·=·"aide"
 142 version·=·"*"
146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
147 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low144 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
148 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low145 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
149 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false146 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
150 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable147 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
151 -·name:·Ensure·aide·is·installed148 -·name:·Ensure·aide·is·installed
152 ··package:149 ··package:
Offset 164, 26 lines modifiedOffset 161, 29 lines modified
164 ··-·PCI-DSSv4-11.5.2161 ··-·PCI-DSSv4-11.5.2
165 ··-·enable_strategy162 ··-·enable_strategy
166 ··-·low_complexity163 ··-·low_complexity
167 ··-·low_disruption164 ··-·low_disruption
168 ··-·medium_severity165 ··-·medium_severity
169 ··-·no_reboot_needed166 ··-·no_reboot_needed
170 ··-·package_aide_installed167 ··-·package_aide_installed
171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
172 [[packages]] 
173 name·=·"aide" 
174 version·=·"*" 
175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_.n_.a_.c_.o_.n_.d_.a_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
176 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
177 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
178 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
179 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 173 #·Remediation·is·applicable·only·in·certain·platforms
 174 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
180 package·--add=aide175 if·!·rpm·-q·--quiet·"aide"·;·then
 176 ····yum·install·-y·"aide"
 177 fi
  
 178 else
 179 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 180 fi
181 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*181 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
182 Run·the·following·command·to·generate·a·new·database:182 Run·the·following·command·to·generate·a·new·database:
183 $·sudo·/usr/sbin/aide·--init183 $·sudo·/usr/sbin/aide·--init
184 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the184 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
185 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these185 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
186 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their186 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
187 integrity.·The·newly-generated·database·can·be·installed·as·follows:187 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 208, 28 lines modifiedOffset 208, 14 lines modified
208 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3208 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
209 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5209 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
210 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199210 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
211 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029211 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029
212 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79212 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
213 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2213 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
214 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r880693_rule214 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r880693_rule
215 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
216 #·Remediation·is·applicable·only·in·certain·platforms 
217 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
218 if·!·rpm·-q·--quiet·"aide"·;·then 
219 ····yum·install·-y·"aide" 
220 fi 
  
221 /usr/sbin/aide·--init 
222 /bin/cp·-p·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz 
  
223 else 
224 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
225 fi 
226 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8215 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
227 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low216 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
228 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low217 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 1816661/1822389 bytes (99.69%) of diff not shown.
21.4 MB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-anssi_nt28_high.html
    
Offset 14302, 16 lines modifiedOffset 14302, 16 lines modified
00037dd0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p00037dd0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p
00037de0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version00037de0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version
00037df0:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.7400037df0:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.74
00037e00:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul00037e00:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul
00037e10:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra00037e10:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra
00037e20:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····00037e20:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····
00037e30:·2020·2020·2020·2020·2020·2020·2020·2020··················00037e30:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037e40:·2861·7320·6f66·2032·3032·362d·3031·2d30··(as·of·2026-01-000037e40:·2861·7320·6f66·2032·3032·342d·3132·2d30··(as·of·2024-12-0
00037e50:·3829·0a20·2020·2020·2020·2020·2020·2020··8).·············00037e50:·3729·0a20·2020·2020·2020·2020·2020·2020··7).·············
00037e60:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d00037e60:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d
00037e70:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·00037e70:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·
00037e80:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol00037e80:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol
00037e90:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x00037e90:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x
00037ea0:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj00037ea0:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj
00037eb0:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou00037eb0:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou
00037ec0:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System00037ec0:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System
Offset 15060, 202 lines modifiedOffset 15060, 202 lines modified
0003ad30:·6765·743d·2223·6964·6d35·3634·3122·2074··get="#idm5641"·t0003ad30:·6765·743d·2223·6964·6d35·3634·3122·2074··get="#idm5641"·t
0003ad40:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003ad40:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003ad50:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003ad50:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003ad60:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003ad60:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003ad70:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003ad70:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003ad80:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003ad80:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003ad90:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003ad90:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003ada0:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·0003ada0:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe
0003adb0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003adb0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003adc0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003adc0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003add0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003add0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003ade0:·6964·3d22·6964·6d35·3634·3122·3e3c·7461··id="idm5641"><ta0003ade0:·2220·6964·3d22·6964·6d35·3634·3122·3e3c··"·id="idm5641"><
0003adf0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0003adf0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003ae00:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0003ae00:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003ae10:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0003ae10:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003ae20:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0003ae20:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003ae30:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003ae30:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003ae40:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003ae40:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003ae50:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003ae50:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003ae60:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>0003ae60:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003ae70:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003ae70:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003ae80:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:0003ae80:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
0003ae90:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</0003ae90:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
0003aea0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003aea0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003aeb0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003aeb0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
0003aec0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t0003aec0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
0003aed0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003aed0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003aee0:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 0003aef0:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod
 0003af00:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003af10:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003af20:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
0003aee0:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins 
0003aef0:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class 
0003af00:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{. 
0003af10:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid 
0003af20:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·= 
0003af30:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed' 
0003af40:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code>< 
0003af50:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003af60:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003af70:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003af80:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003af90:·612d·7461·7267·6574·3d22·2369·646d·3536··a-target="#idm56 
0003afa0:·3432·2220·7461·6269·6e64·6578·3d22·3022··42"·tabindex="0" 
0003afb0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003afc0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003afd0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003afe0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003aff0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003b000:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
0003b010:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
0003b020:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003b030:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003b040:·6522·2069·643d·2269·646d·3536·3432·223e··e"·id="idm5642"> 
0003b050:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003b060:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003b070:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003b080:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003b090:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003b0a0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003b0b0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b0c0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003b0d0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b0e0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003b0f0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0003b100:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
0003b110:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0003b120:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0003b130:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003b140:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi 
0003b150:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica 
0003b160:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert 
0003b170:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if 
0003b180:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker 
0003b190:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp; 
0003b1a0:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co 
0003b1b0:·6e74·6169·6e65·7265·6e76·205d·3b20·7468··ntainerenv·];·th 
0003b1c0:·656e·0a0a·6966·2021·2072·706d·202d·7120··en..if·!·rpm·-q· 
0003b1d0:·2d2d·7175·6965·7420·2261·6964·6522·203b··--quiet·"aide"·; 
0003b1e0:·2074·6865·6e0a·2020·2020·7975·6d20·696e···then.····yum·in 
0003b1f0:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide". 
0003b200:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt 
0003b210:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re 
0003b220:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not 
0003b230:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not 
0003b240:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f 
0003b250:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre>< 
0003b260:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003b270:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003b280:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003b290:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003b2a0:·6574·3d22·2369·646d·3536·3433·2220·7461··et="#idm5643"·ta 
0003b2b0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003b2c0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003b2d0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003b2e0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003b2f0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003b300:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003b310:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet· 
0003b320:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003b330:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003b340:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003af30:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003af40:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003af50:·6d35·3634·3222·2074·6162·696e·6465·783d··m5642"·tabindex=
 0003af60:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003af70:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003af80:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003af90:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003afa0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
Max diff block lines reached; 20603397/20631189 bytes (99.87%) of diff not shown.
1.77 MB
html2text {}
    
Offset 43, 15 lines modifiedOffset 43, 15 lines modified
43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·ANSSI-BP-028·(high)44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·ANSSI-BP-028·(high)
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_nt28_high45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_nt28_high
46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
47 ····*·cpe:/o:oracle:linux:747 ····*·cpe:/o:oracle:linux:7
48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
49 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8449 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
55 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r55 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
56 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n56 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
57 ·········5.·_\x8K_\x8e_\x8r_\x8n_\x8e_\x8l_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n57 ·········5.·_\x8K_\x8e_\x8r_\x8n_\x8e_\x8l_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
Offset 116, 41 lines modifiedOffset 116, 38 lines modified
116 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3116 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
117 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5117 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
118 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199118 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
119 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029119 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029
120 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79120 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
121 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2121 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
122 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r880693_rule122 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r880693_rule
 123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 124 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 125 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 126 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 127 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 128 package·--add=aide
123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
124 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
125 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
126 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
127 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
128 include·install_aide134 include·install_aide
  
129 class·install_aide·{135 class·install_aide·{
130 ··package·{·'aide':136 ··package·{·'aide':
131 ····ensure·=>·'installed',137 ····ensure·=>·'installed',
132 ··}138 ··}
133 }139 }
 140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
135 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
136 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
137 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
138 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
139 #·Remediation·is·applicable·only·in·certain·platforms 
140 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
141 if·!·rpm·-q·--quiet·"aide"·;·then 
142 ····yum·install·-y·"aide" 
143 fi 
  
144 else 
145 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
146 fi141 [[packages]]
 142 name·=·"aide"
 143 version·=·"*"
147 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
148 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low145 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
149 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low146 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
150 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false147 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
151 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable148 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
152 -·name:·Ensure·aide·is·installed149 -·name:·Ensure·aide·is·installed
153 ··package:150 ··package:
Offset 165, 26 lines modifiedOffset 162, 29 lines modified
165 ··-·PCI-DSSv4-11.5.2162 ··-·PCI-DSSv4-11.5.2
166 ··-·enable_strategy163 ··-·enable_strategy
167 ··-·low_complexity164 ··-·low_complexity
168 ··-·low_disruption165 ··-·low_disruption
169 ··-·medium_severity166 ··-·medium_severity
170 ··-·no_reboot_needed167 ··-·no_reboot_needed
171 ··-·package_aide_installed168 ··-·package_aide_installed
172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
173 [[packages]] 
174 name·=·"aide" 
175 version·=·"*" 
176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_.n_.a_.c_.o_.n_.d_.a_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
177 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
178 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
179 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
180 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 174 #·Remediation·is·applicable·only·in·certain·platforms
 175 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
181 package·--add=aide176 if·!·rpm·-q·--quiet·"aide"·;·then
 177 ····yum·install·-y·"aide"
 178 fi
  
 179 else
 180 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 181 fi
182 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*182 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
183 Run·the·following·command·to·generate·a·new·database:183 Run·the·following·command·to·generate·a·new·database:
184 $·sudo·/usr/sbin/aide·--init184 $·sudo·/usr/sbin/aide·--init
185 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the185 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
186 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these186 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
187 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their187 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
188 integrity.·The·newly-generated·database·can·be·installed·as·follows:188 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 209, 28 lines modifiedOffset 209, 14 lines modified
209 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3209 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
210 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5210 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
211 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199211 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
212 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029212 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029
213 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79213 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
214 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2214 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
215 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r880693_rule215 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r880693_rule
216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
217 #·Remediation·is·applicable·only·in·certain·platforms 
218 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
219 if·!·rpm·-q·--quiet·"aide"·;·then 
220 ····yum·install·-y·"aide" 
221 fi 
  
222 /usr/sbin/aide·--init 
223 /bin/cp·-p·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz 
  
224 else 
225 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
226 fi 
227 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
228 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low217 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
229 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low218 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 1850040/1855780 bytes (99.69%) of diff not shown.
9.25 MB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-anssi_nt28_intermediary.html
    
Offset 14303, 16 lines modifiedOffset 14303, 16 lines modified
00037de0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p00037de0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p
00037df0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version00037df0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version
00037e00:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.7400037e00:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.74
00037e10:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul00037e10:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul
00037e20:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra00037e20:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra
00037e30:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····00037e30:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····
00037e40:·2020·2020·2020·2020·2020·2020·2020·2020··················00037e40:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037e50:·2861·7320·6f66·2032·3032·362d·3031·2d30··(as·of·2026-01-000037e50:·2861·7320·6f66·2032·3032·342d·3132·2d30··(as·of·2024-12-0
00037e60:·3829·0a20·2020·2020·2020·2020·2020·2020··8).·············00037e60:·3729·0a20·2020·2020·2020·2020·2020·2020··7).·············
00037e70:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d00037e70:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d
00037e80:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·00037e80:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·
00037e90:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol00037e90:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol
00037ea0:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x00037ea0:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x
00037eb0:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj00037eb0:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj
00037ec0:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou00037ec0:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou
00037ed0:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System00037ed0:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System
Offset 15044, 203 lines modifiedOffset 15044, 203 lines modified
0003ac30:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003ac30:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003ac40:·743d·2223·6964·6d35·3634·3122·2074·6162··t="#idm5641"·tab0003ac40:·743d·2223·6964·6d35·3634·3122·2074·6162··t="#idm5641"·tab
0003ac50:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003ac50:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003ac60:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003ac60:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003ac70:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003ac70:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003ac80:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003ac80:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003ac90:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003ac90:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003aca0:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P0003aca0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
0003acb0:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..0003acb0:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·
0003acc0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003acc0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003acd0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003acd0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003ace0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003ace0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003acf0:·3d22·6964·6d35·3634·3122·3e3c·7461·626c··="idm5641"><tabl0003acf0:·6964·3d22·6964·6d35·3634·3122·3e3c·7461··id="idm5641"><ta
0003ad00:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003ad00:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003ad10:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003ad10:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003ad20:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003ad20:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003ad30:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003ad30:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003ad40:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003ad40:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003ad50:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003ad50:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003ad60:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003ad60:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003ad70:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003ad70:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
0003ad80:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003ad80:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003ad90:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</0003ad90:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
0003ada0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td0003ada0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
0003adb0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St0003adb0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003adc0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003adc0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003add0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>0003add0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
0003ade0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co0003ade0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003adf0:·636f·6465·3e0a·7061·636b·6167·6520·2d2d··code>.package·--
 0003ae00:·6164·643d·6169·6465·0a3c·2f63·6f64·653e··add=aide.</code>
 0003ae10:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003ae20:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003ae30:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003ae40:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0003ae50:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm5
 0003ae60:·3634·3222·2074·6162·696e·6465·783d·2230··642"·tabindex="0
 0003ae70:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0003ae80:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0003ae90:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0003aea0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0003aeb0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003aec0:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
 0003aed0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0003aee0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003aef0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003af00:·6170·7365·2220·6964·3d22·6964·6d35·3634··apse"·id="idm564
 0003af10:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class=
 0003af20:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003af30:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0003af40:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0003af50:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0003af60:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0003af70:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003af80:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003adf0:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta 
0003ae00:·6c6c·5f61·6964·650a·0a63·6c61·7373·2069··ll_aide..class·i 
0003ae10:·6e73·7461·6c6c·5f61·6964·6520·7b0a·2020··nstall_aide·{.·· 
0003ae20:·7061·636b·6167·6520·7b20·2761·6964·6527··package·{·'aide' 
0003ae30:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g 
0003ae40:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',. 
0003ae50:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p 
0003ae60:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003ae70:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003ae80:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003ae90:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003aea0:·7461·7267·6574·3d22·2369·646d·3536·3432··target="#idm5642 
0003aeb0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003aec0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003aed0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003aee0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003aef0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003af00:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003af10:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003af20:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003af30:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003af40:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003af50:·2069·643d·2269·646d·3536·3432·223e·3c74···id="idm5642"><t 
0003af60:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003af70:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003af80:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003af90:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003afa0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003afb0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<0003af90:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003afc0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003afa0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
0003afd0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003afe0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003aff0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot0003afb0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 0003afc0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 0003afd0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0003b000:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<0003afe0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003aff0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003b000:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu
 0003b010:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide.
 0003b020:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a
 0003b030:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package·
 0003b040:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en
 0003b050:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst
 0003b060:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</
0003b010:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b020:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0003b030:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003b040:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003b050:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat 
0003b060:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl 
0003b070:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai 
0003b080:·6e20·706c·6174·666f·726d·730a·6966·205b··n·platforms.if·[ 
0003b090:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren 
0003b0a0:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[ 
0003b0b0:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont 
0003b0c0:·6169·6e65·7265·6e76·205d·3b20·7468·656e··ainerenv·];·then 
Max diff block lines reached; 8705556/8733486 bytes (99.68%) of diff not shown.
942 KB
html2text {}
    
Offset 43, 15 lines modifiedOffset 43, 15 lines modified
43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(intermediary)44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(intermediary)
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_nt28_intermediary45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_nt28_intermediary
46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
47 ····*·cpe:/o:oracle:linux:747 ····*·cpe:/o:oracle:linux:7
48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
49 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8449 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
55 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n55 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
56 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s56 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
57 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s57 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 113, 41 lines modifiedOffset 113, 38 lines modified
113 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3113 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
114 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5114 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
115 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199115 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
116 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029116 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029
117 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79117 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
118 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2118 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
119 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r880693_rule119 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r880693_rule
 120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 121 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 122 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 123 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 124 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 125 package·--add=aide
120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
121 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
122 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
123 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
124 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
125 include·install_aide131 include·install_aide
  
126 class·install_aide·{132 class·install_aide·{
127 ··package·{·'aide':133 ··package·{·'aide':
128 ····ensure·=>·'installed',134 ····ensure·=>·'installed',
129 ··}135 ··}
130 }136 }
 137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
136 #·Remediation·is·applicable·only·in·certain·platforms 
137 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
138 if·!·rpm·-q·--quiet·"aide"·;·then 
139 ····yum·install·-y·"aide" 
140 fi 
  
141 else 
142 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
143 fi138 [[packages]]
 139 name·=·"aide"
 140 version·=·"*"
144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8141 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
145 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low142 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
146 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low143 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
147 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false144 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
148 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable145 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
149 -·name:·Ensure·aide·is·installed146 -·name:·Ensure·aide·is·installed
150 ··package:147 ··package:
Offset 162, 26 lines modifiedOffset 159, 29 lines modified
162 ··-·PCI-DSSv4-11.5.2159 ··-·PCI-DSSv4-11.5.2
163 ··-·enable_strategy160 ··-·enable_strategy
164 ··-·low_complexity161 ··-·low_complexity
165 ··-·low_disruption162 ··-·low_disruption
166 ··-·medium_severity163 ··-·medium_severity
167 ··-·no_reboot_needed164 ··-·no_reboot_needed
168 ··-·package_aide_installed165 ··-·package_aide_installed
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
170 [[packages]] 
171 name·=·"aide" 
172 version·=·"*" 
173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_.n_.a_.c_.o_.n_.d_.a_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 171 #·Remediation·is·applicable·only·in·certain·platforms
 172 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
178 package·--add=aide173 if·!·rpm·-q·--quiet·"aide"·;·then
 174 ····yum·install·-y·"aide"
 175 fi
  
 176 else
 177 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 178 fi
179 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*179 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
180 Run·the·following·command·to·generate·a·new·database:180 Run·the·following·command·to·generate·a·new·database:
181 $·sudo·/usr/sbin/aide·--init181 $·sudo·/usr/sbin/aide·--init
182 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the182 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
183 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these183 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
184 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their184 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
185 integrity.·The·newly-generated·database·can·be·installed·as·follows:185 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 206, 28 lines modifiedOffset 206, 14 lines modified
206 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3206 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
207 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5207 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
208 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199208 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
209 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029209 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029
210 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79210 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
211 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2211 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
212 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r880693_rule212 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r880693_rule
213 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
214 #·Remediation·is·applicable·only·in·certain·platforms 
215 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
216 if·!·rpm·-q·--quiet·"aide"·;·then 
217 ····yum·install·-y·"aide" 
218 fi 
  
219 /usr/sbin/aide·--init 
220 /bin/cp·-p·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz 
  
221 else 
222 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
223 fi 
224 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8213 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
225 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low214 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
226 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low215 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 959071/964918 bytes (99.39%) of diff not shown.
3.39 MB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-anssi_nt28_minimal.html
    
Offset 14302, 15 lines modifiedOffset 14302, 15 lines modified
00037dd0:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur00037dd0:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur
00037de0:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s00037de0:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s
00037df0:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st00037df0:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st
00037e00:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li00037e00:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li
00037e10:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</00037e10:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</
00037e20:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········00037e20:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········
00037e30:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·00037e30:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·
00037e40:·6f66·2032·3032·362d·3031·2d30·3829·0a20··of·2026-01-08).·00037e40:·6f66·2032·3032·342d·3132·2d30·3729·0a20··of·2024-12-07).·
00037e50:·2020·2020·2020·2020·2020·2020·2020·203c·················<00037e50:·2020·2020·2020·2020·2020·2020·2020·203c·················<
00037e60:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><00037e60:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><
00037e70:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont00037e70:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont
00037e80:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li00037e80:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li
00037e90:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf00037e90:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf
00037ea0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.00037ea0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.
00037eb0:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy00037eb0:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy
Offset 14918, 203 lines modifiedOffset 14918, 203 lines modified
0003a450:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003a450:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003a460:·3130·3335·3022·2074·6162·696e·6465·783d··10350"·tabindex=0003a460:·3130·3335·3022·2074·6162·696e·6465·783d··10350"·tabindex=
0003a470:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003a470:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003a480:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003a480:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003a490:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003a490:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003a4a0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003a4a0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003a4b0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003a4b0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003a4c0:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s0003a4c0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible
0003a4d0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003a4e0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003a4f0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003a500:·6170·7365·2220·6964·3d22·6964·6d31·3033··apse"·id="idm103 
0003a510:·3530·223e·3c70·7265·3e3c·636f·6465·3e23··50"><pre><code># 
0003a520:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is· 
0003a530:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only· 
0003a540:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf 
0003a550:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu 
0003a560:·6965·7420·2d71·2079·756d·3b20·7468·656e··iet·-q·yum;·then0003a4d0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0003a4e0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003a4f0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003a500:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003a510:·3130·3335·3022·3e3c·7461·626c·6520·636c··10350"><table·cl
 0003a520:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003a530:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003a540:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003a550:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003a560:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003a570:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003a580:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003a590:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6d65··tion:</th><td>me
 0003a5a0:·6469·756d·3c2f·7464·3e3c·2f74·723e·3c74··dium</td></tr><t
 0003a5b0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 0003a5c0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
 0003a5d0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 0003a5e0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e63··ategy:</th><td>c
 0003a5f0:·6f6e·6669·6775·7265·3c2f·7464·3e3c·2f74··onfigure</td></t
 0003a600:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003a610:·636f·6465·3e2d·206e·616d·653a·2047·6174··code>-·name:·Gat
 0003a620:·6865·7220·7468·6520·7061·636b·6167·6520··her·the·package·
 0003a630:·6661·6374·730a·2020·7061·636b·6167·655f··facts.··package_
 0003a640:·6661·6374·733a·0a20·2020·206d·616e·6167··facts:.····manag
 0003a650:·6572·3a20·6175·746f·0a20·2074·6167·733a··er:·auto.··tags:
 0003a660:·0a20·202d·2043·4a49·532d·352e·3130·2e34··.··-·CJIS-5.10.4
 0003a670:·2e31·0a20·202d·2044·4953·412d·5354·4947··.1.··-·DISA-STIG
 0003a680:·2d4f·4c30·372d·3030·2d30·3230·3035·300a··-OL07-00-020050.
 0003a690:·2020·2d20·4e49·5354·2d38·3030·2d31·3731····-·NIST-800-171
 0003a6a0:·2d33·2e34·2e38·0a20·202d·204e·4953·542d··-3.4.8.··-·NIST-
 0003a6b0:·3830·302d·3533·2d43·4d2d·3131·2861·290a··800-53-CM-11(a).
 0003a6c0:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
 0003a6d0:·434d·2d31·3128·6229·0a20·202d·204e·4953··CM-11(b).··-·NIS
 0003a6e0:·542d·3830·302d·3533·2d43·4d2d·3528·3329··T-800-53-CM-5(3)
 0003a6f0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
 0003a700:·2d43·4d2d·3628·6129·0a20·202d·204e·4953··-CM-6(a).··-·NIS
 0003a710:·542d·3830·302d·3533·2d53·412d·3132·0a20··T-800-53-SA-12.·
 0003a720:·202d·204e·4953·542d·3830·302d·3533·2d53···-·NIST-800-53-S
 0003a730:·412d·3132·2831·3029·0a20·202d·204e·4953··A-12(10).··-·NIS
 0003a740:·542d·3830·302d·3533·2d53·432d·3132·0a20··T-800-53-SC-12.·
 0003a750:·202d·204e·4953·542d·3830·302d·3533·2d53···-·NIST-800-53-S
 0003a760:·432d·3132·2833·290a·2020·2d20·4e49·5354··C-12(3).··-·NIST
 0003a770:·2d38·3030·2d35·332d·5349·2d37·0a20·202d··-800-53-SI-7.··-
 0003a780:·2050·4349·2d44·5353·2d52·6571·2d36·2e32···PCI-DSS-Req-6.2
 0003a790:·0a20·202d·2050·4349·2d44·5353·7634·2d36··.··-·PCI-DSSv4-6
 0003a7a0:·2e33·2e33·0a20·202d·2063·6f6e·6669·6775··.3.3.··-·configu
 0003a7b0:·7265·5f73·7472·6174·6567·790a·2020·2d20··re_strategy.··-·
 0003a7c0:·656e·7375·7265·5f67·7067·6368·6563·6b5f··ensure_gpgcheck_
 0003a7d0:·676c·6f62·616c·6c79·5f61·6374·6976·6174··globally_activat
 0003a7e0:·6564·0a20·202d·2068·6967·685f·7365·7665··ed.··-·high_seve
 0003a7f0:·7269·7479·0a20·202d·206c·6f77·5f63·6f6d··rity.··-·low_com
 0003a800:·706c·6578·6974·790a·2020·2d20·6d65·6469··plexity.··-·medi
 0003a810:·756d·5f64·6973·7275·7074·696f·6e0a·2020··um_disruption.··
 0003a820:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need
 0003a830:·6564·0a0a·2d20·6e61·6d65·3a20·456e·7375··ed..-·name:·Ensu
 0003a840:·7265·2047·5047·2063·6865·636b·2069·7320··re·GPG·check·is·
 0003a850:·676c·6f62·616c·6c79·2061·6374·6976·6174··globally·activat
 0003a860:·6564·0a20·2069·6e69·5f66·696c·653a·0a20··ed.··ini_file:.·
 0003a870:·2020·2064·6573·743a·202f·6574·632f·7975·····dest:·/etc/yu
 0003a880:·6d2e·636f·6e66·0a20·2020·2073·6563·7469··m.conf.····secti
 0003a890:·6f6e·3a20·6d61·696e·0a20·2020·206f·7074··on:·main.····opt
 0003a8a0:·696f·6e3a·2067·7067·6368·6563·6b0a·2020··ion:·gpgcheck.··
 0003a8b0:·2020·7661·6c75·653a·2031·0a20·2020·206e····value:·1.····n
 0003a8c0:·6f5f·6578·7472·615f·7370·6163·6573·3a20··o_extra_spaces:·
 0003a8d0:·7472·7565·0a20·2020·2063·7265·6174·653a··true.····create:
 0003a8e0:·2066·616c·7365·0a20·2077·6865·6e3a·2027···false.··when:·'
 0003a8f0:·2279·756d·2220·696e·2061·6e73·6962·6c65··"yum"·in·ansible
 0003a900:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages'
 0003a910:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI
 0003a920:·532d·352e·3130·2e34·2e31·0a20·202d·2044··S-5.10.4.1.··-·D
 0003a930:·4953·412d·5354·4947·2d4f·4c30·372d·3030··ISA-STIG-OL07-00
 0003a940:·2d30·3230·3035·300a·2020·2d20·4e49·5354··-020050.··-·NIST
 0003a950:·2d38·3030·2d31·3731·2d33·2e34·2e38·0a20··-800-171-3.4.8.·
 0003a960:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C
 0003a970:·4d2d·3131·2861·290a·2020·2d20·4e49·5354··M-11(a).··-·NIST
 0003a980:·2d38·3030·2d35·332d·434d·2d31·3128·6229··-800-53-CM-11(b)
 0003a990:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
 0003a9a0:·2d43·4d2d·3528·3329·0a20·202d·204e·4953··-CM-5(3).··-·NIS
 0003a9b0:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a)
 0003a9c0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
 0003a9d0:·2d53·412d·3132·0a20·202d·204e·4953·542d··-SA-12.··-·NIST-
 0003a9e0:·3830·302d·3533·2d53·412d·3132·2831·3029··800-53-SA-12(10)
 0003a9f0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
 0003aa00:·2d53·432d·3132·0a20·202d·204e·4953·542d··-SC-12.··-·NIST-
 0003aa10:·3830·302d·3533·2d53·432d·3132·2833·290a··800-53-SC-12(3).
 0003aa20:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
 0003aa30:·5349·2d37·0a20·202d·2050·4349·2d44·5353··SI-7.··-·PCI-DSS
 0003aa40:·2d52·6571·2d36·2e32·0a20·202d·2050·4349··-Req-6.2.··-·PCI
 0003aa50:·2d44·5353·7634·2d36·2e33·2e33·0a20·202d··-DSSv4-6.3.3.··-
 0003aa60:·2063·6f6e·6669·6775·7265·5f73·7472·6174···configure_strat
 0003aa70:·6567·790a·2020·2d20·656e·7375·7265·5f67··egy.··-·ensure_g
 0003aa80:·7067·6368·6563·6b5f·676c·6f62·616c·6c79··pgcheck_globally
 0003aa90:·5f61·6374·6976·6174·6564·0a20·202d·2068··_activated.··-·h
 0003aaa0:·6967·685f·7365·7665·7269·7479·0a20·202d··igh_severity.··-
Max diff block lines reached; 3300753/3328545 bytes (99.17%) of diff not shown.
219 KB
html2text {}
    
Offset 43, 15 lines modifiedOffset 43, 15 lines modified
43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(minimal)44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(minimal)
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_nt28_minimal45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_nt28_minimal
46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
47 ····*·cpe:/o:oracle:linux:747 ····*·cpe:/o:oracle:linux:7
48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
49 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8449 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
55 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s55 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
56 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s56 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
57 ·········1.·_\x8D_\x8H_\x8C_\x8P57 ·········1.·_\x8D_\x8H_\x8C_\x8P
Offset 111, 42 lines modifiedOffset 111, 14 lines modified
111 ············_\x8o_\x8s_\x8p_\x8p···········FPT_TUD_EXT.1,·FPT_TUD_EXT.2111 ············_\x8o_\x8s_\x8p_\x8p···········FPT_TUD_EXT.1,·FPT_TUD_EXT.2
112 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-6.2112 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-6.2
113 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000366-GPOS-00153113 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000366-GPOS-00153
114 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020050114 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020050
115 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R59115 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R59
116 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········6.3.3116 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········6.3.3
117 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221710r877463_rule117 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221710r877463_rule
118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
119 #·Remediation·is·applicable·only·in·certain·platforms 
120 if·rpm·--quiet·-q·yum;·then 
  
121 #·Strip·any·search·characters·in·the·key·arg·so·that·the·key·can·be·replaced·without 
122 #·adding·any·search·characters·to·the·config·file. 
123 stripped_key=$(sed·'s/[\^=\$,;+]*//g'·<<<·"^gpgcheck") 
  
124 #·shellcheck·disable=SC2059 
125 printf·-v·formatted_output·"%s·=·%s"·"$stripped_key"·"1" 
  
126 #·If·the·key·exists,·change·it.·Otherwise,·add·it·to·the·config_file. 
127 #·We·search·for·the·key·string·followed·by·a·word·boundary·(matched·by·\>), 
128 #·so·if·we·search·for·'setting',·'setting2'·won't·match. 
129 if·LC_ALL=C·grep·-q·-m·1·-i·-e·"^gpgcheck\\>"·"/etc/yum.conf";·then 
130 ····escaped_formatted_output=$(sed·-e·'s|/|\\/|g'·<<<·"$formatted_output") 
131 ····LC_ALL=C·sed·-i·--follow-symlinks·"s/^gpgcheck\\>.*/$escaped_formatted_output/gi"·"/etc/ 
132 yum.conf" 
133 else 
134 ····if·[[·-s·"/etc/yum.conf"·]]·&&·[[·-n·"$(tail·-c·1·--·"/etc/yum.conf"·||·true)"·]];·then 
135 ········LC_ALL=C·sed·-i·--follow-symlinks·'$a'\\·"/etc/yum.conf" 
136 ····fi 
137 ····printf·'%s\n'·"$formatted_output"·>>·"/etc/yum.conf" 
138 fi 
  
139 else 
140 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
141 fi 
142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
147 -·name:·Gather·the·package·facts123 -·name:·Gather·the·package·facts
148 ··package_facts:124 ··package_facts:
Offset 199, 14 lines modifiedOffset 171, 42 lines modified
199 ··-·PCI-DSSv4-6.3.3171 ··-·PCI-DSSv4-6.3.3
200 ··-·configure_strategy172 ··-·configure_strategy
201 ··-·ensure_gpgcheck_globally_activated173 ··-·ensure_gpgcheck_globally_activated
202 ··-·high_severity174 ··-·high_severity
203 ··-·low_complexity175 ··-·low_complexity
204 ··-·medium_disruption176 ··-·medium_disruption
205 ··-·no_reboot_needed177 ··-·no_reboot_needed
 178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 179 #·Remediation·is·applicable·only·in·certain·platforms
 180 if·rpm·--quiet·-q·yum;·then
  
 181 #·Strip·any·search·characters·in·the·key·arg·so·that·the·key·can·be·replaced·without
 182 #·adding·any·search·characters·to·the·config·file.
 183 stripped_key=$(sed·'s/[\^=\$,;+]*//g'·<<<·"^gpgcheck")
  
 184 #·shellcheck·disable=SC2059
 185 printf·-v·formatted_output·"%s·=·%s"·"$stripped_key"·"1"
  
 186 #·If·the·key·exists,·change·it.·Otherwise,·add·it·to·the·config_file.
 187 #·We·search·for·the·key·string·followed·by·a·word·boundary·(matched·by·\>),
 188 #·so·if·we·search·for·'setting',·'setting2'·won't·match.
 189 if·LC_ALL=C·grep·-q·-m·1·-i·-e·"^gpgcheck\\>"·"/etc/yum.conf";·then
 190 ····escaped_formatted_output=$(sed·-e·'s|/|\\/|g'·<<<·"$formatted_output")
 191 ····LC_ALL=C·sed·-i·--follow-symlinks·"s/^gpgcheck\\>.*/$escaped_formatted_output/gi"·"/etc/
 192 yum.conf"
 193 else
 194 ····if·[[·-s·"/etc/yum.conf"·]]·&&·[[·-n·"$(tail·-c·1·--·"/etc/yum.conf"·||·true)"·]];·then
 195 ········LC_ALL=C·sed·-i·--follow-symlinks·'$a'\\·"/etc/yum.conf"
 196 ····fi
 197 ····printf·'%s\n'·"$formatted_output"·>>·"/etc/yum.conf"
 198 fi
  
 199 else
 200 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 201 fi
206 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·g\x8gp\x8pg\x8gc\x8ch\x8he\x8ec\x8ck\x8k·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·f\x8fo\x8or\x8r·L\x8Lo\x8oc\x8ca\x8al\x8l·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*202 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·g\x8gp\x8pg\x8gc\x8ch\x8he\x8ec\x8ck\x8k·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·f\x8fo\x8or\x8r·L\x8Lo\x8oc\x8ca\x8al\x8l·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
207 yum·should·be·configured·to·verify·the·signature(s)·of·local·packages·prior·to·installation.203 yum·should·be·configured·to·verify·the·signature(s)·of·local·packages·prior·to·installation.
208 To·configure·yum·to·verify·signatures·of·local·packages,·set·the·localpkg_gpgcheck·to·1·in·/204 To·configure·yum·to·verify·signatures·of·local·packages,·set·the·localpkg_gpgcheck·to·1·in·/
209 etc/yum.conf.205 etc/yum.conf.
210 ············Changes·to·any·software·components·can·have·significant·effects·to·the·overall206 ············Changes·to·any·software·components·can·have·significant·effects·to·the·overall
211 ············security·of·the·operating·system.·This·requirement·ensures·the·software·has·not207 ············security·of·the·operating·system.·This·requirement·ensures·the·software·has·not
212 ············been·tampered·and·has·been·provided·by·a·trusted·vendor.208 ············been·tampered·and·has·been·provided·by·a·trusted·vendor.
Offset 228, 42 lines modifiedOffset 228, 14 lines modified
228 ············_\x8n_\x8i_\x8s_\x8t···········CM-11(a),·CM-11(b),·CM-6(a),·CM-5(3),·SA-12,·SA-12(10)228 ············_\x8n_\x8i_\x8s_\x8t···········CM-11(a),·CM-11(b),·CM-6(a),·CM-5(3),·SA-12,·SA-12(10)
229 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1229 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1
230 ············_\x8o_\x8s_\x8p_\x8p···········FPT_TUD_EXT.1,·FPT_TUD_EXT.2230 ············_\x8o_\x8s_\x8p_\x8p···········FPT_TUD_EXT.1,·FPT_TUD_EXT.2
231 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000366-GPOS-00153231 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000366-GPOS-00153
232 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020060232 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020060
233 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R59233 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R59
234 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221711r877463_rule234 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221711r877463_rule
235 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
236 #·Remediation·is·applicable·only·in·certain·platforms 
237 if·rpm·--quiet·-q·yum;·then 
  
238 #·Strip·any·search·characters·in·the·key·arg·so·that·the·key·can·be·replaced·without 
239 #·adding·any·search·characters·to·the·config·file. 
240 stripped_key=$(sed·'s/[\^=\$,;+]*//g'·<<<·"^localpkg_gpgcheck") 
  
241 #·shellcheck·disable=SC2059 
242 printf·-v·formatted_output·"%s·=·%s"·"$stripped_key"·"1" 
  
243 #·If·the·key·exists,·change·it.·Otherwise,·add·it·to·the·config_file. 
244 #·We·search·for·the·key·string·followed·by·a·word·boundary·(matched·by·\>), 
245 #·so·if·we·search·for·'setting',·'setting2'·won't·match. 
246 if·LC_ALL=C·grep·-q·-m·1·-i·-e·"^localpkg_gpgcheck\\>"·"/etc/yum.conf";·then 
247 ····escaped_formatted_output=$(sed·-e·'s|/|\\/|g'·<<<·"$formatted_output") 
248 ····LC_ALL=C·sed·-i·--follow-symlinks·"s/^localpkg_gpgcheck\\>.*/$escaped_formatted_output/ 
249 gi"·"/etc/yum.conf" 
Max diff block lines reached; 217086/223899 bytes (96.96%) of diff not shown.
9.01 MB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-cjis.html
    
Offset 14290, 15 lines modifiedOffset 14290, 15 lines modified
00037d10:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current00037d10:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current
00037d20:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron00037d20:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron
00037d30:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong00037d30:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong
00037d40:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st00037d40:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st
00037d50:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro00037d50:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro
00037d60:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············00037d60:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············
00037d70:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·200037d70:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·2
00037d80:·3032·362d·3031·2d30·3829·0a20·2020·2020··026-01-08).·····00037d80:·3032·342d·3132·2d30·3729·0a20·2020·2020··024-12-07).·····
00037d90:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>00037d90:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>
00037da0:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T00037da0:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T
00037db0:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents00037db0:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents
00037dc0:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·00037dc0:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·
00037dd0:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org00037dd0:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org
00037de0:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont00037de0:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont
00037df0:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system00037df0:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system
Offset 15122, 310 lines modifiedOffset 15122, 310 lines modified
0003b110:·2d74·6172·6765·743d·2223·6964·6d35·3239··-target="#idm5290003b110:·2d74·6172·6765·743d·2223·6964·6d35·3239··-target="#idm529
0003b120:·3922·2074·6162·696e·6465·783d·2230·2220··9"·tabindex="0"·0003b120:·3922·2074·6162·696e·6465·783d·2230·2220··9"·tabindex="0"·
0003b130:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003b130:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003b140:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003b140:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003b150:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003b150:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003b160:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003b160:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003b170:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003b170:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003b180:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
0003b190:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003b1a0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003b1b0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003b1c0:·2220·6964·3d22·6964·6d35·3239·3922·3e3c··"·id="idm5299">< 
0003b1d0:·7072·653e·3c63·6f64·653e·0a23·2046·696e··pre><code>.#·Fin 
0003b1e0:·6420·7768·6963·6820·6669·6c65·7320·6861··d·which·files·ha 
0003b1f0:·7665·2069·6e63·6f72·7265·6374·2068·6173··ve·incorrect·has 
0003b200:·6820·286e·6f74·2069·6e20·2f65·7463·2c20··h·(not·in·/etc,· 
0003b210:·6265·6361·7573·6520·6f66·2074·6865·2073··because·of·the·s 
0003b220:·7973·7465·6d20·7265·6c61·7465·6420·636f··ystem·related·co 
0003b230:·6e66·6967·2066·696c·6573·2920·616e·6420··nfig·files)·and· 
0003b240:·7468·656e·2067·6574·2066·696c·6573·206e··then·get·files·n 
0003b250:·616d·6573·0a66·696c·6573·5f77·6974·685f··ames.files_with_ 
0003b260:·696e·636f·7272·6563·745f·6861·7368·3d22··incorrect_hash=" 
0003b270:·2428·7270·6d20·2d56·6120·2d2d·6e6f·636f··$(rpm·-Va·--noco 
0003b280:·6e66·6967·207c·2067·7265·7020·2d45·2027··nfig·|·grep·-E·' 
0003b290:·5e2e·2e35·2720·7c20·6177·6b20·277b·7072··^..5'·|·awk·'{pr 
0003b2a0:·696e·7420·244e·467d·2720·2922·0a0a·6966··int·$NF}'·)"..if 
0003b2b0:·205b·202d·6e20·2224·6669·6c65·735f·7769···[·-n·"$files_wi 
0003b2c0:·7468·5f69·6e63·6f72·7265·6374·5f68·6173··th_incorrect_has 
0003b2d0:·6822·205d·3b20·7468·656e·0a20·2020·2023··h"·];·then.····# 
0003b2e0:·2046·726f·6d20·6669·6c65·7320·6e61·6d65···From·files·name 
0003b2f0:·7320·6765·7420·7061·636b·6167·6520·6e61··s·get·package·na 
0003b300:·6d65·7320·616e·6420·6368·616e·6765·206e··mes·and·change·n 
0003b310:·6577·6c69·6e65·2074·6f20·7370·6163·652c··ewline·to·space, 
0003b320:·2062·6563·6175·7365·2072·706d·2077·7269···because·rpm·wri 
0003b330:·7465·7320·6561·6368·2070·6163·6b61·6765··tes·each·package 
0003b340:·2074·6f20·6e65·7720·6c69·6e65·0a20·2020···to·new·line.··· 
0003b350:·2070·6163·6b61·6765·735f·746f·5f72·6569···packages_to_rei 
0003b360:·6e73·7461·6c6c·3d22·2428·7270·6d20·2d71··nstall="$(rpm·-q 
0003b370:·6620·2466·696c·6573·5f77·6974·685f·696e··f·$files_with_in 
0003b380:·636f·7272·6563·745f·6861·7368·207c·2074··correct_hash·|·t 
0003b390:·7220·275c·6e27·2027·2027·2922·0a0a·2020··r·'\n'·'·')"..·· 
0003b3a0:·2020·0a20·2020·2079·756d·2072·6569·6e73····.····yum·reins 
0003b3b0:·7461·6c6c·202d·7920·2470·6163·6b61·6765··tall·-y·$package 
0003b3c0:·735f·746f·5f72·6569·6e73·7461·6c6c·0a20··s_to_reinstall.· 
0003b3d0:·2020·200a·6669·0a3c·2f63·6f64·653e·3c2f·····.fi.</code></ 
0003b3e0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003b3f0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003b400:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003b410:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003b420:·2d74·6172·6765·743d·2223·6964·6d35·3330··-target="#idm530 
0003b430:·3022·2074·6162·696e·6465·783d·2230·2220··0"·tabindex="0"· 
0003b440:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003b450:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003b460:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003b470:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003b480:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003b490:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni0003b180:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni
0003b4a0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003b190:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003b4b0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003b1a0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003b4c0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003b1b0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003b4d0:·7073·6522·2069·643d·2269·646d·3533·3030··pse"·id="idm53000003b1c0:·7073·6522·2069·643d·2269·646d·3532·3939··pse"·id="idm5299
0003b4e0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003b1d0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003b4f0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003b1e0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003b500:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003b1f0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003b510:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003b200:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003b520:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003b210:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003b530:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003b220:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003b540:·6869·6768·3c2f·7464·3e3c·2f74·723e·3c74··high</td></tr><t0003b230:·6869·6768·3c2f·7464·3e3c·2f74·723e·3c74··high</td></tr><t
0003b550:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003b240:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003b560:·3a3c·2f74·683e·3c74·643e·6d65·6469·756d··:</th><td>medium0003b250:·3a3c·2f74·683e·3c74·643e·6d65·6469·756d··:</th><td>medium
0003b570:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003b260:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003b580:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t0003b270:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
0003b590:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr0003b280:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
0003b5a0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0003b290:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
0003b5b0:·793a·3c2f·7468·3e3c·7464·3e72·6573·7472··y:</th><td>restr0003b2a0:·793a·3c2f·7468·3e3c·7464·3e72·6573·7472··y:</th><td>restr
0003b5c0:·6963·743c·2f74·643e·3c2f·7472·3e3c·2f74··ict</td></tr></t0003b2b0:·6963·743c·2f74·643e·3c2f·7472·3e3c·2f74··ict</td></tr></t
0003b5d0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003b2c0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
0003b5e0:·2d20·6e61·6d65·3a20·2753·6574·2066·6163··-·name:·'Set·fac0003b2d0:·2d20·6e61·6d65·3a20·2753·6574·2066·6163··-·name:·'Set·fac
0003b5f0:·743a·2050·6163·6b61·6765·206d·616e·6167··t:·Package·manag0003b2e0:·743a·2050·6163·6b61·6765·206d·616e·6167··t:·Package·manag
0003b600:·6572·2072·6569·6e73·7461·6c6c·2063·6f6d··er·reinstall·com0003b2f0:·6572·2072·6569·6e73·7461·6c6c·2063·6f6d··er·reinstall·com
0003b610:·6d61·6e64·270a·2020·7365·745f·6661·6374··mand'.··set_fact0003b300:·6d61·6e64·270a·2020·7365·745f·6661·6374··mand'.··set_fact
0003b620:·3a0a·2020·2020·7061·636b·6167·655f·6d61··:.····package_ma0003b310:·3a0a·2020·2020·7061·636b·6167·655f·6d61··:.····package_ma
0003b630:·6e61·6765·725f·7265·696e·7374·616c·6c5f··nager_reinstall_0003b320:·6e61·6765·725f·7265·696e·7374·616c·6c5f··nager_reinstall_
0003b640:·636d·643a·2079·756d·2072·6569·6e73·7461··cmd:·yum·reinsta0003b330:·636d·643a·2079·756d·2072·6569·6e73·7461··cmd:·yum·reinsta
0003b650:·6c6c·202d·790a·2020·7768·656e·3a20·616e··ll·-y.··when:·an0003b340:·6c6c·202d·790a·2020·7768·656e·3a20·616e··ll·-y.··when:·an
0003b660:·7369·626c·655f·6469·7374·7269·6275·7469··sible_distributi0003b350:·7369·626c·655f·6469·7374·7269·6275·7469··sible_distributi
0003b670:·6f6e·2069·6e20·5b20·2246·6564·6f72·6122··on·in·[·"Fedora"0003b360:·6f6e·2069·6e20·5b20·2246·6564·6f72·6122··on·in·[·"Fedora"
0003b680:·2c20·2252·6564·4861·7422·2c20·2243·656e··,·"RedHat",·"Cen0003b370:·2c20·2252·6564·4861·7422·2c20·2243·656e··,·"RedHat",·"Cen
0003b690:·744f·5322·2c20·224f·7261·636c·654c·696e··tOS",·"OracleLin0003b380:·744f·5322·2c20·224f·7261·636c·654c·696e··tOS",·"OracleLin
0003b6a0:·7578·2220·5d0a·2020·7461·6773·3a0a·2020··ux"·].··tags:.··0003b390:·7578·2220·5d0a·2020·7461·6773·3a0a·2020··ux"·].··tags:.··
0003b6b0:·2d20·434a·4953·2d35·2e31·302e·342e·310a··-·CJIS-5.10.4.1.0003b3a0:·2d20·434a·4953·2d35·2e31·302e·342e·310a··-·CJIS-5.10.4.1.
0003b6c0:·2020·2d20·4449·5341·2d53·5449·472d·4f4c····-·DISA-STIG-OL0003b3b0:·2020·2d20·4449·5341·2d53·5449·472d·4f4c····-·DISA-STIG-OL
0003b6d0:·3037·2d30·302d·3031·3030·3230·0a20·202d··07-00-010020.··-0003b3c0:·3037·2d30·302d·3031·3030·3230·0a20·202d··07-00-010020.··-
0003b6e0:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.0003b3d0:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.
0003b6f0:·332e·380a·2020·2d20·4e49·5354·2d38·3030··3.8.··-·NIST-8000003b3e0:·332e·380a·2020·2d20·4e49·5354·2d38·3030··3.8.··-·NIST-800
0003b700:·2d31·3731·2d33·2e34·2e31·0a20·202d·204e··-171-3.4.1.··-·N0003b3f0:·2d31·3731·2d33·2e34·2e31·0a20·202d·204e··-171-3.4.1.··-·N
0003b710:·4953·542d·3830·302d·3533·2d41·552d·3928··IST-800-53-AU-9(0003b400:·4953·542d·3830·302d·3533·2d41·552d·3928··IST-800-53-AU-9(
0003b720:·3329·0a20·202d·204e·4953·542d·3830·302d··3).··-·NIST-800-0003b410:·3329·0a20·202d·204e·4953·542d·3830·302d··3).··-·NIST-800-
0003b730:·3533·2d43·4d2d·3628·6329·0a20·202d·204e··53-CM-6(c).··-·N0003b420:·3533·2d43·4d2d·3628·6329·0a20·202d·204e··53-CM-6(c).··-·N
0003b740:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6(0003b430:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6(
0003b750:·6429·0a20·202d·204e·4953·542d·3830·302d··d).··-·NIST-800-0003b440:·6429·0a20·202d·204e·4953·542d·3830·302d··d).··-·NIST-800-
0003b760:·3533·2d53·492d·370a·2020·2d20·4e49·5354··53-SI-7.··-·NIST0003b450:·3533·2d53·492d·370a·2020·2d20·4e49·5354··53-SI-7.··-·NIST
0003b770:·2d38·3030·2d35·332d·5349·2d37·2831·290a··-800-53-SI-7(1).0003b460:·2d38·3030·2d35·332d·5349·2d37·2831·290a··-800-53-SI-7(1).
0003b780:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-0003b470:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
0003b790:·5349·2d37·2836·290a·2020·2d20·5043·492d··SI-7(6).··-·PCI-0003b480:·5349·2d37·2836·290a·2020·2d20·5043·492d··SI-7(6).··-·PCI-
0003b7a0:·4453·532d·5265·712d·3131·2e35·0a20·202d··DSS-Req-11.5.··-0003b490:·4453·532d·5265·712d·3131·2e35·0a20·202d··DSS-Req-11.5.··-
0003b7b0:·2050·4349·2d44·5353·7634·2d31·312e·352e···PCI-DSSv4-11.5.0003b4a0:·2050·4349·2d44·5353·7634·2d31·312e·352e···PCI-DSSv4-11.5.
0003b7c0:·320a·2020·2d20·6869·6768·5f63·6f6d·706c··2.··-·high_compl0003b4b0:·320a·2020·2d20·6869·6768·5f63·6f6d·706c··2.··-·high_compl
0003b7d0:·6578·6974·790a·2020·2d20·6869·6768·5f73··exity.··-·high_s0003b4c0:·6578·6974·790a·2020·2d20·6869·6768·5f73··exity.··-·high_s
0003b7e0:·6576·6572·6974·790a·2020·2d20·6d65·6469··everity.··-·medi0003b4d0:·6576·6572·6974·790a·2020·2d20·6d65·6469··everity.··-·medi
0003b7f0:·756d·5f64·6973·7275·7074·696f·6e0a·2020··um_disruption.··0003b4e0:·756d·5f64·6973·7275·7074·696f·6e0a·2020··um_disruption.··
Max diff block lines reached; 8576154/8595252 bytes (99.78%) of diff not shown.
833 KB
html2text {}
    
Offset 40, 15 lines modifiedOffset 40, 15 lines modified
40 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*40 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Criminal·Justice·Information·Services·(CJIS)·Security·Policy41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Criminal·Justice·Information·Services·(CJIS)·Security·Policy
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cjis42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cjis
43 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*43 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
44 ····*·cpe:/o:oracle:linux:744 ····*·cpe:/o:oracle:linux:7
45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
46 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8446 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
50 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e50 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
51 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l51 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
52 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n52 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
53 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s53 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
54 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s54 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 98, 27 lines modifiedOffset 98, 14 lines modified
98 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)98 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
99 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-199 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
100 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5100 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
101 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227101 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
102 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010020102 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010020
103 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2103 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
104 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221653r853660_rule104 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221653r853660_rule
105 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
106 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
107 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
108 if·[·-n·"$files_with_incorrect_hash"·];·then 
109 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
110 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
111 ····yum·reinstall·-y·$packages_to_reinstall 
  
112 fi 
113 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8105 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
114 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high106 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
115 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium107 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
116 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false108 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
117 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict109 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
118 -·name:·'Set·fact:·Package·manager·reinstall·command'110 -·name:·'Set·fact:·Package·manager·reinstall·command'
119 ··set_fact:111 ··set_fact:
Offset 250, 14 lines modifiedOffset 237, 27 lines modified
250 ··-·PCI-DSSv4-11.5.2237 ··-·PCI-DSSv4-11.5.2
251 ··-·high_complexity238 ··-·high_complexity
252 ··-·high_severity239 ··-·high_severity
253 ··-·medium_disruption240 ··-·medium_disruption
254 ··-·no_reboot_needed241 ··-·no_reboot_needed
255 ··-·restrict_strategy242 ··-·restrict_strategy
256 ··-·rpm_verify_hashes243 ··-·rpm_verify_hashes
 244 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 245 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 246 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 247 if·[·-n·"$files_with_incorrect_hash"·];·then
 248 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 249 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 250 ····yum·reinstall·-y·$packages_to_reinstall
  
 251 fi
257 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*252 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
258 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:253 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:
259 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'254 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'
260 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:255 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:
261 $·rpm·-qf·FILENAME256 $·rpm·-qf·FILENAME
  
262 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:257 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
Offset 280, 44 lines modifiedOffset 280, 14 lines modified
280 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)280 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)
281 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1281 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
282 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5282 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
283 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108283 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108
284 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010010284 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010010
285 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2285 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
286 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221652r880585_rule286 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221652r880585_rule
287 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
288 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
289 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
290 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
291 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
292 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
293 declare·-A·SETPERMS_RPM_DICT 
  
294 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
295 #·is·expected·by·the·RPM·database 
296 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}') 
  
297 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
298 do 
299 ········#·NOTE:·some·files·maybe·controlled·by·more·then·one·package 
300 ········readarray·-t·RPM_PACKAGES·<·<(rpm·-qf·"${FILE_PATH}") 
301 ········for·RPM_PACKAGE·in·"${RPM_PACKAGES[@]}" 
302 ········do 
303 ················#·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
304 ················SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
305 ········done 
306 done 
  
307 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
308 #·correct·values 
309 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
310 do 
311 »       rpm·--restore·"${RPM_PACKAGE}" 
312 done 
313 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8287 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
314 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high288 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
315 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium289 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
316 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false290 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
317 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict291 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
318 -·name:·Read·list·of·files·with·incorrect·permissions292 -·name:·Read·list·of·files·with·incorrect·permissions
319 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev293 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 398, 14 lines modifiedOffset 368, 44 lines modified
398 ··-·PCI-DSSv4-11.5.2368 ··-·PCI-DSSv4-11.5.2
399 ··-·high_complexity369 ··-·high_complexity
400 ··-·high_severity370 ··-·high_severity
401 ··-·medium_disruption371 ··-·medium_disruption
402 ··-·no_reboot_needed372 ··-·no_reboot_needed
403 ··-·restrict_strategy373 ··-·restrict_strategy
404 ··-·rpm_verify_permissions374 ··-·rpm_verify_permissions
 375 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 376 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 377 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
Max diff block lines reached; 845634/853421 bytes (99.09%) of diff not shown.
6.27 MB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-cui.html
    
Offset 14330, 15 lines modifiedOffset 14330, 15 lines modified
00037f90:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·00037f90:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·
00037fa0:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong00037fa0:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong
00037fb0:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>00037fb0:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>
00037fc0:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str00037fc0:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str
00037fd0:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron00037fd0:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron
00037fe0:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············00037fe0:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············
00037ff0:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·2000037ff0:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·20
00038000:·3236·2d30·312d·3038·290a·2020·2020·2020··26-01-08).······00038000:·3234·2d31·322d·3037·290a·2020·2020·2020··24-12-07).······
00038010:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><00038010:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><
00038020:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta00038020:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta
00038030:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<00038030:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<
00038040:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h00038040:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h
00038050:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.00038050:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.
00038060:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte00038060:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte
00038070:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"00038070:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"
Offset 15073, 232 lines modifiedOffset 15073, 232 lines modified
0003ae00:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003ae00:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003ae10:·3d22·2369·646d·3631·3732·2220·7461·6269··="#idm6172"·tabi0003ae10:·3d22·2369·646d·3631·3732·2220·7461·6269··="#idm6172"·tabi
0003ae20:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003ae20:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003ae30:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003ae30:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003ae40:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003ae40:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003ae50:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003ae50:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003ae60:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003ae60:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003ae70:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu0003ae70:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
0003ae80:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...0003ae80:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
0003ae90:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003ae90:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003aea0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003aea0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003aeb0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003aeb0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003aec0:·2269·646d·3631·3732·223e·3c74·6162·6c65··"idm6172"><table0003aec0:·643d·2269·646d·3631·3732·223e·3c74·6162··d="idm6172"><tab
0003aed0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003aed0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003aee0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003aee0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003aef0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003aef0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003af00:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003af00:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003af10:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003af10:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003af20:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003af20:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003af30:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003af30:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
0003af40:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003af40:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003af50:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003af50:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003af60:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t0003af60:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
0003af70:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>0003af70:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003af80:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003af80:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003af90:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003af90:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003afa0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003afa0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003afb0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod0003afb0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003afc0:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a
 0003afd0:·6464·3d64·7261·6375·742d·6669·7073·0a3c··dd=dracut-fips.<
 0003afe0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003aff0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003b000:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003b010:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0003b020:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003b030:·2223·6964·6d36·3137·3322·2074·6162·696e··"#idm6173"·tabin
 0003b040:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003b050:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003b060:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003b070:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003b080:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003b090:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
 0003b0a0:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
 0003b0b0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003b0c0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003b0d0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003b0e0:·6964·6d36·3137·3322·3e3c·7461·626c·6520··idm6173"><table·
 0003b0f0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003b100:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003b110:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003b120:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003b130:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003b140:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003b150:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003afc0:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal 
0003afd0:·6c5f·6472·6163·7574·2d66·6970·730a·0a63··l_dracut-fips..c 
0003afe0:·6c61·7373·2069·6e73·7461·6c6c·5f64·7261··lass·install_dra 
0003aff0:·6375·742d·6669·7073·207b·0a20·2070·6163··cut-fips·{.··pac 
0003b000:·6b61·6765·207b·2027·6472·6163·7574·2d66··kage·{·'dracut-f 
0003b010:·6970·7327·3a0a·2020·2020·656e·7375·7265··ips':.····ensure 
0003b020:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe 
0003b030:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code 
0003b040:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003b050:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003b060:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003b070:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003b080:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003b090:·3631·3733·2220·7461·6269·6e64·6578·3d22··6173"·tabindex=" 
0003b0a0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003b0b0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003b0c0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003b0d0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003b0e0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003b0f0:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003b100:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003b110:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003b120:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003b130:·7073·6522·2069·643d·2269·646d·3631·3733··pse"·id="idm6173 
0003b140:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003b150:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003b160:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003b170:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003b180:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003b190:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003b160:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003b1a0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003b170:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003b1b0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003b1c0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003b180:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 0003b190:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
0003b1d0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003b1a0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
0003b1e0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003b1b0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
 0003b1c0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 0003b1d0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003b1e0:·3e69·6e63·6c75·6465·2069·6e73·7461·6c6c··>include·install
 0003b1f0:·5f64·7261·6375·742d·6669·7073·0a0a·636c··_dracut-fips..cl
 0003b200:·6173·7320·696e·7374·616c·6c5f·6472·6163··ass·install_drac
 0003b210:·7574·2d66·6970·7320·7b0a·2020·7061·636b··ut-fips·{.··pack
 0003b220:·6167·6520·7b20·2764·7261·6375·742d·6669··age·{·'dracut-fi
 0003b230:·7073·273a·0a20·2020·2065·6e73·7572·6520··ps':.····ensure·
 0003b240:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
 0003b250:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
0003b1f0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
0003b200:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003b210:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003b220:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003b230:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme 
0003b240:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
0003b250:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
0003b260:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
0003b270:·6966·2028·205b·2021·202d·6620·2f2e·646f··if·(·[·!·-f·/.do 
0003b280:·636b·6572·656e·7620·5d20·2661·6d70·3b26··ckerenv·]·&amp;& 
0003b290:·616d·703b·205b·2021·202d·6620·2f72·756e··amp;·[·!·-f·/run 
Max diff block lines reached; 5849286/5881080 bytes (99.46%) of diff not shown.
676 KB
html2text {}
    
Offset 50, 15 lines modifiedOffset 50, 15 lines modified
50 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Unclassified·Information·in·Non-federal·Information·Systems·and50 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Unclassified·Information·in·Non-federal·Information·Systems·and
51 ··············Organizations·(NIST·800-171)51 ··············Organizations·(NIST·800-171)
52 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cui52 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cui
53 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*53 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
54 ····*·cpe:/o:oracle:linux:754 ····*·cpe:/o:oracle:linux:7
55 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*55 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
56 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8456 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
57 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)57 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
58 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*58 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
59 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s59 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
60 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e60 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
61 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l61 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
62 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n62 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
63 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s63 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
64 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s64 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 99, 41 lines modifiedOffset 99, 38 lines modified
99 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.6.699 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.6.6
100 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.13,·SR·2.6,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6100 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.13,·SR·2.6,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
101 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2101 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2
102 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-007-3·R5.1102 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-007-3·R5.1
103 ············_\x8n_\x8i_\x8s_\x8t···········SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12103 ············_\x8n_\x8i_\x8s_\x8t···········SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
104 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.PT-4104 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.PT-4
105 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-00223105 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-00223
 106 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 107 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 108 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 109 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 110 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 111 package·--add=dracut-fips
106 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
107 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low113 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
108 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low114 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
109 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false115 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
110 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable116 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
111 include·install_dracut-fips117 include·install_dracut-fips
  
112 class·install_dracut-fips·{118 class·install_dracut-fips·{
113 ··package·{·'dracut-fips':119 ··package·{·'dracut-fips':
114 ····ensure·=>·'installed',120 ····ensure·=>·'installed',
115 ··}121 ··}
116 }122 }
 123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
117 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
118 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
119 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
120 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
121 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
122 #·Remediation·is·applicable·only·in·certain·platforms 
123 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·)·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then 
  
124 if·!·rpm·-q·--quiet·"dracut-fips"·;·then 
125 ····yum·install·-y·"dracut-fips" 
126 fi 
  
127 else 
128 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
129 fi124 [[packages]]
 125 name·=·"dracut-fips"
 126 version·=·"*"
130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
135 -·name:·Ensure·dracut-fips·is·installed132 -·name:·Ensure·dracut-fips·is·installed
136 ··package:133 ··package:
Offset 155, 26 lines modifiedOffset 152, 29 lines modified
155 ··-·NIST-800-53-SC-13152 ··-·NIST-800-53-SC-13
156 ··-·enable_strategy153 ··-·enable_strategy
157 ··-·low_complexity154 ··-·low_complexity
158 ··-·low_disruption155 ··-·low_disruption
159 ··-·medium_severity156 ··-·medium_severity
160 ··-·no_reboot_needed157 ··-·no_reboot_needed
161 ··-·package_dracut-fips_installed158 ··-·package_dracut-fips_installed
162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
163 [[packages]] 
164 name·=·"dracut-fips" 
165 version·=·"*" 
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_.n_.a_.c_.o_.n_.d_.a_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low160 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low161 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false162 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable163 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 164 #·Remediation·is·applicable·only·in·certain·platforms
 165 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·)·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
171 package·--add=dracut-fips166 if·!·rpm·-q·--quiet·"dracut-fips"·;·then
 167 ····yum·install·-y·"dracut-fips"
 168 fi
  
 169 else
 170 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 171 fi
172 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·i\x8in\x8n·G\x8GR\x8RU\x8UB\x8B2\x82·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*172 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·i\x8in\x8n·G\x8GR\x8RU\x8UB\x8B2\x82·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
173 To·ensure·FIPS·mode·is·enabled,·install·package·dracut-fips,·and·rebuild·initramfs·by·running·the·following·commands:173 To·ensure·FIPS·mode·is·enabled,·install·package·dracut-fips,·and·rebuild·initramfs·by·running·the·following·commands:
174 $·sudo·yum·install·dracut-fips174 $·sudo·yum·install·dracut-fips
175 dracut·-f175 dracut·-f
176 After·the·dracut·command·has·been·run,·add·the·argument·fips=1·to·the·default·GRUB·2·command·line·for·the·Linux·operating·system·in·/etc/default/grub,·in·the·manner·below:176 After·the·dracut·command·has·been·run,·add·the·argument·fips=1·to·the·default·GRUB·2·command·line·for·the·Linux·operating·system·in·/etc/default/grub,·in·the·manner·below:
177 GRUB_CMDLINE_LINUX="crashkernel=auto·rd.lvm.lv=VolGroup/LogVol06·rd.lvm.lv=VolGroup/lv_swap·rhgb·quiet·rd.shell=0·fips=1"177 GRUB_CMDLINE_LINUX="crashkernel=auto·rd.lvm.lv=VolGroup/LogVol06·rd.lvm.lv=VolGroup/lv_swap·rhgb·quiet·rd.shell=0·fips=1"
178 Finally,·rebuild·the·grub.cfg·file·by·using·the178 Finally,·rebuild·the·grub.cfg·file·by·using·the
Offset 202, 80 lines modifiedOffset 202, 17 lines modified
202 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2202 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2
203 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-007-3·R5.1203 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-007-3·R5.1
204 ············_\x8n_\x8i_\x8s_\x8t···········SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12204 ············_\x8n_\x8i_\x8s_\x8t···········SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
205 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.PT-4205 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.PT-4
206 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223206 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223
207 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-021350207 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-021350
208 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221758r877398_rule208 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221758r877398_rule
209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_.n_.a_.c_.o_.n_.d_.a_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
210 #·Remediation·is·applicable·only·in·certain·platforms 
211 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·)·&&·{·rpm·--quiet·-q·grub2-common;·};·then 
  
212 #·prelink·not·installed 
213 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then 
214 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink 
215 ····then 
216 ········sed·-i·'s/^PRELINKING[:blank:]*=[:blank:]*[:alpha:]*/PRELINKING=no/'·/etc/sysconfig/prelink 
217 ····else 
218 ········printf·'\n'·>>·/etc/sysconfig/prelink 
219 ········printf·'%s\n'·'#·Set·PRELINKING=no·per·security·requirements'·'PRELINKING=no'·>>·/etc/sysconfig/prelink 
220 ····fi 
  
221 ····#·Undo·previous·prelink·changes·to·binaries·if·prelink·is·available. 
222 ····if·test·-x·/usr/sbin/prelink;·then 
223 ········/usr/sbin/prelink·-ua 
Max diff block lines reached; 683882/692690 bytes (98.73%) of diff not shown.
6.34 MB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-e8.html
    
Offset 14297, 16 lines modifiedOffset 14297, 16 lines modified
00037d80:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>00037d80:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>
00037d90:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi00037d90:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi
00037da0:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.00037da0:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.
00037db0:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><00037db0:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><
00037dc0:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d00037dc0:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d
00037dd0:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··00037dd0:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··
00037de0:·2020·2020·2020·2020·2020·2020·2020·2020··················00037de0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037df0:·2020·2861·7320·6f66·2032·3032·362d·3031····(as·of·2026-0100037df0:·2020·2861·7320·6f66·2032·3032·342d·3132····(as·of·2024-12
00037e00:·2d30·3829·0a20·2020·2020·2020·2020·2020··-08).···········00037e00:·2d30·3729·0a20·2020·2020·2020·2020·2020··-07).···········
00037e10:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><00037e10:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><
00037e20:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o00037e20:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o
00037e30:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><00037e30:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><
00037e40:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="00037e40:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="
00037e50:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr00037e50:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr
00037e60:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr00037e60:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr
00037e70:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst00037e70:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst
Offset 15153, 309 lines modifiedOffset 15153, 309 lines modified
0003b300:·6765·743d·2223·6964·6d35·3239·3922·2074··get="#idm5299"·t0003b300:·6765·743d·2223·6964·6d35·3239·3922·2074··get="#idm5299"·t
0003b310:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003b310:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003b320:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003b320:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003b330:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003b330:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003b340:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003b340:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003b350:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003b350:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003b360:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003b360:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003b370:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
0003b380:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b390:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b3a0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b3b0:·3d22·6964·6d35·3239·3922·3e3c·7072·653e··="idm5299"><pre> 
0003b3c0:·3c63·6f64·653e·0a23·2046·696e·6420·7768··<code>.#·Find·wh 
0003b3d0:·6963·6820·6669·6c65·7320·6861·7665·2069··ich·files·have·i 
0003b3e0:·6e63·6f72·7265·6374·2068·6173·6820·286e··ncorrect·hash·(n 
0003b3f0:·6f74·2069·6e20·2f65·7463·2c20·6265·6361··ot·in·/etc,·beca 
0003b400:·7573·6520·6f66·2074·6865·2073·7973·7465··use·of·the·syste 
0003b410:·6d20·7265·6c61·7465·6420·636f·6e66·6967··m·related·config 
0003b420:·2066·696c·6573·2920·616e·6420·7468·656e···files)·and·then 
0003b430:·2067·6574·2066·696c·6573·206e·616d·6573···get·files·names 
0003b440:·0a66·696c·6573·5f77·6974·685f·696e·636f··.files_with_inco 
0003b450:·7272·6563·745f·6861·7368·3d22·2428·7270··rrect_hash="$(rp 
0003b460:·6d20·2d56·6120·2d2d·6e6f·636f·6e66·6967··m·-Va·--noconfig 
0003b470:·207c·2067·7265·7020·2d45·2027·5e2e·2e35···|·grep·-E·'^..5 
0003b480:·2720·7c20·6177·6b20·277b·7072·696e·7420··'·|·awk·'{print· 
0003b490:·244e·467d·2720·2922·0a0a·6966·205b·202d··$NF}'·)"..if·[·- 
0003b4a0:·6e20·2224·6669·6c65·735f·7769·7468·5f69··n·"$files_with_i 
0003b4b0:·6e63·6f72·7265·6374·5f68·6173·6822·205d··ncorrect_hash"·] 
0003b4c0:·3b20·7468·656e·0a20·2020·2023·2046·726f··;·then.····#·Fro 
0003b4d0:·6d20·6669·6c65·7320·6e61·6d65·7320·6765··m·files·names·ge 
0003b4e0:·7420·7061·636b·6167·6520·6e61·6d65·7320··t·package·names· 
0003b4f0:·616e·6420·6368·616e·6765·206e·6577·6c69··and·change·newli 
0003b500:·6e65·2074·6f20·7370·6163·652c·2062·6563··ne·to·space,·bec 
0003b510:·6175·7365·2072·706d·2077·7269·7465·7320··ause·rpm·writes· 
0003b520:·6561·6368·2070·6163·6b61·6765·2074·6f20··each·package·to· 
0003b530:·6e65·7720·6c69·6e65·0a20·2020·2070·6163··new·line.····pac 
0003b540:·6b61·6765·735f·746f·5f72·6569·6e73·7461··kages_to_reinsta 
0003b550:·6c6c·3d22·2428·7270·6d20·2d71·6620·2466··ll="$(rpm·-qf·$f 
0003b560:·696c·6573·5f77·6974·685f·696e·636f·7272··iles_with_incorr 
0003b570:·6563·745f·6861·7368·207c·2074·7220·275c··ect_hash·|·tr·'\ 
0003b580:·6e27·2027·2027·2922·0a0a·2020·2020·0a20··n'·'·')"..····.· 
0003b590:·2020·2079·756d·2072·6569·6e73·7461·6c6c·····yum·reinstall 
0003b5a0:·202d·7920·2470·6163·6b61·6765·735f·746f···-y·$packages_to 
0003b5b0:·5f72·6569·6e73·7461·6c6c·0a20·2020·200a··_reinstall.····. 
0003b5c0:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre> 
0003b5d0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003b5e0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003b5f0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003b600:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003b610:·6765·743d·2223·6964·6d35·3330·3022·2074··get="#idm5300"·t 
0003b620:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003b630:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003b640:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003b650:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003b660:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003b670:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003b680:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet0003b370:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet
0003b690:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003b380:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003b6a0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003b390:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003b6b0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003b3a0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003b6c0:·2069·643d·2269·646d·3533·3030·223e·3c74···id="idm5300"><t0003b3b0:·2069·643d·2269·646d·3532·3939·223e·3c74···id="idm5299"><t
0003b6d0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl0003b3c0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003b6e0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·0003b3d0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003b6f0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0003b3e0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003b700:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">0003b3f0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003b710:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi0003b400:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003b720:·7479·3a3c·2f74·683e·3c74·643e·6869·6768··ty:</th><td>high0003b410:·7479·3a3c·2f74·683e·3c74·643e·6869·6768··ty:</th><td>high
0003b730:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003b420:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003b740:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003b430:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003b750:·683e·3c74·643e·6d65·6469·756d·3c2f·7464··h><td>medium</td0003b440:·683e·3c74·643e·6d65·6469·756d·3c2f·7464··h><td>medium</td
0003b760:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003b450:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003b770:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003b460:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003b780:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003b470:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003b790:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003b480:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003b7a0:·7468·3e3c·7464·3e72·6573·7472·6963·743c··th><td>restrict<0003b490:·7468·3e3c·7464·3e72·6573·7472·6963·743c··th><td>restrict<
0003b7b0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003b4a0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003b7c0:·3e3c·7072·653e·3c63·6f64·653e·2d20·6e61··><pre><code>-·na0003b4b0:·3e3c·7072·653e·3c63·6f64·653e·2d20·6e61··><pre><code>-·na
0003b7d0:·6d65·3a20·2753·6574·2066·6163·743a·2050··me:·'Set·fact:·P0003b4c0:·6d65·3a20·2753·6574·2066·6163·743a·2050··me:·'Set·fact:·P
0003b7e0:·6163·6b61·6765·206d·616e·6167·6572·2072··ackage·manager·r 
0003b7f0:·6569·6e73·7461·6c6c·2063·6f6d·6d61·6e64··einstall·command 
0003b800:·270a·2020·7365·745f·6661·6374·3a0a·2020··'.··set_fact:.·· 
0003b810:·2020·7061·636b·6167·655f·6d61·6e61·6765····package_manage 
0003b820:·725f·7265·696e·7374·616c·6c5f·636d·643a··r_reinstall_cmd: 
0003b830:·2079·756d·2072·6569·6e73·7461·6c6c·202d···yum·reinstall·- 
0003b840:·790a·2020·7768·656e·3a20·616e·7369·626c··y.··when:·ansibl 
0003b850:·655f·6469·7374·7269·6275·7469·6f6e·2069··e_distribution·i 
0003b860:·6e20·5b20·2246·6564·6f72·6122·2c20·2252··n·[·"Fedora",·"R 
0003b870:·6564·4861·7422·2c20·2243·656e·744f·5322··edHat",·"CentOS" 
0003b880:·2c20·224f·7261·636c·654c·696e·7578·2220··,·"OracleLinux"· 
0003b890:·5d0a·2020·7461·6773·3a0a·2020·2d20·434a··].··tags:.··-·CJ 
0003b8a0:·4953·2d35·2e31·302e·342e·310a·2020·2d20··IS-5.10.4.1.··-· 
0003b8b0:·4449·5341·2d53·5449·472d·4f4c·3037·2d30··DISA-STIG-OL07-0 
0003b8c0:·302d·3031·3030·3230·0a20·202d·204e·4953··0-010020.··-·NIS 
0003b8d0:·542d·3830·302d·3137·312d·332e·332e·380a··T-800-171-3.3.8. 
0003b8e0:·2020·2d20·4e49·5354·2d38·3030·2d31·3731····-·NIST-800-171 
0003b8f0:·2d33·2e34·2e31·0a20·202d·204e·4953·542d··-3.4.1.··-·NIST- 
0003b900:·3830·302d·3533·2d41·552d·3928·3329·0a20··800-53-AU-9(3).· 
0003b910:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C 
0003b920:·4d2d·3628·6329·0a20·202d·204e·4953·542d··M-6(c).··-·NIST- 
0003b930:·3830·302d·3533·2d43·4d2d·3628·6429·0a20··800-53-CM-6(d).· 
0003b940:·202d·204e·4953·542d·3830·302d·3533·2d53···-·NIST-800-53-S 
0003b950:·492d·370a·2020·2d20·4e49·5354·2d38·3030··I-7.··-·NIST-800 
0003b960:·2d35·332d·5349·2d37·2831·290a·2020·2d20··-53-SI-7(1).··-· 
0003b970:·4e49·5354·2d38·3030·2d35·332d·5349·2d37··NIST-800-53-SI-7 
0003b980:·2836·290a·2020·2d20·5043·492d·4453·532d··(6).··-·PCI-DSS- 
0003b990:·5265·712d·3131·2e35·0a20·202d·2050·4349··Req-11.5.··-·PCI 
0003b9a0:·2d44·5353·7634·2d31·312e·352e·320a·2020··-DSSv4-11.5.2.·· 
0003b9b0:·2d20·6869·6768·5f63·6f6d·706c·6578·6974··-·high_complexit 
0003b9c0:·790a·2020·2d20·6869·6768·5f73·6576·6572··y.··-·high_sever 
0003b9d0:·6974·790a·2020·2d20·6d65·6469·756d·5f64··ity.··-·medium_d 
Max diff block lines reached; 5982293/6001529 bytes (99.68%) of diff not shown.
634 KB
html2text {}
    
Offset 41, 15 lines modifiedOffset 41, 15 lines modified
41 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*41 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Australian·Cyber·Security·Centre·(ACSC)·Essential·Eight42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Australian·Cyber·Security·Centre·(ACSC)·Essential·Eight
43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_e843 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_e8
44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
45 ····*·cpe:/o:oracle:linux:745 ····*·cpe:/o:oracle:linux:7
46 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
47 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8447 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
48 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)48 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
49 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*49 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
50 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s50 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
51 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e51 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
52 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l52 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
53 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g53 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
54 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s54 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
55 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s55 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 104, 27 lines modifiedOffset 104, 14 lines modified
104 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)104 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
105 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1105 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
106 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5106 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
107 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227107 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
108 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010020108 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010020
109 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2109 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
110 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221653r853660_rule110 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221653r853660_rule
111 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
112 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
113 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
114 if·[·-n·"$files_with_incorrect_hash"·];·then 
115 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
116 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
117 ····yum·reinstall·-y·$packages_to_reinstall 
  
118 fi 
119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8111 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
120 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high112 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
121 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium113 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
122 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false114 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
123 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict115 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
124 -·name:·'Set·fact:·Package·manager·reinstall·command'116 -·name:·'Set·fact:·Package·manager·reinstall·command'
125 ··set_fact:117 ··set_fact:
Offset 256, 14 lines modifiedOffset 243, 27 lines modified
256 ··-·PCI-DSSv4-11.5.2243 ··-·PCI-DSSv4-11.5.2
257 ··-·high_complexity244 ··-·high_complexity
258 ··-·high_severity245 ··-·high_severity
259 ··-·medium_disruption246 ··-·medium_disruption
260 ··-·no_reboot_needed247 ··-·no_reboot_needed
261 ··-·restrict_strategy248 ··-·restrict_strategy
262 ··-·rpm_verify_hashes249 ··-·rpm_verify_hashes
 250 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 251 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 252 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 253 if·[·-n·"$files_with_incorrect_hash"·];·then
 254 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 255 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 256 ····yum·reinstall·-y·$packages_to_reinstall
  
 257 fi
263 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*258 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
264 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:259 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
265 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'260 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
266 run·the·following·command·to·determine·which·package·owns·it:261 run·the·following·command·to·determine·which·package·owns·it:
267 $·rpm·-qf·FILENAME262 $·rpm·-qf·FILENAME
268 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:263 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
269 $·sudo·rpm·--setugids·PACKAGENAME264 $·sudo·rpm·--setugids·PACKAGENAME
Offset 284, 40 lines modifiedOffset 284, 14 lines modified
284 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)284 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
285 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1285 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
286 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5286 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
287 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108287 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
288 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010010288 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010010
289 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2289 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
290 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221652r880585_rule290 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221652r880585_rule
291 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
292 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
293 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
294 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
295 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
296 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
297 declare·-A·SETPERMS_RPM_DICT 
  
298 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
299 #·is·expected·by·the·RPM·database 
300 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
301 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
302 do 
303 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
304 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
305 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
306 done 
  
307 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
308 #·correct·values 
309 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
310 do 
311 ········rpm·--setugids·"${RPM_PACKAGE}" 
312 done 
313 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8291 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
314 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high292 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
315 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium293 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
316 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false294 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
317 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict295 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
318 -·name:·Read·list·of·files·with·incorrect·ownership296 -·name:·Read·list·of·files·with·incorrect·ownership
319 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev297 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 395, 14 lines modifiedOffset 369, 40 lines modified
395 ··-·PCI-DSSv4-11.5.2369 ··-·PCI-DSSv4-11.5.2
396 ··-·high_complexity370 ··-·high_complexity
397 ··-·high_severity371 ··-·high_severity
398 ··-·medium_disruption372 ··-·medium_disruption
399 ··-·no_reboot_needed373 ··-·no_reboot_needed
400 ··-·restrict_strategy374 ··-·restrict_strategy
401 ··-·rpm_verify_ownership375 ··-·rpm_verify_ownership
 376 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 377 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 378 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 379 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 380 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 381 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 642082/649461 bytes (98.86%) of diff not shown.
16.4 MB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-hipaa.html
    
Offset 14316, 15 lines modifiedOffset 14316, 15 lines modified
00037eb0:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr00037eb0:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr
00037ec0:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st00037ec0:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st
00037ed0:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str00037ed0:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str
00037ee0:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>00037ee0:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>
00037ef0:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s00037ef0:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s
00037f00:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········00037f00:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········
00037f10:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o00037f10:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o
00037f20:·6620·3230·3236·2d30·312d·3038·290a·2020··f·2026-01-08).··00037f20:·6620·3230·3234·2d31·322d·3037·290a·2020··f·2024-12-07).··
00037f30:·2020·2020·2020·2020·2020·2020·2020·3c2f················</00037f30:·2020·2020·2020·2020·2020·2020·2020·3c2f················</
00037f40:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h00037f40:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h
00037f50:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte00037f50:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte
00037f60:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>00037f60:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>
00037f70:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_00037f70:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_
00037f80:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c00037f80:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c
00037f90:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys00037f90:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys
Offset 15184, 310 lines modifiedOffset 15184, 310 lines modified
0003b4f0:·7461·7267·6574·3d22·2369·646d·3532·3939··target="#idm52990003b4f0:·7461·7267·6574·3d22·2369·646d·3532·3939··target="#idm5299
0003b500:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003b500:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003b510:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003b510:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003b520:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003b520:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003b530:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003b530:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003b540:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003b540:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003b550:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003b550:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003b560:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003b570:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003b580:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003b590:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003b5a0:·2069·643d·2269·646d·3532·3939·223e·3c70···id="idm5299"><p 
0003b5b0:·7265·3e3c·636f·6465·3e0a·2320·4669·6e64··re><code>.#·Find 
0003b5c0:·2077·6869·6368·2066·696c·6573·2068·6176···which·files·hav 
0003b5d0:·6520·696e·636f·7272·6563·7420·6861·7368··e·incorrect·hash 
0003b5e0:·2028·6e6f·7420·696e·202f·6574·632c·2062···(not·in·/etc,·b 
0003b5f0:·6563·6175·7365·206f·6620·7468·6520·7379··ecause·of·the·sy 
0003b600:·7374·656d·2072·656c·6174·6564·2063·6f6e··stem·related·con 
0003b610:·6669·6720·6669·6c65·7329·2061·6e64·2074··fig·files)·and·t 
0003b620:·6865·6e20·6765·7420·6669·6c65·7320·6e61··hen·get·files·na 
0003b630:·6d65·730a·6669·6c65·735f·7769·7468·5f69··mes.files_with_i 
0003b640:·6e63·6f72·7265·6374·5f68·6173·683d·2224··ncorrect_hash="$ 
0003b650:·2872·706d·202d·5661·202d·2d6e·6f63·6f6e··(rpm·-Va·--nocon 
0003b660:·6669·6720·7c20·6772·6570·202d·4520·275e··fig·|·grep·-E·'^ 
0003b670:·2e2e·3527·207c·2061·776b·2027·7b70·7269··..5'·|·awk·'{pri 
0003b680:·6e74·2024·4e46·7d27·2029·220a·0a69·6620··nt·$NF}'·)"..if· 
0003b690:·5b20·2d6e·2022·2466·696c·6573·5f77·6974··[·-n·"$files_wit 
0003b6a0:·685f·696e·636f·7272·6563·745f·6861·7368··h_incorrect_hash 
0003b6b0:·2220·5d3b·2074·6865·6e0a·2020·2020·2320··"·];·then.····#· 
0003b6c0:·4672·6f6d·2066·696c·6573·206e·616d·6573··From·files·names 
0003b6d0:·2067·6574·2070·6163·6b61·6765·206e·616d···get·package·nam 
0003b6e0:·6573·2061·6e64·2063·6861·6e67·6520·6e65··es·and·change·ne 
0003b6f0:·776c·696e·6520·746f·2073·7061·6365·2c20··wline·to·space,· 
0003b700:·6265·6361·7573·6520·7270·6d20·7772·6974··because·rpm·writ 
0003b710:·6573·2065·6163·6820·7061·636b·6167·6520··es·each·package· 
0003b720:·746f·206e·6577·206c·696e·650a·2020·2020··to·new·line.···· 
0003b730:·7061·636b·6167·6573·5f74·6f5f·7265·696e··packages_to_rein 
0003b740:·7374·616c·6c3d·2224·2872·706d·202d·7166··stall="$(rpm·-qf 
0003b750:·2024·6669·6c65·735f·7769·7468·5f69·6e63···$files_with_inc 
0003b760:·6f72·7265·6374·5f68·6173·6820·7c20·7472··orrect_hash·|·tr 
0003b770:·2027·5c6e·2720·2720·2729·220a·0a20·2020···'\n'·'·')"..··· 
0003b780:·200a·2020·2020·7975·6d20·7265·696e·7374···.····yum·reinst 
0003b790:·616c·6c20·2d79·2024·7061·636b·6167·6573··all·-y·$packages 
0003b7a0:·5f74·6f5f·7265·696e·7374·616c·6c0a·2020··_to_reinstall.·· 
0003b7b0:·2020·0a66·690a·3c2f·636f·6465·3e3c·2f70····.fi.</code></p 
0003b7c0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003b7d0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003b7e0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003b7f0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003b800:·7461·7267·6574·3d22·2369·646d·3533·3030··target="#idm5300 
0003b810:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003b820:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003b830:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003b840:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003b850:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003b860:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003b870:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip0003b560:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip
0003b880:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003b570:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003b890:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003b580:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003b8a0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003b590:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003b8b0:·7365·2220·6964·3d22·6964·6d35·3330·3022··se"·id="idm5300"0003b5a0:·7365·2220·6964·3d22·6964·6d35·3239·3922··se"·id="idm5299"
0003b8c0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003b5b0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003b8d0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003b5c0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003b8e0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003b5d0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003b8f0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003b5e0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003b900:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003b5f0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003b910:·6578·6974·793a·3c2f·7468·3e3c·7464·3e68··exity:</th><td>h0003b600:·6578·6974·793a·3c2f·7468·3e3c·7464·3e68··exity:</th><td>h
0003b920:·6967·683c·2f74·643e·3c2f·7472·3e3c·7472··igh</td></tr><tr0003b610:·6967·683c·2f74·643e·3c2f·7472·3e3c·7472··igh</td></tr><tr
0003b930:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003b620:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003b940:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<0003b630:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<
0003b950:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b640:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b960:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003b650:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003b970:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003b660:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003b980:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003b670:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003b990:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri0003b680:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri
0003b9a0:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta0003b690:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta
0003b9b0:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-0003b6a0:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-
0003b9c0:·206e·616d·653a·2027·5365·7420·6661·6374···name:·'Set·fact0003b6b0:·206e·616d·653a·2027·5365·7420·6661·6374···name:·'Set·fact
0003b9d0:·3a20·5061·636b·6167·6520·6d61·6e61·6765··:·Package·manage 
0003b9e0:·7220·7265·696e·7374·616c·6c20·636f·6d6d··r·reinstall·comm 
0003b9f0:·616e·6427·0a20·2073·6574·5f66·6163·743a··and'.··set_fact: 
0003ba00:·0a20·2020·2070·6163·6b61·6765·5f6d·616e··.····package_man 
0003ba10:·6167·6572·5f72·6569·6e73·7461·6c6c·5f63··ager_reinstall_c 
0003ba20:·6d64·3a20·7975·6d20·7265·696e·7374·616c··md:·yum·reinstal 
0003ba30:·6c20·2d79·0a20·2077·6865·6e3a·2061·6e73··l·-y.··when:·ans 
0003ba40:·6962·6c65·5f64·6973·7472·6962·7574·696f··ible_distributio 
0003ba50:·6e20·696e·205b·2022·4665·646f·7261·222c··n·in·[·"Fedora", 
0003ba60:·2022·5265·6448·6174·222c·2022·4365·6e74···"RedHat",·"Cent 
0003ba70:·4f53·222c·2022·4f72·6163·6c65·4c69·6e75··OS",·"OracleLinu 
0003ba80:·7822·205d·0a20·2074·6167·733a·0a20·202d··x"·].··tags:.··- 
0003ba90:·2043·4a49·532d·352e·3130·2e34·2e31·0a20···CJIS-5.10.4.1.· 
0003baa0:·202d·2044·4953·412d·5354·4947·2d4f·4c30···-·DISA-STIG-OL0 
0003bab0:·372d·3030·2d30·3130·3032·300a·2020·2d20··7-00-010020.··-· 
0003bac0:·4e49·5354·2d38·3030·2d31·3731·2d33·2e33··NIST-800-171-3.3 
0003bad0:·2e38·0a20·202d·204e·4953·542d·3830·302d··.8.··-·NIST-800- 
0003bae0:·3137·312d·332e·342e·310a·2020·2d20·4e49··171-3.4.1.··-·NI 
0003baf0:·5354·2d38·3030·2d35·332d·4155·2d39·2833··ST-800-53-AU-9(3 
0003bb00:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5 
0003bb10:·332d·434d·2d36·2863·290a·2020·2d20·4e49··3-CM-6(c).··-·NI 
0003bb20:·5354·2d38·3030·2d35·332d·434d·2d36·2864··ST-800-53-CM-6(d 
0003bb30:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5 
0003bb40:·332d·5349·2d37·0a20·202d·204e·4953·542d··3-SI-7.··-·NIST- 
0003bb50:·3830·302d·3533·2d53·492d·3728·3129·0a20··800-53-SI-7(1).· 
0003bb60:·202d·204e·4953·542d·3830·302d·3533·2d53···-·NIST-800-53-S 
0003bb70:·492d·3728·3629·0a20·202d·2050·4349·2d44··I-7(6).··-·PCI-D 
0003bb80:·5353·2d52·6571·2d31·312e·350a·2020·2d20··SS-Req-11.5.··-· 
0003bb90:·5043·492d·4453·5376·342d·3131·2e35·2e32··PCI-DSSv4-11.5.2 
0003bba0:·0a20·202d·2068·6967·685f·636f·6d70·6c65··.··-·high_comple 
0003bbb0:·7869·7479·0a20·202d·2068·6967·685f·7365··xity.··-·high_se 
0003bbc0:·7665·7269·7479·0a20·202d·206d·6564·6975··verity.··-·mediu 
0003bbd0:·6d5f·6469·7372·7570·7469·6f6e·0a20·202d··m_disruption.··- 
Max diff block lines reached; 15941596/15960694 bytes (99.88%) of diff not shown.
1.18 MB
html2text {}
    
Offset 46, 15 lines modifiedOffset 46, 15 lines modified
46 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
47 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Health·Insurance·Portability·and·Accountability·Act·(HIPAA)47 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Health·Insurance·Portability·and·Accountability·Act·(HIPAA)
48 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_hipaa48 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_hipaa
49 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*49 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
50 ····*·cpe:/o:oracle:linux:750 ····*·cpe:/o:oracle:linux:7
51 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
52 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8452 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
53 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)53 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
54 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*54 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
55 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s55 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
56 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e56 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
57 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l57 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
58 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n58 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
59 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g59 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
60 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s60 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 111, 27 lines modifiedOffset 111, 14 lines modified
111 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)111 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
112 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1112 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
113 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5113 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
114 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227114 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
115 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010020115 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010020
116 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2116 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
117 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221653r853660_rule117 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221653r853660_rule
118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
119 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
120 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
121 if·[·-n·"$files_with_incorrect_hash"·];·then 
122 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
123 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
124 ····yum·reinstall·-y·$packages_to_reinstall 
  
125 fi 
126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
131 -·name:·'Set·fact:·Package·manager·reinstall·command'123 -·name:·'Set·fact:·Package·manager·reinstall·command'
132 ··set_fact:124 ··set_fact:
Offset 263, 14 lines modifiedOffset 250, 27 lines modified
263 ··-·PCI-DSSv4-11.5.2250 ··-·PCI-DSSv4-11.5.2
264 ··-·high_complexity251 ··-·high_complexity
265 ··-·high_severity252 ··-·high_severity
266 ··-·medium_disruption253 ··-·medium_disruption
267 ··-·no_reboot_needed254 ··-·no_reboot_needed
268 ··-·restrict_strategy255 ··-·restrict_strategy
269 ··-·rpm_verify_hashes256 ··-·rpm_verify_hashes
 257 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 258 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 259 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 260 if·[·-n·"$files_with_incorrect_hash"·];·then
 261 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 262 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 263 ····yum·reinstall·-y·$packages_to_reinstall
  
 264 fi
270 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*265 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
271 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:266 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:
272 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'267 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'
273 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:268 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:
274 $·rpm·-qf·FILENAME269 $·rpm·-qf·FILENAME
  
275 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:270 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
Offset 293, 44 lines modifiedOffset 293, 14 lines modified
293 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)293 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)
294 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1294 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
295 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5295 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
296 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108296 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108
297 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010010297 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010010
298 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2298 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
299 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221652r880585_rule299 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221652r880585_rule
300 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
301 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
302 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
303 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
304 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
305 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
306 declare·-A·SETPERMS_RPM_DICT 
  
307 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
308 #·is·expected·by·the·RPM·database 
309 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}') 
  
310 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
311 do 
312 ········#·NOTE:·some·files·maybe·controlled·by·more·then·one·package 
313 ········readarray·-t·RPM_PACKAGES·<·<(rpm·-qf·"${FILE_PATH}") 
314 ········for·RPM_PACKAGE·in·"${RPM_PACKAGES[@]}" 
315 ········do 
316 ················#·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
317 ················SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
318 ········done 
319 done 
  
320 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
321 #·correct·values 
322 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
323 do 
324 »       rpm·--restore·"${RPM_PACKAGE}" 
325 done 
326 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8300 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
327 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high301 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
328 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium302 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
329 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false303 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
330 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict304 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
331 -·name:·Read·list·of·files·with·incorrect·permissions305 -·name:·Read·list·of·files·with·incorrect·permissions
332 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev306 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 411, 14 lines modifiedOffset 381, 44 lines modified
411 ··-·PCI-DSSv4-11.5.2381 ··-·PCI-DSSv4-11.5.2
412 ··-·high_complexity382 ··-·high_complexity
413 ··-·high_severity383 ··-·high_severity
414 ··-·medium_disruption384 ··-·medium_disruption
415 ··-·no_reboot_needed385 ··-·no_reboot_needed
416 ··-·restrict_strategy386 ··-·restrict_strategy
417 ··-·rpm_verify_permissions387 ··-·rpm_verify_permissions
 388 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 389 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 390 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
Max diff block lines reached; 1232177/1239926 bytes (99.38%) of diff not shown.
27.5 MB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-ncp.html
    
Offset 14368, 15 lines modifiedOffset 14368, 15 lines modified
000381f0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu000381f0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00038200:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00038200:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00038210:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s00038210:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00038220:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00038220:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00038230:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00038230:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00038240:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00038240:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00038250:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00038250:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00038260:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).00038260:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
00038270:·2020·2020·2020·2020·2020·2020·2020·2020··················00038270:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038280:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00038280:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00038290:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00038290:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
000382a0:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l000382a0:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
000382b0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd000382b0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
000382c0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject000382c0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
000382d0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s000382d0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
Offset 15258, 310 lines modifiedOffset 15258, 310 lines modified
0003b990:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm50003b990:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm5
0003b9a0:·3239·3922·2074·6162·696e·6465·783d·2230··299"·tabindex="00003b9a0:·3239·3922·2074·6162·696e·6465·783d·2230··299"·tabindex="0
0003b9b0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003b9b0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003b9c0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003b9c0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003b9d0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003b9d0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003b9e0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003b9e0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003b9f0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003b9f0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003ba00:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
0003ba10:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003ba20:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003ba30:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003ba40:·7365·2220·6964·3d22·6964·6d35·3239·3922··se"·id="idm5299" 
0003ba50:·3e3c·7072·653e·3c63·6f64·653e·0a23·2046··><pre><code>.#·F 
0003ba60:·696e·6420·7768·6963·6820·6669·6c65·7320··ind·which·files· 
0003ba70:·6861·7665·2069·6e63·6f72·7265·6374·2068··have·incorrect·h 
0003ba80:·6173·6820·286e·6f74·2069·6e20·2f65·7463··ash·(not·in·/etc 
0003ba90:·2c20·6265·6361·7573·6520·6f66·2074·6865··,·because·of·the 
0003baa0:·2073·7973·7465·6d20·7265·6c61·7465·6420···system·related· 
0003bab0:·636f·6e66·6967·2066·696c·6573·2920·616e··config·files)·an 
0003bac0:·6420·7468·656e·2067·6574·2066·696c·6573··d·then·get·files 
0003bad0:·206e·616d·6573·0a66·696c·6573·5f77·6974···names.files_wit 
0003bae0:·685f·696e·636f·7272·6563·745f·6861·7368··h_incorrect_hash 
0003baf0:·3d22·2428·7270·6d20·2d56·6120·2d2d·6e6f··="$(rpm·-Va·--no 
0003bb00:·636f·6e66·6967·207c·2067·7265·7020·2d45··config·|·grep·-E 
0003bb10:·2027·5e2e·2e35·2720·7c20·6177·6b20·277b···'^..5'·|·awk·'{ 
0003bb20:·7072·696e·7420·244e·467d·2720·2922·0a0a··print·$NF}'·)".. 
0003bb30:·6966·205b·202d·6e20·2224·6669·6c65·735f··if·[·-n·"$files_ 
0003bb40:·7769·7468·5f69·6e63·6f72·7265·6374·5f68··with_incorrect_h 
0003bb50:·6173·6822·205d·3b20·7468·656e·0a20·2020··ash"·];·then.··· 
0003bb60:·2023·2046·726f·6d20·6669·6c65·7320·6e61···#·From·files·na 
0003bb70:·6d65·7320·6765·7420·7061·636b·6167·6520··mes·get·package· 
0003bb80:·6e61·6d65·7320·616e·6420·6368·616e·6765··names·and·change 
0003bb90:·206e·6577·6c69·6e65·2074·6f20·7370·6163···newline·to·spac 
0003bba0:·652c·2062·6563·6175·7365·2072·706d·2077··e,·because·rpm·w 
0003bbb0:·7269·7465·7320·6561·6368·2070·6163·6b61··rites·each·packa 
0003bbc0:·6765·2074·6f20·6e65·7720·6c69·6e65·0a20··ge·to·new·line.· 
0003bbd0:·2020·2070·6163·6b61·6765·735f·746f·5f72·····packages_to_r 
0003bbe0:·6569·6e73·7461·6c6c·3d22·2428·7270·6d20··einstall="$(rpm· 
0003bbf0:·2d71·6620·2466·696c·6573·5f77·6974·685f··-qf·$files_with_ 
0003bc00:·696e·636f·7272·6563·745f·6861·7368·207c··incorrect_hash·| 
0003bc10:·2074·7220·275c·6e27·2027·2027·2922·0a0a···tr·'\n'·'·')".. 
0003bc20:·2020·2020·0a20·2020·2079·756d·2072·6569······.····yum·rei 
0003bc30:·6e73·7461·6c6c·202d·7920·2470·6163·6b61··nstall·-y·$packa 
0003bc40:·6765·735f·746f·5f72·6569·6e73·7461·6c6c··ges_to_reinstall 
0003bc50:·0a20·2020·200a·6669·0a3c·2f63·6f64·653e··.····.fi.</code> 
0003bc60:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003bc70:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003bc80:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003bc90:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003bca0:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm5 
0003bcb0:·3330·3022·2074·6162·696e·6465·783d·2230··300"·tabindex="0 
0003bcc0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003bcd0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003bce0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003bcf0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003bd00:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003bd10:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s0003ba00:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s
0003bd20:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003ba10:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003bd30:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003ba20:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003bd40:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003ba30:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003bd50:·6c61·7073·6522·2069·643d·2269·646d·3533··lapse"·id="idm530003ba40:·6c61·7073·6522·2069·643d·2269·646d·3532··lapse"·id="idm52
0003bd60:·3030·223e·3c74·6162·6c65·2063·6c61·7373··00"><table·class0003ba50:·3939·223e·3c74·6162·6c65·2063·6c61·7373··99"><table·class
0003bd70:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003ba60:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003bd80:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003ba70:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003bd90:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003ba80:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003bda0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003ba90:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003bdb0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003baa0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003bdc0:·643e·6869·6768·3c2f·7464·3e3c·2f74·723e··d>high</td></tr>0003bab0:·643e·6869·6768·3c2f·7464·3e3c·2f74·723e··d>high</td></tr>
0003bdd0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003bac0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003bde0:·6f6e·3a3c·2f74·683e·3c74·643e·6d65·6469··on:</th><td>medi0003bad0:·6f6e·3a3c·2f74·683e·3c74·643e·6d65·6469··on:</th><td>medi
0003bdf0:·756d·3c2f·7464·3e3c·2f74·723e·3c74·723e··um</td></tr><tr>0003bae0:·756d·3c2f·7464·3e3c·2f74·723e·3c74·723e··um</td></tr><tr>
0003be00:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>0003baf0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
0003be10:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></0003bb00:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
0003be20:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0003bb10:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
0003be30:·6567·793a·3c2f·7468·3e3c·7464·3e72·6573··egy:</th><td>res0003bb20:·6567·793a·3c2f·7468·3e3c·7464·3e72·6573··egy:</th><td>res
0003be40:·7472·6963·743c·2f74·643e·3c2f·7472·3e3c··trict</td></tr><0003bb30:·7472·6963·743c·2f74·643e·3c2f·7472·3e3c··trict</td></tr><
0003be50:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod0003bb40:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
0003be60:·653e·2d20·6e61·6d65·3a20·2753·6574·2066··e>-·name:·'Set·f0003bb50:·653e·2d20·6e61·6d65·3a20·2753·6574·2066··e>-·name:·'Set·f
0003be70:·6163·743a·2050·6163·6b61·6765·206d·616e··act:·Package·man0003bb60:·6163·743a·2050·6163·6b61·6765·206d·616e··act:·Package·man
0003be80:·6167·6572·2072·6569·6e73·7461·6c6c·2063··ager·reinstall·c0003bb70:·6167·6572·2072·6569·6e73·7461·6c6c·2063··ager·reinstall·c
0003be90:·6f6d·6d61·6e64·270a·2020·7365·745f·6661··ommand'.··set_fa0003bb80:·6f6d·6d61·6e64·270a·2020·7365·745f·6661··ommand'.··set_fa
0003bea0:·6374·3a0a·2020·2020·7061·636b·6167·655f··ct:.····package_0003bb90:·6374·3a0a·2020·2020·7061·636b·6167·655f··ct:.····package_
0003beb0:·6d61·6e61·6765·725f·7265·696e·7374·616c··manager_reinstal0003bba0:·6d61·6e61·6765·725f·7265·696e·7374·616c··manager_reinstal
0003bec0:·6c5f·636d·643a·2079·756d·2072·6569·6e73··l_cmd:·yum·reins0003bbb0:·6c5f·636d·643a·2079·756d·2072·6569·6e73··l_cmd:·yum·reins
0003bed0:·7461·6c6c·202d·790a·2020·7768·656e·3a20··tall·-y.··when:·0003bbc0:·7461·6c6c·202d·790a·2020·7768·656e·3a20··tall·-y.··when:·
0003bee0:·616e·7369·626c·655f·6469·7374·7269·6275··ansible_distribu0003bbd0:·616e·7369·626c·655f·6469·7374·7269·6275··ansible_distribu
0003bef0:·7469·6f6e·2069·6e20·5b20·2246·6564·6f72··tion·in·[·"Fedor0003bbe0:·7469·6f6e·2069·6e20·5b20·2246·6564·6f72··tion·in·[·"Fedor
0003bf00:·6122·2c20·2252·6564·4861·7422·2c20·2243··a",·"RedHat",·"C0003bbf0:·6122·2c20·2252·6564·4861·7422·2c20·2243··a",·"RedHat",·"C
0003bf10:·656e·744f·5322·2c20·224f·7261·636c·654c··entOS",·"OracleL0003bc00:·656e·744f·5322·2c20·224f·7261·636c·654c··entOS",·"OracleL
0003bf20:·696e·7578·2220·5d0a·2020·7461·6773·3a0a··inux"·].··tags:.0003bc10:·696e·7578·2220·5d0a·2020·7461·6773·3a0a··inux"·].··tags:.
0003bf30:·2020·2d20·434a·4953·2d35·2e31·302e·342e····-·CJIS-5.10.4.0003bc20:·2020·2d20·434a·4953·2d35·2e31·302e·342e····-·CJIS-5.10.4.
0003bf40:·310a·2020·2d20·4449·5341·2d53·5449·472d··1.··-·DISA-STIG-0003bc30:·310a·2020·2d20·4449·5341·2d53·5449·472d··1.··-·DISA-STIG-
0003bf50:·4f4c·3037·2d30·302d·3031·3030·3230·0a20··OL07-00-010020.·0003bc40:·4f4c·3037·2d30·302d·3031·3030·3230·0a20··OL07-00-010020.·
0003bf60:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-0003bc50:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
0003bf70:·332e·332e·380a·2020·2d20·4e49·5354·2d38··3.3.8.··-·NIST-80003bc60:·332e·332e·380a·2020·2d20·4e49·5354·2d38··3.3.8.··-·NIST-8
0003bf80:·3030·2d31·3731·2d33·2e34·2e31·0a20·202d··00-171-3.4.1.··-0003bc70:·3030·2d31·3731·2d33·2e34·2e31·0a20·202d··00-171-3.4.1.··-
0003bf90:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-0003bc80:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-
0003bfa0:·3928·3329·0a20·202d·204e·4953·542d·3830··9(3).··-·NIST-800003bc90:·3928·3329·0a20·202d·204e·4953·542d·3830··9(3).··-·NIST-80
0003bfb0:·302d·3533·2d43·4d2d·3628·6329·0a20·202d··0-53-CM-6(c).··-0003bca0:·302d·3533·2d43·4d2d·3628·6329·0a20·202d··0-53-CM-6(c).··-
0003bfc0:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-0003bcb0:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-
0003bfd0:·3628·6429·0a20·202d·204e·4953·542d·3830··6(d).··-·NIST-800003bcc0:·3628·6429·0a20·202d·204e·4953·542d·3830··6(d).··-·NIST-80
0003bfe0:·302d·3533·2d53·492d·370a·2020·2d20·4e49··0-53-SI-7.··-·NI0003bcd0:·302d·3533·2d53·492d·370a·2020·2d20·4e49··0-53-SI-7.··-·NI
0003bff0:·5354·2d38·3030·2d35·332d·5349·2d37·2831··ST-800-53-SI-7(10003bce0:·5354·2d38·3030·2d35·332d·5349·2d37·2831··ST-800-53-SI-7(1
0003c000:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-50003bcf0:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5
0003c010:·332d·5349·2d37·2836·290a·2020·2d20·5043··3-SI-7(6).··-·PC0003bd00:·332d·5349·2d37·2836·290a·2020·2d20·5043··3-SI-7(6).··-·PC
0003c020:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·0003bd10:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·
0003c030:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.0003bd20:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.
0003c040:·352e·320a·2020·2d20·6869·6768·5f63·6f6d··5.2.··-·high_com0003bd30:·352e·320a·2020·2d20·6869·6768·5f63·6f6d··5.2.··-·high_com
0003c050:·706c·6578·6974·790a·2020·2d20·6869·6768··plexity.··-·high0003bd40:·706c·6578·6974·790a·2020·2d20·6869·6768··plexity.··-·high
0003c060:·5f73·6576·6572·6974·790a·2020·2d20·6d65··_severity.··-·me0003bd50:·5f73·6576·6572·6974·790a·2020·2d20·6d65··_severity.··-·me
0003c070:·6469·756d·5f64·6973·7275·7074·696f·6e0a··dium_disruption.0003bd60:·6469·756d·5f64·6973·7275·7074·696f·6e0a··dium_disruption.
Max diff block lines reached; 26243882/26286440 bytes (99.84%) of diff not shown.
2.4 MB
html2text {}
Max HTML report size reached
6.27 MB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-ospp.html
    
Offset 14305, 15 lines modifiedOffset 14305, 15 lines modified
00037e00:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·00037e00:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·
00037e10:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong00037e10:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong
00037e20:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>00037e20:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>
00037e30:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str00037e30:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str
00037e40:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron00037e40:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron
00037e50:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············00037e50:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············
00037e60:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·2000037e60:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·20
00037e70:·3236·2d30·312d·3038·290a·2020·2020·2020··26-01-08).······00037e70:·3234·2d31·322d·3037·290a·2020·2020·2020··24-12-07).······
00037e80:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><00037e80:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><
00037e90:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta00037e90:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta
00037ea0:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<00037ea0:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<
00037eb0:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h00037eb0:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h
00037ec0:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.00037ec0:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.
00037ed0:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte00037ed0:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte
00037ee0:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"00037ee0:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"
Offset 15048, 232 lines modifiedOffset 15048, 232 lines modified
0003ac70:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003ac70:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003ac80:·3d22·2369·646d·3631·3732·2220·7461·6269··="#idm6172"·tabi0003ac80:·3d22·2369·646d·3631·3732·2220·7461·6269··="#idm6172"·tabi
0003ac90:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003ac90:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003aca0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003aca0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003acb0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003acb0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003acc0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003acc0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003acd0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003acd0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003ace0:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu0003ace0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
0003acf0:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...0003acf0:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
0003ad00:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003ad00:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003ad10:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003ad10:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003ad20:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003ad20:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003ad30:·2269·646d·3631·3732·223e·3c74·6162·6c65··"idm6172"><table0003ad30:·643d·2269·646d·3631·3732·223e·3c74·6162··d="idm6172"><tab
0003ad40:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003ad40:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003ad50:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003ad50:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003ad60:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003ad60:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003ad70:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003ad70:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003ad80:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003ad80:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003ad90:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003ad90:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003ada0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003ada0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
0003adb0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003adb0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003adc0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003adc0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003add0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t0003add0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
0003ade0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>0003ade0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003adf0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003adf0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003ae00:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003ae00:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003ae10:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003ae10:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003ae20:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod0003ae20:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
0003ae30:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal 
0003ae40:·6c5f·6472·6163·7574·2d66·6970·730a·0a63··l_dracut-fips..c 
0003ae50:·6c61·7373·2069·6e73·7461·6c6c·5f64·7261··lass·install_dra 
0003ae60:·6375·742d·6669·7073·207b·0a20·2070·6163··cut-fips·{.··pac 
0003ae70:·6b61·6765·207b·2027·6472·6163·7574·2d66··kage·{·'dracut-f 
0003ae80:·6970·7327·3a0a·2020·2020·656e·7375·7265··ips':.····ensure 
0003ae90:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe0003ae30:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a
 0003ae40:·6464·3d64·7261·6375·742d·6669·7073·0a3c··dd=dracut-fips.<
 0003ae50:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003ae60:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003ae70:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003ae80:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0003ae90:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003aea0:·2223·6964·6d36·3137·3322·2074·6162·696e··"#idm6173"·tabin
 0003aeb0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003aec0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003aed0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003aee0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003aef0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003af00:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
 0003af10:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
 0003af20:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003af30:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003af40:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003af50:·6964·6d36·3137·3322·3e3c·7461·626c·6520··idm6173"><table·
 0003af60:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003af70:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003af80:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003af90:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003afa0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003afb0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003afc0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 0003afd0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 0003afe0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003aff0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 0003b000:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
 0003b010:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003b020:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
 0003b030:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 0003b040:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003b050:·3e69·6e63·6c75·6465·2069·6e73·7461·6c6c··>include·install
 0003b060:·5f64·7261·6375·742d·6669·7073·0a0a·636c··_dracut-fips..cl
 0003b070:·6173·7320·696e·7374·616c·6c5f·6472·6163··ass·install_drac
 0003b080:·7574·2d66·6970·7320·7b0a·2020·7061·636b··ut-fips·{.··pack
 0003b090:·6167·6520·7b20·2764·7261·6375·742d·6669··age·{·'dracut-fi
 0003b0a0:·7073·273a·0a20·2020·2065·6e73·7572·6520··ps':.····ensure·
 0003b0b0:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
0003aea0:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code0003b0c0:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
 0003b0d0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003b0e0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003b0f0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003b100:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0003b110:·7461·2d74·6172·6765·743d·2223·6964·6d36··ta-target="#idm6
 0003b120:·3137·3422·2074·6162·696e·6465·783d·2230··174"·tabindex="0
 0003b130:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0003b140:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0003b150:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0003b160:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0003b170:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003b180:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B
 0003b190:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet
 0003b1a0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003b1b0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003b1c0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003b1d0:·2069·643d·2269·646d·3631·3734·223e·3c70···id="idm6174"><p
 0003b1e0:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack
 0003b1f0:·6167·6573·5d5d·0a6e·616d·6520·3d20·2264··ages]].name·=·"d
 0003b200:·7261·6375·742d·6669·7073·220a·7665·7273··racut-fips".vers
 0003b210:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code
0003aeb0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0003b220:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
0003aec0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0003b230:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
0003aed0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0003b240:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0003aee0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003b250:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
0003aef0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b260:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003af00:·3631·3733·2220·7461·6269·6e64·6578·3d22··6173"·tabindex="0003b270:·3631·3735·2220·7461·6269·6e64·6578·3d22··6175"·tabindex="
0003af10:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b280:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003af20:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b290:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003af30:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003b2a0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003af40:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003b2b0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003af50:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003b2c0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0003b2d0:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible·
 0003b2e0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003b2f0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
Max diff block lines reached; 5849286/5881080 bytes (99.46%) of diff not shown.
677 KB
html2text {}
    
Offset 43, 15 lines modifiedOffset 43, 15 lines modified
43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Protection·Profile·for·General·Purpose·Operating·Systems44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Protection·Profile·for·General·Purpose·Operating·Systems
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ospp45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ospp
46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
47 ····*·cpe:/o:oracle:linux:747 ····*·cpe:/o:oracle:linux:7
48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
49 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8449 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
55 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n55 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
56 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s56 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
57 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s57 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 92, 41 lines modifiedOffset 92, 38 lines modified
92 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.6.692 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.6.6
93 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.13,·SR·2.6,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.693 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.13,·SR·2.6,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
94 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.294 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2
95 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-007-3·R5.195 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-007-3·R5.1
96 ············_\x8n_\x8i_\x8s_\x8t···········SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-1296 ············_\x8n_\x8i_\x8s_\x8t···········SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
97 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.PT-497 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.PT-4
98 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-0022398 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-00223
 99 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 100 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 101 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 102 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 103 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 104 package·--add=dracut-fips
99 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8105 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
100 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low106 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
101 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low107 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
102 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false108 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
103 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable109 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
104 include·install_dracut-fips110 include·install_dracut-fips
  
105 class·install_dracut-fips·{111 class·install_dracut-fips·{
106 ··package·{·'dracut-fips':112 ··package·{·'dracut-fips':
107 ····ensure·=>·'installed',113 ····ensure·=>·'installed',
108 ··}114 ··}
109 }115 }
 116 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
111 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
112 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
113 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
114 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
115 #·Remediation·is·applicable·only·in·certain·platforms 
116 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·)·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then 
  
117 if·!·rpm·-q·--quiet·"dracut-fips"·;·then 
118 ····yum·install·-y·"dracut-fips" 
119 fi 
  
120 else 
121 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
122 fi117 [[packages]]
 118 name·=·"dracut-fips"
 119 version·=·"*"
123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
124 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low121 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
125 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low122 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
126 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false123 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
127 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable124 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
128 -·name:·Ensure·dracut-fips·is·installed125 -·name:·Ensure·dracut-fips·is·installed
129 ··package:126 ··package:
Offset 148, 26 lines modifiedOffset 145, 29 lines modified
148 ··-·NIST-800-53-SC-13145 ··-·NIST-800-53-SC-13
149 ··-·enable_strategy146 ··-·enable_strategy
150 ··-·low_complexity147 ··-·low_complexity
151 ··-·low_disruption148 ··-·low_disruption
152 ··-·medium_severity149 ··-·medium_severity
153 ··-·no_reboot_needed150 ··-·no_reboot_needed
154 ··-·package_dracut-fips_installed151 ··-·package_dracut-fips_installed
155 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
156 [[packages]] 
157 name·=·"dracut-fips" 
158 version·=·"*" 
159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_.n_.a_.c_.o_.n_.d_.a_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
160 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low153 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
161 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low154 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
162 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false155 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
163 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable156 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 157 #·Remediation·is·applicable·only·in·certain·platforms
 158 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·)·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
164 package·--add=dracut-fips159 if·!·rpm·-q·--quiet·"dracut-fips"·;·then
 160 ····yum·install·-y·"dracut-fips"
 161 fi
  
 162 else
 163 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 164 fi
165 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·i\x8in\x8n·G\x8GR\x8RU\x8UB\x8B2\x82·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*165 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·i\x8in\x8n·G\x8GR\x8RU\x8UB\x8B2\x82·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
166 To·ensure·FIPS·mode·is·enabled,·install·package·dracut-fips,·and·rebuild·initramfs·by·running·the·following·commands:166 To·ensure·FIPS·mode·is·enabled,·install·package·dracut-fips,·and·rebuild·initramfs·by·running·the·following·commands:
167 $·sudo·yum·install·dracut-fips167 $·sudo·yum·install·dracut-fips
168 dracut·-f168 dracut·-f
169 After·the·dracut·command·has·been·run,·add·the·argument·fips=1·to·the·default·GRUB·2·command·line·for·the·Linux·operating·system·in·/etc/default/grub,·in·the·manner·below:169 After·the·dracut·command·has·been·run,·add·the·argument·fips=1·to·the·default·GRUB·2·command·line·for·the·Linux·operating·system·in·/etc/default/grub,·in·the·manner·below:
170 GRUB_CMDLINE_LINUX="crashkernel=auto·rd.lvm.lv=VolGroup/LogVol06·rd.lvm.lv=VolGroup/lv_swap·rhgb·quiet·rd.shell=0·fips=1"170 GRUB_CMDLINE_LINUX="crashkernel=auto·rd.lvm.lv=VolGroup/LogVol06·rd.lvm.lv=VolGroup/lv_swap·rhgb·quiet·rd.shell=0·fips=1"
171 Finally,·rebuild·the·grub.cfg·file·by·using·the171 Finally,·rebuild·the·grub.cfg·file·by·using·the
Offset 195, 80 lines modifiedOffset 195, 17 lines modified
195 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2195 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2
196 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-007-3·R5.1196 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-007-3·R5.1
197 ············_\x8n_\x8i_\x8s_\x8t···········SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12197 ············_\x8n_\x8i_\x8s_\x8t···········SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
198 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.PT-4198 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.PT-4
199 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223199 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223
200 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-021350200 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-021350
201 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221758r877398_rule201 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221758r877398_rule
202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_.n_.a_.c_.o_.n_.d_.a_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
203 #·Remediation·is·applicable·only·in·certain·platforms 
204 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·)·&&·{·rpm·--quiet·-q·grub2-common;·};·then 
  
205 #·prelink·not·installed 
206 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then 
207 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink 
208 ····then 
209 ········sed·-i·'s/^PRELINKING[:blank:]*=[:blank:]*[:alpha:]*/PRELINKING=no/'·/etc/sysconfig/prelink 
210 ····else 
211 ········printf·'\n'·>>·/etc/sysconfig/prelink 
212 ········printf·'%s\n'·'#·Set·PRELINKING=no·per·security·requirements'·'PRELINKING=no'·>>·/etc/sysconfig/prelink 
213 ····fi 
  
214 ····#·Undo·previous·prelink·changes·to·binaries·if·prelink·is·available. 
215 ····if·test·-x·/usr/sbin/prelink;·then 
216 ········/usr/sbin/prelink·-ua 
Max diff block lines reached; 683882/692737 bytes (98.72%) of diff not shown.
9.91 MB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-pci-dss.html
    
Offset 14281, 15 lines modifiedOffset 14281, 15 lines modified
00037c80:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren00037c80:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren
00037c90:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro00037c90:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro
00037ca0:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron00037ca0:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron
00037cb0:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s00037cb0:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s
00037cc0:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str00037cc0:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str
00037cd0:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········00037cd0:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········
00037ce0:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·00037ce0:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·
00037cf0:·3230·3236·2d30·312d·3038·290a·2020·2020··2026-01-08).····00037cf0:·3230·3234·2d31·322d·3037·290a·2020·2020··2024-12-07).····
00037d00:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li00037d00:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li
00037d10:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>00037d10:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>
00037d20:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content00037d20:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content
00037d30:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a00037d30:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a
00037d40:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or00037d40:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or
00037d50:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con00037d50:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con
00037d60:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste00037d60:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste
Offset 15123, 310 lines modifiedOffset 15123, 310 lines modified
0003b120:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b120:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b130:·2369·646d·3532·3939·2220·7461·6269·6e64··#idm5299"·tabind0003b130:·2369·646d·3532·3939·2220·7461·6269·6e64··#idm5299"·tabind
0003b140:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b140:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b150:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b150:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b160:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b160:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b170:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b170:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b180:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b180:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b190:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel 
0003b1a0:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a> 
0003b1b0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b1c0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b1d0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b1e0:·3532·3939·223e·3c70·7265·3e3c·636f·6465··5299"><pre><code 
0003b1f0:·3e0a·2320·4669·6e64·2077·6869·6368·2066··>.#·Find·which·f 
0003b200:·696c·6573·2068·6176·6520·696e·636f·7272··iles·have·incorr 
0003b210:·6563·7420·6861·7368·2028·6e6f·7420·696e··ect·hash·(not·in 
0003b220:·202f·6574·632c·2062·6563·6175·7365·206f···/etc,·because·o 
0003b230:·6620·7468·6520·7379·7374·656d·2072·656c··f·the·system·rel 
0003b240:·6174·6564·2063·6f6e·6669·6720·6669·6c65··ated·config·file 
0003b250:·7329·2061·6e64·2074·6865·6e20·6765·7420··s)·and·then·get· 
0003b260:·6669·6c65·7320·6e61·6d65·730a·6669·6c65··files·names.file 
0003b270:·735f·7769·7468·5f69·6e63·6f72·7265·6374··s_with_incorrect 
0003b280:·5f68·6173·683d·2224·2872·706d·202d·5661··_hash="$(rpm·-Va 
0003b290:·202d·2d6e·6f63·6f6e·6669·6720·7c20·6772···--noconfig·|·gr 
0003b2a0:·6570·202d·4520·275e·2e2e·3527·207c·2061··ep·-E·'^..5'·|·a 
0003b2b0:·776b·2027·7b70·7269·6e74·2024·4e46·7d27··wk·'{print·$NF}' 
0003b2c0:·2029·220a·0a69·6620·5b20·2d6e·2022·2466···)"..if·[·-n·"$f 
0003b2d0:·696c·6573·5f77·6974·685f·696e·636f·7272··iles_with_incorr 
0003b2e0:·6563·745f·6861·7368·2220·5d3b·2074·6865··ect_hash"·];·the 
0003b2f0:·6e0a·2020·2020·2320·4672·6f6d·2066·696c··n.····#·From·fil 
0003b300:·6573·206e·616d·6573·2067·6574·2070·6163··es·names·get·pac 
0003b310:·6b61·6765·206e·616d·6573·2061·6e64·2063··kage·names·and·c 
0003b320:·6861·6e67·6520·6e65·776c·696e·6520·746f··hange·newline·to 
0003b330:·2073·7061·6365·2c20·6265·6361·7573·6520···space,·because· 
0003b340:·7270·6d20·7772·6974·6573·2065·6163·6820··rpm·writes·each· 
0003b350:·7061·636b·6167·6520·746f·206e·6577·206c··package·to·new·l 
0003b360:·696e·650a·2020·2020·7061·636b·6167·6573··ine.····packages 
0003b370:·5f74·6f5f·7265·696e·7374·616c·6c3d·2224··_to_reinstall="$ 
0003b380:·2872·706d·202d·7166·2024·6669·6c65·735f··(rpm·-qf·$files_ 
0003b390:·7769·7468·5f69·6e63·6f72·7265·6374·5f68··with_incorrect_h 
0003b3a0:·6173·6820·7c20·7472·2027·5c6e·2720·2720··ash·|·tr·'\n'·'· 
0003b3b0:·2729·220a·0a20·2020·200a·2020·2020·7975··')"..····.····yu 
0003b3c0:·6d20·7265·696e·7374·616c·6c20·2d79·2024··m·reinstall·-y·$ 
0003b3d0:·7061·636b·6167·6573·5f74·6f5f·7265·696e··packages_to_rein 
0003b3e0:·7374·616c·6c0a·2020·2020·0a66·690a·3c2f··stall.····.fi.</ 
0003b3f0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003b400:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003b410:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003b420:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003b430:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003b440:·2369·646d·3533·3030·2220·7461·6269·6e64··#idm5300"·tabind 
0003b450:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003b460:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003b470:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003b480:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003b490:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003b4a0:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi0003b190:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi
0003b4b0:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...<0003b1a0:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...<
0003b4c0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003b1b0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003b4d0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003b1c0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003b4e0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003b1d0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
0003b4f0:·6964·6d35·3330·3022·3e3c·7461·626c·6520··idm5300"><table·0003b1e0:·6964·6d35·3239·3922·3e3c·7461·626c·6520··idm5299"><table·
0003b500:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003b1f0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003b510:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003b200:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003b520:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003b210:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003b530:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003b220:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0003b540:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003b230:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0003b550:·7468·3e3c·7464·3e68·6967·683c·2f74·643e··th><td>high</td>0003b240:·7468·3e3c·7464·3e68·6967·683c·2f74·643e··th><td>high</td>
0003b560:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003b250:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003b570:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003b260:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003b580:·3e6d·6564·6975·6d3c·2f74·643e·3c2f·7472··>medium</td></tr0003b270:·3e6d·6564·6975·6d3c·2f74·643e·3c2f·7472··>medium</td></tr
0003b590:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:0003b280:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
0003b5a0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</0003b290:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
0003b5b0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003b2a0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b5c0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003b2b0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003b5d0:·643e·7265·7374·7269·6374·3c2f·7464·3e3c··d>restrict</td><0003b2c0:·643e·7265·7374·7269·6374·3c2f·7464·3e3c··d>restrict</td><
0003b5e0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0003b2d0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
0003b5f0:·3e3c·636f·6465·3e2d·206e·616d·653a·2027··><code>-·name:·'0003b2e0:·3e3c·636f·6465·3e2d·206e·616d·653a·2027··><code>-·name:·'
0003b600:·5365·7420·6661·6374·3a20·5061·636b·6167··Set·fact:·Packag0003b2f0:·5365·7420·6661·6374·3a20·5061·636b·6167··Set·fact:·Packag
0003b610:·6520·6d61·6e61·6765·7220·7265·696e·7374··e·manager·reinst0003b300:·6520·6d61·6e61·6765·7220·7265·696e·7374··e·manager·reinst
0003b620:·616c·6c20·636f·6d6d·616e·6427·0a20·2073··all·command'.··s0003b310:·616c·6c20·636f·6d6d·616e·6427·0a20·2073··all·command'.··s
0003b630:·6574·5f66·6163·743a·0a20·2020·2070·6163··et_fact:.····pac0003b320:·6574·5f66·6163·743a·0a20·2020·2070·6163··et_fact:.····pac
0003b640:·6b61·6765·5f6d·616e·6167·6572·5f72·6569··kage_manager_rei0003b330:·6b61·6765·5f6d·616e·6167·6572·5f72·6569··kage_manager_rei
0003b650:·6e73·7461·6c6c·5f63·6d64·3a20·7975·6d20··nstall_cmd:·yum·0003b340:·6e73·7461·6c6c·5f63·6d64·3a20·7975·6d20··nstall_cmd:·yum·
0003b660:·7265·696e·7374·616c·6c20·2d79·0a20·2077··reinstall·-y.··w0003b350:·7265·696e·7374·616c·6c20·2d79·0a20·2077··reinstall·-y.··w
0003b670:·6865·6e3a·2061·6e73·6962·6c65·5f64·6973··hen:·ansible_dis0003b360:·6865·6e3a·2061·6e73·6962·6c65·5f64·6973··hen:·ansible_dis
0003b680:·7472·6962·7574·696f·6e20·696e·205b·2022··tribution·in·[·"0003b370:·7472·6962·7574·696f·6e20·696e·205b·2022··tribution·in·[·"
0003b690:·4665·646f·7261·222c·2022·5265·6448·6174··Fedora",·"RedHat0003b380:·4665·646f·7261·222c·2022·5265·6448·6174··Fedora",·"RedHat
0003b6a0:·222c·2022·4365·6e74·4f53·222c·2022·4f72··",·"CentOS",·"Or0003b390:·222c·2022·4365·6e74·4f53·222c·2022·4f72··",·"CentOS",·"Or
0003b6b0:·6163·6c65·4c69·6e75·7822·205d·0a20·2074··acleLinux"·].··t0003b3a0:·6163·6c65·4c69·6e75·7822·205d·0a20·2074··acleLinux"·].··t
0003b6c0:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5.0003b3b0:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5.
0003b6d0:·3130·2e34·2e31·0a20·202d·2044·4953·412d··10.4.1.··-·DISA-0003b3c0:·3130·2e34·2e31·0a20·202d·2044·4953·412d··10.4.1.··-·DISA-
0003b6e0:·5354·4947·2d4f·4c30·372d·3030·2d30·3130··STIG-OL07-00-0100003b3d0:·5354·4947·2d4f·4c30·372d·3030·2d30·3130··STIG-OL07-00-010
0003b6f0:·3032·300a·2020·2d20·4e49·5354·2d38·3030··020.··-·NIST-8000003b3e0:·3032·300a·2020·2d20·4e49·5354·2d38·3030··020.··-·NIST-800
0003b700:·2d31·3731·2d33·2e33·2e38·0a20·202d·204e··-171-3.3.8.··-·N0003b3f0:·2d31·3731·2d33·2e33·2e38·0a20·202d·204e··-171-3.3.8.··-·N
0003b710:·4953·542d·3830·302d·3137·312d·332e·342e··IST-800-171-3.4.0003b400:·4953·542d·3830·302d·3137·312d·332e·342e··IST-800-171-3.4.
0003b720:·310a·2020·2d20·4e49·5354·2d38·3030·2d35··1.··-·NIST-800-50003b410:·310a·2020·2d20·4e49·5354·2d38·3030·2d35··1.··-·NIST-800-5
0003b730:·332d·4155·2d39·2833·290a·2020·2d20·4e49··3-AU-9(3).··-·NI0003b420:·332d·4155·2d39·2833·290a·2020·2d20·4e49··3-AU-9(3).··-·NI
0003b740:·5354·2d38·3030·2d35·332d·434d·2d36·2863··ST-800-53-CM-6(c0003b430:·5354·2d38·3030·2d35·332d·434d·2d36·2863··ST-800-53-CM-6(c
0003b750:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-50003b440:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5
0003b760:·332d·434d·2d36·2864·290a·2020·2d20·4e49··3-CM-6(d).··-·NI0003b450:·332d·434d·2d36·2864·290a·2020·2d20·4e49··3-CM-6(d).··-·NI
0003b770:·5354·2d38·3030·2d35·332d·5349·2d37·0a20··ST-800-53-SI-7.·0003b460:·5354·2d38·3030·2d35·332d·5349·2d37·0a20··ST-800-53-SI-7.·
0003b780:·202d·204e·4953·542d·3830·302d·3533·2d53···-·NIST-800-53-S0003b470:·202d·204e·4953·542d·3830·302d·3533·2d53···-·NIST-800-53-S
0003b790:·492d·3728·3129·0a20·202d·204e·4953·542d··I-7(1).··-·NIST-0003b480:·492d·3728·3129·0a20·202d·204e·4953·542d··I-7(1).··-·NIST-
0003b7a0:·3830·302d·3533·2d53·492d·3728·3629·0a20··800-53-SI-7(6).·0003b490:·3830·302d·3533·2d53·492d·3728·3629·0a20··800-53-SI-7(6).·
0003b7b0:·202d·2050·4349·2d44·5353·2d52·6571·2d31···-·PCI-DSS-Req-10003b4a0:·202d·2050·4349·2d44·5353·2d52·6571·2d31···-·PCI-DSS-Req-1
0003b7c0:·312e·350a·2020·2d20·5043·492d·4453·5376··1.5.··-·PCI-DSSv0003b4b0:·312e·350a·2020·2d20·5043·492d·4453·5376··1.5.··-·PCI-DSSv
0003b7d0:·342d·3131·2e35·2e32·0a20·202d·2068·6967··4-11.5.2.··-·hig0003b4c0:·342d·3131·2e35·2e32·0a20·202d·2068·6967··4-11.5.2.··-·hig
0003b7e0:·685f·636f·6d70·6c65·7869·7479·0a20·202d··h_complexity.··-0003b4d0:·685f·636f·6d70·6c65·7869·7479·0a20·202d··h_complexity.··-
0003b7f0:·2068·6967·685f·7365·7665·7269·7479·0a20···high_severity.·0003b4e0:·2068·6967·685f·7365·7665·7269·7479·0a20···high_severity.·
0003b800:·202d·206d·6564·6975·6d5f·6469·7372·7570···-·medium_disrup0003b4f0:·202d·206d·6564·6975·6d5f·6469·7372·7570···-·medium_disrup
Max diff block lines reached; 9531635/9550595 bytes (99.80%) of diff not shown.
823 KB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v3.2.1·Control·Baseline·Draft·for·Oracle·Linux·738 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v3.2.1·Control·Baseline·Draft·for·Oracle·Linux·7
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:oracle:linux:741 ····*·cpe:/o:oracle:linux:7
42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
43 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8443 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
49 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n49 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
50 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g50 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
51 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s51 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 97, 27 lines modifiedOffset 97, 14 lines modified
97 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)97 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
98 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-198 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
99 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.599 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
100 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227100 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
101 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010020101 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010020
102 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2102 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
103 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221653r853660_rule103 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221653r853660_rule
104 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
105 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
106 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
107 if·[·-n·"$files_with_incorrect_hash"·];·then 
108 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
109 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
110 ····yum·reinstall·-y·$packages_to_reinstall 
  
111 fi 
112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8104 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
113 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high105 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
114 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium106 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
115 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false107 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
116 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict108 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
117 -·name:·'Set·fact:·Package·manager·reinstall·command'109 -·name:·'Set·fact:·Package·manager·reinstall·command'
118 ··set_fact:110 ··set_fact:
Offset 249, 14 lines modifiedOffset 236, 27 lines modified
249 ··-·PCI-DSSv4-11.5.2236 ··-·PCI-DSSv4-11.5.2
250 ··-·high_complexity237 ··-·high_complexity
251 ··-·high_severity238 ··-·high_severity
252 ··-·medium_disruption239 ··-·medium_disruption
253 ··-·no_reboot_needed240 ··-·no_reboot_needed
254 ··-·restrict_strategy241 ··-·restrict_strategy
255 ··-·rpm_verify_hashes242 ··-·rpm_verify_hashes
 243 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 244 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 245 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 246 if·[·-n·"$files_with_incorrect_hash"·];·then
 247 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 248 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 249 ····yum·reinstall·-y·$packages_to_reinstall
  
 250 fi
256 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*251 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
257 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:252 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:
258 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'253 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'
259 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:254 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:
260 $·rpm·-qf·FILENAME255 $·rpm·-qf·FILENAME
  
261 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:256 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
Offset 279, 44 lines modifiedOffset 279, 14 lines modified
279 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)279 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)
280 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1280 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
281 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5281 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
282 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108282 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108
283 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010010283 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010010
284 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2284 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
285 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221652r880585_rule285 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221652r880585_rule
286 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
287 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
288 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
289 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
290 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
291 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
292 declare·-A·SETPERMS_RPM_DICT 
  
293 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
294 #·is·expected·by·the·RPM·database 
295 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}') 
  
296 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
297 do 
298 ········#·NOTE:·some·files·maybe·controlled·by·more·then·one·package 
299 ········readarray·-t·RPM_PACKAGES·<·<(rpm·-qf·"${FILE_PATH}") 
300 ········for·RPM_PACKAGE·in·"${RPM_PACKAGES[@]}" 
301 ········do 
302 ················#·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
303 ················SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
304 ········done 
305 done 
  
306 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
307 #·correct·values 
308 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
309 do 
310 »       rpm·--restore·"${RPM_PACKAGE}" 
311 done 
312 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8286 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
313 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high287 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
314 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium288 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
315 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false289 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
316 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict290 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
317 -·name:·Read·list·of·files·with·incorrect·permissions291 -·name:·Read·list·of·files·with·incorrect·permissions
318 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev292 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 397, 14 lines modifiedOffset 367, 44 lines modified
397 ··-·PCI-DSSv4-11.5.2367 ··-·PCI-DSSv4-11.5.2
398 ··-·high_complexity368 ··-·high_complexity
399 ··-·high_severity369 ··-·high_severity
400 ··-·medium_disruption370 ··-·medium_disruption
401 ··-·no_reboot_needed371 ··-·no_reboot_needed
402 ··-·restrict_strategy372 ··-·restrict_strategy
403 ··-·rpm_verify_permissions373 ··-·rpm_verify_permissions
 374 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 375 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 376 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
Max diff block lines reached; 834947/842703 bytes (99.08%) of diff not shown.
233 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-sap.html
    
Offset 14289, 16 lines modifiedOffset 14289, 16 lines modified
00037d00:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h00037d00:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h
00037d10:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver00037d10:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver
00037d20:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.00037d20:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.
00037d30:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p00037d30:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p
00037d40:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong00037d40:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong
00037d50:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.00037d50:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.
00037d60:·2020·2020·2020·2020·2020·2020·2020·2020··················00037d60:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037d70:·2020·2020·2861·7320·6f66·2032·3032·362d······(as·of·2026-00037d70:·2020·2020·2861·7320·6f66·2032·3032·342d······(as·of·2024-
00037d80:·3031·2d30·3829·0a20·2020·2020·2020·2020··01-08).·········00037d80:·3132·2d30·3729·0a20·2020·2020·2020·2020··12-07).·········
00037d90:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul00037d90:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul
00037da0:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table00037da0:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table
00037db0:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h200037db0:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2
00037dc0:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href00037dc0:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href
00037dd0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg00037dd0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg
00037de0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_00037de0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
00037df0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy00037df0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy
Offset 14650, 177 lines modifiedOffset 14650, 177 lines modified
00039390:·7461·7267·6574·3d22·2369·646d·3930·3333··target="#idm903300039390:·7461·7267·6574·3d22·2369·646d·3930·3333··target="#idm9033
000393a0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r000393a0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
000393b0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari000393b0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
000393c0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals000393c0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
000393d0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa000393d0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
000393e0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr000393e0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
000393f0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat000393f0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
00039400:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp00039400:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni
00039410:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d00039410:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
00039420:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-00039420:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
00039430:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps00039430:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
00039440:·6522·2069·643d·2269·646d·3930·3333·223e··e"·id="idm9033">00039440:·7073·6522·2069·643d·2269·646d·3930·3333··pse"·id="idm9033
00039450:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta00039450:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
00039460:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe00039460:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
00039470:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered00039470:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
00039480:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed00039480:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
00039490:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple00039490:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
000394a0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo000394a0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
000394b0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><000394b0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
000394c0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</000394c0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
000394d0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
000394e0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
000394f0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
00039500:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
00039510:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
00039520:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
00039530:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
00039540:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include· 
00039550:·696e·7374·616c·6c5f·676c·6962·630a·0a63··install_glibc..c 
00039560:·6c61·7373·2069·6e73·7461·6c6c·5f67·6c69··lass·install_gli 
00039570:·6263·207b·0a20·2070·6163·6b61·6765·207b··bc·{.··package·{ 
00039580:·2027·676c·6962·6327·3a0a·2020·2020·656e···'glibc':.····en 
00039590:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst 
000395a0:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</ 
000395b0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
000395c0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
000395d0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
000395e0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
000395f0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
00039600:·2369·646d·3930·3334·2220·7461·6269·6e64··#idm9034"·tabind 
00039610:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
00039620:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
00039630:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
00039640:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
00039650:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
00039660:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel 
00039670:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a> 
00039680:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
00039690:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
000396a0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
000396b0:·3930·3334·223e·3c74·6162·6c65·2063·6c61··9034"><table·cla 
000396c0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
000396d0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
000396e0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
000396f0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
00039700:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
00039710:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
00039720:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
00039730:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
00039740:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
00039750:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
00039760:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
00039770:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
00039780:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
00039790:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
000397a0:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a69··le><pre><code>.i 
000397b0:·6620·2120·7270·6d20·2d71·202d·2d71·7569··f·!·rpm·-q·--qui 
000397c0:·6574·2022·676c·6962·6322·203b·2074·6865··et·"glibc"·;·the 
000397d0:·6e0a·2020·2020·7975·6d20·696e·7374·616c··n.····yum·instal 
000397e0:·6c20·2d79·2022·676c·6962·6322·0a66·690a··l·-y·"glibc".fi. 
000397f0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
00039800:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
00039810:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
00039820:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
00039830:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
00039840:·3d22·2369·646d·3930·3335·2220·7461·6269··="#idm9035"·tabi 
00039850:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
00039860:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
00039870:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
00039880:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
00039890:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
000398a0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An 
000398b0:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
000398c0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
000398d0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
000398e0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
000398f0:·3d22·6964·6d39·3033·3522·3e3c·7461·626c··="idm9035"><tabl 
00039900:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
00039910:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
00039920:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
00039930:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
00039940:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
00039950:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td000394d0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
00039960:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di000394e0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 000394f0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 00039500:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 00039510:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 00039520:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 00039530:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 00039540:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa
 00039550:·6765·202d·2d61·6464·3d67·6c69·6263·0a3c··ge·--add=glibc.<
 00039560:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 00039570:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 00039580:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 00039590:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 000395a0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 000395b0:·2223·6964·6d39·3033·3422·2074·6162·696e··"#idm9034"·tabin
 000395c0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 000395d0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 000395e0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
Max diff block lines reached; 187738/212080 bytes (88.52%) of diff not shown.
26.3 KB
html2text {}
    
Offset 39, 15 lines modifiedOffset 39, 15 lines modified
39 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*39 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Security·Profile·of·Oracle·Linux·7·for·SAP40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Security·Profile·of·Oracle·Linux·7·for·SAP
41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_sap41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_sap
42 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*42 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
43 ····*·cpe:/o:oracle:linux:743 ····*·cpe:/o:oracle:linux:7
44 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*44 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
45 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8445 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
46 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)46 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
47 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
48 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s48 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
49 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e49 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
50 ·········2.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s50 ·········2.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
51 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s51 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
52 ·········1.·_\x8O_\x8b_\x8s_\x8o_\x8l_\x8e_\x8t_\x8e_\x8·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s52 ·········1.·_\x8O_\x8b_\x8s_\x8o_\x8l_\x8e_\x8t_\x8e_\x8·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
53 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*53 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*
Offset 64, 35 lines modifiedOffset 64, 38 lines modified
64 The·package·glibc·is·installed·on·Linux·by·default,·but·the·glibc·version·might·not·be·sufficient·for·SAP.·Please·refer·to·SAP·note·of·your·Linux·version·for·the64 The·package·glibc·is·installed·on·Linux·by·default,·but·the·glibc·version·might·not·be·sufficient·for·SAP.·Please·refer·to·SAP·note·of·your·Linux·version·for·the
65 minimum·requirement·on·glibc.·The·glibc·package·can·be·installed·with·the·following·command:65 minimum·requirement·on·glibc.·The·glibc·package·can·be·installed·with·the·following·command:
66 $·sudo·yum·install·glibc66 $·sudo·yum·install·glibc
67 Rationale:·The·glibc·package·contains·standard·C·and·math·libraries·used·by·multiple·programs·on·Linux.·The·glibc·shipped·with·first·release·of·each·major·Linux67 Rationale:·The·glibc·package·contains·standard·C·and·math·libraries·used·by·multiple·programs·on·Linux.·The·glibc·shipped·with·first·release·of·each·major·Linux
68 ···········version·is·often·not·sufficient·for·SAP.·An·update·is·required·after·the·first·OS·installation.68 ···········version·is·often·not·sufficient·for·SAP.·An·update·is·required·after·the·first·OS·installation.
69 Severity: ·medium69 Severity: ·medium
70 Rule·ID:···xccdf_org.ssgproject.content_rule_package_glibc_installed70 Rule·ID:···xccdf_org.ssgproject.content_rule_package_glibc_installed
 71 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 72 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 73 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 74 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 75 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 76 package·--add=glibc
71 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x877 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
72 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low78 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
73 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low79 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
74 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false80 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
75 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable81 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
76 include·install_glibc82 include·install_glibc
  
77 class·install_glibc·{83 class·install_glibc·{
78 ··package·{·'glibc':84 ··package·{·'glibc':
79 ····ensure·=>·'installed',85 ····ensure·=>·'installed',
80 ··}86 ··}
81 }87 }
 88 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
82 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
83 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
84 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
85 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
86 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
87 if·!·rpm·-q·--quiet·"glibc"·;·then 
88 ····yum·install·-y·"glibc" 
89 fi89 [[packages]]
 90 name·=·"glibc"
 91 version·=·"*"
90 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x892 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
91 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low93 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
92 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low94 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
93 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false95 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
94 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable96 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
95 -·name:·Ensure·glibc·is·installed97 -·name:·Ensure·glibc·is·installed
96 ··package:98 ··package:
Offset 101, 55 lines modifiedOffset 104, 55 lines modified
101 ··tags:104 ··tags:
102 ··-·enable_strategy105 ··-·enable_strategy
103 ··-·low_complexity106 ··-·low_complexity
104 ··-·low_disruption107 ··-·low_disruption
105 ··-·medium_severity108 ··-·medium_severity
106 ··-·no_reboot_needed109 ··-·no_reboot_needed
107 ··-·package_glibc_installed110 ··-·package_glibc_installed
108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
109 [[packages]] 
110 name·=·"glibc" 
111 version·=·"*" 
112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_.n_.a_.c_.o_.n_.d_.a_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8111 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
113 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low112 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
114 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low113 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
115 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false114 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
116 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable115 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
117 package·--add=glibc116 if·!·rpm·-q·--quiet·"glibc"·;·then
 117 ····yum·install·-y·"glibc"
 118 fi
118 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·u\x8uu\x8ui\x8id\x8dd\x8d·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*119 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·u\x8uu\x8ui\x8id\x8dd\x8d·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
119 The·package·uuidd·is·not·installed·on·normal·Linux·distribution·by·default.·Applications·require·this·package·to·avoid·database·inconsistences·caused·by·duplicated120 The·package·uuidd·is·not·installed·on·normal·Linux·distribution·by·default.·Applications·require·this·package·to·avoid·database·inconsistences·caused·by·duplicated
120 UUIDs.·Especially·in·banking·services·with·SAP·where·massive·UUIDs·are·created·in·a·short·time·period,·it·is·important·to·install·the·package·uuidd.·More·information121 UUIDs.·Especially·in·banking·services·with·SAP·where·massive·UUIDs·are·created·in·a·short·time·period,·it·is·important·to·install·the·package·uuidd.·More·information
121 can·be·found·in·SAP·note·1391070.·The·uuidd·package·can·be·installed·with·the·following·command:122 can·be·found·in·SAP·note·1391070.·The·uuidd·package·can·be·installed·with·the·following·command:
122 $·sudo·yum·install·uuidd123 $·sudo·yum·install·uuidd
123 Rationale:·The·uuidd·package·contains·a·userspace·daemon·(uuidd)·which·is·used·to·generate·unique·identifiers·even·at·very·high·rates·on·SMP·systems.124 Rationale:·The·uuidd·package·contains·a·userspace·daemon·(uuidd)·which·is·used·to·generate·unique·identifiers·even·at·very·high·rates·on·SMP·systems.
124 Severity: ·medium125 Severity: ·medium
125 Rule·ID:···xccdf_org.ssgproject.content_rule_package_uuidd_installed126 Rule·ID:···xccdf_org.ssgproject.content_rule_package_uuidd_installed
 127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 132 package·--add=uuidd
126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
131 include·install_uuidd138 include·install_uuidd
  
132 class·install_uuidd·{139 class·install_uuidd·{
133 ··package·{·'uuidd':140 ··package·{·'uuidd':
134 ····ensure·=>·'installed',141 ····ensure·=>·'installed',
135 ··}142 ··}
136 }143 }
 144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
142 if·!·rpm·-q·--quiet·"uuidd"·;·then 
143 ····yum·install·-y·"uuidd" 
144 fi145 [[packages]]
 146 name·=·"uuidd"
 147 version·=·"*"
145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low149 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low150 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false151 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable152 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 20872/26861 bytes (77.70%) of diff not shown.
9.62 MB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-standard.html
    
Offset 14285, 16 lines modifiedOffset 14285, 16 lines modified
00037cc0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00037cc0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00037cd0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00037cd0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00037ce0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000037ce0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00037cf0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></00037cf0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
00037d00:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00037d00:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00037d10:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00037d10:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00037d20:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037d20:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037d30:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600037d30:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
00037d40:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········00037d40:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00037d50:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00037d50:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00037d60:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00037d60:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00037d70:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00037d70:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00037d80:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00037d80:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00037d90:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00037d90:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00037da0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00037da0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00037db0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00037db0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
Offset 15108, 310 lines modifiedOffset 15108, 310 lines modified
0003b030:·612d·7461·7267·6574·3d22·2369·646d·3532··a-target="#idm520003b030:·612d·7461·7267·6574·3d22·2369·646d·3532··a-target="#idm52
0003b040:·3939·2220·7461·6269·6e64·6578·3d22·3022··99"·tabindex="0"0003b040:·3939·2220·7461·6269·6e64·6578·3d22·3022··99"·tabindex="0"
0003b050:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003b050:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003b060:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003b060:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003b070:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003b070:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003b080:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003b080:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003b090:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003b090:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003b0a0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
0003b0b0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
0003b0c0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003b0d0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003b0e0:·6522·2069·643d·2269·646d·3532·3939·223e··e"·id="idm5299"> 
0003b0f0:·3c70·7265·3e3c·636f·6465·3e0a·2320·4669··<pre><code>.#·Fi 
0003b100:·6e64·2077·6869·6368·2066·696c·6573·2068··nd·which·files·h 
0003b110:·6176·6520·696e·636f·7272·6563·7420·6861··ave·incorrect·ha 
0003b120:·7368·2028·6e6f·7420·696e·202f·6574·632c··sh·(not·in·/etc, 
0003b130:·2062·6563·6175·7365·206f·6620·7468·6520···because·of·the· 
0003b140:·7379·7374·656d·2072·656c·6174·6564·2063··system·related·c 
0003b150:·6f6e·6669·6720·6669·6c65·7329·2061·6e64··onfig·files)·and 
0003b160:·2074·6865·6e20·6765·7420·6669·6c65·7320···then·get·files· 
0003b170:·6e61·6d65·730a·6669·6c65·735f·7769·7468··names.files_with 
0003b180:·5f69·6e63·6f72·7265·6374·5f68·6173·683d··_incorrect_hash= 
0003b190:·2224·2872·706d·202d·5661·202d·2d6e·6f63··"$(rpm·-Va·--noc 
0003b1a0:·6f6e·6669·6720·7c20·6772·6570·202d·4520··onfig·|·grep·-E· 
0003b1b0:·275e·2e2e·3527·207c·2061·776b·2027·7b70··'^..5'·|·awk·'{p 
0003b1c0:·7269·6e74·2024·4e46·7d27·2029·220a·0a69··rint·$NF}'·)"..i 
0003b1d0:·6620·5b20·2d6e·2022·2466·696c·6573·5f77··f·[·-n·"$files_w 
0003b1e0:·6974·685f·696e·636f·7272·6563·745f·6861··ith_incorrect_ha 
0003b1f0:·7368·2220·5d3b·2074·6865·6e0a·2020·2020··sh"·];·then.···· 
0003b200:·2320·4672·6f6d·2066·696c·6573·206e·616d··#·From·files·nam 
0003b210:·6573·2067·6574·2070·6163·6b61·6765·206e··es·get·package·n 
0003b220:·616d·6573·2061·6e64·2063·6861·6e67·6520··ames·and·change· 
0003b230:·6e65·776c·696e·6520·746f·2073·7061·6365··newline·to·space 
0003b240:·2c20·6265·6361·7573·6520·7270·6d20·7772··,·because·rpm·wr 
0003b250:·6974·6573·2065·6163·6820·7061·636b·6167··ites·each·packag 
0003b260:·6520·746f·206e·6577·206c·696e·650a·2020··e·to·new·line.·· 
0003b270:·2020·7061·636b·6167·6573·5f74·6f5f·7265····packages_to_re 
0003b280:·696e·7374·616c·6c3d·2224·2872·706d·202d··install="$(rpm·- 
0003b290:·7166·2024·6669·6c65·735f·7769·7468·5f69··qf·$files_with_i 
0003b2a0:·6e63·6f72·7265·6374·5f68·6173·6820·7c20··ncorrect_hash·|· 
0003b2b0:·7472·2027·5c6e·2720·2720·2729·220a·0a20··tr·'\n'·'·')"..· 
0003b2c0:·2020·200a·2020·2020·7975·6d20·7265·696e·····.····yum·rein 
0003b2d0:·7374·616c·6c20·2d79·2024·7061·636b·6167··stall·-y·$packag 
0003b2e0:·6573·5f74·6f5f·7265·696e·7374·616c·6c0a··es_to_reinstall. 
0003b2f0:·2020·2020·0a66·690a·3c2f·636f·6465·3e3c······.fi.</code>< 
0003b300:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003b310:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003b320:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003b330:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003b340:·612d·7461·7267·6574·3d22·2369·646d·3533··a-target="#idm53 
0003b350:·3030·2220·7461·6269·6e64·6578·3d22·3022··00"·tabindex="0" 
0003b360:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003b370:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003b380:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003b390:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003b3a0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003b3b0:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn0003b0a0:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn
0003b3c0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003b0b0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003b3d0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003b0c0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003b3e0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003b0d0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003b3f0:·6170·7365·2220·6964·3d22·6964·6d35·3330··apse"·id="idm5300003b0e0:·6170·7365·2220·6964·3d22·6964·6d35·3239··apse"·id="idm529
0003b400:·3022·3e3c·7461·626c·6520·636c·6173·733d··0"><table·class=0003b0f0:·3922·3e3c·7461·626c·6520·636c·6173·733d··9"><table·class=
0003b410:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003b100:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003b420:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003b110:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003b430:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003b120:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003b440:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003b130:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003b450:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003b140:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003b460:·3e68·6967·683c·2f74·643e·3c2f·7472·3e3c··>high</td></tr><0003b150:·3e68·6967·683c·2f74·643e·3c2f·7472·3e3c··>high</td></tr><
0003b470:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003b160:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003b480:·6e3a·3c2f·7468·3e3c·7464·3e6d·6564·6975··n:</th><td>mediu0003b170:·6e3a·3c2f·7468·3e3c·7464·3e6d·6564·6975··n:</th><td>mediu
0003b490:·6d3c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··m</td></tr><tr><0003b180:·6d3c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··m</td></tr><tr><
0003b4a0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><0003b190:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
0003b4b0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t0003b1a0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
0003b4c0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate0003b1b0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003b4d0:·6779·3a3c·2f74·683e·3c74·643e·7265·7374··gy:</th><td>rest0003b1c0:·6779·3a3c·2f74·683e·3c74·643e·7265·7374··gy:</th><td>rest
0003b4e0:·7269·6374·3c2f·7464·3e3c·2f74·723e·3c2f··rict</td></tr></0003b1d0:·7269·6374·3c2f·7464·3e3c·2f74·723e·3c2f··rict</td></tr></
0003b4f0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003b1e0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
0003b500:·3e2d·206e·616d·653a·2027·5365·7420·6661··>-·name:·'Set·fa0003b1f0:·3e2d·206e·616d·653a·2027·5365·7420·6661··>-·name:·'Set·fa
0003b510:·6374·3a20·5061·636b·6167·6520·6d61·6e61··ct:·Package·mana0003b200:·6374·3a20·5061·636b·6167·6520·6d61·6e61··ct:·Package·mana
0003b520:·6765·7220·7265·696e·7374·616c·6c20·636f··ger·reinstall·co0003b210:·6765·7220·7265·696e·7374·616c·6c20·636f··ger·reinstall·co
0003b530:·6d6d·616e·6427·0a20·2073·6574·5f66·6163··mmand'.··set_fac0003b220:·6d6d·616e·6427·0a20·2073·6574·5f66·6163··mmand'.··set_fac
0003b540:·743a·0a20·2020·2070·6163·6b61·6765·5f6d··t:.····package_m0003b230:·743a·0a20·2020·2070·6163·6b61·6765·5f6d··t:.····package_m
0003b550:·616e·6167·6572·5f72·6569·6e73·7461·6c6c··anager_reinstall0003b240:·616e·6167·6572·5f72·6569·6e73·7461·6c6c··anager_reinstall
0003b560:·5f63·6d64·3a20·7975·6d20·7265·696e·7374··_cmd:·yum·reinst0003b250:·5f63·6d64·3a20·7975·6d20·7265·696e·7374··_cmd:·yum·reinst
0003b570:·616c·6c20·2d79·0a20·2077·6865·6e3a·2061··all·-y.··when:·a0003b260:·616c·6c20·2d79·0a20·2077·6865·6e3a·2061··all·-y.··when:·a
0003b580:·6e73·6962·6c65·5f64·6973·7472·6962·7574··nsible_distribut0003b270:·6e73·6962·6c65·5f64·6973·7472·6962·7574··nsible_distribut
0003b590:·696f·6e20·696e·205b·2022·4665·646f·7261··ion·in·[·"Fedora0003b280:·696f·6e20·696e·205b·2022·4665·646f·7261··ion·in·[·"Fedora
0003b5a0:·222c·2022·5265·6448·6174·222c·2022·4365··",·"RedHat",·"Ce0003b290:·222c·2022·5265·6448·6174·222c·2022·4365··",·"RedHat",·"Ce
0003b5b0:·6e74·4f53·222c·2022·4f72·6163·6c65·4c69··ntOS",·"OracleLi0003b2a0:·6e74·4f53·222c·2022·4f72·6163·6c65·4c69··ntOS",·"OracleLi
0003b5c0:·6e75·7822·205d·0a20·2074·6167·733a·0a20··nux"·].··tags:.·0003b2b0:·6e75·7822·205d·0a20·2074·6167·733a·0a20··nux"·].··tags:.·
0003b5d0:·202d·2043·4a49·532d·352e·3130·2e34·2e31···-·CJIS-5.10.4.10003b2c0:·202d·2043·4a49·532d·352e·3130·2e34·2e31···-·CJIS-5.10.4.1
0003b5e0:·0a20·202d·2044·4953·412d·5354·4947·2d4f··.··-·DISA-STIG-O0003b2d0:·0a20·202d·2044·4953·412d·5354·4947·2d4f··.··-·DISA-STIG-O
0003b5f0:·4c30·372d·3030·2d30·3130·3032·300a·2020··L07-00-010020.··0003b2e0:·4c30·372d·3030·2d30·3130·3032·300a·2020··L07-00-010020.··
0003b600:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-30003b2f0:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-3
0003b610:·2e33·2e38·0a20·202d·204e·4953·542d·3830··.3.8.··-·NIST-800003b300:·2e33·2e38·0a20·202d·204e·4953·542d·3830··.3.8.··-·NIST-80
0003b620:·302d·3137·312d·332e·342e·310a·2020·2d20··0-171-3.4.1.··-·0003b310:·302d·3137·312d·332e·342e·310a·2020·2d20··0-171-3.4.1.··-·
0003b630:·4e49·5354·2d38·3030·2d35·332d·4155·2d39··NIST-800-53-AU-90003b320:·4e49·5354·2d38·3030·2d35·332d·4155·2d39··NIST-800-53-AU-9
0003b640:·2833·290a·2020·2d20·4e49·5354·2d38·3030··(3).··-·NIST-8000003b330:·2833·290a·2020·2d20·4e49·5354·2d38·3030··(3).··-·NIST-800
0003b650:·2d35·332d·434d·2d36·2863·290a·2020·2d20··-53-CM-6(c).··-·0003b340:·2d35·332d·434d·2d36·2863·290a·2020·2d20··-53-CM-6(c).··-·
0003b660:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-60003b350:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6
0003b670:·2864·290a·2020·2d20·4e49·5354·2d38·3030··(d).··-·NIST-8000003b360:·2864·290a·2020·2d20·4e49·5354·2d38·3030··(d).··-·NIST-800
0003b680:·2d35·332d·5349·2d37·0a20·202d·204e·4953··-53-SI-7.··-·NIS0003b370:·2d35·332d·5349·2d37·0a20·202d·204e·4953··-53-SI-7.··-·NIS
0003b690:·542d·3830·302d·3533·2d53·492d·3728·3129··T-800-53-SI-7(1)0003b380:·542d·3830·302d·3533·2d53·492d·3728·3129··T-800-53-SI-7(1)
0003b6a0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-530003b390:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
0003b6b0:·2d53·492d·3728·3629·0a20·202d·2050·4349··-SI-7(6).··-·PCI0003b3a0:·2d53·492d·3728·3629·0a20·202d·2050·4349··-SI-7(6).··-·PCI
0003b6c0:·2d44·5353·2d52·6571·2d31·312e·350a·2020··-DSS-Req-11.5.··0003b3b0:·2d44·5353·2d52·6571·2d31·312e·350a·2020··-DSS-Req-11.5.··
0003b6d0:·2d20·5043·492d·4453·5376·342d·3131·2e35··-·PCI-DSSv4-11.50003b3c0:·2d20·5043·492d·4453·5376·342d·3131·2e35··-·PCI-DSSv4-11.5
0003b6e0:·2e32·0a20·202d·2068·6967·685f·636f·6d70··.2.··-·high_comp0003b3d0:·2e32·0a20·202d·2068·6967·685f·636f·6d70··.2.··-·high_comp
0003b6f0:·6c65·7869·7479·0a20·202d·2068·6967·685f··lexity.··-·high_0003b3e0:·6c65·7869·7479·0a20·202d·2068·6967·685f··lexity.··-·high_
0003b700:·7365·7665·7269·7479·0a20·202d·206d·6564··severity.··-·med0003b3f0:·7365·7665·7269·7479·0a20·202d·206d·6564··severity.··-·med
Max diff block lines reached; 9286865/9329561 bytes (99.54%) of diff not shown.
737 KB
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Oracle·Linux·739 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Oracle·Linux·7
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard
41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
42 ····*·cpe:/o:oracle:linux:742 ····*·cpe:/o:oracle:linux:7
43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
44 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8444 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
49 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l49 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
51 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s51 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
52 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s52 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
Offset 95, 27 lines modifiedOffset 95, 14 lines modified
95 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)95 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
96 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-196 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
97 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.597 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
98 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-0022798 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
99 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-01002099 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010020
100 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2100 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
101 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221653r853660_rule101 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221653r853660_rule
102 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
103 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
104 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
105 if·[·-n·"$files_with_incorrect_hash"·];·then 
106 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
107 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
108 ····yum·reinstall·-y·$packages_to_reinstall 
  
109 fi 
110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8102 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
111 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high103 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
112 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium104 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
113 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false105 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
114 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict106 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
115 -·name:·'Set·fact:·Package·manager·reinstall·command'107 -·name:·'Set·fact:·Package·manager·reinstall·command'
116 ··set_fact:108 ··set_fact:
Offset 247, 14 lines modifiedOffset 234, 27 lines modified
247 ··-·PCI-DSSv4-11.5.2234 ··-·PCI-DSSv4-11.5.2
248 ··-·high_complexity235 ··-·high_complexity
249 ··-·high_severity236 ··-·high_severity
250 ··-·medium_disruption237 ··-·medium_disruption
251 ··-·no_reboot_needed238 ··-·no_reboot_needed
252 ··-·restrict_strategy239 ··-·restrict_strategy
253 ··-·rpm_verify_hashes240 ··-·rpm_verify_hashes
 241 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 242 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 243 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 244 if·[·-n·"$files_with_incorrect_hash"·];·then
 245 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 246 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 247 ····yum·reinstall·-y·$packages_to_reinstall
  
 248 fi
254 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*249 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
255 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:250 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:
256 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'251 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'
257 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:252 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:
258 $·rpm·-qf·FILENAME253 $·rpm·-qf·FILENAME
  
259 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:254 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
Offset 277, 44 lines modifiedOffset 277, 14 lines modified
277 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)277 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)
278 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1278 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
279 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5279 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
280 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108280 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108
281 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010010281 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010010
282 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2282 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
283 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221652r880585_rule283 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221652r880585_rule
284 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
285 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
286 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
287 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
288 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
289 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
290 declare·-A·SETPERMS_RPM_DICT 
  
291 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
292 #·is·expected·by·the·RPM·database 
293 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}') 
  
294 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
295 do 
296 ········#·NOTE:·some·files·maybe·controlled·by·more·then·one·package 
297 ········readarray·-t·RPM_PACKAGES·<·<(rpm·-qf·"${FILE_PATH}") 
298 ········for·RPM_PACKAGE·in·"${RPM_PACKAGES[@]}" 
299 ········do 
300 ················#·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
301 ················SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
302 ········done 
303 done 
  
304 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
305 #·correct·values 
306 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
307 do 
308 »       rpm·--restore·"${RPM_PACKAGE}" 
309 done 
310 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8284 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
311 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high285 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
312 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium286 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
313 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false287 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
314 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict288 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
315 -·name:·Read·list·of·files·with·incorrect·permissions289 -·name:·Read·list·of·files·with·incorrect·permissions
316 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev290 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 395, 14 lines modifiedOffset 365, 44 lines modified
395 ··-·PCI-DSSv4-11.5.2365 ··-·PCI-DSSv4-11.5.2
396 ··-·high_complexity366 ··-·high_complexity
397 ··-·high_severity367 ··-·high_severity
398 ··-·medium_disruption368 ··-·medium_disruption
399 ··-·no_reboot_needed369 ··-·no_reboot_needed
400 ··-·restrict_strategy370 ··-·restrict_strategy
401 ··-·rpm_verify_permissions371 ··-·rpm_verify_permissions
 372 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 373 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 374 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
Max diff block lines reached; 747340/754984 bytes (98.99%) of diff not shown.
22.6 MB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-stig.html
    
Offset 14278, 16 lines modifiedOffset 14278, 16 lines modified
00037c50:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><00037c50:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><
00037c60:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio00037c60:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio
00037c70:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.700037c70:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.7
00037c80:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u00037c80:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u
00037c90:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr00037c90:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr
00037ca0:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···00037ca0:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···
00037cb0:·2020·2020·2020·2020·2020·2020·2020·2020··················00037cb0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037cc0:·2028·6173·206f·6620·3230·3236·2d30·312d···(as·of·2026-01-00037cc0:·2028·6173·206f·6620·3230·3234·2d31·322d···(as·of·2024-12-
00037cd0:·3038·290a·2020·2020·2020·2020·2020·2020··08).············00037cd0:·3037·290a·2020·2020·2020·2020·2020·2020··07).············
00037ce0:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></00037ce0:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></
00037cf0:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of00037cf0:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of
00037d00:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o00037d00:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o
00037d10:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#00037d10:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#
00037d20:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro00037d20:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro
00037d30:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro00037d30:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro
00037d40:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste00037d40:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste
Offset 15172, 310 lines modifiedOffset 15172, 310 lines modified
0003b430:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b430:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b440:·2369·646d·3532·3939·2220·7461·6269·6e64··#idm5299"·tabind0003b440:·2369·646d·3532·3939·2220·7461·6269·6e64··#idm5299"·tabind
0003b450:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b450:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b460:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b460:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b470:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b470:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b480:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b480:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b490:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b490:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b4a0:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel 
0003b4b0:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a> 
0003b4c0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b4d0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b4e0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b4f0:·3532·3939·223e·3c70·7265·3e3c·636f·6465··5299"><pre><code 
0003b500:·3e0a·2320·4669·6e64·2077·6869·6368·2066··>.#·Find·which·f 
0003b510:·696c·6573·2068·6176·6520·696e·636f·7272··iles·have·incorr 
0003b520:·6563·7420·6861·7368·2028·6e6f·7420·696e··ect·hash·(not·in 
0003b530:·202f·6574·632c·2062·6563·6175·7365·206f···/etc,·because·o 
0003b540:·6620·7468·6520·7379·7374·656d·2072·656c··f·the·system·rel 
0003b550:·6174·6564·2063·6f6e·6669·6720·6669·6c65··ated·config·file 
0003b560:·7329·2061·6e64·2074·6865·6e20·6765·7420··s)·and·then·get· 
0003b570:·6669·6c65·7320·6e61·6d65·730a·6669·6c65··files·names.file 
0003b580:·735f·7769·7468·5f69·6e63·6f72·7265·6374··s_with_incorrect 
0003b590:·5f68·6173·683d·2224·2872·706d·202d·5661··_hash="$(rpm·-Va 
0003b5a0:·202d·2d6e·6f63·6f6e·6669·6720·7c20·6772···--noconfig·|·gr 
0003b5b0:·6570·202d·4520·275e·2e2e·3527·207c·2061··ep·-E·'^..5'·|·a 
0003b5c0:·776b·2027·7b70·7269·6e74·2024·4e46·7d27··wk·'{print·$NF}' 
0003b5d0:·2029·220a·0a69·6620·5b20·2d6e·2022·2466···)"..if·[·-n·"$f 
0003b5e0:·696c·6573·5f77·6974·685f·696e·636f·7272··iles_with_incorr 
0003b5f0:·6563·745f·6861·7368·2220·5d3b·2074·6865··ect_hash"·];·the 
0003b600:·6e0a·2020·2020·2320·4672·6f6d·2066·696c··n.····#·From·fil 
0003b610:·6573·206e·616d·6573·2067·6574·2070·6163··es·names·get·pac 
0003b620:·6b61·6765·206e·616d·6573·2061·6e64·2063··kage·names·and·c 
0003b630:·6861·6e67·6520·6e65·776c·696e·6520·746f··hange·newline·to 
0003b640:·2073·7061·6365·2c20·6265·6361·7573·6520···space,·because· 
0003b650:·7270·6d20·7772·6974·6573·2065·6163·6820··rpm·writes·each· 
0003b660:·7061·636b·6167·6520·746f·206e·6577·206c··package·to·new·l 
0003b670:·696e·650a·2020·2020·7061·636b·6167·6573··ine.····packages 
0003b680:·5f74·6f5f·7265·696e·7374·616c·6c3d·2224··_to_reinstall="$ 
0003b690:·2872·706d·202d·7166·2024·6669·6c65·735f··(rpm·-qf·$files_ 
0003b6a0:·7769·7468·5f69·6e63·6f72·7265·6374·5f68··with_incorrect_h 
0003b6b0:·6173·6820·7c20·7472·2027·5c6e·2720·2720··ash·|·tr·'\n'·'· 
0003b6c0:·2729·220a·0a20·2020·200a·2020·2020·7975··')"..····.····yu 
0003b6d0:·6d20·7265·696e·7374·616c·6c20·2d79·2024··m·reinstall·-y·$ 
0003b6e0:·7061·636b·6167·6573·5f74·6f5f·7265·696e··packages_to_rein 
0003b6f0:·7374·616c·6c0a·2020·2020·0a66·690a·3c2f··stall.····.fi.</ 
0003b700:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003b710:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003b720:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003b730:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003b740:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003b750:·2369·646d·3533·3030·2220·7461·6269·6e64··#idm5300"·tabind 
0003b760:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003b770:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003b780:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003b790:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003b7a0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003b7b0:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi0003b4a0:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi
0003b7c0:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...<0003b4b0:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...<
0003b7d0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003b4c0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003b7e0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003b4d0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003b7f0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003b4e0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
0003b800:·6964·6d35·3330·3022·3e3c·7461·626c·6520··idm5300"><table·0003b4f0:·6964·6d35·3239·3922·3e3c·7461·626c·6520··idm5299"><table·
0003b810:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003b500:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003b820:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003b510:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003b830:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003b520:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003b840:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003b530:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0003b850:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003b540:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0003b860:·7468·3e3c·7464·3e68·6967·683c·2f74·643e··th><td>high</td>0003b550:·7468·3e3c·7464·3e68·6967·683c·2f74·643e··th><td>high</td>
0003b870:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003b560:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003b880:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003b570:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003b890:·3e6d·6564·6975·6d3c·2f74·643e·3c2f·7472··>medium</td></tr0003b580:·3e6d·6564·6975·6d3c·2f74·643e·3c2f·7472··>medium</td></tr
0003b8a0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:0003b590:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
0003b8b0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</0003b5a0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
0003b8c0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003b5b0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b8d0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003b5c0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003b8e0:·643e·7265·7374·7269·6374·3c2f·7464·3e3c··d>restrict</td><0003b5d0:·643e·7265·7374·7269·6374·3c2f·7464·3e3c··d>restrict</td><
0003b8f0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0003b5e0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
0003b900:·3e3c·636f·6465·3e2d·206e·616d·653a·2027··><code>-·name:·'0003b5f0:·3e3c·636f·6465·3e2d·206e·616d·653a·2027··><code>-·name:·'
0003b910:·5365·7420·6661·6374·3a20·5061·636b·6167··Set·fact:·Packag0003b600:·5365·7420·6661·6374·3a20·5061·636b·6167··Set·fact:·Packag
0003b920:·6520·6d61·6e61·6765·7220·7265·696e·7374··e·manager·reinst0003b610:·6520·6d61·6e61·6765·7220·7265·696e·7374··e·manager·reinst
0003b930:·616c·6c20·636f·6d6d·616e·6427·0a20·2073··all·command'.··s0003b620:·616c·6c20·636f·6d6d·616e·6427·0a20·2073··all·command'.··s
0003b940:·6574·5f66·6163·743a·0a20·2020·2070·6163··et_fact:.····pac0003b630:·6574·5f66·6163·743a·0a20·2020·2070·6163··et_fact:.····pac
0003b950:·6b61·6765·5f6d·616e·6167·6572·5f72·6569··kage_manager_rei0003b640:·6b61·6765·5f6d·616e·6167·6572·5f72·6569··kage_manager_rei
0003b960:·6e73·7461·6c6c·5f63·6d64·3a20·7975·6d20··nstall_cmd:·yum·0003b650:·6e73·7461·6c6c·5f63·6d64·3a20·7975·6d20··nstall_cmd:·yum·
0003b970:·7265·696e·7374·616c·6c20·2d79·0a20·2077··reinstall·-y.··w0003b660:·7265·696e·7374·616c·6c20·2d79·0a20·2077··reinstall·-y.··w
0003b980:·6865·6e3a·2061·6e73·6962·6c65·5f64·6973··hen:·ansible_dis0003b670:·6865·6e3a·2061·6e73·6962·6c65·5f64·6973··hen:·ansible_dis
0003b990:·7472·6962·7574·696f·6e20·696e·205b·2022··tribution·in·[·"0003b680:·7472·6962·7574·696f·6e20·696e·205b·2022··tribution·in·[·"
0003b9a0:·4665·646f·7261·222c·2022·5265·6448·6174··Fedora",·"RedHat0003b690:·4665·646f·7261·222c·2022·5265·6448·6174··Fedora",·"RedHat
0003b9b0:·222c·2022·4365·6e74·4f53·222c·2022·4f72··",·"CentOS",·"Or0003b6a0:·222c·2022·4365·6e74·4f53·222c·2022·4f72··",·"CentOS",·"Or
0003b9c0:·6163·6c65·4c69·6e75·7822·205d·0a20·2074··acleLinux"·].··t0003b6b0:·6163·6c65·4c69·6e75·7822·205d·0a20·2074··acleLinux"·].··t
0003b9d0:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5.0003b6c0:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5.
0003b9e0:·3130·2e34·2e31·0a20·202d·2044·4953·412d··10.4.1.··-·DISA-0003b6d0:·3130·2e34·2e31·0a20·202d·2044·4953·412d··10.4.1.··-·DISA-
0003b9f0:·5354·4947·2d4f·4c30·372d·3030·2d30·3130··STIG-OL07-00-0100003b6e0:·5354·4947·2d4f·4c30·372d·3030·2d30·3130··STIG-OL07-00-010
0003ba00:·3032·300a·2020·2d20·4e49·5354·2d38·3030··020.··-·NIST-8000003b6f0:·3032·300a·2020·2d20·4e49·5354·2d38·3030··020.··-·NIST-800
0003ba10:·2d31·3731·2d33·2e33·2e38·0a20·202d·204e··-171-3.3.8.··-·N0003b700:·2d31·3731·2d33·2e33·2e38·0a20·202d·204e··-171-3.3.8.··-·N
0003ba20:·4953·542d·3830·302d·3137·312d·332e·342e··IST-800-171-3.4.0003b710:·4953·542d·3830·302d·3137·312d·332e·342e··IST-800-171-3.4.
0003ba30:·310a·2020·2d20·4e49·5354·2d38·3030·2d35··1.··-·NIST-800-50003b720:·310a·2020·2d20·4e49·5354·2d38·3030·2d35··1.··-·NIST-800-5
0003ba40:·332d·4155·2d39·2833·290a·2020·2d20·4e49··3-AU-9(3).··-·NI0003b730:·332d·4155·2d39·2833·290a·2020·2d20·4e49··3-AU-9(3).··-·NI
0003ba50:·5354·2d38·3030·2d35·332d·434d·2d36·2863··ST-800-53-CM-6(c0003b740:·5354·2d38·3030·2d35·332d·434d·2d36·2863··ST-800-53-CM-6(c
0003ba60:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-50003b750:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5
0003ba70:·332d·434d·2d36·2864·290a·2020·2d20·4e49··3-CM-6(d).··-·NI0003b760:·332d·434d·2d36·2864·290a·2020·2d20·4e49··3-CM-6(d).··-·NI
0003ba80:·5354·2d38·3030·2d35·332d·5349·2d37·0a20··ST-800-53-SI-7.·0003b770:·5354·2d38·3030·2d35·332d·5349·2d37·0a20··ST-800-53-SI-7.·
0003ba90:·202d·204e·4953·542d·3830·302d·3533·2d53···-·NIST-800-53-S0003b780:·202d·204e·4953·542d·3830·302d·3533·2d53···-·NIST-800-53-S
0003baa0:·492d·3728·3129·0a20·202d·204e·4953·542d··I-7(1).··-·NIST-0003b790:·492d·3728·3129·0a20·202d·204e·4953·542d··I-7(1).··-·NIST-
0003bab0:·3830·302d·3533·2d53·492d·3728·3629·0a20··800-53-SI-7(6).·0003b7a0:·3830·302d·3533·2d53·492d·3728·3629·0a20··800-53-SI-7(6).·
0003bac0:·202d·2050·4349·2d44·5353·2d52·6571·2d31···-·PCI-DSS-Req-10003b7b0:·202d·2050·4349·2d44·5353·2d52·6571·2d31···-·PCI-DSS-Req-1
0003bad0:·312e·350a·2020·2d20·5043·492d·4453·5376··1.5.··-·PCI-DSSv0003b7c0:·312e·350a·2020·2d20·5043·492d·4453·5376··1.5.··-·PCI-DSSv
0003bae0:·342d·3131·2e35·2e32·0a20·202d·2068·6967··4-11.5.2.··-·hig0003b7d0:·342d·3131·2e35·2e32·0a20·202d·2068·6967··4-11.5.2.··-·hig
0003baf0:·685f·636f·6d70·6c65·7869·7479·0a20·202d··h_complexity.··-0003b7e0:·685f·636f·6d70·6c65·7869·7479·0a20·202d··h_complexity.··-
0003bb00:·2068·6967·685f·7365·7665·7269·7479·0a20···high_severity.·0003b7f0:·2068·6967·685f·7365·7665·7269·7479·0a20···high_severity.·
Max diff block lines reached; 21967356/21986454 bytes (99.91%) of diff not shown.
1.68 MB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*37 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DISA·STIG·for·Oracle·Linux·738 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DISA·STIG·for·Oracle·Linux·7
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_stig39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_stig
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:oracle:linux:741 ····*·cpe:/o:oracle:linux:7
42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
43 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8443 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
49 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n49 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
50 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g50 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
51 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s51 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 107, 27 lines modifiedOffset 107, 14 lines modified
107 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)107 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
108 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1108 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
109 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5109 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
110 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227110 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
111 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010020111 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010020
112 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2112 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
113 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221653r853660_rule113 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221653r853660_rule
114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
115 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
116 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
117 if·[·-n·"$files_with_incorrect_hash"·];·then 
118 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
119 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
120 ····yum·reinstall·-y·$packages_to_reinstall 
  
121 fi 
122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
123 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high115 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
124 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium116 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
125 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false117 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
126 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict118 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
127 -·name:·'Set·fact:·Package·manager·reinstall·command'119 -·name:·'Set·fact:·Package·manager·reinstall·command'
128 ··set_fact:120 ··set_fact:
Offset 259, 14 lines modifiedOffset 246, 27 lines modified
259 ··-·PCI-DSSv4-11.5.2246 ··-·PCI-DSSv4-11.5.2
260 ··-·high_complexity247 ··-·high_complexity
261 ··-·high_severity248 ··-·high_severity
262 ··-·medium_disruption249 ··-·medium_disruption
263 ··-·no_reboot_needed250 ··-·no_reboot_needed
264 ··-·restrict_strategy251 ··-·restrict_strategy
265 ··-·rpm_verify_hashes252 ··-·rpm_verify_hashes
 253 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 254 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 255 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 256 if·[·-n·"$files_with_incorrect_hash"·];·then
 257 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 258 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 259 ····yum·reinstall·-y·$packages_to_reinstall
  
 260 fi
266 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*261 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
267 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:262 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
268 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'263 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
269 run·the·following·command·to·determine·which·package·owns·it:264 run·the·following·command·to·determine·which·package·owns·it:
270 $·rpm·-qf·FILENAME265 $·rpm·-qf·FILENAME
271 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:266 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
272 $·sudo·rpm·--setugids·PACKAGENAME267 $·sudo·rpm·--setugids·PACKAGENAME
Offset 287, 40 lines modifiedOffset 287, 14 lines modified
287 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)287 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
288 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1288 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
289 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5289 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
290 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108290 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
291 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010010291 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010010
292 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2292 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
293 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221652r880585_rule293 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221652r880585_rule
294 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
295 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
296 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
297 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
298 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
299 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
300 declare·-A·SETPERMS_RPM_DICT 
  
301 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
302 #·is·expected·by·the·RPM·database 
303 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
304 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
305 do 
306 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
307 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
308 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
309 done 
  
310 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
311 #·correct·values 
312 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
313 do 
314 ········rpm·--setugids·"${RPM_PACKAGE}" 
315 done 
316 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8294 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
317 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high295 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
318 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium296 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
319 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false297 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
320 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict298 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
321 -·name:·Read·list·of·files·with·incorrect·ownership299 -·name:·Read·list·of·files·with·incorrect·ownership
322 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev300 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 398, 14 lines modifiedOffset 372, 40 lines modified
398 ··-·PCI-DSSv4-11.5.2372 ··-·PCI-DSSv4-11.5.2
399 ··-·high_complexity373 ··-·high_complexity
400 ··-·high_severity374 ··-·high_severity
401 ··-·medium_disruption375 ··-·medium_disruption
402 ··-·no_reboot_needed376 ··-·no_reboot_needed
403 ··-·restrict_strategy377 ··-·restrict_strategy
404 ··-·rpm_verify_ownership378 ··-·rpm_verify_ownership
 379 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 380 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 381 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 382 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 383 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 384 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 1752640/1759998 bytes (99.58%) of diff not shown.
22.6 MB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-stig_gui.html
    
Offset 14302, 15 lines modifiedOffset 14302, 15 lines modified
00037dd0:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren00037dd0:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren
00037de0:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro00037de0:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro
00037df0:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron00037df0:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron
00037e00:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s00037e00:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s
00037e10:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str00037e10:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str
00037e20:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········00037e20:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········
00037e30:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·00037e30:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·
00037e40:·3230·3236·2d30·312d·3038·290a·2020·2020··2026-01-08).····00037e40:·3230·3234·2d31·322d·3037·290a·2020·2020··2024-12-07).····
00037e50:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li00037e50:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li
00037e60:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>00037e60:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>
00037e70:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content00037e70:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content
00037e80:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a00037e80:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a
00037e90:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or00037e90:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or
00037ea0:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con00037ea0:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con
00037eb0:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste00037eb0:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste
Offset 15191, 309 lines modifiedOffset 15191, 309 lines modified
0003b560:·6765·743d·2223·6964·6d35·3239·3922·2074··get="#idm5299"·t0003b560:·6765·743d·2223·6964·6d35·3239·3922·2074··get="#idm5299"·t
0003b570:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003b570:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003b580:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003b580:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003b590:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003b590:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003b5a0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003b5a0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003b5b0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003b5b0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003b5c0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003b5c0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003b5d0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
0003b5e0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b5f0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b600:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b610:·3d22·6964·6d35·3239·3922·3e3c·7072·653e··="idm5299"><pre> 
0003b620:·3c63·6f64·653e·0a23·2046·696e·6420·7768··<code>.#·Find·wh 
0003b630:·6963·6820·6669·6c65·7320·6861·7665·2069··ich·files·have·i 
0003b640:·6e63·6f72·7265·6374·2068·6173·6820·286e··ncorrect·hash·(n 
0003b650:·6f74·2069·6e20·2f65·7463·2c20·6265·6361··ot·in·/etc,·beca 
0003b660:·7573·6520·6f66·2074·6865·2073·7973·7465··use·of·the·syste 
0003b670:·6d20·7265·6c61·7465·6420·636f·6e66·6967··m·related·config 
0003b680:·2066·696c·6573·2920·616e·6420·7468·656e···files)·and·then 
0003b690:·2067·6574·2066·696c·6573·206e·616d·6573···get·files·names 
0003b6a0:·0a66·696c·6573·5f77·6974·685f·696e·636f··.files_with_inco 
0003b6b0:·7272·6563·745f·6861·7368·3d22·2428·7270··rrect_hash="$(rp 
0003b6c0:·6d20·2d56·6120·2d2d·6e6f·636f·6e66·6967··m·-Va·--noconfig 
0003b6d0:·207c·2067·7265·7020·2d45·2027·5e2e·2e35···|·grep·-E·'^..5 
0003b6e0:·2720·7c20·6177·6b20·277b·7072·696e·7420··'·|·awk·'{print· 
0003b6f0:·244e·467d·2720·2922·0a0a·6966·205b·202d··$NF}'·)"..if·[·- 
0003b700:·6e20·2224·6669·6c65·735f·7769·7468·5f69··n·"$files_with_i 
0003b710:·6e63·6f72·7265·6374·5f68·6173·6822·205d··ncorrect_hash"·] 
0003b720:·3b20·7468·656e·0a20·2020·2023·2046·726f··;·then.····#·Fro 
0003b730:·6d20·6669·6c65·7320·6e61·6d65·7320·6765··m·files·names·ge 
0003b740:·7420·7061·636b·6167·6520·6e61·6d65·7320··t·package·names· 
0003b750:·616e·6420·6368·616e·6765·206e·6577·6c69··and·change·newli 
0003b760:·6e65·2074·6f20·7370·6163·652c·2062·6563··ne·to·space,·bec 
0003b770:·6175·7365·2072·706d·2077·7269·7465·7320··ause·rpm·writes· 
0003b780:·6561·6368·2070·6163·6b61·6765·2074·6f20··each·package·to· 
0003b790:·6e65·7720·6c69·6e65·0a20·2020·2070·6163··new·line.····pac 
0003b7a0:·6b61·6765·735f·746f·5f72·6569·6e73·7461··kages_to_reinsta 
0003b7b0:·6c6c·3d22·2428·7270·6d20·2d71·6620·2466··ll="$(rpm·-qf·$f 
0003b7c0:·696c·6573·5f77·6974·685f·696e·636f·7272··iles_with_incorr 
0003b7d0:·6563·745f·6861·7368·207c·2074·7220·275c··ect_hash·|·tr·'\ 
0003b7e0:·6e27·2027·2027·2922·0a0a·2020·2020·0a20··n'·'·')"..····.· 
0003b7f0:·2020·2079·756d·2072·6569·6e73·7461·6c6c·····yum·reinstall 
0003b800:·202d·7920·2470·6163·6b61·6765·735f·746f···-y·$packages_to 
0003b810:·5f72·6569·6e73·7461·6c6c·0a20·2020·200a··_reinstall.····. 
0003b820:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre> 
0003b830:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003b840:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003b850:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003b860:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003b870:·6765·743d·2223·6964·6d35·3330·3022·2074··get="#idm5300"·t 
0003b880:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003b890:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003b8a0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003b8b0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003b8c0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003b8d0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003b8e0:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet0003b5d0:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet
0003b8f0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003b5e0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003b900:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003b5f0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003b910:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003b600:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003b920:·2069·643d·2269·646d·3533·3030·223e·3c74···id="idm5300"><t0003b610:·2069·643d·2269·646d·3532·3939·223e·3c74···id="idm5299"><t
0003b930:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl0003b620:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003b940:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·0003b630:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003b950:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0003b640:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003b960:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">0003b650:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003b970:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi0003b660:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003b980:·7479·3a3c·2f74·683e·3c74·643e·6869·6768··ty:</th><td>high0003b670:·7479·3a3c·2f74·683e·3c74·643e·6869·6768··ty:</th><td>high
0003b990:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003b680:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003b9a0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003b690:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003b9b0:·683e·3c74·643e·6d65·6469·756d·3c2f·7464··h><td>medium</td0003b6a0:·683e·3c74·643e·6d65·6469·756d·3c2f·7464··h><td>medium</td
0003b9c0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003b6b0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003b9d0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003b6c0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003b9e0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003b6d0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003b9f0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003b6e0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003ba00:·7468·3e3c·7464·3e72·6573·7472·6963·743c··th><td>restrict<0003b6f0:·7468·3e3c·7464·3e72·6573·7472·6963·743c··th><td>restrict<
0003ba10:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003b700:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003ba20:·3e3c·7072·653e·3c63·6f64·653e·2d20·6e61··><pre><code>-·na0003b710:·3e3c·7072·653e·3c63·6f64·653e·2d20·6e61··><pre><code>-·na
0003ba30:·6d65·3a20·2753·6574·2066·6163·743a·2050··me:·'Set·fact:·P0003b720:·6d65·3a20·2753·6574·2066·6163·743a·2050··me:·'Set·fact:·P
0003ba40:·6163·6b61·6765·206d·616e·6167·6572·2072··ackage·manager·r0003b730:·6163·6b61·6765·206d·616e·6167·6572·2072··ackage·manager·r
0003ba50:·6569·6e73·7461·6c6c·2063·6f6d·6d61·6e64··einstall·command0003b740:·6569·6e73·7461·6c6c·2063·6f6d·6d61·6e64··einstall·command
0003ba60:·270a·2020·7365·745f·6661·6374·3a0a·2020··'.··set_fact:.··0003b750:·270a·2020·7365·745f·6661·6374·3a0a·2020··'.··set_fact:.··
0003ba70:·2020·7061·636b·6167·655f·6d61·6e61·6765····package_manage0003b760:·2020·7061·636b·6167·655f·6d61·6e61·6765····package_manage
0003ba80:·725f·7265·696e·7374·616c·6c5f·636d·643a··r_reinstall_cmd:0003b770:·725f·7265·696e·7374·616c·6c5f·636d·643a··r_reinstall_cmd:
0003ba90:·2079·756d·2072·6569·6e73·7461·6c6c·202d···yum·reinstall·-0003b780:·2079·756d·2072·6569·6e73·7461·6c6c·202d···yum·reinstall·-
0003baa0:·790a·2020·7768·656e·3a20·616e·7369·626c··y.··when:·ansibl0003b790:·790a·2020·7768·656e·3a20·616e·7369·626c··y.··when:·ansibl
0003bab0:·655f·6469·7374·7269·6275·7469·6f6e·2069··e_distribution·i0003b7a0:·655f·6469·7374·7269·6275·7469·6f6e·2069··e_distribution·i
0003bac0:·6e20·5b20·2246·6564·6f72·6122·2c20·2252··n·[·"Fedora",·"R0003b7b0:·6e20·5b20·2246·6564·6f72·6122·2c20·2252··n·[·"Fedora",·"R
0003bad0:·6564·4861·7422·2c20·2243·656e·744f·5322··edHat",·"CentOS"0003b7c0:·6564·4861·7422·2c20·2243·656e·744f·5322··edHat",·"CentOS"
0003bae0:·2c20·224f·7261·636c·654c·696e·7578·2220··,·"OracleLinux"·0003b7d0:·2c20·224f·7261·636c·654c·696e·7578·2220··,·"OracleLinux"·
0003baf0:·5d0a·2020·7461·6773·3a0a·2020·2d20·434a··].··tags:.··-·CJ0003b7e0:·5d0a·2020·7461·6773·3a0a·2020·2d20·434a··].··tags:.··-·CJ
0003bb00:·4953·2d35·2e31·302e·342e·310a·2020·2d20··IS-5.10.4.1.··-·0003b7f0:·4953·2d35·2e31·302e·342e·310a·2020·2d20··IS-5.10.4.1.··-·
0003bb10:·4449·5341·2d53·5449·472d·4f4c·3037·2d30··DISA-STIG-OL07-00003b800:·4449·5341·2d53·5449·472d·4f4c·3037·2d30··DISA-STIG-OL07-0
0003bb20:·302d·3031·3030·3230·0a20·202d·204e·4953··0-010020.··-·NIS0003b810:·302d·3031·3030·3230·0a20·202d·204e·4953··0-010020.··-·NIS
0003bb30:·542d·3830·302d·3137·312d·332e·332e·380a··T-800-171-3.3.8.0003b820:·542d·3830·302d·3137·312d·332e·332e·380a··T-800-171-3.3.8.
0003bb40:·2020·2d20·4e49·5354·2d38·3030·2d31·3731····-·NIST-800-1710003b830:·2020·2d20·4e49·5354·2d38·3030·2d31·3731····-·NIST-800-171
0003bb50:·2d33·2e34·2e31·0a20·202d·204e·4953·542d··-3.4.1.··-·NIST-0003b840:·2d33·2e34·2e31·0a20·202d·204e·4953·542d··-3.4.1.··-·NIST-
0003bb60:·3830·302d·3533·2d41·552d·3928·3329·0a20··800-53-AU-9(3).·0003b850:·3830·302d·3533·2d41·552d·3928·3329·0a20··800-53-AU-9(3).·
0003bb70:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C0003b860:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C
0003bb80:·4d2d·3628·6329·0a20·202d·204e·4953·542d··M-6(c).··-·NIST-0003b870:·4d2d·3628·6329·0a20·202d·204e·4953·542d··M-6(c).··-·NIST-
0003bb90:·3830·302d·3533·2d43·4d2d·3628·6429·0a20··800-53-CM-6(d).·0003b880:·3830·302d·3533·2d43·4d2d·3628·6429·0a20··800-53-CM-6(d).·
0003bba0:·202d·204e·4953·542d·3830·302d·3533·2d53···-·NIST-800-53-S0003b890:·202d·204e·4953·542d·3830·302d·3533·2d53···-·NIST-800-53-S
0003bbb0:·492d·370a·2020·2d20·4e49·5354·2d38·3030··I-7.··-·NIST-8000003b8a0:·492d·370a·2020·2d20·4e49·5354·2d38·3030··I-7.··-·NIST-800
0003bbc0:·2d35·332d·5349·2d37·2831·290a·2020·2d20··-53-SI-7(1).··-·0003b8b0:·2d35·332d·5349·2d37·2831·290a·2020·2d20··-53-SI-7(1).··-·
0003bbd0:·4e49·5354·2d38·3030·2d35·332d·5349·2d37··NIST-800-53-SI-70003b8c0:·4e49·5354·2d38·3030·2d35·332d·5349·2d37··NIST-800-53-SI-7
0003bbe0:·2836·290a·2020·2d20·5043·492d·4453·532d··(6).··-·PCI-DSS-0003b8d0:·2836·290a·2020·2d20·5043·492d·4453·532d··(6).··-·PCI-DSS-
0003bbf0:·5265·712d·3131·2e35·0a20·202d·2050·4349··Req-11.5.··-·PCI0003b8e0:·5265·712d·3131·2e35·0a20·202d·2050·4349··Req-11.5.··-·PCI
0003bc00:·2d44·5353·7634·2d31·312e·352e·320a·2020··-DSSv4-11.5.2.··0003b8f0:·2d44·5353·7634·2d31·312e·352e·320a·2020··-DSSv4-11.5.2.··
0003bc10:·2d20·6869·6768·5f63·6f6d·706c·6578·6974··-·high_complexit0003b900:·2d20·6869·6768·5f63·6f6d·706c·6578·6974··-·high_complexit
0003bc20:·790a·2020·2d20·6869·6768·5f73·6576·6572··y.··-·high_sever0003b910:·790a·2020·2d20·6869·6768·5f73·6576·6572··y.··-·high_sever
0003bc30:·6974·790a·2020·2d20·6d65·6469·756d·5f64··ity.··-·medium_d0003b920:·6974·790a·2020·2d20·6d65·6469·756d·5f64··ity.··-·medium_d
0003bc40:·6973·7275·7074·696f·6e0a·2020·2d20·6e6f··isruption.··-·no0003b930:·6973·7275·7074·696f·6e0a·2020·2d20·6e6f··isruption.··-·no
Max diff block lines reached; 21948834/21967932 bytes (99.91%) of diff not shown.
1.68 MB
html2text {}
    
Offset 42, 15 lines modifiedOffset 42, 15 lines modified
42 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DISA·STIG·with·GUI·for·Oracle·Linux·743 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DISA·STIG·with·GUI·for·Oracle·Linux·7
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_stig_gui44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_stig_gui
45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
46 ····*·cpe:/o:oracle:linux:746 ····*·cpe:/o:oracle:linux:7
47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
48 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8448 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
54 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n54 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
55 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g55 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
56 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s56 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 111, 27 lines modifiedOffset 111, 14 lines modified
111 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)111 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
112 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1112 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
113 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5113 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
114 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227114 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
115 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010020115 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010020
116 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2116 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
117 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221653r853660_rule117 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221653r853660_rule
118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
119 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
120 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
121 if·[·-n·"$files_with_incorrect_hash"·];·then 
122 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
123 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
124 ····yum·reinstall·-y·$packages_to_reinstall 
  
125 fi 
126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
131 -·name:·'Set·fact:·Package·manager·reinstall·command'123 -·name:·'Set·fact:·Package·manager·reinstall·command'
132 ··set_fact:124 ··set_fact:
Offset 263, 14 lines modifiedOffset 250, 27 lines modified
263 ··-·PCI-DSSv4-11.5.2250 ··-·PCI-DSSv4-11.5.2
264 ··-·high_complexity251 ··-·high_complexity
265 ··-·high_severity252 ··-·high_severity
266 ··-·medium_disruption253 ··-·medium_disruption
267 ··-·no_reboot_needed254 ··-·no_reboot_needed
268 ··-·restrict_strategy255 ··-·restrict_strategy
269 ··-·rpm_verify_hashes256 ··-·rpm_verify_hashes
 257 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 258 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 259 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 260 if·[·-n·"$files_with_incorrect_hash"·];·then
 261 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 262 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 263 ····yum·reinstall·-y·$packages_to_reinstall
  
 264 fi
270 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*265 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
271 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:266 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
272 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'267 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
273 run·the·following·command·to·determine·which·package·owns·it:268 run·the·following·command·to·determine·which·package·owns·it:
274 $·rpm·-qf·FILENAME269 $·rpm·-qf·FILENAME
275 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:270 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
276 $·sudo·rpm·--setugids·PACKAGENAME271 $·sudo·rpm·--setugids·PACKAGENAME
Offset 291, 40 lines modifiedOffset 291, 14 lines modified
291 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)291 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
292 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1292 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
293 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5293 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
294 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108294 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
295 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010010295 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010010
296 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2296 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
297 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221652r880585_rule297 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221652r880585_rule
298 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
299 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
300 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
301 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
302 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
303 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
304 declare·-A·SETPERMS_RPM_DICT 
  
305 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
306 #·is·expected·by·the·RPM·database 
307 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
308 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
309 do 
310 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
311 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
312 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
313 done 
  
314 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
315 #·correct·values 
316 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
317 do 
318 ········rpm·--setugids·"${RPM_PACKAGE}" 
319 done 
320 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8298 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
321 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high299 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
322 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium300 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
323 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false301 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
324 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict302 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
325 -·name:·Read·list·of·files·with·incorrect·ownership303 -·name:·Read·list·of·files·with·incorrect·ownership
326 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev304 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 402, 14 lines modifiedOffset 376, 40 lines modified
402 ··-·PCI-DSSv4-11.5.2376 ··-·PCI-DSSv4-11.5.2
403 ··-·high_complexity377 ··-·high_complexity
404 ··-·high_severity378 ··-·high_severity
405 ··-·medium_disruption379 ··-·medium_disruption
406 ··-·no_reboot_needed380 ··-·no_reboot_needed
407 ··-·restrict_strategy381 ··-·restrict_strategy
408 ··-·rpm_verify_ownership382 ··-·rpm_verify_ownership
 383 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 384 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 385 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 386 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 387 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 388 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 1749037/1756408 bytes (99.58%) of diff not shown.
22.7 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-anssi_bp28_enhanced.html
    
Offset 14302, 16 lines modifiedOffset 14302, 16 lines modified
00037dd0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00037dd0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00037de0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00037de0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00037df0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000037df0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00037e00:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></00037e00:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
00037e10:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00037e10:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00037e20:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00037e20:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00037e30:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037e30:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037e40:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600037e40:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
00037e50:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········00037e50:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00037e60:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00037e60:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00037e70:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00037e70:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00037e80:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00037e80:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00037e90:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00037e90:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00037ea0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00037ea0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00037eb0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00037eb0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00037ec0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00037ec0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
Offset 15054, 202 lines modifiedOffset 15054, 202 lines modified
0003acd0:·6172·6765·743d·2223·6964·6d35·3638·3422··arget="#idm5684"0003acd0:·6172·6765·743d·2223·6964·6d35·3638·3422··arget="#idm5684"
0003ace0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003ace0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003acf0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003acf0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003ad00:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003ad00:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003ad10:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003ad10:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003ad20:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003ad20:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003ad30:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003ad30:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003ad40:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe0003ad40:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip
0003ad50:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003ad50:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003ad60:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003ad60:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003ad70:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003ad70:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003ad80:·2220·6964·3d22·6964·6d35·3638·3422·3e3c··"·id="idm5684"><0003ad80:·7365·2220·6964·3d22·6964·6d35·3638·3422··se"·id="idm5684"
0003ad90:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003ad90:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003ada0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003ada0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003adb0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003adb0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003adc0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003adc0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003add0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003add0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003ade0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003ade0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003adf0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003adf0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003ae00:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003ae00:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003ae10:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003ae10:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003ae20:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo0003ae20:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
0003ae30:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false0003ae30:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
0003ae40:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003ae40:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
0003ae50:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>0003ae50:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0003ae60:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><0003ae60:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
0003ae70:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0003ae70:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003ae80:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag
 0003ae90:·6520·2d2d·6164·643d·6169·6465·0a3c·2f63··e·--add=aide.</c
 0003aea0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003aeb0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003aec0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003aed0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
0003ae80:·3e3c·636f·6465·3e69·6e63·6c75·6465·2069··><code>include·i 
0003ae90:·6e73·7461·6c6c·5f61·6964·650a·0a63·6c61··nstall_aide..cla 
0003aea0:·7373·2069·6e73·7461·6c6c·5f61·6964·6520··ss·install_aide· 
0003aeb0:·7b0a·2020·7061·636b·6167·6520·7b20·2761··{.··package·{·'a 
0003aec0:·6964·6527·3a0a·2020·2020·656e·7375·7265··ide':.····ensure 
0003aed0:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe 
0003aee0:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code 
0003aef0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003af00:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003af10:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003af20:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003af30:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003af40:·3536·3835·2220·7461·6269·6e64·6578·3d22··5685"·tabindex=" 
0003af50:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003af60:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003af70:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003af80:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003af90:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003afa0:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003afb0:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003afc0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003afd0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003afe0:·7073·6522·2069·643d·2269·646d·3536·3835··pse"·id="idm5685 
0003aff0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003b000:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003b010:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003b020:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003b030:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003b040:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003b050:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003b060:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003b070:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b080:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003b090:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0003b0a0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
0003b0b0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003b0c0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003b0d0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003b0e0:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme 
0003b0f0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
0003b100:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
0003b110:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
0003b120:·6966·205b·2021·202d·6620·2f2e·646f·636b··if·[·!·-f·/.dock 
0003b130:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am 
0003b140:·703b·205b·2021·202d·6620·2f72·756e·2f2e··p;·[·!·-f·/run/. 
0003b150:·636f·6e74·6169·6e65·7265·6e76·205d·3b20··containerenv·];· 
0003b160:·7468·656e·0a0a·6966·2021·2072·706d·202d··then..if·!·rpm·- 
0003b170:·7120·2d2d·7175·6965·7420·2261·6964·6522··q·--quiet·"aide" 
0003b180:·203b·2074·6865·6e0a·2020·2020·7975·6d20···;·then.····yum· 
0003b190:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide 
0003b1a0:·220a·6669·0a0a·656c·7365·0a20·2020·2026··".fi..else.····& 
0003b1b0:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·' 
0003b1c0:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n 
0003b1d0:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n 
0003b1e0:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done' 
0003b1f0:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre 
0003b200:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003b210:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003b220:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c0003aee0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0003aef0:·6964·6d35·3638·3522·2074·6162·696e·6465··idm5685"·tabinde
 0003af00:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 0003af10:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 0003af20:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 0003af30:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 0003af40:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 0003af50:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
 0003af60:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
0003b230:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003b240:·7267·6574·3d22·2369·646d·3536·3836·2220··rget="#idm5686"· 
0003b250:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003b260:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003b270:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003b280:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003b290:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003b2a0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003b2b0:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe 
0003b2c0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
Max diff block lines reached; 21832746/21860538 bytes (99.87%) of diff not shown.
1.84 MB
html2text {}
Max HTML report size reached
23.0 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-anssi_bp28_high.html
    
Offset 14301, 16 lines modifiedOffset 14301, 16 lines modified
00037dc0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00037dc0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00037dd0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00037dd0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00037de0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000037de0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00037df0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></00037df0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
00037e00:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00037e00:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00037e10:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00037e10:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00037e20:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037e20:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037e30:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600037e30:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
00037e40:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········00037e40:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00037e50:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00037e50:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00037e60:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00037e60:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00037e70:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00037e70:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00037e80:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00037e80:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00037e90:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00037e90:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00037ea0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00037ea0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00037eb0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00037eb0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
Offset 15059, 202 lines modifiedOffset 15059, 202 lines modified
0003ad20:·612d·7461·7267·6574·3d22·2369·646d·3536··a-target="#idm560003ad20:·612d·7461·7267·6574·3d22·2369·646d·3536··a-target="#idm56
0003ad30:·3834·2220·7461·6269·6e64·6578·3d22·3022··84"·tabindex="0"0003ad30:·3834·2220·7461·6269·6e64·6578·3d22·3022··84"·tabindex="0"
0003ad40:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003ad40:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003ad50:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003ad50:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003ad60:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003ad60:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003ad70:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003ad70:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003ad80:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003ad80:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003ad90:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni0003ad90:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s
0003ada0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003ada0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003adb0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003adb0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003adc0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003adc0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003add0:·7073·6522·2069·643d·2269·646d·3536·3834··pse"·id="idm56840003add0:·6c61·7073·6522·2069·643d·2269·646d·3536··lapse"·id="idm56
0003ade0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003ade0:·3834·223e·3c74·6162·6c65·2063·6c61·7373··84"><table·class
0003adf0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003adf0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003ae00:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003ae00:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003ae10:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003ae10:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003ae20:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003ae20:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003ae30:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003ae30:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003ae40:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003ae40:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003ae50:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003ae50:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003ae60:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003ae60:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003ae70:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003ae70:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003ae80:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003ae80:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0003ae90:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003ae90:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
0003aea0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003aea0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003aeb0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003aeb0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0003aec0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003aec0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003aed0:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ0003aed0:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 0003aee0:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide.
 0003aef0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 0003af00:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0003af10:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0003af20:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 0003af30:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0003af40:·3d22·2369·646d·3536·3835·2220·7461·6269··="#idm5685"·tabi
 0003af50:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 0003af60:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 0003af70:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 0003af80:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 0003af90:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 0003afa0:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu
 0003afb0:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...
 0003afc0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003afd0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003afe0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003aff0:·2269·646d·3536·3835·223e·3c74·6162·6c65··"idm5685"><table
 0003b000:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003b010:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003b020:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003b030:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003b040:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003aee0:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide.. 
0003aef0:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai 
0003af00:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{ 
0003af10:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens 
0003af20:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta 
0003af30:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c 
0003af40:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003af50:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003af60:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003af70:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003af80:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003af90:·6964·6d35·3638·3522·2074·6162·696e·6465··idm5685"·tabinde 
0003afa0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003afb0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003afc0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003afd0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003afe0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003aff0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003b000:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003b010:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b020:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b030:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5 
0003b040:·3638·3522·3e3c·7461·626c·6520·636c·6173··685"><table·clas 
0003b050:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b060:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b070:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b080:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b090:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b0a0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b0b0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b0c0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003b050:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003b0d0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b060:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003b070:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003b0e0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b0f0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003b100:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b110:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b120:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b130:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R 
0003b140:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003b150:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003b160:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003b170:·6d73·0a69·6620·5b20·2120·2d66·202f·2e64··ms.if·[·!·-f·/.d 
0003b180:·6f63·6b65·7265·6e76·205d·2026·616d·703b··ockerenv·]·&amp; 
0003b190:·2661·6d70·3b20·5b20·2120·2d66·202f·7275··&amp;·[·!·-f·/ru 
0003b1a0:·6e2f·2e63·6f6e·7461·696e·6572·656e·7620··n/.containerenv· 
0003b1b0:·5d3b·2074·6865·6e0a·0a69·6620·2120·7270··];·then..if·!·rp 
0003b1c0:·6d20·2d71·202d·2d71·7569·6574·2022·6169··m·-q·--quiet·"ai 
0003b1d0:·6465·2220·3b20·7468·656e·0a20·2020·2079··de"·;·then.····y 
0003b1e0:·756d·2069·6e73·7461·6c6c·202d·7920·2261··um·install·-y·"a 
0003b1f0:·6964·6522·0a66·690a·0a65·6c73·650a·2020··ide".fi..else.·· 
0003b200:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech 
0003b210:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i 
0003b220:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable 
0003b230:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do 
0003b240:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></ 
0003b250:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003b260:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003b270:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
Max diff block lines reached; 22121530/22149322 bytes (99.87%) of diff not shown.
1.87 MB
html2text {}
Max HTML report size reached
9.51 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-anssi_bp28_intermediary.html
    
Offset 14303, 16 lines modifiedOffset 14303, 16 lines modified
00037de0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00037de0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00037df0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00037df0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00037e00:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000037e00:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00037e10:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></00037e10:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
00037e20:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00037e20:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00037e30:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00037e30:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00037e40:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037e40:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037e50:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600037e50:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
00037e60:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········00037e60:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00037e70:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00037e70:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00037e80:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00037e80:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00037e90:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00037e90:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00037ea0:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00037ea0:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00037eb0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00037eb0:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00037ec0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00037ec0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00037ed0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00037ed0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
Offset 15045, 202 lines modifiedOffset 15045, 202 lines modified
0003ac40:·7461·7267·6574·3d22·2369·646d·3536·3834··target="#idm56840003ac40:·7461·7267·6574·3d22·2369·646d·3536·3834··target="#idm5684
0003ac50:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003ac50:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003ac60:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003ac60:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003ac70:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003ac70:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003ac80:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003ac80:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003ac90:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003ac90:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003aca0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003aca0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003acb0:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp0003acb0:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni
0003acc0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0003acc0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003acd0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003acd0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003ace0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003ace0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003acf0:·6522·2069·643d·2269·646d·3536·3834·223e··e"·id="idm5684">0003acf0:·7073·6522·2069·643d·2269·646d·3536·3834··pse"·id="idm5684
0003ad00:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003ad00:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003ad10:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003ad10:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003ad20:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003ad20:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003ad30:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003ad30:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003ad40:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003ad40:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003ad50:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003ad50:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003ad60:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003ad60:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003ad70:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003ad70:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003ad80:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003ad80:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003ad90:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo0003ad90:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003ada0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals0003ada0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003adb0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><0003adb0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003adc0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th0003adc0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003add0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>0003add0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0003ade0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003ade0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003adf0:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa
 0003ae00:·6765·202d·2d61·6464·3d61·6964·650a·3c2f··ge·--add=aide.</
 0003ae10:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003ae20:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003ae30:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003ae40:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003ae50:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003ae60:·2369·646d·3536·3835·2220·7461·6269·6e64··#idm5685"·tabind
 0003ae70:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003ae80:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003ae90:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003aea0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003aeb0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003aec0:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp
 0003aed0:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</
 0003aee0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003aef0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003af00:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003af10:·646d·3536·3835·223e·3c74·6162·6c65·2063··dm5685"><table·c
 0003af20:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003af30:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003af40:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003af50:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003af60:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003af70:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003af80:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003adf0:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include· 
0003ae00:·696e·7374·616c·6c5f·6169·6465·0a0a·636c··install_aide..cl 
0003ae10:·6173·7320·696e·7374·616c·6c5f·6169·6465··ass·install_aide 
0003ae20:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·' 
0003ae30:·6169·6465·273a·0a20·2020·2065·6e73·7572··aide':.····ensur 
0003ae40:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install 
0003ae50:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod 
0003ae60:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003ae70:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003ae80:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003ae90:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003aea0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003aeb0:·6d35·3638·3522·2074·6162·696e·6465·783d··m5685"·tabindex= 
0003aec0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003aed0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003aee0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003aef0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003af00:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003af10:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s 
0003af20:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003af30:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003af40:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003af50:·6170·7365·2220·6964·3d22·6964·6d35·3638··apse"·id="idm568 
0003af60:·3522·3e3c·7461·626c·6520·636c·6173·733d··5"><table·class= 
0003af70:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003af80:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003af90:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003afa0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003afb0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003af90:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003afc0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003afa0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003afd0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003afe0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003afb0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003afc0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
0003aff0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R0003afd0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
0003b000:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f0003afe0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003aff0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003b000:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003b010:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_
 0003b020:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst
 0003b030:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac
 0003b040:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.·
 0003b050:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;·
 0003b060:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··}
0003b010:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
0003b020:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003b030:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003b040:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003b050:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem 
0003b060:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl 
0003b070:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c 
0003b080:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms 
0003b090:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc 
0003b0a0:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a 
0003b0b0:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/ 
0003b0c0:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·]; 
0003b0d0:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm· 
0003b0e0:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide 
Max diff block lines reached; 8952974/8980766 bytes (99.69%) of diff not shown.
972 KB
html2text {}
    
Offset 43, 15 lines modifiedOffset 43, 15 lines modified
43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(intermediary)44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(intermediary)
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_intermediary45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_intermediary
46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
47 ····*·cpe:/o:oracle:linux:847 ····*·cpe:/o:oracle:linux:8
48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
49 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8449 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
55 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n55 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
56 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s56 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
57 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s57 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 113, 41 lines modifiedOffset 113, 38 lines modified
113 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3113 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
114 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5114 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
115 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199115 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
116 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359116 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359
117 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79117 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
118 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2118 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
119 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule119 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule
 120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 121 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 122 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 123 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 124 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 125 package·--add=aide
120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
121 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
122 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
123 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
124 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
125 include·install_aide131 include·install_aide
  
126 class·install_aide·{132 class·install_aide·{
127 ··package·{·'aide':133 ··package·{·'aide':
128 ····ensure·=>·'installed',134 ····ensure·=>·'installed',
129 ··}135 ··}
130 }136 }
 137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
136 #·Remediation·is·applicable·only·in·certain·platforms 
137 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
138 if·!·rpm·-q·--quiet·"aide"·;·then 
139 ····yum·install·-y·"aide" 
140 fi 
  
141 else 
142 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
143 fi138 [[packages]]
 139 name·=·"aide"
 140 version·=·"*"
144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8141 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
145 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low142 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
146 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low143 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
147 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false144 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
148 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable145 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
149 -·name:·Ensure·aide·is·installed146 -·name:·Ensure·aide·is·installed
150 ··package:147 ··package:
Offset 162, 26 lines modifiedOffset 159, 29 lines modified
162 ··-·PCI-DSSv4-11.5.2159 ··-·PCI-DSSv4-11.5.2
163 ··-·enable_strategy160 ··-·enable_strategy
164 ··-·low_complexity161 ··-·low_complexity
165 ··-·low_disruption162 ··-·low_disruption
166 ··-·medium_severity163 ··-·medium_severity
167 ··-·no_reboot_needed164 ··-·no_reboot_needed
168 ··-·package_aide_installed165 ··-·package_aide_installed
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
170 [[packages]] 
171 name·=·"aide" 
172 version·=·"*" 
173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_.n_.a_.c_.o_.n_.d_.a_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 171 #·Remediation·is·applicable·only·in·certain·platforms
 172 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
178 package·--add=aide173 if·!·rpm·-q·--quiet·"aide"·;·then
 174 ····yum·install·-y·"aide"
 175 fi
  
 176 else
 177 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 178 fi
179 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*179 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
180 Run·the·following·command·to·generate·a·new·database:180 Run·the·following·command·to·generate·a·new·database:
181 $·sudo·/usr/sbin/aide·--init181 $·sudo·/usr/sbin/aide·--init
182 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the182 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
183 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these183 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
184 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their184 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
185 integrity.·The·newly-generated·database·can·be·installed·as·follows:185 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 206, 28 lines modifiedOffset 206, 14 lines modified
206 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3206 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
207 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5207 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
208 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199208 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
209 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359209 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359
210 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79210 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
211 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2211 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
212 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule212 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule
213 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
214 #·Remediation·is·applicable·only·in·certain·platforms 
215 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
216 if·!·rpm·-q·--quiet·"aide"·;·then 
217 ····yum·install·-y·"aide" 
218 fi 
  
219 /usr/sbin/aide·--init 
220 /bin/cp·-p·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz 
  
221 else 
222 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
223 fi 
224 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8213 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
225 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low214 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
226 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low215 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 989339/995186 bytes (99.41%) of diff not shown.
3.7 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-anssi_bp28_minimal.html
    
Offset 14302, 16 lines modifiedOffset 14302, 16 lines modified
00037dd0:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><00037dd0:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><
00037de0:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio00037de0:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio
00037df0:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.700037df0:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.7
00037e00:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u00037e00:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u
00037e10:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr00037e10:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr
00037e20:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···00037e20:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···
00037e30:·2020·2020·2020·2020·2020·2020·2020·2020··················00037e30:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037e40:·2028·6173·206f·6620·3230·3236·2d30·312d···(as·of·2026-01-00037e40:·2028·6173·206f·6620·3230·3234·2d31·322d···(as·of·2024-12-
00037e50:·3038·290a·2020·2020·2020·2020·2020·2020··08).············00037e50:·3037·290a·2020·2020·2020·2020·2020·2020··07).············
00037e60:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></00037e60:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></
00037e70:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of00037e70:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of
00037e80:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o00037e80:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o
00037e90:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#00037e90:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#
00037ea0:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro00037ea0:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro
00037eb0:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro00037eb0:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro
00037ec0:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste00037ec0:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste
Offset 14718, 183 lines modifiedOffset 14718, 183 lines modified
000397d0:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1000397d0:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
000397e0:·3035·3734·2220·7461·6269·6e64·6578·3d22··0574"·tabindex="000397e0:·3035·3734·2220·7461·6269·6e64·6578·3d22··0574"·tabindex="
000397f0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"000397f0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
00039800:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="00039800:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
00039810:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac00039810:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
00039820:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal00039820:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
00039830:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme00039830:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
00039840:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s00039840:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
 00039850:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 00039860:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 00039870:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 00039880:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 00039890:·3130·3537·3422·3e3c·7461·626c·6520·636c··10574"><table·cl
 000398a0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 000398b0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 000398c0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 000398d0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 000398e0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 000398f0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 00039900:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 00039910:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 00039920:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 00039930:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 00039940:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 00039950:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 00039960:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 00039970:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 00039980:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.
 00039990:·7061·636b·6167·6520·2d2d·6164·643d·646e··package·--add=dn
 000399a0:·662d·6175·746f·6d61·7469·630a·3c2f·636f··f-automatic.</co
 000399b0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 000399c0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 000399d0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 000399e0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 000399f0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 00039a00:·646d·3130·3537·3522·2074·6162·696e·6465··dm10575"·tabinde
 00039a10:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 00039a20:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 00039a30:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 00039a40:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 00039a50:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 00039a60:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
 00039a70:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 00039a80:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 00039a90:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 00039aa0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 00039ab0:·6d31·3035·3735·223e·3c74·6162·6c65·2063··m10575"><table·c
 00039ac0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 00039ad0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 00039ae0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 00039af0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 00039b00:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 00039b10:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 00039b20:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 00039b30:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 00039b40:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 00039b50:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 00039b60:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 00039b70:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 00039b80:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 00039b90:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 00039ba0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 00039bb0:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_
 00039bc0:·646e·662d·6175·746f·6d61·7469·630a·0a63··dnf-automatic..c
 00039bd0:·6c61·7373·2069·6e73·7461·6c6c·5f64·6e66··lass·install_dnf
 00039be0:·2d61·7574·6f6d·6174·6963·207b·0a20·2070··-automatic·{.··p
 00039bf0:·6163·6b61·6765·207b·2027·646e·662d·6175··ackage·{·'dnf-au
 00039c00:·746f·6d61·7469·6327·3a0a·2020·2020·656e··tomatic':.····en
 00039c10:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst
 00039c20:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</
 00039c30:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 00039c40:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 00039c50:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 00039c60:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 00039c70:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 00039c80:·2369·646d·3130·3537·3622·2074·6162·696e··#idm10576"·tabin
 00039c90:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 00039ca0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 00039cb0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 00039cc0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 00039cd0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 00039ce0:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB
 00039cf0:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s
00039850:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b00039d00:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
00039860:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa00039d10:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
00039870:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col00039d20:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
00039880:·6c61·7073·6522·2069·643d·2269·646d·3130··lapse"·id="idm1000039d30:·6c61·7073·6522·2069·643d·2269·646d·3130··lapse"·id="idm10
 00039d40:·3537·3622·3e3c·7072·653e·3c63·6f64·653e··576"><pre><code>
 00039d50:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 00039d60:·6d65·203d·2022·646e·662d·6175·746f·6d61··me·=·"dnf-automa
 00039d70:·7469·6322·0a76·6572·7369·6f6e·203d·2022··tic".version·=·"
00039890:·3537·3422·3e3c·7461·626c·6520·636c·6173··574"><table·clas 
000398a0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
000398b0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
000398c0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
000398d0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
000398e0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
000398f0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
00039900:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
00039910:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
00039920:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
00039930:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
00039940:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
00039950:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
00039960:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
00039970:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
00039980:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc 
00039990:·6c75·6465·2069·6e73·7461·6c6c·5f64·6e66··lude·install_dnf 
000399a0:·2d61·7574·6f6d·6174·6963·0a0a·636c·6173··-automatic..clas 
000399b0:·7320·696e·7374·616c·6c5f·646e·662d·6175··s·install_dnf-au 
Max diff block lines reached; 3611395/3636565 bytes (99.31%) of diff not shown.
238 KB
html2text {}
    
Offset 43, 15 lines modifiedOffset 43, 15 lines modified
43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(minimal)44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(minimal)
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_minimal45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_minimal
46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
47 ····*·cpe:/o:oracle:linux:847 ····*·cpe:/o:oracle:linux:8
48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
49 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8449 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
55 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s55 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
56 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s56 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
57 ·········1.·_\x8D_\x8H_\x8C_\x8P57 ·········1.·_\x8D_\x8H_\x8C_\x8P
Offset 80, 35 lines modifiedOffset 80, 38 lines modified
80 $·sudo·yum·install·dnf-automatic80 $·sudo·yum·install·dnf-automatic
81 Rationale:··dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade81 Rationale:··dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade
82 ············suitable·for·automatic,·regular·execution.82 ············suitable·for·automatic,·regular·execution.
83 Severity: ··medium83 Severity: ··medium
84 Rule·ID:····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed84 Rule·ID:····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
85 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-0008085 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
86 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R6186 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
 87 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 88 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 89 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 90 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 91 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 92 package·--add=dnf-automatic
87 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x893 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
88 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low94 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
89 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low95 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
90 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false96 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
91 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable97 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
92 include·install_dnf-automatic98 include·install_dnf-automatic
  
93 class·install_dnf-automatic·{99 class·install_dnf-automatic·{
94 ··package·{·'dnf-automatic':100 ··package·{·'dnf-automatic':
95 ····ensure·=>·'installed',101 ····ensure·=>·'installed',
96 ··}102 ··}
97 }103 }
 104 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
98 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
99 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
100 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
101 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
102 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
103 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then 
104 ····yum·install·-y·"dnf-automatic" 
105 fi105 [[packages]]
 106 name·=·"dnf-automatic"
 107 version·=·"*"
106 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
107 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low109 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
108 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low110 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
109 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false111 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
110 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable112 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
111 -·name:·Ensure·dnf-automatic·is·installed113 -·name:·Ensure·dnf-automatic·is·installed
112 ··package:114 ··package:
Offset 117, 26 lines modifiedOffset 120, 23 lines modified
117 ··tags:120 ··tags:
118 ··-·enable_strategy121 ··-·enable_strategy
119 ··-·low_complexity122 ··-·low_complexity
120 ··-·low_disruption123 ··-·low_disruption
121 ··-·medium_severity124 ··-·medium_severity
122 ··-·no_reboot_needed125 ··-·no_reboot_needed
123 ··-·package_dnf-automatic_installed126 ··-·package_dnf-automatic_installed
124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
125 [[packages]] 
126 name·=·"dnf-automatic" 
127 version·=·"*" 
128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_.n_.a_.c_.o_.n_.d_.a_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
133 package·--add=dnf-automatic132 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
 133 ····yum·install·-y·"dnf-automatic"
 134 fi
134 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*135 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
135 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed136 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
136 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/137 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
137 automatic.conf.138 automatic.conf.
138 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation139 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
139 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and140 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
140 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in141 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 146, 14 lines modifiedOffset 146, 36 lines modified
146 Severity: ··medium146 Severity: ··medium
147 Rule·ID:····xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates147 Rule·ID:····xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates
148 ············_\x8i_\x8s_\x8m····0940,·1144,·1467,·1472,·1483,·1493,·1494,·1495148 ············_\x8i_\x8s_\x8m····0940,·1144,·1467,·1472,·1483,·1493,·1494,·1495
149 ············_\x8n_\x8i_\x8s_\x8t···SI-2(5),·CM-6(a),·SI-2(c)149 ············_\x8n_\x8i_\x8s_\x8t···SI-2(5),·CM-6(a),·SI-2(c)
150 References:·_\x8o_\x8s_\x8p_\x8p···FMT_SMF_EXT.1150 References:·_\x8o_\x8s_\x8p_\x8p···FMT_SMF_EXT.1
151 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080151 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
152 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61152 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
 153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 154 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 155 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 156 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 157 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···unknown
 158 -·name:·Configure·dnf-automatic·to·Install·Available·Updates·Automatically
 159 ··ini_file:
 160 ····dest:·/etc/dnf/automatic.conf
 161 ····section:·commands
 162 ····option:·apply_updates
 163 ····value:·'yes'
 164 ····create:·true
 165 ··tags:
 166 ··-·NIST-800-53-CM-6(a)
 167 ··-·NIST-800-53-SI-2(5)
 168 ··-·NIST-800-53-SI-2(c)
 169 ··-·dnf-automatic_apply_updates
 170 ··-·low_complexity
 171 ··-·medium_disruption
 172 ··-·medium_severity
 173 ··-·no_reboot_needed
 174 ··-·unknown_strategy
153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
154 found=false176 found=false
  
155 #·set·value·in·all·files·if·they·contain·section·or·key177 #·set·value·in·all·files·if·they·contain·section·or·key
156 for·f·in·$(echo·-n·"/etc/dnf/automatic.conf");·do178 for·f·in·$(echo·-n·"/etc/dnf/automatic.conf");·do
157 ····if·[·!·-e·"$f"·];·then179 ····if·[·!·-e·"$f"·];·then
Max diff block lines reached; 238154/243824 bytes (97.67%) of diff not shown.
10.6 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-cjis.html
    
Offset 14290, 15 lines modifiedOffset 14290, 15 lines modified
00037d10:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current00037d10:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current
00037d20:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron00037d20:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron
00037d30:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong00037d30:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong
00037d40:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st00037d40:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st
00037d50:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro00037d50:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro
00037d60:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············00037d60:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············
00037d70:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·200037d70:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·2
00037d80:·3032·362d·3031·2d30·3829·0a20·2020·2020··026-01-08).·····00037d80:·3032·342d·3132·2d30·3729·0a20·2020·2020··024-12-07).·····
00037d90:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>00037d90:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>
00037da0:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T00037da0:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T
00037db0:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents00037db0:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents
00037dc0:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·00037dc0:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·
00037dd0:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org00037dd0:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org
00037de0:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont00037de0:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont
00037df0:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system00037df0:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system
Offset 15105, 301 lines modifiedOffset 15105, 301 lines modified
0003b000:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003b000:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b010:·6964·6d35·3334·3622·2074·6162·696e·6465··idm5346"·tabinde0003b010:·6964·6d35·3334·3622·2074·6162·696e·6465··idm5346"·tabinde
0003b020:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b020:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003b030:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003b030:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003b040:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003b040:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003b050:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003b050:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003b060:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003b060:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003b070:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003b080:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003b090:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b0a0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b0b0:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5 
0003b0c0:·3334·3622·3e3c·7072·653e·3c63·6f64·653e··346"><pre><code> 
0003b0d0:·0a23·2046·696e·6420·7768·6963·6820·6669··.#·Find·which·fi 
0003b0e0:·6c65·7320·6861·7665·2069·6e63·6f72·7265··les·have·incorre 
0003b0f0:·6374·2068·6173·6820·286e·6f74·2069·6e20··ct·hash·(not·in· 
0003b100:·2f65·7463·2c20·6265·6361·7573·6520·6f66··/etc,·because·of 
0003b110:·2074·6865·2073·7973·7465·6d20·7265·6c61···the·system·rela 
0003b120:·7465·6420·636f·6e66·6967·2066·696c·6573··ted·config·files 
0003b130:·2920·616e·6420·7468·656e·2067·6574·2066··)·and·then·get·f 
0003b140:·696c·6573·206e·616d·6573·0a66·696c·6573··iles·names.files 
0003b150:·5f77·6974·685f·696e·636f·7272·6563·745f··_with_incorrect_ 
0003b160:·6861·7368·3d22·2428·7270·6d20·2d56·6120··hash="$(rpm·-Va· 
0003b170:·2d2d·6e6f·636f·6e66·6967·207c·2067·7265··--noconfig·|·gre 
0003b180:·7020·2d45·2027·5e2e·2e35·2720·7c20·6177··p·-E·'^..5'·|·aw 
0003b190:·6b20·277b·7072·696e·7420·244e·467d·2720··k·'{print·$NF}'· 
0003b1a0:·2922·0a0a·6966·205b·202d·6e20·2224·6669··)"..if·[·-n·"$fi 
0003b1b0:·6c65·735f·7769·7468·5f69·6e63·6f72·7265··les_with_incorre 
0003b1c0:·6374·5f68·6173·6822·205d·3b20·7468·656e··ct_hash"·];·then 
0003b1d0:·0a20·2020·2023·2046·726f·6d20·6669·6c65··.····#·From·file 
0003b1e0:·7320·6e61·6d65·7320·6765·7420·7061·636b··s·names·get·pack 
0003b1f0:·6167·6520·6e61·6d65·7320·616e·6420·6368··age·names·and·ch 
0003b200:·616e·6765·206e·6577·6c69·6e65·2074·6f20··ange·newline·to· 
0003b210:·7370·6163·652c·2062·6563·6175·7365·2072··space,·because·r 
0003b220:·706d·2077·7269·7465·7320·6561·6368·2070··pm·writes·each·p 
0003b230:·6163·6b61·6765·2074·6f20·6e65·7720·6c69··ackage·to·new·li 
0003b240:·6e65·0a20·2020·2070·6163·6b61·6765·735f··ne.····packages_ 
0003b250:·746f·5f72·6569·6e73·7461·6c6c·3d22·2428··to_reinstall="$( 
0003b260:·7270·6d20·2d71·6620·2466·696c·6573·5f77··rpm·-qf·$files_w 
0003b270:·6974·685f·696e·636f·7272·6563·745f·6861··ith_incorrect_ha 
0003b280:·7368·207c·2074·7220·275c·6e27·2027·2027··sh·|·tr·'\n'·'·' 
0003b290:·2922·0a0a·2020·2020·0a20·2020·2079·756d··)"..····.····yum 
0003b2a0:·2072·6569·6e73·7461·6c6c·202d·7920·2470···reinstall·-y·$p 
0003b2b0:·6163·6b61·6765·735f·746f·5f72·6569·6e73··ackages_to_reins 
0003b2c0:·7461·6c6c·0a20·2020·200a·6669·0a3c·2f63··tall.····.fi.</c 
0003b2d0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003b2e0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003b2f0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003b300:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003b310:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003b320:·6964·6d35·3334·3722·2074·6162·696e·6465··idm5347"·tabinde 
0003b330:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003b340:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003b350:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003b360:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003b370:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003b380:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib0003b070:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib
0003b390:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</0003b080:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</
0003b3a0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003b090:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003b3b0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003b0a0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003b3c0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003b0b0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003b3d0:·646d·3533·3437·223e·3c74·6162·6c65·2063··dm5347"><table·c0003b0c0:·646d·3533·3436·223e·3c74·6162·6c65·2063··dm5346"><table·c
0003b3e0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003b0d0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003b3f0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003b0e0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003b400:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003b0f0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003b410:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003b100:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003b420:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003b110:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003b430:·683e·3c74·643e·6869·6768·3c2f·7464·3e3c··h><td>high</td><0003b120:·683e·3c74·643e·6869·6768·3c2f·7464·3e3c··h><td>high</td><
0003b440:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003b130:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003b450:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003b140:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003b460:·6d65·6469·756d·3c2f·7464·3e3c·2f74·723e··medium</td></tr>0003b150:·6d65·6469·756d·3c2f·7464·3e3c·2f74·723e··medium</td></tr>
0003b470:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<0003b160:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
0003b480:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003b170:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003b490:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003b180:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003b4a0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003b190:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003b4b0:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></0003b1a0:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></
0003b4c0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003b1b0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
0003b4d0:·3c63·6f64·653e·2d20·6e61·6d65·3a20·2753··<code>-·name:·'S0003b1c0:·3c63·6f64·653e·2d20·6e61·6d65·3a20·2753··<code>-·name:·'S
0003b4e0:·6574·2066·6163·743a·2050·6163·6b61·6765··et·fact:·Package0003b1d0:·6574·2066·6163·743a·2050·6163·6b61·6765··et·fact:·Package
0003b4f0:·206d·616e·6167·6572·2072·6569·6e73·7461···manager·reinsta0003b1e0:·206d·616e·6167·6572·2072·6569·6e73·7461···manager·reinsta
0003b500:·6c6c·2063·6f6d·6d61·6e64·270a·2020·7365··ll·command'.··se0003b1f0:·6c6c·2063·6f6d·6d61·6e64·270a·2020·7365··ll·command'.··se
0003b510:·745f·6661·6374·3a0a·2020·2020·7061·636b··t_fact:.····pack0003b200:·745f·6661·6374·3a0a·2020·2020·7061·636b··t_fact:.····pack
0003b520:·6167·655f·6d61·6e61·6765·725f·7265·696e··age_manager_rein0003b210:·6167·655f·6d61·6e61·6765·725f·7265·696e··age_manager_rein
0003b530:·7374·616c·6c5f·636d·643a·2079·756d·2072··stall_cmd:·yum·r0003b220:·7374·616c·6c5f·636d·643a·2079·756d·2072··stall_cmd:·yum·r
0003b540:·6569·6e73·7461·6c6c·202d·790a·2020·7768··einstall·-y.··wh0003b230:·6569·6e73·7461·6c6c·202d·790a·2020·7768··einstall·-y.··wh
0003b550:·656e·3a20·616e·7369·626c·655f·6469·7374··en:·ansible_dist0003b240:·656e·3a20·616e·7369·626c·655f·6469·7374··en:·ansible_dist
0003b560:·7269·6275·7469·6f6e·2069·6e20·5b20·2246··ribution·in·[·"F0003b250:·7269·6275·7469·6f6e·2069·6e20·5b20·2246··ribution·in·[·"F
0003b570:·6564·6f72·6122·2c20·2252·6564·4861·7422··edora",·"RedHat"0003b260:·6564·6f72·6122·2c20·2252·6564·4861·7422··edora",·"RedHat"
0003b580:·2c20·2243·656e·744f·5322·2c20·224f·7261··,·"CentOS",·"Ora0003b270:·2c20·2243·656e·744f·5322·2c20·224f·7261··,·"CentOS",·"Ora
0003b590:·636c·654c·696e·7578·2220·5d0a·2020·7461··cleLinux"·].··ta0003b280:·636c·654c·696e·7578·2220·5d0a·2020·7461··cleLinux"·].··ta
0003b5a0:·6773·3a0a·2020·2d20·434a·4953·2d35·2e31··gs:.··-·CJIS-5.10003b290:·6773·3a0a·2020·2d20·434a·4953·2d35·2e31··gs:.··-·CJIS-5.1
0003b5b0:·302e·342e·310a·2020·2d20·4e49·5354·2d38··0.4.1.··-·NIST-80003b2a0:·302e·342e·310a·2020·2d20·4e49·5354·2d38··0.4.1.··-·NIST-8
0003b5c0:·3030·2d31·3731·2d33·2e33·2e38·0a20·202d··00-171-3.3.8.··-0003b2b0:·3030·2d31·3731·2d33·2e33·2e38·0a20·202d··00-171-3.3.8.··-
0003b5d0:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.0003b2c0:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.
0003b5e0:·342e·310a·2020·2d20·4e49·5354·2d38·3030··4.1.··-·NIST-8000003b2d0:·342e·310a·2020·2d20·4e49·5354·2d38·3030··4.1.··-·NIST-800
0003b5f0:·2d35·332d·4155·2d39·2833·290a·2020·2d20··-53-AU-9(3).··-·0003b2e0:·2d35·332d·4155·2d39·2833·290a·2020·2d20··-53-AU-9(3).··-·
0003b600:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-60003b2f0:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6
0003b610:·2863·290a·2020·2d20·4e49·5354·2d38·3030··(c).··-·NIST-8000003b300:·2863·290a·2020·2d20·4e49·5354·2d38·3030··(c).··-·NIST-800
0003b620:·2d35·332d·434d·2d36·2864·290a·2020·2d20··-53-CM-6(d).··-·0003b310:·2d35·332d·434d·2d36·2864·290a·2020·2d20··-53-CM-6(d).··-·
0003b630:·4e49·5354·2d38·3030·2d35·332d·5349·2d37··NIST-800-53-SI-70003b320:·4e49·5354·2d38·3030·2d35·332d·5349·2d37··NIST-800-53-SI-7
0003b640:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-530003b330:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
0003b650:·2d53·492d·3728·3129·0a20·202d·204e·4953··-SI-7(1).··-·NIS0003b340:·2d53·492d·3728·3129·0a20·202d·204e·4953··-SI-7(1).··-·NIS
0003b660:·542d·3830·302d·3533·2d53·492d·3728·3629··T-800-53-SI-7(6)0003b350:·542d·3830·302d·3533·2d53·492d·3728·3629··T-800-53-SI-7(6)
0003b670:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req0003b360:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req
0003b680:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS0003b370:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS
0003b690:·5376·342d·3131·2e35·2e32·0a20·202d·2068··Sv4-11.5.2.··-·h0003b380:·5376·342d·3131·2e35·2e32·0a20·202d·2068··Sv4-11.5.2.··-·h
0003b6a0:·6967·685f·636f·6d70·6c65·7869·7479·0a20··igh_complexity.·0003b390:·6967·685f·636f·6d70·6c65·7869·7479·0a20··igh_complexity.·
0003b6b0:·202d·2068·6967·685f·7365·7665·7269·7479···-·high_severity0003b3a0:·202d·2068·6967·685f·7365·7665·7269·7479···-·high_severity
0003b6c0:·0a20·202d·206d·6564·6975·6d5f·6469·7372··.··-·medium_disr0003b3b0:·0a20·202d·206d·6564·6975·6d5f·6469·7372··.··-·medium_disr
0003b6d0:·7570·7469·6f6e·0a20·202d·206e·6f5f·7265··uption.··-·no_re0003b3c0:·7570·7469·6f6e·0a20·202d·206e·6f5f·7265··uption.··-·no_re
0003b6e0:·626f·6f74·5f6e·6565·6465·640a·2020·2d20··boot_needed.··-·0003b3d0:·626f·6f74·5f6e·6565·6465·640a·2020·2d20··boot_needed.··-·
Max diff block lines reached; 10099205/10140521 bytes (99.59%) of diff not shown.
916 KB
html2text {}
    
Offset 40, 15 lines modifiedOffset 40, 15 lines modified
40 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*40 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Criminal·Justice·Information·Services·(CJIS)·Security·Policy41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Criminal·Justice·Information·Services·(CJIS)·Security·Policy
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cjis42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cjis
43 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*43 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
44 ····*·cpe:/o:oracle:linux:844 ····*·cpe:/o:oracle:linux:8
45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
46 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8446 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
50 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e50 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
51 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l51 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
52 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n52 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
53 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s53 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
54 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s54 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 96, 27 lines modifiedOffset 96, 14 lines modified
96 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.696 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
97 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.497 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
98 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)98 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
99 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-199 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
100 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5100 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
101 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227101 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
102 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2102 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
103 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
104 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
105 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
106 if·[·-n·"$files_with_incorrect_hash"·];·then 
107 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
108 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
109 ····yum·reinstall·-y·$packages_to_reinstall 
  
110 fi 
111 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8103 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
112 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high104 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
113 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium105 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
114 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false106 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
115 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict107 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
116 -·name:·'Set·fact:·Package·manager·reinstall·command'108 -·name:·'Set·fact:·Package·manager·reinstall·command'
117 ··set_fact:109 ··set_fact:
Offset 243, 14 lines modifiedOffset 230, 27 lines modified
243 ··-·PCI-DSSv4-11.5.2230 ··-·PCI-DSSv4-11.5.2
244 ··-·high_complexity231 ··-·high_complexity
245 ··-·high_severity232 ··-·high_severity
246 ··-·medium_disruption233 ··-·medium_disruption
247 ··-·no_reboot_needed234 ··-·no_reboot_needed
248 ··-·restrict_strategy235 ··-·restrict_strategy
249 ··-·rpm_verify_hashes236 ··-·rpm_verify_hashes
 237 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 238 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 239 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 240 if·[·-n·"$files_with_incorrect_hash"·];·then
 241 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 242 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 243 ····yum·reinstall·-y·$packages_to_reinstall
  
 244 fi
250 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*245 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
251 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:246 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:
252 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'247 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'
253 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:248 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:
254 $·rpm·-qf·FILENAME249 $·rpm·-qf·FILENAME
  
255 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:250 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
Offset 271, 44 lines modifiedOffset 271, 14 lines modified
271 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5271 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
272 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2272 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
273 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)273 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)
274 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1274 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
275 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5275 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
276 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108276 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108
277 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2277 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
278 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
279 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
280 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
281 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
282 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
283 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
284 declare·-A·SETPERMS_RPM_DICT 
  
285 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
286 #·is·expected·by·the·RPM·database 
287 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}') 
  
288 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
289 do 
290 ········#·NOTE:·some·files·maybe·controlled·by·more·then·one·package 
291 ········readarray·-t·RPM_PACKAGES·<·<(rpm·-qf·"${FILE_PATH}") 
292 ········for·RPM_PACKAGE·in·"${RPM_PACKAGES[@]}" 
293 ········do 
294 ················#·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
295 ················SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
296 ········done 
297 done 
  
298 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
299 #·correct·values 
300 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
301 do 
302 »       rpm·--restore·"${RPM_PACKAGE}" 
303 done 
304 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8278 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
305 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high279 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
306 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium280 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
307 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false281 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
308 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict282 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
309 -·name:·Read·list·of·files·with·incorrect·permissions283 -·name:·Read·list·of·files·with·incorrect·permissions
310 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev284 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 386, 14 lines modifiedOffset 356, 44 lines modified
386 ··-·PCI-DSSv4-11.5.2356 ··-·PCI-DSSv4-11.5.2
387 ··-·high_complexity357 ··-·high_complexity
388 ··-·high_severity358 ··-·high_severity
389 ··-·medium_disruption359 ··-·medium_disruption
390 ··-·no_reboot_needed360 ··-·no_reboot_needed
391 ··-·restrict_strategy361 ··-·restrict_strategy
392 ··-·rpm_verify_permissions362 ··-·rpm_verify_permissions
 363 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 364 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 365 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
Max diff block lines reached; 929728/938025 bytes (99.12%) of diff not shown.
9.67 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-cui.html
    
Offset 14330, 15 lines modifiedOffset 14330, 15 lines modified
00037f90:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·00037f90:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·
00037fa0:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong00037fa0:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong
00037fb0:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>00037fb0:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>
00037fc0:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str00037fc0:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str
00037fd0:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron00037fd0:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron
00037fe0:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············00037fe0:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············
00037ff0:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·2000037ff0:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·20
00038000:·3236·2d30·312d·3038·290a·2020·2020·2020··26-01-08).······00038000:·3234·2d31·322d·3037·290a·2020·2020·2020··24-12-07).······
00038010:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><00038010:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><
00038020:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta00038020:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta
00038030:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<00038030:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<
00038040:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h00038040:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h
00038050:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.00038050:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.
00038060:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte00038060:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte
00038070:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"00038070:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"
Offset 15098, 203 lines modifiedOffset 15098, 203 lines modified
0003af90:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003af90:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003afa0:·743d·2223·6964·6d35·3638·3422·2074·6162··t="#idm5684"·tab0003afa0:·743d·2223·6964·6d35·3638·3422·2074·6162··t="#idm5684"·tab
0003afb0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003afb0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003afc0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003afc0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003afd0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003afd0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003afe0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003afe0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003aff0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003aff0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003b000:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P0003b000:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
0003b010:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..0003b010:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·
0003b020:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003b020:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003b030:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003b030:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003b040:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003b040:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003b050:·3d22·6964·6d35·3638·3422·3e3c·7461·626c··="idm5684"><tabl0003b050:·6964·3d22·6964·6d35·3638·3422·3e3c·7461··id="idm5684"><ta
0003b060:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003b060:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003b070:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003b070:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003b080:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003b080:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003b090:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003b090:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003b0a0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003b0a0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003b0b0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003b0b0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003b0c0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003b0c0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b0d0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003b0d0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
0003b0e0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003b0e0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003b0f0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</0003b0f0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
0003b100:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td0003b100:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
0003b110:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St0003b110:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b120:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003b120:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003b130:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>0003b130:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
0003b140:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co0003b140:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003b150:·636f·6465·3e0a·7061·636b·6167·6520·2d2d··code>.package·--
 0003b160:·6164·643d·6169·6465·0a3c·2f63·6f64·653e··add=aide.</code>
 0003b170:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003b180:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003b190:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
0003b150:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta 
0003b160:·6c6c·5f61·6964·650a·0a63·6c61·7373·2069··ll_aide..class·i 
0003b170:·6e73·7461·6c6c·5f61·6964·6520·7b0a·2020··nstall_aide·{.·· 
0003b180:·7061·636b·6167·6520·7b20·2761·6964·6527··package·{·'aide' 
0003b190:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g 
0003b1a0:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',. 
0003b1b0:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p 
0003b1c0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003b1d0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003b1e0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003b1f0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003b200:·7461·7267·6574·3d22·2369·646d·3536·3835··target="#idm5685 
0003b210:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003b220:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003b230:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003b240:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003b250:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003b260:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003b270:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003b280:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003b290:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003b2a0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003b2b0:·2069·643d·2269·646d·3536·3835·223e·3c74···id="idm5685"><t 
0003b2c0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003b2d0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003b2e0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003b2f0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003b300:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003b310:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003b320:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b330:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003b340:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003b350:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003b360:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003b370:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b380:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0003b390:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003b3a0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003b3b0:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat 
0003b3c0:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl 
0003b3d0:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai 
0003b3e0:·6e20·706c·6174·666f·726d·730a·6966·205b··n·platforms.if·[ 
0003b3f0:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren 
0003b400:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[ 
0003b410:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont 
0003b420:·6169·6e65·7265·6e76·205d·3b20·7468·656e··ainerenv·];·then 
0003b430:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·-- 
0003b440:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t 
0003b450:·6865·6e0a·2020·2020·7975·6d20·696e·7374··hen.····yum·inst 
0003b460:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi 
0003b470:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;& 
0003b480:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme 
0003b490:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a 
0003b4a0:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi 
0003b4b0:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi. 
0003b4c0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003b4d0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003b4e0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003b4f0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003b500:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003b510:·3d22·2369·646d·3536·3836·2220·7461·6269··="#idm5686"·tabi 
0003b520:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003b530:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003b540:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003b550:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003b560:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003b570:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An 
0003b580:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
0003b590:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b5a0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b5b0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003b1a0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0003b1b0:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm5
 0003b1c0:·3638·3522·2074·6162·696e·6465·783d·2230··685"·tabindex="0
 0003b1d0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0003b1e0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0003b1f0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0003b200:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0003b210:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
Max diff block lines reached; 8981197/9008989 bytes (99.69%) of diff not shown.
1.08 MB
html2text {}
    
Offset 50, 15 lines modifiedOffset 50, 15 lines modified
50 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Unclassified·Information·in·Non-federal·Information·Systems·and50 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Unclassified·Information·in·Non-federal·Information·Systems·and
51 ··············Organizations·(NIST·800-171)51 ··············Organizations·(NIST·800-171)
52 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cui52 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cui
53 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*53 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
54 ····*·cpe:/o:oracle:linux:854 ····*·cpe:/o:oracle:linux:8
55 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*55 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
56 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8456 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
57 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)57 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
58 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*58 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
59 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s59 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
60 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e60 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
61 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l61 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
62 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n62 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
63 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g63 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
64 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s64 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 108, 41 lines modifiedOffset 108, 38 lines modified
108 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3108 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
109 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5109 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
110 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199110 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
111 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359111 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359
112 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79112 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
113 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2113 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
114 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule114 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule
 115 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 116 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 117 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 118 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 119 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 120 package·--add=aide
115 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
116 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low122 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
117 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low123 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
118 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false124 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
119 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable125 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
120 include·install_aide126 include·install_aide
  
121 class·install_aide·{127 class·install_aide·{
122 ··package·{·'aide':128 ··package·{·'aide':
123 ····ensure·=>·'installed',129 ····ensure·=>·'installed',
124 ··}130 ··}
125 }131 }
 132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
131 #·Remediation·is·applicable·only·in·certain·platforms 
132 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
133 if·!·rpm·-q·--quiet·"aide"·;·then 
134 ····yum·install·-y·"aide" 
135 fi 
  
136 else 
137 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
138 fi133 [[packages]]
 134 name·=·"aide"
 135 version·=·"*"
139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
144 -·name:·Ensure·aide·is·installed141 -·name:·Ensure·aide·is·installed
145 ··package:142 ··package:
Offset 157, 26 lines modifiedOffset 154, 29 lines modified
157 ··-·PCI-DSSv4-11.5.2154 ··-·PCI-DSSv4-11.5.2
158 ··-·enable_strategy155 ··-·enable_strategy
159 ··-·low_complexity156 ··-·low_complexity
160 ··-·low_disruption157 ··-·low_disruption
161 ··-·medium_severity158 ··-·medium_severity
162 ··-·no_reboot_needed159 ··-·no_reboot_needed
163 ··-·package_aide_installed160 ··-·package_aide_installed
164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
165 [[packages]] 
166 name·=·"aide" 
167 version·=·"*" 
168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_.n_.a_.c_.o_.n_.d_.a_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 166 #·Remediation·is·applicable·only·in·certain·platforms
 167 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
173 package·--add=aide168 if·!·rpm·-q·--quiet·"aide"·;·then
 169 ····yum·install·-y·"aide"
 170 fi
  
 171 else
 172 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 173 fi
174 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules174 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
175 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.175 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
176 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·8.176 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·8.
  
177 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.177 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
178 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*178 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 192, 27 lines modifiedOffset 192, 14 lines modified
192 ············_\x8i_\x8s_\x8m······1446192 ············_\x8i_\x8s_\x8m······1446
193 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1193 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
194 References:·_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12194 References:·_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
195 ············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.1195 ············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.1
196 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223196 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223
197 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···OL08-00-010020197 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···OL08-00-010020
198 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-248524r958408_rule198 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-248524r958408_rule
199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
200 #·Remediation·is·applicable·only·in·certain·platforms 
201 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·);·then 
  
202 fips-mode-setup·--enable 
203 FIPS_CONF="/etc/dracut.conf.d/40-fips.conf" 
204 if·!·grep·"^add_dracutmodules+=\"·fips·\""·$FIPS_CONF;·then 
205 ····echo·"add_dracutmodules+=\"·fips·\""·>>·$FIPS_CONF 
206 fi 
  
207 else 
208 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
209 fi 
210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
211 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium
212 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
213 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
Max diff block lines reached; 1126074/1132515 bytes (99.43%) of diff not shown.
6.63 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-e8.html
    
Offset 14297, 16 lines modifiedOffset 14297, 16 lines modified
00037d80:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>00037d80:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>
00037d90:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi00037d90:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi
00037da0:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.00037da0:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.
00037db0:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><00037db0:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><
00037dc0:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d00037dc0:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d
00037dd0:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··00037dd0:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··
00037de0:·2020·2020·2020·2020·2020·2020·2020·2020··················00037de0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037df0:·2020·2861·7320·6f66·2032·3032·362d·3031····(as·of·2026-0100037df0:·2020·2861·7320·6f66·2032·3032·342d·3132····(as·of·2024-12
00037e00:·2d30·3829·0a20·2020·2020·2020·2020·2020··-08).···········00037e00:·2d30·3729·0a20·2020·2020·2020·2020·2020··-07).···········
00037e10:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><00037e10:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><
00037e20:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o00037e20:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o
00037e30:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><00037e30:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><
00037e40:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="00037e40:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="
00037e50:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr00037e50:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr
00037e60:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr00037e60:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr
00037e70:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst00037e70:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst
Offset 15142, 301 lines modifiedOffset 15142, 301 lines modified
0003b250:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003b250:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b260:·6964·6d35·3334·3622·2074·6162·696e·6465··idm5346"·tabinde0003b260:·6964·6d35·3334·3622·2074·6162·696e·6465··idm5346"·tabinde
0003b270:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b270:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003b280:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003b280:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003b290:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003b290:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003b2a0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003b2a0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003b2b0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003b2b0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003b2c0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003b2d0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003b2e0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b2f0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b300:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5 
0003b310:·3334·3622·3e3c·7072·653e·3c63·6f64·653e··346"><pre><code> 
0003b320:·0a23·2046·696e·6420·7768·6963·6820·6669··.#·Find·which·fi 
0003b330:·6c65·7320·6861·7665·2069·6e63·6f72·7265··les·have·incorre 
0003b340:·6374·2068·6173·6820·286e·6f74·2069·6e20··ct·hash·(not·in· 
0003b350:·2f65·7463·2c20·6265·6361·7573·6520·6f66··/etc,·because·of 
0003b360:·2074·6865·2073·7973·7465·6d20·7265·6c61···the·system·rela 
0003b370:·7465·6420·636f·6e66·6967·2066·696c·6573··ted·config·files 
0003b380:·2920·616e·6420·7468·656e·2067·6574·2066··)·and·then·get·f 
0003b390:·696c·6573·206e·616d·6573·0a66·696c·6573··iles·names.files 
0003b3a0:·5f77·6974·685f·696e·636f·7272·6563·745f··_with_incorrect_ 
0003b3b0:·6861·7368·3d22·2428·7270·6d20·2d56·6120··hash="$(rpm·-Va· 
0003b3c0:·2d2d·6e6f·636f·6e66·6967·207c·2067·7265··--noconfig·|·gre 
0003b3d0:·7020·2d45·2027·5e2e·2e35·2720·7c20·6177··p·-E·'^..5'·|·aw 
0003b3e0:·6b20·277b·7072·696e·7420·244e·467d·2720··k·'{print·$NF}'· 
0003b3f0:·2922·0a0a·6966·205b·202d·6e20·2224·6669··)"..if·[·-n·"$fi 
0003b400:·6c65·735f·7769·7468·5f69·6e63·6f72·7265··les_with_incorre 
0003b410:·6374·5f68·6173·6822·205d·3b20·7468·656e··ct_hash"·];·then 
0003b420:·0a20·2020·2023·2046·726f·6d20·6669·6c65··.····#·From·file 
0003b430:·7320·6e61·6d65·7320·6765·7420·7061·636b··s·names·get·pack 
0003b440:·6167·6520·6e61·6d65·7320·616e·6420·6368··age·names·and·ch 
0003b450:·616e·6765·206e·6577·6c69·6e65·2074·6f20··ange·newline·to· 
0003b460:·7370·6163·652c·2062·6563·6175·7365·2072··space,·because·r 
0003b470:·706d·2077·7269·7465·7320·6561·6368·2070··pm·writes·each·p 
0003b480:·6163·6b61·6765·2074·6f20·6e65·7720·6c69··ackage·to·new·li 
0003b490:·6e65·0a20·2020·2070·6163·6b61·6765·735f··ne.····packages_ 
0003b4a0:·746f·5f72·6569·6e73·7461·6c6c·3d22·2428··to_reinstall="$( 
0003b4b0:·7270·6d20·2d71·6620·2466·696c·6573·5f77··rpm·-qf·$files_w 
0003b4c0:·6974·685f·696e·636f·7272·6563·745f·6861··ith_incorrect_ha 
0003b4d0:·7368·207c·2074·7220·275c·6e27·2027·2027··sh·|·tr·'\n'·'·' 
0003b4e0:·2922·0a0a·2020·2020·0a20·2020·2079·756d··)"..····.····yum 
0003b4f0:·2072·6569·6e73·7461·6c6c·202d·7920·2470···reinstall·-y·$p 
0003b500:·6163·6b61·6765·735f·746f·5f72·6569·6e73··ackages_to_reins 
0003b510:·7461·6c6c·0a20·2020·200a·6669·0a3c·2f63··tall.····.fi.</c 
0003b520:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003b530:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003b540:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003b550:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003b560:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003b570:·6964·6d35·3334·3722·2074·6162·696e·6465··idm5347"·tabinde 
0003b580:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003b590:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003b5a0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003b5b0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003b5c0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003b5d0:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib0003b2c0:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib
0003b5e0:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</0003b2d0:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</
0003b5f0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003b2e0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003b600:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003b2f0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003b610:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003b300:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003b620:·646d·3533·3437·223e·3c74·6162·6c65·2063··dm5347"><table·c0003b310:·646d·3533·3436·223e·3c74·6162·6c65·2063··dm5346"><table·c
0003b630:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003b320:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003b640:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003b330:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003b650:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003b340:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003b660:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003b350:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003b670:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003b360:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003b680:·683e·3c74·643e·6869·6768·3c2f·7464·3e3c··h><td>high</td><0003b370:·683e·3c74·643e·6869·6768·3c2f·7464·3e3c··h><td>high</td><
0003b690:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003b380:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003b6a0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003b390:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003b6b0:·6d65·6469·756d·3c2f·7464·3e3c·2f74·723e··medium</td></tr>0003b3a0:·6d65·6469·756d·3c2f·7464·3e3c·2f74·723e··medium</td></tr>
0003b6c0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<0003b3b0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
0003b6d0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003b3c0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003b6e0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003b3d0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003b6f0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003b3e0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003b700:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></0003b3f0:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></
0003b710:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003b400:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
0003b720:·3c63·6f64·653e·2d20·6e61·6d65·3a20·2753··<code>-·name:·'S0003b410:·3c63·6f64·653e·2d20·6e61·6d65·3a20·2753··<code>-·name:·'S
0003b730:·6574·2066·6163·743a·2050·6163·6b61·6765··et·fact:·Package0003b420:·6574·2066·6163·743a·2050·6163·6b61·6765··et·fact:·Package
0003b740:·206d·616e·6167·6572·2072·6569·6e73·7461···manager·reinsta0003b430:·206d·616e·6167·6572·2072·6569·6e73·7461···manager·reinsta
0003b750:·6c6c·2063·6f6d·6d61·6e64·270a·2020·7365··ll·command'.··se0003b440:·6c6c·2063·6f6d·6d61·6e64·270a·2020·7365··ll·command'.··se
0003b760:·745f·6661·6374·3a0a·2020·2020·7061·636b··t_fact:.····pack0003b450:·745f·6661·6374·3a0a·2020·2020·7061·636b··t_fact:.····pack
0003b770:·6167·655f·6d61·6e61·6765·725f·7265·696e··age_manager_rein0003b460:·6167·655f·6d61·6e61·6765·725f·7265·696e··age_manager_rein
0003b780:·7374·616c·6c5f·636d·643a·2079·756d·2072··stall_cmd:·yum·r0003b470:·7374·616c·6c5f·636d·643a·2079·756d·2072··stall_cmd:·yum·r
0003b790:·6569·6e73·7461·6c6c·202d·790a·2020·7768··einstall·-y.··wh0003b480:·6569·6e73·7461·6c6c·202d·790a·2020·7768··einstall·-y.··wh
0003b7a0:·656e·3a20·616e·7369·626c·655f·6469·7374··en:·ansible_dist0003b490:·656e·3a20·616e·7369·626c·655f·6469·7374··en:·ansible_dist
0003b7b0:·7269·6275·7469·6f6e·2069·6e20·5b20·2246··ribution·in·[·"F0003b4a0:·7269·6275·7469·6f6e·2069·6e20·5b20·2246··ribution·in·[·"F
0003b7c0:·6564·6f72·6122·2c20·2252·6564·4861·7422··edora",·"RedHat"0003b4b0:·6564·6f72·6122·2c20·2252·6564·4861·7422··edora",·"RedHat"
0003b7d0:·2c20·2243·656e·744f·5322·2c20·224f·7261··,·"CentOS",·"Ora0003b4c0:·2c20·2243·656e·744f·5322·2c20·224f·7261··,·"CentOS",·"Ora
0003b7e0:·636c·654c·696e·7578·2220·5d0a·2020·7461··cleLinux"·].··ta0003b4d0:·636c·654c·696e·7578·2220·5d0a·2020·7461··cleLinux"·].··ta
0003b7f0:·6773·3a0a·2020·2d20·434a·4953·2d35·2e31··gs:.··-·CJIS-5.10003b4e0:·6773·3a0a·2020·2d20·434a·4953·2d35·2e31··gs:.··-·CJIS-5.1
0003b800:·302e·342e·310a·2020·2d20·4e49·5354·2d38··0.4.1.··-·NIST-80003b4f0:·302e·342e·310a·2020·2d20·4e49·5354·2d38··0.4.1.··-·NIST-8
0003b810:·3030·2d31·3731·2d33·2e33·2e38·0a20·202d··00-171-3.3.8.··-0003b500:·3030·2d31·3731·2d33·2e33·2e38·0a20·202d··00-171-3.3.8.··-
0003b820:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.0003b510:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.
0003b830:·342e·310a·2020·2d20·4e49·5354·2d38·3030··4.1.··-·NIST-8000003b520:·342e·310a·2020·2d20·4e49·5354·2d38·3030··4.1.··-·NIST-800
0003b840:·2d35·332d·4155·2d39·2833·290a·2020·2d20··-53-AU-9(3).··-·0003b530:·2d35·332d·4155·2d39·2833·290a·2020·2d20··-53-AU-9(3).··-·
0003b850:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-60003b540:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6
0003b860:·2863·290a·2020·2d20·4e49·5354·2d38·3030··(c).··-·NIST-8000003b550:·2863·290a·2020·2d20·4e49·5354·2d38·3030··(c).··-·NIST-800
0003b870:·2d35·332d·434d·2d36·2864·290a·2020·2d20··-53-CM-6(d).··-·0003b560:·2d35·332d·434d·2d36·2864·290a·2020·2d20··-53-CM-6(d).··-·
0003b880:·4e49·5354·2d38·3030·2d35·332d·5349·2d37··NIST-800-53-SI-70003b570:·4e49·5354·2d38·3030·2d35·332d·5349·2d37··NIST-800-53-SI-7
0003b890:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-530003b580:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
0003b8a0:·2d53·492d·3728·3129·0a20·202d·204e·4953··-SI-7(1).··-·NIS0003b590:·2d53·492d·3728·3129·0a20·202d·204e·4953··-SI-7(1).··-·NIS
0003b8b0:·542d·3830·302d·3533·2d53·492d·3728·3629··T-800-53-SI-7(6)0003b5a0:·542d·3830·302d·3533·2d53·492d·3728·3629··T-800-53-SI-7(6)
0003b8c0:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req0003b5b0:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req
0003b8d0:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS0003b5c0:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS
0003b8e0:·5376·342d·3131·2e35·2e32·0a20·202d·2068··Sv4-11.5.2.··-·h0003b5d0:·5376·342d·3131·2e35·2e32·0a20·202d·2068··Sv4-11.5.2.··-·h
0003b8f0:·6967·685f·636f·6d70·6c65·7869·7479·0a20··igh_complexity.·0003b5e0:·6967·685f·636f·6d70·6c65·7869·7479·0a20··igh_complexity.·
0003b900:·202d·2068·6967·685f·7365·7665·7269·7479···-·high_severity0003b5f0:·202d·2068·6967·685f·7365·7665·7269·7479···-·high_severity
0003b910:·0a20·202d·206d·6564·6975·6d5f·6469·7372··.··-·medium_disr0003b600:·0a20·202d·206d·6564·6975·6d5f·6469·7372··.··-·medium_disr
0003b920:·7570·7469·6f6e·0a20·202d·206e·6f5f·7265··uption.··-·no_re0003b610:·7570·7469·6f6e·0a20·202d·206e·6f5f·7265··uption.··-·no_re
Max diff block lines reached; 6233108/6274562 bytes (99.34%) of diff not shown.
665 KB
html2text {}
    
Offset 41, 15 lines modifiedOffset 41, 15 lines modified
41 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*41 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Australian·Cyber·Security·Centre·(ACSC)·Essential·Eight42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Australian·Cyber·Security·Centre·(ACSC)·Essential·Eight
43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_e843 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_e8
44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
45 ····*·cpe:/o:oracle:linux:845 ····*·cpe:/o:oracle:linux:8
46 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
47 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8447 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
48 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)48 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
49 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*49 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
50 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s50 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
51 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e51 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
52 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l52 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
53 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g53 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
54 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s54 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
55 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s55 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 103, 27 lines modifiedOffset 103, 14 lines modified
103 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6103 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
104 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4104 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
105 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)105 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
106 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1106 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
107 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5107 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
108 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227108 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
109 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2109 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
111 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
112 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
113 if·[·-n·"$files_with_incorrect_hash"·];·then 
114 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
115 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
116 ····yum·reinstall·-y·$packages_to_reinstall 
  
117 fi 
118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high111 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium112 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false113 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict114 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
123 -·name:·'Set·fact:·Package·manager·reinstall·command'115 -·name:·'Set·fact:·Package·manager·reinstall·command'
124 ··set_fact:116 ··set_fact:
Offset 250, 14 lines modifiedOffset 237, 27 lines modified
250 ··-·PCI-DSSv4-11.5.2237 ··-·PCI-DSSv4-11.5.2
251 ··-·high_complexity238 ··-·high_complexity
252 ··-·high_severity239 ··-·high_severity
253 ··-·medium_disruption240 ··-·medium_disruption
254 ··-·no_reboot_needed241 ··-·no_reboot_needed
255 ··-·restrict_strategy242 ··-·restrict_strategy
256 ··-·rpm_verify_hashes243 ··-·rpm_verify_hashes
 244 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 245 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 246 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 247 if·[·-n·"$files_with_incorrect_hash"·];·then
 248 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 249 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 250 ····yum·reinstall·-y·$packages_to_reinstall
  
 251 fi
257 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*252 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
258 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:253 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
259 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'254 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
260 run·the·following·command·to·determine·which·package·owns·it:255 run·the·following·command·to·determine·which·package·owns·it:
261 $·rpm·-qf·FILENAME256 $·rpm·-qf·FILENAME
262 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:257 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
263 $·sudo·rpm·--setugids·PACKAGENAME258 $·sudo·rpm·--setugids·PACKAGENAME
Offset 276, 40 lines modifiedOffset 276, 14 lines modified
276 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5276 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
277 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2277 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
278 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)278 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
279 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1279 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
280 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5280 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
281 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108281 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
282 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2282 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
283 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
284 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
285 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
286 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
287 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
288 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
289 declare·-A·SETPERMS_RPM_DICT 
  
290 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
291 #·is·expected·by·the·RPM·database 
292 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
293 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
294 do 
295 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
296 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
297 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
298 done 
  
299 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
300 #·correct·values 
301 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
302 do 
303 ········rpm·--setugids·"${RPM_PACKAGE}" 
304 done 
305 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8283 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
306 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high284 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
307 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium285 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
308 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false286 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
309 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict287 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
310 -·name:·Read·list·of·files·with·incorrect·ownership288 -·name:·Read·list·of·files·with·incorrect·ownership
311 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev289 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 384, 14 lines modifiedOffset 358, 40 lines modified
384 ··-·PCI-DSSv4-11.5.2358 ··-·PCI-DSSv4-11.5.2
385 ··-·high_complexity359 ··-·high_complexity
386 ··-·high_severity360 ··-·high_severity
387 ··-·medium_disruption361 ··-·medium_disruption
388 ··-·no_reboot_needed362 ··-·no_reboot_needed
389 ··-·restrict_strategy363 ··-·restrict_strategy
390 ··-·rpm_verify_ownership364 ··-·rpm_verify_ownership
 365 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 366 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 367 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 368 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 369 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 370 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 672919/680808 bytes (98.84%) of diff not shown.
17.6 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-hipaa.html
    
Offset 14316, 15 lines modifiedOffset 14316, 15 lines modified
00037eb0:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr00037eb0:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr
00037ec0:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st00037ec0:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st
00037ed0:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str00037ed0:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str
00037ee0:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>00037ee0:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>
00037ef0:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s00037ef0:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s
00037f00:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········00037f00:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········
00037f10:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o00037f10:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o
00037f20:·6620·3230·3236·2d30·312d·3038·290a·2020··f·2026-01-08).··00037f20:·6620·3230·3234·2d31·322d·3037·290a·2020··f·2024-12-07).··
00037f30:·2020·2020·2020·2020·2020·2020·2020·3c2f················</00037f30:·2020·2020·2020·2020·2020·2020·2020·3c2f················</
00037f40:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h00037f40:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h
00037f50:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte00037f50:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte
00037f60:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>00037f60:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>
00037f70:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_00037f70:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_
00037f80:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c00037f80:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c
00037f90:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys00037f90:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys
Offset 15167, 301 lines modifiedOffset 15167, 301 lines modified
0003b3e0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b3e0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003b3f0:·646d·3533·3436·2220·7461·6269·6e64·6578··dm5346"·tabindex0003b3f0:·646d·3533·3436·2220·7461·6269·6e64·6578··dm5346"·tabindex
0003b400:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b400:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b410:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b410:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b420:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b420:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b430:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b430:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b440:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b440:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003b450:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
0003b460:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003b470:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003b480:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003b490:·6c61·7073·6522·2069·643d·2269·646d·3533··lapse"·id="idm53 
0003b4a0:·3436·223e·3c70·7265·3e3c·636f·6465·3e0a··46"><pre><code>. 
0003b4b0:·2320·4669·6e64·2077·6869·6368·2066·696c··#·Find·which·fil 
0003b4c0:·6573·2068·6176·6520·696e·636f·7272·6563··es·have·incorrec 
0003b4d0:·7420·6861·7368·2028·6e6f·7420·696e·202f··t·hash·(not·in·/ 
0003b4e0:·6574·632c·2062·6563·6175·7365·206f·6620··etc,·because·of· 
0003b4f0:·7468·6520·7379·7374·656d·2072·656c·6174··the·system·relat 
0003b500:·6564·2063·6f6e·6669·6720·6669·6c65·7329··ed·config·files) 
0003b510:·2061·6e64·2074·6865·6e20·6765·7420·6669···and·then·get·fi 
0003b520:·6c65·7320·6e61·6d65·730a·6669·6c65·735f··les·names.files_ 
0003b530:·7769·7468·5f69·6e63·6f72·7265·6374·5f68··with_incorrect_h 
0003b540:·6173·683d·2224·2872·706d·202d·5661·202d··ash="$(rpm·-Va·- 
0003b550:·2d6e·6f63·6f6e·6669·6720·7c20·6772·6570··-noconfig·|·grep 
0003b560:·202d·4520·275e·2e2e·3527·207c·2061·776b···-E·'^..5'·|·awk 
0003b570:·2027·7b70·7269·6e74·2024·4e46·7d27·2029···'{print·$NF}'·) 
0003b580:·220a·0a69·6620·5b20·2d6e·2022·2466·696c··"..if·[·-n·"$fil 
0003b590:·6573·5f77·6974·685f·696e·636f·7272·6563··es_with_incorrec 
0003b5a0:·745f·6861·7368·2220·5d3b·2074·6865·6e0a··t_hash"·];·then. 
0003b5b0:·2020·2020·2320·4672·6f6d·2066·696c·6573······#·From·files 
0003b5c0:·206e·616d·6573·2067·6574·2070·6163·6b61···names·get·packa 
0003b5d0:·6765·206e·616d·6573·2061·6e64·2063·6861··ge·names·and·cha 
0003b5e0:·6e67·6520·6e65·776c·696e·6520·746f·2073··nge·newline·to·s 
0003b5f0:·7061·6365·2c20·6265·6361·7573·6520·7270··pace,·because·rp 
0003b600:·6d20·7772·6974·6573·2065·6163·6820·7061··m·writes·each·pa 
0003b610:·636b·6167·6520·746f·206e·6577·206c·696e··ckage·to·new·lin 
0003b620:·650a·2020·2020·7061·636b·6167·6573·5f74··e.····packages_t 
0003b630:·6f5f·7265·696e·7374·616c·6c3d·2224·2872··o_reinstall="$(r 
0003b640:·706d·202d·7166·2024·6669·6c65·735f·7769··pm·-qf·$files_wi 
0003b650:·7468·5f69·6e63·6f72·7265·6374·5f68·6173··th_incorrect_has 
0003b660:·6820·7c20·7472·2027·5c6e·2720·2720·2729··h·|·tr·'\n'·'·') 
0003b670:·220a·0a20·2020·200a·2020·2020·7975·6d20··"..····.····yum· 
0003b680:·7265·696e·7374·616c·6c20·2d79·2024·7061··reinstall·-y·$pa 
0003b690:·636b·6167·6573·5f74·6f5f·7265·696e·7374··ckages_to_reinst 
0003b6a0:·616c·6c0a·2020·2020·0a66·690a·3c2f·636f··all.····.fi.</co 
0003b6b0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003b6c0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003b6d0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003b6e0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003b6f0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003b700:·646d·3533·3437·2220·7461·6269·6e64·6578··dm5347"·tabindex 
0003b710:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003b720:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003b730:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003b740:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003b750:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003b760:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl0003b450:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl
0003b770:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a0003b460:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a
0003b780:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003b470:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003b790:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003b480:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003b7a0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003b490:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003b7b0:·6d35·3334·3722·3e3c·7461·626c·6520·636c··m5347"><table·cl0003b4a0:·6d35·3334·3622·3e3c·7461·626c·6520·636c··m5346"><table·cl
0003b7c0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003b4b0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003b7d0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003b4c0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003b7e0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003b4d0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003b7f0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003b4e0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003b800:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003b4f0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003b810:·3e3c·7464·3e68·6967·683c·2f74·643e·3c2f··><td>high</td></0003b500:·3e3c·7464·3e68·6967·683c·2f74·643e·3c2f··><td>high</td></
0003b820:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru0003b510:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003b830:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6d··ption:</th><td>m0003b520:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6d··ption:</th><td>m
0003b840:·6564·6975·6d3c·2f74·643e·3c2f·7472·3e3c··edium</td></tr><0003b530:·6564·6975·6d3c·2f74·643e·3c2f·7472·3e3c··edium</td></tr><
0003b850:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</0003b540:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
0003b860:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td0003b550:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
0003b870:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St0003b560:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
0003b880:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003b570:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0003b890:·7265·7374·7269·6374·3c2f·7464·3e3c·2f74··restrict</td></t0003b580:·7265·7374·7269·6374·3c2f·7464·3e3c·2f74··restrict</td></t
0003b8a0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003b590:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
0003b8b0:·636f·6465·3e2d·206e·616d·653a·2027·5365··code>-·name:·'Se0003b5a0:·636f·6465·3e2d·206e·616d·653a·2027·5365··code>-·name:·'Se
0003b8c0:·7420·6661·6374·3a20·5061·636b·6167·6520··t·fact:·Package·0003b5b0:·7420·6661·6374·3a20·5061·636b·6167·6520··t·fact:·Package·
0003b8d0:·6d61·6e61·6765·7220·7265·696e·7374·616c··manager·reinstal0003b5c0:·6d61·6e61·6765·7220·7265·696e·7374·616c··manager·reinstal
0003b8e0:·6c20·636f·6d6d·616e·6427·0a20·2073·6574··l·command'.··set0003b5d0:·6c20·636f·6d6d·616e·6427·0a20·2073·6574··l·command'.··set
0003b8f0:·5f66·6163·743a·0a20·2020·2070·6163·6b61··_fact:.····packa0003b5e0:·5f66·6163·743a·0a20·2020·2070·6163·6b61··_fact:.····packa
0003b900:·6765·5f6d·616e·6167·6572·5f72·6569·6e73··ge_manager_reins0003b5f0:·6765·5f6d·616e·6167·6572·5f72·6569·6e73··ge_manager_reins
0003b910:·7461·6c6c·5f63·6d64·3a20·7975·6d20·7265··tall_cmd:·yum·re0003b600:·7461·6c6c·5f63·6d64·3a20·7975·6d20·7265··tall_cmd:·yum·re
0003b920:·696e·7374·616c·6c20·2d79·0a20·2077·6865··install·-y.··whe0003b610:·696e·7374·616c·6c20·2d79·0a20·2077·6865··install·-y.··whe
0003b930:·6e3a·2061·6e73·6962·6c65·5f64·6973·7472··n:·ansible_distr0003b620:·6e3a·2061·6e73·6962·6c65·5f64·6973·7472··n:·ansible_distr
0003b940:·6962·7574·696f·6e20·696e·205b·2022·4665··ibution·in·[·"Fe0003b630:·6962·7574·696f·6e20·696e·205b·2022·4665··ibution·in·[·"Fe
0003b950:·646f·7261·222c·2022·5265·6448·6174·222c··dora",·"RedHat",0003b640:·646f·7261·222c·2022·5265·6448·6174·222c··dora",·"RedHat",
0003b960:·2022·4365·6e74·4f53·222c·2022·4f72·6163···"CentOS",·"Orac0003b650:·2022·4365·6e74·4f53·222c·2022·4f72·6163···"CentOS",·"Orac
0003b970:·6c65·4c69·6e75·7822·205d·0a20·2074·6167··leLinux"·].··tag0003b660:·6c65·4c69·6e75·7822·205d·0a20·2074·6167··leLinux"·].··tag
0003b980:·733a·0a20·202d·2043·4a49·532d·352e·3130··s:.··-·CJIS-5.100003b670:·733a·0a20·202d·2043·4a49·532d·352e·3130··s:.··-·CJIS-5.10
0003b990:·2e34·2e31·0a20·202d·204e·4953·542d·3830··.4.1.··-·NIST-800003b680:·2e34·2e31·0a20·202d·204e·4953·542d·3830··.4.1.··-·NIST-80
0003b9a0:·302d·3137·312d·332e·332e·380a·2020·2d20··0-171-3.3.8.··-·0003b690:·302d·3137·312d·332e·332e·380a·2020·2d20··0-171-3.3.8.··-·
0003b9b0:·4e49·5354·2d38·3030·2d31·3731·2d33·2e34··NIST-800-171-3.40003b6a0:·4e49·5354·2d38·3030·2d31·3731·2d33·2e34··NIST-800-171-3.4
0003b9c0:·2e31·0a20·202d·204e·4953·542d·3830·302d··.1.··-·NIST-800-0003b6b0:·2e31·0a20·202d·204e·4953·542d·3830·302d··.1.··-·NIST-800-
0003b9d0:·3533·2d41·552d·3928·3329·0a20·202d·204e··53-AU-9(3).··-·N0003b6c0:·3533·2d41·552d·3928·3329·0a20·202d·204e··53-AU-9(3).··-·N
0003b9e0:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6(0003b6d0:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6(
0003b9f0:·6329·0a20·202d·204e·4953·542d·3830·302d··c).··-·NIST-800-0003b6e0:·6329·0a20·202d·204e·4953·542d·3830·302d··c).··-·NIST-800-
0003ba00:·3533·2d43·4d2d·3628·6429·0a20·202d·204e··53-CM-6(d).··-·N0003b6f0:·3533·2d43·4d2d·3628·6429·0a20·202d·204e··53-CM-6(d).··-·N
0003ba10:·4953·542d·3830·302d·3533·2d53·492d·370a··IST-800-53-SI-7.0003b700:·4953·542d·3830·302d·3533·2d53·492d·370a··IST-800-53-SI-7.
0003ba20:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-0003b710:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
0003ba30:·5349·2d37·2831·290a·2020·2d20·4e49·5354··SI-7(1).··-·NIST0003b720:·5349·2d37·2831·290a·2020·2d20·4e49·5354··SI-7(1).··-·NIST
0003ba40:·2d38·3030·2d35·332d·5349·2d37·2836·290a··-800-53-SI-7(6).0003b730:·2d38·3030·2d35·332d·5349·2d37·2836·290a··-800-53-SI-7(6).
0003ba50:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req-0003b740:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req-
0003ba60:·3131·2e35·0a20·202d·2050·4349·2d44·5353··11.5.··-·PCI-DSS0003b750:·3131·2e35·0a20·202d·2050·4349·2d44·5353··11.5.··-·PCI-DSS
0003ba70:·7634·2d31·312e·352e·320a·2020·2d20·6869··v4-11.5.2.··-·hi0003b760:·7634·2d31·312e·352e·320a·2020·2d20·6869··v4-11.5.2.··-·hi
0003ba80:·6768·5f63·6f6d·706c·6578·6974·790a·2020··gh_complexity.··0003b770:·6768·5f63·6f6d·706c·6578·6974·790a·2020··gh_complexity.··
0003ba90:·2d20·6869·6768·5f73·6576·6572·6974·790a··-·high_severity.0003b780:·2d20·6869·6768·5f73·6576·6572·6974·790a··-·high_severity.
0003baa0:·2020·2d20·6d65·6469·756d·5f64·6973·7275····-·medium_disru0003b790:·2020·2d20·6d65·6469·756d·5f64·6973·7275····-·medium_disru
0003bab0:·7074·696f·6e0a·2020·2d20·6e6f·5f72·6562··ption.··-·no_reb0003b7a0:·7074·696f·6e0a·2020·2d20·6e6f·5f72·6562··ption.··-·no_reb
0003bac0:·6f6f·745f·6e65·6564·6564·0a20·202d·2072··oot_needed.··-·r0003b7b0:·6f6f·745f·6e65·6564·6564·0a20·202d·2072··oot_needed.··-·r
Max diff block lines reached; 17066451/17107767 bytes (99.76%) of diff not shown.
1.26 MB
html2text {}
    
Offset 46, 15 lines modifiedOffset 46, 15 lines modified
46 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
47 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Health·Insurance·Portability·and·Accountability·Act·(HIPAA)47 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Health·Insurance·Portability·and·Accountability·Act·(HIPAA)
48 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_hipaa48 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_hipaa
49 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*49 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
50 ····*·cpe:/o:oracle:linux:850 ····*·cpe:/o:oracle:linux:8
51 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
52 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8452 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
53 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)53 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
54 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*54 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
55 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s55 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
56 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e56 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
57 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l57 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
58 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n58 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
59 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g59 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
60 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s60 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 109, 27 lines modifiedOffset 109, 14 lines modified
109 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6109 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
110 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4110 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
111 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)111 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
112 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1112 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
113 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5113 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
114 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227114 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
115 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2115 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
116 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
117 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
118 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
119 if·[·-n·"$files_with_incorrect_hash"·];·then 
120 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
121 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
122 ····yum·reinstall·-y·$packages_to_reinstall 
  
123 fi 
124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8116 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high117 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
126 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium118 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
127 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false119 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
128 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict120 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
129 -·name:·'Set·fact:·Package·manager·reinstall·command'121 -·name:·'Set·fact:·Package·manager·reinstall·command'
130 ··set_fact:122 ··set_fact:
Offset 256, 14 lines modifiedOffset 243, 27 lines modified
256 ··-·PCI-DSSv4-11.5.2243 ··-·PCI-DSSv4-11.5.2
257 ··-·high_complexity244 ··-·high_complexity
258 ··-·high_severity245 ··-·high_severity
259 ··-·medium_disruption246 ··-·medium_disruption
260 ··-·no_reboot_needed247 ··-·no_reboot_needed
261 ··-·restrict_strategy248 ··-·restrict_strategy
262 ··-·rpm_verify_hashes249 ··-·rpm_verify_hashes
 250 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 251 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 252 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 253 if·[·-n·"$files_with_incorrect_hash"·];·then
 254 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 255 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 256 ····yum·reinstall·-y·$packages_to_reinstall
  
 257 fi
263 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*258 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
264 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:259 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:
265 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'260 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'
266 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:261 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:
267 $·rpm·-qf·FILENAME262 $·rpm·-qf·FILENAME
  
268 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:263 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
Offset 284, 44 lines modifiedOffset 284, 14 lines modified
284 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5284 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
285 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2285 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
286 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)286 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)
287 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1287 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
288 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5288 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
289 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108289 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108
290 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2290 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
291 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
292 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
293 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
294 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
295 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
296 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
297 declare·-A·SETPERMS_RPM_DICT 
  
298 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
299 #·is·expected·by·the·RPM·database 
300 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}') 
  
301 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
302 do 
303 ········#·NOTE:·some·files·maybe·controlled·by·more·then·one·package 
304 ········readarray·-t·RPM_PACKAGES·<·<(rpm·-qf·"${FILE_PATH}") 
305 ········for·RPM_PACKAGE·in·"${RPM_PACKAGES[@]}" 
306 ········do 
307 ················#·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
308 ················SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
309 ········done 
310 done 
  
311 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
312 #·correct·values 
313 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
314 do 
315 »       rpm·--restore·"${RPM_PACKAGE}" 
316 done 
317 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8291 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
318 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high292 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
319 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium293 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
320 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false294 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
321 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict295 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
322 -·name:·Read·list·of·files·with·incorrect·permissions296 -·name:·Read·list·of·files·with·incorrect·permissions
323 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev297 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 399, 14 lines modifiedOffset 369, 44 lines modified
399 ··-·PCI-DSSv4-11.5.2369 ··-·PCI-DSSv4-11.5.2
400 ··-·high_complexity370 ··-·high_complexity
401 ··-·high_severity371 ··-·high_severity
402 ··-·medium_disruption372 ··-·medium_disruption
403 ··-·no_reboot_needed373 ··-·no_reboot_needed
404 ··-·restrict_strategy374 ··-·restrict_strategy
405 ··-·rpm_verify_permissions375 ··-·rpm_verify_permissions
 376 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 377 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 378 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
Max diff block lines reached; 1316396/1324668 bytes (99.38%) of diff not shown.
9.67 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-ospp.html
    
Offset 14305, 15 lines modifiedOffset 14305, 15 lines modified
00037e00:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·00037e00:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·
00037e10:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong00037e10:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong
00037e20:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>00037e20:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>
00037e30:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str00037e30:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str
00037e40:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron00037e40:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron
00037e50:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············00037e50:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············
00037e60:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·2000037e60:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·20
00037e70:·3236·2d30·312d·3038·290a·2020·2020·2020··26-01-08).······00037e70:·3234·2d31·322d·3037·290a·2020·2020·2020··24-12-07).······
00037e80:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><00037e80:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><
00037e90:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta00037e90:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta
00037ea0:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<00037ea0:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<
00037eb0:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h00037eb0:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h
00037ec0:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.00037ec0:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.
00037ed0:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte00037ed0:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte
00037ee0:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"00037ee0:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"
Offset 15073, 203 lines modifiedOffset 15073, 203 lines modified
0003ae00:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003ae00:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003ae10:·743d·2223·6964·6d35·3638·3422·2074·6162··t="#idm5684"·tab0003ae10:·743d·2223·6964·6d35·3638·3422·2074·6162··t="#idm5684"·tab
0003ae20:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003ae20:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003ae30:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003ae30:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003ae40:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003ae40:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003ae50:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003ae50:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003ae60:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003ae60:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003ae70:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P0003ae70:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
0003ae80:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..0003ae80:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·
0003ae90:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003ae90:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003aea0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003aea0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003aeb0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003aeb0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003aec0:·3d22·6964·6d35·3638·3422·3e3c·7461·626c··="idm5684"><tabl0003aec0:·6964·3d22·6964·6d35·3638·3422·3e3c·7461··id="idm5684"><ta
0003aed0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003aed0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003aee0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003aee0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003aef0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003aef0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003af00:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003af00:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003af10:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003af10:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003af20:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003af20:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003af30:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003af30:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003af40:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003af40:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
0003af50:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003af50:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003af60:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</0003af60:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
0003af70:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td0003af70:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
0003af80:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St0003af80:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003af90:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003af90:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003afa0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>0003afa0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
0003afb0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co0003afb0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003afc0:·636f·6465·3e0a·7061·636b·6167·6520·2d2d··code>.package·--
 0003afd0:·6164·643d·6169·6465·0a3c·2f63·6f64·653e··add=aide.</code>
 0003afe0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003aff0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003b000:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
0003afc0:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta 
0003afd0:·6c6c·5f61·6964·650a·0a63·6c61·7373·2069··ll_aide..class·i 
0003afe0:·6e73·7461·6c6c·5f61·6964·6520·7b0a·2020··nstall_aide·{.·· 
0003aff0:·7061·636b·6167·6520·7b20·2761·6964·6527··package·{·'aide' 
0003b000:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g 
0003b010:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',. 
0003b020:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p 
0003b030:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003b040:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003b050:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003b060:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003b070:·7461·7267·6574·3d22·2369·646d·3536·3835··target="#idm5685 
0003b080:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003b090:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003b0a0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003b0b0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003b0c0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003b0d0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003b0e0:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003b0f0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003b100:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003b110:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003b120:·2069·643d·2269·646d·3536·3835·223e·3c74···id="idm5685"><t 
0003b130:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003b140:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003b150:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003b160:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003b170:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003b180:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003b190:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b1a0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003b1b0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003b1c0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003b1d0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003b1e0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b1f0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0003b200:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003b210:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003b220:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat 
0003b230:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl 
0003b240:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai 
0003b250:·6e20·706c·6174·666f·726d·730a·6966·205b··n·platforms.if·[ 
0003b260:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren 
0003b270:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[ 
0003b280:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont 
0003b290:·6169·6e65·7265·6e76·205d·3b20·7468·656e··ainerenv·];·then 
0003b2a0:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·-- 
0003b2b0:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t 
0003b2c0:·6865·6e0a·2020·2020·7975·6d20·696e·7374··hen.····yum·inst 
0003b2d0:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi 
0003b2e0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;& 
0003b2f0:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme 
0003b300:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a 
0003b310:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi 
0003b320:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi. 
0003b330:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003b340:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003b350:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003b360:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003b370:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003b380:·3d22·2369·646d·3536·3836·2220·7461·6269··="#idm5686"·tabi 
0003b390:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003b3a0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003b3b0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003b3c0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003b3d0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003b3e0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An 
0003b3f0:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
0003b400:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b410:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b420:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003b010:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0003b020:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm5
 0003b030:·3638·3522·2074·6162·696e·6465·783d·2230··685"·tabindex="0
 0003b040:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0003b050:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0003b060:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0003b070:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0003b080:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
Max diff block lines reached; 8981197/9008989 bytes (99.69%) of diff not shown.
1.08 MB
html2text {}
    
Offset 43, 15 lines modifiedOffset 43, 15 lines modified
43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Protection·Profile·for·General·Purpose·Operating·Systems44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Protection·Profile·for·General·Purpose·Operating·Systems
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ospp45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ospp
46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
47 ····*·cpe:/o:oracle:linux:847 ····*·cpe:/o:oracle:linux:8
48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
49 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8449 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
55 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n55 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
56 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g56 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
57 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s57 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 101, 41 lines modifiedOffset 101, 38 lines modified
101 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3101 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
102 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5102 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
103 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199103 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
104 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359104 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359
105 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79105 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
106 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2106 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
107 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule107 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule
 108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 109 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 110 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 111 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 112 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 113 package·--add=aide
108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
109 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low115 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
110 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low116 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
111 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false117 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
112 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable118 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
113 include·install_aide119 include·install_aide
  
114 class·install_aide·{120 class·install_aide·{
115 ··package·{·'aide':121 ··package·{·'aide':
116 ····ensure·=>·'installed',122 ····ensure·=>·'installed',
117 ··}123 ··}
118 }124 }
 125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
120 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
121 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
122 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
123 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
124 #·Remediation·is·applicable·only·in·certain·platforms 
125 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
126 if·!·rpm·-q·--quiet·"aide"·;·then 
127 ····yum·install·-y·"aide" 
128 fi 
  
129 else 
130 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
131 fi126 [[packages]]
 127 name·=·"aide"
 128 version·=·"*"
132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
137 -·name:·Ensure·aide·is·installed134 -·name:·Ensure·aide·is·installed
138 ··package:135 ··package:
Offset 150, 26 lines modifiedOffset 147, 29 lines modified
150 ··-·PCI-DSSv4-11.5.2147 ··-·PCI-DSSv4-11.5.2
151 ··-·enable_strategy148 ··-·enable_strategy
152 ··-·low_complexity149 ··-·low_complexity
153 ··-·low_disruption150 ··-·low_disruption
154 ··-·medium_severity151 ··-·medium_severity
155 ··-·no_reboot_needed152 ··-·no_reboot_needed
156 ··-·package_aide_installed153 ··-·package_aide_installed
157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
158 [[packages]] 
159 name·=·"aide" 
160 version·=·"*" 
161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_.n_.a_.c_.o_.n_.d_.a_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 159 #·Remediation·is·applicable·only·in·certain·platforms
 160 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
166 package·--add=aide161 if·!·rpm·-q·--quiet·"aide"·;·then
 162 ····yum·install·-y·"aide"
 163 fi
  
 164 else
 165 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 166 fi
167 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules167 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
168 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.168 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
169 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·8.169 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·8.
  
170 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.170 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
171 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*171 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 185, 27 lines modifiedOffset 185, 14 lines modified
185 ············_\x8i_\x8s_\x8m······1446185 ············_\x8i_\x8s_\x8m······1446
186 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1186 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
187 References:·_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12187 References:·_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
188 ············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.1188 ············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.1
189 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223189 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223
190 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···OL08-00-010020190 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···OL08-00-010020
191 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-248524r958408_rule191 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-248524r958408_rule
192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
193 #·Remediation·is·applicable·only·in·certain·platforms 
194 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·);·then 
  
195 fips-mode-setup·--enable 
196 FIPS_CONF="/etc/dracut.conf.d/40-fips.conf" 
197 if·!·grep·"^add_dracutmodules+=\"·fips·\""·$FIPS_CONF;·then 
198 ····echo·"add_dracutmodules+=\"·fips·\""·>>·$FIPS_CONF 
199 fi 
  
200 else 
201 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
202 fi 
203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
204 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium
205 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
206 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
Max diff block lines reached; 1126072/1132560 bytes (99.43%) of diff not shown.
17.8 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-pci-dss.html
    
Offset 14296, 15 lines modifiedOffset 14296, 15 lines modified
00037d70:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur00037d70:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur
00037d80:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s00037d80:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s
00037d90:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st00037d90:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st
00037da0:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li00037da0:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li
00037db0:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</00037db0:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</
00037dc0:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········00037dc0:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········
00037dd0:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·00037dd0:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·
00037de0:·6f66·2032·3032·362d·3031·2d30·3829·0a20··of·2026-01-08).·00037de0:·6f66·2032·3032·342d·3132·2d30·3729·0a20··of·2024-12-07).·
00037df0:·2020·2020·2020·2020·2020·2020·2020·203c·················<00037df0:·2020·2020·2020·2020·2020·2020·2020·203c·················<
00037e00:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><00037e00:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><
00037e10:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont00037e10:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont
00037e20:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li00037e20:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li
00037e30:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf00037e30:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf
00037e40:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.00037e40:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.
00037e50:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy00037e50:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy
Offset 15162, 301 lines modifiedOffset 15162, 301 lines modified
0003b390:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b390:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003b3a0:·3533·3436·2220·7461·6269·6e64·6578·3d22··5346"·tabindex="0003b3a0:·3533·3436·2220·7461·6269·6e64·6578·3d22··5346"·tabindex="
0003b3b0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b3b0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003b3c0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b3c0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003b3d0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003b3d0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003b3e0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003b3e0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003b3f0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003b3f0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003b400:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003b410:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003b420:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003b430:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003b440:·7073·6522·2069·643d·2269·646d·3533·3436··pse"·id="idm5346 
0003b450:·223e·3c70·7265·3e3c·636f·6465·3e0a·2320··"><pre><code>.#· 
0003b460:·4669·6e64·2077·6869·6368·2066·696c·6573··Find·which·files 
0003b470:·2068·6176·6520·696e·636f·7272·6563·7420···have·incorrect· 
0003b480:·6861·7368·2028·6e6f·7420·696e·202f·6574··hash·(not·in·/et 
0003b490:·632c·2062·6563·6175·7365·206f·6620·7468··c,·because·of·th 
0003b4a0:·6520·7379·7374·656d·2072·656c·6174·6564··e·system·related 
0003b4b0:·2063·6f6e·6669·6720·6669·6c65·7329·2061···config·files)·a 
0003b4c0:·6e64·2074·6865·6e20·6765·7420·6669·6c65··nd·then·get·file 
0003b4d0:·7320·6e61·6d65·730a·6669·6c65·735f·7769··s·names.files_wi 
0003b4e0:·7468·5f69·6e63·6f72·7265·6374·5f68·6173··th_incorrect_has 
0003b4f0:·683d·2224·2872·706d·202d·5661·202d·2d6e··h="$(rpm·-Va·--n 
0003b500:·6f63·6f6e·6669·6720·7c20·6772·6570·202d··oconfig·|·grep·- 
0003b510:·4520·275e·2e2e·3527·207c·2061·776b·2027··E·'^..5'·|·awk·' 
0003b520:·7b70·7269·6e74·2024·4e46·7d27·2029·220a··{print·$NF}'·)". 
0003b530:·0a69·6620·5b20·2d6e·2022·2466·696c·6573··.if·[·-n·"$files 
0003b540:·5f77·6974·685f·696e·636f·7272·6563·745f··_with_incorrect_ 
0003b550:·6861·7368·2220·5d3b·2074·6865·6e0a·2020··hash"·];·then.·· 
0003b560:·2020·2320·4672·6f6d·2066·696c·6573·206e····#·From·files·n 
0003b570:·616d·6573·2067·6574·2070·6163·6b61·6765··ames·get·package 
0003b580:·206e·616d·6573·2061·6e64·2063·6861·6e67···names·and·chang 
0003b590:·6520·6e65·776c·696e·6520·746f·2073·7061··e·newline·to·spa 
0003b5a0:·6365·2c20·6265·6361·7573·6520·7270·6d20··ce,·because·rpm· 
0003b5b0:·7772·6974·6573·2065·6163·6820·7061·636b··writes·each·pack 
0003b5c0:·6167·6520·746f·206e·6577·206c·696e·650a··age·to·new·line. 
0003b5d0:·2020·2020·7061·636b·6167·6573·5f74·6f5f······packages_to_ 
0003b5e0:·7265·696e·7374·616c·6c3d·2224·2872·706d··reinstall="$(rpm 
0003b5f0:·202d·7166·2024·6669·6c65·735f·7769·7468···-qf·$files_with 
0003b600:·5f69·6e63·6f72·7265·6374·5f68·6173·6820··_incorrect_hash· 
0003b610:·7c20·7472·2027·5c6e·2720·2720·2729·220a··|·tr·'\n'·'·')". 
0003b620:·0a20·2020·200a·2020·2020·7975·6d20·7265··.····.····yum·re 
0003b630:·696e·7374·616c·6c20·2d79·2024·7061·636b··install·-y·$pack 
0003b640:·6167·6573·5f74·6f5f·7265·696e·7374·616c··ages_to_reinstal 
0003b650:·6c0a·2020·2020·0a66·690a·3c2f·636f·6465··l.····.fi.</code 
0003b660:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003b670:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003b680:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003b690:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003b6a0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003b6b0:·3533·3437·2220·7461·6269·6e64·6578·3d22··5347"·tabindex=" 
0003b6c0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003b6d0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003b6e0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003b6f0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003b700:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003b710:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible·0003b400:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible·
0003b720:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003b410:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003b730:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003b420:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003b740:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003b430:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003b750:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm50003b440:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5
0003b760:·3334·3722·3e3c·7461·626c·6520·636c·6173··347"><table·clas0003b450:·3334·3622·3e3c·7461·626c·6520·636c·6173··346"><table·clas
0003b770:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003b460:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003b780:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003b470:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003b790:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003b480:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003b7a0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003b490:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003b7b0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003b4a0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003b7c0:·7464·3e68·6967·683c·2f74·643e·3c2f·7472··td>high</td></tr0003b4b0:·7464·3e68·6967·683c·2f74·643e·3c2f·7472··td>high</td></tr
0003b7d0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003b4c0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003b7e0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6d·6564··ion:</th><td>med0003b4d0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6d·6564··ion:</th><td>med
0003b7f0:·6975·6d3c·2f74·643e·3c2f·7472·3e3c·7472··ium</td></tr><tr0003b4e0:·6975·6d3c·2f74·643e·3c2f·7472·3e3c·7472··ium</td></tr><tr
0003b800:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th0003b4f0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
0003b810:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><0003b500:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
0003b820:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003b510:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
0003b830:·7465·6779·3a3c·2f74·683e·3c74·643e·7265··tegy:</th><td>re0003b520:·7465·6779·3a3c·2f74·683e·3c74·643e·7265··tegy:</th><td>re
0003b840:·7374·7269·6374·3c2f·7464·3e3c·2f74·723e··strict</td></tr>0003b530:·7374·7269·6374·3c2f·7464·3e3c·2f74·723e··strict</td></tr>
0003b850:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co0003b540:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
0003b860:·6465·3e2d·206e·616d·653a·2027·5365·7420··de>-·name:·'Set·0003b550:·6465·3e2d·206e·616d·653a·2027·5365·7420··de>-·name:·'Set·
0003b870:·6661·6374·3a20·5061·636b·6167·6520·6d61··fact:·Package·ma0003b560:·6661·6374·3a20·5061·636b·6167·6520·6d61··fact:·Package·ma
0003b880:·6e61·6765·7220·7265·696e·7374·616c·6c20··nager·reinstall·0003b570:·6e61·6765·7220·7265·696e·7374·616c·6c20··nager·reinstall·
0003b890:·636f·6d6d·616e·6427·0a20·2073·6574·5f66··command'.··set_f0003b580:·636f·6d6d·616e·6427·0a20·2073·6574·5f66··command'.··set_f
0003b8a0:·6163·743a·0a20·2020·2070·6163·6b61·6765··act:.····package0003b590:·6163·743a·0a20·2020·2070·6163·6b61·6765··act:.····package
0003b8b0:·5f6d·616e·6167·6572·5f72·6569·6e73·7461··_manager_reinsta0003b5a0:·5f6d·616e·6167·6572·5f72·6569·6e73·7461··_manager_reinsta
0003b8c0:·6c6c·5f63·6d64·3a20·7975·6d20·7265·696e··ll_cmd:·yum·rein0003b5b0:·6c6c·5f63·6d64·3a20·7975·6d20·7265·696e··ll_cmd:·yum·rein
0003b8d0:·7374·616c·6c20·2d79·0a20·2077·6865·6e3a··stall·-y.··when:0003b5c0:·7374·616c·6c20·2d79·0a20·2077·6865·6e3a··stall·-y.··when:
0003b8e0:·2061·6e73·6962·6c65·5f64·6973·7472·6962···ansible_distrib0003b5d0:·2061·6e73·6962·6c65·5f64·6973·7472·6962···ansible_distrib
0003b8f0:·7574·696f·6e20·696e·205b·2022·4665·646f··ution·in·[·"Fedo0003b5e0:·7574·696f·6e20·696e·205b·2022·4665·646f··ution·in·[·"Fedo
0003b900:·7261·222c·2022·5265·6448·6174·222c·2022··ra",·"RedHat",·"0003b5f0:·7261·222c·2022·5265·6448·6174·222c·2022··ra",·"RedHat",·"
0003b910:·4365·6e74·4f53·222c·2022·4f72·6163·6c65··CentOS",·"Oracle0003b600:·4365·6e74·4f53·222c·2022·4f72·6163·6c65··CentOS",·"Oracle
0003b920:·4c69·6e75·7822·205d·0a20·2074·6167·733a··Linux"·].··tags:0003b610:·4c69·6e75·7822·205d·0a20·2074·6167·733a··Linux"·].··tags:
0003b930:·0a20·202d·2043·4a49·532d·352e·3130·2e34··.··-·CJIS-5.10.40003b620:·0a20·202d·2043·4a49·532d·352e·3130·2e34··.··-·CJIS-5.10.4
0003b940:·2e31·0a20·202d·204e·4953·542d·3830·302d··.1.··-·NIST-800-0003b630:·2e31·0a20·202d·204e·4953·542d·3830·302d··.1.··-·NIST-800-
0003b950:·3137·312d·332e·332e·380a·2020·2d20·4e49··171-3.3.8.··-·NI0003b640:·3137·312d·332e·332e·380a·2020·2d20·4e49··171-3.3.8.··-·NI
0003b960:·5354·2d38·3030·2d31·3731·2d33·2e34·2e31··ST-800-171-3.4.10003b650:·5354·2d38·3030·2d31·3731·2d33·2e34·2e31··ST-800-171-3.4.1
 0003b660:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
 0003b670:·2d41·552d·3928·3329·0a20·202d·204e·4953··-AU-9(3).··-·NIS
 0003b680:·542d·3830·302d·3533·2d43·4d2d·3628·6329··T-800-53-CM-6(c)
0003b970:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-530003b690:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
0003b980:·2d41·552d·3928·3329·0a20·202d·204e·4953··-AU-9(3).··-·NIS 
0003b990:·542d·3830·302d·3533·2d43·4d2d·3628·6329··T-800-53-CM-6(c) 
0003b9a0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53 
0003b9b0:·2d43·4d2d·3628·6429·0a20·202d·204e·4953··-CM-6(d).··-·NIS0003b6a0:·2d43·4d2d·3628·6429·0a20·202d·204e·4953··-CM-6(d).··-·NIS
0003b9c0:·542d·3830·302d·3533·2d53·492d·370a·2020··T-800-53-SI-7.··0003b6b0:·542d·3830·302d·3533·2d53·492d·370a·2020··T-800-53-SI-7.··
0003b9d0:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI0003b6c0:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI
0003b9e0:·2d37·2831·290a·2020·2d20·4e49·5354·2d38··-7(1).··-·NIST-80003b6d0:·2d37·2831·290a·2020·2d20·4e49·5354·2d38··-7(1).··-·NIST-8
0003b9f0:·3030·2d35·332d·5349·2d37·2836·290a·2020··00-53-SI-7(6).··0003b6e0:·3030·2d35·332d·5349·2d37·2836·290a·2020··00-53-SI-7(6).··
0003ba00:·2d20·5043·492d·4453·532d·5265·712d·3131··-·PCI-DSS-Req-110003b6f0:·2d20·5043·492d·4453·532d·5265·712d·3131··-·PCI-DSS-Req-11
0003ba10:·2e35·0a20·202d·2050·4349·2d44·5353·7634··.5.··-·PCI-DSSv40003b700:·2e35·0a20·202d·2050·4349·2d44·5353·7634··.5.··-·PCI-DSSv4
0003ba20:·2d31·312e·352e·320a·2020·2d20·6869·6768··-11.5.2.··-·high0003b710:·2d31·312e·352e·320a·2020·2d20·6869·6768··-11.5.2.··-·high
0003ba30:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-·0003b720:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-·
0003ba40:·6869·6768·5f73·6576·6572·6974·790a·2020··high_severity.··0003b730:·6869·6768·5f73·6576·6572·6974·790a·2020··high_severity.··
Max diff block lines reached; 16992122/17033438 bytes (99.76%) of diff not shown.
1.55 MB
html2text {}
    
Offset 40, 15 lines modifiedOffset 40, 15 lines modified
40 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*40 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v4.0·Control·Baseline·for·Oracle·Linux·841 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v4.0·Control·Baseline·for·Oracle·Linux·8
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss
43 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*43 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
44 ····*·cpe:/o:oracle:linux:844 ····*·cpe:/o:oracle:linux:8
45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
46 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8446 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
50 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e50 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
51 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l51 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
52 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n52 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
53 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g53 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
54 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s54 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 106, 27 lines modifiedOffset 106, 14 lines modified
106 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6106 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
107 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4107 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
108 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)108 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
109 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1109 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
110 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5110 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
111 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227111 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
112 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2112 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
113 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
114 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
115 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
116 if·[·-n·"$files_with_incorrect_hash"·];·then 
117 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
118 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
119 ····yum·reinstall·-y·$packages_to_reinstall 
  
120 fi 
121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8113 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
122 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high114 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
123 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium115 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
124 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false116 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
125 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict117 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
126 -·name:·'Set·fact:·Package·manager·reinstall·command'118 -·name:·'Set·fact:·Package·manager·reinstall·command'
127 ··set_fact:119 ··set_fact:
Offset 253, 14 lines modifiedOffset 240, 27 lines modified
253 ··-·PCI-DSSv4-11.5.2240 ··-·PCI-DSSv4-11.5.2
254 ··-·high_complexity241 ··-·high_complexity
255 ··-·high_severity242 ··-·high_severity
256 ··-·medium_disruption243 ··-·medium_disruption
257 ··-·no_reboot_needed244 ··-·no_reboot_needed
258 ··-·restrict_strategy245 ··-·restrict_strategy
259 ··-·rpm_verify_hashes246 ··-·rpm_verify_hashes
 247 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 248 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 249 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 250 if·[·-n·"$files_with_incorrect_hash"·];·then
 251 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 252 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 253 ····yum·reinstall·-y·$packages_to_reinstall
  
 254 fi
260 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*255 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
261 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:256 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
262 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'257 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
263 run·the·following·command·to·determine·which·package·owns·it:258 run·the·following·command·to·determine·which·package·owns·it:
264 $·rpm·-qf·FILENAME259 $·rpm·-qf·FILENAME
265 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:260 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
266 $·sudo·rpm·--setugids·PACKAGENAME261 $·sudo·rpm·--setugids·PACKAGENAME
Offset 279, 40 lines modifiedOffset 279, 14 lines modified
279 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5279 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
280 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2280 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
281 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)281 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
282 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1282 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
283 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5283 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
284 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108284 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
285 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2285 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
286 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
287 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
288 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
289 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
290 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
291 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
292 declare·-A·SETPERMS_RPM_DICT 
  
293 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
294 #·is·expected·by·the·RPM·database 
295 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
296 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
297 do 
298 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
299 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
300 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
301 done 
  
302 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
303 #·correct·values 
304 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
305 do 
306 ········rpm·--setugids·"${RPM_PACKAGE}" 
307 done 
308 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8286 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
309 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high287 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
310 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium288 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
311 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false289 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
312 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict290 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
313 -·name:·Read·list·of·files·with·incorrect·ownership291 -·name:·Read·list·of·files·with·incorrect·ownership
314 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev292 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 387, 14 lines modifiedOffset 361, 40 lines modified
387 ··-·PCI-DSSv4-11.5.2361 ··-·PCI-DSSv4-11.5.2
388 ··-·high_complexity362 ··-·high_complexity
389 ··-·high_severity363 ··-·high_severity
390 ··-·medium_disruption364 ··-·medium_disruption
391 ··-·no_reboot_needed365 ··-·no_reboot_needed
392 ··-·restrict_strategy366 ··-·restrict_strategy
393 ··-·rpm_verify_ownership367 ··-·rpm_verify_ownership
 368 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 369 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 370 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 371 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 372 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 373 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 1613151/1620910 bytes (99.52%) of diff not shown.
10.8 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-standard.html
    
Offset 14285, 16 lines modifiedOffset 14285, 16 lines modified
00037cc0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00037cc0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00037cd0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00037cd0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00037ce0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000037ce0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00037cf0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></00037cf0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
00037d00:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00037d00:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00037d10:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00037d10:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00037d20:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037d20:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037d30:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600037d30:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
00037d40:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········00037d40:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00037d50:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00037d50:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00037d60:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00037d60:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00037d70:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00037d70:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00037d80:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00037d80:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00037d90:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00037d90:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00037da0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00037da0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00037db0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00037db0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
Offset 15091, 301 lines modifiedOffset 15091, 301 lines modified
0003af20:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003af20:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003af30:·2223·6964·6d35·3334·3622·2074·6162·696e··"#idm5346"·tabin0003af30:·2223·6964·6d35·3334·3622·2074·6162·696e··"#idm5346"·tabin
0003af40:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003af40:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003af50:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003af50:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003af60:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003af60:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003af70:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003af70:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003af80:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003af80:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003af90:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
0003afa0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
0003afb0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003afc0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003afd0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003afe0:·6d35·3334·3622·3e3c·7072·653e·3c63·6f64··m5346"><pre><cod 
0003aff0:·653e·0a23·2046·696e·6420·7768·6963·6820··e>.#·Find·which· 
0003b000:·6669·6c65·7320·6861·7665·2069·6e63·6f72··files·have·incor 
0003b010:·7265·6374·2068·6173·6820·286e·6f74·2069··rect·hash·(not·i 
0003b020:·6e20·2f65·7463·2c20·6265·6361·7573·6520··n·/etc,·because· 
0003b030:·6f66·2074·6865·2073·7973·7465·6d20·7265··of·the·system·re 
0003b040:·6c61·7465·6420·636f·6e66·6967·2066·696c··lated·config·fil 
0003b050:·6573·2920·616e·6420·7468·656e·2067·6574··es)·and·then·get 
0003b060:·2066·696c·6573·206e·616d·6573·0a66·696c···files·names.fil 
0003b070:·6573·5f77·6974·685f·696e·636f·7272·6563··es_with_incorrec 
0003b080:·745f·6861·7368·3d22·2428·7270·6d20·2d56··t_hash="$(rpm·-V 
0003b090:·6120·2d2d·6e6f·636f·6e66·6967·207c·2067··a·--noconfig·|·g 
0003b0a0:·7265·7020·2d45·2027·5e2e·2e35·2720·7c20··rep·-E·'^..5'·|· 
0003b0b0:·6177·6b20·277b·7072·696e·7420·244e·467d··awk·'{print·$NF} 
0003b0c0:·2720·2922·0a0a·6966·205b·202d·6e20·2224··'·)"..if·[·-n·"$ 
0003b0d0:·6669·6c65·735f·7769·7468·5f69·6e63·6f72··files_with_incor 
0003b0e0:·7265·6374·5f68·6173·6822·205d·3b20·7468··rect_hash"·];·th 
0003b0f0:·656e·0a20·2020·2023·2046·726f·6d20·6669··en.····#·From·fi 
0003b100:·6c65·7320·6e61·6d65·7320·6765·7420·7061··les·names·get·pa 
0003b110:·636b·6167·6520·6e61·6d65·7320·616e·6420··ckage·names·and· 
0003b120:·6368·616e·6765·206e·6577·6c69·6e65·2074··change·newline·t 
0003b130:·6f20·7370·6163·652c·2062·6563·6175·7365··o·space,·because 
0003b140:·2072·706d·2077·7269·7465·7320·6561·6368···rpm·writes·each 
0003b150:·2070·6163·6b61·6765·2074·6f20·6e65·7720···package·to·new· 
0003b160:·6c69·6e65·0a20·2020·2070·6163·6b61·6765··line.····package 
0003b170:·735f·746f·5f72·6569·6e73·7461·6c6c·3d22··s_to_reinstall=" 
0003b180:·2428·7270·6d20·2d71·6620·2466·696c·6573··$(rpm·-qf·$files 
0003b190:·5f77·6974·685f·696e·636f·7272·6563·745f··_with_incorrect_ 
0003b1a0:·6861·7368·207c·2074·7220·275c·6e27·2027··hash·|·tr·'\n'·' 
0003b1b0:·2027·2922·0a0a·2020·2020·0a20·2020·2079···')"..····.····y 
0003b1c0:·756d·2072·6569·6e73·7461·6c6c·202d·7920··um·reinstall·-y· 
0003b1d0:·2470·6163·6b61·6765·735f·746f·5f72·6569··$packages_to_rei 
0003b1e0:·6e73·7461·6c6c·0a20·2020·200a·6669·0a3c··nstall.····.fi.< 
0003b1f0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003b200:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003b210:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003b220:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003b230:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003b240:·2223·6964·6d35·3334·3722·2074·6162·696e··"#idm5347"·tabin 
0003b250:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003b260:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003b270:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003b280:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003b290:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003b2a0:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans0003af90:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans
0003b2b0:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...0003afa0:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...
0003b2c0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003afb0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003b2d0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003afc0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003b2e0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003afd0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003b2f0:·2269·646d·3533·3437·223e·3c74·6162·6c65··"idm5347"><table0003afe0:·2269·646d·3533·3436·223e·3c74·6162·6c65··"idm5346"><table
0003b300:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003aff0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003b310:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003b000:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003b320:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003b010:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003b330:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003b020:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003b340:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003b030:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003b350:·2f74·683e·3c74·643e·6869·6768·3c2f·7464··/th><td>high</td0003b040:·2f74·683e·3c74·643e·6869·6768·3c2f·7464··/th><td>high</td
0003b360:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003b050:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003b370:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003b060:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003b380:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t0003b070:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t
0003b390:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot0003b080:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
0003b3a0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<0003b090:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003b3b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b0a0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b3c0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003b0b0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003b3d0:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>0003b0c0:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>
0003b3e0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003b0d0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
0003b3f0:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·0003b0e0:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·
0003b400:·2753·6574·2066·6163·743a·2050·6163·6b61··'Set·fact:·Packa0003b0f0:·2753·6574·2066·6163·743a·2050·6163·6b61··'Set·fact:·Packa
0003b410:·6765·206d·616e·6167·6572·2072·6569·6e73··ge·manager·reins0003b100:·6765·206d·616e·6167·6572·2072·6569·6e73··ge·manager·reins
0003b420:·7461·6c6c·2063·6f6d·6d61·6e64·270a·2020··tall·command'.··0003b110:·7461·6c6c·2063·6f6d·6d61·6e64·270a·2020··tall·command'.··
0003b430:·7365·745f·6661·6374·3a0a·2020·2020·7061··set_fact:.····pa0003b120:·7365·745f·6661·6374·3a0a·2020·2020·7061··set_fact:.····pa
0003b440:·636b·6167·655f·6d61·6e61·6765·725f·7265··ckage_manager_re0003b130:·636b·6167·655f·6d61·6e61·6765·725f·7265··ckage_manager_re
0003b450:·696e·7374·616c·6c5f·636d·643a·2079·756d··install_cmd:·yum0003b140:·696e·7374·616c·6c5f·636d·643a·2079·756d··install_cmd:·yum
0003b460:·2072·6569·6e73·7461·6c6c·202d·790a·2020···reinstall·-y.··0003b150:·2072·6569·6e73·7461·6c6c·202d·790a·2020···reinstall·-y.··
0003b470:·7768·656e·3a20·616e·7369·626c·655f·6469··when:·ansible_di0003b160:·7768·656e·3a20·616e·7369·626c·655f·6469··when:·ansible_di
0003b480:·7374·7269·6275·7469·6f6e·2069·6e20·5b20··stribution·in·[·0003b170:·7374·7269·6275·7469·6f6e·2069·6e20·5b20··stribution·in·[·
0003b490:·2246·6564·6f72·6122·2c20·2252·6564·4861··"Fedora",·"RedHa0003b180:·2246·6564·6f72·6122·2c20·2252·6564·4861··"Fedora",·"RedHa
0003b4a0:·7422·2c20·2243·656e·744f·5322·2c20·224f··t",·"CentOS",·"O0003b190:·7422·2c20·2243·656e·744f·5322·2c20·224f··t",·"CentOS",·"O
0003b4b0:·7261·636c·654c·696e·7578·2220·5d0a·2020··racleLinux"·].··0003b1a0:·7261·636c·654c·696e·7578·2220·5d0a·2020··racleLinux"·].··
0003b4c0:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-50003b1b0:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-5
0003b4d0:·2e31·302e·342e·310a·2020·2d20·4e49·5354··.10.4.1.··-·NIST0003b1c0:·2e31·302e·342e·310a·2020·2d20·4e49·5354··.10.4.1.··-·NIST
0003b4e0:·2d38·3030·2d31·3731·2d33·2e33·2e38·0a20··-800-171-3.3.8.·0003b1d0:·2d38·3030·2d31·3731·2d33·2e33·2e38·0a20··-800-171-3.3.8.·
0003b4f0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-0003b1e0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
0003b500:·332e·342e·310a·2020·2d20·4e49·5354·2d38··3.4.1.··-·NIST-80003b1f0:·332e·342e·310a·2020·2d20·4e49·5354·2d38··3.4.1.··-·NIST-8
0003b510:·3030·2d35·332d·4155·2d39·2833·290a·2020··00-53-AU-9(3).··0003b200:·3030·2d35·332d·4155·2d39·2833·290a·2020··00-53-AU-9(3).··
0003b520:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM0003b210:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
0003b530:·2d36·2863·290a·2020·2d20·4e49·5354·2d38··-6(c).··-·NIST-80003b220:·2d36·2863·290a·2020·2d20·4e49·5354·2d38··-6(c).··-·NIST-8
0003b540:·3030·2d35·332d·434d·2d36·2864·290a·2020··00-53-CM-6(d).··0003b230:·3030·2d35·332d·434d·2d36·2864·290a·2020··00-53-CM-6(d).··
0003b550:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI0003b240:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI
0003b560:·2d37·0a20·202d·204e·4953·542d·3830·302d··-7.··-·NIST-800-0003b250:·2d37·0a20·202d·204e·4953·542d·3830·302d··-7.··-·NIST-800-
0003b570:·3533·2d53·492d·3728·3129·0a20·202d·204e··53-SI-7(1).··-·N0003b260:·3533·2d53·492d·3728·3129·0a20·202d·204e··53-SI-7(1).··-·N
0003b580:·4953·542d·3830·302d·3533·2d53·492d·3728··IST-800-53-SI-7(0003b270:·4953·542d·3830·302d·3533·2d53·492d·3728··IST-800-53-SI-7(
0003b590:·3629·0a20·202d·2050·4349·2d44·5353·2d52··6).··-·PCI-DSS-R0003b280:·3629·0a20·202d·2050·4349·2d44·5353·2d52··6).··-·PCI-DSS-R
0003b5a0:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI-0003b290:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI-
0003b5b0:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··-0003b2a0:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··-
0003b5c0:·2068·6967·685f·636f·6d70·6c65·7869·7479···high_complexity0003b2b0:·2068·6967·685f·636f·6d70·6c65·7869·7479···high_complexity
0003b5d0:·0a20·202d·2068·6967·685f·7365·7665·7269··.··-·high_severi0003b2c0:·0a20·202d·2068·6967·685f·7365·7665·7269··.··-·high_severi
0003b5e0:·7479·0a20·202d·206d·6564·6975·6d5f·6469··ty.··-·medium_di0003b2d0:·7479·0a20·202d·206d·6564·6975·6d5f·6469··ty.··-·medium_di
0003b5f0:·7372·7570·7469·6f6e·0a20·202d·206e·6f5f··sruption.··-·no_0003b2e0:·7372·7570·7469·6f6e·0a20·202d·206e·6f5f··sruption.··-·no_
Max diff block lines reached; 10535363/10561085 bytes (99.76%) of diff not shown.
769 KB
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Oracle·Linux·839 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Oracle·Linux·8
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard
41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
42 ····*·cpe:/o:oracle:linux:842 ····*·cpe:/o:oracle:linux:8
43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
44 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8444 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
49 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l49 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
51 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s51 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
52 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s52 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
Offset 93, 27 lines modifiedOffset 93, 14 lines modified
93 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.693 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
94 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.494 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
95 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)95 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
96 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-196 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
97 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.597 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
98 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-0022798 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
99 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.299 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
100 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
101 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
102 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
103 if·[·-n·"$files_with_incorrect_hash"·];·then 
104 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
105 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
106 ····yum·reinstall·-y·$packages_to_reinstall 
  
107 fi 
108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8100 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
109 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high101 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
110 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium102 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
111 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false103 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
112 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict104 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
113 -·name:·'Set·fact:·Package·manager·reinstall·command'105 -·name:·'Set·fact:·Package·manager·reinstall·command'
114 ··set_fact:106 ··set_fact:
Offset 240, 14 lines modifiedOffset 227, 27 lines modified
240 ··-·PCI-DSSv4-11.5.2227 ··-·PCI-DSSv4-11.5.2
241 ··-·high_complexity228 ··-·high_complexity
242 ··-·high_severity229 ··-·high_severity
243 ··-·medium_disruption230 ··-·medium_disruption
244 ··-·no_reboot_needed231 ··-·no_reboot_needed
245 ··-·restrict_strategy232 ··-·restrict_strategy
246 ··-·rpm_verify_hashes233 ··-·rpm_verify_hashes
 234 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 235 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 236 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 237 if·[·-n·"$files_with_incorrect_hash"·];·then
 238 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 239 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 240 ····yum·reinstall·-y·$packages_to_reinstall
  
 241 fi
247 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*242 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
248 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:243 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:
249 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'244 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'
250 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:245 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:
251 $·rpm·-qf·FILENAME246 $·rpm·-qf·FILENAME
  
252 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:247 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
Offset 268, 44 lines modifiedOffset 268, 14 lines modified
268 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5268 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
269 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2269 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
270 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)270 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)
271 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1271 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
272 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5272 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
273 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108273 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108
274 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2274 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
275 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
276 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
277 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
278 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
279 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
280 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
281 declare·-A·SETPERMS_RPM_DICT 
  
282 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
283 #·is·expected·by·the·RPM·database 
284 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}') 
  
285 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
286 do 
287 ········#·NOTE:·some·files·maybe·controlled·by·more·then·one·package 
288 ········readarray·-t·RPM_PACKAGES·<·<(rpm·-qf·"${FILE_PATH}") 
289 ········for·RPM_PACKAGE·in·"${RPM_PACKAGES[@]}" 
290 ········do 
291 ················#·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
292 ················SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
293 ········done 
294 done 
  
295 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
296 #·correct·values 
297 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
298 do 
299 »       rpm·--restore·"${RPM_PACKAGE}" 
300 done 
301 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8275 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
302 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high276 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
303 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium277 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
304 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false278 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
305 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict279 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
306 -·name:·Read·list·of·files·with·incorrect·permissions280 -·name:·Read·list·of·files·with·incorrect·permissions
307 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev281 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 383, 14 lines modifiedOffset 353, 44 lines modified
383 ··-·PCI-DSSv4-11.5.2353 ··-·PCI-DSSv4-11.5.2
384 ··-·high_complexity354 ··-·high_complexity
385 ··-·high_severity355 ··-·high_severity
386 ··-·medium_disruption356 ··-·medium_disruption
387 ··-·no_reboot_needed357 ··-·no_reboot_needed
388 ··-·restrict_strategy358 ··-·restrict_strategy
389 ··-·rpm_verify_permissions359 ··-·rpm_verify_permissions
 360 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 361 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 362 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
Max diff block lines reached; 779022/787188 bytes (98.96%) of diff not shown.
29.0 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-stig.html
    
Offset 14278, 16 lines modifiedOffset 14278, 16 lines modified
00037c50:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>00037c50:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>
00037c60:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi00037c60:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi
00037c70:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.00037c70:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.
00037c80:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><00037c80:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><
00037c90:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d00037c90:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d
00037ca0:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··00037ca0:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··
00037cb0:·2020·2020·2020·2020·2020·2020·2020·2020··················00037cb0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037cc0:·2020·2861·7320·6f66·2032·3032·362d·3031····(as·of·2026-0100037cc0:·2020·2861·7320·6f66·2032·3032·342d·3132····(as·of·2024-12
00037cd0:·2d30·3829·0a20·2020·2020·2020·2020·2020··-08).···········00037cd0:·2d30·3729·0a20·2020·2020·2020·2020·2020··-07).···········
00037ce0:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><00037ce0:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><
00037cf0:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o00037cf0:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o
00037d00:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><00037d00:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><
00037d10:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="00037d10:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="
00037d20:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr00037d20:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr
00037d30:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr00037d30:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr
00037d40:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst00037d40:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst
Offset 15076, 203 lines modifiedOffset 15076, 203 lines modified
0003ae30:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003ae30:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003ae40:·2223·6964·6d35·3638·3422·2074·6162·696e··"#idm5684"·tabin0003ae40:·2223·6964·6d35·3638·3422·2074·6162·696e··"#idm5684"·tabin
0003ae50:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003ae50:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003ae60:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003ae60:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003ae70:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003ae70:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003ae80:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003ae80:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003ae90:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003ae90:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003aea0:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup0003aea0:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana
0003aeb0:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<0003aeb0:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..
0003aec0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003aec0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003aed0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003aed0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003aee0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003aee0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003aef0:·6964·6d35·3638·3422·3e3c·7461·626c·6520··idm5684"><table·0003aef0:·3d22·6964·6d35·3638·3422·3e3c·7461·626c··="idm5684"><tabl
0003af00:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003af00:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0003af10:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003af10:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0003af20:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003af20:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0003af30:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003af30:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0003af40:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003af40:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003af50:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003af50:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003af60:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003af60:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003af70:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003af70:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003af80:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003af80:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003af90:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th0003af90:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
0003afa0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><0003afa0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
0003afb0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003afb0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
0003afc0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003afc0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0003afd0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003afd0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
0003afe0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003afe0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003aff0:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad
 0003b000:·643d·6169·6465·0a3c·2f63·6f64·653e·3c2f··d=aide.</code></
 0003b010:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0003b020:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
0003aff0:·3e69·6e63·6c75·6465·2069·6e73·7461·6c6c··>include·install 
0003b000:·5f61·6964·650a·0a63·6c61·7373·2069·6e73··_aide..class·ins 
0003b010:·7461·6c6c·5f61·6964·6520·7b0a·2020·7061··tall_aide·{.··pa 
0003b020:·636b·6167·6520·7b20·2761·6964·6527·3a0a··ckage·{·'aide':. 
0003b030:·2020·2020·656e·7375·7265·203d·2667·743b······ensure·=&gt; 
0003b040:·2027·696e·7374·616c·6c65·6427·2c0a·2020···'installed',.·· 
0003b050:·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70·7265··}.}.</code></pre 
0003b060:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003b070:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003b080:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003b090:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003b0a0:·7267·6574·3d22·2369·646d·3536·3835·2220··rget="#idm5685"· 
0003b0b0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003b0c0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003b0d0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003b0e0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003b0f0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003b100:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003b110:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
0003b120:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b130:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b140:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003b150:·643d·2269·646d·3536·3835·223e·3c74·6162··d="idm5685"><tab 
0003b160:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003b170:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003b180:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003b190:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003b1a0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003b1b0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b1c0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003b1d0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003b1e0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b1f0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003b200:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003b210:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003b220:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003b230:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003b240:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003b250:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio 
0003b260:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable· 
0003b270:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain· 
0003b280:·706c·6174·666f·726d·730a·6966·205b·2021··platforms.if·[·! 
0003b290:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv· 
0003b2a0:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·! 
0003b2b0:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai 
0003b2c0:·6e65·7265·6e76·205d·3b20·7468·656e·0a0a··nerenv·];·then.. 
0003b2d0:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu 
0003b2e0:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the 
0003b2f0:·6e0a·2020·2020·7975·6d20·696e·7374·616c··n.····yum·instal 
0003b300:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi.. 
0003b310:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am 
0003b320:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi 
0003b330:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app 
0003b340:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing 
0003b350:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</ 
0003b360:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003b370:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003b380:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003b390:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003b3a0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b030:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
0003b3b0:·2369·646d·3536·3836·2220·7461·6269·6e64··#idm5686"·tabind 
0003b3c0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003b3d0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003b3e0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003b3f0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003b400:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003b410:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi 
0003b420:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...< 
0003b430:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003b440:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003b450:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003b040:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 0003b050:·2d74·6172·6765·743d·2223·6964·6d35·3638··-target="#idm568
 0003b060:·3522·2074·6162·696e·6465·783d·2230·2220··5"·tabindex="0"·
 0003b070:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0003b080:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0003b090:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0003b0a0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0003b0b0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
Max diff block lines reached; 27985772/28013702 bytes (99.90%) of diff not shown.
2.24 MB
html2text {}
Max HTML report size reached
28.9 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-stig_gui.html
    
Offset 14302, 15 lines modifiedOffset 14302, 15 lines modified
00037dd0:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current00037dd0:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current
00037de0:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron00037de0:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron
00037df0:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong00037df0:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong
00037e00:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st00037e00:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st
00037e10:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro00037e10:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro
00037e20:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············00037e20:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············
00037e30:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·200037e30:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·2
00037e40:·3032·362d·3031·2d30·3829·0a20·2020·2020··026-01-08).·····00037e40:·3032·342d·3132·2d30·3729·0a20·2020·2020··024-12-07).·····
00037e50:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>00037e50:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>
00037e60:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T00037e60:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T
00037e70:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents00037e70:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents
00037e80:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·00037e80:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·
00037e90:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org00037e90:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org
00037ea0:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont00037ea0:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont
00037eb0:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system00037eb0:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system
Offset 15095, 202 lines modifiedOffset 15095, 202 lines modified
0003af60:·6574·3d22·2369·646d·3536·3834·2220·7461··et="#idm5684"·ta0003af60:·6574·3d22·2369·646d·3536·3834·2220·7461··et="#idm5684"·ta
0003af70:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003af70:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003af80:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003af80:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003af90:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003af90:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003afa0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003afa0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003afb0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003afb0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003afc0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003afc0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003afd0:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.0003afd0:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet
0003afe0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003afe0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003aff0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003aff0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003b000:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003b000:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003b010:·643d·2269·646d·3536·3834·223e·3c74·6162··d="idm5684"><tab0003b010:·2069·643d·2269·646d·3536·3834·223e·3c74···id="idm5684"><t
0003b020:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003b020:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003b030:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003b030:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003b040:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003b040:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003b050:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003b050:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003b060:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003b060:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003b070:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003b070:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003b080:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003b080:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b090:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003b090:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003b0a0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003b0a0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003b0b0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<0003b0b0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
0003b0c0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003b0c0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003b0d0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003b0d0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b0e0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003b0e0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003b0f0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr0003b0f0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
0003b100:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003b100:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003b110:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·-
 0003b120:·2d61·6464·3d61·6964·650a·3c2f·636f·6465··-add=aide.</code
 0003b130:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 0003b140:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 0003b150:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0003b110:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst 
0003b120:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class· 
0003b130:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.· 
0003b140:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide 
0003b150:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=& 
0003b160:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed', 
0003b170:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></ 
0003b180:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003b190:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003b1a0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003b1b0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003b1c0:·2d74·6172·6765·743d·2223·6964·6d35·3638··-target="#idm568 
0003b1d0:·3522·2074·6162·696e·6465·783d·2230·2220··5"·tabindex="0"· 
0003b1e0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003b1f0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003b200:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003b210:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003b220:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003b230:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
0003b240:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003b250:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003b260:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003b270:·2220·6964·3d22·6964·6d35·3638·3522·3e3c··"·id="idm5685">< 
0003b280:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003b290:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003b2a0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003b2b0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003b2c0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003b2d0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003b2e0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b2f0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003b300:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b310:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003b320:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003b330:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b340:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003b350:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003b360:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003b370:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia 
0003b380:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab 
0003b390:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa 
0003b3a0:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if· 
0003b3b0:·5b20·2120·2d66·202f·2e64·6f63·6b65·7265··[·!·-f·/.dockere 
0003b3c0:·6e76·205d·2026·616d·703b·2661·6d70·3b20··nv·]·&amp;&amp;· 
0003b3d0:·5b20·2120·2d66·202f·7275·6e2f·2e63·6f6e··[·!·-f·/run/.con 
0003b3e0:·7461·696e·6572·656e·7620·5d3b·2074·6865··tainerenv·];·the 
0003b3f0:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·- 
0003b400:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;· 
0003b410:·7468·656e·0a20·2020·2079·756d·2069·6e73··then.····yum·ins 
0003b420:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f 
0003b430:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt; 
0003b440:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem 
0003b450:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not· 
0003b460:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth 
0003b470:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi 
0003b480:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003b490:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b4a0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b4b0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b4c0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b4d0:·743d·2223·6964·6d35·3638·3622·2074·6162··t="#idm5686"·tab 
0003b4e0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b4f0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b500:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b510:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b520:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b530:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A 
0003b540:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
0003b550:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b560:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b570:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003b160:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 0003b170:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 0003b180:·3536·3835·2220·7461·6269·6e64·6578·3d22··5685"·tabindex="
 0003b190:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 0003b1a0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 0003b1b0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 0003b1c0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 0003b1d0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0003b1e0:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s
Max diff block lines reached; 27954248/27981902 bytes (99.90%) of diff not shown.
2.24 MB
html2text {}
Max HTML report size reached
21.3 MB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-anssi_bp28_enhanced.html
    
Offset 14302, 15 lines modifiedOffset 14302, 15 lines modified
00037dd0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00037dd0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00037de0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00037de0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00037df0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<00037df0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<
00037e00:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00037e00:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00037e10:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00037e10:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00037e20:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00037e20:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00037e30:·2020·2020·2020·2020·2020·2020·2020·2028·················(00037e30:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00037e40:·6173·206f·6620·3230·3236·2d30·312d·3038··as·of·2026-01-0800037e40:·6173·206f·6620·3230·3234·2d31·322d·3037··as·of·2024-12-07
00037e50:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00037e50:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00037e60:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00037e60:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00037e70:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00037e70:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00037e80:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00037e80:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00037e90:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00037e90:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00037ea0:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00037ea0:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00037eb0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00037eb0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
Offset 15037, 200 lines modifiedOffset 15037, 200 lines modified
0003abc0:·6172·6765·743d·2223·6964·6d35·3232·3222··arget="#idm5222"0003abc0:·6172·6765·743d·2223·6964·6d35·3232·3222··arget="#idm5222"
0003abd0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003abd0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003abe0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003abe0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003abf0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003abf0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003ac00:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003ac00:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003ac10:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003ac10:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003ac20:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003ac20:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003ac30:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe0003ac30:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip
0003ac40:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003ac40:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003ac50:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003ac50:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003ac60:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003ac60:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003ac70:·2220·6964·3d22·6964·6d35·3232·3222·3e3c··"·id="idm5222"><0003ac70:·7365·2220·6964·3d22·6964·6d35·3232·3222··se"·id="idm5222"
0003ac80:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003ac80:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003ac90:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003ac90:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003aca0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003aca0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003acb0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003acb0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003acc0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003acc0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003acd0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003acd0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003ace0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003ace0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003acf0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003acf0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003ad00:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003ad00:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003ad10:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo0003ad10:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
0003ad20:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false0003ad20:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
0003ad30:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003ad30:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
0003ad40:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>0003ad40:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0003ad50:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><0003ad50:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
0003ad60:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0003ad60:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003ad70:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag
 0003ad80:·6520·2d2d·6164·643d·6169·6465·0a3c·2f63··e·--add=aide.</c
0003ad70:·3e3c·636f·6465·3e69·6e63·6c75·6465·2069··><code>include·i 
0003ad80:·6e73·7461·6c6c·5f61·6964·650a·0a63·6c61··nstall_aide..cla 
0003ad90:·7373·2069·6e73·7461·6c6c·5f61·6964·6520··ss·install_aide· 
0003ada0:·7b0a·2020·7061·636b·6167·6520·7b20·2761··{.··package·{·'a 
0003adb0:·6964·6527·3a0a·2020·2020·656e·7375·7265··ide':.····ensure 
0003adc0:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe 
0003add0:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code 
0003ade0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003adf0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003ae00:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003ae10:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003ae20:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003ae30:·3532·3233·2220·7461·6269·6e64·6578·3d22··5223"·tabindex=" 
0003ae40:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003ae50:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003ae60:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003ae70:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003ae80:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003ae90:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003aea0:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003aeb0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003aec0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003aed0:·7073·6522·2069·643d·2269·646d·3532·3233··pse"·id="idm5223 
0003aee0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003aef0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003af00:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003af10:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003af20:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003af30:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003af40:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003af50:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003af60:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003af70:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003af80:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0003af90:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
0003afa0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003afb0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003afc0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003afd0:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme 
0003afe0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
0003aff0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
0003b000:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
0003b010:·6966·205b·2021·202d·6620·2f2e·646f·636b··if·[·!·-f·/.dock 
0003b020:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am 
0003b030:·703b·205b·2021·202d·6620·2f72·756e·2f2e··p;·[·!·-f·/run/. 
0003b040:·636f·6e74·6169·6e65·7265·6e76·205d·3b20··containerenv·];· 
0003b050:·7468·656e·0a0a·6966·2021·2072·706d·202d··then..if·!·rpm·- 
0003b060:·7120·2d2d·7175·6965·7420·2261·6964·6522··q·--quiet·"aide" 
0003b070:·203b·2074·6865·6e0a·2020·2020·7975·6d20···;·then.····yum· 
0003b080:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide 
0003b090:·220a·6669·0a0a·656c·7365·0a20·2020·2026··".fi..else.····& 
0003b0a0:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·' 
0003b0b0:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n 
0003b0c0:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n 
0003b0d0:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done' 
0003b0e0:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre 
0003b0f0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003b100:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003b110:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003b120:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003b130:·7267·6574·3d22·2369·646d·3532·3234·2220··rget="#idm5224"· 
0003b140:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003b150:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003b160:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003b170:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003b180:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003b190:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003b1a0:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe 
0003b1b0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003b1c0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003b1d0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003b1e0:·2220·6964·3d22·6964·6d35·3232·3422·3e3c··"·id="idm5224">< 
0003b1f0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003b200:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003b210:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003b220:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003b230:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003b240:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003b250:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b260:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003b270:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b280:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
Max diff block lines reached; 20429893/20457271 bytes (99.87%) of diff not shown.
1.75 MB
html2text {}
    
Offset 43, 15 lines modifiedOffset 43, 15 lines modified
43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(enhanced)44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(enhanced)
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_enhanced45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_enhanced
46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
47 ····*·cpe:/o:oracle:linux:947 ····*·cpe:/o:oracle:linux:9
48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
49 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8449 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
55 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r55 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
56 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n56 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
57 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g57 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 113, 41 lines modifiedOffset 113, 38 lines modified
113 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3113 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
114 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)114 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
115 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3115 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
116 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5116 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
117 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199117 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
118 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79118 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
119 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2119 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
 120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 121 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 122 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 123 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 124 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 125 package·--add=aide
120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
121 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
122 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
123 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
124 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
125 include·install_aide131 include·install_aide
  
126 class·install_aide·{132 class·install_aide·{
127 ··package·{·'aide':133 ··package·{·'aide':
128 ····ensure·=>·'installed',134 ····ensure·=>·'installed',
129 ··}135 ··}
130 }136 }
 137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
136 #·Remediation·is·applicable·only·in·certain·platforms 
137 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
138 if·!·rpm·-q·--quiet·"aide"·;·then 
139 ····yum·install·-y·"aide" 
140 fi 
  
141 else 
142 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
143 fi138 [[packages]]
 139 name·=·"aide"
 140 version·=·"*"
144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8141 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
145 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low142 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
146 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low143 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
147 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false144 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
148 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable145 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
149 -·name:·Ensure·aide·is·installed146 -·name:·Ensure·aide·is·installed
150 ··package:147 ··package:
Offset 161, 26 lines modifiedOffset 158, 29 lines modified
161 ··-·PCI-DSSv4-11.5.2158 ··-·PCI-DSSv4-11.5.2
162 ··-·enable_strategy159 ··-·enable_strategy
163 ··-·low_complexity160 ··-·low_complexity
164 ··-·low_disruption161 ··-·low_disruption
165 ··-·medium_severity162 ··-·medium_severity
166 ··-·no_reboot_needed163 ··-·no_reboot_needed
167 ··-·package_aide_installed164 ··-·package_aide_installed
168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
169 [[packages]] 
170 name·=·"aide" 
171 version·=·"*" 
172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_.n_.a_.c_.o_.n_.d_.a_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 170 #·Remediation·is·applicable·only·in·certain·platforms
 171 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
177 package·--add=aide172 if·!·rpm·-q·--quiet·"aide"·;·then
 173 ····yum·install·-y·"aide"
 174 fi
  
 175 else
 176 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 177 fi
178 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*178 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
179 Run·the·following·command·to·generate·a·new·database:179 Run·the·following·command·to·generate·a·new·database:
180 $·sudo·/usr/sbin/aide·--init180 $·sudo·/usr/sbin/aide·--init
181 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the181 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
182 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these182 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
183 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their183 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
184 integrity.·The·newly-generated·database·can·be·installed·as·follows:184 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 203, 28 lines modifiedOffset 203, 14 lines modified
203 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3203 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
204 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)204 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
205 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3205 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
206 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5206 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
207 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199207 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
208 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79208 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
209 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2209 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
211 #·Remediation·is·applicable·only·in·certain·platforms 
212 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
213 if·!·rpm·-q·--quiet·"aide"·;·then 
214 ····yum·install·-y·"aide" 
215 fi 
  
216 /usr/sbin/aide·--init 
217 /bin/cp·-p·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz 
  
218 else 
219 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
220 fi 
221 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
222 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low211 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
223 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low212 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 1829207/1834977 bytes (99.69%) of diff not shown.
21.6 MB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-anssi_bp28_high.html
    
Offset 14301, 15 lines modifiedOffset 14301, 15 lines modified
00037dc0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00037dc0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00037dd0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00037dd0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00037de0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<00037de0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<
00037df0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00037df0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00037e00:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00037e00:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00037e10:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00037e10:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00037e20:·2020·2020·2020·2020·2020·2020·2020·2028·················(00037e20:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00037e30:·6173·206f·6620·3230·3236·2d30·312d·3038··as·of·2026-01-0800037e30:·6173·206f·6620·3230·3234·2d31·322d·3037··as·of·2024-12-07
00037e40:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00037e40:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00037e50:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00037e50:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00037e60:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00037e60:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00037e70:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00037e70:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00037e80:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00037e80:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00037e90:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00037e90:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00037ea0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00037ea0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
Offset 15042, 201 lines modifiedOffset 15042, 201 lines modified
0003ac10:·612d·7461·7267·6574·3d22·2369·646d·3532··a-target="#idm520003ac10:·612d·7461·7267·6574·3d22·2369·646d·3532··a-target="#idm52
0003ac20:·3232·2220·7461·6269·6e64·6578·3d22·3022··22"·tabindex="0"0003ac20:·3232·2220·7461·6269·6e64·6578·3d22·3022··22"·tabindex="0"
0003ac30:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003ac30:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003ac40:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003ac40:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003ac50:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003ac50:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003ac60:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003ac60:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003ac70:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003ac70:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003ac80:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni0003ac80:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s
0003ac90:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003ac90:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003aca0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003aca0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003acb0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003acb0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003acc0:·7073·6522·2069·643d·2269·646d·3532·3232··pse"·id="idm52220003acc0:·6c61·7073·6522·2069·643d·2269·646d·3532··lapse"·id="idm52
0003acd0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003acd0:·3232·223e·3c74·6162·6c65·2063·6c61·7373··22"><table·class
0003ace0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003ace0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003acf0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003acf0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003ad00:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003ad00:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003ad10:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003ad10:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003ad20:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003ad20:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003ad30:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003ad30:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003ad40:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003ad40:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003ad50:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003ad50:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003ad60:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003ad60:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003ad70:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003ad70:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0003ad80:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003ad80:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
0003ad90:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003ad90:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003ada0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003ada0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0003adb0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003adb0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003adc0:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ0003adc0:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 0003add0:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide.
0003add0:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide.. 
0003ade0:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai 
0003adf0:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{ 
0003ae00:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens 
0003ae10:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta 
0003ae20:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c 
0003ae30:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003ae40:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003ae50:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003ae60:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003ae70:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003ae80:·6964·6d35·3232·3322·2074·6162·696e·6465··idm5223"·tabinde 
0003ae90:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003aea0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003aeb0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003aec0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003aed0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003aee0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003aef0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003af00:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003af10:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003af20:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5 
0003af30:·3232·3322·3e3c·7461·626c·6520·636c·6173··223"><table·clas 
0003af40:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003af50:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003af60:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003af70:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003af80:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003af90:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003afa0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003afb0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003afc0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003afd0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003afe0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003aff0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b000:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b010:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b020:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R 
0003b030:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003b040:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003b050:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003b060:·6d73·0a69·6620·5b20·2120·2d66·202f·2e64··ms.if·[·!·-f·/.d 
0003b070:·6f63·6b65·7265·6e76·205d·2026·616d·703b··ockerenv·]·&amp; 
0003b080:·2661·6d70·3b20·5b20·2120·2d66·202f·7275··&amp;·[·!·-f·/ru 
0003b090:·6e2f·2e63·6f6e·7461·696e·6572·656e·7620··n/.containerenv· 
0003b0a0:·5d3b·2074·6865·6e0a·0a69·6620·2120·7270··];·then..if·!·rp 
0003b0b0:·6d20·2d71·202d·2d71·7569·6574·2022·6169··m·-q·--quiet·"ai 
0003b0c0:·6465·2220·3b20·7468·656e·0a20·2020·2079··de"·;·then.····y 
0003b0d0:·756d·2069·6e73·7461·6c6c·202d·7920·2261··um·install·-y·"a 
0003b0e0:·6964·6522·0a66·690a·0a65·6c73·650a·2020··ide".fi..else.·· 
0003b0f0:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech 
0003b100:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i 
0003b110:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable 
0003b120:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do 
0003b130:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></ 
0003b140:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003b150:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003b160:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003b170:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003b180:·2d74·6172·6765·743d·2223·6964·6d35·3232··-target="#idm522 
0003b190:·3422·2074·6162·696e·6465·783d·2230·2220··4"·tabindex="0"· 
0003b1a0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003b1b0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003b1c0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003b1d0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003b1e0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003b1f0:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni 
0003b200:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003b210:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003b220:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003b230:·7073·6522·2069·643d·2269·646d·3532·3234··pse"·id="idm5224 
0003b240:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003b250:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003b260:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003b270:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003b280:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003b290:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003b2a0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003b2b0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003b2c0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b2d0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003b2e0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
Max diff block lines reached; 20718884/20746400 bytes (99.87%) of diff not shown.
1.79 MB
html2text {}
Max HTML report size reached
9.3 MB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-anssi_bp28_intermediary.html
    
Offset 14303, 15 lines modifiedOffset 14303, 15 lines modified
00037de0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00037de0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00037df0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00037df0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00037e00:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<00037e00:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<
00037e10:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00037e10:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00037e20:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00037e20:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00037e30:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00037e30:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00037e40:·2020·2020·2020·2020·2020·2020·2020·2028·················(00037e40:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00037e50:·6173·206f·6620·3230·3236·2d30·312d·3038··as·of·2026-01-0800037e50:·6173·206f·6620·3230·3234·2d31·322d·3037··as·of·2024-12-07
00037e60:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00037e60:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00037e70:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00037e70:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00037e80:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00037e80:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00037e90:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00037e90:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00037ea0:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00037ea0:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00037eb0:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00037eb0:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00037ec0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00037ec0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
Offset 15028, 200 lines modifiedOffset 15028, 200 lines modified
0003ab30:·7461·7267·6574·3d22·2369·646d·3532·3232··target="#idm52220003ab30:·7461·7267·6574·3d22·2369·646d·3532·3232··target="#idm5222
0003ab40:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003ab40:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003ab50:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003ab50:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003ab60:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003ab60:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003ab70:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003ab70:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003ab80:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003ab80:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003ab90:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003ab90:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003aba0:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp0003aba0:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni
0003abb0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0003abb0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003abc0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003abc0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003abd0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003abd0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003abe0:·6522·2069·643d·2269·646d·3532·3232·223e··e"·id="idm5222">0003abe0:·7073·6522·2069·643d·2269·646d·3532·3232··pse"·id="idm5222
0003abf0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003abf0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003ac00:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003ac00:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003ac10:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003ac10:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003ac20:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003ac20:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003ac30:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003ac30:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003ac40:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003ac40:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003ac50:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003ac50:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003ac60:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003ac60:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003ac70:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003ac70:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003ac80:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo0003ac80:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003ac90:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals0003ac90:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003aca0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><0003aca0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003acb0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th0003acb0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003acc0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>0003acc0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0003acd0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003acd0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003ace0:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa
 0003acf0:·6765·202d·2d61·6464·3d61·6964·650a·3c2f··ge·--add=aide.</
0003ace0:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include· 
0003acf0:·696e·7374·616c·6c5f·6169·6465·0a0a·636c··install_aide..cl 
0003ad00:·6173·7320·696e·7374·616c·6c5f·6169·6465··ass·install_aide 
0003ad10:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·' 
0003ad20:·6169·6465·273a·0a20·2020·2065·6e73·7572··aide':.····ensur 
0003ad30:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install 
0003ad40:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod 
0003ad50:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003ad60:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003ad70:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003ad80:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003ad90:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003ada0:·6d35·3232·3322·2074·6162·696e·6465·783d··m5223"·tabindex= 
0003adb0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003adc0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003add0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003ade0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003adf0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003ae00:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s 
0003ae10:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003ae20:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003ae30:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003ae40:·6170·7365·2220·6964·3d22·6964·6d35·3232··apse"·id="idm522 
0003ae50:·3322·3e3c·7461·626c·6520·636c·6173·733d··3"><table·class= 
0003ae60:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003ae70:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003ae80:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003ae90:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003aea0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003aeb0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003aec0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003aed0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003aee0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003aef0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003af00:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
0003af10:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003af20:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003af30:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003af40:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem 
0003af50:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl 
0003af60:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c 
0003af70:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms 
0003af80:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc 
0003af90:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a 
0003afa0:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/ 
0003afb0:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·]; 
0003afc0:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm· 
0003afd0:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide 
0003afe0:·2220·3b20·7468·656e·0a20·2020·2079·756d··"·;·then.····yum 
0003aff0:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid 
0003b000:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.···· 
0003b010:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo· 
0003b020:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is· 
0003b030:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,· 
0003b040:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done 
0003b050:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr 
0003b060:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003b070:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003b080:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003b090:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003b0a0:·6172·6765·743d·2223·6964·6d35·3232·3422··arget="#idm5224" 
0003b0b0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003b0c0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003b0d0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003b0e0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003b0f0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003b100:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003b110:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp 
0003b120:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003b130:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003b140:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003b150:·6522·2069·643d·2269·646d·3532·3234·223e··e"·id="idm5224"> 
0003b160:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003b170:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003b180:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003b190:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003b1a0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003b1b0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003b1c0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b1d0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003b1e0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b1f0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
Max diff block lines reached; 8751415/8778793 bytes (99.69%) of diff not shown.
952 KB
html2text {}
    
Offset 43, 15 lines modifiedOffset 43, 15 lines modified
43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(intermediary)44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(intermediary)
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_intermediary45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_intermediary
46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
47 ····*·cpe:/o:oracle:linux:947 ····*·cpe:/o:oracle:linux:9
48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
49 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8449 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
55 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n55 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
56 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s56 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
57 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s57 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 111, 41 lines modifiedOffset 111, 38 lines modified
111 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3111 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
112 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)112 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
113 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3113 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
114 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5114 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
115 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199115 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
116 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79116 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
117 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2117 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
 118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 123 package·--add=aide
118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low126 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false127 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable128 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
123 include·install_aide129 include·install_aide
  
124 class·install_aide·{130 class·install_aide·{
125 ··package·{·'aide':131 ··package·{·'aide':
126 ····ensure·=>·'installed',132 ····ensure·=>·'installed',
127 ··}133 ··}
128 }134 }
 135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
134 #·Remediation·is·applicable·only·in·certain·platforms 
135 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
136 if·!·rpm·-q·--quiet·"aide"·;·then 
137 ····yum·install·-y·"aide" 
138 fi 
  
139 else 
140 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
141 fi136 [[packages]]
 137 name·=·"aide"
 138 version·=·"*"
142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
147 -·name:·Ensure·aide·is·installed144 -·name:·Ensure·aide·is·installed
148 ··package:145 ··package:
Offset 159, 26 lines modifiedOffset 156, 29 lines modified
159 ··-·PCI-DSSv4-11.5.2156 ··-·PCI-DSSv4-11.5.2
160 ··-·enable_strategy157 ··-·enable_strategy
161 ··-·low_complexity158 ··-·low_complexity
162 ··-·low_disruption159 ··-·low_disruption
163 ··-·medium_severity160 ··-·medium_severity
164 ··-·no_reboot_needed161 ··-·no_reboot_needed
165 ··-·package_aide_installed162 ··-·package_aide_installed
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
167 [[packages]] 
168 name·=·"aide" 
169 version·=·"*" 
170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_.n_.a_.c_.o_.n_.d_.a_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 168 #·Remediation·is·applicable·only·in·certain·platforms
 169 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
175 package·--add=aide170 if·!·rpm·-q·--quiet·"aide"·;·then
 171 ····yum·install·-y·"aide"
 172 fi
  
 173 else
 174 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 175 fi
176 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*176 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
177 Run·the·following·command·to·generate·a·new·database:177 Run·the·following·command·to·generate·a·new·database:
178 $·sudo·/usr/sbin/aide·--init178 $·sudo·/usr/sbin/aide·--init
179 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the179 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
180 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these180 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
181 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their181 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
182 integrity.·The·newly-generated·database·can·be·installed·as·follows:182 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 201, 28 lines modifiedOffset 201, 14 lines modified
201 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3201 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
202 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)202 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
203 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3203 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
204 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5204 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
205 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199205 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
206 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79206 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
207 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2207 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
209 #·Remediation·is·applicable·only·in·certain·platforms 
210 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
211 if·!·rpm·-q·--quiet·"aide"·;·then 
212 ····yum·install·-y·"aide" 
213 fi 
  
214 /usr/sbin/aide·--init 
215 /bin/cp·-p·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz 
  
216 else 
217 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
218 fi 
219 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
220 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low209 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
221 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low210 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 968518/974407 bytes (99.40%) of diff not shown.
3.48 MB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-anssi_bp28_minimal.html
    
Offset 14302, 15 lines modifiedOffset 14302, 15 lines modified
00037dd0:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr00037dd0:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr
00037de0:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st00037de0:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st
00037df0:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str00037df0:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str
00037e00:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>00037e00:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>
00037e10:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s00037e10:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s
00037e20:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········00037e20:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········
00037e30:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o00037e30:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o
00037e40:·6620·3230·3236·2d30·312d·3038·290a·2020··f·2026-01-08).··00037e40:·6620·3230·3234·2d31·322d·3037·290a·2020··f·2024-12-07).··
00037e50:·2020·2020·2020·2020·2020·2020·2020·3c2f················</00037e50:·2020·2020·2020·2020·2020·2020·2020·3c2f················</
00037e60:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h00037e60:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h
00037e70:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte00037e70:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte
00037e80:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>00037e80:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>
00037e90:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_00037e90:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_
00037ea0:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c00037ea0:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c
00037eb0:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys00037eb0:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys
Offset 14718, 182 lines modifiedOffset 14718, 182 lines modified
000397d0:·6574·3d22·2369·646d·3834·3339·2220·7461··et="#idm8439"·ta000397d0:·6574·3d22·2369·646d·3834·3339·2220·7461··et="#idm8439"·ta
000397e0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=000397e0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
000397f0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex000397f0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
00039800:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t00039800:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
00039810:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t00039810:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
00039820:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="00039820:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
00039830:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·00039830:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
00039840:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.00039840:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet
00039850:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c00039850:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
00039860:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll00039860:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
00039870:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i00039870:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
00039880:·643d·2269·646d·3834·3339·223e·3c74·6162··d="idm8439"><tab00039880:·2069·643d·2269·646d·3834·3339·223e·3c74···id="idm8439"><t
00039890:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·00039890:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
000398a0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta000398a0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
000398b0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab000398b0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
000398c0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t000398c0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
000398d0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity000398d0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
000398e0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t000398e0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
000398f0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D000398f0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
00039900:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><00039900:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
00039910:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>00039910:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
00039920:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<00039920:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
00039930:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t00039930:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
00039940:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S00039940:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
00039950:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td00039950:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
00039960:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr00039960:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
00039970:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c00039970:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 00039980:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·-
 00039990:·2d61·6464·3d64·6e66·2d61·7574·6f6d·6174··-add=dnf-automat
 000399a0:·6963·0a3c·2f63·6f64·653e·3c2f·7072·653e··ic.</code></pre>
 000399b0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 000399c0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 000399d0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 000399e0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 000399f0:·6765·743d·2223·6964·6d38·3434·3022·2074··get="#idm8440"·t
 00039a00:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 00039a10:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 00039a20:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 00039a30:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 00039a40:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 00039a50:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 00039a60:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·
00039980:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst 
00039990:·616c·6c5f·646e·662d·6175·746f·6d61·7469··all_dnf-automati 
000399a0:·630a·0a63·6c61·7373·2069·6e73·7461·6c6c··c..class·install 
000399b0:·5f64·6e66·2d61·7574·6f6d·6174·6963·207b··_dnf-automatic·{ 
000399c0:·0a20·2070·6163·6b61·6765·207b·2027·646e··.··package·{·'dn 
000399d0:·662d·6175·746f·6d61·7469·6327·3a0a·2020··f-automatic':.·· 
000399e0:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·' 
000399f0:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}. 
00039a00:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre>< 
00039a10:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
00039a20:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
00039a30:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
00039a40:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
00039a50:·6574·3d22·2369·646d·3834·3430·2220·7461··et="#idm8440"·ta 
00039a60:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
00039a70:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
00039a80:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
00039a90:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
00039aa0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
00039ab0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
00039ac0:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
00039ad0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
00039ae0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
00039af0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
00039b00:·2269·646d·3834·3430·223e·3c74·6162·6c65··"idm8440"><table 
00039b10:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
00039b20:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
00039b30:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
00039b40:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
00039b50:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
00039b60:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
00039b70:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
00039b80:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
00039b90:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
00039ba0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
00039bb0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
00039bc0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
00039bd0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
00039be0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
00039bf0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
00039c00:·653e·0a69·6620·2120·7270·6d20·2d71·202d··e>.if·!·rpm·-q·- 
00039c10:·2d71·7569·6574·2022·646e·662d·6175·746f··-quiet·"dnf-auto 
00039c20:·6d61·7469·6322·203b·2074·6865·6e0a·2020··matic"·;·then.·· 
00039c30:·2020·7975·6d20·696e·7374·616c·6c20·2d79····yum·install·-y 
00039c40:·2022·646e·662d·6175·746f·6d61·7469·6322···"dnf-automatic" 
00039c50:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre 
00039c60:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
00039c70:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
00039c80:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
00039c90:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
00039ca0:·7267·6574·3d22·2369·646d·3834·3431·2220··rget="#idm8441"· 
00039cb0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
00039cc0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
00039cd0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
00039ce0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
00039cf0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
00039d00:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
00039d10:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe 
00039d20:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di00039a70:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
00039d30:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c00039a80:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
00039d40:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse00039a90:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
00039d50:·2220·6964·3d22·6964·6d38·3434·3122·3e3c··"·id="idm8441"><00039aa0:·6964·3d22·6964·6d38·3434·3022·3e3c·7461··id="idm8440"><ta
00039d60:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab00039ab0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
00039d70:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped00039ac0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
00039d80:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·00039ad0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
00039d90:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"00039ae0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
00039da0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex00039af0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
00039db0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low00039b00:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
00039dc0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
Max diff block lines reached; 3401219/3426113 bytes (99.27%) of diff not shown.
219 KB
html2text {}
    
Offset 43, 15 lines modifiedOffset 43, 15 lines modified
43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(minimal)44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(minimal)
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_minimal45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_minimal
46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*46 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
47 ····*·cpe:/o:oracle:linux:947 ····*·cpe:/o:oracle:linux:9
48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
49 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8449 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
55 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s55 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
56 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s56 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
57 ·········1.·_\x8D_\x8H_\x8C_\x8P57 ·········1.·_\x8D_\x8H_\x8C_\x8P
Offset 80, 35 lines modifiedOffset 80, 38 lines modified
80 $·sudo·yum·install·dnf-automatic80 $·sudo·yum·install·dnf-automatic
81 Rationale:··dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade81 Rationale:··dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade
82 ············suitable·for·automatic,·regular·execution.82 ············suitable·for·automatic,·regular·execution.
83 Severity: ··medium83 Severity: ··medium
84 Rule·ID:····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed84 Rule·ID:····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
85 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-0008085 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
86 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R6186 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
 87 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 88 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 89 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 90 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 91 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 92 package·--add=dnf-automatic
87 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x893 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
88 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low94 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
89 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low95 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
90 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false96 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
91 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable97 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
92 include·install_dnf-automatic98 include·install_dnf-automatic
  
93 class·install_dnf-automatic·{99 class·install_dnf-automatic·{
94 ··package·{·'dnf-automatic':100 ··package·{·'dnf-automatic':
95 ····ensure·=>·'installed',101 ····ensure·=>·'installed',
96 ··}102 ··}
97 }103 }
 104 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
98 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
99 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
100 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
101 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
102 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
103 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then 
104 ····yum·install·-y·"dnf-automatic" 
105 fi105 [[packages]]
 106 name·=·"dnf-automatic"
 107 version·=·"*"
106 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
107 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low109 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
108 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low110 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
109 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false111 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
110 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable112 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
111 -·name:·Ensure·dnf-automatic·is·installed113 -·name:·Ensure·dnf-automatic·is·installed
112 ··package:114 ··package:
Offset 117, 26 lines modifiedOffset 120, 23 lines modified
117 ··tags:120 ··tags:
118 ··-·enable_strategy121 ··-·enable_strategy
119 ··-·low_complexity122 ··-·low_complexity
120 ··-·low_disruption123 ··-·low_disruption
121 ··-·medium_severity124 ··-·medium_severity
122 ··-·no_reboot_needed125 ··-·no_reboot_needed
123 ··-·package_dnf-automatic_installed126 ··-·package_dnf-automatic_installed
124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
125 [[packages]] 
126 name·=·"dnf-automatic" 
127 version·=·"*" 
128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_.n_.a_.c_.o_.n_.d_.a_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
133 package·--add=dnf-automatic132 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
 133 ····yum·install·-y·"dnf-automatic"
 134 fi
134 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*135 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
135 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed136 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
136 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/137 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
137 automatic.conf.138 automatic.conf.
138 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation139 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
139 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and140 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
140 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in141 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 268, 42 lines modifiedOffset 268, 14 lines modified
268 ···························(a),·CM-11(b)268 ···························(a),·CM-11(b)
269 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1269 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
270 ············_\x8o_\x8s_\x8p_\x8p···········FPT_TUD_EXT.1,·FPT_TUD_EXT.2270 ············_\x8o_\x8s_\x8p_\x8p···········FPT_TUD_EXT.1,·FPT_TUD_EXT.2
271 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-6.2271 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-6.2
272 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000366-GPOS-00153272 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000366-GPOS-00153
273 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R59273 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R59
274 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········6.3.3274 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········6.3.3
275 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
276 #·Remediation·is·applicable·only·in·certain·platforms 
277 if·rpm·--quiet·-q·yum;·then 
  
278 #·Strip·any·search·characters·in·the·key·arg·so·that·the·key·can·be·replaced·without 
279 #·adding·any·search·characters·to·the·config·file. 
280 stripped_key=$(sed·'s/[\^=\$,;+]*//g'·<<<·"^gpgcheck") 
  
281 #·shellcheck·disable=SC2059 
282 printf·-v·formatted_output·"%s·=·%s"·"$stripped_key"·"1" 
  
283 #·If·the·key·exists,·change·it.·Otherwise,·add·it·to·the·config_file. 
284 #·We·search·for·the·key·string·followed·by·a·word·boundary·(matched·by·\>), 
285 #·so·if·we·search·for·'setting',·'setting2'·won't·match. 
286 if·LC_ALL=C·grep·-q·-m·1·-i·-e·"^gpgcheck\\>"·"/etc/yum.conf";·then 
287 ····escaped_formatted_output=$(sed·-e·'s|/|\\/|g'·<<<·"$formatted_output") 
288 ····LC_ALL=C·sed·-i·--follow-symlinks·"s/^gpgcheck\\>.*/$escaped_formatted_output/gi"·"/etc/ 
289 yum.conf" 
290 else 
291 ····if·[[·-s·"/etc/yum.conf"·]]·&&·[[·-n·"$(tail·-c·1·--·"/etc/yum.conf"·||·true)"·]];·then 
292 ········LC_ALL=C·sed·-i·--follow-symlinks·'$a'\\·"/etc/yum.conf" 
293 ····fi 
294 ····printf·'%s\n'·"$formatted_output"·>>·"/etc/yum.conf" 
295 fi 
  
296 else 
297 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
298 fi 
299 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8275 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
Max diff block lines reached; 217871/223980 bytes (97.27%) of diff not shown.
4.95 MB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-cui.html
    
Offset 14331, 15 lines modifiedOffset 14331, 15 lines modified
00037fa0:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·00037fa0:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·
00037fb0:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong00037fb0:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong
00037fc0:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>00037fc0:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>
00037fd0:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str00037fd0:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str
00037fe0:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron00037fe0:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron
00037ff0:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············00037ff0:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············
00038000:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·2000038000:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·20
00038010:·3236·2d30·312d·3038·290a·2020·2020·2020··26-01-08).······00038010:·3234·2d31·322d·3037·290a·2020·2020·2020··24-12-07).······
00038020:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><00038020:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><
00038030:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta00038030:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta
00038040:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<00038040:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<
00038050:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h00038050:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h
00038060:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.00038060:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.
00038070:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte00038070:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte
00038080:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"00038080:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"
Offset 15041, 192 lines modifiedOffset 15041, 192 lines modified
0003ac00:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003ac00:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003ac10:·2369·646d·3537·3130·2220·7461·6269·6e64··#idm5710"·tabind0003ac10:·2369·646d·3537·3130·2220·7461·6269·6e64··#idm5710"·tabind
0003ac20:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003ac20:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003ac30:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003ac30:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003ac40:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003ac40:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003ac50:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003ac50:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003ac60:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003ac60:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003ac70:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel0003ac70:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi
0003ac80:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a> 
0003ac90:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003aca0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003acb0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003acc0:·3537·3130·223e·3c70·7265·3e3c·636f·6465··5710"><pre><code 
0003acd0:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i 
0003ace0:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl 
0003acf0:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla 
0003ad00:·7466·6f72·6d73·0a69·6620·2820·5b20·2120··tforms.if·(·[·!· 
0003ad10:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·] 
0003ad20:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!· 
0003ad30:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain 
0003ad40:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am 
0003ad50:·703b·2021·2028·205b·2022·247b·636f·6e74··p;·!·(·[·"${cont 
0003ad60:·6169·6e65·723a·2d7d·2220·3d3d·2022·6277··ainer:-}"·==·"bw 
0003ad70:·7261·702d·6f73·6275·696c·6422·205d·2029··rap-osbuild"·]·) 
0003ad80:·2029·3b20·7468·656e·0a0a·6669·7073·2d6d···);·then..fips-m 
0003ad90:·6f64·652d·7365·7475·7020·2d2d·656e·6162··ode-setup·--enab 
0003ada0:·6c65·0a46·4950·535f·434f·4e46·3d22·2f65··le.FIPS_CONF="/e 
0003adb0:·7463·2f64·7261·6375·742e·636f·6e66·2e64··tc/dracut.conf.d 
0003adc0:·2f34·302d·6669·7073·2e63·6f6e·6622·0a69··/40-fips.conf".i 
0003add0:·6620·2120·6772·6570·2022·5e61·6464·5f64··f·!·grep·"^add_d 
0003ade0:·7261·6375·746d·6f64·756c·6573·2b3d·5c22··racutmodules+=\" 
0003adf0:·2066·6970·7320·5c22·2220·2446·4950·535f···fips·\""·$FIPS_ 
0003ae00:·434f·4e46·3b20·7468·656e·0a20·2020·2065··CONF;·then.····e 
0003ae10:·6368·6f20·2261·6464·5f64·7261·6375·746d··cho·"add_dracutm 
0003ae20:·6f64·756c·6573·2b3d·5c22·2066·6970·7320··odules+=\"·fips· 
0003ae30:·5c22·2220·2667·743b·2667·743b·2024·4649··\""·&gt;&gt;·$FI 
0003ae40:·5053·5f43·4f4e·460a·6669·0a0a·656c·7365··PS_CONF.fi..else 
0003ae50:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2· 
0003ae60:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio 
0003ae70:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica 
0003ae80:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was 
0003ae90:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code 
0003aea0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003aeb0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003aec0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003aed0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003aee0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003aef0:·3537·3131·2220·7461·6269·6e64·6578·3d22··5711"·tabindex=" 
0003af00:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003af10:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003af20:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003af30:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003af40:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003af50:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible· 
0003af60:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003ac80:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...<
0003af70:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003ac90:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003af80:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003aca0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003af90:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm50003acb0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
0003afa0:·3731·3122·3e3c·7461·626c·6520·636c·6173··711"><table·clas0003acc0:·6964·6d35·3731·3022·3e3c·7461·626c·6520··idm5710"><table·
0003afb0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003acd0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003afc0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003ace0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003afd0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003acf0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003afe0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003ad00:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0003aff0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003ad10:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003ad20:·7468·3e3c·7464·3e6d·6564·6975·6d3c·2f74··th><td>medium</t
 0003ad30:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0003ad40:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003b000:·7464·3e6d·6564·6975·6d3c·2f74·643e·3c2f··td>medium</td></0003ad50:·7464·3e6d·6564·6975·6d3c·2f74·643e·3c2f··td>medium</td></
 0003ad60:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
0003b010:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003b020:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6d··ption:</th><td>m 
0003b030:·6564·6975·6d3c·2f74·643e·3c2f·7472·3e3c··edium</td></tr>< 
0003b040:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003b050:·7468·3e3c·7464·3e74·7275·653c·2f74·643e··th><td>true</td> 
0003b060:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003b070:·6174·6567·793a·3c2f·7468·3e3c·7464·3e72··ategy:</th><td>r0003ad70:·743a·3c2f·7468·3e3c·7464·3e74·7275·653c··t:</th><td>true<
0003b080:·6573·7472·6963·743c·2f74·643e·3c2f·7472··estrict</td></tr0003ad80:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003ad90:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003ada0:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>
0003b090:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003adb0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
0003b0a0:·6f64·653e·2d20·6e61·6d65·3a20·4368·6563··ode>-·name:·Chec0003adc0:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·
0003b0b0:·6b20·746f·2073·6565·2074·6865·2063·7572··k·to·see·the·cur0003add0:·4368·6563·6b20·746f·2073·6565·2074·6865··Check·to·see·the
0003b0c0:·7265·6e74·2073·7461·7475·7320·6f66·2046··rent·status·of·F0003ade0:·2063·7572·7265·6e74·2073·7461·7475·7320···current·status·
0003b0d0:·4950·5320·6d6f·6465·0a20·2063·6f6d·6d61··IPS·mode.··comma 
0003b0e0:·6e64·3a20·2f75·7372·2f62·696e·2f66·6970··nd:·/usr/bin/fip 
0003b0f0:·732d·6d6f·6465·2d73·6574·7570·202d·2d63··s-mode-setup·--c 
0003b100:·6865·636b·0a20·2072·6567·6973·7465·723a··heck.··register: 
0003b110:·2069·735f·6669·7073·5f65·6e61·626c·6564···is_fips_enabled 
0003b120:·0a20·2063·6861·6e67·6564·5f77·6865·6e3a··.··changed_when: 
0003b130:·2066·616c·7365·0a20·2066·6169·6c65·645f···false.··failed_ 
0003b140:·7768·656e·3a20·6661·6c73·650a·2020·7768··when:·false.··wh 
0003b150:·656e·3a20·2820·616e·7369·626c·655f·7669··en:·(·ansible_vi 
0003b160:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ 
0003b170:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke 
0003b180:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open 
0003b190:·767a·222c·2022·706f·646d·616e·222c·0a20··vz",·"podman",.· 
0003b1a0:·2020·2022·636f·6e74·6169·6e65·7222·5d20·····"container"]· 
0003b1b0:·616e·6420·6e6f·7420·2820·6c6f·6f6b·7570··and·not·(·lookup 
0003b1c0:·2822·656e·7622·2c20·2263·6f6e·7461·696e··("env",·"contain 
0003b1d0:·6572·2229·203d·3d20·2262·7772·6170·2d6f··er")·==·"bwrap-o 
0003b1e0:·7362·7569·6c64·2220·2920·290a·2020·7461··sbuild"·)·).··ta 
0003b1f0:·6773·3a0a·2020·2d20·4e49·5354·2d38·3030··gs:.··-·NIST-800 
0003b200:·2d35·332d·434d·2d36·2861·290a·2020·2d20··-53-CM-6(a).··-· 
0003b210:·4e49·5354·2d38·3030·2d35·332d·4941·2d37··NIST-800-53-IA-7 
0003b220:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53 
0003b230:·2d53·432d·3132·0a20·202d·204e·4953·542d··-SC-12.··-·NIST- 
0003b240:·3830·302d·3533·2d53·432d·3132·2832·290a··800-53-SC-12(2). 
0003b250:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53- 
0003b260:·5343·2d31·3228·3329·0a20·202d·204e·4953··SC-12(3).··-·NIS 
0003b270:·542d·3830·302d·3533·2d53·432d·3133·0a20··T-800-53-SC-13.· 
0003b280:·202d·2065·6e61·626c·655f·6472·6163·7574···-·enable_dracut 
Max diff block lines reached; 4599664/4625938 bytes (99.43%) of diff not shown.
554 KB
html2text {}
    
Offset 50, 15 lines modifiedOffset 50, 15 lines modified
50 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Unclassified·Information·in·Non-federal·Information50 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Unclassified·Information·in·Non-federal·Information
51 ··············Systems·and·Organizations·(NIST·800-171)51 ··············Systems·and·Organizations·(NIST·800-171)
52 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cui52 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cui
53 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*53 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
54 ····*·cpe:/o:oracle:linux:954 ····*·cpe:/o:oracle:linux:9
55 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*55 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
56 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8456 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
57 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)57 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
58 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*58 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
59 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s59 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
60 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e60 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
61 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l61 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
62 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n62 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
63 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s63 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
64 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s64 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 97, 27 lines modifiedOffset 97, 14 lines modified
97 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_dracut_fips_module97 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_dracut_fips_module
98 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000068,·CCI-000803,·CCI-00245098 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000068,·CCI-000803,·CCI-002450
99 ············_\x8i_\x8s_\x8m······144699 ············_\x8i_\x8s_\x8m······1446
100 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1100 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
101 ············_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12101 ············_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
102 ············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.1102 ············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.1
103 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223103 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223
104 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
105 #·Remediation·is·applicable·only·in·certain·platforms 
106 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·);·then 
  
107 fips-mode-setup·--enable 
108 FIPS_CONF="/etc/dracut.conf.d/40-fips.conf" 
109 if·!·grep·"^add_dracutmodules+=\"·fips·\""·$FIPS_CONF;·then 
110 ····echo·"add_dracutmodules+=\"·fips·\""·>>·$FIPS_CONF 
111 fi 
  
112 else 
113 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
114 fi 
115 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8104 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
116 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium105 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium
117 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium106 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
118 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true107 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
119 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict108 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
120 -·name:·Check·to·see·the·current·status·of·FIPS·mode109 -·name:·Check·to·see·the·current·status·of·FIPS·mode
121 ··command:·/usr/bin/fips-mode-setup·--check110 ··command:·/usr/bin/fips-mode-setup·--check
Offset 175, 14 lines modifiedOffset 162, 27 lines modified
175 ··-·NIST-800-53-SC-13162 ··-·NIST-800-53-SC-13
176 ··-·enable_dracut_fips_module163 ··-·enable_dracut_fips_module
177 ··-·high_severity164 ··-·high_severity
178 ··-·medium_complexity165 ··-·medium_complexity
179 ··-·medium_disruption166 ··-·medium_disruption
180 ··-·reboot_required167 ··-·reboot_required
181 ··-·restrict_strategy168 ··-·restrict_strategy
 169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 170 #·Remediation·is·applicable·only·in·certain·platforms
 171 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·);·then
  
 172 fips-mode-setup·--enable
 173 FIPS_CONF="/etc/dracut.conf.d/40-fips.conf"
 174 if·!·grep·"^add_dracutmodules+=\"·fips·\""·$FIPS_CONF;·then
 175 ····echo·"add_dracutmodules+=\"·fips·\""·>>·$FIPS_CONF
 176 fi
  
 177 else
 178 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 179 fi
182 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*180 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
183 To·enable·FIPS·mode,·run·the·following·command:181 To·enable·FIPS·mode,·run·the·following·command:
184 fips-mode-setup·--enable182 fips-mode-setup·--enable
  
185 The·fips-mode-setup·command·will·configure·the·system·in·FIPS·mode·by·automatically·configuring·the·following:183 The·fips-mode-setup·command·will·configure·the·system·in·FIPS·mode·by·automatically·configuring·the·following:
186 ····*·Setting·the·kernel·FIPS·mode·flag·(/proc/sys/crypto/fips_enabled)·to·1184 ····*·Setting·the·kernel·FIPS·mode·flag·(/proc/sys/crypto/fips_enabled)·to·1
187 ····*·Creating·/etc/system-fips185 ····*·Creating·/etc/system-fips
Offset 195, 41 lines modifiedOffset 195, 18 lines modified
195 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode195 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode
196 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000068,·CCI-000803,·CCI-002450196 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000068,·CCI-000803,·CCI-002450
197 ············_\x8i_\x8s_\x8m······1446197 ············_\x8i_\x8s_\x8m······1446
198 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1198 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
199 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12199 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
200 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1200 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
201 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176201 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
 202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
203 #·Remediation·is·applicable·only·in·certain·platforms 
204 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·)·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then 
  
205 var_system_crypto_policy='FIPS:OSPP' 
  
  
206 fips-mode-setup·--enable 
  
207 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
208 rc=$? 
  
209 if·test·"$rc"·=·127;·then 
210 »       echo·"$stderr_of_call"·>&2 
211 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
212 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
213 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
214 »       false··#·end·with·an·error·code 
215 elif·test·"$rc"·!=·0;·then 
216 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
217 »       false··#·end·with·an·error·code 
218 fi 
  
 203 [customizations]
 204 fips·=·true
219 else 
220 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
221 fi 
222 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
223 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium
224 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
225 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
226 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
227 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable210 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
228 ··set_fact:211 ··set_fact:
Offset 325, 18 lines modifiedOffset 302, 41 lines modified
325 ··-·NIST-800-53-SC-13302 ··-·NIST-800-53-SC-13
326 ··-·enable_fips_mode303 ··-·enable_fips_mode
327 ··-·high_severity304 ··-·high_severity
328 ··-·medium_complexity305 ··-·medium_complexity
329 ··-·medium_disruption306 ··-·medium_disruption
330 ··-·reboot_required307 ··-·reboot_required
331 ··-·restrict_strategy308 ··-·restrict_strategy
332 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8309 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 310 #·Remediation·is·applicable·only·in·certain·platforms
 311 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·)·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
Max diff block lines reached; 561144/567415 bytes (98.89%) of diff not shown.
6.45 MB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-e8.html
    
Offset 14296, 16 lines modifiedOffset 14296, 16 lines modified
00037d70:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>00037d70:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>
00037d80:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi00037d80:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi
00037d90:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.00037d90:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.
00037da0:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><00037da0:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><
00037db0:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d00037db0:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d
00037dc0:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··00037dc0:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··
00037dd0:·2020·2020·2020·2020·2020·2020·2020·2020··················00037dd0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037de0:·2020·2861·7320·6f66·2032·3032·362d·3031····(as·of·2026-0100037de0:·2020·2861·7320·6f66·2032·3032·342d·3132····(as·of·2024-12
00037df0:·2d30·3829·0a20·2020·2020·2020·2020·2020··-08).···········00037df0:·2d30·3729·0a20·2020·2020·2020·2020·2020··-07).···········
00037e00:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><00037e00:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><
00037e10:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o00037e10:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o
00037e20:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><00037e20:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><
00037e30:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="00037e30:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="
00037e40:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr00037e40:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr
00037e50:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr00037e50:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr
00037e60:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst00037e60:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst
Offset 15136, 301 lines modifiedOffset 15136, 301 lines modified
0003b1f0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003b1f0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003b200:·6d34·3838·3622·2074·6162·696e·6465·783d··m4886"·tabindex=0003b200:·6d34·3838·3622·2074·6162·696e·6465·783d··m4886"·tabindex=
0003b210:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003b210:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003b220:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003b220:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003b230:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003b230:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003b240:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003b240:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003b250:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003b250:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003b260:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s 
0003b270:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003b280:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003b290:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003b2a0:·6170·7365·2220·6964·3d22·6964·6d34·3838··apse"·id="idm488 
0003b2b0:·3622·3e3c·7072·653e·3c63·6f64·653e·0a23··6"><pre><code>.# 
0003b2c0:·2046·696e·6420·7768·6963·6820·6669·6c65···Find·which·file 
0003b2d0:·7320·6861·7665·2069·6e63·6f72·7265·6374··s·have·incorrect 
0003b2e0:·2068·6173·6820·286e·6f74·2069·6e20·2f65···hash·(not·in·/e 
0003b2f0:·7463·2c20·6265·6361·7573·6520·6f66·2074··tc,·because·of·t 
0003b300:·6865·2073·7973·7465·6d20·7265·6c61·7465··he·system·relate 
0003b310:·6420·636f·6e66·6967·2066·696c·6573·2920··d·config·files)· 
0003b320:·616e·6420·7468·656e·2067·6574·2066·696c··and·then·get·fil 
0003b330:·6573·206e·616d·6573·0a66·696c·6573·5f77··es·names.files_w 
0003b340:·6974·685f·696e·636f·7272·6563·745f·6861··ith_incorrect_ha 
0003b350:·7368·3d22·2428·7270·6d20·2d56·6120·2d2d··sh="$(rpm·-Va·-- 
0003b360:·6e6f·636f·6e66·6967·207c·2067·7265·7020··noconfig·|·grep· 
0003b370:·2d45·2027·5e2e·2e35·2720·7c20·6177·6b20··-E·'^..5'·|·awk· 
0003b380:·277b·7072·696e·7420·244e·467d·2720·2922··'{print·$NF}'·)" 
0003b390:·0a0a·6966·205b·202d·6e20·2224·6669·6c65··..if·[·-n·"$file 
0003b3a0:·735f·7769·7468·5f69·6e63·6f72·7265·6374··s_with_incorrect 
0003b3b0:·5f68·6173·6822·205d·3b20·7468·656e·0a20··_hash"·];·then.· 
0003b3c0:·2020·2023·2046·726f·6d20·6669·6c65·7320·····#·From·files· 
0003b3d0:·6e61·6d65·7320·6765·7420·7061·636b·6167··names·get·packag 
0003b3e0:·6520·6e61·6d65·7320·616e·6420·6368·616e··e·names·and·chan 
0003b3f0:·6765·206e·6577·6c69·6e65·2074·6f20·7370··ge·newline·to·sp 
0003b400:·6163·652c·2062·6563·6175·7365·2072·706d··ace,·because·rpm 
0003b410:·2077·7269·7465·7320·6561·6368·2070·6163···writes·each·pac 
0003b420:·6b61·6765·2074·6f20·6e65·7720·6c69·6e65··kage·to·new·line 
0003b430:·0a20·2020·2070·6163·6b61·6765·735f·746f··.····packages_to 
0003b440:·5f72·6569·6e73·7461·6c6c·3d22·2428·7270··_reinstall="$(rp 
0003b450:·6d20·2d71·6620·2466·696c·6573·5f77·6974··m·-qf·$files_wit 
0003b460:·685f·696e·636f·7272·6563·745f·6861·7368··h_incorrect_hash 
0003b470:·207c·2074·7220·275c·6e27·2027·2027·2922···|·tr·'\n'·'·')" 
0003b480:·0a0a·2020·2020·0a20·2020·2079·756d·2072··..····.····yum·r 
0003b490:·6569·6e73·7461·6c6c·202d·7920·2470·6163··einstall·-y·$pac 
0003b4a0:·6b61·6765·735f·746f·5f72·6569·6e73·7461··kages_to_reinsta 
0003b4b0:·6c6c·0a20·2020·200a·6669·0a3c·2f63·6f64··ll.····.fi.</cod 
0003b4c0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003b4d0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003b4e0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003b4f0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003b500:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003b510:·6d34·3838·3722·2074·6162·696e·6465·783d··m4887"·tabindex= 
0003b520:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003b530:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003b540:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003b550:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003b560:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003b570:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible0003b260:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible
0003b580:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003b270:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003b590:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003b280:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003b5a0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003b290:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003b5b0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003b2a0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003b5c0:·3438·3837·223e·3c74·6162·6c65·2063·6c61··4887"><table·cla0003b2b0:·3438·3836·223e·3c74·6162·6c65·2063·6c61··4886"><table·cla
0003b5d0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003b2c0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003b5e0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003b2d0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003b5f0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003b2e0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003b600:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003b2f0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003b610:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003b300:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003b620:·3c74·643e·6869·6768·3c2f·7464·3e3c·2f74··<td>high</td></t0003b310:·3c74·643e·6869·6768·3c2f·7464·3e3c·2f74··<td>high</td></t
0003b630:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003b320:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003b640:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6d65··tion:</th><td>me0003b330:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6d65··tion:</th><td>me
0003b650:·6469·756d·3c2f·7464·3e3c·2f74·723e·3c74··dium</td></tr><t0003b340:·6469·756d·3c2f·7464·3e3c·2f74·723e·3c74··dium</td></tr><t
0003b660:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t0003b350:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
0003b670:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>0003b360:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
0003b680:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003b370:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003b690:·6174·6567·793a·3c2f·7468·3e3c·7464·3e72··ategy:</th><td>r0003b380:·6174·6567·793a·3c2f·7468·3e3c·7464·3e72··ategy:</th><td>r
0003b6a0:·6573·7472·6963·743c·2f74·643e·3c2f·7472··estrict</td></tr0003b390:·6573·7472·6963·743c·2f74·643e·3c2f·7472··estrict</td></tr
0003b6b0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003b3a0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
0003b6c0:·6f64·653e·2d20·6e61·6d65·3a20·2753·6574··ode>-·name:·'Set0003b3b0:·6f64·653e·2d20·6e61·6d65·3a20·2753·6574··ode>-·name:·'Set
0003b6d0:·2066·6163·743a·2050·6163·6b61·6765·206d···fact:·Package·m0003b3c0:·2066·6163·743a·2050·6163·6b61·6765·206d···fact:·Package·m
0003b6e0:·616e·6167·6572·2072·6569·6e73·7461·6c6c··anager·reinstall0003b3d0:·616e·6167·6572·2072·6569·6e73·7461·6c6c··anager·reinstall
0003b6f0:·2063·6f6d·6d61·6e64·270a·2020·7365·745f···command'.··set_0003b3e0:·2063·6f6d·6d61·6e64·270a·2020·7365·745f···command'.··set_
0003b700:·6661·6374·3a0a·2020·2020·7061·636b·6167··fact:.····packag0003b3f0:·6661·6374·3a0a·2020·2020·7061·636b·6167··fact:.····packag
0003b710:·655f·6d61·6e61·6765·725f·7265·696e·7374··e_manager_reinst0003b400:·655f·6d61·6e61·6765·725f·7265·696e·7374··e_manager_reinst
0003b720:·616c·6c5f·636d·643a·2079·756d·2072·6569··all_cmd:·yum·rei0003b410:·616c·6c5f·636d·643a·2079·756d·2072·6569··all_cmd:·yum·rei
0003b730:·6e73·7461·6c6c·202d·790a·2020·7768·656e··nstall·-y.··when0003b420:·6e73·7461·6c6c·202d·790a·2020·7768·656e··nstall·-y.··when
0003b740:·3a20·616e·7369·626c·655f·6469·7374·7269··:·ansible_distri0003b430:·3a20·616e·7369·626c·655f·6469·7374·7269··:·ansible_distri
0003b750:·6275·7469·6f6e·2069·6e20·5b20·2246·6564··bution·in·[·"Fed0003b440:·6275·7469·6f6e·2069·6e20·5b20·2246·6564··bution·in·[·"Fed
0003b760:·6f72·6122·2c20·2252·6564·4861·7422·2c20··ora",·"RedHat",·0003b450:·6f72·6122·2c20·2252·6564·4861·7422·2c20··ora",·"RedHat",·
0003b770:·2243·656e·744f·5322·2c20·224f·7261·636c··"CentOS",·"Oracl0003b460:·2243·656e·744f·5322·2c20·224f·7261·636c··"CentOS",·"Oracl
0003b780:·654c·696e·7578·2220·5d0a·2020·7461·6773··eLinux"·].··tags0003b470:·654c·696e·7578·2220·5d0a·2020·7461·6773··eLinux"·].··tags
0003b790:·3a0a·2020·2d20·434a·4953·2d35·2e31·302e··:.··-·CJIS-5.10.0003b480:·3a0a·2020·2d20·434a·4953·2d35·2e31·302e··:.··-·CJIS-5.10.
0003b7a0:·342e·310a·2020·2d20·4e49·5354·2d38·3030··4.1.··-·NIST-800 
0003b7b0:·2d31·3731·2d33·2e33·2e38·0a20·202d·204e··-171-3.3.8.··-·N 
0003b7c0:·4953·542d·3830·302d·3137·312d·332e·342e··IST-800-171-3.4. 
0003b7d0:·310a·2020·2d20·4e49·5354·2d38·3030·2d35··1.··-·NIST-800-5 
0003b7e0:·332d·4155·2d39·2833·290a·2020·2d20·4e49··3-AU-9(3).··-·NI 
0003b7f0:·5354·2d38·3030·2d35·332d·434d·2d36·2863··ST-800-53-CM-6(c 
0003b800:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5 
0003b810:·332d·434d·2d36·2864·290a·2020·2d20·4e49··3-CM-6(d).··-·NI 
0003b820:·5354·2d38·3030·2d35·332d·5349·2d37·0a20··ST-800-53-SI-7.· 
0003b830:·202d·204e·4953·542d·3830·302d·3533·2d53···-·NIST-800-53-S 
0003b840:·492d·3728·3129·0a20·202d·204e·4953·542d··I-7(1).··-·NIST- 
0003b850:·3830·302d·3533·2d53·492d·3728·3629·0a20··800-53-SI-7(6).· 
0003b860:·202d·2050·4349·2d44·5353·2d52·6571·2d31···-·PCI-DSS-Req-1 
0003b870:·312e·350a·2020·2d20·5043·492d·4453·5376··1.5.··-·PCI-DSSv 
0003b880:·342d·3131·2e35·2e32·0a20·202d·2068·6967··4-11.5.2.··-·hig 
0003b890:·685f·636f·6d70·6c65·7869·7479·0a20·202d··h_complexity.··- 
0003b8a0:·2068·6967·685f·7365·7665·7269·7479·0a20···high_severity.· 
0003b8b0:·202d·206d·6564·6975·6d5f·6469·7372·7570···-·medium_disrup 
0003b8c0:·7469·6f6e·0a20·202d·206e·6f5f·7265·626f··tion.··-·no_rebo 
Max diff block lines reached; 6061917/6103371 bytes (99.32%) of diff not shown.
641 KB
html2text {}
    
Offset 40, 15 lines modifiedOffset 40, 15 lines modified
40 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*40 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Australian·Cyber·Security·Centre·(ACSC)·Essential·Eight41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Australian·Cyber·Security·Centre·(ACSC)·Essential·Eight
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_e842 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_e8
43 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*43 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
44 ····*·cpe:/o:oracle:linux:944 ····*·cpe:/o:oracle:linux:9
45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
46 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8446 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
50 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e50 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
51 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l51 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
52 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g52 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
53 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s53 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
54 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s54 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 101, 27 lines modifiedOffset 101, 14 lines modified
101 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6101 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
102 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4102 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
103 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)103 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
104 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1104 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
105 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5105 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
106 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227106 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
107 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2107 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
109 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
110 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
111 if·[·-n·"$files_with_incorrect_hash"·];·then 
112 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
113 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
114 ····yum·reinstall·-y·$packages_to_reinstall 
  
115 fi 
116 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
117 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high109 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
118 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium110 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
119 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false111 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
120 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict112 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
121 -·name:·'Set·fact:·Package·manager·reinstall·command'113 -·name:·'Set·fact:·Package·manager·reinstall·command'
122 ··set_fact:114 ··set_fact:
Offset 248, 14 lines modifiedOffset 235, 27 lines modified
248 ··-·PCI-DSSv4-11.5.2235 ··-·PCI-DSSv4-11.5.2
249 ··-·high_complexity236 ··-·high_complexity
250 ··-·high_severity237 ··-·high_severity
251 ··-·medium_disruption238 ··-·medium_disruption
252 ··-·no_reboot_needed239 ··-·no_reboot_needed
253 ··-·restrict_strategy240 ··-·restrict_strategy
254 ··-·rpm_verify_hashes241 ··-·rpm_verify_hashes
 242 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 243 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 244 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 245 if·[·-n·"$files_with_incorrect_hash"·];·then
 246 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 247 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 248 ····yum·reinstall·-y·$packages_to_reinstall
  
 249 fi
255 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*250 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
256 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:251 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
257 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'252 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
258 run·the·following·command·to·determine·which·package·owns·it:253 run·the·following·command·to·determine·which·package·owns·it:
259 $·rpm·-qf·FILENAME254 $·rpm·-qf·FILENAME
260 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:255 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
261 $·sudo·rpm·--setugids·PACKAGENAME256 $·sudo·rpm·--setugids·PACKAGENAME
Offset 274, 40 lines modifiedOffset 274, 14 lines modified
274 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5274 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
275 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2275 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
276 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)276 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
277 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1277 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
278 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5278 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
279 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108279 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
280 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2280 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
281 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
282 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
283 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
284 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
285 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
286 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
287 declare·-A·SETPERMS_RPM_DICT 
  
288 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
289 #·is·expected·by·the·RPM·database 
290 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
291 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
292 do 
293 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
294 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
295 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
296 done 
  
297 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
298 #·correct·values 
299 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
300 do 
301 ········rpm·--setugids·"${RPM_PACKAGE}" 
302 done 
303 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8281 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
304 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high282 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
305 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium283 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
306 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false284 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
307 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict285 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
308 -·name:·Read·list·of·files·with·incorrect·ownership286 -·name:·Read·list·of·files·with·incorrect·ownership
309 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev287 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 382, 14 lines modifiedOffset 356, 40 lines modified
382 ··-·PCI-DSSv4-11.5.2356 ··-·PCI-DSSv4-11.5.2
383 ··-·high_complexity357 ··-·high_complexity
384 ··-·high_severity358 ··-·high_severity
385 ··-·medium_disruption359 ··-·medium_disruption
386 ··-·no_reboot_needed360 ··-·no_reboot_needed
387 ··-·restrict_strategy361 ··-·restrict_strategy
388 ··-·rpm_verify_ownership362 ··-·rpm_verify_ownership
 363 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 364 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 365 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 366 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 367 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 368 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 648478/656359 bytes (98.80%) of diff not shown.
16.1 MB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-hipaa.html
    
Offset 14316, 15 lines modifiedOffset 14316, 15 lines modified
00037eb0:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr00037eb0:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr
00037ec0:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st00037ec0:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st
00037ed0:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str00037ed0:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str
00037ee0:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>00037ee0:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>
00037ef0:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s00037ef0:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s
00037f00:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········00037f00:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········
00037f10:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o00037f10:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o
00037f20:·6620·3230·3236·2d30·312d·3038·290a·2020··f·2026-01-08).··00037f20:·6620·3230·3234·2d31·322d·3037·290a·2020··f·2024-12-07).··
00037f30:·2020·2020·2020·2020·2020·2020·2020·3c2f················</00037f30:·2020·2020·2020·2020·2020·2020·2020·3c2f················</
00037f40:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h00037f40:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h
00037f50:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte00037f50:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte
00037f60:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>00037f60:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>
00037f70:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_00037f70:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_
00037f80:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c00037f80:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c
00037f90:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys00037f90:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys
Offset 15162, 301 lines modifiedOffset 15162, 301 lines modified
0003b390:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b390:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003b3a0:·3438·3836·2220·7461·6269·6e64·6578·3d22··4886"·tabindex="0003b3a0:·3438·3836·2220·7461·6269·6e64·6578·3d22··4886"·tabindex="
0003b3b0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b3b0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003b3c0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b3c0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003b3d0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003b3d0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003b3e0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003b3e0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003b3f0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003b3f0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003b400:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003b410:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003b420:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003b430:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003b440:·7073·6522·2069·643d·2269·646d·3438·3836··pse"·id="idm4886 
0003b450:·223e·3c70·7265·3e3c·636f·6465·3e0a·2320··"><pre><code>.#· 
0003b460:·4669·6e64·2077·6869·6368·2066·696c·6573··Find·which·files 
0003b470:·2068·6176·6520·696e·636f·7272·6563·7420···have·incorrect· 
0003b480:·6861·7368·2028·6e6f·7420·696e·202f·6574··hash·(not·in·/et 
0003b490:·632c·2062·6563·6175·7365·206f·6620·7468··c,·because·of·th 
0003b4a0:·6520·7379·7374·656d·2072·656c·6174·6564··e·system·related 
0003b4b0:·2063·6f6e·6669·6720·6669·6c65·7329·2061···config·files)·a 
0003b4c0:·6e64·2074·6865·6e20·6765·7420·6669·6c65··nd·then·get·file 
0003b4d0:·7320·6e61·6d65·730a·6669·6c65·735f·7769··s·names.files_wi 
0003b4e0:·7468·5f69·6e63·6f72·7265·6374·5f68·6173··th_incorrect_has 
0003b4f0:·683d·2224·2872·706d·202d·5661·202d·2d6e··h="$(rpm·-Va·--n 
0003b500:·6f63·6f6e·6669·6720·7c20·6772·6570·202d··oconfig·|·grep·- 
0003b510:·4520·275e·2e2e·3527·207c·2061·776b·2027··E·'^..5'·|·awk·' 
0003b520:·7b70·7269·6e74·2024·4e46·7d27·2029·220a··{print·$NF}'·)". 
0003b530:·0a69·6620·5b20·2d6e·2022·2466·696c·6573··.if·[·-n·"$files 
0003b540:·5f77·6974·685f·696e·636f·7272·6563·745f··_with_incorrect_ 
0003b550:·6861·7368·2220·5d3b·2074·6865·6e0a·2020··hash"·];·then.·· 
0003b560:·2020·2320·4672·6f6d·2066·696c·6573·206e····#·From·files·n 
0003b570:·616d·6573·2067·6574·2070·6163·6b61·6765··ames·get·package 
0003b580:·206e·616d·6573·2061·6e64·2063·6861·6e67···names·and·chang 
0003b590:·6520·6e65·776c·696e·6520·746f·2073·7061··e·newline·to·spa 
0003b5a0:·6365·2c20·6265·6361·7573·6520·7270·6d20··ce,·because·rpm· 
0003b5b0:·7772·6974·6573·2065·6163·6820·7061·636b··writes·each·pack 
0003b5c0:·6167·6520·746f·206e·6577·206c·696e·650a··age·to·new·line. 
0003b5d0:·2020·2020·7061·636b·6167·6573·5f74·6f5f······packages_to_ 
0003b5e0:·7265·696e·7374·616c·6c3d·2224·2872·706d··reinstall="$(rpm 
0003b5f0:·202d·7166·2024·6669·6c65·735f·7769·7468···-qf·$files_with 
0003b600:·5f69·6e63·6f72·7265·6374·5f68·6173·6820··_incorrect_hash· 
0003b610:·7c20·7472·2027·5c6e·2720·2720·2729·220a··|·tr·'\n'·'·')". 
0003b620:·0a20·2020·200a·2020·2020·7975·6d20·7265··.····.····yum·re 
0003b630:·696e·7374·616c·6c20·2d79·2024·7061·636b··install·-y·$pack 
0003b640:·6167·6573·5f74·6f5f·7265·696e·7374·616c··ages_to_reinstal 
0003b650:·6c0a·2020·2020·0a66·690a·3c2f·636f·6465··l.····.fi.</code 
0003b660:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003b670:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003b680:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003b690:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003b6a0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003b6b0:·3438·3837·2220·7461·6269·6e64·6578·3d22··4887"·tabindex=" 
0003b6c0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003b6d0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003b6e0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003b6f0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003b700:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003b710:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible·0003b400:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible·
0003b720:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003b410:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003b730:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003b420:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003b740:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003b430:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003b750:·6c6c·6170·7365·2220·6964·3d22·6964·6d34··llapse"·id="idm40003b440:·6c6c·6170·7365·2220·6964·3d22·6964·6d34··llapse"·id="idm4
0003b760:·3838·3722·3e3c·7461·626c·6520·636c·6173··887"><table·clas0003b450:·3838·3622·3e3c·7461·626c·6520·636c·6173··886"><table·clas
0003b770:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003b460:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003b780:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003b470:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003b790:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003b480:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003b7a0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003b490:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003b7b0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003b4a0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003b7c0:·7464·3e68·6967·683c·2f74·643e·3c2f·7472··td>high</td></tr0003b4b0:·7464·3e68·6967·683c·2f74·643e·3c2f·7472··td>high</td></tr
0003b7d0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003b4c0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003b7e0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6d·6564··ion:</th><td>med0003b4d0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6d·6564··ion:</th><td>med
0003b7f0:·6975·6d3c·2f74·643e·3c2f·7472·3e3c·7472··ium</td></tr><tr0003b4e0:·6975·6d3c·2f74·643e·3c2f·7472·3e3c·7472··ium</td></tr><tr
0003b800:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th0003b4f0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
0003b810:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><0003b500:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
0003b820:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003b510:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
0003b830:·7465·6779·3a3c·2f74·683e·3c74·643e·7265··tegy:</th><td>re0003b520:·7465·6779·3a3c·2f74·683e·3c74·643e·7265··tegy:</th><td>re
0003b840:·7374·7269·6374·3c2f·7464·3e3c·2f74·723e··strict</td></tr>0003b530:·7374·7269·6374·3c2f·7464·3e3c·2f74·723e··strict</td></tr>
0003b850:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co0003b540:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
0003b860:·6465·3e2d·206e·616d·653a·2027·5365·7420··de>-·name:·'Set·0003b550:·6465·3e2d·206e·616d·653a·2027·5365·7420··de>-·name:·'Set·
0003b870:·6661·6374·3a20·5061·636b·6167·6520·6d61··fact:·Package·ma0003b560:·6661·6374·3a20·5061·636b·6167·6520·6d61··fact:·Package·ma
0003b880:·6e61·6765·7220·7265·696e·7374·616c·6c20··nager·reinstall·0003b570:·6e61·6765·7220·7265·696e·7374·616c·6c20··nager·reinstall·
0003b890:·636f·6d6d·616e·6427·0a20·2073·6574·5f66··command'.··set_f0003b580:·636f·6d6d·616e·6427·0a20·2073·6574·5f66··command'.··set_f
0003b8a0:·6163·743a·0a20·2020·2070·6163·6b61·6765··act:.····package0003b590:·6163·743a·0a20·2020·2070·6163·6b61·6765··act:.····package
0003b8b0:·5f6d·616e·6167·6572·5f72·6569·6e73·7461··_manager_reinsta0003b5a0:·5f6d·616e·6167·6572·5f72·6569·6e73·7461··_manager_reinsta
0003b8c0:·6c6c·5f63·6d64·3a20·7975·6d20·7265·696e··ll_cmd:·yum·rein0003b5b0:·6c6c·5f63·6d64·3a20·7975·6d20·7265·696e··ll_cmd:·yum·rein
0003b8d0:·7374·616c·6c20·2d79·0a20·2077·6865·6e3a··stall·-y.··when:0003b5c0:·7374·616c·6c20·2d79·0a20·2077·6865·6e3a··stall·-y.··when:
0003b8e0:·2061·6e73·6962·6c65·5f64·6973·7472·6962···ansible_distrib0003b5d0:·2061·6e73·6962·6c65·5f64·6973·7472·6962···ansible_distrib
0003b8f0:·7574·696f·6e20·696e·205b·2022·4665·646f··ution·in·[·"Fedo0003b5e0:·7574·696f·6e20·696e·205b·2022·4665·646f··ution·in·[·"Fedo
0003b900:·7261·222c·2022·5265·6448·6174·222c·2022··ra",·"RedHat",·"0003b5f0:·7261·222c·2022·5265·6448·6174·222c·2022··ra",·"RedHat",·"
0003b910:·4365·6e74·4f53·222c·2022·4f72·6163·6c65··CentOS",·"Oracle0003b600:·4365·6e74·4f53·222c·2022·4f72·6163·6c65··CentOS",·"Oracle
0003b920:·4c69·6e75·7822·205d·0a20·2074·6167·733a··Linux"·].··tags:0003b610:·4c69·6e75·7822·205d·0a20·2074·6167·733a··Linux"·].··tags:
0003b930:·0a20·202d·2043·4a49·532d·352e·3130·2e34··.··-·CJIS-5.10.40003b620:·0a20·202d·2043·4a49·532d·352e·3130·2e34··.··-·CJIS-5.10.4
0003b940:·2e31·0a20·202d·204e·4953·542d·3830·302d··.1.··-·NIST-800-0003b630:·2e31·0a20·202d·204e·4953·542d·3830·302d··.1.··-·NIST-800-
0003b950:·3137·312d·332e·332e·380a·2020·2d20·4e49··171-3.3.8.··-·NI0003b640:·3137·312d·332e·332e·380a·2020·2d20·4e49··171-3.3.8.··-·NI
0003b960:·5354·2d38·3030·2d31·3731·2d33·2e34·2e31··ST-800-171-3.4.10003b650:·5354·2d38·3030·2d31·3731·2d33·2e34·2e31··ST-800-171-3.4.1
 0003b660:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
 0003b670:·2d41·552d·3928·3329·0a20·202d·204e·4953··-AU-9(3).··-·NIS
 0003b680:·542d·3830·302d·3533·2d43·4d2d·3628·6329··T-800-53-CM-6(c)
0003b970:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-530003b690:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
0003b980:·2d41·552d·3928·3329·0a20·202d·204e·4953··-AU-9(3).··-·NIS 
0003b990:·542d·3830·302d·3533·2d43·4d2d·3628·6329··T-800-53-CM-6(c) 
0003b9a0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53 
0003b9b0:·2d43·4d2d·3628·6429·0a20·202d·204e·4953··-CM-6(d).··-·NIS0003b6a0:·2d43·4d2d·3628·6429·0a20·202d·204e·4953··-CM-6(d).··-·NIS
0003b9c0:·542d·3830·302d·3533·2d53·492d·370a·2020··T-800-53-SI-7.··0003b6b0:·542d·3830·302d·3533·2d53·492d·370a·2020··T-800-53-SI-7.··
0003b9d0:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI0003b6c0:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI
0003b9e0:·2d37·2831·290a·2020·2d20·4e49·5354·2d38··-7(1).··-·NIST-80003b6d0:·2d37·2831·290a·2020·2d20·4e49·5354·2d38··-7(1).··-·NIST-8
0003b9f0:·3030·2d35·332d·5349·2d37·2836·290a·2020··00-53-SI-7(6).··0003b6e0:·3030·2d35·332d·5349·2d37·2836·290a·2020··00-53-SI-7(6).··
0003ba00:·2d20·5043·492d·4453·532d·5265·712d·3131··-·PCI-DSS-Req-110003b6f0:·2d20·5043·492d·4453·532d·5265·712d·3131··-·PCI-DSS-Req-11
0003ba10:·2e35·0a20·202d·2050·4349·2d44·5353·7634··.5.··-·PCI-DSSv40003b700:·2e35·0a20·202d·2050·4349·2d44·5353·7634··.5.··-·PCI-DSSv4
0003ba20:·2d31·312e·352e·320a·2020·2d20·6869·6768··-11.5.2.··-·high0003b710:·2d31·312e·352e·320a·2020·2d20·6869·6768··-11.5.2.··-·high
0003ba30:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-·0003b720:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-·
0003ba40:·6869·6768·5f73·6576·6572·6974·790a·2020··high_severity.··0003b730:·6869·6768·5f73·6576·6572·6974·790a·2020··high_severity.··
Max diff block lines reached; 15624667/15665983 bytes (99.74%) of diff not shown.
1.17 MB
html2text {}
    
Offset 46, 15 lines modifiedOffset 46, 15 lines modified
46 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
47 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Health·Insurance·Portability·and·Accountability·Act·(HIPAA)47 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Health·Insurance·Portability·and·Accountability·Act·(HIPAA)
48 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_hipaa48 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_hipaa
49 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*49 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
50 ····*·cpe:/o:oracle:linux:950 ····*·cpe:/o:oracle:linux:9
51 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
52 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8452 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
53 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)53 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
54 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*54 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
55 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s55 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
56 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e56 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
57 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l57 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
58 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n58 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
59 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g59 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
60 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s60 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 108, 27 lines modifiedOffset 108, 14 lines modified
108 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6108 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
109 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4109 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
110 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)110 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
111 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1111 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
112 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5112 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
113 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227113 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
114 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2114 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
115 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
116 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
117 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
118 if·[·-n·"$files_with_incorrect_hash"·];·then 
119 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
120 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
121 ····yum·reinstall·-y·$packages_to_reinstall 
  
122 fi 
123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8115 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
124 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high116 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
125 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium117 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
126 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false118 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
127 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict119 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
128 -·name:·'Set·fact:·Package·manager·reinstall·command'120 -·name:·'Set·fact:·Package·manager·reinstall·command'
129 ··set_fact:121 ··set_fact:
Offset 255, 14 lines modifiedOffset 242, 27 lines modified
255 ··-·PCI-DSSv4-11.5.2242 ··-·PCI-DSSv4-11.5.2
256 ··-·high_complexity243 ··-·high_complexity
257 ··-·high_severity244 ··-·high_severity
258 ··-·medium_disruption245 ··-·medium_disruption
259 ··-·no_reboot_needed246 ··-·no_reboot_needed
260 ··-·restrict_strategy247 ··-·restrict_strategy
261 ··-·rpm_verify_hashes248 ··-·rpm_verify_hashes
 249 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 250 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 251 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 252 if·[·-n·"$files_with_incorrect_hash"·];·then
 253 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 254 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 255 ····yum·reinstall·-y·$packages_to_reinstall
  
 256 fi
262 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*257 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
263 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:258 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:
264 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'259 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'
265 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:260 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:
266 $·rpm·-qf·FILENAME261 $·rpm·-qf·FILENAME
  
267 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:262 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
Offset 283, 44 lines modifiedOffset 283, 14 lines modified
283 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5283 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
284 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2284 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
285 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)285 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)
286 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1286 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
287 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5287 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
288 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108288 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108
289 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2289 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
290 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
291 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
292 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
293 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
294 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
295 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
296 declare·-A·SETPERMS_RPM_DICT 
  
297 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
298 #·is·expected·by·the·RPM·database 
299 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}') 
  
300 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
301 do 
302 ········#·NOTE:·some·files·maybe·controlled·by·more·then·one·package 
303 ········readarray·-t·RPM_PACKAGES·<·<(rpm·-qf·"${FILE_PATH}") 
304 ········for·RPM_PACKAGE·in·"${RPM_PACKAGES[@]}" 
305 ········do 
306 ················#·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
307 ················SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
308 ········done 
309 done 
  
310 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
311 #·correct·values 
312 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
313 do 
314 »       rpm·--restore·"${RPM_PACKAGE}" 
315 done 
316 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8290 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
317 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high291 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
318 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium292 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
319 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false293 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
320 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict294 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
321 -·name:·Read·list·of·files·with·incorrect·permissions295 -·name:·Read·list·of·files·with·incorrect·permissions
322 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev296 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 398, 14 lines modifiedOffset 368, 44 lines modified
398 ··-·PCI-DSSv4-11.5.2368 ··-·PCI-DSSv4-11.5.2
399 ··-·high_complexity369 ··-·high_complexity
400 ··-·high_severity370 ··-·high_severity
401 ··-·medium_disruption371 ··-·medium_disruption
402 ··-·no_reboot_needed372 ··-·no_reboot_needed
403 ··-·restrict_strategy373 ··-·restrict_strategy
404 ··-·rpm_verify_permissions374 ··-·rpm_verify_permissions
 375 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 376 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 377 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
Max diff block lines reached; 1220086/1228358 bytes (99.33%) of diff not shown.
4.95 MB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-ospp.html
    
Offset 14299, 16 lines modifiedOffset 14299, 16 lines modified
00037da0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p00037da0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p
00037db0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version00037db0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version
00037dc0:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.7400037dc0:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.74
00037dd0:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul00037dd0:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul
00037de0:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra00037de0:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra
00037df0:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····00037df0:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····
00037e00:·2020·2020·2020·2020·2020·2020·2020·2020··················00037e00:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037e10:·2861·7320·6f66·2032·3032·362d·3031·2d30··(as·of·2026-01-000037e10:·2861·7320·6f66·2032·3032·342d·3132·2d30··(as·of·2024-12-0
00037e20:·3829·0a20·2020·2020·2020·2020·2020·2020··8).·············00037e20:·3729·0a20·2020·2020·2020·2020·2020·2020··7).·············
00037e30:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d00037e30:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d
00037e40:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·00037e40:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·
00037e50:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol00037e50:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol
00037e60:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x00037e60:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x
00037e70:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj00037e70:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj
00037e80:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou00037e80:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou
00037e90:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System00037e90:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System
Offset 15010, 191 lines modifiedOffset 15010, 191 lines modified
0003aa10:·2d74·6172·6765·743d·2223·6964·6d35·3731··-target="#idm5710003aa10:·2d74·6172·6765·743d·2223·6964·6d35·3731··-target="#idm571
0003aa20:·3022·2074·6162·696e·6465·783d·2230·2220··0"·tabindex="0"·0003aa20:·3022·2074·6162·696e·6465·783d·2230·2220··0"·tabindex="0"·
0003aa30:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003aa30:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003aa40:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003aa40:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003aa50:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003aa50:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003aa60:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003aa60:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003aa70:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003aa70:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003aa80:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
0003aa90:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003aaa0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003aab0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003aac0:·2220·6964·3d22·6964·6d35·3731·3022·3e3c··"·id="idm5710">< 
0003aad0:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme 
0003aae0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
0003aaf0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
0003ab00:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
0003ab10:·6966·2028·205b·2021·202d·6620·2f2e·646f··if·(·[·!·-f·/.do 
0003ab20:·636b·6572·656e·7620·5d20·2661·6d70·3b26··ckerenv·]·&amp;& 
0003ab30:·616d·703b·205b·2021·202d·6620·2f72·756e··amp;·[·!·-f·/run 
0003ab40:·2f2e·636f·6e74·6169·6e65·7265·6e76·205d··/.containerenv·] 
0003ab50:·2026·616d·703b·2661·6d70·3b20·2120·2820···&amp;&amp;·!·(· 
0003ab60:·5b20·2224·7b63·6f6e·7461·696e·6572·3a2d··[·"${container:- 
0003ab70:·7d22·203d·3d20·2262·7772·6170·2d6f·7362··}"·==·"bwrap-osb 
0003ab80:·7569·6c64·2220·5d20·2920·293b·2074·6865··uild"·]·)·);·the 
0003ab90:·6e0a·0a66·6970·732d·6d6f·6465·2d73·6574··n..fips-mode-set 
0003aba0:·7570·202d·2d65·6e61·626c·650a·4649·5053··up·--enable.FIPS 
0003abb0:·5f43·4f4e·463d·222f·6574·632f·6472·6163··_CONF="/etc/drac 
0003abc0:·7574·2e63·6f6e·662e·642f·3430·2d66·6970··ut.conf.d/40-fip 
0003abd0:·732e·636f·6e66·220a·6966·2021·2067·7265··s.conf".if·!·gre 
0003abe0:·7020·225e·6164·645f·6472·6163·7574·6d6f··p·"^add_dracutmo 
0003abf0:·6475·6c65·732b·3d5c·2220·6669·7073·205c··dules+=\"·fips·\ 
0003ac00:·2222·2024·4649·5053·5f43·4f4e·463b·2074··""·$FIPS_CONF;·t 
0003ac10:·6865·6e0a·2020·2020·6563·686f·2022·6164··hen.····echo·"ad 
0003ac20:·645f·6472·6163·7574·6d6f·6475·6c65·732b··d_dracutmodules+ 
0003ac30:·3d5c·2220·6669·7073·205c·2222·2026·6774··=\"·fips·\""·&gt 
0003ac40:·3b26·6774·3b20·2446·4950·535f·434f·4e46··;&gt;·$FIPS_CONF 
0003ac50:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g 
0003ac60:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R 
0003ac70:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no 
0003ac80:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no 
0003ac90:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'. 
0003aca0:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre> 
0003acb0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003acc0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003acd0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003ace0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003acf0:·6765·743d·2223·6964·6d35·3731·3122·2074··get="#idm5711"·t 
0003ad00:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003ad10:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003ad20:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003ad30:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003ad40:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003ad50:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003ad60:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet0003aa80:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni
0003ad70:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003aa90:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003ad80:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003aaa0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003ad90:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003aab0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003ada0:·2069·643d·2269·646d·3537·3131·223e·3c74···id="idm5711"><t0003aac0:·7073·6522·2069·643d·2269·646d·3537·3130··pse"·id="idm5710
0003adb0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl0003aad0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003adc0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·0003aae0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003add0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0003aaf0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003ade0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">0003ab00:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003adf0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi0003ab10:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003ab20:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003ab30:·6d65·6469·756d·3c2f·7464·3e3c·2f74·723e··medium</td></tr>
 0003ab40:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003ae00:·7479·3a3c·2f74·683e·3c74·643e·6d65·6469··ty:</th><td>medi0003ab50:·6f6e·3a3c·2f74·683e·3c74·643e·6d65·6469··on:</th><td>medi
0003ae10:·756d·3c2f·7464·3e3c·2f74·723e·3c74·723e··um</td></tr><tr>0003ab60:·756d·3c2f·7464·3e3c·2f74·723e·3c74·723e··um</td></tr><tr>
0003ae20:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003ae30:·2f74·683e·3c74·643e·6d65·6469·756d·3c2f··/th><td>medium</ 
0003ae40:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003ae50:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>0003ab70:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003ab80:·3c74·643e·7472·7565·3c2f·7464·3e3c·2f74··<td>true</td></t
 0003ab90:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003aba0:·6779·3a3c·2f74·683e·3c74·643e·7265·7374··gy:</th><td>rest
0003ae60:·7472·7565·3c2f·7464·3e3c·2f74·723e·3c74··true</td></tr><t0003abb0:·7269·6374·3c2f·7464·3e3c·2f74·723e·3c2f··rict</td></tr></
0003ae70:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003ae80:·2f74·683e·3c74·643e·7265·7374·7269·6374··/th><td>restrict 
0003ae90:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003aea0:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n0003abc0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
0003aeb0:·616d·653a·2043·6865·636b·2074·6f20·7365··ame:·Check·to·se0003abd0:·3e2d·206e·616d·653a·2043·6865·636b·2074··>-·name:·Check·t
0003aec0:·6520·7468·6520·6375·7272·656e·7420·7374··e·the·current·st0003abe0:·6f20·7365·6520·7468·6520·6375·7272·656e··o·see·the·curren
0003aed0:·6174·7573·206f·6620·4649·5053·206d·6f64··atus·of·FIPS·mod0003abf0:·7420·7374·6174·7573·206f·6620·4649·5053··t·status·of·FIPS
0003aee0:·650a·2020·636f·6d6d·616e·643a·202f·7573··e.··command:·/us 
0003aef0:·722f·6269·6e2f·6669·7073·2d6d·6f64·652d··r/bin/fips-mode- 
0003af00:·7365·7475·7020·2d2d·6368·6563·6b0a·2020··setup·--check.·· 
0003af10:·7265·6769·7374·6572·3a20·6973·5f66·6970··register:·is_fip 
0003af20:·735f·656e·6162·6c65·640a·2020·6368·616e··s_enabled.··chan 
0003af30:·6765·645f·7768·656e·3a20·6661·6c73·650a··ged_when:·false. 
0003af40:·2020·6661·696c·6564·5f77·6865·6e3a·2066····failed_when:·f 
0003af50:·616c·7365·0a20·2077·6865·6e3a·2028·2061··alse.··when:·(·a 
0003af60:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz 
0003af70:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i 
0003af80:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx 
0003af90:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p 
0003afa0:·6f64·6d61·6e22·2c0a·2020·2020·2263·6f6e··odman",.····"con 
0003afb0:·7461·696e·6572·225d·2061·6e64·206e·6f74··tainer"]·and·not 
0003afc0:·2028·206c·6f6f·6b75·7028·2265·6e76·222c···(·lookup("env", 
0003afd0:·2022·636f·6e74·6169·6e65·7222·2920·3d3d···"container")·== 
0003afe0:·2022·6277·7261·702d·6f73·6275·696c·6422···"bwrap-osbuild" 
0003aff0:·2029·2029·0a20·2074·6167·733a·0a20·202d···)·).··tags:.··- 
0003b000:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM- 
0003b010:·3628·6129·0a20·202d·204e·4953·542d·3830··6(a).··-·NIST-80 
0003b020:·302d·3533·2d49·412d·370a·2020·2d20·4e49··0-53-IA-7.··-·NI 
0003b030:·5354·2d38·3030·2d35·332d·5343·2d31·320a··ST-800-53-SC-12. 
0003b040:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53- 
0003b050:·5343·2d31·3228·3229·0a20·202d·204e·4953··SC-12(2).··-·NIS 
0003b060:·542d·3830·302d·3533·2d53·432d·3132·2833··T-800-53-SC-12(3 
0003b070:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5 
0003b080:·332d·5343·2d31·330a·2020·2d20·656e·6162··3-SC-13.··-·enab 
Max diff block lines reached; 4598836/4625110 bytes (99.43%) of diff not shown.
554 KB
html2text {}
    
Offset 42, 15 lines modifiedOffset 42, 15 lines modified
42 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Protection·Profile·for·General·Purpose·Operating·Systems43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Protection·Profile·for·General·Purpose·Operating·Systems
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ospp44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ospp
45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
46 ····*·cpe:/o:oracle:linux:946 ····*·cpe:/o:oracle:linux:9
47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
48 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8448 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
54 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n54 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
55 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s55 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
56 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s56 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 89, 27 lines modifiedOffset 89, 14 lines modified
89 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_dracut_fips_module89 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_dracut_fips_module
90 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000068,·CCI-000803,·CCI-00245090 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000068,·CCI-000803,·CCI-002450
91 ············_\x8i_\x8s_\x8m······144691 ············_\x8i_\x8s_\x8m······1446
92 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.192 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
93 ············_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-1293 ············_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
94 ············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.194 ············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.1
95 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-0022395 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223
96 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
97 #·Remediation·is·applicable·only·in·certain·platforms 
98 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·);·then 
  
99 fips-mode-setup·--enable 
100 FIPS_CONF="/etc/dracut.conf.d/40-fips.conf" 
101 if·!·grep·"^add_dracutmodules+=\"·fips·\""·$FIPS_CONF;·then 
102 ····echo·"add_dracutmodules+=\"·fips·\""·>>·$FIPS_CONF 
103 fi 
  
104 else 
105 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
106 fi 
107 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x896 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
108 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium97 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium
109 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium98 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
110 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true99 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
111 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict100 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
112 -·name:·Check·to·see·the·current·status·of·FIPS·mode101 -·name:·Check·to·see·the·current·status·of·FIPS·mode
113 ··command:·/usr/bin/fips-mode-setup·--check102 ··command:·/usr/bin/fips-mode-setup·--check
Offset 167, 14 lines modifiedOffset 154, 27 lines modified
167 ··-·NIST-800-53-SC-13154 ··-·NIST-800-53-SC-13
168 ··-·enable_dracut_fips_module155 ··-·enable_dracut_fips_module
169 ··-·high_severity156 ··-·high_severity
170 ··-·medium_complexity157 ··-·medium_complexity
171 ··-·medium_disruption158 ··-·medium_disruption
172 ··-·reboot_required159 ··-·reboot_required
173 ··-·restrict_strategy160 ··-·restrict_strategy
 161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 162 #·Remediation·is·applicable·only·in·certain·platforms
 163 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·);·then
  
 164 fips-mode-setup·--enable
 165 FIPS_CONF="/etc/dracut.conf.d/40-fips.conf"
 166 if·!·grep·"^add_dracutmodules+=\"·fips·\""·$FIPS_CONF;·then
 167 ····echo·"add_dracutmodules+=\"·fips·\""·>>·$FIPS_CONF
 168 fi
  
 169 else
 170 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 171 fi
174 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*172 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
175 To·enable·FIPS·mode,·run·the·following·command:173 To·enable·FIPS·mode,·run·the·following·command:
176 fips-mode-setup·--enable174 fips-mode-setup·--enable
  
177 The·fips-mode-setup·command·will·configure·the·system·in·FIPS·mode·by·automatically·configuring·the·following:175 The·fips-mode-setup·command·will·configure·the·system·in·FIPS·mode·by·automatically·configuring·the·following:
178 ····*·Setting·the·kernel·FIPS·mode·flag·(/proc/sys/crypto/fips_enabled)·to·1176 ····*·Setting·the·kernel·FIPS·mode·flag·(/proc/sys/crypto/fips_enabled)·to·1
179 ····*·Creating·/etc/system-fips177 ····*·Creating·/etc/system-fips
Offset 187, 41 lines modifiedOffset 187, 18 lines modified
187 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode187 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode
188 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000068,·CCI-000803,·CCI-002450188 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000068,·CCI-000803,·CCI-002450
189 ············_\x8i_\x8s_\x8m······1446189 ············_\x8i_\x8s_\x8m······1446
190 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1190 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
191 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12191 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
192 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1192 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
193 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176193 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
 194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
195 #·Remediation·is·applicable·only·in·certain·platforms 
196 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·)·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then 
  
197 var_system_crypto_policy='FIPS:OSPP' 
  
  
198 fips-mode-setup·--enable 
  
199 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
200 rc=$? 
  
201 if·test·"$rc"·=·127;·then 
202 »       echo·"$stderr_of_call"·>&2 
203 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
204 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
205 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
206 »       false··#·end·with·an·error·code 
207 elif·test·"$rc"·!=·0;·then 
208 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
209 »       false··#·end·with·an·error·code 
210 fi 
  
 195 [customizations]
 196 fips·=·true
211 else 
212 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
213 fi 
214 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
215 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium
216 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
217 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
218 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
219 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable202 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
220 ··set_fact:203 ··set_fact:
Offset 317, 18 lines modifiedOffset 294, 41 lines modified
317 ··-·NIST-800-53-SC-13294 ··-·NIST-800-53-SC-13
318 ··-·enable_fips_mode295 ··-·enable_fips_mode
319 ··-·high_severity296 ··-·high_severity
320 ··-·medium_complexity297 ··-·medium_complexity
321 ··-·medium_disruption298 ··-·medium_disruption
322 ··-·reboot_required299 ··-·reboot_required
323 ··-·restrict_strategy300 ··-·restrict_strategy
324 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8301 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 302 #·Remediation·is·applicable·only·in·certain·platforms
 303 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·)·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
Max diff block lines reached; 561143/567453 bytes (98.89%) of diff not shown.
16.3 MB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-pci-dss.html
    
Offset 14296, 15 lines modifiedOffset 14296, 15 lines modified
00037d70:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur00037d70:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur
00037d80:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s00037d80:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s
00037d90:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st00037d90:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st
00037da0:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li00037da0:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li
00037db0:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</00037db0:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</
00037dc0:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········00037dc0:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········
00037dd0:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·00037dd0:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·
00037de0:·6f66·2032·3032·362d·3031·2d30·3829·0a20··of·2026-01-08).·00037de0:·6f66·2032·3032·342d·3132·2d30·3729·0a20··of·2024-12-07).·
00037df0:·2020·2020·2020·2020·2020·2020·2020·203c·················<00037df0:·2020·2020·2020·2020·2020·2020·2020·203c·················<
00037e00:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><00037e00:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><
00037e10:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont00037e10:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont
00037e20:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li00037e20:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li
00037e30:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf00037e30:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf
00037e40:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.00037e40:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.
00037e50:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy00037e50:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy
Offset 15157, 301 lines modifiedOffset 15157, 301 lines modified
0003b340:·612d·7461·7267·6574·3d22·2369·646d·3438··a-target="#idm480003b340:·612d·7461·7267·6574·3d22·2369·646d·3438··a-target="#idm48
0003b350:·3836·2220·7461·6269·6e64·6578·3d22·3022··86"·tabindex="0"0003b350:·3836·2220·7461·6269·6e64·6578·3d22·3022··86"·tabindex="0"
0003b360:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003b360:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003b370:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003b370:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003b380:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003b380:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003b390:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003b390:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003b3a0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003b3a0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003b3b0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
0003b3c0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
0003b3d0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003b3e0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003b3f0:·6522·2069·643d·2269·646d·3438·3836·223e··e"·id="idm4886"> 
0003b400:·3c70·7265·3e3c·636f·6465·3e0a·2320·4669··<pre><code>.#·Fi 
0003b410:·6e64·2077·6869·6368·2066·696c·6573·2068··nd·which·files·h 
0003b420:·6176·6520·696e·636f·7272·6563·7420·6861··ave·incorrect·ha 
0003b430:·7368·2028·6e6f·7420·696e·202f·6574·632c··sh·(not·in·/etc, 
0003b440:·2062·6563·6175·7365·206f·6620·7468·6520···because·of·the· 
0003b450:·7379·7374·656d·2072·656c·6174·6564·2063··system·related·c 
0003b460:·6f6e·6669·6720·6669·6c65·7329·2061·6e64··onfig·files)·and 
0003b470:·2074·6865·6e20·6765·7420·6669·6c65·7320···then·get·files· 
0003b480:·6e61·6d65·730a·6669·6c65·735f·7769·7468··names.files_with 
0003b490:·5f69·6e63·6f72·7265·6374·5f68·6173·683d··_incorrect_hash= 
0003b4a0:·2224·2872·706d·202d·5661·202d·2d6e·6f63··"$(rpm·-Va·--noc 
0003b4b0:·6f6e·6669·6720·7c20·6772·6570·202d·4520··onfig·|·grep·-E· 
0003b4c0:·275e·2e2e·3527·207c·2061·776b·2027·7b70··'^..5'·|·awk·'{p 
0003b4d0:·7269·6e74·2024·4e46·7d27·2029·220a·0a69··rint·$NF}'·)"..i 
0003b4e0:·6620·5b20·2d6e·2022·2466·696c·6573·5f77··f·[·-n·"$files_w 
0003b4f0:·6974·685f·696e·636f·7272·6563·745f·6861··ith_incorrect_ha 
0003b500:·7368·2220·5d3b·2074·6865·6e0a·2020·2020··sh"·];·then.···· 
0003b510:·2320·4672·6f6d·2066·696c·6573·206e·616d··#·From·files·nam 
0003b520:·6573·2067·6574·2070·6163·6b61·6765·206e··es·get·package·n 
0003b530:·616d·6573·2061·6e64·2063·6861·6e67·6520··ames·and·change· 
0003b540:·6e65·776c·696e·6520·746f·2073·7061·6365··newline·to·space 
0003b550:·2c20·6265·6361·7573·6520·7270·6d20·7772··,·because·rpm·wr 
0003b560:·6974·6573·2065·6163·6820·7061·636b·6167··ites·each·packag 
0003b570:·6520·746f·206e·6577·206c·696e·650a·2020··e·to·new·line.·· 
0003b580:·2020·7061·636b·6167·6573·5f74·6f5f·7265····packages_to_re 
0003b590:·696e·7374·616c·6c3d·2224·2872·706d·202d··install="$(rpm·- 
0003b5a0:·7166·2024·6669·6c65·735f·7769·7468·5f69··qf·$files_with_i 
0003b5b0:·6e63·6f72·7265·6374·5f68·6173·6820·7c20··ncorrect_hash·|· 
0003b5c0:·7472·2027·5c6e·2720·2720·2729·220a·0a20··tr·'\n'·'·')"..· 
0003b5d0:·2020·200a·2020·2020·7975·6d20·7265·696e·····.····yum·rein 
0003b5e0:·7374·616c·6c20·2d79·2024·7061·636b·6167··stall·-y·$packag 
0003b5f0:·6573·5f74·6f5f·7265·696e·7374·616c·6c0a··es_to_reinstall. 
0003b600:·2020·2020·0a66·690a·3c2f·636f·6465·3e3c······.fi.</code>< 
0003b610:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003b620:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003b630:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003b640:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003b650:·612d·7461·7267·6574·3d22·2369·646d·3438··a-target="#idm48 
0003b660:·3837·2220·7461·6269·6e64·6578·3d22·3022··87"·tabindex="0" 
0003b670:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003b680:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003b690:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003b6a0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003b6b0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003b6c0:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn0003b3b0:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn
0003b6d0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003b3c0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003b6e0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003b3d0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003b6f0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003b3e0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003b700:·6170·7365·2220·6964·3d22·6964·6d34·3838··apse"·id="idm4880003b3f0:·6170·7365·2220·6964·3d22·6964·6d34·3838··apse"·id="idm488
0003b710:·3722·3e3c·7461·626c·6520·636c·6173·733d··7"><table·class=0003b400:·3622·3e3c·7461·626c·6520·636c·6173·733d··6"><table·class=
0003b720:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003b410:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003b730:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003b420:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003b740:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003b430:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003b750:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003b440:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003b760:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003b450:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003b770:·3e68·6967·683c·2f74·643e·3c2f·7472·3e3c··>high</td></tr><0003b460:·3e68·6967·683c·2f74·643e·3c2f·7472·3e3c··>high</td></tr><
0003b780:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003b470:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003b790:·6e3a·3c2f·7468·3e3c·7464·3e6d·6564·6975··n:</th><td>mediu0003b480:·6e3a·3c2f·7468·3e3c·7464·3e6d·6564·6975··n:</th><td>mediu
0003b7a0:·6d3c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··m</td></tr><tr><0003b490:·6d3c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··m</td></tr><tr><
0003b7b0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><0003b4a0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
0003b7c0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t0003b4b0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
0003b7d0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate0003b4c0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003b7e0:·6779·3a3c·2f74·683e·3c74·643e·7265·7374··gy:</th><td>rest0003b4d0:·6779·3a3c·2f74·683e·3c74·643e·7265·7374··gy:</th><td>rest
0003b7f0:·7269·6374·3c2f·7464·3e3c·2f74·723e·3c2f··rict</td></tr></0003b4e0:·7269·6374·3c2f·7464·3e3c·2f74·723e·3c2f··rict</td></tr></
0003b800:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003b4f0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
0003b810:·3e2d·206e·616d·653a·2027·5365·7420·6661··>-·name:·'Set·fa0003b500:·3e2d·206e·616d·653a·2027·5365·7420·6661··>-·name:·'Set·fa
0003b820:·6374·3a20·5061·636b·6167·6520·6d61·6e61··ct:·Package·mana0003b510:·6374·3a20·5061·636b·6167·6520·6d61·6e61··ct:·Package·mana
0003b830:·6765·7220·7265·696e·7374·616c·6c20·636f··ger·reinstall·co0003b520:·6765·7220·7265·696e·7374·616c·6c20·636f··ger·reinstall·co
0003b840:·6d6d·616e·6427·0a20·2073·6574·5f66·6163··mmand'.··set_fac0003b530:·6d6d·616e·6427·0a20·2073·6574·5f66·6163··mmand'.··set_fac
0003b850:·743a·0a20·2020·2070·6163·6b61·6765·5f6d··t:.····package_m0003b540:·743a·0a20·2020·2070·6163·6b61·6765·5f6d··t:.····package_m
0003b860:·616e·6167·6572·5f72·6569·6e73·7461·6c6c··anager_reinstall0003b550:·616e·6167·6572·5f72·6569·6e73·7461·6c6c··anager_reinstall
0003b870:·5f63·6d64·3a20·7975·6d20·7265·696e·7374··_cmd:·yum·reinst0003b560:·5f63·6d64·3a20·7975·6d20·7265·696e·7374··_cmd:·yum·reinst
0003b880:·616c·6c20·2d79·0a20·2077·6865·6e3a·2061··all·-y.··when:·a0003b570:·616c·6c20·2d79·0a20·2077·6865·6e3a·2061··all·-y.··when:·a
0003b890:·6e73·6962·6c65·5f64·6973·7472·6962·7574··nsible_distribut0003b580:·6e73·6962·6c65·5f64·6973·7472·6962·7574··nsible_distribut
0003b8a0:·696f·6e20·696e·205b·2022·4665·646f·7261··ion·in·[·"Fedora0003b590:·696f·6e20·696e·205b·2022·4665·646f·7261··ion·in·[·"Fedora
0003b8b0:·222c·2022·5265·6448·6174·222c·2022·4365··",·"RedHat",·"Ce0003b5a0:·222c·2022·5265·6448·6174·222c·2022·4365··",·"RedHat",·"Ce
0003b8c0:·6e74·4f53·222c·2022·4f72·6163·6c65·4c69··ntOS",·"OracleLi0003b5b0:·6e74·4f53·222c·2022·4f72·6163·6c65·4c69··ntOS",·"OracleLi
0003b8d0:·6e75·7822·205d·0a20·2074·6167·733a·0a20··nux"·].··tags:.·0003b5c0:·6e75·7822·205d·0a20·2074·6167·733a·0a20··nux"·].··tags:.·
0003b8e0:·202d·2043·4a49·532d·352e·3130·2e34·2e31···-·CJIS-5.10.4.10003b5d0:·202d·2043·4a49·532d·352e·3130·2e34·2e31···-·CJIS-5.10.4.1
0003b8f0:·0a20·202d·204e·4953·542d·3830·302d·3137··.··-·NIST-800-170003b5e0:·0a20·202d·204e·4953·542d·3830·302d·3137··.··-·NIST-800-17
0003b900:·312d·332e·332e·380a·2020·2d20·4e49·5354··1-3.3.8.··-·NIST0003b5f0:·312d·332e·332e·380a·2020·2d20·4e49·5354··1-3.3.8.··-·NIST
0003b910:·2d38·3030·2d31·3731·2d33·2e34·2e31·0a20··-800-171-3.4.1.·0003b600:·2d38·3030·2d31·3731·2d33·2e34·2e31·0a20··-800-171-3.4.1.·
0003b920:·202d·204e·4953·542d·3830·302d·3533·2d41···-·NIST-800-53-A0003b610:·202d·204e·4953·542d·3830·302d·3533·2d41···-·NIST-800-53-A
0003b930:·552d·3928·3329·0a20·202d·204e·4953·542d··U-9(3).··-·NIST-0003b620:·552d·3928·3329·0a20·202d·204e·4953·542d··U-9(3).··-·NIST-
0003b940:·3830·302d·3533·2d43·4d2d·3628·6329·0a20··800-53-CM-6(c).·0003b630:·3830·302d·3533·2d43·4d2d·3628·6329·0a20··800-53-CM-6(c).·
0003b950:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C0003b640:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C
0003b960:·4d2d·3628·6429·0a20·202d·204e·4953·542d··M-6(d).··-·NIST-0003b650:·4d2d·3628·6429·0a20·202d·204e·4953·542d··M-6(d).··-·NIST-
0003b970:·3830·302d·3533·2d53·492d·370a·2020·2d20··800-53-SI-7.··-·0003b660:·3830·302d·3533·2d53·492d·370a·2020·2d20··800-53-SI-7.··-·
0003b980:·4e49·5354·2d38·3030·2d35·332d·5349·2d37··NIST-800-53-SI-70003b670:·4e49·5354·2d38·3030·2d35·332d·5349·2d37··NIST-800-53-SI-7
0003b990:·2831·290a·2020·2d20·4e49·5354·2d38·3030··(1).··-·NIST-8000003b680:·2831·290a·2020·2d20·4e49·5354·2d38·3030··(1).··-·NIST-800
0003b9a0:·2d35·332d·5349·2d37·2836·290a·2020·2d20··-53-SI-7(6).··-·0003b690:·2d35·332d·5349·2d37·2836·290a·2020·2d20··-53-SI-7(6).··-·
0003b9b0:·5043·492d·4453·532d·5265·712d·3131·2e35··PCI-DSS-Req-11.50003b6a0:·5043·492d·4453·532d·5265·712d·3131·2e35··PCI-DSS-Req-11.5
0003b9c0:·0a20·202d·2050·4349·2d44·5353·7634·2d31··.··-·PCI-DSSv4-10003b6b0:·0a20·202d·2050·4349·2d44·5353·7634·2d31··.··-·PCI-DSSv4-1
0003b9d0:·312e·352e·320a·2020·2d20·6869·6768·5f63··1.5.2.··-·high_c0003b6c0:·312e·352e·320a·2020·2d20·6869·6768·5f63··1.5.2.··-·high_c
0003b9e0:·6f6d·706c·6578·6974·790a·2020·2d20·6869··omplexity.··-·hi0003b6d0:·6f6d·706c·6578·6974·790a·2020·2d20·6869··omplexity.··-·hi
0003b9f0:·6768·5f73·6576·6572·6974·790a·2020·2d20··gh_severity.··-·0003b6e0:·6768·5f73·6576·6572·6974·790a·2020·2d20··gh_severity.··-·
0003ba00:·6d65·6469·756d·5f64·6973·7275·7074·696f··medium_disruptio0003b6f0:·6d65·6469·756d·5f64·6973·7275·7074·696f··medium_disruptio
0003ba10:·6e0a·2020·2d20·6e6f·5f72·6562·6f6f·745f··n.··-·no_reboot_0003b700:·6e0a·2020·2d20·6e6f·5f72·6562·6f6f·745f··n.··-·no_reboot_
0003ba20:·6e65·6564·6564·0a20·202d·2072·6573·7472··needed.··-·restr0003b710:·6e65·6564·6564·0a20·202d·2072·6573·7472··needed.··-·restr
Max diff block lines reached; 15519399/15545121 bytes (99.83%) of diff not shown.
1.44 MB
html2text {}
    
Offset 40, 15 lines modifiedOffset 40, 15 lines modified
40 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*40 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v4.0·Control·Baseline·for·Oracle·Linux·941 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v4.0·Control·Baseline·for·Oracle·Linux·9
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss
43 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*43 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
44 ····*·cpe:/o:oracle:linux:944 ····*·cpe:/o:oracle:linux:9
45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
46 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8446 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
50 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e50 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
51 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l51 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
52 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n52 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
53 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g53 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
54 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s54 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 105, 27 lines modifiedOffset 105, 14 lines modified
105 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6105 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
106 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4106 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
107 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)107 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
108 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1108 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
109 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5109 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
110 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227110 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
111 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2111 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
113 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
114 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
115 if·[·-n·"$files_with_incorrect_hash"·];·then 
116 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
117 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
118 ····yum·reinstall·-y·$packages_to_reinstall 
  
119 fi 
120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
121 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high113 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
122 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium114 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
123 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false115 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
124 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict116 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
125 -·name:·'Set·fact:·Package·manager·reinstall·command'117 -·name:·'Set·fact:·Package·manager·reinstall·command'
126 ··set_fact:118 ··set_fact:
Offset 252, 14 lines modifiedOffset 239, 27 lines modified
252 ··-·PCI-DSSv4-11.5.2239 ··-·PCI-DSSv4-11.5.2
253 ··-·high_complexity240 ··-·high_complexity
254 ··-·high_severity241 ··-·high_severity
255 ··-·medium_disruption242 ··-·medium_disruption
256 ··-·no_reboot_needed243 ··-·no_reboot_needed
257 ··-·restrict_strategy244 ··-·restrict_strategy
258 ··-·rpm_verify_hashes245 ··-·rpm_verify_hashes
 246 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 247 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 248 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 249 if·[·-n·"$files_with_incorrect_hash"·];·then
 250 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 251 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 252 ····yum·reinstall·-y·$packages_to_reinstall
  
 253 fi
259 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*254 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
260 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:255 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
261 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'256 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
262 run·the·following·command·to·determine·which·package·owns·it:257 run·the·following·command·to·determine·which·package·owns·it:
263 $·rpm·-qf·FILENAME258 $·rpm·-qf·FILENAME
264 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:259 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
265 $·sudo·rpm·--setugids·PACKAGENAME260 $·sudo·rpm·--setugids·PACKAGENAME
Offset 278, 40 lines modifiedOffset 278, 14 lines modified
278 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5278 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
279 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2279 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
280 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)280 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
281 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1281 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
282 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5282 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
283 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108283 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
284 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2284 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
285 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
286 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
287 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
288 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
289 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
290 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
291 declare·-A·SETPERMS_RPM_DICT 
  
292 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
293 #·is·expected·by·the·RPM·database 
294 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
295 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
296 do 
297 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
298 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
299 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
300 done 
  
301 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
302 #·correct·values 
303 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
304 do 
305 ········rpm·--setugids·"${RPM_PACKAGE}" 
306 done 
307 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8285 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
308 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high286 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
309 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium287 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
310 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false288 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
311 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict289 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
312 -·name:·Read·list·of·files·with·incorrect·ownership290 -·name:·Read·list·of·files·with·incorrect·ownership
313 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev291 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 386, 14 lines modifiedOffset 360, 40 lines modified
386 ··-·PCI-DSSv4-11.5.2360 ··-·PCI-DSSv4-11.5.2
387 ··-·high_complexity361 ··-·high_complexity
388 ··-·high_severity362 ··-·high_severity
389 ··-·medium_disruption363 ··-·medium_disruption
390 ··-·no_reboot_needed364 ··-·no_reboot_needed
391 ··-·restrict_strategy365 ··-·restrict_strategy
392 ··-·rpm_verify_ownership366 ··-·rpm_verify_ownership
 367 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 368 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 369 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 370 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 371 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 372 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 1507139/1514898 bytes (99.49%) of diff not shown.
9.69 MB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-standard.html
    
Offset 14285, 16 lines modifiedOffset 14285, 16 lines modified
00037cc0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00037cc0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00037cd0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00037cd0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00037ce0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000037ce0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00037cf0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></00037cf0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
00037d00:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00037d00:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00037d10:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00037d10:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00037d20:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037d20:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037d30:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600037d30:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
00037d40:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········00037d40:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00037d50:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00037d50:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00037d60:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00037d60:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00037d70:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00037d70:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00037d80:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00037d80:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00037d90:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00037d90:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00037da0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00037da0:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00037db0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00037db0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
Offset 15091, 301 lines modifiedOffset 15091, 301 lines modified
0003af20:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003af20:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003af30:·2223·6964·6d34·3838·3622·2074·6162·696e··"#idm4886"·tabin0003af30:·2223·6964·6d34·3838·3622·2074·6162·696e··"#idm4886"·tabin
0003af40:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003af40:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003af50:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003af50:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003af60:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003af60:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003af70:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003af70:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003af80:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003af80:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003af90:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
0003afa0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
0003afb0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003afc0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003afd0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003afe0:·6d34·3838·3622·3e3c·7072·653e·3c63·6f64··m4886"><pre><cod 
0003aff0:·653e·0a23·2046·696e·6420·7768·6963·6820··e>.#·Find·which· 
0003b000:·6669·6c65·7320·6861·7665·2069·6e63·6f72··files·have·incor 
0003b010:·7265·6374·2068·6173·6820·286e·6f74·2069··rect·hash·(not·i 
0003b020:·6e20·2f65·7463·2c20·6265·6361·7573·6520··n·/etc,·because· 
0003b030:·6f66·2074·6865·2073·7973·7465·6d20·7265··of·the·system·re 
0003b040:·6c61·7465·6420·636f·6e66·6967·2066·696c··lated·config·fil 
0003b050:·6573·2920·616e·6420·7468·656e·2067·6574··es)·and·then·get 
0003b060:·2066·696c·6573·206e·616d·6573·0a66·696c···files·names.fil 
0003b070:·6573·5f77·6974·685f·696e·636f·7272·6563··es_with_incorrec 
0003b080:·745f·6861·7368·3d22·2428·7270·6d20·2d56··t_hash="$(rpm·-V 
0003b090:·6120·2d2d·6e6f·636f·6e66·6967·207c·2067··a·--noconfig·|·g 
0003b0a0:·7265·7020·2d45·2027·5e2e·2e35·2720·7c20··rep·-E·'^..5'·|· 
0003b0b0:·6177·6b20·277b·7072·696e·7420·244e·467d··awk·'{print·$NF} 
0003b0c0:·2720·2922·0a0a·6966·205b·202d·6e20·2224··'·)"..if·[·-n·"$ 
0003b0d0:·6669·6c65·735f·7769·7468·5f69·6e63·6f72··files_with_incor 
0003b0e0:·7265·6374·5f68·6173·6822·205d·3b20·7468··rect_hash"·];·th 
0003b0f0:·656e·0a20·2020·2023·2046·726f·6d20·6669··en.····#·From·fi 
0003b100:·6c65·7320·6e61·6d65·7320·6765·7420·7061··les·names·get·pa 
0003b110:·636b·6167·6520·6e61·6d65·7320·616e·6420··ckage·names·and· 
0003b120:·6368·616e·6765·206e·6577·6c69·6e65·2074··change·newline·t 
0003b130:·6f20·7370·6163·652c·2062·6563·6175·7365··o·space,·because 
0003b140:·2072·706d·2077·7269·7465·7320·6561·6368···rpm·writes·each 
0003b150:·2070·6163·6b61·6765·2074·6f20·6e65·7720···package·to·new· 
0003b160:·6c69·6e65·0a20·2020·2070·6163·6b61·6765··line.····package 
0003b170:·735f·746f·5f72·6569·6e73·7461·6c6c·3d22··s_to_reinstall=" 
0003b180:·2428·7270·6d20·2d71·6620·2466·696c·6573··$(rpm·-qf·$files 
0003b190:·5f77·6974·685f·696e·636f·7272·6563·745f··_with_incorrect_ 
0003b1a0:·6861·7368·207c·2074·7220·275c·6e27·2027··hash·|·tr·'\n'·' 
0003b1b0:·2027·2922·0a0a·2020·2020·0a20·2020·2079···')"..····.····y 
0003b1c0:·756d·2072·6569·6e73·7461·6c6c·202d·7920··um·reinstall·-y· 
0003b1d0:·2470·6163·6b61·6765·735f·746f·5f72·6569··$packages_to_rei 
0003b1e0:·6e73·7461·6c6c·0a20·2020·200a·6669·0a3c··nstall.····.fi.< 
0003b1f0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003b200:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003b210:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003b220:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003b230:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003b240:·2223·6964·6d34·3838·3722·2074·6162·696e··"#idm4887"·tabin 
0003b250:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003b260:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003b270:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003b280:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003b290:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003b2a0:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans0003af90:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans
0003b2b0:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...0003afa0:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...
0003b2c0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003afb0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003b2d0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003afc0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003b2e0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003afd0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003b2f0:·2269·646d·3438·3837·223e·3c74·6162·6c65··"idm4887"><table0003afe0:·2269·646d·3438·3836·223e·3c74·6162·6c65··"idm4886"><table
0003b300:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003aff0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003b310:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003b000:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003b320:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003b010:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003b330:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003b020:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003b340:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003b030:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003b350:·2f74·683e·3c74·643e·6869·6768·3c2f·7464··/th><td>high</td0003b040:·2f74·683e·3c74·643e·6869·6768·3c2f·7464··/th><td>high</td
0003b360:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003b050:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003b370:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003b060:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003b380:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t0003b070:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t
0003b390:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot0003b080:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
0003b3a0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<0003b090:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003b3b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b0a0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b3c0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003b0b0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003b3d0:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>0003b0c0:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>
0003b3e0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003b0d0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
0003b3f0:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·0003b0e0:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·
0003b400:·2753·6574·2066·6163·743a·2050·6163·6b61··'Set·fact:·Packa0003b0f0:·2753·6574·2066·6163·743a·2050·6163·6b61··'Set·fact:·Packa
0003b410:·6765·206d·616e·6167·6572·2072·6569·6e73··ge·manager·reins0003b100:·6765·206d·616e·6167·6572·2072·6569·6e73··ge·manager·reins
0003b420:·7461·6c6c·2063·6f6d·6d61·6e64·270a·2020··tall·command'.··0003b110:·7461·6c6c·2063·6f6d·6d61·6e64·270a·2020··tall·command'.··
0003b430:·7365·745f·6661·6374·3a0a·2020·2020·7061··set_fact:.····pa0003b120:·7365·745f·6661·6374·3a0a·2020·2020·7061··set_fact:.····pa
0003b440:·636b·6167·655f·6d61·6e61·6765·725f·7265··ckage_manager_re0003b130:·636b·6167·655f·6d61·6e61·6765·725f·7265··ckage_manager_re
0003b450:·696e·7374·616c·6c5f·636d·643a·2079·756d··install_cmd:·yum0003b140:·696e·7374·616c·6c5f·636d·643a·2079·756d··install_cmd:·yum
0003b460:·2072·6569·6e73·7461·6c6c·202d·790a·2020···reinstall·-y.··0003b150:·2072·6569·6e73·7461·6c6c·202d·790a·2020···reinstall·-y.··
0003b470:·7768·656e·3a20·616e·7369·626c·655f·6469··when:·ansible_di0003b160:·7768·656e·3a20·616e·7369·626c·655f·6469··when:·ansible_di
0003b480:·7374·7269·6275·7469·6f6e·2069·6e20·5b20··stribution·in·[·0003b170:·7374·7269·6275·7469·6f6e·2069·6e20·5b20··stribution·in·[·
0003b490:·2246·6564·6f72·6122·2c20·2252·6564·4861··"Fedora",·"RedHa0003b180:·2246·6564·6f72·6122·2c20·2252·6564·4861··"Fedora",·"RedHa
0003b4a0:·7422·2c20·2243·656e·744f·5322·2c20·224f··t",·"CentOS",·"O0003b190:·7422·2c20·2243·656e·744f·5322·2c20·224f··t",·"CentOS",·"O
0003b4b0:·7261·636c·654c·696e·7578·2220·5d0a·2020··racleLinux"·].··0003b1a0:·7261·636c·654c·696e·7578·2220·5d0a·2020··racleLinux"·].··
0003b4c0:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-50003b1b0:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-5
0003b4d0:·2e31·302e·342e·310a·2020·2d20·4e49·5354··.10.4.1.··-·NIST0003b1c0:·2e31·302e·342e·310a·2020·2d20·4e49·5354··.10.4.1.··-·NIST
0003b4e0:·2d38·3030·2d31·3731·2d33·2e33·2e38·0a20··-800-171-3.3.8.·0003b1d0:·2d38·3030·2d31·3731·2d33·2e33·2e38·0a20··-800-171-3.3.8.·
0003b4f0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-0003b1e0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
0003b500:·332e·342e·310a·2020·2d20·4e49·5354·2d38··3.4.1.··-·NIST-80003b1f0:·332e·342e·310a·2020·2d20·4e49·5354·2d38··3.4.1.··-·NIST-8
0003b510:·3030·2d35·332d·4155·2d39·2833·290a·2020··00-53-AU-9(3).··0003b200:·3030·2d35·332d·4155·2d39·2833·290a·2020··00-53-AU-9(3).··
0003b520:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM0003b210:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
0003b530:·2d36·2863·290a·2020·2d20·4e49·5354·2d38··-6(c).··-·NIST-80003b220:·2d36·2863·290a·2020·2d20·4e49·5354·2d38··-6(c).··-·NIST-8
0003b540:·3030·2d35·332d·434d·2d36·2864·290a·2020··00-53-CM-6(d).··0003b230:·3030·2d35·332d·434d·2d36·2864·290a·2020··00-53-CM-6(d).··
0003b550:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI0003b240:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI
0003b560:·2d37·0a20·202d·204e·4953·542d·3830·302d··-7.··-·NIST-800-0003b250:·2d37·0a20·202d·204e·4953·542d·3830·302d··-7.··-·NIST-800-
0003b570:·3533·2d53·492d·3728·3129·0a20·202d·204e··53-SI-7(1).··-·N0003b260:·3533·2d53·492d·3728·3129·0a20·202d·204e··53-SI-7(1).··-·N
0003b580:·4953·542d·3830·302d·3533·2d53·492d·3728··IST-800-53-SI-7(0003b270:·4953·542d·3830·302d·3533·2d53·492d·3728··IST-800-53-SI-7(
0003b590:·3629·0a20·202d·2050·4349·2d44·5353·2d52··6).··-·PCI-DSS-R0003b280:·3629·0a20·202d·2050·4349·2d44·5353·2d52··6).··-·PCI-DSS-R
0003b5a0:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI-0003b290:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI-
0003b5b0:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··-0003b2a0:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··-
0003b5c0:·2068·6967·685f·636f·6d70·6c65·7869·7479···high_complexity0003b2b0:·2068·6967·685f·636f·6d70·6c65·7869·7479···high_complexity
0003b5d0:·0a20·202d·2068·6967·685f·7365·7665·7269··.··-·high_severi0003b2c0:·0a20·202d·2068·6967·685f·7365·7665·7269··.··-·high_severi
0003b5e0:·7479·0a20·202d·206d·6564·6975·6d5f·6469··ty.··-·medium_di0003b2d0:·7479·0a20·202d·206d·6564·6975·6d5f·6469··ty.··-·medium_di
0003b5f0:·7372·7570·7469·6f6e·0a20·202d·206e·6f5f··sruption.··-·no_0003b2e0:·7372·7570·7469·6f6e·0a20·202d·206e·6f5f··sruption.··-·no_
Max diff block lines reached; 9369598/9395320 bytes (99.73%) of diff not shown.
747 KB
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Oracle·Linux·939 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·Oracle·Linux·9
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard
41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
42 ····*·cpe:/o:oracle:linux:942 ····*·cpe:/o:oracle:linux:9
43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
44 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8444 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
49 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l49 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
51 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s51 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
52 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s52 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
Offset 93, 27 lines modifiedOffset 93, 14 lines modified
93 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.693 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
94 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.494 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
95 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)95 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
96 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-196 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
97 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.597 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
98 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-0022798 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
99 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.299 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
100 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
101 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
102 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
103 if·[·-n·"$files_with_incorrect_hash"·];·then 
104 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
105 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
106 ····yum·reinstall·-y·$packages_to_reinstall 
  
107 fi 
108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8100 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
109 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high101 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
110 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium102 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
111 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false103 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
112 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict104 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
113 -·name:·'Set·fact:·Package·manager·reinstall·command'105 -·name:·'Set·fact:·Package·manager·reinstall·command'
114 ··set_fact:106 ··set_fact:
Offset 240, 14 lines modifiedOffset 227, 27 lines modified
240 ··-·PCI-DSSv4-11.5.2227 ··-·PCI-DSSv4-11.5.2
241 ··-·high_complexity228 ··-·high_complexity
242 ··-·high_severity229 ··-·high_severity
243 ··-·medium_disruption230 ··-·medium_disruption
244 ··-·no_reboot_needed231 ··-·no_reboot_needed
245 ··-·restrict_strategy232 ··-·restrict_strategy
246 ··-·rpm_verify_hashes233 ··-·rpm_verify_hashes
 234 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 235 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 236 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 237 if·[·-n·"$files_with_incorrect_hash"·];·then
 238 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 239 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 240 ····yum·reinstall·-y·$packages_to_reinstall
  
 241 fi
247 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*242 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
248 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:243 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:
249 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'244 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'
250 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:245 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:
251 $·rpm·-qf·FILENAME246 $·rpm·-qf·FILENAME
  
252 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:247 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
Offset 268, 44 lines modifiedOffset 268, 14 lines modified
268 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5268 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
269 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2269 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
270 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)270 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)
271 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1271 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
272 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5272 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
273 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108273 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108
274 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2274 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
275 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
276 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
277 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
278 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
279 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
280 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
281 declare·-A·SETPERMS_RPM_DICT 
  
282 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
283 #·is·expected·by·the·RPM·database 
284 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}') 
  
285 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
286 do 
287 ········#·NOTE:·some·files·maybe·controlled·by·more·then·one·package 
288 ········readarray·-t·RPM_PACKAGES·<·<(rpm·-qf·"${FILE_PATH}") 
289 ········for·RPM_PACKAGE·in·"${RPM_PACKAGES[@]}" 
290 ········do 
291 ················#·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
292 ················SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
293 ········done 
294 done 
  
295 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
296 #·correct·values 
297 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
298 do 
299 »       rpm·--restore·"${RPM_PACKAGE}" 
300 done 
301 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8275 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
302 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high276 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
303 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium277 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
304 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false278 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
305 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict279 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
306 -·name:·Read·list·of·files·with·incorrect·permissions280 -·name:·Read·list·of·files·with·incorrect·permissions
307 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev281 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 383, 14 lines modifiedOffset 353, 44 lines modified
383 ··-·PCI-DSSv4-11.5.2353 ··-·PCI-DSSv4-11.5.2
384 ··-·high_complexity354 ··-·high_complexity
385 ··-·high_severity355 ··-·high_severity
386 ··-·medium_disruption356 ··-·medium_disruption
387 ··-·no_reboot_needed357 ··-·no_reboot_needed
388 ··-·restrict_strategy358 ··-·restrict_strategy
389 ··-·rpm_verify_permissions359 ··-·rpm_verify_permissions
 360 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 361 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 362 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
Max diff block lines reached; 756792/764958 bytes (98.93%) of diff not shown.
31.3 MB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-stig.html
    
Offset 14279, 16 lines modifiedOffset 14279, 16 lines modified
00037c60:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00037c60:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00037c70:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00037c70:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00037c80:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000037c80:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00037c90:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></00037c90:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
00037ca0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00037ca0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00037cb0:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00037cb0:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00037cc0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037cc0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037cd0:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600037cd0:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
00037ce0:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········00037ce0:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00037cf0:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00037cf0:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00037d00:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00037d00:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00037d10:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00037d10:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00037d20:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00037d20:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00037d30:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00037d30:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00037d40:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00037d40:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00037d50:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00037d50:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
Offset 15061, 200 lines modifiedOffset 15061, 200 lines modified
0003ad40:·2d74·6172·6765·743d·2223·6964·6d35·3232··-target="#idm5220003ad40:·2d74·6172·6765·743d·2223·6964·6d35·3232··-target="#idm522
0003ad50:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·0003ad50:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·
0003ad60:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003ad60:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003ad70:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003ad70:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003ad80:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003ad80:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003ad90:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003ad90:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003ada0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003ada0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003adb0:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip0003adb0:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn
0003adc0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003adc0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003add0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003add0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003ade0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003ade0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003adf0:·7365·2220·6964·3d22·6964·6d35·3232·3222··se"·id="idm5222"0003adf0:·6170·7365·2220·6964·3d22·6964·6d35·3232··apse"·id="idm522
0003ae00:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003ae00:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class=
0003ae10:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003ae10:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003ae20:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003ae20:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003ae30:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003ae30:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003ae40:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003ae40:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003ae50:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l0003ae50:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003ae60:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003ae60:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003ae70:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<0003ae70:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003ae80:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003ae80:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003ae90:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb0003ae90:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
0003aea0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal0003aea0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
0003aeb0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>0003aeb0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
0003aec0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t0003aec0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0003aed0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td0003aed0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
0003aee0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p0003aee0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003aef0:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack
 0003af00:·6167·6520·2d2d·6164·643d·6169·6465·0a3c··age·--add=aide.<
0003aef0:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include 
0003af00:·2069·6e73·7461·6c6c·5f61·6964·650a·0a63···install_aide..c 
0003af10:·6c61·7373·2069·6e73·7461·6c6c·5f61·6964··lass·install_aid 
0003af20:·6520·7b0a·2020·7061·636b·6167·6520·7b20··e·{.··package·{· 
0003af30:·2761·6964·6527·3a0a·2020·2020·656e·7375··'aide':.····ensu 
0003af40:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal 
0003af50:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co 
0003af60:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003af70:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003af80:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003af90:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003afa0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003afb0:·646d·3532·3233·2220·7461·6269·6e64·6578··dm5223"·tabindex 
0003afc0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003afd0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003afe0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003aff0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003b000:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003b010:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
0003b020:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003b030:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003b040:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003b050:·6c61·7073·6522·2069·643d·2269·646d·3532··lapse"·id="idm52 
0003b060:·3233·223e·3c74·6162·6c65·2063·6c61·7373··23"><table·class 
0003b070:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003b080:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003b090:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003b0a0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003b0b0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003b0c0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b0d0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003b0e0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003b0f0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b100:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003b110:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
0003b120:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003b130:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003b140:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003b150:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re 
0003b160:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app 
0003b170:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in· 
0003b180:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform 
0003b190:·730a·6966·205b·2021·202d·6620·2f2e·646f··s.if·[·!·-f·/.do 
0003b1a0:·636b·6572·656e·7620·5d20·2661·6d70·3b26··ckerenv·]·&amp;& 
0003b1b0:·616d·703b·205b·2021·202d·6620·2f72·756e··amp;·[·!·-f·/run 
0003b1c0:·2f2e·636f·6e74·6169·6e65·7265·6e76·205d··/.containerenv·] 
0003b1d0:·3b20·7468·656e·0a0a·6966·2021·2072·706d··;·then..if·!·rpm 
0003b1e0:·202d·7120·2d2d·7175·6965·7420·2261·6964···-q·--quiet·"aid 
0003b1f0:·6522·203b·2074·6865·6e0a·2020·2020·7975··e"·;·then.····yu 
0003b200:·6d20·696e·7374·616c·6c20·2d79·2022·6169··m·install·-y·"ai 
0003b210:·6465·220a·6669·0a0a·656c·7365·0a20·2020··de".fi..else.··· 
0003b220:·2026·6774·3b26·616d·703b·3220·6563·686f···&gt;&amp;2·echo 
0003b230:·2027·5265·6d65·6469·6174·696f·6e20·6973···'Remediation·is 
0003b240:·206e·6f74·2061·7070·6c69·6361·626c·652c···not·applicable, 
0003b250:·206e·6f74·6869·6e67·2077·6173·2064·6f6e···nothing·was·don 
0003b260:·6527·0a66·690a·3c2f·636f·6465·3e3c·2f70··e'.fi.</code></p 
0003b270:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003b280:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003b290:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003b2a0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003b2b0:·7461·7267·6574·3d22·2369·646d·3532·3234··target="#idm5224 
0003b2c0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003b2d0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003b2e0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003b2f0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003b300:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003b310:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003b320:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip 
0003b330:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003b340:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b350:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b360:·7365·2220·6964·3d22·6964·6d35·3232·3422··se"·id="idm5224" 
0003b370:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003b380:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003b390:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003b3a0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003b3b0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003b3c0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003b3d0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b3e0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003b3f0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
Max diff block lines reached; 30181355/30208871 bytes (99.91%) of diff not shown.
2.46 MB
html2text {}
Max HTML report size reached
31.2 MB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-stig_gui.html
    
Offset 14302, 16 lines modifiedOffset 14302, 16 lines modified
00037dd0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h00037dd0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h
00037de0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver00037de0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver
00037df0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.00037df0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.
00037e00:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p00037e00:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p
00037e10:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong00037e10:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong
00037e20:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.00037e20:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.
00037e30:·2020·2020·2020·2020·2020·2020·2020·2020··················00037e30:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037e40:·2020·2020·2861·7320·6f66·2032·3032·362d······(as·of·2026-00037e40:·2020·2020·2861·7320·6f66·2032·3032·342d······(as·of·2024-
00037e50:·3031·2d30·3829·0a20·2020·2020·2020·2020··01-08).·········00037e50:·3132·2d30·3729·0a20·2020·2020·2020·2020··12-07).·········
00037e60:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul00037e60:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul
00037e70:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table00037e70:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table
00037e80:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h200037e80:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2
00037e90:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href00037e90:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href
00037ea0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg00037ea0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg
00037eb0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_00037eb0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
00037ec0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy00037ec0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy
Offset 15079, 200 lines modifiedOffset 15079, 200 lines modified
0003ae60:·6765·743d·2223·6964·6d35·3232·3222·2074··get="#idm5222"·t0003ae60:·6765·743d·2223·6964·6d35·3232·3222·2074··get="#idm5222"·t
0003ae70:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003ae70:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003ae80:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003ae80:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003ae90:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003ae90:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003aea0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003aea0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003aeb0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003aeb0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003aec0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003aec0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003aed0:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·0003aed0:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe
0003aee0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003aee0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003aef0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003aef0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003af00:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003af00:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003af10:·6964·3d22·6964·6d35·3232·3222·3e3c·7461··id="idm5222"><ta0003af10:·2220·6964·3d22·6964·6d35·3232·3222·3e3c··"·id="idm5222"><
0003af20:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0003af20:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003af30:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0003af30:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003af40:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0003af40:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003af50:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0003af50:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003af60:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003af60:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003af70:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003af70:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003af80:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003af80:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003af90:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>0003af90:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003afa0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003afa0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003afb0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:0003afb0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
0003afc0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</0003afc0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
0003afd0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003afd0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003afe0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003afe0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
0003aff0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t0003aff0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
0003b000:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003b000:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003b010:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 0003b020:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod
0003b010:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins 
0003b020:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class 
0003b030:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{. 
0003b040:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid 
0003b050:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·= 
0003b060:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed' 
0003b070:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code>< 
0003b080:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003b090:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003b0a0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003b0b0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003b0c0:·612d·7461·7267·6574·3d22·2369·646d·3532··a-target="#idm52 
0003b0d0:·3233·2220·7461·6269·6e64·6578·3d22·3022··23"·tabindex="0" 
0003b0e0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003b0f0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003b100:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003b110:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003b120:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003b130:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
0003b140:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
0003b150:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003b160:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003b170:·6522·2069·643d·2269·646d·3532·3233·223e··e"·id="idm5223"> 
0003b180:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003b190:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003b1a0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003b1b0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003b1c0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003b1d0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003b1e0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b1f0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003b200:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b210:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003b220:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0003b230:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
0003b240:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0003b250:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0003b260:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003b270:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi 
0003b280:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica 
0003b290:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert 
0003b2a0:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if 
0003b2b0:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker 
0003b2c0:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp; 
0003b2d0:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co 
0003b2e0:·6e74·6169·6e65·7265·6e76·205d·3b20·7468··ntainerenv·];·th 
0003b2f0:·656e·0a0a·6966·2021·2072·706d·202d·7120··en..if·!·rpm·-q· 
0003b300:·2d2d·7175·6965·7420·2261·6964·6522·203b··--quiet·"aide"·; 
0003b310:·2074·6865·6e0a·2020·2020·7975·6d20·696e···then.····yum·in 
0003b320:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide". 
0003b330:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt 
0003b340:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re 
0003b350:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not 
0003b360:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not 
0003b370:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f 
0003b380:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre>< 
0003b390:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003b3a0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003b3b0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003b3c0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003b3d0:·6574·3d22·2369·646d·3532·3234·2220·7461··et="#idm5224"·ta 
0003b3e0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003b3f0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003b400:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003b410:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003b420:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003b430:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003b440:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet· 
0003b450:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003b460:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003b470:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003b480:·6964·3d22·6964·6d35·3232·3422·3e3c·7461··id="idm5224"><ta 
0003b490:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003b4a0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003b4b0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003b4c0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003b4d0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003b4e0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003b4f0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b500:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003b510:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
Max diff block lines reached; 30133312/30160828 bytes (99.91%) of diff not shown.
2.45 MB
html2text {}
Max HTML report size reached
2.57 MB
./usr/share/doc/ssg-nondebian/ssg-openembedded-guide-expanded.html
    
Offset 14324, 15 lines modifiedOffset 14324, 15 lines modified
00037f30:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00037f30:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00037f40:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00037f40:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00037f50:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s00037f50:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00037f60:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00037f60:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00037f70:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00037f70:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00037f80:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00037f80:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00037f90:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00037f90:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00037fa0:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).00037fa0:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
00037fb0:·2020·2020·2020·2020·2020·2020·2020·2020··················00037fb0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037fc0:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00037fc0:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00037fd0:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00037fd0:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00037fe0:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00037fe0:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00037ff0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00037ff0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00038000:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00038000:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00038010:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00038010:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
Offset 15131, 80 lines modifiedOffset 15131, 80 lines modified
0003b1a0:·612d·7461·7267·6574·3d22·2369·646d·3130··a-target="#idm100003b1a0:·612d·7461·7267·6574·3d22·2369·646d·3130··a-target="#idm10
0003b1b0:·3636·2220·7461·6269·6e64·6578·3d22·3022··66"·tabindex="0"0003b1b0:·3636·2220·7461·6269·6e64·6578·3d22·3022··66"·tabindex="0"
0003b1c0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003b1c0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003b1d0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003b1d0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003b1e0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003b1e0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003b1f0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003b1f0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003b200:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003b200:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003b210:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn 
0003b220:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003b230:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003b240:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003b250:·6170·7365·2220·6964·3d22·6964·6d31·3036··apse"·id="idm106 
0003b260:·3622·3e3c·7461·626c·6520·636c·6173·733d··6"><table·class= 
0003b270:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003b280:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003b290:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003b2a0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003b2b0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003b2c0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b2d0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003b2e0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b2f0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003b300:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003b310:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
0003b320:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003b330:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</0003b210:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl
 0003b220:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet·
 0003b230:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003b240:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003b250:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003b260:·6964·3d22·6964·6d31·3036·3622·3e3c·7072··id="idm1066"><pr
 0003b270:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa
 0003b280:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai
 0003b290:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"*
 0003b2a0:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre><
 0003b2b0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0003b2c0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0003b2d0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0003b2e0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0003b2f0:·6574·3d22·2369·646d·3130·3637·2220·7461··et="#idm1067"·ta
 0003b300:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 0003b310:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 0003b320:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 0003b330:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 0003b340:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 0003b350:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003b360:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet·
 0003b370:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003b380:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003b390:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003b3a0:·6964·3d22·6964·6d31·3036·3722·3e3c·7461··id="idm1067"><ta
 0003b3b0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0003b3c0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0003b3d0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0003b3e0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0003b3f0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0003b400:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003b340:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>0003b410:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b420:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003b430:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003b440:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 0003b450:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 0003b460:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b470:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0003b480:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0003b490:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003b4a0:·636f·6465·3e2d·206e·616d·653a·2045·6e73··code>-·name:·Ens
 0003b4b0:·7572·6520·6169·6465·2069·7320·696e·7374··ure·aide·is·inst
0003b350:·3c70·7265·3e3c·636f·6465·3e2d·206e·616d··<pre><code>-·nam 
0003b360:·653a·2045·6e73·7572·6520·6169·6465·2069··e:·Ensure·aide·i 
0003b370:·7320·696e·7374·616c·6c65·640a·2020·7061··s·installed.··pa 
0003b380:·636b·6167·653a·0a20·2020·206e·616d·653a··ckage:.····name: 
0003b390:·2061·6964·650a·2020·2020·7374·6174·653a···aide.····state: 
0003b3a0:·2070·7265·7365·6e74·0a20·2077·6865·6e3a···present.··when: 
0003b3b0:·2061·6e73·6962·6c65·5f76·6972·7475·616c···ansible_virtual 
0003b3c0:·697a·6174·696f·6e5f·7479·7065·206e·6f74··ization_type·not 
0003b3d0:·2069·6e20·5b22·646f·636b·6572·222c·2022···in·["docker",·" 
0003b3e0:·6c78·6322·2c20·226f·7065·6e76·7a22·2c20··lxc",·"openvz",· 
0003b3f0:·2270·6f64·6d61·6e22·2c20·2263·6f6e·7461··"podman",·"conta 
0003b400:·696e·6572·225d·0a20·2074·6167·733a·0a20··iner"].··tags:.· 
0003b410:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3 
0003b420:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53 
0003b430:·2d43·4d2d·3628·6129·0a20·202d·2050·4349··-CM-6(a).··-·PCI 
0003b440:·2d44·5353·2d52·6571·2d31·312e·350a·2020··-DSS-Req-11.5.·· 
0003b450:·2d20·5043·492d·4453·5376·342d·3131·2e35··-·PCI-DSSv4-11.5 
0003b460:·2e32·0a20·202d·2065·6e61·626c·655f·7374··.2.··-·enable_st 
0003b470:·7261·7465·6779·0a20·202d·206c·6f77·5f63··rategy.··-·low_c 
0003b480:·6f6d·706c·6578·6974·790a·2020·2d20·6c6f··omplexity.··-·lo 
0003b490:·775f·6469·7372·7570·7469·6f6e·0a20·202d··w_disruption.··- 
0003b4a0:·206d·6564·6975·6d5f·7365·7665·7269·7479···medium_severity 
0003b4b0:·0a20·202d·206e·6f5f·7265·626f·6f74·5f6e··.··-·no_reboot_n 
0003b4c0:·6565·6465·640a·2020·2d20·7061·636b·6167··eeded.··-·packag0003b4c0:·616c·6c65·640a·2020·7061·636b·6167·653a··alled.··package:
0003b4d0:·655f·6169·6465·5f69·6e73·7461·6c6c·6564··e_aide_installed 
0003b4e0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003b4f0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b500:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b510:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b520:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b530:·743d·2223·6964·6d31·3036·3722·2074·6162··t="#idm1067"·tab 
0003b540:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b550:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b560:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b570:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b580:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b590:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O 
0003b5a0:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint 
0003b5b0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003b5c0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b5d0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b5e0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b5f0:·3130·3637·223e·3c70·7265·3e3c·636f·6465··1067"><pre><code 
Max diff block lines reached; 2395058/2405874 bytes (99.55%) of diff not shown.
280 KB
html2text {}
    
Offset 43, 15 lines modifiedOffset 43, 15 lines modified
43 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*43 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
44 ····*·cpe:/o:openembedded:harden:44 ····*·cpe:/o:openembedded:harden:
45 ····*·cpe:/o:openembedded:nodistro:45 ····*·cpe:/o:openembedded:nodistro:
46 ····*·cpe:/o:openembedded:petalinux:46 ····*·cpe:/o:openembedded:petalinux:
47 ····*·cpe:/o:openembedded:poky:47 ····*·cpe:/o:openembedded:poky:
48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
49 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8449 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)50 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s52 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e53 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l54 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
55 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n55 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
56 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g56 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
57 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s57 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 132, 14 lines modifiedOffset 132, 19 lines modified
132 include·install_aide132 include·install_aide
  
133 class·install_aide·{133 class·install_aide·{
134 ··package·{·'aide':134 ··package·{·'aide':
135 ····ensure·=>·'installed',135 ····ensure·=>·'installed',
136 ··}136 ··}
137 }137 }
 138 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 139 [[packages]]
 140 name·=·"aide"
 141 version·=·"*"
138 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
139 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
140 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
141 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
142 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
143 -·name:·Ensure·aide·is·installed147 -·name:·Ensure·aide·is·installed
144 ··package:148 ··package:
Offset 153, 19 lines modifiedOffset 158, 14 lines modified
153 ··-·PCI-DSSv4-11.5.2158 ··-·PCI-DSSv4-11.5.2
154 ··-·enable_strategy159 ··-·enable_strategy
155 ··-·low_complexity160 ··-·low_complexity
156 ··-·low_disruption161 ··-·low_disruption
157 ··-·medium_severity162 ··-·medium_severity
158 ··-·no_reboot_needed163 ··-·no_reboot_needed
159 ··-·package_aide_installed164 ··-·package_aide_installed
160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
161 [[packages]] 
162 name·=·"aide" 
163 version·=·"*" 
164 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·P\x8Pe\x8er\x8ri\x8io\x8od\x8di\x8ic\x8c·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8ti\x8io\x8on\x8n·o\x8of\x8f·A\x8AI\x8ID\x8DE\x8E·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*165 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·P\x8Pe\x8er\x8ri\x8io\x8od\x8di\x8ic\x8c·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8ti\x8io\x8on\x8n·o\x8of\x8f·A\x8AI\x8ID\x8DE\x8E·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
165 At·a·minimum,·AIDE·should·be·configured·to·run·a·weekly·scan.·To·implement·a·daily·execution·of166 At·a·minimum,·AIDE·should·be·configured·to·run·a·weekly·scan.·To·implement·a·daily·execution·of
166 AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/crontab:167 AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/crontab:
167 05·4·*·*·*·root·/usr/sbin/aide·--check168 05·4·*·*·*·root·/usr/sbin/aide·--check
168 To·implement·a·weekly·execution·of·AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/169 To·implement·a·weekly·execution·of·AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/
169 crontab:170 crontab:
170 05·4·*·*·0·root·/usr/sbin/aide·--check171 05·4·*·*·0·root·/usr/sbin/aide·--check
Offset 359, 33 lines modifiedOffset 359, 14 lines modified
359 ············_\x8i_\x8s_\x8m······1446359 ············_\x8i_\x8s_\x8m······1446
360 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1360 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1
361 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)361 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)
362 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,362 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,
363 ·····················FCS_TLSC_EXT.1363 ·····················FCS_TLSC_EXT.1
364 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174364 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
365 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7365 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7
366 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
367 var_system_crypto_policy='DEFAULT' 
  
  
368 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
369 rc=$? 
  
370 if·test·"$rc"·=·127;·then 
371 »       echo·"$stderr_of_call"·>&2 
372 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
373 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
374 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
375 »       false··#·end·with·an·error·code 
376 elif·test·"$rc"·!=·0;·then 
377 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
378 »       false··#·end·with·an·error·code 
379 fi 
380 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8366 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
381 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low367 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
382 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low368 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
383 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false369 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
384 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict370 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
385 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable371 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
386 ··set_fact:372 ··set_fact:
Offset 428, 14 lines modifiedOffset 409, 33 lines modified
428 ··-·PCI-DSSv4-2.2.7409 ··-·PCI-DSSv4-2.2.7
429 ··-·configure_crypto_policy410 ··-·configure_crypto_policy
430 ··-·high_severity411 ··-·high_severity
431 ··-·low_complexity412 ··-·low_complexity
432 ··-·low_disruption413 ··-·low_disruption
433 ··-·no_reboot_needed414 ··-·no_reboot_needed
434 ··-·restrict_strategy415 ··-·restrict_strategy
 416 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 417 var_system_crypto_policy='DEFAULT'
  
  
 418 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null)
 419 rc=$?
  
 420 if·test·"$rc"·=·127;·then
 421 »       echo·"$stderr_of_call"·>&2
 422 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2
 423 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2
 424 »       echo·"to·see·what·package·to·(re)install"·>&2
  
 425 »       false··#·end·with·an·error·code
 426 elif·test·"$rc"·!=·0;·then
 427 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
 428 »       false··#·end·with·an·error·code
 429 fi
435 Group  ·Updating·Software·  Group·contains·1·rule430 Group  ·Updating·Software·  Group·contains·1·rule
436 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·dnf·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also431 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·dnf·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also
437 provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called432 provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called
438 S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.433 S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.
  
439 OpenEmbedded·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records434 OpenEmbedded·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records
440 metadata·of·installed·packages.·Consistently·using·dnf·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all435 metadata·of·installed·packages.·Consistently·using·dnf·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all
Offset 640, 20 lines modifiedOffset 640, 14 lines modified
640 ···········Display·of·a·standardized·and·approved·use·notification·before·granting·access·to·the640 ···········Display·of·a·standardized·and·approved·use·notification·before·granting·access·to·the
641 ···········operating·system·ensures·privacy·and·security·notification·verbiage·used·is·consistent641 ···········operating·system·ensures·privacy·and·security·notification·verbiage·used·is·consistent
642 Rationale:·with·applicable·federal·laws,·Executive·Orders,·directives,·policies,·regulations,642 Rationale:·with·applicable·federal·laws,·Executive·Orders,·directives,·policies,·regulations,
Max diff block lines reached; 280786/286559 bytes (97.99%) of diff not shown.
2.51 MB
./usr/share/doc/ssg-nondebian/ssg-openembedded-guide-standard.html
    
Offset 14319, 15 lines modifiedOffset 14319, 15 lines modified
00037ee0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00037ee0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00037ef0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00037ef0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00037f00:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s00037f00:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00037f10:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00037f10:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00037f20:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00037f20:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00037f30:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00037f30:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00037f40:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00037f40:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00037f50:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).00037f50:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
00037f60:·2020·2020·2020·2020·2020·2020·2020·2020··················00037f60:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037f70:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00037f70:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00037f80:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00037f80:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00037f90:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00037f90:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00037fa0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00037fa0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00037fb0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00037fb0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00037fc0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00037fc0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
Offset 15126, 80 lines modifiedOffset 15126, 80 lines modified
0003b150:·2d74·6172·6765·743d·2223·6964·6d31·3036··-target="#idm1060003b150:·2d74·6172·6765·743d·2223·6964·6d31·3036··-target="#idm106
0003b160:·3622·2074·6162·696e·6465·783d·2230·2220··6"·tabindex="0"·0003b160:·3622·2074·6162·696e·6465·783d·2230·2220··6"·tabindex="0"·
0003b170:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003b170:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003b180:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003b180:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003b190:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003b190:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003b1a0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003b1a0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003b1b0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003b1b0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003b1c0:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni 
0003b1d0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003b1e0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003b1f0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003b200:·7073·6522·2069·643d·2269·646d·3130·3636··pse"·id="idm1066 
0003b210:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003b220:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003b230:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003b240:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003b250:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003b260:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003b270:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003b280:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003b290:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b2a0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003b2b0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0003b2c0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
0003b2d0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003b1c0:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu
 0003b1d0:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·.
 0003b1e0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003b1f0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003b200:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003b210:·643d·2269·646d·3130·3636·223e·3c70·7265··d="idm1066"><pre
 0003b220:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag
 0003b230:·6573·5d5d·0a6e·616d·6520·3d20·2261·6964··es]].name·=·"aid
 0003b240:·6522·0a76·6572·7369·6f6e·203d·2022·2a22··e".version·=·"*"
 0003b250:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 0003b260:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 0003b270:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 0003b280:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 0003b290:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 0003b2a0:·743d·2223·6964·6d31·3036·3722·2074·6162··t="#idm1067"·tab
 0003b2b0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 0003b2c0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 0003b2d0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 0003b2e0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 0003b2f0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 0003b300:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
 0003b310:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.
 0003b320:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003b330:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003b340:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003b350:·643d·2269·646d·3130·3637·223e·3c74·6162··d="idm1067"><tab
 0003b360:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0003b370:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0003b380:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 0003b390:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 0003b3a0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 0003b3b0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003b3c0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0003b3d0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 0003b3e0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003b3f0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
0003b2e0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003b400:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 0003b410:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 0003b420:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 0003b430:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 0003b440:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003b450:·6f64·653e·2d20·6e61·6d65·3a20·456e·7375··ode>-·name:·Ensu
 0003b460:·7265·2061·6964·6520·6973·2069·6e73·7461··re·aide·is·insta
0003b2f0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003b300:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name 
0003b310:·3a20·456e·7375·7265·2061·6964·6520·6973··:·Ensure·aide·is 
0003b320:·2069·6e73·7461·6c6c·6564·0a20·2070·6163···installed.··pac 
0003b330:·6b61·6765·3a0a·2020·2020·6e61·6d65·3a20··kage:.····name:· 
0003b340:·6169·6465·0a20·2020·2073·7461·7465·3a20··aide.····state:· 
0003b350:·7072·6573·656e·740a·2020·7768·656e·3a20··present.··when:· 
0003b360:·616e·7369·626c·655f·7669·7274·7561·6c69··ansible_virtuali 
0003b370:·7a61·7469·6f6e·5f74·7970·6520·6e6f·7420··zation_type·not· 
0003b380:·696e·205b·2264·6f63·6b65·7222·2c20·226c··in·["docker",·"l 
0003b390:·7863·222c·2022·6f70·656e·767a·222c·2022··xc",·"openvz",·" 
0003b3a0:·706f·646d·616e·222c·2022·636f·6e74·6169··podman",·"contai 
0003b3b0:·6e65·7222·5d0a·2020·7461·6773·3a0a·2020··ner"].··tags:.·· 
0003b3c0:·2d20·434a·4953·2d35·2e31·302e·312e·330a··-·CJIS-5.10.1.3. 
0003b3d0:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53- 
0003b3e0:·434d·2d36·2861·290a·2020·2d20·5043·492d··CM-6(a).··-·PCI- 
0003b3f0:·4453·532d·5265·712d·3131·2e35·0a20·202d··DSS-Req-11.5.··- 
0003b400:·2050·4349·2d44·5353·7634·2d31·312e·352e···PCI-DSSv4-11.5. 
0003b410:·320a·2020·2d20·656e·6162·6c65·5f73·7472··2.··-·enable_str 
0003b420:·6174·6567·790a·2020·2d20·6c6f·775f·636f··ategy.··-·low_co 
0003b430:·6d70·6c65·7869·7479·0a20·202d·206c·6f77··mplexity.··-·low 
0003b440:·5f64·6973·7275·7074·696f·6e0a·2020·2d20··_disruption.··-· 
0003b450:·6d65·6469·756d·5f73·6576·6572·6974·790a··medium_severity. 
0003b460:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne 
0003b470:·6564·6564·0a20·202d·2070·6163·6b61·6765··eded.··-·package0003b470:·6c6c·6564·0a20·2070·6163·6b61·6765·3a0a··lled.··package:.
0003b480:·5f61·6964·655f·696e·7374·616c·6c65·640a··_aide_installed. 
0003b490:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003b4a0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003b4b0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003b4c0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003b4d0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003b4e0:·3d22·2369·646d·3130·3637·2220·7461·6269··="#idm1067"·tabi 
0003b4f0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003b500:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003b510:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003b520:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003b530:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003b540:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS 
0003b550:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint· 
0003b560:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003b570:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b580:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b590:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1 
0003b5a0:·3036·3722·3e3c·7072·653e·3c63·6f64·653e··067"><pre><code> 
Max diff block lines reached; 2337318/2348134 bytes (99.54%) of diff not shown.
273 KB
html2text {}
    
Offset 41, 15 lines modifiedOffset 41, 15 lines modified
41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
42 ····*·cpe:/o:openembedded:harden:42 ····*·cpe:/o:openembedded:harden:
43 ····*·cpe:/o:openembedded:nodistro:43 ····*·cpe:/o:openembedded:nodistro:
44 ····*·cpe:/o:openembedded:petalinux:44 ····*·cpe:/o:openembedded:petalinux:
45 ····*·cpe:/o:openembedded:poky:45 ····*·cpe:/o:openembedded:poky:
46 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
47 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8447 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
48 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)48 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
49 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*49 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
50 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s50 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
51 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e51 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
52 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l52 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
53 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n53 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
54 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g54 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
55 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s55 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 130, 14 lines modifiedOffset 130, 19 lines modified
130 include·install_aide130 include·install_aide
  
131 class·install_aide·{131 class·install_aide·{
132 ··package·{·'aide':132 ··package·{·'aide':
133 ····ensure·=>·'installed',133 ····ensure·=>·'installed',
134 ··}134 ··}
135 }135 }
 136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 137 [[packages]]
 138 name·=·"aide"
 139 version·=·"*"
136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
141 -·name:·Ensure·aide·is·installed145 -·name:·Ensure·aide·is·installed
142 ··package:146 ··package:
Offset 151, 19 lines modifiedOffset 156, 14 lines modified
151 ··-·PCI-DSSv4-11.5.2156 ··-·PCI-DSSv4-11.5.2
152 ··-·enable_strategy157 ··-·enable_strategy
153 ··-·low_complexity158 ··-·low_complexity
154 ··-·low_disruption159 ··-·low_disruption
155 ··-·medium_severity160 ··-·medium_severity
156 ··-·no_reboot_needed161 ··-·no_reboot_needed
157 ··-·package_aide_installed162 ··-·package_aide_installed
158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
159 [[packages]] 
160 name·=·"aide" 
161 version·=·"*" 
162 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·P\x8Pe\x8er\x8ri\x8io\x8od\x8di\x8ic\x8c·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8ti\x8io\x8on\x8n·o\x8of\x8f·A\x8AI\x8ID\x8DE\x8E·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*163 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·P\x8Pe\x8er\x8ri\x8io\x8od\x8di\x8ic\x8c·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8ti\x8io\x8on\x8n·o\x8of\x8f·A\x8AI\x8ID\x8DE\x8E·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
163 At·a·minimum,·AIDE·should·be·configured·to·run·a·weekly·scan.·To·implement·a·daily·execution·of164 At·a·minimum,·AIDE·should·be·configured·to·run·a·weekly·scan.·To·implement·a·daily·execution·of
164 AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/crontab:165 AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/crontab:
165 05·4·*·*·*·root·/usr/sbin/aide·--check166 05·4·*·*·*·root·/usr/sbin/aide·--check
166 To·implement·a·weekly·execution·of·AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/167 To·implement·a·weekly·execution·of·AIDE·at·4:05am·using·cron,·add·the·following·line·to·/etc/
167 crontab:168 crontab:
168 05·4·*·*·0·root·/usr/sbin/aide·--check169 05·4·*·*·0·root·/usr/sbin/aide·--check
Offset 517, 20 lines modifiedOffset 517, 14 lines modified
517 ···········Display·of·a·standardized·and·approved·use·notification·before·granting·access·to·the517 ···········Display·of·a·standardized·and·approved·use·notification·before·granting·access·to·the
518 ···········operating·system·ensures·privacy·and·security·notification·verbiage·used·is·consistent518 ···········operating·system·ensures·privacy·and·security·notification·verbiage·used·is·consistent
519 Rationale:·with·applicable·federal·laws,·Executive·Orders,·directives,·policies,·regulations,519 Rationale:·with·applicable·federal·laws,·Executive·Orders,·directives,·policies,·regulations,
520 ···········standards,·and·guidance.520 ···········standards,·and·guidance.
521 ···········Proper·group·ownership·will·ensure·that·only·root·user·can·modify·the·banner.521 ···········Proper·group·ownership·will·ensure·that·only·root·user·can·modify·the·banner.
522 Severity: ·medium522 Severity: ·medium
523 Rule·ID:···xccdf_org.ssgproject.content_rule_file_groupowner_etc_issue523 Rule·ID:···xccdf_org.ssgproject.content_rule_file_groupowner_etc_issue
524 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
525 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
526 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
527 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
528 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure 
529 chgrp·-L·0·/etc/issue 
530 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8524 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
531 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low525 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
532 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low526 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
533 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false527 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
534 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure528 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
535 -·name:·Test·for·existence·/etc/issue529 -·name:·Test·for·existence·/etc/issue
536 ··stat:530 ··stat:
Offset 552, 30 lines modifiedOffset 546, 30 lines modified
552 ··tags:546 ··tags:
553 ··-·configure_strategy547 ··-·configure_strategy
554 ··-·file_groupowner_etc_issue548 ··-·file_groupowner_etc_issue
555 ··-·low_complexity549 ··-·low_complexity
556 ··-·low_disruption550 ··-·low_disruption
557 ··-·medium_severity551 ··-·medium_severity
558 ··-·no_reboot_needed552 ··-·no_reboot_needed
 553 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 554 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 555 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 556 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 557 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
 558 chgrp·-L·0·/etc/issue
559 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·o\x8of\x8f·M\x8Me\x8es\x8ss\x8sa\x8ag\x8ge\x8e·o\x8of\x8f·t\x8th\x8he\x8e·D\x8Da\x8ay\x8y·B\x8Ba\x8an\x8nn\x8ne\x8er\x8r·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*559 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·o\x8of\x8f·M\x8Me\x8es\x8ss\x8sa\x8ag\x8ge\x8e·o\x8of\x8f·t\x8th\x8he\x8e·D\x8Da\x8ay\x8y·B\x8Ba\x8an\x8nn\x8ne\x8er\x8r·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
560 To·properly·set·the·group·owner·of·/etc/motd,·run·the·command:560 To·properly·set·the·group·owner·of·/etc/motd,·run·the·command:
561 $·sudo·chgrp·root·/etc/motd561 $·sudo·chgrp·root·/etc/motd
562 ···········Display·of·a·standardized·and·approved·use·notification·before·granting·access·to·the562 ···········Display·of·a·standardized·and·approved·use·notification·before·granting·access·to·the
563 ···········operating·system·ensures·privacy·and·security·notification·verbiage·used·is·consistent563 ···········operating·system·ensures·privacy·and·security·notification·verbiage·used·is·consistent
564 Rationale:·with·applicable·federal·laws,·Executive·Orders,·directives,·policies,·regulations,564 Rationale:·with·applicable·federal·laws,·Executive·Orders,·directives,·policies,·regulations,
565 ···········standards,·and·guidance.565 ···········standards,·and·guidance.
566 ···········Proper·group·ownership·will·ensure·that·only·root·user·can·modify·the·banner.566 ···········Proper·group·ownership·will·ensure·that·only·root·user·can·modify·the·banner.
567 Severity: ·medium567 Severity: ·medium
568 Rule·ID:···xccdf_org.ssgproject.content_rule_file_groupowner_etc_motd568 Rule·ID:···xccdf_org.ssgproject.content_rule_file_groupowner_etc_motd
569 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
570 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
571 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
572 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
573 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure 
574 chgrp·-L·0·/etc/motd 
575 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8569 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
576 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low570 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
577 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low571 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
578 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false572 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
579 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure573 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
580 -·name:·Test·for·existence·/etc/motd574 -·name:·Test·for·existence·/etc/motd
581 ··stat:575 ··stat:
Offset 597, 30 lines modifiedOffset 591, 30 lines modified
597 ··tags:591 ··tags:
598 ··-·configure_strategy592 ··-·configure_strategy
599 ··-·file_groupowner_etc_motd593 ··-·file_groupowner_etc_motd
600 ··-·low_complexity594 ··-·low_complexity
601 ··-·low_disruption595 ··-·low_disruption
602 ··-·medium_severity596 ··-·medium_severity
603 ··-·no_reboot_needed597 ··-·no_reboot_needed
 598 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 599 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 600 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 601 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 602 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
 603 chgrp·-L·0·/etc/motd
Max diff block lines reached; 273512/279459 bytes (97.87%) of diff not shown.
3.9 MB
./usr/share/doc/ssg-nondebian/ssg-openeuler2203-guide-standard.html
    
Offset 14317, 16 lines modifiedOffset 14317, 16 lines modified
00037ec0:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><00037ec0:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><
00037ed0:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio00037ed0:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio
00037ee0:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.700037ee0:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.7
00037ef0:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u00037ef0:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u
00037f00:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr00037f00:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr
00037f10:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···00037f10:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···
00037f20:·2020·2020·2020·2020·2020·2020·2020·2020··················00037f20:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037f30:·2028·6173·206f·6620·3230·3236·2d30·312d···(as·of·2026-01-00037f30:·2028·6173·206f·6620·3230·3234·2d31·322d···(as·of·2024-12-
00037f40:·3038·290a·2020·2020·2020·2020·2020·2020··08).············00037f40:·3037·290a·2020·2020·2020·2020·2020·2020··07).············
00037f50:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></00037f50:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></
00037f60:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of00037f60:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of
00037f70:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o00037f70:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o
00037f80:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#00037f80:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#
00037f90:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro00037f90:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro
00037fa0:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro00037fa0:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro
00037fb0:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste00037fb0:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste
Offset 15151, 81 lines modifiedOffset 15151, 81 lines modified
0003b2e0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b2e0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b2f0:·3d22·2369·646d·3131·3234·2220·7461·6269··="#idm1124"·tabi0003b2f0:·3d22·2369·646d·3131·3234·2220·7461·6269··="#idm1124"·tabi
0003b300:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b300:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b310:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b310:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b320:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b320:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b330:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b330:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b340:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b340:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b350:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003b350:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
0003b360:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
0003b370:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b380:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b390:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b3a0:·3d22·6964·6d31·3132·3422·3e3c·7461·626c··="idm1124"><tabl 
0003b3b0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003b3c0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003b3d0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003b3e0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003b3f0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003b400:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b410:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003b420:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003b430:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b440:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003b450:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003b460:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003b470:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003b360:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
 0003b370:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003b380:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003b390:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b3a0:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1
 0003b3b0:·3132·3422·3e3c·7072·653e·3c63·6f64·653e··124"><pre><code>
 0003b3c0:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 0003b3d0:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers
 0003b3e0:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code
 0003b3f0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 0003b400:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 0003b410:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 0003b420:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 0003b430:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 0003b440:·3131·3235·2220·7461·6269·6e64·6578·3d22··1125"·tabindex="
 0003b450:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 0003b460:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 0003b470:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 0003b480:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 0003b490:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0003b4a0:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible·
 0003b4b0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003b4c0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003b4d0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b4e0:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1
 0003b4f0:·3132·3522·3e3c·7461·626c·6520·636c·6173··125"><table·clas
 0003b500:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003b510:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003b520:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003b530:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003b540:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003b550:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003b560:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003b570:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0003b580:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b590:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003b480:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>0003b5a0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003b5b0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003b5c0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003b5d0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003b5e0:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n
 0003b5f0:·616d·653a·2045·6e73·7572·6520·6169·6465··ame:·Ensure·aide
 0003b600:·2069·7320·696e·7374·616c·6c65·640a·2020···is·installed.··
 0003b610:·7061·636b·6167·653a·0a20·2020·206e·616d··package:.····nam
 0003b620:·653a·2061·6964·650a·2020·2020·7374·6174··e:·aide.····stat
 0003b630:·653a·2070·7265·7365·6e74·0a20·2077·6865··e:·present.··whe
 0003b640:·6e3a·2061·6e73·6962·6c65·5f76·6972·7475··n:·ansible_virtu
 0003b650:·616c·697a·6174·696f·6e5f·7479·7065·206e··alization_type·n
 0003b660:·6f74·2069·6e20·5b22·646f·636b·6572·222c··ot·in·["docker",
 0003b670:·2022·6c78·6322·2c20·226f·7065·6e76·7a22···"lxc",·"openvz"
 0003b680:·2c20·2270·6f64·6d61·6e22·2c20·2263·6f6e··,·"podman",·"con
 0003b690:·7461·696e·6572·225d·0a20·2074·6167·733a··tainer"].··tags:
 0003b6a0:·0a20·202d·2043·4a49·532d·352e·3130·2e31··.··-·CJIS-5.10.1
 0003b6b0:·2e33·0a20·202d·204e·4953·542d·3830·302d··.3.··-·NIST-800-
 0003b6c0:·3533·2d43·4d2d·3628·6129·0a20·202d·2050··53-CM-6(a).··-·P
 0003b6d0:·4349·2d44·5353·2d52·6571·2d31·312e·350a··CI-DSS-Req-11.5.
 0003b6e0:·2020·2d20·5043·492d·4453·5376·342d·3131····-·PCI-DSSv4-11
 0003b6f0:·2e35·2e32·0a20·202d·2065·6e61·626c·655f··.5.2.··-·enable_
 0003b700:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low
 0003b710:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-·
 0003b720:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.·
 0003b730:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi
 0003b740:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot
 0003b750:·5f6e·6565·6465·640a·2020·2d20·7061·636b··_needed.··-·pack
 0003b760:·6167·655f·6169·6465·5f69·6e73·7461·6c6c··age_aide_install
0003b490:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003b4a0:·6465·3e2d·206e·616d·653a·2045·6e73·7572··de>-·name:·Ensur 
0003b4b0:·6520·6169·6465·2069·7320·696e·7374·616c··e·aide·is·instal 
0003b4c0:·6c65·640a·2020·7061·636b·6167·653a·0a20··led.··package:.· 
0003b4d0:·2020·206e·616d·653a·2061·6964·650a·2020·····name:·aide.·· 
0003b4e0:·2020·7374·6174·653a·2070·7265·7365·6e74····state:·present 
0003b4f0:·0a20·2077·6865·6e3a·2061·6e73·6962·6c65··.··when:·ansible 
0003b500:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_ 
0003b510:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do 
0003b520:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o 
0003b530:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman" 
0003b540:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].· 
0003b550:·2074·6167·733a·0a20·202d·2043·4a49·532d···tags:.··-·CJIS- 
0003b560:·352e·3130·2e31·2e33·0a20·202d·204e·4953··5.10.1.3.··-·NIS 
0003b570:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a) 
0003b580:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req 
0003b590:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS 
0003b5a0:·5376·342d·3131·2e35·2e32·0a20·202d·2065··Sv4-11.5.2.··-·e 
0003b5b0:·6e61·626c·655f·7374·7261·7465·6779·0a20··nable_strategy.· 
0003b5c0:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit 
Max diff block lines reached; 3674638/3685730 bytes (99.70%) of diff not shown.
394 KB
html2text {}
    
Offset 40, 15 lines modifiedOffset 40, 15 lines modified
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard
41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
42 ····*·cpe:/o:openEuler:openEuler:22.03LTS_SP1:ga:server42 ····*·cpe:/o:openEuler:openEuler:22.03LTS_SP1:ga:server
43 ····*·cpe:/o:openEuler:openEuler:22.03LTS_SP2:ga:server43 ····*·cpe:/o:openEuler:openEuler:22.03LTS_SP2:ga:server
44 ····*·cpe:/o:openEuler:openEuler:22.03LTS:ga:server44 ····*·cpe:/o:openEuler:openEuler:22.03LTS:ga:server
45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
46 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8446 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
50 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e50 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
51 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l51 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
52 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n52 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
53 ·········4.·_\x8K_\x8e_\x8r_\x8n_\x8e_\x8l_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n53 ·········4.·_\x8K_\x8e_\x8r_\x8n_\x8e_\x8l_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
54 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g54 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 134, 14 lines modifiedOffset 134, 19 lines modified
134 include·install_aide134 include·install_aide
  
135 class·install_aide·{135 class·install_aide·{
136 ··package·{·'aide':136 ··package·{·'aide':
137 ····ensure·=>·'installed',137 ····ensure·=>·'installed',
138 ··}138 ··}
139 }139 }
 140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 141 [[packages]]
 142 name·=·"aide"
 143 version·=·"*"
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low145 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low146 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false147 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable148 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
145 -·name:·Ensure·aide·is·installed149 -·name:·Ensure·aide·is·installed
146 ··package:150 ··package:
Offset 155, 19 lines modifiedOffset 160, 14 lines modified
155 ··-·PCI-DSSv4-11.5.2160 ··-·PCI-DSSv4-11.5.2
156 ··-·enable_strategy161 ··-·enable_strategy
157 ··-·low_complexity162 ··-·low_complexity
158 ··-·low_disruption163 ··-·low_disruption
159 ··-·medium_severity164 ··-·medium_severity
160 ··-·no_reboot_needed165 ··-·no_reboot_needed
161 ··-·package_aide_installed166 ··-·package_aide_installed
162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
163 [[packages]] 
164 name·=·"aide" 
165 version·=·"*" 
166 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*167 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
167 Run·the·following·command·to·generate·a·new·database:168 Run·the·following·command·to·generate·a·new·database:
168 $·sudo·/usr/sbin/aide·--init169 $·sudo·/usr/sbin/aide·--init
169 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the170 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
170 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of171 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of
171 these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance172 these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance
172 about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:173 about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 320, 33 lines modifiedOffset 320, 14 lines modified
320 ············_\x8i_\x8s_\x8m······1446320 ············_\x8i_\x8s_\x8m······1446
321 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1321 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1
322 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)322 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)
323 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,323 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,
324 ·····················FCS_TLSC_EXT.1324 ·····················FCS_TLSC_EXT.1
325 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174325 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
326 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7326 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7
327 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
328 var_system_crypto_policy='DEFAULT' 
  
  
329 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
330 rc=$? 
  
331 if·test·"$rc"·=·127;·then 
332 »       echo·"$stderr_of_call"·>&2 
333 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
334 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
335 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
336 »       false··#·end·with·an·error·code 
337 elif·test·"$rc"·!=·0;·then 
338 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
339 »       false··#·end·with·an·error·code 
340 fi 
341 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8327 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
342 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low328 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
343 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low329 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
344 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false330 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
345 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict331 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
346 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable332 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
347 ··set_fact:333 ··set_fact:
Offset 389, 14 lines modifiedOffset 370, 33 lines modified
389 ··-·PCI-DSSv4-2.2.7370 ··-·PCI-DSSv4-2.2.7
390 ··-·configure_crypto_policy371 ··-·configure_crypto_policy
391 ··-·high_severity372 ··-·high_severity
392 ··-·low_complexity373 ··-·low_complexity
393 ··-·low_disruption374 ··-·low_disruption
394 ··-·no_reboot_needed375 ··-·no_reboot_needed
395 ··-·restrict_strategy376 ··-·restrict_strategy
 377 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 378 var_system_crypto_policy='DEFAULT'
  
  
 379 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null)
 380 rc=$?
  
 381 if·test·"$rc"·=·127;·then
 382 »       echo·"$stderr_of_call"·>&2
 383 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2
 384 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2
 385 »       echo·"to·see·what·package·to·(re)install"·>&2
  
 386 »       false··#·end·with·an·error·code
 387 elif·test·"$rc"·!=·0;·then
 388 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
 389 »       false··#·end·with·an·error·code
 390 fi
396 Group  ·Sudo·  Group·contains·1·rule391 Group  ·Sudo·  Group·contains·1·rule
397 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain392 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Sudo,·which·stands·for·"su·'do'",·provides·the·ability·to·delegate·authority·to·certain
398 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,393 users,·groups·of·users,·or·system·administrators.·When·configured·for·system·users·and/or·groups,
399 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed394 Sudo·can·allow·a·user·or·group·to·execute·privileged·commands·that·normally·only·root·is·allowed
400 to·execute.395 to·execute.
  
401 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.396 For·more·information·on·Sudo·and·addition·Sudo·configuration·options,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8s\x8s_\x8u\x8u_\x8d\x8d_\x8o\x8o_\x8.\x8._\x8w\x8w_\x8s\x8s.
Offset 576, 20 lines modifiedOffset 576, 14 lines modified
576 ···········Display·of·a·standardized·and·approved·use·notification·before·granting·access·to·the576 ···········Display·of·a·standardized·and·approved·use·notification·before·granting·access·to·the
577 ···········operating·system·ensures·privacy·and·security·notification·verbiage·used·is·consistent577 ···········operating·system·ensures·privacy·and·security·notification·verbiage·used·is·consistent
578 Rationale:·with·applicable·federal·laws,·Executive·Orders,·directives,·policies,·regulations,578 Rationale:·with·applicable·federal·laws,·Executive·Orders,·directives,·policies,·regulations,
Max diff block lines reached; 397392/403256 bytes (98.55%) of diff not shown.
51.8 KB
./usr/share/doc/ssg-nondebian/ssg-opensuse-guide-standard.html
    
Offset 14317, 16 lines modifiedOffset 14317, 16 lines modified
00037ec0:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>00037ec0:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>
00037ed0:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi00037ed0:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi
00037ee0:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.00037ee0:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.
00037ef0:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><00037ef0:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><
00037f00:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d00037f00:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d
00037f10:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··00037f10:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··
00037f20:·2020·2020·2020·2020·2020·2020·2020·2020··················00037f20:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037f30:·2020·2861·7320·6f66·2032·3032·362d·3031····(as·of·2026-0100037f30:·2020·2861·7320·6f66·2032·3032·342d·3132····(as·of·2024-12
00037f40:·2d30·3829·0a20·2020·2020·2020·2020·2020··-08).···········00037f40:·2d30·3729·0a20·2020·2020·2020·2020·2020··-07).···········
00037f50:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><00037f50:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><
00037f60:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o00037f60:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o
00037f70:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><00037f70:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><
00037f80:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="00037f80:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="
00037f90:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr00037f90:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr
00037fa0:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr00037fa0:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr
00037fb0:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst00037fb0:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst
Offset 14927, 115 lines modifiedOffset 14927, 115 lines modified
0003a4e0:·6172·6765·743d·2223·6964·6d36·3538·3922··arget="#idm6589"0003a4e0:·6172·6765·743d·2223·6964·6d36·3538·3922··arget="#idm6589"
0003a4f0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003a4f0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003a500:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003a500:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003a510:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003a510:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003a520:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003a520:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003a530:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003a530:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003a540:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003a540:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003a550:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script· 
0003a560:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003a570:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003a580:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003a590:·6964·3d22·6964·6d36·3538·3922·3e3c·7461··id="idm6589"><ta 
0003a5a0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003a5b0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003a5c0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003a5d0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003a5e0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003a550:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp
 0003a560:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0003a570:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003a580:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003a590:·6522·2069·643d·2269·646d·3635·3839·223e··e"·id="idm6589">
 0003a5a0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003a5b0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003a5c0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003a5d0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003a5e0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 0003a5f0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 0003a600:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003a610:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
0003a5f0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003a620:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003a600:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003a630:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
0003a610:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003a620:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003a630:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003a640:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003a650:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003a660:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003a670:·643e·636f·6e66·6967·7572·653c·2f74·643e··d>configure</td> 
0003a680:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003a690:·653e·3c63·6f64·653e·6368·6772·7020·2d4c··e><code>chgrp·-L0003a640:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
 0003a650:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 0003a660:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003a670:·3e3c·7464·3e63·6f6e·6669·6775·7265·3c2f··><td>configure</
 0003a680:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003a690:·3c70·7265·3e3c·636f·6465·3e2d·206e·616d··<pre><code>-·nam
 0003a6a0:·653a·2054·6573·7420·666f·7220·6578·6973··e:·Test·for·exis
 0003a6b0:·7465·6e63·6520·2f65·7463·2f70·6173·7377··tence·/etc/passw
 0003a6c0:·640a·2020·7374·6174·3a0a·2020·2020·7061··d.··stat:.····pa
 0003a6d0:·7468·3a20·2f65·7463·2f70·6173·7377·640a··th:·/etc/passwd.
 0003a6e0:·2020·7265·6769·7374·6572·3a20·6669·6c65····register:·file
 0003a6f0:·5f65·7869·7374·730a·2020·7461·6773·3a0a··_exists.··tags:.
 0003a700:·2020·2d20·434a·4953·2d35·2e35·2e32·2e32····-·CJIS-5.5.2.2
 0003a710:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
 0003a720:·2d41·432d·3628·3129·0a20·202d·204e·4953··-AC-6(1).··-·NIS
 0003a730:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a)
 0003a740:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req
 0003a750:·2d38·2e37·2e63·0a20·202d·2050·4349·2d44··-8.7.c.··-·PCI-D
 0003a760:·5353·7634·2d32·2e32·2e36·0a20·202d·2063··SSv4-2.2.6.··-·c
 0003a770:·6f6e·6669·6775·7265·5f73·7472·6174·6567··onfigure_strateg
 0003a780:·790a·2020·2d20·6669·6c65·5f67·726f·7570··y.··-·file_group
 0003a790:·6f77·6e65·725f·6574·635f·7061·7373·7764··owner_etc_passwd
 0003a7a0:·0a20·202d·206c·6f77·5f63·6f6d·706c·6578··.··-·low_complex
 0003a7b0:·6974·790a·2020·2d20·6c6f·775f·6469·7372··ity.··-·low_disr
 0003a7c0:·7570·7469·6f6e·0a20·202d·206d·6564·6975··uption.··-·mediu
 0003a7d0:·6d5f·7365·7665·7269·7479·0a20·202d·206e··m_severity.··-·n
 0003a7e0:·6f5f·7265·626f·6f74·5f6e·6565·6465·640a··o_reboot_needed.
 0003a7f0:·0a2d·206e·616d·653a·2045·6e73·7572·6520··.-·name:·Ensure·
 0003a800:·6772·6f75·7020·6f77·6e65·7220·3020·6f6e··group·owner·0·on
0003a6a0:·2030·202f·6574·632f·7061·7373·7764·0a3c···0·/etc/passwd.<0003a810:·202f·6574·632f·7061·7373·7764·0a20·2066···/etc/passwd.··f
0003a6b0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003a6c0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003a6d0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003a6e0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003a6f0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003a700:·2223·6964·6d36·3539·3022·2074·6162·696e··"#idm6590"·tabin 
0003a710:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003a720:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003a730:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003a740:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003a750:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003a760:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans 
0003a770:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...0003a820:·696c·653a·0a20·2020·2070·6174·683a·202f··ile:.····path:·/
 0003a830:·6574·632f·7061·7373·7764·0a20·2020·2067··etc/passwd.····g
 0003a840:·726f·7570·3a20·2730·270a·2020·7768·656e··roup:·'0'.··when
 0003a850:·3a20·6669·6c65·5f65·7869·7374·732e·7374··:·file_exists.st
 0003a860:·6174·2069·7320·6465·6669·6e65·6420·616e··at·is·defined·an
 0003a870:·6420·6669·6c65·5f65·7869·7374·732e·7374··d·file_exists.st
 0003a880:·6174·2e65·7869·7374·730a·2020·7461·6773··at.exists.··tags
 0003a890:·3a0a·2020·2d20·434a·4953·2d35·2e35·2e32··:.··-·CJIS-5.5.2
 0003a8a0:·2e32·0a20·202d·204e·4953·542d·3830·302d··.2.··-·NIST-800-
 0003a8b0:·3533·2d41·432d·3628·3129·0a20·202d·204e··53-AC-6(1).··-·N
 0003a8c0:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6(
 0003a8d0:·6129·0a20·202d·2050·4349·2d44·5353·2d52··a).··-·PCI-DSS-R
 0003a8e0:·6571·2d38·2e37·2e63·0a20·202d·2050·4349··eq-8.7.c.··-·PCI
 0003a8f0:·2d44·5353·7634·2d32·2e32·2e36·0a20·202d··-DSSv4-2.2.6.··-
 0003a900:·2063·6f6e·6669·6775·7265·5f73·7472·6174···configure_strat
 0003a910:·6567·790a·2020·2d20·6669·6c65·5f67·726f··egy.··-·file_gro
 0003a920:·7570·6f77·6e65·725f·6574·635f·7061·7373··upowner_etc_pass
 0003a930:·7764·0a20·202d·206c·6f77·5f63·6f6d·706c··wd.··-·low_compl
 0003a940:·6578·6974·790a·2020·2d20·6c6f·775f·6469··exity.··-·low_di
 0003a950:·7372·7570·7469·6f6e·0a20·202d·206d·6564··sruption.··-·med
 0003a960:·6975·6d5f·7365·7665·7269·7479·0a20·202d··ium_severity.··-
 0003a970:·206e·6f5f·7265·626f·6f74·5f6e·6565·6465···no_reboot_neede
 0003a980:·640a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··d.</code></pre><
 0003a990:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0003a9a0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0003a9b0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0003a9c0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0003a9d0:·6574·3d22·2369·646d·3635·3930·2220·7461··et="#idm6590"·ta
 0003a9e0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
Max diff block lines reached; 30692/46478 bytes (66.04%) of diff not shown.
6.27 KB
html2text {}
    
Offset 41, 15 lines modifiedOffset 41, 15 lines modified
41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
42 ····*·cpe:/o:opensuse:leap:15.042 ····*·cpe:/o:opensuse:leap:15.0
43 ····*·cpe:/o:opensuse:leap:42.143 ····*·cpe:/o:opensuse:leap:42.1
44 ····*·cpe:/o:opensuse:leap:42.244 ····*·cpe:/o:opensuse:leap:42.2
45 ····*·cpe:/o:opensuse:leap:42.345 ····*·cpe:/o:opensuse:leap:42.3
46 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
47 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8447 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
48 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)48 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
49 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*49 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
50 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s50 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
51 ·········1.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s51 ·········1.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
52 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*52 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*
53 Group  ·Guide·to·the·Secure·Configuration·of·openSUSE·  Group·contains·4·groups53 Group  ·Guide·to·the·Secure·Configuration·of·openSUSE·  Group·contains·4·groups
54 and·3·rules54 and·3·rules
55 Group  ·System·Settings·  Group·contains·3·groups·and·3·rules55 Group  ·System·Settings·  Group·contains·3·groups·and·3·rules
Offset 106, 20 lines modifiedOffset 106, 14 lines modified
106 ···························007-3·R5.1,·CIP-007-3·R5.1.1,·CIP-007-3·R5.1.2106 ···························007-3·R5.1,·CIP-007-3·R5.1.1,·CIP-007-3·R5.1.2
107 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)107 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)
108 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5108 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5
109 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-8.7.c109 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-8.7.c
110 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227110 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
111 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R50111 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R50
112 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6112 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6
113 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
114 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
115 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
116 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
117 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure 
118 chgrp·-L·0·/etc/passwd 
119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8113 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
120 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low114 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
121 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low115 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
122 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false116 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
123 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure117 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
124 -·name:·Test·for·existence·/etc/passwd118 -·name:·Test·for·existence·/etc/passwd
125 ··stat:119 ··stat:
Offset 151, 14 lines modifiedOffset 145, 20 lines modified
151 ··-·PCI-DSSv4-2.2.6145 ··-·PCI-DSSv4-2.2.6
152 ··-·configure_strategy146 ··-·configure_strategy
153 ··-·file_groupowner_etc_passwd147 ··-·file_groupowner_etc_passwd
154 ··-·low_complexity148 ··-·low_complexity
155 ··-·low_disruption149 ··-·low_disruption
156 ··-·medium_severity150 ··-·medium_severity
157 ··-·no_reboot_needed151 ··-·no_reboot_needed
 152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 153 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 154 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 155 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 156 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
 157 chgrp·-L·0·/etc/passwd
158 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·U\x8Us\x8se\x8er\x8r·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·p\x8pa\x8as\x8ss\x8sw\x8wd\x8d·F\x8Fi\x8il\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*158 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·U\x8Us\x8se\x8er\x8r·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·p\x8pa\x8as\x8ss\x8sw\x8wd\x8d·F\x8Fi\x8il\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
159 To·properly·set·the·owner·of·/etc/passwd,·run·the·command:159 To·properly·set·the·owner·of·/etc/passwd,·run·the·command:
160 $·sudo·chown·root·/etc/passwd160 $·sudo·chown·root·/etc/passwd
161 ············The·/etc/passwd·file·contains·information·about·the·users·that·are161 ············The·/etc/passwd·file·contains·information·about·the·users·that·are
162 Rationale:··configured·on·the·system.·Protection·of·this·file·is·critical·for162 Rationale:··configured·on·the·system.·Protection·of·this·file·is·critical·for
163 ············system·security.163 ············system·security.
164 Severity: ··medium164 Severity: ··medium
Offset 179, 20 lines modifiedOffset 179, 14 lines modified
179 ···························007-3·R5.1,·CIP-007-3·R5.1.1,·CIP-007-3·R5.1.2179 ···························007-3·R5.1,·CIP-007-3·R5.1.1,·CIP-007-3·R5.1.2
180 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)180 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)
181 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5181 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5
182 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-8.7.c182 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-8.7.c
183 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227183 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
184 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R50184 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R50
185 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6185 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6
186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure 
191 chown·-L·0·/etc/passwd 
192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
197 -·name:·Test·for·existence·/etc/passwd191 -·name:·Test·for·existence·/etc/passwd
198 ··stat:192 ··stat:
Offset 224, 14 lines modifiedOffset 218, 20 lines modified
224 ··-·PCI-DSSv4-2.2.6218 ··-·PCI-DSSv4-2.2.6
225 ··-·configure_strategy219 ··-·configure_strategy
226 ··-·file_owner_etc_passwd220 ··-·file_owner_etc_passwd
227 ··-·low_complexity221 ··-·low_complexity
228 ··-·low_disruption222 ··-·low_disruption
229 ··-·medium_severity223 ··-·medium_severity
230 ··-·no_reboot_needed224 ··-·no_reboot_needed
 225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
 230 chown·-L·0·/etc/passwd
231 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·o\x8on\x8n·p\x8pa\x8as\x8ss\x8sw\x8wd\x8d·F\x8Fi\x8il\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*231 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·o\x8on\x8n·p\x8pa\x8as\x8ss\x8sw\x8wd\x8d·F\x8Fi\x8il\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
232 To·properly·set·the·permissions·of·/etc/passwd,·run·the·command:232 To·properly·set·the·permissions·of·/etc/passwd,·run·the·command:
233 $·sudo·chmod·0644·/etc/passwd233 $·sudo·chmod·0644·/etc/passwd
234 ············If·the·/etc/passwd·file·is·writable·by·a·group-owner·or·the·world234 ············If·the·/etc/passwd·file·is·writable·by·a·group-owner·or·the·world
235 Rationale:··the·risk·of·its·compromise·is·increased.·The·file·contains·the·list235 Rationale:··the·risk·of·its·compromise·is·increased.·The·file·contains·the·list
236 ············of·accounts·on·the·system·and·associated·information,·and236 ············of·accounts·on·the·system·and·associated·information,·and
237 ············protection·of·this·file·is·critical·for·system·security.237 ············protection·of·this·file·is·critical·for·system·security.
Offset 253, 25 lines modifiedOffset 253, 14 lines modified
253 ···························007-3·R5.1,·CIP-007-3·R5.1.1,·CIP-007-3·R5.1.2253 ···························007-3·R5.1,·CIP-007-3·R5.1.1,·CIP-007-3·R5.1.2
254 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)254 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)
255 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5255 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5
256 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-8.7.c256 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-8.7.c
257 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227257 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
258 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R50258 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R50
259 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6259 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6
260 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
261 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
262 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
263 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
264 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure 
  
  
  
  
  
265 chmod·u-xs,g-xws,o-xwt·/etc/passwd 
266 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8260 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
267 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low261 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
268 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low262 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
269 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false263 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
270 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure264 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
271 -·name:·Test·for·existence·/etc/passwd265 -·name:·Test·for·existence·/etc/passwd
272 ··stat:266 ··stat:
Offset 303, 11 lines modifiedOffset 292, 22 lines modified
303 ··-·PCI-DSSv4-2.2.6292 ··-·PCI-DSSv4-2.2.6
Max diff block lines reached; 675/6398 bytes (10.55%) of diff not shown.
2.37 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-anssi_bp28_enhanced.html
    
Offset 14309, 15 lines modifiedOffset 14309, 15 lines modified
00037e40:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00037e40:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00037e50:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00037e50:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00037e60:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s00037e60:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00037e70:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00037e70:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00037e80:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00037e80:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00037e90:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00037e90:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00037ea0:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00037ea0:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00037eb0:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).00037eb0:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
00037ec0:·2020·2020·2020·2020·2020·2020·2020·2020··················00037ec0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037ed0:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00037ed0:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00037ee0:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00037ee0:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00037ef0:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00037ef0:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00037f00:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00037f00:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00037f10:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00037f10:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00037f20:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00037f20:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
1.12 KB
html2text {}
    
Offset 44, 15 lines modifiedOffset 44, 15 lines modified
44 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*44 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·ANSSI-BP-028·(enhanced)45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·ANSSI-BP-028·(enhanced)
46 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_enhanced46 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_enhanced
47 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*47 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
48 ····*·cpe:/o:redhat:enterprise_linux_coreos:448 ····*·cpe:/o:redhat:enterprise_linux_coreos:4
49 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*49 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
50 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8450 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
51 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)51 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
52 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*52 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
53 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s53 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
54 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e54 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
55 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l55 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
56 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r56 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
57 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n57 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
58 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g58 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
2.36 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-anssi_bp28_high.html
    
Offset 14308, 15 lines modifiedOffset 14308, 15 lines modified
00037e30:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00037e30:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00037e40:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00037e40:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00037e50:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s00037e50:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00037e60:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00037e60:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00037e70:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00037e70:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00037e80:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00037e80:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00037e90:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00037e90:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00037ea0:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).00037ea0:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
00037eb0:·2020·2020·2020·2020·2020·2020·2020·2020··················00037eb0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037ec0:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00037ec0:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00037ed0:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00037ed0:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00037ee0:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00037ee0:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00037ef0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00037ef0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00037f00:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00037f00:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00037f10:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00037f10:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
1.13 KB
html2text {}
    
Offset 44, 15 lines modifiedOffset 44, 15 lines modified
44 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*44 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·ANSSI-BP-028·(high)45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·ANSSI-BP-028·(high)
46 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_high46 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_high
47 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*47 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
48 ····*·cpe:/o:redhat:enterprise_linux_coreos:448 ····*·cpe:/o:redhat:enterprise_linux_coreos:4
49 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*49 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
50 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8450 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
51 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)51 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
52 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*52 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
53 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s53 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
54 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e54 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
55 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l55 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
56 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r56 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
57 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n57 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
58 ·········5.·_\x8K_\x8e_\x8r_\x8n_\x8e_\x8l_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n58 ·········5.·_\x8K_\x8e_\x8r_\x8n_\x8e_\x8l_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
2.49 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-anssi_bp28_intermediary.html
    
Offset 14310, 15 lines modifiedOffset 14310, 15 lines modified
00037e50:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00037e50:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00037e60:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00037e60:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00037e70:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s00037e70:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00037e80:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00037e80:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00037e90:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00037e90:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00037ea0:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00037ea0:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00037eb0:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00037eb0:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00037ec0:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).00037ec0:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
00037ed0:·2020·2020·2020·2020·2020·2020·2020·2020··················00037ed0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037ee0:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00037ee0:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00037ef0:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00037ef0:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00037f00:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00037f00:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00037f10:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00037f10:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00037f20:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00037f20:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00037f30:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00037f30:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
1.24 KB
html2text {}
    
Offset 44, 15 lines modifiedOffset 44, 15 lines modified
44 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*44 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·ANSSI-BP-028·(intermediary)45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·ANSSI-BP-028·(intermediary)
46 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_intermediary46 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_intermediary
47 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*47 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
48 ····*·cpe:/o:redhat:enterprise_linux_coreos:448 ····*·cpe:/o:redhat:enterprise_linux_coreos:4
49 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*49 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
50 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8450 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
51 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)51 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
52 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*52 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
53 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s53 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
54 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e54 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
55 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l55 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
56 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n56 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
57 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s57 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
58 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s58 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
2.36 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-anssi_bp28_minimal.html
    
Offset 14309, 15 lines modifiedOffset 14309, 15 lines modified
00037e40:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren00037e40:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren
00037e50:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro00037e50:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro
00037e60:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron00037e60:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron
00037e70:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s00037e70:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s
00037e80:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str00037e80:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str
00037e90:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········00037e90:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········
00037ea0:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·00037ea0:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·
00037eb0:·3230·3236·2d30·312d·3038·290a·2020·2020··2026-01-08).····00037eb0:·3230·3234·2d31·322d·3037·290a·2020·2020··2024-12-07).····
00037ec0:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li00037ec0:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li
00037ed0:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>00037ed0:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>
00037ee0:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content00037ee0:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content
00037ef0:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a00037ef0:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a
00037f00:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or00037f00:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or
00037f10:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con00037f10:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con
00037f20:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste00037f20:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste
1.12 KB
html2text {}
    
Offset 44, 15 lines modifiedOffset 44, 15 lines modified
44 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*44 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·ANSSI-BP-028·(minimal)45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·ANSSI-BP-028·(minimal)
46 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_minimal46 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_minimal
47 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*47 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
48 ····*·cpe:/o:redhat:enterprise_linux_coreos:448 ····*·cpe:/o:redhat:enterprise_linux_coreos:4
49 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*49 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
50 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8450 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
51 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)51 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
52 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*52 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
53 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s53 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
54 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e54 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
55 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l55 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
56 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s56 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
57 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s57 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
58 ·········1.·_\x8M_\x8a_\x8i_\x8l_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e58 ·········1.·_\x8M_\x8a_\x8i_\x8l_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
2.33 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-bsi-2022.html
    
Offset 14302, 16 lines modifiedOffset 14302, 16 lines modified
00037dd0:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>00037dd0:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>
00037de0:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi00037de0:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi
00037df0:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.00037df0:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.
00037e00:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><00037e00:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><
00037e10:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d00037e10:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d
00037e20:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··00037e20:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··
00037e30:·2020·2020·2020·2020·2020·2020·2020·2020··················00037e30:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037e40:·2020·2861·7320·6f66·2032·3032·362d·3031····(as·of·2026-0100037e40:·2020·2861·7320·6f66·2032·3032·342d·3132····(as·of·2024-12
00037e50:·2d30·3829·0a20·2020·2020·2020·2020·2020··-08).···········00037e50:·2d30·3729·0a20·2020·2020·2020·2020·2020··-07).···········
00037e60:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><00037e60:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><
00037e70:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o00037e70:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o
00037e80:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><00037e80:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><
00037e90:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="00037e90:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="
00037ea0:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr00037ea0:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr
00037eb0:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr00037eb0:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr
00037ec0:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst00037ec0:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst
1000 B
html2text {}
    
Offset 42, 15 lines modifiedOffset 42, 15 lines modified
42 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·BSI·APP.4.4.·and·SYS.1.643 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·BSI·APP.4.4.·and·SYS.1.6
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_bsi-202244 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_bsi-2022
45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
46 ····*·cpe:/o:redhat:enterprise_linux_coreos:446 ····*·cpe:/o:redhat:enterprise_linux_coreos:4
47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
48 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8448 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
52 ·········1.·_\x8S_\x8E_\x8L_\x8i_\x8n_\x8u_\x8x52 ·········1.·_\x8S_\x8E_\x8L_\x8i_\x8n_\x8u_\x8x
53 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*53 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*
54 Group  ·Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·CoreOS·454 Group  ·Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·CoreOS·4
55   Group·contains·2·groups·and·3·rules55   Group·contains·2·groups·and·3·rules
56 Group  ·System·Settings·  Group·contains·1·group·and·3·rules56 Group  ·System·Settings·  Group·contains·1·group·and·3·rules
2.18 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-bsi.html
    
Offset 14302, 15 lines modifiedOffset 14302, 15 lines modified
00037dd0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00037dd0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00037de0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00037de0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00037df0:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s00037df0:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00037e00:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00037e00:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00037e10:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00037e10:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00037e20:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00037e20:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00037e30:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00037e30:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00037e40:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).00037e40:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
00037e50:·2020·2020·2020·2020·2020·2020·2020·2020··················00037e50:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037e60:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00037e60:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00037e70:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00037e70:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00037e80:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00037e80:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00037e90:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00037e90:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00037ea0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00037ea0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00037eb0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00037eb0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
997 B
html2text {}
    
Offset 42, 15 lines modifiedOffset 42, 15 lines modified
42 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·BSI·APP.4.4.·and·SYS.1.643 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·BSI·APP.4.4.·and·SYS.1.6
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_bsi44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_bsi
45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
46 ····*·cpe:/o:redhat:enterprise_linux_coreos:446 ····*·cpe:/o:redhat:enterprise_linux_coreos:4
47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
48 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8448 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
52 ·········1.·_\x8S_\x8E_\x8L_\x8i_\x8n_\x8u_\x8x52 ·········1.·_\x8S_\x8E_\x8L_\x8i_\x8n_\x8u_\x8x
53 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*53 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*
54 Group  ·Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·CoreOS·454 Group  ·Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·CoreOS·4
55   Group·contains·2·groups·and·3·rules55   Group·contains·2·groups·and·3·rules
56 Group  ·System·Settings·  Group·contains·1·group·and·3·rules56 Group  ·System·Settings·  Group·contains·1·group·and·3·rules
2.43 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-e8.html
    
Offset 14303, 16 lines modifiedOffset 14303, 16 lines modified
00037de0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p00037de0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p
00037df0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version00037df0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version
00037e00:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.7400037e00:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.74
00037e10:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul00037e10:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul
00037e20:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra00037e20:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra
00037e30:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····00037e30:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····
00037e40:·2020·2020·2020·2020·2020·2020·2020·2020··················00037e40:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037e50:·2861·7320·6f66·2032·3032·362d·3031·2d30··(as·of·2026-01-000037e50:·2861·7320·6f66·2032·3032·342d·3132·2d30··(as·of·2024-12-0
00037e60:·3829·0a20·2020·2020·2020·2020·2020·2020··8).·············00037e60:·3729·0a20·2020·2020·2020·2020·2020·2020··7).·············
00037e70:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d00037e70:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d
00037e80:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·00037e80:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·
00037e90:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol00037e90:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol
00037ea0:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x00037ea0:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x
00037eb0:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj00037eb0:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj
00037ec0:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou00037ec0:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou
00037ed0:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System00037ed0:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System
1.09 KB
html2text {}
    
Offset 42, 15 lines modifiedOffset 42, 15 lines modified
42 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Australian·Cyber·Security·Centre·(ACSC)·Essential·Eight43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Australian·Cyber·Security·Centre·(ACSC)·Essential·Eight
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_e844 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_e8
45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
46 ····*·cpe:/o:redhat:enterprise_linux_coreos:446 ····*·cpe:/o:redhat:enterprise_linux_coreos:4
47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
48 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8448 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
54 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s54 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
55 ·········4.·_\x8S_\x8E_\x8L_\x8i_\x8n_\x8u_\x8x55 ·········4.·_\x8S_\x8E_\x8L_\x8i_\x8n_\x8u_\x8x
56 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s56 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
2.38 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-high-rev-4.html
    
Offset 14356, 15 lines modifiedOffset 14356, 15 lines modified
00038130:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00038130:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00038140:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00038140:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00038150:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</00038150:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
00038160:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00038160:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
00038170:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft00038170:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
00038180:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······00038180:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
00038190:·2020·2020·2020·2020·2020·2020·2020·2861················(a00038190:·2020·2020·2020·2020·2020·2020·2020·2861················(a
000381a0:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)000381a0:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
000381b0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············000381b0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
000381c0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div000381c0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
000381d0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co000381d0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
000381e0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><000381e0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
000381f0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc000381f0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
00038200:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec00038200:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00038210:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00038210:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
1.16 KB
html2text {}
    
Offset 56, 15 lines modifiedOffset 56, 15 lines modified
56 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·NIST·800-53·High-Impact·Baseline·for·Red·Hat·Enterprise·Linux56 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·NIST·800-53·High-Impact·Baseline·for·Red·Hat·Enterprise·Linux
57 ··············CoreOS57 ··············CoreOS
58 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_high-rev-458 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_high-rev-4
59 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*59 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
60 ····*·cpe:/o:redhat:enterprise_linux_coreos:460 ····*·cpe:/o:redhat:enterprise_linux_coreos:4
61 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*61 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
62 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8462 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
63 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)63 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
64 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*64 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
65 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s65 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
66 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e66 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
67 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l67 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
68 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n68 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
69 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g69 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
70 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s70 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
2.36 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-high.html
    
Offset 14356, 15 lines modifiedOffset 14356, 15 lines modified
00038130:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current00038130:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current
00038140:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron00038140:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron
00038150:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong00038150:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong
00038160:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st00038160:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st
00038170:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro00038170:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro
00038180:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············00038180:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············
00038190:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·200038190:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·2
000381a0:·3032·362d·3031·2d30·3829·0a20·2020·2020··026-01-08).·····000381a0:·3032·342d·3132·2d30·3729·0a20·2020·2020··024-12-07).·····
000381b0:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>000381b0:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>
000381c0:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T000381c0:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T
000381d0:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents000381d0:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents
000381e0:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·000381e0:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·
000381f0:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org000381f0:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org
00038200:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont00038200:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont
00038210:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system00038210:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system
1.15 KB
html2text {}
    
Offset 56, 15 lines modifiedOffset 56, 15 lines modified
56 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·NIST·800-53·High-Impact·Baseline·for·Red·Hat·Enterprise·Linux56 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·NIST·800-53·High-Impact·Baseline·for·Red·Hat·Enterprise·Linux
57 ··············CoreOS57 ··············CoreOS
58 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_high58 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_high
59 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*59 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
60 ····*·cpe:/o:redhat:enterprise_linux_coreos:460 ····*·cpe:/o:redhat:enterprise_linux_coreos:4
61 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*61 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
62 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8462 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
63 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)63 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
64 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*64 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
65 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s65 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
66 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e66 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
67 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l67 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
68 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n68 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
69 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g69 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
70 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s70 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
2.53 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-moderate-rev-4.html
    
Offset 14357, 16 lines modifiedOffset 14357, 16 lines modified
00038140:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>00038140:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>
00038150:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi00038150:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi
00038160:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.00038160:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.
00038170:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><00038170:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><
00038180:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d00038180:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d
00038190:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··00038190:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··
000381a0:·2020·2020·2020·2020·2020·2020·2020·2020··················000381a0:·2020·2020·2020·2020·2020·2020·2020·2020··················
000381b0:·2020·2861·7320·6f66·2032·3032·362d·3031····(as·of·2026-01000381b0:·2020·2861·7320·6f66·2032·3032·342d·3132····(as·of·2024-12
000381c0:·2d30·3829·0a20·2020·2020·2020·2020·2020··-08).···········000381c0:·2d30·3729·0a20·2020·2020·2020·2020·2020··-07).···········
000381d0:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><000381d0:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><
000381e0:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o000381e0:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o
000381f0:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><000381f0:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><
00038200:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="00038200:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="
00038210:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr00038210:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr
00038220:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr00038220:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr
00038230:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst00038230:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst
1.17 KB
html2text {}
    
Offset 56, 15 lines modifiedOffset 56, 15 lines modified
56 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·NIST·800-53·Moderate-Impact·Baseline·for·Red·Hat·Enterprise·Linux56 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·NIST·800-53·Moderate-Impact·Baseline·for·Red·Hat·Enterprise·Linux
57 ··············CoreOS57 ··············CoreOS
58 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_moderate-rev-458 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_moderate-rev-4
59 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*59 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
60 ····*·cpe:/o:redhat:enterprise_linux_coreos:460 ····*·cpe:/o:redhat:enterprise_linux_coreos:4
61 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*61 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
62 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8462 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
63 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)63 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
64 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*64 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
65 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s65 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
66 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e66 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
67 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l67 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
68 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n68 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
69 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g69 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
70 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s70 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
2.38 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-moderate.html
    
Offset 14357, 15 lines modifiedOffset 14357, 15 lines modified
00038140:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur00038140:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur
00038150:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s00038150:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s
00038160:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st00038160:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st
00038170:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li00038170:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li
00038180:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</00038180:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</
00038190:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········00038190:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········
000381a0:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·000381a0:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·
000381b0:·6f66·2032·3032·362d·3031·2d30·3829·0a20··of·2026-01-08).·000381b0:·6f66·2032·3032·342d·3132·2d30·3729·0a20··of·2024-12-07).·
000381c0:·2020·2020·2020·2020·2020·2020·2020·203c·················<000381c0:·2020·2020·2020·2020·2020·2020·2020·203c·················<
000381d0:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><000381d0:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><
000381e0:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont000381e0:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont
000381f0:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li000381f0:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li
00038200:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf00038200:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf
00038210:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.00038210:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.
00038220:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy00038220:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy
1.16 KB
html2text {}
    
Offset 56, 15 lines modifiedOffset 56, 15 lines modified
56 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·NIST·800-53·Moderate-Impact·Baseline·for·Red·Hat·Enterprise·Linux56 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·NIST·800-53·Moderate-Impact·Baseline·for·Red·Hat·Enterprise·Linux
57 ··············CoreOS57 ··············CoreOS
58 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_moderate58 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_moderate
59 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*59 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
60 ····*·cpe:/o:redhat:enterprise_linux_coreos:460 ····*·cpe:/o:redhat:enterprise_linux_coreos:4
61 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*61 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
62 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8462 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
63 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)63 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
64 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*64 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
65 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s65 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
66 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e66 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
67 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l67 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
68 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n68 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
69 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g69 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
70 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s70 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
2.54 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-nerc-cip.html
    
Offset 14315, 16 lines modifiedOffset 14315, 16 lines modified
00037ea0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00037ea0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00037eb0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00037eb0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00037ec0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000037ec0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00037ed0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></00037ed0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
00037ee0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00037ee0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00037ef0:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00037ef0:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00037f00:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037f00:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037f10:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600037f10:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
00037f20:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········00037f20:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00037f30:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00037f30:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00037f40:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00037f40:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00037f50:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00037f50:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00037f60:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00037f60:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00037f70:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00037f70:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00037f80:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00037f80:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00037f90:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00037f90:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
1.19 KB
html2text {}
    
Offset 45, 15 lines modifiedOffset 45, 15 lines modified
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Infrastructure·Protection·(CIP)·cybersecurity·standards·profile45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Infrastructure·Protection·(CIP)·cybersecurity·standards·profile
46 ··············for·Red·Hat·Enterprise·Linux·CoreOS46 ··············for·Red·Hat·Enterprise·Linux·CoreOS
47 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_nerc-cip47 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_nerc-cip
48 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*48 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
49 ····*·cpe:/o:redhat:enterprise_linux_coreos:449 ····*·cpe:/o:redhat:enterprise_linux_coreos:4
50 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
51 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8451 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
52 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)52 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
53 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*53 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
54 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s54 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
55 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e55 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
56 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l56 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
57 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n57 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
58 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g58 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
59 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s59 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
2.48 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-stig-v1r1.html
    
Offset 14287, 16 lines modifiedOffset 14287, 16 lines modified
00037ce0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h00037ce0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h
00037cf0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver00037cf0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver
00037d00:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.00037d00:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.
00037d10:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p00037d10:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p
00037d20:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong00037d20:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong
00037d30:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.00037d30:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.
00037d40:·2020·2020·2020·2020·2020·2020·2020·2020··················00037d40:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037d50:·2020·2020·2861·7320·6f66·2032·3032·362d······(as·of·2026-00037d50:·2020·2020·2861·7320·6f66·2032·3032·342d······(as·of·2024-
00037d60:·3031·2d30·3829·0a20·2020·2020·2020·2020··01-08).·········00037d60:·3132·2d30·3729·0a20·2020·2020·2020·2020··12-07).·········
00037d70:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul00037d70:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul
00037d80:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table00037d80:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table
00037d90:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h200037d90:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2
00037da0:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href00037da0:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href
00037db0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg00037db0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg
00037dc0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_00037dc0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
00037dd0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy00037dd0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy
1.12 KB
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DISA·STIG·for·Red·Hat·Enterprise·Linux·CoreOS39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DISA·STIG·for·Red·Hat·Enterprise·Linux·CoreOS
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_stig-v1r140 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_stig-v1r1
41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
42 ····*·cpe:/o:redhat:enterprise_linux_coreos:442 ····*·cpe:/o:redhat:enterprise_linux_coreos:4
43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
44 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8444 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
49 ·········2.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n49 ·········2.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
51 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s51 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
52 ·········5.·_\x8S_\x8E_\x8L_\x8i_\x8n_\x8u_\x8x52 ·········5.·_\x8S_\x8E_\x8L_\x8i_\x8n_\x8u_\x8x
2.33 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-stig.html
    
Offset 14287, 15 lines modifiedOffset 14287, 15 lines modified
00037ce0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00037ce0:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00037cf0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00037cf0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00037d00:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<00037d00:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<
00037d10:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00037d10:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00037d20:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00037d20:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00037d30:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00037d30:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00037d40:·2020·2020·2020·2020·2020·2020·2020·2028·················(00037d40:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00037d50:·6173·206f·6620·3230·3236·2d30·312d·3038··as·of·2026-01-0800037d50:·6173·206f·6620·3230·3234·2d31·322d·3037··as·of·2024-12-07
00037d60:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00037d60:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00037d70:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00037d70:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00037d80:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00037d80:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00037d90:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00037d90:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00037da0:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00037da0:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00037db0:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00037db0:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00037dc0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00037dc0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
1.12 KB
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*38 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DISA·STIG·for·Red·Hat·Enterprise·Linux·CoreOS39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DISA·STIG·for·Red·Hat·Enterprise·Linux·CoreOS
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_stig40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_stig
41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
42 ····*·cpe:/o:redhat:enterprise_linux_coreos:442 ····*·cpe:/o:redhat:enterprise_linux_coreos:4
43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
44 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8444 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
49 ·········2.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n49 ·········2.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
51 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s51 ·········4.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
52 ·········5.·_\x8S_\x8E_\x8L_\x8i_\x8n_\x8u_\x8x52 ·········5.·_\x8S_\x8E_\x8L_\x8i_\x8n_\x8u_\x8x
21.7 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-anssi_bp28_enhanced.html
    
Offset 14321, 15 lines modifiedOffset 14321, 15 lines modified
00037f00:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00037f00:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00037f10:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00037f10:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00037f20:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</00037f20:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
00037f30:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00037f30:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
00037f40:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft00037f40:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
00037f50:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······00037f50:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
00037f60:·2020·2020·2020·2020·2020·2020·2020·2861················(a00037f60:·2020·2020·2020·2020·2020·2020·2020·2861················(a
00037f70:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)00037f70:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
00037f80:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037f80:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037f90:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div00037f90:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
00037fa0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co00037fa0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
00037fb0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><00037fb0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
00037fc0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc00037fc0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
00037fd0:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec00037fd0:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00037fe0:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00037fe0:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 15097, 234 lines modifiedOffset 15097, 234 lines modified
0003af80:·7461·7267·6574·3d22·2369·646d·3732·3530··target="#idm72500003af80:·7461·7267·6574·3d22·2369·646d·3732·3530··target="#idm7250
0003af90:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003af90:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003afa0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003afa0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003afb0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003afb0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003afc0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003afc0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003afd0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003afd0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003afe0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003afe0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003aff0:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp0003aff0:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni
0003b000:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0003b000:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003b010:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003b010:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003b020:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003b020:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003b030:·6522·2069·643d·2269·646d·3732·3530·223e··e"·id="idm7250">0003b030:·7073·6522·2069·643d·2269·646d·3732·3530··pse"·id="idm7250
0003b040:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003b040:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003b050:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003b050:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003b060:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003b060:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003b070:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003b070:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003b080:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003b080:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003b090:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003b090:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003b0a0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003b0a0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003b0b0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003b0b0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003b0c0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003b0c0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003b0d0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo0003b0d0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003b0e0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals0003b0e0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003b0f0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><0003b0f0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003b100:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th0003b100:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003b110:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>0003b110:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0003b120:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003b120:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003b130:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa
 0003b140:·6765·202d·2d61·6464·3d61·6964·650a·3c2f··ge·--add=aide.</
0003b130:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include· 
0003b140:·696e·7374·616c·6c5f·6169·6465·0a0a·636c··install_aide..cl 
0003b150:·6173·7320·696e·7374·616c·6c5f·6169·6465··ass·install_aide 
0003b160:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·' 
0003b170:·6169·6465·273a·0a20·2020·2065·6e73·7572··aide':.····ensur 
0003b180:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install 
0003b190:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod 
0003b1a0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003b1b0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003b1c0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003b1d0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003b1e0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003b1f0:·6d37·3235·3122·2074·6162·696e·6465·783d··m7251"·tabindex= 
0003b200:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003b210:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003b220:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003b230:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003b240:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003b250:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s 
0003b260:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003b270:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003b280:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003b290:·6170·7365·2220·6964·3d22·6964·6d37·3235··apse"·id="idm725 
0003b2a0:·3122·3e3c·7461·626c·6520·636c·6173·733d··1"><table·class= 
0003b2b0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003b2c0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003b2d0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003b2e0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003b2f0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003b300:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b310:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003b320:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b330:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003b340:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003b350:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
0003b360:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003b370:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003b380:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003b390:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem 
0003b3a0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl 
0003b3b0:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c 
0003b3c0:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms 
0003b3d0:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc 
0003b3e0:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a 
0003b3f0:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/ 
0003b400:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·]; 
0003b410:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm· 
0003b420:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide 
0003b430:·2220·3b20·7468·656e·0a20·2020·2064·6e66··"·;·then.····dnf 
0003b440:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid 
0003b450:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.···· 
0003b460:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo· 
0003b470:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is· 
0003b480:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,· 
0003b490:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done 
0003b4a0:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr 
0003b4b0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003b4c0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003b4d0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003b4e0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003b4f0:·6172·6765·743d·2223·6964·6d37·3235·3222··arget="#idm7252" 
0003b500:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003b510:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003b520:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003b530:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003b540:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003b550:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003b560:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp 
0003b570:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003b580:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003b590:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003b5a0:·6522·2069·643d·2269·646d·3732·3532·223e··e"·id="idm7252"> 
0003b5b0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003b5c0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003b5d0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003b5e0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003b5f0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003b600:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003b610:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b620:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003b630:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b640:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
Max diff block lines reached; 20764089/20796159 bytes (99.85%) of diff not shown.
1.87 MB
html2text {}
Max HTML report size reached
22.2 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-anssi_bp28_high.html
    
Offset 14320, 15 lines modifiedOffset 14320, 15 lines modified
00037ef0:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00037ef0:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00037f00:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00037f00:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00037f10:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</00037f10:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
00037f20:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00037f20:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
00037f30:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft00037f30:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
00037f40:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······00037f40:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
00037f50:·2020·2020·2020·2020·2020·2020·2020·2861················(a00037f50:·2020·2020·2020·2020·2020·2020·2020·2861················(a
00037f60:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)00037f60:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
00037f70:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037f70:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037f80:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div00037f80:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
00037f90:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co00037f90:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
00037fa0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><00037fa0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
00037fb0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc00037fb0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
00037fc0:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec00037fc0:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00037fd0:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00037fd0:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 15102, 235 lines modifiedOffset 15102, 235 lines modified
0003afd0:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm70003afd0:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7
0003afe0:·3235·3022·2074·6162·696e·6465·783d·2230··250"·tabindex="00003afe0:·3235·3022·2074·6162·696e·6465·783d·2230··250"·tabindex="0
0003aff0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003aff0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003b000:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003b000:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003b010:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003b010:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003b020:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003b020:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003b030:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003b030:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003b040:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn0003b040:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·
0003b050:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003b050:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003b060:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003b060:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003b070:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003b070:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003b080:·6170·7365·2220·6964·3d22·6964·6d37·3235··apse"·id="idm7250003b080:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7
0003b090:·3022·3e3c·7461·626c·6520·636c·6173·733d··0"><table·class=0003b090:·3235·3022·3e3c·7461·626c·6520·636c·6173··250"><table·clas
0003b0a0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003b0a0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003b0b0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003b0b0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003b0c0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003b0c0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003b0d0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003b0d0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003b0e0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003b0e0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003b0f0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003b0f0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003b100:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003b100:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003b110:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003b110:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003b120:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R0003b120:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b130:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f0003b130:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003b140:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t0003b140:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003b150:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<0003b150:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003b160:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</0003b160:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
0003b170:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>0003b170:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003b180:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu 
0003b190:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide. 
0003b1a0:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a 
0003b1b0:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package· 
0003b1c0:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en 
0003b1d0:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst 
0003b1e0:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</ 
0003b1f0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003b200:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003b210:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003b220:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003b230:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003b240:·2369·646d·3732·3531·2220·7461·6269·6e64··#idm7251"·tabind 
0003b250:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003b260:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003b270:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003b280:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003b290:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003b2a0:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel 
0003b2b0:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a> 
0003b2c0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b2d0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b2e0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b2f0:·3732·3531·223e·3c74·6162·6c65·2063·6c61··7251"><table·cla 
0003b300:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003b310:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003b320:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003b330:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003b340:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003b350:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b360:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003b370:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003b380:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b390:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003b3a0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003b3b0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003b3c0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003b3d0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003b3e0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#· 
0003b3f0:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a 
0003b400:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i 
0003b410:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo 
0003b420:·726d·730a·6966·205b·2021·202d·6620·2f2e··rms.if·[·!·-f·/. 
0003b430:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp 
0003b440:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r 
0003b450:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv 
0003b460:·205d·3b20·7468·656e·0a0a·6966·2021·2072···];·then..if·!·r 
0003b470:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a 
0003b480:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.···· 
0003b490:·646e·6620·696e·7374·616c·6c20·2d79·2022··dnf·install·-y·" 
0003b4a0:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.· 
0003b4b0:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec 
0003b4c0:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation· 
0003b4d0:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl 
0003b4e0:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d 
0003b4f0:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code>< 
0003b500:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003b510:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003b520:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003b530:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003b540:·612d·7461·7267·6574·3d22·2369·646d·3732··a-target="#idm72 
0003b550:·3532·2220·7461·6269·6e64·6578·3d22·3022··52"·tabindex="0" 
0003b560:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003b570:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003b580:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003b590:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003b5a0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003b5b0:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn 
0003b5c0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003b5d0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003b5e0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003b5f0:·6170·7365·2220·6964·3d22·6964·6d37·3235··apse"·id="idm725 
0003b600:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class= 
0003b610:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003b620:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003b630:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003b640:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003b650:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003b660:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b670:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003b680:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b690:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003b6a0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003b6b0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
Max diff block lines reached; 21187987/21220195 bytes (99.85%) of diff not shown.
1.95 MB
html2text {}
Max HTML report size reached
9.74 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-anssi_bp28_intermediary.html
    
Offset 14322, 15 lines modifiedOffset 14322, 15 lines modified
00037f10:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00037f10:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00037f20:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00037f20:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00037f30:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</00037f30:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
00037f40:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00037f40:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
00037f50:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft00037f50:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
00037f60:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······00037f60:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
00037f70:·2020·2020·2020·2020·2020·2020·2020·2861················(a00037f70:·2020·2020·2020·2020·2020·2020·2020·2861················(a
00037f80:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)00037f80:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
00037f90:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037f90:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037fa0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div00037fa0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
00037fb0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co00037fb0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
00037fc0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><00037fc0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
00037fd0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc00037fd0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
00037fe0:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec00037fe0:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00037ff0:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00037ff0:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 15093, 234 lines modifiedOffset 15093, 234 lines modified
0003af40:·6765·743d·2223·6964·6d37·3235·3022·2074··get="#idm7250"·t0003af40:·6765·743d·2223·6964·6d37·3235·3022·2074··get="#idm7250"·t
0003af50:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003af50:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003af60:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003af60:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003af70:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003af70:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003af80:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003af80:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003af90:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003af90:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003afa0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003afa0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003afb0:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·0003afb0:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe
0003afc0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003afc0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003afd0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003afd0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003afe0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003afe0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003aff0:·6964·3d22·6964·6d37·3235·3022·3e3c·7461··id="idm7250"><ta0003aff0:·2220·6964·3d22·6964·6d37·3235·3022·3e3c··"·id="idm7250"><
0003b000:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0003b000:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003b010:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0003b010:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003b020:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0003b020:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003b030:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0003b030:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003b040:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003b040:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003b050:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003b050:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003b060:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003b060:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003b070:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>0003b070:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003b080:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003b080:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003b090:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:0003b090:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
0003b0a0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</0003b0a0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
0003b0b0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003b0b0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003b0c0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003b0c0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
0003b0d0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t0003b0d0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
0003b0e0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003b0e0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003b0f0:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 0003b100:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod
0003b0f0:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins 
0003b100:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class 
0003b110:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{. 
0003b120:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid 
0003b130:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·= 
0003b140:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed' 
0003b150:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code>< 
0003b160:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003b170:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003b180:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003b190:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003b1a0:·612d·7461·7267·6574·3d22·2369·646d·3732··a-target="#idm72 
0003b1b0:·3531·2220·7461·6269·6e64·6578·3d22·3022··51"·tabindex="0" 
0003b1c0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003b1d0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003b1e0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003b1f0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003b200:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003b210:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
0003b220:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
0003b230:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003b240:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003b250:·6522·2069·643d·2269·646d·3732·3531·223e··e"·id="idm7251"> 
0003b260:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003b270:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003b280:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003b290:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003b2a0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003b2b0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003b2c0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b2d0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003b2e0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b2f0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003b300:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0003b310:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
0003b320:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0003b330:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0003b340:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003b350:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi 
0003b360:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica 
0003b370:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert 
0003b380:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if 
0003b390:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker 
0003b3a0:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp; 
0003b3b0:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co 
0003b3c0:·6e74·6169·6e65·7265·6e76·205d·3b20·7468··ntainerenv·];·th 
0003b3d0:·656e·0a0a·6966·2021·2072·706d·202d·7120··en..if·!·rpm·-q· 
0003b3e0:·2d2d·7175·6965·7420·2261·6964·6522·203b··--quiet·"aide"·; 
0003b3f0:·2074·6865·6e0a·2020·2020·646e·6620·696e···then.····dnf·in 
0003b400:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide". 
0003b410:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt 
0003b420:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re 
0003b430:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not 
0003b440:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not 
0003b450:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f 
0003b460:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre>< 
0003b470:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003b480:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003b490:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003b4a0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003b4b0:·6574·3d22·2369·646d·3732·3532·2220·7461··et="#idm7252"·ta 
0003b4c0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003b4d0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003b4e0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003b4f0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003b500:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003b510:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003b520:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet· 
0003b530:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003b540:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003b550:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003b560:·6964·3d22·6964·6d37·3235·3222·3e3c·7461··id="idm7252"><ta 
0003b570:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003b580:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003b590:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003b5a0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003b5b0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003b5c0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003b5d0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b5e0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003b5f0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b600:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
Max diff block lines reached; 9108591/9140661 bytes (99.65%) of diff not shown.
1.03 MB
html2text {}
    
Offset 46, 15 lines modifiedOffset 46, 15 lines modified
46 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
47 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·ANSSI-BP-028·(intermediary)47 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·ANSSI-BP-028·(intermediary)
48 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_intermediary48 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_intermediary
49 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*49 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
50 ····*·cpe:/o:redhat:enterprise_linux:1050 ····*·cpe:/o:redhat:enterprise_linux:10
51 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
52 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8452 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
53 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)53 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
54 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*54 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
55 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s55 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
56 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e56 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
57 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l57 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
58 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n58 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
59 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s59 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
60 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s60 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 118, 41 lines modifiedOffset 118, 45 lines modified
118 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)118 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
119 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3119 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
120 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5120 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
121 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199121 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
122 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79122 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
123 ·············_\x8c_\x8i_\x8s············6.1.1123 ·············_\x8c_\x8i_\x8s············6.1.1
124 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2124 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
 125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 130 package·--add=aide
125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
130 include·install_aide136 include·install_aide
  
131 class·install_aide·{137 class·install_aide·{
132 ··package·{·'aide':138 ··package·{·'aide':
133 ····ensure·=>·'installed',139 ····ensure·=>·'installed',
134 ··}140 ··}
135 }141 }
 142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 143 [[packages]]
 144 name·=·"aide"
 145 version·=·"*"
136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low147 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low148 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false149 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable150 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
141 #·Remediation·is·applicable·only·in·certain·platforms 
142 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
 151 package·install·aide
143 if·!·rpm·-q·--quiet·"aide"·;·then 
144 ····dnf·install·-y·"aide" 
145 fi 
  
146 else 
147 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
148 fi 
149 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
150 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low153 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
151 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low154 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
152 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false155 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
153 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable156 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
154 -·name:·Ensure·aide·is·installed157 -·name:·Ensure·aide·is·installed
155 ··package:158 ··package:
Offset 167, 33 lines modifiedOffset 171, 29 lines modified
167 ··-·PCI-DSSv4-11.5.2171 ··-·PCI-DSSv4-11.5.2
168 ··-·enable_strategy172 ··-·enable_strategy
169 ··-·low_complexity173 ··-·low_complexity
170 ··-·low_disruption174 ··-·low_disruption
171 ··-·medium_severity175 ··-·medium_severity
172 ··-·no_reboot_needed176 ··-·no_reboot_needed
173 ··-·package_aide_installed177 ··-·package_aide_installed
174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
175 [[packages]] 
176 name·=·"aide" 
177 version·=·"*" 
178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 183 #·Remediation·is·applicable·only·in·certain·platforms
 184 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 185 if·!·rpm·-q·--quiet·"aide"·;·then
 186 ····dnf·install·-y·"aide"
 187 fi
183 package·install·aide 
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
189 package·--add=aide188 else
 189 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 190 fi
190 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*191 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
191 Run·the·following·command·to·generate·a·new·database:192 Run·the·following·command·to·generate·a·new·database:
192 $·sudo·/usr/sbin/aide·--init193 $·sudo·/usr/sbin/aide·--init
193 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the194 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
194 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these195 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
195 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their196 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
196 integrity.·The·newly-generated·database·can·be·installed·as·follows:197 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 218, 28 lines modifiedOffset 218, 14 lines modified
218 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)218 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
219 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3219 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
220 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5220 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
221 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199221 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
222 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79222 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
223 ·············_\x8c_\x8i_\x8s············6.1.1223 ·············_\x8c_\x8i_\x8s············6.1.1
224 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2224 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
226 #·Remediation·is·applicable·only·in·certain·platforms 
227 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
228 if·!·rpm·-q·--quiet·"aide"·;·then 
229 ····dnf·install·-y·"aide" 
230 fi 
  
Max diff block lines reached; 1071001/1077020 bytes (99.44%) of diff not shown.
3.05 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-anssi_bp28_minimal.html
    
Offset 14321, 15 lines modifiedOffset 14321, 15 lines modified
00037f00:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre00037f00:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre
00037f10:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str00037f10:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str
00037f20:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro00037f20:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro
00037f30:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><00037f30:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><
00037f40:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st00037f40:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st
00037f50:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········00037f50:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········
00037f60:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of00037f60:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of
00037f70:·2032·3032·362d·3031·2d30·3829·0a20·2020···2026-01-08).···00037f70:·2032·3032·342d·3132·2d30·3729·0a20·2020···2024-12-07).···
00037f80:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l00037f80:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l
00037f90:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h200037f90:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h2
00037fa0:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten00037fa0:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten
00037fb0:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><00037fb0:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><
00037fc0:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o00037fc0:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o
00037fd0:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co00037fd0:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co
00037fe0:·6e74·656e·745f·6772·6f75·705f·7379·7374··ntent_group_syst00037fe0:·6e74·656e·745f·6772·6f75·705f·7379·7374··ntent_group_syst
Offset 14771, 218 lines modifiedOffset 14771, 218 lines modified
00039b20:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm100039b20:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
00039b30:·3036·3837·2220·7461·6269·6e64·6578·3d22··0687"·tabindex="00039b30:·3036·3837·2220·7461·6269·6e64·6578·3d22··0687"·tabindex="
00039b40:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"00039b40:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
00039b50:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="00039b50:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
00039b60:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac00039b60:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
00039b70:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal00039b70:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
00039b80:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme00039b80:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
00039b90:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s00039b90:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
 00039ba0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 00039bb0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 00039bc0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 00039bd0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 00039be0:·3130·3638·3722·3e3c·7461·626c·6520·636c··10687"><table·cl
 00039bf0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 00039c00:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 00039c10:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 00039c20:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 00039c30:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 00039c40:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 00039c50:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 00039c60:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 00039c70:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 00039c80:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 00039c90:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 00039ca0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 00039cb0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 00039cc0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 00039cd0:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.
 00039ce0:·7061·636b·6167·6520·2d2d·6164·643d·646e··package·--add=dn
 00039cf0:·662d·6175·746f·6d61·7469·630a·3c2f·636f··f-automatic.</co
 00039d00:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 00039d10:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 00039d20:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 00039d30:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 00039d40:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 00039d50:·646d·3130·3638·3822·2074·6162·696e·6465··dm10688"·tabinde
 00039d60:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 00039d70:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 00039d80:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 00039d90:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 00039da0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 00039db0:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
 00039dc0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 00039dd0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 00039de0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 00039df0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 00039e00:·6d31·3036·3838·223e·3c74·6162·6c65·2063··m10688"><table·c
 00039e10:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 00039e20:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 00039e30:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 00039e40:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 00039e50:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 00039e60:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 00039e70:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 00039e80:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 00039e90:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 00039ea0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 00039eb0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 00039ec0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 00039ed0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 00039ee0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 00039ef0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 00039f00:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_
 00039f10:·646e·662d·6175·746f·6d61·7469·630a·0a63··dnf-automatic..c
 00039f20:·6c61·7373·2069·6e73·7461·6c6c·5f64·6e66··lass·install_dnf
 00039f30:·2d61·7574·6f6d·6174·6963·207b·0a20·2070··-automatic·{.··p
 00039f40:·6163·6b61·6765·207b·2027·646e·662d·6175··ackage·{·'dnf-au
 00039f50:·746f·6d61·7469·6327·3a0a·2020·2020·656e··tomatic':.····en
 00039f60:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst
 00039f70:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</
 00039f80:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 00039f90:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 00039fa0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 00039fb0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 00039fc0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 00039fd0:·2369·646d·3130·3638·3922·2074·6162·696e··#idm10689"·tabin
 00039fe0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 00039ff0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003a000:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003a010:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003a020:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003a030:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB
 0003a040:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s
00039ba0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003a050:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
00039bb0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003a060:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
00039bc0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003a070:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
00039bd0:·6c61·7073·6522·2069·643d·2269·646d·3130··lapse"·id="idm100003a080:·6c61·7073·6522·2069·643d·2269·646d·3130··lapse"·id="idm10
 0003a090:·3638·3922·3e3c·7072·653e·3c63·6f64·653e··689"><pre><code>
 0003a0a0:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 0003a0b0:·6d65·203d·2022·646e·662d·6175·746f·6d61··me·=·"dnf-automa
 0003a0c0:·7469·6322·0a76·6572·7369·6f6e·203d·2022··tic".version·=·"
00039be0:·3638·3722·3e3c·7461·626c·6520·636c·6173··687"><table·clas 
00039bf0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
00039c00:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
00039c10:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
00039c20:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
00039c30:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
00039c40:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
00039c50:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
00039c60:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
00039c70:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
00039c80:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
00039c90:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
00039ca0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
00039cb0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
00039cc0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
00039cd0:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc 
00039ce0:·6c75·6465·2069·6e73·7461·6c6c·5f64·6e66··lude·install_dnf 
00039cf0:·2d61·7574·6f6d·6174·6963·0a0a·636c·6173··-automatic..clas 
00039d00:·7320·696e·7374·616c·6c5f·646e·662d·6175··s·install_dnf-au 
00039d10:·746f·6d61·7469·6320·7b0a·2020·7061·636b··tomatic·{.··pack 
Max diff block lines reached; 2947960/2977822 bytes (99.00%) of diff not shown.
214 KB
html2text {}
    
Offset 46, 15 lines modifiedOffset 46, 15 lines modified
46 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
47 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·ANSSI-BP-028·(minimal)47 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·ANSSI-BP-028·(minimal)
48 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_minimal48 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_minimal
49 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*49 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
50 ····*·cpe:/o:redhat:enterprise_linux:1050 ····*·cpe:/o:redhat:enterprise_linux:10
51 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
52 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8452 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
53 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)53 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
54 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*54 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
55 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s55 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
56 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e56 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
57 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l57 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
58 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s58 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
59 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s59 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
60 ·········1.·_\x8D_\x8H_\x8C_\x8P60 ·········1.·_\x8D_\x8H_\x8C_\x8P
Offset 84, 35 lines modifiedOffset 84, 45 lines modified
84 Rationale:···dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade84 Rationale:···dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade
85 ·············suitable·for·automatic,·regular·execution.85 ·············suitable·for·automatic,·regular·execution.
86 Severity: ···medium86 Severity: ···medium
87 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed87 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
88 Identifiers:·CCE-87561-788 Identifiers:·CCE-87561-7
89 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-0008089 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
90 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R6190 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
 91 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 92 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 93 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 94 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 95 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 96 package·--add=dnf-automatic
91 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x897 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
92 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low98 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
93 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low99 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
94 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false100 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
95 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable101 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
96 include·install_dnf-automatic102 include·install_dnf-automatic
  
97 class·install_dnf-automatic·{103 class·install_dnf-automatic·{
98 ··package·{·'dnf-automatic':104 ··package·{·'dnf-automatic':
99 ····ensure·=>·'installed',105 ····ensure·=>·'installed',
100 ··}106 ··}
101 }107 }
 108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 109 [[packages]]
 110 name·=·"dnf-automatic"
 111 version·=·"*"
102 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
103 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low113 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
104 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low114 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
105 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false115 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
106 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable116 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 117 package·install·dnf-automatic
107 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then 
108 ····dnf·install·-y·"dnf-automatic" 
109 fi 
110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
111 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
112 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
113 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
114 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
115 -·name:·Ensure·dnf-automatic·is·installed123 -·name:·Ensure·dnf-automatic·is·installed
116 ··package:124 ··package:
Offset 122, 33 lines modifiedOffset 132, 23 lines modified
122 ··-·CCE-87561-7132 ··-·CCE-87561-7
123 ··-·enable_strategy133 ··-·enable_strategy
124 ··-·low_complexity134 ··-·low_complexity
125 ··-·low_disruption135 ··-·low_disruption
126 ··-·medium_severity136 ··-·medium_severity
127 ··-·no_reboot_needed137 ··-·no_reboot_needed
128 ··-·package_dnf-automatic_installed138 ··-·package_dnf-automatic_installed
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
130 [[packages]] 
131 name·=·"dnf-automatic" 
132 version·=·"*" 
133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
138 package·install·dnf-automatic 
139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
144 package·--add=dnf-automatic144 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
 145 ····dnf·install·-y·"dnf-automatic"
 146 fi
145 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*147 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
146 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed148 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
147 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/149 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
148 automatic.conf.150 automatic.conf.
149 ·············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation151 ·············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
150 ·············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and152 ·············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
151 Rationale:···updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in153 Rationale:···updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 159, 14 lines modifiedOffset 159, 37 lines modified
159 Rule·ID:·····xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates159 Rule·ID:·····xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates
160 Identifiers:·CCE-86671-5160 Identifiers:·CCE-86671-5
161 ·············_\x8i_\x8s_\x8m····0940,·1144,·1467,·1472,·1483,·1493,·1494,·1495161 ·············_\x8i_\x8s_\x8m····0940,·1144,·1467,·1472,·1483,·1493,·1494,·1495
162 ·············_\x8n_\x8i_\x8s_\x8t···SI-2(5),·CM-6(a),·SI-2(c)162 ·············_\x8n_\x8i_\x8s_\x8t···SI-2(5),·CM-6(a),·SI-2(c)
163 References:··_\x8o_\x8s_\x8p_\x8p···FMT_SMF_EXT.1163 References:··_\x8o_\x8s_\x8p_\x8p···FMT_SMF_EXT.1
164 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080164 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
165 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61165 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
 166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···unknown
 171 -·name:·Configure·dnf-automatic·to·Install·Available·Updates·Automatically
 172 ··ini_file:
 173 ····dest:·/etc/dnf/automatic.conf
 174 ····section:·commands
 175 ····option:·apply_updates
 176 ····value:·'yes'
 177 ····create:·true
 178 ··tags:
 179 ··-·CCE-86671-5
 180 ··-·NIST-800-53-CM-6(a)
 181 ··-·NIST-800-53-SI-2(5)
 182 ··-·NIST-800-53-SI-2(c)
 183 ··-·dnf-automatic_apply_updates
 184 ··-·low_complexity
Max diff block lines reached; 212952/218844 bytes (97.31%) of diff not shown.
25.0 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-cis.html
    
Offset 14292, 16 lines modifiedOffset 14292, 16 lines modified
00037d30:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p00037d30:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p
00037d40:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version00037d40:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version
00037d50:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.7400037d50:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.74
00037d60:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul00037d60:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul
00037d70:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra00037d70:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra
00037d80:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····00037d80:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····
00037d90:·2020·2020·2020·2020·2020·2020·2020·2020··················00037d90:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037da0:·2861·7320·6f66·2032·3032·362d·3031·2d30··(as·of·2026-01-000037da0:·2861·7320·6f66·2032·3032·342d·3132·2d30··(as·of·2024-12-0
00037db0:·3829·0a20·2020·2020·2020·2020·2020·2020··8).·············00037db0:·3729·0a20·2020·2020·2020·2020·2020·2020··7).·············
00037dc0:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d00037dc0:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d
00037dd0:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·00037dd0:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·
00037de0:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol00037de0:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol
00037df0:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x00037df0:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x
00037e00:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj00037e00:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj
00037e10:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou00037e10:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou
00037e20:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System00037e20:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System
Offset 15135, 235 lines modifiedOffset 15135, 235 lines modified
0003b1e0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003b1e0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b1f0:·6964·6d37·3235·3022·2074·6162·696e·6465··idm7250"·tabinde0003b1f0:·6964·6d37·3235·3022·2074·6162·696e·6465··idm7250"·tabinde
0003b200:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b200:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003b210:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003b210:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003b220:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003b220:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003b230:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003b230:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003b240:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003b240:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003b250:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe0003b250:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco
0003b260:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a0003b260:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...<
0003b270:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003b270:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003b280:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003b280:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003b290:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003b290:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
0003b2a0:·6d37·3235·3022·3e3c·7461·626c·6520·636c··m7250"><table·cl0003b2a0:·6964·6d37·3235·3022·3e3c·7461·626c·6520··idm7250"><table·
0003b2b0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003b2b0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003b2c0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003b2c0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003b2d0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003b2d0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003b2e0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003b2e0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0003b2f0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003b2f0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0003b300:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003b300:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003b310:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003b310:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003b320:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003b320:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003b330:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003b330:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003b340:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><0003b340:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
0003b350:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t0003b350:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
0003b360:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate0003b360:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
0003b370:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab0003b370:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
0003b380:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta0003b380:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
0003b390:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i0003b390:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003b3a0:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add=
0003b3a0:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a 
0003b3b0:·6964·650a·0a63·6c61·7373·2069·6e73·7461··ide..class·insta 
0003b3c0:·6c6c·5f61·6964·6520·7b0a·2020·7061·636b··ll_aide·{.··pack 
0003b3d0:·6167·6520·7b20·2761·6964·6527·3a0a·2020··age·{·'aide':.·· 
0003b3e0:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·' 
0003b3f0:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}. 
0003b400:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre>< 
0003b410:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003b420:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003b430:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003b440:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003b450:·6574·3d22·2369·646d·3732·3531·2220·7461··et="#idm7251"·ta 
0003b460:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003b470:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003b480:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003b490:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003b4a0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003b4b0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003b4c0:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
0003b4d0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b4e0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b4f0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b500:·2269·646d·3732·3531·223e·3c74·6162·6c65··"idm7251"><table 
0003b510:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003b520:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003b530:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003b540:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003b550:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003b560:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b570:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003b580:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003b590:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b5a0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003b5b0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003b5c0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003b5d0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0003b5e0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0003b5f0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003b600:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation· 
0003b610:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on 
0003b620:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl 
0003b630:·6174·666f·726d·730a·6966·205b·2021·202d··atforms.if·[·!·- 
0003b640:·6620·2f2e·646f·636b·6572·656e·7620·5d20··f·/.dockerenv·]· 
0003b650:·2661·6d70·3b26·616d·703b·205b·2021·202d··&amp;&amp;·[·!·- 
0003b660:·6620·2f72·756e·2f2e·636f·6e74·6169·6e65··f·/run/.containe 
0003b670:·7265·6e76·205d·3b20·7468·656e·0a0a·6966··renv·];·then..if 
0003b680:·2021·2072·706d·202d·7120·2d2d·7175·6965···!·rpm·-q·--quie 
0003b690:·7420·2261·6964·6522·203b·2074·6865·6e0a··t·"aide"·;·then. 
0003b6a0:·2020·2020·646e·6620·696e·7374·616c·6c20······dnf·install· 
0003b6b0:·2d79·2022·6169·6465·220a·6669·0a0a·656c··-y·"aide".fi..el 
0003b6c0:·7365·0a20·2020·2026·6774·3b26·616d·703b··se.····&gt;&amp; 
0003b6d0:·3220·6563·686f·2027·5265·6d65·6469·6174··2·echo·'Remediat 
0003b6e0:·696f·6e20·6973·206e·6f74·2061·7070·6c69··ion·is·not·appli 
0003b6f0:·6361·626c·652c·206e·6f74·6869·6e67·2077··cable,·nothing·w 
0003b700:·6173·2064·6f6e·6527·0a66·690a·3c2f·636f··as·done'.fi.</co 
0003b710:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003b720:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003b730:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003b740:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003b750:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003b760:·646d·3732·3532·2220·7461·6269·6e64·6578··dm7252"·tabindex 
0003b770:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003b780:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003b790:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003b7a0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003b7b0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003b7c0:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl 
0003b7d0:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a 
0003b7e0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b7f0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b800:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b810:·6d37·3235·3222·3e3c·7461·626c·6520·636c··m7252"><table·cl 
0003b820:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003b830:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003b840:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0003b850:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0003b860:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0003b870:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003b880:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003b890:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
0003b8a0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
Max diff block lines reached; 23837444/23869790 bytes (99.86%) of diff not shown.
2.25 MB
html2text {}
Max HTML report size reached
11.4 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-cis_server_l1.html
    
Offset 14293, 15 lines modifiedOffset 14293, 15 lines modified
00037d40:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre00037d40:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre
00037d50:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str00037d50:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str
00037d60:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro00037d60:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro
00037d70:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><00037d70:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><
00037d80:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st00037d80:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st
00037d90:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········00037d90:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········
00037da0:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of00037da0:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of
00037db0:·2032·3032·362d·3031·2d30·3829·0a20·2020···2026-01-08).···00037db0:·2032·3032·342d·3132·2d30·3729·0a20·2020···2024-12-07).···
00037dc0:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l00037dc0:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l
00037dd0:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h200037dd0:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h2
00037de0:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten00037de0:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten
00037df0:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><00037df0:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><
00037e00:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o00037e00:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o
00037e10:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co00037e10:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co
00037e20:·6e74·656e·745f·6772·6f75·705f·7379·7374··ntent_group_syst00037e20:·6e74·656e·745f·6772·6f75·705f·7379·7374··ntent_group_syst
Offset 15104, 235 lines modifiedOffset 15104, 235 lines modified
0003aff0:·612d·7461·7267·6574·3d22·2369·646d·3732··a-target="#idm720003aff0:·612d·7461·7267·6574·3d22·2369·646d·3732··a-target="#idm72
0003b000:·3530·2220·7461·6269·6e64·6578·3d22·3022··50"·tabindex="0"0003b000:·3530·2220·7461·6269·6e64·6578·3d22·3022··50"·tabindex="0"
0003b010:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003b010:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003b020:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003b020:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003b030:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003b030:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003b040:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003b040:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003b050:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003b050:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003b060:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni0003b060:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s
0003b070:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003b070:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003b080:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003b080:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003b090:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003b090:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003b0a0:·7073·6522·2069·643d·2269·646d·3732·3530··pse"·id="idm72500003b0a0:·6c61·7073·6522·2069·643d·2269·646d·3732··lapse"·id="idm72
0003b0b0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003b0b0:·3530·223e·3c74·6162·6c65·2063·6c61·7373··50"><table·class
0003b0c0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003b0c0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003b0d0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003b0d0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003b0e0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003b0e0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003b0f0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003b0f0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003b100:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003b100:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003b110:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003b110:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003b120:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003b120:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003b130:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003b130:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003b140:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003b140:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b150:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003b150:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0003b160:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003b160:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
0003b170:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003b170:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003b180:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003b180:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0003b190:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003b190:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003b1a0:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ0003b1a0:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 0003b1b0:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide.
0003b1b0:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide.. 
0003b1c0:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai 
0003b1d0:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{ 
0003b1e0:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens 
0003b1f0:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta 
0003b200:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c 
0003b210:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003b220:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003b230:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003b240:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003b250:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003b260:·6964·6d37·3235·3122·2074·6162·696e·6465··idm7251"·tabinde 
0003b270:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003b280:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003b290:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003b2a0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003b2b0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003b2c0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003b2d0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003b2e0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b2f0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b300:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7 
0003b310:·3235·3122·3e3c·7461·626c·6520·636c·6173··251"><table·clas 
0003b320:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b330:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b340:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b350:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b360:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b370:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b380:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b390:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b3a0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b3b0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b3c0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003b3d0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b3e0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b3f0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b400:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R 
0003b410:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003b420:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003b430:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003b440:·6d73·0a69·6620·5b20·2120·2d66·202f·2e64··ms.if·[·!·-f·/.d 
0003b450:·6f63·6b65·7265·6e76·205d·2026·616d·703b··ockerenv·]·&amp; 
0003b460:·2661·6d70·3b20·5b20·2120·2d66·202f·7275··&amp;·[·!·-f·/ru 
0003b470:·6e2f·2e63·6f6e·7461·696e·6572·656e·7620··n/.containerenv· 
0003b480:·5d3b·2074·6865·6e0a·0a69·6620·2120·7270··];·then..if·!·rp 
0003b490:·6d20·2d71·202d·2d71·7569·6574·2022·6169··m·-q·--quiet·"ai 
0003b4a0:·6465·2220·3b20·7468·656e·0a20·2020·2064··de"·;·then.····d 
0003b4b0:·6e66·2069·6e73·7461·6c6c·202d·7920·2261··nf·install·-y·"a 
0003b4c0:·6964·6522·0a66·690a·0a65·6c73·650a·2020··ide".fi..else.·· 
0003b4d0:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech 
0003b4e0:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i 
0003b4f0:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable 
0003b500:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do 
0003b510:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></ 
0003b520:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003b530:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003b540:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003b550:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003b560:·2d74·6172·6765·743d·2223·6964·6d37·3235··-target="#idm725 
0003b570:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"· 
0003b580:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003b590:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003b5a0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003b5b0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003b5c0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003b5d0:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni 
0003b5e0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003b5f0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003b600:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003b610:·7073·6522·2069·643d·2269·646d·3732·3532··pse"·id="idm7252 
0003b620:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003b630:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003b640:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003b650:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003b660:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003b670:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003b680:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003b690:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003b6a0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b6b0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003b6c0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
Max diff block lines reached; 10572271/10604479 bytes (99.70%) of diff not shown.
1.27 MB
html2text {}
    
Offset 40, 15 lines modifiedOffset 40, 15 lines modified
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·CIS·Red·Hat·Enterprise·Linux·10·Benchmark·for·Level·1·-40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·CIS·Red·Hat·Enterprise·Linux·10·Benchmark·for·Level·1·-
41 ··············Server41 ··············Server
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_server_l142 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_server_l1
43 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*43 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
44 ····*·cpe:/o:redhat:enterprise_linux:1044 ····*·cpe:/o:redhat:enterprise_linux:10
45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
46 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8446 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
50 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e50 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
51 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l51 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
52 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n52 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
53 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g53 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
54 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s54 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 103, 41 lines modifiedOffset 103, 45 lines modified
103 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)103 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
104 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3104 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
105 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5105 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
106 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199106 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
107 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79107 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
108 ·············_\x8c_\x8i_\x8s············6.1.1108 ·············_\x8c_\x8i_\x8s············6.1.1
109 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2109 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
 110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 111 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 112 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 113 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 114 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 115 package·--add=aide
110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8116 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
111 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low117 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
112 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low118 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
113 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false119 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
114 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable120 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
115 include·install_aide121 include·install_aide
  
116 class·install_aide·{122 class·install_aide·{
117 ··package·{·'aide':123 ··package·{·'aide':
118 ····ensure·=>·'installed',124 ····ensure·=>·'installed',
119 ··}125 ··}
120 }126 }
 127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 128 [[packages]]
 129 name·=·"aide"
 130 version·=·"*"
121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
122 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
123 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
124 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
125 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
126 #·Remediation·is·applicable·only·in·certain·platforms 
127 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
 136 package·install·aide
128 if·!·rpm·-q·--quiet·"aide"·;·then 
129 ····dnf·install·-y·"aide" 
130 fi 
  
131 else 
132 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
133 fi 
134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
135 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
136 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
137 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
138 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
139 -·name:·Ensure·aide·is·installed142 -·name:·Ensure·aide·is·installed
140 ··package:143 ··package:
Offset 152, 33 lines modifiedOffset 156, 29 lines modified
152 ··-·PCI-DSSv4-11.5.2156 ··-·PCI-DSSv4-11.5.2
153 ··-·enable_strategy157 ··-·enable_strategy
154 ··-·low_complexity158 ··-·low_complexity
155 ··-·low_disruption159 ··-·low_disruption
156 ··-·medium_severity160 ··-·medium_severity
157 ··-·no_reboot_needed161 ··-·no_reboot_needed
158 ··-·package_aide_installed162 ··-·package_aide_installed
159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
160 [[packages]] 
161 name·=·"aide" 
162 version·=·"*" 
163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 168 #·Remediation·is·applicable·only·in·certain·platforms
 169 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 170 if·!·rpm·-q·--quiet·"aide"·;·then
 171 ····dnf·install·-y·"aide"
 172 fi
168 package·install·aide 
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
174 package·--add=aide173 else
 174 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 175 fi
175 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*176 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
176 Run·the·following·command·to·generate·a·new·database:177 Run·the·following·command·to·generate·a·new·database:
177 $·sudo·/usr/sbin/aide·--init178 $·sudo·/usr/sbin/aide·--init
178 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:179 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
179 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz180 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
180 To·initiate·a·manual·check,·run·the·following·command:181 To·initiate·a·manual·check,·run·the·following·command:
181 $·sudo·/usr/sbin/aide·--check182 $·sudo·/usr/sbin/aide·--check
Offset 196, 28 lines modifiedOffset 196, 14 lines modified
196 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a)196 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
197 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3197 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
198 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5198 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
199 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199199 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
200 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79200 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
201 ·············_\x8c_\x8i_\x8s············6.1.1201 ·············_\x8c_\x8i_\x8s············6.1.1
202 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2202 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
204 #·Remediation·is·applicable·only·in·certain·platforms 
205 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
206 if·!·rpm·-q·--quiet·"aide"·;·then 
207 ····dnf·install·-y·"aide" 
208 fi 
  
Max diff block lines reached; 1323329/1329418 bytes (99.54%) of diff not shown.
11.0 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-cis_workstation_l1.html
    
Offset 14294, 15 lines modifiedOffset 14294, 15 lines modified
00037d50:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren00037d50:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren
00037d60:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro00037d60:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro
00037d70:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron00037d70:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron
00037d80:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s00037d80:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s
00037d90:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str00037d90:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str
00037da0:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········00037da0:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········
00037db0:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·00037db0:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·
00037dc0:·3230·3236·2d30·312d·3038·290a·2020·2020··2026-01-08).····00037dc0:·3230·3234·2d31·322d·3037·290a·2020·2020··2024-12-07).····
00037dd0:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li00037dd0:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li
00037de0:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>00037de0:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>
00037df0:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content00037df0:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content
00037e00:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a00037e00:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a
00037e10:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or00037e10:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or
00037e20:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con00037e20:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con
00037e30:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste00037e30:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste
Offset 15095, 235 lines modifiedOffset 15095, 235 lines modified
0003af60:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm70003af60:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7
0003af70:·3235·3022·2074·6162·696e·6465·783d·2230··250"·tabindex="00003af70:·3235·3022·2074·6162·696e·6465·783d·2230··250"·tabindex="0
0003af80:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003af80:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003af90:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003af90:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003afa0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003afa0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003afb0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003afb0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003afc0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003afc0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003afd0:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn0003afd0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·
0003afe0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003afe0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003aff0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003aff0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003b000:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003b000:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003b010:·6170·7365·2220·6964·3d22·6964·6d37·3235··apse"·id="idm7250003b010:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7
0003b020:·3022·3e3c·7461·626c·6520·636c·6173·733d··0"><table·class=0003b020:·3235·3022·3e3c·7461·626c·6520·636c·6173··250"><table·clas
0003b030:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003b030:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003b040:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003b040:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003b050:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003b050:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003b060:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003b060:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003b070:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003b070:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003b080:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003b080:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003b090:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003b090:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003b0a0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003b0a0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003b0b0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R0003b0b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b0c0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f0003b0c0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003b0d0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t0003b0d0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003b0e0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<0003b0e0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003b0f0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</0003b0f0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
0003b100:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>0003b100:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003b110:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu 
0003b120:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide. 
0003b130:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a 
0003b140:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package· 
0003b150:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en 
0003b160:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst 
0003b170:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</ 
0003b180:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003b190:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003b1a0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003b1b0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003b1c0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003b1d0:·2369·646d·3732·3531·2220·7461·6269·6e64··#idm7251"·tabind 
0003b1e0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003b1f0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003b200:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003b210:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003b220:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003b230:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel 
0003b240:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a> 
0003b250:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b260:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b270:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b280:·3732·3531·223e·3c74·6162·6c65·2063·6c61··7251"><table·cla 
0003b290:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003b2a0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003b2b0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003b2c0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003b2d0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003b2e0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b2f0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003b300:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003b310:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b320:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003b330:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003b340:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003b350:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003b360:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003b370:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#· 
0003b380:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a 
0003b390:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i 
0003b3a0:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo 
0003b3b0:·726d·730a·6966·205b·2021·202d·6620·2f2e··rms.if·[·!·-f·/. 
0003b3c0:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp 
0003b3d0:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r 
0003b3e0:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv 
0003b3f0:·205d·3b20·7468·656e·0a0a·6966·2021·2072···];·then..if·!·r 
0003b400:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a 
0003b410:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.···· 
0003b420:·646e·6620·696e·7374·616c·6c20·2d79·2022··dnf·install·-y·" 
0003b430:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.· 
0003b440:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec 
0003b450:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation· 
0003b460:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl 
0003b470:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d 
0003b480:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code>< 
0003b490:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003b4a0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003b4b0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003b4c0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003b4d0:·612d·7461·7267·6574·3d22·2369·646d·3732··a-target="#idm72 
0003b4e0:·3532·2220·7461·6269·6e64·6578·3d22·3022··52"·tabindex="0" 
0003b4f0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003b500:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003b510:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003b520:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003b530:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003b540:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn 
0003b550:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003b560:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003b570:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003b580:·6170·7365·2220·6964·3d22·6964·6d37·3235··apse"·id="idm725 
0003b590:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class= 
0003b5a0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003b5b0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003b5c0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003b5d0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003b5e0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003b5f0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b600:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003b610:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b620:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003b630:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003b640:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
Max diff block lines reached; 10190392/10222600 bytes (99.68%) of diff not shown.
1.22 MB
html2text {}
    
Offset 40, 15 lines modifiedOffset 40, 15 lines modified
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·CIS·Red·Hat·Enterprise·Linux·10·Benchmark·for·Level·1·-40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·CIS·Red·Hat·Enterprise·Linux·10·Benchmark·for·Level·1·-
41 ··············Workstation41 ··············Workstation
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_workstation_l142 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_workstation_l1
43 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*43 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
44 ····*·cpe:/o:redhat:enterprise_linux:1044 ····*·cpe:/o:redhat:enterprise_linux:10
45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
46 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8446 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
50 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e50 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
51 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l51 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
52 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n52 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
53 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g53 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
54 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s54 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 101, 41 lines modifiedOffset 101, 45 lines modified
101 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)101 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
102 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3102 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
103 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5103 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
104 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199104 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
105 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79105 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
106 ·············_\x8c_\x8i_\x8s············6.1.1106 ·············_\x8c_\x8i_\x8s············6.1.1
107 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2107 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
 108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 109 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 110 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 111 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 112 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 113 package·--add=aide
108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
109 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low115 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
110 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low116 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
111 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false117 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
112 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable118 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
113 include·install_aide119 include·install_aide
  
114 class·install_aide·{120 class·install_aide·{
115 ··package·{·'aide':121 ··package·{·'aide':
116 ····ensure·=>·'installed',122 ····ensure·=>·'installed',
117 ··}123 ··}
118 }124 }
 125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 126 [[packages]]
 127 name·=·"aide"
 128 version·=·"*"
119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
120 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
121 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
122 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
123 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
124 #·Remediation·is·applicable·only·in·certain·platforms 
125 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
 134 package·install·aide
126 if·!·rpm·-q·--quiet·"aide"·;·then 
127 ····dnf·install·-y·"aide" 
128 fi 
  
129 else 
130 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
131 fi 
132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
137 -·name:·Ensure·aide·is·installed140 -·name:·Ensure·aide·is·installed
138 ··package:141 ··package:
Offset 150, 33 lines modifiedOffset 154, 29 lines modified
150 ··-·PCI-DSSv4-11.5.2154 ··-·PCI-DSSv4-11.5.2
151 ··-·enable_strategy155 ··-·enable_strategy
152 ··-·low_complexity156 ··-·low_complexity
153 ··-·low_disruption157 ··-·low_disruption
154 ··-·medium_severity158 ··-·medium_severity
155 ··-·no_reboot_needed159 ··-·no_reboot_needed
156 ··-·package_aide_installed160 ··-·package_aide_installed
157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
158 [[packages]] 
159 name·=·"aide" 
160 version·=·"*" 
161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 166 #·Remediation·is·applicable·only·in·certain·platforms
 167 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 168 if·!·rpm·-q·--quiet·"aide"·;·then
 169 ····dnf·install·-y·"aide"
 170 fi
166 package·install·aide 
167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
172 package·--add=aide171 else
 172 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 173 fi
173 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*174 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
174 Run·the·following·command·to·generate·a·new·database:175 Run·the·following·command·to·generate·a·new·database:
175 $·sudo·/usr/sbin/aide·--init176 $·sudo·/usr/sbin/aide·--init
176 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:177 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
177 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz178 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
178 To·initiate·a·manual·check,·run·the·following·command:179 To·initiate·a·manual·check,·run·the·following·command:
179 $·sudo·/usr/sbin/aide·--check180 $·sudo·/usr/sbin/aide·--check
Offset 194, 28 lines modifiedOffset 194, 14 lines modified
194 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a)194 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
195 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3195 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
196 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5196 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
197 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199197 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
198 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79198 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
199 ·············_\x8c_\x8i_\x8s············6.1.1199 ·············_\x8c_\x8i_\x8s············6.1.1
200 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2200 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
202 #·Remediation·is·applicable·only·in·certain·platforms 
203 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
204 if·!·rpm·-q·--quiet·"aide"·;·then 
205 ····dnf·install·-y·"aide" 
206 fi 
  
Max diff block lines reached; 1272397/1278496 bytes (99.52%) of diff not shown.
24.8 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-cis_workstation_l2.html
    
Offset 14294, 15 lines modifiedOffset 14294, 15 lines modified
00037d50:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren00037d50:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren
00037d60:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro00037d60:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro
00037d70:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron00037d70:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron
00037d80:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s00037d80:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s
00037d90:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str00037d90:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str
00037da0:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········00037da0:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········
00037db0:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·00037db0:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·
00037dc0:·3230·3236·2d30·312d·3038·290a·2020·2020··2026-01-08).····00037dc0:·3230·3234·2d31·322d·3037·290a·2020·2020··2024-12-07).····
00037dd0:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li00037dd0:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li
00037de0:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>00037de0:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>
00037df0:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content00037df0:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content
00037e00:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a00037e00:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a
00037e10:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or00037e10:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or
00037e20:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con00037e20:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con
00037e30:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste00037e30:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste
Offset 15127, 234 lines modifiedOffset 15127, 234 lines modified
0003b160:·6574·3d22·2369·646d·3732·3530·2220·7461··et="#idm7250"·ta0003b160:·6574·3d22·2369·646d·3732·3530·2220·7461··et="#idm7250"·ta
0003b170:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003b170:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003b180:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003b180:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003b190:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003b190:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003b1a0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003b1a0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003b1b0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003b1b0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003b1c0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003b1c0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003b1d0:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.0003b1d0:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet
0003b1e0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003b1e0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003b1f0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003b1f0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003b200:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003b200:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003b210:·643d·2269·646d·3732·3530·223e·3c74·6162··d="idm7250"><tab0003b210:·2069·643d·2269·646d·3732·3530·223e·3c74···id="idm7250"><t
0003b220:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003b220:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003b230:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003b230:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003b240:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003b240:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003b250:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003b250:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003b260:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003b260:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003b270:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003b270:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003b280:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003b280:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b290:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003b290:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003b2a0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003b2a0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003b2b0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<0003b2b0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
0003b2c0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003b2c0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003b2d0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003b2d0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b2e0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003b2e0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003b2f0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr0003b2f0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
0003b300:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003b300:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003b310:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·-
 0003b320:·2d61·6464·3d61·6964·650a·3c2f·636f·6465··-add=aide.</code
0003b310:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst 
0003b320:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class· 
0003b330:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.· 
0003b340:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide 
0003b350:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=& 
0003b360:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed', 
0003b370:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></ 
0003b380:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003b390:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003b3a0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003b3b0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003b3c0:·2d74·6172·6765·743d·2223·6964·6d37·3235··-target="#idm725 
0003b3d0:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"· 
0003b3e0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003b3f0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003b400:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003b410:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003b420:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003b430:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
0003b440:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003b450:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003b460:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003b470:·2220·6964·3d22·6964·6d37·3235·3122·3e3c··"·id="idm7251">< 
0003b480:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003b490:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003b4a0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003b4b0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003b4c0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003b4d0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003b4e0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b4f0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003b500:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b510:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003b520:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003b530:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b540:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003b550:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003b560:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003b570:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia 
0003b580:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab 
0003b590:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa 
0003b5a0:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if· 
0003b5b0:·5b20·2120·2d66·202f·2e64·6f63·6b65·7265··[·!·-f·/.dockere 
0003b5c0:·6e76·205d·2026·616d·703b·2661·6d70·3b20··nv·]·&amp;&amp;· 
0003b5d0:·5b20·2120·2d66·202f·7275·6e2f·2e63·6f6e··[·!·-f·/run/.con 
0003b5e0:·7461·696e·6572·656e·7620·5d3b·2074·6865··tainerenv·];·the 
0003b5f0:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·- 
0003b600:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;· 
0003b610:·7468·656e·0a20·2020·2064·6e66·2069·6e73··then.····dnf·ins 
0003b620:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f 
0003b630:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt; 
0003b640:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem 
0003b650:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not· 
0003b660:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth 
0003b670:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi 
0003b680:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003b690:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b6a0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b6b0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b6c0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b6d0:·743d·2223·6964·6d37·3235·3222·2074·6162··t="#idm7252"·tab 
0003b6e0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b6f0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b700:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b710:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b720:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b730:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A 
0003b740:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
0003b750:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b760:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b770:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003b780:·643d·2269·646d·3732·3532·223e·3c74·6162··d="idm7252"><tab 
0003b790:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003b7a0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003b7b0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003b7c0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003b7d0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003b7e0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b7f0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003b800:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003b810:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b820:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
Max diff block lines reached; 23645720/23677790 bytes (99.86%) of diff not shown.
2.22 MB
html2text {}
Max HTML report size reached
6.71 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-e8.html
    
Offset 14306, 15 lines modifiedOffset 14306, 15 lines modified
00037e10:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current00037e10:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current
00037e20:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron00037e20:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron
00037e30:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong00037e30:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong
00037e40:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st00037e40:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st
00037e50:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro00037e50:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro
00037e60:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············00037e60:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············
00037e70:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·200037e70:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·2
00037e80:·3032·362d·3031·2d30·3829·0a20·2020·2020··026-01-08).·····00037e80:·3032·342d·3132·2d30·3729·0a20·2020·2020··024-12-07).·····
00037e90:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>00037e90:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>
00037ea0:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T00037ea0:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T
00037eb0:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents00037eb0:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents
00037ec0:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·00037ec0:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·
00037ed0:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org00037ed0:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org
00037ee0:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont00037ee0:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont
00037ef0:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system00037ef0:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system
Offset 15188, 306 lines modifiedOffset 15188, 306 lines modified
0003b530:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003b530:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003b540:·6d36·3930·3822·2074·6162·696e·6465·783d··m6908"·tabindex=0003b540:·6d36·3930·3822·2074·6162·696e·6465·783d··m6908"·tabindex=
0003b550:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003b550:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003b560:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003b560:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003b570:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003b570:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003b580:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003b580:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003b590:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003b590:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003b5a0:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s 
0003b5b0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003b5c0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003b5d0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003b5e0:·6170·7365·2220·6964·3d22·6964·6d36·3930··apse"·id="idm690 
0003b5f0:·3822·3e3c·7072·653e·3c63·6f64·653e·0a23··8"><pre><code>.# 
0003b600:·2046·696e·6420·7768·6963·6820·6669·6c65···Find·which·file 
0003b610:·7320·6861·7665·2069·6e63·6f72·7265·6374··s·have·incorrect 
0003b620:·2068·6173·6820·286e·6f74·2069·6e20·2f65···hash·(not·in·/e 
0003b630:·7463·2c20·6265·6361·7573·6520·6f66·2074··tc,·because·of·t 
0003b640:·6865·2073·7973·7465·6d20·7265·6c61·7465··he·system·relate 
0003b650:·6420·636f·6e66·6967·2066·696c·6573·2920··d·config·files)· 
0003b660:·616e·6420·7468·656e·2067·6574·2066·696c··and·then·get·fil 
0003b670:·6573·206e·616d·6573·0a66·696c·6573·5f77··es·names.files_w 
0003b680:·6974·685f·696e·636f·7272·6563·745f·6861··ith_incorrect_ha 
0003b690:·7368·3d22·2428·7270·6d20·2d56·6120·2d2d··sh="$(rpm·-Va·-- 
0003b6a0:·6e6f·636f·6e66·6967·207c·2067·7265·7020··noconfig·|·grep· 
0003b6b0:·2d45·2027·5e2e·2e35·2720·7c20·6177·6b20··-E·'^..5'·|·awk· 
0003b6c0:·277b·7072·696e·7420·244e·467d·2720·2922··'{print·$NF}'·)" 
0003b6d0:·0a0a·6966·205b·202d·6e20·2224·6669·6c65··..if·[·-n·"$file 
0003b6e0:·735f·7769·7468·5f69·6e63·6f72·7265·6374··s_with_incorrect 
0003b6f0:·5f68·6173·6822·205d·3b20·7468·656e·0a20··_hash"·];·then.· 
0003b700:·2020·2023·2046·726f·6d20·6669·6c65·7320·····#·From·files· 
0003b710:·6e61·6d65·7320·6765·7420·7061·636b·6167··names·get·packag 
0003b720:·6520·6e61·6d65·7320·616e·6420·6368·616e··e·names·and·chan 
0003b730:·6765·206e·6577·6c69·6e65·2074·6f20·7370··ge·newline·to·sp 
0003b740:·6163·652c·2062·6563·6175·7365·2072·706d··ace,·because·rpm 
0003b750:·2077·7269·7465·7320·6561·6368·2070·6163···writes·each·pac 
0003b760:·6b61·6765·2074·6f20·6e65·7720·6c69·6e65··kage·to·new·line 
0003b770:·0a20·2020·2070·6163·6b61·6765·735f·746f··.····packages_to 
0003b780:·5f72·6569·6e73·7461·6c6c·3d22·2428·7270··_reinstall="$(rp 
0003b790:·6d20·2d71·6620·2466·696c·6573·5f77·6974··m·-qf·$files_wit 
0003b7a0:·685f·696e·636f·7272·6563·745f·6861·7368··h_incorrect_hash 
0003b7b0:·207c·2074·7220·275c·6e27·2027·2027·2922···|·tr·'\n'·'·')" 
0003b7c0:·0a0a·2020·2020·0a20·2020·2064·6e66·2072··..····.····dnf·r 
0003b7d0:·6569·6e73·7461·6c6c·202d·7920·2470·6163··einstall·-y·$pac 
0003b7e0:·6b61·6765·735f·746f·5f72·6569·6e73·7461··kages_to_reinsta 
0003b7f0:·6c6c·0a20·2020·200a·6669·0a3c·2f63·6f64··ll.····.fi.</cod 
0003b800:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003b810:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003b820:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003b830:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003b840:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003b850:·6d36·3930·3922·2074·6162·696e·6465·783d··m6909"·tabindex= 
0003b860:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003b870:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003b880:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003b890:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003b8a0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003b8b0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible0003b5a0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible
0003b8c0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003b5b0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003b8d0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003b5c0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003b8e0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003b5d0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003b8f0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003b5e0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003b900:·3639·3039·223e·3c74·6162·6c65·2063·6c61··6909"><table·cla0003b5f0:·3639·3038·223e·3c74·6162·6c65·2063·6c61··6908"><table·cla
0003b910:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003b600:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003b920:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003b610:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003b930:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003b620:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003b940:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003b630:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003b950:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003b640:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003b960:·3c74·643e·6869·6768·3c2f·7464·3e3c·2f74··<td>high</td></t0003b650:·3c74·643e·6869·6768·3c2f·7464·3e3c·2f74··<td>high</td></t
0003b970:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003b660:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003b980:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6d65··tion:</th><td>me0003b670:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6d65··tion:</th><td>me
0003b990:·6469·756d·3c2f·7464·3e3c·2f74·723e·3c74··dium</td></tr><t0003b680:·6469·756d·3c2f·7464·3e3c·2f74·723e·3c74··dium</td></tr><t
0003b9a0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t0003b690:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
0003b9b0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>0003b6a0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
0003b9c0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003b6b0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003b9d0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e72··ategy:</th><td>r0003b6c0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e72··ategy:</th><td>r
0003b9e0:·6573·7472·6963·743c·2f74·643e·3c2f·7472··estrict</td></tr0003b6d0:·6573·7472·6963·743c·2f74·643e·3c2f·7472··estrict</td></tr
0003b9f0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003b6e0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
0003ba00:·6f64·653e·2d20·6e61·6d65·3a20·2753·6574··ode>-·name:·'Set0003b6f0:·6f64·653e·2d20·6e61·6d65·3a20·2753·6574··ode>-·name:·'Set
0003ba10:·2066·6163·743a·2050·6163·6b61·6765·206d···fact:·Package·m0003b700:·2066·6163·743a·2050·6163·6b61·6765·206d···fact:·Package·m
0003ba20:·616e·6167·6572·2072·6569·6e73·7461·6c6c··anager·reinstall0003b710:·616e·6167·6572·2072·6569·6e73·7461·6c6c··anager·reinstall
0003ba30:·2063·6f6d·6d61·6e64·270a·2020·7365·745f···command'.··set_0003b720:·2063·6f6d·6d61·6e64·270a·2020·7365·745f···command'.··set_
0003ba40:·6661·6374·3a0a·2020·2020·7061·636b·6167··fact:.····packag0003b730:·6661·6374·3a0a·2020·2020·7061·636b·6167··fact:.····packag
0003ba50:·655f·6d61·6e61·6765·725f·7265·696e·7374··e_manager_reinst0003b740:·655f·6d61·6e61·6765·725f·7265·696e·7374··e_manager_reinst
0003ba60:·616c·6c5f·636d·643a·2064·6e66·2072·6569··all_cmd:·dnf·rei0003b750:·616c·6c5f·636d·643a·2064·6e66·2072·6569··all_cmd:·dnf·rei
0003ba70:·6e73·7461·6c6c·202d·790a·2020·7768·656e··nstall·-y.··when0003b760:·6e73·7461·6c6c·202d·790a·2020·7768·656e··nstall·-y.··when
0003ba80:·3a20·616e·7369·626c·655f·6469·7374·7269··:·ansible_distri0003b770:·3a20·616e·7369·626c·655f·6469·7374·7269··:·ansible_distri
0003ba90:·6275·7469·6f6e·2069·6e20·5b20·2246·6564··bution·in·[·"Fed0003b780:·6275·7469·6f6e·2069·6e20·5b20·2246·6564··bution·in·[·"Fed
0003baa0:·6f72·6122·2c20·2252·6564·4861·7422·2c20··ora",·"RedHat",·0003b790:·6f72·6122·2c20·2252·6564·4861·7422·2c20··ora",·"RedHat",·
0003bab0:·2243·656e·744f·5322·2c20·224f·7261·636c··"CentOS",·"Oracl0003b7a0:·2243·656e·744f·5322·2c20·224f·7261·636c··"CentOS",·"Oracl
0003bac0:·654c·696e·7578·2220·5d0a·2020·7461·6773··eLinux"·].··tags0003b7b0:·654c·696e·7578·2220·5d0a·2020·7461·6773··eLinux"·].··tags
0003bad0:·3a0a·2020·2d20·4343·452d·3839·3934·342d··:.··-·CCE-89944-0003b7c0:·3a0a·2020·2d20·4343·452d·3839·3934·342d··:.··-·CCE-89944-
0003bae0:·330a·2020·2d20·434a·4953·2d35·2e31·302e··3.··-·CJIS-5.10.0003b7d0:·330a·2020·2d20·434a·4953·2d35·2e31·302e··3.··-·CJIS-5.10.
0003baf0:·342e·310a·2020·2d20·4e49·5354·2d38·3030··4.1.··-·NIST-8000003b7e0:·342e·310a·2020·2d20·4e49·5354·2d38·3030··4.1.··-·NIST-800
0003bb00:·2d31·3731·2d33·2e33·2e38·0a20·202d·204e··-171-3.3.8.··-·N0003b7f0:·2d31·3731·2d33·2e33·2e38·0a20·202d·204e··-171-3.3.8.··-·N
0003bb10:·4953·542d·3830·302d·3137·312d·332e·342e··IST-800-171-3.4.0003b800:·4953·542d·3830·302d·3137·312d·332e·342e··IST-800-171-3.4.
0003bb20:·310a·2020·2d20·4e49·5354·2d38·3030·2d35··1.··-·NIST-800-50003b810:·310a·2020·2d20·4e49·5354·2d38·3030·2d35··1.··-·NIST-800-5
0003bb30:·332d·4155·2d39·2833·290a·2020·2d20·4e49··3-AU-9(3).··-·NI0003b820:·332d·4155·2d39·2833·290a·2020·2d20·4e49··3-AU-9(3).··-·NI
0003bb40:·5354·2d38·3030·2d35·332d·434d·2d36·2863··ST-800-53-CM-6(c0003b830:·5354·2d38·3030·2d35·332d·434d·2d36·2863··ST-800-53-CM-6(c
0003bb50:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-50003b840:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5
0003bb60:·332d·434d·2d36·2864·290a·2020·2d20·4e49··3-CM-6(d).··-·NI0003b850:·332d·434d·2d36·2864·290a·2020·2d20·4e49··3-CM-6(d).··-·NI
0003bb70:·5354·2d38·3030·2d35·332d·5349·2d37·0a20··ST-800-53-SI-7.·0003b860:·5354·2d38·3030·2d35·332d·5349·2d37·0a20··ST-800-53-SI-7.·
0003bb80:·202d·204e·4953·542d·3830·302d·3533·2d53···-·NIST-800-53-S0003b870:·202d·204e·4953·542d·3830·302d·3533·2d53···-·NIST-800-53-S
0003bb90:·492d·3728·3129·0a20·202d·204e·4953·542d··I-7(1).··-·NIST-0003b880:·492d·3728·3129·0a20·202d·204e·4953·542d··I-7(1).··-·NIST-
0003bba0:·3830·302d·3533·2d53·492d·3728·3629·0a20··800-53-SI-7(6).·0003b890:·3830·302d·3533·2d53·492d·3728·3629·0a20··800-53-SI-7(6).·
0003bbb0:·202d·2050·4349·2d44·5353·2d52·6571·2d31···-·PCI-DSS-Req-10003b8a0:·202d·2050·4349·2d44·5353·2d52·6571·2d31···-·PCI-DSS-Req-1
0003bbc0:·312e·350a·2020·2d20·5043·492d·4453·5376··1.5.··-·PCI-DSSv0003b8b0:·312e·350a·2020·2d20·5043·492d·4453·5376··1.5.··-·PCI-DSSv
0003bbd0:·342d·3131·2e35·2e32·0a20·202d·2068·6967··4-11.5.2.··-·hig0003b8c0:·342d·3131·2e35·2e32·0a20·202d·2068·6967··4-11.5.2.··-·hig
0003bbe0:·685f·636f·6d70·6c65·7869·7479·0a20·202d··h_complexity.··-0003b8d0:·685f·636f·6d70·6c65·7869·7479·0a20·202d··h_complexity.··-
0003bbf0:·2068·6967·685f·7365·7665·7269·7479·0a20···high_severity.·0003b8e0:·2068·6967·685f·7365·7665·7269·7479·0a20···high_severity.·
0003bc00:·202d·206d·6564·6975·6d5f·6469·7372·7570···-·medium_disrup0003b8f0:·202d·206d·6564·6975·6d5f·6469·7372·7570···-·medium_disrup
0003bc10:·7469·6f6e·0a20·202d·206e·6f5f·7265·626f··tion.··-·no_rebo0003b900:·7469·6f6e·0a20·202d·206e·6f5f·7265·626f··tion.··-·no_rebo
Max diff block lines reached; 6299374/6341380 bytes (99.34%) of diff not shown.
678 KB
html2text {}
    
Offset 42, 15 lines modifiedOffset 42, 15 lines modified
42 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Australian·Cyber·Security·Centre·(ACSC)·Essential·Eight43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Australian·Cyber·Security·Centre·(ACSC)·Essential·Eight
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_e844 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_e8
45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
46 ····*·cpe:/o:redhat:enterprise_linux:1046 ····*·cpe:/o:redhat:enterprise_linux:10
47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
48 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8448 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
54 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g54 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
55 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s55 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
56 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s56 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 105, 27 lines modifiedOffset 105, 14 lines modified
105 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6105 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
106 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4106 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
107 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)107 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
108 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1108 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
109 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5109 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
110 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227110 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
111 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2111 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
113 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
114 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
115 if·[·-n·"$files_with_incorrect_hash"·];·then 
116 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
117 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
118 ····dnf·reinstall·-y·$packages_to_reinstall 
  
119 fi 
120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
121 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high113 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
122 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium114 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
123 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false115 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
124 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict116 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
125 -·name:·'Set·fact:·Package·manager·reinstall·command'117 -·name:·'Set·fact:·Package·manager·reinstall·command'
126 ··set_fact:118 ··set_fact:
Offset 257, 14 lines modifiedOffset 244, 27 lines modified
257 ··-·PCI-DSSv4-11.5.2244 ··-·PCI-DSSv4-11.5.2
258 ··-·high_complexity245 ··-·high_complexity
259 ··-·high_severity246 ··-·high_severity
260 ··-·medium_disruption247 ··-·medium_disruption
261 ··-·no_reboot_needed248 ··-·no_reboot_needed
262 ··-·restrict_strategy249 ··-·restrict_strategy
263 ··-·rpm_verify_hashes250 ··-·rpm_verify_hashes
 251 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 252 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 253 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 254 if·[·-n·"$files_with_incorrect_hash"·];·then
 255 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 256 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 257 ····dnf·reinstall·-y·$packages_to_reinstall
  
 258 fi
264 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*259 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
265 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:260 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
266 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'261 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
267 run·the·following·command·to·determine·which·package·owns·it:262 run·the·following·command·to·determine·which·package·owns·it:
268 $·rpm·-qf·FILENAME263 $·rpm·-qf·FILENAME
269 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:264 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
270 $·sudo·rpm·--setugids·PACKAGENAME265 $·sudo·rpm·--setugids·PACKAGENAME
Offset 284, 40 lines modifiedOffset 284, 14 lines modified
284 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5284 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
285 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2285 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
286 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)286 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
287 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1287 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
288 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5288 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
289 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108289 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
290 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2290 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
291 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
292 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
293 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
294 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
295 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
296 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
297 declare·-A·SETPERMS_RPM_DICT 
  
298 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
299 #·is·expected·by·the·RPM·database 
300 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
301 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
302 do 
303 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
304 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
305 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
306 done 
  
307 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
308 #·correct·values 
309 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
310 do 
311 ········rpm·--setugids·"${RPM_PACKAGE}" 
312 done 
313 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8291 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
314 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high292 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
315 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium293 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
316 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false294 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
317 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict295 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
318 -·name:·Read·list·of·files·with·incorrect·ownership296 -·name:·Read·list·of·files·with·incorrect·ownership
319 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev297 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 395, 14 lines modifiedOffset 369, 40 lines modified
395 ··-·PCI-DSSv4-11.5.2369 ··-·PCI-DSSv4-11.5.2
396 ··-·high_complexity370 ··-·high_complexity
397 ··-·high_severity371 ··-·high_severity
398 ··-·medium_disruption372 ··-·medium_disruption
399 ··-·no_reboot_needed373 ··-·no_reboot_needed
400 ··-·restrict_strategy374 ··-·restrict_strategy
401 ··-·rpm_verify_ownership375 ··-·rpm_verify_ownership
 376 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 377 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 378 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 379 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 380 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 381 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 686622/694408 bytes (98.88%) of diff not shown.
20.3 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-hipaa.html
    
Offset 14325, 16 lines modifiedOffset 14325, 16 lines modified
00037f40:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><00037f40:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><
00037f50:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio00037f50:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio
00037f60:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.700037f60:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.7
00037f70:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u00037f70:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u
00037f80:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr00037f80:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr
00037f90:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···00037f90:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···
00037fa0:·2020·2020·2020·2020·2020·2020·2020·2020··················00037fa0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037fb0:·2028·6173·206f·6620·3230·3236·2d30·312d···(as·of·2026-01-00037fb0:·2028·6173·206f·6620·3230·3234·2d31·322d···(as·of·2024-12-
00037fc0:·3038·290a·2020·2020·2020·2020·2020·2020··08).············00037fc0:·3037·290a·2020·2020·2020·2020·2020·2020··07).············
00037fd0:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></00037fd0:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></
00037fe0:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of00037fe0:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of
00037ff0:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o00037ff0:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o
00038000:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#00038000:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#
00038010:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro00038010:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro
00038020:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro00038020:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro
00038030:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste00038030:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste
Offset 15209, 306 lines modifiedOffset 15209, 306 lines modified
0003b680:·612d·7461·7267·6574·3d22·2369·646d·3639··a-target="#idm690003b680:·612d·7461·7267·6574·3d22·2369·646d·3639··a-target="#idm69
0003b690:·3038·2220·7461·6269·6e64·6578·3d22·3022··08"·tabindex="0"0003b690:·3038·2220·7461·6269·6e64·6578·3d22·3022··08"·tabindex="0"
0003b6a0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003b6a0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003b6b0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003b6b0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003b6c0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003b6c0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003b6d0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003b6d0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003b6e0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003b6e0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003b6f0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
0003b700:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
0003b710:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003b720:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003b730:·6522·2069·643d·2269·646d·3639·3038·223e··e"·id="idm6908"> 
0003b740:·3c70·7265·3e3c·636f·6465·3e0a·2320·4669··<pre><code>.#·Fi 
0003b750:·6e64·2077·6869·6368·2066·696c·6573·2068··nd·which·files·h 
0003b760:·6176·6520·696e·636f·7272·6563·7420·6861··ave·incorrect·ha 
0003b770:·7368·2028·6e6f·7420·696e·202f·6574·632c··sh·(not·in·/etc, 
0003b780:·2062·6563·6175·7365·206f·6620·7468·6520···because·of·the· 
0003b790:·7379·7374·656d·2072·656c·6174·6564·2063··system·related·c 
0003b7a0:·6f6e·6669·6720·6669·6c65·7329·2061·6e64··onfig·files)·and 
0003b7b0:·2074·6865·6e20·6765·7420·6669·6c65·7320···then·get·files· 
0003b7c0:·6e61·6d65·730a·6669·6c65·735f·7769·7468··names.files_with 
0003b7d0:·5f69·6e63·6f72·7265·6374·5f68·6173·683d··_incorrect_hash= 
0003b7e0:·2224·2872·706d·202d·5661·202d·2d6e·6f63··"$(rpm·-Va·--noc 
0003b7f0:·6f6e·6669·6720·7c20·6772·6570·202d·4520··onfig·|·grep·-E· 
0003b800:·275e·2e2e·3527·207c·2061·776b·2027·7b70··'^..5'·|·awk·'{p 
0003b810:·7269·6e74·2024·4e46·7d27·2029·220a·0a69··rint·$NF}'·)"..i 
0003b820:·6620·5b20·2d6e·2022·2466·696c·6573·5f77··f·[·-n·"$files_w 
0003b830:·6974·685f·696e·636f·7272·6563·745f·6861··ith_incorrect_ha 
0003b840:·7368·2220·5d3b·2074·6865·6e0a·2020·2020··sh"·];·then.···· 
0003b850:·2320·4672·6f6d·2066·696c·6573·206e·616d··#·From·files·nam 
0003b860:·6573·2067·6574·2070·6163·6b61·6765·206e··es·get·package·n 
0003b870:·616d·6573·2061·6e64·2063·6861·6e67·6520··ames·and·change· 
0003b880:·6e65·776c·696e·6520·746f·2073·7061·6365··newline·to·space 
0003b890:·2c20·6265·6361·7573·6520·7270·6d20·7772··,·because·rpm·wr 
0003b8a0:·6974·6573·2065·6163·6820·7061·636b·6167··ites·each·packag 
0003b8b0:·6520·746f·206e·6577·206c·696e·650a·2020··e·to·new·line.·· 
0003b8c0:·2020·7061·636b·6167·6573·5f74·6f5f·7265····packages_to_re 
0003b8d0:·696e·7374·616c·6c3d·2224·2872·706d·202d··install="$(rpm·- 
0003b8e0:·7166·2024·6669·6c65·735f·7769·7468·5f69··qf·$files_with_i 
0003b8f0:·6e63·6f72·7265·6374·5f68·6173·6820·7c20··ncorrect_hash·|· 
0003b900:·7472·2027·5c6e·2720·2720·2729·220a·0a20··tr·'\n'·'·')"..· 
0003b910:·2020·200a·2020·2020·646e·6620·7265·696e·····.····dnf·rein 
0003b920:·7374·616c·6c20·2d79·2024·7061·636b·6167··stall·-y·$packag 
0003b930:·6573·5f74·6f5f·7265·696e·7374·616c·6c0a··es_to_reinstall. 
0003b940:·2020·2020·0a66·690a·3c2f·636f·6465·3e3c······.fi.</code>< 
0003b950:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003b960:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003b970:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003b980:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003b990:·612d·7461·7267·6574·3d22·2369·646d·3639··a-target="#idm69 
0003b9a0:·3039·2220·7461·6269·6e64·6578·3d22·3022··09"·tabindex="0" 
0003b9b0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003b9c0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003b9d0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003b9e0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003b9f0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003ba00:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn0003b6f0:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn
0003ba10:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003b700:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003ba20:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003b710:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003ba30:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003b720:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003ba40:·6170·7365·2220·6964·3d22·6964·6d36·3930··apse"·id="idm6900003b730:·6170·7365·2220·6964·3d22·6964·6d36·3930··apse"·id="idm690
0003ba50:·3922·3e3c·7461·626c·6520·636c·6173·733d··9"><table·class=0003b740:·3822·3e3c·7461·626c·6520·636c·6173·733d··8"><table·class=
0003ba60:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003b750:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003ba70:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003b760:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003ba80:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003b770:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003ba90:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003b780:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003baa0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003b790:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003bab0:·3e68·6967·683c·2f74·643e·3c2f·7472·3e3c··>high</td></tr><0003b7a0:·3e68·6967·683c·2f74·643e·3c2f·7472·3e3c··>high</td></tr><
0003bac0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003b7b0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003bad0:·6e3a·3c2f·7468·3e3c·7464·3e6d·6564·6975··n:</th><td>mediu0003b7c0:·6e3a·3c2f·7468·3e3c·7464·3e6d·6564·6975··n:</th><td>mediu
0003bae0:·6d3c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··m</td></tr><tr><0003b7d0:·6d3c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··m</td></tr><tr><
0003baf0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><0003b7e0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
0003bb00:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t0003b7f0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
0003bb10:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate0003b800:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003bb20:·6779·3a3c·2f74·683e·3c74·643e·7265·7374··gy:</th><td>rest0003b810:·6779·3a3c·2f74·683e·3c74·643e·7265·7374··gy:</th><td>rest
0003bb30:·7269·6374·3c2f·7464·3e3c·2f74·723e·3c2f··rict</td></tr></0003b820:·7269·6374·3c2f·7464·3e3c·2f74·723e·3c2f··rict</td></tr></
0003bb40:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003b830:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
0003bb50:·3e2d·206e·616d·653a·2027·5365·7420·6661··>-·name:·'Set·fa0003b840:·3e2d·206e·616d·653a·2027·5365·7420·6661··>-·name:·'Set·fa
0003bb60:·6374·3a20·5061·636b·6167·6520·6d61·6e61··ct:·Package·mana0003b850:·6374·3a20·5061·636b·6167·6520·6d61·6e61··ct:·Package·mana
0003bb70:·6765·7220·7265·696e·7374·616c·6c20·636f··ger·reinstall·co0003b860:·6765·7220·7265·696e·7374·616c·6c20·636f··ger·reinstall·co
0003bb80:·6d6d·616e·6427·0a20·2073·6574·5f66·6163··mmand'.··set_fac0003b870:·6d6d·616e·6427·0a20·2073·6574·5f66·6163··mmand'.··set_fac
0003bb90:·743a·0a20·2020·2070·6163·6b61·6765·5f6d··t:.····package_m0003b880:·743a·0a20·2020·2070·6163·6b61·6765·5f6d··t:.····package_m
0003bba0:·616e·6167·6572·5f72·6569·6e73·7461·6c6c··anager_reinstall0003b890:·616e·6167·6572·5f72·6569·6e73·7461·6c6c··anager_reinstall
0003bbb0:·5f63·6d64·3a20·646e·6620·7265·696e·7374··_cmd:·dnf·reinst0003b8a0:·5f63·6d64·3a20·646e·6620·7265·696e·7374··_cmd:·dnf·reinst
0003bbc0:·616c·6c20·2d79·0a20·2077·6865·6e3a·2061··all·-y.··when:·a0003b8b0:·616c·6c20·2d79·0a20·2077·6865·6e3a·2061··all·-y.··when:·a
0003bbd0:·6e73·6962·6c65·5f64·6973·7472·6962·7574··nsible_distribut0003b8c0:·6e73·6962·6c65·5f64·6973·7472·6962·7574··nsible_distribut
0003bbe0:·696f·6e20·696e·205b·2022·4665·646f·7261··ion·in·[·"Fedora0003b8d0:·696f·6e20·696e·205b·2022·4665·646f·7261··ion·in·[·"Fedora
0003bbf0:·222c·2022·5265·6448·6174·222c·2022·4365··",·"RedHat",·"Ce0003b8e0:·222c·2022·5265·6448·6174·222c·2022·4365··",·"RedHat",·"Ce
0003bc00:·6e74·4f53·222c·2022·4f72·6163·6c65·4c69··ntOS",·"OracleLi0003b8f0:·6e74·4f53·222c·2022·4f72·6163·6c65·4c69··ntOS",·"OracleLi
0003bc10:·6e75·7822·205d·0a20·2074·6167·733a·0a20··nux"·].··tags:.·0003b900:·6e75·7822·205d·0a20·2074·6167·733a·0a20··nux"·].··tags:.·
0003bc20:·202d·2043·4345·2d38·3939·3434·2d33·0a20···-·CCE-89944-3.·0003b910:·202d·2043·4345·2d38·3939·3434·2d33·0a20···-·CCE-89944-3.·
0003bc30:·202d·2043·4a49·532d·352e·3130·2e34·2e31···-·CJIS-5.10.4.10003b920:·202d·2043·4a49·532d·352e·3130·2e34·2e31···-·CJIS-5.10.4.1
0003bc40:·0a20·202d·204e·4953·542d·3830·302d·3137··.··-·NIST-800-170003b930:·0a20·202d·204e·4953·542d·3830·302d·3137··.··-·NIST-800-17
0003bc50:·312d·332e·332e·380a·2020·2d20·4e49·5354··1-3.3.8.··-·NIST0003b940:·312d·332e·332e·380a·2020·2d20·4e49·5354··1-3.3.8.··-·NIST
0003bc60:·2d38·3030·2d31·3731·2d33·2e34·2e31·0a20··-800-171-3.4.1.·0003b950:·2d38·3030·2d31·3731·2d33·2e34·2e31·0a20··-800-171-3.4.1.·
0003bc70:·202d·204e·4953·542d·3830·302d·3533·2d41···-·NIST-800-53-A0003b960:·202d·204e·4953·542d·3830·302d·3533·2d41···-·NIST-800-53-A
0003bc80:·552d·3928·3329·0a20·202d·204e·4953·542d··U-9(3).··-·NIST-0003b970:·552d·3928·3329·0a20·202d·204e·4953·542d··U-9(3).··-·NIST-
0003bc90:·3830·302d·3533·2d43·4d2d·3628·6329·0a20··800-53-CM-6(c).·0003b980:·3830·302d·3533·2d43·4d2d·3628·6329·0a20··800-53-CM-6(c).·
0003bca0:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C0003b990:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C
0003bcb0:·4d2d·3628·6429·0a20·202d·204e·4953·542d··M-6(d).··-·NIST-0003b9a0:·4d2d·3628·6429·0a20·202d·204e·4953·542d··M-6(d).··-·NIST-
0003bcc0:·3830·302d·3533·2d53·492d·370a·2020·2d20··800-53-SI-7.··-·0003b9b0:·3830·302d·3533·2d53·492d·370a·2020·2d20··800-53-SI-7.··-·
0003bcd0:·4e49·5354·2d38·3030·2d35·332d·5349·2d37··NIST-800-53-SI-70003b9c0:·4e49·5354·2d38·3030·2d35·332d·5349·2d37··NIST-800-53-SI-7
0003bce0:·2831·290a·2020·2d20·4e49·5354·2d38·3030··(1).··-·NIST-8000003b9d0:·2831·290a·2020·2d20·4e49·5354·2d38·3030··(1).··-·NIST-800
0003bcf0:·2d35·332d·5349·2d37·2836·290a·2020·2d20··-53-SI-7(6).··-·0003b9e0:·2d35·332d·5349·2d37·2836·290a·2020·2d20··-53-SI-7(6).··-·
0003bd00:·5043·492d·4453·532d·5265·712d·3131·2e35··PCI-DSS-Req-11.50003b9f0:·5043·492d·4453·532d·5265·712d·3131·2e35··PCI-DSS-Req-11.5
0003bd10:·0a20·202d·2050·4349·2d44·5353·7634·2d31··.··-·PCI-DSSv4-10003ba00:·0a20·202d·2050·4349·2d44·5353·7634·2d31··.··-·PCI-DSSv4-1
0003bd20:·312e·352e·320a·2020·2d20·6869·6768·5f63··1.5.2.··-·high_c0003ba10:·312e·352e·320a·2020·2d20·6869·6768·5f63··1.5.2.··-·high_c
0003bd30:·6f6d·706c·6578·6974·790a·2020·2d20·6869··omplexity.··-·hi0003ba20:·6f6d·706c·6578·6974·790a·2020·2d20·6869··omplexity.··-·hi
0003bd40:·6768·5f73·6576·6572·6974·790a·2020·2d20··gh_severity.··-·0003ba30:·6768·5f73·6576·6572·6974·790a·2020·2d20··gh_severity.··-·
0003bd50:·6d65·6469·756d·5f64·6973·7275·7074·696f··medium_disruptio0003ba40:·6d65·6469·756d·5f64·6973·7275·7074·696f··medium_disruptio
Max diff block lines reached; 19616520/19658664 bytes (99.79%) of diff not shown.
1.52 MB
html2text {}
    
Offset 48, 15 lines modifiedOffset 48, 15 lines modified
48 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Health·Insurance·Portability·and·Accountability·Act48 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Health·Insurance·Portability·and·Accountability·Act
49 ··············(HIPAA)49 ··············(HIPAA)
50 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_hipaa50 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_hipaa
51 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*51 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
52 ····*·cpe:/o:redhat:enterprise_linux:1052 ····*·cpe:/o:redhat:enterprise_linux:10
53 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*53 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
54 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8454 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
55 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)55 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
56 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*56 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
57 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s57 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
58 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e58 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
59 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l59 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
60 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n60 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
61 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g61 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
62 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s62 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 111, 27 lines modifiedOffset 111, 14 lines modified
111 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6111 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
112 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4112 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
113 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)113 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
114 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1114 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
115 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5115 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
116 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227116 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
117 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2117 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
119 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
120 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
121 if·[·-n·"$files_with_incorrect_hash"·];·then 
122 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
123 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
124 ····dnf·reinstall·-y·$packages_to_reinstall 
  
125 fi 
126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
131 -·name:·'Set·fact:·Package·manager·reinstall·command'123 -·name:·'Set·fact:·Package·manager·reinstall·command'
132 ··set_fact:124 ··set_fact:
Offset 263, 14 lines modifiedOffset 250, 27 lines modified
263 ··-·PCI-DSSv4-11.5.2250 ··-·PCI-DSSv4-11.5.2
264 ··-·high_complexity251 ··-·high_complexity
265 ··-·high_severity252 ··-·high_severity
266 ··-·medium_disruption253 ··-·medium_disruption
267 ··-·no_reboot_needed254 ··-·no_reboot_needed
268 ··-·restrict_strategy255 ··-·restrict_strategy
269 ··-·rpm_verify_hashes256 ··-·rpm_verify_hashes
 257 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 258 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 259 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 260 if·[·-n·"$files_with_incorrect_hash"·];·then
 261 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 262 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 263 ····dnf·reinstall·-y·$packages_to_reinstall
  
 264 fi
270 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*265 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
271 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:266 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:
272 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'267 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'
273 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:268 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:
274 $·rpm·-qf·FILENAME269 $·rpm·-qf·FILENAME
  
275 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:270 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
Offset 292, 44 lines modifiedOffset 292, 14 lines modified
292 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5292 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
293 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2293 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
294 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)294 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)
295 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1295 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
296 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5296 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
297 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108297 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108
298 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2298 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
299 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
300 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
301 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
302 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
303 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
304 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
305 declare·-A·SETPERMS_RPM_DICT 
  
306 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
307 #·is·expected·by·the·RPM·database 
308 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}') 
  
309 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
310 do 
311 ········#·NOTE:·some·files·maybe·controlled·by·more·then·one·package 
312 ········readarray·-t·RPM_PACKAGES·<·<(rpm·-qf·"${FILE_PATH}") 
313 ········for·RPM_PACKAGE·in·"${RPM_PACKAGES[@]}" 
314 ········do 
315 ················#·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
316 ················SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
317 ········done 
318 done 
  
319 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
320 #·correct·values 
321 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
322 do 
323 »       rpm·--restore·"${RPM_PACKAGE}" 
324 done 
325 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8299 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
326 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high300 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
327 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium301 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
328 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false302 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
329 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict303 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
330 -·name:·Read·list·of·files·with·incorrect·permissions304 -·name:·Read·list·of·files·with·incorrect·permissions
331 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev305 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 410, 14 lines modifiedOffset 380, 44 lines modified
410 ··-·PCI-DSSv4-11.5.2380 ··-·PCI-DSSv4-11.5.2
411 ··-·high_complexity381 ··-·high_complexity
412 ··-·high_severity382 ··-·high_severity
413 ··-·medium_disruption383 ··-·medium_disruption
414 ··-·no_reboot_needed384 ··-·no_reboot_needed
415 ··-·restrict_strategy385 ··-·restrict_strategy
416 ··-·rpm_verify_permissions386 ··-·rpm_verify_permissions
 387 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 388 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 389 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
Max diff block lines reached; 1590671/1598903 bytes (99.49%) of diff not shown.
11.6 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-ism_o.html
    
Offset 14313, 16 lines modifiedOffset 14313, 16 lines modified
00037e80:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><00037e80:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><
00037e90:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio00037e90:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio
00037ea0:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.700037ea0:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.7
00037eb0:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u00037eb0:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u
00037ec0:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr00037ec0:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr
00037ed0:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···00037ed0:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···
00037ee0:·2020·2020·2020·2020·2020·2020·2020·2020··················00037ee0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037ef0:·2028·6173·206f·6620·3230·3236·2d30·312d···(as·of·2026-01-00037ef0:·2028·6173·206f·6620·3230·3234·2d31·322d···(as·of·2024-12-
00037f00:·3038·290a·2020·2020·2020·2020·2020·2020··08).············00037f00:·3037·290a·2020·2020·2020·2020·2020·2020··07).············
00037f10:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></00037f10:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></
00037f20:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of00037f20:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of
00037f30:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o00037f30:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o
00037f40:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#00037f40:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#
00037f50:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro00037f50:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro
00037f60:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro00037f60:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro
00037f70:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste00037f70:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste
Offset 15232, 306 lines modifiedOffset 15232, 306 lines modified
0003b7f0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b7f0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003b800:·646d·3639·3038·2220·7461·6269·6e64·6578··dm6908"·tabindex0003b800:·646d·3639·3038·2220·7461·6269·6e64·6578··dm6908"·tabindex
0003b810:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b810:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b820:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b820:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b830:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b830:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b840:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b840:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b850:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b850:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003b860:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
0003b870:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003b880:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003b890:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003b8a0:·6c61·7073·6522·2069·643d·2269·646d·3639··lapse"·id="idm69 
0003b8b0:·3038·223e·3c70·7265·3e3c·636f·6465·3e0a··08"><pre><code>. 
0003b8c0:·2320·4669·6e64·2077·6869·6368·2066·696c··#·Find·which·fil 
0003b8d0:·6573·2068·6176·6520·696e·636f·7272·6563··es·have·incorrec 
0003b8e0:·7420·6861·7368·2028·6e6f·7420·696e·202f··t·hash·(not·in·/ 
0003b8f0:·6574·632c·2062·6563·6175·7365·206f·6620··etc,·because·of· 
0003b900:·7468·6520·7379·7374·656d·2072·656c·6174··the·system·relat 
0003b910:·6564·2063·6f6e·6669·6720·6669·6c65·7329··ed·config·files) 
0003b920:·2061·6e64·2074·6865·6e20·6765·7420·6669···and·then·get·fi 
0003b930:·6c65·7320·6e61·6d65·730a·6669·6c65·735f··les·names.files_ 
0003b940:·7769·7468·5f69·6e63·6f72·7265·6374·5f68··with_incorrect_h 
0003b950:·6173·683d·2224·2872·706d·202d·5661·202d··ash="$(rpm·-Va·- 
0003b960:·2d6e·6f63·6f6e·6669·6720·7c20·6772·6570··-noconfig·|·grep 
0003b970:·202d·4520·275e·2e2e·3527·207c·2061·776b···-E·'^..5'·|·awk 
0003b980:·2027·7b70·7269·6e74·2024·4e46·7d27·2029···'{print·$NF}'·) 
0003b990:·220a·0a69·6620·5b20·2d6e·2022·2466·696c··"..if·[·-n·"$fil 
0003b9a0:·6573·5f77·6974·685f·696e·636f·7272·6563··es_with_incorrec 
0003b9b0:·745f·6861·7368·2220·5d3b·2074·6865·6e0a··t_hash"·];·then. 
0003b9c0:·2020·2020·2320·4672·6f6d·2066·696c·6573······#·From·files 
0003b9d0:·206e·616d·6573·2067·6574·2070·6163·6b61···names·get·packa 
0003b9e0:·6765·206e·616d·6573·2061·6e64·2063·6861··ge·names·and·cha 
0003b9f0:·6e67·6520·6e65·776c·696e·6520·746f·2073··nge·newline·to·s 
0003ba00:·7061·6365·2c20·6265·6361·7573·6520·7270··pace,·because·rp 
0003ba10:·6d20·7772·6974·6573·2065·6163·6820·7061··m·writes·each·pa 
0003ba20:·636b·6167·6520·746f·206e·6577·206c·696e··ckage·to·new·lin 
0003ba30:·650a·2020·2020·7061·636b·6167·6573·5f74··e.····packages_t 
0003ba40:·6f5f·7265·696e·7374·616c·6c3d·2224·2872··o_reinstall="$(r 
0003ba50:·706d·202d·7166·2024·6669·6c65·735f·7769··pm·-qf·$files_wi 
0003ba60:·7468·5f69·6e63·6f72·7265·6374·5f68·6173··th_incorrect_has 
0003ba70:·6820·7c20·7472·2027·5c6e·2720·2720·2729··h·|·tr·'\n'·'·') 
0003ba80:·220a·0a20·2020·200a·2020·2020·646e·6620··"..····.····dnf· 
0003ba90:·7265·696e·7374·616c·6c20·2d79·2024·7061··reinstall·-y·$pa 
0003baa0:·636b·6167·6573·5f74·6f5f·7265·696e·7374··ckages_to_reinst 
0003bab0:·616c·6c0a·2020·2020·0a66·690a·3c2f·636f··all.····.fi.</co 
0003bac0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003bad0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003bae0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003baf0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003bb00:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003bb10:·646d·3639·3039·2220·7461·6269·6e64·6578··dm6909"·tabindex 
0003bb20:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003bb30:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003bb40:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003bb50:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003bb60:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003bb70:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl0003b860:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl
0003bb80:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a0003b870:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a
0003bb90:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003b880:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003bba0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003b890:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003bbb0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003b8a0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003bbc0:·6d36·3930·3922·3e3c·7461·626c·6520·636c··m6909"><table·cl0003b8b0:·6d36·3930·3822·3e3c·7461·626c·6520·636c··m6908"><table·cl
0003bbd0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003b8c0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003bbe0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003b8d0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003bbf0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003b8e0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003bc00:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003b8f0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003bc10:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003b900:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003bc20:·3e3c·7464·3e68·6967·683c·2f74·643e·3c2f··><td>high</td></0003b910:·3e3c·7464·3e68·6967·683c·2f74·643e·3c2f··><td>high</td></
0003bc30:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru0003b920:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003bc40:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6d··ption:</th><td>m0003b930:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6d··ption:</th><td>m
0003bc50:·6564·6975·6d3c·2f74·643e·3c2f·7472·3e3c··edium</td></tr><0003b940:·6564·6975·6d3c·2f74·643e·3c2f·7472·3e3c··edium</td></tr><
0003bc60:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</0003b950:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
0003bc70:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td0003b960:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
0003bc80:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St0003b970:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
0003bc90:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003b980:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0003bca0:·7265·7374·7269·6374·3c2f·7464·3e3c·2f74··restrict</td></t0003b990:·7265·7374·7269·6374·3c2f·7464·3e3c·2f74··restrict</td></t
0003bcb0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003b9a0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
0003bcc0:·636f·6465·3e2d·206e·616d·653a·2027·5365··code>-·name:·'Se0003b9b0:·636f·6465·3e2d·206e·616d·653a·2027·5365··code>-·name:·'Se
0003bcd0:·7420·6661·6374·3a20·5061·636b·6167·6520··t·fact:·Package·0003b9c0:·7420·6661·6374·3a20·5061·636b·6167·6520··t·fact:·Package·
0003bce0:·6d61·6e61·6765·7220·7265·696e·7374·616c··manager·reinstal0003b9d0:·6d61·6e61·6765·7220·7265·696e·7374·616c··manager·reinstal
0003bcf0:·6c20·636f·6d6d·616e·6427·0a20·2073·6574··l·command'.··set0003b9e0:·6c20·636f·6d6d·616e·6427·0a20·2073·6574··l·command'.··set
0003bd00:·5f66·6163·743a·0a20·2020·2070·6163·6b61··_fact:.····packa0003b9f0:·5f66·6163·743a·0a20·2020·2070·6163·6b61··_fact:.····packa
0003bd10:·6765·5f6d·616e·6167·6572·5f72·6569·6e73··ge_manager_reins0003ba00:·6765·5f6d·616e·6167·6572·5f72·6569·6e73··ge_manager_reins
0003bd20:·7461·6c6c·5f63·6d64·3a20·646e·6620·7265··tall_cmd:·dnf·re0003ba10:·7461·6c6c·5f63·6d64·3a20·646e·6620·7265··tall_cmd:·dnf·re
0003bd30:·696e·7374·616c·6c20·2d79·0a20·2077·6865··install·-y.··whe0003ba20:·696e·7374·616c·6c20·2d79·0a20·2077·6865··install·-y.··whe
0003bd40:·6e3a·2061·6e73·6962·6c65·5f64·6973·7472··n:·ansible_distr0003ba30:·6e3a·2061·6e73·6962·6c65·5f64·6973·7472··n:·ansible_distr
0003bd50:·6962·7574·696f·6e20·696e·205b·2022·4665··ibution·in·[·"Fe0003ba40:·6962·7574·696f·6e20·696e·205b·2022·4665··ibution·in·[·"Fe
0003bd60:·646f·7261·222c·2022·5265·6448·6174·222c··dora",·"RedHat",0003ba50:·646f·7261·222c·2022·5265·6448·6174·222c··dora",·"RedHat",
0003bd70:·2022·4365·6e74·4f53·222c·2022·4f72·6163···"CentOS",·"Orac0003ba60:·2022·4365·6e74·4f53·222c·2022·4f72·6163···"CentOS",·"Orac
0003bd80:·6c65·4c69·6e75·7822·205d·0a20·2074·6167··leLinux"·].··tag0003ba70:·6c65·4c69·6e75·7822·205d·0a20·2074·6167··leLinux"·].··tag
0003bd90:·733a·0a20·202d·2043·4345·2d38·3939·3434··s:.··-·CCE-899440003ba80:·733a·0a20·202d·2043·4345·2d38·3939·3434··s:.··-·CCE-89944
0003bda0:·2d33·0a20·202d·2043·4a49·532d·352e·3130··-3.··-·CJIS-5.100003ba90:·2d33·0a20·202d·2043·4a49·532d·352e·3130··-3.··-·CJIS-5.10
0003bdb0:·2e34·2e31·0a20·202d·204e·4953·542d·3830··.4.1.··-·NIST-800003baa0:·2e34·2e31·0a20·202d·204e·4953·542d·3830··.4.1.··-·NIST-80
0003bdc0:·302d·3137·312d·332e·332e·380a·2020·2d20··0-171-3.3.8.··-·0003bab0:·302d·3137·312d·332e·332e·380a·2020·2d20··0-171-3.3.8.··-·
0003bdd0:·4e49·5354·2d38·3030·2d31·3731·2d33·2e34··NIST-800-171-3.40003bac0:·4e49·5354·2d38·3030·2d31·3731·2d33·2e34··NIST-800-171-3.4
0003bde0:·2e31·0a20·202d·204e·4953·542d·3830·302d··.1.··-·NIST-800-0003bad0:·2e31·0a20·202d·204e·4953·542d·3830·302d··.1.··-·NIST-800-
0003bdf0:·3533·2d41·552d·3928·3329·0a20·202d·204e··53-AU-9(3).··-·N0003bae0:·3533·2d41·552d·3928·3329·0a20·202d·204e··53-AU-9(3).··-·N
0003be00:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6(0003baf0:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6(
0003be10:·6329·0a20·202d·204e·4953·542d·3830·302d··c).··-·NIST-800-0003bb00:·6329·0a20·202d·204e·4953·542d·3830·302d··c).··-·NIST-800-
0003be20:·3533·2d43·4d2d·3628·6429·0a20·202d·204e··53-CM-6(d).··-·N0003bb10:·3533·2d43·4d2d·3628·6429·0a20·202d·204e··53-CM-6(d).··-·N
0003be30:·4953·542d·3830·302d·3533·2d53·492d·370a··IST-800-53-SI-7.0003bb20:·4953·542d·3830·302d·3533·2d53·492d·370a··IST-800-53-SI-7.
0003be40:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-0003bb30:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
0003be50:·5349·2d37·2831·290a·2020·2d20·4e49·5354··SI-7(1).··-·NIST0003bb40:·5349·2d37·2831·290a·2020·2d20·4e49·5354··SI-7(1).··-·NIST
0003be60:·2d38·3030·2d35·332d·5349·2d37·2836·290a··-800-53-SI-7(6).0003bb50:·2d38·3030·2d35·332d·5349·2d37·2836·290a··-800-53-SI-7(6).
0003be70:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req-0003bb60:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req-
0003be80:·3131·2e35·0a20·202d·2050·4349·2d44·5353··11.5.··-·PCI-DSS0003bb70:·3131·2e35·0a20·202d·2050·4349·2d44·5353··11.5.··-·PCI-DSS
0003be90:·7634·2d31·312e·352e·320a·2020·2d20·6869··v4-11.5.2.··-·hi0003bb80:·7634·2d31·312e·352e·320a·2020·2d20·6869··v4-11.5.2.··-·hi
0003bea0:·6768·5f63·6f6d·706c·6578·6974·790a·2020··gh_complexity.··0003bb90:·6768·5f63·6f6d·706c·6578·6974·790a·2020··gh_complexity.··
0003beb0:·2d20·6869·6768·5f73·6576·6572·6974·790a··-·high_severity.0003bba0:·2d20·6869·6768·5f73·6576·6572·6974·790a··-·high_severity.
0003bec0:·2020·2d20·6d65·6469·756d·5f64·6973·7275····-·medium_disru0003bbb0:·2020·2d20·6d65·6469·756d·5f64·6973·7275····-·medium_disru
Max diff block lines reached; 10885206/10927350 bytes (99.61%) of diff not shown.
1.15 MB
html2text {}
    
Offset 45, 15 lines modifiedOffset 45, 15 lines modified
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Australian·Cyber·Security·Centre·(ACSC)·ISM·Official·-45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Australian·Cyber·Security·Centre·(ACSC)·ISM·Official·-
46 ··············Base46 ··············Base
47 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ism_o47 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ism_o
48 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*48 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
49 ····*·cpe:/o:redhat:enterprise_linux:1049 ····*·cpe:/o:redhat:enterprise_linux:10
50 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
51 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8451 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
52 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)52 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
53 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*53 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
54 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s54 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
55 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e55 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
56 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l56 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
57 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g57 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
58 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s58 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
59 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s59 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 115, 27 lines modifiedOffset 115, 14 lines modified
115 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6115 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
116 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4116 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
117 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)117 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
118 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1118 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
119 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5119 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
120 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227120 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
121 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2121 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
123 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
124 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
125 if·[·-n·"$files_with_incorrect_hash"·];·then 
126 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
127 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
128 ····dnf·reinstall·-y·$packages_to_reinstall 
  
129 fi 
130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high123 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium124 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false125 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict126 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
135 -·name:·'Set·fact:·Package·manager·reinstall·command'127 -·name:·'Set·fact:·Package·manager·reinstall·command'
136 ··set_fact:128 ··set_fact:
Offset 267, 14 lines modifiedOffset 254, 27 lines modified
267 ··-·PCI-DSSv4-11.5.2254 ··-·PCI-DSSv4-11.5.2
268 ··-·high_complexity255 ··-·high_complexity
269 ··-·high_severity256 ··-·high_severity
270 ··-·medium_disruption257 ··-·medium_disruption
271 ··-·no_reboot_needed258 ··-·no_reboot_needed
272 ··-·restrict_strategy259 ··-·restrict_strategy
273 ··-·rpm_verify_hashes260 ··-·rpm_verify_hashes
 261 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 262 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 263 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 264 if·[·-n·"$files_with_incorrect_hash"·];·then
 265 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 266 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 267 ····dnf·reinstall·-y·$packages_to_reinstall
  
 268 fi
274 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*269 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
275 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:270 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
276 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'271 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
277 run·the·following·command·to·determine·which·package·owns·it:272 run·the·following·command·to·determine·which·package·owns·it:
278 $·rpm·-qf·FILENAME273 $·rpm·-qf·FILENAME
279 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:274 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
280 $·sudo·rpm·--setugids·PACKAGENAME275 $·sudo·rpm·--setugids·PACKAGENAME
Offset 294, 40 lines modifiedOffset 294, 14 lines modified
294 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5294 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
295 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2295 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
296 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)296 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
297 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1297 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
298 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5298 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
299 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108299 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
300 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2300 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
301 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
302 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
303 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
304 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
305 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
306 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
307 declare·-A·SETPERMS_RPM_DICT 
  
308 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
309 #·is·expected·by·the·RPM·database 
310 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
311 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
312 do 
313 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
314 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
315 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
316 done 
  
317 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
318 #·correct·values 
319 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
320 do 
321 ········rpm·--setugids·"${RPM_PACKAGE}" 
322 done 
323 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8301 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
324 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high302 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
325 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium303 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
326 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false304 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
327 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict305 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
328 -·name:·Read·list·of·files·with·incorrect·ownership306 -·name:·Read·list·of·files·with·incorrect·ownership
329 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev307 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 405, 14 lines modifiedOffset 379, 40 lines modified
405 ··-·PCI-DSSv4-11.5.2379 ··-·PCI-DSSv4-11.5.2
406 ··-·high_complexity380 ··-·high_complexity
407 ··-·high_severity381 ··-·high_severity
408 ··-·medium_disruption382 ··-·medium_disruption
409 ··-·no_reboot_needed383 ··-·no_reboot_needed
410 ··-·restrict_strategy384 ··-·restrict_strategy
411 ··-·rpm_verify_ownership385 ··-·rpm_verify_ownership
 386 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 387 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 388 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 389 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 390 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 391 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 1193404/1201119 bytes (99.36%) of diff not shown.
11.6 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-ism_o_secret.html
    
Offset 14317, 16 lines modifiedOffset 14317, 16 lines modified
00037ec0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p00037ec0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p
00037ed0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version00037ed0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version
00037ee0:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.7400037ee0:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.74
00037ef0:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul00037ef0:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul
00037f00:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra00037f00:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra
00037f10:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····00037f10:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····
00037f20:·2020·2020·2020·2020·2020·2020·2020·2020··················00037f20:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037f30:·2861·7320·6f66·2032·3032·362d·3031·2d30··(as·of·2026-01-000037f30:·2861·7320·6f66·2032·3032·342d·3132·2d30··(as·of·2024-12-0
00037f40:·3829·0a20·2020·2020·2020·2020·2020·2020··8).·············00037f40:·3729·0a20·2020·2020·2020·2020·2020·2020··7).·············
00037f50:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d00037f50:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d
00037f60:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·00037f60:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·
00037f70:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol00037f70:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol
00037f80:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x00037f80:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x
00037f90:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj00037f90:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj
00037fa0:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou00037fa0:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou
00037fb0:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System00037fb0:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System
Offset 15236, 306 lines modifiedOffset 15236, 306 lines modified
0003b830:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003b830:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003b840:·6d36·3930·3822·2074·6162·696e·6465·783d··m6908"·tabindex=0003b840:·6d36·3930·3822·2074·6162·696e·6465·783d··m6908"·tabindex=
0003b850:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003b850:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003b860:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003b860:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003b870:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003b870:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003b880:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003b880:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003b890:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003b890:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003b8a0:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s 
0003b8b0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003b8c0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003b8d0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003b8e0:·6170·7365·2220·6964·3d22·6964·6d36·3930··apse"·id="idm690 
0003b8f0:·3822·3e3c·7072·653e·3c63·6f64·653e·0a23··8"><pre><code>.# 
0003b900:·2046·696e·6420·7768·6963·6820·6669·6c65···Find·which·file 
0003b910:·7320·6861·7665·2069·6e63·6f72·7265·6374··s·have·incorrect 
0003b920:·2068·6173·6820·286e·6f74·2069·6e20·2f65···hash·(not·in·/e 
0003b930:·7463·2c20·6265·6361·7573·6520·6f66·2074··tc,·because·of·t 
0003b940:·6865·2073·7973·7465·6d20·7265·6c61·7465··he·system·relate 
0003b950:·6420·636f·6e66·6967·2066·696c·6573·2920··d·config·files)· 
0003b960:·616e·6420·7468·656e·2067·6574·2066·696c··and·then·get·fil 
0003b970:·6573·206e·616d·6573·0a66·696c·6573·5f77··es·names.files_w 
0003b980:·6974·685f·696e·636f·7272·6563·745f·6861··ith_incorrect_ha 
0003b990:·7368·3d22·2428·7270·6d20·2d56·6120·2d2d··sh="$(rpm·-Va·-- 
0003b9a0:·6e6f·636f·6e66·6967·207c·2067·7265·7020··noconfig·|·grep· 
0003b9b0:·2d45·2027·5e2e·2e35·2720·7c20·6177·6b20··-E·'^..5'·|·awk· 
0003b9c0:·277b·7072·696e·7420·244e·467d·2720·2922··'{print·$NF}'·)" 
0003b9d0:·0a0a·6966·205b·202d·6e20·2224·6669·6c65··..if·[·-n·"$file 
0003b9e0:·735f·7769·7468·5f69·6e63·6f72·7265·6374··s_with_incorrect 
0003b9f0:·5f68·6173·6822·205d·3b20·7468·656e·0a20··_hash"·];·then.· 
0003ba00:·2020·2023·2046·726f·6d20·6669·6c65·7320·····#·From·files· 
0003ba10:·6e61·6d65·7320·6765·7420·7061·636b·6167··names·get·packag 
0003ba20:·6520·6e61·6d65·7320·616e·6420·6368·616e··e·names·and·chan 
0003ba30:·6765·206e·6577·6c69·6e65·2074·6f20·7370··ge·newline·to·sp 
0003ba40:·6163·652c·2062·6563·6175·7365·2072·706d··ace,·because·rpm 
0003ba50:·2077·7269·7465·7320·6561·6368·2070·6163···writes·each·pac 
0003ba60:·6b61·6765·2074·6f20·6e65·7720·6c69·6e65··kage·to·new·line 
0003ba70:·0a20·2020·2070·6163·6b61·6765·735f·746f··.····packages_to 
0003ba80:·5f72·6569·6e73·7461·6c6c·3d22·2428·7270··_reinstall="$(rp 
0003ba90:·6d20·2d71·6620·2466·696c·6573·5f77·6974··m·-qf·$files_wit 
0003baa0:·685f·696e·636f·7272·6563·745f·6861·7368··h_incorrect_hash 
0003bab0:·207c·2074·7220·275c·6e27·2027·2027·2922···|·tr·'\n'·'·')" 
0003bac0:·0a0a·2020·2020·0a20·2020·2064·6e66·2072··..····.····dnf·r 
0003bad0:·6569·6e73·7461·6c6c·202d·7920·2470·6163··einstall·-y·$pac 
0003bae0:·6b61·6765·735f·746f·5f72·6569·6e73·7461··kages_to_reinsta 
0003baf0:·6c6c·0a20·2020·200a·6669·0a3c·2f63·6f64··ll.····.fi.</cod 
0003bb00:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003bb10:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003bb20:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003bb30:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003bb40:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003bb50:·6d36·3930·3922·2074·6162·696e·6465·783d··m6909"·tabindex= 
0003bb60:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003bb70:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003bb80:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003bb90:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003bba0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003bbb0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible0003b8a0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible
0003bbc0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003b8b0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003bbd0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003b8c0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003bbe0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003b8d0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003bbf0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003b8e0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003bc00:·3639·3039·223e·3c74·6162·6c65·2063·6c61··6909"><table·cla0003b8f0:·3639·3038·223e·3c74·6162·6c65·2063·6c61··6908"><table·cla
0003bc10:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003b900:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003bc20:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003b910:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003bc30:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003b920:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003bc40:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003b930:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003bc50:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003b940:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003bc60:·3c74·643e·6869·6768·3c2f·7464·3e3c·2f74··<td>high</td></t0003b950:·3c74·643e·6869·6768·3c2f·7464·3e3c·2f74··<td>high</td></t
0003bc70:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003b960:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003bc80:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6d65··tion:</th><td>me0003b970:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6d65··tion:</th><td>me
0003bc90:·6469·756d·3c2f·7464·3e3c·2f74·723e·3c74··dium</td></tr><t0003b980:·6469·756d·3c2f·7464·3e3c·2f74·723e·3c74··dium</td></tr><t
0003bca0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t0003b990:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
0003bcb0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>0003b9a0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
0003bcc0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003b9b0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003bcd0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e72··ategy:</th><td>r0003b9c0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e72··ategy:</th><td>r
0003bce0:·6573·7472·6963·743c·2f74·643e·3c2f·7472··estrict</td></tr0003b9d0:·6573·7472·6963·743c·2f74·643e·3c2f·7472··estrict</td></tr
0003bcf0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003b9e0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
0003bd00:·6f64·653e·2d20·6e61·6d65·3a20·2753·6574··ode>-·name:·'Set0003b9f0:·6f64·653e·2d20·6e61·6d65·3a20·2753·6574··ode>-·name:·'Set
0003bd10:·2066·6163·743a·2050·6163·6b61·6765·206d···fact:·Package·m0003ba00:·2066·6163·743a·2050·6163·6b61·6765·206d···fact:·Package·m
0003bd20:·616e·6167·6572·2072·6569·6e73·7461·6c6c··anager·reinstall0003ba10:·616e·6167·6572·2072·6569·6e73·7461·6c6c··anager·reinstall
0003bd30:·2063·6f6d·6d61·6e64·270a·2020·7365·745f···command'.··set_0003ba20:·2063·6f6d·6d61·6e64·270a·2020·7365·745f···command'.··set_
0003bd40:·6661·6374·3a0a·2020·2020·7061·636b·6167··fact:.····packag0003ba30:·6661·6374·3a0a·2020·2020·7061·636b·6167··fact:.····packag
0003bd50:·655f·6d61·6e61·6765·725f·7265·696e·7374··e_manager_reinst0003ba40:·655f·6d61·6e61·6765·725f·7265·696e·7374··e_manager_reinst
0003bd60:·616c·6c5f·636d·643a·2064·6e66·2072·6569··all_cmd:·dnf·rei0003ba50:·616c·6c5f·636d·643a·2064·6e66·2072·6569··all_cmd:·dnf·rei
0003bd70:·6e73·7461·6c6c·202d·790a·2020·7768·656e··nstall·-y.··when0003ba60:·6e73·7461·6c6c·202d·790a·2020·7768·656e··nstall·-y.··when
0003bd80:·3a20·616e·7369·626c·655f·6469·7374·7269··:·ansible_distri0003ba70:·3a20·616e·7369·626c·655f·6469·7374·7269··:·ansible_distri
0003bd90:·6275·7469·6f6e·2069·6e20·5b20·2246·6564··bution·in·[·"Fed0003ba80:·6275·7469·6f6e·2069·6e20·5b20·2246·6564··bution·in·[·"Fed
0003bda0:·6f72·6122·2c20·2252·6564·4861·7422·2c20··ora",·"RedHat",·0003ba90:·6f72·6122·2c20·2252·6564·4861·7422·2c20··ora",·"RedHat",·
0003bdb0:·2243·656e·744f·5322·2c20·224f·7261·636c··"CentOS",·"Oracl0003baa0:·2243·656e·744f·5322·2c20·224f·7261·636c··"CentOS",·"Oracl
0003bdc0:·654c·696e·7578·2220·5d0a·2020·7461·6773··eLinux"·].··tags0003bab0:·654c·696e·7578·2220·5d0a·2020·7461·6773··eLinux"·].··tags
0003bdd0:·3a0a·2020·2d20·4343·452d·3839·3934·342d··:.··-·CCE-89944-0003bac0:·3a0a·2020·2d20·4343·452d·3839·3934·342d··:.··-·CCE-89944-
0003bde0:·330a·2020·2d20·434a·4953·2d35·2e31·302e··3.··-·CJIS-5.10.0003bad0:·330a·2020·2d20·434a·4953·2d35·2e31·302e··3.··-·CJIS-5.10.
0003bdf0:·342e·310a·2020·2d20·4e49·5354·2d38·3030··4.1.··-·NIST-8000003bae0:·342e·310a·2020·2d20·4e49·5354·2d38·3030··4.1.··-·NIST-800
0003be00:·2d31·3731·2d33·2e33·2e38·0a20·202d·204e··-171-3.3.8.··-·N0003baf0:·2d31·3731·2d33·2e33·2e38·0a20·202d·204e··-171-3.3.8.··-·N
0003be10:·4953·542d·3830·302d·3137·312d·332e·342e··IST-800-171-3.4.0003bb00:·4953·542d·3830·302d·3137·312d·332e·342e··IST-800-171-3.4.
0003be20:·310a·2020·2d20·4e49·5354·2d38·3030·2d35··1.··-·NIST-800-50003bb10:·310a·2020·2d20·4e49·5354·2d38·3030·2d35··1.··-·NIST-800-5
0003be30:·332d·4155·2d39·2833·290a·2020·2d20·4e49··3-AU-9(3).··-·NI0003bb20:·332d·4155·2d39·2833·290a·2020·2d20·4e49··3-AU-9(3).··-·NI
0003be40:·5354·2d38·3030·2d35·332d·434d·2d36·2863··ST-800-53-CM-6(c0003bb30:·5354·2d38·3030·2d35·332d·434d·2d36·2863··ST-800-53-CM-6(c
0003be50:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-50003bb40:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5
0003be60:·332d·434d·2d36·2864·290a·2020·2d20·4e49··3-CM-6(d).··-·NI0003bb50:·332d·434d·2d36·2864·290a·2020·2d20·4e49··3-CM-6(d).··-·NI
0003be70:·5354·2d38·3030·2d35·332d·5349·2d37·0a20··ST-800-53-SI-7.·0003bb60:·5354·2d38·3030·2d35·332d·5349·2d37·0a20··ST-800-53-SI-7.·
0003be80:·202d·204e·4953·542d·3830·302d·3533·2d53···-·NIST-800-53-S0003bb70:·202d·204e·4953·542d·3830·302d·3533·2d53···-·NIST-800-53-S
0003be90:·492d·3728·3129·0a20·202d·204e·4953·542d··I-7(1).··-·NIST-0003bb80:·492d·3728·3129·0a20·202d·204e·4953·542d··I-7(1).··-·NIST-
0003bea0:·3830·302d·3533·2d53·492d·3728·3629·0a20··800-53-SI-7(6).·0003bb90:·3830·302d·3533·2d53·492d·3728·3629·0a20··800-53-SI-7(6).·
0003beb0:·202d·2050·4349·2d44·5353·2d52·6571·2d31···-·PCI-DSS-Req-10003bba0:·202d·2050·4349·2d44·5353·2d52·6571·2d31···-·PCI-DSS-Req-1
0003bec0:·312e·350a·2020·2d20·5043·492d·4453·5376··1.5.··-·PCI-DSSv0003bbb0:·312e·350a·2020·2d20·5043·492d·4453·5376··1.5.··-·PCI-DSSv
0003bed0:·342d·3131·2e35·2e32·0a20·202d·2068·6967··4-11.5.2.··-·hig0003bbc0:·342d·3131·2e35·2e32·0a20·202d·2068·6967··4-11.5.2.··-·hig
0003bee0:·685f·636f·6d70·6c65·7869·7479·0a20·202d··h_complexity.··-0003bbd0:·685f·636f·6d70·6c65·7869·7479·0a20·202d··h_complexity.··-
0003bef0:·2068·6967·685f·7365·7665·7269·7479·0a20···high_severity.·0003bbe0:·2068·6967·685f·7365·7665·7269·7479·0a20···high_severity.·
0003bf00:·202d·206d·6564·6975·6d5f·6469·7372·7570···-·medium_disrup0003bbf0:·202d·206d·6564·6975·6d5f·6469·7372·7570···-·medium_disrup
Max diff block lines reached; 10884861/10927005 bytes (99.61%) of diff not shown.
1.15 MB
html2text {}
    
Offset 46, 15 lines modifiedOffset 46, 15 lines modified
46 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Australian·Cyber·Security·Centre·(ACSC)·ISM·Official·-46 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Australian·Cyber·Security·Centre·(ACSC)·ISM·Official·-
47 ··············Secret47 ··············Secret
48 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ism_o_secret48 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ism_o_secret
49 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*49 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
50 ····*·cpe:/o:redhat:enterprise_linux:1050 ····*·cpe:/o:redhat:enterprise_linux:10
51 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
52 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8452 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
53 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)53 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
54 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*54 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
55 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s55 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
56 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e56 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
57 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l57 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
58 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g58 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
59 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s59 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
60 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s60 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 116, 27 lines modifiedOffset 116, 14 lines modified
116 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6116 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
117 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4117 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
118 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)118 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
119 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1119 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
120 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5120 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
121 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227121 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
124 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
125 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
126 if·[·-n·"$files_with_incorrect_hash"·];·then 
127 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
128 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
129 ····dnf·reinstall·-y·$packages_to_reinstall 
  
130 fi 
131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high124 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium125 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false126 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict127 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
136 -·name:·'Set·fact:·Package·manager·reinstall·command'128 -·name:·'Set·fact:·Package·manager·reinstall·command'
137 ··set_fact:129 ··set_fact:
Offset 268, 14 lines modifiedOffset 255, 27 lines modified
268 ··-·PCI-DSSv4-11.5.2255 ··-·PCI-DSSv4-11.5.2
269 ··-·high_complexity256 ··-·high_complexity
270 ··-·high_severity257 ··-·high_severity
271 ··-·medium_disruption258 ··-·medium_disruption
272 ··-·no_reboot_needed259 ··-·no_reboot_needed
273 ··-·restrict_strategy260 ··-·restrict_strategy
274 ··-·rpm_verify_hashes261 ··-·rpm_verify_hashes
 262 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 263 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 264 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 265 if·[·-n·"$files_with_incorrect_hash"·];·then
 266 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 267 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 268 ····dnf·reinstall·-y·$packages_to_reinstall
  
 269 fi
275 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*270 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
276 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:271 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
277 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'272 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
278 run·the·following·command·to·determine·which·package·owns·it:273 run·the·following·command·to·determine·which·package·owns·it:
279 $·rpm·-qf·FILENAME274 $·rpm·-qf·FILENAME
280 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:275 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
281 $·sudo·rpm·--setugids·PACKAGENAME276 $·sudo·rpm·--setugids·PACKAGENAME
Offset 295, 40 lines modifiedOffset 295, 14 lines modified
295 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5295 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
296 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2296 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
297 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)297 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
298 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1298 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
299 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5299 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
300 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108300 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
301 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2301 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
302 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
303 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
304 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
305 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
306 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
307 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
308 declare·-A·SETPERMS_RPM_DICT 
  
309 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
310 #·is·expected·by·the·RPM·database 
311 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
312 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
313 do 
314 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
315 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
316 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
317 done 
  
318 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
319 #·correct·values 
320 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
321 do 
322 ········rpm·--setugids·"${RPM_PACKAGE}" 
323 done 
324 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8302 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
325 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high303 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
326 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium304 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
327 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false305 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
328 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict306 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
329 -·name:·Read·list·of·files·with·incorrect·ownership307 -·name:·Read·list·of·files·with·incorrect·ownership
330 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev308 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 406, 14 lines modifiedOffset 380, 40 lines modified
406 ··-·PCI-DSSv4-11.5.2380 ··-·PCI-DSSv4-11.5.2
407 ··-·high_complexity381 ··-·high_complexity
408 ··-·high_severity382 ··-·high_severity
409 ··-·medium_disruption383 ··-·medium_disruption
410 ··-·no_reboot_needed384 ··-·no_reboot_needed
411 ··-·restrict_strategy385 ··-·restrict_strategy
412 ··-·rpm_verify_ownership386 ··-·rpm_verify_ownership
 387 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 388 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 389 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 390 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 391 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 392 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 1193404/1201128 bytes (99.36%) of diff not shown.
11.6 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-ism_o_top_secret.html
    
Offset 14315, 15 lines modifiedOffset 14315, 15 lines modified
00037ea0:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current00037ea0:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current
00037eb0:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron00037eb0:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron
00037ec0:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong00037ec0:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong
00037ed0:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st00037ed0:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st
00037ee0:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro00037ee0:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro
00037ef0:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············00037ef0:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············
00037f00:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·200037f00:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·2
00037f10:·3032·362d·3031·2d30·3829·0a20·2020·2020··026-01-08).·····00037f10:·3032·342d·3132·2d30·3729·0a20·2020·2020··024-12-07).·····
00037f20:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>00037f20:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>
00037f30:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T00037f30:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T
00037f40:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents00037f40:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents
00037f50:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·00037f50:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·
00037f60:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org00037f60:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org
00037f70:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont00037f70:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont
00037f80:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system00037f80:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system
Offset 15234, 305 lines modifiedOffset 15234, 305 lines modified
0003b810:·6765·743d·2223·6964·6d36·3930·3822·2074··get="#idm6908"·t0003b810:·6765·743d·2223·6964·6d36·3930·3822·2074··get="#idm6908"·t
0003b820:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003b820:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003b830:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003b830:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003b840:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003b840:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003b850:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003b850:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003b860:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003b860:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003b870:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003b870:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003b880:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
0003b890:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b8a0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b8b0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b8c0:·3d22·6964·6d36·3930·3822·3e3c·7072·653e··="idm6908"><pre> 
0003b8d0:·3c63·6f64·653e·0a23·2046·696e·6420·7768··<code>.#·Find·wh 
0003b8e0:·6963·6820·6669·6c65·7320·6861·7665·2069··ich·files·have·i 
0003b8f0:·6e63·6f72·7265·6374·2068·6173·6820·286e··ncorrect·hash·(n 
0003b900:·6f74·2069·6e20·2f65·7463·2c20·6265·6361··ot·in·/etc,·beca 
0003b910:·7573·6520·6f66·2074·6865·2073·7973·7465··use·of·the·syste 
0003b920:·6d20·7265·6c61·7465·6420·636f·6e66·6967··m·related·config 
0003b930:·2066·696c·6573·2920·616e·6420·7468·656e···files)·and·then 
0003b940:·2067·6574·2066·696c·6573·206e·616d·6573···get·files·names 
0003b950:·0a66·696c·6573·5f77·6974·685f·696e·636f··.files_with_inco 
0003b960:·7272·6563·745f·6861·7368·3d22·2428·7270··rrect_hash="$(rp 
0003b970:·6d20·2d56·6120·2d2d·6e6f·636f·6e66·6967··m·-Va·--noconfig 
0003b980:·207c·2067·7265·7020·2d45·2027·5e2e·2e35···|·grep·-E·'^..5 
0003b990:·2720·7c20·6177·6b20·277b·7072·696e·7420··'·|·awk·'{print· 
0003b9a0:·244e·467d·2720·2922·0a0a·6966·205b·202d··$NF}'·)"..if·[·- 
0003b9b0:·6e20·2224·6669·6c65·735f·7769·7468·5f69··n·"$files_with_i 
0003b9c0:·6e63·6f72·7265·6374·5f68·6173·6822·205d··ncorrect_hash"·] 
0003b9d0:·3b20·7468·656e·0a20·2020·2023·2046·726f··;·then.····#·Fro 
0003b9e0:·6d20·6669·6c65·7320·6e61·6d65·7320·6765··m·files·names·ge 
0003b9f0:·7420·7061·636b·6167·6520·6e61·6d65·7320··t·package·names· 
0003ba00:·616e·6420·6368·616e·6765·206e·6577·6c69··and·change·newli 
0003ba10:·6e65·2074·6f20·7370·6163·652c·2062·6563··ne·to·space,·bec 
0003ba20:·6175·7365·2072·706d·2077·7269·7465·7320··ause·rpm·writes· 
0003ba30:·6561·6368·2070·6163·6b61·6765·2074·6f20··each·package·to· 
0003ba40:·6e65·7720·6c69·6e65·0a20·2020·2070·6163··new·line.····pac 
0003ba50:·6b61·6765·735f·746f·5f72·6569·6e73·7461··kages_to_reinsta 
0003ba60:·6c6c·3d22·2428·7270·6d20·2d71·6620·2466··ll="$(rpm·-qf·$f 
0003ba70:·696c·6573·5f77·6974·685f·696e·636f·7272··iles_with_incorr 
0003ba80:·6563·745f·6861·7368·207c·2074·7220·275c··ect_hash·|·tr·'\ 
0003ba90:·6e27·2027·2027·2922·0a0a·2020·2020·0a20··n'·'·')"..····.· 
0003baa0:·2020·2064·6e66·2072·6569·6e73·7461·6c6c·····dnf·reinstall 
0003bab0:·202d·7920·2470·6163·6b61·6765·735f·746f···-y·$packages_to 
0003bac0:·5f72·6569·6e73·7461·6c6c·0a20·2020·200a··_reinstall.····. 
0003bad0:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre> 
0003bae0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003baf0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003bb00:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003bb10:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003bb20:·6765·743d·2223·6964·6d36·3930·3922·2074··get="#idm6909"·t 
0003bb30:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003bb40:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003bb50:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003bb60:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003bb70:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003bb80:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003bb90:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet0003b880:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet
0003bba0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003b890:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003bbb0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003b8a0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003bbc0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003b8b0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003bbd0:·2069·643d·2269·646d·3639·3039·223e·3c74···id="idm6909"><t0003b8c0:·2069·643d·2269·646d·3639·3038·223e·3c74···id="idm6908"><t
0003bbe0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl0003b8d0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003bbf0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·0003b8e0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003bc00:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0003b8f0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003bc10:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">0003b900:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003bc20:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi0003b910:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003bc30:·7479·3a3c·2f74·683e·3c74·643e·6869·6768··ty:</th><td>high0003b920:·7479·3a3c·2f74·683e·3c74·643e·6869·6768··ty:</th><td>high
0003bc40:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003b930:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003bc50:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003b940:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003bc60:·683e·3c74·643e·6d65·6469·756d·3c2f·7464··h><td>medium</td0003b950:·683e·3c74·643e·6d65·6469·756d·3c2f·7464··h><td>medium</td
0003bc70:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003b960:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003bc80:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003b970:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003bc90:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003b980:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003bca0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003b990:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003bcb0:·7468·3e3c·7464·3e72·6573·7472·6963·743c··th><td>restrict<0003b9a0:·7468·3e3c·7464·3e72·6573·7472·6963·743c··th><td>restrict<
0003bcc0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003b9b0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003bcd0:·3e3c·7072·653e·3c63·6f64·653e·2d20·6e61··><pre><code>-·na0003b9c0:·3e3c·7072·653e·3c63·6f64·653e·2d20·6e61··><pre><code>-·na
0003bce0:·6d65·3a20·2753·6574·2066·6163·743a·2050··me:·'Set·fact:·P0003b9d0:·6d65·3a20·2753·6574·2066·6163·743a·2050··me:·'Set·fact:·P
0003bcf0:·6163·6b61·6765·206d·616e·6167·6572·2072··ackage·manager·r0003b9e0:·6163·6b61·6765·206d·616e·6167·6572·2072··ackage·manager·r
0003bd00:·6569·6e73·7461·6c6c·2063·6f6d·6d61·6e64··einstall·command0003b9f0:·6569·6e73·7461·6c6c·2063·6f6d·6d61·6e64··einstall·command
0003bd10:·270a·2020·7365·745f·6661·6374·3a0a·2020··'.··set_fact:.··0003ba00:·270a·2020·7365·745f·6661·6374·3a0a·2020··'.··set_fact:.··
0003bd20:·2020·7061·636b·6167·655f·6d61·6e61·6765····package_manage0003ba10:·2020·7061·636b·6167·655f·6d61·6e61·6765····package_manage
0003bd30:·725f·7265·696e·7374·616c·6c5f·636d·643a··r_reinstall_cmd:0003ba20:·725f·7265·696e·7374·616c·6c5f·636d·643a··r_reinstall_cmd:
0003bd40:·2064·6e66·2072·6569·6e73·7461·6c6c·202d···dnf·reinstall·-0003ba30:·2064·6e66·2072·6569·6e73·7461·6c6c·202d···dnf·reinstall·-
0003bd50:·790a·2020·7768·656e·3a20·616e·7369·626c··y.··when:·ansibl0003ba40:·790a·2020·7768·656e·3a20·616e·7369·626c··y.··when:·ansibl
0003bd60:·655f·6469·7374·7269·6275·7469·6f6e·2069··e_distribution·i0003ba50:·655f·6469·7374·7269·6275·7469·6f6e·2069··e_distribution·i
0003bd70:·6e20·5b20·2246·6564·6f72·6122·2c20·2252··n·[·"Fedora",·"R0003ba60:·6e20·5b20·2246·6564·6f72·6122·2c20·2252··n·[·"Fedora",·"R
0003bd80:·6564·4861·7422·2c20·2243·656e·744f·5322··edHat",·"CentOS"0003ba70:·6564·4861·7422·2c20·2243·656e·744f·5322··edHat",·"CentOS"
0003bd90:·2c20·224f·7261·636c·654c·696e·7578·2220··,·"OracleLinux"·0003ba80:·2c20·224f·7261·636c·654c·696e·7578·2220··,·"OracleLinux"·
0003bda0:·5d0a·2020·7461·6773·3a0a·2020·2d20·4343··].··tags:.··-·CC0003ba90:·5d0a·2020·7461·6773·3a0a·2020·2d20·4343··].··tags:.··-·CC
0003bdb0:·452d·3839·3934·342d·330a·2020·2d20·434a··E-89944-3.··-·CJ0003baa0:·452d·3839·3934·342d·330a·2020·2d20·434a··E-89944-3.··-·CJ
0003bdc0:·4953·2d35·2e31·302e·342e·310a·2020·2d20··IS-5.10.4.1.··-·0003bab0:·4953·2d35·2e31·302e·342e·310a·2020·2d20··IS-5.10.4.1.··-·
0003bdd0:·4e49·5354·2d38·3030·2d31·3731·2d33·2e33··NIST-800-171-3.30003bac0:·4e49·5354·2d38·3030·2d31·3731·2d33·2e33··NIST-800-171-3.3
0003bde0:·2e38·0a20·202d·204e·4953·542d·3830·302d··.8.··-·NIST-800-0003bad0:·2e38·0a20·202d·204e·4953·542d·3830·302d··.8.··-·NIST-800-
0003bdf0:·3137·312d·332e·342e·310a·2020·2d20·4e49··171-3.4.1.··-·NI0003bae0:·3137·312d·332e·342e·310a·2020·2d20·4e49··171-3.4.1.··-·NI
0003be00:·5354·2d38·3030·2d35·332d·4155·2d39·2833··ST-800-53-AU-9(30003baf0:·5354·2d38·3030·2d35·332d·4155·2d39·2833··ST-800-53-AU-9(3
0003be10:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-50003bb00:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5
0003be20:·332d·434d·2d36·2863·290a·2020·2d20·4e49··3-CM-6(c).··-·NI0003bb10:·332d·434d·2d36·2863·290a·2020·2d20·4e49··3-CM-6(c).··-·NI
0003be30:·5354·2d38·3030·2d35·332d·434d·2d36·2864··ST-800-53-CM-6(d0003bb20:·5354·2d38·3030·2d35·332d·434d·2d36·2864··ST-800-53-CM-6(d
0003be40:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-50003bb30:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5
0003be50:·332d·5349·2d37·0a20·202d·204e·4953·542d··3-SI-7.··-·NIST-0003bb40:·332d·5349·2d37·0a20·202d·204e·4953·542d··3-SI-7.··-·NIST-
0003be60:·3830·302d·3533·2d53·492d·3728·3129·0a20··800-53-SI-7(1).·0003bb50:·3830·302d·3533·2d53·492d·3728·3129·0a20··800-53-SI-7(1).·
0003be70:·202d·204e·4953·542d·3830·302d·3533·2d53···-·NIST-800-53-S0003bb60:·202d·204e·4953·542d·3830·302d·3533·2d53···-·NIST-800-53-S
0003be80:·492d·3728·3629·0a20·202d·2050·4349·2d44··I-7(6).··-·PCI-D0003bb70:·492d·3728·3629·0a20·202d·2050·4349·2d44··I-7(6).··-·PCI-D
0003be90:·5353·2d52·6571·2d31·312e·350a·2020·2d20··SS-Req-11.5.··-·0003bb80:·5353·2d52·6571·2d31·312e·350a·2020·2d20··SS-Req-11.5.··-·
0003bea0:·5043·492d·4453·5376·342d·3131·2e35·2e32··PCI-DSSv4-11.5.20003bb90:·5043·492d·4453·5376·342d·3131·2e35·2e32··PCI-DSSv4-11.5.2
0003beb0:·0a20·202d·2068·6967·685f·636f·6d70·6c65··.··-·high_comple0003bba0:·0a20·202d·2068·6967·685f·636f·6d70·6c65··.··-·high_comple
0003bec0:·7869·7479·0a20·202d·2068·6967·685f·7365··xity.··-·high_se0003bbb0:·7869·7479·0a20·202d·2068·6967·685f·7365··xity.··-·high_se
0003bed0:·7665·7269·7479·0a20·202d·206d·6564·6975··verity.··-·mediu0003bbc0:·7665·7269·7479·0a20·202d·206d·6564·6975··verity.··-·mediu
0003bee0:·6d5f·6469·7372·7570·7469·6f6e·0a20·202d··m_disruption.··-0003bbd0:·6d5f·6469·7372·7570·7469·6f6e·0a20·202d··m_disruption.··-
0003bef0:·206e·6f5f·7265·626f·6f74·5f6e·6565·6465···no_reboot_neede0003bbe0:·206e·6f5f·7265·626f·6f74·5f6e·6565·6465···no_reboot_neede
Max diff block lines reached; 10885206/10927074 bytes (99.62%) of diff not shown.
1.15 MB
html2text {}
    
Offset 45, 15 lines modifiedOffset 45, 15 lines modified
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Australian·Cyber·Security·Centre·(ACSC)·ISM·Official·-45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Australian·Cyber·Security·Centre·(ACSC)·ISM·Official·-
46 ··············Top·Secret46 ··············Top·Secret
47 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ism_o_top_secret47 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ism_o_top_secret
48 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*48 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
49 ····*·cpe:/o:redhat:enterprise_linux:1049 ····*·cpe:/o:redhat:enterprise_linux:10
50 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
51 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8451 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
52 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)52 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
53 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*53 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
54 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s54 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
55 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e55 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
56 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l56 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
57 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g57 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
58 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s58 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
59 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s59 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 115, 27 lines modifiedOffset 115, 14 lines modified
115 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6115 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
116 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4116 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
117 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)117 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
118 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1118 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
119 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5119 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
120 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227120 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
121 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2121 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
123 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
124 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
125 if·[·-n·"$files_with_incorrect_hash"·];·then 
126 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
127 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
128 ····dnf·reinstall·-y·$packages_to_reinstall 
  
129 fi 
130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high123 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium124 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false125 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict126 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
135 -·name:·'Set·fact:·Package·manager·reinstall·command'127 -·name:·'Set·fact:·Package·manager·reinstall·command'
136 ··set_fact:128 ··set_fact:
Offset 267, 14 lines modifiedOffset 254, 27 lines modified
267 ··-·PCI-DSSv4-11.5.2254 ··-·PCI-DSSv4-11.5.2
268 ··-·high_complexity255 ··-·high_complexity
269 ··-·high_severity256 ··-·high_severity
270 ··-·medium_disruption257 ··-·medium_disruption
271 ··-·no_reboot_needed258 ··-·no_reboot_needed
272 ··-·restrict_strategy259 ··-·restrict_strategy
273 ··-·rpm_verify_hashes260 ··-·rpm_verify_hashes
 261 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 262 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 263 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 264 if·[·-n·"$files_with_incorrect_hash"·];·then
 265 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 266 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 267 ····dnf·reinstall·-y·$packages_to_reinstall
  
 268 fi
274 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*269 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
275 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:270 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
276 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'271 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
277 run·the·following·command·to·determine·which·package·owns·it:272 run·the·following·command·to·determine·which·package·owns·it:
278 $·rpm·-qf·FILENAME273 $·rpm·-qf·FILENAME
279 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:274 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
280 $·sudo·rpm·--setugids·PACKAGENAME275 $·sudo·rpm·--setugids·PACKAGENAME
Offset 294, 40 lines modifiedOffset 294, 14 lines modified
294 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5294 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
295 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2295 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
296 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)296 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
297 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1297 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
298 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5298 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
299 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108299 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
300 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2300 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
301 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
302 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
303 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
304 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
305 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
306 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
307 declare·-A·SETPERMS_RPM_DICT 
  
308 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
309 #·is·expected·by·the·RPM·database 
310 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
311 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
312 do 
313 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
314 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
315 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
316 done 
  
317 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
318 #·correct·values 
319 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
320 do 
321 ········rpm·--setugids·"${RPM_PACKAGE}" 
322 done 
323 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8301 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
324 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high302 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
325 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium303 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
326 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false304 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
327 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict305 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
328 -·name:·Read·list·of·files·with·incorrect·ownership306 -·name:·Read·list·of·files·with·incorrect·ownership
329 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev307 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 405, 14 lines modifiedOffset 379, 40 lines modified
405 ··-·PCI-DSSv4-11.5.2379 ··-·PCI-DSSv4-11.5.2
406 ··-·high_complexity380 ··-·high_complexity
407 ··-·high_severity381 ··-·high_severity
408 ··-·medium_disruption382 ··-·medium_disruption
409 ··-·no_reboot_needed383 ··-·no_reboot_needed
410 ··-·restrict_strategy384 ··-·restrict_strategy
411 ··-·rpm_verify_ownership385 ··-·rpm_verify_ownership
 386 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 387 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 388 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 389 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 390 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 391 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 1193404/1201136 bytes (99.36%) of diff not shown.
16.8 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-pci-dss.html
    
Offset 14307, 15 lines modifiedOffset 14307, 15 lines modified
00037e20:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur00037e20:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur
00037e30:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s00037e30:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s
00037e40:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st00037e40:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st
00037e50:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li00037e50:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li
00037e60:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</00037e60:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</
00037e70:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········00037e70:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········
00037e80:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·00037e80:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·
00037e90:·6f66·2032·3032·362d·3031·2d30·3829·0a20··of·2026-01-08).·00037e90:·6f66·2032·3032·342d·3132·2d30·3729·0a20··of·2024-12-07).·
00037ea0:·2020·2020·2020·2020·2020·2020·2020·203c·················<00037ea0:·2020·2020·2020·2020·2020·2020·2020·203c·················<
00037eb0:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><00037eb0:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><
00037ec0:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont00037ec0:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont
00037ed0:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li00037ed0:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li
00037ee0:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf00037ee0:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf
00037ef0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.00037ef0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.
00037f00:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy00037f00:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy
Offset 15215, 306 lines modifiedOffset 15215, 306 lines modified
0003b6e0:·7461·7267·6574·3d22·2369·646d·3639·3038··target="#idm69080003b6e0:·7461·7267·6574·3d22·2369·646d·3639·3038··target="#idm6908
0003b6f0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003b6f0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003b700:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003b700:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003b710:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003b710:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003b720:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003b720:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003b730:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003b730:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003b740:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003b740:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003b750:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003b760:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003b770:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003b780:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003b790:·2069·643d·2269·646d·3639·3038·223e·3c70···id="idm6908"><p 
0003b7a0:·7265·3e3c·636f·6465·3e0a·2320·4669·6e64··re><code>.#·Find 
0003b7b0:·2077·6869·6368·2066·696c·6573·2068·6176···which·files·hav 
0003b7c0:·6520·696e·636f·7272·6563·7420·6861·7368··e·incorrect·hash 
0003b7d0:·2028·6e6f·7420·696e·202f·6574·632c·2062···(not·in·/etc,·b 
0003b7e0:·6563·6175·7365·206f·6620·7468·6520·7379··ecause·of·the·sy 
0003b7f0:·7374·656d·2072·656c·6174·6564·2063·6f6e··stem·related·con 
0003b800:·6669·6720·6669·6c65·7329·2061·6e64·2074··fig·files)·and·t 
0003b810:·6865·6e20·6765·7420·6669·6c65·7320·6e61··hen·get·files·na 
0003b820:·6d65·730a·6669·6c65·735f·7769·7468·5f69··mes.files_with_i 
0003b830:·6e63·6f72·7265·6374·5f68·6173·683d·2224··ncorrect_hash="$ 
0003b840:·2872·706d·202d·5661·202d·2d6e·6f63·6f6e··(rpm·-Va·--nocon 
0003b850:·6669·6720·7c20·6772·6570·202d·4520·275e··fig·|·grep·-E·'^ 
0003b860:·2e2e·3527·207c·2061·776b·2027·7b70·7269··..5'·|·awk·'{pri 
0003b870:·6e74·2024·4e46·7d27·2029·220a·0a69·6620··nt·$NF}'·)"..if· 
0003b880:·5b20·2d6e·2022·2466·696c·6573·5f77·6974··[·-n·"$files_wit 
0003b890:·685f·696e·636f·7272·6563·745f·6861·7368··h_incorrect_hash 
0003b8a0:·2220·5d3b·2074·6865·6e0a·2020·2020·2320··"·];·then.····#· 
0003b8b0:·4672·6f6d·2066·696c·6573·206e·616d·6573··From·files·names 
0003b8c0:·2067·6574·2070·6163·6b61·6765·206e·616d···get·package·nam 
0003b8d0:·6573·2061·6e64·2063·6861·6e67·6520·6e65··es·and·change·ne 
0003b8e0:·776c·696e·6520·746f·2073·7061·6365·2c20··wline·to·space,· 
0003b8f0:·6265·6361·7573·6520·7270·6d20·7772·6974··because·rpm·writ 
0003b900:·6573·2065·6163·6820·7061·636b·6167·6520··es·each·package· 
0003b910:·746f·206e·6577·206c·696e·650a·2020·2020··to·new·line.···· 
0003b920:·7061·636b·6167·6573·5f74·6f5f·7265·696e··packages_to_rein 
0003b930:·7374·616c·6c3d·2224·2872·706d·202d·7166··stall="$(rpm·-qf 
0003b940:·2024·6669·6c65·735f·7769·7468·5f69·6e63···$files_with_inc 
0003b950:·6f72·7265·6374·5f68·6173·6820·7c20·7472··orrect_hash·|·tr 
0003b960:·2027·5c6e·2720·2720·2729·220a·0a20·2020···'\n'·'·')"..··· 
0003b970:·200a·2020·2020·646e·6620·7265·696e·7374···.····dnf·reinst 
0003b980:·616c·6c20·2d79·2024·7061·636b·6167·6573··all·-y·$packages 
0003b990:·5f74·6f5f·7265·696e·7374·616c·6c0a·2020··_to_reinstall.·· 
0003b9a0:·2020·0a66·690a·3c2f·636f·6465·3e3c·2f70····.fi.</code></p 
0003b9b0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003b9c0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003b9d0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003b9e0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003b9f0:·7461·7267·6574·3d22·2369·646d·3639·3039··target="#idm6909 
0003ba00:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003ba10:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003ba20:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003ba30:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003ba40:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003ba50:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003ba60:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip0003b750:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip
0003ba70:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003b760:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003ba80:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003b770:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003ba90:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003b780:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003baa0:·7365·2220·6964·3d22·6964·6d36·3930·3922··se"·id="idm6909"0003b790:·7365·2220·6964·3d22·6964·6d36·3930·3822··se"·id="idm6908"
0003bab0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003b7a0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003bac0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003b7b0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003bad0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003b7c0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003bae0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003b7d0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003baf0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003b7e0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003bb00:·6578·6974·793a·3c2f·7468·3e3c·7464·3e68··exity:</th><td>h0003b7f0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e68··exity:</th><td>h
0003bb10:·6967·683c·2f74·643e·3c2f·7472·3e3c·7472··igh</td></tr><tr0003b800:·6967·683c·2f74·643e·3c2f·7472·3e3c·7472··igh</td></tr><tr
0003bb20:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003b810:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003bb30:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<0003b820:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<
0003bb40:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b830:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003bb50:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003b840:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003bb60:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003b850:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003bb70:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003b860:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003bb80:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri0003b870:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri
0003bb90:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta0003b880:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta
0003bba0:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-0003b890:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-
0003bbb0:·206e·616d·653a·2027·5365·7420·6661·6374···name:·'Set·fact0003b8a0:·206e·616d·653a·2027·5365·7420·6661·6374···name:·'Set·fact
0003bbc0:·3a20·5061·636b·6167·6520·6d61·6e61·6765··:·Package·manage0003b8b0:·3a20·5061·636b·6167·6520·6d61·6e61·6765··:·Package·manage
0003bbd0:·7220·7265·696e·7374·616c·6c20·636f·6d6d··r·reinstall·comm0003b8c0:·7220·7265·696e·7374·616c·6c20·636f·6d6d··r·reinstall·comm
0003bbe0:·616e·6427·0a20·2073·6574·5f66·6163·743a··and'.··set_fact:0003b8d0:·616e·6427·0a20·2073·6574·5f66·6163·743a··and'.··set_fact:
0003bbf0:·0a20·2020·2070·6163·6b61·6765·5f6d·616e··.····package_man0003b8e0:·0a20·2020·2070·6163·6b61·6765·5f6d·616e··.····package_man
0003bc00:·6167·6572·5f72·6569·6e73·7461·6c6c·5f63··ager_reinstall_c0003b8f0:·6167·6572·5f72·6569·6e73·7461·6c6c·5f63··ager_reinstall_c
0003bc10:·6d64·3a20·646e·6620·7265·696e·7374·616c··md:·dnf·reinstal0003b900:·6d64·3a20·646e·6620·7265·696e·7374·616c··md:·dnf·reinstal
0003bc20:·6c20·2d79·0a20·2077·6865·6e3a·2061·6e73··l·-y.··when:·ans0003b910:·6c20·2d79·0a20·2077·6865·6e3a·2061·6e73··l·-y.··when:·ans
0003bc30:·6962·6c65·5f64·6973·7472·6962·7574·696f··ible_distributio0003b920:·6962·6c65·5f64·6973·7472·6962·7574·696f··ible_distributio
0003bc40:·6e20·696e·205b·2022·4665·646f·7261·222c··n·in·[·"Fedora",0003b930:·6e20·696e·205b·2022·4665·646f·7261·222c··n·in·[·"Fedora",
0003bc50:·2022·5265·6448·6174·222c·2022·4365·6e74···"RedHat",·"Cent0003b940:·2022·5265·6448·6174·222c·2022·4365·6e74···"RedHat",·"Cent
0003bc60:·4f53·222c·2022·4f72·6163·6c65·4c69·6e75··OS",·"OracleLinu0003b950:·4f53·222c·2022·4f72·6163·6c65·4c69·6e75··OS",·"OracleLinu
0003bc70:·7822·205d·0a20·2074·6167·733a·0a20·202d··x"·].··tags:.··-0003b960:·7822·205d·0a20·2074·6167·733a·0a20·202d··x"·].··tags:.··-
0003bc80:·2043·4345·2d38·3939·3434·2d33·0a20·202d···CCE-89944-3.··-0003b970:·2043·4345·2d38·3939·3434·2d33·0a20·202d···CCE-89944-3.··-
0003bc90:·2043·4a49·532d·352e·3130·2e34·2e31·0a20···CJIS-5.10.4.1.·0003b980:·2043·4a49·532d·352e·3130·2e34·2e31·0a20···CJIS-5.10.4.1.·
0003bca0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-0003b990:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
0003bcb0:·332e·332e·380a·2020·2d20·4e49·5354·2d38··3.3.8.··-·NIST-80003b9a0:·332e·332e·380a·2020·2d20·4e49·5354·2d38··3.3.8.··-·NIST-8
0003bcc0:·3030·2d31·3731·2d33·2e34·2e31·0a20·202d··00-171-3.4.1.··-0003b9b0:·3030·2d31·3731·2d33·2e34·2e31·0a20·202d··00-171-3.4.1.··-
0003bcd0:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-0003b9c0:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-
0003bce0:·3928·3329·0a20·202d·204e·4953·542d·3830··9(3).··-·NIST-800003b9d0:·3928·3329·0a20·202d·204e·4953·542d·3830··9(3).··-·NIST-80
0003bcf0:·302d·3533·2d43·4d2d·3628·6329·0a20·202d··0-53-CM-6(c).··-0003b9e0:·302d·3533·2d43·4d2d·3628·6329·0a20·202d··0-53-CM-6(c).··-
0003bd00:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-0003b9f0:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-
0003bd10:·3628·6429·0a20·202d·204e·4953·542d·3830··6(d).··-·NIST-800003ba00:·3628·6429·0a20·202d·204e·4953·542d·3830··6(d).··-·NIST-80
0003bd20:·302d·3533·2d53·492d·370a·2020·2d20·4e49··0-53-SI-7.··-·NI0003ba10:·302d·3533·2d53·492d·370a·2020·2d20·4e49··0-53-SI-7.··-·NI
0003bd30:·5354·2d38·3030·2d35·332d·5349·2d37·2831··ST-800-53-SI-7(10003ba20:·5354·2d38·3030·2d35·332d·5349·2d37·2831··ST-800-53-SI-7(1
0003bd40:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-50003ba30:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5
0003bd50:·332d·5349·2d37·2836·290a·2020·2d20·5043··3-SI-7(6).··-·PC0003ba40:·332d·5349·2d37·2836·290a·2020·2d20·5043··3-SI-7(6).··-·PC
0003bd60:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·0003ba50:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·
0003bd70:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.0003ba60:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.
0003bd80:·352e·320a·2020·2d20·6869·6768·5f63·6f6d··5.2.··-·high_com0003ba70:·352e·320a·2020·2d20·6869·6768·5f63·6f6d··5.2.··-·high_com
0003bd90:·706c·6578·6974·790a·2020·2d20·6869·6768··plexity.··-·high0003ba80:·706c·6578·6974·790a·2020·2d20·6869·6768··plexity.··-·high
0003bda0:·5f73·6576·6572·6974·790a·2020·2d20·6d65··_severity.··-·me0003ba90:·5f73·6576·6572·6974·790a·2020·2d20·6d65··_severity.··-·me
0003bdb0:·6469·756d·5f64·6973·7275·7074·696f·6e0a··dium_disruption.0003baa0:·6469·756d·5f64·6973·7275·7074·696f·6e0a··dium_disruption.
0003bdc0:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne0003bab0:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne
Max diff block lines reached; 15928064/15970070 bytes (99.74%) of diff not shown.
1.53 MB
html2text {}
    
Offset 44, 15 lines modifiedOffset 44, 15 lines modified
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·PCI-DSS·v4.0·Control·Baseline·for·Red·Hat·Enterprise44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·PCI-DSS·v4.0·Control·Baseline·for·Red·Hat·Enterprise
45 ··············Linux·1045 ··············Linux·10
46 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss46 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss
47 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*47 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
48 ····*·cpe:/o:redhat:enterprise_linux:1048 ····*·cpe:/o:redhat:enterprise_linux:10
49 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*49 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
50 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8450 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
51 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)51 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
52 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*52 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
53 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s53 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
54 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e54 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
55 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l55 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
56 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n56 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
57 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g57 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
58 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s58 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 112, 27 lines modifiedOffset 112, 14 lines modified
112 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6112 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
113 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4113 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
114 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)114 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
115 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1115 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
116 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5116 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
117 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227117 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
118 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2118 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
120 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
121 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
122 if·[·-n·"$files_with_incorrect_hash"·];·then 
123 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
124 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
125 ····dnf·reinstall·-y·$packages_to_reinstall 
  
126 fi 
127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high120 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium121 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false122 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict123 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
132 -·name:·'Set·fact:·Package·manager·reinstall·command'124 -·name:·'Set·fact:·Package·manager·reinstall·command'
133 ··set_fact:125 ··set_fact:
Offset 264, 14 lines modifiedOffset 251, 27 lines modified
264 ··-·PCI-DSSv4-11.5.2251 ··-·PCI-DSSv4-11.5.2
265 ··-·high_complexity252 ··-·high_complexity
266 ··-·high_severity253 ··-·high_severity
267 ··-·medium_disruption254 ··-·medium_disruption
268 ··-·no_reboot_needed255 ··-·no_reboot_needed
269 ··-·restrict_strategy256 ··-·restrict_strategy
270 ··-·rpm_verify_hashes257 ··-·rpm_verify_hashes
 258 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 259 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 260 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 261 if·[·-n·"$files_with_incorrect_hash"·];·then
 262 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 263 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 264 ····dnf·reinstall·-y·$packages_to_reinstall
  
 265 fi
271 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*266 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
272 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:267 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
273 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'268 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
274 run·the·following·command·to·determine·which·package·owns·it:269 run·the·following·command·to·determine·which·package·owns·it:
275 $·rpm·-qf·FILENAME270 $·rpm·-qf·FILENAME
276 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:271 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
277 $·sudo·rpm·--setugids·PACKAGENAME272 $·sudo·rpm·--setugids·PACKAGENAME
Offset 291, 40 lines modifiedOffset 291, 14 lines modified
291 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5291 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
292 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2292 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
293 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)293 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
294 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1294 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
295 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5295 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
296 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108296 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
297 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2297 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
298 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
299 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
300 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
301 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
302 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
303 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
304 declare·-A·SETPERMS_RPM_DICT 
  
305 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
306 #·is·expected·by·the·RPM·database 
307 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
308 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
309 do 
310 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
311 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
312 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
313 done 
  
314 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
315 #·correct·values 
316 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
317 do 
318 ········rpm·--setugids·"${RPM_PACKAGE}" 
319 done 
320 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8298 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
321 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high299 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
322 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium300 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
323 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false301 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
324 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict302 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
325 -·name:·Read·list·of·files·with·incorrect·ownership303 -·name:·Read·list·of·files·with·incorrect·ownership
326 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev304 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 402, 14 lines modifiedOffset 376, 40 lines modified
402 ··-·PCI-DSSv4-11.5.2376 ··-·PCI-DSSv4-11.5.2
403 ··-·high_complexity377 ··-·high_complexity
404 ··-·high_severity378 ··-·high_severity
405 ··-·medium_disruption379 ··-·medium_disruption
406 ··-·no_reboot_needed380 ··-·no_reboot_needed
407 ··-·restrict_strategy381 ··-·restrict_strategy
408 ··-·rpm_verify_ownership382 ··-·rpm_verify_ownership
 383 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 384 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 385 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 386 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 387 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 388 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 1596122/1603854 bytes (99.52%) of diff not shown.
34.2 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-stig.html
    
Offset 14302, 16 lines modifiedOffset 14302, 16 lines modified
00037dd0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p00037dd0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p
00037de0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version00037de0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version
00037df0:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.7400037df0:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.74
00037e00:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul00037e00:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul
00037e10:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra00037e10:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra
00037e20:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····00037e20:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····
00037e30:·2020·2020·2020·2020·2020·2020·2020·2020··················00037e30:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037e40:·2861·7320·6f66·2032·3032·362d·3031·2d30··(as·of·2026-01-000037e40:·2861·7320·6f66·2032·3032·342d·3132·2d30··(as·of·2024-12-0
00037e50:·3829·0a20·2020·2020·2020·2020·2020·2020··8).·············00037e50:·3729·0a20·2020·2020·2020·2020·2020·2020··7).·············
00037e60:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d00037e60:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d
00037e70:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·00037e70:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·
00037e80:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol00037e80:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol
00037e90:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x00037e90:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x
00037ea0:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj00037ea0:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj
00037eb0:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou00037eb0:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou
00037ec0:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System00037ec0:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System
Offset 15130, 234 lines modifiedOffset 15130, 234 lines modified
0003b190:·7267·6574·3d22·2369·646d·3732·3530·2220··rget="#idm7250"·0003b190:·7267·6574·3d22·2369·646d·3732·3530·2220··rget="#idm7250"·
0003b1a0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003b1a0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003b1b0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003b1b0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003b1c0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003b1c0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003b1d0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003b1d0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003b1e0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003b1e0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003b1f0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003b1f0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003b200:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet0003b200:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp
0003b210:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003b210:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
0003b220:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003b220:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0003b230:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003b230:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0003b240:·2069·643d·2269·646d·3732·3530·223e·3c74···id="idm7250"><t0003b240:·6522·2069·643d·2269·646d·3732·3530·223e··e"·id="idm7250">
0003b250:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl0003b250:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
0003b260:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·0003b260:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
0003b270:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0003b270:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
0003b280:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">0003b280:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
0003b290:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi0003b290:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003b2a0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<0003b2a0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0003b2b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b2b0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003b2c0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th0003b2c0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
0003b2d0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003b2d0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003b2e0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot0003b2e0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
0003b2f0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<0003b2f0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
0003b300:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b300:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
0003b310:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003b310:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0003b320:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003b320:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
0003b330:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003b330:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003b340:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package
 0003b350:·202d·2d61·6464·3d61·6964·650a·3c2f·636f···--add=aide.</co
0003b340:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in 
0003b350:·7374·616c·6c5f·6169·6465·0a0a·636c·6173··stall_aide..clas 
0003b360:·7320·696e·7374·616c·6c5f·6169·6465·207b··s·install_aide·{ 
0003b370:·0a20·2070·6163·6b61·6765·207b·2027·6169··.··package·{·'ai 
0003b380:·6465·273a·0a20·2020·2065·6e73·7572·6520··de':.····ensure· 
0003b390:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed 
0003b3a0:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code> 
0003b3b0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003b3c0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003b3d0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003b3e0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003b3f0:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7 
0003b400:·3235·3122·2074·6162·696e·6465·783d·2230··251"·tabindex="0 
0003b410:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003b420:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003b430:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003b440:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003b450:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003b460:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
0003b470:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003b480:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b490:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b4a0:·7365·2220·6964·3d22·6964·6d37·3235·3122··se"·id="idm7251" 
0003b4b0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003b4c0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003b4d0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003b4e0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003b4f0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003b500:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003b510:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b520:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003b530:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b540:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003b550:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003b560:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003b570:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003b580:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003b590:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003b5a0:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed 
0003b5b0:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic 
0003b5c0:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer 
0003b5d0:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i 
0003b5e0:·6620·5b20·2120·2d66·202f·2e64·6f63·6b65··f·[·!·-f·/.docke 
0003b5f0:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp 
0003b600:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c 
0003b610:·6f6e·7461·696e·6572·656e·7620·5d3b·2074··ontainerenv·];·t 
0003b620:·6865·6e0a·0a69·6620·2120·7270·6d20·2d71··hen..if·!·rpm·-q 
0003b630:·202d·2d71·7569·6574·2022·6169·6465·2220···--quiet·"aide"· 
0003b640:·3b20·7468·656e·0a20·2020·2064·6e66·2069··;·then.····dnf·i 
0003b650:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide" 
0003b660:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g 
0003b670:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R 
0003b680:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no 
0003b690:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no 
0003b6a0:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'. 
0003b6b0:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre> 
0003b6c0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003b6d0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003b6e0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003b6f0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003b700:·6765·743d·2223·6964·6d37·3235·3222·2074··get="#idm7252"·t 
0003b710:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003b720:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003b730:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003b740:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003b750:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003b760:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003b770:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet 
0003b780:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003b790:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003b7a0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003b7b0:·2069·643d·2269·646d·3732·3532·223e·3c74···id="idm7252"><t 
0003b7c0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003b7d0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003b7e0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003b7f0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003b800:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003b810:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003b820:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b830:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003b840:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
Max diff block lines reached; 32976441/33008649 bytes (99.90%) of diff not shown.
2.76 MB
html2text {}
Max HTML report size reached
34.1 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-stig_gui.html
    
Offset 14302, 16 lines modifiedOffset 14302, 16 lines modified
00037dd0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h00037dd0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h
00037de0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver00037de0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver
00037df0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.00037df0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.
00037e00:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p00037e00:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p
00037e10:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong00037e10:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong
00037e20:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.00037e20:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.
00037e30:·2020·2020·2020·2020·2020·2020·2020·2020··················00037e30:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037e40:·2020·2020·2861·7320·6f66·2032·3032·362d······(as·of·2026-00037e40:·2020·2020·2861·7320·6f66·2032·3032·342d······(as·of·2024-
00037e50:·3031·2d30·3829·0a20·2020·2020·2020·2020··01-08).·········00037e50:·3132·2d30·3729·0a20·2020·2020·2020·2020··12-07).·········
00037e60:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul00037e60:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul
00037e70:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table00037e70:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table
00037e80:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h200037e80:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2
00037e90:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href00037e90:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href
00037ea0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg00037ea0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg
00037eb0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_00037eb0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
00037ec0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy00037ec0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy
Offset 15130, 235 lines modifiedOffset 15130, 235 lines modified
0003b190:·612d·7461·7267·6574·3d22·2369·646d·3732··a-target="#idm720003b190:·612d·7461·7267·6574·3d22·2369·646d·3732··a-target="#idm72
0003b1a0:·3530·2220·7461·6269·6e64·6578·3d22·3022··50"·tabindex="0"0003b1a0:·3530·2220·7461·6269·6e64·6578·3d22·3022··50"·tabindex="0"
0003b1b0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003b1b0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003b1c0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003b1c0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003b1d0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003b1d0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003b1e0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003b1e0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003b1f0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003b1f0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003b200:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni0003b200:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s
0003b210:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003b210:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003b220:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003b220:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003b230:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003b230:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003b240:·7073·6522·2069·643d·2269·646d·3732·3530··pse"·id="idm72500003b240:·6c61·7073·6522·2069·643d·2269·646d·3732··lapse"·id="idm72
0003b250:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003b250:·3530·223e·3c74·6162·6c65·2063·6c61·7373··50"><table·class
0003b260:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003b260:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003b270:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003b270:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003b280:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003b280:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003b290:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003b290:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003b2a0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003b2a0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003b2b0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003b2b0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003b2c0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003b2c0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003b2d0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003b2d0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003b2e0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003b2e0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b2f0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003b2f0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0003b300:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003b300:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
0003b310:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003b310:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003b320:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003b320:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0003b330:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003b330:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003b340:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ0003b340:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 0003b350:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide.
0003b350:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide.. 
0003b360:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai 
0003b370:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{ 
0003b380:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens 
0003b390:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta 
0003b3a0:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c 
0003b3b0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003b3c0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003b3d0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003b3e0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003b3f0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003b400:·6964·6d37·3235·3122·2074·6162·696e·6465··idm7251"·tabinde 
0003b410:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003b420:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003b430:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003b440:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003b450:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003b460:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003b470:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003b480:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b490:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b4a0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7 
0003b4b0:·3235·3122·3e3c·7461·626c·6520·636c·6173··251"><table·clas 
0003b4c0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b4d0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b4e0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b4f0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b500:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b510:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b520:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b530:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b540:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b550:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b560:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003b570:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b580:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b590:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b5a0:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R 
0003b5b0:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003b5c0:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003b5d0:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003b5e0:·6d73·0a69·6620·5b20·2120·2d66·202f·2e64··ms.if·[·!·-f·/.d 
0003b5f0:·6f63·6b65·7265·6e76·205d·2026·616d·703b··ockerenv·]·&amp; 
0003b600:·2661·6d70·3b20·5b20·2120·2d66·202f·7275··&amp;·[·!·-f·/ru 
0003b610:·6e2f·2e63·6f6e·7461·696e·6572·656e·7620··n/.containerenv· 
0003b620:·5d3b·2074·6865·6e0a·0a69·6620·2120·7270··];·then..if·!·rp 
0003b630:·6d20·2d71·202d·2d71·7569·6574·2022·6169··m·-q·--quiet·"ai 
0003b640:·6465·2220·3b20·7468·656e·0a20·2020·2064··de"·;·then.····d 
0003b650:·6e66·2069·6e73·7461·6c6c·202d·7920·2261··nf·install·-y·"a 
0003b660:·6964·6522·0a66·690a·0a65·6c73·650a·2020··ide".fi..else.·· 
0003b670:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech 
0003b680:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i 
0003b690:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable 
0003b6a0:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do 
0003b6b0:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></ 
0003b6c0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003b6d0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003b6e0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003b6f0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003b700:·2d74·6172·6765·743d·2223·6964·6d37·3235··-target="#idm725 
0003b710:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"· 
0003b720:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003b730:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003b740:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003b750:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003b760:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003b770:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni 
0003b780:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003b790:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003b7a0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003b7b0:·7073·6522·2069·643d·2269·646d·3732·3532··pse"·id="idm7252 
0003b7c0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003b7d0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003b7e0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003b7f0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003b800:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003b810:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003b820:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003b830:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003b840:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b850:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
Max diff block lines reached; 32884305/32916651 bytes (99.90%) of diff not shown.
2.74 MB
html2text {}
Max HTML report size reached
23.3 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-anssi_bp28_enhanced.html
    
Offset 14451, 15 lines modifiedOffset 14451, 15 lines modified
00038720:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00038720:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00038730:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00038730:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00038740:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</00038740:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
00038750:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00038750:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
00038760:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft00038760:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
00038770:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······00038770:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
00038780:·2020·2020·2020·2020·2020·2020·2020·2861················(a00038780:·2020·2020·2020·2020·2020·2020·2020·2861················(a
00038790:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)00038790:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
000387a0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············000387a0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
000387b0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div000387b0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
000387c0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co000387c0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
000387d0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><000387d0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
000387e0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc000387e0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
000387f0:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec000387f0:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00038800:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00038800:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 15247, 237 lines modifiedOffset 15247, 237 lines modified
0003b8e0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b8e0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003b8f0:·2223·6964·6d37·3938·3022·2074·6162·696e··"#idm7980"·tabin0003b8f0:·2223·6964·6d37·3938·3022·2074·6162·696e··"#idm7980"·tabin
0003b900:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b900:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b910:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b910:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b920:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b920:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b930:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b930:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b940:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b940:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b950:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup0003b950:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana
0003b960:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<0003b960:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..
0003b970:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003b970:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003b980:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003b980:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003b990:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003b990:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003b9a0:·6964·6d37·3938·3022·3e3c·7461·626c·6520··idm7980"><table·0003b9a0:·3d22·6964·6d37·3938·3022·3e3c·7461·626c··="idm7980"><tabl
0003b9b0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003b9b0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0003b9c0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003b9c0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0003b9d0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003b9d0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0003b9e0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003b9e0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0003b9f0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003b9f0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003ba00:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003ba00:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003ba10:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003ba10:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003ba20:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003ba20:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003ba30:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003ba30:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003ba40:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th0003ba40:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
0003ba50:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><0003ba50:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
0003ba60:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003ba60:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
0003ba70:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003ba70:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0003ba80:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003ba80:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
0003ba90:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003ba90:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003baa0:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad
 0003bab0:·643d·6169·6465·0a3c·2f63·6f64·653e·3c2f··d=aide.</code></
 0003bac0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0003bad0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
0003baa0:·3e69·6e63·6c75·6465·2069·6e73·7461·6c6c··>include·install 
0003bab0:·5f61·6964·650a·0a63·6c61·7373·2069·6e73··_aide..class·ins 
0003bac0:·7461·6c6c·5f61·6964·6520·7b0a·2020·7061··tall_aide·{.··pa 
0003bad0:·636b·6167·6520·7b20·2761·6964·6527·3a0a··ckage·{·'aide':. 
0003bae0:·2020·2020·656e·7375·7265·203d·2667·743b······ensure·=&gt; 
0003baf0:·2027·696e·7374·616c·6c65·6427·2c0a·2020···'installed',.·· 
0003bb00:·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70·7265··}.}.</code></pre 
0003bb10:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003bb20:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003bb30:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003bb40:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003bb50:·7267·6574·3d22·2369·646d·3739·3831·2220··rget="#idm7981"· 
0003bb60:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003bb70:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003bb80:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003bb90:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003bba0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003bbb0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003bbc0:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
0003bbd0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003bbe0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003bbf0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003bc00:·643d·2269·646d·3739·3831·223e·3c74·6162··d="idm7981"><tab 
0003bc10:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003bc20:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003bc30:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003bc40:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003bc50:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003bc60:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003bc70:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003bc80:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003bc90:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003bca0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003bcb0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003bcc0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003bcd0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003bce0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003bcf0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003bd00:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio 
0003bd10:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable· 
0003bd20:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain· 
0003bd30:·706c·6174·666f·726d·730a·6966·205b·2021··platforms.if·[·! 
0003bd40:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv· 
0003bd50:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·! 
0003bd60:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai 
0003bd70:·6e65·7265·6e76·205d·3b20·7468·656e·0a0a··nerenv·];·then.. 
0003bd80:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu 
0003bd90:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the 
0003bda0:·6e0a·2020·2020·7975·6d20·696e·7374·616c··n.····yum·instal 
0003bdb0:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi.. 
0003bdc0:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am 
0003bdd0:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi 
0003bde0:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app 
0003bdf0:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing 
0003be00:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</ 
0003be10:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003be20:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003be30:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003be40:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003be50:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003bae0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
0003be60:·2369·646d·3739·3832·2220·7461·6269·6e64··#idm7982"·tabind 
0003be70:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003be80:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003be90:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003bea0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003beb0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003bec0:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi 
0003bed0:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...< 
0003bee0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003bef0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003bf00:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003baf0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 0003bb00:·2d74·6172·6765·743d·2223·6964·6d37·3938··-target="#idm798
 0003bb10:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·
 0003bb20:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0003bb30:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0003bb40:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0003bb50:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0003bb60:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003bb70:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
Max diff block lines reached; 22292593/22325077 bytes (99.85%) of diff not shown.
1.98 MB
html2text {}
Max HTML report size reached
23.6 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-anssi_bp28_high.html
    
Offset 14450, 15 lines modifiedOffset 14450, 15 lines modified
00038710:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00038710:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00038720:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00038720:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00038730:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</00038730:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
00038740:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00038740:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
00038750:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft00038750:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
00038760:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······00038760:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
00038770:·2020·2020·2020·2020·2020·2020·2020·2861················(a00038770:·2020·2020·2020·2020·2020·2020·2020·2861················(a
00038780:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)00038780:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
00038790:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00038790:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
000387a0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div000387a0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
000387b0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co000387b0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
000387c0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><000387c0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
000387d0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc000387d0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
000387e0:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec000387e0:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
000387f0:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_000387f0:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 15253, 236 lines modifiedOffset 15253, 236 lines modified
0003b940:·6574·3d22·2369·646d·3739·3830·2220·7461··et="#idm7980"·ta0003b940:·6574·3d22·2369·646d·3739·3830·2220·7461··et="#idm7980"·ta
0003b950:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003b950:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003b960:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003b960:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003b970:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003b970:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003b980:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003b980:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003b990:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003b990:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003b9a0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003b9a0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003b9b0:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.0003b9b0:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet
0003b9c0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003b9c0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003b9d0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003b9d0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003b9e0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003b9e0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003b9f0:·643d·2269·646d·3739·3830·223e·3c74·6162··d="idm7980"><tab0003b9f0:·2069·643d·2269·646d·3739·3830·223e·3c74···id="idm7980"><t
0003ba00:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003ba00:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003ba10:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003ba10:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003ba20:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003ba20:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003ba30:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003ba30:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003ba40:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003ba40:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003ba50:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003ba50:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003ba60:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003ba60:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003ba70:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003ba70:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003ba80:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003ba80:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003ba90:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<0003ba90:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
0003baa0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003baa0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003bab0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003bab0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003bac0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003bac0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003bad0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr0003bad0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
0003bae0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003bae0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003baf0:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·-
 0003bb00:·2d61·6464·3d61·6964·650a·3c2f·636f·6465··-add=aide.</code
 0003bb10:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 0003bb20:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 0003bb30:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0003baf0:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst 
0003bb00:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class· 
0003bb10:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.· 
0003bb20:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide 
0003bb30:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=& 
0003bb40:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed', 
0003bb50:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></ 
0003bb60:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003bb70:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003bb80:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003bb90:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003bba0:·2d74·6172·6765·743d·2223·6964·6d37·3938··-target="#idm798 
0003bbb0:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"· 
0003bbc0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003bbd0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003bbe0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003bbf0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003bc00:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003bc10:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
0003bc20:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003bc30:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003bc40:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003bc50:·2220·6964·3d22·6964·6d37·3938·3122·3e3c··"·id="idm7981">< 
0003bc60:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003bc70:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003bc80:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003bc90:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003bca0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003bcb0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003bcc0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003bcd0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003bce0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003bcf0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003bd00:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003bd10:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003bd20:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003bd30:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003bd40:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003bd50:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia 
0003bd60:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab 
0003bd70:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa 
0003bd80:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if· 
0003bd90:·5b20·2120·2d66·202f·2e64·6f63·6b65·7265··[·!·-f·/.dockere 
0003bda0:·6e76·205d·2026·616d·703b·2661·6d70·3b20··nv·]·&amp;&amp;· 
0003bdb0:·5b20·2120·2d66·202f·7275·6e2f·2e63·6f6e··[·!·-f·/run/.con 
0003bdc0:·7461·696e·6572·656e·7620·5d3b·2074·6865··tainerenv·];·the 
0003bdd0:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·- 
0003bde0:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;· 
0003bdf0:·7468·656e·0a20·2020·2079·756d·2069·6e73··then.····yum·ins 
0003be00:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f 
0003be10:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt; 
0003be20:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem 
0003be30:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not· 
0003be40:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth 
0003be50:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi 
0003be60:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003be70:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003be80:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003be90:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003bea0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003beb0:·743d·2223·6964·6d37·3938·3222·2074·6162··t="#idm7982"·tab 
0003bec0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003bed0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003bee0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003bef0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003bf00:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003bf10:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A 
0003bf20:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
0003bf30:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003bf40:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003bf50:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003bb40:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 0003bb50:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 0003bb60:·3739·3831·2220·7461·6269·6e64·6578·3d22··7981"·tabindex="
 0003bb70:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 0003bb80:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 0003bb90:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 0003bba0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 0003bbb0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0003bbc0:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s
Max diff block lines reached; 22570104/22602450 bytes (99.86%) of diff not shown.
2.01 MB
html2text {}
Max HTML report size reached
9.93 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-anssi_bp28_intermediary.html
    
Offset 14452, 15 lines modifiedOffset 14452, 15 lines modified
00038730:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00038730:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00038740:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00038740:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00038750:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</00038750:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
00038760:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00038760:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
00038770:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft00038770:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
00038780:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······00038780:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
00038790:·2020·2020·2020·2020·2020·2020·2020·2861················(a00038790:·2020·2020·2020·2020·2020·2020·2020·2861················(a
000387a0:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)000387a0:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
000387b0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············000387b0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
000387c0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div000387c0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
000387d0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co000387d0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
000387e0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><000387e0:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
000387f0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc000387f0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
00038800:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec00038800:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00038810:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00038810:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 15243, 237 lines modifiedOffset 15243, 237 lines modified
0003b8a0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b8a0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003b8b0:·646d·3739·3830·2220·7461·6269·6e64·6578··dm7980"·tabindex0003b8b0:·646d·3739·3830·2220·7461·6269·6e64·6578··dm7980"·tabindex
0003b8c0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b8c0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b8d0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b8d0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b8e0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b8e0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b8f0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b8f0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b900:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b900:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003b910:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet0003b910:·6d65·6469·6174·696f·6e20·416e·6163·6f6e··mediation·Anacon
0003b920:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003b920:·6461·2073·6e69·7070·6574·20e2·87b2·3c2f··da·snippet·...</
0003b930:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003b930:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003b940:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003b940:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003b950:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003b950:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003b960:·3739·3830·223e·3c74·6162·6c65·2063·6c61··7980"><table·cla0003b960:·646d·3739·3830·223e·3c74·6162·6c65·2063··dm7980"><table·c
0003b970:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003b970:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003b980:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003b980:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003b990:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003b990:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003b9a0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003b9a0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003b9b0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003b9b0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003b9c0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003b9c0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003b9d0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003b9d0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003b9e0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003b9e0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003b9f0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003b9f0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003ba00:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t0003ba00:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
0003ba10:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr0003ba10:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
0003ba20:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0003ba20:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
0003ba30:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl0003ba30:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003ba40:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0003ba40:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
0003ba50:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in0003ba50:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003ba60:·0a70·6163·6b61·6765·202d·2d61·6464·3d61··.package·--add=a
 0003ba70:·6964·650a·3c2f·636f·6465·3e3c·2f70·7265··ide.</code></pre
 0003ba80:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0003ba90:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0003baa0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0003bab0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 0003bac0:·7267·6574·3d22·2369·646d·3739·3831·2220··rget="#idm7981"·
 0003bad0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0003bae0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 0003baf0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 0003bb00:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 0003bb10:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 0003bb20:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003bb30:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
 0003bb40:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003bb50:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003bb60:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003bb70:·2069·643d·2269·646d·3739·3831·223e·3c74···id="idm7981"><t
 0003bb80:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003bb90:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0003bba0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0003bbb0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003bbc0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003ba60:·636c·7564·6520·696e·7374·616c·6c5f·6169··clude·install_ai 
0003ba70:·6465·0a0a·636c·6173·7320·696e·7374·616c··de..class·instal 
0003ba80:·6c5f·6169·6465·207b·0a20·2070·6163·6b61··l_aide·{.··packa 
0003ba90:·6765·207b·2027·6169·6465·273a·0a20·2020··ge·{·'aide':.··· 
0003baa0:·2065·6e73·7572·6520·3d26·6774·3b20·2769···ensure·=&gt;·'i 
0003bab0:·6e73·7461·6c6c·6564·272c·0a20·207d·0a7d··nstalled',.··}.} 
0003bac0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003bad0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003bae0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003baf0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003bb00:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003bb10:·743d·2223·6964·6d37·3938·3122·2074·6162··t="#idm7981"·tab 
0003bb20:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003bb30:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003bb40:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003bb50:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003bb60:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003bb70:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
0003bb80:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
0003bb90:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003bba0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003bbb0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003bbc0:·6964·6d37·3938·3122·3e3c·7461·626c·6520··idm7981"><table· 
0003bbd0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003bbe0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003bbf0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003bc00:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003bc10:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003bc20:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003bc30:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003bc40:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003bc50:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003bc60:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003bc70:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003bc80:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003bc90:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003bbd0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003bbe0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003bbf0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003bca0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
0003bcb0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
0003bcc0:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i 
0003bcd0:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl 
0003bce0:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla 
0003bcf0:·7466·6f72·6d73·0a69·6620·5b20·2120·2d66··tforms.if·[·!·-f 
0003bd00:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·& 
0003bd10:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f 
0003bd20:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container 
0003bd30:·656e·7620·5d3b·2074·6865·6e0a·0a69·6620··env·];·then..if· 
0003bd40:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet 
0003bd50:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.· 
0003bd60:·2020·2079·756d·2069·6e73·7461·6c6c·202d·····yum·install·- 
0003bd70:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els 
0003bd80:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2 
0003bd90:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati 
0003bda0:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic 
0003bdb0:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa 
0003bdc0:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod 
0003bdd0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003bde0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003bdf0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
Max diff block lines reached; 9286033/9318517 bytes (99.65%) of diff not shown.
1.04 MB
html2text {}
    
Offset 56, 15 lines modifiedOffset 56, 15 lines modified
56 ····*·cpe:/o:redhat:enterprise_linux:8.656 ····*·cpe:/o:redhat:enterprise_linux:8.6
57 ····*·cpe:/o:redhat:enterprise_linux:8.757 ····*·cpe:/o:redhat:enterprise_linux:8.7
58 ····*·cpe:/o:redhat:enterprise_linux:8.858 ····*·cpe:/o:redhat:enterprise_linux:8.8
59 ····*·cpe:/o:redhat:enterprise_linux:8.959 ····*·cpe:/o:redhat:enterprise_linux:8.9
60 ····*·cpe:/o:redhat:enterprise_linux:860 ····*·cpe:/o:redhat:enterprise_linux:8
61 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*61 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
62 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8462 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
63 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)63 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
64 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*64 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
65 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s65 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
66 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e66 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
67 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l67 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
68 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n68 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
69 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s69 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
70 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s70 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 131, 41 lines modifiedOffset 131, 45 lines modified
131 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5131 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
132 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199132 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
133 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359133 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359
134 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79134 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
135 ·············_\x8c_\x8i_\x8s············5.3.1135 ·············_\x8c_\x8i_\x8s············5.3.1
136 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2136 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
137 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule137 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule
 138 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 139 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 140 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 141 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 142 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 143 package·--add=aide
138 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
139 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low145 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
140 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low146 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
141 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false147 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
142 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable148 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
143 include·install_aide149 include·install_aide
  
144 class·install_aide·{150 class·install_aide·{
145 ··package·{·'aide':151 ··package·{·'aide':
146 ····ensure·=>·'installed',152 ····ensure·=>·'installed',
147 ··}153 ··}
148 }154 }
 155 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 156 [[packages]]
 157 name·=·"aide"
 158 version·=·"*"
149 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
150 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low160 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
151 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low161 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
152 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false162 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
153 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable163 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
154 #·Remediation·is·applicable·only·in·certain·platforms 
155 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
 164 package·install·aide
156 if·!·rpm·-q·--quiet·"aide"·;·then 
157 ····yum·install·-y·"aide" 
158 fi 
  
159 else 
160 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
161 fi 
162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
163 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
164 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
165 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
166 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
167 -·name:·Ensure·aide·is·installed170 -·name:·Ensure·aide·is·installed
168 ··package:171 ··package:
Offset 181, 33 lines modifiedOffset 185, 29 lines modified
181 ··-·PCI-DSSv4-11.5.2185 ··-·PCI-DSSv4-11.5.2
182 ··-·enable_strategy186 ··-·enable_strategy
183 ··-·low_complexity187 ··-·low_complexity
184 ··-·low_disruption188 ··-·low_disruption
185 ··-·medium_severity189 ··-·medium_severity
186 ··-·no_reboot_needed190 ··-·no_reboot_needed
187 ··-·package_aide_installed191 ··-·package_aide_installed
188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
189 [[packages]] 
190 name·=·"aide" 
191 version·=·"*" 
192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 197 #·Remediation·is·applicable·only·in·certain·platforms
 198 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 199 if·!·rpm·-q·--quiet·"aide"·;·then
 200 ····yum·install·-y·"aide"
 201 fi
197 package·install·aide 
198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
203 package·--add=aide202 else
 203 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 204 fi
204 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*205 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
205 Run·the·following·command·to·generate·a·new·database:206 Run·the·following·command·to·generate·a·new·database:
206 $·sudo·/usr/sbin/aide·--init207 $·sudo·/usr/sbin/aide·--init
207 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the208 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
208 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these209 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
209 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their210 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
210 integrity.·The·newly-generated·database·can·be·installed·as·follows:211 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 234, 28 lines modifiedOffset 234, 14 lines modified
234 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5234 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
235 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199235 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
236 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359236 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359
237 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79237 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
238 ·············_\x8c_\x8i_\x8s············5.3.1238 ·············_\x8c_\x8i_\x8s············5.3.1
239 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2239 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
240 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule240 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule
241 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
242 #·Remediation·is·applicable·only·in·certain·platforms 
243 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
244 if·!·rpm·-q·--quiet·"aide"·;·then 
245 ····yum·install·-y·"aide" 
246 fi 
  
Max diff block lines reached; 1087427/1093234 bytes (99.47%) of diff not shown.
3.23 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-anssi_bp28_minimal.html
    
Offset 14451, 15 lines modifiedOffset 14451, 15 lines modified
00038720:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre00038720:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre
00038730:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str00038730:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str
00038740:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro00038740:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro
00038750:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><00038750:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><
00038760:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st00038760:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st
00038770:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········00038770:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········
00038780:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of00038780:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of
00038790:·2032·3032·362d·3031·2d30·3829·0a20·2020···2026-01-08).···00038790:·2032·3032·342d·3132·2d30·3729·0a20·2020···2024-12-07).···
000387a0:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l000387a0:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l
000387b0:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h2000387b0:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h2
000387c0:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten000387c0:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten
000387d0:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><000387d0:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><
000387e0:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o000387e0:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o
000387f0:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co000387f0:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co
00038800:·6e74·656e·745f·6772·6f75·705f·7379·7374··ntent_group_syst00038800:·6e74·656e·745f·6772·6f75·705f·7379·7374··ntent_group_syst
Offset 14901, 217 lines modifiedOffset 14901, 217 lines modified
0003a340:·6765·743d·2223·6964·6d31·3333·3839·2220··get="#idm13389"·0003a340:·6765·743d·2223·6964·6d31·3333·3839·2220··get="#idm13389"·
0003a350:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003a350:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003a360:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003a360:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003a370:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003a370:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003a380:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003a380:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003a390:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003a390:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003a3a0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003a3a0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003a3b0:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet0003a3b0:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp
0003a3c0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003a3c0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
0003a3d0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003a3d0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0003a3e0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003a3e0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0003a3f0:·2069·643d·2269·646d·3133·3338·3922·3e3c···id="idm13389"><0003a3f0:·6522·2069·643d·2269·646d·3133·3338·3922··e"·id="idm13389"
0003a400:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003a400:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003a410:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003a410:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003a420:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003a420:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003a430:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003a430:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003a440:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003a440:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003a450:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003a450:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003a460:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003a460:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003a470:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003a470:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003a480:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003a480:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003a490:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo0003a490:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
0003a4a0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false0003a4a0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
0003a4b0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003a4b0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
0003a4c0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>0003a4c0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0003a4d0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><0003a4d0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
0003a4e0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0003a4e0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003a4f0:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag
 0003a500:·6520·2d2d·6164·643d·646e·662d·6175·746f··e·--add=dnf-auto
 0003a510:·6d61·7469·630a·3c2f·636f·6465·3e3c·2f70··matic.</code></p
 0003a520:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
0003a4f0:·3e3c·636f·6465·3e69·6e63·6c75·6465·2069··><code>include·i 
0003a500:·6e73·7461·6c6c·5f64·6e66·2d61·7574·6f6d··nstall_dnf-autom 
0003a510:·6174·6963·0a0a·636c·6173·7320·696e·7374··atic..class·inst 
0003a520:·616c·6c5f·646e·662d·6175·746f·6d61·7469··all_dnf-automati 
0003a530:·6320·7b0a·2020·7061·636b·6167·6520·7b20··c·{.··package·{· 
0003a540:·2764·6e66·2d61·7574·6f6d·6174·6963·273a··'dnf-automatic': 
0003a550:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt 
0003a560:·3b20·2769·6e73·7461·6c6c·6564·272c·0a20··;·'installed',.· 
0003a570:·207d·0a7d·0a3c·2f63·6f64·653e·3c2f·7072···}.}.</code></pr 
0003a580:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003a590:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes0003a530:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
0003a5a0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003a5b0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t0003a540:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
 0003a550:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
0003a5c0:·6172·6765·743d·2223·6964·6d31·3333·3930··arget="#idm133900003a560:·7461·7267·6574·3d22·2369·646d·3133·3339··target="#idm1339
 0003a570:·3022·2074·6162·696e·6465·783d·2230·2220··0"·tabindex="0"·
 0003a580:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0003a590:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0003a5a0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0003a5b0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0003a5c0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003a5d0:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
0003a5d0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003a5e0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003a5f0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003a600:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003a610:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003a620:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003a630:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003a640:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003a650:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003a660:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003a670:·2069·643d·2269·646d·3133·3339·3022·3e3c···id="idm13390">< 
0003a680:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003a690:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003a6a0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003a6b0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003a6c0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003a6d0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003a6e0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003a6f0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003a700:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003a710:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003a720:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003a730:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003a740:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003a750:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003a760:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003a770:·3e3c·636f·6465·3e0a·6966·2021·2072·706d··><code>.if·!·rpm 
0003a780:·202d·7120·2d2d·7175·6965·7420·2264·6e66···-q·--quiet·"dnf 
0003a790:·2d61·7574·6f6d·6174·6963·2220·3b20·7468··-automatic"·;·th 
0003a7a0:·656e·0a20·2020·2079·756d·2069·6e73·7461··en.····yum·insta 
0003a7b0:·6c6c·202d·7920·2264·6e66·2d61·7574·6f6d··ll·-y·"dnf-autom 
0003a7c0:·6174·6963·220a·6669·0a3c·2f63·6f64·653e··atic".fi.</code> 
0003a7d0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003a7e0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003a7f0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003a800:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003a810:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1 
0003a820:·3333·3931·2220·7461·6269·6e64·6578·3d22··3391"·tabindex=" 
0003a830:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003a840:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003a850:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003a860:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003a870:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003a880:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible· 
0003a890:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003a8a0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003a8b0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003a8c0:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1 
0003a8d0:·3333·3931·223e·3c74·6162·6c65·2063·6c61··3391"><table·cla 
0003a8e0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003a8f0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003a900:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003a910:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003a920:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003a930:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003a940:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003a950:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003a960:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
Max diff block lines reached; 3129460/3159184 bytes (99.06%) of diff not shown.
217 KB
html2text {}
    
Offset 56, 15 lines modifiedOffset 56, 15 lines modified
56 ····*·cpe:/o:redhat:enterprise_linux:8.656 ····*·cpe:/o:redhat:enterprise_linux:8.6
57 ····*·cpe:/o:redhat:enterprise_linux:8.757 ····*·cpe:/o:redhat:enterprise_linux:8.7
58 ····*·cpe:/o:redhat:enterprise_linux:8.858 ····*·cpe:/o:redhat:enterprise_linux:8.8
59 ····*·cpe:/o:redhat:enterprise_linux:8.959 ····*·cpe:/o:redhat:enterprise_linux:8.9
60 ····*·cpe:/o:redhat:enterprise_linux:860 ····*·cpe:/o:redhat:enterprise_linux:8
61 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*61 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
62 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8462 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
63 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)63 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
64 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*64 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
65 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s65 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
66 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e66 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
67 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l67 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
68 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s68 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
69 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s69 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
70 ·········1.·_\x8D_\x8H_\x8C_\x8P70 ·········1.·_\x8D_\x8H_\x8C_\x8P
Offset 94, 35 lines modifiedOffset 94, 45 lines modified
94 Rationale:···dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade94 Rationale:···dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade
95 ·············suitable·for·automatic,·regular·execution.95 ·············suitable·for·automatic,·regular·execution.
96 Severity: ···medium96 Severity: ···medium
97 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed97 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
98 Identifiers:·CCE-82985-398 Identifiers:·CCE-82985-3
99 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-0008099 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
100 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61100 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
 101 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 102 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 103 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 104 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 105 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 106 package·--add=dnf-automatic
101 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8107 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
102 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low108 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
103 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low109 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
104 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false110 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
105 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable111 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
106 include·install_dnf-automatic112 include·install_dnf-automatic
  
107 class·install_dnf-automatic·{113 class·install_dnf-automatic·{
108 ··package·{·'dnf-automatic':114 ··package·{·'dnf-automatic':
109 ····ensure·=>·'installed',115 ····ensure·=>·'installed',
110 ··}116 ··}
111 }117 }
 118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 119 [[packages]]
 120 name·=·"dnf-automatic"
 121 version·=·"*"
112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
113 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low123 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
114 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low124 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
115 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false125 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
116 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable126 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 127 package·install·dnf-automatic
117 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then 
118 ····yum·install·-y·"dnf-automatic" 
119 fi 
120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
121 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
122 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
123 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
124 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
125 -·name:·Ensure·dnf-automatic·is·installed133 -·name:·Ensure·dnf-automatic·is·installed
126 ··package:134 ··package:
Offset 132, 33 lines modifiedOffset 142, 23 lines modified
132 ··-·CCE-82985-3142 ··-·CCE-82985-3
133 ··-·enable_strategy143 ··-·enable_strategy
134 ··-·low_complexity144 ··-·low_complexity
135 ··-·low_disruption145 ··-·low_disruption
136 ··-·medium_severity146 ··-·medium_severity
137 ··-·no_reboot_needed147 ··-·no_reboot_needed
138 ··-·package_dnf-automatic_installed148 ··-·package_dnf-automatic_installed
139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
140 [[packages]] 
141 name·=·"dnf-automatic" 
142 version·=·"*" 
143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8149 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
144 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
145 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
146 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
147 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
148 package·install·dnf-automatic 
149 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
150 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low150 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
151 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low151 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
152 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false152 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
153 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable153 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
154 package·--add=dnf-automatic154 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
 155 ····yum·install·-y·"dnf-automatic"
 156 fi
155 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*157 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
156 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed158 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
157 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/159 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
158 automatic.conf.160 automatic.conf.
159 ·············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation161 ·············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
160 ·············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and162 ·············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
161 Rationale:···updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in163 Rationale:···updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 169, 14 lines modifiedOffset 169, 37 lines modified
169 Rule·ID:·····xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates169 Rule·ID:·····xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates
170 Identifiers:·CCE-82494-6170 Identifiers:·CCE-82494-6
171 ·············_\x8i_\x8s_\x8m····0940,·1144,·1467,·1472,·1483,·1493,·1494,·1495171 ·············_\x8i_\x8s_\x8m····0940,·1144,·1467,·1472,·1483,·1493,·1494,·1495
172 ·············_\x8n_\x8i_\x8s_\x8t···SI-2(5),·CM-6(a),·SI-2(c)172 ·············_\x8n_\x8i_\x8s_\x8t···SI-2(5),·CM-6(a),·SI-2(c)
173 References:··_\x8o_\x8s_\x8p_\x8p···FMT_SMF_EXT.1173 References:··_\x8o_\x8s_\x8p_\x8p···FMT_SMF_EXT.1
174 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080174 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
175 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61175 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
 176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 177 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 178 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 179 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 180 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···unknown
 181 -·name:·Configure·dnf-automatic·to·Install·Available·Updates·Automatically
 182 ··ini_file:
 183 ····dest:·/etc/dnf/automatic.conf
 184 ····section:·commands
 185 ····option:·apply_updates
 186 ····value:·'yes'
 187 ····create:·true
 188 ··tags:
 189 ··-·CCE-82494-6
 190 ··-·NIST-800-53-CM-6(a)
 191 ··-·NIST-800-53-SI-2(5)
 192 ··-·NIST-800-53-SI-2(c)
 193 ··-·dnf-automatic_apply_updates
 194 ··-·low_complexity
Max diff block lines reached; 216907/222659 bytes (97.42%) of diff not shown.
26.7 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-cis.html
    
Offset 14434, 15 lines modifiedOffset 14434, 15 lines modified
00038610:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren00038610:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren
00038620:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro00038620:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro
00038630:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron00038630:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron
00038640:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s00038640:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s
00038650:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str00038650:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str
00038660:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········00038660:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········
00038670:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·00038670:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·
00038680:·3230·3236·2d30·312d·3038·290a·2020·2020··2026-01-08).····00038680:·3230·3234·2d31·322d·3037·290a·2020·2020··2024-12-07).····
00038690:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li00038690:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li
000386a0:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>000386a0:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>
000386b0:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content000386b0:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content
000386c0:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a000386c0:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a
000386d0:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or000386d0:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or
000386e0:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con000386e0:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con
000386f0:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste000386f0:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste
Offset 15293, 237 lines modifiedOffset 15293, 237 lines modified
0003bbc0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003bbc0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003bbd0:·6d37·3938·3022·2074·6162·696e·6465·783d··m7980"·tabindex=0003bbd0:·6d37·3938·3022·2074·6162·696e·6465·783d··m7980"·tabindex=
0003bbe0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003bbe0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003bbf0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003bbf0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003bc00:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003bc00:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003bc10:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003bc10:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003bc20:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003bc20:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003bc30:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·0003bc30:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond
0003bc40:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003bc40:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a
0003bc50:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003bc50:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003bc60:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003bc60:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003bc70:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm70003bc70:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003bc80:·3938·3022·3e3c·7461·626c·6520·636c·6173··980"><table·clas0003bc80:·6d37·3938·3022·3e3c·7461·626c·6520·636c··m7980"><table·cl
0003bc90:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003bc90:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003bca0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003bca0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003bcb0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003bcb0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003bcc0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003bcc0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003bcd0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003bcd0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003bce0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003bce0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003bcf0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003bcf0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003bd00:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003bd00:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0003bd10:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003bd10:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003bd20:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003bd20:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
0003bd30:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003bd30:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
0003bd40:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003bd40:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003bd50:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003bd50:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003bd60:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003bd60:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003bd70:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc0003bd70:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.
 0003bd80:·7061·636b·6167·6520·2d2d·6164·643d·6169··package·--add=ai
 0003bd90:·6465·0a3c·2f63·6f64·653e·3c2f·7072·653e··de.</code></pre>
0003bd80:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid 
0003bd90:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install 
0003bda0:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag 
0003bdb0:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.···· 
0003bdc0:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in 
0003bdd0:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}. 
0003bde0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003bdf0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003be00:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003be10:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003be20:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003be30:·3d22·2369·646d·3739·3831·2220·7461·6269··="#idm7981"·tabi 
0003be40:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003be50:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003be60:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003be70:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003be80:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003be90:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
0003bea0:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</ 
0003beb0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003bec0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003bed0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003bee0:·646d·3739·3831·223e·3c74·6162·6c65·2063··dm7981"><table·c 
0003bef0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003bf00:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003bf10:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003bf20:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003bf30:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003bf40:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003bf50:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003bf60:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003bf70:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003bf80:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003bf90:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0003bfa0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003bfb0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003bfc0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003bfd0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003bfe0:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is 
0003bff0:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only 
0003c000:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat 
0003c010:·666f·726d·730a·6966·205b·2021·202d·6620··forms.if·[·!·-f· 
0003c020:·2f2e·646f·636b·6572·656e·7620·5d20·2661··/.dockerenv·]·&a 
0003c030:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f· 
0003c040:·2f72·756e·2f2e·636f·6e74·6169·6e65·7265··/run/.containere 
0003c050:·6e76·205d·3b20·7468·656e·0a0a·6966·2021··nv·];·then..if·! 
0003c060:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet· 
0003c070:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.·· 
0003c080:·2020·7975·6d20·696e·7374·616c·6c20·2d79····yum·install·-y 
0003c090:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else 
0003c0a0:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2· 
0003c0b0:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio 
0003c0c0:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica 
0003c0d0:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was 
0003c0e0:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code 
0003c0f0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003c100:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003c110:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003c120:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003c130:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003c140:·3739·3832·2220·7461·6269·6e64·6578·3d22··7982"·tabindex=" 
0003c150:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003c160:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003c170:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003c180:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003c190:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003c1a0:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible· 
0003c1b0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003c1c0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003c1d0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003c1e0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7 
0003c1f0:·3938·3222·3e3c·7461·626c·6520·636c·6173··982"><table·clas 
0003c200:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003c210:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003c220:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003c230:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003c240:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003c250:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003c260:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003c270:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003c280:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
Max diff block lines reached; 25517726/25550210 bytes (99.87%) of diff not shown.
2.34 MB
html2text {}
Max HTML report size reached
11.7 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-cis_server_l1.html
    
Offset 14434, 16 lines modifiedOffset 14434, 16 lines modified
00038610:·7369·6f6e·2048·6973·746f·7279·3c2f·6832··sion·History</h200038610:·7369·6f6e·2048·6973·746f·7279·3c2f·6832··sion·History</h2
00038620:·3e3c·703e·4375·7272·656e·7420·7665·7273··><p>Current·vers00038620:·3e3c·703e·4375·7272·656e·7420·7665·7273··><p>Current·vers
00038630:·696f·6e3a·203c·7374·726f·6e67·3e30·2e31··ion:·<strong>0.100038630:·696f·6e3a·203c·7374·726f·6e67·3e30·2e31··ion:·<strong>0.1
00038640:·2e37·343c·2f73·7472·6f6e·673e·3c2f·703e··.74</strong></p>00038640:·2e37·343c·2f73·7472·6f6e·673e·3c2f·703e··.74</strong></p>
00038650:·3c75·6c3e·3c6c·693e·3c73·7472·6f6e·673e··<ul><li><strong>00038650:·3c75·6c3e·3c6c·693e·3c73·7472·6f6e·673e··<ul><li><strong>
00038660:·6472·6166·743c·2f73·7472·6f6e·673e·0a20··draft</strong>.·00038660:·6472·6166·743c·2f73·7472·6f6e·673e·0a20··draft</strong>.·
00038670:·2020·2020·2020·2020·2020·2020·2020·2020··················00038670:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038680:·2020·2028·6173·206f·6620·3230·3236·2d30·····(as·of·2026-000038680:·2020·2028·6173·206f·6620·3230·3234·2d31·····(as·of·2024-1
00038690:·312d·3038·290a·2020·2020·2020·2020·2020··1-08).··········00038690:·322d·3037·290a·2020·2020·2020·2020·2020··2-07).··········
000386a0:·2020·2020·2020·3c2f·6c69·3e3c·2f75·6c3e········</li></ul>000386a0:·2020·2020·2020·3c2f·6c69·3e3c·2f75·6c3e········</li></ul>
000386b0:·3c2f·6469·763e·3c68·323e·5461·626c·6520··</div><h2>Table·000386b0:·3c2f·6469·763e·3c68·323e·5461·626c·6520··</div><h2>Table·
000386c0:·6f66·2043·6f6e·7465·6e74·733c·2f68·323e··of·Contents</h2>000386c0:·6f66·2043·6f6e·7465·6e74·733c·2f68·323e··of·Contents</h2>
000386d0:·3c6f·6c3e·3c6c·693e·3c61·2068·7265·663d··<ol><li><a·href=000386d0:·3c6f·6c3e·3c6c·693e·3c61·2068·7265·663d··<ol><li><a·href=
000386e0:·2223·7863·6364·665f·6f72·672e·7373·6770··"#xccdf_org.ssgp000386e0:·2223·7863·6364·665f·6f72·672e·7373·6770··"#xccdf_org.ssgp
000386f0:·726f·6a65·6374·2e63·6f6e·7465·6e74·5f67··roject.content_g000386f0:·726f·6a65·6374·2e63·6f6e·7465·6e74·5f67··roject.content_g
00038700:·726f·7570·5f73·7973·7465·6d22·3e53·7973··roup_system">Sys00038700:·726f·7570·5f73·7973·7465·6d22·3e53·7973··roup_system">Sys
Offset 15262, 236 lines modifiedOffset 15262, 236 lines modified
0003b9d0:·7461·7267·6574·3d22·2369·646d·3739·3830··target="#idm79800003b9d0:·7461·7267·6574·3d22·2369·646d·3739·3830··target="#idm7980
0003b9e0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003b9e0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003b9f0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003b9f0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003ba00:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003ba00:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003ba10:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003ba10:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003ba20:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003ba20:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003ba30:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003ba30:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003ba40:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp0003ba40:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni
0003ba50:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0003ba50:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003ba60:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003ba60:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003ba70:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003ba70:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003ba80:·6522·2069·643d·2269·646d·3739·3830·223e··e"·id="idm7980">0003ba80:·7073·6522·2069·643d·2269·646d·3739·3830··pse"·id="idm7980
0003ba90:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003ba90:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003baa0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003baa0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003bab0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003bab0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003bac0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003bac0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003bad0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003bad0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003bae0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003bae0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003baf0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003baf0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003bb00:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003bb00:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003bb10:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003bb10:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003bb20:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo0003bb20:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003bb30:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals0003bb30:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003bb40:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><0003bb40:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003bb50:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th0003bb50:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003bb60:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>0003bb60:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0003bb70:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003bb70:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003bb80:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa
 0003bb90:·6765·202d·2d61·6464·3d61·6964·650a·3c2f··ge·--add=aide.</
 0003bba0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003bbb0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003bbc0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003bbd0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003bbe0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003bbf0:·2369·646d·3739·3831·2220·7461·6269·6e64··#idm7981"·tabind
 0003bc00:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003bc10:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003bc20:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003bc30:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003bc40:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003bc50:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp
 0003bc60:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</
 0003bc70:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003bc80:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003bc90:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003bca0:·646d·3739·3831·223e·3c74·6162·6c65·2063··dm7981"><table·c
 0003bcb0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003bcc0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003bcd0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003bce0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003bcf0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003bd00:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003bd10:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003bb80:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include· 
0003bb90:·696e·7374·616c·6c5f·6169·6465·0a0a·636c··install_aide..cl 
0003bba0:·6173·7320·696e·7374·616c·6c5f·6169·6465··ass·install_aide 
0003bbb0:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·' 
0003bbc0:·6169·6465·273a·0a20·2020·2065·6e73·7572··aide':.····ensur 
0003bbd0:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install 
0003bbe0:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod 
0003bbf0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003bc00:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003bc10:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003bc20:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003bc30:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003bc40:·6d37·3938·3122·2074·6162·696e·6465·783d··m7981"·tabindex= 
0003bc50:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003bc60:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003bc70:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003bc80:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003bc90:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003bca0:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s 
0003bcb0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003bcc0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003bcd0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003bce0:·6170·7365·2220·6964·3d22·6964·6d37·3938··apse"·id="idm798 
0003bcf0:·3122·3e3c·7461·626c·6520·636c·6173·733d··1"><table·class= 
0003bd00:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003bd10:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003bd20:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003bd30:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003bd40:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003bd20:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003bd50:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003bd30:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003bd60:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003bd70:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003bd40:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003bd50:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
0003bd80:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R0003bd60:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
0003bd90:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f0003bd70:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003bd80:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003bd90:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003bda0:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_
 0003bdb0:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst
 0003bdc0:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac
 0003bdd0:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.·
 0003bde0:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;·
 0003bdf0:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··}
0003bda0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
0003bdb0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003bdc0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003bdd0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003bde0:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem 
0003bdf0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl 
0003be00:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c 
0003be10:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms 
0003be20:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc 
0003be30:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a 
0003be40:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/ 
0003be50:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·]; 
0003be60:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm· 
0003be70:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide 
Max diff block lines reached; 10870380/10902864 bytes (99.70%) of diff not shown.
1.28 MB
html2text {}
    
Offset 52, 15 lines modifiedOffset 52, 15 lines modified
52 ····*·cpe:/o:redhat:enterprise_linux:8.652 ····*·cpe:/o:redhat:enterprise_linux:8.6
53 ····*·cpe:/o:redhat:enterprise_linux:8.753 ····*·cpe:/o:redhat:enterprise_linux:8.7
54 ····*·cpe:/o:redhat:enterprise_linux:8.854 ····*·cpe:/o:redhat:enterprise_linux:8.8
55 ····*·cpe:/o:redhat:enterprise_linux:8.955 ····*·cpe:/o:redhat:enterprise_linux:8.9
56 ····*·cpe:/o:redhat:enterprise_linux:856 ····*·cpe:/o:redhat:enterprise_linux:8
57 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*57 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
58 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8458 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
59 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)59 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
60 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*60 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
61 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s61 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
62 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e62 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
63 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l63 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
64 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n64 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
65 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g65 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
66 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s66 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 117, 41 lines modifiedOffset 117, 45 lines modified
117 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5117 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
118 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199118 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
119 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359119 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359
120 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79120 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
121 ·············_\x8c_\x8i_\x8s············5.3.1121 ·············_\x8c_\x8i_\x8s············5.3.1
122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
123 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule123 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule
 124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 126 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 127 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 128 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 129 package·--add=aide
124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
126 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
127 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
128 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
129 include·install_aide135 include·install_aide
  
130 class·install_aide·{136 class·install_aide·{
131 ··package·{·'aide':137 ··package·{·'aide':
132 ····ensure·=>·'installed',138 ····ensure·=>·'installed',
133 ··}139 ··}
134 }140 }
 141 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 142 [[packages]]
 143 name·=·"aide"
 144 version·=·"*"
135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
140 #·Remediation·is·applicable·only·in·certain·platforms 
141 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
 150 package·install·aide
142 if·!·rpm·-q·--quiet·"aide"·;·then 
143 ····yum·install·-y·"aide" 
144 fi 
  
145 else 
146 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
147 fi 
148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
149 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
150 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
151 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
152 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
153 -·name:·Ensure·aide·is·installed156 -·name:·Ensure·aide·is·installed
154 ··package:157 ··package:
Offset 167, 33 lines modifiedOffset 171, 29 lines modified
167 ··-·PCI-DSSv4-11.5.2171 ··-·PCI-DSSv4-11.5.2
168 ··-·enable_strategy172 ··-·enable_strategy
169 ··-·low_complexity173 ··-·low_complexity
170 ··-·low_disruption174 ··-·low_disruption
171 ··-·medium_severity175 ··-·medium_severity
172 ··-·no_reboot_needed176 ··-·no_reboot_needed
173 ··-·package_aide_installed177 ··-·package_aide_installed
174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
175 [[packages]] 
176 name·=·"aide" 
177 version·=·"*" 
178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 183 #·Remediation·is·applicable·only·in·certain·platforms
 184 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 185 if·!·rpm·-q·--quiet·"aide"·;·then
 186 ····yum·install·-y·"aide"
 187 fi
183 package·install·aide 
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
189 package·--add=aide188 else
 189 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 190 fi
190 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*191 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
191 Run·the·following·command·to·generate·a·new·database:192 Run·the·following·command·to·generate·a·new·database:
192 $·sudo·/usr/sbin/aide·--init193 $·sudo·/usr/sbin/aide·--init
193 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:194 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
194 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz195 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
195 To·initiate·a·manual·check,·run·the·following·command:196 To·initiate·a·manual·check,·run·the·following·command:
196 $·sudo·/usr/sbin/aide·--check197 $·sudo·/usr/sbin/aide·--check
Offset 213, 28 lines modifiedOffset 213, 14 lines modified
213 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5213 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
214 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199214 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
215 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359215 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359
216 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79216 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
217 ·············_\x8c_\x8i_\x8s············5.3.1217 ·············_\x8c_\x8i_\x8s············5.3.1
218 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2218 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
219 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule219 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule
220 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
221 #·Remediation·is·applicable·only·in·certain·platforms 
222 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
223 if·!·rpm·-q·--quiet·"aide"·;·then 
224 ····yum·install·-y·"aide" 
225 fi 
  
Max diff block lines reached; 1337795/1343721 bytes (99.56%) of diff not shown.
11.4 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-cis_workstation_l1.html
    
Offset 14436, 15 lines modifiedOffset 14436, 15 lines modified
00038630:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·00038630:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·
00038640:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong00038640:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong
00038650:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>00038650:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>
00038660:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str00038660:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str
00038670:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron00038670:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron
00038680:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············00038680:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············
00038690:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·2000038690:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·20
000386a0:·3236·2d30·312d·3038·290a·2020·2020·2020··26-01-08).······000386a0:·3234·2d31·322d·3037·290a·2020·2020·2020··24-12-07).······
000386b0:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><000386b0:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><
000386c0:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta000386c0:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta
000386d0:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<000386d0:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<
000386e0:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h000386e0:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h
000386f0:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.000386f0:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.
00038700:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte00038700:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte
00038710:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"00038710:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"
Offset 15253, 237 lines modifiedOffset 15253, 237 lines modified
0003b940:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b940:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003b950:·646d·3739·3830·2220·7461·6269·6e64·6578··dm7980"·tabindex0003b950:·646d·3739·3830·2220·7461·6269·6e64·6578··dm7980"·tabindex
0003b960:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b960:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b970:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b970:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b980:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b980:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b990:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b990:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b9a0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b9a0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003b9b0:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet0003b9b0:·6d65·6469·6174·696f·6e20·416e·6163·6f6e··mediation·Anacon
0003b9c0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003b9c0:·6461·2073·6e69·7070·6574·20e2·87b2·3c2f··da·snippet·...</
0003b9d0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003b9d0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003b9e0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003b9e0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003b9f0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003b9f0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003ba00:·3739·3830·223e·3c74·6162·6c65·2063·6c61··7980"><table·cla0003ba00:·646d·3739·3830·223e·3c74·6162·6c65·2063··dm7980"><table·c
0003ba10:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003ba10:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003ba20:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003ba20:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003ba30:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003ba30:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003ba40:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003ba40:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003ba50:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003ba50:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003ba60:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003ba60:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003ba70:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003ba70:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003ba80:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003ba80:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003ba90:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003ba90:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003baa0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t0003baa0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
0003bab0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr0003bab0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
0003bac0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0003bac0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
0003bad0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl0003bad0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003bae0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0003bae0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
0003baf0:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in0003baf0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003bb00:·0a70·6163·6b61·6765·202d·2d61·6464·3d61··.package·--add=a
 0003bb10:·6964·650a·3c2f·636f·6465·3e3c·2f70·7265··ide.</code></pre
 0003bb20:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0003bb30:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0003bb40:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0003bb50:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 0003bb60:·7267·6574·3d22·2369·646d·3739·3831·2220··rget="#idm7981"·
 0003bb70:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0003bb80:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 0003bb90:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 0003bba0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 0003bbb0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 0003bbc0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003bbd0:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
 0003bbe0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003bbf0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003bc00:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003bc10:·2069·643d·2269·646d·3739·3831·223e·3c74···id="idm7981"><t
 0003bc20:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003bc30:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0003bc40:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0003bc50:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003bc60:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0003bc70:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003bc80:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003bc90:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003bb00:·636c·7564·6520·696e·7374·616c·6c5f·6169··clude·install_ai 
0003bb10:·6465·0a0a·636c·6173·7320·696e·7374·616c··de..class·instal 
0003bb20:·6c5f·6169·6465·207b·0a20·2070·6163·6b61··l_aide·{.··packa 
0003bb30:·6765·207b·2027·6169·6465·273a·0a20·2020··ge·{·'aide':.··· 
0003bb40:·2065·6e73·7572·6520·3d26·6774·3b20·2769···ensure·=&gt;·'i 
0003bb50:·6e73·7461·6c6c·6564·272c·0a20·207d·0a7d··nstalled',.··}.} 
0003bb60:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003bb70:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003bb80:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003bb90:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003bba0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003bbb0:·743d·2223·6964·6d37·3938·3122·2074·6162··t="#idm7981"·tab 
0003bbc0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003bbd0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003bbe0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003bbf0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003bc00:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003bc10:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
0003bc20:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
0003bc30:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003bc40:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003bc50:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003bc60:·6964·6d37·3938·3122·3e3c·7461·626c·6520··idm7981"><table· 
0003bc70:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003bc80:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003bc90:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003bca0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003bcb0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003bcc0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003bca0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003bcd0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003bce0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003bcb0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0003bcc0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003bcf0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003bcd0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003bce0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003bcf0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0003bd00:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003bd10:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in
 0003bd20:·7374·616c·6c5f·6169·6465·0a0a·636c·6173··stall_aide..clas
 0003bd30:·7320·696e·7374·616c·6c5f·6169·6465·207b··s·install_aide·{
 0003bd40:·0a20·2070·6163·6b61·6765·207b·2027·6169··.··package·{·'ai
 0003bd50:·6465·273a·0a20·2020·2065·6e73·7572·6520··de':.····ensure·
 0003bd60:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
 0003bd70:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
0003bd00:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003bd10:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003bd20:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003bd30:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
0003bd40:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
0003bd50:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
0003bd60:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i 
0003bd70:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl 
0003bd80:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla 
0003bd90:·7466·6f72·6d73·0a69·6620·5b20·2120·2d66··tforms.if·[·!·-f 
0003bda0:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·& 
0003bdb0:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f 
0003bdc0:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container 
0003bdd0:·656e·7620·5d3b·2074·6865·6e0a·0a69·6620··env·];·then..if· 
Max diff block lines reached; 10570257/10602741 bytes (99.69%) of diff not shown.
1.25 MB
html2text {}
    
Offset 53, 15 lines modifiedOffset 53, 15 lines modified
53 ····*·cpe:/o:redhat:enterprise_linux:8.653 ····*·cpe:/o:redhat:enterprise_linux:8.6
54 ····*·cpe:/o:redhat:enterprise_linux:8.754 ····*·cpe:/o:redhat:enterprise_linux:8.7
55 ····*·cpe:/o:redhat:enterprise_linux:8.855 ····*·cpe:/o:redhat:enterprise_linux:8.8
56 ····*·cpe:/o:redhat:enterprise_linux:8.956 ····*·cpe:/o:redhat:enterprise_linux:8.9
57 ····*·cpe:/o:redhat:enterprise_linux:857 ····*·cpe:/o:redhat:enterprise_linux:8
58 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*58 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
59 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8459 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
60 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)60 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
61 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*61 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
62 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s62 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
63 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e63 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
64 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l64 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
65 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n65 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
66 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g66 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
67 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s67 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 116, 41 lines modifiedOffset 116, 45 lines modified
116 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5116 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
117 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199117 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
118 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359118 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359
119 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79119 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
120 ·············_\x8c_\x8i_\x8s············5.3.1120 ·············_\x8c_\x8i_\x8s············5.3.1
121 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2121 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
122 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule122 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule
 123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 124 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 125 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 126 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 127 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 128 package·--add=aide
123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
124 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
125 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
126 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
127 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
128 include·install_aide134 include·install_aide
  
129 class·install_aide·{135 class·install_aide·{
130 ··package·{·'aide':136 ··package·{·'aide':
131 ····ensure·=>·'installed',137 ····ensure·=>·'installed',
132 ··}138 ··}
133 }139 }
 140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 141 [[packages]]
 142 name·=·"aide"
 143 version·=·"*"
134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
135 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low145 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
136 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low146 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
137 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false147 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
138 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable148 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
139 #·Remediation·is·applicable·only·in·certain·platforms 
140 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
 149 package·install·aide
141 if·!·rpm·-q·--quiet·"aide"·;·then 
142 ····yum·install·-y·"aide" 
143 fi 
  
144 else 
145 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
146 fi 
147 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
148 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low151 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
149 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low152 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
150 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false153 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
151 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable154 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
152 -·name:·Ensure·aide·is·installed155 -·name:·Ensure·aide·is·installed
153 ··package:156 ··package:
Offset 166, 33 lines modifiedOffset 170, 29 lines modified
166 ··-·PCI-DSSv4-11.5.2170 ··-·PCI-DSSv4-11.5.2
167 ··-·enable_strategy171 ··-·enable_strategy
168 ··-·low_complexity172 ··-·low_complexity
169 ··-·low_disruption173 ··-·low_disruption
170 ··-·medium_severity174 ··-·medium_severity
171 ··-·no_reboot_needed175 ··-·no_reboot_needed
172 ··-·package_aide_installed176 ··-·package_aide_installed
173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
174 [[packages]] 
175 name·=·"aide" 
176 version·=·"*" 
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 182 #·Remediation·is·applicable·only·in·certain·platforms
 183 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 184 if·!·rpm·-q·--quiet·"aide"·;·then
 185 ····yum·install·-y·"aide"
 186 fi
182 package·install·aide 
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
188 package·--add=aide187 else
 188 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 189 fi
189 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*190 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
190 Run·the·following·command·to·generate·a·new·database:191 Run·the·following·command·to·generate·a·new·database:
191 $·sudo·/usr/sbin/aide·--init192 $·sudo·/usr/sbin/aide·--init
192 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:193 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
193 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz194 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
194 To·initiate·a·manual·check,·run·the·following·command:195 To·initiate·a·manual·check,·run·the·following·command:
195 $·sudo·/usr/sbin/aide·--check196 $·sudo·/usr/sbin/aide·--check
Offset 212, 28 lines modifiedOffset 212, 14 lines modified
212 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5212 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
213 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199213 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
214 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359214 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359
215 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79215 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
216 ·············_\x8c_\x8i_\x8s············5.3.1216 ·············_\x8c_\x8i_\x8s············5.3.1
217 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2217 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
218 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule218 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule
219 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
220 #·Remediation·is·applicable·only·in·certain·platforms 
221 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
222 if·!·rpm·-q·--quiet·"aide"·;·then 
223 ····yum·install·-y·"aide" 
224 fi 
  
Max diff block lines reached; 1303947/1309873 bytes (99.55%) of diff not shown.
26.5 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-cis_workstation_l2.html
    
Offset 14436, 15 lines modifiedOffset 14436, 15 lines modified
00038630:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·00038630:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·
00038640:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong00038640:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong
00038650:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>00038650:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>
00038660:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str00038660:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str
00038670:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron00038670:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron
00038680:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············00038680:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············
00038690:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·2000038690:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·20
000386a0:·3236·2d30·312d·3038·290a·2020·2020·2020··26-01-08).······000386a0:·3234·2d31·322d·3037·290a·2020·2020·2020··24-12-07).······
000386b0:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><000386b0:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><
000386c0:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta000386c0:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta
000386d0:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<000386d0:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<
000386e0:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h000386e0:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h
000386f0:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.000386f0:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.
00038700:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte00038700:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte
00038710:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"00038710:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"
Offset 15285, 236 lines modifiedOffset 15285, 236 lines modified
0003bb40:·6172·6765·743d·2223·6964·6d37·3938·3022··arget="#idm7980"0003bb40:·6172·6765·743d·2223·6964·6d37·3938·3022··arget="#idm7980"
0003bb50:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003bb50:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003bb60:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003bb60:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003bb70:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003bb70:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003bb80:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003bb80:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003bb90:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003bb90:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003bba0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003bba0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003bbb0:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe0003bbb0:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip
0003bbc0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003bbc0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003bbd0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003bbd0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003bbe0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003bbe0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003bbf0:·2220·6964·3d22·6964·6d37·3938·3022·3e3c··"·id="idm7980"><0003bbf0:·7365·2220·6964·3d22·6964·6d37·3938·3022··se"·id="idm7980"
0003bc00:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003bc00:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003bc10:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003bc10:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003bc20:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003bc20:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003bc30:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003bc30:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003bc40:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003bc40:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003bc50:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003bc50:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003bc60:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003bc60:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003bc70:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003bc70:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003bc80:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003bc80:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003bc90:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo0003bc90:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
0003bca0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false0003bca0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
0003bcb0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003bcb0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
0003bcc0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>0003bcc0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0003bcd0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><0003bcd0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
0003bce0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0003bce0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003bcf0:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag
 0003bd00:·6520·2d2d·6164·643d·6169·6465·0a3c·2f63··e·--add=aide.</c
 0003bd10:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003bd20:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003bd30:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003bd40:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
0003bcf0:·3e3c·636f·6465·3e69·6e63·6c75·6465·2069··><code>include·i 
0003bd00:·6e73·7461·6c6c·5f61·6964·650a·0a63·6c61··nstall_aide..cla 
0003bd10:·7373·2069·6e73·7461·6c6c·5f61·6964·6520··ss·install_aide· 
0003bd20:·7b0a·2020·7061·636b·6167·6520·7b20·2761··{.··package·{·'a 
0003bd30:·6964·6527·3a0a·2020·2020·656e·7375·7265··ide':.····ensure 
0003bd40:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe 
0003bd50:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code 
0003bd60:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003bd70:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003bd80:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003bd90:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003bda0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003bdb0:·3739·3831·2220·7461·6269·6e64·6578·3d22··7981"·tabindex=" 
0003bdc0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003bdd0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003bde0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003bdf0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003be00:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003be10:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003be20:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003be30:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003be40:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003be50:·7073·6522·2069·643d·2269·646d·3739·3831··pse"·id="idm7981 
0003be60:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003be70:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003be80:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003be90:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003bea0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003beb0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003bec0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003bed0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003bee0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003bef0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003bf00:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0003bf10:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
0003bf20:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003bf30:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003bf40:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003bf50:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme 
0003bf60:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
0003bf70:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
0003bf80:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
0003bf90:·6966·205b·2021·202d·6620·2f2e·646f·636b··if·[·!·-f·/.dock 
0003bfa0:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am 
0003bfb0:·703b·205b·2021·202d·6620·2f72·756e·2f2e··p;·[·!·-f·/run/. 
0003bfc0:·636f·6e74·6169·6e65·7265·6e76·205d·3b20··containerenv·];· 
0003bfd0:·7468·656e·0a0a·6966·2021·2072·706d·202d··then..if·!·rpm·- 
0003bfe0:·7120·2d2d·7175·6965·7420·2261·6964·6522··q·--quiet·"aide" 
0003bff0:·203b·2074·6865·6e0a·2020·2020·7975·6d20···;·then.····yum· 
0003c000:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide 
0003c010:·220a·6669·0a0a·656c·7365·0a20·2020·2026··".fi..else.····& 
0003c020:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·' 
0003c030:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n 
0003c040:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n 
0003c050:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done' 
0003c060:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre 
0003c070:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003c080:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003c090:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003c0a0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003c0b0:·7267·6574·3d22·2369·646d·3739·3832·2220··rget="#idm7982"· 
0003c0c0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003c0d0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003c0e0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003c0f0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003c100:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003c110:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003c120:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe 
0003c130:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003c140:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003c150:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003c160:·2220·6964·3d22·6964·6d37·3938·3222·3e3c··"·id="idm7982">< 
0003c170:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003c180:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003c190:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003c1a0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003c1b0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003c1c0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
Max diff block lines reached; 25327037/25359383 bytes (99.87%) of diff not shown.
2.32 MB
html2text {}
Max HTML report size reached
10.1 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-cui.html
    
Offset 14469, 15 lines modifiedOffset 14469, 15 lines modified
00038840:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr00038840:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr
00038850:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st00038850:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st
00038860:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str00038860:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str
00038870:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>00038870:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>
00038880:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s00038880:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s
00038890:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········00038890:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········
000388a0:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o000388a0:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o
000388b0:·6620·3230·3236·2d30·312d·3038·290a·2020··f·2026-01-08).··000388b0:·6620·3230·3234·2d31·322d·3037·290a·2020··f·2024-12-07).··
000388c0:·2020·2020·2020·2020·2020·2020·2020·3c2f················</000388c0:·2020·2020·2020·2020·2020·2020·2020·3c2f················</
000388d0:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h000388d0:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h
000388e0:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte000388e0:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte
000388f0:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>000388f0:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>
00038900:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_00038900:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_
00038910:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c00038910:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c
00038920:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys00038920:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys
Offset 15284, 236 lines modifiedOffset 15284, 236 lines modified
0003bb30:·2d74·6172·6765·743d·2223·6964·6d37·3938··-target="#idm7980003bb30:·2d74·6172·6765·743d·2223·6964·6d37·3938··-target="#idm798
0003bb40:·3022·2074·6162·696e·6465·783d·2230·2220··0"·tabindex="0"·0003bb40:·3022·2074·6162·696e·6465·783d·2230·2220··0"·tabindex="0"·
0003bb50:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003bb50:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003bb60:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003bb60:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003bb70:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003bb70:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003bb80:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003bb80:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003bb90:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003bb90:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003bba0:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip0003bba0:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn
0003bbb0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003bbb0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003bbc0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003bbc0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003bbd0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003bbd0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003bbe0:·7365·2220·6964·3d22·6964·6d37·3938·3022··se"·id="idm7980"0003bbe0:·6170·7365·2220·6964·3d22·6964·6d37·3938··apse"·id="idm798
0003bbf0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003bbf0:·3022·3e3c·7461·626c·6520·636c·6173·733d··0"><table·class=
0003bc00:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003bc00:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003bc10:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003bc10:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003bc20:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003bc20:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003bc30:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003bc30:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003bc40:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l0003bc40:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003bc50:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003bc50:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003bc60:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<0003bc60:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003bc70:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003bc70:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003bc80:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb0003bc80:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
0003bc90:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal0003bc90:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
0003bca0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>0003bca0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
0003bcb0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t0003bcb0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0003bcc0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td0003bcc0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
0003bcd0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p0003bcd0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003bce0:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack
 0003bcf0:·6167·6520·2d2d·6164·643d·6169·6465·0a3c··age·--add=aide.<
 0003bd00:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003bd10:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003bd20:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003bd30:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0003bd40:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003bd50:·2223·6964·6d37·3938·3122·2074·6162·696e··"#idm7981"·tabin
 0003bd60:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003bd70:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003bd80:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003bd90:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003bda0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003bdb0:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
 0003bdc0:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
 0003bdd0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003bde0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003bdf0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003be00:·6964·6d37·3938·3122·3e3c·7461·626c·6520··idm7981"><table·
 0003be10:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003be20:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003be30:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003be40:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003be50:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003be60:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003be70:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 0003be80:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003bce0:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include 
0003bcf0:·2069·6e73·7461·6c6c·5f61·6964·650a·0a63···install_aide..c 
0003bd00:·6c61·7373·2069·6e73·7461·6c6c·5f61·6964··lass·install_aid 
0003bd10:·6520·7b0a·2020·7061·636b·6167·6520·7b20··e·{.··package·{· 
0003bd20:·2761·6964·6527·3a0a·2020·2020·656e·7375··'aide':.····ensu 
0003bd30:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal 
0003bd40:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co 
0003bd50:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003bd60:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003bd70:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003bd80:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003bd90:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003bda0:·646d·3739·3831·2220·7461·6269·6e64·6578··dm7981"·tabindex 
0003bdb0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003bdc0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003bdd0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003bde0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003bdf0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003be00:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
0003be10:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003be20:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003be30:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003be40:·6c61·7073·6522·2069·643d·2269·646d·3739··lapse"·id="idm79 
0003be50:·3831·223e·3c74·6162·6c65·2063·6c61·7373··81"><table·class 
0003be60:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003be70:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003be80:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003be90:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003bea0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003beb0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003be90:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003bec0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003bed0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003bea0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 0003beb0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
0003bee0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003bec0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
0003bef0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>0003bed0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
 0003bee0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 0003bef0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003bf00:·3e69·6e63·6c75·6465·2069·6e73·7461·6c6c··>include·install
 0003bf10:·5f61·6964·650a·0a63·6c61·7373·2069·6e73··_aide..class·ins
 0003bf20:·7461·6c6c·5f61·6964·6520·7b0a·2020·7061··tall_aide·{.··pa
 0003bf30:·636b·6167·6520·7b20·2761·6964·6527·3a0a··ckage·{·'aide':.
 0003bf40:·2020·2020·656e·7375·7265·203d·2667·743b······ensure·=&gt;
 0003bf50:·2027·696e·7374·616c·6c65·6427·2c0a·2020···'installed',.··
0003bf00:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
0003bf10:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003bf20:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003bf30:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003bf40:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re 
0003bf50:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app 
0003bf60:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in· 
0003bf70:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform 
0003bf80:·730a·6966·205b·2021·202d·6620·2f2e·646f··s.if·[·!·-f·/.do 
0003bf90:·636b·6572·656e·7620·5d20·2661·6d70·3b26··ckerenv·]·&amp;& 
0003bfa0:·616d·703b·205b·2021·202d·6620·2f72·756e··amp;·[·!·-f·/run 
0003bfb0:·2f2e·636f·6e74·6169·6e65·7265·6e76·205d··/.containerenv·] 
0003bfc0:·3b20·7468·656e·0a0a·6966·2021·2072·706d··;·then..if·!·rpm 
0003bfd0:·202d·7120·2d2d·7175·6965·7420·2261·6964···-q·--quiet·"aid 
Max diff block lines reached; 9229631/9261977 bytes (99.65%) of diff not shown.
1.23 MB
html2text {}
    
Offset 61, 15 lines modifiedOffset 61, 15 lines modified
61 ····*·cpe:/o:redhat:enterprise_linux:8.661 ····*·cpe:/o:redhat:enterprise_linux:8.6
62 ····*·cpe:/o:redhat:enterprise_linux:8.762 ····*·cpe:/o:redhat:enterprise_linux:8.7
63 ····*·cpe:/o:redhat:enterprise_linux:8.863 ····*·cpe:/o:redhat:enterprise_linux:8.8
64 ····*·cpe:/o:redhat:enterprise_linux:8.964 ····*·cpe:/o:redhat:enterprise_linux:8.9
65 ····*·cpe:/o:redhat:enterprise_linux:865 ····*·cpe:/o:redhat:enterprise_linux:8
66 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*66 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
67 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8467 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
68 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)68 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
69 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*69 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
70 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s70 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
71 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e71 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
72 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l72 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
73 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n73 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
74 ·········4.·_\x8z_\x8I_\x8P_\x8L_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n74 ·········4.·_\x8z_\x8I_\x8P_\x8L_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
75 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g75 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 122, 41 lines modifiedOffset 122, 45 lines modified
122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
123 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199123 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359
125 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79125 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
126 ·············_\x8c_\x8i_\x8s············5.3.1126 ·············_\x8c_\x8i_\x8s············5.3.1
127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
128 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule128 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule
 129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 134 package·--add=aide
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
134 include·install_aide140 include·install_aide
  
135 class·install_aide·{141 class·install_aide·{
136 ··package·{·'aide':142 ··package·{·'aide':
137 ····ensure·=>·'installed',143 ····ensure·=>·'installed',
138 ··}144 ··}
139 }145 }
 146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 147 [[packages]]
 148 name·=·"aide"
 149 version·=·"*"
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low151 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low152 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false153 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable154 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
145 #·Remediation·is·applicable·only·in·certain·platforms 
146 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
 155 package·install·aide
147 if·!·rpm·-q·--quiet·"aide"·;·then 
148 ····yum·install·-y·"aide" 
149 fi 
  
150 else 
151 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
152 fi 
153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
154 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low157 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
155 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low158 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
156 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false159 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
157 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable160 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
158 -·name:·Ensure·aide·is·installed161 -·name:·Ensure·aide·is·installed
159 ··package:162 ··package:
Offset 172, 33 lines modifiedOffset 176, 29 lines modified
172 ··-·PCI-DSSv4-11.5.2176 ··-·PCI-DSSv4-11.5.2
173 ··-·enable_strategy177 ··-·enable_strategy
174 ··-·low_complexity178 ··-·low_complexity
175 ··-·low_disruption179 ··-·low_disruption
176 ··-·medium_severity180 ··-·medium_severity
177 ··-·no_reboot_needed181 ··-·no_reboot_needed
178 ··-·package_aide_installed182 ··-·package_aide_installed
179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
180 [[packages]] 
181 name·=·"aide" 
182 version·=·"*" 
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 188 #·Remediation·is·applicable·only·in·certain·platforms
 189 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 190 if·!·rpm·-q·--quiet·"aide"·;·then
 191 ····yum·install·-y·"aide"
 192 fi
188 package·install·aide 
189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
194 package·--add=aide193 else
 194 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 195 fi
195 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules196 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
196 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.197 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
197 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.198 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.
  
198 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.199 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
199 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*200 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 215, 27 lines modifiedOffset 215, 14 lines modified
215 ·············_\x8i_\x8s_\x8m······1446215 ·············_\x8i_\x8s_\x8m······1446
216 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1216 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
217 References:··_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12217 References:··_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
218 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.1218 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.1
219 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223219 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223
220 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-08-010020220 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-08-010020
221 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r928585_rule221 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r928585_rule
222 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
223 #·Remediation·is·applicable·only·in·certain·platforms 
224 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·);·then 
  
225 fips-mode-setup·--enable 
226 FIPS_CONF="/etc/dracut.conf.d/40-fips.conf" 
227 if·!·grep·"^add_dracutmodules+=\"·fips·\""·$FIPS_CONF;·then 
228 ····echo·"add_dracutmodules+=\"·fips·\""·>>·$FIPS_CONF 
Max diff block lines reached; 1282256/1288701 bytes (99.50%) of diff not shown.
7.01 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-e8.html
    
Offset 14436, 15 lines modifiedOffset 14436, 15 lines modified
00038630:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v00038630:·2f68·323e·3c70·3e43·7572·7265·6e74·2076··/h2><p>Current·v
00038640:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>00038640:·6572·7369·6f6e·3a20·3c73·7472·6f6e·673e··ersion:·<strong>
00038650:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><00038650:·302e·312e·3734·3c2f·7374·726f·6e67·3e3c··0.1.74</strong><
00038660:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro00038660:·2f70·3e3c·756c·3e3c·6c69·3e3c·7374·726f··/p><ul><li><stro
00038670:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong00038670:·6e67·3e64·7261·6674·3c2f·7374·726f·6e67··ng>draft</strong
00038680:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············00038680:·3e0a·2020·2020·2020·2020·2020·2020·2020··>.··············
00038690:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·20200038690:·2020·2020·2020·2861·7320·6f66·2032·3032········(as·of·202
000386a0:·362d·3031·2d30·3829·0a20·2020·2020·2020··6-01-08).·······000386a0:·342d·3132·2d30·3729·0a20·2020·2020·2020··4-12-07).·······
000386b0:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></000386b0:·2020·2020·2020·2020·203c·2f6c·693e·3c2f···········</li></
000386c0:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab000386c0:·756c·3e3c·2f64·6976·3e3c·6832·3e54·6162··ul></div><h2>Tab
000386d0:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</000386d0:·6c65·206f·6620·436f·6e74·656e·7473·3c2f··le·of·Contents</
000386e0:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr000386e0:·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872··h2><ol><li><a·hr
000386f0:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s000386f0:·6566·3d22·2378·6363·6466·5f6f·7267·2e73··ef="#xccdf_org.s
00038700:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten00038700:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten
00038710:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">00038710:·745f·6772·6f75·705f·7379·7374·656d·223e··t_group_system">
Offset 15318, 305 lines modifiedOffset 15318, 305 lines modified
0003bd50:·7267·6574·3d22·2369·646d·3736·3336·2220··rget="#idm7636"·0003bd50:·7267·6574·3d22·2369·646d·3736·3336·2220··rget="#idm7636"·
0003bd60:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003bd60:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003bd70:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003bd70:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003bd80:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003bd80:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003bd90:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003bd90:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003bda0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003bda0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003bdb0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003bdb0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003bdc0:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
0003bdd0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003bde0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003bdf0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003be00:·643d·2269·646d·3736·3336·223e·3c70·7265··d="idm7636"><pre 
0003be10:·3e3c·636f·6465·3e0a·2320·4669·6e64·2077··><code>.#·Find·w 
0003be20:·6869·6368·2066·696c·6573·2068·6176·6520··hich·files·have· 
0003be30:·696e·636f·7272·6563·7420·6861·7368·2028··incorrect·hash·( 
0003be40:·6e6f·7420·696e·202f·6574·632c·2062·6563··not·in·/etc,·bec 
0003be50:·6175·7365·206f·6620·7468·6520·7379·7374··ause·of·the·syst 
0003be60:·656d·2072·656c·6174·6564·2063·6f6e·6669··em·related·confi 
0003be70:·6720·6669·6c65·7329·2061·6e64·2074·6865··g·files)·and·the 
0003be80:·6e20·6765·7420·6669·6c65·7320·6e61·6d65··n·get·files·name 
0003be90:·730a·6669·6c65·735f·7769·7468·5f69·6e63··s.files_with_inc 
0003bea0:·6f72·7265·6374·5f68·6173·683d·2224·2872··orrect_hash="$(r 
0003beb0:·706d·202d·5661·202d·2d6e·6f63·6f6e·6669··pm·-Va·--noconfi 
0003bec0:·6720·7c20·6772·6570·202d·4520·275e·2e2e··g·|·grep·-E·'^.. 
0003bed0:·3527·207c·2061·776b·2027·7b70·7269·6e74··5'·|·awk·'{print 
0003bee0:·2024·4e46·7d27·2029·220a·0a69·6620·5b20···$NF}'·)"..if·[· 
0003bef0:·2d6e·2022·2466·696c·6573·5f77·6974·685f··-n·"$files_with_ 
0003bf00:·696e·636f·7272·6563·745f·6861·7368·2220··incorrect_hash"· 
0003bf10:·5d3b·2074·6865·6e0a·2020·2020·2320·4672··];·then.····#·Fr 
0003bf20:·6f6d·2066·696c·6573·206e·616d·6573·2067··om·files·names·g 
0003bf30:·6574·2070·6163·6b61·6765·206e·616d·6573··et·package·names 
0003bf40:·2061·6e64·2063·6861·6e67·6520·6e65·776c···and·change·newl 
0003bf50:·696e·6520·746f·2073·7061·6365·2c20·6265··ine·to·space,·be 
0003bf60:·6361·7573·6520·7270·6d20·7772·6974·6573··cause·rpm·writes 
0003bf70:·2065·6163·6820·7061·636b·6167·6520·746f···each·package·to 
0003bf80:·206e·6577·206c·696e·650a·2020·2020·7061···new·line.····pa 
0003bf90:·636b·6167·6573·5f74·6f5f·7265·696e·7374··ckages_to_reinst 
0003bfa0:·616c·6c3d·2224·2872·706d·202d·7166·2024··all="$(rpm·-qf·$ 
0003bfb0:·6669·6c65·735f·7769·7468·5f69·6e63·6f72··files_with_incor 
0003bfc0:·7265·6374·5f68·6173·6820·7c20·7472·2027··rect_hash·|·tr·' 
0003bfd0:·5c6e·2720·2720·2729·220a·0a20·2020·200a··\n'·'·')"..····. 
0003bfe0:·2020·2020·7975·6d20·7265·696e·7374·616c······yum·reinstal 
0003bff0:·6c20·2d79·2024·7061·636b·6167·6573·5f74··l·-y·$packages_t 
0003c000:·6f5f·7265·696e·7374·616c·6c0a·2020·2020··o_reinstall.···· 
0003c010:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre 
0003c020:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003c030:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003c040:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003c050:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003c060:·7267·6574·3d22·2369·646d·3736·3337·2220··rget="#idm7637"· 
0003c070:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003c080:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003c090:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003c0a0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003c0b0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003c0c0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003c0d0:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe0003bdc0:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe
0003c0e0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003bdd0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003c0f0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003bde0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003c100:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003bdf0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003c110:·2220·6964·3d22·6964·6d37·3633·3722·3e3c··"·id="idm7637"><0003be00:·2220·6964·3d22·6964·6d37·3633·3622·3e3c··"·id="idm7636"><
0003c120:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003be10:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003c130:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003be20:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003c140:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003be30:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003c150:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003be40:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003c160:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003be50:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003c170:·6974·793a·3c2f·7468·3e3c·7464·3e68·6967··ity:</th><td>hig0003be60:·6974·793a·3c2f·7468·3e3c·7464·3e68·6967··ity:</th><td>hig
0003c180:·683c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··h</td></tr><tr><0003be70:·683c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··h</td></tr><tr><
0003c190:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003be80:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
0003c1a0:·7468·3e3c·7464·3e6d·6564·6975·6d3c·2f74··th><td>medium</t0003be90:·7468·3e3c·7464·3e6d·6564·6975·6d3c·2f74··th><td>medium</t
0003c1b0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R0003bea0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
0003c1c0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f0003beb0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
0003c1d0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t0003bec0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
0003c1e0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<0003bed0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0003c1f0:·2f74·683e·3c74·643e·7265·7374·7269·6374··/th><td>restrict0003bee0:·2f74·683e·3c74·643e·7265·7374·7269·6374··/th><td>restrict
0003c200:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003bef0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003c210:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n0003bf00:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n
0003c220:·616d·653a·2027·5365·7420·6661·6374·3a20··ame:·'Set·fact:·0003bf10:·616d·653a·2027·5365·7420·6661·6374·3a20··ame:·'Set·fact:·
0003c230:·5061·636b·6167·6520·6d61·6e61·6765·7220··Package·manager·0003bf20:·5061·636b·6167·6520·6d61·6e61·6765·7220··Package·manager·
0003c240:·7265·696e·7374·616c·6c20·636f·6d6d·616e··reinstall·comman0003bf30:·7265·696e·7374·616c·6c20·636f·6d6d·616e··reinstall·comman
0003c250:·6427·0a20·2073·6574·5f66·6163·743a·0a20··d'.··set_fact:.·0003bf40:·6427·0a20·2073·6574·5f66·6163·743a·0a20··d'.··set_fact:.·
0003c260:·2020·2070·6163·6b61·6765·5f6d·616e·6167·····package_manag0003bf50:·2020·2070·6163·6b61·6765·5f6d·616e·6167·····package_manag
0003c270:·6572·5f72·6569·6e73·7461·6c6c·5f63·6d64··er_reinstall_cmd0003bf60:·6572·5f72·6569·6e73·7461·6c6c·5f63·6d64··er_reinstall_cmd
0003c280:·3a20·7975·6d20·7265·696e·7374·616c·6c20··:·yum·reinstall·0003bf70:·3a20·7975·6d20·7265·696e·7374·616c·6c20··:·yum·reinstall·
0003c290:·2d79·0a20·2077·6865·6e3a·2061·6e73·6962··-y.··when:·ansib0003bf80:·2d79·0a20·2077·6865·6e3a·2061·6e73·6962··-y.··when:·ansib
0003c2a0:·6c65·5f64·6973·7472·6962·7574·696f·6e20··le_distribution·0003bf90:·6c65·5f64·6973·7472·6962·7574·696f·6e20··le_distribution·
0003c2b0:·696e·205b·2022·4665·646f·7261·222c·2022··in·[·"Fedora",·"0003bfa0:·696e·205b·2022·4665·646f·7261·222c·2022··in·[·"Fedora",·"
0003c2c0:·5265·6448·6174·222c·2022·4365·6e74·4f53··RedHat",·"CentOS0003bfb0:·5265·6448·6174·222c·2022·4365·6e74·4f53··RedHat",·"CentOS
0003c2d0:·222c·2022·4f72·6163·6c65·4c69·6e75·7822··",·"OracleLinux"0003bfc0:·222c·2022·4f72·6163·6c65·4c69·6e75·7822··",·"OracleLinux"
0003c2e0:·205d·0a20·2074·6167·733a·0a20·202d·2043···].··tags:.··-·C0003bfd0:·205d·0a20·2074·6167·733a·0a20·202d·2043···].··tags:.··-·C
0003c2f0:·4345·2d38·3038·3537·2d36·0a20·202d·2043··CE-80857-6.··-·C0003bfe0:·4345·2d38·3038·3537·2d36·0a20·202d·2043··CE-80857-6.··-·C
0003c300:·4a49·532d·352e·3130·2e34·2e31·0a20·202d··JIS-5.10.4.1.··-0003bff0:·4a49·532d·352e·3130·2e34·2e31·0a20·202d··JIS-5.10.4.1.··-
0003c310:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.0003c000:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.
0003c320:·332e·380a·2020·2d20·4e49·5354·2d38·3030··3.8.··-·NIST-8000003c010:·332e·380a·2020·2d20·4e49·5354·2d38·3030··3.8.··-·NIST-800
0003c330:·2d31·3731·2d33·2e34·2e31·0a20·202d·204e··-171-3.4.1.··-·N0003c020:·2d31·3731·2d33·2e34·2e31·0a20·202d·204e··-171-3.4.1.··-·N
0003c340:·4953·542d·3830·302d·3533·2d41·552d·3928··IST-800-53-AU-9(0003c030:·4953·542d·3830·302d·3533·2d41·552d·3928··IST-800-53-AU-9(
0003c350:·3329·0a20·202d·204e·4953·542d·3830·302d··3).··-·NIST-800-0003c040:·3329·0a20·202d·204e·4953·542d·3830·302d··3).··-·NIST-800-
0003c360:·3533·2d43·4d2d·3628·6329·0a20·202d·204e··53-CM-6(c).··-·N0003c050:·3533·2d43·4d2d·3628·6329·0a20·202d·204e··53-CM-6(c).··-·N
0003c370:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6(0003c060:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6(
0003c380:·6429·0a20·202d·204e·4953·542d·3830·302d··d).··-·NIST-800-0003c070:·6429·0a20·202d·204e·4953·542d·3830·302d··d).··-·NIST-800-
0003c390:·3533·2d53·492d·370a·2020·2d20·4e49·5354··53-SI-7.··-·NIST0003c080:·3533·2d53·492d·370a·2020·2d20·4e49·5354··53-SI-7.··-·NIST
0003c3a0:·2d38·3030·2d35·332d·5349·2d37·2831·290a··-800-53-SI-7(1).0003c090:·2d38·3030·2d35·332d·5349·2d37·2831·290a··-800-53-SI-7(1).
0003c3b0:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53- 
0003c3c0:·5349·2d37·2836·290a·2020·2d20·5043·492d··SI-7(6).··-·PCI- 
0003c3d0:·4453·532d·5265·712d·3131·2e35·0a20·202d··DSS-Req-11.5.··- 
0003c3e0:·2050·4349·2d44·5353·7634·2d31·312e·352e···PCI-DSSv4-11.5. 
0003c3f0:·320a·2020·2d20·6869·6768·5f63·6f6d·706c··2.··-·high_compl 
0003c400:·6578·6974·790a·2020·2d20·6869·6768·5f73··exity.··-·high_s 
0003c410:·6576·6572·6974·790a·2020·2d20·6d65·6469··everity.··-·medi 
0003c420:·756d·5f64·6973·7275·7074·696f·6e0a·2020··um_disruption.·· 
0003c430:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need 
Max diff block lines reached; 6577866/6619734 bytes (99.37%) of diff not shown.
712 KB
html2text {}
    
Offset 52, 15 lines modifiedOffset 52, 15 lines modified
52 ····*·cpe:/o:redhat:enterprise_linux:8.652 ····*·cpe:/o:redhat:enterprise_linux:8.6
53 ····*·cpe:/o:redhat:enterprise_linux:8.753 ····*·cpe:/o:redhat:enterprise_linux:8.7
54 ····*·cpe:/o:redhat:enterprise_linux:8.854 ····*·cpe:/o:redhat:enterprise_linux:8.8
55 ····*·cpe:/o:redhat:enterprise_linux:8.955 ····*·cpe:/o:redhat:enterprise_linux:8.9
56 ····*·cpe:/o:redhat:enterprise_linux:856 ····*·cpe:/o:redhat:enterprise_linux:8
57 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*57 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
58 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8458 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
59 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)59 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
60 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*60 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
61 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s61 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
62 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e62 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
63 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l63 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
64 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g64 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
65 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s65 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
66 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s66 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 115, 27 lines modifiedOffset 115, 14 lines modified
115 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6115 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
116 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4116 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
117 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)117 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
118 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1118 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
119 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5119 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
120 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227120 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
121 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2121 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
123 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
124 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
125 if·[·-n·"$files_with_incorrect_hash"·];·then 
126 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
127 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
128 ····yum·reinstall·-y·$packages_to_reinstall 
  
129 fi 
130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high123 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium124 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false125 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict126 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
135 -·name:·'Set·fact:·Package·manager·reinstall·command'127 -·name:·'Set·fact:·Package·manager·reinstall·command'
136 ··set_fact:128 ··set_fact:
Offset 267, 14 lines modifiedOffset 254, 27 lines modified
267 ··-·PCI-DSSv4-11.5.2254 ··-·PCI-DSSv4-11.5.2
268 ··-·high_complexity255 ··-·high_complexity
269 ··-·high_severity256 ··-·high_severity
270 ··-·medium_disruption257 ··-·medium_disruption
271 ··-·no_reboot_needed258 ··-·no_reboot_needed
272 ··-·restrict_strategy259 ··-·restrict_strategy
273 ··-·rpm_verify_hashes260 ··-·rpm_verify_hashes
 261 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 262 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 263 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 264 if·[·-n·"$files_with_incorrect_hash"·];·then
 265 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 266 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 267 ····yum·reinstall·-y·$packages_to_reinstall
  
 268 fi
274 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*269 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
275 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:270 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
276 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'271 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
277 run·the·following·command·to·determine·which·package·owns·it:272 run·the·following·command·to·determine·which·package·owns·it:
278 $·rpm·-qf·FILENAME273 $·rpm·-qf·FILENAME
279 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:274 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
280 $·sudo·rpm·--setugids·PACKAGENAME275 $·sudo·rpm·--setugids·PACKAGENAME
Offset 294, 40 lines modifiedOffset 294, 14 lines modified
294 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5294 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
295 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2295 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
296 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)296 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
297 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1297 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
298 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5298 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
299 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108299 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
300 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2300 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
301 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
302 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
303 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
304 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
305 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
306 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
307 declare·-A·SETPERMS_RPM_DICT 
  
308 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
309 #·is·expected·by·the·RPM·database 
310 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
311 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
312 do 
313 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
314 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
315 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
316 done 
  
317 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
318 #·correct·values 
319 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
320 do 
321 ········rpm·--setugids·"${RPM_PACKAGE}" 
322 done 
323 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8301 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
324 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high302 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
325 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium303 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
326 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false304 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
327 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict305 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
328 -·name:·Read·list·of·files·with·incorrect·ownership306 -·name:·Read·list·of·files·with·incorrect·ownership
329 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev307 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 405, 14 lines modifiedOffset 379, 40 lines modified
405 ··-·PCI-DSSv4-11.5.2379 ··-·PCI-DSSv4-11.5.2
406 ··-·high_complexity380 ··-·high_complexity
407 ··-·high_severity381 ··-·high_severity
408 ··-·medium_disruption382 ··-·medium_disruption
409 ··-·no_reboot_needed383 ··-·no_reboot_needed
410 ··-·restrict_strategy384 ··-·restrict_strategy
411 ··-·rpm_verify_ownership385 ··-·rpm_verify_ownership
 386 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 387 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 388 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 389 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 390 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 391 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 721793/729551 bytes (98.94%) of diff not shown.
17.8 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-hipaa.html
    
Offset 14455, 16 lines modifiedOffset 14455, 16 lines modified
00038760:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>00038760:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>
00038770:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi00038770:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi
00038780:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.00038780:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.
00038790:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><00038790:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><
000387a0:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d000387a0:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d
000387b0:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··000387b0:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··
000387c0:·2020·2020·2020·2020·2020·2020·2020·2020··················000387c0:·2020·2020·2020·2020·2020·2020·2020·2020··················
000387d0:·2020·2861·7320·6f66·2032·3032·362d·3031····(as·of·2026-01000387d0:·2020·2861·7320·6f66·2032·3032·342d·3132····(as·of·2024-12
000387e0:·2d30·3829·0a20·2020·2020·2020·2020·2020··-08).···········000387e0:·2d30·3729·0a20·2020·2020·2020·2020·2020··-07).···········
000387f0:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><000387f0:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><
00038800:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o00038800:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o
00038810:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><00038810:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><
00038820:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="00038820:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="
00038830:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr00038830:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr
00038840:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr00038840:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr
00038850:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst00038850:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst
Offset 15344, 306 lines modifiedOffset 15344, 306 lines modified
0003bef0:·7461·7267·6574·3d22·2369·646d·3736·3336··target="#idm76360003bef0:·7461·7267·6574·3d22·2369·646d·3736·3336··target="#idm7636
0003bf00:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003bf00:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003bf10:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003bf10:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003bf20:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003bf20:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003bf30:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003bf30:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003bf40:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003bf40:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003bf50:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003bf50:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003bf60:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003bf70:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003bf80:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003bf90:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003bfa0:·2069·643d·2269·646d·3736·3336·223e·3c70···id="idm7636"><p 
0003bfb0:·7265·3e3c·636f·6465·3e0a·2320·4669·6e64··re><code>.#·Find 
0003bfc0:·2077·6869·6368·2066·696c·6573·2068·6176···which·files·hav 
0003bfd0:·6520·696e·636f·7272·6563·7420·6861·7368··e·incorrect·hash 
0003bfe0:·2028·6e6f·7420·696e·202f·6574·632c·2062···(not·in·/etc,·b 
0003bff0:·6563·6175·7365·206f·6620·7468·6520·7379··ecause·of·the·sy 
0003c000:·7374·656d·2072·656c·6174·6564·2063·6f6e··stem·related·con 
0003c010:·6669·6720·6669·6c65·7329·2061·6e64·2074··fig·files)·and·t 
0003c020:·6865·6e20·6765·7420·6669·6c65·7320·6e61··hen·get·files·na 
0003c030:·6d65·730a·6669·6c65·735f·7769·7468·5f69··mes.files_with_i 
0003c040:·6e63·6f72·7265·6374·5f68·6173·683d·2224··ncorrect_hash="$ 
0003c050:·2872·706d·202d·5661·202d·2d6e·6f63·6f6e··(rpm·-Va·--nocon 
0003c060:·6669·6720·7c20·6772·6570·202d·4520·275e··fig·|·grep·-E·'^ 
0003c070:·2e2e·3527·207c·2061·776b·2027·7b70·7269··..5'·|·awk·'{pri 
0003c080:·6e74·2024·4e46·7d27·2029·220a·0a69·6620··nt·$NF}'·)"..if· 
0003c090:·5b20·2d6e·2022·2466·696c·6573·5f77·6974··[·-n·"$files_wit 
0003c0a0:·685f·696e·636f·7272·6563·745f·6861·7368··h_incorrect_hash 
0003c0b0:·2220·5d3b·2074·6865·6e0a·2020·2020·2320··"·];·then.····#· 
0003c0c0:·4672·6f6d·2066·696c·6573·206e·616d·6573··From·files·names 
0003c0d0:·2067·6574·2070·6163·6b61·6765·206e·616d···get·package·nam 
0003c0e0:·6573·2061·6e64·2063·6861·6e67·6520·6e65··es·and·change·ne 
0003c0f0:·776c·696e·6520·746f·2073·7061·6365·2c20··wline·to·space,· 
0003c100:·6265·6361·7573·6520·7270·6d20·7772·6974··because·rpm·writ 
0003c110:·6573·2065·6163·6820·7061·636b·6167·6520··es·each·package· 
0003c120:·746f·206e·6577·206c·696e·650a·2020·2020··to·new·line.···· 
0003c130:·7061·636b·6167·6573·5f74·6f5f·7265·696e··packages_to_rein 
0003c140:·7374·616c·6c3d·2224·2872·706d·202d·7166··stall="$(rpm·-qf 
0003c150:·2024·6669·6c65·735f·7769·7468·5f69·6e63···$files_with_inc 
0003c160:·6f72·7265·6374·5f68·6173·6820·7c20·7472··orrect_hash·|·tr 
0003c170:·2027·5c6e·2720·2720·2729·220a·0a20·2020···'\n'·'·')"..··· 
0003c180:·200a·2020·2020·7975·6d20·7265·696e·7374···.····yum·reinst 
0003c190:·616c·6c20·2d79·2024·7061·636b·6167·6573··all·-y·$packages 
0003c1a0:·5f74·6f5f·7265·696e·7374·616c·6c0a·2020··_to_reinstall.·· 
0003c1b0:·2020·0a66·690a·3c2f·636f·6465·3e3c·2f70····.fi.</code></p 
0003c1c0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003c1d0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003c1e0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003c1f0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003c200:·7461·7267·6574·3d22·2369·646d·3736·3337··target="#idm7637 
0003c210:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003c220:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003c230:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003c240:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003c250:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003c260:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003c270:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip0003bf60:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip
0003c280:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003bf70:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003c290:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003bf80:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003c2a0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003bf90:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003c2b0:·7365·2220·6964·3d22·6964·6d37·3633·3722··se"·id="idm7637"0003bfa0:·7365·2220·6964·3d22·6964·6d37·3633·3622··se"·id="idm7636"
0003c2c0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003bfb0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003c2d0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003bfc0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003c2e0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003bfd0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003c2f0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003bfe0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003c300:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003bff0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003c310:·6578·6974·793a·3c2f·7468·3e3c·7464·3e68··exity:</th><td>h0003c000:·6578·6974·793a·3c2f·7468·3e3c·7464·3e68··exity:</th><td>h
0003c320:·6967·683c·2f74·643e·3c2f·7472·3e3c·7472··igh</td></tr><tr0003c010:·6967·683c·2f74·643e·3c2f·7472·3e3c·7472··igh</td></tr><tr
0003c330:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003c020:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003c340:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<0003c030:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<
0003c350:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003c040:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c360:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003c050:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003c370:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003c060:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003c380:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003c070:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003c390:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri0003c080:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri
0003c3a0:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta0003c090:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta
0003c3b0:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-0003c0a0:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-
0003c3c0:·206e·616d·653a·2027·5365·7420·6661·6374···name:·'Set·fact0003c0b0:·206e·616d·653a·2027·5365·7420·6661·6374···name:·'Set·fact
0003c3d0:·3a20·5061·636b·6167·6520·6d61·6e61·6765··:·Package·manage0003c0c0:·3a20·5061·636b·6167·6520·6d61·6e61·6765··:·Package·manage
0003c3e0:·7220·7265·696e·7374·616c·6c20·636f·6d6d··r·reinstall·comm0003c0d0:·7220·7265·696e·7374·616c·6c20·636f·6d6d··r·reinstall·comm
0003c3f0:·616e·6427·0a20·2073·6574·5f66·6163·743a··and'.··set_fact:0003c0e0:·616e·6427·0a20·2073·6574·5f66·6163·743a··and'.··set_fact:
0003c400:·0a20·2020·2070·6163·6b61·6765·5f6d·616e··.····package_man0003c0f0:·0a20·2020·2070·6163·6b61·6765·5f6d·616e··.····package_man
0003c410:·6167·6572·5f72·6569·6e73·7461·6c6c·5f63··ager_reinstall_c0003c100:·6167·6572·5f72·6569·6e73·7461·6c6c·5f63··ager_reinstall_c
0003c420:·6d64·3a20·7975·6d20·7265·696e·7374·616c··md:·yum·reinstal0003c110:·6d64·3a20·7975·6d20·7265·696e·7374·616c··md:·yum·reinstal
0003c430:·6c20·2d79·0a20·2077·6865·6e3a·2061·6e73··l·-y.··when:·ans0003c120:·6c20·2d79·0a20·2077·6865·6e3a·2061·6e73··l·-y.··when:·ans
0003c440:·6962·6c65·5f64·6973·7472·6962·7574·696f··ible_distributio0003c130:·6962·6c65·5f64·6973·7472·6962·7574·696f··ible_distributio
0003c450:·6e20·696e·205b·2022·4665·646f·7261·222c··n·in·[·"Fedora",0003c140:·6e20·696e·205b·2022·4665·646f·7261·222c··n·in·[·"Fedora",
0003c460:·2022·5265·6448·6174·222c·2022·4365·6e74···"RedHat",·"Cent0003c150:·2022·5265·6448·6174·222c·2022·4365·6e74···"RedHat",·"Cent
0003c470:·4f53·222c·2022·4f72·6163·6c65·4c69·6e75··OS",·"OracleLinu0003c160:·4f53·222c·2022·4f72·6163·6c65·4c69·6e75··OS",·"OracleLinu
0003c480:·7822·205d·0a20·2074·6167·733a·0a20·202d··x"·].··tags:.··-0003c170:·7822·205d·0a20·2074·6167·733a·0a20·202d··x"·].··tags:.··-
0003c490:·2043·4345·2d38·3038·3537·2d36·0a20·202d···CCE-80857-6.··-0003c180:·2043·4345·2d38·3038·3537·2d36·0a20·202d···CCE-80857-6.··-
0003c4a0:·2043·4a49·532d·352e·3130·2e34·2e31·0a20···CJIS-5.10.4.1.·0003c190:·2043·4a49·532d·352e·3130·2e34·2e31·0a20···CJIS-5.10.4.1.·
0003c4b0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-0003c1a0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
0003c4c0:·332e·332e·380a·2020·2d20·4e49·5354·2d38··3.3.8.··-·NIST-80003c1b0:·332e·332e·380a·2020·2d20·4e49·5354·2d38··3.3.8.··-·NIST-8
0003c4d0:·3030·2d31·3731·2d33·2e34·2e31·0a20·202d··00-171-3.4.1.··-0003c1c0:·3030·2d31·3731·2d33·2e34·2e31·0a20·202d··00-171-3.4.1.··-
0003c4e0:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-0003c1d0:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-
0003c4f0:·3928·3329·0a20·202d·204e·4953·542d·3830··9(3).··-·NIST-800003c1e0:·3928·3329·0a20·202d·204e·4953·542d·3830··9(3).··-·NIST-80
0003c500:·302d·3533·2d43·4d2d·3628·6329·0a20·202d··0-53-CM-6(c).··-0003c1f0:·302d·3533·2d43·4d2d·3628·6329·0a20·202d··0-53-CM-6(c).··-
0003c510:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-0003c200:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-
0003c520:·3628·6429·0a20·202d·204e·4953·542d·3830··6(d).··-·NIST-800003c210:·3628·6429·0a20·202d·204e·4953·542d·3830··6(d).··-·NIST-80
0003c530:·302d·3533·2d53·492d·370a·2020·2d20·4e49··0-53-SI-7.··-·NI0003c220:·302d·3533·2d53·492d·370a·2020·2d20·4e49··0-53-SI-7.··-·NI
0003c540:·5354·2d38·3030·2d35·332d·5349·2d37·2831··ST-800-53-SI-7(10003c230:·5354·2d38·3030·2d35·332d·5349·2d37·2831··ST-800-53-SI-7(1
0003c550:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5 
0003c560:·332d·5349·2d37·2836·290a·2020·2d20·5043··3-SI-7(6).··-·PC 
0003c570:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.· 
0003c580:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11. 
0003c590:·352e·320a·2020·2d20·6869·6768·5f63·6f6d··5.2.··-·high_com 
0003c5a0:·706c·6578·6974·790a·2020·2d20·6869·6768··plexity.··-·high 
0003c5b0:·5f73·6576·6572·6974·790a·2020·2d20·6d65··_severity.··-·me 
0003c5c0:·6469·756d·5f64·6973·7275·7074·696f·6e0a··dium_disruption. 
Max diff block lines reached; 17320735/17362879 bytes (99.76%) of diff not shown.
1.26 MB
html2text {}
    
Offset 57, 15 lines modifiedOffset 57, 15 lines modified
57 ····*·cpe:/o:redhat:enterprise_linux:8.657 ····*·cpe:/o:redhat:enterprise_linux:8.6
58 ····*·cpe:/o:redhat:enterprise_linux:8.758 ····*·cpe:/o:redhat:enterprise_linux:8.7
59 ····*·cpe:/o:redhat:enterprise_linux:8.859 ····*·cpe:/o:redhat:enterprise_linux:8.8
60 ····*·cpe:/o:redhat:enterprise_linux:8.960 ····*·cpe:/o:redhat:enterprise_linux:8.9
61 ····*·cpe:/o:redhat:enterprise_linux:861 ····*·cpe:/o:redhat:enterprise_linux:8
62 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*62 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
63 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8463 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
64 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)64 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
65 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*65 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
66 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s66 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
67 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e67 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
68 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l68 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
69 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n69 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
70 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g70 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
71 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s71 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 121, 27 lines modifiedOffset 121, 14 lines modified
121 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6121 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
122 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4122 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
123 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)123 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
124 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1124 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
125 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5125 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
126 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227126 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
129 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
130 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
131 if·[·-n·"$files_with_incorrect_hash"·];·then 
132 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
133 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
134 ····yum·reinstall·-y·$packages_to_reinstall 
  
135 fi 
136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
141 -·name:·'Set·fact:·Package·manager·reinstall·command'133 -·name:·'Set·fact:·Package·manager·reinstall·command'
142 ··set_fact:134 ··set_fact:
Offset 273, 14 lines modifiedOffset 260, 27 lines modified
273 ··-·PCI-DSSv4-11.5.2260 ··-·PCI-DSSv4-11.5.2
274 ··-·high_complexity261 ··-·high_complexity
275 ··-·high_severity262 ··-·high_severity
276 ··-·medium_disruption263 ··-·medium_disruption
277 ··-·no_reboot_needed264 ··-·no_reboot_needed
278 ··-·restrict_strategy265 ··-·restrict_strategy
279 ··-·rpm_verify_hashes266 ··-·rpm_verify_hashes
 267 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 268 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 269 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 270 if·[·-n·"$files_with_incorrect_hash"·];·then
 271 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 272 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 273 ····yum·reinstall·-y·$packages_to_reinstall
  
 274 fi
280 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*275 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
281 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:276 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:
282 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'277 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'
283 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:278 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:
284 $·rpm·-qf·FILENAME279 $·rpm·-qf·FILENAME
  
285 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:280 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
Offset 302, 44 lines modifiedOffset 302, 14 lines modified
302 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5302 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
303 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2303 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
304 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)304 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)
305 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1305 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
306 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5306 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
307 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108307 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108
308 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2308 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
309 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
310 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
311 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
312 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
313 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
314 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
315 declare·-A·SETPERMS_RPM_DICT 
  
316 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
317 #·is·expected·by·the·RPM·database 
318 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}') 
  
319 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
320 do 
321 ········#·NOTE:·some·files·maybe·controlled·by·more·then·one·package 
322 ········readarray·-t·RPM_PACKAGES·<·<(rpm·-qf·"${FILE_PATH}") 
323 ········for·RPM_PACKAGE·in·"${RPM_PACKAGES[@]}" 
324 ········do 
325 ················#·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
326 ················SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
327 ········done 
328 done 
  
329 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
330 #·correct·values 
331 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
332 do 
333 »       rpm·--restore·"${RPM_PACKAGE}" 
334 done 
335 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8309 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
336 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high310 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
337 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium311 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
338 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false312 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
339 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict313 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
340 -·name:·Read·list·of·files·with·incorrect·permissions314 -·name:·Read·list·of·files·with·incorrect·permissions
341 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev315 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 420, 14 lines modifiedOffset 390, 44 lines modified
420 ··-·PCI-DSSv4-11.5.2390 ··-·PCI-DSSv4-11.5.2
421 ··-·high_complexity391 ··-·high_complexity
422 ··-·high_severity392 ··-·high_severity
423 ··-·medium_disruption393 ··-·medium_disruption
424 ··-·no_reboot_needed394 ··-·no_reboot_needed
425 ··-·restrict_strategy395 ··-·restrict_strategy
426 ··-·rpm_verify_permissions396 ··-·rpm_verify_permissions
 397 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 398 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 399 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
Max diff block lines reached; 1309538/1317680 bytes (99.38%) of diff not shown.
10.7 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-ism_o.html
    
Offset 14448, 16 lines modifiedOffset 14448, 16 lines modified
000386f0:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>000386f0:·696f·6e20·4869·7374·6f72·793c·2f68·323e··ion·History</h2>
00038700:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi00038700:·3c70·3e43·7572·7265·6e74·2076·6572·7369··<p>Current·versi
00038710:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.00038710:·6f6e·3a20·3c73·7472·6f6e·673e·302e·312e··on:·<strong>0.1.
00038720:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><00038720:·3734·3c2f·7374·726f·6e67·3e3c·2f70·3e3c··74</strong></p><
00038730:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d00038730:·756c·3e3c·6c69·3e3c·7374·726f·6e67·3e64··ul><li><strong>d
00038740:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··00038740:·7261·6674·3c2f·7374·726f·6e67·3e0a·2020··raft</strong>.··
00038750:·2020·2020·2020·2020·2020·2020·2020·2020··················00038750:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038760:·2020·2861·7320·6f66·2032·3032·362d·3031····(as·of·2026-0100038760:·2020·2861·7320·6f66·2032·3032·342d·3132····(as·of·2024-12
00038770:·2d30·3829·0a20·2020·2020·2020·2020·2020··-08).···········00038770:·2d30·3729·0a20·2020·2020·2020·2020·2020··-07).···········
00038780:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><00038780:·2020·2020·203c·2f6c·693e·3c2f·756c·3e3c·······</li></ul><
00038790:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o00038790:·2f64·6976·3e3c·6832·3e54·6162·6c65·206f··/div><h2>Table·o
000387a0:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><000387a0:·6620·436f·6e74·656e·7473·3c2f·6832·3e3c··f·Contents</h2><
000387b0:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="000387b0:·6f6c·3e3c·6c69·3e3c·6120·6872·6566·3d22··ol><li><a·href="
000387c0:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr000387c0:·2378·6363·6466·5f6f·7267·2e73·7367·7072··#xccdf_org.ssgpr
000387d0:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr000387d0:·6f6a·6563·742e·636f·6e74·656e·745f·6772··oject.content_gr
000387e0:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst000387e0:·6f75·705f·7379·7374·656d·223e·5379·7374··oup_system">Syst
Offset 15352, 306 lines modifiedOffset 15352, 306 lines modified
0003bf70:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm70003bf70:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7
0003bf80:·3633·3622·2074·6162·696e·6465·783d·2230··636"·tabindex="00003bf80:·3633·3622·2074·6162·696e·6465·783d·2230··636"·tabindex="0
0003bf90:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003bf90:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003bfa0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003bfa0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003bfb0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003bfb0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003bfc0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003bfc0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003bfd0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003bfd0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003bfe0:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
0003bff0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003c000:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003c010:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003c020:·7365·2220·6964·3d22·6964·6d37·3633·3622··se"·id="idm7636" 
0003c030:·3e3c·7072·653e·3c63·6f64·653e·0a23·2046··><pre><code>.#·F 
0003c040:·696e·6420·7768·6963·6820·6669·6c65·7320··ind·which·files· 
0003c050:·6861·7665·2069·6e63·6f72·7265·6374·2068··have·incorrect·h 
0003c060:·6173·6820·286e·6f74·2069·6e20·2f65·7463··ash·(not·in·/etc 
0003c070:·2c20·6265·6361·7573·6520·6f66·2074·6865··,·because·of·the 
0003c080:·2073·7973·7465·6d20·7265·6c61·7465·6420···system·related· 
0003c090:·636f·6e66·6967·2066·696c·6573·2920·616e··config·files)·an 
0003c0a0:·6420·7468·656e·2067·6574·2066·696c·6573··d·then·get·files 
0003c0b0:·206e·616d·6573·0a66·696c·6573·5f77·6974···names.files_wit 
0003c0c0:·685f·696e·636f·7272·6563·745f·6861·7368··h_incorrect_hash 
0003c0d0:·3d22·2428·7270·6d20·2d56·6120·2d2d·6e6f··="$(rpm·-Va·--no 
0003c0e0:·636f·6e66·6967·207c·2067·7265·7020·2d45··config·|·grep·-E 
0003c0f0:·2027·5e2e·2e35·2720·7c20·6177·6b20·277b···'^..5'·|·awk·'{ 
0003c100:·7072·696e·7420·244e·467d·2720·2922·0a0a··print·$NF}'·)".. 
0003c110:·6966·205b·202d·6e20·2224·6669·6c65·735f··if·[·-n·"$files_ 
0003c120:·7769·7468·5f69·6e63·6f72·7265·6374·5f68··with_incorrect_h 
0003c130:·6173·6822·205d·3b20·7468·656e·0a20·2020··ash"·];·then.··· 
0003c140:·2023·2046·726f·6d20·6669·6c65·7320·6e61···#·From·files·na 
0003c150:·6d65·7320·6765·7420·7061·636b·6167·6520··mes·get·package· 
0003c160:·6e61·6d65·7320·616e·6420·6368·616e·6765··names·and·change 
0003c170:·206e·6577·6c69·6e65·2074·6f20·7370·6163···newline·to·spac 
0003c180:·652c·2062·6563·6175·7365·2072·706d·2077··e,·because·rpm·w 
0003c190:·7269·7465·7320·6561·6368·2070·6163·6b61··rites·each·packa 
0003c1a0:·6765·2074·6f20·6e65·7720·6c69·6e65·0a20··ge·to·new·line.· 
0003c1b0:·2020·2070·6163·6b61·6765·735f·746f·5f72·····packages_to_r 
0003c1c0:·6569·6e73·7461·6c6c·3d22·2428·7270·6d20··einstall="$(rpm· 
0003c1d0:·2d71·6620·2466·696c·6573·5f77·6974·685f··-qf·$files_with_ 
0003c1e0:·696e·636f·7272·6563·745f·6861·7368·207c··incorrect_hash·| 
0003c1f0:·2074·7220·275c·6e27·2027·2027·2922·0a0a···tr·'\n'·'·')".. 
0003c200:·2020·2020·0a20·2020·2079·756d·2072·6569······.····yum·rei 
0003c210:·6e73·7461·6c6c·202d·7920·2470·6163·6b61··nstall·-y·$packa 
0003c220:·6765·735f·746f·5f72·6569·6e73·7461·6c6c··ges_to_reinstall 
0003c230:·0a20·2020·200a·6669·0a3c·2f63·6f64·653e··.····.fi.</code> 
0003c240:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003c250:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003c260:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003c270:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003c280:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7 
0003c290:·3633·3722·2074·6162·696e·6465·783d·2230··637"·tabindex="0 
0003c2a0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003c2b0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003c2c0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003c2d0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003c2e0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003c2f0:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s0003bfe0:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s
0003c300:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003bff0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003c310:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003c000:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003c320:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003c010:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003c330:·6c61·7073·6522·2069·643d·2269·646d·3736··lapse"·id="idm760003c020:·6c61·7073·6522·2069·643d·2269·646d·3736··lapse"·id="idm76
0003c340:·3337·223e·3c74·6162·6c65·2063·6c61·7373··37"><table·class0003c030:·3336·223e·3c74·6162·6c65·2063·6c61·7373··36"><table·class
0003c350:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003c040:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003c360:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003c050:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003c370:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003c060:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003c380:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003c070:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003c390:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003c080:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003c3a0:·643e·6869·6768·3c2f·7464·3e3c·2f74·723e··d>high</td></tr>0003c090:·643e·6869·6768·3c2f·7464·3e3c·2f74·723e··d>high</td></tr>
0003c3b0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003c0a0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003c3c0:·6f6e·3a3c·2f74·683e·3c74·643e·6d65·6469··on:</th><td>medi0003c0b0:·6f6e·3a3c·2f74·683e·3c74·643e·6d65·6469··on:</th><td>medi
0003c3d0:·756d·3c2f·7464·3e3c·2f74·723e·3c74·723e··um</td></tr><tr>0003c0c0:·756d·3c2f·7464·3e3c·2f74·723e·3c74·723e··um</td></tr><tr>
0003c3e0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>0003c0d0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
0003c3f0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></0003c0e0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
0003c400:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0003c0f0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
0003c410:·6567·793a·3c2f·7468·3e3c·7464·3e72·6573··egy:</th><td>res0003c100:·6567·793a·3c2f·7468·3e3c·7464·3e72·6573··egy:</th><td>res
0003c420:·7472·6963·743c·2f74·643e·3c2f·7472·3e3c··trict</td></tr><0003c110:·7472·6963·743c·2f74·643e·3c2f·7472·3e3c··trict</td></tr><
0003c430:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod0003c120:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
0003c440:·653e·2d20·6e61·6d65·3a20·2753·6574·2066··e>-·name:·'Set·f0003c130:·653e·2d20·6e61·6d65·3a20·2753·6574·2066··e>-·name:·'Set·f
0003c450:·6163·743a·2050·6163·6b61·6765·206d·616e··act:·Package·man0003c140:·6163·743a·2050·6163·6b61·6765·206d·616e··act:·Package·man
0003c460:·6167·6572·2072·6569·6e73·7461·6c6c·2063··ager·reinstall·c0003c150:·6167·6572·2072·6569·6e73·7461·6c6c·2063··ager·reinstall·c
0003c470:·6f6d·6d61·6e64·270a·2020·7365·745f·6661··ommand'.··set_fa0003c160:·6f6d·6d61·6e64·270a·2020·7365·745f·6661··ommand'.··set_fa
0003c480:·6374·3a0a·2020·2020·7061·636b·6167·655f··ct:.····package_0003c170:·6374·3a0a·2020·2020·7061·636b·6167·655f··ct:.····package_
0003c490:·6d61·6e61·6765·725f·7265·696e·7374·616c··manager_reinstal0003c180:·6d61·6e61·6765·725f·7265·696e·7374·616c··manager_reinstal
0003c4a0:·6c5f·636d·643a·2079·756d·2072·6569·6e73··l_cmd:·yum·reins0003c190:·6c5f·636d·643a·2079·756d·2072·6569·6e73··l_cmd:·yum·reins
0003c4b0:·7461·6c6c·202d·790a·2020·7768·656e·3a20··tall·-y.··when:·0003c1a0:·7461·6c6c·202d·790a·2020·7768·656e·3a20··tall·-y.··when:·
0003c4c0:·616e·7369·626c·655f·6469·7374·7269·6275··ansible_distribu0003c1b0:·616e·7369·626c·655f·6469·7374·7269·6275··ansible_distribu
0003c4d0:·7469·6f6e·2069·6e20·5b20·2246·6564·6f72··tion·in·[·"Fedor0003c1c0:·7469·6f6e·2069·6e20·5b20·2246·6564·6f72··tion·in·[·"Fedor
0003c4e0:·6122·2c20·2252·6564·4861·7422·2c20·2243··a",·"RedHat",·"C0003c1d0:·6122·2c20·2252·6564·4861·7422·2c20·2243··a",·"RedHat",·"C
0003c4f0:·656e·744f·5322·2c20·224f·7261·636c·654c··entOS",·"OracleL0003c1e0:·656e·744f·5322·2c20·224f·7261·636c·654c··entOS",·"OracleL
0003c500:·696e·7578·2220·5d0a·2020·7461·6773·3a0a··inux"·].··tags:.0003c1f0:·696e·7578·2220·5d0a·2020·7461·6773·3a0a··inux"·].··tags:.
0003c510:·2020·2d20·4343·452d·3830·3835·372d·360a····-·CCE-80857-6.0003c200:·2020·2d20·4343·452d·3830·3835·372d·360a····-·CCE-80857-6.
0003c520:·2020·2d20·434a·4953·2d35·2e31·302e·342e····-·CJIS-5.10.4.0003c210:·2020·2d20·434a·4953·2d35·2e31·302e·342e····-·CJIS-5.10.4.
0003c530:·310a·2020·2d20·4e49·5354·2d38·3030·2d31··1.··-·NIST-800-10003c220:·310a·2020·2d20·4e49·5354·2d38·3030·2d31··1.··-·NIST-800-1
0003c540:·3731·2d33·2e33·2e38·0a20·202d·204e·4953··71-3.3.8.··-·NIS0003c230:·3731·2d33·2e33·2e38·0a20·202d·204e·4953··71-3.3.8.··-·NIS
0003c550:·542d·3830·302d·3137·312d·332e·342e·310a··T-800-171-3.4.1.0003c240:·542d·3830·302d·3137·312d·332e·342e·310a··T-800-171-3.4.1.
0003c560:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-0003c250:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
0003c570:·4155·2d39·2833·290a·2020·2d20·4e49·5354··AU-9(3).··-·NIST0003c260:·4155·2d39·2833·290a·2020·2d20·4e49·5354··AU-9(3).··-·NIST
0003c580:·2d38·3030·2d35·332d·434d·2d36·2863·290a··-800-53-CM-6(c).0003c270:·2d38·3030·2d35·332d·434d·2d36·2863·290a··-800-53-CM-6(c).
0003c590:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-0003c280:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
0003c5a0:·434d·2d36·2864·290a·2020·2d20·4e49·5354··CM-6(d).··-·NIST0003c290:·434d·2d36·2864·290a·2020·2d20·4e49·5354··CM-6(d).··-·NIST
0003c5b0:·2d38·3030·2d35·332d·5349·2d37·0a20·202d··-800-53-SI-7.··-0003c2a0:·2d38·3030·2d35·332d·5349·2d37·0a20·202d··-800-53-SI-7.··-
0003c5c0:·204e·4953·542d·3830·302d·3533·2d53·492d···NIST-800-53-SI-0003c2b0:·204e·4953·542d·3830·302d·3533·2d53·492d···NIST-800-53-SI-
0003c5d0:·3728·3129·0a20·202d·204e·4953·542d·3830··7(1).··-·NIST-800003c2c0:·3728·3129·0a20·202d·204e·4953·542d·3830··7(1).··-·NIST-80
0003c5e0:·302d·3533·2d53·492d·3728·3629·0a20·202d··0-53-SI-7(6).··-0003c2d0:·302d·3533·2d53·492d·3728·3629·0a20·202d··0-53-SI-7(6).··-
0003c5f0:·2050·4349·2d44·5353·2d52·6571·2d31·312e···PCI-DSS-Req-11.0003c2e0:·2050·4349·2d44·5353·2d52·6571·2d31·312e···PCI-DSS-Req-11.
0003c600:·350a·2020·2d20·5043·492d·4453·5376·342d··5.··-·PCI-DSSv4-0003c2f0:·350a·2020·2d20·5043·492d·4453·5376·342d··5.··-·PCI-DSSv4-
0003c610:·3131·2e35·2e32·0a20·202d·2068·6967·685f··11.5.2.··-·high_0003c300:·3131·2e35·2e32·0a20·202d·2068·6967·685f··11.5.2.··-·high_
0003c620:·636f·6d70·6c65·7869·7479·0a20·202d·2068··complexity.··-·h0003c310:·636f·6d70·6c65·7869·7479·0a20·202d·2068··complexity.··-·h
0003c630:·6967·685f·7365·7665·7269·7479·0a20·202d··igh_severity.··-0003c320:·6967·685f·7365·7665·7269·7479·0a20·202d··igh_severity.··-
0003c640:·206d·6564·6975·6d5f·6469·7372·7570·7469···medium_disrupti0003c330:·206d·6564·6975·6d5f·6469·7372·7570·7469···medium_disrupti
Max diff block lines reached; 10065788/10107932 bytes (99.58%) of diff not shown.
1.02 MB
html2text {}
    
Offset 55, 15 lines modifiedOffset 55, 15 lines modified
55 ····*·cpe:/o:redhat:enterprise_linux:8.655 ····*·cpe:/o:redhat:enterprise_linux:8.6
56 ····*·cpe:/o:redhat:enterprise_linux:8.756 ····*·cpe:/o:redhat:enterprise_linux:8.7
57 ····*·cpe:/o:redhat:enterprise_linux:8.857 ····*·cpe:/o:redhat:enterprise_linux:8.8
58 ····*·cpe:/o:redhat:enterprise_linux:8.958 ····*·cpe:/o:redhat:enterprise_linux:8.9
59 ····*·cpe:/o:redhat:enterprise_linux:859 ····*·cpe:/o:redhat:enterprise_linux:8
60 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*60 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
61 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8461 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
62 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)62 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
63 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*63 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
64 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s64 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
65 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e65 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
66 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l66 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
67 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g67 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
68 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s68 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
69 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s69 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 122, 27 lines modifiedOffset 122, 14 lines modified
122 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6122 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
123 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4123 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
124 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)124 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
125 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1125 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
126 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5126 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
127 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227127 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
128 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2128 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
130 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
131 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
132 if·[·-n·"$files_with_incorrect_hash"·];·then 
133 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
134 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
135 ····yum·reinstall·-y·$packages_to_reinstall 
  
136 fi 
137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
142 -·name:·'Set·fact:·Package·manager·reinstall·command'134 -·name:·'Set·fact:·Package·manager·reinstall·command'
143 ··set_fact:135 ··set_fact:
Offset 274, 14 lines modifiedOffset 261, 27 lines modified
274 ··-·PCI-DSSv4-11.5.2261 ··-·PCI-DSSv4-11.5.2
275 ··-·high_complexity262 ··-·high_complexity
276 ··-·high_severity263 ··-·high_severity
277 ··-·medium_disruption264 ··-·medium_disruption
278 ··-·no_reboot_needed265 ··-·no_reboot_needed
279 ··-·restrict_strategy266 ··-·restrict_strategy
280 ··-·rpm_verify_hashes267 ··-·rpm_verify_hashes
 268 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 269 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 270 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 271 if·[·-n·"$files_with_incorrect_hash"·];·then
 272 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 273 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 274 ····yum·reinstall·-y·$packages_to_reinstall
  
 275 fi
281 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*276 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
282 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:277 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
283 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'278 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
284 run·the·following·command·to·determine·which·package·owns·it:279 run·the·following·command·to·determine·which·package·owns·it:
285 $·rpm·-qf·FILENAME280 $·rpm·-qf·FILENAME
286 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:281 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
287 $·sudo·rpm·--setugids·PACKAGENAME282 $·sudo·rpm·--setugids·PACKAGENAME
Offset 301, 40 lines modifiedOffset 301, 14 lines modified
301 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5301 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
302 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2302 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
303 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)303 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
304 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1304 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
305 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5305 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
306 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108306 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
307 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2307 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
308 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
309 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
310 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
311 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
312 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
313 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
314 declare·-A·SETPERMS_RPM_DICT 
  
315 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
316 #·is·expected·by·the·RPM·database 
317 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
318 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
319 do 
320 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
321 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
322 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
323 done 
  
324 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
325 #·correct·values 
326 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
327 do 
328 ········rpm·--setugids·"${RPM_PACKAGE}" 
329 done 
330 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8308 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
331 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high309 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
332 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium310 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
333 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false311 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
334 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict312 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
335 -·name:·Read·list·of·files·with·incorrect·ownership313 -·name:·Read·list·of·files·with·incorrect·ownership
336 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev314 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 412, 14 lines modifiedOffset 386, 40 lines modified
412 ··-·PCI-DSSv4-11.5.2386 ··-·PCI-DSSv4-11.5.2
413 ··-·high_complexity387 ··-·high_complexity
414 ··-·high_severity388 ··-·high_severity
415 ··-·medium_disruption389 ··-·medium_disruption
416 ··-·no_reboot_needed390 ··-·no_reboot_needed
417 ··-·restrict_strategy391 ··-·restrict_strategy
418 ··-·rpm_verify_ownership392 ··-·rpm_verify_ownership
 393 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 394 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 395 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 396 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 397 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 398 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 1061153/1068911 bytes (99.27%) of diff not shown.
10.1 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-ospp.html
    
Offset 14442, 15 lines modifiedOffset 14442, 15 lines modified
00038690:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00038690:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
000386a0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:000386a0:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
000386b0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<000386b0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<
000386c0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>000386c0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
000386d0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf000386d0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
000386e0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····000386e0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
000386f0:·2020·2020·2020·2020·2020·2020·2020·2028·················(000386f0:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00038700:·6173·206f·6620·3230·3236·2d30·312d·3038··as·of·2026-01-0800038700:·6173·206f·6620·3230·3234·2d31·322d·3037··as·of·2024-12-07
00038710:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00038710:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00038720:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00038720:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00038730:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00038730:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00038740:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00038740:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00038750:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00038750:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00038760:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00038760:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00038770:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00038770:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
Offset 15257, 237 lines modifiedOffset 15257, 237 lines modified
0003b980:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003b980:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003b990:·6d37·3938·3022·2074·6162·696e·6465·783d··m7980"·tabindex=0003b990:·6d37·3938·3022·2074·6162·696e·6465·783d··m7980"·tabindex=
0003b9a0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003b9a0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003b9b0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003b9b0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003b9c0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003b9c0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003b9d0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003b9d0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003b9e0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003b9e0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003b9f0:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·0003b9f0:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond
0003ba00:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003ba00:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a
0003ba10:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003ba10:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003ba20:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003ba20:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003ba30:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm70003ba30:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003ba40:·3938·3022·3e3c·7461·626c·6520·636c·6173··980"><table·clas0003ba40:·6d37·3938·3022·3e3c·7461·626c·6520·636c··m7980"><table·cl
0003ba50:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003ba50:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003ba60:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003ba60:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003ba70:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003ba70:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003ba80:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003ba80:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003ba90:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003ba90:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003baa0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003baa0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003bab0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003bab0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003bac0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003bac0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0003bad0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003bad0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003bae0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003bae0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
0003baf0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003baf0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
0003bb00:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003bb00:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003bb10:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003bb10:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003bb20:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003bb20:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003bb30:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc0003bb30:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.
 0003bb40:·7061·636b·6167·6520·2d2d·6164·643d·6169··package·--add=ai
 0003bb50:·6465·0a3c·2f63·6f64·653e·3c2f·7072·653e··de.</code></pre>
 0003bb60:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0003bb70:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0003bb80:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0003bb90:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 0003bba0:·6765·743d·2223·6964·6d37·3938·3122·2074··get="#idm7981"·t
 0003bbb0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 0003bbc0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 0003bbd0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 0003bbe0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 0003bbf0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 0003bc00:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003bc10:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·
 0003bc20:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003bc30:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003bc40:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003bc50:·6964·3d22·6964·6d37·3938·3122·3e3c·7461··id="idm7981"><ta
 0003bc60:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0003bc70:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0003bc80:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0003bc90:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0003bca0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0003bcb0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0003bcc0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003bcd0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
0003bb40:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid 
0003bb50:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install 
0003bb60:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag 
0003bb70:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.···· 
0003bb80:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in 
0003bb90:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}. 
0003bba0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003bbb0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003bbc0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003bbd0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003bbe0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003bbf0:·3d22·2369·646d·3739·3831·2220·7461·6269··="#idm7981"·tabi 
0003bc00:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003bc10:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003bc20:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003bc30:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003bc40:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003bc50:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
0003bc60:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</ 
0003bc70:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003bc80:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003bc90:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003bca0:·646d·3739·3831·223e·3c74·6162·6c65·2063··dm7981"><table·c 
0003bcb0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003bcc0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003bcd0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003bce0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003bcf0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003bd00:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003bce0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003bd10:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003bd20:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l0003bcf0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 0003bd00:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
0003bd30:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003bd10:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003bd20:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0003bd30:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0003bd40:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003bd50:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins
 0003bd60:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class
 0003bd70:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{.
 0003bd80:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid
 0003bd90:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·=
 0003bda0:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed'
 0003bdb0:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code><
0003bd40:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003bd50:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0003bd60:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003bd70:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003bd80:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003bd90:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003bda0:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is 
0003bdb0:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only 
0003bdc0:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat 
0003bdd0:·666f·726d·730a·6966·205b·2021·202d·6620··forms.if·[·!·-f· 
0003bde0:·2f2e·646f·636b·6572·656e·7620·5d20·2661··/.dockerenv·]·&a 
0003bdf0:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f· 
0003be00:·2f72·756e·2f2e·636f·6e74·6169·6e65·7265··/run/.containere 
0003be10:·6e76·205d·3b20·7468·656e·0a0a·6966·2021··nv·];·then..if·! 
Max diff block lines reached; 9230597/9263081 bytes (99.65%) of diff not shown.
1.23 MB
html2text {}
    
Offset 53, 15 lines modifiedOffset 53, 15 lines modified
53 ····*·cpe:/o:redhat:enterprise_linux:8.653 ····*·cpe:/o:redhat:enterprise_linux:8.6
54 ····*·cpe:/o:redhat:enterprise_linux:8.754 ····*·cpe:/o:redhat:enterprise_linux:8.7
55 ····*·cpe:/o:redhat:enterprise_linux:8.855 ····*·cpe:/o:redhat:enterprise_linux:8.8
56 ····*·cpe:/o:redhat:enterprise_linux:8.956 ····*·cpe:/o:redhat:enterprise_linux:8.9
57 ····*·cpe:/o:redhat:enterprise_linux:857 ····*·cpe:/o:redhat:enterprise_linux:8
58 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*58 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
59 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8459 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
60 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)60 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
61 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*61 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
62 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s62 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
63 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e63 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
64 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l64 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
65 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n65 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
66 ·········4.·_\x8z_\x8I_\x8P_\x8L_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n66 ·········4.·_\x8z_\x8I_\x8P_\x8L_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
67 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g67 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 114, 41 lines modifiedOffset 114, 45 lines modified
114 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5114 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
115 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199115 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
116 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359116 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359
117 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79117 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
118 ·············_\x8c_\x8i_\x8s············5.3.1118 ·············_\x8c_\x8i_\x8s············5.3.1
119 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2119 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
120 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule120 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r880730_rule
 121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 122 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 123 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 124 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 125 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 126 package·--add=aide
121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
122 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
123 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
124 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
125 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
126 include·install_aide132 include·install_aide
  
127 class·install_aide·{133 class·install_aide·{
128 ··package·{·'aide':134 ··package·{·'aide':
129 ····ensure·=>·'installed',135 ····ensure·=>·'installed',
130 ··}136 ··}
131 }137 }
 138 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 139 [[packages]]
 140 name·=·"aide"
 141 version·=·"*"
132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
137 #·Remediation·is·applicable·only·in·certain·platforms 
138 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
 147 package·install·aide
139 if·!·rpm·-q·--quiet·"aide"·;·then 
140 ····yum·install·-y·"aide" 
141 fi 
  
142 else 
143 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
144 fi 
145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low149 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low150 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false151 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable152 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
150 -·name:·Ensure·aide·is·installed153 -·name:·Ensure·aide·is·installed
151 ··package:154 ··package:
Offset 164, 33 lines modifiedOffset 168, 29 lines modified
164 ··-·PCI-DSSv4-11.5.2168 ··-·PCI-DSSv4-11.5.2
165 ··-·enable_strategy169 ··-·enable_strategy
166 ··-·low_complexity170 ··-·low_complexity
167 ··-·low_disruption171 ··-·low_disruption
168 ··-·medium_severity172 ··-·medium_severity
169 ··-·no_reboot_needed173 ··-·no_reboot_needed
170 ··-·package_aide_installed174 ··-·package_aide_installed
171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
172 [[packages]] 
173 name·=·"aide" 
174 version·=·"*" 
175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
176 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low176 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
177 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low177 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
178 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false178 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
179 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable179 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 180 #·Remediation·is·applicable·only·in·certain·platforms
 181 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 182 if·!·rpm·-q·--quiet·"aide"·;·then
 183 ····yum·install·-y·"aide"
 184 fi
180 package·install·aide 
181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
186 package·--add=aide185 else
 186 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 187 fi
187 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules188 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
188 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.189 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
189 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.190 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.
  
190 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.191 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
191 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*192 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 207, 27 lines modifiedOffset 207, 14 lines modified
207 ·············_\x8i_\x8s_\x8m······1446207 ·············_\x8i_\x8s_\x8m······1446
208 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1208 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
209 References:··_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12209 References:··_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
210 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.1210 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.1
211 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223211 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223
212 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-08-010020212 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-08-010020
213 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r928585_rule213 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r928585_rule
214 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
215 #·Remediation·is·applicable·only·in·certain·platforms 
216 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·);·then 
  
217 fips-mode-setup·--enable 
218 FIPS_CONF="/etc/dracut.conf.d/40-fips.conf" 
219 if·!·grep·"^add_dracutmodules+=\"·fips·\""·$FIPS_CONF;·then 
220 ····echo·"add_dracutmodules+=\"·fips·\""·>>·$FIPS_CONF 
Max diff block lines reached; 1282276/1288721 bytes (99.50%) of diff not shown.
18.1 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-pci-dss.html
    
Offset 14437, 15 lines modifiedOffset 14437, 15 lines modified
00038640:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current00038640:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current
00038650:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron00038650:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron
00038660:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong00038660:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong
00038670:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st00038670:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st
00038680:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro00038680:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro
00038690:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············00038690:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············
000386a0:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·2000386a0:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·2
000386b0:·3032·362d·3031·2d30·3829·0a20·2020·2020··026-01-08).·····000386b0:·3032·342d·3132·2d30·3729·0a20·2020·2020··024-12-07).·····
000386c0:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>000386c0:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>
000386d0:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T000386d0:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T
000386e0:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents000386e0:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents
000386f0:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·000386f0:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·
00038700:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org00038700:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org
00038710:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont00038710:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont
00038720:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system00038720:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system
Offset 15344, 306 lines modifiedOffset 15344, 306 lines modified
0003bef0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003bef0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003bf00:·6964·6d37·3633·3622·2074·6162·696e·6465··idm7636"·tabinde0003bf00:·6964·6d37·3633·3622·2074·6162·696e·6465··idm7636"·tabinde
0003bf10:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003bf10:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003bf20:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003bf20:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003bf30:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003bf30:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003bf40:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003bf40:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003bf50:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003bf50:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003bf60:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003bf70:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003bf80:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003bf90:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003bfa0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7 
0003bfb0:·3633·3622·3e3c·7072·653e·3c63·6f64·653e··636"><pre><code> 
0003bfc0:·0a23·2046·696e·6420·7768·6963·6820·6669··.#·Find·which·fi 
0003bfd0:·6c65·7320·6861·7665·2069·6e63·6f72·7265··les·have·incorre 
0003bfe0:·6374·2068·6173·6820·286e·6f74·2069·6e20··ct·hash·(not·in· 
0003bff0:·2f65·7463·2c20·6265·6361·7573·6520·6f66··/etc,·because·of 
0003c000:·2074·6865·2073·7973·7465·6d20·7265·6c61···the·system·rela 
0003c010:·7465·6420·636f·6e66·6967·2066·696c·6573··ted·config·files 
0003c020:·2920·616e·6420·7468·656e·2067·6574·2066··)·and·then·get·f 
0003c030:·696c·6573·206e·616d·6573·0a66·696c·6573··iles·names.files 
0003c040:·5f77·6974·685f·696e·636f·7272·6563·745f··_with_incorrect_ 
0003c050:·6861·7368·3d22·2428·7270·6d20·2d56·6120··hash="$(rpm·-Va· 
0003c060:·2d2d·6e6f·636f·6e66·6967·207c·2067·7265··--noconfig·|·gre 
0003c070:·7020·2d45·2027·5e2e·2e35·2720·7c20·6177··p·-E·'^..5'·|·aw 
0003c080:·6b20·277b·7072·696e·7420·244e·467d·2720··k·'{print·$NF}'· 
0003c090:·2922·0a0a·6966·205b·202d·6e20·2224·6669··)"..if·[·-n·"$fi 
0003c0a0:·6c65·735f·7769·7468·5f69·6e63·6f72·7265··les_with_incorre 
0003c0b0:·6374·5f68·6173·6822·205d·3b20·7468·656e··ct_hash"·];·then 
0003c0c0:·0a20·2020·2023·2046·726f·6d20·6669·6c65··.····#·From·file 
0003c0d0:·7320·6e61·6d65·7320·6765·7420·7061·636b··s·names·get·pack 
0003c0e0:·6167·6520·6e61·6d65·7320·616e·6420·6368··age·names·and·ch 
0003c0f0:·616e·6765·206e·6577·6c69·6e65·2074·6f20··ange·newline·to· 
0003c100:·7370·6163·652c·2062·6563·6175·7365·2072··space,·because·r 
0003c110:·706d·2077·7269·7465·7320·6561·6368·2070··pm·writes·each·p 
0003c120:·6163·6b61·6765·2074·6f20·6e65·7720·6c69··ackage·to·new·li 
0003c130:·6e65·0a20·2020·2070·6163·6b61·6765·735f··ne.····packages_ 
0003c140:·746f·5f72·6569·6e73·7461·6c6c·3d22·2428··to_reinstall="$( 
0003c150:·7270·6d20·2d71·6620·2466·696c·6573·5f77··rpm·-qf·$files_w 
0003c160:·6974·685f·696e·636f·7272·6563·745f·6861··ith_incorrect_ha 
0003c170:·7368·207c·2074·7220·275c·6e27·2027·2027··sh·|·tr·'\n'·'·' 
0003c180:·2922·0a0a·2020·2020·0a20·2020·2079·756d··)"..····.····yum 
0003c190:·2072·6569·6e73·7461·6c6c·202d·7920·2470···reinstall·-y·$p 
0003c1a0:·6163·6b61·6765·735f·746f·5f72·6569·6e73··ackages_to_reins 
0003c1b0:·7461·6c6c·0a20·2020·200a·6669·0a3c·2f63··tall.····.fi.</c 
0003c1c0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003c1d0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003c1e0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003c1f0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003c200:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003c210:·6964·6d37·3633·3722·2074·6162·696e·6465··idm7637"·tabinde 
0003c220:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003c230:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003c240:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003c250:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003c260:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003c270:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib0003bf60:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib
0003c280:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</0003bf70:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</
0003c290:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003bf80:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003c2a0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003bf90:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003c2b0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003bfa0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003c2c0:·646d·3736·3337·223e·3c74·6162·6c65·2063··dm7637"><table·c0003bfb0:·646d·3736·3336·223e·3c74·6162·6c65·2063··dm7636"><table·c
0003c2d0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003bfc0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003c2e0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003bfd0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003c2f0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003bfe0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003c300:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003bff0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003c310:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003c000:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003c320:·683e·3c74·643e·6869·6768·3c2f·7464·3e3c··h><td>high</td><0003c010:·683e·3c74·643e·6869·6768·3c2f·7464·3e3c··h><td>high</td><
0003c330:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003c020:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003c340:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003c030:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003c350:·6d65·6469·756d·3c2f·7464·3e3c·2f74·723e··medium</td></tr>0003c040:·6d65·6469·756d·3c2f·7464·3e3c·2f74·723e··medium</td></tr>
0003c360:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<0003c050:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
0003c370:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003c060:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003c380:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003c070:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003c390:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003c080:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003c3a0:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></0003c090:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></
0003c3b0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003c0a0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
0003c3c0:·3c63·6f64·653e·2d20·6e61·6d65·3a20·2753··<code>-·name:·'S0003c0b0:·3c63·6f64·653e·2d20·6e61·6d65·3a20·2753··<code>-·name:·'S
0003c3d0:·6574·2066·6163·743a·2050·6163·6b61·6765··et·fact:·Package0003c0c0:·6574·2066·6163·743a·2050·6163·6b61·6765··et·fact:·Package
0003c3e0:·206d·616e·6167·6572·2072·6569·6e73·7461···manager·reinsta0003c0d0:·206d·616e·6167·6572·2072·6569·6e73·7461···manager·reinsta
0003c3f0:·6c6c·2063·6f6d·6d61·6e64·270a·2020·7365··ll·command'.··se0003c0e0:·6c6c·2063·6f6d·6d61·6e64·270a·2020·7365··ll·command'.··se
0003c400:·745f·6661·6374·3a0a·2020·2020·7061·636b··t_fact:.····pack0003c0f0:·745f·6661·6374·3a0a·2020·2020·7061·636b··t_fact:.····pack
0003c410:·6167·655f·6d61·6e61·6765·725f·7265·696e··age_manager_rein0003c100:·6167·655f·6d61·6e61·6765·725f·7265·696e··age_manager_rein
0003c420:·7374·616c·6c5f·636d·643a·2079·756d·2072··stall_cmd:·yum·r0003c110:·7374·616c·6c5f·636d·643a·2079·756d·2072··stall_cmd:·yum·r
0003c430:·6569·6e73·7461·6c6c·202d·790a·2020·7768··einstall·-y.··wh0003c120:·6569·6e73·7461·6c6c·202d·790a·2020·7768··einstall·-y.··wh
0003c440:·656e·3a20·616e·7369·626c·655f·6469·7374··en:·ansible_dist0003c130:·656e·3a20·616e·7369·626c·655f·6469·7374··en:·ansible_dist
0003c450:·7269·6275·7469·6f6e·2069·6e20·5b20·2246··ribution·in·[·"F0003c140:·7269·6275·7469·6f6e·2069·6e20·5b20·2246··ribution·in·[·"F
0003c460:·6564·6f72·6122·2c20·2252·6564·4861·7422··edora",·"RedHat"0003c150:·6564·6f72·6122·2c20·2252·6564·4861·7422··edora",·"RedHat"
0003c470:·2c20·2243·656e·744f·5322·2c20·224f·7261··,·"CentOS",·"Ora0003c160:·2c20·2243·656e·744f·5322·2c20·224f·7261··,·"CentOS",·"Ora
0003c480:·636c·654c·696e·7578·2220·5d0a·2020·7461··cleLinux"·].··ta0003c170:·636c·654c·696e·7578·2220·5d0a·2020·7461··cleLinux"·].··ta
0003c490:·6773·3a0a·2020·2d20·4343·452d·3830·3835··gs:.··-·CCE-80850003c180:·6773·3a0a·2020·2d20·4343·452d·3830·3835··gs:.··-·CCE-8085
0003c4a0:·372d·360a·2020·2d20·434a·4953·2d35·2e31··7-6.··-·CJIS-5.10003c190:·372d·360a·2020·2d20·434a·4953·2d35·2e31··7-6.··-·CJIS-5.1
0003c4b0:·302e·342e·310a·2020·2d20·4e49·5354·2d38··0.4.1.··-·NIST-80003c1a0:·302e·342e·310a·2020·2d20·4e49·5354·2d38··0.4.1.··-·NIST-8
0003c4c0:·3030·2d31·3731·2d33·2e33·2e38·0a20·202d··00-171-3.3.8.··-0003c1b0:·3030·2d31·3731·2d33·2e33·2e38·0a20·202d··00-171-3.3.8.··-
0003c4d0:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.0003c1c0:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.
0003c4e0:·342e·310a·2020·2d20·4e49·5354·2d38·3030··4.1.··-·NIST-8000003c1d0:·342e·310a·2020·2d20·4e49·5354·2d38·3030··4.1.··-·NIST-800
0003c4f0:·2d35·332d·4155·2d39·2833·290a·2020·2d20··-53-AU-9(3).··-·0003c1e0:·2d35·332d·4155·2d39·2833·290a·2020·2d20··-53-AU-9(3).··-·
0003c500:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-60003c1f0:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6
0003c510:·2863·290a·2020·2d20·4e49·5354·2d38·3030··(c).··-·NIST-8000003c200:·2863·290a·2020·2d20·4e49·5354·2d38·3030··(c).··-·NIST-800
0003c520:·2d35·332d·434d·2d36·2864·290a·2020·2d20··-53-CM-6(d).··-·0003c210:·2d35·332d·434d·2d36·2864·290a·2020·2d20··-53-CM-6(d).··-·
0003c530:·4e49·5354·2d38·3030·2d35·332d·5349·2d37··NIST-800-53-SI-70003c220:·4e49·5354·2d38·3030·2d35·332d·5349·2d37··NIST-800-53-SI-7
0003c540:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53 
0003c550:·2d53·492d·3728·3129·0a20·202d·204e·4953··-SI-7(1).··-·NIS 
0003c560:·542d·3830·302d·3533·2d53·492d·3728·3629··T-800-53-SI-7(6) 
0003c570:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req 
0003c580:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS 
0003c590:·5376·342d·3131·2e35·2e32·0a20·202d·2068··Sv4-11.5.2.··-·h 
0003c5a0:·6967·685f·636f·6d70·6c65·7869·7479·0a20··igh_complexity.· 
0003c5b0:·202d·2068·6967·685f·7365·7665·7269·7479···-·high_severity 
0003c5c0:·0a20·202d·206d·6564·6975·6d5f·6469·7372··.··-·medium_disr 
0003c5d0:·7570·7469·6f6e·0a20·202d·206e·6f5f·7265··uption.··-·no_re 
Max diff block lines reached; 17256595/17298601 bytes (99.76%) of diff not shown.
1.61 MB
html2text {}
    
Offset 53, 15 lines modifiedOffset 53, 15 lines modified
53 ····*·cpe:/o:redhat:enterprise_linux:8.653 ····*·cpe:/o:redhat:enterprise_linux:8.6
54 ····*·cpe:/o:redhat:enterprise_linux:8.754 ····*·cpe:/o:redhat:enterprise_linux:8.7
55 ····*·cpe:/o:redhat:enterprise_linux:8.855 ····*·cpe:/o:redhat:enterprise_linux:8.8
56 ····*·cpe:/o:redhat:enterprise_linux:8.956 ····*·cpe:/o:redhat:enterprise_linux:8.9
57 ····*·cpe:/o:redhat:enterprise_linux:857 ····*·cpe:/o:redhat:enterprise_linux:8
58 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*58 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
59 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8459 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
60 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)60 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
61 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*61 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
62 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s62 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
63 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e63 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
64 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l64 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
65 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n65 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
66 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g66 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
67 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s67 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 121, 27 lines modifiedOffset 121, 14 lines modified
121 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6121 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
122 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4122 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
123 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)123 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
124 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1124 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
125 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5125 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
126 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227126 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
129 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
130 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
131 if·[·-n·"$files_with_incorrect_hash"·];·then 
132 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
133 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
134 ····yum·reinstall·-y·$packages_to_reinstall 
  
135 fi 
136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
141 -·name:·'Set·fact:·Package·manager·reinstall·command'133 -·name:·'Set·fact:·Package·manager·reinstall·command'
142 ··set_fact:134 ··set_fact:
Offset 273, 14 lines modifiedOffset 260, 27 lines modified
273 ··-·PCI-DSSv4-11.5.2260 ··-·PCI-DSSv4-11.5.2
274 ··-·high_complexity261 ··-·high_complexity
275 ··-·high_severity262 ··-·high_severity
276 ··-·medium_disruption263 ··-·medium_disruption
277 ··-·no_reboot_needed264 ··-·no_reboot_needed
278 ··-·restrict_strategy265 ··-·restrict_strategy
279 ··-·rpm_verify_hashes266 ··-·rpm_verify_hashes
 267 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 268 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 269 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 270 if·[·-n·"$files_with_incorrect_hash"·];·then
 271 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 272 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 273 ····yum·reinstall·-y·$packages_to_reinstall
  
 274 fi
280 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*275 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
281 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:276 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
282 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'277 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
283 run·the·following·command·to·determine·which·package·owns·it:278 run·the·following·command·to·determine·which·package·owns·it:
284 $·rpm·-qf·FILENAME279 $·rpm·-qf·FILENAME
285 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:280 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
286 $·sudo·rpm·--setugids·PACKAGENAME281 $·sudo·rpm·--setugids·PACKAGENAME
Offset 300, 40 lines modifiedOffset 300, 14 lines modified
300 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5300 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
301 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2301 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
302 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)302 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
303 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1303 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
304 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5304 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
305 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108305 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
306 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2306 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
307 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
308 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
309 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
310 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
311 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
312 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
313 declare·-A·SETPERMS_RPM_DICT 
  
314 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
315 #·is·expected·by·the·RPM·database 
316 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
317 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
318 do 
319 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
320 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
321 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
322 done 
  
323 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
324 #·correct·values 
325 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
326 do 
327 ········rpm·--setugids·"${RPM_PACKAGE}" 
328 done 
329 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8307 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
330 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high308 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
331 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium309 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
332 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false310 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
333 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict311 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
334 -·name:·Read·list·of·files·with·incorrect·ownership312 -·name:·Read·list·of·files·with·incorrect·ownership
335 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev313 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 411, 14 lines modifiedOffset 385, 40 lines modified
411 ··-·PCI-DSSv4-11.5.2385 ··-·PCI-DSSv4-11.5.2
412 ··-·high_complexity386 ··-·high_complexity
413 ··-·high_severity387 ··-·high_severity
414 ··-·medium_disruption388 ··-·medium_disruption
415 ··-·no_reboot_needed389 ··-·no_reboot_needed
416 ··-·restrict_strategy390 ··-·restrict_strategy
417 ··-·rpm_verify_ownership391 ··-·rpm_verify_ownership
 392 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 393 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 394 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 395 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 396 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 397 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 1679344/1686982 bytes (99.55%) of diff not shown.
30.1 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-stig.html
    
Offset 14446, 15 lines modifiedOffset 14446, 15 lines modified
000386d0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu000386d0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
000386e0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<000386e0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
000386f0:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s000386f0:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00038700:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00038700:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00038710:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00038710:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00038720:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00038720:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00038730:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00038730:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00038740:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).00038740:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
00038750:·2020·2020·2020·2020·2020·2020·2020·2020··················00038750:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038760:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00038760:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00038770:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00038770:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00038780:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00038780:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00038790:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00038790:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
000387a0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject000387a0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
000387b0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s000387b0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
Offset 15284, 236 lines modifiedOffset 15284, 236 lines modified
0003bb30:·7267·6574·3d22·2369·646d·3739·3830·2220··rget="#idm7980"·0003bb30:·7267·6574·3d22·2369·646d·3739·3830·2220··rget="#idm7980"·
0003bb40:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003bb40:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003bb50:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003bb50:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003bb60:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003bb60:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003bb70:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003bb70:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003bb80:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003bb80:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003bb90:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003bb90:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003bba0:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet0003bba0:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp
0003bbb0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003bbb0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
0003bbc0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003bbc0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0003bbd0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003bbd0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0003bbe0:·2069·643d·2269·646d·3739·3830·223e·3c74···id="idm7980"><t0003bbe0:·6522·2069·643d·2269·646d·3739·3830·223e··e"·id="idm7980">
0003bbf0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl0003bbf0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
0003bc00:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·0003bc00:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
0003bc10:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0003bc10:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
0003bc20:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">0003bc20:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
0003bc30:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi0003bc30:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003bc40:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<0003bc40:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0003bc50:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003bc50:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003bc60:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th0003bc60:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
0003bc70:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003bc70:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003bc80:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot0003bc80:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
0003bc90:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<0003bc90:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
0003bca0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003bca0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
0003bcb0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003bcb0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0003bcc0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003bcc0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
0003bcd0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003bcd0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003bce0:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package
 0003bcf0:·202d·2d61·6464·3d61·6964·650a·3c2f·636f···--add=aide.</co
 0003bd00:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0003bd10:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 0003bd20:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 0003bd30:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
0003bce0:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in 
0003bcf0:·7374·616c·6c5f·6169·6465·0a0a·636c·6173··stall_aide..clas 
0003bd00:·7320·696e·7374·616c·6c5f·6169·6465·207b··s·install_aide·{ 
0003bd10:·0a20·2070·6163·6b61·6765·207b·2027·6169··.··package·{·'ai 
0003bd20:·6465·273a·0a20·2020·2065·6e73·7572·6520··de':.····ensure· 
0003bd30:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed 
0003bd40:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code> 
0003bd50:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003bd60:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003bd70:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003bd80:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003bd90:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7 
0003bda0:·3938·3122·2074·6162·696e·6465·783d·2230··981"·tabindex="0 
0003bdb0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003bdc0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003bdd0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003bde0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003bdf0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003be00:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
0003be10:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003be20:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003be30:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003be40:·7365·2220·6964·3d22·6964·6d37·3938·3122··se"·id="idm7981" 
0003be50:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003be60:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003be70:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003be80:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003be90:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003bea0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003beb0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003bec0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003bed0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003bee0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003bef0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003bf00:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003bf10:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003bf20:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003bf30:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003bf40:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed 
0003bf50:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic 
0003bf60:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer 
0003bf70:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i 
0003bf80:·6620·5b20·2120·2d66·202f·2e64·6f63·6b65··f·[·!·-f·/.docke 
0003bf90:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp 
0003bfa0:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c 
0003bfb0:·6f6e·7461·696e·6572·656e·7620·5d3b·2074··ontainerenv·];·t 
0003bfc0:·6865·6e0a·0a69·6620·2120·7270·6d20·2d71··hen..if·!·rpm·-q 
0003bfd0:·202d·2d71·7569·6574·2022·6169·6465·2220···--quiet·"aide"· 
0003bfe0:·3b20·7468·656e·0a20·2020·2079·756d·2069··;·then.····yum·i 
0003bff0:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide" 
0003c000:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g 
0003c010:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R 
0003c020:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no 
0003c030:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no 
0003c040:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'. 
0003c050:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre> 
0003c060:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003c070:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003c080:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co0003bd40:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 0003bd50:·646d·3739·3831·2220·7461·6269·6e64·6578··dm7981"·tabindex
 0003bd60:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 0003bd70:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 0003bd80:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 0003bd90:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 0003bda0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 0003bdb0:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet
0003c090:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003c0a0:·6765·743d·2223·6964·6d37·3938·3222·2074··get="#idm7982"·t 
0003c0b0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003c0c0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003c0d0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003c0e0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003c0f0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003c100:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003c110:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet 
0003c120:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003c130:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003c140:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
Max diff block lines reached; 28950315/28982661 bytes (99.89%) of diff not shown.
2.41 MB
html2text {}
Max HTML report size reached
29.9 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-stig_gui.html
    
Offset 14470, 16 lines modifiedOffset 14470, 16 lines modified
00038850:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><00038850:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><
00038860:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio00038860:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio
00038870:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.700038870:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.7
00038880:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u00038880:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u
00038890:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr00038890:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr
000388a0:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···000388a0:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···
000388b0:·2020·2020·2020·2020·2020·2020·2020·2020··················000388b0:·2020·2020·2020·2020·2020·2020·2020·2020··················
000388c0:·2028·6173·206f·6620·3230·3236·2d30·312d···(as·of·2026-01-000388c0:·2028·6173·206f·6620·3230·3234·2d31·322d···(as·of·2024-12-
000388d0:·3038·290a·2020·2020·2020·2020·2020·2020··08).············000388d0:·3037·290a·2020·2020·2020·2020·2020·2020··07).············
000388e0:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></000388e0:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></
000388f0:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of000388f0:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of
00038900:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o00038900:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o
00038910:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#00038910:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#
00038920:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro00038920:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro
00038930:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro00038930:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro
00038940:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste00038940:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste
Offset 15303, 236 lines modifiedOffset 15303, 236 lines modified
0003bc60:·6172·6765·743d·2223·6964·6d37·3938·3022··arget="#idm7980"0003bc60:·6172·6765·743d·2223·6964·6d37·3938·3022··arget="#idm7980"
0003bc70:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003bc70:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003bc80:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003bc80:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003bc90:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003bc90:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003bca0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003bca0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003bcb0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003bcb0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003bcc0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003bcc0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003bcd0:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe0003bcd0:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip
0003bce0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003bce0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003bcf0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003bcf0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003bd00:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003bd00:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003bd10:·2220·6964·3d22·6964·6d37·3938·3022·3e3c··"·id="idm7980"><0003bd10:·7365·2220·6964·3d22·6964·6d37·3938·3022··se"·id="idm7980"
0003bd20:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003bd20:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003bd30:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003bd30:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003bd40:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003bd40:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003bd50:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003bd50:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003bd60:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003bd60:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003bd70:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003bd70:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003bd80:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003bd80:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003bd90:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003bd90:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003bda0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003bda0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003bdb0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo0003bdb0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
0003bdc0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false0003bdc0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
0003bdd0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003bdd0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
0003bde0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>0003bde0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0003bdf0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><0003bdf0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
0003be00:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0003be00:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003be10:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag
 0003be20:·6520·2d2d·6164·643d·6169·6465·0a3c·2f63··e·--add=aide.</c
 0003be30:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003be40:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003be50:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003be60:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
0003be10:·3e3c·636f·6465·3e69·6e63·6c75·6465·2069··><code>include·i 
0003be20:·6e73·7461·6c6c·5f61·6964·650a·0a63·6c61··nstall_aide..cla 
0003be30:·7373·2069·6e73·7461·6c6c·5f61·6964·6520··ss·install_aide· 
0003be40:·7b0a·2020·7061·636b·6167·6520·7b20·2761··{.··package·{·'a 
0003be50:·6964·6527·3a0a·2020·2020·656e·7375·7265··ide':.····ensure 
0003be60:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe 
0003be70:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code 
0003be80:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003be90:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003bea0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003beb0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003bec0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003bed0:·3739·3831·2220·7461·6269·6e64·6578·3d22··7981"·tabindex=" 
0003bee0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003bef0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003bf00:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003bf10:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003bf20:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003bf30:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003bf40:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003bf50:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003bf60:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003bf70:·7073·6522·2069·643d·2269·646d·3739·3831··pse"·id="idm7981 
0003bf80:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003bf90:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003bfa0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003bfb0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003bfc0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003bfd0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003bfe0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003bff0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003c000:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003c010:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003c020:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0003c030:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
0003c040:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003c050:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003c060:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003c070:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme 
0003c080:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
0003c090:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
0003c0a0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
0003c0b0:·6966·205b·2021·202d·6620·2f2e·646f·636b··if·[·!·-f·/.dock 
0003c0c0:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am 
0003c0d0:·703b·205b·2021·202d·6620·2f72·756e·2f2e··p;·[·!·-f·/run/. 
0003c0e0:·636f·6e74·6169·6e65·7265·6e76·205d·3b20··containerenv·];· 
0003c0f0:·7468·656e·0a0a·6966·2021·2072·706d·202d··then..if·!·rpm·- 
0003c100:·7120·2d2d·7175·6965·7420·2261·6964·6522··q·--quiet·"aide" 
0003c110:·203b·2074·6865·6e0a·2020·2020·7975·6d20···;·then.····yum· 
0003c120:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide 
0003c130:·220a·6669·0a0a·656c·7365·0a20·2020·2026··".fi..else.····& 
0003c140:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·' 
0003c150:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n 
0003c160:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n 
0003c170:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done' 
0003c180:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre 
0003c190:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003c1a0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003c1b0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c0003be70:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0003be80:·6964·6d37·3938·3122·2074·6162·696e·6465··idm7981"·tabinde
 0003be90:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 0003bea0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 0003beb0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 0003bec0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 0003bed0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 0003bee0:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
 0003bef0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
0003c1c0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003c1d0:·7267·6574·3d22·2369·646d·3739·3832·2220··rget="#idm7982"· 
0003c1e0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003c1f0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003c200:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003c210:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003c220:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003c230:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003c240:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe 
0003c250:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
Max diff block lines reached; 28799402/28831886 bytes (99.89%) of diff not shown.
2.39 MB
html2text {}
Max HTML report size reached
23.1 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-anssi_bp28_enhanced.html
    
Offset 14316, 16 lines modifiedOffset 14316, 16 lines modified
00037eb0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p00037eb0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p
00037ec0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version00037ec0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version
00037ed0:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.7400037ed0:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.74
00037ee0:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul00037ee0:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul
00037ef0:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra00037ef0:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra
00037f00:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····00037f00:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····
00037f10:·2020·2020·2020·2020·2020·2020·2020·2020··················00037f10:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037f20:·2861·7320·6f66·2032·3032·362d·3031·2d30··(as·of·2026-01-000037f20:·2861·7320·6f66·2032·3032·342d·3132·2d30··(as·of·2024-12-0
00037f30:·3829·0a20·2020·2020·2020·2020·2020·2020··8).·············00037f30:·3729·0a20·2020·2020·2020·2020·2020·2020··7).·············
00037f40:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d00037f40:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d
00037f50:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·00037f50:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·
00037f60:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol00037f60:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol
00037f70:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x00037f70:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x
00037f80:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj00037f80:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj
00037f90:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou00037f90:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou
00037fa0:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System00037fa0:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System
Offset 15108, 237 lines modifiedOffset 15108, 237 lines modified
0003b030:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003b030:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b040:·6964·6d38·3430·3622·2074·6162·696e·6465··idm8406"·tabinde0003b040:·6964·6d38·3430·3622·2074·6162·696e·6465··idm8406"·tabinde
0003b050:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b050:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003b060:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003b060:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003b070:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003b070:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003b080:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003b080:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003b090:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003b090:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003b0a0:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe0003b0a0:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco
0003b0b0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a0003b0b0:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...<
0003b0c0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003b0c0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003b0d0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003b0d0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003b0e0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003b0e0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
0003b0f0:·6d38·3430·3622·3e3c·7461·626c·6520·636c··m8406"><table·cl0003b0f0:·6964·6d38·3430·3622·3e3c·7461·626c·6520··idm8406"><table·
0003b100:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003b100:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003b110:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003b110:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003b120:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003b120:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003b130:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003b130:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0003b140:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003b140:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0003b150:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003b150:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003b160:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003b160:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003b170:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003b170:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003b180:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003b180:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003b190:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><0003b190:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
0003b1a0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t0003b1a0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
0003b1b0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate0003b1b0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
0003b1c0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab0003b1c0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
0003b1d0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta0003b1d0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
0003b1e0:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i0003b1e0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003b1f0:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add=
 0003b200:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr
 0003b210:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 0003b220:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 0003b230:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 0003b240:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 0003b250:·6172·6765·743d·2223·6964·6d38·3430·3722··arget="#idm8407"
 0003b260:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 0003b270:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 0003b280:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 0003b290:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 0003b2a0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 0003b2b0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003b2c0:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe
 0003b2d0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003b2e0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003b2f0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003b300:·2220·6964·3d22·6964·6d38·3430·3722·3e3c··"·id="idm8407"><
 0003b310:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003b320:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003b330:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003b340:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003b350:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003b1f0:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a 
0003b200:·6964·650a·0a63·6c61·7373·2069·6e73·7461··ide..class·insta 
0003b210:·6c6c·5f61·6964·6520·7b0a·2020·7061·636b··ll_aide·{.··pack 
0003b220:·6167·6520·7b20·2761·6964·6527·3a0a·2020··age·{·'aide':.·· 
0003b230:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·' 
0003b240:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}. 
0003b250:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre>< 
0003b260:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003b270:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003b280:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003b290:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003b2a0:·6574·3d22·2369·646d·3834·3037·2220·7461··et="#idm8407"·ta 
0003b2b0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003b2c0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003b2d0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003b2e0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003b2f0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003b300:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003b310:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
0003b320:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b330:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b340:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b350:·2269·646d·3834·3037·223e·3c74·6162·6c65··"idm8407"><table 
0003b360:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003b370:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003b380:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003b390:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003b3a0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003b3b0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b3c0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003b3d0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003b3e0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b3f0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003b400:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003b410:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003b420:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003b360:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003b430:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0003b440:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003b450:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation· 
0003b460:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on 
0003b470:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl 
0003b480:·6174·666f·726d·730a·6966·205b·2021·202d··atforms.if·[·!·- 
0003b490:·6620·2f2e·646f·636b·6572·656e·7620·5d20··f·/.dockerenv·]· 
0003b4a0:·2661·6d70·3b26·616d·703b·205b·2021·202d··&amp;&amp;·[·!·- 
0003b4b0:·6620·2f72·756e·2f2e·636f·6e74·6169·6e65··f·/run/.containe 
0003b4c0:·7265·6e76·205d·3b20·7468·656e·0a0a·6966··renv·];·then..if 
0003b4d0:·2021·2072·706d·202d·7120·2d2d·7175·6965···!·rpm·-q·--quie 
0003b4e0:·7420·2261·6964·6522·203b·2074·6865·6e0a··t·"aide"·;·then. 
0003b4f0:·2020·2020·646e·6620·696e·7374·616c·6c20······dnf·install· 
0003b500:·2d79·2022·6169·6465·220a·6669·0a0a·656c··-y·"aide".fi..el 
0003b510:·7365·0a20·2020·2026·6774·3b26·616d·703b··se.····&gt;&amp; 
0003b520:·3220·6563·686f·2027·5265·6d65·6469·6174··2·echo·'Remediat 
0003b530:·696f·6e20·6973·206e·6f74·2061·7070·6c69··ion·is·not·appli 
0003b540:·6361·626c·652c·206e·6f74·6869·6e67·2077··cable,·nothing·w 
0003b550:·6173·2064·6f6e·6527·0a66·690a·3c2f·636f··as·done'.fi.</co 
0003b560:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003b570:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003b580:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003b590:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
Max diff block lines reached; 22173935/22206557 bytes (99.85%) of diff not shown.
1.97 MB
html2text {}
Max HTML report size reached
23.6 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-anssi_bp28_high.html
    
Offset 14315, 16 lines modifiedOffset 14315, 16 lines modified
00037ea0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p00037ea0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p
00037eb0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version00037eb0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version
00037ec0:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.7400037ec0:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.74
00037ed0:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul00037ed0:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul
00037ee0:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra00037ee0:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra
00037ef0:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····00037ef0:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····
00037f00:·2020·2020·2020·2020·2020·2020·2020·2020··················00037f00:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037f10:·2861·7320·6f66·2032·3032·362d·3031·2d30··(as·of·2026-01-000037f10:·2861·7320·6f66·2032·3032·342d·3132·2d30··(as·of·2024-12-0
00037f20:·3829·0a20·2020·2020·2020·2020·2020·2020··8).·············00037f20:·3729·0a20·2020·2020·2020·2020·2020·2020··7).·············
00037f30:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d00037f30:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d
00037f40:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·00037f40:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·
00037f50:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol00037f50:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol
00037f60:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x00037f60:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x
00037f70:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj00037f70:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj
00037f80:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou00037f80:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou
00037f90:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System00037f90:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System
Offset 15113, 237 lines modifiedOffset 15113, 237 lines modified
0003b080:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b080:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b090:·3d22·2369·646d·3834·3036·2220·7461·6269··="#idm8406"·tabi0003b090:·3d22·2369·646d·3834·3036·2220·7461·6269··="#idm8406"·tabi
0003b0a0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b0a0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b0b0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b0b0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b0c0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b0c0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b0d0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b0d0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b0e0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b0e0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b0f0:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu0003b0f0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
0003b100:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...0003b100:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
0003b110:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003b110:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003b120:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003b120:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003b130:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003b130:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003b140:·2269·646d·3834·3036·223e·3c74·6162·6c65··"idm8406"><table0003b140:·643d·2269·646d·3834·3036·223e·3c74·6162··d="idm8406"><tab
0003b150:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003b150:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003b160:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003b160:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003b170:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003b170:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003b180:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003b180:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003b190:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003b190:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003b1a0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003b1a0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003b1b0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003b1b0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
0003b1c0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003b1c0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003b1d0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003b1d0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003b1e0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t0003b1e0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
0003b1f0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>0003b1f0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003b200:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003b200:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003b210:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003b210:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003b220:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003b220:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003b230:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod0003b230:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003b240:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a
 0003b250:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code><
 0003b260:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003b270:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003b280:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
0003b240:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal 
0003b250:·6c5f·6169·6465·0a0a·636c·6173·7320·696e··l_aide..class·in 
0003b260:·7374·616c·6c5f·6169·6465·207b·0a20·2070··stall_aide·{.··p 
0003b270:·6163·6b61·6765·207b·2027·6169·6465·273a··ackage·{·'aide': 
0003b280:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt 
0003b290:·3b20·2769·6e73·7461·6c6c·6564·272c·0a20··;·'installed',.· 
0003b2a0:·207d·0a7d·0a3c·2f63·6f64·653e·3c2f·7072···}.}.</code></pr 
0003b2b0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003b2c0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003b2d0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003b2e0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003b2f0:·6172·6765·743d·2223·6964·6d38·3430·3722··arget="#idm8407" 
0003b300:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003b310:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003b320:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003b330:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003b340:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003b350:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003b360:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script· 
0003b370:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003b380:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003b390:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003b3a0:·6964·3d22·6964·6d38·3430·3722·3e3c·7461··id="idm8407"><ta 
0003b3b0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003b3c0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003b3d0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003b3e0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003b3f0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003b400:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003b410:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b420:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003b430:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b440:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003b450:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003b460:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b470:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003b480:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0003b490:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003b4a0:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati 
0003b4b0:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable 
0003b4c0:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain 
0003b4d0:·2070·6c61·7466·6f72·6d73·0a69·6620·5b20···platforms.if·[· 
0003b4e0:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv 
0003b4f0:·205d·2026·616d·703b·2661·6d70·3b20·5b20···]·&amp;&amp;·[· 
0003b500:·2120·2d66·202f·7275·6e2f·2e63·6f6e·7461··!·-f·/run/.conta 
0003b510:·696e·6572·656e·7620·5d3b·2074·6865·6e0a··inerenv·];·then. 
0003b520:·0a69·6620·2120·7270·6d20·2d71·202d·2d71··.if·!·rpm·-q·--q 
0003b530:·7569·6574·2022·6169·6465·2220·3b20·7468··uiet·"aide"·;·th 
0003b540:·656e·0a20·2020·2064·6e66·2069·6e73·7461··en.····dnf·insta 
0003b550:·6c6c·202d·7920·2261·6964·6522·0a66·690a··ll·-y·"aide".fi. 
0003b560:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a 
0003b570:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed 
0003b580:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap 
0003b590:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin 
0003b5a0:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.< 
0003b5b0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003b5c0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003b5d0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003b5e0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003b5f0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003b600:·2223·6964·6d38·3430·3822·2074·6162·696e··"#idm8408"·tabin 
0003b610:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003b620:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003b630:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003b640:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003b650:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003b660:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans 
0003b670:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·... 
0003b680:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b690:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b6a0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003b290:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003b2a0:·612d·7461·7267·6574·3d22·2369·646d·3834··a-target="#idm84
 0003b2b0:·3037·2220·7461·6269·6e64·6578·3d22·3022··07"·tabindex="0"
 0003b2c0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003b2d0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003b2e0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003b2f0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
Max diff block lines reached; 22600250/22632872 bytes (99.86%) of diff not shown.
2.01 MB
html2text {}
Max HTML report size reached
9.98 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-anssi_bp28_intermediary.html
    
Offset 14317, 16 lines modifiedOffset 14317, 16 lines modified
00037ec0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p00037ec0:·6e20·4869·7374·6f72·793c·2f68·323e·3c70··n·History</h2><p
00037ed0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version00037ed0:·3e43·7572·7265·6e74·2076·6572·7369·6f6e··>Current·version
00037ee0:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.7400037ee0:·3a20·3c73·7472·6f6e·673e·302e·312e·3734··:·<strong>0.1.74
00037ef0:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul00037ef0:·3c2f·7374·726f·6e67·3e3c·2f70·3e3c·756c··</strong></p><ul
00037f00:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra00037f00:·3e3c·6c69·3e3c·7374·726f·6e67·3e64·7261··><li><strong>dra
00037f10:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····00037f10:·6674·3c2f·7374·726f·6e67·3e0a·2020·2020··ft</strong>.····
00037f20:·2020·2020·2020·2020·2020·2020·2020·2020··················00037f20:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037f30:·2861·7320·6f66·2032·3032·362d·3031·2d30··(as·of·2026-01-000037f30:·2861·7320·6f66·2032·3032·342d·3132·2d30··(as·of·2024-12-0
00037f40:·3829·0a20·2020·2020·2020·2020·2020·2020··8).·············00037f40:·3729·0a20·2020·2020·2020·2020·2020·2020··7).·············
00037f50:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d00037f50:·2020·203c·2f6c·693e·3c2f·756c·3e3c·2f64·····</li></ul></d
00037f60:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·00037f60:·6976·3e3c·6832·3e54·6162·6c65·206f·6620··iv><h2>Table·of·
00037f70:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol00037f70:·436f·6e74·656e·7473·3c2f·6832·3e3c·6f6c··Contents</h2><ol
00037f80:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x00037f80:·3e3c·6c69·3e3c·6120·6872·6566·3d22·2378··><li><a·href="#x
00037f90:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj00037f90:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj
00037fa0:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou00037fa0:·6563·742e·636f·6e74·656e·745f·6772·6f75··ect.content_grou
00037fb0:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System00037fb0:·705f·7379·7374·656d·223e·5379·7374·656d··p_system">System
Offset 15104, 236 lines modifiedOffset 15104, 236 lines modified
0003aff0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003aff0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003b000:·3834·3036·2220·7461·6269·6e64·6578·3d22··8406"·tabindex="0003b000:·3834·3036·2220·7461·6269·6e64·6578·3d22··8406"·tabindex="
0003b010:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b010:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003b020:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b020:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003b030:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003b030:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003b040:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003b040:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003b050:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003b050:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003b060:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s0003b060:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
0003b070:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003b070:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003b080:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003b080:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003b090:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003b090:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003b0a0:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm840003b0a0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003b0b0:·3036·223e·3c74·6162·6c65·2063·6c61·7373··06"><table·class0003b0b0:·3834·3036·223e·3c74·6162·6c65·2063·6c61··8406"><table·cla
0003b0c0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003b0c0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003b0d0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003b0d0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003b0e0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003b0e0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003b0f0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003b0f0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003b100:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003b100:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003b110:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003b110:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003b120:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003b120:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003b130:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003b130:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
0003b140:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003b140:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003b150:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>0003b150:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
0003b160:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><0003b160:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
0003b170:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003b170:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
0003b180:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0003b180:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003b190:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003b190:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0003b1a0:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl0003b1a0:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p
 0003b1b0:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid
 0003b1c0:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><
 0003b1d0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0003b1e0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0003b1f0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0003b200:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0003b210:·6574·3d22·2369·646d·3834·3037·2220·7461··et="#idm8407"·ta
 0003b220:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 0003b230:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 0003b240:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 0003b250:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 0003b260:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 0003b270:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003b280:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.
 0003b290:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003b2a0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003b1b0:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide 
0003b1c0:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_ 
0003b1d0:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package 
0003b1e0:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e 
0003b1f0:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins 
0003b200:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.< 
0003b210:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003b220:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003b230:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003b240:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003b250:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003b260:·2223·6964·6d38·3430·3722·2074·6162·696e··"#idm8407"·tabin 
0003b270:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003b280:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003b290:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003b2a0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003b2b0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003b2c0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
0003b2d0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
0003b2e0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b2f0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003b2b0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003b300:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b310:·6d38·3430·3722·3e3c·7461·626c·6520·636c··m8407"><table·cl 
0003b320:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003b330:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003b340:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0003b350:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0003b360:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003b2c0:·643d·2269·646d·3834·3037·223e·3c74·6162··d="idm8407"><tab
 0003b2d0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0003b2e0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0003b2f0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 0003b300:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 0003b310:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 0003b320:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003b330:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0003b340:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003b370:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003b350:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003b380:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003b390:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003b360:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 0003b370:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003b3a0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003b380:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 0003b390:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003b3b0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
0003b3c0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
0003b3d0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
0003b3e0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
0003b3f0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
0003b400:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code># 
0003b410:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is· 
0003b420:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only· 
0003b430:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf 
0003b440:·6f72·6d73·0a69·6620·5b20·2120·2d66·202f··orms.if·[·!·-f·/ 
0003b450:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am 
0003b460:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/ 
0003b470:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren 
0003b480:·7620·5d3b·2074·6865·6e0a·0a69·6620·2120··v·];·then..if·!· 
0003b490:·7270·6d20·2d71·202d·2d71·7569·6574·2022··rpm·-q·--quiet·" 
0003b4a0:·6169·6465·2220·3b20·7468·656e·0a20·2020··aide"·;·then.··· 
0003b4b0:·2064·6e66·2069·6e73·7461·6c6c·202d·7920···dnf·install·-y· 
0003b4c0:·2261·6964·6522·0a66·690a·0a65·6c73·650a··"aide".fi..else. 
0003b4d0:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e 
0003b4e0:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation 
0003b4f0:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab 
0003b500:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was· 
0003b510:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code> 
0003b520:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
Max diff block lines reached; 9334604/9367088 bytes (99.65%) of diff not shown.
1.04 MB
html2text {}
    
Offset 45, 15 lines modifiedOffset 45, 15 lines modified
45 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
46 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(intermediary)46 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(intermediary)
47 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_intermediary47 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_intermediary
48 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*48 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
49 ····*·cpe:/o:redhat:enterprise_linux:949 ····*·cpe:/o:redhat:enterprise_linux:9
50 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
51 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8451 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
52 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)52 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
53 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*53 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
54 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s54 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
55 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e55 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
56 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l56 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
57 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n57 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
58 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s58 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
59 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s59 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 119, 41 lines modifiedOffset 119, 45 lines modified
119 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5119 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
120 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199120 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
121 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79121 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
122 ·············_\x8c_\x8i_\x8s············6.1.1122 ·············_\x8c_\x8i_\x8s············6.1.1
123 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2123 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010
125 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule125 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule
 126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 131 package·--add=aide
126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
131 include·install_aide137 include·install_aide
  
132 class·install_aide·{138 class·install_aide·{
133 ··package·{·'aide':139 ··package·{·'aide':
134 ····ensure·=>·'installed',140 ····ensure·=>·'installed',
135 ··}141 ··}
136 }142 }
 143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 144 [[packages]]
 145 name·=·"aide"
 146 version·=·"*"
137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8147 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low148 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low149 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false150 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable151 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
142 #·Remediation·is·applicable·only·in·certain·platforms 
143 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
 152 package·install·aide
144 if·!·rpm·-q·--quiet·"aide"·;·then 
145 ····dnf·install·-y·"aide" 
146 fi 
  
147 else 
148 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
149 fi 
150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
151 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low154 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
152 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low155 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
153 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false156 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
154 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable157 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
155 -·name:·Ensure·aide·is·installed158 -·name:·Ensure·aide·is·installed
156 ··package:159 ··package:
Offset 169, 33 lines modifiedOffset 173, 29 lines modified
169 ··-·PCI-DSSv4-11.5.2173 ··-·PCI-DSSv4-11.5.2
170 ··-·enable_strategy174 ··-·enable_strategy
171 ··-·low_complexity175 ··-·low_complexity
172 ··-·low_disruption176 ··-·low_disruption
173 ··-·medium_severity177 ··-·medium_severity
174 ··-·no_reboot_needed178 ··-·no_reboot_needed
175 ··-·package_aide_installed179 ··-·package_aide_installed
176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
177 [[packages]] 
178 name·=·"aide" 
179 version·=·"*" 
180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 185 #·Remediation·is·applicable·only·in·certain·platforms
 186 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 187 if·!·rpm·-q·--quiet·"aide"·;·then
 188 ····dnf·install·-y·"aide"
 189 fi
185 package·install·aide 
186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
191 package·--add=aide190 else
 191 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 192 fi
192 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*193 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
193 Run·the·following·command·to·generate·a·new·database:194 Run·the·following·command·to·generate·a·new·database:
194 $·sudo·/usr/sbin/aide·--init195 $·sudo·/usr/sbin/aide·--init
195 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the196 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
196 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these197 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
197 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their198 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
198 integrity.·The·newly-generated·database·can·be·installed·as·follows:199 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 222, 28 lines modifiedOffset 222, 14 lines modified
222 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5222 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
223 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199223 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
224 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79224 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
225 ·············_\x8c_\x8i_\x8s············6.1.1225 ·············_\x8c_\x8i_\x8s············6.1.1
226 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2226 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
227 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010227 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010
228 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule228 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule
229 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
230 #·Remediation·is·applicable·only·in·certain·platforms 
231 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
232 if·!·rpm·-q·--quiet·"aide"·;·then 
233 ····dnf·install·-y·"aide" 
234 fi 
  
Max diff block lines reached; 1089674/1095622 bytes (99.46%) of diff not shown.
3.22 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-anssi_bp28_minimal.html
    
Offset 14316, 15 lines modifiedOffset 14316, 15 lines modified
00037eb0:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur00037eb0:·7374·6f72·793c·2f68·323e·3c70·3e43·7572··story</h2><p>Cur
00037ec0:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s00037ec0:·7265·6e74·2076·6572·7369·6f6e·3a20·3c73··rent·version:·<s
00037ed0:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st00037ed0:·7472·6f6e·673e·302e·312e·3734·3c2f·7374··trong>0.1.74</st
00037ee0:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li00037ee0:·726f·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69··rong></p><ul><li
00037ef0:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</00037ef0:·3e3c·7374·726f·6e67·3e64·7261·6674·3c2f··><strong>draft</
00037f00:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········00037f00:·7374·726f·6e67·3e0a·2020·2020·2020·2020··strong>.········
00037f10:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·00037f10:·2020·2020·2020·2020·2020·2020·2861·7320··············(as·
00037f20:·6f66·2032·3032·362d·3031·2d30·3829·0a20··of·2026-01-08).·00037f20:·6f66·2032·3032·342d·3132·2d30·3729·0a20··of·2024-12-07).·
00037f30:·2020·2020·2020·2020·2020·2020·2020·203c·················<00037f30:·2020·2020·2020·2020·2020·2020·2020·203c·················<
00037f40:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><00037f40:·2f6c·693e·3c2f·756c·3e3c·2f64·6976·3e3c··/li></ul></div><
00037f50:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont00037f50:·6832·3e54·6162·6c65·206f·6620·436f·6e74··h2>Table·of·Cont
00037f60:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li00037f60:·656e·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69··ents</h2><ol><li
00037f70:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf00037f70:·3e3c·6120·6872·6566·3d22·2378·6363·6466··><a·href="#xccdf
00037f80:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.00037f80:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.
00037f90:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy00037f90:·636f·6e74·656e·745f·6772·6f75·705f·7379··content_group_sy
Offset 14766, 218 lines modifiedOffset 14766, 218 lines modified
00039ad0:·6172·6765·743d·2223·6964·6d31·3237·3539··arget="#idm1275900039ad0:·6172·6765·743d·2223·6964·6d31·3237·3539··arget="#idm12759
00039ae0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r00039ae0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
00039af0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari00039af0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
00039b00:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals00039b00:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
00039b10:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa00039b10:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
00039b20:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr00039b20:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
00039b30:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat00039b30:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
00039b40:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp00039b40:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni
00039b50:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d00039b50:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
00039b60:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-00039b60:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
00039b70:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps00039b70:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
00039b80:·6522·2069·643d·2269·646d·3132·3735·3922··e"·id="idm12759"00039b80:·7073·6522·2069·643d·2269·646d·3132·3735··pse"·id="idm1275
00039b90:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t00039b90:·3922·3e3c·7461·626c·6520·636c·6173·733d··9"><table·class=
00039ba0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip00039ba0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
00039bb0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere00039bb0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
00039bc0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense00039bc0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
00039bd0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl00039bd0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
00039be0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l00039be0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
00039bf0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>00039bf0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
00039c00:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<00039c00:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
00039c10:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>00039c10:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
00039c20:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb00039c20:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
00039c30:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal00039c30:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
00039c40:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>00039c40:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
00039c50:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t00039c50:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
00039c60:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td00039c60:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
00039c70:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p00039c70:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
00039c80:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include00039c80:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack
 00039c90:·6167·6520·2d2d·6164·643d·646e·662d·6175··age·--add=dnf-au
 00039ca0:·746f·6d61·7469·630a·3c2f·636f·6465·3e3c··tomatic.</code><
 00039cb0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 00039cc0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 00039cd0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 00039ce0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 00039cf0:·612d·7461·7267·6574·3d22·2369·646d·3132··a-target="#idm12
 00039d00:·3736·3022·2074·6162·696e·6465·783d·2230··760"·tabindex="0
 00039d10:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 00039d20:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 00039d30:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 00039d40:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 00039d50:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 00039d60:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
 00039d70:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 00039d80:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 00039d90:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 00039da0:·6170·7365·2220·6964·3d22·6964·6d31·3237··apse"·id="idm127
 00039db0:·3630·223e·3c74·6162·6c65·2063·6c61·7373··60"><table·class
 00039dc0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 00039dd0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 00039de0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 00039df0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 00039e00:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 00039e10:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 00039e20:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 00039e30:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 00039e40:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 00039e50:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 00039e60:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 00039e70:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 00039e80:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 00039e90:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 00039ea0:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
 00039eb0:·7564·6520·696e·7374·616c·6c5f·646e·662d··ude·install_dnf-
 00039ec0:·6175·746f·6d61·7469·630a·0a63·6c61·7373··automatic..class
00039c90:·2069·6e73·7461·6c6c·5f64·6e66·2d61·7574···install_dnf-aut00039ed0:·2069·6e73·7461·6c6c·5f64·6e66·2d61·7574···install_dnf-aut
 00039ee0:·6f6d·6174·6963·207b·0a20·2070·6163·6b61··omatic·{.··packa
 00039ef0:·6765·207b·2027·646e·662d·6175·746f·6d61··ge·{·'dnf-automa
 00039f00:·7469·6327·3a0a·2020·2020·656e·7375·7265··tic':.····ensure
 00039f10:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe
 00039f20:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code
 00039f30:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 00039f40:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 00039f50:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 00039f60:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 00039f70:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 00039f80:·3132·3736·3122·2074·6162·696e·6465·783d··12761"·tabindex=
 00039f90:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 00039fa0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 00039fb0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 00039fc0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 00039fd0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 00039fe0:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild
 00039ff0:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp
00039ca0:·6f6d·6174·6963·0a0a·636c·6173·7320·696e··omatic..class·in 
00039cb0:·7374·616c·6c5f·646e·662d·6175·746f·6d61··stall_dnf-automa 
00039cc0:·7469·6320·7b0a·2020·7061·636b·6167·6520··tic·{.··package· 
00039cd0:·7b20·2764·6e66·2d61·7574·6f6d·6174·6963··{·'dnf-automatic 
00039ce0:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=& 
00039cf0:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed', 
00039d00:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></ 
00039d10:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
00039d20:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
00039d30:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
00039d40:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
00039d50:·2d74·6172·6765·743d·2223·6964·6d31·3237··-target="#idm127 
00039d60:·3630·2220·7461·6269·6e64·6578·3d22·3022··60"·tabindex="0" 
00039d70:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
00039d80:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
00039d90:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
00039da0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
00039db0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
00039dc0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
00039dd0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d0003a000:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
00039de0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003a010:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
00039df0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003a020:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
00039e00:·6522·2069·643d·2269·646d·3132·3736·3022··e"·id="idm12760"0003a030:·6522·2069·643d·2269·646d·3132·3736·3122··e"·id="idm12761"
00039e10:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
00039e20:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
00039e30:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
00039e40:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
00039e50:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
Max diff block lines reached; 3128701/3158563 bytes (99.05%) of diff not shown.
215 KB
html2text {}
    
Offset 45, 15 lines modifiedOffset 45, 15 lines modified
45 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
46 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(minimal)46 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(minimal)
47 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_minimal47 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_minimal
48 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*48 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
49 ····*·cpe:/o:redhat:enterprise_linux:949 ····*·cpe:/o:redhat:enterprise_linux:9
50 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
51 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8451 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
52 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)52 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
53 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*53 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
54 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s54 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
55 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e55 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
56 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l56 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
57 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s57 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
58 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s58 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
59 ·········1.·_\x8D_\x8H_\x8C_\x8P59 ·········1.·_\x8D_\x8H_\x8C_\x8P
Offset 83, 35 lines modifiedOffset 83, 45 lines modified
83 Rationale:···dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade83 Rationale:···dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade
84 ·············suitable·for·automatic,·regular·execution.84 ·············suitable·for·automatic,·regular·execution.
85 Severity: ···medium85 Severity: ···medium
86 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed86 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
87 Identifiers:·CCE-83454-987 Identifiers:·CCE-83454-9
88 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-0008088 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
89 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R6189 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
 90 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 91 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 92 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 93 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 94 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 95 package·--add=dnf-automatic
90 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x896 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
91 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low97 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
92 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low98 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
93 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false99 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
94 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable100 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
95 include·install_dnf-automatic101 include·install_dnf-automatic
  
96 class·install_dnf-automatic·{102 class·install_dnf-automatic·{
97 ··package·{·'dnf-automatic':103 ··package·{·'dnf-automatic':
98 ····ensure·=>·'installed',104 ····ensure·=>·'installed',
99 ··}105 ··}
100 }106 }
 107 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 108 [[packages]]
 109 name·=·"dnf-automatic"
 110 version·=·"*"
101 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8111 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
102 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low112 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
103 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low113 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
104 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false114 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
105 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable115 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 116 package·install·dnf-automatic
106 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then 
107 ····dnf·install·-y·"dnf-automatic" 
108 fi 
109 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8117 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
110 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low118 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
111 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low119 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
112 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false120 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
113 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable121 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
114 -·name:·Ensure·dnf-automatic·is·installed122 -·name:·Ensure·dnf-automatic·is·installed
115 ··package:123 ··package:
Offset 121, 33 lines modifiedOffset 131, 23 lines modified
121 ··-·CCE-83454-9131 ··-·CCE-83454-9
122 ··-·enable_strategy132 ··-·enable_strategy
123 ··-·low_complexity133 ··-·low_complexity
124 ··-·low_disruption134 ··-·low_disruption
125 ··-·medium_severity135 ··-·medium_severity
126 ··-·no_reboot_needed136 ··-·no_reboot_needed
127 ··-·package_dnf-automatic_installed137 ··-·package_dnf-automatic_installed
128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
129 [[packages]] 
130 name·=·"dnf-automatic" 
131 version·=·"*" 
132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8138 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
137 package·install·dnf-automatic 
138 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
139 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low139 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
140 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low140 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
141 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false141 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
142 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable142 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
143 package·--add=dnf-automatic143 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
 144 ····dnf·install·-y·"dnf-automatic"
 145 fi
144 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*146 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
145 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed147 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
146 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/148 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
147 automatic.conf.149 automatic.conf.
148 ·············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation150 ·············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
149 ·············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and151 ·············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
150 Rationale:···updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in152 Rationale:···updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 158, 14 lines modifiedOffset 158, 37 lines modified
158 Rule·ID:·····xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates158 Rule·ID:·····xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates
159 Identifiers:·CCE-83456-4159 Identifiers:·CCE-83456-4
160 ·············_\x8i_\x8s_\x8m····0940,·1144,·1467,·1472,·1483,·1493,·1494,·1495160 ·············_\x8i_\x8s_\x8m····0940,·1144,·1467,·1472,·1483,·1493,·1494,·1495
161 ·············_\x8n_\x8i_\x8s_\x8t···SI-2(5),·CM-6(a),·SI-2(c)161 ·············_\x8n_\x8i_\x8s_\x8t···SI-2(5),·CM-6(a),·SI-2(c)
162 References:··_\x8o_\x8s_\x8p_\x8p···FMT_SMF_EXT.1162 References:··_\x8o_\x8s_\x8p_\x8p···FMT_SMF_EXT.1
163 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080163 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
164 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61164 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
 165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···unknown
 170 -·name:·Configure·dnf-automatic·to·Install·Available·Updates·Automatically
 171 ··ini_file:
 172 ····dest:·/etc/dnf/automatic.conf
 173 ····section:·commands
 174 ····option:·apply_updates
 175 ····value:·'yes'
 176 ····create:·true
 177 ··tags:
 178 ··-·CCE-83456-4
 179 ··-·NIST-800-53-CM-6(a)
 180 ··-·NIST-800-53-SI-2(5)
 181 ··-·NIST-800-53-SI-2(c)
 182 ··-·dnf-automatic_apply_updates
 183 ··-·low_complexity
Max diff block lines reached; 214037/219920 bytes (97.32%) of diff not shown.
13.4 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-ccn_advanced.html
    
Offset 14302, 16 lines modifiedOffset 14302, 16 lines modified
00037dd0:·7369·6f6e·2048·6973·746f·7279·3c2f·6832··sion·History</h200037dd0:·7369·6f6e·2048·6973·746f·7279·3c2f·6832··sion·History</h2
00037de0:·3e3c·703e·4375·7272·656e·7420·7665·7273··><p>Current·vers00037de0:·3e3c·703e·4375·7272·656e·7420·7665·7273··><p>Current·vers
00037df0:·696f·6e3a·203c·7374·726f·6e67·3e30·2e31··ion:·<strong>0.100037df0:·696f·6e3a·203c·7374·726f·6e67·3e30·2e31··ion:·<strong>0.1
00037e00:·2e37·343c·2f73·7472·6f6e·673e·3c2f·703e··.74</strong></p>00037e00:·2e37·343c·2f73·7472·6f6e·673e·3c2f·703e··.74</strong></p>
00037e10:·3c75·6c3e·3c6c·693e·3c73·7472·6f6e·673e··<ul><li><strong>00037e10:·3c75·6c3e·3c6c·693e·3c73·7472·6f6e·673e··<ul><li><strong>
00037e20:·6472·6166·743c·2f73·7472·6f6e·673e·0a20··draft</strong>.·00037e20:·6472·6166·743c·2f73·7472·6f6e·673e·0a20··draft</strong>.·
00037e30:·2020·2020·2020·2020·2020·2020·2020·2020··················00037e30:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037e40:·2020·2028·6173·206f·6620·3230·3236·2d30·····(as·of·2026-000037e40:·2020·2028·6173·206f·6620·3230·3234·2d31·····(as·of·2024-1
00037e50:·312d·3038·290a·2020·2020·2020·2020·2020··1-08).··········00037e50:·322d·3037·290a·2020·2020·2020·2020·2020··2-07).··········
00037e60:·2020·2020·2020·3c2f·6c69·3e3c·2f75·6c3e········</li></ul>00037e60:·2020·2020·2020·3c2f·6c69·3e3c·2f75·6c3e········</li></ul>
00037e70:·3c2f·6469·763e·3c68·323e·5461·626c·6520··</div><h2>Table·00037e70:·3c2f·6469·763e·3c68·323e·5461·626c·6520··</div><h2>Table·
00037e80:·6f66·2043·6f6e·7465·6e74·733c·2f68·323e··of·Contents</h2>00037e80:·6f66·2043·6f6e·7465·6e74·733c·2f68·323e··of·Contents</h2>
00037e90:·3c6f·6c3e·3c6c·693e·3c61·2068·7265·663d··<ol><li><a·href=00037e90:·3c6f·6c3e·3c6c·693e·3c61·2068·7265·663d··<ol><li><a·href=
00037ea0:·2223·7863·6364·665f·6f72·672e·7373·6770··"#xccdf_org.ssgp00037ea0:·2223·7863·6364·665f·6f72·672e·7373·6770··"#xccdf_org.ssgp
00037eb0:·726f·6a65·6374·2e63·6f6e·7465·6e74·5f67··roject.content_g00037eb0:·726f·6a65·6374·2e63·6f6e·7465·6e74·5f67··roject.content_g
00037ec0:·726f·7570·5f73·7973·7465·6d22·3e53·7973··roup_system">Sys00037ec0:·726f·7570·5f73·7973·7465·6d22·3e53·7973··roup_system">Sys
Offset 15169, 252 lines modifiedOffset 15169, 252 lines modified
0003b400:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b400:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003b410:·2223·6964·6d39·3230·3022·2074·6162·696e··"#idm9200"·tabin0003b410:·2223·6964·6d39·3230·3022·2074·6162·696e··"#idm9200"·tabin
0003b420:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b420:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b430:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b430:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b440:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b440:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b450:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b450:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b460:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b460:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b470:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She0003b470:·3e52·656d·6564·6961·7469·6f6e·204b·7562··>Remediation·Kub
 0003b480:·6572·6e65·7465·7320·736e·6970·7065·7420··ernetes·snippet·
 0003b490:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003b4a0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003b4b0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003b4c0:·6964·3d22·6964·6d39·3230·3022·3e3c·7461··id="idm9200"><ta
 0003b4d0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0003b4e0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0003b4f0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0003b500:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0003b510:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0003b520:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0003b530:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b540:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003b550:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003b560:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 0003b570:·3c2f·7468·3e3c·7464·3e74·7275·653c·2f74··</th><td>true</t
0003b480:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
0003b490:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b4a0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b4b0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b4c0:·6d39·3230·3022·3e3c·7072·653e·3c63·6f64··m9200"><pre><cod 
0003b4d0:·653e·0a76·6172·5f73·7973·7465·6d5f·6372··e>.var_system_cr 
0003b4e0:·7970·746f·5f70·6f6c·6963·793d·273c·6162··ypto_policy='<ab 
0003b4f0:·6272·2074·6974·6c65·3d22·6672·6f6d·2050··br·title="from·P 
0003b500:·726f·6669·6c65·2f72·6566·696e·652d·7661··rofile/refine-va 
0003b510:·6c75·653a·2078·6363·6466·5f6f·7267·2e73··lue:·xccdf_org.s 
0003b520:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten 
0003b530:·745f·7661·6c75·655f·7661·725f·7379·7374··t_value_var_syst 
0003b540:·656d·5f63·7279·7074·6f5f·706f·6c69·6379··em_crypto_policy 
0003b550:·223e·4445·4641·554c·543c·2f61·6262·723e··">DEFAULT</abbr> 
0003b560:·270a·0a0a·7374·6465·7272·5f6f·665f·6361··'...stderr_of_ca 
0003b570:·6c6c·3d24·2875·7064·6174·652d·6372·7970··ll=$(update-cryp 
0003b580:·746f·2d70·6f6c·6963·6965·7320·2d2d·7365··to-policies·--se 
0003b590:·7420·247b·7661·725f·7379·7374·656d·5f63··t·${var_system_c 
0003b5a0:·7279·7074·6f5f·706f·6c69·6379·7d20·3226··rypto_policy}·2& 
0003b5b0:·6774·3b26·616d·703b·3120·2667·743b·202f··gt;&amp;1·&gt;·/ 
0003b5c0:·6465·762f·6e75·6c6c·290a·7263·3d24·3f0a··dev/null).rc=$?. 
0003b5d0:·0a69·6620·7465·7374·2022·2472·6322·203d··.if·test·"$rc"·= 
0003b5e0:·2031·3237·3b20·7468·656e·0a09·6563·686f···127;·then..echo 
0003b5f0:·2022·2473·7464·6572·725f·6f66·5f63·616c···"$stderr_of_cal 
0003b600:·6c22·2026·6774·3b26·616d·703b·320a·0965··l"·&gt;&amp;2..e 
0003b610:·6368·6f20·224d·616b·6520·7375·7265·2074··cho·"Make·sure·t 
0003b620:·6861·7420·7468·6520·7363·7269·7074·2069··hat·the·script·i 
0003b630:·7320·696e·7374·616c·6c65·6420·6f6e·2074··s·installed·on·t 
0003b640:·6865·2072·656d·6564·6961·7465·6420·7379··he·remediated·sy 
0003b650:·7374·656d·2e22·2026·6774·3b26·616d·703b··stem."·&gt;&amp; 
0003b660:·320a·0965·6368·6f20·2253·6565·206f·7574··2..echo·"See·out 
0003b670:·7075·7420·6f66·2074·6865·2027·646e·6620··put·of·the·'dnf· 
0003b680:·7072·6f76·6964·6573·2075·7064·6174·652d··provides·update- 
0003b690:·6372·7970·746f·2d70·6f6c·6963·6965·7327··crypto-policies' 
0003b6a0:·2063·6f6d·6d61·6e64·2220·2667·743b·2661···command"·&gt;&a 
0003b6b0:·6d70·3b32·0a09·6563·686f·2022·746f·2073··mp;2..echo·"to·s 
0003b6c0:·6565·2077·6861·7420·7061·636b·6167·6520··ee·what·package· 
0003b6d0:·746f·2028·7265·2969·6e73·7461·6c6c·2220··to·(re)install"· 
0003b6e0:·2667·743b·2661·6d70·3b32·0a0a·0966·616c··&gt;&amp;2...fal 
0003b6f0:·7365·2020·2320·656e·6420·7769·7468·2061··se··#·end·with·a 
0003b700:·6e20·6572·726f·7220·636f·6465·0a65·6c69··n·error·code.eli 
0003b710:·6620·7465·7374·2022·2472·6322·2021·3d20··f·test·"$rc"·!=· 
0003b720:·303b·2074·6865·6e0a·0965·6368·6f20·2245··0;·then..echo·"E 
0003b730:·7272·6f72·2069·6e76·6f6b·696e·6720·7468··rror·invoking·th 
0003b740:·6520·7570·6461·7465·2d63·7279·7074·6f2d··e·update-crypto- 
0003b750:·706f·6c69·6369·6573·2073·6372·6970·743a··policies·script: 
0003b760:·2024·7374·6465·7272·5f6f·665f·6361·6c6c···$stderr_of_call 
0003b770:·2220·2667·743b·2661·6d70·3b32·0a09·6661··"·&gt;&amp;2..fa 
0003b780:·6c73·6520·2023·2065·6e64·2077·6974·6820··lse··#·end·with· 
0003b790:·616e·2065·7272·6f72·2063·6f64·650a·6669··an·error·code.fi 
0003b7a0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003b7b0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b7c0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b7d0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b7e0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b7f0:·743d·2223·6964·6d39·3230·3222·2074·6162··t="#idm9202"·tab 
0003b800:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b810:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b820:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b830:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b840:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b850:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A 
0003b860:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
0003b870:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b880:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b890:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003b8a0:·643d·2269·646d·3932·3032·223e·3c74·6162··d="idm9202"><tab 
0003b8b0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003b8c0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003b8d0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003b8e0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003b8f0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003b900:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b910:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003b920:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003b930:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b940:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003b950:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003b960:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003b580:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003b970:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003b590:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003b980:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></0003b5a0:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></
0003b990:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003b5b0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003b5c0:·3c63·6f64·653e·2d2d·2d0a·6170·6956·6572··<code>---.apiVer
 0003b5d0:·7369·6f6e·3a20·6d61·6368·696e·6563·6f6e··sion:·machinecon
 0003b5e0:·6669·6775·7261·7469·6f6e·2e6f·7065·6e73··figuration.opens
 0003b5f0:·6869·6674·2e69·6f2f·7631·0a6b·696e·643a··hift.io/v1.kind:
Max diff block lines reached; 12878167/12912859 bytes (99.73%) of diff not shown.
1.11 MB
html2text {}
    
Offset 42, 15 lines modifiedOffset 42, 15 lines modified
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Centro·Criptológico·Nacional·(CCN)·-·STIC·for·Red·Hat·Enterprise42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Centro·Criptológico·Nacional·(CCN)·-·STIC·for·Red·Hat·Enterprise
43 ··············Linux·9·-·Advanced43 ··············Linux·9·-·Advanced
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ccn_advanced44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ccn_advanced
45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
46 ····*·cpe:/o:redhat:enterprise_linux:946 ····*·cpe:/o:redhat:enterprise_linux:9
47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
48 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8448 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
54 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n54 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
55 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s55 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
56 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s56 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 104, 33 lines modifiedOffset 104, 39 lines modified
104 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1104 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
105 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174105 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
106 ·············_\x8c_\x8c_\x8n······A.5.SEC-RHEL4106 ·············_\x8c_\x8c_\x8n······A.5.SEC-RHEL4
107 ·············_\x8c_\x8i_\x8s······1.6.1107 ·············_\x8c_\x8i_\x8s······1.6.1
108 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7108 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7
109 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-09-671010,·RHEL-09-672030,·RHEL-09-672045109 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-09-671010,·RHEL-09-672030,·RHEL-09-672045
110 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule,·SV-258238r926701_rule,·SV-258241r926710_rule110 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule,·SV-258238r926701_rule,·SV-258241r926710_rule
111 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8111 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
  
112 var_system_crypto_policy='DEFAULT' 
  
  
113 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
114 rc=$? 
  
115 if·test·"$rc"·=·127;·then 
116 »       echo·"$stderr_of_call"·>&2 
117 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
118 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
119 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
120 »       false··#·end·with·an·error·code 
121 elif·test·"$rc"·!=·0;·then 
122 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
123 »       false··#·end·with·an·error·code 
124 fi112 C.Co.om.mp.pl.le.ex.xi.it.ty.y:.:·low
 113 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 114 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 115 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 116 ---
 117 apiVersion:·machineconfiguration.openshift.io/v1
 118 kind:·MachineConfig
 119 spec:
 120 ··config:
 121 ····ignition:
 122 ······version:·3.1.0
 123 ····systemd:
 124 ······units:
 125 ········-·name:·configure-crypto-policy.service
 126 ··········enabled:·true
 127 ··········contents:·|
 128 ············[Unit]
 129 ············Before=kubelet.service
 130 ············[Service]
 131 ············Type=oneshot
 132 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 133 ············RemainAfterExit=yes
 134 ············[Install]
 135 ············WantedBy=multi-user.target
125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
130 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable141 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
131 ··set_fact:142 ··set_fact:
Offset 181, 39 lines modifiedOffset 187, 33 lines modified
181 ··-·PCI-DSSv4-2.2.7187 ··-·PCI-DSSv4-2.2.7
182 ··-·configure_crypto_policy188 ··-·configure_crypto_policy
183 ··-·high_severity189 ··-·high_severity
184 ··-·low_complexity190 ··-·low_complexity
185 ··-·low_disruption191 ··-·low_disruption
186 ··-·no_reboot_needed192 ··-·no_reboot_needed
187 ··-·restrict_strategy193 ··-·restrict_strategy
188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
  
 195 var_system_crypto_policy='DEFAULT'
  
  
 196 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null)
 197 rc=$?
  
 198 if·test·"$rc"·=·127;·then
 199 »       echo·"$stderr_of_call"·>&2
 200 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2
 201 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2
 202 »       echo·"to·see·what·package·to·(re)install"·>&2
  
 203 »       false··#·end·with·an·error·code
 204 elif·test·"$rc"·!=·0;·then
 205 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
 206 »       false··#·end·with·an·error·code
 207 fi
189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
193 --- 
194 apiVersion:·machineconfiguration.openshift.io/v1 
195 kind:·MachineConfig 
196 spec: 
197 ··config: 
198 ····ignition: 
199 ······version:·3.1.0 
200 ····systemd: 
201 ······units: 
202 ········-·name:·configure-crypto-policy.service 
203 ··········enabled:·true 
204 ··········contents:·| 
205 ············[Unit] 
206 ············Before=kubelet.service 
207 ············[Service] 
208 ············Type=oneshot 
209 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
210 ············RemainAfterExit=yes 
211 ············[Install] 
212 ············WantedBy=multi-user.target 
213 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*208 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
214 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.209 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
215 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.210 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
216 Severity: ···medium211 Severity: ···medium
Max diff block lines reached; 1162379/1168337 bytes (99.49%) of diff not shown.
9.25 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-ccn_basic.html
    
Offset 14302, 15 lines modifiedOffset 14302, 15 lines modified
00037dd0:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·00037dd0:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·
00037de0:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong00037de0:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong
00037df0:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>00037df0:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>
00037e00:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str00037e00:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str
00037e10:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron00037e10:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron
00037e20:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············00037e20:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············
00037e30:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·2000037e30:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·20
00037e40:·3236·2d30·312d·3038·290a·2020·2020·2020··26-01-08).······00037e40:·3234·2d31·322d·3037·290a·2020·2020·2020··24-12-07).······
00037e50:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><00037e50:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><
00037e60:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta00037e60:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta
00037e70:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<00037e70:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<
00037e80:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h00037e80:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h
00037e90:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.00037e90:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.
00037ea0:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte00037ea0:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte
00037eb0:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"00037eb0:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"
Offset 15129, 252 lines modifiedOffset 15129, 252 lines modified
0003b180:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b180:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b190:·3d22·2369·646d·3932·3030·2220·7461·6269··="#idm9200"·tabi0003b190:·3d22·2369·646d·3932·3030·2220·7461·6269··="#idm9200"·tabi
0003b1a0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b1a0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b1b0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b1b0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b1c0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b1c0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b1d0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b1d0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b1e0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b1e0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b1f0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh0003b1f0:·223e·5265·6d65·6469·6174·696f·6e20·4b75··">Remediation·Ku
0003b200:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</ 
0003b210:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003b220:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003b230:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003b240:·646d·3932·3030·223e·3c70·7265·3e3c·636f··dm9200"><pre><co 
0003b250:·6465·3e0a·7661·725f·7379·7374·656d·5f63··de>.var_system_c 
0003b260:·7279·7074·6f5f·706f·6c69·6379·3d27·3c61··rypto_policy='<a 
0003b270:·6262·7220·7469·746c·653d·2266·726f·6d20··bbr·title="from· 
0003b280:·5072·6f66·696c·652f·7265·6669·6e65·2d76··Profile/refine-v 
0003b290:·616c·7565·3a20·7863·6364·665f·6f72·672e··alue:·xccdf_org. 
0003b2a0:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte 
0003b2b0:·6e74·5f76·616c·7565·5f76·6172·5f73·7973··nt_value_var_sys 
0003b2c0:·7465·6d5f·6372·7970·746f·5f70·6f6c·6963··tem_crypto_polic 
0003b2d0:·7922·3e44·4546·4155·4c54·3c2f·6162·6272··y">DEFAULT</abbr 
0003b2e0:·3e27·0a0a·0a73·7464·6572·725f·6f66·5f63··>'...stderr_of_c0003b200:·6265·726e·6574·6573·2073·6e69·7070·6574··bernetes·snippet
 0003b210:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003b220:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003b230:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003b240:·2069·643d·2269·646d·3932·3030·223e·3c74···id="idm9200"><t
 0003b250:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003b260:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0003b270:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0003b280:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003b290:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0003b2a0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003b2b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b2c0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0003b2d0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b2e0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0003b2f0:·3a3c·2f74·683e·3c74·643e·7472·7565·3c2f··:</th><td>true</
 0003b300:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b310:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0003b320:·643e·7265·7374·7269·6374·3c2f·7464·3e3c··d>restrict</td><
 0003b330:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003b340:·3e3c·636f·6465·3e2d·2d2d·0a61·7069·5665··><code>---.apiVe
 0003b350:·7273·696f·6e3a·206d·6163·6869·6e65·636f··rsion:·machineco
 0003b360:·6e66·6967·7572·6174·696f·6e2e·6f70·656e··nfiguration.open
 0003b370:·7368·6966·742e·696f·2f76·310a·6b69·6e64··shift.io/v1.kind
 0003b380:·3a20·4d61·6368·696e·6543·6f6e·6669·670a··:·MachineConfig.
 0003b390:·7370·6563·3a0a·2020·636f·6e66·6967·3a0a··spec:.··config:.
 0003b3a0:·2020·2020·6967·6e69·7469·6f6e·3a0a·2020······ignition:.··
 0003b3b0:·2020·2020·7665·7273·696f·6e3a·2033·2e31······version:·3.1
 0003b3c0:·2e30·0a20·2020·2073·7973·7465·6d64·3a0a··.0.····systemd:.
 0003b3d0:·2020·2020·2020·756e·6974·733a·0a20·2020········units:.···
 0003b3e0:·2020·2020·202d·206e·616d·653a·2063·6f6e·······-·name:·con
 0003b3f0:·6669·6775·7265·2d63·7279·7074·6f2d·706f··figure-crypto-po
 0003b400:·6c69·6379·2e73·6572·7669·6365·0a20·2020··licy.service.···
 0003b410:·2020·2020·2020·2065·6e61·626c·6564·3a20·········enabled:·
 0003b420:·7472·7565·0a20·2020·2020·2020·2020·2063··true.··········c
 0003b430:·6f6e·7465·6e74·733a·207c·0a20·2020·2020··ontents:·|.·····
 0003b440:·2020·2020·2020·205b·556e·6974·5d0a·2020·········[Unit].··
 0003b450:·2020·2020·2020·2020·2020·4265·666f·7265············Before
 0003b460:·3d6b·7562·656c·6574·2e73·6572·7669·6365··=kubelet.service
 0003b470:·0a20·2020·2020·2020·2020·2020·205b·5365··.············[Se
 0003b480:·7276·6963·655d·0a20·2020·2020·2020·2020··rvice].·········
 0003b490:·2020·2054·7970·653d·6f6e·6573·686f·740a·····Type=oneshot.
 0003b4a0:·2020·2020·2020·2020·2020·2020·4578·6563··············Exec
0003b2f0:·616c·6c3d·2428·7570·6461·7465·2d63·7279··all=$(update-cry0003b4b0:·5374·6172·743d·7570·6461·7465·2d63·7279··Start=update-cry
0003b300:·7074·6f2d·706f·6c69·6369·6573·202d·2d73··pto-policies·--s0003b4c0:·7074·6f2d·706f·6c69·6369·6573·202d·2d73··pto-policies·--s
0003b310:·6574·2024·7b76·6172·5f73·7973·7465·6d5f··et·${var_system_0003b4d0:·6574·207b·7b2e·7661·725f·7379·7374·656d··et·{{.var_system
 0003b4e0:·5f63·7279·7074·6f5f·706f·6c69·6379·7d7d··_crypto_policy}}
 0003b4f0:·0a20·2020·2020·2020·2020·2020·2052·656d··.············Rem
 0003b500:·6169·6e41·6674·6572·4578·6974·3d79·6573··ainAfterExit=yes
 0003b510:·0a20·2020·2020·2020·2020·2020·205b·496e··.············[In
 0003b520:·7374·616c·6c5d·0a20·2020·2020·2020·2020··stall].·········
 0003b530:·2020·2057·616e·7465·6442·793d·6d75·6c74·····WantedBy=mult
 0003b540:·692d·7573·6572·2e74·6172·6765·740a·3c2f··i-user.target.</
 0003b550:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003b560:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003b570:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003b580:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003b590:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003b5a0:·2369·646d·3932·3031·2220·7461·6269·6e64··#idm9201"·tabind
 0003b5b0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003b5c0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003b5d0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003b5e0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003b5f0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003b600:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi
 0003b610:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...<
 0003b620:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003b630:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003b640:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003b650:·6964·6d39·3230·3122·3e3c·7461·626c·6520··idm9201"><table·
 0003b660:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003b670:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003b680:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003b690:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003b6a0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003b6b0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003b6c0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 0003b6d0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 0003b6e0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003b6f0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 0003b700:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
 0003b710:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003b720:·7465·6779·3a3c·2f74·683e·3c74·643e·7265··tegy:</th><td>re
 0003b730:·7374·7269·6374·3c2f·7464·3e3c·2f74·723e··strict</td></tr>
 0003b740:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003b750:·6465·3e2d·206e·616d·653a·2058·4343·4446··de>-·name:·XCCDF
 0003b760:·2056·616c·7565·2076·6172·5f73·7973·7465···Value·var_syste
0003b320:·6372·7970·746f·5f70·6f6c·6963·797d·2032··crypto_policy}·20003b770:·6d5f·6372·7970·746f·5f70·6f6c·6963·7920··m_crypto_policy·
0003b330:·2667·743b·2661·6d70·3b31·2026·6774·3b20··&gt;&amp;1·&gt;· 
Max diff block lines reached; 8787268/8821822 bytes (99.61%) of diff not shown.
853 KB
html2text {}
    
Offset 42, 15 lines modifiedOffset 42, 15 lines modified
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Centro·Criptológico·Nacional·(CCN)·-·STIC·for·Red·Hat·Enterprise42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Centro·Criptológico·Nacional·(CCN)·-·STIC·for·Red·Hat·Enterprise
43 ··············Linux·9·-·Basic43 ··············Linux·9·-·Basic
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ccn_basic44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ccn_basic
45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
46 ····*·cpe:/o:redhat:enterprise_linux:946 ····*·cpe:/o:redhat:enterprise_linux:9
47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
48 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8448 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
54 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n54 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
55 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s55 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
56 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s56 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 96, 33 lines modifiedOffset 96, 39 lines modified
96 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.196 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
97 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-0017497 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
98 ·············_\x8c_\x8c_\x8n······A.5.SEC-RHEL498 ·············_\x8c_\x8c_\x8n······A.5.SEC-RHEL4
99 ·············_\x8c_\x8i_\x8s······1.6.199 ·············_\x8c_\x8i_\x8s······1.6.1
100 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7100 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7
101 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-09-671010,·RHEL-09-672030,·RHEL-09-672045101 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-09-671010,·RHEL-09-672030,·RHEL-09-672045
102 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule,·SV-258238r926701_rule,·SV-258241r926710_rule102 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule,·SV-258238r926701_rule,·SV-258241r926710_rule
103 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8103 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
  
104 var_system_crypto_policy='DEFAULT' 
  
  
105 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
106 rc=$? 
  
107 if·test·"$rc"·=·127;·then 
108 »       echo·"$stderr_of_call"·>&2 
109 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
110 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
111 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
112 »       false··#·end·with·an·error·code 
113 elif·test·"$rc"·!=·0;·then 
114 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
115 »       false··#·end·with·an·error·code 
116 fi104 C.Co.om.mp.pl.le.ex.xi.it.ty.y:.:·low
 105 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 106 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 107 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 108 ---
 109 apiVersion:·machineconfiguration.openshift.io/v1
 110 kind:·MachineConfig
 111 spec:
 112 ··config:
 113 ····ignition:
 114 ······version:·3.1.0
 115 ····systemd:
 116 ······units:
 117 ········-·name:·configure-crypto-policy.service
 118 ··········enabled:·true
 119 ··········contents:·|
 120 ············[Unit]
 121 ············Before=kubelet.service
 122 ············[Service]
 123 ············Type=oneshot
 124 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 125 ············RemainAfterExit=yes
 126 ············[Install]
 127 ············WantedBy=multi-user.target
117 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
118 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
119 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
120 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
121 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
122 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable133 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
123 ··set_fact:134 ··set_fact:
Offset 173, 39 lines modifiedOffset 179, 33 lines modified
173 ··-·PCI-DSSv4-2.2.7179 ··-·PCI-DSSv4-2.2.7
174 ··-·configure_crypto_policy180 ··-·configure_crypto_policy
175 ··-·high_severity181 ··-·high_severity
176 ··-·low_complexity182 ··-·low_complexity
177 ··-·low_disruption183 ··-·low_disruption
178 ··-·no_reboot_needed184 ··-·no_reboot_needed
179 ··-·restrict_strategy185 ··-·restrict_strategy
180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
  
 187 var_system_crypto_policy='DEFAULT'
  
  
 188 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null)
 189 rc=$?
  
 190 if·test·"$rc"·=·127;·then
 191 »       echo·"$stderr_of_call"·>&2
 192 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2
 193 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2
 194 »       echo·"to·see·what·package·to·(re)install"·>&2
  
 195 »       false··#·end·with·an·error·code
 196 elif·test·"$rc"·!=·0;·then
 197 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
 198 »       false··#·end·with·an·error·code
 199 fi
181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
185 --- 
186 apiVersion:·machineconfiguration.openshift.io/v1 
187 kind:·MachineConfig 
188 spec: 
189 ··config: 
190 ····ignition: 
191 ······version:·3.1.0 
192 ····systemd: 
193 ······units: 
194 ········-·name:·configure-crypto-policy.service 
195 ··········enabled:·true 
196 ··········contents:·| 
197 ············[Unit] 
198 ············Before=kubelet.service 
199 ············[Service] 
200 ············Type=oneshot 
201 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
202 ············RemainAfterExit=yes 
203 ············[Install] 
204 ············WantedBy=multi-user.target 
205 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*200 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
206 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.201 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
207 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.202 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
208 Severity: ···medium203 Severity: ···medium
Max diff block lines reached; 867126/873076 bytes (99.32%) of diff not shown.
10.6 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-ccn_intermediate.html
    
Offset 14303, 16 lines modifiedOffset 14303, 16 lines modified
00037de0:·7369·6f6e·2048·6973·746f·7279·3c2f·6832··sion·History</h200037de0:·7369·6f6e·2048·6973·746f·7279·3c2f·6832··sion·History</h2
00037df0:·3e3c·703e·4375·7272·656e·7420·7665·7273··><p>Current·vers00037df0:·3e3c·703e·4375·7272·656e·7420·7665·7273··><p>Current·vers
00037e00:·696f·6e3a·203c·7374·726f·6e67·3e30·2e31··ion:·<strong>0.100037e00:·696f·6e3a·203c·7374·726f·6e67·3e30·2e31··ion:·<strong>0.1
00037e10:·2e37·343c·2f73·7472·6f6e·673e·3c2f·703e··.74</strong></p>00037e10:·2e37·343c·2f73·7472·6f6e·673e·3c2f·703e··.74</strong></p>
00037e20:·3c75·6c3e·3c6c·693e·3c73·7472·6f6e·673e··<ul><li><strong>00037e20:·3c75·6c3e·3c6c·693e·3c73·7472·6f6e·673e··<ul><li><strong>
00037e30:·6472·6166·743c·2f73·7472·6f6e·673e·0a20··draft</strong>.·00037e30:·6472·6166·743c·2f73·7472·6f6e·673e·0a20··draft</strong>.·
00037e40:·2020·2020·2020·2020·2020·2020·2020·2020··················00037e40:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037e50:·2020·2028·6173·206f·6620·3230·3236·2d30·····(as·of·2026-000037e50:·2020·2028·6173·206f·6620·3230·3234·2d31·····(as·of·2024-1
00037e60:·312d·3038·290a·2020·2020·2020·2020·2020··1-08).··········00037e60:·322d·3037·290a·2020·2020·2020·2020·2020··2-07).··········
00037e70:·2020·2020·2020·3c2f·6c69·3e3c·2f75·6c3e········</li></ul>00037e70:·2020·2020·2020·3c2f·6c69·3e3c·2f75·6c3e········</li></ul>
00037e80:·3c2f·6469·763e·3c68·323e·5461·626c·6520··</div><h2>Table·00037e80:·3c2f·6469·763e·3c68·323e·5461·626c·6520··</div><h2>Table·
00037e90:·6f66·2043·6f6e·7465·6e74·733c·2f68·323e··of·Contents</h2>00037e90:·6f66·2043·6f6e·7465·6e74·733c·2f68·323e··of·Contents</h2>
00037ea0:·3c6f·6c3e·3c6c·693e·3c61·2068·7265·663d··<ol><li><a·href=00037ea0:·3c6f·6c3e·3c6c·693e·3c61·2068·7265·663d··<ol><li><a·href=
00037eb0:·2223·7863·6364·665f·6f72·672e·7373·6770··"#xccdf_org.ssgp00037eb0:·2223·7863·6364·665f·6f72·672e·7373·6770··"#xccdf_org.ssgp
00037ec0:·726f·6a65·6374·2e63·6f6e·7465·6e74·5f67··roject.content_g00037ec0:·726f·6a65·6374·2e63·6f6e·7465·6e74·5f67··roject.content_g
00037ed0:·726f·7570·5f73·7973·7465·6d22·3e53·7973··roup_system">Sys00037ed0:·726f·7570·5f73·7973·7465·6d22·3e53·7973··roup_system">Sys
Offset 15170, 252 lines modifiedOffset 15170, 252 lines modified
0003b410:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b410:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003b420:·2223·6964·6d39·3230·3022·2074·6162·696e··"#idm9200"·tabin0003b420:·2223·6964·6d39·3230·3022·2074·6162·696e··"#idm9200"·tabin
0003b430:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b430:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b440:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b440:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b450:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b450:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b460:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b460:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b470:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b470:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b480:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She0003b480:·3e52·656d·6564·6961·7469·6f6e·204b·7562··>Remediation·Kub
 0003b490:·6572·6e65·7465·7320·736e·6970·7065·7420··ernetes·snippet·
 0003b4a0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003b4b0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003b4c0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003b4d0:·6964·3d22·6964·6d39·3230·3022·3e3c·7461··id="idm9200"><ta
 0003b4e0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0003b4f0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0003b500:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0003b510:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0003b520:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0003b530:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0003b540:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b550:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003b560:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003b570:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 0003b580:·3c2f·7468·3e3c·7464·3e74·7275·653c·2f74··</th><td>true</t
0003b490:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
0003b4a0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b4b0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b4c0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b4d0:·6d39·3230·3022·3e3c·7072·653e·3c63·6f64··m9200"><pre><cod 
0003b4e0:·653e·0a76·6172·5f73·7973·7465·6d5f·6372··e>.var_system_cr 
0003b4f0:·7970·746f·5f70·6f6c·6963·793d·273c·6162··ypto_policy='<ab 
0003b500:·6272·2074·6974·6c65·3d22·6672·6f6d·2050··br·title="from·P 
0003b510:·726f·6669·6c65·2f72·6566·696e·652d·7661··rofile/refine-va 
0003b520:·6c75·653a·2078·6363·6466·5f6f·7267·2e73··lue:·xccdf_org.s 
0003b530:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten 
0003b540:·745f·7661·6c75·655f·7661·725f·7379·7374··t_value_var_syst 
0003b550:·656d·5f63·7279·7074·6f5f·706f·6c69·6379··em_crypto_policy 
0003b560:·223e·4445·4641·554c·543c·2f61·6262·723e··">DEFAULT</abbr> 
0003b570:·270a·0a0a·7374·6465·7272·5f6f·665f·6361··'...stderr_of_ca 
0003b580:·6c6c·3d24·2875·7064·6174·652d·6372·7970··ll=$(update-cryp 
0003b590:·746f·2d70·6f6c·6963·6965·7320·2d2d·7365··to-policies·--se 
0003b5a0:·7420·247b·7661·725f·7379·7374·656d·5f63··t·${var_system_c 
0003b5b0:·7279·7074·6f5f·706f·6c69·6379·7d20·3226··rypto_policy}·2& 
0003b5c0:·6774·3b26·616d·703b·3120·2667·743b·202f··gt;&amp;1·&gt;·/ 
0003b5d0:·6465·762f·6e75·6c6c·290a·7263·3d24·3f0a··dev/null).rc=$?. 
0003b5e0:·0a69·6620·7465·7374·2022·2472·6322·203d··.if·test·"$rc"·= 
0003b5f0:·2031·3237·3b20·7468·656e·0a09·6563·686f···127;·then..echo 
0003b600:·2022·2473·7464·6572·725f·6f66·5f63·616c···"$stderr_of_cal 
0003b610:·6c22·2026·6774·3b26·616d·703b·320a·0965··l"·&gt;&amp;2..e 
0003b620:·6368·6f20·224d·616b·6520·7375·7265·2074··cho·"Make·sure·t 
0003b630:·6861·7420·7468·6520·7363·7269·7074·2069··hat·the·script·i 
0003b640:·7320·696e·7374·616c·6c65·6420·6f6e·2074··s·installed·on·t 
0003b650:·6865·2072·656d·6564·6961·7465·6420·7379··he·remediated·sy 
0003b660:·7374·656d·2e22·2026·6774·3b26·616d·703b··stem."·&gt;&amp; 
0003b670:·320a·0965·6368·6f20·2253·6565·206f·7574··2..echo·"See·out 
0003b680:·7075·7420·6f66·2074·6865·2027·646e·6620··put·of·the·'dnf· 
0003b690:·7072·6f76·6964·6573·2075·7064·6174·652d··provides·update- 
0003b6a0:·6372·7970·746f·2d70·6f6c·6963·6965·7327··crypto-policies' 
0003b6b0:·2063·6f6d·6d61·6e64·2220·2667·743b·2661···command"·&gt;&a 
0003b6c0:·6d70·3b32·0a09·6563·686f·2022·746f·2073··mp;2..echo·"to·s 
0003b6d0:·6565·2077·6861·7420·7061·636b·6167·6520··ee·what·package· 
0003b6e0:·746f·2028·7265·2969·6e73·7461·6c6c·2220··to·(re)install"· 
0003b6f0:·2667·743b·2661·6d70·3b32·0a0a·0966·616c··&gt;&amp;2...fal 
0003b700:·7365·2020·2320·656e·6420·7769·7468·2061··se··#·end·with·a 
0003b710:·6e20·6572·726f·7220·636f·6465·0a65·6c69··n·error·code.eli 
0003b720:·6620·7465·7374·2022·2472·6322·2021·3d20··f·test·"$rc"·!=· 
0003b730:·303b·2074·6865·6e0a·0965·6368·6f20·2245··0;·then..echo·"E 
0003b740:·7272·6f72·2069·6e76·6f6b·696e·6720·7468··rror·invoking·th 
0003b750:·6520·7570·6461·7465·2d63·7279·7074·6f2d··e·update-crypto- 
0003b760:·706f·6c69·6369·6573·2073·6372·6970·743a··policies·script: 
0003b770:·2024·7374·6465·7272·5f6f·665f·6361·6c6c···$stderr_of_call 
0003b780:·2220·2667·743b·2661·6d70·3b32·0a09·6661··"·&gt;&amp;2..fa 
0003b790:·6c73·6520·2023·2065·6e64·2077·6974·6820··lse··#·end·with· 
0003b7a0:·616e·2065·7272·6f72·2063·6f64·650a·6669··an·error·code.fi 
0003b7b0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003b7c0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b7d0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b7e0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b7f0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b800:·743d·2223·6964·6d39·3230·3222·2074·6162··t="#idm9202"·tab 
0003b810:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b820:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b830:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b840:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b850:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b860:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A 
0003b870:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
0003b880:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b890:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b8a0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003b8b0:·643d·2269·646d·3932·3032·223e·3c74·6162··d="idm9202"><tab 
0003b8c0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003b8d0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003b8e0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003b8f0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003b900:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003b910:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b920:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003b930:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003b940:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b950:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003b960:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003b970:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003b590:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003b980:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003b5a0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003b990:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></0003b5b0:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></
0003b9a0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003b5c0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003b5d0:·3c63·6f64·653e·2d2d·2d0a·6170·6956·6572··<code>---.apiVer
 0003b5e0:·7369·6f6e·3a20·6d61·6368·696e·6563·6f6e··sion:·machinecon
 0003b5f0:·6669·6775·7261·7469·6f6e·2e6f·7065·6e73··figuration.opens
 0003b600:·6869·6674·2e69·6f2f·7631·0a6b·696e·643a··hift.io/v1.kind:
Max diff block lines reached; 10040730/10075422 bytes (99.66%) of diff not shown.
1.02 MB
html2text {}
    
Offset 42, 15 lines modifiedOffset 42, 15 lines modified
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Centro·Criptológico·Nacional·(CCN)·-·STIC·for·Red·Hat·Enterprise42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Centro·Criptológico·Nacional·(CCN)·-·STIC·for·Red·Hat·Enterprise
43 ··············Linux·9·-·Intermediate43 ··············Linux·9·-·Intermediate
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ccn_intermediate44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ccn_intermediate
45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
46 ····*·cpe:/o:redhat:enterprise_linux:946 ····*·cpe:/o:redhat:enterprise_linux:9
47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
48 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8448 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
54 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n54 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
55 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s55 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
56 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s56 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 104, 33 lines modifiedOffset 104, 39 lines modified
104 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1104 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
105 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174105 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
106 ·············_\x8c_\x8c_\x8n······A.5.SEC-RHEL4106 ·············_\x8c_\x8c_\x8n······A.5.SEC-RHEL4
107 ·············_\x8c_\x8i_\x8s······1.6.1107 ·············_\x8c_\x8i_\x8s······1.6.1
108 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7108 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7
109 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-09-671010,·RHEL-09-672030,·RHEL-09-672045109 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-09-671010,·RHEL-09-672030,·RHEL-09-672045
110 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule,·SV-258238r926701_rule,·SV-258241r926710_rule110 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule,·SV-258238r926701_rule,·SV-258241r926710_rule
111 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8111 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
  
112 var_system_crypto_policy='DEFAULT' 
  
  
113 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
114 rc=$? 
  
115 if·test·"$rc"·=·127;·then 
116 »       echo·"$stderr_of_call"·>&2 
117 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
118 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
119 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
120 »       false··#·end·with·an·error·code 
121 elif·test·"$rc"·!=·0;·then 
122 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
123 »       false··#·end·with·an·error·code 
124 fi112 C.Co.om.mp.pl.le.ex.xi.it.ty.y:.:·low
 113 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 114 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 115 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 116 ---
 117 apiVersion:·machineconfiguration.openshift.io/v1
 118 kind:·MachineConfig
 119 spec:
 120 ··config:
 121 ····ignition:
 122 ······version:·3.1.0
 123 ····systemd:
 124 ······units:
 125 ········-·name:·configure-crypto-policy.service
 126 ··········enabled:·true
 127 ··········contents:·|
 128 ············[Unit]
 129 ············Before=kubelet.service
 130 ············[Service]
 131 ············Type=oneshot
 132 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 133 ············RemainAfterExit=yes
 134 ············[Install]
 135 ············WantedBy=multi-user.target
125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
130 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable141 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
131 ··set_fact:142 ··set_fact:
Offset 181, 39 lines modifiedOffset 187, 33 lines modified
181 ··-·PCI-DSSv4-2.2.7187 ··-·PCI-DSSv4-2.2.7
182 ··-·configure_crypto_policy188 ··-·configure_crypto_policy
183 ··-·high_severity189 ··-·high_severity
184 ··-·low_complexity190 ··-·low_complexity
185 ··-·low_disruption191 ··-·low_disruption
186 ··-·no_reboot_needed192 ··-·no_reboot_needed
187 ··-·restrict_strategy193 ··-·restrict_strategy
188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
  
 195 var_system_crypto_policy='DEFAULT'
  
  
 196 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null)
 197 rc=$?
  
 198 if·test·"$rc"·=·127;·then
 199 »       echo·"$stderr_of_call"·>&2
 200 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2
 201 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2
 202 »       echo·"to·see·what·package·to·(re)install"·>&2
  
 203 »       false··#·end·with·an·error·code
 204 elif·test·"$rc"·!=·0;·then
 205 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
 206 »       false··#·end·with·an·error·code
 207 fi
189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
193 --- 
194 apiVersion:·machineconfiguration.openshift.io/v1 
195 kind:·MachineConfig 
196 spec: 
197 ··config: 
198 ····ignition: 
199 ······version:·3.1.0 
200 ····systemd: 
201 ······units: 
202 ········-·name:·configure-crypto-policy.service 
203 ··········enabled:·true 
204 ··········contents:·| 
205 ············[Unit] 
206 ············Before=kubelet.service 
207 ············[Service] 
208 ············Type=oneshot 
209 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
210 ············RemainAfterExit=yes 
211 ············[Install] 
212 ············WantedBy=multi-user.target 
213 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*208 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
214 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.209 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
215 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.210 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
216 Severity: ···medium211 Severity: ···medium
Max diff block lines reached; 1059810/1065776 bytes (99.44%) of diff not shown.
26.3 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-cis.html
    
Offset 14299, 15 lines modifiedOffset 14299, 15 lines modified
00037da0:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr00037da0:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr
00037db0:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st00037db0:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st
00037dc0:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str00037dc0:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str
00037dd0:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>00037dd0:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>
00037de0:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s00037de0:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s
00037df0:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········00037df0:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········
00037e00:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o00037e00:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o
00037e10:·6620·3230·3236·2d30·312d·3038·290a·2020··f·2026-01-08).··00037e10:·6620·3230·3234·2d31·322d·3037·290a·2020··f·2024-12-07).··
00037e20:·2020·2020·2020·2020·2020·2020·2020·3c2f················</00037e20:·2020·2020·2020·2020·2020·2020·2020·3c2f················</
00037e30:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h00037e30:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h
00037e40:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte00037e40:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte
00037e50:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>00037e50:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>
00037e60:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_00037e60:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_
00037e70:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c00037e70:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c
00037e80:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys00037e80:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys
Offset 15158, 237 lines modifiedOffset 15158, 237 lines modified
0003b350:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003b350:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b360:·6964·6d38·3430·3622·2074·6162·696e·6465··idm8406"·tabinde0003b360:·6964·6d38·3430·3622·2074·6162·696e·6465··idm8406"·tabinde
0003b370:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b370:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003b380:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003b380:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003b390:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003b390:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003b3a0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003b3a0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003b3b0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003b3b0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003b3c0:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe0003b3c0:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco
0003b3d0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a0003b3d0:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...<
0003b3e0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003b3e0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003b3f0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003b3f0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003b400:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003b400:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
0003b410:·6d38·3430·3622·3e3c·7461·626c·6520·636c··m8406"><table·cl0003b410:·6964·6d38·3430·3622·3e3c·7461·626c·6520··idm8406"><table·
0003b420:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003b420:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003b430:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003b430:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003b440:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003b440:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003b450:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003b450:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0003b460:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003b460:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0003b470:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003b470:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003b480:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003b480:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003b490:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003b490:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003b4a0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003b4a0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003b4b0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><0003b4b0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
0003b4c0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t0003b4c0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
0003b4d0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate0003b4d0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
0003b4e0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab0003b4e0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
0003b4f0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta0003b4f0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
0003b500:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i0003b500:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003b510:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add=
 0003b520:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr
 0003b530:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 0003b540:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 0003b550:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 0003b560:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 0003b570:·6172·6765·743d·2223·6964·6d38·3430·3722··arget="#idm8407"
 0003b580:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 0003b590:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 0003b5a0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 0003b5b0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 0003b5c0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 0003b5d0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003b5e0:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe
 0003b5f0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003b600:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003b610:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003b620:·2220·6964·3d22·6964·6d38·3430·3722·3e3c··"·id="idm8407"><
 0003b630:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003b640:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003b650:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003b660:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003b670:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003b510:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a 
0003b520:·6964·650a·0a63·6c61·7373·2069·6e73·7461··ide..class·insta 
0003b530:·6c6c·5f61·6964·6520·7b0a·2020·7061·636b··ll_aide·{.··pack 
0003b540:·6167·6520·7b20·2761·6964·6527·3a0a·2020··age·{·'aide':.·· 
0003b550:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·' 
0003b560:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}. 
0003b570:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre>< 
0003b580:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003b590:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003b5a0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003b5b0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003b5c0:·6574·3d22·2369·646d·3834·3037·2220·7461··et="#idm8407"·ta 
0003b5d0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003b5e0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003b5f0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003b600:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003b610:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003b620:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003b630:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
0003b640:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b650:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b660:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b670:·2269·646d·3834·3037·223e·3c74·6162·6c65··"idm8407"><table 
0003b680:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003b690:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003b6a0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003b6b0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003b6c0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003b6d0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b6e0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003b6f0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003b700:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b710:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003b720:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003b730:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003b740:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003b680:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003b750:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0003b760:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003b770:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation· 
0003b780:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on 
0003b790:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl 
0003b7a0:·6174·666f·726d·730a·6966·205b·2021·202d··atforms.if·[·!·- 
0003b7b0:·6620·2f2e·646f·636b·6572·656e·7620·5d20··f·/.dockerenv·]· 
0003b7c0:·2661·6d70·3b26·616d·703b·205b·2021·202d··&amp;&amp;·[·!·- 
0003b7d0:·6620·2f72·756e·2f2e·636f·6e74·6169·6e65··f·/run/.containe 
0003b7e0:·7265·6e76·205d·3b20·7468·656e·0a0a·6966··renv·];·then..if 
0003b7f0:·2021·2072·706d·202d·7120·2d2d·7175·6965···!·rpm·-q·--quie 
0003b800:·7420·2261·6964·6522·203b·2074·6865·6e0a··t·"aide"·;·then. 
0003b810:·2020·2020·646e·6620·696e·7374·616c·6c20······dnf·install· 
0003b820:·2d79·2022·6169·6465·220a·6669·0a0a·656c··-y·"aide".fi..el 
0003b830:·7365·0a20·2020·2026·6774·3b26·616d·703b··se.····&gt;&amp; 
0003b840:·3220·6563·686f·2027·5265·6d65·6469·6174··2·echo·'Remediat 
0003b850:·696f·6e20·6973·206e·6f74·2061·7070·6c69··ion·is·not·appli 
0003b860:·6361·626c·652c·206e·6f74·6869·6e67·2077··cable,·nothing·w 
0003b870:·6173·2064·6f6e·6527·0a66·690a·3c2f·636f··as·done'.fi.</co 
0003b880:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003b890:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003b8a0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003b8b0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003b8c0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
Max diff block lines reached; 25168223/25200707 bytes (99.87%) of diff not shown.
2.31 MB
html2text {}
Max HTML report size reached
11.5 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-cis_server_l1.html
    
Offset 14299, 16 lines modifiedOffset 14299, 16 lines modified
00037da0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00037da0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00037db0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00037db0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00037dc0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000037dc0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00037dd0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></00037dd0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
00037de0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00037de0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00037df0:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00037df0:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00037e00:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037e00:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037e10:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600037e10:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
00037e20:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········00037e20:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00037e30:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00037e30:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00037e40:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00037e40:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00037e50:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00037e50:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00037e60:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00037e60:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00037e70:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00037e70:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00037e80:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00037e80:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00037e90:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00037e90:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
Offset 15127, 236 lines modifiedOffset 15127, 236 lines modified
0003b160:·612d·7461·7267·6574·3d22·2369·646d·3834··a-target="#idm840003b160:·612d·7461·7267·6574·3d22·2369·646d·3834··a-target="#idm84
0003b170:·3036·2220·7461·6269·6e64·6578·3d22·3022··06"·tabindex="0"0003b170:·3036·2220·7461·6269·6e64·6578·3d22·3022··06"·tabindex="0"
0003b180:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003b180:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003b190:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003b190:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003b1a0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003b1a0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003b1b0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003b1b0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003b1c0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003b1c0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003b1d0:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni0003b1d0:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s
0003b1e0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003b1e0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003b1f0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003b1f0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003b200:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003b200:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003b210:·7073·6522·2069·643d·2269·646d·3834·3036··pse"·id="idm84060003b210:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm84
0003b220:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003b220:·3036·223e·3c74·6162·6c65·2063·6c61·7373··06"><table·class
0003b230:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003b230:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003b240:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003b240:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003b250:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003b250:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003b260:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003b260:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003b270:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003b270:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003b280:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003b280:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003b290:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003b290:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003b2a0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003b2a0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003b2b0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003b2b0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b2c0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003b2c0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0003b2d0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003b2d0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
0003b2e0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003b2e0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003b2f0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003b2f0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0003b300:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003b300:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003b310:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ0003b310:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 0003b320:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide.
 0003b330:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003b320:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide.. 
0003b330:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai 
0003b340:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{ 
0003b350:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens 
0003b360:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta 
0003b370:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c 
0003b380:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003b390:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003b3a0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003b3b0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003b3c0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003b3d0:·6964·6d38·3430·3722·2074·6162·696e·6465··idm8407"·tabinde 
0003b3e0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003b3f0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003b400:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003b410:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003b420:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003b430:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003b440:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003b450:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003b340:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0003b350:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0003b360:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0003b460:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b470:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8 
0003b480:·3430·3722·3e3c·7461·626c·6520·636c·6173··407"><table·clas 
0003b490:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b4a0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b4b0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b4c0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b4d0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b4e0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b4f0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b500:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b510:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b520:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b530:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003b540:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b550:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b560:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b570:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R 
0003b580:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003b590:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003b5a0:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003b5b0:·6d73·0a69·6620·5b20·2120·2d66·202f·2e64··ms.if·[·!·-f·/.d 
0003b5c0:·6f63·6b65·7265·6e76·205d·2026·616d·703b··ockerenv·]·&amp; 
0003b5d0:·2661·6d70·3b20·5b20·2120·2d66·202f·7275··&amp;·[·!·-f·/ru 
0003b5e0:·6e2f·2e63·6f6e·7461·696e·6572·656e·7620··n/.containerenv· 
0003b5f0:·5d3b·2074·6865·6e0a·0a69·6620·2120·7270··];·then..if·!·rp 
0003b600:·6d20·2d71·202d·2d71·7569·6574·2022·6169··m·-q·--quiet·"ai 
0003b610:·6465·2220·3b20·7468·656e·0a20·2020·2064··de"·;·then.····d 
0003b620:·6e66·2069·6e73·7461·6c6c·202d·7920·2261··nf·install·-y·"a 
0003b630:·6964·6522·0a66·690a·0a65·6c73·650a·2020··ide".fi..else.·· 
0003b640:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech 
0003b650:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i 
0003b660:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable 
0003b670:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do 
0003b680:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></ 
0003b690:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003b6a0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003b6b0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle0003b370:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0003b380:·3d22·2369·646d·3834·3037·2220·7461·6269··="#idm8407"·tabi
 0003b390:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 0003b3a0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 0003b3b0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 0003b3c0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 0003b3d0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 0003b3e0:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu
 0003b3f0:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...
 0003b400:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003b410:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003b420:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003b430:·2269·646d·3834·3037·223e·3c74·6162·6c65··"idm8407"><table
 0003b440:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003b450:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003b460:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003b470:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003b480:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 0003b490:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003b4a0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003b4b0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
Max diff block lines reached; 10715976/10748460 bytes (99.70%) of diff not shown.
1.27 MB
html2text {}
    
Offset 41, 15 lines modifiedOffset 41, 15 lines modified
41 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*41 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Red·Hat·Enterprise·Linux·9·Benchmark·for·Level·1·-·Server42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Red·Hat·Enterprise·Linux·9·Benchmark·for·Level·1·-·Server
43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_server_l143 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_server_l1
44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
45 ····*·cpe:/o:redhat:enterprise_linux:945 ····*·cpe:/o:redhat:enterprise_linux:9
46 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
47 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8447 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
48 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)48 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
49 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*49 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
50 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s50 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
51 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e51 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
52 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l52 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
53 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n53 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
54 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g54 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
55 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s55 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 106, 41 lines modifiedOffset 106, 45 lines modified
106 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5106 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
107 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199107 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
108 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79108 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
109 ·············_\x8c_\x8i_\x8s············6.1.1109 ·············_\x8c_\x8i_\x8s············6.1.1
110 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2110 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
111 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010111 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010
112 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule112 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule
 113 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 114 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 115 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 116 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 117 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 118 package·--add=aide
113 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
114 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low120 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
115 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low121 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
116 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false122 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
117 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable123 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
118 include·install_aide124 include·install_aide
  
119 class·install_aide·{125 class·install_aide·{
120 ··package·{·'aide':126 ··package·{·'aide':
121 ····ensure·=>·'installed',127 ····ensure·=>·'installed',
122 ··}128 ··}
123 }129 }
 130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 131 [[packages]]
 132 name·=·"aide"
 133 version·=·"*"
124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low135 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
126 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low136 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
127 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false137 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
128 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable138 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
129 #·Remediation·is·applicable·only·in·certain·platforms 
130 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
 139 package·install·aide
131 if·!·rpm·-q·--quiet·"aide"·;·then 
132 ····dnf·install·-y·"aide" 
133 fi 
  
134 else 
135 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
136 fi 
137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
142 -·name:·Ensure·aide·is·installed145 -·name:·Ensure·aide·is·installed
143 ··package:146 ··package:
Offset 156, 33 lines modifiedOffset 160, 29 lines modified
156 ··-·PCI-DSSv4-11.5.2160 ··-·PCI-DSSv4-11.5.2
157 ··-·enable_strategy161 ··-·enable_strategy
158 ··-·low_complexity162 ··-·low_complexity
159 ··-·low_disruption163 ··-·low_disruption
160 ··-·medium_severity164 ··-·medium_severity
161 ··-·no_reboot_needed165 ··-·no_reboot_needed
162 ··-·package_aide_installed166 ··-·package_aide_installed
163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
164 [[packages]] 
165 name·=·"aide" 
166 version·=·"*" 
167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 172 #·Remediation·is·applicable·only·in·certain·platforms
 173 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 174 if·!·rpm·-q·--quiet·"aide"·;·then
 175 ····dnf·install·-y·"aide"
 176 fi
172 package·install·aide 
173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
178 package·--add=aide177 else
 178 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 179 fi
179 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*180 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
180 Run·the·following·command·to·generate·a·new·database:181 Run·the·following·command·to·generate·a·new·database:
181 $·sudo·/usr/sbin/aide·--init182 $·sudo·/usr/sbin/aide·--init
182 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:183 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
183 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz184 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
184 To·initiate·a·manual·check,·run·the·following·command:185 To·initiate·a·manual·check,·run·the·following·command:
185 $·sudo·/usr/sbin/aide·--check186 $·sudo·/usr/sbin/aide·--check
Offset 202, 28 lines modifiedOffset 202, 14 lines modified
202 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5202 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
203 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199203 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
204 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79204 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
205 ·············_\x8c_\x8i_\x8s············6.1.1205 ·············_\x8c_\x8i_\x8s············6.1.1
206 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2206 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
207 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010207 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010
208 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule208 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule
209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
210 #·Remediation·is·applicable·only·in·certain·platforms 
211 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
212 if·!·rpm·-q·--quiet·"aide"·;·then 
213 ····dnf·install·-y·"aide" 
214 fi 
  
Max diff block lines reached; 1324675/1330766 bytes (99.54%) of diff not shown.
11.1 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-cis_workstation_l1.html
    
Offset 14301, 15 lines modifiedOffset 14301, 15 lines modified
00037dc0:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren00037dc0:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren
00037dd0:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro00037dd0:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro
00037de0:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron00037de0:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron
00037df0:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s00037df0:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s
00037e00:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str00037e00:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str
00037e10:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········00037e10:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········
00037e20:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·00037e20:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·
00037e30:·3230·3236·2d30·312d·3038·290a·2020·2020··2026-01-08).····00037e30:·3230·3234·2d31·322d·3037·290a·2020·2020··2024-12-07).····
00037e40:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li00037e40:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li
00037e50:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>00037e50:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>
00037e60:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content00037e60:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content
00037e70:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a00037e70:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a
00037e80:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or00037e80:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or
00037e90:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con00037e90:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con
00037ea0:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste00037ea0:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste
Offset 15118, 237 lines modifiedOffset 15118, 237 lines modified
0003b0d0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b0d0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b0e0:·2369·646d·3834·3036·2220·7461·6269·6e64··#idm8406"·tabind0003b0e0:·2369·646d·3834·3036·2220·7461·6269·6e64··#idm8406"·tabind
0003b0f0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b0f0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b100:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b100:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b110:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b110:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b120:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b120:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b130:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b130:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b140:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp0003b140:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac
0003b150:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</0003b150:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...
0003b160:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003b160:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003b170:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003b170:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003b180:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003b180:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003b190:·646d·3834·3036·223e·3c74·6162·6c65·2063··dm8406"><table·c0003b190:·2269·646d·3834·3036·223e·3c74·6162·6c65··"idm8406"><table
0003b1a0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003b1a0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003b1b0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003b1b0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003b1c0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003b1c0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003b1d0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003b1d0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003b1e0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003b1e0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003b1f0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003b1f0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003b200:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru0003b200:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003b210:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l0003b210:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003b220:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003b220:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003b230:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>0003b230:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
0003b240:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></0003b240:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
0003b250:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0003b250:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003b260:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena0003b260:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003b270:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t0003b270:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003b280:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003b280:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003b290:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add
 0003b2a0:·3d61·6964·650a·3c2f·636f·6465·3e3c·2f70··=aide.</code></p
 0003b2b0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
 0003b2c0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
 0003b2d0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
 0003b2e0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
 0003b2f0:·7461·7267·6574·3d22·2369·646d·3834·3037··target="#idm8407
 0003b300:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 0003b310:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 0003b320:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 0003b330:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 0003b340:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 0003b350:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0003b360:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp
 0003b370:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0003b380:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003b390:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003b3a0:·6522·2069·643d·2269·646d·3834·3037·223e··e"·id="idm8407">
 0003b3b0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003b3c0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003b3d0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003b3e0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003b3f0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003b290:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_ 
0003b2a0:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst 
0003b2b0:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac 
0003b2c0:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.· 
0003b2d0:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;· 
0003b2e0:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··} 
0003b2f0:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre> 
0003b300:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003b310:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003b320:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003b330:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003b340:·6765·743d·2223·6964·6d38·3430·3722·2074··get="#idm8407"·t 
0003b350:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003b360:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003b370:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003b380:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003b390:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003b3a0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003b3b0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
0003b3c0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b3d0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b3e0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b3f0:·3d22·6964·6d38·3430·3722·3e3c·7461·626c··="idm8407"><tabl 
0003b400:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003b410:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003b420:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003b430:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003b440:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003b450:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b460:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003b470:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003b480:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b490:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003b4a0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003b4b0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003b4c0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003b400:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0003b4d0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003b4e0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003b4f0:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation 
0003b500:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o 
0003b510:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p 
0003b520:·6c61·7466·6f72·6d73·0a69·6620·5b20·2120··latforms.if·[·!· 
0003b530:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·] 
0003b540:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!· 
0003b550:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain 
0003b560:·6572·656e·7620·5d3b·2074·6865·6e0a·0a69··erenv·];·then..i 
0003b570:·6620·2120·7270·6d20·2d71·202d·2d71·7569··f·!·rpm·-q·--qui 
0003b580:·6574·2022·6169·6465·2220·3b20·7468·656e··et·"aide"·;·then 
0003b590:·0a20·2020·2064·6e66·2069·6e73·7461·6c6c··.····dnf·install 
0003b5a0:·202d·7920·2261·6964·6522·0a66·690a·0a65···-y·"aide".fi..e 
0003b5b0:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp 
0003b5c0:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia 
0003b5d0:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl 
0003b5e0:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing· 
0003b5f0:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c 
0003b600:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003b610:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003b620:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003b630:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003b640:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
Max diff block lines reached; 10331199/10363683 bytes (99.69%) of diff not shown.
1.22 MB
html2text {}
    
Offset 42, 15 lines modifiedOffset 42, 15 lines modified
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Red·Hat·Enterprise·Linux·9·Benchmark·for·Level·1·-42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·Red·Hat·Enterprise·Linux·9·Benchmark·for·Level·1·-
43 ··············Workstation43 ··············Workstation
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_workstation_l144 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_workstation_l1
45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
46 ····*·cpe:/o:redhat:enterprise_linux:946 ····*·cpe:/o:redhat:enterprise_linux:9
47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
48 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8448 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
54 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n54 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
55 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g55 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
56 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s56 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 105, 41 lines modifiedOffset 105, 45 lines modified
105 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5105 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
106 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199106 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
107 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79107 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
108 ·············_\x8c_\x8i_\x8s············6.1.1108 ·············_\x8c_\x8i_\x8s············6.1.1
109 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2109 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
110 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010110 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010
111 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule111 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule
 112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 113 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 114 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 115 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 116 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 117 package·--add=aide
112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
113 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
114 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
115 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
116 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
117 include·install_aide123 include·install_aide
  
118 class·install_aide·{124 class·install_aide·{
119 ··package·{·'aide':125 ··package·{·'aide':
120 ····ensure·=>·'installed',126 ····ensure·=>·'installed',
121 ··}127 ··}
122 }128 }
 129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 130 [[packages]]
 131 name·=·"aide"
 132 version·=·"*"
123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
124 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
125 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
126 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
127 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
128 #·Remediation·is·applicable·only·in·certain·platforms 
129 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
 138 package·install·aide
130 if·!·rpm·-q·--quiet·"aide"·;·then 
131 ····dnf·install·-y·"aide" 
132 fi 
  
133 else 
134 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
135 fi 
136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
141 -·name:·Ensure·aide·is·installed144 -·name:·Ensure·aide·is·installed
142 ··package:145 ··package:
Offset 155, 33 lines modifiedOffset 159, 29 lines modified
155 ··-·PCI-DSSv4-11.5.2159 ··-·PCI-DSSv4-11.5.2
156 ··-·enable_strategy160 ··-·enable_strategy
157 ··-·low_complexity161 ··-·low_complexity
158 ··-·low_disruption162 ··-·low_disruption
159 ··-·medium_severity163 ··-·medium_severity
160 ··-·no_reboot_needed164 ··-·no_reboot_needed
161 ··-·package_aide_installed165 ··-·package_aide_installed
162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
163 [[packages]] 
164 name·=·"aide" 
165 version·=·"*" 
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 171 #·Remediation·is·applicable·only·in·certain·platforms
 172 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 173 if·!·rpm·-q·--quiet·"aide"·;·then
 174 ····dnf·install·-y·"aide"
 175 fi
171 package·install·aide 
172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
177 package·--add=aide176 else
 177 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 178 fi
178 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*179 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
179 Run·the·following·command·to·generate·a·new·database:180 Run·the·following·command·to·generate·a·new·database:
180 $·sudo·/usr/sbin/aide·--init181 $·sudo·/usr/sbin/aide·--init
181 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:182 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
182 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz183 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
183 To·initiate·a·manual·check,·run·the·following·command:184 To·initiate·a·manual·check,·run·the·following·command:
184 $·sudo·/usr/sbin/aide·--check185 $·sudo·/usr/sbin/aide·--check
Offset 201, 28 lines modifiedOffset 201, 14 lines modified
201 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5201 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
202 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199202 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
203 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79203 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
204 ·············_\x8c_\x8i_\x8s············6.1.1204 ·············_\x8c_\x8i_\x8s············6.1.1
205 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2205 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
206 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010206 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010
207 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule207 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r926389_rule
208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
209 #·Remediation·is·applicable·only·in·certain·platforms 
210 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
211 if·!·rpm·-q·--quiet·"aide"·;·then 
212 ····dnf·install·-y·"aide" 
213 fi 
  
Max diff block lines reached; 1275205/1281232 bytes (99.53%) of diff not shown.
26.1 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-cis_workstation_l2.html
    
Offset 14301, 15 lines modifiedOffset 14301, 15 lines modified
00037dc0:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren00037dc0:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren
00037dd0:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro00037dd0:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro
00037de0:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron00037de0:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron
00037df0:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s00037df0:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s
00037e00:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str00037e00:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str
00037e10:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········00037e10:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········
00037e20:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·00037e20:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·
00037e30:·3230·3236·2d30·312d·3038·290a·2020·2020··2026-01-08).····00037e30:·3230·3234·2d31·322d·3037·290a·2020·2020··2024-12-07).····
00037e40:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li00037e40:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li
00037e50:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>00037e50:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>
00037e60:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content00037e60:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content
00037e70:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a00037e70:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a
00037e80:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or00037e80:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or
00037e90:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con00037e90:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con
00037ea0:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste00037ea0:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste
Offset 15150, 236 lines modifiedOffset 15150, 236 lines modified
0003b2d0:·2d74·6172·6765·743d·2223·6964·6d38·3430··-target="#idm8400003b2d0:·2d74·6172·6765·743d·2223·6964·6d38·3430··-target="#idm840
0003b2e0:·3622·2074·6162·696e·6465·783d·2230·2220··6"·tabindex="0"·0003b2e0:·3622·2074·6162·696e·6465·783d·2230·2220··6"·tabindex="0"·
0003b2f0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003b2f0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003b300:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003b300:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003b310:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003b310:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003b320:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003b320:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003b330:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003b330:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003b340:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip0003b340:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn
0003b350:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003b350:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003b360:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003b360:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003b370:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003b370:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003b380:·7365·2220·6964·3d22·6964·6d38·3430·3622··se"·id="idm8406"0003b380:·6170·7365·2220·6964·3d22·6964·6d38·3430··apse"·id="idm840
0003b390:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003b390:·3622·3e3c·7461·626c·6520·636c·6173·733d··6"><table·class=
0003b3a0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003b3a0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003b3b0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003b3b0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003b3c0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003b3c0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003b3d0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003b3d0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003b3e0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l0003b3e0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003b3f0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003b3f0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003b400:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<0003b400:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003b410:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003b410:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003b420:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb0003b420:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
0003b430:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal0003b430:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
0003b440:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>0003b440:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
0003b450:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t0003b450:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0003b460:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td0003b460:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
0003b470:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p0003b470:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003b480:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack
 0003b490:·6167·6520·2d2d·6164·643d·6169·6465·0a3c··age·--add=aide.<
 0003b4a0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003b4b0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003b4c0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003b4d0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
0003b480:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include 
0003b490:·2069·6e73·7461·6c6c·5f61·6964·650a·0a63···install_aide..c 
0003b4a0:·6c61·7373·2069·6e73·7461·6c6c·5f61·6964··lass·install_aid 
0003b4b0:·6520·7b0a·2020·7061·636b·6167·6520·7b20··e·{.··package·{· 
0003b4c0:·2761·6964·6527·3a0a·2020·2020·656e·7375··'aide':.····ensu 
0003b4d0:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal 
0003b4e0:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co 
0003b4f0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003b500:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003b510:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003b520:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003b530:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003b540:·646d·3834·3037·2220·7461·6269·6e64·6578··dm8407"·tabindex 
0003b550:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003b560:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003b570:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003b580:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003b590:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003b5a0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
0003b5b0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003b5c0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003b5d0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003b5e0:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm84 
0003b5f0:·3037·223e·3c74·6162·6c65·2063·6c61·7373··07"><table·class 
0003b600:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003b610:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003b620:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003b630:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003b640:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003b650:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b660:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003b670:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003b680:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b690:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003b6a0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
0003b6b0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003b6c0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003b6d0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003b6e0:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re 
0003b6f0:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app 
0003b700:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in· 
0003b710:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform 
0003b720:·730a·6966·205b·2021·202d·6620·2f2e·646f··s.if·[·!·-f·/.do 
0003b730:·636b·6572·656e·7620·5d20·2661·6d70·3b26··ckerenv·]·&amp;& 
0003b740:·616d·703b·205b·2021·202d·6620·2f72·756e··amp;·[·!·-f·/run 
0003b750:·2f2e·636f·6e74·6169·6e65·7265·6e76·205d··/.containerenv·] 
0003b760:·3b20·7468·656e·0a0a·6966·2021·2072·706d··;·then..if·!·rpm 
0003b770:·202d·7120·2d2d·7175·6965·7420·2261·6964···-q·--quiet·"aid 
0003b780:·6522·203b·2074·6865·6e0a·2020·2020·646e··e"·;·then.····dn 
0003b790:·6620·696e·7374·616c·6c20·2d79·2022·6169··f·install·-y·"ai 
0003b7a0:·6465·220a·6669·0a0a·656c·7365·0a20·2020··de".fi..else.··· 
0003b7b0:·2026·6774·3b26·616d·703b·3220·6563·686f···&gt;&amp;2·echo 
0003b7c0:·2027·5265·6d65·6469·6174·696f·6e20·6973···'Remediation·is 
0003b7d0:·206e·6f74·2061·7070·6c69·6361·626c·652c···not·applicable, 
0003b7e0:·206e·6f74·6869·6e67·2077·6173·2064·6f6e···nothing·was·don 
0003b7f0:·6527·0a66·690a·3c2f·636f·6465·3e3c·2f70··e'.fi.</code></p 
0003b800:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003b810:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003b820:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=0003b4e0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003b4f0:·2223·6964·6d38·3430·3722·2074·6162·696e··"#idm8407"·tabin
 0003b500:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003b510:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003b520:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003b530:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003b540:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003b550:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
 0003b560:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
 0003b570:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003b580:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003b590:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003b5a0:·6964·6d38·3430·3722·3e3c·7461·626c·6520··idm8407"><table·
 0003b5b0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003b5c0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003b5d0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003b5e0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003b5f0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003b600:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003b610:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
Max diff block lines reached; 24975121/25007467 bytes (99.87%) of diff not shown.
2.29 MB
html2text {}
Max HTML report size reached
6.86 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-cui.html
    
Offset 14335, 15 lines modifiedOffset 14335, 15 lines modified
00037fe0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00037fe0:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00037ff0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00037ff0:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00038000:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s00038000:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00038010:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00038010:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00038020:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00038020:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00038030:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00038030:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00038040:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00038040:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00038050:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).00038050:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
00038060:·2020·2020·2020·2020·2020·2020·2020·2020··················00038060:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038070:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00038070:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00038080:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00038080:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00038090:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00038090:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
000380a0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd000380a0:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
000380b0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject000380b0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
000380c0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s000380c0:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
Offset 15103, 200 lines modifiedOffset 15103, 200 lines modified
0003afe0:·2d74·6172·6765·743d·2223·6964·6d38·3933··-target="#idm8930003afe0:·2d74·6172·6765·743d·2223·6964·6d38·3933··-target="#idm893
0003aff0:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·0003aff0:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·
0003b000:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003b000:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003b010:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003b010:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003b020:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003b020:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003b030:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003b030:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003b040:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003b040:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003b050:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
0003b060:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003b070:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003b080:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003b090:·2220·6964·3d22·6964·6d38·3933·3122·3e3c··"·id="idm8931">< 
0003b0a0:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme 
0003b0b0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
0003b0c0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
0003b0d0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
0003b0e0:·6966·2028·205b·2021·202d·6620·2f2e·646f··if·(·[·!·-f·/.do 
0003b0f0:·636b·6572·656e·7620·5d20·2661·6d70·3b26··ckerenv·]·&amp;& 
0003b100:·616d·703b·205b·2021·202d·6620·2f72·756e··amp;·[·!·-f·/run 
0003b110:·2f2e·636f·6e74·6169·6e65·7265·6e76·205d··/.containerenv·] 
0003b120:·2026·616d·703b·2661·6d70·3b20·2120·2820···&amp;&amp;·!·(· 
0003b130:·5b20·2224·7b63·6f6e·7461·696e·6572·3a2d··[·"${container:- 
0003b140:·7d22·203d·3d20·2262·7772·6170·2d6f·7362··}"·==·"bwrap-osb 
0003b150:·7569·6c64·2220·5d20·2920·293b·2074·6865··uild"·]·)·);·the 
0003b160:·6e0a·0a66·6970·732d·6d6f·6465·2d73·6574··n..fips-mode-set 
0003b170:·7570·202d·2d65·6e61·626c·650a·4649·5053··up·--enable.FIPS 
0003b180:·5f43·4f4e·463d·222f·6574·632f·6472·6163··_CONF="/etc/drac 
0003b190:·7574·2e63·6f6e·662e·642f·3430·2d66·6970··ut.conf.d/40-fip 
0003b1a0:·732e·636f·6e66·220a·6966·2021·2067·7265··s.conf".if·!·gre 
0003b1b0:·7020·225e·6164·645f·6472·6163·7574·6d6f··p·"^add_dracutmo 
0003b1c0:·6475·6c65·732b·3d5c·2220·6669·7073·205c··dules+=\"·fips·\ 
0003b1d0:·2222·2024·4649·5053·5f43·4f4e·463b·2074··""·$FIPS_CONF;·t 
0003b1e0:·6865·6e0a·2020·2020·6563·686f·2022·6164··hen.····echo·"ad 
0003b1f0:·645f·6472·6163·7574·6d6f·6475·6c65·732b··d_dracutmodules+ 
0003b200:·3d5c·2220·6669·7073·205c·2222·2026·6774··=\"·fips·\""·&gt 
0003b210:·3b26·6774·3b20·2446·4950·535f·434f·4e46··;&gt;·$FIPS_CONF 
0003b220:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g 
0003b230:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R 
0003b240:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no 
0003b250:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no 
0003b260:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'. 
0003b270:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre> 
0003b280:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003b290:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003b2a0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003b2b0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003b2c0:·6765·743d·2223·6964·6d38·3933·3222·2074··get="#idm8932"·t 
0003b2d0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003b2e0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003b2f0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003b300:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003b310:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003b320:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003b330:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet0003b050:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni
0003b340:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003b060:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003b350:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003b070:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003b360:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003b080:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003b370:·2069·643d·2269·646d·3839·3332·223e·3c74···id="idm8932"><t0003b090:·7073·6522·2069·643d·2269·646d·3839·3331··pse"·id="idm8931
0003b380:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl0003b0a0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003b390:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·0003b0b0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003b3a0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0003b0c0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003b3b0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">0003b0d0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003b3c0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi0003b0e0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003b0f0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003b100:·6d65·6469·756d·3c2f·7464·3e3c·2f74·723e··medium</td></tr>
 0003b110:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003b3d0:·7479·3a3c·2f74·683e·3c74·643e·6d65·6469··ty:</th><td>medi0003b120:·6f6e·3a3c·2f74·683e·3c74·643e·6d65·6469··on:</th><td>medi
0003b3e0:·756d·3c2f·7464·3e3c·2f74·723e·3c74·723e··um</td></tr><tr>0003b130:·756d·3c2f·7464·3e3c·2f74·723e·3c74·723e··um</td></tr><tr>
0003b3f0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003b400:·2f74·683e·3c74·643e·6d65·6469·756d·3c2f··/th><td>medium</ 
0003b410:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b420:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>0003b140:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003b150:·3c74·643e·7472·7565·3c2f·7464·3e3c·2f74··<td>true</td></t
 0003b160:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003b170:·6779·3a3c·2f74·683e·3c74·643e·7265·7374··gy:</th><td>rest
0003b430:·7472·7565·3c2f·7464·3e3c·2f74·723e·3c74··true</td></tr><t0003b180:·7269·6374·3c2f·7464·3e3c·2f74·723e·3c2f··rict</td></tr></
0003b440:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003b450:·2f74·683e·3c74·643e·7265·7374·7269·6374··/th><td>restrict 
0003b460:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b470:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n0003b190:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
0003b480:·616d·653a·2043·6865·636b·2074·6f20·7365··ame:·Check·to·se0003b1a0:·3e2d·206e·616d·653a·2043·6865·636b·2074··>-·name:·Check·t
0003b490:·6520·7468·6520·6375·7272·656e·7420·7374··e·the·current·st0003b1b0:·6f20·7365·6520·7468·6520·6375·7272·656e··o·see·the·curren
0003b4a0:·6174·7573·206f·6620·4649·5053·206d·6f64··atus·of·FIPS·mod0003b1c0:·7420·7374·6174·7573·206f·6620·4649·5053··t·status·of·FIPS
0003b4b0:·650a·2020·636f·6d6d·616e·643a·202f·7573··e.··command:·/us0003b1d0:·206d·6f64·650a·2020·636f·6d6d·616e·643a···mode.··command:
0003b4c0:·722f·6269·6e2f·6669·7073·2d6d·6f64·652d··r/bin/fips-mode-0003b1e0:·202f·7573·722f·6269·6e2f·6669·7073·2d6d···/usr/bin/fips-m
0003b4d0:·7365·7475·7020·2d2d·6368·6563·6b0a·2020··setup·--check.··0003b1f0:·6f64·652d·7365·7475·7020·2d2d·6368·6563··ode-setup·--chec
0003b4e0:·7265·6769·7374·6572·3a20·6973·5f66·6970··register:·is_fip0003b200:·6b0a·2020·7265·6769·7374·6572·3a20·6973··k.··register:·is
0003b4f0:·735f·656e·6162·6c65·640a·2020·6368·616e··s_enabled.··chan0003b210:·5f66·6970·735f·656e·6162·6c65·640a·2020··_fips_enabled.··
0003b500:·6765·645f·7768·656e·3a20·6661·6c73·650a··ged_when:·false.0003b220:·6368·616e·6765·645f·7768·656e·3a20·6661··changed_when:·fa
0003b510:·2020·6661·696c·6564·5f77·6865·6e3a·2066····failed_when:·f0003b230:·6c73·650a·2020·6661·696c·6564·5f77·6865··lse.··failed_whe
0003b520:·616c·7365·0a20·2077·6865·6e3a·2028·2061··alse.··when:·(·a0003b240:·6e3a·2066·616c·7365·0a20·2077·6865·6e3a··n:·false.··when:
0003b530:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz0003b250:·2028·2061·6e73·6962·6c65·5f76·6972·7475···(·ansible_virtu
0003b540:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i0003b260:·616c·697a·6174·696f·6e5f·7479·7065·206e··alization_type·n
0003b550:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx0003b270:·6f74·2069·6e20·5b22·646f·636b·6572·222c··ot·in·["docker",
0003b560:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p0003b280:·2022·6c78·6322·2c20·226f·7065·6e76·7a22···"lxc",·"openvz"
0003b570:·6f64·6d61·6e22·2c0a·2020·2020·2263·6f6e··odman",.····"con0003b290:·2c20·2270·6f64·6d61·6e22·2c0a·2020·2020··,·"podman",.····
0003b580:·7461·696e·6572·225d·2061·6e64·206e·6f74··tainer"]·and·not0003b2a0:·2263·6f6e·7461·696e·6572·225d·2061·6e64··"container"]·and
0003b590:·2028·206c·6f6f·6b75·7028·2265·6e76·222c···(·lookup("env",0003b2b0:·206e·6f74·2028·206c·6f6f·6b75·7028·2265···not·(·lookup("e
0003b5a0:·2022·636f·6e74·6169·6e65·7222·2920·3d3d···"container")·==0003b2c0:·6e76·222c·2022·636f·6e74·6169·6e65·7222··nv",·"container"
0003b5b0:·2022·6277·7261·702d·6f73·6275·696c·6422···"bwrap-osbuild"0003b2d0:·2920·3d3d·2022·6277·7261·702d·6f73·6275··)·==·"bwrap-osbu
0003b5c0:·2029·2029·0a20·2074·6167·733a·0a20·202d···)·).··tags:.··-0003b2e0:·696c·6422·2029·2029·0a20·2074·6167·733a··ild"·)·).··tags:
0003b5d0:·2043·4345·2d38·3635·3437·2d37·0a20·202d···CCE-86547-7.··-0003b2f0:·0a20·202d·2043·4345·2d38·3635·3437·2d37··.··-·CCE-86547-7
0003b5e0:·2044·4953·412d·5354·4947·2d52·4845·4c2d···DISA-STIG-RHEL-0003b300:·0a20·202d·2044·4953·412d·5354·4947·2d52··.··-·DISA-STIG-R
0003b5f0:·3039·2d36·3731·3031·300a·2020·2d20·4e49··09-671010.··-·NI0003b310:·4845·4c2d·3039·2d36·3731·3031·300a·2020··HEL-09-671010.··
0003b600:·5354·2d38·3030·2d35·332d·434d·2d36·2861··ST-800-53-CM-6(a 
0003b610:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-50003b320:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
 0003b330:·2d36·2861·290a·2020·2d20·4e49·5354·2d38··-6(a).··-·NIST-8
0003b620:·332d·4941·2d37·0a20·202d·204e·4953·542d··3-IA-7.··-·NIST-0003b340:·3030·2d35·332d·4941·2d37·0a20·202d·204e··00-53-IA-7.··-·N
0003b630:·3830·302d·3533·2d53·432d·3132·0a20·202d··800-53-SC-12.··- 
0003b640:·204e·4953·542d·3830·302d·3533·2d53·432d···NIST-800-53-SC-0003b350:·4953·542d·3830·302d·3533·2d53·432d·3132··IST-800-53-SC-12
0003b650:·3132·2832·290a·2020·2d20·4e49·5354·2d38··12(2).··-·NIST-8 
Max diff block lines reached; 6265854/6293232 bytes (99.56%) of diff not shown.
877 KB
html2text {}
    
Offset 50, 15 lines modifiedOffset 50, 15 lines modified
50 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Unclassified·Information·in·Non-federal·Information50 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DRAFT·-·Unclassified·Information·in·Non-federal·Information
51 ··············Systems·and·Organizations·(NIST·800-171)51 ··············Systems·and·Organizations·(NIST·800-171)
52 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cui52 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cui
53 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*53 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
54 ····*·cpe:/o:redhat:enterprise_linux:954 ····*·cpe:/o:redhat:enterprise_linux:9
55 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*55 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
56 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8456 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
57 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)57 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
58 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*58 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
59 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s59 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
60 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e60 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
61 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l61 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
62 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n62 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
63 ·········4.·_\x8z_\x8I_\x8P_\x8L_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n63 ·········4.·_\x8z_\x8I_\x8P_\x8L_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
64 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s64 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 101, 27 lines modifiedOffset 101, 14 lines modified
101 ·············_\x8i_\x8s_\x8m······1446101 ·············_\x8i_\x8s_\x8m······1446
102 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1102 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
103 References:··_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12103 References:··_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
104 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.1104 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.1
105 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223105 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223
106 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-09-671010106 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-09-671010
107 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule107 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule
108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
109 #·Remediation·is·applicable·only·in·certain·platforms 
110 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·);·then 
  
111 fips-mode-setup·--enable 
112 FIPS_CONF="/etc/dracut.conf.d/40-fips.conf" 
113 if·!·grep·"^add_dracutmodules+=\"·fips·\""·$FIPS_CONF;·then 
114 ····echo·"add_dracutmodules+=\"·fips·\""·>>·$FIPS_CONF 
115 fi 
  
116 else 
117 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
118 fi 
119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
120 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium109 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium
121 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium110 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
122 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true111 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
123 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict112 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
124 -·name:·Check·to·see·the·current·status·of·FIPS·mode113 -·name:·Check·to·see·the·current·status·of·FIPS·mode
125 ··command:·/usr/bin/fips-mode-setup·--check114 ··command:·/usr/bin/fips-mode-setup·--check
Offset 185, 14 lines modifiedOffset 172, 27 lines modified
185 ··-·NIST-800-53-SC-13172 ··-·NIST-800-53-SC-13
186 ··-·enable_dracut_fips_module173 ··-·enable_dracut_fips_module
187 ··-·high_severity174 ··-·high_severity
188 ··-·medium_complexity175 ··-·medium_complexity
189 ··-·medium_disruption176 ··-·medium_disruption
190 ··-·reboot_required177 ··-·reboot_required
191 ··-·restrict_strategy178 ··-·restrict_strategy
 179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 180 #·Remediation·is·applicable·only·in·certain·platforms
 181 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·);·then
  
 182 fips-mode-setup·--enable
 183 FIPS_CONF="/etc/dracut.conf.d/40-fips.conf"
 184 if·!·grep·"^add_dracutmodules+=\"·fips·\""·$FIPS_CONF;·then
 185 ····echo·"add_dracutmodules+=\"·fips·\""·>>·$FIPS_CONF
 186 fi
  
 187 else
 188 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 189 fi
192 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*190 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
193 To·enable·FIPS·mode,·run·the·following·command:191 To·enable·FIPS·mode,·run·the·following·command:
194 fips-mode-setup·--enable192 fips-mode-setup·--enable
  
195 The·fips-mode-setup·command·will·configure·the·system·in·FIPS·mode·by·automatically·configuring·the·following:193 The·fips-mode-setup·command·will·configure·the·system·in·FIPS·mode·by·automatically·configuring·the·following:
196 ····*·Setting·the·kernel·FIPS·mode·flag·(/proc/sys/crypto/fips_enabled)·to·1194 ····*·Setting·the·kernel·FIPS·mode·flag·(/proc/sys/crypto/fips_enabled)·to·1
197 ····*·Creating·/etc/system-fips195 ····*·Creating·/etc/system-fips
Offset 208, 41 lines modifiedOffset 208, 18 lines modified
208 ·············_\x8i_\x8s_\x8m······1446208 ·············_\x8i_\x8s_\x8m······1446
209 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1209 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
210 References:··_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12210 References:··_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
211 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1211 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
212 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176212 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
213 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-09-671010213 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-09-671010
214 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule214 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule
 215 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
215 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
216 #·Remediation·is·applicable·only·in·certain·platforms 
217 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·)·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then 
  
218 var_system_crypto_policy='FIPS' 
  
  
219 fips-mode-setup·--enable 
  
220 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
221 rc=$? 
  
222 if·test·"$rc"·=·127;·then 
223 »       echo·"$stderr_of_call"·>&2 
224 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
225 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
226 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
227 »       false··#·end·with·an·error·code 
228 elif·test·"$rc"·!=·0;·then 
229 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
230 »       false··#·end·with·an·error·code 
231 fi 
  
 216 [customizations]
 217 fips·=·true
232 else 
233 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
234 fi 
235 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8218 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
236 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium219 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium
237 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium220 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
238 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true221 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
239 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict222 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
240 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable223 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
241 ··set_fact:224 ··set_fact:
Offset 346, 18 lines modifiedOffset 323, 41 lines modified
346 ··-·NIST-800-53-SC-13323 ··-·NIST-800-53-SC-13
347 ··-·enable_fips_mode324 ··-·enable_fips_mode
348 ··-·high_severity325 ··-·high_severity
349 ··-·medium_complexity326 ··-·medium_complexity
350 ··-·medium_disruption327 ··-·medium_disruption
351 ··-·reboot_required328 ··-·reboot_required
352 ··-·restrict_strategy329 ··-·restrict_strategy
353 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8330 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 331 #·Remediation·is·applicable·only·in·certain·platforms
 332 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·)·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
Max diff block lines reached; 892129/898378 bytes (99.30%) of diff not shown.
6.98 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-e8.html
    
Offset 14301, 15 lines modifiedOffset 14301, 15 lines modified
00037dc0:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current00037dc0:·793c·2f68·323e·3c70·3e43·7572·7265·6e74··y</h2><p>Current
00037dd0:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron00037dd0:·2076·6572·7369·6f6e·3a20·3c73·7472·6f6e···version:·<stron
00037de0:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong00037de0:·673e·302e·312e·3734·3c2f·7374·726f·6e67··g>0.1.74</strong
00037df0:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st00037df0:·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c·7374··></p><ul><li><st
00037e00:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro00037e00:·726f·6e67·3e64·7261·6674·3c2f·7374·726f··rong>draft</stro
00037e10:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············00037e10:·6e67·3e0a·2020·2020·2020·2020·2020·2020··ng>.············
00037e20:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·200037e20:·2020·2020·2020·2020·2861·7320·6f66·2032··········(as·of·2
00037e30:·3032·362d·3031·2d30·3829·0a20·2020·2020··026-01-08).·····00037e30:·3032·342d·3132·2d30·3729·0a20·2020·2020··024-12-07).·····
00037e40:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>00037e40:·2020·2020·2020·2020·2020·203c·2f6c·693e·············</li>
00037e50:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T00037e50:·3c2f·756c·3e3c·2f64·6976·3e3c·6832·3e54··</ul></div><h2>T
00037e60:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents00037e60:·6162·6c65·206f·6620·436f·6e74·656e·7473··able·of·Contents
00037e70:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·00037e70:·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c·6120··</h2><ol><li><a·
00037e80:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org00037e80:·6872·6566·3d22·2378·6363·6466·5f6f·7267··href="#xccdf_org
00037e90:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont00037e90:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont
00037ea0:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system00037ea0:·656e·745f·6772·6f75·705f·7379·7374·656d··ent_group_system
Offset 15183, 306 lines modifiedOffset 15183, 306 lines modified
0003b4e0:·7461·7267·6574·3d22·2369·646d·3830·3632··target="#idm80620003b4e0:·7461·7267·6574·3d22·2369·646d·3830·3632··target="#idm8062
0003b4f0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003b4f0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003b500:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003b500:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003b510:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003b510:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003b520:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003b520:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003b530:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003b530:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003b540:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003b540:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003b550:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003b560:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003b570:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003b580:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003b590:·2069·643d·2269·646d·3830·3632·223e·3c70···id="idm8062"><p 
0003b5a0:·7265·3e3c·636f·6465·3e0a·2320·4669·6e64··re><code>.#·Find 
0003b5b0:·2077·6869·6368·2066·696c·6573·2068·6176···which·files·hav 
0003b5c0:·6520·696e·636f·7272·6563·7420·6861·7368··e·incorrect·hash 
0003b5d0:·2028·6e6f·7420·696e·202f·6574·632c·2062···(not·in·/etc,·b 
0003b5e0:·6563·6175·7365·206f·6620·7468·6520·7379··ecause·of·the·sy 
0003b5f0:·7374·656d·2072·656c·6174·6564·2063·6f6e··stem·related·con 
0003b600:·6669·6720·6669·6c65·7329·2061·6e64·2074··fig·files)·and·t 
0003b610:·6865·6e20·6765·7420·6669·6c65·7320·6e61··hen·get·files·na 
0003b620:·6d65·730a·6669·6c65·735f·7769·7468·5f69··mes.files_with_i 
0003b630:·6e63·6f72·7265·6374·5f68·6173·683d·2224··ncorrect_hash="$ 
0003b640:·2872·706d·202d·5661·202d·2d6e·6f63·6f6e··(rpm·-Va·--nocon 
0003b650:·6669·6720·7c20·6772·6570·202d·4520·275e··fig·|·grep·-E·'^ 
0003b660:·2e2e·3527·207c·2061·776b·2027·7b70·7269··..5'·|·awk·'{pri 
0003b670:·6e74·2024·4e46·7d27·2029·220a·0a69·6620··nt·$NF}'·)"..if· 
0003b680:·5b20·2d6e·2022·2466·696c·6573·5f77·6974··[·-n·"$files_wit 
0003b690:·685f·696e·636f·7272·6563·745f·6861·7368··h_incorrect_hash 
0003b6a0:·2220·5d3b·2074·6865·6e0a·2020·2020·2320··"·];·then.····#· 
0003b6b0:·4672·6f6d·2066·696c·6573·206e·616d·6573··From·files·names 
0003b6c0:·2067·6574·2070·6163·6b61·6765·206e·616d···get·package·nam 
0003b6d0:·6573·2061·6e64·2063·6861·6e67·6520·6e65··es·and·change·ne 
0003b6e0:·776c·696e·6520·746f·2073·7061·6365·2c20··wline·to·space,· 
0003b6f0:·6265·6361·7573·6520·7270·6d20·7772·6974··because·rpm·writ 
0003b700:·6573·2065·6163·6820·7061·636b·6167·6520··es·each·package· 
0003b710:·746f·206e·6577·206c·696e·650a·2020·2020··to·new·line.···· 
0003b720:·7061·636b·6167·6573·5f74·6f5f·7265·696e··packages_to_rein 
0003b730:·7374·616c·6c3d·2224·2872·706d·202d·7166··stall="$(rpm·-qf 
0003b740:·2024·6669·6c65·735f·7769·7468·5f69·6e63···$files_with_inc 
0003b750:·6f72·7265·6374·5f68·6173·6820·7c20·7472··orrect_hash·|·tr 
0003b760:·2027·5c6e·2720·2720·2729·220a·0a20·2020···'\n'·'·')"..··· 
0003b770:·200a·2020·2020·646e·6620·7265·696e·7374···.····dnf·reinst 
0003b780:·616c·6c20·2d79·2024·7061·636b·6167·6573··all·-y·$packages 
0003b790:·5f74·6f5f·7265·696e·7374·616c·6c0a·2020··_to_reinstall.·· 
0003b7a0:·2020·0a66·690a·3c2f·636f·6465·3e3c·2f70····.fi.</code></p 
0003b7b0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003b7c0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003b7d0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003b7e0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003b7f0:·7461·7267·6574·3d22·2369·646d·3830·3633··target="#idm8063 
0003b800:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003b810:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003b820:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003b830:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003b840:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003b850:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003b860:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip0003b550:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip
0003b870:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003b560:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003b880:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003b570:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003b890:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003b580:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003b8a0:·7365·2220·6964·3d22·6964·6d38·3036·3322··se"·id="idm8063"0003b590:·7365·2220·6964·3d22·6964·6d38·3036·3222··se"·id="idm8062"
0003b8b0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003b5a0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003b8c0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003b5b0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003b8d0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003b5c0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003b8e0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003b5d0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003b8f0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003b5e0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003b900:·6578·6974·793a·3c2f·7468·3e3c·7464·3e68··exity:</th><td>h0003b5f0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e68··exity:</th><td>h
0003b910:·6967·683c·2f74·643e·3c2f·7472·3e3c·7472··igh</td></tr><tr0003b600:·6967·683c·2f74·643e·3c2f·7472·3e3c·7472··igh</td></tr><tr
0003b920:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003b610:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003b930:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<0003b620:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<
0003b940:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b630:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b950:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003b640:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003b960:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003b650:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003b970:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003b660:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003b980:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri0003b670:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri
0003b990:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta0003b680:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta
0003b9a0:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-0003b690:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-
0003b9b0:·206e·616d·653a·2027·5365·7420·6661·6374···name:·'Set·fact0003b6a0:·206e·616d·653a·2027·5365·7420·6661·6374···name:·'Set·fact
0003b9c0:·3a20·5061·636b·6167·6520·6d61·6e61·6765··:·Package·manage0003b6b0:·3a20·5061·636b·6167·6520·6d61·6e61·6765··:·Package·manage
0003b9d0:·7220·7265·696e·7374·616c·6c20·636f·6d6d··r·reinstall·comm0003b6c0:·7220·7265·696e·7374·616c·6c20·636f·6d6d··r·reinstall·comm
0003b9e0:·616e·6427·0a20·2073·6574·5f66·6163·743a··and'.··set_fact:0003b6d0:·616e·6427·0a20·2073·6574·5f66·6163·743a··and'.··set_fact:
0003b9f0:·0a20·2020·2070·6163·6b61·6765·5f6d·616e··.····package_man0003b6e0:·0a20·2020·2070·6163·6b61·6765·5f6d·616e··.····package_man
0003ba00:·6167·6572·5f72·6569·6e73·7461·6c6c·5f63··ager_reinstall_c0003b6f0:·6167·6572·5f72·6569·6e73·7461·6c6c·5f63··ager_reinstall_c
0003ba10:·6d64·3a20·646e·6620·7265·696e·7374·616c··md:·dnf·reinstal0003b700:·6d64·3a20·646e·6620·7265·696e·7374·616c··md:·dnf·reinstal
0003ba20:·6c20·2d79·0a20·2077·6865·6e3a·2061·6e73··l·-y.··when:·ans0003b710:·6c20·2d79·0a20·2077·6865·6e3a·2061·6e73··l·-y.··when:·ans
0003ba30:·6962·6c65·5f64·6973·7472·6962·7574·696f··ible_distributio0003b720:·6962·6c65·5f64·6973·7472·6962·7574·696f··ible_distributio
0003ba40:·6e20·696e·205b·2022·4665·646f·7261·222c··n·in·[·"Fedora",0003b730:·6e20·696e·205b·2022·4665·646f·7261·222c··n·in·[·"Fedora",
0003ba50:·2022·5265·6448·6174·222c·2022·4365·6e74···"RedHat",·"Cent0003b740:·2022·5265·6448·6174·222c·2022·4365·6e74···"RedHat",·"Cent
0003ba60:·4f53·222c·2022·4f72·6163·6c65·4c69·6e75··OS",·"OracleLinu0003b750:·4f53·222c·2022·4f72·6163·6c65·4c69·6e75··OS",·"OracleLinu
0003ba70:·7822·205d·0a20·2074·6167·733a·0a20·202d··x"·].··tags:.··-0003b760:·7822·205d·0a20·2074·6167·733a·0a20·202d··x"·].··tags:.··-
0003ba80:·2043·4345·2d39·3038·3431·2d38·0a20·202d···CCE-90841-8.··-0003b770:·2043·4345·2d39·3038·3431·2d38·0a20·202d···CCE-90841-8.··-
0003ba90:·2043·4a49·532d·352e·3130·2e34·2e31·0a20···CJIS-5.10.4.1.·0003b780:·2043·4a49·532d·352e·3130·2e34·2e31·0a20···CJIS-5.10.4.1.·
0003baa0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-0003b790:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
0003bab0:·332e·332e·380a·2020·2d20·4e49·5354·2d38··3.3.8.··-·NIST-80003b7a0:·332e·332e·380a·2020·2d20·4e49·5354·2d38··3.3.8.··-·NIST-8
0003bac0:·3030·2d31·3731·2d33·2e34·2e31·0a20·202d··00-171-3.4.1.··-0003b7b0:·3030·2d31·3731·2d33·2e34·2e31·0a20·202d··00-171-3.4.1.··-
0003bad0:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-0003b7c0:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-
0003bae0:·3928·3329·0a20·202d·204e·4953·542d·3830··9(3).··-·NIST-800003b7d0:·3928·3329·0a20·202d·204e·4953·542d·3830··9(3).··-·NIST-80
0003baf0:·302d·3533·2d43·4d2d·3628·6329·0a20·202d··0-53-CM-6(c).··-0003b7e0:·302d·3533·2d43·4d2d·3628·6329·0a20·202d··0-53-CM-6(c).··-
0003bb00:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-0003b7f0:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-
0003bb10:·3628·6429·0a20·202d·204e·4953·542d·3830··6(d).··-·NIST-800003b800:·3628·6429·0a20·202d·204e·4953·542d·3830··6(d).··-·NIST-80
0003bb20:·302d·3533·2d53·492d·370a·2020·2d20·4e49··0-53-SI-7.··-·NI0003b810:·302d·3533·2d53·492d·370a·2020·2d20·4e49··0-53-SI-7.··-·NI
0003bb30:·5354·2d38·3030·2d35·332d·5349·2d37·2831··ST-800-53-SI-7(10003b820:·5354·2d38·3030·2d35·332d·5349·2d37·2831··ST-800-53-SI-7(1
0003bb40:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-50003b830:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5
0003bb50:·332d·5349·2d37·2836·290a·2020·2d20·5043··3-SI-7(6).··-·PC0003b840:·332d·5349·2d37·2836·290a·2020·2d20·5043··3-SI-7(6).··-·PC
0003bb60:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·0003b850:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·
0003bb70:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.0003b860:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.
0003bb80:·352e·320a·2020·2d20·6869·6768·5f63·6f6d··5.2.··-·high_com0003b870:·352e·320a·2020·2d20·6869·6768·5f63·6f6d··5.2.··-·high_com
0003bb90:·706c·6578·6974·790a·2020·2d20·6869·6768··plexity.··-·high0003b880:·706c·6578·6974·790a·2020·2d20·6869·6768··plexity.··-·high
0003bba0:·5f73·6576·6572·6974·790a·2020·2d20·6d65··_severity.··-·me0003b890:·5f73·6576·6572·6974·790a·2020·2d20·6d65··_severity.··-·me
0003bbb0:·6469·756d·5f64·6973·7275·7074·696f·6e0a··dium_disruption.0003b8a0:·6469·756d·5f64·6973·7275·7074·696f·6e0a··dium_disruption.
0003bbc0:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne0003b8b0:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne
Max diff block lines reached; 6555217/6597223 bytes (99.36%) of diff not shown.
706 KB
html2text {}
    
Offset 41, 15 lines modifiedOffset 41, 15 lines modified
41 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*41 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Australian·Cyber·Security·Centre·(ACSC)·Essential·Eight42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Australian·Cyber·Security·Centre·(ACSC)·Essential·Eight
43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_e843 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_e8
44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
45 ····*·cpe:/o:redhat:enterprise_linux:945 ····*·cpe:/o:redhat:enterprise_linux:9
46 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
47 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8447 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
48 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)48 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
49 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*49 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
50 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s50 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
51 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e51 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
52 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l52 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
53 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g53 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
54 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s54 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
55 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s55 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 104, 27 lines modifiedOffset 104, 14 lines modified
104 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6104 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
105 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4105 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
106 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)106 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
107 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1107 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
108 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5108 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
109 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227109 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
110 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2110 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
111 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
112 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
113 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
114 if·[·-n·"$files_with_incorrect_hash"·];·then 
115 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
116 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
117 ····dnf·reinstall·-y·$packages_to_reinstall 
  
118 fi 
119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8111 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
120 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high112 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
121 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium113 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
122 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false114 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
123 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict115 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
124 -·name:·'Set·fact:·Package·manager·reinstall·command'116 -·name:·'Set·fact:·Package·manager·reinstall·command'
125 ··set_fact:117 ··set_fact:
Offset 256, 14 lines modifiedOffset 243, 27 lines modified
256 ··-·PCI-DSSv4-11.5.2243 ··-·PCI-DSSv4-11.5.2
257 ··-·high_complexity244 ··-·high_complexity
258 ··-·high_severity245 ··-·high_severity
259 ··-·medium_disruption246 ··-·medium_disruption
260 ··-·no_reboot_needed247 ··-·no_reboot_needed
261 ··-·restrict_strategy248 ··-·restrict_strategy
262 ··-·rpm_verify_hashes249 ··-·rpm_verify_hashes
 250 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 251 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 252 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 253 if·[·-n·"$files_with_incorrect_hash"·];·then
 254 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 255 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 256 ····dnf·reinstall·-y·$packages_to_reinstall
  
 257 fi
263 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*258 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
264 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:259 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
265 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'260 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
266 run·the·following·command·to·determine·which·package·owns·it:261 run·the·following·command·to·determine·which·package·owns·it:
267 $·rpm·-qf·FILENAME262 $·rpm·-qf·FILENAME
268 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:263 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
269 $·sudo·rpm·--setugids·PACKAGENAME264 $·sudo·rpm·--setugids·PACKAGENAME
Offset 283, 40 lines modifiedOffset 283, 14 lines modified
283 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5283 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
284 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2284 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
285 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)285 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
286 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1286 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
287 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5287 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
288 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108288 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
289 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2289 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
290 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
291 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
292 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
293 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
294 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
295 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
296 declare·-A·SETPERMS_RPM_DICT 
  
297 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
298 #·is·expected·by·the·RPM·database 
299 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
300 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
301 do 
302 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
303 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
304 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
305 done 
  
306 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
307 #·correct·values 
308 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
309 do 
310 ········rpm·--setugids·"${RPM_PACKAGE}" 
311 done 
312 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8290 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
313 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high291 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
314 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium292 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
315 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false293 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
316 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict294 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
317 -·name:·Read·list·of·files·with·incorrect·ownership295 -·name:·Read·list·of·files·with·incorrect·ownership
318 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev296 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 394, 14 lines modifiedOffset 368, 40 lines modified
394 ··-·PCI-DSSv4-11.5.2368 ··-·PCI-DSSv4-11.5.2
395 ··-·high_complexity369 ··-·high_complexity
396 ··-·high_severity370 ··-·high_severity
397 ··-·medium_disruption371 ··-·medium_disruption
398 ··-·no_reboot_needed372 ··-·no_reboot_needed
399 ··-·restrict_strategy373 ··-·restrict_strategy
400 ··-·rpm_verify_ownership374 ··-·rpm_verify_ownership
 375 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 376 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 377 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 378 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 379 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 380 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 714817/722723 bytes (98.91%) of diff not shown.
17.6 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-hipaa.html
    
Offset 14320, 16 lines modifiedOffset 14320, 16 lines modified
00037ef0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h00037ef0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h
00037f00:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver00037f00:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver
00037f10:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.00037f10:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.
00037f20:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p00037f20:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p
00037f30:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong00037f30:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong
00037f40:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.00037f40:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.
00037f50:·2020·2020·2020·2020·2020·2020·2020·2020··················00037f50:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037f60:·2020·2020·2861·7320·6f66·2032·3032·362d······(as·of·2026-00037f60:·2020·2020·2861·7320·6f66·2032·3032·342d······(as·of·2024-
00037f70:·3031·2d30·3829·0a20·2020·2020·2020·2020··01-08).·········00037f70:·3132·2d30·3729·0a20·2020·2020·2020·2020··12-07).·········
00037f80:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul00037f80:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul
00037f90:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table00037f90:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table
00037fa0:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h200037fa0:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2
00037fb0:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href00037fb0:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href
00037fc0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg00037fc0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg
00037fd0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_00037fd0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
00037fe0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy00037fe0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy
Offset 15204, 306 lines modifiedOffset 15204, 306 lines modified
0003b630:·7461·7267·6574·3d22·2369·646d·3830·3632··target="#idm80620003b630:·7461·7267·6574·3d22·2369·646d·3830·3632··target="#idm8062
0003b640:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003b640:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003b650:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003b650:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003b660:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003b660:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003b670:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003b670:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003b680:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003b680:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003b690:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003b690:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003b6a0:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003b6b0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003b6c0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003b6d0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003b6e0:·2069·643d·2269·646d·3830·3632·223e·3c70···id="idm8062"><p 
0003b6f0:·7265·3e3c·636f·6465·3e0a·2320·4669·6e64··re><code>.#·Find 
0003b700:·2077·6869·6368·2066·696c·6573·2068·6176···which·files·hav 
0003b710:·6520·696e·636f·7272·6563·7420·6861·7368··e·incorrect·hash 
0003b720:·2028·6e6f·7420·696e·202f·6574·632c·2062···(not·in·/etc,·b 
0003b730:·6563·6175·7365·206f·6620·7468·6520·7379··ecause·of·the·sy 
0003b740:·7374·656d·2072·656c·6174·6564·2063·6f6e··stem·related·con 
0003b750:·6669·6720·6669·6c65·7329·2061·6e64·2074··fig·files)·and·t 
0003b760:·6865·6e20·6765·7420·6669·6c65·7320·6e61··hen·get·files·na 
0003b770:·6d65·730a·6669·6c65·735f·7769·7468·5f69··mes.files_with_i 
0003b780:·6e63·6f72·7265·6374·5f68·6173·683d·2224··ncorrect_hash="$ 
0003b790:·2872·706d·202d·5661·202d·2d6e·6f63·6f6e··(rpm·-Va·--nocon 
0003b7a0:·6669·6720·7c20·6772·6570·202d·4520·275e··fig·|·grep·-E·'^ 
0003b7b0:·2e2e·3527·207c·2061·776b·2027·7b70·7269··..5'·|·awk·'{pri 
0003b7c0:·6e74·2024·4e46·7d27·2029·220a·0a69·6620··nt·$NF}'·)"..if· 
0003b7d0:·5b20·2d6e·2022·2466·696c·6573·5f77·6974··[·-n·"$files_wit 
0003b7e0:·685f·696e·636f·7272·6563·745f·6861·7368··h_incorrect_hash 
0003b7f0:·2220·5d3b·2074·6865·6e0a·2020·2020·2320··"·];·then.····#· 
0003b800:·4672·6f6d·2066·696c·6573·206e·616d·6573··From·files·names 
0003b810:·2067·6574·2070·6163·6b61·6765·206e·616d···get·package·nam 
0003b820:·6573·2061·6e64·2063·6861·6e67·6520·6e65··es·and·change·ne 
0003b830:·776c·696e·6520·746f·2073·7061·6365·2c20··wline·to·space,· 
0003b840:·6265·6361·7573·6520·7270·6d20·7772·6974··because·rpm·writ 
0003b850:·6573·2065·6163·6820·7061·636b·6167·6520··es·each·package· 
0003b860:·746f·206e·6577·206c·696e·650a·2020·2020··to·new·line.···· 
0003b870:·7061·636b·6167·6573·5f74·6f5f·7265·696e··packages_to_rein 
0003b880:·7374·616c·6c3d·2224·2872·706d·202d·7166··stall="$(rpm·-qf 
0003b890:·2024·6669·6c65·735f·7769·7468·5f69·6e63···$files_with_inc 
0003b8a0:·6f72·7265·6374·5f68·6173·6820·7c20·7472··orrect_hash·|·tr 
0003b8b0:·2027·5c6e·2720·2720·2729·220a·0a20·2020···'\n'·'·')"..··· 
0003b8c0:·200a·2020·2020·646e·6620·7265·696e·7374···.····dnf·reinst 
0003b8d0:·616c·6c20·2d79·2024·7061·636b·6167·6573··all·-y·$packages 
0003b8e0:·5f74·6f5f·7265·696e·7374·616c·6c0a·2020··_to_reinstall.·· 
0003b8f0:·2020·0a66·690a·3c2f·636f·6465·3e3c·2f70····.fi.</code></p 
0003b900:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003b910:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003b920:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003b930:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003b940:·7461·7267·6574·3d22·2369·646d·3830·3633··target="#idm8063 
0003b950:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003b960:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003b970:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003b980:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003b990:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003b9a0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003b9b0:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip0003b6a0:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip
0003b9c0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003b6b0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003b9d0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003b6c0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003b9e0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003b6d0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003b9f0:·7365·2220·6964·3d22·6964·6d38·3036·3322··se"·id="idm8063"0003b6e0:·7365·2220·6964·3d22·6964·6d38·3036·3222··se"·id="idm8062"
0003ba00:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003b6f0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003ba10:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003b700:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003ba20:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003b710:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003ba30:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003b720:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003ba40:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003b730:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003ba50:·6578·6974·793a·3c2f·7468·3e3c·7464·3e68··exity:</th><td>h0003b740:·6578·6974·793a·3c2f·7468·3e3c·7464·3e68··exity:</th><td>h
0003ba60:·6967·683c·2f74·643e·3c2f·7472·3e3c·7472··igh</td></tr><tr0003b750:·6967·683c·2f74·643e·3c2f·7472·3e3c·7472··igh</td></tr><tr
0003ba70:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003b760:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003ba80:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<0003b770:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<
0003ba90:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b780:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003baa0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003b790:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003bab0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003b7a0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003bac0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003b7b0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003bad0:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri0003b7c0:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri
0003bae0:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta0003b7d0:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta
0003baf0:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-0003b7e0:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-
0003bb00:·206e·616d·653a·2027·5365·7420·6661·6374···name:·'Set·fact0003b7f0:·206e·616d·653a·2027·5365·7420·6661·6374···name:·'Set·fact
0003bb10:·3a20·5061·636b·6167·6520·6d61·6e61·6765··:·Package·manage0003b800:·3a20·5061·636b·6167·6520·6d61·6e61·6765··:·Package·manage
0003bb20:·7220·7265·696e·7374·616c·6c20·636f·6d6d··r·reinstall·comm0003b810:·7220·7265·696e·7374·616c·6c20·636f·6d6d··r·reinstall·comm
0003bb30:·616e·6427·0a20·2073·6574·5f66·6163·743a··and'.··set_fact:0003b820:·616e·6427·0a20·2073·6574·5f66·6163·743a··and'.··set_fact:
0003bb40:·0a20·2020·2070·6163·6b61·6765·5f6d·616e··.····package_man0003b830:·0a20·2020·2070·6163·6b61·6765·5f6d·616e··.····package_man
0003bb50:·6167·6572·5f72·6569·6e73·7461·6c6c·5f63··ager_reinstall_c0003b840:·6167·6572·5f72·6569·6e73·7461·6c6c·5f63··ager_reinstall_c
0003bb60:·6d64·3a20·646e·6620·7265·696e·7374·616c··md:·dnf·reinstal0003b850:·6d64·3a20·646e·6620·7265·696e·7374·616c··md:·dnf·reinstal
0003bb70:·6c20·2d79·0a20·2077·6865·6e3a·2061·6e73··l·-y.··when:·ans0003b860:·6c20·2d79·0a20·2077·6865·6e3a·2061·6e73··l·-y.··when:·ans
0003bb80:·6962·6c65·5f64·6973·7472·6962·7574·696f··ible_distributio0003b870:·6962·6c65·5f64·6973·7472·6962·7574·696f··ible_distributio
0003bb90:·6e20·696e·205b·2022·4665·646f·7261·222c··n·in·[·"Fedora",0003b880:·6e20·696e·205b·2022·4665·646f·7261·222c··n·in·[·"Fedora",
0003bba0:·2022·5265·6448·6174·222c·2022·4365·6e74···"RedHat",·"Cent0003b890:·2022·5265·6448·6174·222c·2022·4365·6e74···"RedHat",·"Cent
0003bbb0:·4f53·222c·2022·4f72·6163·6c65·4c69·6e75··OS",·"OracleLinu0003b8a0:·4f53·222c·2022·4f72·6163·6c65·4c69·6e75··OS",·"OracleLinu
0003bbc0:·7822·205d·0a20·2074·6167·733a·0a20·202d··x"·].··tags:.··-0003b8b0:·7822·205d·0a20·2074·6167·733a·0a20·202d··x"·].··tags:.··-
0003bbd0:·2043·4345·2d39·3038·3431·2d38·0a20·202d···CCE-90841-8.··-0003b8c0:·2043·4345·2d39·3038·3431·2d38·0a20·202d···CCE-90841-8.··-
0003bbe0:·2043·4a49·532d·352e·3130·2e34·2e31·0a20···CJIS-5.10.4.1.·0003b8d0:·2043·4a49·532d·352e·3130·2e34·2e31·0a20···CJIS-5.10.4.1.·
0003bbf0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-0003b8e0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
0003bc00:·332e·332e·380a·2020·2d20·4e49·5354·2d38··3.3.8.··-·NIST-80003b8f0:·332e·332e·380a·2020·2d20·4e49·5354·2d38··3.3.8.··-·NIST-8
0003bc10:·3030·2d31·3731·2d33·2e34·2e31·0a20·202d··00-171-3.4.1.··-0003b900:·3030·2d31·3731·2d33·2e34·2e31·0a20·202d··00-171-3.4.1.··-
0003bc20:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-0003b910:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-
0003bc30:·3928·3329·0a20·202d·204e·4953·542d·3830··9(3).··-·NIST-800003b920:·3928·3329·0a20·202d·204e·4953·542d·3830··9(3).··-·NIST-80
0003bc40:·302d·3533·2d43·4d2d·3628·6329·0a20·202d··0-53-CM-6(c).··-0003b930:·302d·3533·2d43·4d2d·3628·6329·0a20·202d··0-53-CM-6(c).··-
0003bc50:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-0003b940:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-
0003bc60:·3628·6429·0a20·202d·204e·4953·542d·3830··6(d).··-·NIST-800003b950:·3628·6429·0a20·202d·204e·4953·542d·3830··6(d).··-·NIST-80
0003bc70:·302d·3533·2d53·492d·370a·2020·2d20·4e49··0-53-SI-7.··-·NI0003b960:·302d·3533·2d53·492d·370a·2020·2d20·4e49··0-53-SI-7.··-·NI
0003bc80:·5354·2d38·3030·2d35·332d·5349·2d37·2831··ST-800-53-SI-7(10003b970:·5354·2d38·3030·2d35·332d·5349·2d37·2831··ST-800-53-SI-7(1
0003bc90:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-50003b980:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5
0003bca0:·332d·5349·2d37·2836·290a·2020·2d20·5043··3-SI-7(6).··-·PC0003b990:·332d·5349·2d37·2836·290a·2020·2d20·5043··3-SI-7(6).··-·PC
0003bcb0:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·0003b9a0:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·
0003bcc0:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.0003b9b0:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.
0003bcd0:·352e·320a·2020·2d20·6869·6768·5f63·6f6d··5.2.··-·high_com0003b9c0:·352e·320a·2020·2d20·6869·6768·5f63·6f6d··5.2.··-·high_com
0003bce0:·706c·6578·6974·790a·2020·2d20·6869·6768··plexity.··-·high0003b9d0:·706c·6578·6974·790a·2020·2d20·6869·6768··plexity.··-·high
0003bcf0:·5f73·6576·6572·6974·790a·2020·2d20·6d65··_severity.··-·me0003b9e0:·5f73·6576·6572·6974·790a·2020·2d20·6d65··_severity.··-·me
0003bd00:·6469·756d·5f64·6973·7275·7074·696f·6e0a··dium_disruption.0003b9f0:·6469·756d·5f64·6973·7275·7074·696f·6e0a··dium_disruption.
Max diff block lines reached; 17118572/17160716 bytes (99.75%) of diff not shown.
1.23 MB
html2text {}
    
Offset 46, 15 lines modifiedOffset 46, 15 lines modified
46 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
47 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Health·Insurance·Portability·and·Accountability·Act·(HIPAA)47 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Health·Insurance·Portability·and·Accountability·Act·(HIPAA)
48 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_hipaa48 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_hipaa
49 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*49 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
50 ····*·cpe:/o:redhat:enterprise_linux:950 ····*·cpe:/o:redhat:enterprise_linux:9
51 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
52 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8452 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
53 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)53 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
54 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*54 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
55 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s55 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
56 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e56 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
57 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l57 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
58 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n58 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
59 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g59 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
60 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s60 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 109, 27 lines modifiedOffset 109, 14 lines modified
109 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6109 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
110 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4110 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
111 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)111 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
112 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1112 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
113 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5113 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
114 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227114 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
115 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2115 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
116 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
117 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
118 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
119 if·[·-n·"$files_with_incorrect_hash"·];·then 
120 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
121 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
122 ····dnf·reinstall·-y·$packages_to_reinstall 
  
123 fi 
124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8116 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high117 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
126 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium118 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
127 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false119 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
128 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict120 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
129 -·name:·'Set·fact:·Package·manager·reinstall·command'121 -·name:·'Set·fact:·Package·manager·reinstall·command'
130 ··set_fact:122 ··set_fact:
Offset 261, 14 lines modifiedOffset 248, 27 lines modified
261 ··-·PCI-DSSv4-11.5.2248 ··-·PCI-DSSv4-11.5.2
262 ··-·high_complexity249 ··-·high_complexity
263 ··-·high_severity250 ··-·high_severity
264 ··-·medium_disruption251 ··-·medium_disruption
265 ··-·no_reboot_needed252 ··-·no_reboot_needed
266 ··-·restrict_strategy253 ··-·restrict_strategy
267 ··-·rpm_verify_hashes254 ··-·rpm_verify_hashes
 255 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 256 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 257 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 258 if·[·-n·"$files_with_incorrect_hash"·];·then
 259 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 260 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 261 ····dnf·reinstall·-y·$packages_to_reinstall
  
 262 fi
268 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*263 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
269 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:264 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:
270 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'265 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'
271 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:266 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:
272 $·rpm·-qf·FILENAME267 $·rpm·-qf·FILENAME
  
273 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:268 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
Offset 290, 44 lines modifiedOffset 290, 14 lines modified
290 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5290 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
291 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2291 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
292 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)292 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)
293 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1293 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
294 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5294 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
295 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108295 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108
296 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2296 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
297 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
298 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
299 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
300 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
301 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
302 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
303 declare·-A·SETPERMS_RPM_DICT 
  
304 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
305 #·is·expected·by·the·RPM·database 
306 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}') 
  
307 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
308 do 
309 ········#·NOTE:·some·files·maybe·controlled·by·more·then·one·package 
310 ········readarray·-t·RPM_PACKAGES·<·<(rpm·-qf·"${FILE_PATH}") 
311 ········for·RPM_PACKAGE·in·"${RPM_PACKAGES[@]}" 
312 ········do 
313 ················#·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
314 ················SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
315 ········done 
316 done 
  
317 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
318 #·correct·values 
319 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
320 do 
321 »       rpm·--restore·"${RPM_PACKAGE}" 
322 done 
323 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8297 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
324 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high298 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
325 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium299 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
326 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false300 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
327 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict301 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
328 -·name:·Read·list·of·files·with·incorrect·permissions302 -·name:·Read·list·of·files·with·incorrect·permissions
329 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev303 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 408, 14 lines modifiedOffset 378, 44 lines modified
408 ··-·PCI-DSSv4-11.5.2378 ··-·PCI-DSSv4-11.5.2
409 ··-·high_complexity379 ··-·high_complexity
410 ··-·high_severity380 ··-·high_severity
411 ··-·medium_disruption381 ··-·medium_disruption
412 ··-·no_reboot_needed382 ··-·no_reboot_needed
413 ··-·restrict_strategy383 ··-·restrict_strategy
414 ··-·rpm_verify_permissions384 ··-·rpm_verify_permissions
 385 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 386 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 387 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
Max diff block lines reached; 1281863/1290160 bytes (99.36%) of diff not shown.
10.5 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-ism_o.html
    
Offset 14313, 16 lines modifiedOffset 14313, 16 lines modified
00037e80:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h00037e80:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h
00037e90:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver00037e90:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver
00037ea0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.00037ea0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.
00037eb0:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p00037eb0:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p
00037ec0:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong00037ec0:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong
00037ed0:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.00037ed0:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.
00037ee0:·2020·2020·2020·2020·2020·2020·2020·2020··················00037ee0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037ef0:·2020·2020·2861·7320·6f66·2032·3032·362d······(as·of·2026-00037ef0:·2020·2020·2861·7320·6f66·2032·3032·342d······(as·of·2024-
00037f00:·3031·2d30·3829·0a20·2020·2020·2020·2020··01-08).·········00037f00:·3132·2d30·3729·0a20·2020·2020·2020·2020··12-07).·········
00037f10:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul00037f10:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul
00037f20:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table00037f20:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table
00037f30:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h200037f30:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2
00037f40:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href00037f40:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href
00037f50:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg00037f50:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg
00037f60:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_00037f60:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
00037f70:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy00037f70:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy
Offset 15217, 306 lines modifiedOffset 15217, 306 lines modified
0003b700:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003b700:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003b710:·6d38·3036·3222·2074·6162·696e·6465·783d··m8062"·tabindex=0003b710:·6d38·3036·3222·2074·6162·696e·6465·783d··m8062"·tabindex=
0003b720:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003b720:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003b730:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003b730:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003b740:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003b740:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003b750:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003b750:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003b760:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003b760:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003b770:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s 
0003b780:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003b790:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003b7a0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003b7b0:·6170·7365·2220·6964·3d22·6964·6d38·3036··apse"·id="idm806 
0003b7c0:·3222·3e3c·7072·653e·3c63·6f64·653e·0a23··2"><pre><code>.# 
0003b7d0:·2046·696e·6420·7768·6963·6820·6669·6c65···Find·which·file 
0003b7e0:·7320·6861·7665·2069·6e63·6f72·7265·6374··s·have·incorrect 
0003b7f0:·2068·6173·6820·286e·6f74·2069·6e20·2f65···hash·(not·in·/e 
0003b800:·7463·2c20·6265·6361·7573·6520·6f66·2074··tc,·because·of·t 
0003b810:·6865·2073·7973·7465·6d20·7265·6c61·7465··he·system·relate 
0003b820:·6420·636f·6e66·6967·2066·696c·6573·2920··d·config·files)· 
0003b830:·616e·6420·7468·656e·2067·6574·2066·696c··and·then·get·fil 
0003b840:·6573·206e·616d·6573·0a66·696c·6573·5f77··es·names.files_w 
0003b850:·6974·685f·696e·636f·7272·6563·745f·6861··ith_incorrect_ha 
0003b860:·7368·3d22·2428·7270·6d20·2d56·6120·2d2d··sh="$(rpm·-Va·-- 
0003b870:·6e6f·636f·6e66·6967·207c·2067·7265·7020··noconfig·|·grep· 
0003b880:·2d45·2027·5e2e·2e35·2720·7c20·6177·6b20··-E·'^..5'·|·awk· 
0003b890:·277b·7072·696e·7420·244e·467d·2720·2922··'{print·$NF}'·)" 
0003b8a0:·0a0a·6966·205b·202d·6e20·2224·6669·6c65··..if·[·-n·"$file 
0003b8b0:·735f·7769·7468·5f69·6e63·6f72·7265·6374··s_with_incorrect 
0003b8c0:·5f68·6173·6822·205d·3b20·7468·656e·0a20··_hash"·];·then.· 
0003b8d0:·2020·2023·2046·726f·6d20·6669·6c65·7320·····#·From·files· 
0003b8e0:·6e61·6d65·7320·6765·7420·7061·636b·6167··names·get·packag 
0003b8f0:·6520·6e61·6d65·7320·616e·6420·6368·616e··e·names·and·chan 
0003b900:·6765·206e·6577·6c69·6e65·2074·6f20·7370··ge·newline·to·sp 
0003b910:·6163·652c·2062·6563·6175·7365·2072·706d··ace,·because·rpm 
0003b920:·2077·7269·7465·7320·6561·6368·2070·6163···writes·each·pac 
0003b930:·6b61·6765·2074·6f20·6e65·7720·6c69·6e65··kage·to·new·line 
0003b940:·0a20·2020·2070·6163·6b61·6765·735f·746f··.····packages_to 
0003b950:·5f72·6569·6e73·7461·6c6c·3d22·2428·7270··_reinstall="$(rp 
0003b960:·6d20·2d71·6620·2466·696c·6573·5f77·6974··m·-qf·$files_wit 
0003b970:·685f·696e·636f·7272·6563·745f·6861·7368··h_incorrect_hash 
0003b980:·207c·2074·7220·275c·6e27·2027·2027·2922···|·tr·'\n'·'·')" 
0003b990:·0a0a·2020·2020·0a20·2020·2064·6e66·2072··..····.····dnf·r 
0003b9a0:·6569·6e73·7461·6c6c·202d·7920·2470·6163··einstall·-y·$pac 
0003b9b0:·6b61·6765·735f·746f·5f72·6569·6e73·7461··kages_to_reinsta 
0003b9c0:·6c6c·0a20·2020·200a·6669·0a3c·2f63·6f64··ll.····.fi.</cod 
0003b9d0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003b9e0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003b9f0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003ba00:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003ba10:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003ba20:·6d38·3036·3322·2074·6162·696e·6465·783d··m8063"·tabindex= 
0003ba30:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003ba40:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003ba50:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003ba60:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003ba70:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003ba80:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible0003b770:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible
0003ba90:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003b780:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003baa0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003b790:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003bab0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003b7a0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003bac0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003b7b0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003bad0:·3830·3633·223e·3c74·6162·6c65·2063·6c61··8063"><table·cla0003b7c0:·3830·3632·223e·3c74·6162·6c65·2063·6c61··8062"><table·cla
0003bae0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003b7d0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003baf0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003b7e0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003bb00:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003b7f0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003bb10:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003b800:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003bb20:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003b810:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003bb30:·3c74·643e·6869·6768·3c2f·7464·3e3c·2f74··<td>high</td></t0003b820:·3c74·643e·6869·6768·3c2f·7464·3e3c·2f74··<td>high</td></t
0003bb40:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003b830:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003bb50:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6d65··tion:</th><td>me0003b840:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6d65··tion:</th><td>me
0003bb60:·6469·756d·3c2f·7464·3e3c·2f74·723e·3c74··dium</td></tr><t0003b850:·6469·756d·3c2f·7464·3e3c·2f74·723e·3c74··dium</td></tr><t
0003bb70:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t0003b860:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
0003bb80:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>0003b870:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
0003bb90:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003b880:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003bba0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e72··ategy:</th><td>r0003b890:·6174·6567·793a·3c2f·7468·3e3c·7464·3e72··ategy:</th><td>r
0003bbb0:·6573·7472·6963·743c·2f74·643e·3c2f·7472··estrict</td></tr0003b8a0:·6573·7472·6963·743c·2f74·643e·3c2f·7472··estrict</td></tr
0003bbc0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003b8b0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
0003bbd0:·6f64·653e·2d20·6e61·6d65·3a20·2753·6574··ode>-·name:·'Set0003b8c0:·6f64·653e·2d20·6e61·6d65·3a20·2753·6574··ode>-·name:·'Set
0003bbe0:·2066·6163·743a·2050·6163·6b61·6765·206d···fact:·Package·m0003b8d0:·2066·6163·743a·2050·6163·6b61·6765·206d···fact:·Package·m
0003bbf0:·616e·6167·6572·2072·6569·6e73·7461·6c6c··anager·reinstall0003b8e0:·616e·6167·6572·2072·6569·6e73·7461·6c6c··anager·reinstall
0003bc00:·2063·6f6d·6d61·6e64·270a·2020·7365·745f···command'.··set_0003b8f0:·2063·6f6d·6d61·6e64·270a·2020·7365·745f···command'.··set_
0003bc10:·6661·6374·3a0a·2020·2020·7061·636b·6167··fact:.····packag0003b900:·6661·6374·3a0a·2020·2020·7061·636b·6167··fact:.····packag
0003bc20:·655f·6d61·6e61·6765·725f·7265·696e·7374··e_manager_reinst0003b910:·655f·6d61·6e61·6765·725f·7265·696e·7374··e_manager_reinst
0003bc30:·616c·6c5f·636d·643a·2064·6e66·2072·6569··all_cmd:·dnf·rei0003b920:·616c·6c5f·636d·643a·2064·6e66·2072·6569··all_cmd:·dnf·rei
0003bc40:·6e73·7461·6c6c·202d·790a·2020·7768·656e··nstall·-y.··when0003b930:·6e73·7461·6c6c·202d·790a·2020·7768·656e··nstall·-y.··when
0003bc50:·3a20·616e·7369·626c·655f·6469·7374·7269··:·ansible_distri0003b940:·3a20·616e·7369·626c·655f·6469·7374·7269··:·ansible_distri
0003bc60:·6275·7469·6f6e·2069·6e20·5b20·2246·6564··bution·in·[·"Fed0003b950:·6275·7469·6f6e·2069·6e20·5b20·2246·6564··bution·in·[·"Fed
0003bc70:·6f72·6122·2c20·2252·6564·4861·7422·2c20··ora",·"RedHat",·0003b960:·6f72·6122·2c20·2252·6564·4861·7422·2c20··ora",·"RedHat",·
0003bc80:·2243·656e·744f·5322·2c20·224f·7261·636c··"CentOS",·"Oracl0003b970:·2243·656e·744f·5322·2c20·224f·7261·636c··"CentOS",·"Oracl
0003bc90:·654c·696e·7578·2220·5d0a·2020·7461·6773··eLinux"·].··tags0003b980:·654c·696e·7578·2220·5d0a·2020·7461·6773··eLinux"·].··tags
0003bca0:·3a0a·2020·2d20·4343·452d·3930·3834·312d··:.··-·CCE-90841-0003b990:·3a0a·2020·2d20·4343·452d·3930·3834·312d··:.··-·CCE-90841-
0003bcb0:·380a·2020·2d20·434a·4953·2d35·2e31·302e··8.··-·CJIS-5.10.0003b9a0:·380a·2020·2d20·434a·4953·2d35·2e31·302e··8.··-·CJIS-5.10.
0003bcc0:·342e·310a·2020·2d20·4e49·5354·2d38·3030··4.1.··-·NIST-8000003b9b0:·342e·310a·2020·2d20·4e49·5354·2d38·3030··4.1.··-·NIST-800
0003bcd0:·2d31·3731·2d33·2e33·2e38·0a20·202d·204e··-171-3.3.8.··-·N0003b9c0:·2d31·3731·2d33·2e33·2e38·0a20·202d·204e··-171-3.3.8.··-·N
0003bce0:·4953·542d·3830·302d·3137·312d·332e·342e··IST-800-171-3.4.0003b9d0:·4953·542d·3830·302d·3137·312d·332e·342e··IST-800-171-3.4.
0003bcf0:·310a·2020·2d20·4e49·5354·2d38·3030·2d35··1.··-·NIST-800-50003b9e0:·310a·2020·2d20·4e49·5354·2d38·3030·2d35··1.··-·NIST-800-5
0003bd00:·332d·4155·2d39·2833·290a·2020·2d20·4e49··3-AU-9(3).··-·NI0003b9f0:·332d·4155·2d39·2833·290a·2020·2d20·4e49··3-AU-9(3).··-·NI
0003bd10:·5354·2d38·3030·2d35·332d·434d·2d36·2863··ST-800-53-CM-6(c0003ba00:·5354·2d38·3030·2d35·332d·434d·2d36·2863··ST-800-53-CM-6(c
0003bd20:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-50003ba10:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5
0003bd30:·332d·434d·2d36·2864·290a·2020·2d20·4e49··3-CM-6(d).··-·NI0003ba20:·332d·434d·2d36·2864·290a·2020·2d20·4e49··3-CM-6(d).··-·NI
0003bd40:·5354·2d38·3030·2d35·332d·5349·2d37·0a20··ST-800-53-SI-7.·0003ba30:·5354·2d38·3030·2d35·332d·5349·2d37·0a20··ST-800-53-SI-7.·
0003bd50:·202d·204e·4953·542d·3830·302d·3533·2d53···-·NIST-800-53-S0003ba40:·202d·204e·4953·542d·3830·302d·3533·2d53···-·NIST-800-53-S
0003bd60:·492d·3728·3129·0a20·202d·204e·4953·542d··I-7(1).··-·NIST-0003ba50:·492d·3728·3129·0a20·202d·204e·4953·542d··I-7(1).··-·NIST-
0003bd70:·3830·302d·3533·2d53·492d·3728·3629·0a20··800-53-SI-7(6).·0003ba60:·3830·302d·3533·2d53·492d·3728·3629·0a20··800-53-SI-7(6).·
0003bd80:·202d·2050·4349·2d44·5353·2d52·6571·2d31···-·PCI-DSS-Req-10003ba70:·202d·2050·4349·2d44·5353·2d52·6571·2d31···-·PCI-DSS-Req-1
0003bd90:·312e·350a·2020·2d20·5043·492d·4453·5376··1.5.··-·PCI-DSSv0003ba80:·312e·350a·2020·2d20·5043·492d·4453·5376··1.5.··-·PCI-DSSv
0003bda0:·342d·3131·2e35·2e32·0a20·202d·2068·6967··4-11.5.2.··-·hig0003ba90:·342d·3131·2e35·2e32·0a20·202d·2068·6967··4-11.5.2.··-·hig
0003bdb0:·685f·636f·6d70·6c65·7869·7479·0a20·202d··h_complexity.··-0003baa0:·685f·636f·6d70·6c65·7869·7479·0a20·202d··h_complexity.··-
0003bdc0:·2068·6967·685f·7365·7665·7269·7479·0a20···high_severity.·0003bab0:·2068·6967·685f·7365·7665·7269·7479·0a20···high_severity.·
0003bdd0:·202d·206d·6564·6975·6d5f·6469·7372·7570···-·medium_disrup0003bac0:·202d·206d·6564·6975·6d5f·6469·7372·7570···-·medium_disrup
Max diff block lines reached; 9951807/9993951 bytes (99.58%) of diff not shown.
1020 KB
html2text {}
    
Offset 44, 15 lines modifiedOffset 44, 15 lines modified
44 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*44 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Australian·Cyber·Security·Centre·(ACSC)·ISM·Official45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Australian·Cyber·Security·Centre·(ACSC)·ISM·Official
46 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ism_o46 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ism_o
47 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*47 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
48 ····*·cpe:/o:redhat:enterprise_linux:948 ····*·cpe:/o:redhat:enterprise_linux:9
49 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*49 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
50 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8450 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
51 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)51 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
52 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*52 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
53 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s53 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
54 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e54 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
55 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l55 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
56 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g56 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
57 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s57 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
58 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s58 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 111, 27 lines modifiedOffset 111, 14 lines modified
111 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6111 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
112 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4112 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
113 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)113 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
114 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1114 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
115 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5115 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
116 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227116 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
117 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2117 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
119 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
120 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
121 if·[·-n·"$files_with_incorrect_hash"·];·then 
122 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
123 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
124 ····dnf·reinstall·-y·$packages_to_reinstall 
  
125 fi 
126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
131 -·name:·'Set·fact:·Package·manager·reinstall·command'123 -·name:·'Set·fact:·Package·manager·reinstall·command'
132 ··set_fact:124 ··set_fact:
Offset 263, 14 lines modifiedOffset 250, 27 lines modified
263 ··-·PCI-DSSv4-11.5.2250 ··-·PCI-DSSv4-11.5.2
264 ··-·high_complexity251 ··-·high_complexity
265 ··-·high_severity252 ··-·high_severity
266 ··-·medium_disruption253 ··-·medium_disruption
267 ··-·no_reboot_needed254 ··-·no_reboot_needed
268 ··-·restrict_strategy255 ··-·restrict_strategy
269 ··-·rpm_verify_hashes256 ··-·rpm_verify_hashes
 257 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 258 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 259 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 260 if·[·-n·"$files_with_incorrect_hash"·];·then
 261 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 262 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 263 ····dnf·reinstall·-y·$packages_to_reinstall
  
 264 fi
270 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*265 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
271 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:266 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
272 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'267 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
273 run·the·following·command·to·determine·which·package·owns·it:268 run·the·following·command·to·determine·which·package·owns·it:
274 $·rpm·-qf·FILENAME269 $·rpm·-qf·FILENAME
275 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:270 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
276 $·sudo·rpm·--setugids·PACKAGENAME271 $·sudo·rpm·--setugids·PACKAGENAME
Offset 290, 40 lines modifiedOffset 290, 14 lines modified
290 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5290 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
291 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2291 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
292 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)292 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
293 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1293 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
294 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5294 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
295 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108295 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
296 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2296 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
297 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
298 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
299 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
300 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
301 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
302 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
303 declare·-A·SETPERMS_RPM_DICT 
  
304 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
305 #·is·expected·by·the·RPM·database 
306 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
307 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
308 do 
309 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
310 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
311 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
312 done 
  
313 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
314 #·correct·values 
315 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
316 do 
317 ········rpm·--setugids·"${RPM_PACKAGE}" 
318 done 
319 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8297 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
320 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high298 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
321 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium299 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
322 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false300 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
323 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict301 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
324 -·name:·Read·list·of·files·with·incorrect·ownership302 -·name:·Read·list·of·files·with·incorrect·ownership
325 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev303 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 401, 14 lines modifiedOffset 375, 40 lines modified
401 ··-·PCI-DSSv4-11.5.2375 ··-·PCI-DSSv4-11.5.2
402 ··-·high_complexity376 ··-·high_complexity
403 ··-·high_severity377 ··-·high_severity
404 ··-·medium_disruption378 ··-·medium_disruption
405 ··-·no_reboot_needed379 ··-·no_reboot_needed
406 ··-·restrict_strategy380 ··-·restrict_strategy
407 ··-·rpm_verify_ownership381 ··-·rpm_verify_ownership
 382 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 383 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 384 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 385 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 386 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 387 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 1038507/1046413 bytes (99.24%) of diff not shown.
6.86 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-ospp.html
    
Offset 14302, 16 lines modifiedOffset 14302, 16 lines modified
00037dd0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h00037dd0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h
00037de0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver00037de0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver
00037df0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.00037df0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.
00037e00:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p00037e00:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p
00037e10:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong00037e10:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong
00037e20:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.00037e20:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.
00037e30:·2020·2020·2020·2020·2020·2020·2020·2020··················00037e30:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037e40:·2020·2020·2861·7320·6f66·2032·3032·362d······(as·of·2026-00037e40:·2020·2020·2861·7320·6f66·2032·3032·342d······(as·of·2024-
00037e50:·3031·2d30·3829·0a20·2020·2020·2020·2020··01-08).·········00037e50:·3132·2d30·3729·0a20·2020·2020·2020·2020··12-07).·········
00037e60:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul00037e60:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul
00037e70:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table00037e70:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table
00037e80:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h200037e80:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2
00037e90:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href00037e90:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href
00037ea0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg00037ea0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg
00037eb0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_00037eb0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
00037ec0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy00037ec0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy
Offset 15070, 200 lines modifiedOffset 15070, 200 lines modified
0003add0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003add0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003ade0:·2369·646d·3839·3331·2220·7461·6269·6e64··#idm8931"·tabind0003ade0:·2369·646d·3839·3331·2220·7461·6269·6e64··#idm8931"·tabind
0003adf0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003adf0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003ae00:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003ae00:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003ae10:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003ae10:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003ae20:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003ae20:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003ae30:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003ae30:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003ae40:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel0003ae40:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi
0003ae50:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a> 
0003ae60:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003ae70:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003ae80:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003ae90:·3839·3331·223e·3c70·7265·3e3c·636f·6465··8931"><pre><code 
0003aea0:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i 
0003aeb0:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl 
0003aec0:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla 
0003aed0:·7466·6f72·6d73·0a69·6620·2820·5b20·2120··tforms.if·(·[·!· 
0003aee0:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·] 
0003aef0:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!· 
0003af00:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain 
0003af10:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am 
0003af20:·703b·2021·2028·205b·2022·247b·636f·6e74··p;·!·(·[·"${cont 
0003af30:·6169·6e65·723a·2d7d·2220·3d3d·2022·6277··ainer:-}"·==·"bw 
0003af40:·7261·702d·6f73·6275·696c·6422·205d·2029··rap-osbuild"·]·) 
0003af50:·2029·3b20·7468·656e·0a0a·6669·7073·2d6d···);·then..fips-m 
0003af60:·6f64·652d·7365·7475·7020·2d2d·656e·6162··ode-setup·--enab 
0003af70:·6c65·0a46·4950·535f·434f·4e46·3d22·2f65··le.FIPS_CONF="/e 
0003af80:·7463·2f64·7261·6375·742e·636f·6e66·2e64··tc/dracut.conf.d 
0003af90:·2f34·302d·6669·7073·2e63·6f6e·6622·0a69··/40-fips.conf".i 
0003afa0:·6620·2120·6772·6570·2022·5e61·6464·5f64··f·!·grep·"^add_d 
0003afb0:·7261·6375·746d·6f64·756c·6573·2b3d·5c22··racutmodules+=\" 
0003afc0:·2066·6970·7320·5c22·2220·2446·4950·535f···fips·\""·$FIPS_ 
0003afd0:·434f·4e46·3b20·7468·656e·0a20·2020·2065··CONF;·then.····e 
0003afe0:·6368·6f20·2261·6464·5f64·7261·6375·746d··cho·"add_dracutm 
0003aff0:·6f64·756c·6573·2b3d·5c22·2066·6970·7320··odules+=\"·fips· 
0003b000:·5c22·2220·2667·743b·2667·743b·2024·4649··\""·&gt;&gt;·$FI 
0003b010:·5053·5f43·4f4e·460a·6669·0a0a·656c·7365··PS_CONF.fi..else 
0003b020:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2· 
0003b030:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio 
0003b040:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica 
0003b050:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was 
0003b060:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code 
0003b070:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003b080:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003b090:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003b0a0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003b0b0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003b0c0:·3839·3332·2220·7461·6269·6e64·6578·3d22··8932"·tabindex=" 
0003b0d0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003b0e0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003b0f0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003b100:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003b110:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003b120:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible· 
0003b130:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003ae50:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...<
0003b140:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b150:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003ae60:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003ae70:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003b160:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm80003ae80:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
0003b170:·3933·3222·3e3c·7461·626c·6520·636c·6173··932"><table·clas 
0003b180:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003ae90:·6964·6d38·3933·3122·3e3c·7461·626c·6520··idm8931"><table·
 0003aea0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003b190:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003aeb0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003b1a0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003aec0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003b1b0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b1c0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003aed0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003aee0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003aef0:·7468·3e3c·7464·3e6d·6564·6975·6d3c·2f74··th><td>medium</t
 0003af00:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0003af10:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003b1d0:·7464·3e6d·6564·6975·6d3c·2f74·643e·3c2f··td>medium</td></0003af20:·7464·3e6d·6564·6975·6d3c·2f74·643e·3c2f··td>medium</td></
 0003af30:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
0003b1e0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003b1f0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6d··ption:</th><td>m 
0003b200:·6564·6975·6d3c·2f74·643e·3c2f·7472·3e3c··edium</td></tr>< 
0003b210:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003b220:·7468·3e3c·7464·3e74·7275·653c·2f74·643e··th><td>true</td> 
0003b230:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003b240:·6174·6567·793a·3c2f·7468·3e3c·7464·3e72··ategy:</th><td>r0003af40:·743a·3c2f·7468·3e3c·7464·3e74·7275·653c··t:</th><td>true<
0003b250:·6573·7472·6963·743c·2f74·643e·3c2f·7472··estrict</td></tr 
0003b260:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003b270:·6f64·653e·2d20·6e61·6d65·3a20·4368·6563··ode>-·name:·Chec 
0003b280:·6b20·746f·2073·6565·2074·6865·2063·7572··k·to·see·the·cur0003af50:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003af60:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003af70:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>
 0003af80:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003af90:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·
 0003afa0:·4368·6563·6b20·746f·2073·6565·2074·6865··Check·to·see·the
0003b290:·7265·6e74·2073·7461·7475·7320·6f66·2046··rent·status·of·F0003afb0:·2063·7572·7265·6e74·2073·7461·7475·7320···current·status·
0003b2a0:·4950·5320·6d6f·6465·0a20·2063·6f6d·6d61··IPS·mode.··comma0003afc0:·6f66·2046·4950·5320·6d6f·6465·0a20·2063··of·FIPS·mode.··c
0003b2b0:·6e64·3a20·2f75·7372·2f62·696e·2f66·6970··nd:·/usr/bin/fip 
0003b2c0:·732d·6d6f·6465·2d73·6574·7570·202d·2d63··s-mode-setup·--c0003afd0:·6f6d·6d61·6e64·3a20·2f75·7372·2f62·696e··ommand:·/usr/bin
 0003afe0:·2f66·6970·732d·6d6f·6465·2d73·6574·7570··/fips-mode-setup
0003b2d0:·6865·636b·0a20·2072·6567·6973·7465·723a··heck.··register:0003aff0:·202d·2d63·6865·636b·0a20·2072·6567·6973···--check.··regis
 0003b000:·7465·723a·2069·735f·6669·7073·5f65·6e61··ter:·is_fips_ena
 0003b010:·626c·6564·0a20·2063·6861·6e67·6564·5f77··bled.··changed_w
 0003b020:·6865·6e3a·2066·616c·7365·0a20·2066·6169··hen:·false.··fai
 0003b030:·6c65·645f·7768·656e·3a20·6661·6c73·650a··led_when:·false.
 0003b040:·2020·7768·656e·3a20·2820·616e·7369·626c····when:·(·ansibl
 0003b050:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization
 0003b060:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d
 0003b070:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"
 0003b080:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman
 0003b090:·222c·0a20·2020·2022·636f·6e74·6169·6e65··",.····"containe
 0003b0a0:·7222·5d20·616e·6420·6e6f·7420·2820·6c6f··r"]·and·not·(·lo
 0003b0b0:·6f6b·7570·2822·656e·7622·2c20·2263·6f6e··okup("env",·"con
 0003b0c0:·7461·696e·6572·2229·203d·3d20·2262·7772··tainer")·==·"bwr
 0003b0d0:·6170·2d6f·7362·7569·6c64·2220·2920·290a··ap-osbuild"·)·).
 0003b0e0:·2020·7461·6773·3a0a·2020·2d20·4343·452d····tags:.··-·CCE-
 0003b0f0:·3836·3534·372d·370a·2020·2d20·4449·5341··86547-7.··-·DISA
Max diff block lines reached; 6272547/6292335 bytes (99.69%) of diff not shown.
877 KB
html2text {}
    
Offset 41, 15 lines modifiedOffset 41, 15 lines modified
41 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*41 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Protection·Profile·for·General·Purpose·Operating·Systems42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Protection·Profile·for·General·Purpose·Operating·Systems
43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ospp43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_ospp
44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
45 ····*·cpe:/o:redhat:enterprise_linux:945 ····*·cpe:/o:redhat:enterprise_linux:9
46 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
47 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8447 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
48 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)48 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
49 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*49 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
50 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s50 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
51 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e51 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
52 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l52 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
53 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n53 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
54 ·········4.·_\x8z_\x8I_\x8P_\x8L_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n54 ·········4.·_\x8z_\x8I_\x8P_\x8L_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
55 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s55 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 92, 27 lines modifiedOffset 92, 14 lines modified
92 ·············_\x8i_\x8s_\x8m······144692 ·············_\x8i_\x8s_\x8m······1446
93 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.193 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
94 References:··_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-1294 References:··_\x8n_\x8i_\x8s_\x8t·····SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
95 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.195 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_RBG_EXT.1
96 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-0022396 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223
97 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-09-67101097 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-09-671010
98 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule98 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule
99 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
100 #·Remediation·is·applicable·only·in·certain·platforms 
101 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·);·then 
  
102 fips-mode-setup·--enable 
103 FIPS_CONF="/etc/dracut.conf.d/40-fips.conf" 
104 if·!·grep·"^add_dracutmodules+=\"·fips·\""·$FIPS_CONF;·then 
105 ····echo·"add_dracutmodules+=\"·fips·\""·>>·$FIPS_CONF 
106 fi 
  
107 else 
108 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
109 fi 
110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x899 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
111 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium100 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium
112 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium101 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
113 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true102 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
114 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict103 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
115 -·name:·Check·to·see·the·current·status·of·FIPS·mode104 -·name:·Check·to·see·the·current·status·of·FIPS·mode
116 ··command:·/usr/bin/fips-mode-setup·--check105 ··command:·/usr/bin/fips-mode-setup·--check
Offset 176, 14 lines modifiedOffset 163, 27 lines modified
176 ··-·NIST-800-53-SC-13163 ··-·NIST-800-53-SC-13
177 ··-·enable_dracut_fips_module164 ··-·enable_dracut_fips_module
178 ··-·high_severity165 ··-·high_severity
179 ··-·medium_complexity166 ··-·medium_complexity
180 ··-·medium_disruption167 ··-·medium_disruption
181 ··-·reboot_required168 ··-·reboot_required
182 ··-·restrict_strategy169 ··-·restrict_strategy
 170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 171 #·Remediation·is·applicable·only·in·certain·platforms
 172 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·);·then
  
 173 fips-mode-setup·--enable
 174 FIPS_CONF="/etc/dracut.conf.d/40-fips.conf"
 175 if·!·grep·"^add_dracutmodules+=\"·fips·\""·$FIPS_CONF;·then
 176 ····echo·"add_dracutmodules+=\"·fips·\""·>>·$FIPS_CONF
 177 fi
  
 178 else
 179 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 180 fi
183 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*181 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
184 To·enable·FIPS·mode,·run·the·following·command:182 To·enable·FIPS·mode,·run·the·following·command:
185 fips-mode-setup·--enable183 fips-mode-setup·--enable
  
186 The·fips-mode-setup·command·will·configure·the·system·in·FIPS·mode·by·automatically·configuring·the·following:184 The·fips-mode-setup·command·will·configure·the·system·in·FIPS·mode·by·automatically·configuring·the·following:
187 ····*·Setting·the·kernel·FIPS·mode·flag·(/proc/sys/crypto/fips_enabled)·to·1185 ····*·Setting·the·kernel·FIPS·mode·flag·(/proc/sys/crypto/fips_enabled)·to·1
188 ····*·Creating·/etc/system-fips186 ····*·Creating·/etc/system-fips
Offset 199, 41 lines modifiedOffset 199, 18 lines modified
199 ·············_\x8i_\x8s_\x8m······1446199 ·············_\x8i_\x8s_\x8m······1446
200 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1200 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
201 References:··_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12201 References:··_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
202 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1202 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
203 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176203 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
204 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-09-671010204 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-09-671010
205 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule205 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r926677_rule
 206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
207 #·Remediation·is·applicable·only·in·certain·platforms 
208 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·)·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then 
  
209 var_system_crypto_policy='FIPS:OSPP' 
  
  
210 fips-mode-setup·--enable 
  
211 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/dev/null) 
212 rc=$? 
  
213 if·test·"$rc"·=·127;·then 
214 »       echo·"$stderr_of_call"·>&2 
215 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
216 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
217 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
218 »       false··#·end·with·an·error·code 
219 elif·test·"$rc"·!=·0;·then 
220 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
221 »       false··#·end·with·an·error·code 
222 fi 
  
 207 [customizations]
 208 fips·=·true
223 else 
224 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
225 fi 
226 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
227 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium210 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·medium
228 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium211 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
229 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true212 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
230 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict213 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
231 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable214 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
232 ··set_fact:215 ··set_fact:
Offset 337, 18 lines modifiedOffset 314, 41 lines modified
337 ··-·NIST-800-53-SC-13314 ··-·NIST-800-53-SC-13
338 ··-·enable_fips_mode315 ··-·enable_fips_mode
339 ··-·high_severity316 ··-·high_severity
340 ··-·medium_complexity317 ··-·medium_complexity
341 ··-·medium_disruption318 ··-·medium_disruption
342 ··-·reboot_required319 ··-·reboot_required
343 ··-·restrict_strategy320 ··-·restrict_strategy
344 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8321 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 322 #·Remediation·is·applicable·only·in·certain·platforms
 323 if·(·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·)·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
Max diff block lines reached; 892153/898436 bytes (99.30%) of diff not shown.
18.1 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-pci-dss.html
    
Offset 14302, 15 lines modifiedOffset 14302, 15 lines modified
00037dd0:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre00037dd0:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre
00037de0:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str00037de0:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str
00037df0:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro00037df0:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro
00037e00:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><00037e00:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><
00037e10:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st00037e10:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st
00037e20:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········00037e20:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········
00037e30:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of00037e30:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of
00037e40:·2032·3032·362d·3031·2d30·3829·0a20·2020···2026-01-08).···00037e40:·2032·3032·342d·3132·2d30·3729·0a20·2020···2024-12-07).···
00037e50:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l00037e50:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l
00037e60:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h200037e60:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h2
00037e70:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten00037e70:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten
00037e80:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><00037e80:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><
00037e90:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o00037e90:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o
00037ea0:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co00037ea0:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co
00037eb0:·6e74·656e·745f·6772·6f75·705f·7379·7374··ntent_group_syst00037eb0:·6e74·656e·745f·6772·6f75·705f·7379·7374··ntent_group_syst
Offset 15209, 306 lines modifiedOffset 15209, 306 lines modified
0003b680:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b680:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003b690:·2223·6964·6d38·3036·3222·2074·6162·696e··"#idm8062"·tabin0003b690:·2223·6964·6d38·3036·3222·2074·6162·696e··"#idm8062"·tabin
0003b6a0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b6a0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b6b0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b6b0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b6c0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b6c0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b6d0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b6d0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b6e0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b6e0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b6f0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
0003b700:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
0003b710:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b720:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b730:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b740:·6d38·3036·3222·3e3c·7072·653e·3c63·6f64··m8062"><pre><cod 
0003b750:·653e·0a23·2046·696e·6420·7768·6963·6820··e>.#·Find·which· 
0003b760:·6669·6c65·7320·6861·7665·2069·6e63·6f72··files·have·incor 
0003b770:·7265·6374·2068·6173·6820·286e·6f74·2069··rect·hash·(not·i 
0003b780:·6e20·2f65·7463·2c20·6265·6361·7573·6520··n·/etc,·because· 
0003b790:·6f66·2074·6865·2073·7973·7465·6d20·7265··of·the·system·re 
0003b7a0:·6c61·7465·6420·636f·6e66·6967·2066·696c··lated·config·fil 
0003b7b0:·6573·2920·616e·6420·7468·656e·2067·6574··es)·and·then·get 
0003b7c0:·2066·696c·6573·206e·616d·6573·0a66·696c···files·names.fil 
0003b7d0:·6573·5f77·6974·685f·696e·636f·7272·6563··es_with_incorrec 
0003b7e0:·745f·6861·7368·3d22·2428·7270·6d20·2d56··t_hash="$(rpm·-V 
0003b7f0:·6120·2d2d·6e6f·636f·6e66·6967·207c·2067··a·--noconfig·|·g 
0003b800:·7265·7020·2d45·2027·5e2e·2e35·2720·7c20··rep·-E·'^..5'·|· 
0003b810:·6177·6b20·277b·7072·696e·7420·244e·467d··awk·'{print·$NF} 
0003b820:·2720·2922·0a0a·6966·205b·202d·6e20·2224··'·)"..if·[·-n·"$ 
0003b830:·6669·6c65·735f·7769·7468·5f69·6e63·6f72··files_with_incor 
0003b840:·7265·6374·5f68·6173·6822·205d·3b20·7468··rect_hash"·];·th 
0003b850:·656e·0a20·2020·2023·2046·726f·6d20·6669··en.····#·From·fi 
0003b860:·6c65·7320·6e61·6d65·7320·6765·7420·7061··les·names·get·pa 
0003b870:·636b·6167·6520·6e61·6d65·7320·616e·6420··ckage·names·and· 
0003b880:·6368·616e·6765·206e·6577·6c69·6e65·2074··change·newline·t 
0003b890:·6f20·7370·6163·652c·2062·6563·6175·7365··o·space,·because 
0003b8a0:·2072·706d·2077·7269·7465·7320·6561·6368···rpm·writes·each 
0003b8b0:·2070·6163·6b61·6765·2074·6f20·6e65·7720···package·to·new· 
0003b8c0:·6c69·6e65·0a20·2020·2070·6163·6b61·6765··line.····package 
0003b8d0:·735f·746f·5f72·6569·6e73·7461·6c6c·3d22··s_to_reinstall=" 
0003b8e0:·2428·7270·6d20·2d71·6620·2466·696c·6573··$(rpm·-qf·$files 
0003b8f0:·5f77·6974·685f·696e·636f·7272·6563·745f··_with_incorrect_ 
0003b900:·6861·7368·207c·2074·7220·275c·6e27·2027··hash·|·tr·'\n'·' 
0003b910:·2027·2922·0a0a·2020·2020·0a20·2020·2064···')"..····.····d 
0003b920:·6e66·2072·6569·6e73·7461·6c6c·202d·7920··nf·reinstall·-y· 
0003b930:·2470·6163·6b61·6765·735f·746f·5f72·6569··$packages_to_rei 
0003b940:·6e73·7461·6c6c·0a20·2020·200a·6669·0a3c··nstall.····.fi.< 
0003b950:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003b960:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003b970:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003b980:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003b990:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003b9a0:·2223·6964·6d38·3036·3322·2074·6162·696e··"#idm8063"·tabin 
0003b9b0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003b9c0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003b9d0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003b9e0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003b9f0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003ba00:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans0003b6f0:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans
0003ba10:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...0003b700:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...
0003ba20:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003b710:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003ba30:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003b720:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003ba40:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003b730:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003ba50:·2269·646d·3830·3633·223e·3c74·6162·6c65··"idm8063"><table0003b740:·2269·646d·3830·3632·223e·3c74·6162·6c65··"idm8062"><table
0003ba60:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003b750:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003ba70:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003b760:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003ba80:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003b770:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003ba90:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003b780:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003baa0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003b790:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003bab0:·2f74·683e·3c74·643e·6869·6768·3c2f·7464··/th><td>high</td0003b7a0:·2f74·683e·3c74·643e·6869·6768·3c2f·7464··/th><td>high</td
0003bac0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003b7b0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003bad0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003b7c0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003bae0:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t0003b7d0:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t
0003baf0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot0003b7e0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
0003bb00:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<0003b7f0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003bb10:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b800:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003bb20:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003b810:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003bb30:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>0003b820:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>
0003bb40:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003b830:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
0003bb50:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·0003b840:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·
0003bb60:·2753·6574·2066·6163·743a·2050·6163·6b61··'Set·fact:·Packa0003b850:·2753·6574·2066·6163·743a·2050·6163·6b61··'Set·fact:·Packa
0003bb70:·6765·206d·616e·6167·6572·2072·6569·6e73··ge·manager·reins0003b860:·6765·206d·616e·6167·6572·2072·6569·6e73··ge·manager·reins
0003bb80:·7461·6c6c·2063·6f6d·6d61·6e64·270a·2020··tall·command'.··0003b870:·7461·6c6c·2063·6f6d·6d61·6e64·270a·2020··tall·command'.··
0003bb90:·7365·745f·6661·6374·3a0a·2020·2020·7061··set_fact:.····pa0003b880:·7365·745f·6661·6374·3a0a·2020·2020·7061··set_fact:.····pa
0003bba0:·636b·6167·655f·6d61·6e61·6765·725f·7265··ckage_manager_re0003b890:·636b·6167·655f·6d61·6e61·6765·725f·7265··ckage_manager_re
0003bbb0:·696e·7374·616c·6c5f·636d·643a·2064·6e66··install_cmd:·dnf0003b8a0:·696e·7374·616c·6c5f·636d·643a·2064·6e66··install_cmd:·dnf
0003bbc0:·2072·6569·6e73·7461·6c6c·202d·790a·2020···reinstall·-y.··0003b8b0:·2072·6569·6e73·7461·6c6c·202d·790a·2020···reinstall·-y.··
0003bbd0:·7768·656e·3a20·616e·7369·626c·655f·6469··when:·ansible_di0003b8c0:·7768·656e·3a20·616e·7369·626c·655f·6469··when:·ansible_di
0003bbe0:·7374·7269·6275·7469·6f6e·2069·6e20·5b20··stribution·in·[·0003b8d0:·7374·7269·6275·7469·6f6e·2069·6e20·5b20··stribution·in·[·
0003bbf0:·2246·6564·6f72·6122·2c20·2252·6564·4861··"Fedora",·"RedHa0003b8e0:·2246·6564·6f72·6122·2c20·2252·6564·4861··"Fedora",·"RedHa
0003bc00:·7422·2c20·2243·656e·744f·5322·2c20·224f··t",·"CentOS",·"O0003b8f0:·7422·2c20·2243·656e·744f·5322·2c20·224f··t",·"CentOS",·"O
0003bc10:·7261·636c·654c·696e·7578·2220·5d0a·2020··racleLinux"·].··0003b900:·7261·636c·654c·696e·7578·2220·5d0a·2020··racleLinux"·].··
0003bc20:·7461·6773·3a0a·2020·2d20·4343·452d·3930··tags:.··-·CCE-900003b910:·7461·6773·3a0a·2020·2d20·4343·452d·3930··tags:.··-·CCE-90
0003bc30:·3834·312d·380a·2020·2d20·434a·4953·2d35··841-8.··-·CJIS-50003b920:·3834·312d·380a·2020·2d20·434a·4953·2d35··841-8.··-·CJIS-5
0003bc40:·2e31·302e·342e·310a·2020·2d20·4e49·5354··.10.4.1.··-·NIST0003b930:·2e31·302e·342e·310a·2020·2d20·4e49·5354··.10.4.1.··-·NIST
0003bc50:·2d38·3030·2d31·3731·2d33·2e33·2e38·0a20··-800-171-3.3.8.·0003b940:·2d38·3030·2d31·3731·2d33·2e33·2e38·0a20··-800-171-3.3.8.·
0003bc60:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-0003b950:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
0003bc70:·332e·342e·310a·2020·2d20·4e49·5354·2d38··3.4.1.··-·NIST-80003b960:·332e·342e·310a·2020·2d20·4e49·5354·2d38··3.4.1.··-·NIST-8
0003bc80:·3030·2d35·332d·4155·2d39·2833·290a·2020··00-53-AU-9(3).··0003b970:·3030·2d35·332d·4155·2d39·2833·290a·2020··00-53-AU-9(3).··
0003bc90:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM0003b980:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
0003bca0:·2d36·2863·290a·2020·2d20·4e49·5354·2d38··-6(c).··-·NIST-80003b990:·2d36·2863·290a·2020·2d20·4e49·5354·2d38··-6(c).··-·NIST-8
0003bcb0:·3030·2d35·332d·434d·2d36·2864·290a·2020··00-53-CM-6(d).··0003b9a0:·3030·2d35·332d·434d·2d36·2864·290a·2020··00-53-CM-6(d).··
0003bcc0:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI0003b9b0:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI
0003bcd0:·2d37·0a20·202d·204e·4953·542d·3830·302d··-7.··-·NIST-800-0003b9c0:·2d37·0a20·202d·204e·4953·542d·3830·302d··-7.··-·NIST-800-
0003bce0:·3533·2d53·492d·3728·3129·0a20·202d·204e··53-SI-7(1).··-·N0003b9d0:·3533·2d53·492d·3728·3129·0a20·202d·204e··53-SI-7(1).··-·N
0003bcf0:·4953·542d·3830·302d·3533·2d53·492d·3728··IST-800-53-SI-7(0003b9e0:·4953·542d·3830·302d·3533·2d53·492d·3728··IST-800-53-SI-7(
0003bd00:·3629·0a20·202d·2050·4349·2d44·5353·2d52··6).··-·PCI-DSS-R0003b9f0:·3629·0a20·202d·2050·4349·2d44·5353·2d52··6).··-·PCI-DSS-R
0003bd10:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI-0003ba00:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI-
0003bd20:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··-0003ba10:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··-
0003bd30:·2068·6967·685f·636f·6d70·6c65·7869·7479···high_complexity0003ba20:·2068·6967·685f·636f·6d70·6c65·7869·7479···high_complexity
0003bd40:·0a20·202d·2068·6967·685f·7365·7665·7269··.··-·high_severi0003ba30:·0a20·202d·2068·6967·685f·7365·7665·7269··.··-·high_severi
0003bd50:·7479·0a20·202d·206d·6564·6975·6d5f·6469··ty.··-·medium_di0003ba40:·7479·0a20·202d·206d·6564·6975·6d5f·6469··ty.··-·medium_di
0003bd60:·7372·7570·7469·6f6e·0a20·202d·206e·6f5f··sruption.··-·no_0003ba50:·7372·7570·7469·6f6e·0a20·202d·206e·6f5f··sruption.··-·no_
Max diff block lines reached; 17215433/17257439 bytes (99.76%) of diff not shown.
1.61 MB
html2text {}
    
Offset 42, 15 lines modifiedOffset 42, 15 lines modified
42 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v4.0·Control·Baseline·for·Red·Hat·Enterprise·Linux·943 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v4.0·Control·Baseline·for·Red·Hat·Enterprise·Linux·9
44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss44 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss
45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*45 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
46 ····*·cpe:/o:redhat:enterprise_linux:946 ····*·cpe:/o:redhat:enterprise_linux:9
47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
48 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8448 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
54 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n54 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
55 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g55 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
56 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s56 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 110, 27 lines modifiedOffset 110, 14 lines modified
110 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6110 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
111 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4111 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
112 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)112 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
113 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1113 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
114 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5114 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
115 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227115 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
116 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2116 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
117 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
118 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
119 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
120 if·[·-n·"$files_with_incorrect_hash"·];·then 
121 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
122 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
123 ····dnf·reinstall·-y·$packages_to_reinstall 
  
124 fi 
125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8117 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high118 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium119 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false120 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict121 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
130 -·name:·'Set·fact:·Package·manager·reinstall·command'122 -·name:·'Set·fact:·Package·manager·reinstall·command'
131 ··set_fact:123 ··set_fact:
Offset 262, 14 lines modifiedOffset 249, 27 lines modified
262 ··-·PCI-DSSv4-11.5.2249 ··-·PCI-DSSv4-11.5.2
263 ··-·high_complexity250 ··-·high_complexity
264 ··-·high_severity251 ··-·high_severity
265 ··-·medium_disruption252 ··-·medium_disruption
266 ··-·no_reboot_needed253 ··-·no_reboot_needed
267 ··-·restrict_strategy254 ··-·restrict_strategy
268 ··-·rpm_verify_hashes255 ··-·rpm_verify_hashes
 256 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 257 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 258 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 259 if·[·-n·"$files_with_incorrect_hash"·];·then
 260 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 261 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 262 ····dnf·reinstall·-y·$packages_to_reinstall
  
 263 fi
269 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*264 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
270 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:265 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
271 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'266 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
272 run·the·following·command·to·determine·which·package·owns·it:267 run·the·following·command·to·determine·which·package·owns·it:
273 $·rpm·-qf·FILENAME268 $·rpm·-qf·FILENAME
274 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:269 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
275 $·sudo·rpm·--setugids·PACKAGENAME270 $·sudo·rpm·--setugids·PACKAGENAME
Offset 289, 40 lines modifiedOffset 289, 14 lines modified
289 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5289 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
290 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2290 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
291 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)291 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
292 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1292 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
293 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5293 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
294 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108294 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
295 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2295 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
296 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
297 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
298 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
299 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
300 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
301 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
302 declare·-A·SETPERMS_RPM_DICT 
  
303 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
304 #·is·expected·by·the·RPM·database 
305 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
306 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
307 do 
308 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
309 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
310 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
311 done 
  
312 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
313 #·correct·values 
314 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
315 do 
316 ········rpm·--setugids·"${RPM_PACKAGE}" 
317 done 
318 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8296 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
319 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high297 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
320 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium298 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
321 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false299 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
322 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict300 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
323 -·name:·Read·list·of·files·with·incorrect·ownership301 -·name:·Read·list·of·files·with·incorrect·ownership
324 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev302 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 400, 14 lines modifiedOffset 374, 40 lines modified
400 ··-·PCI-DSSv4-11.5.2374 ··-·PCI-DSSv4-11.5.2
401 ··-·high_complexity375 ··-·high_complexity
402 ··-·high_severity376 ··-·high_severity
403 ··-·medium_disruption377 ··-·medium_disruption
404 ··-·no_reboot_needed378 ··-·no_reboot_needed
405 ··-·restrict_strategy379 ··-·restrict_strategy
406 ··-·rpm_verify_ownership380 ··-·rpm_verify_ownership
 381 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 382 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 383 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 384 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 385 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 386 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 1677686/1685482 bytes (99.54%) of diff not shown.
33.7 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-stig.html
    
Offset 14311, 15 lines modifiedOffset 14311, 15 lines modified
00037e60:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00037e60:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00037e70:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00037e70:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00037e80:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</00037e80:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
00037e90:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00037e90:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
00037ea0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft00037ea0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
00037eb0:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······00037eb0:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
00037ec0:·2020·2020·2020·2020·2020·2020·2020·2861················(a00037ec0:·2020·2020·2020·2020·2020·2020·2020·2861················(a
00037ed0:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)00037ed0:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
00037ee0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037ee0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037ef0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div00037ef0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
00037f00:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co00037f00:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
00037f10:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><00037f10:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
00037f20:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc00037f20:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
00037f30:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec00037f30:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00037f40:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00037f40:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 15153, 237 lines modifiedOffset 15153, 237 lines modified
0003b300:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b300:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b310:·3d22·2369·646d·3834·3036·2220·7461·6269··="#idm8406"·tabi0003b310:·3d22·2369·646d·3834·3036·2220·7461·6269··="#idm8406"·tabi
0003b320:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b320:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b330:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b330:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b340:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b340:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b350:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b350:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b360:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b360:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b370:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu0003b370:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
0003b380:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...0003b380:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
0003b390:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003b390:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003b3a0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003b3a0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003b3b0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003b3b0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003b3c0:·2269·646d·3834·3036·223e·3c74·6162·6c65··"idm8406"><table0003b3c0:·643d·2269·646d·3834·3036·223e·3c74·6162··d="idm8406"><tab
0003b3d0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003b3d0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003b3e0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003b3e0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003b3f0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003b3f0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003b400:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003b400:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003b410:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003b410:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003b420:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003b420:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003b430:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003b430:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
0003b440:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003b440:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003b450:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003b450:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003b460:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t0003b460:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
0003b470:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>0003b470:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003b480:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003b480:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003b490:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003b490:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003b4a0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003b4a0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003b4b0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod0003b4b0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003b4c0:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a
 0003b4d0:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code><
 0003b4e0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003b4f0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003b500:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003b510:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003b520:·612d·7461·7267·6574·3d22·2369·646d·3834··a-target="#idm84
 0003b530:·3037·2220·7461·6269·6e64·6578·3d22·3022··07"·tabindex="0"
 0003b540:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003b550:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003b560:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003b570:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003b580:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003b590:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
 0003b5a0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0003b5b0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003b5c0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003b5d0:·7073·6522·2069·643d·2269·646d·3834·3037··pse"·id="idm8407
 0003b5e0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003b5f0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0003b600:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0003b610:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003b620:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003b630:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003b640:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003b650:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003b4c0:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal 
0003b4d0:·6c5f·6169·6465·0a0a·636c·6173·7320·696e··l_aide..class·in 
0003b4e0:·7374·616c·6c5f·6169·6465·207b·0a20·2070··stall_aide·{.··p 
0003b4f0:·6163·6b61·6765·207b·2027·6169·6465·273a··ackage·{·'aide': 
0003b500:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt 
0003b510:·3b20·2769·6e73·7461·6c6c·6564·272c·0a20··;·'installed',.· 
0003b520:·207d·0a7d·0a3c·2f63·6f64·653e·3c2f·7072···}.}.</code></pr 
0003b530:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003b540:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003b550:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003b560:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003b570:·6172·6765·743d·2223·6964·6d38·3430·3722··arget="#idm8407" 
0003b580:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003b590:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003b5a0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003b5b0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003b5c0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003b5d0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003b5e0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script· 
0003b5f0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003b600:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003b610:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003b620:·6964·3d22·6964·6d38·3430·3722·3e3c·7461··id="idm8407"><ta 
0003b630:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003b640:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003b650:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003b660:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003b670:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003b680:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003b660:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003b690:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003b670:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 0003b680:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003b6a0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003b6b0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b6c0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003b6d0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003b6e0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b6f0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003b700:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0003b710:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003b720:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati 
0003b730:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable 
0003b740:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain 
0003b750:·2070·6c61·7466·6f72·6d73·0a69·6620·5b20···platforms.if·[· 
0003b760:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv 
0003b770:·205d·2026·616d·703b·2661·6d70·3b20·5b20···]·&amp;&amp;·[· 
0003b780:·2120·2d66·202f·7275·6e2f·2e63·6f6e·7461··!·-f·/run/.conta 
0003b790:·696e·6572·656e·7620·5d3b·2074·6865·6e0a··inerenv·];·then. 
0003b7a0:·0a69·6620·2120·7270·6d20·2d71·202d·2d71··.if·!·rpm·-q·--q 
0003b7b0:·7569·6574·2022·6169·6465·2220·3b20·7468··uiet·"aide"·;·th 
0003b7c0:·656e·0a20·2020·2064·6e66·2069·6e73·7461··en.····dnf·insta 
0003b7d0:·6c6c·202d·7920·2261·6964·6522·0a66·690a··ll·-y·"aide".fi. 
0003b7e0:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a 
0003b7f0:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed 
0003b800:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap 
0003b810:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin 
0003b820:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.< 
0003b830:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
Max diff block lines reached; 32377851/32410335 bytes (99.90%) of diff not shown.
2.75 MB
html2text {}
Max HTML report size reached
33.5 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-stig_gui.html
    
Offset 14335, 15 lines modifiedOffset 14335, 15 lines modified
00037fe0:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre00037fe0:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre
00037ff0:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str00037ff0:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str
00038000:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro00038000:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro
00038010:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><00038010:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><
00038020:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st00038020:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st
00038030:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········00038030:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········
00038040:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of00038040:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of
00038050:·2032·3032·362d·3031·2d30·3829·0a20·2020···2026-01-08).···00038050:·2032·3032·342d·3132·2d30·3729·0a20·2020···2024-12-07).···
00038060:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l00038060:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l
00038070:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h200038070:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h2
00038080:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten00038080:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten
00038090:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><00038090:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><
000380a0:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o000380a0:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o
000380b0:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co000380b0:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co
000380c0:·6e74·656e·745f·6772·6f75·705f·7379·7374··ntent_group_syst000380c0:·6e74·656e·745f·6772·6f75·705f·7379·7374··ntent_group_syst
Offset 15172, 236 lines modifiedOffset 15172, 236 lines modified
0003b430:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm80003b430:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8
0003b440:·3430·3622·2074·6162·696e·6465·783d·2230··406"·tabindex="00003b440:·3430·3622·2074·6162·696e·6465·783d·2230··406"·tabindex="0
0003b450:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003b450:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003b460:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003b460:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003b470:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003b470:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003b480:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003b480:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003b490:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003b490:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003b4a0:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn0003b4a0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·
0003b4b0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003b4b0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003b4c0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003b4c0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003b4d0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003b4d0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003b4e0:·6170·7365·2220·6964·3d22·6964·6d38·3430··apse"·id="idm8400003b4e0:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
0003b4f0:·3622·3e3c·7461·626c·6520·636c·6173·733d··6"><table·class=0003b4f0:·3430·3622·3e3c·7461·626c·6520·636c·6173··406"><table·clas
0003b500:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003b500:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003b510:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003b510:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003b520:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003b520:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003b530:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003b530:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003b540:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003b540:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003b550:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003b550:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003b560:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003b560:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003b570:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003b570:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003b580:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R0003b580:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b590:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f0003b590:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003b5a0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t0003b5a0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003b5b0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<0003b5b0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003b5c0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</0003b5c0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
0003b5d0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>0003b5d0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003b5e0:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu0003b5e0:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa
 0003b5f0:·636b·6167·6520·2d2d·6164·643d·6169·6465··ckage·--add=aide
 0003b600:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 0003b610:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 0003b620:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 0003b630:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 0003b640:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 0003b650:·743d·2223·6964·6d38·3430·3722·2074·6162··t="#idm8407"·tab
 0003b660:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 0003b670:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 0003b680:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 0003b690:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 0003b6a0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 0003b6b0:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P
 0003b6c0:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..
 0003b6d0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003b6e0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003b5f0:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide. 
0003b600:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a 
0003b610:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package· 
0003b620:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en 
0003b630:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst 
0003b640:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</ 
0003b650:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003b660:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003b670:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003b680:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003b690:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003b6a0:·2369·646d·3834·3037·2220·7461·6269·6e64··#idm8407"·tabind 
0003b6b0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003b6c0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003b6d0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003b6e0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003b6f0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003b700:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel 
0003b710:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a> 
0003b720:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b730:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003b6f0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003b740:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b750:·3834·3037·223e·3c74·6162·6c65·2063·6c61··8407"><table·cla 
0003b760:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003b770:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003b780:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003b790:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003b7a0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003b700:·3d22·6964·6d38·3430·3722·3e3c·7461·626c··="idm8407"><tabl
 0003b710:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003b720:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003b730:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003b740:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003b750:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 0003b760:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b770:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0003b780:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003b7b0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003b790:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003b7c0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003b7d0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003b7a0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 0003b7b0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
0003b7e0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003b7c0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0003b7d0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 0003b7e0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 0003b7f0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003b800:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta
 0003b810:·6c6c·5f61·6964·650a·0a63·6c61·7373·2069··ll_aide..class·i
 0003b820:·6e73·7461·6c6c·5f61·6964·6520·7b0a·2020··nstall_aide·{.··
 0003b830:·7061·636b·6167·6520·7b20·2761·6964·6527··package·{·'aide'
 0003b840:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g
 0003b850:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',.
 0003b860:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p
0003b7f0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003b800:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003b810:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003b820:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003b830:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003b840:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#· 
0003b850:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a 
0003b860:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i 
0003b870:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo 
0003b880:·726d·730a·6966·205b·2021·202d·6620·2f2e··rms.if·[·!·-f·/. 
0003b890:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp 
0003b8a0:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r 
0003b8b0:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv 
0003b8c0:·205d·3b20·7468·656e·0a0a·6966·2021·2072···];·then..if·!·r 
0003b8d0:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a 
0003b8e0:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.···· 
Max diff block lines reached; 32238185/32270531 bytes (99.90%) of diff not shown.
2.73 MB
html2text {}
Max HTML report size reached
14.3 MB
./usr/share/doc/ssg-nondebian/ssg-rhv4-guide-pci-dss.html
    
Offset 14301, 15 lines modifiedOffset 14301, 15 lines modified
00037dc0:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr00037dc0:·746f·7279·3c2f·6832·3e3c·703e·4375·7272··tory</h2><p>Curr
00037dd0:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st00037dd0:·656e·7420·7665·7273·696f·6e3a·203c·7374··ent·version:·<st
00037de0:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str00037de0:·726f·6e67·3e30·2e31·2e37·343c·2f73·7472··rong>0.1.74</str
00037df0:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>00037df0:·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c·693e··ong></p><ul><li>
00037e00:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s00037e00:·3c73·7472·6f6e·673e·6472·6166·743c·2f73··<strong>draft</s
00037e10:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········00037e10:·7472·6f6e·673e·0a20·2020·2020·2020·2020··trong>.·········
00037e20:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o00037e20:·2020·2020·2020·2020·2020·2028·6173·206f·············(as·o
00037e30:·6620·3230·3236·2d30·312d·3038·290a·2020··f·2026-01-08).··00037e30:·6620·3230·3234·2d31·322d·3037·290a·2020··f·2024-12-07).··
00037e40:·2020·2020·2020·2020·2020·2020·2020·3c2f················</00037e40:·2020·2020·2020·2020·2020·2020·2020·3c2f················</
00037e50:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h00037e50:·6c69·3e3c·2f75·6c3e·3c2f·6469·763e·3c68··li></ul></div><h
00037e60:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte00037e60:·323e·5461·626c·6520·6f66·2043·6f6e·7465··2>Table·of·Conte
00037e70:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>00037e70:·6e74·733c·2f68·323e·3c6f·6c3e·3c6c·693e··nts</h2><ol><li>
00037e80:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_00037e80:·3c61·2068·7265·663d·2223·7863·6364·665f··<a·href="#xccdf_
00037e90:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c00037e90:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c
00037ea0:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys00037ea0:·6f6e·7465·6e74·5f67·726f·7570·5f73·7973··ontent_group_sys
Offset 15127, 301 lines modifiedOffset 15127, 301 lines modified
0003b160:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b160:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003b170:·2223·6964·6d31·3538·3422·2074·6162·696e··"#idm1584"·tabin0003b170:·2223·6964·6d31·3538·3422·2074·6162·696e··"#idm1584"·tabin
0003b180:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b180:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b190:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b190:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b1a0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b1a0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b1b0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b1b0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b1c0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b1c0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b1d0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
0003b1e0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
0003b1f0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b200:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b210:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b220:·6d31·3538·3422·3e3c·7072·653e·3c63·6f64··m1584"><pre><cod 
0003b230:·653e·0a23·2046·696e·6420·7768·6963·6820··e>.#·Find·which· 
0003b240:·6669·6c65·7320·6861·7665·2069·6e63·6f72··files·have·incor 
0003b250:·7265·6374·2068·6173·6820·286e·6f74·2069··rect·hash·(not·i 
0003b260:·6e20·2f65·7463·2c20·6265·6361·7573·6520··n·/etc,·because· 
0003b270:·6f66·2074·6865·2073·7973·7465·6d20·7265··of·the·system·re 
0003b280:·6c61·7465·6420·636f·6e66·6967·2066·696c··lated·config·fil 
0003b290:·6573·2920·616e·6420·7468·656e·2067·6574··es)·and·then·get 
0003b2a0:·2066·696c·6573·206e·616d·6573·0a66·696c···files·names.fil 
0003b2b0:·6573·5f77·6974·685f·696e·636f·7272·6563··es_with_incorrec 
0003b2c0:·745f·6861·7368·3d22·2428·7270·6d20·2d56··t_hash="$(rpm·-V 
0003b2d0:·6120·2d2d·6e6f·636f·6e66·6967·207c·2067··a·--noconfig·|·g 
0003b2e0:·7265·7020·2d45·2027·5e2e·2e35·2720·7c20··rep·-E·'^..5'·|· 
0003b2f0:·6177·6b20·277b·7072·696e·7420·244e·467d··awk·'{print·$NF} 
0003b300:·2720·2922·0a0a·6966·205b·202d·6e20·2224··'·)"..if·[·-n·"$ 
0003b310:·6669·6c65·735f·7769·7468·5f69·6e63·6f72··files_with_incor 
0003b320:·7265·6374·5f68·6173·6822·205d·3b20·7468··rect_hash"·];·th 
0003b330:·656e·0a20·2020·2023·2046·726f·6d20·6669··en.····#·From·fi 
0003b340:·6c65·7320·6e61·6d65·7320·6765·7420·7061··les·names·get·pa 
0003b350:·636b·6167·6520·6e61·6d65·7320·616e·6420··ckage·names·and· 
0003b360:·6368·616e·6765·206e·6577·6c69·6e65·2074··change·newline·t 
0003b370:·6f20·7370·6163·652c·2062·6563·6175·7365··o·space,·because 
0003b380:·2072·706d·2077·7269·7465·7320·6561·6368···rpm·writes·each 
0003b390:·2070·6163·6b61·6765·2074·6f20·6e65·7720···package·to·new· 
0003b3a0:·6c69·6e65·0a20·2020·2070·6163·6b61·6765··line.····package 
0003b3b0:·735f·746f·5f72·6569·6e73·7461·6c6c·3d22··s_to_reinstall=" 
0003b3c0:·2428·7270·6d20·2d71·6620·2466·696c·6573··$(rpm·-qf·$files 
0003b3d0:·5f77·6974·685f·696e·636f·7272·6563·745f··_with_incorrect_ 
0003b3e0:·6861·7368·207c·2074·7220·275c·6e27·2027··hash·|·tr·'\n'·' 
0003b3f0:·2027·2922·0a0a·2020·2020·0a20·2020·2079···')"..····.····y 
0003b400:·756d·2072·6569·6e73·7461·6c6c·202d·7920··um·reinstall·-y· 
0003b410:·2470·6163·6b61·6765·735f·746f·5f72·6569··$packages_to_rei 
0003b420:·6e73·7461·6c6c·0a20·2020·200a·6669·0a3c··nstall.····.fi.< 
0003b430:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003b440:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003b450:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003b460:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003b470:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003b480:·2223·6964·6d31·3538·3522·2074·6162·696e··"#idm1585"·tabin 
0003b490:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003b4a0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003b4b0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003b4c0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003b4d0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003b4e0:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans0003b1d0:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans
0003b4f0:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...0003b1e0:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...
0003b500:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003b1f0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003b510:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003b200:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003b520:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003b210:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003b530:·2269·646d·3135·3835·223e·3c74·6162·6c65··"idm1585"><table0003b220:·2269·646d·3135·3834·223e·3c74·6162·6c65··"idm1584"><table
0003b540:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003b230:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003b550:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003b240:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003b560:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003b250:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003b570:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003b260:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003b580:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003b270:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003b590:·2f74·683e·3c74·643e·6869·6768·3c2f·7464··/th><td>high</td0003b280:·2f74·683e·3c74·643e·6869·6768·3c2f·7464··/th><td>high</td
0003b5a0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003b290:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003b5b0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003b2a0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003b5c0:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t0003b2b0:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t
0003b5d0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot0003b2c0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
0003b5e0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<0003b2d0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003b5f0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b2e0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b600:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003b2f0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003b610:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>0003b300:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>
0003b620:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003b310:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
0003b630:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·0003b320:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·
0003b640:·2753·6574·2066·6163·743a·2050·6163·6b61··'Set·fact:·Packa0003b330:·2753·6574·2066·6163·743a·2050·6163·6b61··'Set·fact:·Packa
0003b650:·6765·206d·616e·6167·6572·2072·6569·6e73··ge·manager·reins0003b340:·6765·206d·616e·6167·6572·2072·6569·6e73··ge·manager·reins
0003b660:·7461·6c6c·2063·6f6d·6d61·6e64·270a·2020··tall·command'.··0003b350:·7461·6c6c·2063·6f6d·6d61·6e64·270a·2020··tall·command'.··
0003b670:·7365·745f·6661·6374·3a0a·2020·2020·7061··set_fact:.····pa0003b360:·7365·745f·6661·6374·3a0a·2020·2020·7061··set_fact:.····pa
0003b680:·636b·6167·655f·6d61·6e61·6765·725f·7265··ckage_manager_re0003b370:·636b·6167·655f·6d61·6e61·6765·725f·7265··ckage_manager_re
0003b690:·696e·7374·616c·6c5f·636d·643a·2079·756d··install_cmd:·yum0003b380:·696e·7374·616c·6c5f·636d·643a·2079·756d··install_cmd:·yum
0003b6a0:·2072·6569·6e73·7461·6c6c·202d·790a·2020···reinstall·-y.··0003b390:·2072·6569·6e73·7461·6c6c·202d·790a·2020···reinstall·-y.··
0003b6b0:·7768·656e·3a20·616e·7369·626c·655f·6469··when:·ansible_di0003b3a0:·7768·656e·3a20·616e·7369·626c·655f·6469··when:·ansible_di
0003b6c0:·7374·7269·6275·7469·6f6e·2069·6e20·5b20··stribution·in·[·0003b3b0:·7374·7269·6275·7469·6f6e·2069·6e20·5b20··stribution·in·[·
0003b6d0:·2246·6564·6f72·6122·2c20·2252·6564·4861··"Fedora",·"RedHa0003b3c0:·2246·6564·6f72·6122·2c20·2252·6564·4861··"Fedora",·"RedHa
0003b6e0:·7422·2c20·2243·656e·744f·5322·2c20·224f··t",·"CentOS",·"O0003b3d0:·7422·2c20·2243·656e·744f·5322·2c20·224f··t",·"CentOS",·"O
0003b6f0:·7261·636c·654c·696e·7578·2220·5d0a·2020··racleLinux"·].··0003b3e0:·7261·636c·654c·696e·7578·2220·5d0a·2020··racleLinux"·].··
0003b700:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-50003b3f0:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-5
0003b710:·2e31·302e·342e·310a·2020·2d20·4e49·5354··.10.4.1.··-·NIST0003b400:·2e31·302e·342e·310a·2020·2d20·4e49·5354··.10.4.1.··-·NIST
0003b720:·2d38·3030·2d31·3731·2d33·2e33·2e38·0a20··-800-171-3.3.8.·0003b410:·2d38·3030·2d31·3731·2d33·2e33·2e38·0a20··-800-171-3.3.8.·
0003b730:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-0003b420:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
0003b740:·332e·342e·310a·2020·2d20·4e49·5354·2d38··3.4.1.··-·NIST-80003b430:·332e·342e·310a·2020·2d20·4e49·5354·2d38··3.4.1.··-·NIST-8
0003b750:·3030·2d35·332d·4155·2d39·2833·290a·2020··00-53-AU-9(3).··0003b440:·3030·2d35·332d·4155·2d39·2833·290a·2020··00-53-AU-9(3).··
0003b760:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM0003b450:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
0003b770:·2d36·2863·290a·2020·2d20·4e49·5354·2d38··-6(c).··-·NIST-80003b460:·2d36·2863·290a·2020·2d20·4e49·5354·2d38··-6(c).··-·NIST-8
0003b780:·3030·2d35·332d·434d·2d36·2864·290a·2020··00-53-CM-6(d).··0003b470:·3030·2d35·332d·434d·2d36·2864·290a·2020··00-53-CM-6(d).··
0003b790:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI0003b480:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI
0003b7a0:·2d37·0a20·202d·204e·4953·542d·3830·302d··-7.··-·NIST-800-0003b490:·2d37·0a20·202d·204e·4953·542d·3830·302d··-7.··-·NIST-800-
0003b7b0:·3533·2d53·492d·3728·3129·0a20·202d·204e··53-SI-7(1).··-·N0003b4a0:·3533·2d53·492d·3728·3129·0a20·202d·204e··53-SI-7(1).··-·N
0003b7c0:·4953·542d·3830·302d·3533·2d53·492d·3728··IST-800-53-SI-7(0003b4b0:·4953·542d·3830·302d·3533·2d53·492d·3728··IST-800-53-SI-7(
0003b7d0:·3629·0a20·202d·2050·4349·2d44·5353·2d52··6).··-·PCI-DSS-R0003b4c0:·3629·0a20·202d·2050·4349·2d44·5353·2d52··6).··-·PCI-DSS-R
0003b7e0:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI-0003b4d0:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI-
0003b7f0:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··-0003b4e0:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··-
0003b800:·2068·6967·685f·636f·6d70·6c65·7869·7479···high_complexity0003b4f0:·2068·6967·685f·636f·6d70·6c65·7869·7479···high_complexity
0003b810:·0a20·202d·2068·6967·685f·7365·7665·7269··.··-·high_severi0003b500:·0a20·202d·2068·6967·685f·7365·7665·7269··.··-·high_severi
0003b820:·7479·0a20·202d·206d·6564·6975·6d5f·6469··ty.··-·medium_di0003b510:·7479·0a20·202d·206d·6564·6975·6d5f·6469··ty.··-·medium_di
0003b830:·7372·7570·7469·6f6e·0a20·202d·206e·6f5f··sruption.··-·no_0003b520:·7372·7570·7469·6f6e·0a20·202d·206e·6f5f··sruption.··-·no_
0003b840:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.··0003b530:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.··
Max diff block lines reached; 13938220/13963804 bytes (99.82%) of diff not shown.
1010 KB
html2text {}
    
Offset 39, 15 lines modifiedOffset 39, 15 lines modified
39 ··············(RHVH)39 ··············(RHVH)
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss
41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*41 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
42 ····*·cpe:/o:redhat:enterprise_linux:8::hypervisor42 ····*·cpe:/o:redhat:enterprise_linux:8::hypervisor
43 ····*·cpe:/a:redhat:enterprise_virtualization_manager:443 ····*·cpe:/a:redhat:enterprise_virtualization_manager:4
44 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*44 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
45 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8445 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
46 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)46 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
47 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
48 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s48 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
49 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e49 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
50 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l50 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
51 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n51 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
52 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g52 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
53 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s53 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 97, 27 lines modifiedOffset 97, 14 lines modified
97 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.697 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
98 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.498 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
99 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)99 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
100 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1100 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
101 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5101 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
102 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227102 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
103 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2103 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
104 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
105 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
106 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
107 if·[·-n·"$files_with_incorrect_hash"·];·then 
108 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
109 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
110 ····yum·reinstall·-y·$packages_to_reinstall 
  
111 fi 
112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8104 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
113 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high105 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
114 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium106 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
115 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false107 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
116 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict108 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
117 -·name:·'Set·fact:·Package·manager·reinstall·command'109 -·name:·'Set·fact:·Package·manager·reinstall·command'
118 ··set_fact:110 ··set_fact:
Offset 244, 14 lines modifiedOffset 231, 27 lines modified
244 ··-·PCI-DSSv4-11.5.2231 ··-·PCI-DSSv4-11.5.2
245 ··-·high_complexity232 ··-·high_complexity
246 ··-·high_severity233 ··-·high_severity
247 ··-·medium_disruption234 ··-·medium_disruption
248 ··-·no_reboot_needed235 ··-·no_reboot_needed
249 ··-·restrict_strategy236 ··-·restrict_strategy
250 ··-·rpm_verify_hashes237 ··-·rpm_verify_hashes
 238 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 239 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 240 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 241 if·[·-n·"$files_with_incorrect_hash"·];·then
 242 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 243 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 244 ····yum·reinstall·-y·$packages_to_reinstall
  
 245 fi
251 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*246 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
252 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:247 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and·commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:
253 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'248 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'
254 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:249 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,·run·the·following·command·to·determine·which·package·owns·it:
255 $·rpm·-qf·FILENAME250 $·rpm·-qf·FILENAME
  
256 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:251 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
Offset 272, 44 lines modifiedOffset 272, 14 lines modified
272 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5272 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
273 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2273 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
274 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)274 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)
275 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1275 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
276 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5276 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
277 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108277 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,·SRG-OS-000278-GPOS-00108
278 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2278 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
279 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
280 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
281 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
282 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
283 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
284 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
285 declare·-A·SETPERMS_RPM_DICT 
  
286 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
287 #·is·expected·by·the·RPM·database 
288 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}') 
  
289 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
290 do 
291 ········#·NOTE:·some·files·maybe·controlled·by·more·then·one·package 
292 ········readarray·-t·RPM_PACKAGES·<·<(rpm·-qf·"${FILE_PATH}") 
293 ········for·RPM_PACKAGE·in·"${RPM_PACKAGES[@]}" 
294 ········do 
295 ················#·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
296 ················SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
297 ········done 
298 done 
  
299 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
300 #·correct·values 
301 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
302 do 
303 »       rpm·--restore·"${RPM_PACKAGE}" 
304 done 
305 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8279 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
306 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high280 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
307 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium281 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
308 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false282 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
309 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict283 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
310 -·name:·Read·list·of·files·with·incorrect·permissions284 -·name:·Read·list·of·files·with·incorrect·permissions
311 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev285 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 387, 14 lines modifiedOffset 357, 44 lines modified
387 ··-·PCI-DSSv4-11.5.2357 ··-·PCI-DSSv4-11.5.2
388 ··-·high_complexity358 ··-·high_complexity
389 ··-·high_severity359 ··-·high_severity
390 ··-·medium_disruption360 ··-·medium_disruption
391 ··-·no_reboot_needed361 ··-·no_reboot_needed
392 ··-·restrict_strategy362 ··-·restrict_strategy
393 ··-·rpm_verify_permissions363 ··-·rpm_verify_permissions
 364 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 365 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 366 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
Max diff block lines reached; 1027053/1035209 bytes (99.21%) of diff not shown.
25.3 MB
./usr/share/doc/ssg-nondebian/ssg-rhv4-guide-rhvh-stig.html
    
Offset 14302, 16 lines modifiedOffset 14302, 16 lines modified
00037dd0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h00037dd0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h
00037de0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver00037de0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver
00037df0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.00037df0:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.
00037e00:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p00037e00:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p
00037e10:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong00037e10:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong
00037e20:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.00037e20:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.
00037e30:·2020·2020·2020·2020·2020·2020·2020·2020··················00037e30:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037e40:·2020·2020·2861·7320·6f66·2032·3032·362d······(as·of·2026-00037e40:·2020·2020·2861·7320·6f66·2032·3032·342d······(as·of·2024-
00037e50:·3031·2d30·3829·0a20·2020·2020·2020·2020··01-08).·········00037e50:·3132·2d30·3729·0a20·2020·2020·2020·2020··12-07).·········
00037e60:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul00037e60:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul
00037e70:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table00037e70:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table
00037e80:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h200037e80:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2
00037e90:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href00037e90:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href
00037ea0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg00037ea0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg
00037eb0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_00037eb0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
00037ec0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy00037ec0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy
Offset 15180, 301 lines modifiedOffset 15180, 301 lines modified
0003b4b0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b4b0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003b4c0:·646d·3135·3834·2220·7461·6269·6e64·6578··dm1584"·tabindex0003b4c0:·646d·3135·3834·2220·7461·6269·6e64·6578··dm1584"·tabindex
0003b4d0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b4d0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b4e0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b4e0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b4f0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b4f0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b500:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b500:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b510:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b510:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003b520:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
0003b530:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003b540:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003b550:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003b560:·6c61·7073·6522·2069·643d·2269·646d·3135··lapse"·id="idm15 
0003b570:·3834·223e·3c70·7265·3e3c·636f·6465·3e0a··84"><pre><code>. 
0003b580:·2320·4669·6e64·2077·6869·6368·2066·696c··#·Find·which·fil 
0003b590:·6573·2068·6176·6520·696e·636f·7272·6563··es·have·incorrec 
0003b5a0:·7420·6861·7368·2028·6e6f·7420·696e·202f··t·hash·(not·in·/ 
0003b5b0:·6574·632c·2062·6563·6175·7365·206f·6620··etc,·because·of· 
0003b5c0:·7468·6520·7379·7374·656d·2072·656c·6174··the·system·relat 
0003b5d0:·6564·2063·6f6e·6669·6720·6669·6c65·7329··ed·config·files) 
0003b5e0:·2061·6e64·2074·6865·6e20·6765·7420·6669···and·then·get·fi 
0003b5f0:·6c65·7320·6e61·6d65·730a·6669·6c65·735f··les·names.files_ 
0003b600:·7769·7468·5f69·6e63·6f72·7265·6374·5f68··with_incorrect_h 
0003b610:·6173·683d·2224·2872·706d·202d·5661·202d··ash="$(rpm·-Va·- 
0003b620:·2d6e·6f63·6f6e·6669·6720·7c20·6772·6570··-noconfig·|·grep 
0003b630:·202d·4520·275e·2e2e·3527·207c·2061·776b···-E·'^..5'·|·awk 
0003b640:·2027·7b70·7269·6e74·2024·4e46·7d27·2029···'{print·$NF}'·) 
0003b650:·220a·0a69·6620·5b20·2d6e·2022·2466·696c··"..if·[·-n·"$fil 
0003b660:·6573·5f77·6974·685f·696e·636f·7272·6563··es_with_incorrec 
0003b670:·745f·6861·7368·2220·5d3b·2074·6865·6e0a··t_hash"·];·then. 
0003b680:·2020·2020·2320·4672·6f6d·2066·696c·6573······#·From·files 
0003b690:·206e·616d·6573·2067·6574·2070·6163·6b61···names·get·packa 
0003b6a0:·6765·206e·616d·6573·2061·6e64·2063·6861··ge·names·and·cha 
0003b6b0:·6e67·6520·6e65·776c·696e·6520·746f·2073··nge·newline·to·s 
0003b6c0:·7061·6365·2c20·6265·6361·7573·6520·7270··pace,·because·rp 
0003b6d0:·6d20·7772·6974·6573·2065·6163·6820·7061··m·writes·each·pa 
0003b6e0:·636b·6167·6520·746f·206e·6577·206c·696e··ckage·to·new·lin 
0003b6f0:·650a·2020·2020·7061·636b·6167·6573·5f74··e.····packages_t 
0003b700:·6f5f·7265·696e·7374·616c·6c3d·2224·2872··o_reinstall="$(r 
0003b710:·706d·202d·7166·2024·6669·6c65·735f·7769··pm·-qf·$files_wi 
0003b720:·7468·5f69·6e63·6f72·7265·6374·5f68·6173··th_incorrect_has 
0003b730:·6820·7c20·7472·2027·5c6e·2720·2720·2729··h·|·tr·'\n'·'·') 
0003b740:·220a·0a20·2020·200a·2020·2020·7975·6d20··"..····.····yum· 
0003b750:·7265·696e·7374·616c·6c20·2d79·2024·7061··reinstall·-y·$pa 
0003b760:·636b·6167·6573·5f74·6f5f·7265·696e·7374··ckages_to_reinst 
0003b770:·616c·6c0a·2020·2020·0a66·690a·3c2f·636f··all.····.fi.</co 
0003b780:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003b790:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003b7a0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003b7b0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003b7c0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003b7d0:·646d·3135·3835·2220·7461·6269·6e64·6578··dm1585"·tabindex 
0003b7e0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003b7f0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003b800:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003b810:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003b820:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003b830:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl0003b520:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl
0003b840:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a0003b530:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a
0003b850:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003b540:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003b860:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003b550:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003b870:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003b560:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003b880:·6d31·3538·3522·3e3c·7461·626c·6520·636c··m1585"><table·cl0003b570:·6d31·3538·3422·3e3c·7461·626c·6520·636c··m1584"><table·cl
0003b890:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003b580:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003b8a0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003b590:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003b8b0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003b5a0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003b8c0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003b5b0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003b8d0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003b5c0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003b8e0:·3e3c·7464·3e68·6967·683c·2f74·643e·3c2f··><td>high</td></0003b5d0:·3e3c·7464·3e68·6967·683c·2f74·643e·3c2f··><td>high</td></
0003b8f0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru0003b5e0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003b900:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6d··ption:</th><td>m0003b5f0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6d··ption:</th><td>m
0003b910:·6564·6975·6d3c·2f74·643e·3c2f·7472·3e3c··edium</td></tr><0003b600:·6564·6975·6d3c·2f74·643e·3c2f·7472·3e3c··edium</td></tr><
0003b920:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</0003b610:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
0003b930:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td0003b620:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
0003b940:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St0003b630:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
0003b950:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003b640:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0003b960:·7265·7374·7269·6374·3c2f·7464·3e3c·2f74··restrict</td></t0003b650:·7265·7374·7269·6374·3c2f·7464·3e3c·2f74··restrict</td></t
0003b970:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003b660:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
0003b980:·636f·6465·3e2d·206e·616d·653a·2027·5365··code>-·name:·'Se0003b670:·636f·6465·3e2d·206e·616d·653a·2027·5365··code>-·name:·'Se
0003b990:·7420·6661·6374·3a20·5061·636b·6167·6520··t·fact:·Package·0003b680:·7420·6661·6374·3a20·5061·636b·6167·6520··t·fact:·Package·
0003b9a0:·6d61·6e61·6765·7220·7265·696e·7374·616c··manager·reinstal0003b690:·6d61·6e61·6765·7220·7265·696e·7374·616c··manager·reinstal
0003b9b0:·6c20·636f·6d6d·616e·6427·0a20·2073·6574··l·command'.··set0003b6a0:·6c20·636f·6d6d·616e·6427·0a20·2073·6574··l·command'.··set
0003b9c0:·5f66·6163·743a·0a20·2020·2070·6163·6b61··_fact:.····packa0003b6b0:·5f66·6163·743a·0a20·2020·2070·6163·6b61··_fact:.····packa
0003b9d0:·6765·5f6d·616e·6167·6572·5f72·6569·6e73··ge_manager_reins0003b6c0:·6765·5f6d·616e·6167·6572·5f72·6569·6e73··ge_manager_reins
0003b9e0:·7461·6c6c·5f63·6d64·3a20·7975·6d20·7265··tall_cmd:·yum·re0003b6d0:·7461·6c6c·5f63·6d64·3a20·7975·6d20·7265··tall_cmd:·yum·re
0003b9f0:·696e·7374·616c·6c20·2d79·0a20·2077·6865··install·-y.··whe0003b6e0:·696e·7374·616c·6c20·2d79·0a20·2077·6865··install·-y.··whe
0003ba00:·6e3a·2061·6e73·6962·6c65·5f64·6973·7472··n:·ansible_distr0003b6f0:·6e3a·2061·6e73·6962·6c65·5f64·6973·7472··n:·ansible_distr
0003ba10:·6962·7574·696f·6e20·696e·205b·2022·4665··ibution·in·[·"Fe0003b700:·6962·7574·696f·6e20·696e·205b·2022·4665··ibution·in·[·"Fe
0003ba20:·646f·7261·222c·2022·5265·6448·6174·222c··dora",·"RedHat",0003b710:·646f·7261·222c·2022·5265·6448·6174·222c··dora",·"RedHat",
0003ba30:·2022·4365·6e74·4f53·222c·2022·4f72·6163···"CentOS",·"Orac0003b720:·2022·4365·6e74·4f53·222c·2022·4f72·6163···"CentOS",·"Orac
0003ba40:·6c65·4c69·6e75·7822·205d·0a20·2074·6167··leLinux"·].··tag0003b730:·6c65·4c69·6e75·7822·205d·0a20·2074·6167··leLinux"·].··tag
0003ba50:·733a·0a20·202d·2043·4a49·532d·352e·3130··s:.··-·CJIS-5.100003b740:·733a·0a20·202d·2043·4a49·532d·352e·3130··s:.··-·CJIS-5.10
0003ba60:·2e34·2e31·0a20·202d·204e·4953·542d·3830··.4.1.··-·NIST-800003b750:·2e34·2e31·0a20·202d·204e·4953·542d·3830··.4.1.··-·NIST-80
0003ba70:·302d·3137·312d·332e·332e·380a·2020·2d20··0-171-3.3.8.··-·0003b760:·302d·3137·312d·332e·332e·380a·2020·2d20··0-171-3.3.8.··-·
0003ba80:·4e49·5354·2d38·3030·2d31·3731·2d33·2e34··NIST-800-171-3.40003b770:·4e49·5354·2d38·3030·2d31·3731·2d33·2e34··NIST-800-171-3.4
0003ba90:·2e31·0a20·202d·204e·4953·542d·3830·302d··.1.··-·NIST-800-0003b780:·2e31·0a20·202d·204e·4953·542d·3830·302d··.1.··-·NIST-800-
0003baa0:·3533·2d41·552d·3928·3329·0a20·202d·204e··53-AU-9(3).··-·N0003b790:·3533·2d41·552d·3928·3329·0a20·202d·204e··53-AU-9(3).··-·N
0003bab0:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6(0003b7a0:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6(
0003bac0:·6329·0a20·202d·204e·4953·542d·3830·302d··c).··-·NIST-800-0003b7b0:·6329·0a20·202d·204e·4953·542d·3830·302d··c).··-·NIST-800-
0003bad0:·3533·2d43·4d2d·3628·6429·0a20·202d·204e··53-CM-6(d).··-·N0003b7c0:·3533·2d43·4d2d·3628·6429·0a20·202d·204e··53-CM-6(d).··-·N
0003bae0:·4953·542d·3830·302d·3533·2d53·492d·370a··IST-800-53-SI-7.0003b7d0:·4953·542d·3830·302d·3533·2d53·492d·370a··IST-800-53-SI-7.
0003baf0:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-0003b7e0:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
0003bb00:·5349·2d37·2831·290a·2020·2d20·4e49·5354··SI-7(1).··-·NIST0003b7f0:·5349·2d37·2831·290a·2020·2d20·4e49·5354··SI-7(1).··-·NIST
0003bb10:·2d38·3030·2d35·332d·5349·2d37·2836·290a··-800-53-SI-7(6).0003b800:·2d38·3030·2d35·332d·5349·2d37·2836·290a··-800-53-SI-7(6).
0003bb20:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req-0003b810:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req-
0003bb30:·3131·2e35·0a20·202d·2050·4349·2d44·5353··11.5.··-·PCI-DSS0003b820:·3131·2e35·0a20·202d·2050·4349·2d44·5353··11.5.··-·PCI-DSS
0003bb40:·7634·2d31·312e·352e·320a·2020·2d20·6869··v4-11.5.2.··-·hi0003b830:·7634·2d31·312e·352e·320a·2020·2d20·6869··v4-11.5.2.··-·hi
0003bb50:·6768·5f63·6f6d·706c·6578·6974·790a·2020··gh_complexity.··0003b840:·6768·5f63·6f6d·706c·6578·6974·790a·2020··gh_complexity.··
0003bb60:·2d20·6869·6768·5f73·6576·6572·6974·790a··-·high_severity.0003b850:·2d20·6869·6768·5f73·6576·6572·6974·790a··-·high_severity.
0003bb70:·2020·2d20·6d65·6469·756d·5f64·6973·7275····-·medium_disru0003b860:·2020·2d20·6d65·6469·756d·5f64·6973·7275····-·medium_disru
0003bb80:·7074·696f·6e0a·2020·2d20·6e6f·5f72·6562··ption.··-·no_reb0003b870:·7074·696f·6e0a·2020·2d20·6e6f·5f72·6562··ption.··-·no_reb
Max diff block lines reached; 24229738/24271192 bytes (99.83%) of diff not shown.
2.12 MB
html2text {}
Max HTML report size reached
16.3 MB
./usr/share/doc/ssg-nondebian/ssg-rhv4-guide-rhvh-vpp.html
    
Offset 14383, 16 lines modifiedOffset 14383, 16 lines modified
000382e0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h000382e0:·6973·696f·6e20·4869·7374·6f72·793c·2f68··ision·History</h
000382f0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver000382f0:·323e·3c70·3e43·7572·7265·6e74·2076·6572··2><p>Current·ver
00038300:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.00038300:·7369·6f6e·3a20·3c73·7472·6f6e·673e·302e··sion:·<strong>0.
00038310:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p00038310:·312e·3734·3c2f·7374·726f·6e67·3e3c·2f70··1.74</strong></p
00038320:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong00038320:·3e3c·756c·3e3c·6c69·3e3c·7374·726f·6e67··><ul><li><strong
00038330:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.00038330:·3e64·7261·6674·3c2f·7374·726f·6e67·3e0a··>draft</strong>.
00038340:·2020·2020·2020·2020·2020·2020·2020·2020··················00038340:·2020·2020·2020·2020·2020·2020·2020·2020··················
00038350:·2020·2020·2861·7320·6f66·2032·3032·362d······(as·of·2026-00038350:·2020·2020·2861·7320·6f66·2032·3032·342d······(as·of·2024-
00038360:·3031·2d30·3829·0a20·2020·2020·2020·2020··01-08).·········00038360:·3132·2d30·3729·0a20·2020·2020·2020·2020··12-07).·········
00038370:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul00038370:·2020·2020·2020·203c·2f6c·693e·3c2f·756c·········</li></ul
00038380:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table00038380:·3e3c·2f64·6976·3e3c·6832·3e54·6162·6c65··></div><h2>Table
00038390:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h200038390:·206f·6620·436f·6e74·656e·7473·3c2f·6832···of·Contents</h2
000383a0:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href000383a0:·3e3c·6f6c·3e3c·6c69·3e3c·6120·6872·6566··><ol><li><a·href
000383b0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg000383b0:·3d22·2378·6363·6466·5f6f·7267·2e73·7367··="#xccdf_org.ssg
000383c0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_000383c0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
000383d0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy000383d0:·6772·6f75·705f·7379·7374·656d·223e·5379··group_system">Sy
Offset 15203, 301 lines modifiedOffset 15203, 301 lines modified
0003b620:·7461·7267·6574·3d22·2369·646d·3135·3834··target="#idm15840003b620:·7461·7267·6574·3d22·2369·646d·3135·3834··target="#idm1584
0003b630:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003b630:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003b640:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003b640:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003b650:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003b650:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003b660:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003b660:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003b670:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003b670:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003b680:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003b680:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003b690:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003b6a0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003b6b0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003b6c0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003b6d0:·2069·643d·2269·646d·3135·3834·223e·3c70···id="idm1584"><p 
0003b6e0:·7265·3e3c·636f·6465·3e0a·2320·4669·6e64··re><code>.#·Find 
0003b6f0:·2077·6869·6368·2066·696c·6573·2068·6176···which·files·hav 
0003b700:·6520·696e·636f·7272·6563·7420·6861·7368··e·incorrect·hash 
0003b710:·2028·6e6f·7420·696e·202f·6574·632c·2062···(not·in·/etc,·b 
0003b720:·6563·6175·7365·206f·6620·7468·6520·7379··ecause·of·the·sy 
0003b730:·7374·656d·2072·656c·6174·6564·2063·6f6e··stem·related·con 
0003b740:·6669·6720·6669·6c65·7329·2061·6e64·2074··fig·files)·and·t 
0003b750:·6865·6e20·6765·7420·6669·6c65·7320·6e61··hen·get·files·na 
0003b760:·6d65·730a·6669·6c65·735f·7769·7468·5f69··mes.files_with_i 
0003b770:·6e63·6f72·7265·6374·5f68·6173·683d·2224··ncorrect_hash="$ 
0003b780:·2872·706d·202d·5661·202d·2d6e·6f63·6f6e··(rpm·-Va·--nocon 
0003b790:·6669·6720·7c20·6772·6570·202d·4520·275e··fig·|·grep·-E·'^ 
0003b7a0:·2e2e·3527·207c·2061·776b·2027·7b70·7269··..5'·|·awk·'{pri 
0003b7b0:·6e74·2024·4e46·7d27·2029·220a·0a69·6620··nt·$NF}'·)"..if· 
0003b7c0:·5b20·2d6e·2022·2466·696c·6573·5f77·6974··[·-n·"$files_wit 
0003b7d0:·685f·696e·636f·7272·6563·745f·6861·7368··h_incorrect_hash 
0003b7e0:·2220·5d3b·2074·6865·6e0a·2020·2020·2320··"·];·then.····#· 
0003b7f0:·4672·6f6d·2066·696c·6573·206e·616d·6573··From·files·names 
0003b800:·2067·6574·2070·6163·6b61·6765·206e·616d···get·package·nam 
0003b810:·6573·2061·6e64·2063·6861·6e67·6520·6e65··es·and·change·ne 
0003b820:·776c·696e·6520·746f·2073·7061·6365·2c20··wline·to·space,· 
0003b830:·6265·6361·7573·6520·7270·6d20·7772·6974··because·rpm·writ 
0003b840:·6573·2065·6163·6820·7061·636b·6167·6520··es·each·package· 
0003b850:·746f·206e·6577·206c·696e·650a·2020·2020··to·new·line.···· 
0003b860:·7061·636b·6167·6573·5f74·6f5f·7265·696e··packages_to_rein 
0003b870:·7374·616c·6c3d·2224·2872·706d·202d·7166··stall="$(rpm·-qf 
0003b880:·2024·6669·6c65·735f·7769·7468·5f69·6e63···$files_with_inc 
0003b890:·6f72·7265·6374·5f68·6173·6820·7c20·7472··orrect_hash·|·tr 
0003b8a0:·2027·5c6e·2720·2720·2729·220a·0a20·2020···'\n'·'·')"..··· 
0003b8b0:·200a·2020·2020·7975·6d20·7265·696e·7374···.····yum·reinst 
0003b8c0:·616c·6c20·2d79·2024·7061·636b·6167·6573··all·-y·$packages 
0003b8d0:·5f74·6f5f·7265·696e·7374·616c·6c0a·2020··_to_reinstall.·· 
0003b8e0:·2020·0a66·690a·3c2f·636f·6465·3e3c·2f70····.fi.</code></p 
0003b8f0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003b900:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003b910:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003b920:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003b930:·7461·7267·6574·3d22·2369·646d·3135·3835··target="#idm1585 
0003b940:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003b950:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003b960:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003b970:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003b980:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003b990:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003b9a0:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip0003b690:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip
0003b9b0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003b6a0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003b9c0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003b6b0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003b9d0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003b6c0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003b9e0:·7365·2220·6964·3d22·6964·6d31·3538·3522··se"·id="idm1585"0003b6d0:·7365·2220·6964·3d22·6964·6d31·3538·3422··se"·id="idm1584"
0003b9f0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003b6e0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003ba00:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003b6f0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003ba10:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003b700:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003ba20:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003b710:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003ba30:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003b720:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003ba40:·6578·6974·793a·3c2f·7468·3e3c·7464·3e68··exity:</th><td>h0003b730:·6578·6974·793a·3c2f·7468·3e3c·7464·3e68··exity:</th><td>h
0003ba50:·6967·683c·2f74·643e·3c2f·7472·3e3c·7472··igh</td></tr><tr0003b740:·6967·683c·2f74·643e·3c2f·7472·3e3c·7472··igh</td></tr><tr
0003ba60:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003b750:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003ba70:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<0003b760:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<
0003ba80:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b770:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003ba90:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003b780:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003baa0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003b790:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003bab0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003b7a0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003bac0:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri0003b7b0:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri
0003bad0:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta0003b7c0:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta
0003bae0:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-0003b7d0:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-
0003baf0:·206e·616d·653a·2027·5365·7420·6661·6374···name:·'Set·fact0003b7e0:·206e·616d·653a·2027·5365·7420·6661·6374···name:·'Set·fact
0003bb00:·3a20·5061·636b·6167·6520·6d61·6e61·6765··:·Package·manage0003b7f0:·3a20·5061·636b·6167·6520·6d61·6e61·6765··:·Package·manage
0003bb10:·7220·7265·696e·7374·616c·6c20·636f·6d6d··r·reinstall·comm0003b800:·7220·7265·696e·7374·616c·6c20·636f·6d6d··r·reinstall·comm
0003bb20:·616e·6427·0a20·2073·6574·5f66·6163·743a··and'.··set_fact:0003b810:·616e·6427·0a20·2073·6574·5f66·6163·743a··and'.··set_fact:
0003bb30:·0a20·2020·2070·6163·6b61·6765·5f6d·616e··.····package_man0003b820:·0a20·2020·2070·6163·6b61·6765·5f6d·616e··.····package_man
0003bb40:·6167·6572·5f72·6569·6e73·7461·6c6c·5f63··ager_reinstall_c0003b830:·6167·6572·5f72·6569·6e73·7461·6c6c·5f63··ager_reinstall_c
0003bb50:·6d64·3a20·7975·6d20·7265·696e·7374·616c··md:·yum·reinstal0003b840:·6d64·3a20·7975·6d20·7265·696e·7374·616c··md:·yum·reinstal
0003bb60:·6c20·2d79·0a20·2077·6865·6e3a·2061·6e73··l·-y.··when:·ans0003b850:·6c20·2d79·0a20·2077·6865·6e3a·2061·6e73··l·-y.··when:·ans
0003bb70:·6962·6c65·5f64·6973·7472·6962·7574·696f··ible_distributio0003b860:·6962·6c65·5f64·6973·7472·6962·7574·696f··ible_distributio
0003bb80:·6e20·696e·205b·2022·4665·646f·7261·222c··n·in·[·"Fedora",0003b870:·6e20·696e·205b·2022·4665·646f·7261·222c··n·in·[·"Fedora",
0003bb90:·2022·5265·6448·6174·222c·2022·4365·6e74···"RedHat",·"Cent0003b880:·2022·5265·6448·6174·222c·2022·4365·6e74···"RedHat",·"Cent
0003bba0:·4f53·222c·2022·4f72·6163·6c65·4c69·6e75··OS",·"OracleLinu0003b890:·4f53·222c·2022·4f72·6163·6c65·4c69·6e75··OS",·"OracleLinu
0003bbb0:·7822·205d·0a20·2074·6167·733a·0a20·202d··x"·].··tags:.··-0003b8a0:·7822·205d·0a20·2074·6167·733a·0a20·202d··x"·].··tags:.··-
0003bbc0:·2043·4a49·532d·352e·3130·2e34·2e31·0a20···CJIS-5.10.4.1.·0003b8b0:·2043·4a49·532d·352e·3130·2e34·2e31·0a20···CJIS-5.10.4.1.·
0003bbd0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-0003b8c0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
0003bbe0:·332e·332e·380a·2020·2d20·4e49·5354·2d38··3.3.8.··-·NIST-80003b8d0:·332e·332e·380a·2020·2d20·4e49·5354·2d38··3.3.8.··-·NIST-8
0003bbf0:·3030·2d31·3731·2d33·2e34·2e31·0a20·202d··00-171-3.4.1.··-0003b8e0:·3030·2d31·3731·2d33·2e34·2e31·0a20·202d··00-171-3.4.1.··-
0003bc00:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-0003b8f0:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-
0003bc10:·3928·3329·0a20·202d·204e·4953·542d·3830··9(3).··-·NIST-800003b900:·3928·3329·0a20·202d·204e·4953·542d·3830··9(3).··-·NIST-80
0003bc20:·302d·3533·2d43·4d2d·3628·6329·0a20·202d··0-53-CM-6(c).··-0003b910:·302d·3533·2d43·4d2d·3628·6329·0a20·202d··0-53-CM-6(c).··-
0003bc30:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-0003b920:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-
0003bc40:·3628·6429·0a20·202d·204e·4953·542d·3830··6(d).··-·NIST-800003b930:·3628·6429·0a20·202d·204e·4953·542d·3830··6(d).··-·NIST-80
0003bc50:·302d·3533·2d53·492d·370a·2020·2d20·4e49··0-53-SI-7.··-·NI0003b940:·302d·3533·2d53·492d·370a·2020·2d20·4e49··0-53-SI-7.··-·NI
0003bc60:·5354·2d38·3030·2d35·332d·5349·2d37·2831··ST-800-53-SI-7(10003b950:·5354·2d38·3030·2d35·332d·5349·2d37·2831··ST-800-53-SI-7(1
0003bc70:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-50003b960:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5
0003bc80:·332d·5349·2d37·2836·290a·2020·2d20·5043··3-SI-7(6).··-·PC0003b970:·332d·5349·2d37·2836·290a·2020·2d20·5043··3-SI-7(6).··-·PC
0003bc90:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·0003b980:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·
0003bca0:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.0003b990:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.
0003bcb0:·352e·320a·2020·2d20·6869·6768·5f63·6f6d··5.2.··-·high_com0003b9a0:·352e·320a·2020·2d20·6869·6768·5f63·6f6d··5.2.··-·high_com
0003bcc0:·706c·6578·6974·790a·2020·2d20·6869·6768··plexity.··-·high0003b9b0:·706c·6578·6974·790a·2020·2d20·6869·6768··plexity.··-·high
0003bcd0:·5f73·6576·6572·6974·790a·2020·2d20·6d65··_severity.··-·me0003b9c0:·5f73·6576·6572·6974·790a·2020·2d20·6d65··_severity.··-·me
0003bce0:·6469·756d·5f64·6973·7275·7074·696f·6e0a··dium_disruption.0003b9d0:·6469·756d·5f64·6973·7275·7074·696f·6e0a··dium_disruption.
0003bcf0:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne0003b9e0:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne
Max diff block lines reached; 15985756/16011616 bytes (99.84%) of diff not shown.
1.07 MB
html2text {}
    
Offset 59, 15 lines modifiedOffset 59, 15 lines modified
59 ··············Virtualization·Host·(RHVH)59 ··············Virtualization·Host·(RHVH)
60 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_rhvh-vpp60 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_rhvh-vpp
61 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*61 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
62 ····*·cpe:/o:redhat:enterprise_linux:8::hypervisor62 ····*·cpe:/o:redhat:enterprise_linux:8::hypervisor
63 ····*·cpe:/a:redhat:enterprise_virtualization_manager:463 ····*·cpe:/a:redhat:enterprise_virtualization_manager:4
64 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*64 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
65 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8465 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
66 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)66 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
67 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*67 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
68 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s68 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
69 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e69 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
70 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l70 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
71 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n71 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
72 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s72 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
73 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s73 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 116, 27 lines modifiedOffset 116, 14 lines modified
116 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6116 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.3,·SR·3.4,·SR·3.8,·SR·7.6
117 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4117 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4
118 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)118 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
119 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1119 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
121 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227121 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
122 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2122 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
124 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names 
125 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
126 if·[·-n·"$files_with_incorrect_hash"·];·then 
127 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line 
128 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
129 ····yum·reinstall·-y·$packages_to_reinstall 
  
130 fi 
131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high124 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium125 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false126 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict127 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
136 -·name:·'Set·fact:·Package·manager·reinstall·command'128 -·name:·'Set·fact:·Package·manager·reinstall·command'
137 ··set_fact:129 ··set_fact:
Offset 263, 14 lines modifiedOffset 250, 27 lines modified
263 ··-·PCI-DSSv4-11.5.2250 ··-·PCI-DSSv4-11.5.2
264 ··-·high_complexity251 ··-·high_complexity
265 ··-·high_severity252 ··-·high_severity
266 ··-·medium_disruption253 ··-·medium_disruption
267 ··-·no_reboot_needed254 ··-·no_reboot_needed
268 ··-·restrict_strategy255 ··-·restrict_strategy
269 ··-·rpm_verify_hashes256 ··-·rpm_verify_hashes
 257 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 258 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then·get·files·names
 259 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 260 if·[·-n·"$files_with_incorrect_hash"·];·then
 261 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to·new·line
 262 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 263 ····yum·reinstall·-y·$packages_to_reinstall
  
 264 fi
270 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*265 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
271 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:266 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,·including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,·which·can·be·found·with:
272 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'267 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
273 run·the·following·command·to·determine·which·package·owns·it:268 run·the·following·command·to·determine·which·package·owns·it:
274 $·rpm·-qf·FILENAME269 $·rpm·-qf·FILENAME
275 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:270 Next,·run·the·following·command·to·reset·its·permissions·to·the·correct·values:
276 $·sudo·rpm·--setugids·PACKAGENAME271 $·sudo·rpm·--setugids·PACKAGENAME
Offset 289, 40 lines modifiedOffset 289, 14 lines modified
289 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5289 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.1.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.5.1,·A.12.6.2,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5
290 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2290 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-003-8·R6,·CIP-007-3·R4,·CIP-007-3·R4.1,·CIP-007-3·R4.2
291 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)291 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
292 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1292 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
293 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5293 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
294 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108294 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000278-GPOS-00108
295 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2295 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
296 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
297 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
298 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
299 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
300 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
301 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
302 declare·-A·SETPERMS_RPM_DICT 
  
303 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
304 #·is·expected·by·the·RPM·database 
305 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}') 
  
306 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
307 do 
308 ········RPM_PACKAGE=$(rpm·-qf·"$FILE_PATH") 
309 »       #·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about·duplicates. 
310 »       SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
311 done 
  
312 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
313 #·correct·values 
314 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
315 do 
316 ········rpm·--setugids·"${RPM_PACKAGE}" 
317 done 
318 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8296 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
319 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high297 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
320 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium298 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
321 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false299 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
322 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict300 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
323 -·name:·Read·list·of·files·with·incorrect·ownership301 -·name:·Read·list·of·files·with·incorrect·ownership
324 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev302 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 397, 14 lines modifiedOffset 371, 40 lines modified
397 ··-·PCI-DSSv4-11.5.2371 ··-·PCI-DSSv4-11.5.2
398 ··-·high_complexity372 ··-·high_complexity
399 ··-·high_severity373 ··-·high_severity
400 ··-·medium_disruption374 ··-·medium_disruption
401 ··-·no_reboot_needed375 ··-·no_reboot_needed
402 ··-·restrict_strategy376 ··-·restrict_strategy
403 ··-·rpm_verify_ownership377 ··-·rpm_verify_ownership
 378 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 379 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
 380 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 381 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 382 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
  
 383 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for
Max diff block lines reached; 1114302/1122169 bytes (99.30%) of diff not shown.
20.7 MB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-anssi_bp28_enhanced.html
    
Offset 14343, 15 lines modifiedOffset 14343, 15 lines modified
00038060:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00038060:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00038070:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00038070:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00038080:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</00038080:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
00038090:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00038090:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
000380a0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft000380a0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
000380b0:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······000380b0:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
000380c0:·2020·2020·2020·2020·2020·2020·2020·2861················(a000380c0:·2020·2020·2020·2020·2020·2020·2020·2861················(a
000380d0:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)000380d0:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
000380e0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············000380e0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
000380f0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div000380f0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
00038100:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co00038100:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
00038110:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><00038110:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
00038120:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc00038120:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
00038130:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec00038130:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00038140:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00038140:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 15172, 129 lines modifiedOffset 15172, 129 lines modified
0003b430:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003b430:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003b440:·6d35·3339·3022·2074·6162·696e·6465·783d··m5390"·tabindex=0003b440:·6d35·3339·3022·2074·6162·696e·6465·783d··m5390"·tabindex=
0003b450:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003b450:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003b460:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003b460:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003b470:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003b470:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003b480:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003b480:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003b490:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003b490:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003b4a0:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s0003b4a0:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild
 0003b4b0:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp
 0003b4c0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0003b4d0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003b4e0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003b4f0:·6522·2069·643d·2269·646d·3533·3930·223e··e"·id="idm5390">
0003b4b0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003b4c0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003b4d0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003b4e0:·6170·7365·2220·6964·3d22·6964·6d35·3339··apse"·id="idm539 
0003b4f0:·3022·3e3c·7461·626c·6520·636c·6173·733d··0"><table·class= 
0003b500:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003b510:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003b520:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003b530:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003b540:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003b550:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b560:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003b570:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b580:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003b590:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003b5a0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
0003b5b0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003b5c0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003b5d0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003b5e0:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem0003b500:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa
 0003b510:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=·
 0003b520:·2261·6964·6522·0a76·6572·7369·6f6e·203d··"aide".version·=
0003b5f0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl 
0003b600:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c 
0003b610:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms 
0003b620:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc 
0003b630:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a 
0003b640:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/ 
0003b650:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·]; 
0003b660:·2074·6865·6e0a·0a7a·7970·7065·7220·696e···then..zypper·in 
0003b670:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide". 
0003b680:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a 
0003b690:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed 
0003b6a0:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap 
0003b6b0:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin 
0003b6c0:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.< 
0003b6d0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003b6e0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003b6f0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003b700:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003b710:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003b720:·2223·6964·6d35·3339·3122·2074·6162·696e··"#idm5391"·tabin 
0003b730:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003b740:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003b750:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003b760:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003b770:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003b780:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans 
0003b790:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·... 
0003b7a0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b7b0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b7c0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b7d0:·2269·646d·3533·3931·223e·3c74·6162·6c65··"idm5391"><table 
0003b7e0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003b7f0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003b800:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003b810:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003b820:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003b830:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b840:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003b850:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003b860:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b870:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003b880:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003b890:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003b8a0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0003b8b0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0003b8c0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003b8d0:·653e·2d20·6e61·6d65·3a20·456e·7375·7265··e>-·name:·Ensure 
0003b8e0:·2061·6964·6520·6973·2069·6e73·7461·6c6c···aide·is·install 
0003b8f0:·6564·0a20·2070·6163·6b61·6765·3a0a·2020··ed.··package:.·· 
0003b900:·2020·6e61·6d65·3a20·6169·6465·0a20·2020····name:·aide.··· 
0003b910:·2073·7461·7465·3a20·7072·6573·656e·740a···state:·present. 
0003b920:·2020·7768·656e·3a20·616e·7369·626c·655f····when:·ansible_ 
0003b930:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t 
0003b940:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc 
0003b950:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op 
0003b960:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman", 
0003b970:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].·· 
0003b980:·7461·6773·3a0a·2020·2d20·4343·452d·3833··tags:.··-·CCE-83 
0003b990:·3036·372d·390a·2020·2d20·434a·4953·2d35··067-9.··-·CJIS-5 
0003b9a0:·2e31·302e·312e·330a·2020·2d20·4449·5341··.10.1.3.··-·DISA 
0003b9b0:·2d53·5449·472d·534c·4553·2d31·322d·3031··-STIG-SLES-12-01 
0003b9c0:·3034·3939·0a20·202d·204e·4953·542d·3830··0499.··-·NIST-80 
0003b9d0:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··- 
0003b9e0:·2050·4349·2d44·5353·2d52·6571·2d31·312e···PCI-DSS-Req-11. 
0003b9f0:·350a·2020·2d20·5043·492d·4453·5376·342d··5.··-·PCI-DSSv4- 
0003ba00:·3131·2e35·2e32·0a20·202d·2065·6e61·626c··11.5.2.··-·enabl 
0003ba10:·655f·7374·7261·7465·6779·0a20·202d·206c··e_strategy.··-·l 
0003ba20:·6f77·5f63·6f6d·706c·6578·6974·790a·2020··ow_complexity.·· 
0003ba30:·2d20·6c6f·775f·6469·7372·7570·7469·6f6e··-·low_disruption 
0003ba40:·0a20·202d·206d·6564·6975·6d5f·7365·7665··.··-·medium_seve 
0003ba50:·7269·7479·0a20·202d·206e·6f5f·7265·626f··rity.··-·no_rebo 
0003ba60:·6f74·5f6e·6565·6465·640a·2020·2d20·7061··ot_needed.··-·pa 
0003ba70:·636b·6167·655f·6169·6465·5f69·6e73·7461··ckage_aide_insta 
0003ba80:·6c6c·6564·0a3c·2f63·6f64·653e·3c2f·7072··lled.</code></pr0003b530:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr
0003ba90:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class0003b540:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
0003baa0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes0003b550:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
Max diff block lines reached; 19894621/19912201 bytes (99.91%) of diff not shown.
1.76 MB
html2text {}
    
Offset 49, 15 lines modifiedOffset 49, 15 lines modified
49 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(enhanced)49 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(enhanced)
50 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_enhanced50 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_enhanced
51 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*51 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
52 ····*·cpe:/o:suse:linux_enterprise_desktop:1252 ····*·cpe:/o:suse:linux_enterprise_desktop:12
53 ····*·cpe:/o:suse:linux_enterprise_server:1253 ····*·cpe:/o:suse:linux_enterprise_server:12
54 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*54 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
55 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8455 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
56 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)56 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
57 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*57 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
58 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s58 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
59 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e59 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
60 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l60 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
61 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r61 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
62 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n62 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
63 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g63 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 134, 27 lines modifiedOffset 134, 19 lines modified
134 include·install_aide134 include·install_aide
  
135 class·install_aide·{135 class·install_aide·{
136 ··package·{·'aide':136 ··package·{·'aide':
137 ····ensure·=>·'installed',137 ····ensure·=>·'installed',
138 ··}138 ··}
139 }139 }
 140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
145 #·Remediation·is·applicable·only·in·certain·platforms 
146 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
147 zypper·install·-y·"aide" 
  
148 else 
149 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
150 fi141 [[packages]]
 142 name·=·"aide"
 143 version·=·"*"
151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low145 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low146 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false147 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable148 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
156 -·name:·Ensure·aide·is·installed149 -·name:·Ensure·aide·is·installed
157 ··package:150 ··package:
Offset 170, 19 lines modifiedOffset 162, 27 lines modified
170 ··-·PCI-DSSv4-11.5.2162 ··-·PCI-DSSv4-11.5.2
171 ··-·enable_strategy163 ··-·enable_strategy
172 ··-·low_complexity164 ··-·low_complexity
173 ··-·low_disruption165 ··-·low_disruption
174 ··-·medium_severity166 ··-·medium_severity
175 ··-·no_reboot_needed167 ··-·no_reboot_needed
176 ··-·package_aide_installed168 ··-·package_aide_installed
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 174 #·Remediation·is·applicable·only·in·certain·platforms
 175 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
178 [[packages]] 
179 name·=·"aide" 
180 version·=·"*"176 zypper·install·-y·"aide"
  
 177 else
 178 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 179 fi
181 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*180 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
182 Run·the·following·command·to·generate·a·new·database:181 Run·the·following·command·to·generate·a·new·database:
183 $·sudo·/usr/bin/aide·--init182 $·sudo·/usr/bin/aide·--init
184 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the183 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the
185 configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these·files),·in·a·secure184 configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these·files),·in·a·secure
186 location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-185 location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-
187 generated·database·can·be·installed·as·follows:186 generated·database·can·be·installed·as·follows:
Offset 209, 29 lines modifiedOffset 209, 14 lines modified
209 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5209 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
210 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199210 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
211 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499211 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499
212 ·············_\x8c_\x8i_\x8s············1.4.1212 ·············_\x8c_\x8i_\x8s············1.4.1
213 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79213 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
214 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2214 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
215 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r880937_rule215 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r880937_rule
216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
217 #·Remediation·is·applicable·only·in·certain·platforms 
218 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
219 zypper·-q·--no-remote·ref 
  
  
220 zypper·install·-y·"aide" 
  
221 /usr/bin/aide·--init 
222 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db 
  
223 else 
224 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
225 fi 
226 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
227 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low217 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
228 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low218 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
229 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false219 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
230 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict220 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
231 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated221 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated
232 ··ansible.builtin.command:·zypper·-q·--no-remote·ref222 ··ansible.builtin.command:·zypper·-q·--no-remote·ref
Offset 327, 14 lines modifiedOffset 312, 29 lines modified
327 ··-·PCI-DSSv4-11.5.2312 ··-·PCI-DSSv4-11.5.2
328 ··-·aide_build_database313 ··-·aide_build_database
329 ··-·low_complexity314 ··-·low_complexity
330 ··-·low_disruption315 ··-·low_disruption
331 ··-·medium_severity316 ··-·medium_severity
332 ··-·no_reboot_needed317 ··-·no_reboot_needed
333 ··-·restrict_strategy318 ··-·restrict_strategy
 319 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 320 #·Remediation·is·applicable·only·in·certain·platforms
 321 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 322 zypper·-q·--no-remote·ref
  
  
 323 zypper·install·-y·"aide"
  
 324 /usr/bin/aide·--init
 325 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db
  
 326 else
Max diff block lines reached; 1838926/1844233 bytes (99.71%) of diff not shown.
21.0 MB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-anssi_bp28_high.html
    
Offset 14342, 15 lines modifiedOffset 14342, 15 lines modified
00038050:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00038050:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00038060:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00038060:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00038070:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</00038070:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
00038080:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00038080:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
00038090:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft00038090:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
000380a0:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······000380a0:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
000380b0:·2020·2020·2020·2020·2020·2020·2020·2861················(a000380b0:·2020·2020·2020·2020·2020·2020·2020·2861················(a
000380c0:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)000380c0:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
000380d0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············000380d0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
000380e0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div000380e0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
000380f0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co000380f0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
00038100:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><00038100:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
00038110:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc00038110:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
00038120:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec00038120:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00038130:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00038130:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 15177, 130 lines modifiedOffset 15177, 130 lines modified
0003b480:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b480:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b490:·2369·646d·3533·3930·2220·7461·6269·6e64··#idm5390"·tabind0003b490:·2369·646d·3533·3930·2220·7461·6269·6e64··#idm5390"·tabind
0003b4a0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b4a0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b4b0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b4b0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b4c0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b4c0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b4d0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b4d0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b4e0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b4e0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b4f0:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel0003b4f0:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu
 0003b500:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn
 0003b510:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0003b520:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003b530:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003b540:·6170·7365·2220·6964·3d22·6964·6d35·3339··apse"·id="idm539
0003b500:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a> 
0003b510:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b520:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b530:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b540:·3533·3930·223e·3c74·6162·6c65·2063·6c61··5390"><table·cla 
0003b550:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003b560:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003b570:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003b580:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003b590:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003b5a0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b5b0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003b5c0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003b5d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b5e0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003b5f0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003b600:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003b610:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003b620:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003b630:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·0003b550:·3022·3e3c·7072·653e·3c63·6f64·653e·0a5b··0"><pre><code>.[
 0003b560:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name
 0003b570:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio
 0003b580:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code><
0003b640:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a 
0003b650:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i 
0003b660:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo 
0003b670:·726d·730a·6966·205b·2021·202d·6620·2f2e··rms.if·[·!·-f·/. 
0003b680:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp 
0003b690:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r 
0003b6a0:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv 
0003b6b0:·205d·3b20·7468·656e·0a0a·7a79·7070·6572···];·then..zypper 
0003b6c0:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid 
0003b6d0:·6522·0a0a·656c·7365·0a20·2020·2026·6774··e"..else.····&gt 
0003b6e0:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re 
0003b6f0:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not 
0003b700:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not 
0003b710:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f 
0003b720:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre>< 
0003b730:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003b740:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003b750:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003b760:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003b770:·6574·3d22·2369·646d·3533·3931·2220·7461··et="#idm5391"·ta 
0003b780:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003b790:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003b7a0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003b7b0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003b7c0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003b7d0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003b7e0:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet· 
0003b7f0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003b800:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003b810:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003b820:·6964·3d22·6964·6d35·3339·3122·3e3c·7461··id="idm5391"><ta 
0003b830:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003b840:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003b850:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003b860:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003b870:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003b880:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003b890:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b8a0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003b8b0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b8c0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003b8d0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003b8e0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b8f0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003b900:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0003b910:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003b920:·636f·6465·3e2d·206e·616d·653a·2045·6e73··code>-·name:·Ens 
0003b930:·7572·6520·6169·6465·2069·7320·696e·7374··ure·aide·is·inst 
0003b940:·616c·6c65·640a·2020·7061·636b·6167·653a··alled.··package: 
0003b950:·0a20·2020·206e·616d·653a·2061·6964·650a··.····name:·aide. 
0003b960:·2020·2020·7374·6174·653a·2070·7265·7365······state:·prese 
0003b970:·6e74·0a20·2077·6865·6e3a·2061·6e73·6962··nt.··when:·ansib 
0003b980:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio 
0003b990:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·[" 
0003b9a0:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",· 
0003b9b0:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma 
0003b9c0:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"] 
0003b9d0:·0a20·2074·6167·733a·0a20·202d·2043·4345··.··tags:.··-·CCE 
0003b9e0:·2d38·3330·3637·2d39·0a20·202d·2043·4a49··-83067-9.··-·CJI 
0003b9f0:·532d·352e·3130·2e31·2e33·0a20·202d·2044··S-5.10.1.3.··-·D 
0003ba00:·4953·412d·5354·4947·2d53·4c45·532d·3132··ISA-STIG-SLES-12 
0003ba10:·2d30·3130·3439·390a·2020·2d20·4e49·5354··-010499.··-·NIST 
0003ba20:·2d38·3030·2d35·332d·434d·2d36·2861·290a··-800-53-CM-6(a). 
0003ba30:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req- 
0003ba40:·3131·2e35·0a20·202d·2050·4349·2d44·5353··11.5.··-·PCI-DSS 
0003ba50:·7634·2d31·312e·352e·320a·2020·2d20·656e··v4-11.5.2.··-·en 
0003ba60:·6162·6c65·5f73·7472·6174·6567·790a·2020··able_strategy.·· 
0003ba70:·2d20·6c6f·775f·636f·6d70·6c65·7869·7479··-·low_complexity 
0003ba80:·0a20·202d·206c·6f77·5f64·6973·7275·7074··.··-·low_disrupt 
0003ba90:·696f·6e0a·2020·2d20·6d65·6469·756d·5f73··ion.··-·medium_s 
0003baa0:·6576·6572·6974·790a·2020·2d20·6e6f·5f72··everity.··-·no_r 
0003bab0:·6562·6f6f·745f·6e65·6564·6564·0a20·202d··eboot_needed.··- 
0003bac0:·2070·6163·6b61·6765·5f61·6964·655f·696e···package_aide_in 
0003bad0:·7374·616c·6c65·640a·3c2f·636f·6465·3e3c··stalled.</code>< 
0003bae0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl0003b590:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
Max diff block lines reached; 20099815/20117533 bytes (99.91%) of diff not shown.
1.79 MB
html2text {}
Max HTML report size reached
8.24 MB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-anssi_bp28_intermediary.html
    
Offset 14344, 15 lines modifiedOffset 14344, 15 lines modified
00038070:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00038070:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00038080:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00038080:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00038090:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</00038090:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
000380a0:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><000380a0:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
000380b0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft000380b0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
000380c0:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······000380c0:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
000380d0:·2020·2020·2020·2020·2020·2020·2020·2861················(a000380d0:·2020·2020·2020·2020·2020·2020·2020·2861················(a
000380e0:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)000380e0:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
000380f0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············000380f0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00038100:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div00038100:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
00038110:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co00038110:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
00038120:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><00038120:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
00038130:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc00038130:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
00038140:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec00038140:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00038150:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00038150:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 15163, 129 lines modifiedOffset 15163, 129 lines modified
0003b3a0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b3a0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003b3b0:·646d·3533·3930·2220·7461·6269·6e64·6578··dm5390"·tabindex0003b3b0:·646d·3533·3930·2220·7461·6269·6e64·6578··dm5390"·tabindex
0003b3c0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b3c0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b3d0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b3d0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b3e0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b3e0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b3f0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b3f0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b400:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b400:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003b410:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·0003b410:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil
 0003b420:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip
 0003b430:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
 0003b440:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0003b450:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0003b460:·7365·2220·6964·3d22·6964·6d35·3339·3022··se"·id="idm5390"
0003b420:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003b430:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003b440:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003b450:·6c61·7073·6522·2069·643d·2269·646d·3533··lapse"·id="idm53 
0003b460:·3930·223e·3c74·6162·6c65·2063·6c61·7373··90"><table·class 
0003b470:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003b480:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003b490:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003b4a0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003b4b0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003b4c0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b4d0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003b4e0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003b4f0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b500:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003b510:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
0003b520:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003b530:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003b540:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003b550:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re0003b470:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p
 0003b480:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·=
 0003b490:·2022·6169·6465·220a·7665·7273·696f·6e20···"aide".version·
 0003b4a0:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p
0003b560:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app 
0003b570:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in· 
0003b580:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform 
0003b590:·730a·6966·205b·2021·202d·6620·2f2e·646f··s.if·[·!·-f·/.do 
0003b5a0:·636b·6572·656e·7620·5d20·2661·6d70·3b26··ckerenv·]·&amp;& 
0003b5b0:·616d·703b·205b·2021·202d·6620·2f72·756e··amp;·[·!·-f·/run 
0003b5c0:·2f2e·636f·6e74·6169·6e65·7265·6e76·205d··/.containerenv·] 
0003b5d0:·3b20·7468·656e·0a0a·7a79·7070·6572·2069··;·then..zypper·i 
0003b5e0:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide" 
0003b5f0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;& 
0003b600:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme 
0003b610:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a 
0003b620:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi 
0003b630:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi. 
0003b640:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003b650:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003b660:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003b670:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003b680:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003b690:·3d22·2369·646d·3533·3931·2220·7461·6269··="#idm5391"·tabi 
0003b6a0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003b6b0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003b6c0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003b6d0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003b6e0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003b6f0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An 
0003b700:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
0003b710:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b720:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b730:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b740:·3d22·6964·6d35·3339·3122·3e3c·7461·626c··="idm5391"><tabl 
0003b750:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003b760:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003b770:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003b780:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003b790:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003b7a0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b7b0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003b7c0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003b7d0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b7e0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003b7f0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003b800:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003b810:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003b820:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003b830:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003b840:·6465·3e2d·206e·616d·653a·2045·6e73·7572··de>-·name:·Ensur 
0003b850:·6520·6169·6465·2069·7320·696e·7374·616c··e·aide·is·instal 
0003b860:·6c65·640a·2020·7061·636b·6167·653a·0a20··led.··package:.· 
0003b870:·2020·206e·616d·653a·2061·6964·650a·2020·····name:·aide.·· 
0003b880:·2020·7374·6174·653a·2070·7265·7365·6e74····state:·present 
0003b890:·0a20·2077·6865·6e3a·2061·6e73·6962·6c65··.··when:·ansible 
0003b8a0:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_ 
0003b8b0:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do 
0003b8c0:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o 
0003b8d0:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman" 
0003b8e0:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].· 
0003b8f0:·2074·6167·733a·0a20·202d·2043·4345·2d38···tags:.··-·CCE-8 
0003b900:·3330·3637·2d39·0a20·202d·2043·4a49·532d··3067-9.··-·CJIS- 
0003b910:·352e·3130·2e31·2e33·0a20·202d·2044·4953··5.10.1.3.··-·DIS 
0003b920:·412d·5354·4947·2d53·4c45·532d·3132·2d30··A-STIG-SLES-12-0 
0003b930:·3130·3439·390a·2020·2d20·4e49·5354·2d38··10499.··-·NIST-8 
0003b940:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).·· 
0003b950:·2d20·5043·492d·4453·532d·5265·712d·3131··-·PCI-DSS-Req-11 
0003b960:·2e35·0a20·202d·2050·4349·2d44·5353·7634··.5.··-·PCI-DSSv4 
0003b970:·2d31·312e·352e·320a·2020·2d20·656e·6162··-11.5.2.··-·enab 
0003b980:·6c65·5f73·7472·6174·6567·790a·2020·2d20··le_strategy.··-· 
0003b990:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.· 
0003b9a0:·202d·206c·6f77·5f64·6973·7275·7074·696f···-·low_disruptio 
0003b9b0:·6e0a·2020·2d20·6d65·6469·756d·5f73·6576··n.··-·medium_sev 
0003b9c0:·6572·6974·790a·2020·2d20·6e6f·5f72·6562··erity.··-·no_reb 
0003b9d0:·6f6f·745f·6e65·6564·6564·0a20·202d·2070··oot_needed.··-·p 
0003b9e0:·6163·6b61·6765·5f61·6964·655f·696e·7374··ackage_aide_inst 
0003b9f0:·616c·6c65·640a·3c2f·636f·6465·3e3c·2f70··alled.</code></p 
0003ba00:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas0003b4b0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
Max diff block lines reached; 7704192/7721772 bytes (99.77%) of diff not shown.
897 KB
html2text {}
    
Offset 49, 15 lines modifiedOffset 49, 15 lines modified
49 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(intermediary)49 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(intermediary)
50 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_intermediary50 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_intermediary
51 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*51 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
52 ····*·cpe:/o:suse:linux_enterprise_desktop:1252 ····*·cpe:/o:suse:linux_enterprise_desktop:12
53 ····*·cpe:/o:suse:linux_enterprise_server:1253 ····*·cpe:/o:suse:linux_enterprise_server:12
54 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*54 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
55 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8455 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
56 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)56 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
57 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*57 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
58 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s58 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
59 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e59 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
60 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l60 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
61 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n61 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
62 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s62 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
63 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s63 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 134, 27 lines modifiedOffset 134, 19 lines modified
134 include·install_aide134 include·install_aide
  
135 class·install_aide·{135 class·install_aide·{
136 ··package·{·'aide':136 ··package·{·'aide':
137 ····ensure·=>·'installed',137 ····ensure·=>·'installed',
138 ··}138 ··}
139 }139 }
 140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
145 #·Remediation·is·applicable·only·in·certain·platforms 
146 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
147 zypper·install·-y·"aide" 
  
148 else 
149 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
150 fi141 [[packages]]
 142 name·=·"aide"
 143 version·=·"*"
151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low145 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low146 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false147 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable148 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
156 -·name:·Ensure·aide·is·installed149 -·name:·Ensure·aide·is·installed
157 ··package:150 ··package:
Offset 170, 19 lines modifiedOffset 162, 27 lines modified
170 ··-·PCI-DSSv4-11.5.2162 ··-·PCI-DSSv4-11.5.2
171 ··-·enable_strategy163 ··-·enable_strategy
172 ··-·low_complexity164 ··-·low_complexity
173 ··-·low_disruption165 ··-·low_disruption
174 ··-·medium_severity166 ··-·medium_severity
175 ··-·no_reboot_needed167 ··-·no_reboot_needed
176 ··-·package_aide_installed168 ··-·package_aide_installed
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 174 #·Remediation·is·applicable·only·in·certain·platforms
 175 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
178 [[packages]] 
179 name·=·"aide" 
180 version·=·"*"176 zypper·install·-y·"aide"
  
 177 else
 178 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 179 fi
181 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*180 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
182 Run·the·following·command·to·generate·a·new·database:181 Run·the·following·command·to·generate·a·new·database:
183 $·sudo·/usr/bin/aide·--init182 $·sudo·/usr/bin/aide·--init
184 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the183 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the
185 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these184 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these
186 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their185 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
187 integrity.·The·newly-generated·database·can·be·installed·as·follows:186 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 209, 29 lines modifiedOffset 209, 14 lines modified
209 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5209 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
210 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199210 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
211 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499211 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499
212 ·············_\x8c_\x8i_\x8s············1.4.1212 ·············_\x8c_\x8i_\x8s············1.4.1
213 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79213 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
214 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2214 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
215 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r880937_rule215 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r880937_rule
216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
217 #·Remediation·is·applicable·only·in·certain·platforms 
218 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
219 zypper·-q·--no-remote·ref 
  
  
220 zypper·install·-y·"aide" 
  
221 /usr/bin/aide·--init 
222 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db 
  
223 else 
224 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
225 fi 
226 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
227 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low217 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
228 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low218 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
229 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false219 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
230 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict220 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
231 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated221 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated
232 ··ansible.builtin.command:·zypper·-q·--no-remote·ref222 ··ansible.builtin.command:·zypper·-q·--no-remote·ref
Offset 327, 14 lines modifiedOffset 312, 29 lines modified
327 ··-·PCI-DSSv4-11.5.2312 ··-·PCI-DSSv4-11.5.2
328 ··-·aide_build_database313 ··-·aide_build_database
329 ··-·low_complexity314 ··-·low_complexity
330 ··-·low_disruption315 ··-·low_disruption
331 ··-·medium_severity316 ··-·medium_severity
332 ··-·no_reboot_needed317 ··-·no_reboot_needed
333 ··-·restrict_strategy318 ··-·restrict_strategy
 319 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 320 #·Remediation·is·applicable·only·in·certain·platforms
 321 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 322 zypper·-q·--no-remote·ref
  
  
 323 zypper·install·-y·"aide"
  
 324 /usr/bin/aide·--init
 325 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db
  
 326 else
Max diff block lines reached; 913215/918639 bytes (99.41%) of diff not shown.
2.02 MB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-anssi_bp28_minimal.html
    
Offset 14343, 15 lines modifiedOffset 14343, 15 lines modified
00038060:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre00038060:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre
00038070:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str00038070:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str
00038080:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro00038080:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro
00038090:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><00038090:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><
000380a0:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st000380a0:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st
000380b0:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········000380b0:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········
000380c0:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of000380c0:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of
000380d0:·2032·3032·362d·3031·2d30·3829·0a20·2020···2026-01-08).···000380d0:·2032·3032·342d·3132·2d30·3729·0a20·2020···2024-12-07).···
000380e0:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l000380e0:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l
000380f0:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h2000380f0:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h2
00038100:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten00038100:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten
00038110:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><00038110:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><
00038120:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o00038120:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o
00038130:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co00038130:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co
00038140:·6e74·656e·745f·6772·6f75·705f·7379·7374··ntent_group_syst00038140:·6e74·656e·745f·6772·6f75·705f·7379·7374··ntent_group_syst
Offset 14833, 106 lines modifiedOffset 14833, 106 lines modified
00039f00:·2d74·6172·6765·743d·2223·6964·6d38·3133··-target="#idm81300039f00:·2d74·6172·6765·743d·2223·6964·6d38·3133··-target="#idm813
00039f10:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·00039f10:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·
00039f20:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar00039f20:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
00039f30:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal00039f30:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
00039f40:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ00039f40:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
00039f50:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h00039f50:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
00039f60:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia00039f60:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 00039f70:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu
 00039f80:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·.
 00039f90:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 00039fa0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 00039fb0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 00039fc0:·643d·2269·646d·3831·3331·223e·3c70·7265··d="idm8131"><pre
 00039fd0:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag
 00039fe0:·6573·5d5d·0a6e·616d·6520·3d20·2264·6e66··es]].name·=·"dnf
 00039ff0:·2d61·7574·6f6d·6174·6963·220a·7665·7273··-automatic".vers
 0003a000:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code
00039f70:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
00039f80:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
00039f90:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
00039fa0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
00039fb0:·2220·6964·3d22·6964·6d38·3133·3122·3e3c··"·id="idm8131">< 
00039fc0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
00039fd0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
00039fe0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
00039ff0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003a000:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003a010:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003a020:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003a030:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003a040:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003a050:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003a060:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003a070:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003a080:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003a090:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003a0a0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003a0b0:·3e3c·636f·6465·3e0a·7a79·7070·6572·2069··><code>.zypper·i 
0003a0c0:·6e73·7461·6c6c·202d·7920·2264·6e66·2d61··nstall·-y·"dnf-a 
0003a0d0:·7574·6f6d·6174·6963·220a·3c2f·636f·6465··utomatic".</code 
0003a0e0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0003a010:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
0003a0f0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0003a020:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
0003a100:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0003a030:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0003a110:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003a040:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
0003a120:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003a050:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003a130:·3831·3332·2220·7461·6269·6e64·6578·3d22··8132"·tabindex="0003a060:·3831·3332·2220·7461·6269·6e64·6578·3d22··8132"·tabindex="
0003a140:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003a070:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003a150:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003a080:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003a160:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003a090:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003a170:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003a0a0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003a180:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003a0b0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003a190:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible·0003a0c0:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible·
0003a1a0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003a0d0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003a1b0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003a0e0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003a1c0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003a0f0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003a1d0:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm80003a100:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
0003a1e0:·3133·3222·3e3c·7461·626c·6520·636c·6173··132"><table·clas0003a110:·3133·3222·3e3c·7461·626c·6520·636c·6173··132"><table·clas
0003a1f0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003a120:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003a200:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003a130:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003a210:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003a140:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003a220:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003a150:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003a230:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003a160:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003a240:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003a170:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003a250:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003a180:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003a260:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003a190:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003a270:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003a1a0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003a280:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003a1b0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003a290:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003a1c0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003a2a0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003a1d0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003a2b0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003a1e0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
0003a2c0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003a1f0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003a2d0:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n0003a200:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n
0003a2e0:·616d·653a·2045·6e73·7572·6520·646e·662d··ame:·Ensure·dnf-0003a210:·616d·653a·2045·6e73·7572·6520·646e·662d··ame:·Ensure·dnf-
0003a2f0:·6175·746f·6d61·7469·6320·6973·2069·6e73··automatic·is·ins0003a220:·6175·746f·6d61·7469·6320·6973·2069·6e73··automatic·is·ins
0003a300:·7461·6c6c·6564·0a20·2070·6163·6b61·6765··talled.··package0003a230:·7461·6c6c·6564·0a20·2070·6163·6b61·6765··talled.··package
0003a310:·3a0a·2020·2020·6e61·6d65·3a20·646e·662d··:.····name:·dnf-0003a240:·3a0a·2020·2020·6e61·6d65·3a20·646e·662d··:.····name:·dnf-
0003a320:·6175·746f·6d61·7469·630a·2020·2020·7374··automatic.····st0003a250:·6175·746f·6d61·7469·630a·2020·2020·7374··automatic.····st
0003a330:·6174·653a·2070·7265·7365·6e74·0a20·2074··ate:·present.··t0003a260:·6174·653a·2070·7265·7365·6e74·0a20·2074··ate:·present.··t
0003a340:·6167·733a·0a20·202d·2043·4345·2d39·3134··ags:.··-·CCE-9140003a270:·6167·733a·0a20·202d·2043·4345·2d39·3134··ags:.··-·CCE-914
0003a350:·3736·2d32·0a20·202d·2065·6e61·626c·655f··76-2.··-·enable_0003a280:·3736·2d32·0a20·202d·2065·6e61·626c·655f··76-2.··-·enable_
0003a360:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low0003a290:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low
0003a370:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-·0003a2a0:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-·
0003a380:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.·0003a2b0:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.·
0003a390:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi0003a2c0:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi
0003a3a0:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot0003a2d0:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot
0003a3b0:·5f6e·6565·6465·640a·2020·2d20·7061·636b··_needed.··-·pack0003a2e0:·5f6e·6565·6465·640a·2020·2d20·7061·636b··_needed.··-·pack
0003a3c0:·6167·655f·646e·662d·6175·746f·6d61·7469··age_dnf-automati0003a2f0:·6167·655f·646e·662d·6175·746f·6d61·7469··age_dnf-automati
0003a3d0:·635f·696e·7374·616c·6c65·640a·3c2f·636f··c_installed.</co0003a300:·635f·696e·7374·616c·6c65·640a·3c2f·636f··c_installed.</co
0003a3e0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><0003a310:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
0003a3f0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn0003a320:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
0003a400:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t0003a330:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
0003a410:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"0003a340:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
0003a420:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003a350:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003a430:·646d·3831·3333·2220·7461·6269·6e64·6578··dm8133"·tabindex0003a360:·646d·3831·3333·2220·7461·6269·6e64·6578··dm8133"·tabindex
0003a440:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003a370:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003a450:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003a380:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003a460:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003a390:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003a470:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003a3a0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003a480:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003a3b0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003a490:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil0003a3c0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
0003a4a0:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
0003a4b0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003a4c0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003a4d0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003a4e0:·7365·2220·6964·3d22·6964·6d38·3133·3322··se"·id="idm8133"0003a3d0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 0003a3e0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003a3f0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003a400:·6c61·7073·6522·2069·643d·2269·646d·3831··lapse"·id="idm81
 0003a410:·3333·223e·3c74·6162·6c65·2063·6c61·7373··33"><table·class
 0003a420:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003a430:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
Max diff block lines reached; 1957844/1972250 bytes (99.27%) of diff not shown.
144 KB
html2text {}
    
Offset 49, 15 lines modifiedOffset 49, 15 lines modified
49 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(minimal)49 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(minimal)
50 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_minimal50 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_minimal
51 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*51 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
52 ····*·cpe:/o:suse:linux_enterprise_desktop:1252 ····*·cpe:/o:suse:linux_enterprise_desktop:12
53 ····*·cpe:/o:suse:linux_enterprise_server:1253 ····*·cpe:/o:suse:linux_enterprise_server:12
54 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*54 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
55 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8455 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
56 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)56 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
57 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*57 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
58 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s58 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
59 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e59 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
60 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l60 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
61 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s61 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
62 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s62 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
63 ·········1.·_\x8D_\x8H_\x8C_\x8P63 ·········1.·_\x8D_\x8H_\x8C_\x8P
Offset 99, 21 lines modifiedOffset 99, 19 lines modified
99 include·install_dnf-automatic99 include·install_dnf-automatic
  
100 class·install_dnf-automatic·{100 class·install_dnf-automatic·{
101 ··package·{·'dnf-automatic':101 ··package·{·'dnf-automatic':
102 ····ensure·=>·'installed',102 ····ensure·=>·'installed',
103 ··}103 ··}
104 }104 }
 105 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
105 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
106 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
107 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
108 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
109 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
110 zypper·install·-y·"dnf-automatic"106 [[packages]]
 107 name·=·"dnf-automatic"
 108 version·=·"*"
111 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8109 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
112 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low110 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
113 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low111 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
114 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false112 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
115 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable113 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
116 -·name:·Ensure·dnf-automatic·is·installed114 -·name:·Ensure·dnf-automatic·is·installed
117 ··package:115 ··package:
Offset 123, 19 lines modifiedOffset 121, 21 lines modified
123 ··-·CCE-91476-2121 ··-·CCE-91476-2
124 ··-·enable_strategy122 ··-·enable_strategy
125 ··-·low_complexity123 ··-·low_complexity
126 ··-·low_disruption124 ··-·low_disruption
127 ··-·medium_severity125 ··-·medium_severity
128 ··-·no_reboot_needed126 ··-·no_reboot_needed
129 ··-·package_dnf-automatic_installed127 ··-·package_dnf-automatic_installed
130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 133 zypper·install·-y·"dnf-automatic"
131 [[packages]] 
132 name·=·"dnf-automatic" 
133 version·=·"*" 
134 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*134 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
135 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically135 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically
136 installed·by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/136 installed·by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
137 automatic.conf.137 automatic.conf.
138 ·············Installing·software·updates·is·a·fundamental·mitigation·against·the138 ·············Installing·software·updates·is·a·fundamental·mitigation·against·the
139 ·············exploitation·of·publicly-known·vulnerabilities.·If·the·most·recent·security139 ·············exploitation·of·publicly-known·vulnerabilities.·If·the·most·recent·security
140 Rationale:···patches·and·updates·are·not·installed,·unauthorized·users·may·take·advantage140 Rationale:···patches·and·updates·are·not·installed,·unauthorized·users·may·take·advantage
Offset 146, 14 lines modifiedOffset 146, 37 lines modified
146 Rule·ID:·····xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates146 Rule·ID:·····xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates
147 Identifiers:·CCE-91474-7147 Identifiers:·CCE-91474-7
148 ·············_\x8i_\x8s_\x8m····0940,·1144,·1467,·1472,·1483,·1493,·1494,·1495148 ·············_\x8i_\x8s_\x8m····0940,·1144,·1467,·1472,·1483,·1493,·1494,·1495
149 ·············_\x8n_\x8i_\x8s_\x8t···SI-2(5),·CM-6(a),·SI-2(c)149 ·············_\x8n_\x8i_\x8s_\x8t···SI-2(5),·CM-6(a),·SI-2(c)
150 References:··_\x8o_\x8s_\x8p_\x8p···FMT_SMF_EXT.1150 References:··_\x8o_\x8s_\x8p_\x8p···FMT_SMF_EXT.1
151 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080151 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
152 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61152 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
 153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 154 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 155 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 156 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 157 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···unknown
 158 -·name:·Configure·dnf-automatic·to·Install·Available·Updates·Automatically
 159 ··ini_file:
 160 ····dest:·/etc/dnf/automatic.conf
 161 ····section:·commands
 162 ····option:·apply_updates
 163 ····value:·'yes'
 164 ····create:·true
 165 ··tags:
 166 ··-·CCE-91474-7
 167 ··-·NIST-800-53-CM-6(a)
 168 ··-·NIST-800-53-SI-2(5)
 169 ··-·NIST-800-53-SI-2(c)
 170 ··-·dnf-automatic_apply_updates
 171 ··-·low_complexity
 172 ··-·medium_disruption
 173 ··-·medium_severity
 174 ··-·no_reboot_needed
 175 ··-·unknown_strategy
153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
154 found=false177 found=false
  
155 #·set·value·in·all·files·if·they·contain·section·or·key178 #·set·value·in·all·files·if·they·contain·section·or·key
156 for·f·in·$(echo·-n·"/etc/dnf/automatic.conf");·do179 for·f·in·$(echo·-n·"/etc/dnf/automatic.conf");·do
157 ····if·[·!·-e·"$f"·];·then180 ····if·[·!·-e·"$f"·];·then
Offset 182, 50 lines modifiedOffset 205, 50 lines modified
182 if·!·$found·;·then205 if·!·$found·;·then
183 ····file=$(echo·"/etc/dnf/automatic.conf"·|·cut·-f1·-d·'·')206 ····file=$(echo·"/etc/dnf/automatic.conf"·|·cut·-f1·-d·'·')
184 ····mkdir·-p·"$(dirname·"$file")"207 ····mkdir·-p·"$(dirname·"$file")"
  
185 ····echo·-e·"[commands]\napply_updates=yes"·>>·"$file"208 ····echo·-e·"[commands]\napply_updates=yes"·>>·"$file"
  
186 fi209 fi
 210 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·O\x8On\x8nl\x8ly\x8y·S\x8Se\x8ec\x8cu\x8ur\x8ri\x8it\x8ty\x8y·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
 211 To·configure·dnf-automatic·to·install·only·security·updates·automatically,·set
 212 upgrade_type·to·security·under·[commands]·section·in·/etc/dnf/automatic.conf.
 213 ·············By·default,·dnf-automatic·installs·all·available·updates.·Reducing·the·amount
 214 Rationale:···of·updated·packages·only·to·updates·that·were·issued·as·a·part·of·a·security
 215 ·············advisory·increases·the·system·stability.
 216 Severity: ···low
 217 Rule·ID:·····xccdf_org.ssgproject.content_rule_dnf-automatic_security_updates_only
 218 Identifiers:·CCE-91478-8
 219 ·············_\x8n_\x8i_\x8s_\x8t···SI-2(5),·CM-6(a),·SI-2(c)
 220 References:··_\x8o_\x8s_\x8p_\x8p···FMT_SMF_EXT.1
 221 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
 222 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8223 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low224 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium225 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
Max diff block lines reached; 141799/147698 bytes (96.01%) of diff not shown.
19.7 MB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-cis.html
    
Offset 14312, 15 lines modifiedOffset 14312, 15 lines modified
00037e70:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·00037e70:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·
00037e80:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong00037e80:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong
00037e90:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>00037e90:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>
00037ea0:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str00037ea0:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str
00037eb0:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron00037eb0:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron
00037ec0:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············00037ec0:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············
00037ed0:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·2000037ed0:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·20
00037ee0:·3236·2d30·312d·3038·290a·2020·2020·2020··26-01-08).······00037ee0:·3234·2d31·322d·3037·290a·2020·2020·2020··24-12-07).······
00037ef0:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><00037ef0:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><
00037f00:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta00037f00:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta
00037f10:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<00037f10:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<
00037f20:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h00037f20:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h
00037f30:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.00037f30:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.
00037f40:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte00037f40:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte
00037f50:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"00037f50:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"
Offset 15209, 129 lines modifiedOffset 15209, 129 lines modified
0003b680:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003b680:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b690:·6964·6d35·3339·3022·2074·6162·696e·6465··idm5390"·tabinde0003b690:·6964·6d35·3339·3022·2074·6162·696e·6465··idm5390"·tabinde
0003b6a0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b6a0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003b6b0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003b6b0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003b6c0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003b6c0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003b6d0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003b6d0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003b6e0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003b6e0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003b6f0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell0003b6f0:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui
 0003b700:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni
 0003b710:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0003b720:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003b730:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003b740:·7073·6522·2069·643d·2269·646d·3533·3930··pse"·id="idm5390
0003b700:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003b710:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b720:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b730:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5 
0003b740:·3339·3022·3e3c·7461·626c·6520·636c·6173··390"><table·clas 
0003b750:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b760:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b770:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b780:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b790:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b7a0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b7b0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b7c0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b7d0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b7e0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b7f0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003b800:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b810:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b820:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b830:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R0003b750:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[
 0003b760:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name·
 0003b770:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version
 0003b780:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></
0003b840:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003b850:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003b860:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003b870:·6d73·0a69·6620·5b20·2120·2d66·202f·2e64··ms.if·[·!·-f·/.d 
0003b880:·6f63·6b65·7265·6e76·205d·2026·616d·703b··ockerenv·]·&amp; 
0003b890:·2661·6d70·3b20·5b20·2120·2d66·202f·7275··&amp;·[·!·-f·/ru 
0003b8a0:·6e2f·2e63·6f6e·7461·696e·6572·656e·7620··n/.containerenv· 
0003b8b0:·5d3b·2074·6865·6e0a·0a7a·7970·7065·7220··];·then..zypper· 
0003b8c0:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide 
0003b8d0:·220a·0a65·6c73·650a·2020·2020·2667·743b··"..else.····&gt; 
0003b8e0:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem 
0003b8f0:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not· 
0003b900:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth 
0003b910:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi 
0003b920:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003b930:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b940:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b950:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b960:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b970:·743d·2223·6964·6d35·3339·3122·2074·6162··t="#idm5391"·tab 
0003b980:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b990:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b9a0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b9b0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b9c0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b9d0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A 
0003b9e0:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
0003b9f0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003ba00:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003ba10:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003ba20:·643d·2269·646d·3533·3931·223e·3c74·6162··d="idm5391"><tab 
0003ba30:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003ba40:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003ba50:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003ba60:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003ba70:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003ba80:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003ba90:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003baa0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003bab0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003bac0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003bad0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003bae0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003baf0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003bb00:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003bb10:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003bb20:·6f64·653e·2d20·6e61·6d65·3a20·456e·7375··ode>-·name:·Ensu 
0003bb30:·7265·2061·6964·6520·6973·2069·6e73·7461··re·aide·is·insta 
0003bb40:·6c6c·6564·0a20·2070·6163·6b61·6765·3a0a··lled.··package:. 
0003bb50:·2020·2020·6e61·6d65·3a20·6169·6465·0a20······name:·aide.· 
0003bb60:·2020·2073·7461·7465·3a20·7072·6573·656e·····state:·presen 
0003bb70:·740a·2020·7768·656e·3a20·616e·7369·626c··t.··when:·ansibl 
0003bb80:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization 
0003bb90:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d 
0003bba0:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·" 
0003bbb0:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman 
0003bbc0:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"]. 
0003bbd0:·2020·7461·6773·3a0a·2020·2d20·4343·452d····tags:.··-·CCE- 
0003bbe0:·3833·3036·372d·390a·2020·2d20·434a·4953··83067-9.··-·CJIS 
0003bbf0:·2d35·2e31·302e·312e·330a·2020·2d20·4449··-5.10.1.3.··-·DI 
0003bc00:·5341·2d53·5449·472d·534c·4553·2d31·322d··SA-STIG-SLES-12- 
0003bc10:·3031·3034·3939·0a20·202d·204e·4953·542d··010499.··-·NIST- 
0003bc20:·3830·302d·3533·2d43·4d2d·3628·6129·0a20··800-53-CM-6(a).· 
0003bc30:·202d·2050·4349·2d44·5353·2d52·6571·2d31···-·PCI-DSS-Req-1 
0003bc40:·312e·350a·2020·2d20·5043·492d·4453·5376··1.5.··-·PCI-DSSv 
0003bc50:·342d·3131·2e35·2e32·0a20·202d·2065·6e61··4-11.5.2.··-·ena 
0003bc60:·626c·655f·7374·7261·7465·6779·0a20·202d··ble_strategy.··- 
0003bc70:·206c·6f77·5f63·6f6d·706c·6578·6974·790a···low_complexity. 
0003bc80:·2020·2d20·6c6f·775f·6469·7372·7570·7469····-·low_disrupti 
0003bc90:·6f6e·0a20·202d·206d·6564·6975·6d5f·7365··on.··-·medium_se 
0003bca0:·7665·7269·7479·0a20·202d·206e·6f5f·7265··verity.··-·no_re 
0003bcb0:·626f·6f74·5f6e·6565·6465·640a·2020·2d20··boot_needed.··-· 
0003bcc0:·7061·636b·6167·655f·6169·6465·5f69·6e73··package_aide_ins 
0003bcd0:·7461·6c6c·6564·0a3c·2f63·6f64·653e·3c2f··talled.</code></ 
0003bce0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla0003b790:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
Max diff block lines reached; 18852658/18870238 bytes (99.91%) of diff not shown.
1.73 MB
html2text {}
    
Offset 42, 15 lines modifiedOffset 42, 15 lines modified
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·SUSE·Linux·Enterprise·12·Benchmark·for·Level·2·-·Server42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·SUSE·Linux·Enterprise·12·Benchmark·for·Level·2·-·Server
43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis
44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
45 ····*·cpe:/o:suse:linux_enterprise_desktop:1245 ····*·cpe:/o:suse:linux_enterprise_desktop:12
46 ····*·cpe:/o:suse:linux_enterprise_server:1246 ····*·cpe:/o:suse:linux_enterprise_server:12
47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
48 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8448 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
54 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r54 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
55 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n55 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
56 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g56 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 140, 27 lines modifiedOffset 140, 19 lines modified
140 include·install_aide140 include·install_aide
  
141 class·install_aide·{141 class·install_aide·{
142 ··package·{·'aide':142 ··package·{·'aide':
143 ····ensure·=>·'installed',143 ····ensure·=>·'installed',
144 ··}144 ··}
145 }145 }
 146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
147 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
148 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
149 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
150 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
151 #·Remediation·is·applicable·only·in·certain·platforms 
152 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
153 zypper·install·-y·"aide" 
  
154 else 
155 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
156 fi147 [[packages]]
 148 name·=·"aide"
 149 version·=·"*"
157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
158 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low151 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
159 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low152 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
160 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false153 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
161 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable154 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
162 -·name:·Ensure·aide·is·installed155 -·name:·Ensure·aide·is·installed
163 ··package:156 ··package:
Offset 176, 19 lines modifiedOffset 168, 27 lines modified
176 ··-·PCI-DSSv4-11.5.2168 ··-·PCI-DSSv4-11.5.2
177 ··-·enable_strategy169 ··-·enable_strategy
178 ··-·low_complexity170 ··-·low_complexity
179 ··-·low_disruption171 ··-·low_disruption
180 ··-·medium_severity172 ··-·medium_severity
181 ··-·no_reboot_needed173 ··-·no_reboot_needed
182 ··-·package_aide_installed174 ··-·package_aide_installed
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 176 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 177 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 178 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 179 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 180 #·Remediation·is·applicable·only·in·certain·platforms
 181 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
184 [[packages]] 
185 name·=·"aide" 
186 version·=·"*"182 zypper·install·-y·"aide"
  
 183 else
 184 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 185 fi
187 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*186 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
188 Run·the·following·command·to·generate·a·new·database:187 Run·the·following·command·to·generate·a·new·database:
189 $·sudo·/usr/bin/aide·--init188 $·sudo·/usr/bin/aide·--init
190 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the189 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the
191 configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these·files),·in·a·secure190 configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these·files),·in·a·secure
192 location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-191 location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-
193 generated·database·can·be·installed·as·follows:192 generated·database·can·be·installed·as·follows:
Offset 215, 29 lines modifiedOffset 215, 14 lines modified
215 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5215 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
216 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199216 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
217 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499217 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499
218 ·············_\x8c_\x8i_\x8s············1.4.1218 ·············_\x8c_\x8i_\x8s············1.4.1
219 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79219 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
220 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2220 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
221 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r880937_rule221 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r880937_rule
222 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
223 #·Remediation·is·applicable·only·in·certain·platforms 
224 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
225 zypper·-q·--no-remote·ref 
  
  
226 zypper·install·-y·"aide" 
  
227 /usr/bin/aide·--init 
228 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db 
  
229 else 
230 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
231 fi 
232 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8222 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
233 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low223 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
234 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low224 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
235 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false225 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
236 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict226 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
237 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated227 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated
238 ··ansible.builtin.command:·zypper·-q·--no-remote·ref228 ··ansible.builtin.command:·zypper·-q·--no-remote·ref
Offset 333, 14 lines modifiedOffset 318, 29 lines modified
333 ··-·PCI-DSSv4-11.5.2318 ··-·PCI-DSSv4-11.5.2
334 ··-·aide_build_database319 ··-·aide_build_database
335 ··-·low_complexity320 ··-·low_complexity
336 ··-·low_disruption321 ··-·low_disruption
337 ··-·medium_severity322 ··-·medium_severity
338 ··-·no_reboot_needed323 ··-·no_reboot_needed
339 ··-·restrict_strategy324 ··-·restrict_strategy
 325 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 326 #·Remediation·is·applicable·only·in·certain·platforms
 327 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 328 zypper·-q·--no-remote·ref
  
  
 329 zypper·install·-y·"aide"
  
 330 /usr/bin/aide·--init
 331 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db
  
 332 else
Max diff block lines reached; 1812000/1817447 bytes (99.70%) of diff not shown.
8.44 MB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-cis_server_l1.html
    
Offset 14312, 16 lines modifiedOffset 14312, 16 lines modified
00037e70:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><00037e70:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><
00037e80:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio00037e80:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio
00037e90:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.700037e90:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.7
00037ea0:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u00037ea0:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u
00037eb0:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr00037eb0:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr
00037ec0:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···00037ec0:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···
00037ed0:·2020·2020·2020·2020·2020·2020·2020·2020··················00037ed0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037ee0:·2028·6173·206f·6620·3230·3236·2d30·312d···(as·of·2026-01-00037ee0:·2028·6173·206f·6620·3230·3234·2d31·322d···(as·of·2024-12-
00037ef0:·3038·290a·2020·2020·2020·2020·2020·2020··08).············00037ef0:·3037·290a·2020·2020·2020·2020·2020·2020··07).············
00037f00:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></00037f00:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></
00037f10:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of00037f10:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of
00037f20:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o00037f20:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o
00037f30:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#00037f30:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#
00037f40:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro00037f40:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro
00037f50:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro00037f50:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro
00037f60:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste00037f60:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste
Offset 15187, 130 lines modifiedOffset 15187, 130 lines modified
0003b520:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b520:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b530:·3d22·2369·646d·3533·3930·2220·7461·6269··="#idm5390"·tabi0003b530:·3d22·2369·646d·3533·3930·2220·7461·6269··="#idm5390"·tabi
0003b540:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b540:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b550:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b550:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b560:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b560:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b570:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b570:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b580:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b580:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b590:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh0003b590:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
 0003b5a0:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
 0003b5b0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003b5c0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003b5d0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b5e0:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5
0003b5a0:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</ 
0003b5b0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003b5c0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003b5d0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003b5e0:·646d·3533·3930·223e·3c74·6162·6c65·2063··dm5390"><table·c 
0003b5f0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003b600:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003b610:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003b620:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003b630:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003b640:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b650:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003b660:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003b670:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b680:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003b690:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0003b6a0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003b6b0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003b6c0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003b6d0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003b5f0:·3339·3022·3e3c·7072·653e·3c63·6f64·653e··390"><pre><code>
 0003b600:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 0003b610:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers
 0003b620:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code
0003b6e0:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is 
0003b6f0:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only 
0003b700:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat 
0003b710:·666f·726d·730a·6966·205b·2021·202d·6620··forms.if·[·!·-f· 
0003b720:·2f2e·646f·636b·6572·656e·7620·5d20·2661··/.dockerenv·]·&a 
0003b730:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f· 
0003b740:·2f72·756e·2f2e·636f·6e74·6169·6e65·7265··/run/.containere 
0003b750:·6e76·205d·3b20·7468·656e·0a0a·7a79·7070··nv·];·then..zypp 
0003b760:·6572·2069·6e73·7461·6c6c·202d·7920·2261··er·install·-y·"a 
0003b770:·6964·6522·0a0a·656c·7365·0a20·2020·2026··ide"..else.····& 
0003b780:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·' 
0003b790:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n 
0003b7a0:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n 
0003b7b0:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done' 
0003b7c0:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre 
0003b7d0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003b7e0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003b7f0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003b800:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003b810:·7267·6574·3d22·2369·646d·3533·3931·2220··rget="#idm5391"· 
0003b820:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003b830:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003b840:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003b850:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003b860:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003b870:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003b880:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe 
0003b890:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003b8a0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003b8b0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003b8c0:·2220·6964·3d22·6964·6d35·3339·3122·3e3c··"·id="idm5391">< 
0003b8d0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003b8e0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003b8f0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003b900:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003b910:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003b920:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003b930:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b940:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003b950:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b960:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003b970:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003b980:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b990:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003b9a0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003b9b0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003b9c0:·3e3c·636f·6465·3e2d·206e·616d·653a·2045··><code>-·name:·E 
0003b9d0:·6e73·7572·6520·6169·6465·2069·7320·696e··nsure·aide·is·in 
0003b9e0:·7374·616c·6c65·640a·2020·7061·636b·6167··stalled.··packag 
0003b9f0:·653a·0a20·2020·206e·616d·653a·2061·6964··e:.····name:·aid 
0003ba00:·650a·2020·2020·7374·6174·653a·2070·7265··e.····state:·pre 
0003ba10:·7365·6e74·0a20·2077·6865·6e3a·2061·6e73··sent.··when:·ans 
0003ba20:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat 
0003ba30:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in· 
0003ba40:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc" 
0003ba50:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod 
0003ba60:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container 
0003ba70:·225d·0a20·2074·6167·733a·0a20·202d·2043··"].··tags:.··-·C 
0003ba80:·4345·2d38·3330·3637·2d39·0a20·202d·2043··CE-83067-9.··-·C 
0003ba90:·4a49·532d·352e·3130·2e31·2e33·0a20·202d··JIS-5.10.1.3.··- 
0003baa0:·2044·4953·412d·5354·4947·2d53·4c45·532d···DISA-STIG-SLES- 
0003bab0:·3132·2d30·3130·3439·390a·2020·2d20·4e49··12-010499.··-·NI 
0003bac0:·5354·2d38·3030·2d35·332d·434d·2d36·2861··ST-800-53-CM-6(a 
0003bad0:·290a·2020·2d20·5043·492d·4453·532d·5265··).··-·PCI-DSS-Re 
0003bae0:·712d·3131·2e35·0a20·202d·2050·4349·2d44··q-11.5.··-·PCI-D 
0003baf0:·5353·7634·2d31·312e·352e·320a·2020·2d20··SSv4-11.5.2.··-· 
0003bb00:·656e·6162·6c65·5f73·7472·6174·6567·790a··enable_strategy. 
0003bb10:·2020·2d20·6c6f·775f·636f·6d70·6c65·7869····-·low_complexi 
0003bb20:·7479·0a20·202d·206c·6f77·5f64·6973·7275··ty.··-·low_disru 
0003bb30:·7074·696f·6e0a·2020·2d20·6d65·6469·756d··ption.··-·medium 
0003bb40:·5f73·6576·6572·6974·790a·2020·2d20·6e6f··_severity.··-·no 
0003bb50:·5f72·6562·6f6f·745f·6e65·6564·6564·0a20··_reboot_needed.· 
0003bb60:·202d·2070·6163·6b61·6765·5f61·6964·655f···-·package_aide_ 
0003bb70:·696e·7374·616c·6c65·640a·3c2f·636f·6465··installed.</code 
Max diff block lines reached; 7847915/7865771 bytes (99.77%) of diff not shown.
960 KB
html2text {}
    
Offset 42, 15 lines modifiedOffset 42, 15 lines modified
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·SUSE·Linux·Enterprise·12·Benchmark·for·Level·1·-·Server42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·SUSE·Linux·Enterprise·12·Benchmark·for·Level·1·-·Server
43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_server_l143 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_server_l1
44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
45 ····*·cpe:/o:suse:linux_enterprise_desktop:1245 ····*·cpe:/o:suse:linux_enterprise_desktop:12
46 ····*·cpe:/o:suse:linux_enterprise_server:1246 ····*·cpe:/o:suse:linux_enterprise_server:12
47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
48 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8448 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
54 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r54 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
55 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n55 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
56 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g56 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 137, 27 lines modifiedOffset 137, 19 lines modified
137 include·install_aide137 include·install_aide
  
138 class·install_aide·{138 class·install_aide·{
139 ··package·{·'aide':139 ··package·{·'aide':
140 ····ensure·=>·'installed',140 ····ensure·=>·'installed',
141 ··}141 ··}
142 }142 }
 143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
144 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
145 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
146 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
147 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
148 #·Remediation·is·applicable·only·in·certain·platforms 
149 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
150 zypper·install·-y·"aide" 
  
151 else 
152 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
153 fi144 [[packages]]
 145 name·=·"aide"
 146 version·=·"*"
154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8147 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low148 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low149 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false150 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable151 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
159 -·name:·Ensure·aide·is·installed152 -·name:·Ensure·aide·is·installed
160 ··package:153 ··package:
Offset 173, 19 lines modifiedOffset 165, 27 lines modified
173 ··-·PCI-DSSv4-11.5.2165 ··-·PCI-DSSv4-11.5.2
174 ··-·enable_strategy166 ··-·enable_strategy
175 ··-·low_complexity167 ··-·low_complexity
176 ··-·low_disruption168 ··-·low_disruption
177 ··-·medium_severity169 ··-·medium_severity
178 ··-·no_reboot_needed170 ··-·no_reboot_needed
179 ··-·package_aide_installed171 ··-·package_aide_installed
180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 177 #·Remediation·is·applicable·only·in·certain·platforms
 178 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
181 [[packages]] 
182 name·=·"aide" 
183 version·=·"*"179 zypper·install·-y·"aide"
  
 180 else
 181 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 182 fi
184 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*183 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
185 Run·the·following·command·to·generate·a·new·database:184 Run·the·following·command·to·generate·a·new·database:
186 $·sudo·/usr/bin/aide·--init185 $·sudo·/usr/bin/aide·--init
187 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the186 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the
188 configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these·files),·in·a·secure187 configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these·files),·in·a·secure
189 location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-188 location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-
190 generated·database·can·be·installed·as·follows:189 generated·database·can·be·installed·as·follows:
Offset 212, 29 lines modifiedOffset 212, 14 lines modified
212 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5212 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
213 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199213 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
214 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499214 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499
215 ·············_\x8c_\x8i_\x8s············1.4.1215 ·············_\x8c_\x8i_\x8s············1.4.1
216 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79216 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
217 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2217 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
218 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r880937_rule218 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r880937_rule
219 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
220 #·Remediation·is·applicable·only·in·certain·platforms 
221 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
222 zypper·-q·--no-remote·ref 
  
  
223 zypper·install·-y·"aide" 
  
224 /usr/bin/aide·--init 
225 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db 
  
226 else 
227 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
228 fi 
229 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8219 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
230 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low220 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
231 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low221 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
232 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false222 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
233 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict223 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
234 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated224 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated
235 ··ansible.builtin.command:·zypper·-q·--no-remote·ref225 ··ansible.builtin.command:·zypper·-q·--no-remote·ref
Offset 330, 14 lines modifiedOffset 315, 29 lines modified
330 ··-·PCI-DSSv4-11.5.2315 ··-·PCI-DSSv4-11.5.2
331 ··-·aide_build_database316 ··-·aide_build_database
332 ··-·low_complexity317 ··-·low_complexity
333 ··-·low_disruption318 ··-·low_disruption
334 ··-·medium_severity319 ··-·medium_severity
335 ··-·no_reboot_needed320 ··-·no_reboot_needed
336 ··-·restrict_strategy321 ··-·restrict_strategy
 322 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 323 #·Remediation·is·applicable·only·in·certain·platforms
 324 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 325 zypper·-q·--no-remote·ref
  
  
 326 zypper·install·-y·"aide"
  
 327 /usr/bin/aide·--init
 328 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db
  
 329 else
Max diff block lines reached; 977489/982946 bytes (99.44%) of diff not shown.
8.2 MB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-cis_workstation_l1.html
    
Offset 14313, 16 lines modifiedOffset 14313, 16 lines modified
00037e80:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00037e80:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00037e90:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00037e90:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00037ea0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000037ea0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00037eb0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></00037eb0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
00037ec0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00037ec0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00037ed0:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00037ed0:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00037ee0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037ee0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037ef0:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600037ef0:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
00037f00:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········00037f00:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00037f10:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00037f10:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00037f20:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00037f20:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00037f30:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00037f30:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00037f40:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00037f40:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00037f50:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00037f50:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00037f60:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00037f60:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00037f70:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00037f70:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
Offset 15174, 129 lines modifiedOffset 15174, 129 lines modified
0003b450:·6574·3d22·2369·646d·3533·3930·2220·7461··et="#idm5390"·ta0003b450:·6574·3d22·2369·646d·3533·3930·2220·7461··et="#idm5390"·ta
0003b460:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003b460:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003b470:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003b470:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003b480:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003b480:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003b490:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003b490:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003b4a0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003b4a0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003b4b0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003b4b0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003b4c0:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin
 0003b4d0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 0003b4e0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003b4f0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003b500:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003b510:·6d35·3339·3022·3e3c·7072·653e·3c63·6f64··m5390"><pre><cod
 0003b520:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]].
 0003b530:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve
 0003b540:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co
0003b4c0:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
0003b4d0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b4e0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b4f0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b500:·2269·646d·3533·3930·223e·3c74·6162·6c65··"idm5390"><table 
0003b510:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003b520:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003b530:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003b540:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003b550:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003b560:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b570:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003b580:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003b590:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b5a0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003b5b0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003b5c0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003b5d0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0003b5e0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0003b5f0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003b600:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation· 
0003b610:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on 
0003b620:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl 
0003b630:·6174·666f·726d·730a·6966·205b·2021·202d··atforms.if·[·!·- 
0003b640:·6620·2f2e·646f·636b·6572·656e·7620·5d20··f·/.dockerenv·]· 
0003b650:·2661·6d70·3b26·616d·703b·205b·2021·202d··&amp;&amp;·[·!·- 
0003b660:·6620·2f72·756e·2f2e·636f·6e74·6169·6e65··f·/run/.containe 
0003b670:·7265·6e76·205d·3b20·7468·656e·0a0a·7a79··renv·];·then..zy 
0003b680:·7070·6572·2069·6e73·7461·6c6c·202d·7920··pper·install·-y· 
0003b690:·2261·6964·6522·0a0a·656c·7365·0a20·2020··"aide"..else.··· 
0003b6a0:·2026·6774·3b26·616d·703b·3220·6563·686f···&gt;&amp;2·echo 
0003b6b0:·2027·5265·6d65·6469·6174·696f·6e20·6973···'Remediation·is 
0003b6c0:·206e·6f74·2061·7070·6c69·6361·626c·652c···not·applicable, 
0003b6d0:·206e·6f74·6869·6e67·2077·6173·2064·6f6e···nothing·was·don 
0003b6e0:·6527·0a66·690a·3c2f·636f·6465·3e3c·2f70··e'.fi.</code></p 
0003b6f0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003b700:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003b710:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003b720:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003b730:·7461·7267·6574·3d22·2369·646d·3533·3931··target="#idm5391 
0003b740:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003b750:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003b760:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003b770:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003b780:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003b790:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003b7a0:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip 
0003b7b0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003b7c0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b7d0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b7e0:·7365·2220·6964·3d22·6964·6d35·3339·3122··se"·id="idm5391" 
0003b7f0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003b800:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003b810:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003b820:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003b830:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003b840:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003b850:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b860:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003b870:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b880:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003b890:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003b8a0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003b8b0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003b8c0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003b8d0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003b8e0:·7265·3e3c·636f·6465·3e2d·206e·616d·653a··re><code>-·name: 
0003b8f0:·2045·6e73·7572·6520·6169·6465·2069·7320···Ensure·aide·is· 
0003b900:·696e·7374·616c·6c65·640a·2020·7061·636b··installed.··pack 
0003b910:·6167·653a·0a20·2020·206e·616d·653a·2061··age:.····name:·a 
0003b920:·6964·650a·2020·2020·7374·6174·653a·2070··ide.····state:·p 
0003b930:·7265·7365·6e74·0a20·2077·6865·6e3a·2061··resent.··when:·a 
0003b940:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz 
0003b950:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i 
0003b960:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx 
0003b970:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p 
0003b980:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain 
0003b990:·6572·225d·0a20·2074·6167·733a·0a20·202d··er"].··tags:.··- 
0003b9a0:·2043·4345·2d38·3330·3637·2d39·0a20·202d···CCE-83067-9.··- 
0003b9b0:·2043·4a49·532d·352e·3130·2e31·2e33·0a20···CJIS-5.10.1.3.· 
0003b9c0:·202d·2044·4953·412d·5354·4947·2d53·4c45···-·DISA-STIG-SLE 
0003b9d0:·532d·3132·2d30·3130·3439·390a·2020·2d20··S-12-010499.··-· 
0003b9e0:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6 
0003b9f0:·2861·290a·2020·2d20·5043·492d·4453·532d··(a).··-·PCI-DSS- 
0003ba00:·5265·712d·3131·2e35·0a20·202d·2050·4349··Req-11.5.··-·PCI 
0003ba10:·2d44·5353·7634·2d31·312e·352e·320a·2020··-DSSv4-11.5.2.·· 
0003ba20:·2d20·656e·6162·6c65·5f73·7472·6174·6567··-·enable_strateg 
0003ba30:·790a·2020·2d20·6c6f·775f·636f·6d70·6c65··y.··-·low_comple 
0003ba40:·7869·7479·0a20·202d·206c·6f77·5f64·6973··xity.··-·low_dis 
0003ba50:·7275·7074·696f·6e0a·2020·2d20·6d65·6469··ruption.··-·medi 
0003ba60:·756d·5f73·6576·6572·6974·790a·2020·2d20··um_severity.··-· 
0003ba70:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed 
0003ba80:·0a20·202d·2070·6163·6b61·6765·5f61·6964··.··-·package_aid 
0003ba90:·655f·696e·7374·616c·6c65·640a·3c2f·636f··e_installed.</co 
Max diff block lines reached; 7622015/7639733 bytes (99.77%) of diff not shown.
936 KB
html2text {}
    
Offset 42, 15 lines modifiedOffset 42, 15 lines modified
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·SUSE·Linux·Enterprise·12·Benchmark·for·Level·1·-·Workstation42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·SUSE·Linux·Enterprise·12·Benchmark·for·Level·1·-·Workstation
43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_workstation_l143 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_workstation_l1
44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
45 ····*·cpe:/o:suse:linux_enterprise_desktop:1245 ····*·cpe:/o:suse:linux_enterprise_desktop:12
46 ····*·cpe:/o:suse:linux_enterprise_server:1246 ····*·cpe:/o:suse:linux_enterprise_server:12
47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
48 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8448 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
54 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r54 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
55 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n55 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
56 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g56 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 134, 27 lines modifiedOffset 134, 19 lines modified
134 include·install_aide134 include·install_aide
  
135 class·install_aide·{135 class·install_aide·{
136 ··package·{·'aide':136 ··package·{·'aide':
137 ····ensure·=>·'installed',137 ····ensure·=>·'installed',
138 ··}138 ··}
139 }139 }
 140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
145 #·Remediation·is·applicable·only·in·certain·platforms 
146 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
147 zypper·install·-y·"aide" 
  
148 else 
149 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
150 fi141 [[packages]]
 142 name·=·"aide"
 143 version·=·"*"
151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low145 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low146 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false147 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable148 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
156 -·name:·Ensure·aide·is·installed149 -·name:·Ensure·aide·is·installed
157 ··package:150 ··package:
Offset 170, 19 lines modifiedOffset 162, 27 lines modified
170 ··-·PCI-DSSv4-11.5.2162 ··-·PCI-DSSv4-11.5.2
171 ··-·enable_strategy163 ··-·enable_strategy
172 ··-·low_complexity164 ··-·low_complexity
173 ··-·low_disruption165 ··-·low_disruption
174 ··-·medium_severity166 ··-·medium_severity
175 ··-·no_reboot_needed167 ··-·no_reboot_needed
176 ··-·package_aide_installed168 ··-·package_aide_installed
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 174 #·Remediation·is·applicable·only·in·certain·platforms
 175 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
178 [[packages]] 
179 name·=·"aide" 
180 version·=·"*"176 zypper·install·-y·"aide"
  
 177 else
 178 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 179 fi
181 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*180 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
182 Run·the·following·command·to·generate·a·new·database:181 Run·the·following·command·to·generate·a·new·database:
183 $·sudo·/usr/bin/aide·--init182 $·sudo·/usr/bin/aide·--init
184 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the183 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the
185 configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these·files),·in·a·secure184 configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these·files),·in·a·secure
186 location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-185 location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-
187 generated·database·can·be·installed·as·follows:186 generated·database·can·be·installed·as·follows:
Offset 209, 29 lines modifiedOffset 209, 14 lines modified
209 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5209 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
210 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199210 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
211 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499211 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499
212 ·············_\x8c_\x8i_\x8s············1.4.1212 ·············_\x8c_\x8i_\x8s············1.4.1
213 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79213 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
214 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2214 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
215 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r880937_rule215 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r880937_rule
216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
217 #·Remediation·is·applicable·only·in·certain·platforms 
218 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
219 zypper·-q·--no-remote·ref 
  
  
220 zypper·install·-y·"aide" 
  
221 /usr/bin/aide·--init 
222 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db 
  
223 else 
224 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
225 fi 
226 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
227 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low217 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
228 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low218 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
229 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false219 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
230 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict220 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
231 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated221 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated
232 ··ansible.builtin.command:·zypper·-q·--no-remote·ref222 ··ansible.builtin.command:·zypper·-q·--no-remote·ref
Offset 327, 14 lines modifiedOffset 312, 29 lines modified
327 ··-·PCI-DSSv4-11.5.2312 ··-·PCI-DSSv4-11.5.2
328 ··-·aide_build_database313 ··-·aide_build_database
329 ··-·low_complexity314 ··-·low_complexity
330 ··-·low_disruption315 ··-·low_disruption
331 ··-·medium_severity316 ··-·medium_severity
332 ··-·no_reboot_needed317 ··-·no_reboot_needed
333 ··-·restrict_strategy318 ··-·restrict_strategy
 319 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 320 #·Remediation·is·applicable·only·in·certain·platforms
 321 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 322 zypper·-q·--no-remote·ref
  
  
 323 zypper·install·-y·"aide"
  
 324 /usr/bin/aide·--init
 325 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db
  
 326 else
Max diff block lines reached; 953380/958847 bytes (99.43%) of diff not shown.
19.6 MB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-cis_workstation_l2.html
    
Offset 14313, 15 lines modifiedOffset 14313, 15 lines modified
00037e80:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00037e80:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00037e90:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00037e90:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00037ea0:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s00037ea0:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00037eb0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00037eb0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00037ec0:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00037ec0:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00037ed0:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00037ed0:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00037ee0:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00037ee0:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00037ef0:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).00037ef0:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
00037f00:·2020·2020·2020·2020·2020·2020·2020·2020··················00037f00:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037f10:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00037f10:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00037f20:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00037f20:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00037f30:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00037f30:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00037f40:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00037f40:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00037f50:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00037f50:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00037f60:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00037f60:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
Offset 15200, 130 lines modifiedOffset 15200, 130 lines modified
0003b5f0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b5f0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003b600:·2223·6964·6d35·3339·3022·2074·6162·696e··"#idm5390"·tabin0003b600:·2223·6964·6d35·3339·3022·2074·6162·696e··"#idm5390"·tabin
0003b610:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b610:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b620:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b620:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b630:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b630:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b640:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b640:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b650:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b650:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b660:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She0003b660:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB
 0003b670:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s
 0003b680:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0003b690:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003b6a0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003b6b0:·6c61·7073·6522·2069·643d·2269·646d·3533··lapse"·id="idm53
0003b670:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
0003b680:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b690:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b6a0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b6b0:·6d35·3339·3022·3e3c·7461·626c·6520·636c··m5390"><table·cl 
0003b6c0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003b6d0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003b6e0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0003b6f0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0003b700:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0003b710:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003b720:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003b730:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
0003b740:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b750:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
0003b760:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
0003b770:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
0003b780:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
0003b790:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
0003b7a0:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#0003b6c0:·3930·223e·3c70·7265·3e3c·636f·6465·3e0a··90"><pre><code>.
 0003b6d0:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam
 0003b6e0:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi
 0003b6f0:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code>
0003b7b0:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is· 
0003b7c0:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only· 
0003b7d0:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf 
0003b7e0:·6f72·6d73·0a69·6620·5b20·2120·2d66·202f··orms.if·[·!·-f·/ 
0003b7f0:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am 
0003b800:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/ 
0003b810:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren 
0003b820:·7620·5d3b·2074·6865·6e0a·0a7a·7970·7065··v·];·then..zyppe 
0003b830:·7220·696e·7374·616c·6c20·2d79·2022·6169··r·install·-y·"ai 
0003b840:·6465·220a·0a65·6c73·650a·2020·2020·2667··de"..else.····&g 
0003b850:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R 
0003b860:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no 
0003b870:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no 
0003b880:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'. 
0003b890:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre> 
0003b8a0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003b8b0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003b8c0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003b8d0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003b8e0:·6765·743d·2223·6964·6d35·3339·3122·2074··get="#idm5391"·t 
0003b8f0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003b900:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003b910:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003b920:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003b930:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003b940:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003b950:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet 
0003b960:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003b970:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003b980:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003b990:·2069·643d·2269·646d·3533·3931·223e·3c74···id="idm5391"><t 
0003b9a0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003b9b0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003b9c0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003b9d0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003b9e0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003b9f0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003ba00:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003ba10:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003ba20:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003ba30:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003ba40:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003ba50:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003ba60:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0003ba70:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003ba80:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003ba90:·3c63·6f64·653e·2d20·6e61·6d65·3a20·456e··<code>-·name:·En 
0003baa0:·7375·7265·2061·6964·6520·6973·2069·6e73··sure·aide·is·ins 
0003bab0:·7461·6c6c·6564·0a20·2070·6163·6b61·6765··talled.··package 
0003bac0:·3a0a·2020·2020·6e61·6d65·3a20·6169·6465··:.····name:·aide 
0003bad0:·0a20·2020·2073·7461·7465·3a20·7072·6573··.····state:·pres 
0003bae0:·656e·740a·2020·7768·656e·3a20·616e·7369··ent.··when:·ansi 
0003baf0:·626c·655f·7669·7274·7561·6c69·7a61·7469··ble_virtualizati 
0003bb00:·6f6e·5f74·7970·6520·6e6f·7420·696e·205b··on_type·not·in·[ 
0003bb10:·2264·6f63·6b65·7222·2c20·226c·7863·222c··"docker",·"lxc", 
0003bb20:·2022·6f70·656e·767a·222c·2022·706f·646d···"openvz",·"podm 
0003bb30:·616e·222c·2022·636f·6e74·6169·6e65·7222··an",·"container" 
0003bb40:·5d0a·2020·7461·6773·3a0a·2020·2d20·4343··].··tags:.··-·CC 
0003bb50:·452d·3833·3036·372d·390a·2020·2d20·434a··E-83067-9.··-·CJ 
0003bb60:·4953·2d35·2e31·302e·312e·330a·2020·2d20··IS-5.10.1.3.··-· 
0003bb70:·4449·5341·2d53·5449·472d·534c·4553·2d31··DISA-STIG-SLES-1 
0003bb80:·322d·3031·3034·3939·0a20·202d·204e·4953··2-010499.··-·NIS 
0003bb90:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a) 
0003bba0:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req 
0003bbb0:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS 
0003bbc0:·5376·342d·3131·2e35·2e32·0a20·202d·2065··Sv4-11.5.2.··-·e 
0003bbd0:·6e61·626c·655f·7374·7261·7465·6779·0a20··nable_strategy.· 
0003bbe0:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit 
0003bbf0:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup 
0003bc00:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_ 
0003bc10:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_ 
0003bc20:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.·· 
0003bc30:·2d20·7061·636b·6167·655f·6169·6465·5f69··-·package_aide_i 
0003bc40:·6e73·7461·6c6c·6564·0a3c·2f63·6f64·653e··nstalled.</code> 
0003bc50:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c0003b700:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
Max diff block lines reached; 18778296/18796014 bytes (99.91%) of diff not shown.
1.72 MB
html2text {}
    
Offset 42, 15 lines modifiedOffset 42, 15 lines modified
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·SUSE·Linux·Enterprise·12·Benchmark·Level·2·-·Workstation42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·SUSE·Linux·Enterprise·12·Benchmark·Level·2·-·Workstation
43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_workstation_l243 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_workstation_l2
44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
45 ····*·cpe:/o:suse:linux_enterprise_desktop:1245 ····*·cpe:/o:suse:linux_enterprise_desktop:12
46 ····*·cpe:/o:suse:linux_enterprise_server:1246 ····*·cpe:/o:suse:linux_enterprise_server:12
47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
48 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8448 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
54 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r54 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
55 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n55 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
56 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g56 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 138, 27 lines modifiedOffset 138, 19 lines modified
138 include·install_aide138 include·install_aide
  
139 class·install_aide·{139 class·install_aide·{
140 ··package·{·'aide':140 ··package·{·'aide':
141 ····ensure·=>·'installed',141 ····ensure·=>·'installed',
142 ··}142 ··}
143 }143 }
 144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
145 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
146 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
147 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
148 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
149 #·Remediation·is·applicable·only·in·certain·platforms 
150 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
151 zypper·install·-y·"aide" 
  
152 else 
153 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
154 fi145 [[packages]]
 146 name·=·"aide"
 147 version·=·"*"
155 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
156 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low149 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
157 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low150 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
158 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false151 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
159 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable152 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
160 -·name:·Ensure·aide·is·installed153 -·name:·Ensure·aide·is·installed
161 ··package:154 ··package:
Offset 174, 19 lines modifiedOffset 166, 27 lines modified
174 ··-·PCI-DSSv4-11.5.2166 ··-·PCI-DSSv4-11.5.2
175 ··-·enable_strategy167 ··-·enable_strategy
176 ··-·low_complexity168 ··-·low_complexity
177 ··-·low_disruption169 ··-·low_disruption
178 ··-·medium_severity170 ··-·medium_severity
179 ··-·no_reboot_needed171 ··-·no_reboot_needed
180 ··-·package_aide_installed172 ··-·package_aide_installed
181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 178 #·Remediation·is·applicable·only·in·certain·platforms
 179 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
182 [[packages]] 
183 name·=·"aide" 
184 version·=·"*"180 zypper·install·-y·"aide"
  
 181 else
 182 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 183 fi
185 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*184 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
186 Run·the·following·command·to·generate·a·new·database:185 Run·the·following·command·to·generate·a·new·database:
187 $·sudo·/usr/bin/aide·--init186 $·sudo·/usr/bin/aide·--init
188 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the187 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the
189 configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these·files),·in·a·secure188 configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these·files),·in·a·secure
190 location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-189 location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-
191 generated·database·can·be·installed·as·follows:190 generated·database·can·be·installed·as·follows:
Offset 213, 29 lines modifiedOffset 213, 14 lines modified
213 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5213 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
214 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199214 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
215 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499215 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499
216 ·············_\x8c_\x8i_\x8s············1.4.1216 ·············_\x8c_\x8i_\x8s············1.4.1
217 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79217 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
218 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2218 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
219 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r880937_rule219 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r880937_rule
220 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
221 #·Remediation·is·applicable·only·in·certain·platforms 
222 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
223 zypper·-q·--no-remote·ref 
  
  
224 zypper·install·-y·"aide" 
  
225 /usr/bin/aide·--init 
226 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db 
  
227 else 
228 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
229 fi 
230 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8220 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
231 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low221 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
232 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low222 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
233 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false223 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
234 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict224 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
235 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated225 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated
236 ··ansible.builtin.command:·zypper·-q·--no-remote·ref226 ··ansible.builtin.command:·zypper·-q·--no-remote·ref
Offset 331, 14 lines modifiedOffset 316, 29 lines modified
331 ··-·PCI-DSSv4-11.5.2316 ··-·PCI-DSSv4-11.5.2
332 ··-·aide_build_database317 ··-·aide_build_database
333 ··-·low_complexity318 ··-·low_complexity
334 ··-·low_disruption319 ··-·low_disruption
335 ··-·medium_severity320 ··-·medium_severity
336 ··-·no_reboot_needed321 ··-·no_reboot_needed
337 ··-·restrict_strategy322 ··-·restrict_strategy
 323 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 324 #·Remediation·is·applicable·only·in·certain·platforms
 325 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 326 zypper·-q·--no-remote·ref
  
  
 327 zypper·install·-y·"aide"
  
 328 /usr/bin/aide·--init
 329 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db
  
 330 else
Max diff block lines reached; 1794880/1800343 bytes (99.70%) of diff not shown.
18.7 MB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-pci-dss-4.html
    
Offset 14297, 15 lines modifiedOffset 14297, 15 lines modified
00037d80:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00037d80:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00037d90:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00037d90:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00037da0:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s00037da0:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00037db0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00037db0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00037dc0:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00037dc0:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00037dd0:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00037dd0:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00037de0:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00037de0:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00037df0:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).00037df0:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
00037e00:·2020·2020·2020·2020·2020·2020·2020·2020··················00037e00:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037e10:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00037e10:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00037e20:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00037e20:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00037e30:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00037e30:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00037e40:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00037e40:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00037e50:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00037e50:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00037e60:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00037e60:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
Offset 15218, 306 lines modifiedOffset 15218, 306 lines modified
0003b710:·2d74·6172·6765·743d·2223·6964·6d35·3034··-target="#idm5040003b710:·2d74·6172·6765·743d·2223·6964·6d35·3034··-target="#idm504
0003b720:·3722·2074·6162·696e·6465·783d·2230·2220··7"·tabindex="0"·0003b720:·3722·2074·6162·696e·6465·783d·2230·2220··7"·tabindex="0"·
0003b730:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003b730:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003b740:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003b740:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003b750:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003b750:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003b760:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003b760:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003b770:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003b770:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003b780:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
0003b790:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003b7a0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003b7b0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003b7c0:·2220·6964·3d22·6964·6d35·3034·3722·3e3c··"·id="idm5047">< 
0003b7d0:·7072·653e·3c63·6f64·653e·0a23·2046·696e··pre><code>.#·Fin 
0003b7e0:·6420·7768·6963·6820·6669·6c65·7320·6861··d·which·files·ha 
0003b7f0:·7665·2069·6e63·6f72·7265·6374·2068·6173··ve·incorrect·has 
0003b800:·6820·286e·6f74·2069·6e20·2f65·7463·2c20··h·(not·in·/etc,· 
0003b810:·6265·6361·7573·6520·6f66·2074·6865·2073··because·of·the·s 
0003b820:·7973·7465·6d20·7265·6c61·7465·6420·636f··ystem·related·co 
0003b830:·6e66·6967·2066·696c·6573·2920·616e·6420··nfig·files)·and· 
0003b840:·7468·656e·2067·6574·2066·696c·6573·206e··then·get·files·n 
0003b850:·616d·6573·0a66·696c·6573·5f77·6974·685f··ames.files_with_ 
0003b860:·696e·636f·7272·6563·745f·6861·7368·3d22··incorrect_hash=" 
0003b870:·2428·7270·6d20·2d56·6120·2d2d·6e6f·636f··$(rpm·-Va·--noco 
0003b880:·6e66·6967·207c·2067·7265·7020·2d45·2027··nfig·|·grep·-E·' 
0003b890:·5e2e·2e35·2720·7c20·6177·6b20·277b·7072··^..5'·|·awk·'{pr 
0003b8a0:·696e·7420·244e·467d·2720·2922·0a0a·6966··int·$NF}'·)"..if 
0003b8b0:·205b·202d·6e20·2224·6669·6c65·735f·7769···[·-n·"$files_wi 
0003b8c0:·7468·5f69·6e63·6f72·7265·6374·5f68·6173··th_incorrect_has 
0003b8d0:·6822·205d·3b20·7468·656e·0a20·2020·2023··h"·];·then.····# 
0003b8e0:·2046·726f·6d20·6669·6c65·7320·6e61·6d65···From·files·name 
0003b8f0:·7320·6765·7420·7061·636b·6167·6520·6e61··s·get·package·na 
0003b900:·6d65·7320·616e·6420·6368·616e·6765·206e··mes·and·change·n 
0003b910:·6577·6c69·6e65·2074·6f20·7370·6163·652c··ewline·to·space, 
0003b920:·2062·6563·6175·7365·2072·706d·2077·7269···because·rpm·wri 
0003b930:·7465·7320·6561·6368·2070·6163·6b61·6765··tes·each·package 
0003b940:·2074·6f20·6e65·7720·6c69·6e65·0a20·2020···to·new·line.··· 
0003b950:·2070·6163·6b61·6765·735f·746f·5f72·6569···packages_to_rei 
0003b960:·6e73·7461·6c6c·3d22·2428·7270·6d20·2d71··nstall="$(rpm·-q 
0003b970:·6620·2466·696c·6573·5f77·6974·685f·696e··f·$files_with_in 
0003b980:·636f·7272·6563·745f·6861·7368·207c·2074··correct_hash·|·t 
0003b990:·7220·275c·6e27·2027·2027·2922·0a0a·2020··r·'\n'·'·')"..·· 
0003b9a0:·2020·0a20·2020·207a·7970·7065·7220·696e····.····zypper·in 
0003b9b0:·7374·616c·6c20·2d66·202d·7920·2470·6163··stall·-f·-y·$pac 
0003b9c0:·6b61·6765·735f·746f·5f72·6569·6e73·7461··kages_to_reinsta 
0003b9d0:·6c6c·0a20·2020·200a·6669·0a3c·2f63·6f64··ll.····.fi.</cod 
0003b9e0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003b9f0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003ba00:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003ba10:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003ba20:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003ba30:·6d35·3034·3822·2074·6162·696e·6465·783d··m5048"·tabindex= 
0003ba40:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003ba50:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003ba60:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003ba70:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003ba80:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003ba90:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible0003b780:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni
0003baa0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003b790:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003bab0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003b7a0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003bac0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003b7b0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003bad0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003b7c0:·7073·6522·2069·643d·2269·646d·3530·3437··pse"·id="idm5047
0003bae0:·3530·3438·223e·3c74·6162·6c65·2063·6c61··5048"><table·cla0003b7d0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003baf0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003b7e0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003bb00:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003b7f0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003bb10:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003b800:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003bb20:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003b810:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003bb30:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003b820:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003bb40:·3c74·643e·6869·6768·3c2f·7464·3e3c·2f74··<td>high</td></t 
0003bb50:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003bb60:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6d65··tion:</th><td>me 
0003bb70:·6469·756d·3c2f·7464·3e3c·2f74·723e·3c74··dium</td></tr><t0003b830:·6869·6768·3c2f·7464·3e3c·2f74·723e·3c74··high</td></tr><t
 0003b840:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003b850:·3a3c·2f74·683e·3c74·643e·6d65·6469·756d··:</th><td>medium
 0003b860:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003bb80:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t0003b870:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
0003bb90:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>0003b880:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
0003bba0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003b890:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
0003bbb0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e72··ategy:</th><td>r0003b8a0:·793a·3c2f·7468·3e3c·7464·3e72·6573·7472··y:</th><td>restr
0003bbc0:·6573·7472·6963·743c·2f74·643e·3c2f·7472··estrict</td></tr0003b8b0:·6963·743c·2f74·643e·3c2f·7472·3e3c·2f74··ict</td></tr></t
0003bbd0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003b8c0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003b8d0:·2d20·6e61·6d65·3a20·2753·6574·2066·6163··-·name:·'Set·fac
 0003b8e0:·743a·2050·6163·6b61·6765·206d·616e·6167··t:·Package·manag
 0003b8f0:·6572·2072·6569·6e73·7461·6c6c·2063·6f6d··er·reinstall·com
 0003b900:·6d61·6e64·270a·2020·7365·745f·6661·6374··mand'.··set_fact
 0003b910:·3a0a·2020·2020·7061·636b·6167·655f·6d61··:.····package_ma
 0003b920:·6e61·6765·725f·7265·696e·7374·616c·6c5f··nager_reinstall_
 0003b930:·636d·643a·207a·7970·7065·7220·7265·696e··cmd:·zypper·rein
 0003b940:·7374·616c·6c20·2d79·0a20·2077·6865·6e3a··stall·-y.··when:
 0003b950:·2061·6e73·6962·6c65·5f64·6973·7472·6962···ansible_distrib
 0003b960:·7574·696f·6e20·696e·205b·2022·4665·646f··ution·in·[·"Fedo
 0003b970:·7261·222c·2022·5265·6448·6174·222c·2022··ra",·"RedHat",·"
 0003b980:·4365·6e74·4f53·222c·2022·4f72·6163·6c65··CentOS",·"Oracle
 0003b990:·4c69·6e75·7822·205d·0a20·2074·6167·733a··Linux"·].··tags:
 0003b9a0:·0a20·202d·2043·4345·2d39·3136·3332·2d30··.··-·CCE-91632-0
 0003b9b0:·0a20·202d·2043·4a49·532d·352e·3130·2e34··.··-·CJIS-5.10.4
 0003b9c0:·2e31·0a20·202d·204e·4953·542d·3830·302d··.1.··-·NIST-800-
 0003b9d0:·3137·312d·332e·332e·380a·2020·2d20·4e49··171-3.3.8.··-·NI
 0003b9e0:·5354·2d38·3030·2d31·3731·2d33·2e34·2e31··ST-800-171-3.4.1
 0003b9f0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
 0003ba00:·2d41·552d·3928·3329·0a20·202d·204e·4953··-AU-9(3).··-·NIS
 0003ba10:·542d·3830·302d·3533·2d43·4d2d·3628·6329··T-800-53-CM-6(c)
 0003ba20:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
 0003ba30:·2d43·4d2d·3628·6429·0a20·202d·204e·4953··-CM-6(d).··-·NIS
 0003ba40:·542d·3830·302d·3533·2d53·492d·370a·2020··T-800-53-SI-7.··
 0003ba50:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI
 0003ba60:·2d37·2831·290a·2020·2d20·4e49·5354·2d38··-7(1).··-·NIST-8
 0003ba70:·3030·2d35·332d·5349·2d37·2836·290a·2020··00-53-SI-7(6).··
 0003ba80:·2d20·5043·492d·4453·532d·5265·712d·3131··-·PCI-DSS-Req-11
 0003ba90:·2e35·0a20·202d·2050·4349·2d44·5353·7634··.5.··-·PCI-DSSv4
 0003baa0:·2d31·312e·352e·320a·2020·2d20·6869·6768··-11.5.2.··-·high
 0003bab0:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-·
Max diff block lines reached; 18129745/18171751 bytes (99.77%) of diff not shown.
1.38 MB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v4·Control·Baseline·for·SUSE·Linux·enterprise·1237 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v4·Control·Baseline·for·SUSE·Linux·enterprise·12
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss-438 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss-4
39 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*39 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
40 ····*·cpe:/o:suse:linux_enterprise_desktop:1240 ····*·cpe:/o:suse:linux_enterprise_desktop:12
41 ····*·cpe:/o:suse:linux_enterprise_server:1241 ····*·cpe:/o:suse:linux_enterprise_server:12
42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
43 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8443 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
49 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n49 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
50 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g50 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
51 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s51 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 134, 29 lines modifiedOffset 134, 14 lines modified
134 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,134 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,
135 ····························A.14.2.3,·A.14.2.4135 ····························A.14.2.3,·A.14.2.4
136 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)136 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
137 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1137 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
138 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5138 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
139 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227139 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
140 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2140 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
141 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
142 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then 
143 get·files·names 
144 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
145 if·[·-n·"$files_with_incorrect_hash"·];·then 
146 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to 
147 new·line 
148 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
149 ····zypper·install·-f·-y·$packages_to_reinstall 
  
150 fi 
151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8141 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high142 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium143 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false144 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict145 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
156 -·name:·'Set·fact:·Package·manager·reinstall·command'146 -·name:·'Set·fact:·Package·manager·reinstall·command'
157 ··set_fact:147 ··set_fact:
Offset 288, 14 lines modifiedOffset 273, 29 lines modified
288 ··-·PCI-DSSv4-11.5.2273 ··-·PCI-DSSv4-11.5.2
289 ··-·high_complexity274 ··-·high_complexity
290 ··-·high_severity275 ··-·high_severity
291 ··-·medium_disruption276 ··-·medium_disruption
292 ··-·no_reboot_needed277 ··-·no_reboot_needed
293 ··-·restrict_strategy278 ··-·restrict_strategy
294 ··-·rpm_verify_hashes279 ··-·rpm_verify_hashes
 280 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 281 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then
 282 get·files·names
 283 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 284 if·[·-n·"$files_with_incorrect_hash"·];·then
 285 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to
 286 new·line
 287 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 288 ····zypper·install·-f·-y·$packages_to_reinstall
  
 289 fi
295 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*290 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
296 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,291 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,
297 including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,292 including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,
298 which·can·be·found·with:293 which·can·be·found·with:
299 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'294 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
300 run·the·following·command·to·determine·which·package·owns·it:295 run·the·following·command·to·determine·which·package·owns·it:
301 $·rpm·-qf·FILENAME296 $·rpm·-qf·FILENAME
Offset 377, 46 lines modifiedOffset 377, 14 lines modified
377 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)377 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)
378 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1378 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
379 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5379 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
380 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,380 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,
381 ····························SRG-OS-000278-GPOS-00108381 ····························SRG-OS-000278-GPOS-00108
382 ·············_\x8c_\x8i_\x8s············6.1.1382 ·············_\x8c_\x8i_\x8s············6.1.1
383 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2383 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
384 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
385 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
386 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
387 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
388 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
389 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
390 declare·-A·SETPERMS_RPM_DICT 
  
391 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
392 #·is·expected·by·the·RPM·database 
393 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,2,1)=="M")·print 
394 $NF·}') 
  
395 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
396 do 
397 ········#·NOTE:·some·files·maybe·controlled·by·more·then·one·package 
398 ········readarray·-t·RPM_PACKAGES·<·<(rpm·-qf·"${FILE_PATH}") 
399 ········for·RPM_PACKAGE·in·"${RPM_PACKAGES[@]}" 
400 ········do 
401 ················#·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about 
402 duplicates. 
403 ················SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
404 ········done 
405 done 
  
406 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
407 #·correct·values 
408 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
409 do 
410 »       rpm·--restore·"${RPM_PACKAGE}" 
411 done 
412 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8384 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
413 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high385 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
414 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium386 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
415 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false387 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
416 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict388 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
417 -·name:·Read·list·of·files·with·incorrect·permissions389 -·name:·Read·list·of·files·with·incorrect·permissions
418 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev390 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 497, 14 lines modifiedOffset 465, 46 lines modified
497 ··-·PCI-DSSv4-11.5.2465 ··-·PCI-DSSv4-11.5.2
498 ··-·high_complexity466 ··-·high_complexity
499 ··-·high_severity467 ··-·high_severity
500 ··-·medium_disruption468 ··-·medium_disruption
Max diff block lines reached; 1444335/1450536 bytes (99.57%) of diff not shown.
17.4 MB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-pci-dss.html
    
Offset 14298, 15 lines modifiedOffset 14298, 15 lines modified
00037d90:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·00037d90:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·
00037da0:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong00037da0:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong
00037db0:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>00037db0:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>
00037dc0:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str00037dc0:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str
00037dd0:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron00037dd0:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron
00037de0:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············00037de0:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············
00037df0:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·2000037df0:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·20
00037e00:·3236·2d30·312d·3038·290a·2020·2020·2020··26-01-08).······00037e00:·3234·2d31·322d·3037·290a·2020·2020·2020··24-12-07).······
00037e10:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><00037e10:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><
00037e20:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta00037e20:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta
00037e30:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<00037e30:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<
00037e40:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h00037e40:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h
00037e50:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.00037e50:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.
00037e60:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte00037e60:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte
00037e70:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"00037e70:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"
Offset 15163, 306 lines modifiedOffset 15163, 306 lines modified
0003b3a0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003b3a0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b3b0:·6964·6d35·3034·3722·2074·6162·696e·6465··idm5047"·tabinde0003b3b0:·6964·6d35·3034·3722·2074·6162·696e·6465··idm5047"·tabinde
0003b3c0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b3c0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003b3d0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003b3d0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003b3e0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003b3e0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003b3f0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003b3f0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003b400:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003b400:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003b410:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell0003b410:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib
0003b420:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003b430:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b440:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b450:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5 
0003b460:·3034·3722·3e3c·7072·653e·3c63·6f64·653e··047"><pre><code> 
0003b470:·0a23·2046·696e·6420·7768·6963·6820·6669··.#·Find·which·fi 
0003b480:·6c65·7320·6861·7665·2069·6e63·6f72·7265··les·have·incorre 
0003b490:·6374·2068·6173·6820·286e·6f74·2069·6e20··ct·hash·(not·in· 
0003b4a0:·2f65·7463·2c20·6265·6361·7573·6520·6f66··/etc,·because·of 
0003b4b0:·2074·6865·2073·7973·7465·6d20·7265·6c61···the·system·rela 
0003b4c0:·7465·6420·636f·6e66·6967·2066·696c·6573··ted·config·files 
0003b4d0:·2920·616e·6420·7468·656e·2067·6574·2066··)·and·then·get·f 
0003b4e0:·696c·6573·206e·616d·6573·0a66·696c·6573··iles·names.files 
0003b4f0:·5f77·6974·685f·696e·636f·7272·6563·745f··_with_incorrect_ 
0003b500:·6861·7368·3d22·2428·7270·6d20·2d56·6120··hash="$(rpm·-Va· 
0003b510:·2d2d·6e6f·636f·6e66·6967·207c·2067·7265··--noconfig·|·gre 
0003b520:·7020·2d45·2027·5e2e·2e35·2720·7c20·6177··p·-E·'^..5'·|·aw 
0003b530:·6b20·277b·7072·696e·7420·244e·467d·2720··k·'{print·$NF}'· 
0003b540:·2922·0a0a·6966·205b·202d·6e20·2224·6669··)"..if·[·-n·"$fi 
0003b550:·6c65·735f·7769·7468·5f69·6e63·6f72·7265··les_with_incorre 
0003b560:·6374·5f68·6173·6822·205d·3b20·7468·656e··ct_hash"·];·then 
0003b570:·0a20·2020·2023·2046·726f·6d20·6669·6c65··.····#·From·file 
0003b580:·7320·6e61·6d65·7320·6765·7420·7061·636b··s·names·get·pack 
0003b590:·6167·6520·6e61·6d65·7320·616e·6420·6368··age·names·and·ch 
0003b5a0:·616e·6765·206e·6577·6c69·6e65·2074·6f20··ange·newline·to· 
0003b5b0:·7370·6163·652c·2062·6563·6175·7365·2072··space,·because·r 
0003b5c0:·706d·2077·7269·7465·7320·6561·6368·2070··pm·writes·each·p 
0003b5d0:·6163·6b61·6765·2074·6f20·6e65·7720·6c69··ackage·to·new·li 
0003b5e0:·6e65·0a20·2020·2070·6163·6b61·6765·735f··ne.····packages_ 
0003b5f0:·746f·5f72·6569·6e73·7461·6c6c·3d22·2428··to_reinstall="$( 
0003b600:·7270·6d20·2d71·6620·2466·696c·6573·5f77··rpm·-qf·$files_w 
0003b610:·6974·685f·696e·636f·7272·6563·745f·6861··ith_incorrect_ha 
0003b620:·7368·207c·2074·7220·275c·6e27·2027·2027··sh·|·tr·'\n'·'·' 
0003b630:·2922·0a0a·2020·2020·0a20·2020·207a·7970··)"..····.····zyp 
0003b640:·7065·7220·696e·7374·616c·6c20·2d66·202d··per·install·-f·- 
0003b650:·7920·2470·6163·6b61·6765·735f·746f·5f72··y·$packages_to_r 
0003b660:·6569·6e73·7461·6c6c·0a20·2020·200a·6669··einstall.····.fi 
0003b670:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003b680:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b690:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b6a0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b6b0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b6c0:·743d·2223·6964·6d35·3034·3822·2074·6162··t="#idm5048"·tab 
0003b6d0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b6e0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b6f0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b700:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b710:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b720:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A 
0003b730:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.0003b420:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</
0003b740:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003b430:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003b750:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003b440:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003b760:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003b450:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003b770:·643d·2269·646d·3530·3438·223e·3c74·6162··d="idm5048"><tab0003b460:·646d·3530·3437·223e·3c74·6162·6c65·2063··dm5047"><table·c
0003b780:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003b470:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003b790:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003b480:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003b7a0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003b490:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003b7b0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003b4a0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003b7c0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003b4b0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003b7d0:·3a3c·2f74·683e·3c74·643e·6869·6768·3c2f··:</th><td>high</ 
0003b7e0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b7f0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003b800:·3c74·643e·6d65·6469·756d·3c2f·7464·3e3c··<td>medium</td><0003b4c0:·683e·3c74·643e·6869·6768·3c2f·7464·3e3c··h><td>high</td><
0003b810:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo0003b4d0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 0003b4e0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 0003b4f0:·6d65·6469·756d·3c2f·7464·3e3c·2f74·723e··medium</td></tr>
 0003b500:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
0003b820:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals0003b510:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003b830:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><0003b520:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003b840:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th0003b530:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003b850:·3e3c·7464·3e72·6573·7472·6963·743c·2f74··><td>restrict</t0003b540:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></
0003b860:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003b550:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
0003b870:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name0003b560:·3c63·6f64·653e·2d20·6e61·6d65·3a20·2753··<code>-·name:·'S
 0003b570:·6574·2066·6163·743a·2050·6163·6b61·6765··et·fact:·Package
 0003b580:·206d·616e·6167·6572·2072·6569·6e73·7461···manager·reinsta
 0003b590:·6c6c·2063·6f6d·6d61·6e64·270a·2020·7365··ll·command'.··se
 0003b5a0:·745f·6661·6374·3a0a·2020·2020·7061·636b··t_fact:.····pack
 0003b5b0:·6167·655f·6d61·6e61·6765·725f·7265·696e··age_manager_rein
 0003b5c0:·7374·616c·6c5f·636d·643a·207a·7970·7065··stall_cmd:·zyppe
 0003b5d0:·7220·7265·696e·7374·616c·6c20·2d79·0a20··r·reinstall·-y.·
 0003b5e0:·2077·6865·6e3a·2061·6e73·6962·6c65·5f64···when:·ansible_d
 0003b5f0:·6973·7472·6962·7574·696f·6e20·696e·205b··istribution·in·[
 0003b600:·2022·4665·646f·7261·222c·2022·5265·6448···"Fedora",·"RedH
 0003b610:·6174·222c·2022·4365·6e74·4f53·222c·2022··at",·"CentOS",·"
 0003b620:·4f72·6163·6c65·4c69·6e75·7822·205d·0a20··OracleLinux"·].·
 0003b630:·2074·6167·733a·0a20·202d·2043·4345·2d39···tags:.··-·CCE-9
 0003b640:·3136·3332·2d30·0a20·202d·2043·4a49·532d··1632-0.··-·CJIS-
 0003b650:·352e·3130·2e34·2e31·0a20·202d·204e·4953··5.10.4.1.··-·NIS
 0003b660:·542d·3830·302d·3137·312d·332e·332e·380a··T-800-171-3.3.8.
 0003b670:·2020·2d20·4e49·5354·2d38·3030·2d31·3731····-·NIST-800-171
 0003b680:·2d33·2e34·2e31·0a20·202d·204e·4953·542d··-3.4.1.··-·NIST-
 0003b690:·3830·302d·3533·2d41·552d·3928·3329·0a20··800-53-AU-9(3).·
 0003b6a0:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C
 0003b6b0:·4d2d·3628·6329·0a20·202d·204e·4953·542d··M-6(c).··-·NIST-
 0003b6c0:·3830·302d·3533·2d43·4d2d·3628·6429·0a20··800-53-CM-6(d).·
 0003b6d0:·202d·204e·4953·542d·3830·302d·3533·2d53···-·NIST-800-53-S
 0003b6e0:·492d·370a·2020·2d20·4e49·5354·2d38·3030··I-7.··-·NIST-800
 0003b6f0:·2d35·332d·5349·2d37·2831·290a·2020·2d20··-53-SI-7(1).··-·
 0003b700:·4e49·5354·2d38·3030·2d35·332d·5349·2d37··NIST-800-53-SI-7
 0003b710:·2836·290a·2020·2d20·5043·492d·4453·532d··(6).··-·PCI-DSS-
 0003b720:·5265·712d·3131·2e35·0a20·202d·2050·4349··Req-11.5.··-·PCI
 0003b730:·2d44·5353·7634·2d31·312e·352e·320a·2020··-DSSv4-11.5.2.··
 0003b740:·2d20·6869·6768·5f63·6f6d·706c·6578·6974··-·high_complexit
Max diff block lines reached; 16961416/17003422 bytes (99.75%) of diff not shown.
1.23 MB
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v3.2.1·Control·Baseline·for·SUSE·Linux·enterprise·1238 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v3.2.1·Control·Baseline·for·SUSE·Linux·enterprise·12
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:suse:linux_enterprise_desktop:1241 ····*·cpe:/o:suse:linux_enterprise_desktop:12
42 ····*·cpe:/o:suse:linux_enterprise_server:1242 ····*·cpe:/o:suse:linux_enterprise_server:12
43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
44 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8444 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
49 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l49 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
50 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n50 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
51 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g51 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
52 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s52 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 124, 29 lines modifiedOffset 124, 14 lines modified
124 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,124 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,
125 ····························A.14.2.3,·A.14.2.4125 ····························A.14.2.3,·A.14.2.4
126 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)126 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
127 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1127 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
128 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5128 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
129 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227129 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
130 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2130 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
132 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then 
133 get·files·names 
134 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
135 if·[·-n·"$files_with_incorrect_hash"·];·then 
136 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to 
137 new·line 
138 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
139 ····zypper·install·-f·-y·$packages_to_reinstall 
  
140 fi 
141 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
142 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
143 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
144 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
145 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
146 -·name:·'Set·fact:·Package·manager·reinstall·command'136 -·name:·'Set·fact:·Package·manager·reinstall·command'
147 ··set_fact:137 ··set_fact:
Offset 278, 14 lines modifiedOffset 263, 29 lines modified
278 ··-·PCI-DSSv4-11.5.2263 ··-·PCI-DSSv4-11.5.2
279 ··-·high_complexity264 ··-·high_complexity
280 ··-·high_severity265 ··-·high_severity
281 ··-·medium_disruption266 ··-·medium_disruption
282 ··-·no_reboot_needed267 ··-·no_reboot_needed
283 ··-·restrict_strategy268 ··-·restrict_strategy
284 ··-·rpm_verify_hashes269 ··-·rpm_verify_hashes
 270 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 271 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then
 272 get·files·names
 273 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 274 if·[·-n·"$files_with_incorrect_hash"·];·then
 275 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to
 276 new·line
 277 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 278 ····zypper·install·-f·-y·$packages_to_reinstall
  
 279 fi
285 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*280 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
286 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,281 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,
287 including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,282 including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,
288 which·can·be·found·with:283 which·can·be·found·with:
289 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'284 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
290 run·the·following·command·to·determine·which·package·owns·it:285 run·the·following·command·to·determine·which·package·owns·it:
291 $·rpm·-qf·FILENAME286 $·rpm·-qf·FILENAME
Offset 367, 46 lines modifiedOffset 367, 14 lines modified
367 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)367 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)
368 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1368 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
369 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5369 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
370 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,370 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,
371 ····························SRG-OS-000278-GPOS-00108371 ····························SRG-OS-000278-GPOS-00108
372 ·············_\x8c_\x8i_\x8s············6.1.1372 ·············_\x8c_\x8i_\x8s············6.1.1
373 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2373 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
374 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
375 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
376 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
377 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
378 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
379 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
380 declare·-A·SETPERMS_RPM_DICT 
  
381 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
382 #·is·expected·by·the·RPM·database 
383 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,2,1)=="M")·print 
384 $NF·}') 
  
385 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
386 do 
387 ········#·NOTE:·some·files·maybe·controlled·by·more·then·one·package 
388 ········readarray·-t·RPM_PACKAGES·<·<(rpm·-qf·"${FILE_PATH}") 
389 ········for·RPM_PACKAGE·in·"${RPM_PACKAGES[@]}" 
390 ········do 
391 ················#·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about 
392 duplicates. 
393 ················SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
394 ········done 
395 done 
  
396 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
397 #·correct·values 
398 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
399 do 
400 »       rpm·--restore·"${RPM_PACKAGE}" 
401 done 
402 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8374 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
403 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high375 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
404 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium376 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
405 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false377 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
406 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict378 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
407 -·name:·Read·list·of·files·with·incorrect·permissions379 -·name:·Read·list·of·files·with·incorrect·permissions
408 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev380 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 487, 14 lines modifiedOffset 455, 46 lines modified
487 ··-·PCI-DSSv4-11.5.2455 ··-·PCI-DSSv4-11.5.2
488 ··-·high_complexity456 ··-·high_complexity
489 ··-·high_severity457 ··-·high_severity
490 ··-·medium_disruption458 ··-·medium_disruption
Max diff block lines reached; 1286783/1292986 bytes (99.52%) of diff not shown.
52.8 KB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-standard.html
    
Offset 14304, 16 lines modifiedOffset 14304, 16 lines modified
00037df0:·7369·6f6e·2048·6973·746f·7279·3c2f·6832··sion·History</h200037df0:·7369·6f6e·2048·6973·746f·7279·3c2f·6832··sion·History</h2
00037e00:·3e3c·703e·4375·7272·656e·7420·7665·7273··><p>Current·vers00037e00:·3e3c·703e·4375·7272·656e·7420·7665·7273··><p>Current·vers
00037e10:·696f·6e3a·203c·7374·726f·6e67·3e30·2e31··ion:·<strong>0.100037e10:·696f·6e3a·203c·7374·726f·6e67·3e30·2e31··ion:·<strong>0.1
00037e20:·2e37·343c·2f73·7472·6f6e·673e·3c2f·703e··.74</strong></p>00037e20:·2e37·343c·2f73·7472·6f6e·673e·3c2f·703e··.74</strong></p>
00037e30:·3c75·6c3e·3c6c·693e·3c73·7472·6f6e·673e··<ul><li><strong>00037e30:·3c75·6c3e·3c6c·693e·3c73·7472·6f6e·673e··<ul><li><strong>
00037e40:·6472·6166·743c·2f73·7472·6f6e·673e·0a20··draft</strong>.·00037e40:·6472·6166·743c·2f73·7472·6f6e·673e·0a20··draft</strong>.·
00037e50:·2020·2020·2020·2020·2020·2020·2020·2020··················00037e50:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037e60:·2020·2028·6173·206f·6620·3230·3236·2d30·····(as·of·2026-000037e60:·2020·2028·6173·206f·6620·3230·3234·2d31·····(as·of·2024-1
00037e70:·312d·3038·290a·2020·2020·2020·2020·2020··1-08).··········00037e70:·322d·3037·290a·2020·2020·2020·2020·2020··2-07).··········
00037e80:·2020·2020·2020·3c2f·6c69·3e3c·2f75·6c3e········</li></ul>00037e80:·2020·2020·2020·3c2f·6c69·3e3c·2f75·6c3e········</li></ul>
00037e90:·3c2f·6469·763e·3c68·323e·5461·626c·6520··</div><h2>Table·00037e90:·3c2f·6469·763e·3c68·323e·5461·626c·6520··</div><h2>Table·
00037ea0:·6f66·2043·6f6e·7465·6e74·733c·2f68·323e··of·Contents</h2>00037ea0:·6f66·2043·6f6e·7465·6e74·733c·2f68·323e··of·Contents</h2>
00037eb0:·3c6f·6c3e·3c6c·693e·3c61·2068·7265·663d··<ol><li><a·href=00037eb0:·3c6f·6c3e·3c6c·693e·3c61·2068·7265·663d··<ol><li><a·href=
00037ec0:·2223·7863·6364·665f·6f72·672e·7373·6770··"#xccdf_org.ssgp00037ec0:·2223·7863·6364·665f·6f72·672e·7373·6770··"#xccdf_org.ssgp
00037ed0:·726f·6a65·6374·2e63·6f6e·7465·6e74·5f67··roject.content_g00037ed0:·726f·6a65·6374·2e63·6f6e·7465·6e74·5f67··roject.content_g
00037ee0:·726f·7570·5f73·7973·7465·6d22·3e53·7973··roup_system">Sys00037ee0:·726f·7570·5f73·7973·7465·6d22·3e53·7973··roup_system">Sys
Offset 14954, 117 lines modifiedOffset 14954, 117 lines modified
0003a690:·6574·3d22·2369·646d·3234·3536·3022·2074··et="#idm24560"·t0003a690:·6574·3d22·2369·646d·3234·3536·3022·2074··et="#idm24560"·t
0003a6a0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003a6a0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003a6b0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003a6b0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003a6c0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003a6c0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003a6d0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003a6d0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003a6e0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003a6e0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003a6f0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003a6f0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003a700:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
0003a710:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003a720:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003a730:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003a740:·3d22·6964·6d32·3435·3630·223e·3c74·6162··="idm24560"><tab 
0003a750:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003a760:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003a770:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003a780:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003a790:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003a700:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet
 0003a710:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003a720:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003a730:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003a740:·2069·643d·2269·646d·3234·3536·3022·3e3c···id="idm24560"><
 0003a750:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003a760:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003a770:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003a780:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003a790:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0003a7a0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0003a7b0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003a7c0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003a7a0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003a7d0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003a7b0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003a7c0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003a7d0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003a7e0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003a7f0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003a800:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003a810:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003a820:·3e63·6f6e·6669·6775·7265·3c2f·7464·3e3c··>configure</td>< 
0003a830:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003a840:·3e3c·636f·6465·3e63·6867·7270·202d·4c20··><code>chgrp·-L·0003a7e0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
 0003a7f0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
 0003a800:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003a810:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 0003a820:·3c74·643e·636f·6e66·6967·7572·653c·2f74··<td>configure</t
 0003a830:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003a840:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name
 0003a850:·3a20·5465·7374·2066·6f72·2065·7869·7374··:·Test·for·exist
 0003a860:·656e·6365·202f·6574·632f·7061·7373·7764··ence·/etc/passwd
 0003a870:·0a20·2073·7461·743a·0a20·2020·2070·6174··.··stat:.····pat
 0003a880:·683a·202f·6574·632f·7061·7373·7764·0a20··h:·/etc/passwd.·
 0003a890:·2072·6567·6973·7465·723a·2066·696c·655f···register:·file_
 0003a8a0:·6578·6973·7473·0a20·2074·6167·733a·0a20··exists.··tags:.·
 0003a8b0:·202d·2043·4345·2d39·3136·3237·2d30·0a20···-·CCE-91627-0.·
 0003a8c0:·202d·2043·4a49·532d·352e·352e·322e·320a···-·CJIS-5.5.2.2.
 0003a8d0:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
 0003a8e0:·4143·2d36·2831·290a·2020·2d20·4e49·5354··AC-6(1).··-·NIST
 0003a8f0:·2d38·3030·2d35·332d·434d·2d36·2861·290a··-800-53-CM-6(a).
 0003a900:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req-
 0003a910:·382e·372e·630a·2020·2d20·5043·492d·4453··8.7.c.··-·PCI-DS
 0003a920:·5376·342d·322e·322e·360a·2020·2d20·636f··Sv4-2.2.6.··-·co
 0003a930:·6e66·6967·7572·655f·7374·7261·7465·6779··nfigure_strategy
 0003a940:·0a20·202d·2066·696c·655f·6772·6f75·706f··.··-·file_groupo
 0003a950:·776e·6572·5f65·7463·5f70·6173·7377·640a··wner_etc_passwd.
 0003a960:·2020·2d20·6c6f·775f·636f·6d70·6c65·7869····-·low_complexi
 0003a970:·7479·0a20·202d·206c·6f77·5f64·6973·7275··ty.··-·low_disru
 0003a980:·7074·696f·6e0a·2020·2d20·6d65·6469·756d··ption.··-·medium
 0003a990:·5f73·6576·6572·6974·790a·2020·2d20·6e6f··_severity.··-·no
 0003a9a0:·5f72·6562·6f6f·745f·6e65·6564·6564·0a0a··_reboot_needed..
 0003a9b0:·2d20·6e61·6d65·3a20·456e·7375·7265·2067··-·name:·Ensure·g
 0003a9c0:·726f·7570·206f·776e·6572·2030·206f·6e20··roup·owner·0·on·
0003a850:·3020·2f65·7463·2f70·6173·7377·640a·3c2f··0·/etc/passwd.</0003a9d0:·2f65·7463·2f70·6173·7377·640a·2020·6669··/etc/passwd.··fi
0003a860:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003a870:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003a880:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003a890:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003a8a0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003a8b0:·2369·646d·3234·3536·3122·2074·6162·696e··#idm24561"·tabin 
0003a8c0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003a8d0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003a8e0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003a8f0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003a900:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003a910:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans 
0003a920:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...0003a9e0:·6c65·3a0a·2020·2020·7061·7468·3a20·2f65··le:.····path:·/e
 0003a9f0:·7463·2f70·6173·7377·640a·2020·2020·6772··tc/passwd.····gr
 0003aa00:·6f75·703a·2027·3027·0a20·2077·6865·6e3a··oup:·'0'.··when:
 0003aa10:·2066·696c·655f·6578·6973·7473·2e73·7461···file_exists.sta
 0003aa20:·7420·6973·2064·6566·696e·6564·2061·6e64··t·is·defined·and
 0003aa30:·2066·696c·655f·6578·6973·7473·2e73·7461···file_exists.sta
 0003aa40:·742e·6578·6973·7473·0a20·2074·6167·733a··t.exists.··tags:
 0003aa50:·0a20·202d·2043·4345·2d39·3136·3237·2d30··.··-·CCE-91627-0
 0003aa60:·0a20·202d·2043·4a49·532d·352e·352e·322e··.··-·CJIS-5.5.2.
 0003aa70:·320a·2020·2d20·4e49·5354·2d38·3030·2d35··2.··-·NIST-800-5
 0003aa80:·332d·4143·2d36·2831·290a·2020·2d20·4e49··3-AC-6(1).··-·NI
 0003aa90:·5354·2d38·3030·2d35·332d·434d·2d36·2861··ST-800-53-CM-6(a
 0003aaa0:·290a·2020·2d20·5043·492d·4453·532d·5265··).··-·PCI-DSS-Re
 0003aab0:·712d·382e·372e·630a·2020·2d20·5043·492d··q-8.7.c.··-·PCI-
 0003aac0:·4453·5376·342d·322e·322e·360a·2020·2d20··DSSv4-2.2.6.··-·
 0003aad0:·636f·6e66·6967·7572·655f·7374·7261·7465··configure_strate
 0003aae0:·6779·0a20·202d·2066·696c·655f·6772·6f75··gy.··-·file_grou
 0003aaf0:·706f·776e·6572·5f65·7463·5f70·6173·7377··powner_etc_passw
 0003ab00:·640a·2020·2d20·6c6f·775f·636f·6d70·6c65··d.··-·low_comple
 0003ab10:·7869·7479·0a20·202d·206c·6f77·5f64·6973··xity.··-·low_dis
 0003ab20:·7275·7074·696f·6e0a·2020·2d20·6d65·6469··ruption.··-·medi
 0003ab30:·756d·5f73·6576·6572·6974·790a·2020·2d20··um_severity.··-·
 0003ab40:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed
 0003ab50:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 0003ab60:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 0003ab70:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 0003ab80:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
Max diff block lines reached; 31382/47444 bytes (66.15%) of diff not shown.
6.35 KB
html2text {}
    
Offset 40, 15 lines modifiedOffset 40, 15 lines modified
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·SUSE·Linux·Enterprise·1240 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·SUSE·Linux·Enterprise·12
41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard
42 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*42 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
43 ····*·cpe:/o:suse:linux_enterprise_desktop:1243 ····*·cpe:/o:suse:linux_enterprise_desktop:12
44 ····*·cpe:/o:suse:linux_enterprise_server:1244 ····*·cpe:/o:suse:linux_enterprise_server:12
45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
46 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8446 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
50 ·········1.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s50 ·········1.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
51 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*51 *\x8**\x8**\x8**\x8**\x8*·C\x8Ch\x8he\x8ec\x8ck\x8kl\x8li\x8is\x8st\x8t·*\x8**\x8**\x8**\x8**\x8*
52 Group  ·Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·12·  Group52 Group  ·Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·12·  Group
53 contains·4·groups·and·3·rules53 contains·4·groups·and·3·rules
54 Group  ·System·Settings·  Group·contains·3·groups·and·3·rules54 Group  ·System·Settings·  Group·contains·3·groups·and·3·rules
Offset 107, 20 lines modifiedOffset 107, 14 lines modified
107 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)107 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)
108 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5108 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5
109 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-8.7.c109 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-8.7.c
110 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227110 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
111 ·············_\x8c_\x8i_\x8s············6.1.2111 ·············_\x8c_\x8i_\x8s············6.1.2
112 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R50112 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R50
113 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6113 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6
114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
115 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
116 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
117 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
118 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure 
119 chgrp·-L·0·/etc/passwd 
120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
121 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low115 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
122 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low116 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
123 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false117 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
124 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure118 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
125 -·name:·Test·for·existence·/etc/passwd119 -·name:·Test·for·existence·/etc/passwd
126 ··stat:120 ··stat:
Offset 154, 14 lines modifiedOffset 148, 20 lines modified
154 ··-·PCI-DSSv4-2.2.6148 ··-·PCI-DSSv4-2.2.6
155 ··-·configure_strategy149 ··-·configure_strategy
156 ··-·file_groupowner_etc_passwd150 ··-·file_groupowner_etc_passwd
157 ··-·low_complexity151 ··-·low_complexity
158 ··-·low_disruption152 ··-·low_disruption
159 ··-·medium_severity153 ··-·medium_severity
160 ··-·no_reboot_needed154 ··-·no_reboot_needed
 155 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 156 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 157 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 158 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 159 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
 160 chgrp·-L·0·/etc/passwd
161 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·U\x8Us\x8se\x8er\x8r·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·p\x8pa\x8as\x8ss\x8sw\x8wd\x8d·F\x8Fi\x8il\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*161 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·U\x8Us\x8se\x8er\x8r·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·p\x8pa\x8as\x8ss\x8sw\x8wd\x8d·F\x8Fi\x8il\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
162 To·properly·set·the·owner·of·/etc/passwd,·run·the·command:162 To·properly·set·the·owner·of·/etc/passwd,·run·the·command:
163 $·sudo·chown·root·/etc/passwd163 $·sudo·chown·root·/etc/passwd
164 ·············The·/etc/passwd·file·contains·information·about·the·users·that·are164 ·············The·/etc/passwd·file·contains·information·about·the·users·that·are
165 Rationale:···configured·on·the·system.·Protection·of·this·file·is·critical·for165 Rationale:···configured·on·the·system.·Protection·of·this·file·is·critical·for
166 ·············system·security.166 ·············system·security.
167 Severity: ···medium167 Severity: ···medium
Offset 184, 20 lines modifiedOffset 184, 14 lines modified
184 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)184 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)
185 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5185 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5
186 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-8.7.c186 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-8.7.c
187 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227187 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
188 ·············_\x8c_\x8i_\x8s············6.1.2188 ·············_\x8c_\x8i_\x8s············6.1.2
189 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R50189 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R50
190 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6190 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6
191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure 
196 chown·-L·0·/etc/passwd 
197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
202 -·name:·Test·for·existence·/etc/passwd196 -·name:·Test·for·existence·/etc/passwd
203 ··stat:197 ··stat:
Offset 231, 14 lines modifiedOffset 225, 20 lines modified
231 ··-·PCI-DSSv4-2.2.6225 ··-·PCI-DSSv4-2.2.6
232 ··-·configure_strategy226 ··-·configure_strategy
233 ··-·file_owner_etc_passwd227 ··-·file_owner_etc_passwd
234 ··-·low_complexity228 ··-·low_complexity
235 ··-·low_disruption229 ··-·low_disruption
236 ··-·medium_severity230 ··-·medium_severity
237 ··-·no_reboot_needed231 ··-·no_reboot_needed
 232 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 233 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 234 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 235 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 236 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
 237 chown·-L·0·/etc/passwd
238 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·o\x8on\x8n·p\x8pa\x8as\x8ss\x8sw\x8wd\x8d·F\x8Fi\x8il\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*238 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·o\x8on\x8n·p\x8pa\x8as\x8ss\x8sw\x8wd\x8d·F\x8Fi\x8il\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
239 To·properly·set·the·permissions·of·/etc/passwd,·run·the·command:239 To·properly·set·the·permissions·of·/etc/passwd,·run·the·command:
240 $·sudo·chmod·0644·/etc/passwd240 $·sudo·chmod·0644·/etc/passwd
241 ·············If·the·/etc/passwd·file·is·writable·by·a·group-owner·or·the·world241 ·············If·the·/etc/passwd·file·is·writable·by·a·group-owner·or·the·world
242 Rationale:···the·risk·of·its·compromise·is·increased.·The·file·contains·the242 Rationale:···the·risk·of·its·compromise·is·increased.·The·file·contains·the
243 ·············list·of·accounts·on·the·system·and·associated·information,·and243 ·············list·of·accounts·on·the·system·and·associated·information,·and
244 ·············protection·of·this·file·is·critical·for·system·security.244 ·············protection·of·this·file·is·critical·for·system·security.
Offset 262, 25 lines modifiedOffset 262, 14 lines modified
262 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)262 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AC-6(1)
263 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5263 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5
264 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-8.7.c264 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-8.7.c
265 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227265 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
266 ·············_\x8c_\x8i_\x8s············6.1.2266 ·············_\x8c_\x8i_\x8s············6.1.2
267 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R50267 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R50
268 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6268 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6
269 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
270 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
271 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
272 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
273 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure 
  
  
  
  
  
274 chmod·u-xs,g-xws,o-xwt·/etc/passwd 
275 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8269 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
276 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low270 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
277 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low271 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
278 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false272 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
279 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure273 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
280 -·name:·Test·for·existence·/etc/passwd274 -·name:·Test·for·existence·/etc/passwd
281 ··stat:275 ··stat:
Offset 314, 11 lines modifiedOffset 303, 22 lines modified
314 ··-·PCI-DSSv4-2.2.6303 ··-·PCI-DSSv4-2.2.6
Max diff block lines reached; 675/6479 bytes (10.42%) of diff not shown.
20.2 MB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-stig.html
    
Offset 14297, 15 lines modifiedOffset 14297, 15 lines modified
00037d80:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00037d80:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00037d90:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00037d90:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00037da0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<00037da0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<
00037db0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00037db0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00037dc0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00037dc0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00037dd0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00037dd0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00037de0:·2020·2020·2020·2020·2020·2020·2020·2028·················(00037de0:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00037df0:·6173·206f·6620·3230·3236·2d30·312d·3038··as·of·2026-01-0800037df0:·6173·206f·6620·3230·3234·2d31·322d·3037··as·of·2024-12-07
00037e00:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00037e00:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00037e10:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00037e10:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00037e20:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00037e20:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00037e30:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00037e30:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00037e40:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00037e40:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00037e50:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00037e50:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00037e60:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00037e60:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
Offset 15145, 130 lines modifiedOffset 15145, 130 lines modified
0003b280:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003b280:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003b290:·743d·2223·6964·6d35·3339·3022·2074·6162··t="#idm5390"·tab0003b290:·743d·2223·6964·6d35·3339·3022·2074·6162··t="#idm5390"·tab
0003b2a0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003b2a0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003b2b0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003b2b0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003b2c0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003b2c0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003b2d0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003b2d0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003b2e0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003b2e0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 0003b2f0:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O
 0003b300:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint
 0003b310:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0003b320:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003b330:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003b340:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003b350:·3533·3930·223e·3c70·7265·3e3c·636f·6465··5390"><pre><code
 0003b360:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n
 0003b370:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver
 0003b380:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod
 0003b390:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003b3a0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003b3b0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003b3c0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003b3d0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003b3e0:·6d35·3339·3122·2074·6162·696e·6465·783d··m5391"·tabindex=
 0003b3f0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003b400:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003b410:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003b420:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003b430:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003b440:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible
 0003b450:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0003b460:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003b470:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003b480:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003b490:·3533·3931·223e·3c74·6162·6c65·2063·6c61··5391"><table·cla
 0003b4a0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0003b4b0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0003b4c0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003b4d0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003b4e0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003b4f0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003b500:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0003b510:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003b520:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b530:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
 0003b540:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 0003b550:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003b560:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 0003b570:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 0003b580:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-·
 0003b590:·6e61·6d65·3a20·456e·7375·7265·2061·6964··name:·Ensure·aid
 0003b5a0:·6520·6973·2069·6e73·7461·6c6c·6564·0a20··e·is·installed.·
 0003b5b0:·2070·6163·6b61·6765·3a0a·2020·2020·6e61···package:.····na
 0003b5c0:·6d65·3a20·6169·6465·0a20·2020·2073·7461··me:·aide.····sta
 0003b5d0:·7465·3a20·7072·6573·656e·740a·2020·7768··te:·present.··wh
 0003b5e0:·656e·3a20·616e·7369·626c·655f·7669·7274··en:·ansible_virt
 0003b5f0:·7561·6c69·7a61·7469·6f6e·5f74·7970·6520··ualization_type·
 0003b600:·6e6f·7420·696e·205b·2264·6f63·6b65·7222··not·in·["docker"
 0003b610:·2c20·226c·7863·222c·2022·6f70·656e·767a··,·"lxc",·"openvz
 0003b620:·222c·2022·706f·646d·616e·222c·2022·636f··",·"podman",·"co
 0003b630:·6e74·6169·6e65·7222·5d0a·2020·7461·6773··ntainer"].··tags
 0003b640:·3a0a·2020·2d20·4343·452d·3833·3036·372d··:.··-·CCE-83067-
 0003b650:·390a·2020·2d20·434a·4953·2d35·2e31·302e··9.··-·CJIS-5.10.
 0003b660:·312e·330a·2020·2d20·4449·5341·2d53·5449··1.3.··-·DISA-STI
 0003b670:·472d·534c·4553·2d31·322d·3031·3034·3939··G-SLES-12-010499
 0003b680:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
 0003b690:·2d43·4d2d·3628·6129·0a20·202d·2050·4349··-CM-6(a).··-·PCI
 0003b6a0:·2d44·5353·2d52·6571·2d31·312e·350a·2020··-DSS-Req-11.5.··
 0003b6b0:·2d20·5043·492d·4453·5376·342d·3131·2e35··-·PCI-DSSv4-11.5
 0003b6c0:·2e32·0a20·202d·2065·6e61·626c·655f·7374··.2.··-·enable_st
 0003b6d0:·7261·7465·6779·0a20·202d·206c·6f77·5f63··rategy.··-·low_c
 0003b6e0:·6f6d·706c·6578·6974·790a·2020·2d20·6c6f··omplexity.··-·lo
 0003b6f0:·775f·6469·7372·7570·7469·6f6e·0a20·202d··w_disruption.··-
 0003b700:·206d·6564·6975·6d5f·7365·7665·7269·7479···medium_severity
 0003b710:·0a20·202d·206e·6f5f·7265·626f·6f74·5f6e··.··-·no_reboot_n
 0003b720:·6565·6465·640a·2020·2d20·7061·636b·6167··eeded.··-·packag
 0003b730:·655f·6169·6465·5f69·6e73·7461·6c6c·6564··e_aide_installed
 0003b740:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 0003b750:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 0003b760:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 0003b770:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 0003b780:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 0003b790:·743d·2223·6964·6d35·3339·3222·2074·6162··t="#idm5392"·tab
 0003b7a0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 0003b7b0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 0003b7c0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 0003b7d0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 0003b7e0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003b2f0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S0003b7f0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S
0003b300:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<0003b800:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<
0003b310:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003b810:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003b320:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003b820:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003b330:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003b830:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
0003b340:·6964·6d35·3339·3022·3e3c·7461·626c·6520··idm5390"><table·0003b840:·6964·6d35·3339·3222·3e3c·7461·626c·6520··idm5392"><table·
0003b350:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003b850:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003b360:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003b860:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003b370:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003b870:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003b380:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003b880:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0003b390:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003b890:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0003b3a0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003b8a0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003b3b0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003b8b0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003b3c0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003b8c0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003b3d0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003b8d0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003b3e0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th0003b8e0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
0003b3f0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><0003b8f0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
0003b400:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003b900:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
0003b410:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003b910:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
0003b420:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003b920:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
0003b430:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003b930:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
0003b440:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i0003b940:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
0003b450:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl0003b950:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
0003b460:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla0003b960:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
Max diff block lines reached; 19646129/19663847 bytes (99.91%) of diff not shown.
1.4 MB
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DISA·STIG·for·SUSE·Linux·Enterprise·1238 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DISA·STIG·for·SUSE·Linux·Enterprise·12
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_stig39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_stig
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:suse:linux_enterprise_desktop:1241 ····*·cpe:/o:suse:linux_enterprise_desktop:12
42 ····*·cpe:/o:suse:linux_enterprise_server:1242 ····*·cpe:/o:suse:linux_enterprise_server:12
43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
44 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8444 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
49 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l49 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
50 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r50 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
51 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n51 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
52 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g52 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 126, 27 lines modifiedOffset 126, 19 lines modified
126 include·install_aide126 include·install_aide
  
127 class·install_aide·{127 class·install_aide·{
128 ··package·{·'aide':128 ··package·{·'aide':
129 ····ensure·=>·'installed',129 ····ensure·=>·'installed',
130 ··}130 ··}
131 }131 }
 132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
137 #·Remediation·is·applicable·only·in·certain·platforms 
138 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
139 zypper·install·-y·"aide" 
  
140 else 
141 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
142 fi133 [[packages]]
 134 name·=·"aide"
 135 version·=·"*"
143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
144 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
145 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
146 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
147 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
148 -·name:·Ensure·aide·is·installed141 -·name:·Ensure·aide·is·installed
149 ··package:142 ··package:
Offset 162, 19 lines modifiedOffset 154, 27 lines modified
162 ··-·PCI-DSSv4-11.5.2154 ··-·PCI-DSSv4-11.5.2
163 ··-·enable_strategy155 ··-·enable_strategy
164 ··-·low_complexity156 ··-·low_complexity
165 ··-·low_disruption157 ··-·low_disruption
166 ··-·medium_severity158 ··-·medium_severity
167 ··-·no_reboot_needed159 ··-·no_reboot_needed
168 ··-·package_aide_installed160 ··-·package_aide_installed
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 166 #·Remediation·is·applicable·only·in·certain·platforms
 167 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
170 [[packages]] 
171 name·=·"aide" 
172 version·=·"*"168 zypper·install·-y·"aide"
  
 169 else
 170 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 171 fi
173 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*172 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
174 Run·the·following·command·to·generate·a·new·database:173 Run·the·following·command·to·generate·a·new·database:
175 $·sudo·/usr/bin/aide·--init174 $·sudo·/usr/bin/aide·--init
176 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the175 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the
177 configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these·files),·in·a·secure176 configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these·files),·in·a·secure
178 location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-177 location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-
179 generated·database·can·be·installed·as·follows:178 generated·database·can·be·installed·as·follows:
Offset 201, 29 lines modifiedOffset 201, 14 lines modified
201 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5201 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
202 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199202 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
203 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499203 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499
204 ·············_\x8c_\x8i_\x8s············1.4.1204 ·············_\x8c_\x8i_\x8s············1.4.1
205 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79205 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
206 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2206 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
207 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r880937_rule207 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r880937_rule
208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
209 #·Remediation·is·applicable·only·in·certain·platforms 
210 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
211 zypper·-q·--no-remote·ref 
  
  
212 zypper·install·-y·"aide" 
  
213 /usr/bin/aide·--init 
214 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db 
  
215 else 
216 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
217 fi 
218 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
219 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low209 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
220 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low210 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
221 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false211 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
222 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict212 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
223 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated213 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated
224 ··ansible.builtin.command:·zypper·-q·--no-remote·ref214 ··ansible.builtin.command:·zypper·-q·--no-remote·ref
Offset 319, 14 lines modifiedOffset 304, 29 lines modified
319 ··-·PCI-DSSv4-11.5.2304 ··-·PCI-DSSv4-11.5.2
320 ··-·aide_build_database305 ··-·aide_build_database
321 ··-·low_complexity306 ··-·low_complexity
322 ··-·low_disruption307 ··-·low_disruption
323 ··-·medium_severity308 ··-·medium_severity
324 ··-·no_reboot_needed309 ··-·no_reboot_needed
325 ··-·restrict_strategy310 ··-·restrict_strategy
 311 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 312 #·Remediation·is·applicable·only·in·certain·platforms
 313 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 314 zypper·-q·--no-remote·ref
  
  
 315 zypper·install·-y·"aide"
  
 316 /usr/bin/aide·--init
 317 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db
  
 318 else
Max diff block lines reached; 1462545/1467980 bytes (99.63%) of diff not shown.
20.9 MB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-anssi_bp28_enhanced.html
    
Offset 14343, 15 lines modifiedOffset 14343, 15 lines modified
00038060:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00038060:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00038070:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00038070:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00038080:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</00038080:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
00038090:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00038090:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
000380a0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft000380a0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
000380b0:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······000380b0:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
000380c0:·2020·2020·2020·2020·2020·2020·2020·2861················(a000380c0:·2020·2020·2020·2020·2020·2020·2020·2861················(a
000380d0:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)000380d0:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
000380e0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············000380e0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
000380f0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div000380f0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
00038100:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co00038100:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
00038110:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><00038110:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
00038120:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc00038120:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
00038130:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec00038130:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00038140:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00038140:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 15172, 129 lines modifiedOffset 15172, 129 lines modified
0003b430:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003b430:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003b440:·6d36·3333·3322·2074·6162·696e·6465·783d··m6333"·tabindex=0003b440:·6d36·3333·3322·2074·6162·696e·6465·783d··m6333"·tabindex=
0003b450:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003b450:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003b460:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003b460:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003b470:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003b470:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003b480:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003b480:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003b490:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003b490:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003b4a0:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s0003b4a0:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild
 0003b4b0:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp
 0003b4c0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0003b4d0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003b4e0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003b4f0:·6522·2069·643d·2269·646d·3633·3333·223e··e"·id="idm6333">
0003b4b0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003b4c0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003b4d0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003b4e0:·6170·7365·2220·6964·3d22·6964·6d36·3333··apse"·id="idm633 
0003b4f0:·3322·3e3c·7461·626c·6520·636c·6173·733d··3"><table·class= 
0003b500:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003b510:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003b520:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003b530:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003b540:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003b550:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b560:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003b570:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b580:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003b590:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003b5a0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
0003b5b0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003b5c0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003b5d0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003b5e0:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem0003b500:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa
 0003b510:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=·
 0003b520:·2261·6964·6522·0a76·6572·7369·6f6e·203d··"aide".version·=
0003b5f0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl 
0003b600:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c 
0003b610:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms 
0003b620:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc 
0003b630:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a 
0003b640:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/ 
0003b650:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·]; 
0003b660:·2074·6865·6e0a·0a7a·7970·7065·7220·696e···then..zypper·in 
0003b670:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide". 
0003b680:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a 
0003b690:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed 
0003b6a0:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap 
0003b6b0:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin 
0003b6c0:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.< 
0003b6d0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003b6e0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003b6f0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003b700:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003b710:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003b720:·2223·6964·6d36·3333·3422·2074·6162·696e··"#idm6334"·tabin 
0003b730:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003b740:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003b750:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003b760:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003b770:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003b780:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans 
0003b790:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·... 
0003b7a0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b7b0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b7c0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b7d0:·2269·646d·3633·3334·223e·3c74·6162·6c65··"idm6334"><table 
0003b7e0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003b7f0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003b800:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003b810:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003b820:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003b830:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b840:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003b850:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003b860:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b870:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003b880:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003b890:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003b8a0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0003b8b0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0003b8c0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003b8d0:·653e·2d20·6e61·6d65·3a20·456e·7375·7265··e>-·name:·Ensure 
0003b8e0:·2061·6964·6520·6973·2069·6e73·7461·6c6c···aide·is·install 
0003b8f0:·6564·0a20·2070·6163·6b61·6765·3a0a·2020··ed.··package:.·· 
0003b900:·2020·6e61·6d65·3a20·6169·6465·0a20·2020····name:·aide.··· 
0003b910:·2073·7461·7465·3a20·7072·6573·656e·740a···state:·present. 
0003b920:·2020·7768·656e·3a20·616e·7369·626c·655f····when:·ansible_ 
0003b930:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t 
0003b940:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc 
0003b950:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op 
0003b960:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman", 
0003b970:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].·· 
0003b980:·7461·6773·3a0a·2020·2d20·4343·452d·3833··tags:.··-·CCE-83 
0003b990:·3238·392d·390a·2020·2d20·434a·4953·2d35··289-9.··-·CJIS-5 
0003b9a0:·2e31·302e·312e·330a·2020·2d20·4449·5341··.10.1.3.··-·DISA 
0003b9b0:·2d53·5449·472d·534c·4553·2d31·352d·3031··-STIG-SLES-15-01 
0003b9c0:·3034·3139·0a20·202d·204e·4953·542d·3830··0419.··-·NIST-80 
0003b9d0:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··- 
0003b9e0:·2050·4349·2d44·5353·2d52·6571·2d31·312e···PCI-DSS-Req-11. 
0003b9f0:·350a·2020·2d20·5043·492d·4453·5376·342d··5.··-·PCI-DSSv4- 
0003ba00:·3131·2e35·2e32·0a20·202d·2065·6e61·626c··11.5.2.··-·enabl 
0003ba10:·655f·7374·7261·7465·6779·0a20·202d·206c··e_strategy.··-·l 
0003ba20:·6f77·5f63·6f6d·706c·6578·6974·790a·2020··ow_complexity.·· 
0003ba30:·2d20·6c6f·775f·6469·7372·7570·7469·6f6e··-·low_disruption 
0003ba40:·0a20·202d·206d·6564·6975·6d5f·7365·7665··.··-·medium_seve 
0003ba50:·7269·7479·0a20·202d·206e·6f5f·7265·626f··rity.··-·no_rebo 
0003ba60:·6f74·5f6e·6565·6465·640a·2020·2d20·7061··ot_needed.··-·pa 
0003ba70:·636b·6167·655f·6169·6465·5f69·6e73·7461··ckage_aide_insta 
0003ba80:·6c6c·6564·0a3c·2f63·6f64·653e·3c2f·7072··lled.</code></pr0003b530:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr
0003ba90:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class0003b540:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
0003baa0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes0003b550:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
Max diff block lines reached; 20004538/20022118 bytes (99.91%) of diff not shown.
1.76 MB
html2text {}
    
Offset 49, 15 lines modifiedOffset 49, 15 lines modified
49 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(enhanced)49 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(enhanced)
50 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_enhanced50 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_enhanced
51 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*51 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
52 ····*·cpe:/o:suse:linux_enterprise_desktop:1552 ····*·cpe:/o:suse:linux_enterprise_desktop:15
53 ····*·cpe:/o:suse:linux_enterprise_server:1553 ····*·cpe:/o:suse:linux_enterprise_server:15
54 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*54 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
55 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8455 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
56 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)56 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
57 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*57 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
58 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s58 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
59 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e59 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
60 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l60 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
61 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r61 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
62 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n62 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
63 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g63 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 134, 27 lines modifiedOffset 134, 19 lines modified
134 include·install_aide134 include·install_aide
  
135 class·install_aide·{135 class·install_aide·{
136 ··package·{·'aide':136 ··package·{·'aide':
137 ····ensure·=>·'installed',137 ····ensure·=>·'installed',
138 ··}138 ··}
139 }139 }
 140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
145 #·Remediation·is·applicable·only·in·certain·platforms 
146 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
147 zypper·install·-y·"aide" 
  
148 else 
149 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
150 fi141 [[packages]]
 142 name·=·"aide"
 143 version·=·"*"
151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low145 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low146 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false147 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable148 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
156 -·name:·Ensure·aide·is·installed149 -·name:·Ensure·aide·is·installed
157 ··package:150 ··package:
Offset 170, 19 lines modifiedOffset 162, 27 lines modified
170 ··-·PCI-DSSv4-11.5.2162 ··-·PCI-DSSv4-11.5.2
171 ··-·enable_strategy163 ··-·enable_strategy
172 ··-·low_complexity164 ··-·low_complexity
173 ··-·low_disruption165 ··-·low_disruption
174 ··-·medium_severity166 ··-·medium_severity
175 ··-·no_reboot_needed167 ··-·no_reboot_needed
176 ··-·package_aide_installed168 ··-·package_aide_installed
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 174 #·Remediation·is·applicable·only·in·certain·platforms
 175 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
178 [[packages]] 
179 name·=·"aide" 
180 version·=·"*"176 zypper·install·-y·"aide"
  
 177 else
 178 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 179 fi
181 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*180 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
182 Run·the·following·command·to·generate·a·new·database:181 Run·the·following·command·to·generate·a·new·database:
183 $·sudo·/usr/bin/aide·--init182 $·sudo·/usr/bin/aide·--init
184 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the183 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the
185 configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these·files),·in·a·secure184 configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these·files),·in·a·secure
186 location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-185 location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-
187 generated·database·can·be·installed·as·follows:186 generated·database·can·be·installed·as·follows:
Offset 209, 29 lines modifiedOffset 209, 14 lines modified
209 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5209 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
210 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199210 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
211 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419211 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419
212 ·············_\x8c_\x8i_\x8s············1.4.1212 ·············_\x8c_\x8i_\x8s············1.4.1
213 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79213 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
214 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2214 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
215 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r880967_rule215 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r880967_rule
216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
217 #·Remediation·is·applicable·only·in·certain·platforms 
218 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
219 zypper·-q·--no-remote·ref 
  
  
220 zypper·install·-y·"aide" 
  
221 /usr/bin/aide·--init 
222 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db 
  
223 else 
224 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
225 fi 
226 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
227 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low217 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
228 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low218 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
229 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false219 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
230 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict220 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
231 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated221 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated
232 ··ansible.builtin.command:·zypper·-q·--no-remote·ref222 ··ansible.builtin.command:·zypper·-q·--no-remote·ref
Offset 327, 14 lines modifiedOffset 312, 29 lines modified
327 ··-·PCI-DSSv4-11.5.2312 ··-·PCI-DSSv4-11.5.2
328 ··-·aide_build_database313 ··-·aide_build_database
329 ··-·low_complexity314 ··-·low_complexity
330 ··-·low_disruption315 ··-·low_disruption
331 ··-·medium_severity316 ··-·medium_severity
332 ··-·no_reboot_needed317 ··-·no_reboot_needed
333 ··-·restrict_strategy318 ··-·restrict_strategy
 319 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 320 #·Remediation·is·applicable·only·in·certain·platforms
 321 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 322 zypper·-q·--no-remote·ref
  
  
 323 zypper·install·-y·"aide"
  
 324 /usr/bin/aide·--init
 325 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db
  
 326 else
Max diff block lines reached; 1842812/1848119 bytes (99.71%) of diff not shown.
21.2 MB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-anssi_bp28_high.html
    
Offset 14342, 15 lines modifiedOffset 14342, 15 lines modified
00038050:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00038050:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00038060:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00038060:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00038070:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</00038070:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
00038080:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00038080:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
00038090:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft00038090:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
000380a0:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······000380a0:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
000380b0:·2020·2020·2020·2020·2020·2020·2020·2861················(a000380b0:·2020·2020·2020·2020·2020·2020·2020·2861················(a
000380c0:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)000380c0:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
000380d0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············000380d0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
000380e0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div000380e0:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
000380f0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co000380f0:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
00038100:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><00038100:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
00038110:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc00038110:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
00038120:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec00038120:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00038130:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00038130:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 15177, 130 lines modifiedOffset 15177, 130 lines modified
0003b480:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b480:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b490:·2369·646d·3633·3333·2220·7461·6269·6e64··#idm6333"·tabind0003b490:·2369·646d·3633·3333·2220·7461·6269·6e64··#idm6333"·tabind
0003b4a0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b4a0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b4b0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b4b0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b4c0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b4c0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b4d0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b4d0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b4e0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b4e0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b4f0:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel0003b4f0:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu
 0003b500:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn
 0003b510:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0003b520:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003b530:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003b540:·6170·7365·2220·6964·3d22·6964·6d36·3333··apse"·id="idm633
0003b500:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a> 
0003b510:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b520:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b530:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b540:·3633·3333·223e·3c74·6162·6c65·2063·6c61··6333"><table·cla 
0003b550:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003b560:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003b570:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003b580:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003b590:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003b5a0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b5b0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003b5c0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003b5d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b5e0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003b5f0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003b600:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003b610:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003b620:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003b630:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·0003b550:·3322·3e3c·7072·653e·3c63·6f64·653e·0a5b··3"><pre><code>.[
 0003b560:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name
 0003b570:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio
 0003b580:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code><
0003b640:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a 
0003b650:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i 
0003b660:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo 
0003b670:·726d·730a·6966·205b·2021·202d·6620·2f2e··rms.if·[·!·-f·/. 
0003b680:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp 
0003b690:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r 
0003b6a0:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv 
0003b6b0:·205d·3b20·7468·656e·0a0a·7a79·7070·6572···];·then..zypper 
0003b6c0:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid 
0003b6d0:·6522·0a0a·656c·7365·0a20·2020·2026·6774··e"..else.····&gt 
0003b6e0:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re 
0003b6f0:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not 
0003b700:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not 
0003b710:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f 
0003b720:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre>< 
0003b730:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003b740:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003b750:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003b760:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003b770:·6574·3d22·2369·646d·3633·3334·2220·7461··et="#idm6334"·ta 
0003b780:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003b790:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003b7a0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003b7b0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003b7c0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003b7d0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003b7e0:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet· 
0003b7f0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003b800:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003b810:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003b820:·6964·3d22·6964·6d36·3333·3422·3e3c·7461··id="idm6334"><ta 
0003b830:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003b840:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003b850:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003b860:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003b870:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003b880:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003b890:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b8a0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003b8b0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b8c0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003b8d0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003b8e0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b8f0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003b900:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0003b910:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003b920:·636f·6465·3e2d·206e·616d·653a·2045·6e73··code>-·name:·Ens 
0003b930:·7572·6520·6169·6465·2069·7320·696e·7374··ure·aide·is·inst 
0003b940:·616c·6c65·640a·2020·7061·636b·6167·653a··alled.··package: 
0003b950:·0a20·2020·206e·616d·653a·2061·6964·650a··.····name:·aide. 
0003b960:·2020·2020·7374·6174·653a·2070·7265·7365······state:·prese 
0003b970:·6e74·0a20·2077·6865·6e3a·2061·6e73·6962··nt.··when:·ansib 
0003b980:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio 
0003b990:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·[" 
0003b9a0:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",· 
0003b9b0:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma 
0003b9c0:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"] 
0003b9d0:·0a20·2074·6167·733a·0a20·202d·2043·4345··.··tags:.··-·CCE 
0003b9e0:·2d38·3332·3839·2d39·0a20·202d·2043·4a49··-83289-9.··-·CJI 
0003b9f0:·532d·352e·3130·2e31·2e33·0a20·202d·2044··S-5.10.1.3.··-·D 
0003ba00:·4953·412d·5354·4947·2d53·4c45·532d·3135··ISA-STIG-SLES-15 
0003ba10:·2d30·3130·3431·390a·2020·2d20·4e49·5354··-010419.··-·NIST 
0003ba20:·2d38·3030·2d35·332d·434d·2d36·2861·290a··-800-53-CM-6(a). 
0003ba30:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req- 
0003ba40:·3131·2e35·0a20·202d·2050·4349·2d44·5353··11.5.··-·PCI-DSS 
0003ba50:·7634·2d31·312e·352e·320a·2020·2d20·656e··v4-11.5.2.··-·en 
0003ba60:·6162·6c65·5f73·7472·6174·6567·790a·2020··able_strategy.·· 
0003ba70:·2d20·6c6f·775f·636f·6d70·6c65·7869·7479··-·low_complexity 
0003ba80:·0a20·202d·206c·6f77·5f64·6973·7275·7074··.··-·low_disrupt 
0003ba90:·696f·6e0a·2020·2d20·6d65·6469·756d·5f73··ion.··-·medium_s 
0003baa0:·6576·6572·6974·790a·2020·2d20·6e6f·5f72··everity.··-·no_r 
0003bab0:·6562·6f6f·745f·6e65·6564·6564·0a20·202d··eboot_needed.··- 
0003bac0:·2070·6163·6b61·6765·5f61·6964·655f·696e···package_aide_in 
0003bad0:·7374·616c·6c65·640a·3c2f·636f·6465·3e3c··stalled.</code>< 
0003bae0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl0003b590:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
Max diff block lines reached; 20300281/20317999 bytes (99.91%) of diff not shown.
1.81 MB
html2text {}
Max HTML report size reached
8.21 MB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-anssi_bp28_intermediary.html
    
Offset 14344, 15 lines modifiedOffset 14344, 15 lines modified
00038070:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00038070:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00038080:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00038080:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00038090:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</00038090:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
000380a0:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><000380a0:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
000380b0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft000380b0:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
000380c0:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······000380c0:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
000380d0:·2020·2020·2020·2020·2020·2020·2020·2861················(a000380d0:·2020·2020·2020·2020·2020·2020·2020·2861················(a
000380e0:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)000380e0:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
000380f0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············000380f0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00038100:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div00038100:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
00038110:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co00038110:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
00038120:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><00038120:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
00038130:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc00038130:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
00038140:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec00038140:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00038150:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00038150:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 15163, 129 lines modifiedOffset 15163, 129 lines modified
0003b3a0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b3a0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003b3b0:·646d·3633·3333·2220·7461·6269·6e64·6578··dm6333"·tabindex0003b3b0:·646d·3633·3333·2220·7461·6269·6e64·6578··dm6333"·tabindex
0003b3c0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b3c0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b3d0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b3d0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b3e0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b3e0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b3f0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b3f0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b400:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b400:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003b410:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·0003b410:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil
 0003b420:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip
 0003b430:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
 0003b440:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0003b450:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0003b460:·7365·2220·6964·3d22·6964·6d36·3333·3322··se"·id="idm6333"
0003b420:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003b430:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003b440:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003b450:·6c61·7073·6522·2069·643d·2269·646d·3633··lapse"·id="idm63 
0003b460:·3333·223e·3c74·6162·6c65·2063·6c61·7373··33"><table·class 
0003b470:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003b480:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003b490:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003b4a0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003b4b0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003b4c0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b4d0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003b4e0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003b4f0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b500:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003b510:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
0003b520:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003b530:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003b540:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003b550:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re0003b470:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p
 0003b480:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·=
 0003b490:·2022·6169·6465·220a·7665·7273·696f·6e20···"aide".version·
 0003b4a0:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p
0003b560:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app 
0003b570:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in· 
0003b580:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform 
0003b590:·730a·6966·205b·2021·202d·6620·2f2e·646f··s.if·[·!·-f·/.do 
0003b5a0:·636b·6572·656e·7620·5d20·2661·6d70·3b26··ckerenv·]·&amp;& 
0003b5b0:·616d·703b·205b·2021·202d·6620·2f72·756e··amp;·[·!·-f·/run 
0003b5c0:·2f2e·636f·6e74·6169·6e65·7265·6e76·205d··/.containerenv·] 
0003b5d0:·3b20·7468·656e·0a0a·7a79·7070·6572·2069··;·then..zypper·i 
0003b5e0:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide" 
0003b5f0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;& 
0003b600:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme 
0003b610:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a 
0003b620:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi 
0003b630:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi. 
0003b640:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003b650:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003b660:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003b670:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003b680:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003b690:·3d22·2369·646d·3633·3334·2220·7461·6269··="#idm6334"·tabi 
0003b6a0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003b6b0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003b6c0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003b6d0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003b6e0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003b6f0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An 
0003b700:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
0003b710:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b720:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b730:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b740:·3d22·6964·6d36·3333·3422·3e3c·7461·626c··="idm6334"><tabl 
0003b750:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003b760:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003b770:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003b780:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003b790:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003b7a0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b7b0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003b7c0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003b7d0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b7e0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003b7f0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003b800:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003b810:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003b820:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003b830:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003b840:·6465·3e2d·206e·616d·653a·2045·6e73·7572··de>-·name:·Ensur 
0003b850:·6520·6169·6465·2069·7320·696e·7374·616c··e·aide·is·instal 
0003b860:·6c65·640a·2020·7061·636b·6167·653a·0a20··led.··package:.· 
0003b870:·2020·206e·616d·653a·2061·6964·650a·2020·····name:·aide.·· 
0003b880:·2020·7374·6174·653a·2070·7265·7365·6e74····state:·present 
0003b890:·0a20·2077·6865·6e3a·2061·6e73·6962·6c65··.··when:·ansible 
0003b8a0:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_ 
0003b8b0:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do 
0003b8c0:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o 
0003b8d0:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman" 
0003b8e0:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].· 
0003b8f0:·2074·6167·733a·0a20·202d·2043·4345·2d38···tags:.··-·CCE-8 
0003b900:·3332·3839·2d39·0a20·202d·2043·4a49·532d··3289-9.··-·CJIS- 
0003b910:·352e·3130·2e31·2e33·0a20·202d·2044·4953··5.10.1.3.··-·DIS 
0003b920:·412d·5354·4947·2d53·4c45·532d·3135·2d30··A-STIG-SLES-15-0 
0003b930:·3130·3431·390a·2020·2d20·4e49·5354·2d38··10419.··-·NIST-8 
0003b940:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).·· 
0003b950:·2d20·5043·492d·4453·532d·5265·712d·3131··-·PCI-DSS-Req-11 
0003b960:·2e35·0a20·202d·2050·4349·2d44·5353·7634··.5.··-·PCI-DSSv4 
0003b970:·2d31·312e·352e·320a·2020·2d20·656e·6162··-11.5.2.··-·enab 
0003b980:·6c65·5f73·7472·6174·6567·790a·2020·2d20··le_strategy.··-· 
0003b990:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.· 
0003b9a0:·202d·206c·6f77·5f64·6973·7275·7074·696f···-·low_disruptio 
0003b9b0:·6e0a·2020·2d20·6d65·6469·756d·5f73·6576··n.··-·medium_sev 
0003b9c0:·6572·6974·790a·2020·2d20·6e6f·5f72·6562··erity.··-·no_reb 
0003b9d0:·6f6f·745f·6e65·6564·6564·0a20·202d·2070··oot_needed.··-·p 
0003b9e0:·6163·6b61·6765·5f61·6964·655f·696e·7374··ackage_aide_inst 
0003b9f0:·616c·6c65·640a·3c2f·636f·6465·3e3c·2f70··alled.</code></p 
0003ba00:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas0003b4b0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
Max diff block lines reached; 7678082/7695662 bytes (99.77%) of diff not shown.
896 KB
html2text {}
    
Offset 49, 15 lines modifiedOffset 49, 15 lines modified
49 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(intermediary)49 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(intermediary)
50 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_intermediary50 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_intermediary
51 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*51 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
52 ····*·cpe:/o:suse:linux_enterprise_desktop:1552 ····*·cpe:/o:suse:linux_enterprise_desktop:15
53 ····*·cpe:/o:suse:linux_enterprise_server:1553 ····*·cpe:/o:suse:linux_enterprise_server:15
54 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*54 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
55 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8455 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
56 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)56 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
57 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*57 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
58 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s58 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
59 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e59 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
60 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l60 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
61 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n61 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
62 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s62 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
63 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s63 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 134, 27 lines modifiedOffset 134, 19 lines modified
134 include·install_aide134 include·install_aide
  
135 class·install_aide·{135 class·install_aide·{
136 ··package·{·'aide':136 ··package·{·'aide':
137 ····ensure·=>·'installed',137 ····ensure·=>·'installed',
138 ··}138 ··}
139 }139 }
 140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
145 #·Remediation·is·applicable·only·in·certain·platforms 
146 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
147 zypper·install·-y·"aide" 
  
148 else 
149 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
150 fi141 [[packages]]
 142 name·=·"aide"
 143 version·=·"*"
151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low145 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low146 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false147 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable148 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
156 -·name:·Ensure·aide·is·installed149 -·name:·Ensure·aide·is·installed
157 ··package:150 ··package:
Offset 170, 19 lines modifiedOffset 162, 27 lines modified
170 ··-·PCI-DSSv4-11.5.2162 ··-·PCI-DSSv4-11.5.2
171 ··-·enable_strategy163 ··-·enable_strategy
172 ··-·low_complexity164 ··-·low_complexity
173 ··-·low_disruption165 ··-·low_disruption
174 ··-·medium_severity166 ··-·medium_severity
175 ··-·no_reboot_needed167 ··-·no_reboot_needed
176 ··-·package_aide_installed168 ··-·package_aide_installed
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 174 #·Remediation·is·applicable·only·in·certain·platforms
 175 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
178 [[packages]] 
179 name·=·"aide" 
180 version·=·"*"176 zypper·install·-y·"aide"
  
 177 else
 178 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 179 fi
181 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*180 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
182 Run·the·following·command·to·generate·a·new·database:181 Run·the·following·command·to·generate·a·new·database:
183 $·sudo·/usr/bin/aide·--init182 $·sudo·/usr/bin/aide·--init
184 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the183 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the
185 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these184 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these
186 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their185 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
187 integrity.·The·newly-generated·database·can·be·installed·as·follows:186 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 209, 29 lines modifiedOffset 209, 14 lines modified
209 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5209 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
210 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199210 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
211 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419211 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419
212 ·············_\x8c_\x8i_\x8s············1.4.1212 ·············_\x8c_\x8i_\x8s············1.4.1
213 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79213 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
214 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2214 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
215 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r880967_rule215 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r880967_rule
216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
217 #·Remediation·is·applicable·only·in·certain·platforms 
218 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
219 zypper·-q·--no-remote·ref 
  
  
220 zypper·install·-y·"aide" 
  
221 /usr/bin/aide·--init 
222 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db 
  
223 else 
224 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
225 fi 
226 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
227 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low217 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
228 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low218 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
229 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false219 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
230 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict220 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
231 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated221 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated
232 ··ansible.builtin.command:·zypper·-q·--no-remote·ref222 ··ansible.builtin.command:·zypper·-q·--no-remote·ref
Offset 327, 14 lines modifiedOffset 312, 29 lines modified
327 ··-·PCI-DSSv4-11.5.2312 ··-·PCI-DSSv4-11.5.2
328 ··-·aide_build_database313 ··-·aide_build_database
329 ··-·low_complexity314 ··-·low_complexity
330 ··-·low_disruption315 ··-·low_disruption
331 ··-·medium_severity316 ··-·medium_severity
332 ··-·no_reboot_needed317 ··-·no_reboot_needed
333 ··-·restrict_strategy318 ··-·restrict_strategy
 319 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 320 #·Remediation·is·applicable·only·in·certain·platforms
 321 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 322 zypper·-q·--no-remote·ref
  
  
 323 zypper·install·-y·"aide"
  
 324 /usr/bin/aide·--init
 325 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db
  
 326 else
Max diff block lines reached; 911692/917116 bytes (99.41%) of diff not shown.
2.02 MB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-anssi_bp28_minimal.html
    
Offset 14343, 15 lines modifiedOffset 14343, 15 lines modified
00038060:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre00038060:·6f72·793c·2f68·323e·3c70·3e43·7572·7265··ory</h2><p>Curre
00038070:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str00038070:·6e74·2076·6572·7369·6f6e·3a20·3c73·7472··nt·version:·<str
00038080:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro00038080:·6f6e·673e·302e·312e·3734·3c2f·7374·726f··ong>0.1.74</stro
00038090:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><00038090:·6e67·3e3c·2f70·3e3c·756c·3e3c·6c69·3e3c··ng></p><ul><li><
000380a0:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st000380a0:·7374·726f·6e67·3e64·7261·6674·3c2f·7374··strong>draft</st
000380b0:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········000380b0:·726f·6e67·3e0a·2020·2020·2020·2020·2020··rong>.··········
000380c0:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of000380c0:·2020·2020·2020·2020·2020·2861·7320·6f66············(as·of
000380d0:·2032·3032·362d·3031·2d30·3829·0a20·2020···2026-01-08).···000380d0:·2032·3032·342d·3132·2d30·3729·0a20·2020···2024-12-07).···
000380e0:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l000380e0:·2020·2020·2020·2020·2020·2020·203c·2f6c···············</l
000380f0:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h2000380f0:·693e·3c2f·756c·3e3c·2f64·6976·3e3c·6832··i></ul></div><h2
00038100:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten00038100:·3e54·6162·6c65·206f·6620·436f·6e74·656e··>Table·of·Conten
00038110:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><00038110:·7473·3c2f·6832·3e3c·6f6c·3e3c·6c69·3e3c··ts</h2><ol><li><
00038120:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o00038120:·6120·6872·6566·3d22·2378·6363·6466·5f6f··a·href="#xccdf_o
00038130:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co00038130:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co
00038140:·6e74·656e·745f·6772·6f75·705f·7379·7374··ntent_group_syst00038140:·6e74·656e·745f·6772·6f75·705f·7379·7374··ntent_group_syst
Offset 14833, 106 lines modifiedOffset 14833, 106 lines modified
00039f00:·2d74·6172·6765·743d·2223·6964·6d38·3839··-target="#idm88900039f00:·2d74·6172·6765·743d·2223·6964·6d38·3839··-target="#idm889
00039f10:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·00039f10:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·
00039f20:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar00039f20:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
00039f30:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal00039f30:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
00039f40:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ00039f40:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
00039f50:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h00039f50:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
00039f60:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia00039f60:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 00039f70:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu
 00039f80:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·.
 00039f90:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 00039fa0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 00039fb0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 00039fc0:·643d·2269·646d·3838·3932·223e·3c70·7265··d="idm8892"><pre
 00039fd0:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag
 00039fe0:·6573·5d5d·0a6e·616d·6520·3d20·2264·6e66··es]].name·=·"dnf
 00039ff0:·2d61·7574·6f6d·6174·6963·220a·7665·7273··-automatic".vers
 0003a000:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code
00039f70:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
00039f80:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
00039f90:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
00039fa0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
00039fb0:·2220·6964·3d22·6964·6d38·3839·3222·3e3c··"·id="idm8892">< 
00039fc0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
00039fd0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
00039fe0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
00039ff0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003a000:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003a010:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003a020:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003a030:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003a040:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003a050:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003a060:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003a070:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003a080:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003a090:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003a0a0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003a0b0:·3e3c·636f·6465·3e0a·7a79·7070·6572·2069··><code>.zypper·i 
0003a0c0:·6e73·7461·6c6c·202d·7920·2264·6e66·2d61··nstall·-y·"dnf-a 
0003a0d0:·7574·6f6d·6174·6963·220a·3c2f·636f·6465··utomatic".</code 
0003a0e0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0003a010:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
0003a0f0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0003a020:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
0003a100:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0003a030:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0003a110:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003a040:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
0003a120:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003a050:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003a130:·3838·3933·2220·7461·6269·6e64·6578·3d22··8893"·tabindex="0003a060:·3838·3933·2220·7461·6269·6e64·6578·3d22··8893"·tabindex="
0003a140:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003a070:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003a150:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003a080:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003a160:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003a090:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003a170:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003a0a0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003a180:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003a0b0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003a190:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible·0003a0c0:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible·
0003a1a0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003a0d0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003a1b0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003a0e0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003a1c0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003a0f0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003a1d0:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm80003a100:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
0003a1e0:·3839·3322·3e3c·7461·626c·6520·636c·6173··893"><table·clas0003a110:·3839·3322·3e3c·7461·626c·6520·636c·6173··893"><table·clas
0003a1f0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003a120:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003a200:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003a130:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003a210:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003a140:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003a220:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003a150:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003a230:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003a160:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003a240:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003a170:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003a250:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003a180:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003a260:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003a190:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003a270:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003a1a0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003a280:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003a1b0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003a290:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003a1c0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003a2a0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003a1d0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003a2b0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003a1e0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
0003a2c0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003a1f0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003a2d0:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n0003a200:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n
0003a2e0:·616d·653a·2045·6e73·7572·6520·646e·662d··ame:·Ensure·dnf-0003a210:·616d·653a·2045·6e73·7572·6520·646e·662d··ame:·Ensure·dnf-
0003a2f0:·6175·746f·6d61·7469·6320·6973·2069·6e73··automatic·is·ins0003a220:·6175·746f·6d61·7469·6320·6973·2069·6e73··automatic·is·ins
0003a300:·7461·6c6c·6564·0a20·2070·6163·6b61·6765··talled.··package0003a230:·7461·6c6c·6564·0a20·2070·6163·6b61·6765··talled.··package
0003a310:·3a0a·2020·2020·6e61·6d65·3a20·646e·662d··:.····name:·dnf-0003a240:·3a0a·2020·2020·6e61·6d65·3a20·646e·662d··:.····name:·dnf-
0003a320:·6175·746f·6d61·7469·630a·2020·2020·7374··automatic.····st0003a250:·6175·746f·6d61·7469·630a·2020·2020·7374··automatic.····st
0003a330:·6174·653a·2070·7265·7365·6e74·0a20·2074··ate:·present.··t0003a260:·6174·653a·2070·7265·7365·6e74·0a20·2074··ate:·present.··t
0003a340:·6167·733a·0a20·202d·2043·4345·2d39·3131··ags:.··-·CCE-9110003a270:·6167·733a·0a20·202d·2043·4345·2d39·3131··ags:.··-·CCE-911
0003a350:·3633·2d36·0a20·202d·2065·6e61·626c·655f··63-6.··-·enable_0003a280:·3633·2d36·0a20·202d·2065·6e61·626c·655f··63-6.··-·enable_
0003a360:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low0003a290:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low
0003a370:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-·0003a2a0:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-·
0003a380:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.·0003a2b0:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.·
0003a390:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi0003a2c0:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi
0003a3a0:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot0003a2d0:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot
0003a3b0:·5f6e·6565·6465·640a·2020·2d20·7061·636b··_needed.··-·pack0003a2e0:·5f6e·6565·6465·640a·2020·2d20·7061·636b··_needed.··-·pack
0003a3c0:·6167·655f·646e·662d·6175·746f·6d61·7469··age_dnf-automati0003a2f0:·6167·655f·646e·662d·6175·746f·6d61·7469··age_dnf-automati
0003a3d0:·635f·696e·7374·616c·6c65·640a·3c2f·636f··c_installed.</co0003a300:·635f·696e·7374·616c·6c65·640a·3c2f·636f··c_installed.</co
0003a3e0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><0003a310:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
0003a3f0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn0003a320:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
0003a400:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t0003a330:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
0003a410:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"0003a340:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
0003a420:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003a350:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003a430:·646d·3838·3934·2220·7461·6269·6e64·6578··dm8894"·tabindex0003a360:·646d·3838·3934·2220·7461·6269·6e64·6578··dm8894"·tabindex
0003a440:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003a370:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003a450:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003a380:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003a460:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003a390:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003a470:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003a3a0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003a480:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003a3b0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003a490:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil0003a3c0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
0003a4a0:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
0003a4b0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003a4c0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003a4d0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003a4e0:·7365·2220·6964·3d22·6964·6d38·3839·3422··se"·id="idm8894"0003a3d0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 0003a3e0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003a3f0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003a400:·6c61·7073·6522·2069·643d·2269·646d·3838··lapse"·id="idm88
 0003a410:·3934·223e·3c74·6162·6c65·2063·6c61·7373··94"><table·class
 0003a420:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003a430:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
Max diff block lines reached; 1952990/1967396 bytes (99.27%) of diff not shown.
144 KB
html2text {}
    
Offset 49, 15 lines modifiedOffset 49, 15 lines modified
49 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(minimal)49 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·ANSSI-BP-028·(minimal)
50 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_minimal50 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_anssi_bp28_minimal
51 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*51 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
52 ····*·cpe:/o:suse:linux_enterprise_desktop:1552 ····*·cpe:/o:suse:linux_enterprise_desktop:15
53 ····*·cpe:/o:suse:linux_enterprise_server:1553 ····*·cpe:/o:suse:linux_enterprise_server:15
54 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*54 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
55 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8455 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
56 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)56 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
57 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*57 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
58 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s58 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
59 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e59 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
60 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l60 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
61 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s61 ·········3.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
62 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s62 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
63 ·········1.·_\x8D_\x8H_\x8C_\x8P63 ·········1.·_\x8D_\x8H_\x8C_\x8P
Offset 99, 21 lines modifiedOffset 99, 19 lines modified
99 include·install_dnf-automatic99 include·install_dnf-automatic
  
100 class·install_dnf-automatic·{100 class·install_dnf-automatic·{
101 ··package·{·'dnf-automatic':101 ··package·{·'dnf-automatic':
102 ····ensure·=>·'installed',102 ····ensure·=>·'installed',
103 ··}103 ··}
104 }104 }
 105 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
105 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
106 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
107 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
108 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
109 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
110 zypper·install·-y·"dnf-automatic"106 [[packages]]
 107 name·=·"dnf-automatic"
 108 version·=·"*"
111 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8109 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
112 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low110 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
113 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low111 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
114 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false112 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
115 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable113 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
116 -·name:·Ensure·dnf-automatic·is·installed114 -·name:·Ensure·dnf-automatic·is·installed
117 ··package:115 ··package:
Offset 123, 19 lines modifiedOffset 121, 21 lines modified
123 ··-·CCE-91163-6121 ··-·CCE-91163-6
124 ··-·enable_strategy122 ··-·enable_strategy
125 ··-·low_complexity123 ··-·low_complexity
126 ··-·low_disruption124 ··-·low_disruption
127 ··-·medium_severity125 ··-·medium_severity
128 ··-·no_reboot_needed126 ··-·no_reboot_needed
129 ··-·package_dnf-automatic_installed127 ··-·package_dnf-automatic_installed
130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 133 zypper·install·-y·"dnf-automatic"
131 [[packages]] 
132 name·=·"dnf-automatic" 
133 version·=·"*" 
134 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*134 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
135 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically135 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically
136 installed·by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/136 installed·by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
137 automatic.conf.137 automatic.conf.
138 ·············Installing·software·updates·is·a·fundamental·mitigation·against·the138 ·············Installing·software·updates·is·a·fundamental·mitigation·against·the
139 ·············exploitation·of·publicly-known·vulnerabilities.·If·the·most·recent·security139 ·············exploitation·of·publicly-known·vulnerabilities.·If·the·most·recent·security
140 Rationale:···patches·and·updates·are·not·installed,·unauthorized·users·may·take·advantage140 Rationale:···patches·and·updates·are·not·installed,·unauthorized·users·may·take·advantage
Offset 146, 14 lines modifiedOffset 146, 37 lines modified
146 Rule·ID:·····xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates146 Rule·ID:·····xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates
147 Identifiers:·CCE-91165-1147 Identifiers:·CCE-91165-1
148 ·············_\x8i_\x8s_\x8m····0940,·1144,·1467,·1472,·1483,·1493,·1494,·1495148 ·············_\x8i_\x8s_\x8m····0940,·1144,·1467,·1472,·1483,·1493,·1494,·1495
149 ·············_\x8n_\x8i_\x8s_\x8t···SI-2(5),·CM-6(a),·SI-2(c)149 ·············_\x8n_\x8i_\x8s_\x8t···SI-2(5),·CM-6(a),·SI-2(c)
150 References:··_\x8o_\x8s_\x8p_\x8p···FMT_SMF_EXT.1150 References:··_\x8o_\x8s_\x8p_\x8p···FMT_SMF_EXT.1
151 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080151 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
152 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61152 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
 153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 154 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 155 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 156 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 157 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···unknown
 158 -·name:·Configure·dnf-automatic·to·Install·Available·Updates·Automatically
 159 ··ini_file:
 160 ····dest:·/etc/dnf/automatic.conf
 161 ····section:·commands
 162 ····option:·apply_updates
 163 ····value:·'yes'
 164 ····create:·true
 165 ··tags:
 166 ··-·CCE-91165-1
 167 ··-·NIST-800-53-CM-6(a)
 168 ··-·NIST-800-53-SI-2(5)
 169 ··-·NIST-800-53-SI-2(c)
 170 ··-·dnf-automatic_apply_updates
 171 ··-·low_complexity
 172 ··-·medium_disruption
 173 ··-·medium_severity
 174 ··-·no_reboot_needed
 175 ··-·unknown_strategy
153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
154 found=false177 found=false
  
155 #·set·value·in·all·files·if·they·contain·section·or·key178 #·set·value·in·all·files·if·they·contain·section·or·key
156 for·f·in·$(echo·-n·"/etc/dnf/automatic.conf");·do179 for·f·in·$(echo·-n·"/etc/dnf/automatic.conf");·do
157 ····if·[·!·-e·"$f"·];·then180 ····if·[·!·-e·"$f"·];·then
Offset 182, 50 lines modifiedOffset 205, 50 lines modified
182 if·!·$found·;·then205 if·!·$found·;·then
183 ····file=$(echo·"/etc/dnf/automatic.conf"·|·cut·-f1·-d·'·')206 ····file=$(echo·"/etc/dnf/automatic.conf"·|·cut·-f1·-d·'·')
184 ····mkdir·-p·"$(dirname·"$file")"207 ····mkdir·-p·"$(dirname·"$file")"
  
185 ····echo·-e·"[commands]\napply_updates=yes"·>>·"$file"208 ····echo·-e·"[commands]\napply_updates=yes"·>>·"$file"
  
186 fi209 fi
 210 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·O\x8On\x8nl\x8ly\x8y·S\x8Se\x8ec\x8cu\x8ur\x8ri\x8it\x8ty\x8y·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
 211 To·configure·dnf-automatic·to·install·only·security·updates·automatically,·set
 212 upgrade_type·to·security·under·[commands]·section·in·/etc/dnf/automatic.conf.
 213 ·············By·default,·dnf-automatic·installs·all·available·updates.·Reducing·the·amount
 214 Rationale:···of·updated·packages·only·to·updates·that·were·issued·as·a·part·of·a·security
 215 ·············advisory·increases·the·system·stability.
 216 Severity: ···low
 217 Rule·ID:·····xccdf_org.ssgproject.content_rule_dnf-automatic_security_updates_only
 218 Identifiers:·CCE-91166-9
 219 ·············_\x8n_\x8i_\x8s_\x8t···SI-2(5),·CM-6(a),·SI-2(c)
 220 References:··_\x8o_\x8s_\x8p_\x8p···FMT_SMF_EXT.1
 221 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
 222 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8223 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low224 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium225 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
Max diff block lines reached; 141716/147615 bytes (96.00%) of diff not shown.
20.3 MB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-cis.html
    
Offset 14312, 15 lines modifiedOffset 14312, 15 lines modified
00037e70:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·00037e70:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·
00037e80:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong00037e80:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong
00037e90:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>00037e90:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>
00037ea0:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str00037ea0:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str
00037eb0:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron00037eb0:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron
00037ec0:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············00037ec0:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············
00037ed0:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·2000037ed0:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·20
00037ee0:·3236·2d30·312d·3038·290a·2020·2020·2020··26-01-08).······00037ee0:·3234·2d31·322d·3037·290a·2020·2020·2020··24-12-07).······
00037ef0:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><00037ef0:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><
00037f00:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta00037f00:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta
00037f10:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<00037f10:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<
00037f20:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h00037f20:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h
00037f30:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.00037f30:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.
00037f40:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte00037f40:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte
00037f50:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"00037f50:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"
Offset 15209, 129 lines modifiedOffset 15209, 129 lines modified
0003b680:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003b680:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b690:·6964·6d36·3333·3322·2074·6162·696e·6465··idm6333"·tabinde0003b690:·6964·6d36·3333·3322·2074·6162·696e·6465··idm6333"·tabinde
0003b6a0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b6a0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003b6b0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003b6b0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003b6c0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003b6c0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003b6d0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003b6d0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003b6e0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003b6e0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003b6f0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell0003b6f0:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui
 0003b700:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni
 0003b710:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0003b720:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003b730:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003b740:·7073·6522·2069·643d·2269·646d·3633·3333··pse"·id="idm6333
0003b700:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003b710:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b720:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b730:·6c6c·6170·7365·2220·6964·3d22·6964·6d36··llapse"·id="idm6 
0003b740:·3333·3322·3e3c·7461·626c·6520·636c·6173··333"><table·clas 
0003b750:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b760:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b770:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b780:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b790:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b7a0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b7b0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b7c0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b7d0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b7e0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b7f0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003b800:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b810:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b820:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b830:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R0003b750:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[
 0003b760:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name·
 0003b770:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version
 0003b780:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></
0003b840:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003b850:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003b860:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003b870:·6d73·0a69·6620·5b20·2120·2d66·202f·2e64··ms.if·[·!·-f·/.d 
0003b880:·6f63·6b65·7265·6e76·205d·2026·616d·703b··ockerenv·]·&amp; 
0003b890:·2661·6d70·3b20·5b20·2120·2d66·202f·7275··&amp;·[·!·-f·/ru 
0003b8a0:·6e2f·2e63·6f6e·7461·696e·6572·656e·7620··n/.containerenv· 
0003b8b0:·5d3b·2074·6865·6e0a·0a7a·7970·7065·7220··];·then..zypper· 
0003b8c0:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide 
0003b8d0:·220a·0a65·6c73·650a·2020·2020·2667·743b··"..else.····&gt; 
0003b8e0:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem 
0003b8f0:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not· 
0003b900:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth 
0003b910:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi 
0003b920:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003b930:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b940:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b950:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b960:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b970:·743d·2223·6964·6d36·3333·3422·2074·6162··t="#idm6334"·tab 
0003b980:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b990:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b9a0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b9b0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b9c0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b9d0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A 
0003b9e0:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
0003b9f0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003ba00:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003ba10:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003ba20:·643d·2269·646d·3633·3334·223e·3c74·6162··d="idm6334"><tab 
0003ba30:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003ba40:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003ba50:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003ba60:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003ba70:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003ba80:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003ba90:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003baa0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003bab0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003bac0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003bad0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003bae0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003baf0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003bb00:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003bb10:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003bb20:·6f64·653e·2d20·6e61·6d65·3a20·456e·7375··ode>-·name:·Ensu 
0003bb30:·7265·2061·6964·6520·6973·2069·6e73·7461··re·aide·is·insta 
0003bb40:·6c6c·6564·0a20·2070·6163·6b61·6765·3a0a··lled.··package:. 
0003bb50:·2020·2020·6e61·6d65·3a20·6169·6465·0a20······name:·aide.· 
0003bb60:·2020·2073·7461·7465·3a20·7072·6573·656e·····state:·presen 
0003bb70:·740a·2020·7768·656e·3a20·616e·7369·626c··t.··when:·ansibl 
0003bb80:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization 
0003bb90:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d 
0003bba0:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·" 
0003bbb0:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman 
0003bbc0:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"]. 
0003bbd0:·2020·7461·6773·3a0a·2020·2d20·4343·452d····tags:.··-·CCE- 
0003bbe0:·3833·3238·392d·390a·2020·2d20·434a·4953··83289-9.··-·CJIS 
0003bbf0:·2d35·2e31·302e·312e·330a·2020·2d20·4449··-5.10.1.3.··-·DI 
0003bc00:·5341·2d53·5449·472d·534c·4553·2d31·352d··SA-STIG-SLES-15- 
0003bc10:·3031·3034·3139·0a20·202d·204e·4953·542d··010419.··-·NIST- 
0003bc20:·3830·302d·3533·2d43·4d2d·3628·6129·0a20··800-53-CM-6(a).· 
0003bc30:·202d·2050·4349·2d44·5353·2d52·6571·2d31···-·PCI-DSS-Req-1 
0003bc40:·312e·350a·2020·2d20·5043·492d·4453·5376··1.5.··-·PCI-DSSv 
0003bc50:·342d·3131·2e35·2e32·0a20·202d·2065·6e61··4-11.5.2.··-·ena 
0003bc60:·626c·655f·7374·7261·7465·6779·0a20·202d··ble_strategy.··- 
0003bc70:·206c·6f77·5f63·6f6d·706c·6578·6974·790a···low_complexity. 
0003bc80:·2020·2d20·6c6f·775f·6469·7372·7570·7469····-·low_disrupti 
0003bc90:·6f6e·0a20·202d·206d·6564·6975·6d5f·7365··on.··-·medium_se 
0003bca0:·7665·7269·7479·0a20·202d·206e·6f5f·7265··verity.··-·no_re 
0003bcb0:·626f·6f74·5f6e·6565·6465·640a·2020·2d20··boot_needed.··-· 
0003bcc0:·7061·636b·6167·655f·6169·6465·5f69·6e73··package_aide_ins 
0003bcd0:·7461·6c6c·6564·0a3c·2f63·6f64·653e·3c2f··talled.</code></ 
0003bce0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla0003b790:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
Max diff block lines reached; 19384579/19402159 bytes (99.91%) of diff not shown.
1.78 MB
html2text {}
Max HTML report size reached
8.89 MB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-cis_server_l1.html
    
Offset 14312, 16 lines modifiedOffset 14312, 16 lines modified
00037e70:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><00037e70:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><
00037e80:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio00037e80:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio
00037e90:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.700037e90:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.7
00037ea0:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u00037ea0:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u
00037eb0:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr00037eb0:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr
00037ec0:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···00037ec0:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···
00037ed0:·2020·2020·2020·2020·2020·2020·2020·2020··················00037ed0:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037ee0:·2028·6173·206f·6620·3230·3236·2d30·312d···(as·of·2026-01-00037ee0:·2028·6173·206f·6620·3230·3234·2d31·322d···(as·of·2024-12-
00037ef0:·3038·290a·2020·2020·2020·2020·2020·2020··08).············00037ef0:·3037·290a·2020·2020·2020·2020·2020·2020··07).············
00037f00:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></00037f00:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></
00037f10:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of00037f10:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of
00037f20:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o00037f20:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o
00037f30:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#00037f30:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#
00037f40:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro00037f40:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro
00037f50:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro00037f50:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro
00037f60:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste00037f60:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste
Offset 15187, 130 lines modifiedOffset 15187, 130 lines modified
0003b520:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b520:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b530:·3d22·2369·646d·3633·3333·2220·7461·6269··="#idm6333"·tabi0003b530:·3d22·2369·646d·3633·3333·2220·7461·6269··="#idm6333"·tabi
0003b540:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b540:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b550:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b550:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b560:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b560:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b570:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b570:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b580:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b580:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b590:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh0003b590:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
 0003b5a0:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint·
 0003b5b0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003b5c0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003b5d0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b5e0:·6c6c·6170·7365·2220·6964·3d22·6964·6d36··llapse"·id="idm6
0003b5a0:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</ 
0003b5b0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003b5c0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003b5d0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003b5e0:·646d·3633·3333·223e·3c74·6162·6c65·2063··dm6333"><table·c 
0003b5f0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003b600:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003b610:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003b620:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003b630:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003b640:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b650:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003b660:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003b670:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b680:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003b690:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0003b6a0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003b6b0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003b6c0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003b6d0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003b5f0:·3333·3322·3e3c·7072·653e·3c63·6f64·653e··333"><pre><code>
 0003b600:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na
 0003b610:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers
 0003b620:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code
0003b6e0:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is 
0003b6f0:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only 
0003b700:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat 
0003b710:·666f·726d·730a·6966·205b·2021·202d·6620··forms.if·[·!·-f· 
0003b720:·2f2e·646f·636b·6572·656e·7620·5d20·2661··/.dockerenv·]·&a 
0003b730:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f· 
0003b740:·2f72·756e·2f2e·636f·6e74·6169·6e65·7265··/run/.containere 
0003b750:·6e76·205d·3b20·7468·656e·0a0a·7a79·7070··nv·];·then..zypp 
0003b760:·6572·2069·6e73·7461·6c6c·202d·7920·2261··er·install·-y·"a 
0003b770:·6964·6522·0a0a·656c·7365·0a20·2020·2026··ide"..else.····& 
0003b780:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·' 
0003b790:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n 
0003b7a0:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n 
0003b7b0:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done' 
0003b7c0:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre 
0003b7d0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003b7e0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003b7f0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003b800:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003b810:·7267·6574·3d22·2369·646d·3633·3334·2220··rget="#idm6334"· 
0003b820:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003b830:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003b840:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003b850:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003b860:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003b870:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003b880:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe 
0003b890:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003b8a0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003b8b0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003b8c0:·2220·6964·3d22·6964·6d36·3333·3422·3e3c··"·id="idm6334">< 
0003b8d0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003b8e0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003b8f0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003b900:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003b910:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003b920:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003b930:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b940:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003b950:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b960:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003b970:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003b980:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b990:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003b9a0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003b9b0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003b9c0:·3e3c·636f·6465·3e2d·206e·616d·653a·2045··><code>-·name:·E 
0003b9d0:·6e73·7572·6520·6169·6465·2069·7320·696e··nsure·aide·is·in 
0003b9e0:·7374·616c·6c65·640a·2020·7061·636b·6167··stalled.··packag 
0003b9f0:·653a·0a20·2020·206e·616d·653a·2061·6964··e:.····name:·aid 
0003ba00:·650a·2020·2020·7374·6174·653a·2070·7265··e.····state:·pre 
0003ba10:·7365·6e74·0a20·2077·6865·6e3a·2061·6e73··sent.··when:·ans 
0003ba20:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat 
0003ba30:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in· 
0003ba40:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc" 
0003ba50:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod 
0003ba60:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container 
0003ba70:·225d·0a20·2074·6167·733a·0a20·202d·2043··"].··tags:.··-·C 
0003ba80:·4345·2d38·3332·3839·2d39·0a20·202d·2043··CE-83289-9.··-·C 
0003ba90:·4a49·532d·352e·3130·2e31·2e33·0a20·202d··JIS-5.10.1.3.··- 
0003baa0:·2044·4953·412d·5354·4947·2d53·4c45·532d···DISA-STIG-SLES- 
0003bab0:·3135·2d30·3130·3431·390a·2020·2d20·4e49··15-010419.··-·NI 
0003bac0:·5354·2d38·3030·2d35·332d·434d·2d36·2861··ST-800-53-CM-6(a 
0003bad0:·290a·2020·2d20·5043·492d·4453·532d·5265··).··-·PCI-DSS-Re 
0003bae0:·712d·3131·2e35·0a20·202d·2050·4349·2d44··q-11.5.··-·PCI-D 
0003baf0:·5353·7634·2d31·312e·352e·320a·2020·2d20··SSv4-11.5.2.··-· 
0003bb00:·656e·6162·6c65·5f73·7472·6174·6567·790a··enable_strategy. 
0003bb10:·2020·2d20·6c6f·775f·636f·6d70·6c65·7869····-·low_complexi 
0003bb20:·7479·0a20·202d·206c·6f77·5f64·6973·7275··ty.··-·low_disru 
0003bb30:·7074·696f·6e0a·2020·2d20·6d65·6469·756d··ption.··-·medium 
0003bb40:·5f73·6576·6572·6974·790a·2020·2d20·6e6f··_severity.··-·no 
0003bb50:·5f72·6562·6f6f·745f·6e65·6564·6564·0a20··_reboot_needed.· 
0003bb60:·202d·2070·6163·6b61·6765·5f61·6964·655f···-·package_aide_ 
0003bb70:·696e·7374·616c·6c65·640a·3c2f·636f·6465··installed.</code 
Max diff block lines reached; 8272771/8290627 bytes (99.78%) of diff not shown.
1000 KB
html2text {}
    
Offset 42, 15 lines modifiedOffset 42, 15 lines modified
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·SUSE·Linux·Enterprise·15·Benchmark·for·Level·1·-·Server42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·SUSE·Linux·Enterprise·15·Benchmark·for·Level·1·-·Server
43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_server_l143 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_server_l1
44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
45 ····*·cpe:/o:suse:linux_enterprise_desktop:1545 ····*·cpe:/o:suse:linux_enterprise_desktop:15
46 ····*·cpe:/o:suse:linux_enterprise_server:1546 ····*·cpe:/o:suse:linux_enterprise_server:15
47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
48 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8448 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
54 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r54 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
55 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n55 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
56 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g56 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 137, 27 lines modifiedOffset 137, 19 lines modified
137 include·install_aide137 include·install_aide
  
138 class·install_aide·{138 class·install_aide·{
139 ··package·{·'aide':139 ··package·{·'aide':
140 ····ensure·=>·'installed',140 ····ensure·=>·'installed',
141 ··}141 ··}
142 }142 }
 143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
144 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
145 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
146 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
147 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
148 #·Remediation·is·applicable·only·in·certain·platforms 
149 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
150 zypper·install·-y·"aide" 
  
151 else 
152 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
153 fi144 [[packages]]
 145 name·=·"aide"
 146 version·=·"*"
154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8147 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low148 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low149 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false150 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable151 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
159 -·name:·Ensure·aide·is·installed152 -·name:·Ensure·aide·is·installed
160 ··package:153 ··package:
Offset 173, 19 lines modifiedOffset 165, 27 lines modified
173 ··-·PCI-DSSv4-11.5.2165 ··-·PCI-DSSv4-11.5.2
174 ··-·enable_strategy166 ··-·enable_strategy
175 ··-·low_complexity167 ··-·low_complexity
176 ··-·low_disruption168 ··-·low_disruption
177 ··-·medium_severity169 ··-·medium_severity
178 ··-·no_reboot_needed170 ··-·no_reboot_needed
179 ··-·package_aide_installed171 ··-·package_aide_installed
180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 177 #·Remediation·is·applicable·only·in·certain·platforms
 178 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
181 [[packages]] 
182 name·=·"aide" 
183 version·=·"*"179 zypper·install·-y·"aide"
  
 180 else
 181 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 182 fi
184 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*183 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
185 Run·the·following·command·to·generate·a·new·database:184 Run·the·following·command·to·generate·a·new·database:
186 $·sudo·/usr/bin/aide·--init185 $·sudo·/usr/bin/aide·--init
187 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the186 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the
188 configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these·files),·in·a·secure187 configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these·files),·in·a·secure
189 location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-188 location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-
190 generated·database·can·be·installed·as·follows:189 generated·database·can·be·installed·as·follows:
Offset 212, 29 lines modifiedOffset 212, 14 lines modified
212 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5212 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
213 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199213 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
214 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419214 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419
215 ·············_\x8c_\x8i_\x8s············1.4.1215 ·············_\x8c_\x8i_\x8s············1.4.1
216 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79216 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
217 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2217 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
218 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r880967_rule218 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r880967_rule
219 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
220 #·Remediation·is·applicable·only·in·certain·platforms 
221 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
222 zypper·-q·--no-remote·ref 
  
  
223 zypper·install·-y·"aide" 
  
224 /usr/bin/aide·--init 
225 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db 
  
226 else 
227 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
228 fi 
229 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8219 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
230 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low220 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
231 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low221 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
232 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false222 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
233 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict223 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
234 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated224 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated
235 ··ansible.builtin.command:·zypper·-q·--no-remote·ref225 ··ansible.builtin.command:·zypper·-q·--no-remote·ref
Offset 330, 14 lines modifiedOffset 315, 29 lines modified
330 ··-·PCI-DSSv4-11.5.2315 ··-·PCI-DSSv4-11.5.2
331 ··-·aide_build_database316 ··-·aide_build_database
332 ··-·low_complexity317 ··-·low_complexity
333 ··-·low_disruption318 ··-·low_disruption
334 ··-·medium_severity319 ··-·medium_severity
335 ··-·no_reboot_needed320 ··-·no_reboot_needed
336 ··-·restrict_strategy321 ··-·restrict_strategy
 322 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 323 #·Remediation·is·applicable·only·in·certain·platforms
 324 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 325 zypper·-q·--no-remote·ref
  
  
 326 zypper·install·-y·"aide"
  
 327 /usr/bin/aide·--init
 328 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db
  
 329 else
Max diff block lines reached; 1022567/1028037 bytes (99.47%) of diff not shown.
8.65 MB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-cis_workstation_l1.html
    
Offset 14313, 16 lines modifiedOffset 14313, 16 lines modified
00037e80:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00037e80:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00037e90:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00037e90:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00037ea0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000037ea0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00037eb0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></00037eb0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
00037ec0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00037ec0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00037ed0:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00037ed0:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00037ee0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037ee0:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037ef0:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600037ef0:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
00037f00:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········00037f00:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00037f10:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00037f10:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00037f20:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00037f20:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00037f30:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00037f30:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00037f40:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00037f40:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00037f50:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00037f50:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00037f60:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00037f60:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00037f70:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00037f70:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
Offset 15174, 129 lines modifiedOffset 15174, 129 lines modified
0003b450:·6574·3d22·2369·646d·3633·3333·2220·7461··et="#idm6333"·ta0003b450:·6574·3d22·2369·646d·3633·3333·2220·7461··et="#idm6333"·ta
0003b460:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003b460:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003b470:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003b470:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003b480:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003b480:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003b490:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003b490:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003b4a0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003b4a0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003b4b0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003b4b0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003b4c0:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin
 0003b4d0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 0003b4e0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003b4f0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003b500:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003b510:·6d36·3333·3322·3e3c·7072·653e·3c63·6f64··m6333"><pre><cod
 0003b520:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]].
 0003b530:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve
 0003b540:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co
0003b4c0:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
0003b4d0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b4e0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b4f0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b500:·2269·646d·3633·3333·223e·3c74·6162·6c65··"idm6333"><table 
0003b510:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003b520:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003b530:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003b540:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003b550:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003b560:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b570:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003b580:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003b590:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b5a0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003b5b0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003b5c0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003b5d0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0003b5e0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0003b5f0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003b600:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation· 
0003b610:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on 
0003b620:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl 
0003b630:·6174·666f·726d·730a·6966·205b·2021·202d··atforms.if·[·!·- 
0003b640:·6620·2f2e·646f·636b·6572·656e·7620·5d20··f·/.dockerenv·]· 
0003b650:·2661·6d70·3b26·616d·703b·205b·2021·202d··&amp;&amp;·[·!·- 
0003b660:·6620·2f72·756e·2f2e·636f·6e74·6169·6e65··f·/run/.containe 
0003b670:·7265·6e76·205d·3b20·7468·656e·0a0a·7a79··renv·];·then..zy 
0003b680:·7070·6572·2069·6e73·7461·6c6c·202d·7920··pper·install·-y· 
0003b690:·2261·6964·6522·0a0a·656c·7365·0a20·2020··"aide"..else.··· 
0003b6a0:·2026·6774·3b26·616d·703b·3220·6563·686f···&gt;&amp;2·echo 
0003b6b0:·2027·5265·6d65·6469·6174·696f·6e20·6973···'Remediation·is 
0003b6c0:·206e·6f74·2061·7070·6c69·6361·626c·652c···not·applicable, 
0003b6d0:·206e·6f74·6869·6e67·2077·6173·2064·6f6e···nothing·was·don 
0003b6e0:·6527·0a66·690a·3c2f·636f·6465·3e3c·2f70··e'.fi.</code></p 
0003b6f0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003b700:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003b710:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003b720:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003b730:·7461·7267·6574·3d22·2369·646d·3633·3334··target="#idm6334 
0003b740:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003b750:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003b760:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003b770:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003b780:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003b790:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003b7a0:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip 
0003b7b0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003b7c0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b7d0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b7e0:·7365·2220·6964·3d22·6964·6d36·3333·3422··se"·id="idm6334" 
0003b7f0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003b800:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003b810:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003b820:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003b830:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003b840:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003b850:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b860:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003b870:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b880:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003b890:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003b8a0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003b8b0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003b8c0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003b8d0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003b8e0:·7265·3e3c·636f·6465·3e2d·206e·616d·653a··re><code>-·name: 
0003b8f0:·2045·6e73·7572·6520·6169·6465·2069·7320···Ensure·aide·is· 
0003b900:·696e·7374·616c·6c65·640a·2020·7061·636b··installed.··pack 
0003b910:·6167·653a·0a20·2020·206e·616d·653a·2061··age:.····name:·a 
0003b920:·6964·650a·2020·2020·7374·6174·653a·2070··ide.····state:·p 
0003b930:·7265·7365·6e74·0a20·2077·6865·6e3a·2061··resent.··when:·a 
0003b940:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz 
0003b950:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i 
0003b960:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx 
0003b970:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p 
0003b980:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain 
0003b990:·6572·225d·0a20·2074·6167·733a·0a20·202d··er"].··tags:.··- 
0003b9a0:·2043·4345·2d38·3332·3839·2d39·0a20·202d···CCE-83289-9.··- 
0003b9b0:·2043·4a49·532d·352e·3130·2e31·2e33·0a20···CJIS-5.10.1.3.· 
0003b9c0:·202d·2044·4953·412d·5354·4947·2d53·4c45···-·DISA-STIG-SLE 
0003b9d0:·532d·3135·2d30·3130·3431·390a·2020·2d20··S-15-010419.··-· 
0003b9e0:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6 
0003b9f0:·2861·290a·2020·2d20·5043·492d·4453·532d··(a).··-·PCI-DSS- 
0003ba00:·5265·712d·3131·2e35·0a20·202d·2050·4349··Req-11.5.··-·PCI 
0003ba10:·2d44·5353·7634·2d31·312e·352e·320a·2020··-DSSv4-11.5.2.·· 
0003ba20:·2d20·656e·6162·6c65·5f73·7472·6174·6567··-·enable_strateg 
0003ba30:·790a·2020·2d20·6c6f·775f·636f·6d70·6c65··y.··-·low_comple 
0003ba40:·7869·7479·0a20·202d·206c·6f77·5f64·6973··xity.··-·low_dis 
0003ba50:·7275·7074·696f·6e0a·2020·2d20·6d65·6469··ruption.··-·medi 
0003ba60:·756d·5f73·6576·6572·6974·790a·2020·2d20··um_severity.··-· 
0003ba70:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed 
0003ba80:·0a20·202d·2070·6163·6b61·6765·5f61·6964··.··-·package_aid 
0003ba90:·655f·696e·7374·616c·6c65·640a·3c2f·636f··e_installed.</co 
Max diff block lines reached; 8044389/8062107 bytes (99.78%) of diff not shown.
981 KB
html2text {}
    
Offset 42, 15 lines modifiedOffset 42, 15 lines modified
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·SUSE·Linux·Enterprise·15·Benchmark·for·Level·1·-·Workstation42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·CIS·SUSE·Linux·Enterprise·15·Benchmark·for·Level·1·-·Workstation
43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_workstation_l143 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_cis_workstation_l1
44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
45 ····*·cpe:/o:suse:linux_enterprise_desktop:1545 ····*·cpe:/o:suse:linux_enterprise_desktop:15
46 ····*·cpe:/o:suse:linux_enterprise_server:1546 ····*·cpe:/o:suse:linux_enterprise_server:15
47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
48 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8448 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
54 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r54 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
55 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n55 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
56 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g56 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 134, 27 lines modifiedOffset 134, 19 lines modified
134 include·install_aide134 include·install_aide
  
135 class·install_aide·{135 class·install_aide·{
136 ··package·{·'aide':136 ··package·{·'aide':
137 ····ensure·=>·'installed',137 ····ensure·=>·'installed',
138 ··}138 ··}
139 }139 }
 140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
145 #·Remediation·is·applicable·only·in·certain·platforms 
146 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
147 zypper·install·-y·"aide" 
  
148 else 
149 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
150 fi141 [[packages]]
 142 name·=·"aide"
 143 version·=·"*"
151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low145 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low146 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false147 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable148 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
156 -·name:·Ensure·aide·is·installed149 -·name:·Ensure·aide·is·installed
157 ··package:150 ··package:
Offset 170, 19 lines modifiedOffset 162, 27 lines modified
170 ··-·PCI-DSSv4-11.5.2162 ··-·PCI-DSSv4-11.5.2
171 ··-·enable_strategy163 ··-·enable_strategy
172 ··-·low_complexity164 ··-·low_complexity
173 ··-·low_disruption165 ··-·low_disruption
174 ··-·medium_severity166 ··-·medium_severity
175 ··-·no_reboot_needed167 ··-·no_reboot_needed
176 ··-·package_aide_installed168 ··-·package_aide_installed
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 174 #·Remediation·is·applicable·only·in·certain·platforms
 175 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
178 [[packages]] 
179 name·=·"aide" 
180 version·=·"*"176 zypper·install·-y·"aide"
  
 177 else
 178 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 179 fi
181 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*180 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
182 Run·the·following·command·to·generate·a·new·database:181 Run·the·following·command·to·generate·a·new·database:
183 $·sudo·/usr/bin/aide·--init182 $·sudo·/usr/bin/aide·--init
184 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the183 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the
185 configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these·files),·in·a·secure184 configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/aide·(or·hashes·of·these·files),·in·a·secure
186 location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-185 location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-
187 generated·database·can·be·installed·as·follows:186 generated·database·can·be·installed·as·follows:
Offset 209, 29 lines modifiedOffset 209, 14 lines modified
209 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5209 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
210 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199210 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
211 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419211 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419
212 ·············_\x8c_\x8i_\x8s············1.4.1212 ·············_\x8c_\x8i_\x8s············1.4.1
213 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79213 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
214 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2214 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
215 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r880967_rule215 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r880967_rule
216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
217 #·Remediation·is·applicable·only·in·certain·platforms 
218 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
219 zypper·-q·--no-remote·ref 
  
  
220 zypper·install·-y·"aide" 
  
221 /usr/bin/aide·--init 
222 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db 
  
223 else 
224 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
225 fi 
226 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
227 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low217 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
228 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low218 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
229 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false219 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
230 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict220 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
231 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated221 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated
232 ··ansible.builtin.command:·zypper·-q·--no-remote·ref222 ··ansible.builtin.command:·zypper·-q·--no-remote·ref
Offset 327, 14 lines modifiedOffset 312, 29 lines modified
327 ··-·PCI-DSSv4-11.5.2312 ··-·PCI-DSSv4-11.5.2
328 ··-·aide_build_database313 ··-·aide_build_database
329 ··-·low_complexity314 ··-·low_complexity
330 ··-·low_disruption315 ··-·low_disruption
331 ··-·medium_severity316 ··-·medium_severity
332 ··-·no_reboot_needed317 ··-·no_reboot_needed
333 ··-·restrict_strategy318 ··-·restrict_strategy
 319 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 320 #·Remediation·is·applicable·only·in·certain·platforms
 321 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 322 zypper·-q·--no-remote·ref
  
  
 323 zypper·install·-y·"aide"
  
 324 /usr/bin/aide·--init
 325 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db
  
 326 else
Max diff block lines reached; 998679/1004159 bytes (99.45%) of diff not shown.
20.2 MB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-cis_workstation_l2.html
    
Offset 14313, 15 lines modifiedOffset 14313, 15 lines modified
00037e80:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00037e80:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00037e90:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00037e90:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00037ea0:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s00037ea0:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00037eb0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00037eb0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00037ec0:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00037ec0:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00037ed0:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00037ed0:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00037ee0:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00037ee0:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00037ef0:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).00037ef0:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
00037f00:·2020·2020·2020·2020·2020·2020·2020·2020··················00037f00:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037f10:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00037f10:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00037f20:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00037f20:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00037f30:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00037f30:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00037f40:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00037f40:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00037f50:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00037f50:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00037f60:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00037f60:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
Offset 15200, 130 lines modifiedOffset 15200, 130 lines modified
0003b5f0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b5f0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003b600:·2223·6964·6d36·3333·3322·2074·6162·696e··"#idm6333"·tabin0003b600:·2223·6964·6d36·3333·3322·2074·6162·696e··"#idm6333"·tabin
0003b610:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b610:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b620:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b620:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b630:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b630:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b640:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b640:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b650:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b650:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b660:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She0003b660:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB
 0003b670:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s
 0003b680:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0003b690:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003b6a0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003b6b0:·6c61·7073·6522·2069·643d·2269·646d·3633··lapse"·id="idm63
0003b670:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
0003b680:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b690:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b6a0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b6b0:·6d36·3333·3322·3e3c·7461·626c·6520·636c··m6333"><table·cl 
0003b6c0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003b6d0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003b6e0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0003b6f0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0003b700:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0003b710:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003b720:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003b730:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
0003b740:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b750:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
0003b760:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
0003b770:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
0003b780:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
0003b790:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
0003b7a0:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#0003b6c0:·3333·223e·3c70·7265·3e3c·636f·6465·3e0a··33"><pre><code>.
 0003b6d0:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam
 0003b6e0:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi
 0003b6f0:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code>
0003b7b0:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is· 
0003b7c0:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only· 
0003b7d0:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf 
0003b7e0:·6f72·6d73·0a69·6620·5b20·2120·2d66·202f··orms.if·[·!·-f·/ 
0003b7f0:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am 
0003b800:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/ 
0003b810:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren 
0003b820:·7620·5d3b·2074·6865·6e0a·0a7a·7970·7065··v·];·then..zyppe 
0003b830:·7220·696e·7374·616c·6c20·2d79·2022·6169··r·install·-y·"ai 
0003b840:·6465·220a·0a65·6c73·650a·2020·2020·2667··de"..else.····&g 
0003b850:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R 
0003b860:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no 
0003b870:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no 
0003b880:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'. 
0003b890:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre> 
0003b8a0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003b8b0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003b8c0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003b8d0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003b8e0:·6765·743d·2223·6964·6d36·3333·3422·2074··get="#idm6334"·t 
0003b8f0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003b900:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003b910:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003b920:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003b930:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003b940:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003b950:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet 
0003b960:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003b970:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003b980:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003b990:·2069·643d·2269·646d·3633·3334·223e·3c74···id="idm6334"><t 
0003b9a0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003b9b0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003b9c0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003b9d0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003b9e0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003b9f0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003ba00:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003ba10:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003ba20:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003ba30:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003ba40:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003ba50:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003ba60:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0003ba70:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003ba80:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003ba90:·3c63·6f64·653e·2d20·6e61·6d65·3a20·456e··<code>-·name:·En 
0003baa0:·7375·7265·2061·6964·6520·6973·2069·6e73··sure·aide·is·ins 
0003bab0:·7461·6c6c·6564·0a20·2070·6163·6b61·6765··talled.··package 
0003bac0:·3a0a·2020·2020·6e61·6d65·3a20·6169·6465··:.····name:·aide 
0003bad0:·0a20·2020·2073·7461·7465·3a20·7072·6573··.····state:·pres 
0003bae0:·656e·740a·2020·7768·656e·3a20·616e·7369··ent.··when:·ansi 
0003baf0:·626c·655f·7669·7274·7561·6c69·7a61·7469··ble_virtualizati 
0003bb00:·6f6e·5f74·7970·6520·6e6f·7420·696e·205b··on_type·not·in·[ 
0003bb10:·2264·6f63·6b65·7222·2c20·226c·7863·222c··"docker",·"lxc", 
0003bb20:·2022·6f70·656e·767a·222c·2022·706f·646d···"openvz",·"podm 
0003bb30:·616e·222c·2022·636f·6e74·6169·6e65·7222··an",·"container" 
0003bb40:·5d0a·2020·7461·6773·3a0a·2020·2d20·4343··].··tags:.··-·CC 
0003bb50:·452d·3833·3238·392d·390a·2020·2d20·434a··E-83289-9.··-·CJ 
0003bb60:·4953·2d35·2e31·302e·312e·330a·2020·2d20··IS-5.10.1.3.··-· 
0003bb70:·4449·5341·2d53·5449·472d·534c·4553·2d31··DISA-STIG-SLES-1 
0003bb80:·352d·3031·3034·3139·0a20·202d·204e·4953··5-010419.··-·NIS 
0003bb90:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a) 
0003bba0:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req 
0003bbb0:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS 
0003bbc0:·5376·342d·3131·2e35·2e32·0a20·202d·2065··Sv4-11.5.2.··-·e 
0003bbd0:·6e61·626c·655f·7374·7261·7465·6779·0a20··nable_strategy.· 
0003bbe0:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit 
0003bbf0:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup 
0003bc00:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_ 
0003bc10:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_ 
0003bc20:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.·· 
0003bc30:·2d20·7061·636b·6167·655f·6169·6465·5f69··-·package_aide_i 
0003bc40:·6e73·7461·6c6c·6564·0a3c·2f63·6f64·653e··nstalled.</code> 
0003bc50:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c0003b700:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
Max diff block lines reached; 19308906/19326624 bytes (99.91%) of diff not shown.
1.78 MB
html2text {}
Max HTML report size reached
16.4 MB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-hipaa.html
    
Offset 14324, 16 lines modifiedOffset 14324, 16 lines modified
00037f30:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><00037f30:·6f6e·2048·6973·746f·7279·3c2f·6832·3e3c··on·History</h2><
00037f40:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio00037f40:·703e·4375·7272·656e·7420·7665·7273·696f··p>Current·versio
00037f50:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.700037f50:·6e3a·203c·7374·726f·6e67·3e30·2e31·2e37··n:·<strong>0.1.7
00037f60:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u00037f60:·343c·2f73·7472·6f6e·673e·3c2f·703e·3c75··4</strong></p><u
00037f70:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr00037f70:·6c3e·3c6c·693e·3c73·7472·6f6e·673e·6472··l><li><strong>dr
00037f80:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···00037f80:·6166·743c·2f73·7472·6f6e·673e·0a20·2020··aft</strong>.···
00037f90:·2020·2020·2020·2020·2020·2020·2020·2020··················00037f90:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037fa0:·2028·6173·206f·6620·3230·3236·2d30·312d···(as·of·2026-01-00037fa0:·2028·6173·206f·6620·3230·3234·2d31·322d···(as·of·2024-12-
00037fb0:·3038·290a·2020·2020·2020·2020·2020·2020··08).············00037fb0:·3037·290a·2020·2020·2020·2020·2020·2020··07).············
00037fc0:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></00037fc0:·2020·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f······</li></ul></
00037fd0:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of00037fd0:·6469·763e·3c68·323e·5461·626c·6520·6f66··div><h2>Table·of
00037fe0:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o00037fe0:·2043·6f6e·7465·6e74·733c·2f68·323e·3c6f···Contents</h2><o
00037ff0:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#00037ff0:·6c3e·3c6c·693e·3c61·2068·7265·663d·2223··l><li><a·href="#
00038000:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro00038000:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro
00038010:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro00038010:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro
00038020:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste00038020:·7570·5f73·7973·7465·6d22·3e53·7973·7465··up_system">Syste
Offset 15209, 306 lines modifiedOffset 15209, 306 lines modified
0003b680:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003b680:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003b690:·6d35·3939·3022·2074·6162·696e·6465·783d··m5990"·tabindex=0003b690:·6d35·3939·3022·2074·6162·696e·6465·783d··m5990"·tabindex=
0003b6a0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003b6a0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003b6b0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003b6b0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003b6c0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003b6c0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003b6d0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003b6d0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003b6e0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003b6e0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003b6f0:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s0003b6f0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible
0003b700:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003b710:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003b720:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003b730:·6170·7365·2220·6964·3d22·6964·6d35·3939··apse"·id="idm599 
0003b740:·3022·3e3c·7072·653e·3c63·6f64·653e·0a23··0"><pre><code>.# 
0003b750:·2046·696e·6420·7768·6963·6820·6669·6c65···Find·which·file 
0003b760:·7320·6861·7665·2069·6e63·6f72·7265·6374··s·have·incorrect 
0003b770:·2068·6173·6820·286e·6f74·2069·6e20·2f65···hash·(not·in·/e 
0003b780:·7463·2c20·6265·6361·7573·6520·6f66·2074··tc,·because·of·t 
0003b790:·6865·2073·7973·7465·6d20·7265·6c61·7465··he·system·relate 
0003b7a0:·6420·636f·6e66·6967·2066·696c·6573·2920··d·config·files)· 
0003b7b0:·616e·6420·7468·656e·2067·6574·2066·696c··and·then·get·fil 
0003b7c0:·6573·206e·616d·6573·0a66·696c·6573·5f77··es·names.files_w0003b700:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0003b710:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003b720:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003b730:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003b740:·3539·3930·223e·3c74·6162·6c65·2063·6c61··5990"><table·cla
 0003b750:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0003b760:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0003b770:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003b780:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003b790:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003b7a0:·3c74·643e·6869·6768·3c2f·7464·3e3c·2f74··<td>high</td></t
 0003b7b0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003b7c0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6d65··tion:</th><td>me
 0003b7d0:·6469·756d·3c2f·7464·3e3c·2f74·723e·3c74··dium</td></tr><t
 0003b7e0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 0003b7f0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
 0003b800:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 0003b810:·6174·6567·793a·3c2f·7468·3e3c·7464·3e72··ategy:</th><td>r
 0003b820:·6573·7472·6963·743c·2f74·643e·3c2f·7472··estrict</td></tr
 0003b830:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003b840:·6f64·653e·2d20·6e61·6d65·3a20·2753·6574··ode>-·name:·'Set
 0003b850:·2066·6163·743a·2050·6163·6b61·6765·206d···fact:·Package·m
 0003b860:·616e·6167·6572·2072·6569·6e73·7461·6c6c··anager·reinstall
 0003b870:·2063·6f6d·6d61·6e64·270a·2020·7365·745f···command'.··set_
 0003b880:·6661·6374·3a0a·2020·2020·7061·636b·6167··fact:.····packag
 0003b890:·655f·6d61·6e61·6765·725f·7265·696e·7374··e_manager_reinst
 0003b8a0:·616c·6c5f·636d·643a·207a·7970·7065·7220··all_cmd:·zypper·
 0003b8b0:·7265·696e·7374·616c·6c20·2d79·0a20·2077··reinstall·-y.··w
 0003b8c0:·6865·6e3a·2061·6e73·6962·6c65·5f64·6973··hen:·ansible_dis
 0003b8d0:·7472·6962·7574·696f·6e20·696e·205b·2022··tribution·in·[·"
 0003b8e0:·4665·646f·7261·222c·2022·5265·6448·6174··Fedora",·"RedHat
 0003b8f0:·222c·2022·4365·6e74·4f53·222c·2022·4f72··",·"CentOS",·"Or
 0003b900:·6163·6c65·4c69·6e75·7822·205d·0a20·2074··acleLinux"·].··t
 0003b910:·6167·733a·0a20·202d·2043·4345·2d38·3537··ags:.··-·CCE-857
 0003b920:·3838·2d38·0a20·202d·2043·4a49·532d·352e··88-8.··-·CJIS-5.
 0003b930:·3130·2e34·2e31·0a20·202d·204e·4953·542d··10.4.1.··-·NIST-
 0003b940:·3830·302d·3137·312d·332e·332e·380a·2020··800-171-3.3.8.··
 0003b950:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-3
 0003b960:·2e34·2e31·0a20·202d·204e·4953·542d·3830··.4.1.··-·NIST-80
 0003b970:·302d·3533·2d41·552d·3928·3329·0a20·202d··0-53-AU-9(3).··-
 0003b980:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-
 0003b990:·3628·6329·0a20·202d·204e·4953·542d·3830··6(c).··-·NIST-80
 0003b9a0:·302d·3533·2d43·4d2d·3628·6429·0a20·202d··0-53-CM-6(d).··-
 0003b9b0:·204e·4953·542d·3830·302d·3533·2d53·492d···NIST-800-53-SI-
 0003b9c0:·370a·2020·2d20·4e49·5354·2d38·3030·2d35··7.··-·NIST-800-5
 0003b9d0:·332d·5349·2d37·2831·290a·2020·2d20·4e49··3-SI-7(1).··-·NI
 0003b9e0:·5354·2d38·3030·2d35·332d·5349·2d37·2836··ST-800-53-SI-7(6
 0003b9f0:·290a·2020·2d20·5043·492d·4453·532d·5265··).··-·PCI-DSS-Re
 0003ba00:·712d·3131·2e35·0a20·202d·2050·4349·2d44··q-11.5.··-·PCI-D
 0003ba10:·5353·7634·2d31·312e·352e·320a·2020·2d20··SSv4-11.5.2.··-·
 0003ba20:·6869·6768·5f63·6f6d·706c·6578·6974·790a··high_complexity.
 0003ba30:·2020·2d20·6869·6768·5f73·6576·6572·6974····-·high_severit
 0003ba40:·790a·2020·2d20·6d65·6469·756d·5f64·6973··y.··-·medium_dis
 0003ba50:·7275·7074·696f·6e0a·2020·2d20·6e6f·5f72··ruption.··-·no_r
 0003ba60:·6562·6f6f·745f·6e65·6564·6564·0a20·202d··eboot_needed.··-
 0003ba70:·2072·6573·7472·6963·745f·7374·7261·7465···restrict_strate
 0003ba80:·6779·0a20·202d·2072·706d·5f76·6572·6966··gy.··-·rpm_verif
 0003ba90:·795f·6861·7368·6573·0a0a·2d20·6e61·6d65··y_hashes..-·name
 0003baa0:·3a20·2753·6574·2066·6163·743a·2050·6163··:·'Set·fact:·Pac
 0003bab0:·6b61·6765·206d·616e·6167·6572·2072·6569··kage·manager·rei
 0003bac0:·6e73·7461·6c6c·2063·6f6d·6d61·6e64·2028··nstall·command·(
 0003bad0:·7a79·7070·6572·2927·0a20·2073·6574·5f66··zypper)'.··set_f
 0003bae0:·6163·743a·0a20·2020·2070·6163·6b61·6765··act:.····package
 0003baf0:·5f6d·616e·6167·6572·5f72·6569·6e73·7461··_manager_reinsta
 0003bb00:·6c6c·5f63·6d64·3a20·7a79·7070·6572·2069··ll_cmd:·zypper·i
 0003bb10:·6e20·2d66·202d·790a·2020·7768·656e·3a20··n·-f·-y.··when:·
 0003bb20:·616e·7369·626c·655f·6469·7374·7269·6275··ansible_distribu
 0003bb30:·7469·6f6e·203d·3d20·2253·4c45·5322·0a20··tion·==·"SLES".·
 0003bb40:·2074·6167·733a·0a20·202d·2043·4345·2d38···tags:.··-·CCE-8
 0003bb50:·3537·3838·2d38·0a20·202d·2043·4a49·532d··5788-8.··-·CJIS-
 0003bb60:·352e·3130·2e34·2e31·0a20·202d·204e·4953··5.10.4.1.··-·NIS
 0003bb70:·542d·3830·302d·3137·312d·332e·332e·380a··T-800-171-3.3.8.
 0003bb80:·2020·2d20·4e49·5354·2d38·3030·2d31·3731····-·NIST-800-171
 0003bb90:·2d33·2e34·2e31·0a20·202d·204e·4953·542d··-3.4.1.··-·NIST-
 0003bba0:·3830·302d·3533·2d41·552d·3928·3329·0a20··800-53-AU-9(3).·
 0003bbb0:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C
 0003bbc0:·4d2d·3628·6329·0a20·202d·204e·4953·542d··M-6(c).··-·NIST-
 0003bbd0:·3830·302d·3533·2d43·4d2d·3628·6429·0a20··800-53-CM-6(d).·
 0003bbe0:·202d·204e·4953·542d·3830·302d·3533·2d53···-·NIST-800-53-S
 0003bbf0:·492d·370a·2020·2d20·4e49·5354·2d38·3030··I-7.··-·NIST-800
 0003bc00:·2d35·332d·5349·2d37·2831·290a·2020·2d20··-53-SI-7(1).··-·
 0003bc10:·4e49·5354·2d38·3030·2d35·332d·5349·2d37··NIST-800-53-SI-7
 0003bc20:·2836·290a·2020·2d20·5043·492d·4453·532d··(6).··-·PCI-DSS-
 0003bc30:·5265·712d·3131·2e35·0a20·202d·2050·4349··Req-11.5.··-·PCI
 0003bc40:·2d44·5353·7634·2d31·312e·352e·320a·2020··-DSSv4-11.5.2.··
 0003bc50:·2d20·6869·6768·5f63·6f6d·706c·6578·6974··-·high_complexit
 0003bc60:·790a·2020·2d20·6869·6768·5f73·6576·6572··y.··-·high_sever
 0003bc70:·6974·790a·2020·2d20·6d65·6469·756d·5f64··ity.··-·medium_d
 0003bc80:·6973·7275·7074·696f·6e0a·2020·2d20·6e6f··isruption.··-·no
 0003bc90:·5f72·6562·6f6f·745f·6e65·6564·6564·0a20··_reboot_needed.·
Max diff block lines reached; 15875248/15917392 bytes (99.74%) of diff not shown.
1.17 MB
html2text {}
    
Offset 45, 15 lines modifiedOffset 45, 15 lines modified
45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Health·Insurance·Portability·and·Accountability·Act·(HIPAA)45 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Health·Insurance·Portability·and·Accountability·Act·(HIPAA)
46 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_hipaa46 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_hipaa
47 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*47 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
48 ····*·cpe:/o:suse:linux_enterprise_desktop:1548 ····*·cpe:/o:suse:linux_enterprise_desktop:15
49 ····*·cpe:/o:suse:linux_enterprise_server:1549 ····*·cpe:/o:suse:linux_enterprise_server:15
50 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
51 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8451 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
52 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)52 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
53 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*53 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
54 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s54 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
55 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e55 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
56 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l56 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
57 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n57 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
58 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g58 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
59 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s59 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 135, 29 lines modifiedOffset 135, 14 lines modified
135 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,135 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,
136 ····························A.14.2.3,·A.14.2.4136 ····························A.14.2.3,·A.14.2.4
137 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)137 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
138 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1138 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
139 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5139 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
140 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227140 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
141 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2141 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
143 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then 
144 get·files·names 
145 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
146 if·[·-n·"$files_with_incorrect_hash"·];·then 
147 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to 
148 new·line 
149 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
150 ····zypper·install·-f·-y·$packages_to_reinstall 
  
151 fi 
152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
153 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
154 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
155 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
156 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
157 -·name:·'Set·fact:·Package·manager·reinstall·command'147 -·name:·'Set·fact:·Package·manager·reinstall·command'
158 ··set_fact:148 ··set_fact:
Offset 289, 14 lines modifiedOffset 274, 29 lines modified
289 ··-·PCI-DSSv4-11.5.2274 ··-·PCI-DSSv4-11.5.2
290 ··-·high_complexity275 ··-·high_complexity
291 ··-·high_severity276 ··-·high_severity
292 ··-·medium_disruption277 ··-·medium_disruption
293 ··-·no_reboot_needed278 ··-·no_reboot_needed
294 ··-·restrict_strategy279 ··-·restrict_strategy
295 ··-·rpm_verify_hashes280 ··-·rpm_verify_hashes
 281 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 282 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then
 283 get·files·names
 284 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 285 if·[·-n·"$files_with_incorrect_hash"·];·then
 286 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to
 287 new·line
 288 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 289 ····zypper·install·-f·-y·$packages_to_reinstall
  
 290 fi
296 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*291 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·F\x8Fi\x8il\x8le\x8e·P\x8Pe\x8er\x8rm\x8mi\x8is\x8ss\x8si\x8io\x8on\x8ns\x8s·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
297 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,292 The·RPM·package·management·system·can·check·file·access·permissions·of·installed·software·packages,
298 including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and293 including·many·that·are·important·to·system·security.·Verify·that·the·file·permissions·of·system·files·and
299 commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:294 commands·match·vendor·values.·Check·the·file·permissions·with·the·following·command:
300 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'295 $·sudo·rpm·-Va·|·awk·'{·if·(substr($0,2,1)=="M")·print·$NF·}'
301 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,296 Output·indicates·files·that·do·not·match·vendor·defaults.·After·locating·a·file·with·incorrect·permissions,
302 run·the·following·command·to·determine·which·package·owns·it:297 run·the·following·command·to·determine·which·package·owns·it:
Offset 336, 46 lines modifiedOffset 336, 14 lines modified
336 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)336 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)
337 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1337 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
338 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5338 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
339 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,339 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,
340 ····························SRG-OS-000278-GPOS-00108340 ····························SRG-OS-000278-GPOS-00108
341 ·············_\x8c_\x8i_\x8s············6.1.1341 ·············_\x8c_\x8i_\x8s············6.1.1
342 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2342 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
343 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
344 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
345 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
346 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
347 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
348 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
349 declare·-A·SETPERMS_RPM_DICT 
  
350 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
351 #·is·expected·by·the·RPM·database 
352 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,2,1)=="M")·print 
353 $NF·}') 
  
354 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
355 do 
356 ········#·NOTE:·some·files·maybe·controlled·by·more·then·one·package 
357 ········readarray·-t·RPM_PACKAGES·<·<(rpm·-qf·"${FILE_PATH}") 
358 ········for·RPM_PACKAGE·in·"${RPM_PACKAGES[@]}" 
359 ········do 
360 ················#·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about 
361 duplicates. 
362 ················SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
363 ········done 
364 done 
  
365 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
366 #·correct·values 
367 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
368 do 
369 »       rpm·--restore·"${RPM_PACKAGE}" 
370 done 
371 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8343 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
372 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high344 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
373 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium345 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
374 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false346 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
375 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict347 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
376 -·name:·Read·list·of·files·with·incorrect·permissions348 -·name:·Read·list·of·files·with·incorrect·permissions
377 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev349 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 456, 14 lines modifiedOffset 424, 46 lines modified
456 ··-·PCI-DSSv4-11.5.2424 ··-·PCI-DSSv4-11.5.2
457 ··-·high_complexity425 ··-·high_complexity
458 ··-·high_severity426 ··-·high_severity
459 ··-·medium_disruption427 ··-·medium_disruption
Max diff block lines reached; 1224852/1231204 bytes (99.48%) of diff not shown.
15.0 MB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-pci-dss-4.html
    
Offset 14297, 15 lines modifiedOffset 14297, 15 lines modified
00037d80:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu00037d80:·6973·746f·7279·3c2f·6832·3e3c·703e·4375··istory</h2><p>Cu
00037d90:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<00037d90:·7272·656e·7420·7665·7273·696f·6e3a·203c··rrent·version:·<
00037da0:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s00037da0:·7374·726f·6e67·3e30·2e31·2e37·343c·2f73··strong>0.1.74</s
00037db0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l00037db0:·7472·6f6e·673e·3c2f·703e·3c75·6c3e·3c6c··trong></p><ul><l
00037dc0:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<00037dc0:·693e·3c73·7472·6f6e·673e·6472·6166·743c··i><strong>draft<
00037dd0:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······00037dd0:·2f73·7472·6f6e·673e·0a20·2020·2020·2020··/strong>.·······
00037de0:·2020·2020·2020·2020·2020·2020·2028·6173···············(as00037de0:·2020·2020·2020·2020·2020·2020·2028·6173···············(as
00037df0:·206f·6620·3230·3236·2d30·312d·3038·290a···of·2026-01-08).00037df0:·206f·6620·3230·3234·2d31·322d·3037·290a···of·2024-12-07).
00037e00:·2020·2020·2020·2020·2020·2020·2020·2020··················00037e00:·2020·2020·2020·2020·2020·2020·2020·2020··················
00037e10:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>00037e10:·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469·763e··</li></ul></div>
00037e20:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con00037e20:·3c68·323e·5461·626c·6520·6f66·2043·6f6e··<h2>Table·of·Con
00037e30:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l00037e30:·7465·6e74·733c·2f68·323e·3c6f·6c3e·3c6c··tents</h2><ol><l
00037e40:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd00037e40:·693e·3c61·2068·7265·663d·2223·7863·6364··i><a·href="#xccd
00037e50:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00037e50:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject
00037e60:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s00037e60:·2e63·6f6e·7465·6e74·5f67·726f·7570·5f73··.content_group_s
Offset 15196, 307 lines modifiedOffset 15196, 307 lines modified
0003b5b0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b5b0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003b5c0:·2223·6964·6d35·3939·3022·2074·6162·696e··"#idm5990"·tabin0003b5c0:·2223·6964·6d35·3939·3022·2074·6162·696e··"#idm5990"·tabin
0003b5d0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b5d0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b5e0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b5e0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b5f0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b5f0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b600:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b600:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b610:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b610:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b620:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She0003b620:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans
0003b630:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
0003b640:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b650:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b660:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b670:·6d35·3939·3022·3e3c·7072·653e·3c63·6f64··m5990"><pre><cod 
0003b680:·653e·0a23·2046·696e·6420·7768·6963·6820··e>.#·Find·which· 
0003b690:·6669·6c65·7320·6861·7665·2069·6e63·6f72··files·have·incor 
0003b6a0:·7265·6374·2068·6173·6820·286e·6f74·2069··rect·hash·(not·i 
0003b6b0:·6e20·2f65·7463·2c20·6265·6361·7573·6520··n·/etc,·because· 
0003b6c0:·6f66·2074·6865·2073·7973·7465·6d20·7265··of·the·system·re 
0003b6d0:·6c61·7465·6420·636f·6e66·6967·2066·696c··lated·config·fil 
0003b6e0:·6573·2920·616e·6420·7468·656e·2067·6574··es)·and·then·get 
0003b6f0:·2066·696c·6573·206e·616d·6573·0a66·696c···files·names.fil 
0003b700:·6573·5f77·6974·685f·696e·636f·7272·6563··es_with_incorrec 
0003b710:·745f·6861·7368·3d22·2428·7270·6d20·2d56··t_hash="$(rpm·-V 
0003b720:·6120·2d2d·6e6f·636f·6e66·6967·207c·2067··a·--noconfig·|·g 
0003b730:·7265·7020·2d45·2027·5e2e·2e35·2720·7c20··rep·-E·'^..5'·|· 
0003b740:·6177·6b20·277b·7072·696e·7420·244e·467d··awk·'{print·$NF} 
0003b750:·2720·2922·0a0a·6966·205b·202d·6e20·2224··'·)"..if·[·-n·"$ 
0003b760:·6669·6c65·735f·7769·7468·5f69·6e63·6f72··files_with_incor 
0003b770:·7265·6374·5f68·6173·6822·205d·3b20·7468··rect_hash"·];·th 
0003b780:·656e·0a20·2020·2023·2046·726f·6d20·6669··en.····#·From·fi 
0003b790:·6c65·7320·6e61·6d65·7320·6765·7420·7061··les·names·get·pa 
0003b7a0:·636b·6167·6520·6e61·6d65·7320·616e·6420··ckage·names·and· 
0003b7b0:·6368·616e·6765·206e·6577·6c69·6e65·2074··change·newline·t 
0003b7c0:·6f20·7370·6163·652c·2062·6563·6175·7365··o·space,·because 
0003b7d0:·2072·706d·2077·7269·7465·7320·6561·6368···rpm·writes·each 
0003b7e0:·2070·6163·6b61·6765·2074·6f20·6e65·7720···package·to·new· 
0003b7f0:·6c69·6e65·0a20·2020·2070·6163·6b61·6765··line.····package 
0003b800:·735f·746f·5f72·6569·6e73·7461·6c6c·3d22··s_to_reinstall=" 
0003b810:·2428·7270·6d20·2d71·6620·2466·696c·6573··$(rpm·-qf·$files 
0003b820:·5f77·6974·685f·696e·636f·7272·6563·745f··_with_incorrect_ 
0003b830:·6861·7368·207c·2074·7220·275c·6e27·2027··hash·|·tr·'\n'·' 
0003b840:·2027·2922·0a0a·2020·2020·0a20·2020·207a···')"..····.····z 
0003b850:·7970·7065·7220·696e·7374·616c·6c20·2d66··ypper·install·-f 
0003b860:·202d·7920·2470·6163·6b61·6765·735f·746f···-y·$packages_to 
0003b870:·5f72·6569·6e73·7461·6c6c·0a20·2020·200a··_reinstall.····. 
0003b880:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre> 
0003b890:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003b8a0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003b8b0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003b8c0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003b8d0:·6765·743d·2223·6964·6d35·3939·3122·2074··get="#idm5991"·t 
0003b8e0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003b8f0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003b900:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003b910:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003b920:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003b930:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003b940:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet0003b630:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...
0003b950:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003b640:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003b960:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003b650:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003b970:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003b660:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003b980:·2069·643d·2269·646d·3539·3931·223e·3c74···id="idm5991"><t0003b670:·2269·646d·3539·3930·223e·3c74·6162·6c65··"idm5990"><table
0003b990:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl0003b680:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003b9a0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·0003b690:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003b9b0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0003b6a0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003b9c0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">0003b6b0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003b9d0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi0003b6c0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003b9e0:·7479·3a3c·2f74·683e·3c74·643e·6869·6768··ty:</th><td>high 
0003b9f0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003ba00:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003ba10:·683e·3c74·643e·6d65·6469·756d·3c2f·7464··h><td>medium</td0003b6d0:·2f74·683e·3c74·643e·6869·6768·3c2f·7464··/th><td>high</td
0003ba20:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003b6e0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0003b6f0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0003b700:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t
 0003b710:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
0003ba30:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003b720:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003ba40:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
0003ba50:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003ba60:·7468·3e3c·7464·3e72·6573·7472·6963·743c··th><td>restrict< 
0003ba70:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003b730:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b740:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003b750:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>
 0003b760:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
0003ba80:·3e3c·7072·653e·3c63·6f64·653e·2d20·6e61··><pre><code>-·na0003b770:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·
 0003b780:·2753·6574·2066·6163·743a·2050·6163·6b61··'Set·fact:·Packa
 0003b790:·6765·206d·616e·6167·6572·2072·6569·6e73··ge·manager·reins
 0003b7a0:·7461·6c6c·2063·6f6d·6d61·6e64·270a·2020··tall·command'.··
 0003b7b0:·7365·745f·6661·6374·3a0a·2020·2020·7061··set_fact:.····pa
 0003b7c0:·636b·6167·655f·6d61·6e61·6765·725f·7265··ckage_manager_re
 0003b7d0:·696e·7374·616c·6c5f·636d·643a·207a·7970··install_cmd:·zyp
 0003b7e0:·7065·7220·7265·696e·7374·616c·6c20·2d79··per·reinstall·-y
 0003b7f0:·0a20·2077·6865·6e3a·2061·6e73·6962·6c65··.··when:·ansible
 0003b800:·5f64·6973·7472·6962·7574·696f·6e20·696e··_distribution·in
 0003b810:·205b·2022·4665·646f·7261·222c·2022·5265···[·"Fedora",·"Re
 0003b820:·6448·6174·222c·2022·4365·6e74·4f53·222c··dHat",·"CentOS",
 0003b830:·2022·4f72·6163·6c65·4c69·6e75·7822·205d···"OracleLinux"·]
 0003b840:·0a20·2074·6167·733a·0a20·202d·2043·4345··.··tags:.··-·CCE
 0003b850:·2d38·3537·3838·2d38·0a20·202d·2043·4a49··-85788-8.··-·CJI
 0003b860:·532d·352e·3130·2e34·2e31·0a20·202d·204e··S-5.10.4.1.··-·N
 0003b870:·4953·542d·3830·302d·3137·312d·332e·332e··IST-800-171-3.3.
 0003b880:·380a·2020·2d20·4e49·5354·2d38·3030·2d31··8.··-·NIST-800-1
 0003b890:·3731·2d33·2e34·2e31·0a20·202d·204e·4953··71-3.4.1.··-·NIS
 0003b8a0:·542d·3830·302d·3533·2d41·552d·3928·3329··T-800-53-AU-9(3)
 0003b8b0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
 0003b8c0:·2d43·4d2d·3628·6329·0a20·202d·204e·4953··-CM-6(c).··-·NIS
 0003b8d0:·542d·3830·302d·3533·2d43·4d2d·3628·6429··T-800-53-CM-6(d)
 0003b8e0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
 0003b8f0:·2d53·492d·370a·2020·2d20·4e49·5354·2d38··-SI-7.··-·NIST-8
 0003b900:·3030·2d35·332d·5349·2d37·2831·290a·2020··00-53-SI-7(1).··
 0003b910:·2d20·4e49·5354·2d38·3030·2d35·332d·5349··-·NIST-800-53-SI
 0003b920:·2d37·2836·290a·2020·2d20·5043·492d·4453··-7(6).··-·PCI-DS
Max diff block lines reached; 14266833/14308977 bytes (99.71%) of diff not shown.
1.32 MB
html2text {}
    
Offset 37, 15 lines modifiedOffset 37, 15 lines modified
37 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v4·Control·Baseline·for·SUSE·Linux·enterprise·1537 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·PCI-DSS·v4·Control·Baseline·for·SUSE·Linux·enterprise·15
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss-438 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pci-dss-4
39 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*39 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
40 ····*·cpe:/o:suse:linux_enterprise_desktop:1540 ····*·cpe:/o:suse:linux_enterprise_desktop:15
41 ····*·cpe:/o:suse:linux_enterprise_server:1541 ····*·cpe:/o:suse:linux_enterprise_server:15
42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*42 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
43 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8443 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)44 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s46 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e47 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l48 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
49 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n49 ·········3.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
50 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g50 ·········4.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
51 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s51 ·········5.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
Offset 130, 29 lines modifiedOffset 130, 14 lines modified
130 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,130 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,
131 ····························A.14.2.3,·A.14.2.4131 ····························A.14.2.3,·A.14.2.4
132 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)132 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3)
133 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1133 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-6,·PR.DS-8,·PR.IP-1
134 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5134 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
135 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227135 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
136 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2136 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
138 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then 
139 get·files·names 
140 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)" 
  
141 if·[·-n·"$files_with_incorrect_hash"·];·then 
142 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to 
143 new·line 
144 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')" 
  
  
145 ····zypper·install·-f·-y·$packages_to_reinstall 
  
146 fi 
147 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
148 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
149 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
150 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
151 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
152 -·name:·'Set·fact:·Package·manager·reinstall·command'142 -·name:·'Set·fact:·Package·manager·reinstall·command'
153 ··set_fact:143 ··set_fact:
Offset 284, 14 lines modifiedOffset 269, 29 lines modified
284 ··-·PCI-DSSv4-11.5.2269 ··-·PCI-DSSv4-11.5.2
285 ··-·high_complexity270 ··-·high_complexity
286 ··-·high_severity271 ··-·high_severity
287 ··-·medium_disruption272 ··-·medium_disruption
288 ··-·no_reboot_needed273 ··-·no_reboot_needed
289 ··-·restrict_strategy274 ··-·restrict_strategy
290 ··-·rpm_verify_hashes275 ··-·rpm_verify_hashes
 276 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 277 #·Find·which·files·have·incorrect·hash·(not·in·/etc,·because·of·the·system·related·config·files)·and·then
 278 get·files·names
 279 files_with_incorrect_hash="$(rpm·-Va·--noconfig·|·grep·-E·'^..5'·|·awk·'{print·$NF}'·)"
  
 280 if·[·-n·"$files_with_incorrect_hash"·];·then
 281 ····#·From·files·names·get·package·names·and·change·newline·to·space,·because·rpm·writes·each·package·to
 282 new·line
 283 ····packages_to_reinstall="$(rpm·-qf·$files_with_incorrect_hash·|·tr·'\n'·'·')"
  
  
 284 ····zypper·install·-f·-y·$packages_to_reinstall
  
 285 fi
291 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*286 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·a\x8an\x8nd\x8d·C\x8Co\x8or\x8rr\x8re\x8ec\x8ct\x8t·O\x8Ow\x8wn\x8ne\x8er\x8rs\x8sh\x8hi\x8ip\x8p·w\x8wi\x8it\x8th\x8h·R\x8RP\x8PM\x8M·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
292 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,287 The·RPM·package·management·system·can·check·file·ownership·permissions·of·installed·software·packages,
293 including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,288 including·many·that·are·important·to·system·security.·After·locating·a·file·with·incorrect·permissions,
294 which·can·be·found·with:289 which·can·be·found·with:
295 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'290 rpm·-Va·|·awk·'{·if·(substr($0,6,1)=="U"·||·substr($0,7,1)=="G")·print·$NF·}'
296 run·the·following·command·to·determine·which·package·owns·it:291 run·the·following·command·to·determine·which·package·owns·it:
297 $·rpm·-qf·FILENAME292 $·rpm·-qf·FILENAME
Offset 373, 46 lines modifiedOffset 373, 14 lines modified
373 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)373 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(d),·CM-6(c),·SI-7,·SI-7(1),·SI-7(6),·AU-9(3),·CM-6(a)
374 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1374 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-4,·PR.DS-5,·PR.IP-1,·PR.PT-1
375 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5375 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
376 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,376 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000256-GPOS-00097,·SRG-OS-000257-GPOS-00098,·SRG-OS-000258-GPOS-00099,
377 ····························SRG-OS-000278-GPOS-00108377 ····························SRG-OS-000278-GPOS-00108
378 ·············_\x8c_\x8i_\x8s············6.1.1378 ·············_\x8c_\x8i_\x8s············6.1.1
379 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2379 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
380 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
381 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high 
382 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium 
383 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
384 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
  
385 #·Declare·array·to·hold·set·of·RPM·packages·we·need·to·correct·permissions·for 
386 declare·-A·SETPERMS_RPM_DICT 
  
387 #·Create·a·list·of·files·on·the·system·having·permissions·different·from·what 
388 #·is·expected·by·the·RPM·database 
389 readarray·-t·FILES_WITH_INCORRECT_PERMS·<·<(rpm·-Va·--nofiledigest·|·awk·'{·if·(substr($0,2,1)=="M")·print 
390 $NF·}') 
  
391 for·FILE_PATH·in·"${FILES_WITH_INCORRECT_PERMS[@]}" 
392 do 
393 ········#·NOTE:·some·files·maybe·controlled·by·more·then·one·package 
394 ········readarray·-t·RPM_PACKAGES·<·<(rpm·-qf·"${FILE_PATH}") 
395 ········for·RPM_PACKAGE·in·"${RPM_PACKAGES[@]}" 
396 ········do 
397 ················#·Use·an·associative·array·to·store·packages·as·it's·keys,·not·having·to·care·about 
398 duplicates. 
399 ················SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1 
400 ········done 
401 done 
  
402 #·For·each·of·the·RPM·packages·left·in·the·list·--·reset·its·permissions·to·the 
403 #·correct·values 
404 for·RPM_PACKAGE·in·"${!SETPERMS_RPM_DICT[@]}" 
405 do 
406 »       rpm·--restore·"${RPM_PACKAGE}" 
407 done 
408 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8380 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
409 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high381 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·high
410 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium382 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
411 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false383 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
412 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict384 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
413 -·name:·Read·list·of·files·with·incorrect·permissions385 -·name:·Read·list·of·files·with·incorrect·permissions
414 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev386 ··command:·rpm·-Va·--nodeps·--nosignature·--nofiledigest·--nosize·--nomtime·--nordev
Offset 493, 14 lines modifiedOffset 461, 46 lines modified
493 ··-·PCI-DSSv4-11.5.2461 ··-·PCI-DSSv4-11.5.2
494 ··-·high_complexity462 ··-·high_complexity
495 ··-·high_severity463 ··-·high_severity
496 ··-·medium_disruption464 ··-·medium_disruption
Max diff block lines reached; 1381893/1388094 bytes (99.55%) of diff not shown.
23.2 MB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-pcs-hardening-sap.html
    
Offset 14314, 15 lines modifiedOffset 14314, 15 lines modified
00037e90:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·00037e90:·3c2f·6832·3e3c·703e·4375·7272·656e·7420··</h2><p>Current·
00037ea0:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong00037ea0:·7665·7273·696f·6e3a·203c·7374·726f·6e67··version:·<strong
00037eb0:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>00037eb0:·3e30·2e31·2e37·343c·2f73·7472·6f6e·673e··>0.1.74</strong>
00037ec0:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str00037ec0:·3c2f·703e·3c75·6c3e·3c6c·693e·3c73·7472··</p><ul><li><str
00037ed0:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron00037ed0:·6f6e·673e·6472·6166·743c·2f73·7472·6f6e··ong>draft</stron
00037ee0:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············00037ee0:·673e·0a20·2020·2020·2020·2020·2020·2020··g>.·············
00037ef0:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·2000037ef0:·2020·2020·2020·2028·6173·206f·6620·3230·········(as·of·20
00037f00:·3236·2d30·312d·3038·290a·2020·2020·2020··26-01-08).······00037f00:·3234·2d31·322d·3037·290a·2020·2020·2020··24-12-07).······
00037f10:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><00037f10:·2020·2020·2020·2020·2020·3c2f·6c69·3e3c············</li><
00037f20:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta00037f20:·2f75·6c3e·3c2f·6469·763e·3c68·323e·5461··/ul></div><h2>Ta
00037f30:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<00037f30:·626c·6520·6f66·2043·6f6e·7465·6e74·733c··ble·of·Contents<
00037f40:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h00037f40:·2f68·323e·3c6f·6c3e·3c6c·693e·3c61·2068··/h2><ol><li><a·h
00037f50:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.00037f50:·7265·663d·2223·7863·6364·665f·6f72·672e··ref="#xccdf_org.
00037f60:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte00037f60:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte
00037f70:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"00037f70:·6e74·5f67·726f·7570·5f73·7973·7465·6d22··nt_group_system"
Offset 15135, 129 lines modifiedOffset 15135, 129 lines modified
0003b1e0:·7461·7267·6574·3d22·2369·646d·3633·3333··target="#idm63330003b1e0:·7461·7267·6574·3d22·2369·646d·3633·3333··target="#idm6333
0003b1f0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003b1f0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003b200:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003b200:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003b210:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003b210:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003b220:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003b220:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003b230:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003b230:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003b240:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003b240:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0003b250:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue
 0003b260:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·..
 0003b270:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003b280:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003b290:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003b2a0:·3d22·6964·6d36·3333·3322·3e3c·7072·653e··="idm6333"><pre>
 0003b2b0:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package
 0003b2c0:·735d·5d0a·6e61·6d65·203d·2022·6169·6465··s]].name·=·"aide
 0003b2d0:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*".
0003b250:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003b260:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003b270:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003b280:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003b290:·2069·643d·2269·646d·3633·3333·223e·3c74···id="idm6333"><t 
0003b2a0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003b2b0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003b2c0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003b2d0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003b2e0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003b2f0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003b300:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b310:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003b320:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003b330:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003b340:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003b350:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b360:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0003b370:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003b380:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003b390:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat 
0003b3a0:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl 
0003b3b0:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai 
0003b3c0:·6e20·706c·6174·666f·726d·730a·6966·205b··n·platforms.if·[ 
0003b3d0:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren 
0003b3e0:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[ 
0003b3f0:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont 
0003b400:·6169·6e65·7265·6e76·205d·3b20·7468·656e··ainerenv·];·then 
0003b410:·0a0a·7a79·7070·6572·2069·6e73·7461·6c6c··..zypper·install 
0003b420:·202d·7920·2261·6964·6522·0a0a·656c·7365···-y·"aide"..else 
0003b430:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2· 
0003b440:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio 
0003b450:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica 
0003b460:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was 
0003b470:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code 
0003b480:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003b490:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003b4a0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003b4b0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003b4c0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003b4d0:·3633·3334·2220·7461·6269·6e64·6578·3d22··6334"·tabindex=" 
0003b4e0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003b4f0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003b500:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003b510:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003b520:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003b530:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible· 
0003b540:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003b550:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b560:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b570:·6c6c·6170·7365·2220·6964·3d22·6964·6d36··llapse"·id="idm6 
0003b580:·3333·3422·3e3c·7461·626c·6520·636c·6173··334"><table·clas 
0003b590:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b5a0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b5b0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b5c0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b5d0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b5e0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b5f0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b600:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b610:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b620:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b630:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003b640:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b650:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b660:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b670:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n 
0003b680:·616d·653a·2045·6e73·7572·6520·6169·6465··ame:·Ensure·aide 
0003b690:·2069·7320·696e·7374·616c·6c65·640a·2020···is·installed.·· 
0003b6a0:·7061·636b·6167·653a·0a20·2020·206e·616d··package:.····nam 
0003b6b0:·653a·2061·6964·650a·2020·2020·7374·6174··e:·aide.····stat 
0003b6c0:·653a·2070·7265·7365·6e74·0a20·2077·6865··e:·present.··whe 
0003b6d0:·6e3a·2061·6e73·6962·6c65·5f76·6972·7475··n:·ansible_virtu 
0003b6e0:·616c·697a·6174·696f·6e5f·7479·7065·206e··alization_type·n 
0003b6f0:·6f74·2069·6e20·5b22·646f·636b·6572·222c··ot·in·["docker", 
0003b700:·2022·6c78·6322·2c20·226f·7065·6e76·7a22···"lxc",·"openvz" 
0003b710:·2c20·2270·6f64·6d61·6e22·2c20·2263·6f6e··,·"podman",·"con 
0003b720:·7461·696e·6572·225d·0a20·2074·6167·733a··tainer"].··tags: 
0003b730:·0a20·202d·2043·4345·2d38·3332·3839·2d39··.··-·CCE-83289-9 
0003b740:·0a20·202d·2043·4a49·532d·352e·3130·2e31··.··-·CJIS-5.10.1 
0003b750:·2e33·0a20·202d·2044·4953·412d·5354·4947··.3.··-·DISA-STIG 
0003b760:·2d53·4c45·532d·3135·2d30·3130·3431·390a··-SLES-15-010419. 
0003b770:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53- 
0003b780:·434d·2d36·2861·290a·2020·2d20·5043·492d··CM-6(a).··-·PCI- 
0003b790:·4453·532d·5265·712d·3131·2e35·0a20·202d··DSS-Req-11.5.··- 
0003b7a0:·2050·4349·2d44·5353·7634·2d31·312e·352e···PCI-DSSv4-11.5. 
0003b7b0:·320a·2020·2d20·656e·6162·6c65·5f73·7472··2.··-·enable_str 
0003b7c0:·6174·6567·790a·2020·2d20·6c6f·775f·636f··ategy.··-·low_co 
0003b7d0:·6d70·6c65·7869·7479·0a20·202d·206c·6f77··mplexity.··-·low 
0003b7e0:·5f64·6973·7275·7074·696f·6e0a·2020·2d20··_disruption.··-· 
0003b7f0:·6d65·6469·756d·5f73·6576·6572·6974·790a··medium_severity. 
0003b800:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne 
0003b810:·6564·6564·0a20·202d·2070·6163·6b61·6765··eded.··-·package 
0003b820:·5f61·6964·655f·696e·7374·616c·6c65·640a··_aide_installed. 
0003b830:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d0003b2e0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
Max diff block lines reached; 22529907/22547487 bytes (99.92%) of diff not shown.
1.66 MB
html2text {}
    
Offset 42, 15 lines modifiedOffset 42, 15 lines modified
42 ··············(SLES)·for·SAP·Applications·1542 ··············(SLES)·for·SAP·Applications·15
43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pcs-hardening-sap43 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pcs-hardening-sap
44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*44 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
45 ····*·cpe:/o:suse:linux_enterprise_desktop:1545 ····*·cpe:/o:suse:linux_enterprise_desktop:15
46 ····*·cpe:/o:suse:linux_enterprise_server:1546 ····*·cpe:/o:suse:linux_enterprise_server:15
47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
48 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8448 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)49 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*50 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s51 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e52 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l53 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
54 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g54 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
55 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s55 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
56 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s56 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 125, 27 lines modifiedOffset 125, 19 lines modified
125 include·install_aide125 include·install_aide
  
126 class·install_aide·{126 class·install_aide·{
127 ··package·{·'aide':127 ··package·{·'aide':
128 ····ensure·=>·'installed',128 ····ensure·=>·'installed',
129 ··}129 ··}
130 }130 }
 131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
136 #·Remediation·is·applicable·only·in·certain·platforms 
137 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
138 zypper·install·-y·"aide" 
  
139 else 
140 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
141 fi132 [[packages]]
 133 name·=·"aide"
 134 version·=·"*"
142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
147 -·name:·Ensure·aide·is·installed140 -·name:·Ensure·aide·is·installed
148 ··package:141 ··package:
Offset 161, 19 lines modifiedOffset 153, 27 lines modified
161 ··-·PCI-DSSv4-11.5.2153 ··-·PCI-DSSv4-11.5.2
162 ··-·enable_strategy154 ··-·enable_strategy
163 ··-·low_complexity155 ··-·low_complexity
164 ··-·low_disruption156 ··-·low_disruption
165 ··-·medium_severity157 ··-·medium_severity
166 ··-·no_reboot_needed158 ··-·no_reboot_needed
167 ··-·package_aide_installed159 ··-·package_aide_installed
168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 161 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 162 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 163 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 164 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 165 #·Remediation·is·applicable·only·in·certain·platforms
 166 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
169 [[packages]] 
170 name·=·"aide" 
171 version·=·"*"167 zypper·install·-y·"aide"
  
 168 else
 169 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 170 fi
172 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·A\x8AI\x8ID\x8DE\x8E·t\x8to\x8o·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8he\x8e·A\x8Au\x8ud\x8di\x8it\x8t·T\x8To\x8oo\x8ol\x8ls\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*171 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·A\x8AI\x8ID\x8DE\x8E·t\x8to\x8o·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8he\x8e·A\x8Au\x8ud\x8di\x8it\x8t·T\x8To\x8oo\x8ol\x8ls\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
173 The·operating·system·file·integrity·tool·must·be·configured·to·protect·the·integrity·of·the·audit·tools.172 The·operating·system·file·integrity·tool·must·be·configured·to·protect·the·integrity·of·the·audit·tools.
174 ·············Protecting·the·integrity·of·the·tools·used·for·auditing·purposes·is·a·critical·step·toward173 ·············Protecting·the·integrity·of·the·tools·used·for·auditing·purposes·is·a·critical·step·toward
175 ·············ensuring·the·integrity·of·audit·information.·Audit·information·includes·all·information·(e.g.,174 ·············ensuring·the·integrity·of·audit·information.·Audit·information·includes·all·information·(e.g.,
176 ·············audit·records,·audit·settings,·and·audit·reports)·needed·to·successfully·audit·information175 ·············audit·records,·audit·settings,·and·audit·reports)·needed·to·successfully·audit·information
177 ·············system·activity.·Audit·tools·include·but·are·not·limited·to·vendor-provided·and·open-source176 ·············system·activity.·Audit·tools·include·but·are·not·limited·to·vendor-provided·and·open-source
178 ·············audit·tools·needed·to·successfully·view·and·manipulate·audit·information·system·activity·and177 ·············audit·tools·needed·to·successfully·view·and·manipulate·audit·information·system·activity·and
Offset 187, 82 lines modifiedOffset 187, 14 lines modified
187 Rule·ID:·····xccdf_org.ssgproject.content_rule_aide_check_audit_tools187 Rule·ID:·····xccdf_org.ssgproject.content_rule_aide_check_audit_tools
188 Identifiers:·CCE-85610-4188 Identifiers:·CCE-85610-4
189 ·············_\x8d_\x8i_\x8s_\x8a····CCI-001496189 ·············_\x8d_\x8i_\x8s_\x8a····CCI-001496
190 ·············_\x8n_\x8i_\x8s_\x8t····AU-9(3),·AU-9(3).1190 ·············_\x8n_\x8i_\x8s_\x8t····AU-9(3),·AU-9(3).1
191 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000278-GPOS-00108191 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000278-GPOS-00108
192 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-030630192 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-030630
193 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234962r877393_rule193 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234962r877393_rule
194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
199 #·Remediation·is·applicable·only·in·certain·platforms 
200 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
201 zypper·install·-y·"aide" 
  
  
  
  
  
  
  
  
  
  
202 if·grep·-i·'^.*/usr/sbin/auditctl.*$'·/etc/aide.conf;·then 
203 sed·-i·"s#.*/usr/sbin/auditctl.*#/usr/sbin/auditctl·p+i+n+u+g+s+b+acl+selinux+xattrs+sha512#"·/etc/ 
204 aide.conf 
205 else 
206 echo·"/usr/sbin/auditctl·p+i+n+u+g+s+b+acl+selinux+xattrs+sha512"·>>·/etc/aide.conf 
207 fi 
  
208 if·grep·-i·'^.*/usr/sbin/auditd.*$'·/etc/aide.conf;·then 
209 sed·-i·"s#.*/usr/sbin/auditd.*#/usr/sbin/auditd·p+i+n+u+g+s+b+acl+selinux+xattrs+sha512#"·/etc/aide.conf 
210 else 
211 echo·"/usr/sbin/auditd·p+i+n+u+g+s+b+acl+selinux+xattrs+sha512"·>>·/etc/aide.conf 
212 fi 
  
213 if·grep·-i·'^.*/usr/sbin/ausearch.*$'·/etc/aide.conf;·then 
214 sed·-i·"s#.*/usr/sbin/ausearch.*#/usr/sbin/ausearch·p+i+n+u+g+s+b+acl+selinux+xattrs+sha512#"·/etc/ 
215 aide.conf 
216 else 
217 echo·"/usr/sbin/ausearch·p+i+n+u+g+s+b+acl+selinux+xattrs+sha512"·>>·/etc/aide.conf 
218 fi 
  
219 if·grep·-i·'^.*/usr/sbin/aureport.*$'·/etc/aide.conf;·then 
220 sed·-i·"s#.*/usr/sbin/aureport.*#/usr/sbin/aureport·p+i+n+u+g+s+b+acl+selinux+xattrs+sha512#"·/etc/ 
221 aide.conf 
222 else 
Max diff block lines reached; 1735820/1742378 bytes (99.62%) of diff not shown.
21.4 MB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-pcs-hardening.html
    
Offset 14300, 16 lines modifiedOffset 14300, 16 lines modified
00037db0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</00037db0:·7669·7369·6f6e·2048·6973·746f·7279·3c2f··vision·History</
00037dc0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve00037dc0:·6832·3e3c·703e·4375·7272·656e·7420·7665··h2><p>Current·ve
00037dd0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>000037dd0:·7273·696f·6e3a·203c·7374·726f·6e67·3e30··rsion:·<strong>0
00037de0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></00037de0:·2e31·2e37·343c·2f73·7472·6f6e·673e·3c2f··.1.74</strong></
00037df0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron00037df0:·703e·3c75·6c3e·3c6c·693e·3c73·7472·6f6e··p><ul><li><stron
00037e00:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>00037e00:·673e·6472·6166·743c·2f73·7472·6f6e·673e··g>draft</strong>
00037e10:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037e10:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037e20:·2020·2020·2028·6173·206f·6620·3230·3236·······(as·of·202600037e20:·2020·2020·2028·6173·206f·6620·3230·3234·······(as·of·2024
00037e30:·2d30·312d·3038·290a·2020·2020·2020·2020··-01-08).········00037e30:·2d31·322d·3037·290a·2020·2020·2020·2020··-12-07).········
00037e40:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u00037e40:·2020·2020·2020·2020·3c2f·6c69·3e3c·2f75··········</li></u
00037e50:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl00037e50:·6c3e·3c2f·6469·763e·3c68·323e·5461·626c··l></div><h2>Tabl
00037e60:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h00037e60:·6520·6f66·2043·6f6e·7465·6e74·733c·2f68··e·of·Contents</h
00037e70:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre00037e70:·323e·3c6f·6c3e·3c6c·693e·3c61·2068·7265··2><ol><li><a·hre
00037e80:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss00037e80:·663d·2223·7863·6364·665f·6f72·672e·7373··f="#xccdf_org.ss
00037e90:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content00037e90:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
00037ea0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S00037ea0:·5f67·726f·7570·5f73·7973·7465·6d22·3e53··_group_system">S
Offset 15007, 358 lines modifiedOffset 15007, 358 lines modified
0003a9e0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003a9e0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003a9f0:·743d·2223·6964·6d36·3434·3022·2074·6162··t="#idm6440"·tab0003a9f0:·743d·2223·6964·6d36·3434·3022·2074·6162··t="#idm6440"·tab
0003aa00:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003aa00:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003aa10:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003aa10:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003aa20:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003aa20:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003aa30:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003aa30:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003aa40:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003aa40:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003aa50:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S0003aa50:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
 0003aa60:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.
 0003aa70:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003aa80:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003aa90:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003aaa0:·643d·2269·646d·3634·3430·223e·3c74·6162··d="idm6440"><tab
 0003aab0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0003aac0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0003aad0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 0003aae0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 0003aaf0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 0003ab00:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003ab10:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0003ab20:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003aa60:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
0003aa70:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003aa80:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003aa90:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003aaa0:·6964·6d36·3434·3022·3e3c·7461·626c·6520··idm6440"><table· 
0003aab0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003aac0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003aad0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003aae0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003aaf0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003ab00:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003ab10:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003ab20:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003ab30:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003ab40:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003ab50:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003ab60:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003ab70:·7465·6779·3a3c·2f74·683e·3c74·643e·7265··tegy:</th><td>re 
0003ab80:·7374·7269·6374·3c2f·7464·3e3c·2f74·723e··strict</td></tr>0003ab30:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003ab90:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003aba0:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation 
0003abb0:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o 
0003abc0:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p 
0003abd0:·6c61·7466·6f72·6d73·0a69·6620·5b20·2120··latforms.if·[·!· 
0003abe0:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·] 
0003abf0:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!· 
0003ac00:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain 
0003ac10:·6572·656e·7620·5d3b·2074·6865·6e0a·0a7a··erenv·];·then..z 
0003ac20:·7970·7065·7220·696e·7374·616c·6c20·2d79··ypper·install·-y 
0003ac30:·2022·6169·6465·220a·0a0a·0a0a·0a0a·0a0a···"aide"......... 
0003ac40:·0a0a·6966·2067·7265·7020·2d69·2027·5e2e··..if·grep·-i·'^. 
0003ac50:·2a2f·7573·722f·7362·696e·2f61·7564·6974··*/usr/sbin/audit 
0003ac60:·6374·6c2e·2a24·2720·2f65·7463·2f61·6964··ctl.*$'·/etc/aid 
0003ac70:·652e·636f·6e66·3b20·7468·656e·0a73·6564··e.conf;·then.sed 
0003ac80:·202d·6920·2273·232e·2a2f·7573·722f·7362···-i·"s#.*/usr/sb 
0003ac90:·696e·2f61·7564·6974·6374·6c2e·2a23·2f75··in/auditctl.*#/u 
0003aca0:·7372·2f73·6269·6e2f·6175·6469·7463·746c··sr/sbin/auditctl 
0003acb0:·2070·2b69·2b6e·2b75·2b67·2b73·2b62·2b61···p+i+n+u+g+s+b+a 
0003acc0:·636c·2b73·656c·696e·7578·2b78·6174·7472··cl+selinux+xattr 
0003acd0:·732b·7368·6135·3132·2322·202f·6574·632f··s+sha512#"·/etc/ 
0003ace0:·6169·6465·2e63·6f6e·660a·656c·7365·0a65··aide.conf.else.e 
0003acf0:·6368·6f20·222f·7573·722f·7362·696e·2f61··cho·"/usr/sbin/a 
0003ad00:·7564·6974·6374·6c20·702b·692b·6e2b·752b··uditctl·p+i+n+u+ 
0003ad10:·672b·732b·622b·6163·6c2b·7365·6c69·6e75··g+s+b+acl+selinu 
0003ad20:·782b·7861·7474·7273·2b73·6861·3531·3222··x+xattrs+sha512" 
0003ad30:·2026·6774·3b26·6774·3b20·2f65·7463·2f61···&gt;&gt;·/etc/a 
0003ad40:·6964·652e·636f·6e66·0a66·690a·0a69·6620··ide.conf.fi..if· 
0003ad50:·6772·6570·202d·6920·275e·2e2a·2f75·7372··grep·-i·'^.*/usr 
0003ad60:·2f73·6269·6e2f·6175·6469·7464·2e2a·2427··/sbin/auditd.*$' 
0003ad70:·202f·6574·632f·6169·6465·2e63·6f6e·663b···/etc/aide.conf; 
0003ad80:·2074·6865·6e0a·7365·6420·2d69·2022·7323···then.sed·-i·"s# 
0003ad90:·2e2a·2f75·7372·2f73·6269·6e2f·6175·6469··.*/usr/sbin/audi 
0003ada0:·7464·2e2a·232f·7573·722f·7362·696e·2f61··td.*#/usr/sbin/a 
0003adb0:·7564·6974·6420·702b·692b·6e2b·752b·672b··uditd·p+i+n+u+g+ 
0003adc0:·732b·622b·6163·6c2b·7365·6c69·6e75·782b··s+b+acl+selinux+ 
0003add0:·7861·7474·7273·2b73·6861·3531·3223·2220··xattrs+sha512#"· 
0003ade0:·2f65·7463·2f61·6964·652e·636f·6e66·0a65··/etc/aide.conf.e 
0003adf0:·6c73·650a·6563·686f·2022·2f75·7372·2f73··lse.echo·"/usr/s 
0003ae00:·6269·6e2f·6175·6469·7464·2070·2b69·2b6e··bin/auditd·p+i+n 
0003ae10:·2b75·2b67·2b73·2b62·2b61·636c·2b73·656c··+u+g+s+b+acl+sel 
0003ae20:·696e·7578·2b78·6174·7472·732b·7368·6135··inux+xattrs+sha5 
0003ae30:·3132·2220·2667·743b·2667·743b·202f·6574··12"·&gt;&gt;·/et 
0003ae40:·632f·6169·6465·2e63·6f6e·660a·6669·0a0a··c/aide.conf.fi.. 
0003ae50:·6966·2067·7265·7020·2d69·2027·5e2e·2a2f··if·grep·-i·'^.*/ 
0003ae60:·7573·722f·7362·696e·2f61·7573·6561·7263··usr/sbin/ausearc 
0003ae70:·682e·2a24·2720·2f65·7463·2f61·6964·652e··h.*$'·/etc/aide. 
0003ae80:·636f·6e66·3b20·7468·656e·0a73·6564·202d··conf;·then.sed·- 
0003ae90:·6920·2273·232e·2a2f·7573·722f·7362·696e··i·"s#.*/usr/sbin 
0003aea0:·2f61·7573·6561·7263·682e·2a23·2f75·7372··/ausearch.*#/usr 
0003aeb0:·2f73·6269·6e2f·6175·7365·6172·6368·2070··/sbin/ausearch·p 
0003aec0:·2b69·2b6e·2b75·2b67·2b73·2b62·2b61·636c··+i+n+u+g+s+b+acl 
0003aed0:·2b73·656c·696e·7578·2b78·6174·7472·732b··+selinux+xattrs+ 
0003aee0:·7368·6135·3132·2322·202f·6574·632f·6169··sha512#"·/etc/ai 
0003aef0:·6465·2e63·6f6e·660a·656c·7365·0a65·6368··de.conf.else.ech 
0003af00:·6f20·222f·7573·722f·7362·696e·2f61·7573··o·"/usr/sbin/aus 
0003af10:·6561·7263·6820·702b·692b·6e2b·752b·672b··earch·p+i+n+u+g+ 
0003af20:·732b·622b·6163·6c2b·7365·6c69·6e75·782b··s+b+acl+selinux+ 
0003af30:·7861·7474·7273·2b73·6861·3531·3222·2026··xattrs+sha512"·& 
0003af40:·6774·3b26·6774·3b20·2f65·7463·2f61·6964··gt;&gt;·/etc/aid 
0003af50:·652e·636f·6e66·0a66·690a·0a69·6620·6772··e.conf.fi..if·gr 
0003af60:·6570·202d·6920·275e·2e2a·2f75·7372·2f73··ep·-i·'^.*/usr/s 
0003af70:·6269·6e2f·6175·7265·706f·7274·2e2a·2427··bin/aureport.*$' 
0003af80:·202f·6574·632f·6169·6465·2e63·6f6e·663b···/etc/aide.conf; 
0003af90:·2074·6865·6e0a·7365·6420·2d69·2022·7323···then.sed·-i·"s# 
0003afa0:·2e2a·2f75·7372·2f73·6269·6e2f·6175·7265··.*/usr/sbin/aure 
0003afb0:·706f·7274·2e2a·232f·7573·722f·7362·696e··port.*#/usr/sbin 
0003afc0:·2f61·7572·6570·6f72·7420·702b·692b·6e2b··/aureport·p+i+n+ 
0003afd0:·752b·672b·732b·622b·6163·6c2b·7365·6c69··u+g+s+b+acl+seli 
0003afe0:·6e75·782b·7861·7474·7273·2b73·6861·3531··nux+xattrs+sha51 
Max diff block lines reached; 20875245/20924565 bytes (99.76%) of diff not shown.
1.43 MB
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Public·Cloud·Hardening·for·SUSE·Linux·Enterprise·1538 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Public·Cloud·Hardening·for·SUSE·Linux·Enterprise·15
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pcs-hardening39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_pcs-hardening
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:suse:linux_enterprise_desktop:1541 ····*·cpe:/o:suse:linux_enterprise_desktop:15
42 ····*·cpe:/o:suse:linux_enterprise_server:1542 ····*·cpe:/o:suse:linux_enterprise_server:15
43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
44 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8444 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
49 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l49 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g50 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
51 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s51 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
52 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s52 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 101, 82 lines modifiedOffset 101, 14 lines modified
101 Rule·ID:·····xccdf_org.ssgproject.content_rule_aide_check_audit_tools101 Rule·ID:·····xccdf_org.ssgproject.content_rule_aide_check_audit_tools
102 Identifiers:·CCE-85610-4102 Identifiers:·CCE-85610-4
103 ·············_\x8d_\x8i_\x8s_\x8a····CCI-001496103 ·············_\x8d_\x8i_\x8s_\x8a····CCI-001496
104 ·············_\x8n_\x8i_\x8s_\x8t····AU-9(3),·AU-9(3).1104 ·············_\x8n_\x8i_\x8s_\x8t····AU-9(3),·AU-9(3).1
105 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000278-GPOS-00108105 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000278-GPOS-00108
106 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-030630106 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-030630
107 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234962r877393_rule107 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234962r877393_rule
108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
109 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
110 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
111 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
112 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
113 #·Remediation·is·applicable·only·in·certain·platforms 
114 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
115 zypper·install·-y·"aide" 
  
  
  
  
  
  
  
  
  
  
116 if·grep·-i·'^.*/usr/sbin/auditctl.*$'·/etc/aide.conf;·then 
117 sed·-i·"s#.*/usr/sbin/auditctl.*#/usr/sbin/auditctl·p+i+n+u+g+s+b+acl+selinux+xattrs+sha512#"·/etc/ 
118 aide.conf 
119 else 
120 echo·"/usr/sbin/auditctl·p+i+n+u+g+s+b+acl+selinux+xattrs+sha512"·>>·/etc/aide.conf 
121 fi 
  
122 if·grep·-i·'^.*/usr/sbin/auditd.*$'·/etc/aide.conf;·then 
123 sed·-i·"s#.*/usr/sbin/auditd.*#/usr/sbin/auditd·p+i+n+u+g+s+b+acl+selinux+xattrs+sha512#"·/etc/aide.conf 
124 else 
125 echo·"/usr/sbin/auditd·p+i+n+u+g+s+b+acl+selinux+xattrs+sha512"·>>·/etc/aide.conf 
126 fi 
  
127 if·grep·-i·'^.*/usr/sbin/ausearch.*$'·/etc/aide.conf;·then 
128 sed·-i·"s#.*/usr/sbin/ausearch.*#/usr/sbin/ausearch·p+i+n+u+g+s+b+acl+selinux+xattrs+sha512#"·/etc/ 
129 aide.conf 
130 else 
131 echo·"/usr/sbin/ausearch·p+i+n+u+g+s+b+acl+selinux+xattrs+sha512"·>>·/etc/aide.conf 
132 fi 
  
133 if·grep·-i·'^.*/usr/sbin/aureport.*$'·/etc/aide.conf;·then 
134 sed·-i·"s#.*/usr/sbin/aureport.*#/usr/sbin/aureport·p+i+n+u+g+s+b+acl+selinux+xattrs+sha512#"·/etc/ 
135 aide.conf 
136 else 
137 echo·"/usr/sbin/aureport·p+i+n+u+g+s+b+acl+selinux+xattrs+sha512"·>>·/etc/aide.conf 
138 fi 
  
139 if·grep·-i·'^.*/usr/sbin/autrace.*$'·/etc/aide.conf;·then 
140 sed·-i·"s#.*/usr/sbin/autrace.*#/usr/sbin/autrace·p+i+n+u+g+s+b+acl+selinux+xattrs+sha512#"·/etc/aide.conf 
141 else 
142 echo·"/usr/sbin/autrace·p+i+n+u+g+s+b+acl+selinux+xattrs+sha512"·>>·/etc/aide.conf 
143 fi 
  
144 if·grep·-i·'^.*/usr/sbin/augenrules.*$'·/etc/aide.conf;·then 
145 sed·-i·"s#.*/usr/sbin/augenrules.*#/usr/sbin/augenrules·p+i+n+u+g+s+b+acl+selinux+xattrs+sha512#"·/etc/ 
146 aide.conf 
147 else 
148 echo·"/usr/sbin/augenrules·p+i+n+u+g+s+b+acl+selinux+xattrs+sha512"·>>·/etc/aide.conf 
149 fi 
  
150 if·grep·-i·'^.*/usr/sbin/audispd.*$'·/etc/aide.conf;·then 
151 sed·-i·"s#.*/usr/sbin/audispd.*#/usr/sbin/audispd·p+i+n+u+g+s+b+acl+selinux+xattrs+sha512#"·/etc/aide.conf 
152 else 
153 echo·"/usr/sbin/audispd·p+i+n+u+g+s+b+acl+selinux+xattrs+sha512"·>>·/etc/aide.conf 
154 fi 
  
155 else 
156 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
157 fi 
158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
159 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low109 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
160 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low110 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
161 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false111 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
162 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict112 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
163 -·name:·Configure·AIDE·to·Verify·the·Audit·Tools·-·Gather·List·of·Packages113 -·name:·Configure·AIDE·to·Verify·the·Audit·Tools·-·Gather·List·of·Packages
164 ··tags:114 ··tags:
Offset 269, 14 lines modifiedOffset 201, 82 lines modified
269 ··-·NIST-800-53-AU-9(3).1201 ··-·NIST-800-53-AU-9(3).1
270 ··-·aide_check_audit_tools202 ··-·aide_check_audit_tools
271 ··-·low_complexity203 ··-·low_complexity
272 ··-·low_disruption204 ··-·low_disruption
273 ··-·medium_severity205 ··-·medium_severity
274 ··-·no_reboot_needed206 ··-·no_reboot_needed
275 ··-·restrict_strategy207 ··-·restrict_strategy
 208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 209 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 210 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 211 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 212 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 213 #·Remediation·is·applicable·only·in·certain·platforms
 214 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 215 zypper·install·-y·"aide"
  
  
  
  
  
  
  
  
  
  
 216 if·grep·-i·'^.*/usr/sbin/auditctl.*$'·/etc/aide.conf;·then
 217 sed·-i·"s#.*/usr/sbin/auditctl.*#/usr/sbin/auditctl·p+i+n+u+g+s+b+acl+selinux+xattrs+sha512#"·/etc/
Max diff block lines reached; 1490979/1497892 bytes (99.54%) of diff not shown.
9.55 MB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-standard.html
    
Offset 14307, 15 lines modifiedOffset 14307, 15 lines modified
00037e20:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren00037e20:·7279·3c2f·6832·3e3c·703e·4375·7272·656e··ry</h2><p>Curren
00037e30:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro00037e30:·7420·7665·7273·696f·6e3a·203c·7374·726f··t·version:·<stro
00037e40:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron00037e40:·6e67·3e30·2e31·2e37·343c·2f73·7472·6f6e··ng>0.1.74</stron
00037e50:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s00037e50:·673e·3c2f·703e·3c75·6c3e·3c6c·693e·3c73··g></p><ul><li><s
00037e60:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str00037e60:·7472·6f6e·673e·6472·6166·743c·2f73·7472··trong>draft</str
00037e70:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········00037e70:·6f6e·673e·0a20·2020·2020·2020·2020·2020··ong>.···········
00037e80:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·00037e80:·2020·2020·2020·2020·2028·6173·206f·6620···········(as·of·
00037e90:·3230·3236·2d30·312d·3038·290a·2020·2020··2026-01-08).····00037e90:·3230·3234·2d31·322d·3037·290a·2020·2020··2024-12-07).····
00037ea0:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li00037ea0:·2020·2020·2020·2020·2020·2020·3c2f·6c69··············</li
00037eb0:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>00037eb0:·3e3c·2f75·6c3e·3c2f·6469·763e·3c68·323e··></ul></div><h2>
00037ec0:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content00037ec0:·5461·626c·6520·6f66·2043·6f6e·7465·6e74··Table·of·Content
00037ed0:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a00037ed0:·733c·2f68·323e·3c6f·6c3e·3c6c·693e·3c61··s</h2><ol><li><a
00037ee0:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or00037ee0:·2068·7265·663d·2223·7863·6364·665f·6f72···href="#xccdf_or
00037ef0:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con00037ef0:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con
00037f00:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste00037f00:·7465·6e74·5f67·726f·7570·5f73·7973·7465··tent_group_syste
Offset 16822, 96 lines modifiedOffset 16822, 96 lines modified
00041b50:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe00041b50:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
00041b60:·743d·2223·6964·6d39·3336·3222·2074·6162··t="#idm9362"·tab00041b60:·743d·2223·6964·6d39·3336·3222·2074·6162··t="#idm9362"·tab
00041b70:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="00041b70:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
00041b80:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp00041b80:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
00041b90:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti00041b90:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
00041ba0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to00041ba0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
00041bb0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#00041bb0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
00041bc0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S00041bc0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
00041bd0:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
00041be0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
00041bf0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
00041c00:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
00041c10:·6964·6d39·3336·3222·3e3c·7461·626c·6520··idm9362"><table· 
00041c20:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
00041c30:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
00041c40:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
00041c50:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
00041c60:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
00041c70:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
00041c80:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
00041c90:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>00041bd0:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.
 00041be0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 00041bf0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 00041c00:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 00041c10:·643d·2269·646d·3933·3632·223e·3c74·6162··d="idm9362"><tab
 00041c20:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 00041c30:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 00041c40:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 00041c50:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 00041c60:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 00041c70:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 00041c80:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 00041c90:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 00041ca0:·7464·3e68·6967·683c·2f74·643e·3c2f·7472··td>high</td></tr
 00041cb0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 00041cc0:·3c2f·7468·3e3c·7464·3e74·7275·653c·2f74··</th><td>true</t
 00041cd0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 00041ce0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
00041ca0:·6869·6768·3c2f·7464·3e3c·2f74·723e·3c74··high</td></tr><t00041cf0:·3e70·6174·6368·3c2f·7464·3e3c·2f74·723e··>patch</td></tr>
00041cb0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
00041cc0:·683e·3c74·643e·7472·7565·3c2f·7464·3e3c··h><td>true</td>< 
00041cd0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
00041ce0:·7465·6779·3a3c·2f74·683e·3c74·643e·7061··tegy:</th><td>pa 
00041cf0:·7463·683c·2f74·643e·3c2f·7472·3e3c·2f74··tch</td></tr></t 
00041d00:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
00041d10:·0a0a·7a79·7070·6572·2070·6174·6368·202d··..zypper·patch·- 
00041d20:·6720·7365·6375·7269·7479·202d·790a·3c2f··g·security·-y.</ 
00041d30:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
00041d40:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
00041d50:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
00041d60:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps00041d00:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 00041d10:·6465·3e2d·206e·616d·653a·2053·6563·7572··de>-·name:·Secur
 00041d20:·6974·7920·7061·7463·6865·7320·6172·6520··ity·patches·are·
 00041d30:·7570·2074·6f20·6461·7465·0a20·2070·6163··up·to·date.··pac
 00041d40:·6b61·6765·3a0a·2020·2020·6e61·6d65·3a20··kage:.····name:·
 00041d50:·272a·270a·2020·2020·7374·6174·653a·206c··'*'.····state:·l
 00041d60:·6174·6573·740a·2020·7461·6773·3a0a·2020··atest.··tags:.··
 00041d70:·2d20·4343·452d·3833·3236·312d·380a·2020··-·CCE-83261-8.··
 00041d80:·2d20·434a·4953·2d35·2e31·302e·342e·310a··-·CJIS-5.10.4.1.
 00041d90:·2020·2d20·4449·5341·2d53·5449·472d·534c····-·DISA-STIG-SL
 00041da0:·4553·2d31·352d·3031·3030·3130·0a20·202d··ES-15-010010.··-
 00041db0:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-
 00041dc0:·3628·6129·0a20·202d·204e·4953·542d·3830··6(a).··-·NIST-80
 00041dd0:·302d·3533·2d53·492d·3228·3529·0a20·202d··0-53-SI-2(5).··-
 00041de0:·204e·4953·542d·3830·302d·3533·2d53·492d···NIST-800-53-SI-
 00041df0:·3228·6329·0a20·202d·2050·4349·2d44·5353··2(c).··-·PCI-DSS
 00041e00:·2d52·6571·2d36·2e32·0a20·202d·2050·4349··-Req-6.2.··-·PCI
 00041e10:·2d44·5353·7634·2d36·2e33·2e33·0a20·202d··-DSSv4-6.3.3.··-
 00041e20:·2068·6967·685f·6469·7372·7570·7469·6f6e···high_disruption
 00041e30:·0a20·202d·206c·6f77·5f63·6f6d·706c·6578··.··-·low_complex
 00041e40:·6974·790a·2020·2d20·6d65·6469·756d·5f73··ity.··-·medium_s
 00041e50:·6576·6572·6974·790a·2020·2d20·7061·7463··everity.··-·patc
 00041e60:·685f·7374·7261·7465·6779·0a20·202d·2072··h_strategy.··-·r
 00041e70:·6562·6f6f·745f·7265·7175·6972·6564·0a20··eboot_required.·
 00041e80:·202d·2073·6563·7572·6974·795f·7061·7463···-·security_patc
 00041e90:·6865·735f·7570·5f74·6f5f·6461·7465·0a20··hes_up_to_date.·
 00041ea0:·202d·2073·6b69·705f·616e·7369·626c·655f···-·skip_ansible_
 00041eb0:·6c69·6e74·0a3c·2f63·6f64·653e·3c2f·7072··lint.</code></pr
 00041ec0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 00041ed0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
00041d70:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="00041ee0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
00041d80:·2369·646d·3933·3633·2220·7461·6269·6e64··#idm9363"·tabind 
00041d90:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
00041da0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
00041db0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
00041dc0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
00041dd0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
00041de0:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi 
00041df0:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...<00041ef0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 00041f00:·6172·6765·743d·2223·6964·6d39·3336·3322··arget="#idm9363"
 00041f10:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 00041f20:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 00041f30:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 00041f40:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 00041f50:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 00041f60:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 00041f70:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
00041e00:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas00041f80:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
00041e10:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps00041f90:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
00041e20:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="00041fa0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
00041e30:·6964·6d39·3336·3322·3e3c·7461·626c·6520··idm9363"><table·00041fb0:·6964·3d22·6964·6d39·3336·3322·3e3c·7461··id="idm9363"><ta
00041e40:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab00041fc0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
00041e50:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table00041fd0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
00041e60:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-00041fe0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
00041e70:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><00041ff0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
00041e80:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</00042000:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
00041e90:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><00042010:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
00041ea0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
00041eb0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
00041ec0:·6869·6768·3c2f·7464·3e3c·2f74·723e·3c74··high</td></tr><t 
00041ed0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
Max diff block lines reached; 9098510/9111534 bytes (99.86%) of diff not shown.
885 KB
html2text {}
    
Offset 41, 15 lines modifiedOffset 41, 15 lines modified
41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·SUSE·Linux·Enterprise·1541 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·SUSE·Linux·Enterprise·15
42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard42 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard
43 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*43 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
44 ····*·cpe:/o:suse:linux_enterprise_desktop:1544 ····*·cpe:/o:suse:linux_enterprise_desktop:15
45 ····*·cpe:/o:suse:linux_enterprise_server:1545 ····*·cpe:/o:suse:linux_enterprise_server:15
46 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
47 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8447 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
48 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)48 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
49 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*49 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
50 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s50 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
51 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e51 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
52 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l52 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
53 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g53 ·········3.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
54 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s54 ·········4.·_\x8N_\x8e_\x8t_\x8w_\x8o_\x8r_\x8k_\x8·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8F_\x8i_\x8r_\x8e_\x8w_\x8a_\x8l_\x8l_\x8s
55 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s55 ·········5.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
Offset 276, 22 lines modifiedOffset 276, 14 lines modified
276 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-6.2276 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-6.2
277 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227277 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
278 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010010278 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010010
279 ·············_\x8c_\x8i_\x8s············1.9279 ·············_\x8c_\x8i_\x8s············1.9
280 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R61280 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R61
281 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········6.3.3281 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········6.3.3
282 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-234802r622137_rule282 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-234802r622137_rule
283 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
284 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
285 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high 
286 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
287 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···patch 
  
  
288 zypper·patch·-g·security·-y 
289 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8283 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
290 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low284 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
291 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high285 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
292 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true286 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
293 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···patch287 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···patch
294 -·name:·Security·patches·are·up·to·date288 -·name:·Security·patches·are·up·to·date
295 ··package:289 ··package:
Offset 309, 14 lines modifiedOffset 301, 22 lines modified
309 ··-·high_disruption301 ··-·high_disruption
310 ··-·low_complexity302 ··-·low_complexity
311 ··-·medium_severity303 ··-·medium_severity
312 ··-·patch_strategy304 ··-·patch_strategy
313 ··-·reboot_required305 ··-·reboot_required
314 ··-·security_patches_up_to_date306 ··-·security_patches_up_to_date
315 ··-·skip_ansible_lint307 ··-·skip_ansible_lint
 308 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 309 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 310 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
 311 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 312 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···patch
  
  
 313 zypper·patch·-g·security·-y
316 Group  ·Account·and·Access·Control·  Group·contains·6·groups·and·7·rules314 Group  ·Account·and·Access·Control·  Group·contains·6·groups·and·7·rules
317 _\x8[_\x8r_\x8e_\x8f_\x8]  ·In·traditional·Unix·security,·if·an·attacker·gains·shell·access·to·a·certain·login·account,315 _\x8[_\x8r_\x8e_\x8f_\x8]  ·In·traditional·Unix·security,·if·an·attacker·gains·shell·access·to·a·certain·login·account,
318 they·can·perform·any·action·or·access·any·file·to·which·that·account·has·access.·Therefore,·making·it316 they·can·perform·any·action·or·access·any·file·to·which·that·account·has·access.·Therefore,·making·it
319 more·difficult·for·unauthorized·people·to·gain·shell·access·to·accounts,·particularly·to·privileged317 more·difficult·for·unauthorized·people·to·gain·shell·access·to·accounts,·particularly·to·privileged
320 accounts,·is·a·necessary·part·of·securing·a·system.·This·section·introduces·mechanisms·for318 accounts,·is·a·necessary·part·of·securing·a·system.·This·section·introduces·mechanisms·for
321 restricting·access·to·accounts·under·SUSE·Linux·Enterprise·15.319 restricting·access·to·accounts·under·SUSE·Linux·Enterprise·15.
322 Group  ·Protect·Accounts·by·Configuring·PAM·  Group·contains·2·groups·and·2·rules320 Group  ·Protect·Accounts·by·Configuring·PAM·  Group·contains·2·groups·and·2·rules
Offset 518, 306 lines modifiedOffset 518, 14 lines modified
518 ·············_\x8n_\x8i_\x8s_\x8t···········AC-9,·AC-9(1)518 ·············_\x8n_\x8i_\x8s_\x8t···········AC-9,·AC-9(1)
519 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-7519 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-7
520 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.2.4520 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.2.4
521 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227521 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
522 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-020080522 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-020080
523 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.2.1.4523 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.2.1.4
524 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-234873r858542_rule524 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-234873r858542_rule
525 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
526 #·Remediation·is·applicable·only·in·certain·platforms 
527 if·rpm·--quiet·-q·pam;·then 
  
528 if·[·-f·/usr/bin/authselect·];·then 
529 ····if·authselect·list-features·sssd·|·grep·-q·with-silent-lastlog;·then 
530 ········if·!·authselect·check;·then 
531 ········echo·" 
532 ········authselect·integrity·check·failed.·Remediation·aborted! 
533 ········This·remediation·could·not·be·applied·because·an·authselect·profile·was·not·selected·or·the 
534 selected·profile·is·not·intact. 
535 ········It·is·not·recommended·to·manually·edit·the·PAM·files·when·authselect·tool·is·available. 
536 ········In·cases·where·the·default·authselect·profile·does·not·cover·a·specific·demand,·a·custom 
537 authselect·profile·is·recommended." 
538 ········exit·1 
539 ········fi 
540 ········authselect·disable-feature·with-silent-lastlog 
  
541 ········authselect·apply-changes·-b 
542 ····else 
  
543 ········if·!·authselect·check;·then 
544 ········echo·" 
545 ········authselect·integrity·check·failed.·Remediation·aborted! 
546 ········This·remediation·could·not·be·applied·because·an·authselect·profile·was·not·selected·or·the 
547 selected·profile·is·not·intact. 
548 ········It·is·not·recommended·to·manually·edit·the·PAM·files·when·authselect·tool·is·available. 
549 ········In·cases·where·the·default·authselect·profile·does·not·cover·a·specific·demand,·a·custom 
550 authselect·profile·is·recommended." 
551 ········exit·1 
552 ········fi 
  
553 ········CURRENT_PROFILE=$(authselect·current·-r·|·awk·'{·print·$1·}') 
554 ········#·If·not·already·in·use,·a·custom·profile·is·created·preserving·the·enabled·features. 
555 ········if·[[·!·$CURRENT_PROFILE·==·custom/*·]];·then 
556 ············ENABLED_FEATURES=$(authselect·current·|·tail·-n+3·|·awk·'{·print·$2·}') 
557 ············authselect·create-profile·hardening·-b·$CURRENT_PROFILE 
558 ············CURRENT_PROFILE="custom/hardening" 
  
559 ············authselect·apply-changes·-b·--backup=before-hardening-custom-profile 
560 ············authselect·select·$CURRENT_PROFILE 
561 ············for·feature·in·$ENABLED_FEATURES;·do 
562 ················authselect·enable-feature·$feature; 
563 ············done 
  
564 ············authselect·apply-changes·-b·--backup=after-hardening-custom-profile 
565 ········fi 
566 ········PAM_FILE_NAME=$(basename·"/etc/pam.d/login") 
567 ········PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME" 
  
568 ········authselect·apply-changes·-b 
569 ········if·[·-e·"$PAM_FILE_PATH"·]·;·then 
570 ············PAM_FILE_PATH="$PAM_FILE_PATH" 
571 ············if·[·-f·/usr/bin/authselect·];·then 
  
572 ················if·!·authselect·check;·then 
573 ················echo·" 
574 ················authselect·integrity·check·failed.·Remediation·aborted! 
Max diff block lines reached; 889307/906640 bytes (98.09%) of diff not shown.
21.8 MB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-stig.html
    
Offset 14297, 15 lines modifiedOffset 14297, 15 lines modified
00037d80:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00037d80:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00037d90:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00037d90:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00037da0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<00037da0:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<
00037db0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00037db0:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00037dc0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00037dc0:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00037dd0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00037dd0:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00037de0:·2020·2020·2020·2020·2020·2020·2020·2028·················(00037de0:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00037df0:·6173·206f·6620·3230·3236·2d30·312d·3038··as·of·2026-01-0800037df0:·6173·206f·6620·3230·3234·2d31·322d·3037··as·of·2024-12-07
00037e00:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00037e00:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00037e10:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00037e10:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00037e20:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00037e20:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00037e30:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00037e30:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00037e40:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00037e40:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00037e50:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00037e50:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00037e60:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00037e60:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
Offset 15145, 130 lines modifiedOffset 15145, 130 lines modified
0003b280:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003b280:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003b290:·743d·2223·6964·6d36·3333·3322·2074·6162··t="#idm6333"·tab0003b290:·743d·2223·6964·6d36·3333·3322·2074·6162··t="#idm6333"·tab
0003b2a0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003b2a0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003b2b0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003b2b0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003b2c0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003b2c0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003b2d0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003b2d0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003b2e0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003b2e0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 0003b2f0:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O
 0003b300:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint
 0003b310:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0003b320:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003b330:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003b340:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003b350:·3633·3333·223e·3c70·7265·3e3c·636f·6465··6333"><pre><code
 0003b360:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n
 0003b370:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver
 0003b380:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod
 0003b390:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003b3a0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003b3b0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003b3c0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003b3d0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003b3e0:·6d36·3333·3422·2074·6162·696e·6465·783d··m6334"·tabindex=
 0003b3f0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003b400:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003b410:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003b420:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003b430:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003b440:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible
 0003b450:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0003b460:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003b470:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003b480:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003b490:·3633·3334·223e·3c74·6162·6c65·2063·6c61··6334"><table·cla
 0003b4a0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0003b4b0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0003b4c0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003b4d0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003b4e0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003b4f0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003b500:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0003b510:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003b520:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b530:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
 0003b540:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 0003b550:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003b560:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 0003b570:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 0003b580:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-·
 0003b590:·6e61·6d65·3a20·456e·7375·7265·2061·6964··name:·Ensure·aid
 0003b5a0:·6520·6973·2069·6e73·7461·6c6c·6564·0a20··e·is·installed.·
 0003b5b0:·2070·6163·6b61·6765·3a0a·2020·2020·6e61···package:.····na
 0003b5c0:·6d65·3a20·6169·6465·0a20·2020·2073·7461··me:·aide.····sta
 0003b5d0:·7465·3a20·7072·6573·656e·740a·2020·7768··te:·present.··wh
 0003b5e0:·656e·3a20·616e·7369·626c·655f·7669·7274··en:·ansible_virt
 0003b5f0:·7561·6c69·7a61·7469·6f6e·5f74·7970·6520··ualization_type·
 0003b600:·6e6f·7420·696e·205b·2264·6f63·6b65·7222··not·in·["docker"
 0003b610:·2c20·226c·7863·222c·2022·6f70·656e·767a··,·"lxc",·"openvz
 0003b620:·222c·2022·706f·646d·616e·222c·2022·636f··",·"podman",·"co
 0003b630:·6e74·6169·6e65·7222·5d0a·2020·7461·6773··ntainer"].··tags
 0003b640:·3a0a·2020·2d20·4343·452d·3833·3238·392d··:.··-·CCE-83289-
 0003b650:·390a·2020·2d20·434a·4953·2d35·2e31·302e··9.··-·CJIS-5.10.
 0003b660:·312e·330a·2020·2d20·4449·5341·2d53·5449··1.3.··-·DISA-STI
 0003b670:·472d·534c·4553·2d31·352d·3031·3034·3139··G-SLES-15-010419
 0003b680:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
 0003b690:·2d43·4d2d·3628·6129·0a20·202d·2050·4349··-CM-6(a).··-·PCI
 0003b6a0:·2d44·5353·2d52·6571·2d31·312e·350a·2020··-DSS-Req-11.5.··
 0003b6b0:·2d20·5043·492d·4453·5376·342d·3131·2e35··-·PCI-DSSv4-11.5
 0003b6c0:·2e32·0a20·202d·2065·6e61·626c·655f·7374··.2.··-·enable_st
 0003b6d0:·7261·7465·6779·0a20·202d·206c·6f77·5f63··rategy.··-·low_c
 0003b6e0:·6f6d·706c·6578·6974·790a·2020·2d20·6c6f··omplexity.··-·lo
 0003b6f0:·775f·6469·7372·7570·7469·6f6e·0a20·202d··w_disruption.··-
 0003b700:·206d·6564·6975·6d5f·7365·7665·7269·7479···medium_severity
 0003b710:·0a20·202d·206e·6f5f·7265·626f·6f74·5f6e··.··-·no_reboot_n
 0003b720:·6565·6465·640a·2020·2d20·7061·636b·6167··eeded.··-·packag
 0003b730:·655f·6169·6465·5f69·6e73·7461·6c6c·6564··e_aide_installed
 0003b740:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 0003b750:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 0003b760:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 0003b770:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 0003b780:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 0003b790:·743d·2223·6964·6d36·3333·3522·2074·6162··t="#idm6335"·tab
 0003b7a0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 0003b7b0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 0003b7c0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 0003b7d0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 0003b7e0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003b2f0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S0003b7f0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S
0003b300:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<0003b800:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<
0003b310:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003b810:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003b320:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003b820:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003b330:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003b830:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
0003b340:·6964·6d36·3333·3322·3e3c·7461·626c·6520··idm6333"><table·0003b840:·6964·6d36·3333·3522·3e3c·7461·626c·6520··idm6335"><table·
0003b350:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003b850:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003b360:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003b860:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003b370:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003b870:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003b380:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003b880:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0003b390:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003b890:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0003b3a0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003b8a0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003b3b0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003b8b0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003b3c0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003b8c0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003b3d0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003b8d0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003b3e0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th0003b8e0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
0003b3f0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><0003b8f0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
0003b400:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003b900:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
0003b410:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003b910:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
0003b420:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003b920:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
0003b430:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003b930:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
0003b440:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i0003b940:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
0003b450:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl0003b950:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
0003b460:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla0003b960:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
Max diff block lines reached; 21176935/21194653 bytes (99.92%) of diff not shown.
1.56 MB
html2text {}
    
Offset 38, 15 lines modifiedOffset 38, 15 lines modified
38 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DISA·STIG·for·SUSE·Linux·Enterprise·1538 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·DISA·STIG·for·SUSE·Linux·Enterprise·15
39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_stig39 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_stig
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:suse:linux_enterprise_desktop:1541 ····*·cpe:/o:suse:linux_enterprise_desktop:15
42 ····*·cpe:/o:suse:linux_enterprise_server:1542 ····*·cpe:/o:suse:linux_enterprise_server:15
43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*43 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
44 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8444 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)45 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*46 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s47 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e48 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
49 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l49 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
50 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r50 ·········3.·_\x8A_\x8p_\x8p_\x8A_\x8r_\x8m_\x8o_\x8r
51 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n51 ·········4.·_\x8G_\x8R_\x8U_\x8B_\x82_\x8·_\x8b_\x8o_\x8o_\x8t_\x8l_\x8o_\x8a_\x8d_\x8e_\x8r_\x8·_\x8c_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8a_\x8t_\x8i_\x8o_\x8n
52 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g52 ·········5.·_\x8C_\x8o_\x8n_\x8f_\x8i_\x8g_\x8u_\x8r_\x8e_\x8·_\x8S_\x8y_\x8s_\x8l_\x8o_\x8g
Offset 118, 27 lines modifiedOffset 118, 19 lines modified
118 include·install_aide118 include·install_aide
  
119 class·install_aide·{119 class·install_aide·{
120 ··package·{·'aide':120 ··package·{·'aide':
121 ····ensure·=>·'installed',121 ····ensure·=>·'installed',
122 ··}122 ··}
123 }123 }
 124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
126 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
127 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
128 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
129 #·Remediation·is·applicable·only·in·certain·platforms 
130 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
131 zypper·install·-y·"aide" 
  
132 else 
133 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
134 fi125 [[packages]]
 126 name·=·"aide"
 127 version·=·"*"
135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
140 -·name:·Ensure·aide·is·installed133 -·name:·Ensure·aide·is·installed
141 ··package:134 ··package:
Offset 154, 19 lines modifiedOffset 146, 27 lines modified
154 ··-·PCI-DSSv4-11.5.2146 ··-·PCI-DSSv4-11.5.2
155 ··-·enable_strategy147 ··-·enable_strategy
156 ··-·low_complexity148 ··-·low_complexity
157 ··-·low_disruption149 ··-·low_disruption
158 ··-·medium_severity150 ··-·medium_severity
159 ··-·no_reboot_needed151 ··-·no_reboot_needed
160 ··-·package_aide_installed152 ··-·package_aide_installed
161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_.h_.e_.l_.l_.·_.s_.c_.r_.i_.p_\x8t_\x8·_\x8
 154 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 155 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 156 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 157 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
 158 #·Remediation·is·applicable·only·in·certain·platforms
 159 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
162 [[packages]] 
163 name·=·"aide" 
164 version·=·"*"160 zypper·install·-y·"aide"
  
 161 else
 162 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
 163 fi
165 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*164 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
166 Run·the·following·command·to·generate·a·new·database:165 Run·the·following·command·to·generate·a·new·database:
167 $·sudo·/usr/bin/aide·--init166 $·sudo·/usr/bin/aide·--init
168 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/167 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/bin/
169 aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database168 aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database
170 can·be·installed·as·follows:169 can·be·installed·as·follows:
171 $·sudo·cp·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db170 $·sudo·cp·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db
Offset 190, 29 lines modifiedOffset 190, 14 lines modified
190 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5190 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
191 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199191 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
192 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419192 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419
193 ·············_\x8c_\x8i_\x8s············1.4.1193 ·············_\x8c_\x8i_\x8s············1.4.1
194 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79194 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
195 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2195 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
196 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r880967_rule196 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r880967_rule
197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
198 #·Remediation·is·applicable·only·in·certain·platforms 
199 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then 
  
200 zypper·-q·--no-remote·ref 
  
  
201 zypper·install·-y·"aide" 
  
202 /usr/bin/aide·--init 
203 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db 
  
204 else 
205 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
206 fi 
207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
212 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated202 -·name:·Build·and·Test·AIDE·Database·-·Ensure·Repositories·Are·Updated
213 ··ansible.builtin.command:·zypper·-q·--no-remote·ref203 ··ansible.builtin.command:·zypper·-q·--no-remote·ref
Offset 308, 14 lines modifiedOffset 293, 29 lines modified
308 ··-·PCI-DSSv4-11.5.2293 ··-·PCI-DSSv4-11.5.2
309 ··-·aide_build_database294 ··-·aide_build_database
310 ··-·low_complexity295 ··-·low_complexity
311 ··-·low_disruption296 ··-·low_disruption
312 ··-·medium_severity297 ··-·medium_severity
313 ··-·no_reboot_needed298 ··-·no_reboot_needed
314 ··-·restrict_strategy299 ··-·restrict_strategy
 300 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 301 #·Remediation·is·applicable·only·in·certain·platforms
 302 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
 303 zypper·-q·--no-remote·ref
  
  
 304 zypper·install·-y·"aide"
  
 305 /usr/bin/aide·--init
 306 /bin/cp·-p·/var/lib/aide/aide.db.new·/var/lib/aide/aide.db
  
 307 else
Max diff block lines reached; 1634788/1640281 bytes (99.67%) of diff not shown.
5.06 MB
./usr/share/doc/ssg-nondebian/ssg-slmicro5-guide-stig.html
    
Offset 14319, 15 lines modifiedOffset 14319, 15 lines modified
00037ee0:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C00037ee0:·4869·7374·6f72·793c·2f68·323e·3c70·3e43··History</h2><p>C
00037ef0:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·00037ef0:·7572·7265·6e74·2076·6572·7369·6f6e·3a20··urrent·version:·
00037f00:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</00037f00:·3c73·7472·6f6e·673e·302e·312e·3734·3c2f··<strong>0.1.74</
00037f10:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><00037f10:·7374·726f·6e67·3e3c·2f70·3e3c·756c·3e3c··strong></p><ul><
00037f20:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft00037f20:·6c69·3e3c·7374·726f·6e67·3e64·7261·6674··li><strong>draft
00037f30:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······00037f30:·3c2f·7374·726f·6e67·3e0a·2020·2020·2020··</strong>.······
00037f40:·2020·2020·2020·2020·2020·2020·2020·2861················(a00037f40:·2020·2020·2020·2020·2020·2020·2020·2861················(a
00037f50:·7320·6f66·2032·3032·362d·3031·2d30·3829··s·of·2026-01-08)00037f50:·7320·6f66·2032·3032·342d·3132·2d30·3729··s·of·2024-12-07)
00037f60:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············00037f60:·0a20·2020·2020·2020·2020·2020·2020·2020··.···············
00037f70:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div00037f70:·203c·2f6c·693e·3c2f·756c·3e3c·2f64·6976···</li></ul></div
00037f80:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co00037f80:·3e3c·6832·3e54·6162·6c65·206f·6620·436f··><h2>Table·of·Co
00037f90:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><00037f90:·6e74·656e·7473·3c2f·6832·3e3c·6f6c·3e3c··ntents</h2><ol><
00037fa0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc00037fa0:·6c69·3e3c·6120·6872·6566·3d22·2378·6363··li><a·href="#xcc
00037fb0:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec00037fb0:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
00037fc0:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_00037fc0:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 15543, 456 lines modifiedOffset 15543, 456 lines modified
0003cb60:·612d·7461·7267·6574·3d22·2369·646d·3535··a-target="#idm550003cb60:·612d·7461·7267·6574·3d22·2369·646d·3535··a-target="#idm55
0003cb70:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·0003cb70:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·
0003cb80:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003cb80:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003cb90:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003cb90:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003cba0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003cba0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003cbb0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003cbb0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
Diff chunk too large, falling back to line-by-line diff (442 lines added, 442 lines removed)
0003cbc0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003cbc0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003cbd0:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip0003cbd0:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni
0003cbe0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003cbe0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003cbf0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003cbf0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003cc00:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003cc00:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003cc10:·2220·6964·3d22·6964·6d35·3531·223e·3c70··"·id="idm551"><p0003cc10:·7073·6522·2069·643d·2269·646d·3535·3122··pse"·id="idm551"
0003cc20:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed0003cc20:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003cc30:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic0003cc30:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003cc40:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer0003cc40:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003cc50:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i0003cc50:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003cc60:·6620·7270·6d20·2d2d·7175·6965·7420·2d71··f·rpm·--quiet·-q0003cc60:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003cc70:·2070·616d·3b20·7468·656e·0a0a·7661·725f···pam;·then..var_0003cc70:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003cc80:·7061·7373·776f·7264·5f70·616d·5f64·656c··password_pam_del0003cc80:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003cc90:·6179·3d27·3c61·6262·7220·7469·746c·653d··ay='<abbr·title=0003cc90:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003cca0:·2266·726f·6d20·5072·6f66·696c·652f·7265··"from·Profile/re0003cca0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003ccb0:·6669·6e65·2d76·616c·7565·3a20·7863·6364··fine-value:·xccd0003ccb0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
0003ccc0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject0003ccc0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
0003ccd0:·2e63·6f6e·7465·6e74·5f76·616c·7565·5f76··.content_value_v0003ccd0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
0003cce0:·6172·5f70·6173·7377·6f72·645f·7061·6d5f··ar_password_pam_0003cce0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0003ccf0:·6465·6c61·7922·3e34·3030·3030·3030·3c2f··delay">4000000</0003ccf0:·683e·3c74·643e·7265·7374·7269·6374·3c2f··h><td>restrict</
0003cd00:·6162·6272·3e27·0a0a·0a69·6620·5b20·2d65··abbr>'...if·[·-e0003cd00:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
0003cd10:·2022·2f65·7463·2f70·616d·2e64·2f63·6f6d···"/etc/pam.d/com0003cd10:·3c70·7265·3e3c·636f·6465·3e2d·206e·616d··<pre><code>-·nam
0003cd20:·6d6f·6e2d·6175·7468·2220·5d20·3b20·7468··mon-auth"·]·;·th0003cd20:·653a·2047·6174·6865·7220·7468·6520·7061··e:·Gather·the·pa
0003cd30:·656e·0a20·2020·2076·616c·7565·5265·6765··en.····valueRege0003cd30:·636b·6167·6520·6661·6374·730a·2020·7061··ckage·facts.··pa
0003cd40:·783d·2224·7661·725f·7061·7373·776f·7264··x="$var_password0003cd40:·636b·6167·655f·6661·6374·733a·0a20·2020··ckage_facts:.···
0003cd50:·5f70·616d·5f64·656c·6179·2220·6465·6661··_pam_delay"·defa0003cd50:·206d·616e·6167·6572·3a20·6175·746f·0a20···manager:·auto.·
0003cd60:·756c·7456·616c·7565·3d22·2476·6172·5f70··ultValue="$var_p0003cd60:·2074·6167·733a·0a20·202d·2043·4345·2d39···tags:.··-·CCE-9
0003cd70:·6173·7377·6f72·645f·7061·6d5f·6465·6c61··assword_pam_dela0003cd70:·3430·3932·2d34·0a20·202d·2044·4953·412d··4092-4.··-·DISA-
0003cd80:·7922·0a20·2020·2023·206e·6f6e·2d65·6d70··y".····#·non-emp0003cd80:·5354·4947·2d53·4c45·4d2d·3035·2d34·3132··STIG-SLEM-05-412
0003cd90:·7479·2076·616c·7565·7320·6e65·6564·2074··ty·values·need·t0003cd90:·3032·350a·2020·2d20·6163·636f·756e·7473··025.··-·accounts
0003cda0:·6f20·6265·2070·7265·6365·6465·6420·6279··o·be·preceded·by0003cda0:·5f70·6173·7377·6f72·6473·5f70·616d·5f66··_passwords_pam_f
0003cdb0:·2061·6e20·6571·7561·6c73·2073·6967·6e0a···an·equals·sign.0003cdb0:·6169·6c64·656c·6179·5f64·656c·6179·0a20··aildelay_delay.·
0003cdc0:·2020·2020·5b20·2d6e·2022·247b·7661·6c75······[·-n·"${valu0003cdc0:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit
0003cdd0:·6552·6567·6578·7d22·205d·2026·616d·703b··eRegex}"·]·&amp;0003cdd0:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup
0003cde0:·2661·6d70·3b20·7661·6c75·6552·6567·6578··&amp;·valueRegex0003cde0:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_
0003cdf0:·3d22·3d24·7b76·616c·7565·5265·6765·787d··="=${valueRegex}0003cdf0:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_
0003ce00:·220a·2020·2020·2320·6164·6420·616e·2065··".····#·add·an·e0003ce00:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.··
0003ce10:·7175·616c·7320·7369·676e·2074·6f20·6e6f··quals·sign·to·no0003ce10:·2d20·7265·7374·7269·6374·5f73·7472·6174··-·restrict_strat
0003ce20:·6e2d·656d·7074·7920·7661·6c75·6573·0a20··n-empty·values.·0003ce20:·6567·790a·2d20·6e61·6d65·3a20·5843·4344··egy.-·name:·XCCD
0003ce30:·2020·205b·202d·6e20·2224·7b64·6566·6175·····[·-n·"${defau0003ce30:·4620·5661·6c75·6520·7661·725f·7061·7373··F·Value·var_pass
0003ce40:·6c74·5661·6c75·657d·2220·5d20·2661·6d70··ltValue}"·]·&amp0003ce40:·776f·7264·5f70·616d·5f64·656c·6179·2023··word_pam_delay·#
0003ce50:·3b26·616d·703b·2064·6566·6175·6c74·5661··;&amp;·defaultVa0003ce50:·2070·726f·6d6f·7465·2074·6f20·7661·7269···promote·to·vari
0003ce60:·6c75·653d·223d·247b·6465·6661·756c·7456··lue="=${defaultV0003ce60:·6162·6c65·0a20·2073·6574·5f66·6163·743a··able.··set_fact:
0003ce70:·616c·7565·7d22·0a0a·2020·2020·2320·6669··alue}"..····#·fi0003ce70:·0a20·2020·2076·6172·5f70·6173·7377·6f72··.····var_passwor
0003ce80:·7820·2774·7970·6527·2069·6620·6974·2773··x·'type'·if·it's0003ce80:·645f·7061·6d5f·6465·6c61·793a·2021·2173··d_pam_delay:·!!s
0003ce90:·2077·726f·6e67·0a20·2020·2069·6620·6772···wrong.····if·gr0003ce90:·7472·203c·6162·6272·2074·6974·6c65·3d22··tr·<abbr·title="
0003cea0:·6570·202d·7120·2d50·2022·5e5c·5c73·2a28··ep·-q·-P·"^\\s*(0003cea0:·6672·6f6d·2050·726f·6669·6c65·2f72·6566··from·Profile/ref
0003ceb0:·3f22·2721·2722·6175·7468·5c5c·7329·5b5b··?"'!'"auth\\s)[[0003ceb0:·696e·652d·7661·6c75·653a·2078·6363·6466··ine-value:·xccdf
0003cec0:·3a61·6c6e·756d·3a5d·5d2b·5c5c·732b·5b5b··:alnum:]]+\\s+[[0003cec0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.
0003ced0:·3a61·6c6e·756d·3a5d·5d2b·5c5c·732b·7061··:alnum:]]+\\s+pa0003ced0:·636f·6e74·656e·745f·7661·6c75·655f·7661··content_value_va
0003cee0:·6d5f·6661·696c·6465·6c61·792e·736f·2220··m_faildelay.so"·0003cee0:·725f·7061·7373·776f·7264·5f70·616d·5f64··r_password_pam_d
0003cef0:·266c·743b·2022·2f65·7463·2f70·616d·2e64··&lt;·"/etc/pam.d0003cef0:·656c·6179·223e·3430·3030·3030·303c·2f61··elay">4000000</a
0003cf00:·2f63·6f6d·6d6f·6e2d·6175·7468·2220·3b20··/common-auth"·;·0003cf00:·6262·723e·0a20·2074·6167·733a·0a20·2020··bbr>.··tags:.···
0003cf10:·7468·656e·0a20·2020·2020·2020·2073·6564··then.········sed0003cf10:·202d·2061·6c77·6179·730a·0a2d·206e·616d···-·always..-·nam
0003cf20:·202d·2d66·6f6c·6c6f·772d·7379·6d6c·696e···--follow-symlin0003cf20:·653a·2053·6574·2063·6f6e·7472·6f6c·5f66··e:·Set·control_f
0003cf30:·6b73·202d·6920·2d45·202d·6520·2273·2f5e··ks·-i·-E·-e·"s/^0003cf30:·6c61·6720·6661·6374·0a20·2073·6574·5f66··lag·fact.··set_f
0003cf40:·285c·5c73·2a29·5b5b·3a61·6c6e·756d·3a5d··(\\s*)[[:alnum:]0003cf40:·6163·743a·0a20·2020·2063·6f6e·7472·6f6c··act:.····control
0003cf50:·5d2b·285c·5c73·2b5b·5b3a·616c·6e75·6d3a··]+(\\s+[[:alnum:0003cf50:·5f66·6c61·673a·2072·6571·7569·7265·640a··_flag:·required.
0003cf60:·5d5d·2b5c·5c73·2b70·616d·5f66·6169·6c64··]]+\\s+pam_faild0003cf60:·2020·7768·656e·3a20·2722·7061·6d22·2069····when:·'"pam"·i
0003cf70:·656c·6179·2e73·6f29·2f5c·5c31·6175·7468··elay.so)/\\1auth0003cf70:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts.
0003cf80:·5c5c·322f·2220·222f·6574·632f·7061·6d2e··\\2/"·"/etc/pam.0003cf80:·7061·636b·6167·6573·270a·2020·7461·6773··packages'.··tags
0003cf90:·642f·636f·6d6d·6f6e·2d61·7574·6822·0a20··d/common-auth".·0003cf90:·3a0a·2020·2d20·4343·452d·3934·3039·322d··:.··-·CCE-94092-
0003cfa0:·2020·2066·690a·0a20·2020·2023·2066·6978·····fi..····#·fix0003cfa0:·340a·2020·2d20·4449·5341·2d53·5449·472d··4.··-·DISA-STIG-
0003cfb0:·2027·636f·6e74·726f·6c27·2069·6620·6974···'control'·if·it0003cfb0:·534c·454d·2d30·352d·3431·3230·3235·0a20··SLEM-05-412025.·
0003cfc0:·2773·2077·726f·6e67·0a20·2020·2069·6620··'s·wrong.····if·0003cfc0:·202d·2061·6363·6f75·6e74·735f·7061·7373···-·accounts_pass
0003cfd0:·6772·6570·202d·7120·2d50·2022·5e5c·5c73··grep·-q·-P·"^\\s0003cfd0:·776f·7264·735f·7061·6d5f·6661·696c·6465··words_pam_failde
0003cfe0:·2a61·7574·685c·5c73·2b28·3f22·2721·2722··*auth\\s+(?"'!'"0003cfe0:·6c61·795f·6465·6c61·790a·2020·2d20·6c6f··lay_delay.··-·lo
0003cff0:·7265·7175·6972·6564·295b·5b3a·616c·6e75··required)[[:alnu0003cff0:·775f·636f·6d70·6c65·7869·7479·0a20·202d··w_complexity.··-
0003d000:·6d3a·5d5d·2b5c·5c73·2b70·616d·5f66·6169··m:]]+\\s+pam_fai0003d000:·206c·6f77·5f64·6973·7275·7074·696f·6e0a···low_disruption.
0003d010:·6c64·656c·6179·2e73·6f22·2026·6c74·3b20··ldelay.so"·&lt;·0003d010:·2020·2d20·6d65·6469·756d·5f73·6576·6572····-·medium_sever
0003d020:·222f·6574·632f·7061·6d2e·642f·636f·6d6d··"/etc/pam.d/comm0003d020:·6974·790a·2020·2d20·6e6f·5f72·6562·6f6f··ity.··-·no_reboo
0003d030:·6f6e·2d61·7574·6822·203b·2074·6865·6e0a··on-auth"·;·then.0003d030:·745f·6e65·6564·6564·0a20·202d·2072·6573··t_needed.··-·res
0003d040:·2020·2020·2020·2020·7365·6420·2d2d·666f··········sed·--fo0003d040:·7472·6963·745f·7374·7261·7465·6779·0a0a··trict_strategy..
0003d050:·6c6c·6f77·2d73·796d·6c69·6e6b·7320·2d69··llow-symlinks·-i0003d050:·2d20·6e61·6d65·3a20·4368·6563·6b20·746f··-·name:·Check·to
0003d060:·202d·4520·2d65·2022·732f·5e28·5c5c·732a···-E·-e·"s/^(\\s*0003d060:·2073·6565·2069·6620·2770·616d·5f66·6169···see·if·'pam_fai
0003d070:·6175·7468·5c5c·732b·295b·5b3a·616c·6e75··auth\\s+)[[:alnu0003d070:·6c64·656c·6179·2e73·6f27·206d·6f64·756c··ldelay.so'·modul
0003d080:·6d3a·5d5d·2b28·5c5c·732b·7061·6d5f·6661··m:]]+(\\s+pam_fa0003d080:·6520·6973·2063·6f6e·6669·6775·7265·6420··e·is·configured·
0003d090:·696c·6465·6c61·792e·736f·292f·5c5c·3172··ildelay.so)/\\1r0003d090:·696e·2027·2f65·7463·2f70·616d·2e64·2f63··in·'/etc/pam.d/c
0003d0a0:·6571·7569·7265·645c·5c32·2f22·2022·2f65··equired\\2/"·"/e0003d0a0:·6f6d·6d6f·6e2d·6175·7468·270a·2020·7368··ommon-auth'.··sh
0003d0b0:·7463·2f70·616d·2e64·2f63·6f6d·6d6f·6e2d··tc/pam.d/common-0003d0b0:·656c·6c3a·207c·0a20·2020·2073·6574·202d··ell:·|.····set·-
0003d0c0:·6175·7468·220a·2020·2020·6669·0a0a·2020··auth".····fi..··0003d0c0:·6f20·7069·7065·6661·696c·0a20·2020·2067··o·pipefail.····g
0003d0d0:·2020·2320·6669·7820·7468·6520·7661·6c75····#·fix·the·valu0003d0d0:·7265·7020·2d45·2027·5e5c·732a·6175·7468··rep·-E·'^\s*auth
0003d0e0:·6520·666f·7220·276f·7074·696f·6e27·2069··e·for·'option'·i0003d0e0:·5c73·2b5c·532b·5c73·2b70·616d·5f66·6169··\s+\S+\s+pam_fai
0003d0f0:·6620·6f6e·6520·6578·6973·7473·2062·7574··f·one·exists·but0003d0f0:·6c64·656c·6179·2e73·6f27·202f·6574·632f··ldelay.so'·/etc/
0003d100:·2064·6f65·7320·6e6f·7420·6d61·7463·6820···does·not·match·0003d100:·7061·6d2e·642f·636f·6d6d·6f6e·2d61·7574··pam.d/common-aut
0003d110:·2776·616c·7565·5265·6765·7827·0a20·2020··'valueRegex'.···0003d110:·6820·7c7c·2074·7275·650a·2020·7265·6769··h·||·true.··regi
0003d120:·2069·6620·6772·6570·202d·7120·2d50·2022···if·grep·-q·-P·"0003d120:·7374·6572·3a20·6368·6563·6b5f·7061·6d5f··ster:·check_pam_
0003d130:·5e5c·5c73·2a61·7574·685c·5c73·2b72·6571··^\\s*auth\\s+req0003d130:·6d6f·6475·6c65·5f72·6573·756c·740a·2020··module_result.··
0003d140:·7569·7265·645c·5c73·2b70·616d·5f66·6169··uired\\s+pam_fai0003d140:·7768·656e·3a20·2722·7061·6d22·2069·6e20··when:·'"pam"·in·
0003d150:·6c64·656c·6179·2e73·6f28·5c5c·732e·2b29··ldelay.so(\\s.+)0003d150:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa
0003d160:·3f5c·5c73·2b64·656c·6179·283f·2227·2127··?\\s+delay(?"'!'0003d160:·636b·6167·6573·270a·2020·7461·6773·3a0a··ckages'.··tags:.
0003d170:·2224·7b76·616c·7565·5265·6765·787d·285c··"${valueRegex}(\0003d170:·2020·2d20·4343·452d·3934·3039·322d·340a····-·CCE-94092-4.
0003d180:·5c73·7c5c·2429·2922·2026·6c74·3b20·222f··\s|\$))"·&lt;·"/0003d180:·2020·2d20·4449·5341·2d53·5449·472d·534c····-·DISA-STIG-SL
0003d190:·6574·632f·7061·6d2e·642f·636f·6d6d·6f6e··etc/pam.d/common0003d190:·454d·2d30·352d·3431·3230·3235·0a20·202d··EM-05-412025.··-
0003d1a0:·2d61·7574·6822·203b·2074·6865·6e0a·2020··-auth"·;·then.··0003d1a0:·2061·6363·6f75·6e74·735f·7061·7373·776f···accounts_passwo
0003d1b0:·2020·2020·2020·7365·6420·2d2d·666f·6c6c········sed·--foll0003d1b0:·7264·735f·7061·6d5f·6661·696c·6465·6c61··rds_pam_faildela
0003d1c0:·6f77·2d73·796d·6c69·6e6b·7320·2d69·202d··ow-symlinks·-i·-0003d1c0:·795f·6465·6c61·790a·2020·2d20·6c6f·775f··y_delay.··-·low_
0003d1d0:·4520·2d65·2022·732f·5e28·5c5c·732a·6175··E·-e·"s/^(\\s*au0003d1d0:·636f·6d70·6c65·7869·7479·0a20·202d·206c··complexity.··-·l
0003d1e0:·7468·5c5c·732b·7265·7175·6972·6564·5c5c··th\\s+required\\0003d1e0:·6f77·5f64·6973·7275·7074·696f·6e0a·2020··ow_disruption.··
0003d1f0:·732b·7061·6d5f·6661·696c·6465·6c61·792e··s+pam_faildelay.0003d1f0:·2d20·6d65·6469·756d·5f73·6576·6572·6974··-·medium_severit
0003d200:·736f·285c·5c73·2e2b·293f·5c5c·7329·6465··so(\\s.+)?\\s)de0003d200:·790a·2020·2d20·6e6f·5f72·6562·6f6f·745f··y.··-·no_reboot_
0003d210:·6c61·793d·5b5e·5b3a·7370·6163·653a·5d5d··lay=[^[:space:]]0003d210:·6e65·6564·6564·0a20·202d·2072·6573·7472··needed.··-·restr
0003d220:·2a2f·5c5c·3164·656c·6179·247b·6465·6661··*/\\1delay${defa0003d220:·6963·745f·7374·7261·7465·6779·0a0a·2d20··ict_strategy..-·
0003d230:·756c·7456·616c·7565·7d2f·2220·222f·6574··ultValue}/"·"/et0003d230:·6e61·6d65·3a20·436f·6e66·6967·7572·6520··name:·Configure·
Max diff block lines reached; 4852071/4914777 bytes (98.72%) of diff not shown.
384 KB
html2text {}
    
Offset 40, 15 lines modifiedOffset 40, 15 lines modified
40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*40 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
41 ····*·cpe:/o:suse:sle-microos:5.241 ····*·cpe:/o:suse:sle-microos:5.2
42 ····*·cpe:/o:suse:sle-micro:5.342 ····*·cpe:/o:suse:sle-micro:5.3
43 ····*·cpe:/o:suse:sle-micro:5.443 ····*·cpe:/o:suse:sle-micro:5.4
44 ····*·cpe:/o:suse:sle-micro:5.544 ····*·cpe:/o:suse:sle-micro:5.5
45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*45 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
46 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8446 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)47 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*48 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s49 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
50 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e50 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
51 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l51 ·········2.·_\x8A_\x8c_\x8c_\x8o_\x8u_\x8n_\x8t_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8c_\x8c_\x8e_\x8s_\x8s_\x8·_\x8C_\x8o_\x8n_\x8t_\x8r_\x8o_\x8l
52 ·········3.·_\x8S_\x8E_\x8L_\x8i_\x8n_\x8u_\x8x52 ·········3.·_\x8S_\x8E_\x8L_\x8i_\x8n_\x8u_\x8x
53 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s53 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
54 ·········1.·_\x8S_\x8S_\x8H_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r54 ·········1.·_\x8S_\x8S_\x8H_\x8·_\x8S_\x8e_\x8r_\x8v_\x8e_\x8r
Offset 149, 67 lines modifiedOffset 149, 14 lines modified
149 Severity: ···medium149 Severity: ···medium
150 Rule·ID:·····xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faildelay_delay150 Rule·ID:·····xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faildelay_delay
151 Identifiers:·CCE-94092-4151 Identifiers:·CCE-94092-4
152 ·············_\x8d_\x8i_\x8s_\x8a····CCI-000366152 ·············_\x8d_\x8i_\x8s_\x8a····CCI-000366
153 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-00226153 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-00226
154 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLEM-05-412025154 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLEM-05-412025
155 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-261365r996541_rule155 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-261365r996541_rule
156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
157 #·Remediation·is·applicable·only·in·certain·platforms 
158 if·rpm·--quiet·-q·pam;·then 
  
159 var_password_pam_delay='4000000' 
  
  
160 if·[·-e·"/etc/pam.d/common-auth"·]·;·then 
161 ····valueRegex="$var_password_pam_delay"·defaultValue="$var_password_pam_delay" 
162 ····#·non-empty·values·need·to·be·preceded·by·an·equals·sign 
163 ····[·-n·"${valueRegex}"·]·&&·valueRegex="=${valueRegex}" 
164 ····#·add·an·equals·sign·to·non-empty·values 
165 ····[·-n·"${defaultValue}"·]·&&·defaultValue="=${defaultValue}" 
  
166 ····#·fix·'type'·if·it's·wrong 
167 ····if·grep·-q·-P·"^\\s*(?"'!'"auth\\s)[[:alnum:]]+\\s+[[:alnum:]]+\\s+pam_faildelay.so"·<·"/etc/ 
168 pam.d/common-auth"·;·then 
169 ········sed·--follow-symlinks·-i·-E·-e·"s/^(\\s*)[[:alnum:]]+(\\s+[[:alnum: 
170 ]]+\\s+pam_faildelay.so)/\\1auth\\2/"·"/etc/pam.d/common-auth" 
171 ····fi 
  
172 ····#·fix·'control'·if·it's·wrong 
173 ····if·grep·-q·-P·"^\\s*auth\\s+(?"'!'"required)[[:alnum:]]+\\s+pam_faildelay.so"·<·"/etc/pam.d/ 
174 common-auth"·;·then 
175 ········sed·--follow-symlinks·-i·-E·-e·"s/^(\\s*auth\\s+)[[:alnum:]]+(\\s+pam_faildelay.so)/ 
176 \\1required\\2/"·"/etc/pam.d/common-auth" 
177 ····fi 
  
178 ····#·fix·the·value·for·'option'·if·one·exists·but·does·not·match·'valueRegex' 
179 ····if·grep·-q·-P·"^\\s*auth\\s+required\\s+pam_faildelay.so(\\s.+)?\\s+delay(?"'!'"${valueRegex} 
180 (\\s|\$))"·<·"/etc/pam.d/common-auth"·;·then 
181 ········sed·--follow-symlinks·-i·-E·-e·"s/^(\\s*auth\\s+required\\s+pam_faildelay.so 
182 (\\s.+)?\\s)delay=[^[:space:]]*/\\1delay${defaultValue}/"·"/etc/pam.d/common-auth" 
  
183 ····#·add·'option=default'·if·option·is·not·set 
184 ····elif·grep·-q·-E·"^\\s*auth\\s+required\\s+pam_faildelay.so"·<·"/etc/pam.d/common-auth"·&& 
185 ············grep····-E·"^\\s*auth\\s+required\\s+pam_faildelay.so"·<·"/etc/pam.d/common-auth"·| 
186 grep·-q·-E·-v·"\\sdelay(=|\\s|\$)"·;·then 
  
187 ········sed·--follow-symlinks·-i·-E·-e·"s/^(\\s*auth\\s+required\\s+pam_faildelay.so[^\\n]*)/\\1 
188 delay${defaultValue}/"·"/etc/pam.d/common-auth" 
189 ····#·add·a·new·entry·if·none·exists 
190 ····elif·!·grep·-q·-P·"^\\s*auth\\s+required\\s+pam_faildelay.so(\\s.+)?\\s+delay${valueRegex} 
191 (\\s|\$)"·<·"/etc/pam.d/common-auth"·;·then 
192 ········echo·"auth·required·pam_faildelay.so·delay${defaultValue}"·>>·"/etc/pam.d/common-auth" 
193 ····fi 
194 else 
195 ····echo·"/etc/pam.d/common-auth·doesn't·exist"·>&2 
196 fi 
  
197 else 
198 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
199 fi 
200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low157 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low158 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false159 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict160 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
205 -·name:·Gather·the·package·facts161 -·name:·Gather·the·package·facts
206 ··package_facts:162 ··package_facts:
Offset 348, 97 lines modifiedOffset 295, 80 lines modified
348 ··-·DISA-STIG-SLEM-05-412025295 ··-·DISA-STIG-SLEM-05-412025
349 ··-·accounts_passwords_pam_faildelay_delay296 ··-·accounts_passwords_pam_faildelay_delay
350 ··-·low_complexity297 ··-·low_complexity
351 ··-·low_disruption298 ··-·low_disruption
352 ··-·medium_severity299 ··-·medium_severity
353 ··-·no_reboot_needed300 ··-·no_reboot_needed
354 ··-·restrict_strategy301 ··-·restrict_strategy
355 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8SL\x8LE\x8EM\x8M·5\x85·m\x8mu\x8us\x8st\x8t·u\x8us\x8se\x8e·t\x8th\x8he\x8e·d\x8de\x8ef\x8fa\x8au\x8ul\x8lt\x8t·p\x8pa\x8am\x8m_\x8_t\x8ta\x8al\x8ll\x8ly\x8y2\x82·t\x8ta\x8al\x8ll\x8ly\x8y·d\x8di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y.\x8.·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8* 
356 This·rule·configures·the·system·to·use·default·pam_tally2·tally·directory 
357 ·············By·limiting·the·number·of·failed·logon·attempts,·the·risk·of·unauthorized·system 
358 Rationale:···access·via·user·password·guessing,·otherwise·known·as·brute-force·attacks,·is 
359 ·············reduced.·Limits·are·imposed·by·locking·the·account. 
360 Severity: ···medium 
361 Rule·ID:·····xccdf_org.ssgproject.content_rule_accounts_passwords_pam_tally2_file 
362 Identifiers:·CCE-94089-0 
363 ·············_\x8d_\x8i_\x8s_\x8a····CCI-000044 
364 ·············_\x8n_\x8i_\x8s_\x8t····AC-7(a) 
365 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000021-GPOS-00005 
366 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLEM-05-412030 
367 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-261366r996837_rule 
368 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8302 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
369 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
370 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
371 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
372 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
373 #·Remediation·is·applicable·only·in·certain·platforms303 #·Remediation·is·applicable·only·in·certain·platforms
374 if·rpm·--quiet·-q·pam;·then304 if·rpm·--quiet·-q·pam;·then
  
 305 var_password_pam_delay='4000000'
375 declare·-a·VALUES=() 
376 declare·-a·VALUE_NAMES=() 
377 declare·-a·ARGS=() 
378 declare·-a·NEW_ARGS=() 
379 declare·-a·DEL_ARGS=() 
  
  
380 VALUES+=("") 
381 VALUE_NAMES+=("") 
382 ARGS+=("file") 
383 NEW_ARGS+=("") 
384 DEL_ARGS+=("file=")306 if·[·-e·"/etc/pam.d/common-auth"·]·;·then
 307 ····valueRegex="$var_password_pam_delay"·defaultValue="$var_password_pam_delay"
 308 ····#·non-empty·values·need·to·be·preceded·by·an·equals·sign
Max diff block lines reached; 386871/392863 bytes (98.47%) of diff not shown.
307 KB
./usr/share/doc/ssg-nondebian/ssg-uos20-guide-standard.html
    
Offset 14290, 15 lines modifiedOffset 14290, 15 lines modified
00037d10:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>00037d10:·2048·6973·746f·7279·3c2f·6832·3e3c·703e···History</h2><p>
00037d20:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:00037d20:·4375·7272·656e·7420·7665·7273·696f·6e3a··Current·version:
00037d30:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<00037d30:·203c·7374·726f·6e67·3e30·2e31·2e37·343c···<strong>0.1.74<
00037d40:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>00037d40:·2f73·7472·6f6e·673e·3c2f·703e·3c75·6c3e··/strong></p><ul>
00037d50:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf00037d50:·3c6c·693e·3c73·7472·6f6e·673e·6472·6166··<li><strong>draf
00037d60:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····00037d60:·743c·2f73·7472·6f6e·673e·0a20·2020·2020··t</strong>.·····
00037d70:·2020·2020·2020·2020·2020·2020·2020·2028·················(00037d70:·2020·2020·2020·2020·2020·2020·2020·2028·················(
00037d80:·6173·206f·6620·3230·3236·2d30·312d·3038··as·of·2026-01-0800037d80:·6173·206f·6620·3230·3234·2d31·322d·3037··as·of·2024-12-07
00037d90:·290a·2020·2020·2020·2020·2020·2020·2020··).··············00037d90:·290a·2020·2020·2020·2020·2020·2020·2020··).··············
00037da0:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di00037da0:·2020·3c2f·6c69·3e3c·2f75·6c3e·3c2f·6469····</li></ul></di
00037db0:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C00037db0:·763e·3c68·323e·5461·626c·6520·6f66·2043··v><h2>Table·of·C
00037dc0:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>00037dc0:·6f6e·7465·6e74·733c·2f68·323e·3c6f·6c3e··ontents</h2><ol>
00037dd0:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc00037dd0:·3c6c·693e·3c61·2068·7265·663d·2223·7863··<li><a·href="#xc
00037de0:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje00037de0:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
00037df0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group00037df0:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
Offset 16132, 173 lines modifiedOffset 16132, 173 lines modified
0003f030:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003f030:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003f040:·6d38·3633·2220·7461·6269·6e64·6578·3d22··m863"·tabindex="0003f040:·6d38·3633·2220·7461·6269·6e64·6578·3d22··m863"·tabindex="
0003f050:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003f050:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003f060:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003f060:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003f070:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003f070:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003f080:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003f080:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003f090:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003f090:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003f0a0:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc0003f0a0:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible·
 0003f0b0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0003f0c0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003f0d0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003f0e0:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
 0003f0f0:·3633·223e·3c74·6162·6c65·2063·6c61·7373··63"><table·class
 0003f100:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003f110:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0003f120:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003f130:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003f140:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003f150:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003f160:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003f0b0:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003f0c0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003f0d0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003f0e0:·7073·6522·2069·643d·2269·646d·3836·3322··pse"·id="idm863" 
0003f0f0:·3e3c·7072·653e·3c63·6f64·653e·0a76·6172··><pre><code>.var 
0003f100:·5f73·7973·7465·6d5f·6372·7970·746f·5f70··_system_crypto_p 
0003f110:·6f6c·6963·793d·273c·6162·6272·2074·6974··olicy='<abbr·tit 
0003f120:·6c65·3d22·6672·6f6d·2042·656e·6368·6d61··le="from·Benchma 
0003f130:·726b·2f56·616c·7565·3a20·7863·6364·665f··rk/Value:·xccdf_ 
0003f140:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c 
0003f150:·6f6e·7465·6e74·5f76·616c·7565·5f76·6172··ontent_value_var 
0003f160:·5f73·7973·7465·6d5f·6372·7970·746f·5f70··_system_crypto_p 
0003f170:·6f6c·6963·7922·3e44·4546·4155·4c54·3c2f··olicy">DEFAULT</ 
0003f180:·6162·6272·3e27·0a0a·0a73·7464·6572·725f··abbr>'...stderr_ 
0003f190:·6f66·5f63·616c·6c3d·2428·7570·6461·7465··of_call=$(update 
0003f1a0:·2d63·7279·7074·6f2d·706f·6c69·6369·6573··-crypto-policies 
0003f1b0:·202d·2d73·6574·2024·7b76·6172·5f73·7973···--set·${var_sys 
0003f1c0:·7465·6d5f·6372·7970·746f·5f70·6f6c·6963··tem_crypto_polic 
0003f1d0:·797d·2032·2667·743b·2661·6d70·3b31·2026··y}·2&gt;&amp;1·& 
0003f1e0:·6774·3b20·2f64·6576·2f6e·756c·6c29·0a72··gt;·/dev/null).r 
0003f1f0:·633d·243f·0a0a·6966·2074·6573·7420·2224··c=$?..if·test·"$ 
0003f200:·7263·2220·3d20·3132·373b·2074·6865·6e0a··rc"·=·127;·then. 
0003f210:·0965·6368·6f20·2224·7374·6465·7272·5f6f··.echo·"$stderr_o 
0003f220:·665f·6361·6c6c·2220·2667·743b·2661·6d70··f_call"·&gt;&amp 
0003f230:·3b32·0a09·6563·686f·2022·4d61·6b65·2073··;2..echo·"Make·s 
0003f240:·7572·6520·7468·6174·2074·6865·2073·6372··ure·that·the·scr 
0003f250:·6970·7420·6973·2069·6e73·7461·6c6c·6564··ipt·is·installed 
0003f260:·206f·6e20·7468·6520·7265·6d65·6469·6174···on·the·remediat 
0003f270:·6564·2073·7973·7465·6d2e·2220·2667·743b··ed·system."·&gt; 
0003f280:·2661·6d70·3b32·0a09·6563·686f·2022·5365··&amp;2..echo·"Se 
0003f290:·6520·6f75·7470·7574·206f·6620·7468·6520··e·output·of·the· 
0003f2a0:·2764·6e66·2070·726f·7669·6465·7320·7570··'dnf·provides·up 
0003f2b0:·6461·7465·2d63·7279·7074·6f2d·706f·6c69··date-crypto-poli 
0003f2c0:·6369·6573·2720·636f·6d6d·616e·6422·2026··cies'·command"·& 
0003f2d0:·6774·3b26·616d·703b·320a·0965·6368·6f20··gt;&amp;2..echo· 
0003f2e0:·2274·6f20·7365·6520·7768·6174·2070·6163··"to·see·what·pac 
0003f2f0:·6b61·6765·2074·6f20·2872·6529·696e·7374··kage·to·(re)inst 
0003f300:·616c·6c22·2026·6774·3b26·616d·703b·320a··all"·&gt;&amp;2. 
0003f310:·0a09·6661·6c73·6520·2023·2065·6e64·2077··..false··#·end·w 
0003f320:·6974·6820·616e·2065·7272·6f72·2063·6f64··ith·an·error·cod 
0003f330:·650a·656c·6966·2074·6573·7420·2224·7263··e.elif·test·"$rc 
0003f340:·2220·213d·2030·3b20·7468·656e·0a09·6563··"·!=·0;·then..ec 
0003f350:·686f·2022·4572·726f·7220·696e·766f·6b69··ho·"Error·invoki 
0003f360:·6e67·2074·6865·2075·7064·6174·652d·6372··ng·the·update-cr 
0003f370:·7970·746f·2d70·6f6c·6963·6965·7320·7363··ypto-policies·sc 
0003f380:·7269·7074·3a20·2473·7464·6572·725f·6f66··ript:·$stderr_of 
0003f390:·5f63·616c·6c22·2026·6774·3b26·616d·703b··_call"·&gt;&amp; 
0003f3a0:·320a·0966·616c·7365·2020·2320·656e·6420··2..false··#·end· 
0003f3b0:·7769·7468·2061·6e20·6572·726f·7220·636f··with·an·error·co 
0003f3c0:·6465·0a66·690a·3c2f·636f·6465·3e3c·2f70··de.fi.</code></p 
0003f3d0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003f3e0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003f3f0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003f400:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003f410:·7461·7267·6574·3d22·2369·646d·3836·3522··target="#idm865" 
0003f420:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003f430:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003f440:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003f450:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003f460:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003f470:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003f480:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp 
0003f490:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003f4a0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003f4b0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003f4c0:·6522·2069·643d·2269·646d·3836·3522·3e3c··e"·id="idm865">< 
0003f4d0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003f4e0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003f4f0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003f500:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003f510:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003f520:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003f170:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003f530:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003f540:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003f550:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003f560:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003f570:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003f580:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003f180:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003f190:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003f1a0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003f1b0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003f1c0:·3c2f·7468·3e3c·7464·3e72·6573·7472·6963··</th><td>restric
 0003f1d0:·743c·2f74·643e·3c2f·7472·3e3c·2f74·6162··t</td></tr></tab
 0003f1e0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-·
 0003f1f0:·6e61·6d65·3a20·5843·4344·4620·5661·6c75··name:·XCCDF·Valu
0003f590:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003f5a0:·3c74·643e·7265·7374·7269·6374·3c2f·7464··<td>restrict</td 
0003f5b0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003f5c0:·7265·3e3c·636f·6465·3e2d·206e·616d·653a··re><code>-·name: 
0003f5d0:·2058·4343·4446·2056·616c·7565·2076·6172···XCCDF·Value·var 
0003f5e0:·5f73·7973·7465·6d5f·6372·7970·746f·5f70··_system_crypto_p 
Max diff block lines reached; 264850/288502 bytes (91.80%) of diff not shown.
24.9 KB
html2text {}
    
Offset 39, 15 lines modifiedOffset 39, 15 lines modified
39 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*39 *\x8**\x8**\x8**\x8**\x8*·P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8In\x8nf\x8fo\x8or\x8rm\x8ma\x8at\x8ti\x8io\x8on\x8n·*\x8**\x8**\x8**\x8**\x8*
40 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·UnionTech·OS·Server·2040 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·T\x8Ti\x8it\x8tl\x8le\x8e·Standard·System·Security·Profile·for·UnionTech·OS·Server·20
41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard41 P\x8Pr\x8ro\x8of\x8fi\x8il\x8le\x8e·I\x8ID\x8D····xccdf_org.ssgproject.content_profile_standard
42 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*42 *\x8**\x8**\x8*·C\x8CP\x8PE\x8E·P\x8Pl\x8la\x8at\x8tf\x8fo\x8or\x8rm\x8ms\x8s·*\x8**\x8**\x8*
43 ····*·cpe:/o:uos:uniontech_os_server:2043 ····*·cpe:/o:uos:uniontech_os_server:20
44 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*44 *\x8**\x8**\x8**\x8**\x8*·R\x8Re\x8ev\x8vi\x8is\x8si\x8io\x8on\x8n·H\x8Hi\x8is\x8st\x8to\x8or\x8ry\x8y·*\x8**\x8**\x8**\x8**\x8*
45 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x8445 Current·version:·0\x80.\x8.1\x81.\x8.7\x874\x84
46 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2026-01-08)46 ····*·d\x8dr\x8ra\x8af\x8ft\x8t·(as·of·2024-12-07)
47 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*47 *\x8**\x8**\x8**\x8**\x8*·T\x8Ta\x8ab\x8bl\x8le\x8e·o\x8of\x8f·C\x8Co\x8on\x8nt\x8te\x8en\x8nt\x8ts\x8s·*\x8**\x8**\x8**\x8**\x8*
48 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s48 ···1.·_\x8S_\x8y_\x8s_\x8t_\x8e_\x8m_\x8·_\x8S_\x8e_\x8t_\x8t_\x8i_\x8n_\x8g_\x8s
49 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e49 ·········1.·_\x8I_\x8n_\x8s_\x8t_\x8a_\x8l_\x8l_\x8i_\x8n_\x8g_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8i_\x8n_\x8t_\x8a_\x8i_\x8n_\x8i_\x8n_\x8g_\x8·_\x8S_\x8o_\x8f_\x8t_\x8w_\x8a_\x8r_\x8e
50 ·········2.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s50 ·········2.·_\x8F_\x8i_\x8l_\x8e_\x8·_\x8P_\x8e_\x8r_\x8m_\x8i_\x8s_\x8s_\x8i_\x8o_\x8n_\x8s_\x8·_\x8a_\x8n_\x8d_\x8·_\x8M_\x8a_\x8s_\x8k_\x8s
51 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s51 ···2.·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
52 ·········1.·_\x8B_\x8a_\x8s_\x8e_\x8·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s52 ·········1.·_\x8B_\x8a_\x8s_\x8e_\x8·_\x8S_\x8e_\x8r_\x8v_\x8i_\x8c_\x8e_\x8s
53 ·········2.·_\x8C_\x8r_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8t_\x8·_\x8D_\x8a_\x8e_\x8m_\x8o_\x8n_\x8s53 ·········2.·_\x8C_\x8r_\x8o_\x8n_\x8·_\x8a_\x8n_\x8d_\x8·_\x8A_\x8t_\x8·_\x8D_\x8a_\x8e_\x8m_\x8o_\x8n_\x8s
Offset 275, 34 lines modifiedOffset 275, 14 lines modified
275 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1275 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1,·CIP-007-3·R7.1
276 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)276 References:·_\x8n_\x8i_\x8s_\x8t·····AC-17(a),·AC-17(2),·CM-6(a),·MA-4(6),·SC-13,·SC-12(2),·SC-12(3)
277 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),277 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),
278 ·····················FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1278 ·····················FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
279 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-279 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-
280 ·····················000394-GPOS-00174280 ·····················000394-GPOS-00174
281 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7281 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··2.2.7
282 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
  
283 var_system_crypto_policy='DEFAULT' 
  
  
284 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/ 
285 dev/null) 
286 rc=$? 
  
287 if·test·"$rc"·=·127;·then 
288 »       echo·"$stderr_of_call"·>&2 
289 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2 
290 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2 
291 »       echo·"to·see·what·package·to·(re)install"·>&2 
  
292 »       false··#·end·with·an·error·code 
293 elif·test·"$rc"·!=·0;·then 
294 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2 
295 »       false··#·end·with·an·error·code 
296 fi 
297 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8282 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
298 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low283 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
299 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low284 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
300 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false285 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
301 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict286 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
302 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable287 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
303 ··set_fact:288 ··set_fact:
Offset 345, 14 lines modifiedOffset 325, 34 lines modified
345 ··-·PCI-DSSv4-2.2.7325 ··-·PCI-DSSv4-2.2.7
346 ··-·configure_crypto_policy326 ··-·configure_crypto_policy
347 ··-·high_severity327 ··-·high_severity
348 ··-·low_complexity328 ··-·low_complexity
349 ··-·low_disruption329 ··-·low_disruption
350 ··-·no_reboot_needed330 ··-·no_reboot_needed
351 ··-·restrict_strategy331 ··-·restrict_strategy
 332 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
 333 var_system_crypto_policy='DEFAULT'
  
  
 334 stderr_of_call=$(update-crypto-policies·--set·${var_system_crypto_policy}·2>&1·>·/
 335 dev/null)
 336 rc=$?
  
 337 if·test·"$rc"·=·127;·then
 338 »       echo·"$stderr_of_call"·>&2
 339 »       echo·"Make·sure·that·the·script·is·installed·on·the·remediated·system."·>&2
 340 »       echo·"See·output·of·the·'dnf·provides·update-crypto-policies'·command"·>&2
 341 »       echo·"to·see·what·package·to·(re)install"·>&2
  
 342 »       false··#·end·with·an·error·code
 343 elif·test·"$rc"·!=·0;·then
 344 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
 345 »       false··#·end·with·an·error·code
 346 fi
352 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·K\x8Ke\x8er\x8rb\x8be\x8er\x8ro\x8os\x8s·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*347 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·K\x8Ke\x8er\x8rb\x8be\x8er\x8ro\x8os\x8s·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
353 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many348 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many
354 packages.·Kerberos·is·supported·by·crypto·policy,·but·it's·configuration·may·be·set349 packages.·Kerberos·is·supported·by·crypto·policy,·but·it's·configuration·may·be·set
355 up·to·ignore·it.·To·check·that·Crypto·Policies·settings·for·Kerberos·are·configured350 up·to·ignore·it.·To·check·that·Crypto·Policies·settings·for·Kerberos·are·configured
356 correctly,·examine·that·there·is·a·symlink·at·/etc/krb5.conf.d/crypto-policies351 correctly,·examine·that·there·is·a·symlink·at·/etc/krb5.conf.d/crypto-policies
357 targeting·/etc/cypto-policies/back-ends/krb5.config.·If·the·symlink·exists,352 targeting·/etc/cypto-policies/back-ends/krb5.config.·If·the·symlink·exists,
358 Kerberos·is·configured·to·use·the·system-wide·crypto·policy·settings.353 Kerberos·is·configured·to·use·the·system-wide·crypto·policy·settings.
Offset 360, 22 lines modifiedOffset 360, 14 lines modified
360 ············violate·expectations,·and·makes·system·configuration·more·fragmented.360 ············violate·expectations,·and·makes·system·configuration·more·fragmented.
361 Severity: ··high361 Severity: ··high
362 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_kerberos_crypto_policy362 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_kerberos_crypto_policy
363 ············_\x8i_\x8s_\x8m······0418,·1055,·1402363 ············_\x8i_\x8s_\x8m······0418,·1055,·1402
364 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1364 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
365 ············_\x8n_\x8i_\x8s_\x8t·····SC-13,·SC-12(2),·SC-12(3)365 ············_\x8n_\x8i_\x8s_\x8t·····SC-13,·SC-12(2),·SC-12(3)
366 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000120-GPOS-00061366 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000120-GPOS-00061
367 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
368 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
369 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
370 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
371 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure 
  
372 rm·-f·/etc/krb5.conf.d/crypto-policies 
373 ln·-s·/etc/crypto-policies/back-ends/krb5.config·/etc/krb5.conf.d/crypto-policies 
374 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8367 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
375 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low368 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
376 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low369 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
377 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true370 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
378 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure371 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
379 -·name:·Configure·Kerberos·to·use·System·Crypto·Policy372 -·name:·Configure·Kerberos·to·use·System·Crypto·Policy
380 ··file:373 ··file:
Offset 388, 14 lines modifiedOffset 380, 22 lines modified
388 ··-·NIST-800-53-SC-13380 ··-·NIST-800-53-SC-13
389 ··-·configure_kerberos_crypto_policy381 ··-·configure_kerberos_crypto_policy
390 ··-·configure_strategy382 ··-·configure_strategy
391 ··-·high_severity383 ··-·high_severity
392 ··-·low_complexity384 ··-·low_complexity
393 ··-·low_disruption385 ··-·low_disruption
394 ··-·reboot_required386 ··-·reboot_required
 387 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 388 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 389 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 390 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 391 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
  
 392 rm·-f·/etc/krb5.conf.d/crypto-policies
 393 ln·-s·/etc/crypto-policies/back-ends/krb5.config·/etc/krb5.conf.d/crypto-policies
395 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·L\x8Li\x8ib\x8br\x8re\x8es\x8sw\x8wa\x8an\x8n·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*394 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·L\x8Li\x8ib\x8br\x8re\x8es\x8sw\x8wa\x8an\x8n·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
396 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many395 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many
397 packages.·Libreswan·is·supported·by·system·crypto·policy,·but·the·Libreswan396 packages.·Libreswan·is·supported·by·system·crypto·policy,·but·the·Libreswan
Max diff block lines reached; 19310/25512 bytes (75.69%) of diff not shown.
3.49 MB
./usr/share/doc/ssg-nondebian/table-ol7-anssirefs.html
    
Offset 63, 280 lines modifiedOffset 63, 280 lines modified
000003e0:·2054·6974·6c65·3c2f·7468·3e0a·2020·2020···Title</th>.····000003e0:·2054·6974·6c65·3c2f·7468·3e0a·2020·2020···Title</th>.····
000003f0:·3c74·683e·4465·7363·7269·7074·696f·6e3c··<th>Description<000003f0:·3c74·683e·4465·7363·7269·7074·696f·6e3c··<th>Description<
00000400:·2f74·683e·0a20·2020·203c·7468·3e52·6174··/th>.····<th>Rat00000400:·2f74·683e·0a20·2020·203c·7468·3e52·6174··/th>.····<th>Rat
00000410:·696f·6e61·6c65·3c2f·7468·3e0a·2020·3c2f··ionale</th>.··</00000410:·696f·6e61·6c65·3c2f·7468·3e0a·2020·3c2f··ionale</th>.··</
00000420:·7468·6561·643e·0a20·203c·7462·6f64·793e··thead>.··<tbody>00000420:·7468·6561·643e·0a20·203c·7462·6f64·793e··thead>.··<tbody>
00000430:·0a20·203c·7472·3e0a·2020·2020·2020·3c74··.··<tr>.······<t00000430:·0a20·203c·7472·3e0a·2020·2020·2020·3c74··.··<tr>.······<t
00000440:·643e·5231·3c2f·7464·3e0a·2020·2020·2020··d>R1</td>.······00000440:·643e·5231·3c2f·7464·3e0a·2020·2020·2020··d>R1</td>.······
00000450:·3c74·643e·456e·7375·7265·2053·4d45·5020··<td>Ensure·SMEP· 
00000460:·6973·206e·6f74·2064·6973·6162·6c65·6420··is·not·disabled· 
00000470:·6475·7269·6e67·2062·6f6f·743c·2f74·643e··during·boot</td>00000450:·3c74·643e·496e·7374·616c·6c20·5041·4520··<td>Install·PAE·
 00000460:·4b65·726e·656c·206f·6e20·5375·7070·6f72··Kernel·on·Suppor
 00000470:·7465·6420·3332·2d62·6974·2078·3836·2053··ted·32-bit·x86·S
 00000480:·7973·7465·6d73·3c2f·7464·3e0a·2020·2020··ystems</td>.····
 00000490:·2020·3c74·6420·786d·6c3a·6c61·6e67·3d22····<td·xml:lang="
 000004a0:·656e·2d55·5322·3e0a·2020·2020·2020·2020··en-US">.········
 000004b0:·5379·7374·656d·7320·7468·6174·2061·7265··Systems·that·are
 000004c0:·2075·7369·6e67·2074·6865·2036·342d·6269···using·the·64-bi
 000004d0:·7420·7838·3620·6b65·726e·656c·2070·6163··t·x86·kernel·pac
 000004e0:·6b61·6765·0a64·6f20·6e6f·7420·6e65·6564··kage.do·not·need
 000004f0:·2074·6f20·696e·7374·616c·6c20·7468·6520···to·install·the·
 00000500:·6b65·726e·656c·2d50·4145·2070·6163·6b61··kernel-PAE·packa
 00000510:·6765·2062·6563·6175·7365·2074·6865·2036··ge·because·the·6
 00000520:·342d·6269·740a·7838·3620·6b65·726e·656c··4-bit.x86·kernel
 00000530:·2061·6c72·6561·6479·2069·6e63·6c75·6465···already·include
 00000540:·7320·7468·6973·2073·7570·706f·7274·2e20··s·this·support.·
 00000550:·486f·7765·7665·722c·2069·6620·7468·6520··However,·if·the·
 00000560:·7379·7374·656d·2069·730a·3332·2d62·6974··system·is.32-bit
 00000570:·2061·6e64·2061·6c73·6f20·7375·7070·6f72···and·also·suppor
 00000580:·7473·2074·6865·2050·4145·2061·6e64·204e··ts·the·PAE·and·N
 00000590:·5820·6665·6174·7572·6573·2061·730a·6465··X·features·as.de
 000005a0:·7465·726d·696e·6564·2069·6e20·7468·6520··termined·in·the·
 000005b0:·7072·6576·696f·7573·2073·6563·7469·6f6e··previous·section
 000005c0:·2c20·7468·6520·6b65·726e·656c·2d50·4145··,·the·kernel-PAE
 000005d0:·2070·6163·6b61·6765·2073·686f·756c·640a···package·should.
 000005e0:·6265·2069·6e73·7461·6c6c·6564·2074·6f20··be·installed·to·
 000005f0:·656e·6162·6c65·2058·4420·6f72·204e·5820··enable·XD·or·NX·
 00000600:·7375·7070·6f72·742e·0a54·6865·203c·636f··support..The·<co
 00000610:·6465·3e6b·6572·6e65·6c2d·5041·453c·2f63··de>kernel-PAE</c
 00000620:·6f64·653e·2070·6163·6b61·6765·2063·616e··ode>·package·can
 00000630:·2062·6520·696e·7374·616c·6c65·6420·7769···be·installed·wi
 00000640:·7468·2074·6865·2066·6f6c·6c6f·7769·6e67··th·the·following
 00000650:·2063·6f6d·6d61·6e64·3a0a·3c70·7265·3e0a···command:.<pre>.
 00000660:·2420·7375·646f·2079·756d·2069·6e73·7461··$·sudo·yum·insta
 00000670:·6c6c·206b·6572·6e65·6c2d·5041·453c·2f70··ll·kernel-PAE</p
 00000680:·7265·3e0a·5468·6520·696e·7374·616c·6c61··re>.The·installa
 00000690:·7469·6f6e·2070·726f·6365·7373·2073·686f··tion·process·sho
 000006a0:·756c·6420·616c·736f·2068·6176·6520·636f··uld·also·have·co
 000006b0:·6e66·6967·7572·6564·2074·6865·0a62·6f6f··nfigured·the.boo
 000006c0:·746c·6f61·6465·7220·746f·206c·6f61·6420··tloader·to·load·
 000006d0:·7468·6520·6e65·7720·6b65·726e·656c·2061··the·new·kernel·a
 000006e0:·7420·626f·6f74·2e20·5665·7269·6679·2074··t·boot.·Verify·t
 000006f0:·6869·7320·6166·7465·7220·7265·626f·6f74··his·after·reboot
 00000700:·0a61·6e64·206d·6f64·6966·7920·3c74·743e··.and·modify·<tt>
 00000710:·2f65·7463·2f64·6566·6175·6c74·2f67·7275··/etc/default/gru
 00000720:·623c·2f74·743e·2069·6620·6e65·6365·7373··b</tt>·if·necess
 00000730:·6172·792e·0a20·2020·2020·203c·2f74·643e··ary..······</td>
00000480:·0a20·2020·2020·203c·7464·2078·6d6c·3a6c··.······<td·xml:l00000740:·0a20·2020·2020·203c·7464·2078·6d6c·3a6c··.······<td·xml:l
00000490:·616e·673d·2265·6e2d·5553·223e·0a20·2020··ang="en-US">.···00000750:·616e·673d·2265·6e2d·5553·223e·0a20·2020··ang="en-US">.···
 00000760:·2020·2020·204f·6e20·3332·2d62·6974·2073·······On·32-bit·s
 00000770:·7973·7465·6d73·2074·6861·7420·7375·7070··ystems·that·supp
 00000780:·6f72·7420·7468·6520·5844·206f·7220·4e58··ort·the·XD·or·NX
 00000790:·2062·6974·2c20·7468·6520·7665·6e64·6f72···bit,·the·vendor
 000007a0:·2d73·7570·706c·6965·640a·5041·4520·6b65··-supplied.PAE·ke
 000007b0:·726e·656c·2069·7320·7265·7175·6972·6564··rnel·is·required
 000007c0:·2074·6f20·656e·6162·6c65·2065·6974·6865···to·enable·eithe
 000007d0:·7220·4578·6563·7574·6520·4469·7361·626c··r·Execute·Disabl
 000007e0:·6520·2858·4429·206f·7220·4e6f·2045·7865··e·(XD)·or·No·Exe
 000007f0:·6375·7465·2028·4e58·2920·7375·7070·6f72··cute·(NX)·suppor
 00000800:·742e·0a20·2020·2020·203c·2f74·643e·0a20··t..······</td>.·
 00000810:·2020·203c·2f74·723e·0a20·2020·203c·7472·····</tr>.····<tr
 00000820:·3e0a·2020·2020·2020·3c74·643e·5231·3c2f··>.······<td>R1</
 00000830:·7464·3e0a·2020·2020·2020·3c74·643e·456e··td>.······<td>En
 00000840:·7375·7265·2053·4d41·5020·6973·206e·6f74··sure·SMAP·is·not
 00000850:·2064·6973·6162·6c65·6420·6475·7269·6e67···disabled·during
000004a0:·2020·2020·2054·6865·2053·4d45·5020·6973·······The·SMEP·is 
000004b0:·2075·7365·6420·746f·2070·7265·7665·6e74···used·to·prevent 
000004c0:·2074·6865·2073·7570·6572·7669·736f·7220···the·supervisor· 
000004d0:·6d6f·6465·2066·726f·6d20·6578·6563·7574··mode·from·execut 
000004e0:·696e·6720·7573·6572·2073·7061·6365·2063··ing·user·space·c 
000004f0:·6f64·652c·0a69·7420·6973·2065·6e61·626c··ode,.it·is·enabl 
00000500:·6564·2062·7920·6465·6661·756c·7420·7369··ed·by·default·si 
00000510:·6e63·6520·4c69·6e75·7820·6b65·726e·656c··nce·Linux·kernel 
00000520:·2033·2e30·2e20·4275·7420·6974·2063·6f75···3.0.·But·it·cou 
00000530:·6c64·2062·6520·6469·7361·626c·6564·2074··ld·be·disabled·t 
00000540:·6872·6f75·6768·0a6b·6572·6e65·6c20·626f··hrough.kernel·bo 
00000550:·6f74·2070·6172·616d·6574·6572·732e·0a0a··ot·parameters... 
00000560:·456e·7375·7265·2074·6861·7420·5375·7065··Ensure·that·Supe 
00000570:·7276·6973·6f72·204d·6f64·6520·4578·6563··rvisor·Mode·Exec 
00000580:·7574·696f·6e20·5072·6576·656e·7469·6f6e··ution·Prevention 
00000590:·2028·534d·4550·2920·6973·206e·6f74·2064···(SMEP)·is·not·d 
000005a0:·6973·6162·6c65·6420·6279·0a74·6865·203c··isabled·by.the·< 
000005b0:·7474·3e6e·6f73·6d65·703c·2f74·743e·2062··tt>nosmep</tt>·b 
000005c0:·6f6f·7420·7061·7261·6d65·6e74·6572·206f··oot·paramenter·o 
000005d0:·7074·696f·6e2e·0a0a·4368·6563·6b20·7468··ption...Check·th 
000005e0:·6174·2074·6865·206c·696e·6520·3c70·7265··at·the·line·<pre 
000005f0:·3e47·5255·425f·434d·444c·494e·455f·4c49··>GRUB_CMDLINE_LI 
00000600:·4e55·583d·222e·2e2e·223c·2f70·7265·3e20··NUX="..."</pre>· 
00000610:·7769·7468·696e·203c·7474·3e2f·6574·632f··within·<tt>/etc/ 
00000620:·6465·6661·756c·742f·6772·7562·3c2f·7474··default/grub</tt 
00000630:·3e0a·646f·6573·6e27·7420·636f·6e74·6169··>.doesn't·contai 
00000640:·6e20·7468·6520·6172·6775·6d65·6e74·203c··n·the·argument·< 
00000650:·7474·3e6e·6f73·6d65·703c·2f74·743e·2e0a··tt>nosmep</tt>.. 
00000660:·5275·6e20·7468·6520·666f·6c6c·6f77·696e··Run·the·followin 
00000670:·6720·636f·6d6d·616e·6420·746f·2075·7064··g·command·to·upd 
00000680:·6174·6520·636f·6d6d·616e·6420·6c69·6e65··ate·command·line 
00000690:·2066·6f72·2061·6c72·6561·6479·2069·6e73···for·already·ins 
000006a0:·7461·6c6c·6564·206b·6572·6e65·6c73·3a0a··talled·kernels:. 
000006b0:·3c70·7265·3e23·2067·7275·6262·7920·2d2d··<pre>#·grubby·-- 
000006c0:·7570·6461·7465·2d6b·6572·6e65·6c3d·414c··update-kernel=AL 
000006d0:·4c20·2d2d·7265·6d6f·7665·2d61·7267·733d··L·--remove-args= 
000006e0:·226e·6f73·6d65·7022·3c2f·7072·653e·0a20··"nosmep"</pre>.· 
000006f0:·2020·2020·203c·2f74·643e·0a20·2020·2020·······</td>.·····00000860:·2062·6f6f·743c·2f74·643e·0a20·2020·2020···boot</td>.·····
00000700:·203c·7464·2078·6d6c·3a6c·616e·673d·2265···<td·xml:lang="e00000870:·203c·7464·2078·6d6c·3a6c·616e·673d·2265···<td·xml:lang="e
00000710:·6e2d·5553·223e·0a20·2020·2020·2020·2044··n-US">.········D00000880:·6e2d·5553·223e·0a20·2020·2020·2020·2054··n-US">.········T
 00000890:·6865·2053·4d41·5020·6973·2075·7365·6420··he·SMAP·is·used·
 000008a0:·746f·2070·7265·7665·6e74·2074·6865·2073··to·prevent·the·s
 000008b0:·7570·6572·7669·736f·7220·6d6f·6465·2066··upervisor·mode·f
 000008c0:·726f·6d20·756e·696e·7465·6e74·696f·6e61··rom·unintentiona
 000008d0:·6c6c·7920·7265·6164·696e·672f·7772·6974··lly·reading/writ
 000008e0:·696e·6720·696e·746f·0a6d·656d·6f72·7920··ing·into.memory·
 000008f0:·7061·6765·7320·696e·2074·6865·2075·7365··pages·in·the·use
 00000900:·7220·7370·6163·652c·2069·7420·6973·2065··r·space,·it·is·e
 00000910:·6e61·626c·6564·2062·7920·6465·6661·756c··nabled·by·defaul
 00000920:·7420·7369·6e63·6520·4c69·6e75·7820·6b65··t·since·Linux·ke
 00000930:·726e·656c·2033·2e37·2e0a·4275·7420·6974··rnel·3.7..But·it
 00000940:·2063·6f75·6c64·2062·6520·6469·7361·626c···could·be·disabl
 00000950:·6564·2074·6872·6f75·6768·206b·6572·6e65··ed·through·kerne
Max diff block lines reached; 2950037/2986491 bytes (98.78%) of diff not shown.
658 KB
html2text {}
    
Offset 1, 35 lines modifiedOffset 1, 13 lines modified
  
  
1 Rules·with·ANSSI·Reference·in·Guide·to·the·Secure·Configuration·of·Oracle·Linux1 Rules·with·ANSSI·Reference·in·Guide·to·the·Secure·Configuration·of·Oracle·Linux
2 72 7
  
  
3 ······························The·SMEP·is·used·to·prevent·the·supervisor 
4 ······························mode·from·executing·user·space·code,·it·is 
5 ······························enabled·by·default·since·Linux·kernel·3.0. 
6 ······························But·it·could·be·disabled·through·kernel·boot 
7 ······························parameters.·Ensure·that·Supervisor·Mode 
8 ······························Execution·Prevention·(SMEP)·is·not·disabled··Disabling·SMEP·can·facilitate 
9 ····Ensure·SMEP·is·not········by·the·nosmep·boot·paramenter·option.·Check··exploitation·of·certain 
10 R1··disabled·during·boot······that·the·line································vulnerabilities·because·it·allows·the 
11 ······························GRUB_CMDLINE_LINUX="..."·····················kernel·to·unintentionally·execute·code 
12 ······························within·/etc/default/grub·doesn't·contain·the·in·less·privileged·memory·space. 
13 ······························argument·nosmep.·Run·the·following·command 
14 ······························to·update·command·line·for·already·installed 
15 ······························kernels: 
16 ······························#·grubby·--update-kernel=ALL·--remove- 
17 ······························args="nosmep" 
18 ···········································································Use·of·a·64-bit·operating·system 
19 ···········································································offers·a·few·advantages,·like·a·larger 
20 ····Prefer·to·use·a·64-bit····Prefer·installation·of·64-bit·operating······address·space·range·for·Address·Space 
21 R1··Operating·System·when·····systems·when·the·CPU·supports·it.············Layout·Randomization·(ASLR)·and 
22 ····supported······························································systematic·presence·of·No·eXecute·and 
23 ···········································································Execute·Disable·(NX/XD)·protection 
24 ···········································································bits. 
25 ······························Systems·that·are·using·the·64-bit·x86·kernel3 ······························Systems·that·are·using·the·64-bit·x86·kernel
26 ······························package·do·not·need·to·install·the·kernel-4 ······························package·do·not·need·to·install·the·kernel-
27 ······························PAE·package·because·the·64-bit·x86·kernel5 ······························PAE·package·because·the·64-bit·x86·kernel
28 ······························already·includes·this·support.·However,·if6 ······························already·includes·this·support.·However,·if
29 ······························the·system·is·32-bit·and·also·supports·the7 ······························the·system·is·32-bit·and·also·supports·the
30 ······························PAE·and·NX·features·as·determined·in·the·····On·32-bit·systems·that·support·the·XD8 ······························PAE·and·NX·features·as·determined·in·the·····On·32-bit·systems·that·support·the·XD
31 ····Install·PAE·Kernel·on·····previous·section,·the·kernel-PAE·package·····or·NX·bit,·the·vendor-supplied·PAE9 ····Install·PAE·Kernel·on·····previous·section,·the·kernel-PAE·package·····or·NX·bit,·the·vendor-supplied·PAE
Offset 62, 31 lines modifiedOffset 40, 53 lines modified
62 ······························Advanced·Encryption·Standard·(AES)·or·New····utilizing·encryption·to·protect·data.40 ······························Advanced·Encryption·Standard·(AES)·or·New····utilizing·encryption·to·protect·data.
63 ····Install·the·dracut-fips-··Instructions·(AES-NI)·engine,·the·system·····The·operating·system·must·implement41 ····Install·the·dracut-fips-··Instructions·(AES-NI)·engine,·the·system·····The·operating·system·must·implement
64 R1··aesni·Package·············requires·that·the·dracut-fips-aesni·package··cryptographic·modules·adhering·to·the42 R1··aesni·Package·············requires·that·the·dracut-fips-aesni·package··cryptographic·modules·adhering·to·the
65 ······························be·installed.·The·dracut-fips-aesni·package··higher·standards·approved·by·the43 ······························be·installed.·The·dracut-fips-aesni·package··higher·standards·approved·by·the
66 ······························can·be·installed·with·the·following·command:·federal·government·since·this·provides44 ······························can·be·installed·with·the·following·command:·federal·government·since·this·provides
67 ······························$·sudo·yum·install·dracut-fips-aesni·········assurance·they·have·been·tested·and45 ······························$·sudo·yum·install·dracut-fips-aesni·········assurance·they·have·been·tested·and
68 ···········································································validated.46 ···········································································validated.
 47 ······························The·SMEP·is·used·to·prevent·the·supervisor
 48 ······························mode·from·executing·user·space·code,·it·is
 49 ······························enabled·by·default·since·Linux·kernel·3.0.
 50 ······························But·it·could·be·disabled·through·kernel·boot
 51 ······························parameters.·Ensure·that·Supervisor·Mode
 52 ······························Execution·Prevention·(SMEP)·is·not·disabled··Disabling·SMEP·can·facilitate
 53 ····Ensure·SMEP·is·not········by·the·nosmep·boot·paramenter·option.·Check··exploitation·of·certain
 54 R1··disabled·during·boot······that·the·line································vulnerabilities·because·it·allows·the
 55 ······························GRUB_CMDLINE_LINUX="..."·····················kernel·to·unintentionally·execute·code
 56 ······························within·/etc/default/grub·doesn't·contain·the·in·less·privileged·memory·space.
 57 ······························argument·nosmep.·Run·the·following·command
 58 ······························to·update·command·line·for·already·installed
 59 ······························kernels:
 60 ······························#·grubby·--update-kernel=ALL·--remove-
 61 ······························args="nosmep"
 62 ···········································································Use·of·a·64-bit·operating·system
 63 ···········································································offers·a·few·advantages,·like·a·larger
 64 ····Prefer·to·use·a·64-bit····Prefer·installation·of·64-bit·operating······address·space·range·for·Address·Space
 65 R1··Operating·System·when·····systems·when·the·CPU·supports·it.············Layout·Randomization·(ASLR)·and
 66 ····supported······························································systematic·presence·of·No·eXecute·and
 67 ···········································································Execute·Disable·(NX/XD)·protection
 68 ···········································································bits.
69 ······························The·grub2·boot·loader·should·have·a69 ······························The·grub2·boot·loader·should·have·a
70 ······························superuser·account·and·password·protection70 ······························superuser·account·and·password·protection
71 ······························enabled·to·protect·boot-time·settings.·······Password·protection·on·the·boot·loader71 ······························enabled·to·protect·boot-time·settings.·······Password·protection·on·the·boot·loader
72 ···········································································configuration·ensures·users·with72 ···········································································configuration·ensures·users·with
73 ····Set·Boot·Loader·Password··Since·plaintext·passwords·are·a·security·····physical·access·cannot·trivially·alter73 ····Set·the·UEFI·Boot·Loader··Since·plaintext·passwords·are·a·security·····physical·access·cannot·trivially·alter
74 R5··in·grub2··················risk,·generate·a·hash·for·the·password·by····important·bootloader·settings.·These74 R5··Password··················risk,·generate·a·hash·for·the·password·by····important·bootloader·settings.·These
75 ······························running·the·following·command:···············include·which·kernel·to·use,·and75 ······························running·the·following·command:···············include·which·kernel·to·use,·and
76 ······························#·grub2-setpassword··························whether·to·enter·single-user·mode.76 ······························#·grub2-setpassword··························whether·to·enter·single-user·mode.
77 ······························When·prompted,·enter·the·password·that·was77 ······························When·prompted,·enter·the·password·that·was
78 ······························selected.78 ······························selected.
  
79 ······························The·grub2·boot·loader·should·have·a79 ······························The·grub2·boot·loader·should·have·a
80 ······························superuser·account·and·password·protection80 ······························superuser·account·and·password·protection
81 ······························enabled·to·protect·boot-time·settings.·······Password·protection·on·the·boot·loader81 ······························enabled·to·protect·boot-time·settings.·······Password·protection·on·the·boot·loader
82 ···········································································configuration·ensures·users·with82 ···········································································configuration·ensures·users·with
83 ····Set·the·UEFI·Boot·Loader··Since·plaintext·passwords·are·a·security·····physical·access·cannot·trivially·alter83 ····Set·Boot·Loader·Password··Since·plaintext·passwords·are·a·security·····physical·access·cannot·trivially·alter
84 R5··Password··················risk,·generate·a·hash·for·the·password·by····important·bootloader·settings.·These84 R5··in·grub2··················risk,·generate·a·hash·for·the·password·by····important·bootloader·settings.·These
85 ······························running·the·following·command:···············include·which·kernel·to·use,·and85 ······························running·the·following·command:···············include·which·kernel·to·use,·and
86 ······························#·grub2-setpassword··························whether·to·enter·single-user·mode.86 ······························#·grub2-setpassword··························whether·to·enter·single-user·mode.
87 ······························When·prompted,·enter·the·password·that·was87 ······························When·prompted,·enter·the·password·that·was
88 ······························selected.88 ······························selected.
  
89 ······························On·x86·architecture·supporting·VT-d,·the89 ······························On·x86·architecture·supporting·VT-d,·the
90 ······························IOMMU·manages·the·access·control·policy90 ······························IOMMU·manages·the·access·control·policy
Offset 99, 77 lines modifiedOffset 99, 14 lines modified
99 ······························systems.·Modify·the·line·within·/etc/········hardware·devices.99 ······························systems.·Modify·the·line·within·/etc/········hardware·devices.
100 ······························default/grub·as·shown·below:100 ······························default/grub·as·shown·below:
101 ······························GRUB_CMDLINE_LINUX="...·iommu=force·..."101 ······························GRUB_CMDLINE_LINUX="...·iommu=force·..."
102 ······························Run·the·following·command·to·update·command102 ······························Run·the·following·command·to·update·command
103 ······························line·for·already·installed·kernels:103 ······························line·for·already·installed·kernels:
104 ······························#·grubby·--update-kernel=ALL·--104 ······························#·grubby·--update-kernel=ALL·--
105 ······························args="iommu=force"105 ······························args="iommu=force"
106 ······························To·enable·poisoning·of·SLUB/SLAB·objects, 
107 ······························add·the·argument·slub_debug=P·to·the·default 
108 ······························GRUB·2·command·line·for·the·Linux·operating··Poisoning·writes·an·arbitrary·value·to 
109 ······························system.·To·ensure·that·slub_debug=P·is·added·freed·objects,·so·any·modification·or 
110 ······························as·a·kernel·command·line·argument·to·newly···reference·to·that·object·after·being 
111 ······························installed·kernels,·add·slub_debug=P·to·the···freed·or·before·being·initialized·will 
112 R8··Enable·SLUB/SLAB··········default·Grub2·command·line·for·Linux·········be·detected·and·prevented.·This 
113 ····allocator·poisoning·······operating·systems.·Modify·the·line·within·/··prevents·many·types·of·use-after-free 
114 ······························etc/default/grub·as·shown·below:·············vulnerabilities·at·little·performance 
115 ······························GRUB_CMDLINE_LINUX="...·slub_debug=P·..."····cost.·Also·prevents·leak·of·data·and 
116 ······························Run·the·following·command·to·update·command··detection·of·corrupted·memory. 
117 ······························line·for·already·installed·kernels: 
118 ······························#·grubby·--update-kernel=ALL·-- 
119 ······························args="slub_debug=P" 
120 ······························L1·Terminal·Fault·(L1TF)·is·a·hardware 
121 ······························vulnerability·which·allows·unprivileged 
122 ······························speculative·access·to·data·which·is 
123 ······························available·in·the·Level·1·Data·Cache·when·the 
124 ······························page·table·entry·isn't·present.·Select·the 
125 ······························appropriate·mitigation·by·adding·the 
126 ······························argument·l1tf=flush·to·the·default·GRUB·2 
127 ······························command·line·for·the·Linux·operating·system. 
128 ······························To·ensure·that·l1tf=flush·is·added·as·a······The·L1TF·vulnerability·allows·an 
129 ······························kernel·command·line·argument·to·newly········attacker·to·bypass·memory·access 
130 ····Configure·L1·Terminal·····installed·kernels,·add·l1tf=flush·to·the·····security·controls·imposed·by·the 
131 R8··Fault·mitigations·········default·Grub2·command·line·for·Linux·········system·or·hypervisor.·The·L1TF 
132 ······························operating·systems.·Modify·the·line·within·/··vulnerability·allows·read·access·to 
133 ······························etc/default/grub·as·shown·below:·············any·physical·memory·location·that·is 
134 ······························GRUB_CMDLINE_LINUX="...·l1tf=flush·..."······cached·in·the·L1·Data·Cache. 
135 ······························Run·the·following·command·to·update·command 
Max diff block lines reached; 659733/674278 bytes (97.84%) of diff not shown.
1.23 MB
./usr/share/doc/ssg-nondebian/table-ol7-cuirefs.html
Ordering differences only
    
Offset 40, 90 lines modifiedOffset 40, 14 lines modified
40 ····<th>Mapping</th>40 ····<th>Mapping</th>
41 ····<th>Rule·Title</th>41 ····<th>Rule·Title</th>
42 ····<th>Description</th>42 ····<th>Description</th>
43 ····<th>Rationale</th>43 ····<th>Rationale</th>
44 ··</thead>44 ··</thead>
45 ··<tbody>45 ··<tbody>
46 ··<tr>46 ··<tr>
47 ······<td>3.1.1<br/>3.1.5</td> 
48 ······<td>Verify·Only·Root·Has·UID·0</td> 
49 ······<td·xml:lang="en-US"> 
50 ········If·any·account·other·than·root·has·a·UID·of·0,·this·misconfiguration·should 
51 be·investigated·and·the·accounts·other·than·root·should·be·removed·or·have 
52 their·UID·changed. 
53 <br·/> 
54 If·the·account·is·associated·with·system·commands·or·applications·the·UID 
55 should·be·changed·to·one·greater·than·"0"·but·less·than·"1000." 
56 Otherwise·assign·a·UID·greater·than·"1000"·that·has·not·already·been 
57 assigned. 
58 ······</td> 
59 ······<td·xml:lang="en-US"> 
60 ········An·account·has·root·authority·if·it·has·a·UID·of·0.·Multiple·accounts 
61 with·a·UID·of·0·afford·more·opportunity·for·potential·intruders·to 
62 guess·a·password·for·a·privileged·account.·Proper·configuration·of 
63 sudo·is·recommended·to·afford·multiple·system·administrators 
64 access·to·root·privileges·in·an·accountable·manner. 
65 ······</td> 
66 ····</tr> 
67 ····<tr> 
68 ······<td>3.1.1<br/>3.1.5</td> 
69 ······<td>Disable·SSH·Root·Login</td> 
70 ······<td·xml:lang="en-US"> 
71 ········The·root·user·should·never·be·allowed·to·login·to·a 
72 system·directly·over·a·network. 
73 To·disable·root·login·via·SSH,·add·or·correct·the·following·line·in 
  
  
74 <tt>/etc/ssh/sshd_config</tt>: 
  
75 <pre>PermitRootLogin·no</pre> 
76 ······</td> 
77 ······<td·xml:lang="en-US"> 
78 ········Even·though·the·communications·channel·may·be·encrypted,·an·additional·layer·of 
79 security·is·gained·by·extending·the·policy·of·not·logging·directly·on·as·root. 
80 In·addition,·logging·in·with·a·user-specific·account·provides·individual 
81 accountability·of·actions·performed·on·the·system·and·also·helps·to·minimize 
82 direct·attack·attempts·on·root's·password. 
83 ······</td> 
84 ····</tr> 
85 ····<tr> 
86 ······<td>3.1.1<br/>3.4.5</td> 
87 ······<td>Require·Authentication·for·Emergency·Systemd·Target</td> 
88 ······<td·xml:lang="en-US"> 
89 ········Emergency·mode·is·intended·as·a·system·recovery 
90 method,·providing·a·single·user·root·access·to·the·system 
91 during·a·failed·boot·sequence. 
92 <br·/><br·/> 
93 By·default,·Emergency·mode·is·protected·by·requiring·a·password·and·is·set 
94 in·<tt>/usr/lib/systemd/system/emergency.service</tt>. 
95 ······</td> 
96 ······<td·xml:lang="en-US"> 
97 ········This·prevents·attackers·with·physical·access·from·trivially·bypassing·security 
98 on·the·machine·and·gaining·root·access.·Such·accesses·are·further·prevented 
99 by·configuring·the·bootloader·password. 
100 ······</td> 
101 ····</tr> 
102 ····<tr> 
103 ······<td>3.1.1</td> 
104 ······<td>Disable·GDM·Automatic·Login</td> 
105 ······<td·xml:lang="en-US"> 
106 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·automatically·login·without 
107 user·interaction·or·credentials.·User·should·always·be·required·to·authenticate·themselves 
108 to·the·system·that·they·are·authorized·to·use.·To·disable·user·ability·to·automatically 
109 login·to·the·system,·set·the·<tt>AutomaticLoginEnable</tt>·to·<tt>false</tt>·in·the 
110 <tt>[daemon]</tt>·section·in·<tt>/etc/gdm/custom.conf</tt>.·For·example: 
111 <pre>[daemon] 
112 AutomaticLoginEnable=false</pre> 
113 ······</td> 
114 ······<td·xml:lang="en-US"> 
115 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating 
116 system·security. 
117 ······</td> 
118 ····</tr> 
119 ····<tr> 
120 ······<td>3.1.1</td>47 ······<td>3.1.1</td>
121 ······<td>Disable·GDM·Guest·Login</td>48 ······<td>Disable·GDM·Guest·Login</td>
122 ······<td·xml:lang="en-US">49 ······<td·xml:lang="en-US">
123 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·login·without·credentials50 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·login·without·credentials
124 which·can·be·useful·for·public·kiosk·scenarios.·Allowing·users·to·login·without·credentials51 which·can·be·useful·for·public·kiosk·scenarios.·Allowing·users·to·login·without·credentials
125 or·"guest"·account·access·has·inherent·security·risks·and·should·be·disabled.·To·do·disable52 or·"guest"·account·access·has·inherent·security·risks·and·should·be·disabled.·To·do·disable
126 timed·logins·or·guest·account·access,·set·the·<tt>TimedLoginEnable</tt>·to·<tt>false</tt>·in53 timed·logins·or·guest·account·access,·set·the·<tt>TimedLoginEnable</tt>·to·<tt>false</tt>·in
Offset 153, 14 lines modifiedOffset 77, 57 lines modified
153 ······<td·xml:lang="en-US">77 ······<td·xml:lang="en-US">
154 ········If·an·account·has·an·empty·password,·anyone·could·log·in·and78 ········If·an·account·has·an·empty·password,·anyone·could·log·in·and
155 run·commands·with·the·privileges·of·that·account.·Accounts·with79 run·commands·with·the·privileges·of·that·account.·Accounts·with
156 empty·passwords·should·never·be·used·in·operational·environments.80 empty·passwords·should·never·be·used·in·operational·environments.
157 ······</td>81 ······</td>
158 ····</tr>82 ····</tr>
159 ····<tr>83 ····<tr>
 84 ······<td>3.1.1<br/>3.1.6</td>
 85 ······<td>Direct·root·Logins·Not·Allowed</td>
 86 ······<td·xml:lang="en-US">
 87 ········To·further·limit·access·to·the·<tt>root</tt>·account,·administrators
 88 can·disable·root·logins·at·the·console·by·editing·the·<tt>/etc/securetty</tt>·file.
 89 This·file·lists·all·devices·the·root·user·is·allowed·to·login·to.·If·the·file·does
 90 not·exist·at·all,·the·root·user·can·login·through·any·communication·device·on·the
 91 system,·whether·via·the·console·or·via·a·raw·network·interface.·This·is·dangerous
 92 as·user·can·login·to·the·system·as·root·via·Telnet,·which·sends·the·password·in
 93 plain·text·over·the·network.·By·default,·Oracle·Linux·7's
 94 <tt>/etc/securetty</tt>·file·only·allows·the·root·user·to·login·at·the·console
 95 physically·attached·to·the·system.·To·prevent·root·from·logging·in,·remove·the
 96 contents·of·this·file.·To·prevent·direct·root·logins,·remove·the·contents·of·this
 97 file·by·typing·the·following·command:
 98 <pre>
 99 $·sudo·echo·&gt;·/etc/securetty
 100 </pre>
 101 ······</td>
 102 ······<td·xml:lang="en-US">
 103 ········Disabling·direct·root·logins·ensures·proper·accountability·and·multifactor
 104 authentication·to·privileged·accounts.·Users·will·first·login,·then·escalate
 105 to·privileged·(root)·access·via·su·/·sudo.·This·is·required·for·FISMA·Low
 106 and·FISMA·Moderate·systems.
 107 ······</td>
 108 ····</tr>
 109 ····<tr>
 110 ······<td>3.1.1<br/>3.1.5</td>
 111 ······<td>Restrict·Virtual·Console·Root·Logins</td>
 112 ······<td·xml:lang="en-US">
Max diff block lines reached; 457387/463330 bytes (98.72%) of diff not shown.
805 KB
html2text {}
    
Offset 1, 73 lines modifiedOffset 1, 13 lines modified
  
  
1 Rules·with·NIST-800-171·Reference·in·Guide·to·the·Secure·Configuration·of1 Rules·with·NIST-800-171·Reference·in·Guide·to·the·Secure·Configuration·of
2 Oracle·Linux·72 Oracle·Linux·7
  
  
3 ······························································································An·account·has·root 
4 ······························································································authority·if·it·has 
5 ······························································································a·UID·of·0.·Multiple 
6 ······························································································accounts·with·a·UID 
7 ·······································If·any·account·other·than·root·has·a·UID·of·0,·this····of·0·afford·more 
8 ·······································misconfiguration·should·be·investigated·and·the········opportunity·for 
9 ·······································accounts·other·than·root·should·be·removed·or·have·····potential·intruders 
10 ·······································their·UID·changed.·····································to·guess·a·password 
11 3.1.1···Verify·Only·Root·Has·UID·0·····If·the·account·is·associated·with·system·commands·or···for·a·privileged 
12 3.1.5··································applications·the·UID·should·be·changed·to·one·greater··account.·Proper 
13 ·······································than·"0"·but·less·than·"1000."·Otherwise·assign·a·UID··configuration·of 
14 ·······································greater·than·"1000"·that·has·not·already·been··········sudo·is·recommended 
15 ·······································assigned.··············································to·afford·multiple 
16 ······························································································system 
17 ······························································································administrators 
18 ······························································································access·to·root 
19 ······························································································privileges·in·an 
20 ······························································································accountable·manner. 
21 ······························································································Even·though·the 
22 ······························································································communications 
23 ······························································································channel·may·be 
24 ······························································································encrypted,·an 
25 ······························································································additional·layer·of 
26 ······························································································security·is·gained 
27 ······························································································by·extending·the 
28 ······························································································policy·of·not 
29 ·······································The·root·user·should·never·be·allowed·to·login·to·a····logging·directly·on 
30 3.1.1··································system·directly·over·a·network.·To·disable·root·login··as·root.·In 
31 3.1.5···Disable·SSH·Root·Login·········via·SSH,·add·or·correct·the·following·line·in·/etc/····addition,·logging·in 
32 ·······································ssh/sshd_config:·······································with·a·user-specific 
33 ·······································PermitRootLogin·no·····································account·provides 
34 ······························································································individual 
35 ······························································································accountability·of 
36 ······························································································actions·performed·on 
37 ······························································································the·system·and·also 
38 ······························································································helps·to·minimize 
39 ······························································································direct·attack 
40 ······························································································attempts·on·root's 
41 ······························································································password. 
42 ······························································································This·prevents 
43 ······························································································attackers·with 
44 ·······································Emergency·mode·is·intended·as·a·system·recovery········physical·access·from 
45 ·······································method,·providing·a·single·user·root·access·to·the·····trivially·bypassing 
46 3.1.1···Require·Authentication·for·····system·during·a·failed·boot·sequence.··················security·on·the 
47 3.4.5···Emergency·Systemd·Target······························································machine·and·gaining 
48 ·······································By·default,·Emergency·mode·is·protected·by·requiring·a·root·access.·Such 
49 ·······································password·and·is·set·in·/usr/lib/systemd/system/········accesses·are·further 
50 ·······································emergency.service.·····································prevented·by 
51 ······························································································configuring·the 
52 ······························································································bootloader·password. 
53 ·······································The·GNOME·Display·Manager·(GDM)·can·allow·users·to 
54 ·······································automatically·login·without·user·interaction·or 
55 ·······································credentials.·User·should·always·be·required·to·········Failure·to·restrict 
56 ·······································authenticate·themselves·to·the·system·that·they·are····system·access·to 
57 3.1.1···Disable·GDM·Automatic·Login····authorized·to·use.·To·disable·user·ability·to··········authenticated·users 
58 ·······································automatically·login·to·the·system,·set·the·············negatively·impacts 
59 ·······································AutomaticLoginEnable·to·false·in·the·[daemon]·section··operating·system 
60 ·······································in·/etc/gdm/custom.conf.·For·example:··················security. 
61 ·······································[daemon] 
62 ·······································AutomaticLoginEnable=false 
63 ·······································The·GNOME·Display·Manager·(GDM)·can·allow·users·to3 ·······································The·GNOME·Display·Manager·(GDM)·can·allow·users·to
64 ·······································login·without·credentials·which·can·be·useful·for4 ·······································login·without·credentials·which·can·be·useful·for
65 ·······································public·kiosk·scenarios.·Allowing·users·to·login········Failure·to·restrict5 ·······································public·kiosk·scenarios.·Allowing·users·to·login········Failure·to·restrict
66 ·······································without·credentials·or·"guest"·account·access·has······system·access·to6 ·······································without·credentials·or·"guest"·account·access·has······system·access·to
67 3.1.1···Disable·GDM·Guest·Login········inherent·security·risks·and·should·be·disabled.·To·do··authenticated·users7 3.1.1···Disable·GDM·Guest·Login········inherent·security·risks·and·should·be·disabled.·To·do··authenticated·users
68 ·······································disable·timed·logins·or·guest·account·access,·set·the··negatively·impacts8 ·······································disable·timed·logins·or·guest·account·access,·set·the··negatively·impacts
69 ·······································TimedLoginEnable·to·false·in·the·[daemon]·section·in·/·operating·system9 ·······································TimedLoginEnable·to·false·in·the·[daemon]·section·in·/·operating·system
Offset 81, 162 lines modifiedOffset 21, 144 lines modified
81 3.1.1···Prevent·Login·to·Accounts·With·it·may·be·possible·to·log·into·the·account·without·····with·the·privileges21 3.1.1···Prevent·Login·to·Accounts·With·it·may·be·possible·to·log·into·the·account·without·····with·the·privileges
82 3.1.5···Empty·Password·················authentication.·Remove·any·instances·of·the·nullok·in··of·that·account.22 3.1.5···Empty·Password·················authentication.·Remove·any·instances·of·the·nullok·in··of·that·account.
83 ·······································/etc/pam.d/system-auth·and·/etc/pam.d/password-auth·to·Accounts·with·empty23 ·······································/etc/pam.d/system-auth·and·/etc/pam.d/password-auth·to·Accounts·with·empty
84 ·······································prevent·logins·with·empty·passwords.···················passwords·should24 ·······································prevent·logins·with·empty·passwords.···················passwords·should
85 ······························································································never·be·used·in25 ······························································································never·be·used·in
86 ······························································································operational26 ······························································································operational
87 ······························································································environments.27 ······························································································environments.
 28 ·······································To·further·limit·access·to·the·root·account,
 29 ·······································administrators·can·disable·root·logins·at·the·console··Disabling·direct
 30 ·······································by·editing·the·/etc/securetty·file.·This·file·lists····root·logins·ensures
 31 ·······································all·devices·the·root·user·is·allowed·to·login·to.·If···proper
 32 ·······································the·file·does·not·exist·at·all,·the·root·user·can······accountability·and
 33 ·······································login·through·any·communication·device·on·the·system,··multifactor
 34 ·······································whether·via·the·console·or·via·a·raw·network···········authentication·to
 35 3.1.1··································interface.·This·is·dangerous·as·user·can·login·to·the··privileged·accounts.
 36 3.1.6···Direct·root·Logins·Not·Allowed·system·as·root·via·Telnet,·which·sends·the·password·in·Users·will·first
 37 ·······································plain·text·over·the·network.·By·default,·Oracle·Linux··login,·then·escalate
 38 ·······································7's·/etc/securetty·file·only·allows·the·root·user·to···to·privileged·(root)
 39 ·······································login·at·the·console·physically·attached·to·the········access·via·su·/
 40 ·······································system.·To·prevent·root·from·logging·in,·remove·the····sudo.·This·is
 41 ·······································contents·of·this·file.·To·prevent·direct·root·logins,··required·for·FISMA
 42 ·······································remove·the·contents·of·this·file·by·typing·the·········Low·and·FISMA
 43 ·······································following·command:·····································Moderate·systems.
 44 ·······································$·sudo·echo·>·/etc/securetty
 45 ·······································To·restrict·root·logins·through·the·(deprecated)·······Preventing·direct
 46 ·······································virtual·console·devices,·ensure·lines·of·this·form·do··root·login·to
 47 ·······································not·appear·in·/etc/securetty:··························virtual·console
 48 3.1.1···Restrict·Virtual·Console·Root··vc/1···················································devices·helps·ensure
 49 3.1.5···Logins·························vc/2···················································accountability·for
 50 ·······································vc/3···················································actions·taken·on·the
 51 ·······································vc/4···················································system·using·the
 52 ······························································································root·account.
88 ·······································Disallow·SSH·login·with·empty·passwords.·The·default53 ·······································Disallow·SSH·login·with·empty·passwords.·The·default
89 ·······································SSH·configuration·disables·logins·with·empty···········Configuring·this54 ·······································SSH·configuration·disables·logins·with·empty···········Configuring·this
90 ·······································passwords.·The·appropriate·configuration·is·used·if·no·setting·for·the·SSH55 ·······································passwords.·The·appropriate·configuration·is·used·if·no·setting·for·the·SSH
91 ·······································value·is·set·for·PermitEmptyPasswords.·················daemon·provides56 ·······································value·is·set·for·PermitEmptyPasswords.·················daemon·provides
92 ·······································To·explicitly·disallow·SSH·login·from·accounts·with····additional·assurance57 ·······································To·explicitly·disallow·SSH·login·from·accounts·with····additional·assurance
93 3.1.1···Disable·SSH·Access·via·Empty···empty·passwords,·add·or·correct·the·following·line·in··that·remote·login58 3.1.1···Disable·SSH·Access·via·Empty···empty·passwords,·add·or·correct·the·following·line·in··that·remote·login
94 3.1.5···Passwords······················/etc/ssh/sshd_config:··································via·SSH·will·require59 3.1.5···Passwords······················/etc/ssh/sshd_config:··································via·SSH·will·require
95 ·······································PermitEmptyPasswords·no································a·password,·even·in60 ·······································PermitEmptyPasswords·no································a·password,·even·in
96 ·······································Any·accounts·with·empty·passwords·should·be·disabled···the·event·of61 ·······································Any·accounts·with·empty·passwords·should·be·disabled···the·event·of
97 ·······································immediately,·and·PAM·configuration·should·prevent······misconfiguration62 ·······································immediately,·and·PAM·configuration·should·prevent······misconfiguration
98 ·······································users·from·being·able·to·assign·themselves·empty·······elsewhere.63 ·······································users·from·being·able·to·assign·themselves·empty·······elsewhere.
99 ·······································passwords.64 ·······································passwords.
100 ·······································To·restrict·root·logins·through·the·(deprecated)·······Preventing·direct 
101 ·······································virtual·console·devices,·ensure·lines·of·this·form·do··root·login·to 
102 ·······································not·appear·in·/etc/securetty:··························virtual·console 
103 3.1.1···Restrict·Virtual·Console·Root··vc/1···················································devices·helps·ensure 
104 3.1.5···Logins·························vc/2···················································accountability·for65 ·······································The·GNOME·Display·Manager·(GDM)·can·allow·users·to
 66 ·······································automatically·login·without·user·interaction·or
 67 ·······································credentials.·User·should·always·be·required·to·········Failure·to·restrict
 68 ·······································authenticate·themselves·to·the·system·that·they·are····system·access·to
 69 3.1.1···Disable·GDM·Automatic·Login····authorized·to·use.·To·disable·user·ability·to··········authenticated·users
Max diff block lines reached; 808148/824725 bytes (97.99%) of diff not shown.
9.66 KB
./usr/share/doc/ssg-nondebian/table-ol7-nistrefs-stig.html
    
Offset 7705, 18 lines modifiedOffset 7705, 18 lines modified
0001e180:·776f·7264·7320·6865·6c70·7320·656e·7375··words·helps·ensu0001e180:·776f·7264·7320·6865·6c70·7320·656e·7375··words·helps·ensu
0001e190:·7265·2074·6861·7420·6120·636f·6d70·726f··re·that·a·compro0001e190:·7265·2074·6861·7420·6120·636f·6d70·726f··re·that·a·compro
0001e1a0:·6d69·7365·6420·7061·7373·776f·7264·2069··mised·password·i0001e1a0:·6d69·7365·6420·7061·7373·776f·7264·2069··mised·password·i
0001e1b0:·7320·6e6f·740a·7265·2d75·7365·6420·6279··s·not.re-used·by0001e1b0:·7320·6e6f·740a·7265·2d75·7365·6420·6279··s·not.re-used·by
0001e1c0:·2061·2075·7365·722e·0a20·203c·2f74·643e···a·user..··</td>0001e1c0:·2061·2075·7365·722e·0a20·203c·2f74·643e···a·user..··</td>
0001e1d0:·0a20·203c·7464·3e76·6172·5f70·6173·7377··.··<td>var_passw0001e1d0:·0a20·203c·7464·3e76·6172·5f70·6173·7377··.··<td>var_passw
0001e1e0:·6f72·645f·7061·6d5f·7265·6d65·6d62·6572··ord_pam_remember0001e1e0:·6f72·645f·7061·6d5f·7265·6d65·6d62·6572··ord_pam_remember
0001e1f0:·3d35·3c62·722f·3e76·6172·5f70·6173·7377··=5<br/>var_passw 
0001e200:·6f72·645f·7061·6d5f·7265·6d65·6d62·6572··ord_pam_remember 
0001e210:·5f63·6f6e·7472·6f6c·5f66·6c61·673d·7265··_control_flag=re0001e1f0:·5f63·6f6e·7472·6f6c·5f66·6c61·673d·7265··_control_flag=re
 0001e200:·7175·6972·6564·3c62·722f·3e76·6172·5f70··quired<br/>var_p
 0001e210:·6173·7377·6f72·645f·7061·6d5f·7265·6d65··assword_pam_reme
0001e220:·7175·6972·6564·3c2f·7464·3e0a·3c2f·7472··quired</td>.</tr0001e220:·6d62·6572·3d35·3c2f·7464·3e0a·3c2f·7472··mber=5</td>.</tr
0001e230:·3e0a·3c74·723e·0a20·203c·7464·3e49·412d··>.<tr>.··<td>IA-0001e230:·3e0a·3c74·723e·0a20·203c·7464·3e49·412d··>.<tr>.··<td>IA-
0001e240:·3528·6629·3c62·722f·3e49·412d·3528·3129··5(f)<br/>IA-5(1)0001e240:·3528·6629·3c62·722f·3e49·412d·3528·3129··5(f)<br/>IA-5(1)
0001e250:·2865·293c·2f74·643e·0a20·203c·7464·3e4e··(e)</td>.··<td>N0001e250:·2865·293c·2f74·643e·0a20·203c·7464·3e4e··(e)</td>.··<td>N
0001e260:·2f41·3c2f·7464·3e0a·2020·3c74·643e·4c69··/A</td>.··<td>Li0001e260:·2f41·3c2f·7464·3e0a·2020·3c74·643e·4c69··/A</td>.··<td>Li
0001e270:·6d69·7420·5061·7373·776f·7264·2052·6575··mit·Password·Reu0001e270:·6d69·7420·5061·7373·776f·7264·2052·6575··mit·Password·Reu
0001e280:·7365·3a20·7379·7374·656d·2d61·7574·683c··se:·system-auth<0001e280:·7365·3a20·7379·7374·656d·2d61·7574·683c··se:·system-auth<
0001e290:·2f74·643e·0a20·203c·7464·2078·6d6c·3a6c··/td>.··<td·xml:l0001e290:·2f74·643e·0a20·203c·7464·2078·6d6c·3a6c··/td>.··<td·xml:l
Offset 7754, 19 lines modifiedOffset 7754, 19 lines modified
0001e490:·6576·696f·7573·2070·6173·7377·6f72·6473··evious·passwords0001e490:·6576·696f·7573·2070·6173·7377·6f72·6473··evious·passwords
0001e4a0:·2068·656c·7073·2065·6e73·7572·6520·7468···helps·ensure·th0001e4a0:·2068·656c·7073·2065·6e73·7572·6520·7468···helps·ensure·th
0001e4b0:·6174·2061·2063·6f6d·7072·6f6d·6973·6564··at·a·compromised0001e4b0:·6174·2061·2063·6f6d·7072·6f6d·6973·6564··at·a·compromised
0001e4c0:·2070·6173·7377·6f72·6420·6973·206e·6f74···password·is·not0001e4c0:·2070·6173·7377·6f72·6420·6973·206e·6f74···password·is·not
0001e4d0:·0a72·652d·7573·6564·2062·7920·6120·7573··.re-used·by·a·us0001e4d0:·0a72·652d·7573·6564·2062·7920·6120·7573··.re-used·by·a·us
0001e4e0:·6572·2e0a·2020·3c2f·7464·3e0a·2020·3c74··er..··</td>.··<t0001e4e0:·6572·2e0a·2020·3c2f·7464·3e0a·2020·3c74··er..··</td>.··<t
0001e4f0:·643e·7661·725f·7061·7373·776f·7264·5f70··d>var_password_p0001e4f0:·643e·7661·725f·7061·7373·776f·7264·5f70··d>var_password_p
0001e500:·616d·5f72·656d·656d·6265·723d·353c·6272··am_remember=5<br 
0001e510:·2f3e·7661·725f·7061·7373·776f·7264·5f70··/>var_password_p 
0001e520:·616d·5f72·656d·656d·6265·725f·636f·6e74··am_remember_cont0001e500:·616d·5f72·656d·656d·6265·725f·636f·6e74··am_remember_cont
0001e530:·726f·6c5f·666c·6167·3d72·6571·7569·7265··rol_flag=require0001e510:·726f·6c5f·666c·6167·3d72·6571·7569·7265··rol_flag=require
 0001e520:·643c·6272·2f3e·7661·725f·7061·7373·776f··d<br/>var_passwo
 0001e530:·7264·5f70·616d·5f72·656d·656d·6265·723d··rd_pam_remember=
0001e540:·643c·2f74·643e·0a3c·2f74·723e·0a3c·7472··d</td>.</tr>.<tr0001e540:·353c·2f74·643e·0a3c·2f74·723e·0a3c·7472··5</td>.</tr>.<tr
0001e550:·3e0a·2020·3c74·643e·4941·2d35·2863·293c··>.··<td>IA-5(c)<0001e550:·3e0a·2020·3c74·643e·4941·2d35·2863·293c··>.··<td>IA-5(c)<
0001e560:·6272·2f3e·4941·2d35·2831·2928·6129·3c62··br/>IA-5(1)(a)<b0001e560:·6272·2f3e·4941·2d35·2831·2928·6129·3c62··br/>IA-5(1)(a)<b
0001e570:·722f·3e43·4d2d·3628·6129·3c62·722f·3e49··r/>CM-6(a)<br/>I0001e570:·722f·3e43·4d2d·3628·6129·3c62·722f·3e49··r/>CM-6(a)<br/>I
0001e580:·412d·3528·3429·3c2f·7464·3e0a·2020·3c74··A-5(4)</td>.··<t0001e580:·412d·3528·3429·3c2f·7464·3e0a·2020·3c74··A-5(4)</td>.··<t
0001e590:·643e·4e2f·413c·2f74·643e·0a20·203c·7464··d>N/A</td>.··<td0001e590:·643e·4e2f·413c·2f74·643e·0a20·203c·7464··d>N/A</td>.··<td
0001e5a0:·3e45·6e73·7572·6520·5041·4d20·456e·666f··>Ensure·PAM·Enfo0001e5a0:·3e45·6e73·7572·6520·5041·4d20·456e·666f··>Ensure·PAM·Enfo
0001e5b0:·7263·6573·2050·6173·7377·6f72·6420·5265··rces·Password·Re0001e5b0:·7263·6573·2050·6173·7377·6f72·6420·5265··rces·Password·Re
Offset 8613, 18 lines modifiedOffset 8613, 18 lines modified
00021a40:·6b0a·616e·6420·7573·6520·7468·6520·696e··k.and·use·the·in00021a40:·6b0a·616e·6420·7573·6520·7468·6520·696e··k.and·use·the·in
00021a50:·666f·726d·6174·696f·6e20·746f·2070·6f74··formation·to·pot00021a50:·666f·726d·6174·696f·6e20·746f·2070·6f74··formation·to·pot
00021a60:·656e·7469·616c·6c79·2063·6f6d·7072·6f6d··entially·comprom00021a60:·656e·7469·616c·6c79·2063·6f6d·7072·6f6d··entially·comprom
00021a70:·6973·6520·7468·6520·696e·7465·6772·6974··ise·the·integrit00021a70:·6973·6520·7468·6520·696e·7465·6772·6974··ise·the·integrit
00021a80:·7920·6f66·2074·6865·2073·7973·7465·6d20··y·of·the·system·00021a80:·7920·6f66·2074·6865·2073·7973·7465·6d20··y·of·the·system·
00021a90:·616e·640a·6e65·7477·6f72·6b28·7329·2e0a··and.network(s)..00021a90:·616e·640a·6e65·7477·6f72·6b28·7329·2e0a··and.network(s)..
00021aa0:·2020·3c2f·7464·3e0a·2020·3c74·643e·7661····</td>.··<td>va00021aa0:·2020·3c2f·7464·3e0a·2020·3c74·643e·7661····</td>.··<td>va
00021ab0:·725f·736e·6d70·645f·7277·5f73·7472·696e··r_snmpd_rw_strin00021ab0:·725f·736e·6d70·645f·726f·5f73·7472·696e··r_snmpd_ro_strin
00021ac0:·673d·6368·616e·6765·6d65·7277·3c62·722f··g=changemerw<br/00021ac0:·673d·6368·616e·6765·6d65·726f·3c62·722f··g=changemero<br/
00021ad0:·3e76·6172·5f73·6e6d·7064·5f72·6f5f·7374··>var_snmpd_ro_st00021ad0:·3e76·6172·5f73·6e6d·7064·5f72·775f·7374··>var_snmpd_rw_st
00021ae0:·7269·6e67·3d63·6861·6e67·656d·6572·6f3c··ring=changemero<00021ae0:·7269·6e67·3d63·6861·6e67·656d·6572·773c··ring=changemerw<
00021af0:·2f74·643e·0a3c·2f74·723e·0a3c·7472·3e0a··/td>.</tr>.<tr>.00021af0:·2f74·643e·0a3c·2f74·723e·0a3c·7472·3e0a··/td>.</tr>.<tr>.
00021b00:·2020·3c74·643e·5343·2d35·3c2f·7464·3e0a····<td>SC-5</td>.00021b00:·2020·3c74·643e·5343·2d35·3c2f·7464·3e0a····<td>SC-5</td>.
00021b10:·2020·3c74·643e·4e2f·413c·2f74·643e·0a20····<td>N/A</td>.·00021b10:·2020·3c74·643e·4e2f·413c·2f74·643e·0a20····<td>N/A</td>.·
00021b20:·203c·7464·3e43·6f6e·6669·6775·7265·204b···<td>Configure·K00021b20:·203c·7464·3e43·6f6e·6669·6775·7265·204b···<td>Configure·K
00021b30:·6572·6e65·6c20·746f·2052·6174·6520·4c69··ernel·to·Rate·Li00021b30:·6572·6e65·6c20·746f·2052·6174·6520·4c69··ernel·to·Rate·Li
00021b40:·6d69·7420·5365·6e64·696e·6720·6f66·2044··mit·Sending·of·D00021b40:·6d69·7420·5365·6e64·696e·6720·6f66·2044··mit·Sending·of·D
00021b50:·7570·6c69·6361·7465·2054·4350·2041·636b··uplicate·TCP·Ack00021b50:·7570·6c69·6361·7465·2054·4350·2041·636b··uplicate·TCP·Ack
4.89 KB
html2text {}
    
Offset 2580, 28 lines modifiedOffset 2580, 28 lines modified
2580 ··············································································ensuring·a·larger2580 ··············································································ensuring·a·larger
2581 ··············································································search·space.2581 ··············································································search·space.
2582 ··································Do·not·allow·users·to·reuse·recent2582 ··································Do·not·allow·users·to·reuse·recent
2583 ··································passwords.·This·can·be·accomplished·by2583 ··································passwords.·This·can·be·accomplished·by
2584 ··································using·the·remember·option·for·the···········Preventing·re-use2584 ··································using·the·remember·option·for·the···········Preventing·re-use
2585 ··································pam_pwhistory·PAM·module.···················of·previous2585 ··································pam_pwhistory·PAM·module.···················of·previous
2586 IA-5(f)·······································································passwords·helps2586 IA-5(f)·······································································passwords·helps
2587 IA-5(1)·N/·Limit·Password·Reuse:··In·the·file·/etc/pam.d/password-auth,·make··ensure·that·a·······var_password_pam_remember=52587 IA-5(1)·N/·Limit·Password·Reuse:··In·the·file·/etc/pam.d/password-auth,·make··ensure·that·a·······var_password_pam_remember_control_flag=required
2588 (e)·····A··password-auth··········sure·the·parameter·remember·is·present·and··compromised·········var_password_pam_remember_control_flag=required2588 (e)·····A··password-auth··········sure·the·parameter·remember·is·present·and··compromised·········var_password_pam_remember=5
2589 ··································it·has·a·value·equal·to·or·greater·than·5···password·is·not·re-2589 ··································it·has·a·value·equal·to·or·greater·than·5···password·is·not·re-
2590 ··············································································used·by·a·user.2590 ··············································································used·by·a·user.
2591 ··································For·example:2591 ··································For·example:
2592 ··································password·required·pam_pwhistory.so2592 ··································password·required·pam_pwhistory.so
2593 ··································use_authtok·remember=52593 ··································use_authtok·remember=5
2594 ··································Do·not·allow·users·to·reuse·recent2594 ··································Do·not·allow·users·to·reuse·recent
2595 ··································passwords.·This·can·be·accomplished·by2595 ··································passwords.·This·can·be·accomplished·by
2596 ··································using·the·remember·option·for·the···········Preventing·re-use2596 ··································using·the·remember·option·for·the···········Preventing·re-use
2597 ··································pam_pwhistory·PAM·module.···················of·previous2597 ··································pam_pwhistory·PAM·module.···················of·previous
2598 IA-5(f)·······································································passwords·helps2598 IA-5(f)·······································································passwords·helps
2599 IA-5(1)·N/·Limit·Password·Reuse:··In·the·file·/etc/pam.d/system-auth,·make····ensure·that·a·······var_password_pam_remember=52599 IA-5(1)·N/·Limit·Password·Reuse:··In·the·file·/etc/pam.d/system-auth,·make····ensure·that·a·······var_password_pam_remember_control_flag=required
2600 (e)·····A··system-auth············sure·the·parameter·remember·is·present·and··compromised·········var_password_pam_remember_control_flag=required2600 (e)·····A··system-auth············sure·the·parameter·remember·is·present·and··compromised·········var_password_pam_remember=5
2601 ··································it·has·a·value·equal·to·or·greater·than·5···password·is·not·re-2601 ··································it·has·a·value·equal·to·or·greater·than·5···password·is·not·re-
2602 ··············································································used·by·a·user.2602 ··············································································used·by·a·user.
2603 ··································For·example:2603 ··································For·example:
2604 ··································password·required·pam_pwhistory.so2604 ··································password·required·pam_pwhistory.so
2605 ··································use_authtok·remember=52605 ··································use_authtok·remember=5
2606 ··············································································Use·of·a·complex2606 ··············································································Use·of·a·complex
2607 ··············································································password·helps·to2607 ··············································································password·helps·to
Offset 2913, 16 lines modifiedOffset 2913, 16 lines modified
2913 ··············································································network·management2913 ··············································································network·management
2914 ··············································································protocol·(SNMP)2914 ··············································································protocol·(SNMP)
2915 ··············································································community·strings2915 ··············································································community·strings
2916 ··············································································must·be·changed·to2916 ··············································································must·be·changed·to
2917 ··································Edit·/etc/snmp/snmpd.conf,·remove·or·change·maintain·security.2917 ··································Edit·/etc/snmp/snmpd.conf,·remove·or·change·maintain·security.
2918 ··································the·default·community·strings·of·public·and·If·the·service·is2918 ··································the·default·community·strings·of·public·and·If·the·service·is
2919 ··································private.·This·profile·configures·new·read-··running·with·the2919 ··································private.·This·profile·configures·new·read-··running·with·the
2920 ········N/·Ensure·Default·SNMP····only·community·string·to·changemero·and·····default·············var_snmpd_rw_string=changemerw2920 ········N/·Ensure·Default·SNMP····only·community·string·to·changemero·and·····default·············var_snmpd_ro_string=changemero
2921 IA-5(e)·A··Password·Is·Not·Used···read-write·community·string·to·changemerw.··authenticators,·····var_snmpd_ro_string=changemero2921 IA-5(e)·A··Password·Is·Not·Used···read-write·community·string·to·changemerw.··authenticators,·····var_snmpd_rw_string=changemerw
2922 ··································Once·the·default·community·strings·have·····then·anyone·can2922 ··································Once·the·default·community·strings·have·····then·anyone·can
2923 ··································been·changed,·restart·the·SNMP·service:·····gather·data·about2923 ··································been·changed,·restart·the·SNMP·service:·····gather·data·about
2924 ··································$·sudo·service·snmpd·restart················the·system·and·the2924 ··································$·sudo·service·snmpd·restart················the·system·and·the
2925 ··············································································network·and·use·the2925 ··············································································network·and·use·the
2926 ··············································································information·to2926 ··············································································information·to
2927 ··············································································potentially2927 ··············································································potentially
2928 ··············································································compromise·the2928 ··············································································compromise·the
9.74 KB
./usr/share/doc/ssg-nondebian/table-ol7-nistrefs-stig_gui.html
    
Offset 7706, 18 lines modifiedOffset 7706, 18 lines modified
0001e190:·7373·776f·7264·7320·6865·6c70·7320·656e··sswords·helps·en0001e190:·7373·776f·7264·7320·6865·6c70·7320·656e··sswords·helps·en
0001e1a0:·7375·7265·2074·6861·7420·6120·636f·6d70··sure·that·a·comp0001e1a0:·7375·7265·2074·6861·7420·6120·636f·6d70··sure·that·a·comp
0001e1b0:·726f·6d69·7365·6420·7061·7373·776f·7264··romised·password0001e1b0:·726f·6d69·7365·6420·7061·7373·776f·7264··romised·password
0001e1c0:·2069·7320·6e6f·740a·7265·2d75·7365·6420···is·not.re-used·0001e1c0:·2069·7320·6e6f·740a·7265·2d75·7365·6420···is·not.re-used·
0001e1d0:·6279·2061·2075·7365·722e·0a20·203c·2f74··by·a·user..··</t0001e1d0:·6279·2061·2075·7365·722e·0a20·203c·2f74··by·a·user..··</t
0001e1e0:·643e·0a20·203c·7464·3e76·6172·5f70·6173··d>.··<td>var_pas0001e1e0:·643e·0a20·203c·7464·3e76·6172·5f70·6173··d>.··<td>var_pas
0001e1f0:·7377·6f72·645f·7061·6d5f·7265·6d65·6d62··sword_pam_rememb0001e1f0:·7377·6f72·645f·7061·6d5f·7265·6d65·6d62··sword_pam_rememb
 0001e200:·6572·3d35·3c62·722f·3e76·6172·5f70·6173··er=5<br/>var_pas
 0001e210:·7377·6f72·645f·7061·6d5f·7265·6d65·6d62··sword_pam_rememb
0001e200:·6572·5f63·6f6e·7472·6f6c·5f66·6c61·673d··er_control_flag=0001e220:·6572·5f63·6f6e·7472·6f6c·5f66·6c61·673d··er_control_flag=
0001e210:·7265·7175·6972·6564·3c62·722f·3e76·6172··required<br/>var0001e230:·7265·7175·6972·6564·3c2f·7464·3e0a·3c2f··required</td>.</
0001e220:·5f70·6173·7377·6f72·645f·7061·6d5f·7265··_password_pam_re 
0001e230:·6d65·6d62·6572·3d35·3c2f·7464·3e0a·3c2f··member=5</td>.</ 
0001e240:·7472·3e0a·3c74·723e·0a20·203c·7464·3e49··tr>.<tr>.··<td>I0001e240:·7472·3e0a·3c74·723e·0a20·203c·7464·3e49··tr>.<tr>.··<td>I
0001e250:·412d·3528·6629·3c62·722f·3e49·412d·3528··A-5(f)<br/>IA-5(0001e250:·412d·3528·6629·3c62·722f·3e49·412d·3528··A-5(f)<br/>IA-5(
0001e260:·3129·2865·293c·2f74·643e·0a20·203c·7464··1)(e)</td>.··<td0001e260:·3129·2865·293c·2f74·643e·0a20·203c·7464··1)(e)</td>.··<td
0001e270:·3e4e·2f41·3c2f·7464·3e0a·2020·3c74·643e··>N/A</td>.··<td>0001e270:·3e4e·2f41·3c2f·7464·3e0a·2020·3c74·643e··>N/A</td>.··<td>
0001e280:·4c69·6d69·7420·5061·7373·776f·7264·2052··Limit·Password·R0001e280:·4c69·6d69·7420·5061·7373·776f·7264·2052··Limit·Password·R
0001e290:·6575·7365·3a20·7379·7374·656d·2d61·7574··euse:·system-aut0001e290:·6575·7365·3a20·7379·7374·656d·2d61·7574··euse:·system-aut
0001e2a0:·683c·2f74·643e·0a20·203c·7464·2078·6d6c··h</td>.··<td·xml0001e2a0:·683c·2f74·643e·0a20·203c·7464·2078·6d6c··h</td>.··<td·xml
Offset 7755, 19 lines modifiedOffset 7755, 19 lines modified
0001e4a0:·7072·6576·696f·7573·2070·6173·7377·6f72··previous·passwor0001e4a0:·7072·6576·696f·7573·2070·6173·7377·6f72··previous·passwor
0001e4b0:·6473·2068·656c·7073·2065·6e73·7572·6520··ds·helps·ensure·0001e4b0:·6473·2068·656c·7073·2065·6e73·7572·6520··ds·helps·ensure·
0001e4c0:·7468·6174·2061·2063·6f6d·7072·6f6d·6973··that·a·compromis0001e4c0:·7468·6174·2061·2063·6f6d·7072·6f6d·6973··that·a·compromis
0001e4d0:·6564·2070·6173·7377·6f72·6420·6973·206e··ed·password·is·n0001e4d0:·6564·2070·6173·7377·6f72·6420·6973·206e··ed·password·is·n
0001e4e0:·6f74·0a72·652d·7573·6564·2062·7920·6120··ot.re-used·by·a·0001e4e0:·6f74·0a72·652d·7573·6564·2062·7920·6120··ot.re-used·by·a·
0001e4f0:·7573·6572·2e0a·2020·3c2f·7464·3e0a·2020··user..··</td>.··0001e4f0:·7573·6572·2e0a·2020·3c2f·7464·3e0a·2020··user..··</td>.··
0001e500:·3c74·643e·7661·725f·7061·7373·776f·7264··<td>var_password0001e500:·3c74·643e·7661·725f·7061·7373·776f·7264··<td>var_password
 0001e510:·5f70·616d·5f72·656d·656d·6265·723d·353c··_pam_remember=5<
 0001e520:·6272·2f3e·7661·725f·7061·7373·776f·7264··br/>var_password
0001e510:·5f70·616d·5f72·656d·656d·6265·725f·636f··_pam_remember_co0001e530:·5f70·616d·5f72·656d·656d·6265·725f·636f··_pam_remember_co
0001e520:·6e74·726f·6c5f·666c·6167·3d72·6571·7569··ntrol_flag=requi0001e540:·6e74·726f·6c5f·666c·6167·3d72·6571·7569··ntrol_flag=requi
0001e530:·7265·643c·6272·2f3e·7661·725f·7061·7373··red<br/>var_pass 
0001e540:·776f·7264·5f70·616d·5f72·656d·656d·6265··word_pam_remembe 
0001e550:·723d·353c·2f74·643e·0a3c·2f74·723e·0a3c··r=5</td>.</tr>.<0001e550:·7265·643c·2f74·643e·0a3c·2f74·723e·0a3c··red</td>.</tr>.<
0001e560:·7472·3e0a·2020·3c74·643e·4941·2d35·2863··tr>.··<td>IA-5(c0001e560:·7472·3e0a·2020·3c74·643e·4941·2d35·2863··tr>.··<td>IA-5(c
0001e570:·293c·6272·2f3e·4941·2d35·2831·2928·6129··)<br/>IA-5(1)(a)0001e570:·293c·6272·2f3e·4941·2d35·2831·2928·6129··)<br/>IA-5(1)(a)
0001e580:·3c62·722f·3e43·4d2d·3628·6129·3c62·722f··<br/>CM-6(a)<br/0001e580:·3c62·722f·3e43·4d2d·3628·6129·3c62·722f··<br/>CM-6(a)<br/
0001e590:·3e49·412d·3528·3429·3c2f·7464·3e0a·2020··>IA-5(4)</td>.··0001e590:·3e49·412d·3528·3429·3c2f·7464·3e0a·2020··>IA-5(4)</td>.··
0001e5a0:·3c74·643e·4e2f·413c·2f74·643e·0a20·203c··<td>N/A</td>.··<0001e5a0:·3c74·643e·4e2f·413c·2f74·643e·0a20·203c··<td>N/A</td>.··<
0001e5b0:·7464·3e45·6e73·7572·6520·5041·4d20·456e··td>Ensure·PAM·En0001e5b0:·7464·3e45·6e73·7572·6520·5041·4d20·456e··td>Ensure·PAM·En
0001e5c0:·666f·7263·6573·2050·6173·7377·6f72·6420··forces·Password·0001e5c0:·666f·7263·6573·2050·6173·7377·6f72·6420··forces·Password·
Offset 8614, 19 lines modifiedOffset 8614, 19 lines modified
00021a50:·6f72·6b0a·616e·6420·7573·6520·7468·6520··ork.and·use·the·00021a50:·6f72·6b0a·616e·6420·7573·6520·7468·6520··ork.and·use·the·
00021a60:·696e·666f·726d·6174·696f·6e20·746f·2070··information·to·p00021a60:·696e·666f·726d·6174·696f·6e20·746f·2070··information·to·p
00021a70:·6f74·656e·7469·616c·6c79·2063·6f6d·7072··otentially·compr00021a70:·6f74·656e·7469·616c·6c79·2063·6f6d·7072··otentially·compr
00021a80:·6f6d·6973·6520·7468·6520·696e·7465·6772··omise·the·integr00021a80:·6f6d·6973·6520·7468·6520·696e·7465·6772··omise·the·integr
00021a90:·6974·7920·6f66·2074·6865·2073·7973·7465··ity·of·the·syste00021a90:·6974·7920·6f66·2074·6865·2073·7973·7465··ity·of·the·syste
00021aa0:·6d20·616e·640a·6e65·7477·6f72·6b28·7329··m·and.network(s)00021aa0:·6d20·616e·640a·6e65·7477·6f72·6b28·7329··m·and.network(s)
00021ab0:·2e0a·2020·3c2f·7464·3e0a·2020·3c74·643e··..··</td>.··<td>00021ab0:·2e0a·2020·3c2f·7464·3e0a·2020·3c74·643e··..··</td>.··<td>
00021ac0:·7661·725f·736e·6d70·645f·726f·5f73·7472··var_snmpd_ro_str00021ac0:·7661·725f·736e·6d70·645f·7277·5f73·7472··var_snmpd_rw_str
00021ad0:·696e·673d·6368·616e·6765·6d65·726f·3c62··ing=changemero<b00021ad0:·696e·673d·6368·616e·6765·6d65·7277·3c62··ing=changemerw<b
00021ae0:·722f·3e76·6172·5f73·6e6d·7064·5f72·775f··r/>var_snmpd_rw_00021ae0:·722f·3e76·6172·5f73·6e6d·7064·5f72·6f5f··r/>var_snmpd_ro_
00021af0:·7374·7269·6e67·3d63·6861·6e67·656d·6572··string=changemer00021af0:·7374·7269·6e67·3d63·6861·6e67·656d·6572··string=changemer
00021b00:·773c·2f74·643e·0a3c·2f74·723e·0a3c·7472··w</td>.</tr>.<tr00021b00:·6f3c·2f74·643e·0a3c·2f74·723e·0a3c·7472··o</td>.</tr>.<tr
00021b10:·3e0a·2020·3c74·643e·5343·2d35·3c2f·7464··>.··<td>SC-5</td00021b10:·3e0a·2020·3c74·643e·5343·2d35·3c2f·7464··>.··<td>SC-5</td
00021b20:·3e0a·2020·3c74·643e·4e2f·413c·2f74·643e··>.··<td>N/A</td>00021b20:·3e0a·2020·3c74·643e·4e2f·413c·2f74·643e··>.··<td>N/A</td>
00021b30:·0a20·203c·7464·3e43·6f6e·6669·6775·7265··.··<td>Configure00021b30:·0a20·203c·7464·3e43·6f6e·6669·6775·7265··.··<td>Configure
00021b40:·204b·6572·6e65·6c20·746f·2052·6174·6520···Kernel·to·Rate·00021b40:·204b·6572·6e65·6c20·746f·2052·6174·6520···Kernel·to·Rate·
00021b50:·4c69·6d69·7420·5365·6e64·696e·6720·6f66··Limit·Sending·of00021b50:·4c69·6d69·7420·5365·6e64·696e·6720·6f66··Limit·Sending·of
00021b60:·2044·7570·6c69·6361·7465·2054·4350·2041···Duplicate·TCP·A00021b60:·2044·7570·6c69·6361·7465·2054·4350·2041···Duplicate·TCP·A
00021b70:·636b·6e6f·776c·6564·676d·656e·7473·3c2f··cknowledgments</00021b70:·636b·6e6f·776c·6564·676d·656e·7473·3c2f··cknowledgments</
4.89 KB
html2text {}
    
Offset 2580, 28 lines modifiedOffset 2580, 28 lines modified
2580 ··············································································ensuring·a·larger2580 ··············································································ensuring·a·larger
2581 ··············································································search·space.2581 ··············································································search·space.
2582 ··································Do·not·allow·users·to·reuse·recent2582 ··································Do·not·allow·users·to·reuse·recent
2583 ··································passwords.·This·can·be·accomplished·by2583 ··································passwords.·This·can·be·accomplished·by
2584 ··································using·the·remember·option·for·the···········Preventing·re-use2584 ··································using·the·remember·option·for·the···········Preventing·re-use
2585 ··································pam_pwhistory·PAM·module.···················of·previous2585 ··································pam_pwhistory·PAM·module.···················of·previous
2586 IA-5(f)·······································································passwords·helps2586 IA-5(f)·······································································passwords·helps
2587 IA-5(1)·N/·Limit·Password·Reuse:··In·the·file·/etc/pam.d/password-auth,·make··ensure·that·a·······var_password_pam_remember_control_flag=required2587 IA-5(1)·N/·Limit·Password·Reuse:··In·the·file·/etc/pam.d/password-auth,·make··ensure·that·a·······var_password_pam_remember=5
2588 (e)·····A··password-auth··········sure·the·parameter·remember·is·present·and··compromised·········var_password_pam_remember=52588 (e)·····A··password-auth··········sure·the·parameter·remember·is·present·and··compromised·········var_password_pam_remember_control_flag=required
2589 ··································it·has·a·value·equal·to·or·greater·than·5···password·is·not·re-2589 ··································it·has·a·value·equal·to·or·greater·than·5···password·is·not·re-
2590 ··············································································used·by·a·user.2590 ··············································································used·by·a·user.
2591 ··································For·example:2591 ··································For·example:
2592 ··································password·required·pam_pwhistory.so2592 ··································password·required·pam_pwhistory.so
2593 ··································use_authtok·remember=52593 ··································use_authtok·remember=5
2594 ··································Do·not·allow·users·to·reuse·recent2594 ··································Do·not·allow·users·to·reuse·recent
2595 ··································passwords.·This·can·be·accomplished·by2595 ··································passwords.·This·can·be·accomplished·by
2596 ··································using·the·remember·option·for·the···········Preventing·re-use2596 ··································using·the·remember·option·for·the···········Preventing·re-use
2597 ··································pam_pwhistory·PAM·module.···················of·previous2597 ··································pam_pwhistory·PAM·module.···················of·previous
2598 IA-5(f)·······································································passwords·helps2598 IA-5(f)·······································································passwords·helps
2599 IA-5(1)·N/·Limit·Password·Reuse:··In·the·file·/etc/pam.d/system-auth,·make····ensure·that·a·······var_password_pam_remember_control_flag=required2599 IA-5(1)·N/·Limit·Password·Reuse:··In·the·file·/etc/pam.d/system-auth,·make····ensure·that·a·······var_password_pam_remember=5
2600 (e)·····A··system-auth············sure·the·parameter·remember·is·present·and··compromised·········var_password_pam_remember=52600 (e)·····A··system-auth············sure·the·parameter·remember·is·present·and··compromised·········var_password_pam_remember_control_flag=required
2601 ··································it·has·a·value·equal·to·or·greater·than·5···password·is·not·re-2601 ··································it·has·a·value·equal·to·or·greater·than·5···password·is·not·re-
2602 ··············································································used·by·a·user.2602 ··············································································used·by·a·user.
2603 ··································For·example:2603 ··································For·example:
2604 ··································password·required·pam_pwhistory.so2604 ··································password·required·pam_pwhistory.so
2605 ··································use_authtok·remember=52605 ··································use_authtok·remember=5
2606 ··············································································Use·of·a·complex2606 ··············································································Use·of·a·complex
2607 ··············································································password·helps·to2607 ··············································································password·helps·to
Offset 2913, 16 lines modifiedOffset 2913, 16 lines modified
2913 ··············································································network·management2913 ··············································································network·management
2914 ··············································································protocol·(SNMP)2914 ··············································································protocol·(SNMP)
2915 ··············································································community·strings2915 ··············································································community·strings
2916 ··············································································must·be·changed·to2916 ··············································································must·be·changed·to
2917 ··································Edit·/etc/snmp/snmpd.conf,·remove·or·change·maintain·security.2917 ··································Edit·/etc/snmp/snmpd.conf,·remove·or·change·maintain·security.
2918 ··································the·default·community·strings·of·public·and·If·the·service·is2918 ··································the·default·community·strings·of·public·and·If·the·service·is
2919 ··································private.·This·profile·configures·new·read-··running·with·the2919 ··································private.·This·profile·configures·new·read-··running·with·the
2920 ········N/·Ensure·Default·SNMP····only·community·string·to·changemero·and·····default·············var_snmpd_ro_string=changemero2920 ········N/·Ensure·Default·SNMP····only·community·string·to·changemero·and·····default·············var_snmpd_rw_string=changemerw
2921 IA-5(e)·A··Password·Is·Not·Used···read-write·community·string·to·changemerw.··authenticators,·····var_snmpd_rw_string=changemerw2921 IA-5(e)·A··Password·Is·Not·Used···read-write·community·string·to·changemerw.··authenticators,·····var_snmpd_ro_string=changemero
2922 ··································Once·the·default·community·strings·have·····then·anyone·can2922 ··································Once·the·default·community·strings·have·····then·anyone·can
2923 ··································been·changed,·restart·the·SNMP·service:·····gather·data·about2923 ··································been·changed,·restart·the·SNMP·service:·····gather·data·about
2924 ··································$·sudo·service·snmpd·restart················the·system·and·the2924 ··································$·sudo·service·snmpd·restart················the·system·and·the
2925 ··············································································network·and·use·the2925 ··············································································network·and·use·the
2926 ··············································································information·to2926 ··············································································information·to
2927 ··············································································potentially2927 ··············································································potentially
2928 ··············································································compromise·the2928 ··············································································compromise·the
9.45 MB
./usr/share/doc/ssg-nondebian/table-ol7-nistrefs.html
    
Offset 66, 14920 lines modifiedOffset 66, 14920 lines modified
00000410:·0a20·2020·203c·7468·3e52·6174·696f·6e61··.····<th>Rationa00000410:·0a20·2020·203c·7468·3e52·6174·696f·6e61··.····<th>Rationa
00000420:·6c65·3c2f·7468·3e0a·2020·3c2f·7468·6561··le</th>.··</thea00000420:·6c65·3c2f·7468·3e0a·2020·3c2f·7468·6561··le</th>.··</thea
00000430:·643e·0a20·203c·7462·6f64·793e·0a20·203c··d>.··<tbody>.··<00000430:·643e·0a20·203c·7462·6f64·793e·0a20·203c··d>.··<tbody>.··<
00000440:·7472·3e0a·2020·2020·2020·3c74·643e·4155··tr>.······<td>AU00000440:·7472·3e0a·2020·2020·2020·3c74·643e·4155··tr>.······<td>AU
00000450:·2d32·2861·293c·2f74·643e·0a20·2020·2020··-2(a)</td>.·····00000450:·2d32·2861·293c·2f74·643e·0a20·2020·2020··-2(a)</td>.·····
00000460:·203c·7464·3e43·6f6e·6669·6775·7265·2061···<td>Configure·a00000460:·203c·7464·3e43·6f6e·6669·6775·7265·2061···<td>Configure·a
Diff chunk too large, falling back to line-by-line diff (1902 lines added, 1902 lines removed)
00000470:·7564·6974·696e·6720·6f66·2075·6e73·7563··uditing·of·unsuc00000470:·7564·6974·696e·6720·6f66·2075·6e73·7563··uditing·of·unsuc
00000480:·6365·7373·6675·6c20·6669·6c65·2061·6363··cessful·file·acc00000480:·6365·7373·6675·6c20·6669·6c65·206d·6f64··cessful·file·mod
00000490:·6573·7365·733c·2f74·643e·0a20·2020·2020··esses</td>.·····00000490:·6966·6963·6174·696f·6e73·3c2f·7464·3e0a··ifications</td>.
000004a0:·203c·7464·2078·6d6c·3a6c·616e·673d·2265···<td·xml:lang="e000004a0:·2020·2020·2020·3c74·6420·786d·6c3a·6c61········<td·xml:la
000004b0:·6e2d·5553·223e·0a20·2020·2020·2020·2045··n-US">.········E000004b0:·6e67·3d22·656e·2d55·5322·3e0a·2020·2020··ng="en-US">.····
000004c0:·6e73·7572·6520·7468·6174·2075·6e73·7563··nsure·that·unsuc000004c0:·2020·2020·456e·7375·7265·2074·6861·7420······Ensure·that·
000004d0:·6365·7373·6675·6c20·6174·7465·6d70·7473··cessful·attempts000004d0:·756e·7375·6363·6573·7366·756c·2061·7474··unsuccessful·att
000004e0:·2074·6f20·6163·6365·7373·2061·2066·696c···to·access·a·fil000004e0:·656d·7074·7320·746f·206d·6f64·6966·7920··empts·to·modify·
000004f0:·6520·6172·6520·6175·6469·7465·642e·0a0a··e·are·audited...000004f0:·6120·6669·6c65·2061·7265·2061·7564·6974··a·file·are·audit
00000500:·5468·6520·666f·6c6c·6f77·696e·6720·7275··The·following·ru00000500:·6564·2e0a·0a54·6865·2066·6f6c·6c6f·7769··ed...The·followi
00000510:·6c65·7320·636f·6e66·6967·7572·6520·6175··les·configure·au00000510:·6e67·2072·756c·6573·2063·6f6e·6669·6775··ng·rules·configu
00000520:·6469·7420·6173·2064·6573·6372·6962·6564··dit·as·described00000520:·7265·2061·7564·6974·2061·7320·6465·7363··re·audit·as·desc
00000530:·2061·626f·7665·3a0a·3c70·7265·3e23·2320···above:.<pre>##·00000530:·7269·6265·6420·6162·6f76·653a·0a3c·7072··ribed·above:.<pr
00000540:·556e·7375·6363·6573·7366·756c·2066·696c··Unsuccessful·fil00000540:·653e·2323·2055·6e73·7563·6365·7373·6675··e>##·Unsuccessfu
00000550:·6520·6163·6365·7373·2028·616e·7920·6f74··e·access·(any·ot00000550:·6c20·6669·6c65·206d·6f64·6966·6963·6174··l·file·modificat
00000560:·6865·7220·6f70·656e·7329·2054·6869·7320··her·opens)·This·00000560:·696f·6e73·2028·6f70·656e·2066·6f72·2077··ions·(open·for·w
00000570:·6861·7320·746f·2067·6f20·6c61·7374·2e0a··has·to·go·last..00000570:·7269·7465·206f·7220·7472·756e·6361·7465··rite·or·truncate
00000580:·2d61·2061·6c77·6179·732c·6578·6974·202d··-a·always,exit·-00000580:·290a·2d61·2061·6c77·6179·732c·6578·6974··).-a·always,exit
00000590:·4620·6172·6368·3d62·3332·202d·5320·6f70··F·arch=b32·-S·op00000590:·202d·4620·6172·6368·3d62·3332·202d·5320···-F·arch=b32·-S·
000005a0:·656e·2c6f·7065·6e61·742c·6f70·656e·6174··en,openat,openat000005a0:·6f70·656e·6174·2c6f·7065·6e5f·6279·5f68··openat,open_by_h
000005b0:·322c·6f70·656e·5f62·795f·6861·6e64·6c65··2,open_by_handle000005b0:·616e·646c·655f·6174·202d·4620·6132·2661··andle_at·-F·a2&a
000005c0:·5f61·7420·2d46·2065·7869·743d·2d45·4143··_at·-F·exit=-EAC000005c0:·6d70·3b30·3130·3033·202d·4620·6578·6974··mp;01003·-F·exit
000005d0:·4345·5320·2d46·2061·7569·643e·3d31·3030··CES·-F·auid>=100000005d0:·3d2d·4541·4343·4553·202d·4620·6175·6964··=-EACCES·-F·auid
000005e0:·3020·2d46·2061·7569·6421·3d75·6e73·6574··0·-F·auid!=unset000005e0:·2667·743b·3d31·3030·3020·2d46·2061·7569··&gt;=1000·-F·aui
000005f0:·202d·4620·6b65·793d·756e·7375·6363·6573···-F·key=unsucces000005f0:·6421·3d75·6e73·6574·202d·4620·6b65·793d··d!=unset·-F·key=
00000600:·7366·756c·2d61·6363·6573·730a·2d61·2061··sful-access.-a·a00000600:·756e·7375·6363·6573·7366·756c·2d6d·6f64··unsuccessful-mod
00000610:·6c77·6179·732c·6578·6974·202d·4620·6172··lways,exit·-F·ar00000610:·6966·6963·6174·696f·6e0a·2d61·2061·6c77··ification.-a·alw
00000620:·6368·3d62·3634·202d·5320·6f70·656e·2c6f··ch=b64·-S·open,o00000620:·6179·732c·6578·6974·202d·4620·6172·6368··ays,exit·-F·arch
00000630:·7065·6e61·742c·6f70·656e·6174·322c·6f70··penat,openat2,op00000630:·3d62·3634·202d·5320·6f70·656e·6174·2c6f··=b64·-S·openat,o
00000640:·656e·5f62·795f·6861·6e64·6c65·5f61·7420··en_by_handle_at·00000640:·7065·6e5f·6279·5f68·616e·646c·655f·6174··pen_by_handle_at
00000650:·2d46·2065·7869·743d·2d45·4143·4345·5320··-F·exit=-EACCES·00000650:·202d·4620·6132·2661·6d70·3b30·3130·3033···-F·a2&amp;01003
00000660:·2d46·2061·7569·643e·3d31·3030·3020·2d46··-F·auid>=1000·-F00000660:·202d·4620·6578·6974·3d2d·4541·4343·4553···-F·exit=-EACCES
00000670:·2061·7569·6421·3d75·6e73·6574·202d·4620···auid!=unset·-F·00000670:·202d·4620·6175·6964·2667·743b·3d31·3030···-F·auid&gt;=100
00000680:·6b65·793d·756e·7375·6363·6573·7366·756c··key=unsuccessful00000680:·3020·2d46·2061·7569·6421·3d75·6e73·6574··0·-F·auid!=unset
00000690:·2d61·6363·6573·730a·2d61·2061·6c77·6179··-access.-a·alway00000690:·202d·4620·6b65·793d·756e·7375·6363·6573···-F·key=unsucces
000006a0:·732c·6578·6974·202d·4620·6172·6368·3d62··s,exit·-F·arch=b000006a0:·7366·756c·2d6d·6f64·6966·6963·6174·696f··sful-modificatio
000006b0:·3332·202d·5320·6f70·656e·2c6f·7065·6e61··32·-S·open,opena000006b0:·6e0a·2d61·2061·6c77·6179·732c·6578·6974··n.-a·always,exit
000006c0:·742c·6f70·656e·6174·322c·6f70·656e·5f62··t,openat2,open_b000006c0:·202d·4620·6172·6368·3d62·3332·202d·5320···-F·arch=b32·-S·
000006d0:·795f·6861·6e64·6c65·5f61·7420·2d46·2065··y_handle_at·-F·e000006d0:·6f70·656e·202d·4620·6131·2661·6d70·3b30··open·-F·a1&amp;0
000006e0:·7869·743d·2d45·5045·524d·202d·4620·6175··xit=-EPERM·-F·au000006e0:·3130·3033·202d·4620·6578·6974·3d2d·4541··1003·-F·exit=-EA
000006f0:·6964·3e3d·3130·3030·202d·4620·6175·6964··id>=1000·-F·auid000006f0:·4343·4553·202d·4620·6175·6964·2667·743b··CCES·-F·auid&gt;
00000700:·213d·756e·7365·7420·2d46·206b·6579·3d75··!=unset·-F·key=u00000700:·3d31·3030·3020·2d46·2061·7569·6421·3d75··=1000·-F·auid!=u
00000710:·6e73·7563·6365·7373·6675·6c2d·6163·6365··nsuccessful-acce00000710:·6e73·6574·202d·4620·6b65·793d·756e·7375··nset·-F·key=unsu
00000720:·7373·0a2d·6120·616c·7761·7973·2c65·7869··ss.-a·always,exi00000720:·6363·6573·7366·756c·2d6d·6f64·6966·6963··ccessful-modific
00000730:·7420·2d46·2061·7263·683d·6236·3420·2d53··t·-F·arch=b64·-S00000730:·6174·696f·6e0a·2d61·2061·6c77·6179·732c··ation.-a·always,
00000740:·206f·7065·6e2c·6f70·656e·6174·2c6f·7065···open,openat,ope00000740:·6578·6974·202d·4620·6172·6368·3d62·3634··exit·-F·arch=b64
00000750:·6e61·7432·2c6f·7065·6e5f·6279·5f68·616e··nat2,open_by_han00000750:·202d·5320·6f70·656e·202d·4620·6131·2661···-S·open·-F·a1&a
00000760:·646c·655f·6174·202d·4620·6578·6974·3d2d··dle_at·-F·exit=-00000760:·6d70·3b30·3130·3033·202d·4620·6578·6974··mp;01003·-F·exit
00000770:·4550·4552·4d20·2d46·2061·7569·643e·3d31··EPERM·-F·auid>=100000770:·3d2d·4541·4343·4553·202d·4620·6175·6964··=-EACCES·-F·auid
00000780:·3030·3020·2d46·2061·7569·6421·3d75·6e73··000·-F·auid!=uns00000780:·2667·743b·3d31·3030·3020·2d46·2061·7569··&gt;=1000·-F·aui
00000790:·6574·202d·4620·6b65·793d·756e·7375·6363··et·-F·key=unsucc00000790:·6421·3d75·6e73·6574·202d·4620·6b65·793d··d!=unset·-F·key=
000007a0:·6573·7366·756c·2d61·6363·6573·7320·2020··essful-access···000007a0:·756e·7375·6363·6573·7366·756c·2d6d·6f64··unsuccessful-mod
000007b0:·203c·2f70·7265·3e0a·0a4c·6f61·6420·6e65···</pre>..Load·ne000007b0:·6966·6963·6174·696f·6e0a·2d61·2061·6c77··ification.-a·alw
000007c0:·7720·4175·6469·7420·7275·6c65·7320·696e··w·Audit·rules·in000007c0:·6179·732c·6578·6974·202d·4620·6172·6368··ays,exit·-F·arch
000007d0:·746f·206b·6572·6e65·6c20·6279·2072·756e··to·kernel·by·run000007d0:·3d62·3332·202d·5320·7472·756e·6361·7465··=b32·-S·truncate
000007e0:·6e69·6e67·3a0a·3c70·7265·3e61·7567·656e··ning:.<pre>augen000007e0:·2c66·7472·756e·6361·7465·202d·4620·6578··,ftruncate·-F·ex
000007f0:·7275·6c65·7320·2d2d·6c6f·6164·3c2f·7072··rules·--load</pr000007f0:·6974·3d2d·4541·4343·4553·202d·4620·6175··it=-EACCES·-F·au
00000800:·653e·0a0a·4e6f·7465·3a20·5468·6973·2072··e>..Note:·This·r00000800:·6964·2667·743b·3d31·3030·3020·2d46·2061··id&gt;=1000·-F·a
00000810:·756c·6520·7573·6573·2061·2073·7065·6369··ule·uses·a·speci00000810:·7569·6421·3d75·6e73·6574·202d·4620·6b65··uid!=unset·-F·ke
00000820:·616c·2073·6574·206f·6620·4175·6469·7420··al·set·of·Audit·00000820:·793d·756e·7375·6363·6573·7366·756c·2d6d··y=unsuccessful-m
00000830:·7275·6c65·7320·746f·2063·6f6d·706c·7920··rules·to·comply·00000830:·6f64·6966·6963·6174·696f·6e0a·2d61·2061··odification.-a·a
00000840:·7769·7468·204f·5350·5020·342e·322e·312e··with·OSPP·4.2.1.00000840:·6c77·6179·732c·6578·6974·202d·4620·6172··lways,exit·-F·ar
00000850:·2059·6f75·206d·6179·2072·6575·7365·2074···You·may·reuse·t00000850:·6368·3d62·3634·202d·5320·7472·756e·6361··ch=b64·-S·trunca
00000860:·6869·7320·7275·6c65·2069·6e20·6469·6666··his·rule·in·diff00000860:·7465·2c66·7472·756e·6361·7465·202d·4620··te,ftruncate·-F·
00000870:·6572·656e·7420·7072·6f66·696c·6573·2e20··erent·profiles.·00000870:·6578·6974·3d2d·4541·4343·4553·202d·4620··exit=-EACCES·-F·
00000880:·4966·2079·6f75·2064·6563·6964·6520·746f··If·you·decide·to00000880:·6175·6964·2667·743b·3d31·3030·3020·2d46··auid&gt;=1000·-F
00000890:·2064·6f20·736f·2c20·6974·2069·7320·7265···do·so,·it·is·re00000890:·2061·7569·6421·3d75·6e73·6574·202d·4620···auid!=unset·-F·
000008a0:·636f·6d6d·656e·6465·6420·7468·6174·2079··commended·that·y000008a0:·6b65·793d·756e·7375·6363·6573·7366·756c··key=unsuccessful
000008b0:·6f75·2069·6e73·7065·6374·2063·6f6e·7465··ou·inspect·conte000008b0:·2d6d·6f64·6966·6963·6174·696f·6e0a·2d61··-modification.-a
000008c0:·6e74·7320·6f66·2074·6865·2066·696c·6520··nts·of·the·file·000008c0:·2061·6c77·6179·732c·6578·6974·202d·4620···always,exit·-F·
000008d0:·636c·6f73·656c·7920·616e·6420·6d61·6b65··closely·and·make000008d0:·6172·6368·3d62·3332·202d·5320·6f70·656e··arch=b32·-S·open
000008e0:·2073·7572·6520·7468·6174·2074·6865·7920···sure·that·they·000008e0:·6174·2c6f·7065·6e5f·6279·5f68·616e·646c··at,open_by_handl
000008f0:·6172·6520·616c·6c69·676e·6564·2077·6974··are·alligned·wit000008f0:·655f·6174·202d·4620·6132·2661·6d70·3b30··e_at·-F·a2&amp;0
00000900:·6820·796f·7572·206e·6565·6473·2e0a·2020··h·your·needs..··00000900:·3130·3033·202d·4620·6578·6974·3d2d·4550··1003·-F·exit=-EP
00000910:·2020·2020·3c2f·7464·3e0a·2020·2020·2020······</td>.······00000910:·4552·4d20·2d46·2061·7569·6426·6774·3b3d··ERM·-F·auid&gt;=
00000920:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en00000920:·3130·3030·202d·4620·6175·6964·213d·756e··1000·-F·auid!=un
00000930:·2d55·5322·3e0a·2020·2020·2020·2020·556e··-US">.········Un00000930:·7365·7420·2d46·206b·6579·3d75·6e73·7563··set·-F·key=unsuc
00000940:·7375·6363·6573·7366·756c·2061·7474·656d··successful·attem00000940:·6365·7373·6675·6c2d·6d6f·6469·6669·6361··cessful-modifica
00000950:·7074·7320·746f·2061·6363·6573·7320·6120··pts·to·access·a·00000950:·7469·6f6e·0a2d·6120·616c·7761·7973·2c65··tion.-a·always,e
00000960:·6669·6c65·206d·6967·6874·2062·6520·7369··file·might·be·si00000960:·7869·7420·2d46·2061·7263·683d·6236·3420··xit·-F·arch=b64·
00000970:·676e·7320·6f66·206d·616c·6963·696f·7573··gns·of·malicious00000970:·2d53·206f·7065·6e61·742c·6f70·656e·5f62··-S·openat,open_b
00000980:·2061·6374·6976·6974·7920·6861·7070·656e···activity·happen00000980:·795f·6861·6e64·6c65·5f61·7420·2d46·2061··y_handle_at·-F·a
00000990:·696e·6720·7769·7468·696e·2074·6865·2073··ing·within·the·s00000990:·3226·616d·703b·3031·3030·3320·2d46·2065··2&amp;01003·-F·e
000009a0:·7973·7465·6d2e·2041·7564·6974·696e·6720··ystem.·Auditing·000009a0:·7869·743d·2d45·5045·524d·202d·4620·6175··xit=-EPERM·-F·au
000009b0:·6f66·2073·7563·6820·6163·7469·7669·7469··of·such·activiti000009b0:·6964·2667·743b·3d31·3030·3020·2d46·2061··id&gt;=1000·-F·a
000009c0:·6573·2068·656c·7073·2069·6e20·7468·6569··es·helps·in·thei000009c0:·7569·6421·3d75·6e73·6574·202d·4620·6b65··uid!=unset·-F·ke
000009d0:·7220·6d6f·6e69·746f·7269·6e67·2061·6e64··r·monitoring·and000009d0:·793d·756e·7375·6363·6573·7366·756c·2d6d··y=unsuccessful-m
000009e0:·2069·6e76·6573·7469·6761·7469·6f6e·2e0a···investigation..000009e0:·6f64·6966·6963·6174·696f·6e0a·2d61·2061··odification.-a·a
000009f0:·2020·2020·2020·3c2f·7464·3e0a·2020·2020········</td>.····000009f0:·6c77·6179·732c·6578·6974·202d·4620·6172··lways,exit·-F·ar
00000a00:·3c2f·7472·3e0a·2020·2020·3c74·723e·0a20··</tr>.····<tr>.·00000a00:·6368·3d62·3332·202d·5320·6f70·656e·202d··ch=b32·-S·open·-
00000a10:·2020·2020·203c·7464·3e41·552d·3228·6429·······<td>AU-2(d)00000a10:·4620·6131·2661·6d70·3b30·3130·3033·202d··F·a1&amp;01003·-
00000a20:·3c62·722f·3e41·552d·3132·2863·293c·6272··<br/>AU-12(c)<br00000a20:·4620·6578·6974·3d2d·4550·4552·4d20·2d46··F·exit=-EPERM·-F
00000a30:·2f3e·434d·2d36·2861·293c·2f74·643e·0a20··/>CM-6(a)</td>.·00000a30:·2061·7569·6426·6774·3b3d·3130·3030·202d···auid&gt;=1000·-
00000a40:·2020·2020·203c·7464·3e52·6563·6f72·6420·······<td>Record·00000a40:·4620·6175·6964·213d·756e·7365·7420·2d46··F·auid!=unset·-F
00000a50:·556e·7375·6363·6573·7366·756c·2050·6572··Unsuccessful·Per00000a50:·206b·6579·3d75·6e73·7563·6365·7373·6675···key=unsuccessfu
00000a60:·6d69·7373·696f·6e20·4368·616e·6765·7320··mission·Changes·00000a60:·6c2d·6d6f·6469·6669·6361·7469·6f6e·0a2d··l-modification.-
00000a70:·746f·2046·696c·6573·202d·2073·6574·7861··to·Files·-·setxa00000a70:·6120·616c·7761·7973·2c65·7869·7420·2d46··a·always,exit·-F
00000a80:·7474·723c·2f74·643e·0a20·2020·2020·203c··ttr</td>.······<00000a80:·2061·7263·683d·6236·3420·2d53·206f·7065···arch=b64·-S·ope
00000a90:·7464·2078·6d6c·3a6c·616e·673d·2265·6e2d··td·xml:lang="en-00000a90:·6e20·2d46·2061·3126·616d·703b·3031·3030··n·-F·a1&amp;0100
00000aa0:·5553·223e·0a20·2020·2020·2020·2054·6865··US">.········The00000aa0:·3320·2d46·2065·7869·743d·2d45·5045·524d··3·-F·exit=-EPERM
00000ab0:·2061·7564·6974·2073·7973·7465·6d20·7368···audit·system·sh00000ab0:·202d·4620·6175·6964·2667·743b·3d31·3030···-F·auid&gt;=100
00000ac0:·6f75·6c64·2063·6f6c·6c65·6374·2075·6e73··ould·collect·uns00000ac0:·3020·2d46·2061·7569·6421·3d75·6e73·6574··0·-F·auid!=unset
00000ad0:·7563·6365·7373·6675·6c20·6669·6c65·2070··uccessful·file·p00000ad0:·202d·4620·6b65·793d·756e·7375·6363·6573···-F·key=unsucces
00000ae0:·6572·6d69·7373·696f·6e20·6368·616e·6765··ermission·change00000ae0:·7366·756c·2d6d·6f64·6966·6963·6174·696f··sful-modificatio
00000af0:·0a61·7474·656d·7074·7320·666f·7220·616c··.attempts·for·al00000af0:·6e0a·2d61·2061·6c77·6179·732c·6578·6974··n.-a·always,exit
00000b00:·6c20·7573·6572·7320·616e·6420·726f·6f74··l·users·and·root00000b00:·202d·4620·6172·6368·3d62·3332·202d·5320···-F·arch=b32·-S·
00000b10:·2e0a·4966·2074·6865·203c·7474·3e61·7564··..If·the·<tt>aud00000b10:·7472·756e·6361·7465·2c66·7472·756e·6361··truncate,ftrunca
00000b20:·6974·643c·2f74·743e·2064·6165·6d6f·6e20··itd</tt>·daemon·00000b20:·7465·202d·4620·6578·6974·3d2d·4550·4552··te·-F·exit=-EPER
00000b30:·6973·2063·6f6e·6669·6775·7265·640a·746f··is·configured.to00000b30:·4d20·2d46·2061·7569·6426·6774·3b3d·3130··M·-F·auid&gt;=10
00000b40:·2075·7365·2074·6865·203c·7474·3e61·7567···use·the·<tt>aug00000b40:·3030·202d·4620·6175·6964·213d·756e·7365··00·-F·auid!=unse
00000b50:·656e·7275·6c65·733c·2f74·743e·2070·726f··enrules</tt>·pro00000b50:·7420·2d46·206b·6579·3d75·6e73·7563·6365··t·-F·key=unsucce
00000b60:·6772·616d·2074·6f20·7265·6164·2061·7564··gram·to·read·aud00000b60:·7373·6675·6c2d·6d6f·6469·6669·6361·7469··ssful-modificati
00000b70:·6974·2072·756c·6573·2064·7572·696e·6720··it·rules·during·00000b70:·6f6e·0a2d·6120·616c·7761·7973·2c65·7869··on.-a·always,exi
00000b80:·6461·656d·6f6e·0a73·7461·7274·7570·2028··daemon.startup·(00000b80:·7420·2d46·2061·7263·683d·6236·3420·2d53··t·-F·arch=b64·-S
00000b90:·7468·6520·6465·6661·756c·7429·2c20·6164··the·default),·ad00000b90:·2074·7275·6e63·6174·652c·6674·7275·6e63···truncate,ftrunc
00000ba0:·6420·7468·6520·666f·6c6c·6f77·696e·6720··d·the·following·00000ba0:·6174·6520·2d46·2065·7869·743d·2d45·5045··ate·-F·exit=-EPE
00000bb0:·6c69·6e65·7320·746f·2061·2066·696c·6520··lines·to·a·file·00000bb0:·524d·202d·4620·6175·6964·2667·743b·3d31··RM·-F·auid&gt;=1
00000bc0:·7769·7468·2073·7566·6669·780a·3c74·743e··with·suffix.<tt>00000bc0:·3030·3020·2d46·2061·7569·6421·3d75·6e73··000·-F·auid!=uns
00000bd0:·2e72·756c·6573·3c2f·7474·3e20·696e·2074··.rules</tt>·in·t00000bd0:·6574·202d·4620·6b65·793d·756e·7375·6363··et·-F·key=unsucc
00000be0:·6865·2064·6972·6563·746f·7279·203c·7474··he·directory·<tt00000be0:·6573·7366·756c·2d6d·6f64·6966·6963·6174··essful-modificat
Max diff block lines reached; 7019720/7282774 bytes (96.39%) of diff not shown.
2.5 MB
html2text {}
Max HTML report size reached
1.33 MB
./usr/share/doc/ssg-nondebian/table-ol7-ospprefs.html
Ordering differences only
    
Offset 75, 14 lines modifiedOffset 75, 70 lines modified
75 ········<tt>openscap-scanner</tt>·contains·the·<tt>oscap</tt>·command·line·tool.·This·tool·is·a75 ········<tt>openscap-scanner</tt>·contains·the·<tt>oscap</tt>·command·line·tool.·This·tool·is·a
76 configuration·and·vulnerability·scanner,·capable·of·performing·compliance·checking·using76 configuration·and·vulnerability·scanner,·capable·of·performing·compliance·checking·using
77 SCAP·content.77 SCAP·content.
78 ······</td>78 ······</td>
79 ····</tr>79 ····</tr>
80 ····<tr>80 ····<tr>
81 ······<td>FAU_GEN.1</td>81 ······<td>FAU_GEN.1</td>
 82 ······<td>Configure·basic·parameters·of·Audit·system</td>
 83 ······<td·xml:lang="en-US">
 84 ········Perform·basic·configuration·of·Audit·system.
 85 Make·sure·that·any·previously·defined·rules·are·cleared,·the·auditing·system·is·configured·to·handle·sudden·bursts·of·events,·and·in·cases·of·failure,·messages·are·configured·to·be·directed·to·system·log.
  
 86 The·following·rules·configure·audit·as·described·above:
 87 <pre>##·First·rule·-·delete·all
 88 -D
  
 89 ##·Increase·the·buffers·to·survive·stress·events.
 90 ##·Make·this·bigger·for·busy·systems
 91 -b·8192
  
 92 ##·This·determine·how·long·to·wait·in·burst·of·events
 93 --backlog_wait_time·60000
  
 94 ##·Set·failure·mode·to·syslog
 95 -f·1····</pre>
  
 96 Load·new·Audit·rules·into·kernel·by·running:
 97 <pre>augenrules·--load</pre>
 98 ······</td>
 99 ······<td·xml:lang="en-US">
 100 ········Without·basic·configurations,·audit·may·not·perform·as·expected.·It·may·not·be·able·to·correctly·handle·events·under·stressful·conditions,·or·log·events·in·case·of·failure.
 101 ······</td>
 102 ····</tr>
 103 ····<tr>
 104 ······<td>FAU_GEN.1</td>
 105 ······<td>Ensure·the·audit-libs·package·as·a·part·of·audit·Subsystem·is·Installed</td>
 106 ······<td·xml:lang="en-US">
 107 ········The·audit-libs·package·should·be·installed.
 108 ······</td>
 109 ······<td·xml:lang="en-US">
 110 ········The·auditd·service·is·an·access·monitoring·and·accounting·daemon,·watching·system·calls·to·audit·any·access,·in·comparison·with·potential·local·access·control·policy·such·as·SELinux·policy.
 111 ······</td>
 112 ····</tr>
 113 ····<tr>
 114 ······<td>FAU_GEN.1</td>
 115 ······<td>Enable·Auditing·to·Start·Prior·to·the·Audit·Daemon·in·zIPL</td>
 116 ······<td·xml:lang="en-US">
 117 ········To·ensure·all·processes·can·be·audited,·even·those·which·start·prior·to·the·audit·daemon,
 118 check·that·all·boot·entries·in·<tt>/boot/loader/entries/*.conf</tt>·have·<tt>audit=1</tt>
 119 included·in·its·options.<br·/>
  
 120 To·ensure·that·new·kernels·and·boot·entries·continue·to·enable·audit,
 121 add·<tt>audit=1</tt>·to·<tt>/etc/kernel/cmdline</tt>.
 122 ······</td>
 123 ······<td·xml:lang="en-US">
 124 ········Each·process·on·the·system·carries·an·"auditable"·flag·which·indicates·whether
 125 its·activities·can·be·audited.·Although·<tt>auditd</tt>·takes·care·of·enabling
 126 this·for·all·processes·which·launch·after·it·does,·adding·the·kernel·argument
 127 ensures·it·is·set·for·every·process·during·boot.
 128 ······</td>
 129 ····</tr>
 130 ····<tr>
 131 ······<td>FAU_GEN.1</td>
82 ······<td>Disable·SSH·Root·Login</td>132 ······<td>Disable·SSH·Root·Login</td>
83 ······<td·xml:lang="en-US">133 ······<td·xml:lang="en-US">
84 ········The·root·user·should·never·be·allowed·to·login·to·a134 ········The·root·user·should·never·be·allowed·to·login·to·a
85 system·directly·over·a·network.135 system·directly·over·a·network.
86 To·disable·root·login·via·SSH,·add·or·correct·the·following·line·in136 To·disable·root·login·via·SSH,·add·or·correct·the·following·line·in
  
  
Offset 117, 65 lines modifiedOffset 173, 14 lines modified
117 its·activities·can·be·audited.·Although·<tt>auditd</tt>·takes·care·of·enabling173 its·activities·can·be·audited.·Although·<tt>auditd</tt>·takes·care·of·enabling
118 this·for·all·processes·which·launch·after·it·does,·adding·the·kernel·argument174 this·for·all·processes·which·launch·after·it·does,·adding·the·kernel·argument
119 ensures·it·is·set·for·every·process·during·boot.175 ensures·it·is·set·for·every·process·during·boot.
120 ······</td>176 ······</td>
121 ····</tr>177 ····</tr>
122 ····<tr>178 ····<tr>
123 ······<td>FAU_GEN.1</td>179 ······<td>FAU_GEN.1</td>
124 ······<td>Ensure·the·audit·Subsystem·is·Installed</td> 
125 ······<td·xml:lang="en-US"> 
126 ········The·audit·package·should·be·installed. 
127 ······</td> 
128 ······<td·xml:lang="en-US"> 
129 ········The·auditd·service·is·an·access·monitoring·and·accounting·daemon,·watching·system·calls·to·audit·any·access,·in·comparison·with·potential·local·access·control·policy·such·as·SELinux·policy. 
130 ······</td> 
131 ····</tr> 
132 ····<tr> 
133 ······<td>FAU_GEN.1</td> 
134 ······<td>Include·Local·Events·in·Audit·Logs</td> 
135 ······<td·xml:lang="en-US"> 
136 ········To·configure·Audit·daemon·to·include·local·events·in·Audit·logs,·set 
137 <tt>local_events</tt>·to·<tt>yes</tt>·in·<tt>/etc/audit/auditd.conf</tt>. 
138 This·is·the·default·setting. 
139 ······</td> 
140 ······<td·xml:lang="en-US"> 
141 ········If·option·<tt>local_events</tt>·isn't·set·to·<tt>yes</tt>·only·events·from 
142 network·will·be·aggregated. 
143 ······</td> 
144 ····</tr> 
145 ····<tr> 
146 ······<td>FAU_GEN.1</td> 
147 ······<td>Configure·basic·parameters·of·Audit·system</td> 
148 ······<td·xml:lang="en-US"> 
149 ········Perform·basic·configuration·of·Audit·system. 
150 Make·sure·that·any·previously·defined·rules·are·cleared,·the·auditing·system·is·configured·to·handle·sudden·bursts·of·events,·and·in·cases·of·failure,·messages·are·configured·to·be·directed·to·system·log. 
  
151 The·following·rules·configure·audit·as·described·above: 
152 <pre>##·First·rule·-·delete·all 
153 -D 
  
154 ##·Increase·the·buffers·to·survive·stress·events. 
155 ##·Make·this·bigger·for·busy·systems 
156 -b·8192 
  
157 ##·This·determine·how·long·to·wait·in·burst·of·events 
158 --backlog_wait_time·60000 
  
159 ##·Set·failure·mode·to·syslog 
160 -f·1····</pre> 
  
161 Load·new·Audit·rules·into·kernel·by·running: 
162 <pre>augenrules·--load</pre> 
163 ······</td> 
164 ······<td·xml:lang="en-US"> 
165 ········Without·basic·configurations,·audit·may·not·perform·as·expected.·It·may·not·be·able·to·correctly·handle·events·under·stressful·conditions,·or·log·events·in·case·of·failure. 
166 ······</td> 
167 ····</tr> 
Max diff block lines reached; 504668/509828 bytes (98.99%) of diff not shown.
862 KB
html2text {}
    
Offset 43, 14 lines modifiedOffset 43, 55 lines modified
43 ·····························································································································command·line·tool.·This43 ·····························································································································command·line·tool.·This
44 AGD_PRE.1·········Install·openscap-·The·openscap-scanner·package·can·be·installed·with·the·following·command:················tool·is·a·configuration44 AGD_PRE.1·········Install·openscap-·The·openscap-scanner·package·can·be·installed·with·the·following·command:················tool·is·a·configuration
45 AGD_OPE.1·········scanner·Package···$·sudo·yum·install·openscap-scanner······················································and·vulnerability45 AGD_OPE.1·········scanner·Package···$·sudo·yum·install·openscap-scanner······················································and·vulnerability
46 ·····························································································································scanner,·capable·of46 ·····························································································································scanner,·capable·of
47 ·····························································································································performing·compliance47 ·····························································································································performing·compliance
48 ·····························································································································checking·using·SCAP48 ·····························································································································checking·using·SCAP
49 ·····························································································································content.49 ·····························································································································content.
 50 ····································Perform·basic·configuration·of·Audit·system.·Make·sure·that·any·previously·defined·rules
 51 ····································are·cleared,·the·auditing·system·is·configured·to·handle·sudden·bursts·of·events,·and·in
 52 ····································cases·of·failure,·messages·are·configured·to·be·directed·to·system·log.·The·following
 53 ····································rules·configure·audit·as·described·above:
 54 ····································##·First·rule·-·delete·all·······························································Without·basic
 55 ····································-D·······················································································configurations,·audit
 56 ·····························································································································may·not·perform·as
 57 ··················Configure·basic···##·Increase·the·buffers·to·survive·stress·events.········································expected.·It·may·not·be
 58 FAU_GEN.1·········parameters·of·····##·Make·this·bigger·for·busy·systems·····················································able·to·correctly
 59 ··················Audit·system······-b·8192··················································································handle·events·under
 60 ·····························································································································stressful·conditions,
 61 ····································##·This·determine·how·long·to·wait·in·burst·of·events····································or·log·events·in·case
 62 ····································--backlog_wait_time·60000································································of·failure.
  
 63 ····································##·Set·failure·mode·to·syslog
 64 ····································-f·1
 65 ····································Load·new·Audit·rules·into·kernel·by·running:
 66 ····································augenrules·--load
 67 ·····························································································································The·auditd·service·is
 68 ·····························································································································an·access·monitoring
 69 ··················Ensure·the·audit-··························································································and·accounting·daemon,
 70 ··················libs·package·as·a··························································································watching·system·calls
 71 FAU_GEN.1·········part·of·audit·····The·audit-libs·package·should·be·installed.··············································to·audit·any·access,·in
 72 ··················Subsystem·is·······························································································comparison·with
 73 ··················Installed··································································································potential·local·access
 74 ·····························································································································control·policy·such·as
 75 ·····························································································································SELinux·policy.
 76 ·····························································································································Each·process·on·the
 77 ·····························································································································system·carries·an
 78 ·····························································································································"auditable"·flag·which
 79 ·····························································································································indicates·whether·its
 80 ····································To·ensure·all·processes·can·be·audited,·even·those·which·start·prior·to·the·audit········activities·can·be
 81 ··················Enable·Auditing···daemon,·check·that·all·boot·entries·in·/boot/loader/entries/*.conf·have·audit=1·included·audited.·Although
 82 FAU_GEN.1·········to·Start·Prior·to·in·its·options.··········································································auditd·takes·care·of
 83 ··················the·Audit·Daemon··To·ensure·that·new·kernels·and·boot·entries·continue·to·enable·audit,·add·audit=1·to·/···enabling·this·for·all
 84 ··················in·zIPL···········etc/kernel/cmdline.······································································processes·which·launch
 85 ·····························································································································after·it·does,·adding
 86 ·····························································································································the·kernel·argument
 87 ·····························································································································ensures·it·is·set·for
 88 ·····························································································································every·process·during
 89 ·····························································································································boot.
50 ·····························································································································Even·though·the90 ·····························································································································Even·though·the
51 ·····························································································································communications·channel91 ·····························································································································communications·channel
52 ·····························································································································may·be·encrypted,·an92 ·····························································································································may·be·encrypted,·an
53 ·····························································································································additional·layer·of93 ·····························································································································additional·layer·of
54 ·····························································································································security·is·gained·by94 ·····························································································································security·is·gained·by
55 ·····························································································································extending·the·policy·of95 ·····························································································································extending·the·policy·of
56 ·····························································································································not·logging·directly·on96 ·····························································································································not·logging·directly·on
Offset 74, 45 lines modifiedOffset 115, 14 lines modified
74 ··················to·the·Audit······operating·systems.·Modify·the·line·within·/etc/default/grub·as·shown·below:··············enabling·this·for·all115 ··················to·the·Audit······operating·systems.·Modify·the·line·within·/etc/default/grub·as·shown·below:··············enabling·this·for·all
75 ··················Daemon············GRUB_CMDLINE_LINUX="...·audit=1·..."·····················································processes·which·launch116 ··················Daemon············GRUB_CMDLINE_LINUX="...·audit=1·..."·····················································processes·which·launch
76 ····································Run·the·following·command·to·update·command·line·for·already·installed·kernels:··········after·it·does,·adding117 ····································Run·the·following·command·to·update·command·line·for·already·installed·kernels:··········after·it·does,·adding
77 ····································#·grubby·--update-kernel=ALL·--args="audit=1"············································the·kernel·argument118 ····································#·grubby·--update-kernel=ALL·--args="audit=1"············································the·kernel·argument
78 ·····························································································································ensures·it·is·set·for119 ·····························································································································ensures·it·is·set·for
79 ·····························································································································every·process·during120 ·····························································································································every·process·during
80 ·····························································································································boot.121 ·····························································································································boot.
81 ·····························································································································The·auditd·service·is 
82 ·····························································································································an·access·monitoring 
83 ·····························································································································and·accounting·daemon, 
84 ··················Ensure·the·audit···························································································watching·system·calls 
85 FAU_GEN.1·········Subsystem·is······The·audit·package·should·be·installed.···················································to·audit·any·access,·in 
86 ··················Installed··································································································comparison·with 
87 ·····························································································································potential·local·access 
88 ·····························································································································control·policy·such·as 
89 ·····························································································································SELinux·policy. 
90 ··················Include·Local······························································································If·option·local_events 
91 FAU_GEN.1·········Events·in·Audit···To·configure·Audit·daemon·to·include·local·events·in·Audit·logs,·set·local_events·to·yes·isn't·set·to·yes·only 
92 ··················Logs··············in·/etc/audit/auditd.conf.·This·is·the·default·setting.··································events·from·network 
93 ·····························································································································will·be·aggregated. 
94 ····································Perform·basic·configuration·of·Audit·system.·Make·sure·that·any·previously·defined·rules 
95 ····································are·cleared,·the·auditing·system·is·configured·to·handle·sudden·bursts·of·events,·and·in 
96 ····································cases·of·failure,·messages·are·configured·to·be·directed·to·system·log.·The·following 
97 ····································rules·configure·audit·as·described·above: 
98 ····································##·First·rule·-·delete·all·······························································Without·basic 
99 ····································-D·······················································································configurations,·audit 
100 ·····························································································································may·not·perform·as 
101 ··················Configure·basic···##·Increase·the·buffers·to·survive·stress·events.········································expected.·It·may·not·be 
102 FAU_GEN.1·········parameters·of·····##·Make·this·bigger·for·busy·systems·····················································able·to·correctly 
103 ··················Audit·system······-b·8192··················································································handle·events·under 
104 ·····························································································································stressful·conditions, 
105 ····································##·This·determine·how·long·to·wait·in·burst·of·events····································or·log·events·in·case 
106 ····································--backlog_wait_time·60000································································of·failure. 
  
107 ····································##·Set·failure·mode·to·syslog 
108 ····································-f·1 
109 ····································Load·new·Audit·rules·into·kernel·by·running: 
110 ····································augenrules·--load 
111 ·····························································································································Without·establishing122 ·····························································································································Without·establishing
112 ·····························································································································what·type·of·events123 ·····························································································································what·type·of·events
113 ·····························································································································occurred,·it·would·be124 ·····························································································································occurred,·it·would·be
114 ·····························································································································difficult·to·establish,125 ·····························································································································difficult·to·establish,
115 ·····························································································································correlate,·and126 ·····························································································································correlate,·and
116 ·····························································································································investigate·the·events127 ·····························································································································investigate·the·events
117 ·····························································································································leading·up·to·an·outage128 ·····························································································································leading·up·to·an·outage
Offset 129, 83 lines modifiedOffset 139, 667 lines modified
129 ·····························································································································audit·subsystem·ensures139 ·····························································································································audit·subsystem·ensures
130 ·····························································································································that·actions·of140 ·····························································································································that·actions·of
131 ·····························································································································individual·system·users141 ·····························································································································individual·system·users
132 ·····························································································································can·be·uniquely·traced142 ·····························································································································can·be·uniquely·traced
133 ·····························································································································to·those·users·so·they143 ·····························································································································to·those·users·so·they
134 ·····························································································································can·be·held·accountable144 ·····························································································································can·be·held·accountable
135 ·····························································································································for·their·actions.145 ·····························································································································for·their·actions.
 146 ··················Include·Local······························································································If·option·local_events
 147 FAU_GEN.1·········Events·in·Audit···To·configure·Audit·daemon·to·include·local·events·in·Audit·logs,·set·local_events·to·yes·isn't·set·to·yes·only
 148 ··················Logs··············in·/etc/audit/auditd.conf.·This·is·the·default·setting.··································events·from·network
136 ·····························································································································Each·process·on·the 
137 ·····························································································································system·carries·an 
138 ·····························································································································"auditable"·flag·which 
139 ·····························································································································indicates·whether·its 
140 ····································To·ensure·all·processes·can·be·audited,·even·those·which·start·prior·to·the·audit········activities·can·be 
141 ··················Enable·Auditing···daemon,·check·that·all·boot·entries·in·/boot/loader/entries/*.conf·have·audit=1·included·audited.·Although 
142 FAU_GEN.1·········to·Start·Prior·to·in·its·options.··········································································auditd·takes·care·of 
143 ··················the·Audit·Daemon··To·ensure·that·new·kernels·and·boot·entries·continue·to·enable·audit,·add·audit=1·to·/···enabling·this·for·all 
144 ··················in·zIPL···········etc/kernel/cmdline.······································································processes·which·launch 
145 ·····························································································································after·it·does,·adding 
146 ·····························································································································the·kernel·argument 
147 ·····························································································································ensures·it·is·set·for 
148 ·····························································································································every·process·during 
149 ·····························································································································boot.149 ·····························································································································will·be·aggregated.
150 ·····························································································································The·auditd·service·is150 ·····························································································································The·auditd·service·is
Max diff block lines reached; 865253/882671 bytes (98.03%) of diff not shown.
782 KB
./usr/share/doc/ssg-nondebian/table-ol7-pcidssrefs.html
Ordering differences only
    
Offset 157, 28 lines modifiedOffset 157, 14 lines modified
157 default·zone·to·<tt>drop</tt>·implements·proper·design·for·a·firewall,·i.e.157 default·zone·to·<tt>drop</tt>·implements·proper·design·for·a·firewall,·i.e.
158 any·packets·which·are·not·explicitly·permitted·should·not·be158 any·packets·which·are·not·explicitly·permitted·should·not·be
159 accepted.159 accepted.
160 ······</td>160 ······</td>
161 ····</tr>161 ····</tr>
162 ····<tr>162 ····<tr>
163 ······<td>Req-1.4.1</td>163 ······<td>Req-1.4.1</td>
164 ······<td>Install·iptables·Package</td> 
165 ······<td·xml:lang="en-US"> 
166 ········The·<code>iptables</code>·package·can·be·installed·with·the·following·command: 
167 <pre> 
168 $·sudo·yum·install·iptables</pre> 
169 ······</td> 
170 ······<td·xml:lang="en-US"> 
171 ········<tt>iptables</tt>·controls·the·Linux·kernel·network·packet·filtering 
172 code.·<tt>iptables</tt>·allows·system·operators·to·set·up·firewalls·and·IP 
173 masquerading,·etc. 
174 ······</td> 
175 ····</tr> 
176 ····<tr> 
177 ······<td>Req-1.4.1</td> 
178 ······<td>Set·nftables·Configuration·for·Loopback·Traffic</td>164 ······<td>Set·nftables·Configuration·for·Loopback·Traffic</td>
179 ······<td·xml:lang="en-US">165 ······<td·xml:lang="en-US">
180 ········Configure·the·loopback·interface·to·accept·traffic.166 ········Configure·the·loopback·interface·to·accept·traffic.
181 Configure·all·other·interfaces·to·deny·traffic·to·the·loopback167 Configure·all·other·interfaces·to·deny·traffic·to·the·loopback
182 network.168 network.
183 ······</td>169 ······</td>
184 ······<td·xml:lang="en-US">170 ······<td·xml:lang="en-US">
Offset 187, 14 lines modifiedOffset 173, 28 lines modified
187 is·the·only·place·that·loopback·network·traffic·should·be·seen,173 is·the·only·place·that·loopback·network·traffic·should·be·seen,
188 all·other·interfaces·should·ignore·traffic·on·this·network·as·an174 all·other·interfaces·should·ignore·traffic·on·this·network·as·an
189 anti-spoofing·measure.175 anti-spoofing·measure.
190 ······</td>176 ······</td>
191 ····</tr>177 ····</tr>
192 ····<tr>178 ····<tr>
193 ······<td>Req-1.4.1</td>179 ······<td>Req-1.4.1</td>
 180 ······<td>Install·iptables·Package</td>
 181 ······<td·xml:lang="en-US">
 182 ········The·<code>iptables</code>·package·can·be·installed·with·the·following·command:
 183 <pre>
 184 $·sudo·yum·install·iptables</pre>
 185 ······</td>
 186 ······<td·xml:lang="en-US">
 187 ········<tt>iptables</tt>·controls·the·Linux·kernel·network·packet·filtering
 188 code.·<tt>iptables</tt>·allows·system·operators·to·set·up·firewalls·and·IP
 189 masquerading,·etc.
 190 ······</td>
 191 ····</tr>
 192 ····<tr>
 193 ······<td>Req-1.4.1</td>
194 ······<td>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</td>194 ······<td>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</td>
195 ······<td·xml:lang="en-US">195 ······<td·xml:lang="en-US">
196 ········To·set·the·runtime·status·of·the·<code>net.ipv4.tcp_syncookies</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1</pre>196 ········To·set·the·runtime·status·of·the·<code>net.ipv4.tcp_syncookies</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1</pre>
197 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.tcp_syncookies·=·1</pre>197 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.tcp_syncookies·=·1</pre>
198 ······</td>198 ······</td>
199 ······<td·xml:lang="en-US">199 ······<td·xml:lang="en-US">
200 ········A·TCP·SYN·flood·attack·can·cause·a·denial·of·service·by·filling·a200 ········A·TCP·SYN·flood·attack·can·cause·a·denial·of·service·by·filling·a
Offset 203, 14 lines modifiedOffset 203, 35 lines modified
203 verifying·the·initiator·is·attempting·a·valid·connection·and·is·not·a·flood203 verifying·the·initiator·is·attempting·a·valid·connection·and·is·not·a·flood
204 source.·This·feature·is·activated·when·a·flood·condition·is·detected,·and204 source.·This·feature·is·activated·when·a·flood·condition·is·detected,·and
205 enables·the·system·to·continue·servicing·valid·connection·requests.205 enables·the·system·to·continue·servicing·valid·connection·requests.
206 ······</td>206 ······</td>
207 ····</tr>207 ····</tr>
208 ····<tr>208 ····<tr>
209 ······<td>Req-1.4.2</td>209 ······<td>Req-1.4.2</td>
 210 ······<td>Disable·DCCP·Support</td>
 211 ······<td·xml:lang="en-US">
 212 ········The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a
 213 relatively·new·transport·layer·protocol,·designed·to·support
 214 streaming·media·and·telephony.
  
 215 To·configure·the·system·to·prevent·the·<code>dccp</code>
 216 kernel·module·from·being·loaded,·add·the·following·line·to·the·file·<code>/etc/modprobe.d/dccp.conf</code>:
 217 <pre>install·dccp·/bin/false</pre>
  
 218 To·configure·the·system·to·prevent·the·<code>dccp</code>·from·being·used,
 219 add·the·following·line·to·file·<code>/etc/modprobe.d/dccp.conf</code>:
 220 <pre>blacklist·dccp</pre>
 221 ······</td>
 222 ······<td·xml:lang="en-US">
 223 ········Disabling·DCCP·protects
 224 the·system·against·exploitation·of·any·flaws·in·its·implementation.
 225 ······</td>
 226 ····</tr>
 227 ····<tr>
 228 ······<td>Req-1.4.2</td>
210 ······<td>Disable·SCTP·Support</td>229 ······<td>Disable·SCTP·Support</td>
211 ······<td·xml:lang="en-US">230 ······<td·xml:lang="en-US">
212 ········The·Stream·Control·Transmission·Protocol·(SCTP)·is·a231 ········The·Stream·Control·Transmission·Protocol·(SCTP)·is·a
213 transport·layer·protocol,·designed·to·support·the·idea·of232 transport·layer·protocol,·designed·to·support·the·idea·of
214 message-oriented·communication,·with·several·streams·of·messages233 message-oriented·communication,·with·several·streams·of·messages
215 within·one·connection.234 within·one·connection.
  
Offset 224, 75 lines modifiedOffset 245, 58 lines modified
224 ······</td>245 ······</td>
225 ······<td·xml:lang="en-US">246 ······<td·xml:lang="en-US">
226 ········Disabling·SCTP·protects247 ········Disabling·SCTP·protects
227 the·system·against·exploitation·of·any·flaws·in·its·implementation.248 the·system·against·exploitation·of·any·flaws·in·its·implementation.
228 ······</td>249 ······</td>
229 ····</tr>250 ····</tr>
230 ····<tr>251 ····<tr>
231 ······<td>Req-1.4.2</td> 
232 ······<td>Disable·DCCP·Support</td> 
233 ······<td·xml:lang="en-US"> 
234 ········The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a 
235 relatively·new·transport·layer·protocol,·designed·to·support 
236 streaming·media·and·telephony. 
  
237 To·configure·the·system·to·prevent·the·<code>dccp</code> 
238 kernel·module·from·being·loaded,·add·the·following·line·to·the·file·<code>/etc/modprobe.d/dccp.conf</code>: 
239 <pre>install·dccp·/bin/false</pre> 
  
240 To·configure·the·system·to·prevent·the·<code>dccp</code>·from·being·used, 
241 add·the·following·line·to·file·<code>/etc/modprobe.d/dccp.conf</code>: 
242 <pre>blacklist·dccp</pre> 
243 ······</td> 
244 ······<td·xml:lang="en-US"> 
245 ········Disabling·DCCP·protects 
246 the·system·against·exploitation·of·any·flaws·in·its·implementation. 
247 ······</td> 
248 ····</tr> 
249 ····<tr> 
250 ······<td>Req-1.4.3</td>252 ······<td>Req-1.4.3</td>
251 ······<td>Disable·Kernel·Parameter·for·Accepting·Secure·ICMP·Redirects·on·all·IPv4·Interfaces</td>253 ······<td>Disable·Kernel·Parameter·for·Accepting·Secure·ICMP·Redirects·on·all·IPv4·Interfaces</td>
252 ······<td·xml:lang="en-US">254 ······<td·xml:lang="en-US">
253 ········To·set·the·runtime·status·of·the·<code>net.ipv4.conf.all.secure_redirects</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.conf.all.secure_redirects=0</pre>255 ········To·set·the·runtime·status·of·the·<code>net.ipv4.conf.all.secure_redirects</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.conf.all.secure_redirects=0</pre>
254 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.conf.all.secure_redirects·=·0</pre>256 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.conf.all.secure_redirects·=·0</pre>
Max diff block lines reached; 299706/304898 bytes (98.30%) of diff not shown.
485 KB
html2text {}
    
Offset 112, 23 lines modifiedOffset 112, 14 lines modified
112 ·········Incoming·Packets····firewalld.conf·to·be:··································drop·implements112 ·········Incoming·Packets····firewalld.conf·to·be:··································drop·implements
113 ·····························DefaultZone=drop·······································proper·design·for·a113 ·····························DefaultZone=drop·······································proper·design·for·a
114 ····················································································firewall,·i.e.·any114 ····················································································firewall,·i.e.·any
115 ····················································································packets·which·are115 ····················································································packets·which·are
116 ····················································································not·explicitly116 ····················································································not·explicitly
117 ····················································································permitted·should117 ····················································································permitted·should
118 ····················································································not·be·accepted.118 ····················································································not·be·accepted.
119 ····················································································iptables·controls 
120 ····················································································the·Linux·kernel 
121 ····················································································network·packet 
122 Req-·····Install·iptables····The·iptables·package·can·be·installed·with·the·········filtering·code. 
123 1.4.1····Package·············following·command:·····································iptables·allows 
124 ·····························$·sudo·yum·install·iptables····························system·operators·to 
125 ····················································································set·up·firewalls 
126 ····················································································and·IP 
127 ····················································································masquerading,·etc. 
128 ····················································································Loopback·traffic·is119 ····················································································Loopback·traffic·is
129 ····················································································generated·between120 ····················································································generated·between
130 ····················································································processes·on121 ····················································································processes·on
131 ····················································································machine·and·is122 ····················································································machine·and·is
132 ····················································································typically·critical123 ····················································································typically·critical
133 ····················································································to·operation·of·the124 ····················································································to·operation·of·the
134 ····················································································system.·The125 ····················································································system.·The
Offset 138, 14 lines modifiedOffset 129, 23 lines modified
138 ····················································································network·traffic129 ····················································································network·traffic
139 ····················································································should·be·seen,·all130 ····················································································should·be·seen,·all
140 ····················································································other·interfaces131 ····················································································other·interfaces
141 ····················································································should·ignore132 ····················································································should·ignore
142 ····················································································traffic·on·this133 ····················································································traffic·on·this
143 ····················································································network·as·an·anti-134 ····················································································network·as·an·anti-
144 ····················································································spoofing·measure.135 ····················································································spoofing·measure.
 136 ····················································································iptables·controls
 137 ····················································································the·Linux·kernel
 138 ····················································································network·packet
 139 Req-·····Install·iptables····The·iptables·package·can·be·installed·with·the·········filtering·code.
 140 1.4.1····Package·············following·command:·····································iptables·allows
 141 ·····························$·sudo·yum·install·iptables····························system·operators·to
 142 ····················································································set·up·firewalls
 143 ····················································································and·IP
 144 ····················································································masquerading,·etc.
145 ····················································································A·TCP·SYN·flood145 ····················································································A·TCP·SYN·flood
146 ····················································································attack·can·cause·a146 ····················································································attack·can·cause·a
147 ····················································································denial·of·service147 ····················································································denial·of·service
148 ····················································································by·filling·a148 ····················································································by·filling·a
149 ····················································································system's·TCP149 ····················································································system's·TCP
150 ····················································································connection·table150 ····················································································connection·table
151 ····················································································with·connections·in151 ····················································································with·connections·in
Offset 164, 90 lines modifiedOffset 164, 47 lines modified
164 ····················································································flood·condition·is164 ····················································································flood·condition·is
165 ····················································································detected,·and165 ····················································································detected,·and
166 ····················································································enables·the·system166 ····················································································enables·the·system
167 ····················································································to·continue167 ····················································································to·continue
168 ····················································································servicing·valid168 ····················································································servicing·valid
169 ····················································································connection169 ····················································································connection
170 ····················································································requests.170 ····················································································requests.
 171 ·····························The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a
 172 ·····························relatively·new·transport·layer·protocol,·designed·to
 173 ·····························support·streaming·media·and·telephony.·To·configure····Disabling·DCCP
 174 ·····························the·system·to·prevent·the·dccp·kernel·module·from······protects·the·system
 175 Req-·····Disable·DCCP········being·loaded,·add·the·following·line·to·the·file·/etc/·against
 176 1.4.2····Support·············modprobe.d/dccp.conf:··································exploitation·of·any
 177 ·····························install·dccp·/bin/false································flaws·in·its
 178 ·····························To·configure·the·system·to·prevent·the·dccp·from·being·implementation.
 179 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/
 180 ·····························dccp.conf:
 181 ·····························blacklist·dccp
171 ·····························The·Stream·Control·Transmission·Protocol·(SCTP)·is·a182 ·····························The·Stream·Control·Transmission·Protocol·(SCTP)·is·a
172 ·····························transport·layer·protocol,·designed·to·support·the·idea183 ·····························transport·layer·protocol,·designed·to·support·the·idea
173 ·····························of·message-oriented·communication,·with·several184 ·····························of·message-oriented·communication,·with·several
174 ·····························streams·of·messages·within·one·connection.·To··········Disabling·SCTP185 ·····························streams·of·messages·within·one·connection.·To··········Disabling·SCTP
175 ·····························configure·the·system·to·prevent·the·sctp·kernel·module·protects·the·system186 ·····························configure·the·system·to·prevent·the·sctp·kernel·module·protects·the·system
176 Req-·····Disable·SCTP········from·being·loaded,·add·the·following·line·to·the·file··against187 Req-·····Disable·SCTP········from·being·loaded,·add·the·following·line·to·the·file··against
177 1.4.2····Support·············/etc/modprobe.d/sctp.conf:·····························exploitation·of·any188 1.4.2····Support·············/etc/modprobe.d/sctp.conf:·····························exploitation·of·any
178 ·····························install·sctp·/bin/false································flaws·in·its189 ·····························install·sctp·/bin/false································flaws·in·its
179 ·····························To·configure·the·system·to·prevent·the·sctp·from·being·implementation.190 ·····························To·configure·the·system·to·prevent·the·sctp·from·being·implementation.
180 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/191 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/
181 ·····························sctp.conf:192 ·····························sctp.conf:
182 ·····························blacklist·sctp193 ·····························blacklist·sctp
183 ·····························The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a 
184 ·····························relatively·new·transport·layer·protocol,·designed·to 
185 ·····························support·streaming·media·and·telephony.·To·configure····Disabling·DCCP 
186 ·····························the·system·to·prevent·the·dccp·kernel·module·from······protects·the·system 
187 Req-·····Disable·DCCP········being·loaded,·add·the·following·line·to·the·file·/etc/·against 
188 1.4.2····Support·············modprobe.d/dccp.conf:··································exploitation·of·any 
189 ·····························install·dccp·/bin/false································flaws·in·its 
190 ·····························To·configure·the·system·to·prevent·the·dccp·from·being·implementation. 
191 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/ 
192 ·····························dccp.conf: 
193 ·····························blacklist·dccp 
194 ····················································································Accepting·"secure"194 ····················································································Accepting·"secure"
195 ·····························To·set·the·runtime·status·of·the·······················ICMP·redirects195 ·····························To·set·the·runtime·status·of·the·······················ICMP·redirects
196 ·········Disable·Kernel······net.ipv4.conf.all.secure_redirects·kernel·parameter,···(from·those196 ·········Disable·Kernel······net.ipv4.conf.all.secure_redirects·kernel·parameter,···(from·those
197 ·········Parameter·for·······run·the·following·command:·····························gateways·listed·as197 ·········Parameter·for·······run·the·following·command:·····························gateways·listed·as
198 Req-·····Accepting·Secure····$·sudo·sysctl·-w·net.ipv4.conf.all.secure_redirects=0··default·gateways)198 Req-·····Accepting·Secure····$·sudo·sysctl·-w·net.ipv4.conf.all.secure_redirects=0··default·gateways)
199 1.4.3····ICMP·Redirects·on···To·make·sure·that·the·setting·is·persistent,·add·the···has·few·legitimate199 1.4.3····ICMP·Redirects·on···To·make·sure·that·the·setting·is·persistent,·add·the···has·few·legitimate
200 ·········all·IPv4·Interfaces·following·line·to·a·file·in·the·directory·/etc/········uses.·It·should·be200 ·········all·IPv4·Interfaces·following·line·to·a·file·in·the·directory·/etc/········uses.·It·should·be
201 ·····························sysctl.d:··············································disabled·unless·it201 ·····························sysctl.d:··············································disabled·unless·it
202 ·····························net.ipv4.conf.all.secure_redirects·=·0·················is·absolutely202 ·····························net.ipv4.conf.all.secure_redirects·=·0·················is·absolutely
203 ····················································································required.203 ····················································································required.
204 ····················································································Responding·to 
205 ····················································································broadcast·(ICMP) 
206 ····················································································echoes·facilitates 
207 ·····························To·set·the·runtime·status·of·the·······················network·mapping·and 
208 ·····························net.ipv4.icmp_echo_ignore_broadcasts·kernel·parameter,·provides·a·vector 
209 ·········Enable·Kernel·······run·the·following·command:·····························for·amplification 
210 ·········Parameter·to·Ignore·$·sudo·sysctl·-········································attacks. 
211 Req-·····ICMP·Broadcast·Echo·w·net.ipv4.icmp_echo_ignore_broadcasts=1···············Ignoring·ICMP·echo 
212 1.4.3····Requests·on·IPv4····To·make·sure·that·the·setting·is·persistent,·add·the···requests·(pings) 
213 ·········Interfaces··········following·line·to·a·file·in·the·directory·/etc/········sent·to·broadcast 
214 ·····························sysctl.d:··············································or·multicast 
215 ·····························net.ipv4.icmp_echo_ignore_broadcasts·=·1···············addresses·makes·the 
216 ····················································································system·slightly 
217 ····················································································more·difficult·to 
218 ····················································································enumerate·on·the 
219 ····················································································network. 
220 ····················································································Enabling·reverse 
221 ····················································································path·filtering 
222 ····················································································drops·packets·with 
223 ····················································································source·addresses 
224 ····················································································that·should·not 
225 ·····························To·set·the·runtime·status·of·the·······················have·been·able·to 
226 ·········Enable·Kernel·······net.ipv4.conf.all.rp_filter·kernel·parameter,·run·the··be·received·on·the 
227 ·········Parameter·to·Use····following·command:·····································interface·they·were 
228 Req-·····Reverse·Path········$·sudo·sysctl·-w·net.ipv4.conf.all.rp_filter=1·········received·on.·It 
229 1.4.3····Filtering·on·all····To·make·sure·that·the·setting·is·persistent,·add·the···should·not·be·used 
230 ·········IPv4·Interfaces·····following·line·to·a·file·in·the·directory·/etc/········on·systems·which 
231 ·····························sysctl.d:··············································are·routers·for 
Max diff block lines reached; 482482/496163 bytes (97.24%) of diff not shown.
3.51 MB
./usr/share/doc/ssg-nondebian/table-ol8-anssirefs.html
    
Offset 63, 280 lines modifiedOffset 63, 280 lines modified
000003e0:·2054·6974·6c65·3c2f·7468·3e0a·2020·2020···Title</th>.····000003e0:·2054·6974·6c65·3c2f·7468·3e0a·2020·2020···Title</th>.····
000003f0:·3c74·683e·4465·7363·7269·7074·696f·6e3c··<th>Description<000003f0:·3c74·683e·4465·7363·7269·7074·696f·6e3c··<th>Description<
00000400:·2f74·683e·0a20·2020·203c·7468·3e52·6174··/th>.····<th>Rat00000400:·2f74·683e·0a20·2020·203c·7468·3e52·6174··/th>.····<th>Rat
00000410:·696f·6e61·6c65·3c2f·7468·3e0a·2020·3c2f··ionale</th>.··</00000410:·696f·6e61·6c65·3c2f·7468·3e0a·2020·3c2f··ionale</th>.··</
00000420:·7468·6561·643e·0a20·203c·7462·6f64·793e··thead>.··<tbody>00000420:·7468·6561·643e·0a20·203c·7462·6f64·793e··thead>.··<tbody>
00000430:·0a20·203c·7472·3e0a·2020·2020·2020·3c74··.··<tr>.······<t00000430:·0a20·203c·7472·3e0a·2020·2020·2020·3c74··.··<tr>.······<t
00000440:·643e·5231·3c2f·7464·3e0a·2020·2020·2020··d>R1</td>.······00000440:·643e·5231·3c2f·7464·3e0a·2020·2020·2020··d>R1</td>.······
00000450:·3c74·643e·456e·7375·7265·2053·4d45·5020··<td>Ensure·SMEP· 
00000460:·6973·206e·6f74·2064·6973·6162·6c65·6420··is·not·disabled· 
00000470:·6475·7269·6e67·2062·6f6f·743c·2f74·643e··during·boot</td>00000450:·3c74·643e·496e·7374·616c·6c20·5041·4520··<td>Install·PAE·
 00000460:·4b65·726e·656c·206f·6e20·5375·7070·6f72··Kernel·on·Suppor
 00000470:·7465·6420·3332·2d62·6974·2078·3836·2053··ted·32-bit·x86·S
 00000480:·7973·7465·6d73·3c2f·7464·3e0a·2020·2020··ystems</td>.····
 00000490:·2020·3c74·6420·786d·6c3a·6c61·6e67·3d22····<td·xml:lang="
 000004a0:·656e·2d55·5322·3e0a·2020·2020·2020·2020··en-US">.········
 000004b0:·5379·7374·656d·7320·7468·6174·2061·7265··Systems·that·are
 000004c0:·2075·7369·6e67·2074·6865·2036·342d·6269···using·the·64-bi
 000004d0:·7420·7838·3620·6b65·726e·656c·2070·6163··t·x86·kernel·pac
 000004e0:·6b61·6765·0a64·6f20·6e6f·7420·6e65·6564··kage.do·not·need
 000004f0:·2074·6f20·696e·7374·616c·6c20·7468·6520···to·install·the·
 00000500:·6b65·726e·656c·2d50·4145·2070·6163·6b61··kernel-PAE·packa
 00000510:·6765·2062·6563·6175·7365·2074·6865·2036··ge·because·the·6
 00000520:·342d·6269·740a·7838·3620·6b65·726e·656c··4-bit.x86·kernel
 00000530:·2061·6c72·6561·6479·2069·6e63·6c75·6465···already·include
 00000540:·7320·7468·6973·2073·7570·706f·7274·2e20··s·this·support.·
 00000550:·486f·7765·7665·722c·2069·6620·7468·6520··However,·if·the·
 00000560:·7379·7374·656d·2069·730a·3332·2d62·6974··system·is.32-bit
 00000570:·2061·6e64·2061·6c73·6f20·7375·7070·6f72···and·also·suppor
 00000580:·7473·2074·6865·2050·4145·2061·6e64·204e··ts·the·PAE·and·N
 00000590:·5820·6665·6174·7572·6573·2061·730a·6465··X·features·as.de
 000005a0:·7465·726d·696e·6564·2069·6e20·7468·6520··termined·in·the·
 000005b0:·7072·6576·696f·7573·2073·6563·7469·6f6e··previous·section
 000005c0:·2c20·7468·6520·6b65·726e·656c·2d50·4145··,·the·kernel-PAE
 000005d0:·2070·6163·6b61·6765·2073·686f·756c·640a···package·should.
 000005e0:·6265·2069·6e73·7461·6c6c·6564·2074·6f20··be·installed·to·
 000005f0:·656e·6162·6c65·2058·4420·6f72·204e·5820··enable·XD·or·NX·
 00000600:·7375·7070·6f72·742e·0a54·6865·203c·636f··support..The·<co
 00000610:·6465·3e6b·6572·6e65·6c2d·5041·453c·2f63··de>kernel-PAE</c
 00000620:·6f64·653e·2070·6163·6b61·6765·2063·616e··ode>·package·can
 00000630:·2062·6520·696e·7374·616c·6c65·6420·7769···be·installed·wi
 00000640:·7468·2074·6865·2066·6f6c·6c6f·7769·6e67··th·the·following
 00000650:·2063·6f6d·6d61·6e64·3a0a·3c70·7265·3e0a···command:.<pre>.
 00000660:·2420·7375·646f·2079·756d·2069·6e73·7461··$·sudo·yum·insta
 00000670:·6c6c·206b·6572·6e65·6c2d·5041·453c·2f70··ll·kernel-PAE</p
 00000680:·7265·3e0a·5468·6520·696e·7374·616c·6c61··re>.The·installa
 00000690:·7469·6f6e·2070·726f·6365·7373·2073·686f··tion·process·sho
 000006a0:·756c·6420·616c·736f·2068·6176·6520·636f··uld·also·have·co
 000006b0:·6e66·6967·7572·6564·2074·6865·0a62·6f6f··nfigured·the.boo
 000006c0:·746c·6f61·6465·7220·746f·206c·6f61·6420··tloader·to·load·
 000006d0:·7468·6520·6e65·7720·6b65·726e·656c·2061··the·new·kernel·a
 000006e0:·7420·626f·6f74·2e20·5665·7269·6679·2074··t·boot.·Verify·t
 000006f0:·6869·7320·6166·7465·7220·7265·626f·6f74··his·after·reboot
 00000700:·0a61·6e64·206d·6f64·6966·7920·3c74·743e··.and·modify·<tt>
 00000710:·2f65·7463·2f64·6566·6175·6c74·2f67·7275··/etc/default/gru
 00000720:·623c·2f74·743e·2069·6620·6e65·6365·7373··b</tt>·if·necess
 00000730:·6172·792e·0a20·2020·2020·203c·2f74·643e··ary..······</td>
00000480:·0a20·2020·2020·203c·7464·2078·6d6c·3a6c··.······<td·xml:l00000740:·0a20·2020·2020·203c·7464·2078·6d6c·3a6c··.······<td·xml:l
00000490:·616e·673d·2265·6e2d·5553·223e·0a20·2020··ang="en-US">.···00000750:·616e·673d·2265·6e2d·5553·223e·0a20·2020··ang="en-US">.···
 00000760:·2020·2020·204f·6e20·3332·2d62·6974·2073·······On·32-bit·s
 00000770:·7973·7465·6d73·2074·6861·7420·7375·7070··ystems·that·supp
 00000780:·6f72·7420·7468·6520·5844·206f·7220·4e58··ort·the·XD·or·NX
 00000790:·2062·6974·2c20·7468·6520·7665·6e64·6f72···bit,·the·vendor
 000007a0:·2d73·7570·706c·6965·640a·5041·4520·6b65··-supplied.PAE·ke
 000007b0:·726e·656c·2069·7320·7265·7175·6972·6564··rnel·is·required
 000007c0:·2074·6f20·656e·6162·6c65·2065·6974·6865···to·enable·eithe
 000007d0:·7220·4578·6563·7574·6520·4469·7361·626c··r·Execute·Disabl
 000007e0:·6520·2858·4429·206f·7220·4e6f·2045·7865··e·(XD)·or·No·Exe
 000007f0:·6375·7465·2028·4e58·2920·7375·7070·6f72··cute·(NX)·suppor
 00000800:·742e·0a20·2020·2020·203c·2f74·643e·0a20··t..······</td>.·
 00000810:·2020·203c·2f74·723e·0a20·2020·203c·7472·····</tr>.····<tr
 00000820:·3e0a·2020·2020·2020·3c74·643e·5231·3c2f··>.······<td>R1</
 00000830:·7464·3e0a·2020·2020·2020·3c74·643e·456e··td>.······<td>En
 00000840:·7375·7265·2053·4d41·5020·6973·206e·6f74··sure·SMAP·is·not
 00000850:·2064·6973·6162·6c65·6420·6475·7269·6e67···disabled·during
000004a0:·2020·2020·2054·6865·2053·4d45·5020·6973·······The·SMEP·is 
000004b0:·2075·7365·6420·746f·2070·7265·7665·6e74···used·to·prevent 
000004c0:·2074·6865·2073·7570·6572·7669·736f·7220···the·supervisor· 
000004d0:·6d6f·6465·2066·726f·6d20·6578·6563·7574··mode·from·execut 
000004e0:·696e·6720·7573·6572·2073·7061·6365·2063··ing·user·space·c 
000004f0:·6f64·652c·0a69·7420·6973·2065·6e61·626c··ode,.it·is·enabl 
00000500:·6564·2062·7920·6465·6661·756c·7420·7369··ed·by·default·si 
00000510:·6e63·6520·4c69·6e75·7820·6b65·726e·656c··nce·Linux·kernel 
00000520:·2033·2e30·2e20·4275·7420·6974·2063·6f75···3.0.·But·it·cou 
00000530:·6c64·2062·6520·6469·7361·626c·6564·2074··ld·be·disabled·t 
00000540:·6872·6f75·6768·0a6b·6572·6e65·6c20·626f··hrough.kernel·bo 
00000550:·6f74·2070·6172·616d·6574·6572·732e·0a0a··ot·parameters... 
00000560:·456e·7375·7265·2074·6861·7420·5375·7065··Ensure·that·Supe 
00000570:·7276·6973·6f72·204d·6f64·6520·4578·6563··rvisor·Mode·Exec 
00000580:·7574·696f·6e20·5072·6576·656e·7469·6f6e··ution·Prevention 
00000590:·2028·534d·4550·2920·6973·206e·6f74·2064···(SMEP)·is·not·d 
000005a0:·6973·6162·6c65·6420·6279·0a74·6865·203c··isabled·by.the·< 
000005b0:·7474·3e6e·6f73·6d65·703c·2f74·743e·2062··tt>nosmep</tt>·b 
000005c0:·6f6f·7420·7061·7261·6d65·6e74·6572·206f··oot·paramenter·o 
000005d0:·7074·696f·6e2e·0a0a·4368·6563·6b20·7468··ption...Check·th 
000005e0:·6174·2074·6865·206c·696e·6520·3c70·7265··at·the·line·<pre 
000005f0:·3e47·5255·425f·434d·444c·494e·455f·4c49··>GRUB_CMDLINE_LI 
00000600:·4e55·583d·222e·2e2e·223c·2f70·7265·3e20··NUX="..."</pre>· 
00000610:·7769·7468·696e·203c·7474·3e2f·6574·632f··within·<tt>/etc/ 
00000620:·6465·6661·756c·742f·6772·7562·3c2f·7474··default/grub</tt 
00000630:·3e0a·646f·6573·6e27·7420·636f·6e74·6169··>.doesn't·contai 
00000640:·6e20·7468·6520·6172·6775·6d65·6e74·203c··n·the·argument·< 
00000650:·7474·3e6e·6f73·6d65·703c·2f74·743e·2e0a··tt>nosmep</tt>.. 
00000660:·5275·6e20·7468·6520·666f·6c6c·6f77·696e··Run·the·followin 
00000670:·6720·636f·6d6d·616e·6420·746f·2075·7064··g·command·to·upd 
00000680:·6174·6520·636f·6d6d·616e·6420·6c69·6e65··ate·command·line 
00000690:·2066·6f72·2061·6c72·6561·6479·2069·6e73···for·already·ins 
000006a0:·7461·6c6c·6564·206b·6572·6e65·6c73·3a0a··talled·kernels:. 
000006b0:·3c70·7265·3e23·2067·7275·6262·7920·2d2d··<pre>#·grubby·-- 
000006c0:·7570·6461·7465·2d6b·6572·6e65·6c3d·414c··update-kernel=AL 
000006d0:·4c20·2d2d·7265·6d6f·7665·2d61·7267·733d··L·--remove-args= 
000006e0:·226e·6f73·6d65·7022·3c2f·7072·653e·0a20··"nosmep"</pre>.· 
000006f0:·2020·2020·203c·2f74·643e·0a20·2020·2020·······</td>.·····00000860:·2062·6f6f·743c·2f74·643e·0a20·2020·2020···boot</td>.·····
00000700:·203c·7464·2078·6d6c·3a6c·616e·673d·2265···<td·xml:lang="e00000870:·203c·7464·2078·6d6c·3a6c·616e·673d·2265···<td·xml:lang="e
00000710:·6e2d·5553·223e·0a20·2020·2020·2020·2044··n-US">.········D00000880:·6e2d·5553·223e·0a20·2020·2020·2020·2054··n-US">.········T
 00000890:·6865·2053·4d41·5020·6973·2075·7365·6420··he·SMAP·is·used·
 000008a0:·746f·2070·7265·7665·6e74·2074·6865·2073··to·prevent·the·s
 000008b0:·7570·6572·7669·736f·7220·6d6f·6465·2066··upervisor·mode·f
 000008c0:·726f·6d20·756e·696e·7465·6e74·696f·6e61··rom·unintentiona
 000008d0:·6c6c·7920·7265·6164·696e·672f·7772·6974··lly·reading/writ
 000008e0:·696e·6720·696e·746f·0a6d·656d·6f72·7920··ing·into.memory·
 000008f0:·7061·6765·7320·696e·2074·6865·2075·7365··pages·in·the·use
 00000900:·7220·7370·6163·652c·2069·7420·6973·2065··r·space,·it·is·e
 00000910:·6e61·626c·6564·2062·7920·6465·6661·756c··nabled·by·defaul
 00000920:·7420·7369·6e63·6520·4c69·6e75·7820·6b65··t·since·Linux·ke
 00000930:·726e·656c·2033·2e37·2e0a·4275·7420·6974··rnel·3.7..But·it
 00000940:·2063·6f75·6c64·2062·6520·6469·7361·626c···could·be·disabl
 00000950:·6564·2074·6872·6f75·6768·206b·6572·6e65··ed·through·kerne
Max diff block lines reached; 2965033/3001487 bytes (98.79%) of diff not shown.
661 KB
html2text {}
    
Offset 1, 35 lines modifiedOffset 1, 13 lines modified
  
  
1 Rules·with·ANSSI·Reference·in·Guide·to·the·Secure·Configuration·of·Oracle·Linux1 Rules·with·ANSSI·Reference·in·Guide·to·the·Secure·Configuration·of·Oracle·Linux
2 82 8
  
  
3 ······························The·SMEP·is·used·to·prevent·the·supervisor 
4 ······························mode·from·executing·user·space·code,·it·is 
5 ······························enabled·by·default·since·Linux·kernel·3.0. 
6 ······························But·it·could·be·disabled·through·kernel·boot 
7 ······························parameters.·Ensure·that·Supervisor·Mode 
8 ······························Execution·Prevention·(SMEP)·is·not·disabled··Disabling·SMEP·can·facilitate 
9 ····Ensure·SMEP·is·not········by·the·nosmep·boot·paramenter·option.·Check··exploitation·of·certain 
10 R1··disabled·during·boot······that·the·line································vulnerabilities·because·it·allows·the 
11 ······························GRUB_CMDLINE_LINUX="..."·····················kernel·to·unintentionally·execute·code 
12 ······························within·/etc/default/grub·doesn't·contain·the·in·less·privileged·memory·space. 
13 ······························argument·nosmep.·Run·the·following·command 
14 ······························to·update·command·line·for·already·installed 
15 ······························kernels: 
16 ······························#·grubby·--update-kernel=ALL·--remove- 
17 ······························args="nosmep" 
18 ···········································································Use·of·a·64-bit·operating·system 
19 ···········································································offers·a·few·advantages,·like·a·larger 
20 ····Prefer·to·use·a·64-bit····Prefer·installation·of·64-bit·operating······address·space·range·for·Address·Space 
21 R1··Operating·System·when·····systems·when·the·CPU·supports·it.············Layout·Randomization·(ASLR)·and 
22 ····supported······························································systematic·presence·of·No·eXecute·and 
23 ···········································································Execute·Disable·(NX/XD)·protection 
24 ···········································································bits. 
25 ······························Systems·that·are·using·the·64-bit·x86·kernel3 ······························Systems·that·are·using·the·64-bit·x86·kernel
26 ······························package·do·not·need·to·install·the·kernel-4 ······························package·do·not·need·to·install·the·kernel-
27 ······························PAE·package·because·the·64-bit·x86·kernel5 ······························PAE·package·because·the·64-bit·x86·kernel
28 ······························already·includes·this·support.·However,·if6 ······························already·includes·this·support.·However,·if
29 ······························the·system·is·32-bit·and·also·supports·the7 ······························the·system·is·32-bit·and·also·supports·the
30 ······························PAE·and·NX·features·as·determined·in·the·····On·32-bit·systems·that·support·the·XD8 ······························PAE·and·NX·features·as·determined·in·the·····On·32-bit·systems·that·support·the·XD
31 ····Install·PAE·Kernel·on·····previous·section,·the·kernel-PAE·package·····or·NX·bit,·the·vendor-supplied·PAE9 ····Install·PAE·Kernel·on·····previous·section,·the·kernel-PAE·package·····or·NX·bit,·the·vendor-supplied·PAE
Offset 62, 31 lines modifiedOffset 40, 53 lines modified
62 ······························Advanced·Encryption·Standard·(AES)·or·New····utilizing·encryption·to·protect·data.40 ······························Advanced·Encryption·Standard·(AES)·or·New····utilizing·encryption·to·protect·data.
63 ····Install·the·dracut-fips-··Instructions·(AES-NI)·engine,·the·system·····The·operating·system·must·implement41 ····Install·the·dracut-fips-··Instructions·(AES-NI)·engine,·the·system·····The·operating·system·must·implement
64 R1··aesni·Package·············requires·that·the·dracut-fips-aesni·package··cryptographic·modules·adhering·to·the42 R1··aesni·Package·············requires·that·the·dracut-fips-aesni·package··cryptographic·modules·adhering·to·the
65 ······························be·installed.·The·dracut-fips-aesni·package··higher·standards·approved·by·the43 ······························be·installed.·The·dracut-fips-aesni·package··higher·standards·approved·by·the
66 ······························can·be·installed·with·the·following·command:·federal·government·since·this·provides44 ······························can·be·installed·with·the·following·command:·federal·government·since·this·provides
67 ······························$·sudo·yum·install·dracut-fips-aesni·········assurance·they·have·been·tested·and45 ······························$·sudo·yum·install·dracut-fips-aesni·········assurance·they·have·been·tested·and
68 ···········································································validated.46 ···········································································validated.
 47 ······························The·SMEP·is·used·to·prevent·the·supervisor
 48 ······························mode·from·executing·user·space·code,·it·is
 49 ······························enabled·by·default·since·Linux·kernel·3.0.
 50 ······························But·it·could·be·disabled·through·kernel·boot
 51 ······························parameters.·Ensure·that·Supervisor·Mode
 52 ······························Execution·Prevention·(SMEP)·is·not·disabled··Disabling·SMEP·can·facilitate
 53 ····Ensure·SMEP·is·not········by·the·nosmep·boot·paramenter·option.·Check··exploitation·of·certain
 54 R1··disabled·during·boot······that·the·line································vulnerabilities·because·it·allows·the
 55 ······························GRUB_CMDLINE_LINUX="..."·····················kernel·to·unintentionally·execute·code
 56 ······························within·/etc/default/grub·doesn't·contain·the·in·less·privileged·memory·space.
 57 ······························argument·nosmep.·Run·the·following·command
 58 ······························to·update·command·line·for·already·installed
 59 ······························kernels:
 60 ······························#·grubby·--update-kernel=ALL·--remove-
 61 ······························args="nosmep"
 62 ···········································································Use·of·a·64-bit·operating·system
 63 ···········································································offers·a·few·advantages,·like·a·larger
 64 ····Prefer·to·use·a·64-bit····Prefer·installation·of·64-bit·operating······address·space·range·for·Address·Space
 65 R1··Operating·System·when·····systems·when·the·CPU·supports·it.············Layout·Randomization·(ASLR)·and
 66 ····supported······························································systematic·presence·of·No·eXecute·and
 67 ···········································································Execute·Disable·(NX/XD)·protection
 68 ···········································································bits.
69 ······························The·grub2·boot·loader·should·have·a69 ······························The·grub2·boot·loader·should·have·a
70 ······························superuser·account·and·password·protection70 ······························superuser·account·and·password·protection
71 ······························enabled·to·protect·boot-time·settings.·······Password·protection·on·the·boot·loader71 ······························enabled·to·protect·boot-time·settings.·······Password·protection·on·the·boot·loader
72 ···········································································configuration·ensures·users·with72 ···········································································configuration·ensures·users·with
73 ····Set·Boot·Loader·Password··Since·plaintext·passwords·are·a·security·····physical·access·cannot·trivially·alter73 ····Set·the·UEFI·Boot·Loader··Since·plaintext·passwords·are·a·security·····physical·access·cannot·trivially·alter
74 R5··in·grub2··················risk,·generate·a·hash·for·the·password·by····important·bootloader·settings.·These74 R5··Password··················risk,·generate·a·hash·for·the·password·by····important·bootloader·settings.·These
75 ······························running·the·following·command:···············include·which·kernel·to·use,·and75 ······························running·the·following·command:···············include·which·kernel·to·use,·and
76 ······························#·grub2-setpassword··························whether·to·enter·single-user·mode.76 ······························#·grub2-setpassword··························whether·to·enter·single-user·mode.
77 ······························When·prompted,·enter·the·password·that·was77 ······························When·prompted,·enter·the·password·that·was
78 ······························selected.78 ······························selected.
  
79 ······························The·grub2·boot·loader·should·have·a79 ······························The·grub2·boot·loader·should·have·a
80 ······························superuser·account·and·password·protection80 ······························superuser·account·and·password·protection
81 ······························enabled·to·protect·boot-time·settings.·······Password·protection·on·the·boot·loader81 ······························enabled·to·protect·boot-time·settings.·······Password·protection·on·the·boot·loader
82 ···········································································configuration·ensures·users·with82 ···········································································configuration·ensures·users·with
83 ····Set·the·UEFI·Boot·Loader··Since·plaintext·passwords·are·a·security·····physical·access·cannot·trivially·alter83 ····Set·Boot·Loader·Password··Since·plaintext·passwords·are·a·security·····physical·access·cannot·trivially·alter
84 R5··Password··················risk,·generate·a·hash·for·the·password·by····important·bootloader·settings.·These84 R5··in·grub2··················risk,·generate·a·hash·for·the·password·by····important·bootloader·settings.·These
85 ······························running·the·following·command:···············include·which·kernel·to·use,·and85 ······························running·the·following·command:···············include·which·kernel·to·use,·and
86 ······························#·grub2-setpassword··························whether·to·enter·single-user·mode.86 ······························#·grub2-setpassword··························whether·to·enter·single-user·mode.
87 ······························When·prompted,·enter·the·password·that·was87 ······························When·prompted,·enter·the·password·that·was
88 ······························selected.88 ······························selected.
  
89 ······························On·x86·architecture·supporting·VT-d,·the89 ······························On·x86·architecture·supporting·VT-d,·the
90 ······························IOMMU·manages·the·access·control·policy90 ······························IOMMU·manages·the·access·control·policy
Offset 99, 77 lines modifiedOffset 99, 14 lines modified
99 ······························systems.·Modify·the·line·within·/etc/········hardware·devices.99 ······························systems.·Modify·the·line·within·/etc/········hardware·devices.
100 ······························default/grub·as·shown·below:100 ······························default/grub·as·shown·below:
101 ······························GRUB_CMDLINE_LINUX="...·iommu=force·..."101 ······························GRUB_CMDLINE_LINUX="...·iommu=force·..."
102 ······························Run·the·following·command·to·update·command102 ······························Run·the·following·command·to·update·command
103 ······························line·for·already·installed·kernels:103 ······························line·for·already·installed·kernels:
104 ······························#·grubby·--update-kernel=ALL·--104 ······························#·grubby·--update-kernel=ALL·--
105 ······························args="iommu=force"105 ······························args="iommu=force"
106 ······························To·enable·poisoning·of·SLUB/SLAB·objects, 
107 ······························add·the·argument·slub_debug=P·to·the·default 
108 ······························GRUB·2·command·line·for·the·Linux·operating··Poisoning·writes·an·arbitrary·value·to 
109 ······························system.·To·ensure·that·slub_debug=P·is·added·freed·objects,·so·any·modification·or 
110 ······························as·a·kernel·command·line·argument·to·newly···reference·to·that·object·after·being 
111 ······························installed·kernels,·add·slub_debug=P·to·the···freed·or·before·being·initialized·will 
112 R8··Enable·SLUB/SLAB··········default·Grub2·command·line·for·Linux·········be·detected·and·prevented.·This 
113 ····allocator·poisoning·······operating·systems.·Modify·the·line·within·/··prevents·many·types·of·use-after-free 
114 ······························etc/default/grub·as·shown·below:·············vulnerabilities·at·little·performance 
115 ······························GRUB_CMDLINE_LINUX="...·slub_debug=P·..."····cost.·Also·prevents·leak·of·data·and 
116 ······························Run·the·following·command·to·update·command··detection·of·corrupted·memory. 
117 ······························line·for·already·installed·kernels: 
118 ······························#·grubby·--update-kernel=ALL·-- 
119 ······························args="slub_debug=P" 
120 ······························L1·Terminal·Fault·(L1TF)·is·a·hardware 
121 ······························vulnerability·which·allows·unprivileged 
122 ······························speculative·access·to·data·which·is 
123 ······························available·in·the·Level·1·Data·Cache·when·the 
124 ······························page·table·entry·isn't·present.·Select·the 
125 ······························appropriate·mitigation·by·adding·the 
126 ······························argument·l1tf=flush·to·the·default·GRUB·2 
127 ······························command·line·for·the·Linux·operating·system. 
128 ······························To·ensure·that·l1tf=flush·is·added·as·a······The·L1TF·vulnerability·allows·an 
129 ······························kernel·command·line·argument·to·newly········attacker·to·bypass·memory·access 
130 ····Configure·L1·Terminal·····installed·kernels,·add·l1tf=flush·to·the·····security·controls·imposed·by·the 
131 R8··Fault·mitigations·········default·Grub2·command·line·for·Linux·········system·or·hypervisor.·The·L1TF 
132 ······························operating·systems.·Modify·the·line·within·/··vulnerability·allows·read·access·to 
133 ······························etc/default/grub·as·shown·below:·············any·physical·memory·location·that·is 
134 ······························GRUB_CMDLINE_LINUX="...·l1tf=flush·..."······cached·in·the·L1·Data·Cache. 
135 ······························Run·the·following·command·to·update·command 
Max diff block lines reached; 662542/677087 bytes (97.85%) of diff not shown.
1.24 MB
./usr/share/doc/ssg-nondebian/table-ol8-cuirefs.html
Ordering differences only
    
Offset 40, 90 lines modifiedOffset 40, 14 lines modified
40 ····<th>Mapping</th>40 ····<th>Mapping</th>
41 ····<th>Rule·Title</th>41 ····<th>Rule·Title</th>
42 ····<th>Description</th>42 ····<th>Description</th>
43 ····<th>Rationale</th>43 ····<th>Rationale</th>
44 ··</thead>44 ··</thead>
45 ··<tbody>45 ··<tbody>
46 ··<tr>46 ··<tr>
47 ······<td>3.1.1<br/>3.1.5</td> 
48 ······<td>Verify·Only·Root·Has·UID·0</td> 
49 ······<td·xml:lang="en-US"> 
50 ········If·any·account·other·than·root·has·a·UID·of·0,·this·misconfiguration·should 
51 be·investigated·and·the·accounts·other·than·root·should·be·removed·or·have 
52 their·UID·changed. 
53 <br·/> 
54 If·the·account·is·associated·with·system·commands·or·applications·the·UID 
55 should·be·changed·to·one·greater·than·"0"·but·less·than·"1000." 
56 Otherwise·assign·a·UID·greater·than·"1000"·that·has·not·already·been 
57 assigned. 
58 ······</td> 
59 ······<td·xml:lang="en-US"> 
60 ········An·account·has·root·authority·if·it·has·a·UID·of·0.·Multiple·accounts 
61 with·a·UID·of·0·afford·more·opportunity·for·potential·intruders·to 
62 guess·a·password·for·a·privileged·account.·Proper·configuration·of 
63 sudo·is·recommended·to·afford·multiple·system·administrators 
64 access·to·root·privileges·in·an·accountable·manner. 
65 ······</td> 
66 ····</tr> 
67 ····<tr> 
68 ······<td>3.1.1<br/>3.1.5</td> 
69 ······<td>Disable·SSH·Root·Login</td> 
70 ······<td·xml:lang="en-US"> 
71 ········The·root·user·should·never·be·allowed·to·login·to·a 
72 system·directly·over·a·network. 
73 To·disable·root·login·via·SSH,·add·or·correct·the·following·line·in 
  
  
74 <tt>/etc/ssh/sshd_config</tt>: 
  
75 <pre>PermitRootLogin·no</pre> 
76 ······</td> 
77 ······<td·xml:lang="en-US"> 
78 ········Even·though·the·communications·channel·may·be·encrypted,·an·additional·layer·of 
79 security·is·gained·by·extending·the·policy·of·not·logging·directly·on·as·root. 
80 In·addition,·logging·in·with·a·user-specific·account·provides·individual 
81 accountability·of·actions·performed·on·the·system·and·also·helps·to·minimize 
82 direct·attack·attempts·on·root's·password. 
83 ······</td> 
84 ····</tr> 
85 ····<tr> 
86 ······<td>3.1.1<br/>3.4.5</td> 
87 ······<td>Require·Authentication·for·Emergency·Systemd·Target</td> 
88 ······<td·xml:lang="en-US"> 
89 ········Emergency·mode·is·intended·as·a·system·recovery 
90 method,·providing·a·single·user·root·access·to·the·system 
91 during·a·failed·boot·sequence. 
92 <br·/><br·/> 
93 By·default,·Emergency·mode·is·protected·by·requiring·a·password·and·is·set 
94 in·<tt>/usr/lib/systemd/system/emergency.service</tt>. 
95 ······</td> 
96 ······<td·xml:lang="en-US"> 
97 ········This·prevents·attackers·with·physical·access·from·trivially·bypassing·security 
98 on·the·machine·and·gaining·root·access.·Such·accesses·are·further·prevented 
99 by·configuring·the·bootloader·password. 
100 ······</td> 
101 ····</tr> 
102 ····<tr> 
103 ······<td>3.1.1</td> 
104 ······<td>Disable·GDM·Automatic·Login</td> 
105 ······<td·xml:lang="en-US"> 
106 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·automatically·login·without 
107 user·interaction·or·credentials.·User·should·always·be·required·to·authenticate·themselves 
108 to·the·system·that·they·are·authorized·to·use.·To·disable·user·ability·to·automatically 
109 login·to·the·system,·set·the·<tt>AutomaticLoginEnable</tt>·to·<tt>false</tt>·in·the 
110 <tt>[daemon]</tt>·section·in·<tt>/etc/gdm/custom.conf</tt>.·For·example: 
111 <pre>[daemon] 
112 AutomaticLoginEnable=false</pre> 
113 ······</td> 
114 ······<td·xml:lang="en-US"> 
115 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating 
116 system·security. 
117 ······</td> 
118 ····</tr> 
119 ····<tr> 
120 ······<td>3.1.1</td>47 ······<td>3.1.1</td>
121 ······<td>Disable·GDM·Guest·Login</td>48 ······<td>Disable·GDM·Guest·Login</td>
122 ······<td·xml:lang="en-US">49 ······<td·xml:lang="en-US">
123 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·login·without·credentials50 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·login·without·credentials
124 which·can·be·useful·for·public·kiosk·scenarios.·Allowing·users·to·login·without·credentials51 which·can·be·useful·for·public·kiosk·scenarios.·Allowing·users·to·login·without·credentials
125 or·"guest"·account·access·has·inherent·security·risks·and·should·be·disabled.·To·do·disable52 or·"guest"·account·access·has·inherent·security·risks·and·should·be·disabled.·To·do·disable
126 timed·logins·or·guest·account·access,·set·the·<tt>TimedLoginEnable</tt>·to·<tt>false</tt>·in53 timed·logins·or·guest·account·access,·set·the·<tt>TimedLoginEnable</tt>·to·<tt>false</tt>·in
Offset 153, 14 lines modifiedOffset 77, 57 lines modified
153 ······<td·xml:lang="en-US">77 ······<td·xml:lang="en-US">
154 ········If·an·account·has·an·empty·password,·anyone·could·log·in·and78 ········If·an·account·has·an·empty·password,·anyone·could·log·in·and
155 run·commands·with·the·privileges·of·that·account.·Accounts·with79 run·commands·with·the·privileges·of·that·account.·Accounts·with
156 empty·passwords·should·never·be·used·in·operational·environments.80 empty·passwords·should·never·be·used·in·operational·environments.
157 ······</td>81 ······</td>
158 ····</tr>82 ····</tr>
159 ····<tr>83 ····<tr>
 84 ······<td>3.1.1<br/>3.1.6</td>
 85 ······<td>Direct·root·Logins·Not·Allowed</td>
 86 ······<td·xml:lang="en-US">
 87 ········To·further·limit·access·to·the·<tt>root</tt>·account,·administrators
 88 can·disable·root·logins·at·the·console·by·editing·the·<tt>/etc/securetty</tt>·file.
 89 This·file·lists·all·devices·the·root·user·is·allowed·to·login·to.·If·the·file·does
 90 not·exist·at·all,·the·root·user·can·login·through·any·communication·device·on·the
 91 system,·whether·via·the·console·or·via·a·raw·network·interface.·This·is·dangerous
 92 as·user·can·login·to·the·system·as·root·via·Telnet,·which·sends·the·password·in
 93 plain·text·over·the·network.·By·default,·Oracle·Linux·8's
 94 <tt>/etc/securetty</tt>·file·only·allows·the·root·user·to·login·at·the·console
 95 physically·attached·to·the·system.·To·prevent·root·from·logging·in,·remove·the
 96 contents·of·this·file.·To·prevent·direct·root·logins,·remove·the·contents·of·this
 97 file·by·typing·the·following·command:
 98 <pre>
 99 $·sudo·echo·&gt;·/etc/securetty
 100 </pre>
 101 ······</td>
 102 ······<td·xml:lang="en-US">
 103 ········Disabling·direct·root·logins·ensures·proper·accountability·and·multifactor
 104 authentication·to·privileged·accounts.·Users·will·first·login,·then·escalate
 105 to·privileged·(root)·access·via·su·/·sudo.·This·is·required·for·FISMA·Low
 106 and·FISMA·Moderate·systems.
 107 ······</td>
 108 ····</tr>
 109 ····<tr>
 110 ······<td>3.1.1<br/>3.1.5</td>
 111 ······<td>Restrict·Virtual·Console·Root·Logins</td>
 112 ······<td·xml:lang="en-US">
Max diff block lines reached; 463868/469811 bytes (98.74%) of diff not shown.
810 KB
html2text {}
    
Offset 1, 73 lines modifiedOffset 1, 13 lines modified
  
  
1 Rules·with·NIST-800-171·Reference·in·Guide·to·the·Secure·Configuration·of1 Rules·with·NIST-800-171·Reference·in·Guide·to·the·Secure·Configuration·of
2 Oracle·Linux·82 Oracle·Linux·8
  
  
3 ······························································································An·account·has·root 
4 ······························································································authority·if·it·has 
5 ······························································································a·UID·of·0.·Multiple 
6 ······························································································accounts·with·a·UID 
7 ·······································If·any·account·other·than·root·has·a·UID·of·0,·this····of·0·afford·more 
8 ·······································misconfiguration·should·be·investigated·and·the········opportunity·for 
9 ·······································accounts·other·than·root·should·be·removed·or·have·····potential·intruders 
10 ·······································their·UID·changed.·····································to·guess·a·password 
11 3.1.1···Verify·Only·Root·Has·UID·0·····If·the·account·is·associated·with·system·commands·or···for·a·privileged 
12 3.1.5··································applications·the·UID·should·be·changed·to·one·greater··account.·Proper 
13 ·······································than·"0"·but·less·than·"1000."·Otherwise·assign·a·UID··configuration·of 
14 ·······································greater·than·"1000"·that·has·not·already·been··········sudo·is·recommended 
15 ·······································assigned.··············································to·afford·multiple 
16 ······························································································system 
17 ······························································································administrators 
18 ······························································································access·to·root 
19 ······························································································privileges·in·an 
20 ······························································································accountable·manner. 
21 ······························································································Even·though·the 
22 ······························································································communications 
23 ······························································································channel·may·be 
24 ······························································································encrypted,·an 
25 ······························································································additional·layer·of 
26 ······························································································security·is·gained 
27 ······························································································by·extending·the 
28 ······························································································policy·of·not 
29 ·······································The·root·user·should·never·be·allowed·to·login·to·a····logging·directly·on 
30 3.1.1··································system·directly·over·a·network.·To·disable·root·login··as·root.·In 
31 3.1.5···Disable·SSH·Root·Login·········via·SSH,·add·or·correct·the·following·line·in·/etc/····addition,·logging·in 
32 ·······································ssh/sshd_config:·······································with·a·user-specific 
33 ·······································PermitRootLogin·no·····································account·provides 
34 ······························································································individual 
35 ······························································································accountability·of 
36 ······························································································actions·performed·on 
37 ······························································································the·system·and·also 
38 ······························································································helps·to·minimize 
39 ······························································································direct·attack 
40 ······························································································attempts·on·root's 
41 ······························································································password. 
42 ······························································································This·prevents 
43 ······························································································attackers·with 
44 ·······································Emergency·mode·is·intended·as·a·system·recovery········physical·access·from 
45 ·······································method,·providing·a·single·user·root·access·to·the·····trivially·bypassing 
46 3.1.1···Require·Authentication·for·····system·during·a·failed·boot·sequence.··················security·on·the 
47 3.4.5···Emergency·Systemd·Target······························································machine·and·gaining 
48 ·······································By·default,·Emergency·mode·is·protected·by·requiring·a·root·access.·Such 
49 ·······································password·and·is·set·in·/usr/lib/systemd/system/········accesses·are·further 
50 ·······································emergency.service.·····································prevented·by 
51 ······························································································configuring·the 
52 ······························································································bootloader·password. 
53 ·······································The·GNOME·Display·Manager·(GDM)·can·allow·users·to 
54 ·······································automatically·login·without·user·interaction·or 
55 ·······································credentials.·User·should·always·be·required·to·········Failure·to·restrict 
56 ·······································authenticate·themselves·to·the·system·that·they·are····system·access·to 
57 3.1.1···Disable·GDM·Automatic·Login····authorized·to·use.·To·disable·user·ability·to··········authenticated·users 
58 ·······································automatically·login·to·the·system,·set·the·············negatively·impacts 
59 ·······································AutomaticLoginEnable·to·false·in·the·[daemon]·section··operating·system 
60 ·······································in·/etc/gdm/custom.conf.·For·example:··················security. 
61 ·······································[daemon] 
62 ·······································AutomaticLoginEnable=false 
63 ·······································The·GNOME·Display·Manager·(GDM)·can·allow·users·to3 ·······································The·GNOME·Display·Manager·(GDM)·can·allow·users·to
64 ·······································login·without·credentials·which·can·be·useful·for4 ·······································login·without·credentials·which·can·be·useful·for
65 ·······································public·kiosk·scenarios.·Allowing·users·to·login········Failure·to·restrict5 ·······································public·kiosk·scenarios.·Allowing·users·to·login········Failure·to·restrict
66 ·······································without·credentials·or·"guest"·account·access·has······system·access·to6 ·······································without·credentials·or·"guest"·account·access·has······system·access·to
67 3.1.1···Disable·GDM·Guest·Login········inherent·security·risks·and·should·be·disabled.·To·do··authenticated·users7 3.1.1···Disable·GDM·Guest·Login········inherent·security·risks·and·should·be·disabled.·To·do··authenticated·users
68 ·······································disable·timed·logins·or·guest·account·access,·set·the··negatively·impacts8 ·······································disable·timed·logins·or·guest·account·access,·set·the··negatively·impacts
69 ·······································TimedLoginEnable·to·false·in·the·[daemon]·section·in·/·operating·system9 ·······································TimedLoginEnable·to·false·in·the·[daemon]·section·in·/·operating·system
Offset 81, 162 lines modifiedOffset 21, 144 lines modified
81 3.1.1···Prevent·Login·to·Accounts·With·it·may·be·possible·to·log·into·the·account·without·····with·the·privileges21 3.1.1···Prevent·Login·to·Accounts·With·it·may·be·possible·to·log·into·the·account·without·····with·the·privileges
82 3.1.5···Empty·Password·················authentication.·Remove·any·instances·of·the·nullok·in··of·that·account.22 3.1.5···Empty·Password·················authentication.·Remove·any·instances·of·the·nullok·in··of·that·account.
83 ·······································/etc/pam.d/system-auth·and·/etc/pam.d/password-auth·to·Accounts·with·empty23 ·······································/etc/pam.d/system-auth·and·/etc/pam.d/password-auth·to·Accounts·with·empty
84 ·······································prevent·logins·with·empty·passwords.···················passwords·should24 ·······································prevent·logins·with·empty·passwords.···················passwords·should
85 ······························································································never·be·used·in25 ······························································································never·be·used·in
86 ······························································································operational26 ······························································································operational
87 ······························································································environments.27 ······························································································environments.
 28 ·······································To·further·limit·access·to·the·root·account,
 29 ·······································administrators·can·disable·root·logins·at·the·console··Disabling·direct
 30 ·······································by·editing·the·/etc/securetty·file.·This·file·lists····root·logins·ensures
 31 ·······································all·devices·the·root·user·is·allowed·to·login·to.·If···proper
 32 ·······································the·file·does·not·exist·at·all,·the·root·user·can······accountability·and
 33 ·······································login·through·any·communication·device·on·the·system,··multifactor
 34 ·······································whether·via·the·console·or·via·a·raw·network···········authentication·to
 35 3.1.1··································interface.·This·is·dangerous·as·user·can·login·to·the··privileged·accounts.
 36 3.1.6···Direct·root·Logins·Not·Allowed·system·as·root·via·Telnet,·which·sends·the·password·in·Users·will·first
 37 ·······································plain·text·over·the·network.·By·default,·Oracle·Linux··login,·then·escalate
 38 ·······································8's·/etc/securetty·file·only·allows·the·root·user·to···to·privileged·(root)
 39 ·······································login·at·the·console·physically·attached·to·the········access·via·su·/
 40 ·······································system.·To·prevent·root·from·logging·in,·remove·the····sudo.·This·is
 41 ·······································contents·of·this·file.·To·prevent·direct·root·logins,··required·for·FISMA
 42 ·······································remove·the·contents·of·this·file·by·typing·the·········Low·and·FISMA
 43 ·······································following·command:·····································Moderate·systems.
 44 ·······································$·sudo·echo·>·/etc/securetty
 45 ·······································To·restrict·root·logins·through·the·(deprecated)·······Preventing·direct
 46 ·······································virtual·console·devices,·ensure·lines·of·this·form·do··root·login·to
 47 ·······································not·appear·in·/etc/securetty:··························virtual·console
 48 3.1.1···Restrict·Virtual·Console·Root··vc/1···················································devices·helps·ensure
 49 3.1.5···Logins·························vc/2···················································accountability·for
 50 ·······································vc/3···················································actions·taken·on·the
 51 ·······································vc/4···················································system·using·the
 52 ······························································································root·account.
88 ·······································Disallow·SSH·login·with·empty·passwords.·The·default53 ·······································Disallow·SSH·login·with·empty·passwords.·The·default
89 ·······································SSH·configuration·disables·logins·with·empty···········Configuring·this54 ·······································SSH·configuration·disables·logins·with·empty···········Configuring·this
90 ·······································passwords.·The·appropriate·configuration·is·used·if·no·setting·for·the·SSH55 ·······································passwords.·The·appropriate·configuration·is·used·if·no·setting·for·the·SSH
91 ·······································value·is·set·for·PermitEmptyPasswords.·················daemon·provides56 ·······································value·is·set·for·PermitEmptyPasswords.·················daemon·provides
92 ·······································To·explicitly·disallow·SSH·login·from·accounts·with····additional·assurance57 ·······································To·explicitly·disallow·SSH·login·from·accounts·with····additional·assurance
93 3.1.1···Disable·SSH·Access·via·Empty···empty·passwords,·add·or·correct·the·following·line·in··that·remote·login58 3.1.1···Disable·SSH·Access·via·Empty···empty·passwords,·add·or·correct·the·following·line·in··that·remote·login
94 3.1.5···Passwords······················/etc/ssh/sshd_config:··································via·SSH·will·require59 3.1.5···Passwords······················/etc/ssh/sshd_config:··································via·SSH·will·require
95 ·······································PermitEmptyPasswords·no································a·password,·even·in60 ·······································PermitEmptyPasswords·no································a·password,·even·in
96 ·······································Any·accounts·with·empty·passwords·should·be·disabled···the·event·of61 ·······································Any·accounts·with·empty·passwords·should·be·disabled···the·event·of
97 ·······································immediately,·and·PAM·configuration·should·prevent······misconfiguration62 ·······································immediately,·and·PAM·configuration·should·prevent······misconfiguration
98 ·······································users·from·being·able·to·assign·themselves·empty·······elsewhere.63 ·······································users·from·being·able·to·assign·themselves·empty·······elsewhere.
99 ·······································passwords.64 ·······································passwords.
100 ·······································To·restrict·root·logins·through·the·(deprecated)·······Preventing·direct 
101 ·······································virtual·console·devices,·ensure·lines·of·this·form·do··root·login·to 
102 ·······································not·appear·in·/etc/securetty:··························virtual·console 
103 3.1.1···Restrict·Virtual·Console·Root··vc/1···················································devices·helps·ensure 
104 3.1.5···Logins·························vc/2···················································accountability·for65 ·······································The·GNOME·Display·Manager·(GDM)·can·allow·users·to
 66 ·······································automatically·login·without·user·interaction·or
 67 ·······································credentials.·User·should·always·be·required·to·········Failure·to·restrict
 68 ·······································authenticate·themselves·to·the·system·that·they·are····system·access·to
 69 3.1.1···Disable·GDM·Automatic·Login····authorized·to·use.·To·disable·user·ability·to··········authenticated·users
Max diff block lines reached; 813299/829876 bytes (98.00%) of diff not shown.
3.25 KB
./usr/share/doc/ssg-nondebian/table-ol8-nistrefs-ospp.html
    
Offset 4102, 15 lines modifiedOffset 4102, 15 lines modified
4102 <tt>RekeyLimit</tt>.4102 <tt>RekeyLimit</tt>.
4103 ··</td>4103 ··</td>
4104 ··<td·xml:lang="en-US">4104 ··<td·xml:lang="en-US">
4105 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling4105 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling
4106 time-based·limit,·effects·of·potential·attacks·against4106 time-based·limit,·effects·of·potential·attacks·against
4107 encryption·keys·are·limited.4107 encryption·keys·are·limited.
4108 ··</td>4108 ··</td>
4109 ··<td>var_ssh_client_rekey_limit_time=1hour<br/>var_ssh_client_rekey_limit_size=1G</td>4109 ··<td>var_ssh_client_rekey_limit_size=1G<br/>var_ssh_client_rekey_limit_time=1hour</td>
4110 </tr>4110 </tr>
4111 <tr>4111 <tr>
4112 ··<td></td>4112 ··<td></td>
4113 ··<td>N/A</td>4113 ··<td>N/A</td>
4114 ··<td>SSH·client·uses·strong·entropy·to·seed·(for·CSH·like·shells)</td>4114 ··<td>SSH·client·uses·strong·entropy·to·seed·(for·CSH·like·shells)</td>
4115 ··<td·xml:lang="en-US">4115 ··<td·xml:lang="en-US">
4116 To·set·up·SSH·client·to·use·entropy·from·a·high-quality·source,·make·sure4116 To·set·up·SSH·client·to·use·entropy·from·a·high-quality·source,·make·sure
2.51 KB
html2text {}
    
Offset 3301, 16 lines modifiedOffset 3301, 16 lines modified
3301 ·····A··rsyslog·remote···echo·'global(DefaultNetstreamDriverCAFile="/etc/pki/tls/cert.pem")'·>>·/etc/rsyslog.conf·error:·ca3301 ·····A··rsyslog·remote···echo·'global(DefaultNetstreamDriverCAFile="/etc/pki/tls/cert.pem")'·>>·/etc/rsyslog.conf·error:·ca
3302 ········logging··········Replace·the·/etc/pki/tls/cert.pem·in·the·above·command·with·the·path·to·the·file·with·CA·certificate·is·not3302 ········logging··········Replace·the·/etc/pki/tls/cert.pem·in·the·above·command·with·the·path·to·the·file·with·CA·certificate·is·not
3303 ·························certificate·generated·for·the·purpose·of·remote·logging.·································set,·cannot3303 ·························certificate·generated·for·the·purpose·of·remote·logging.·································set,·cannot
3304 ··················································································································continue3304 ··················································································································continue
3305 ·························The·RekeyLimit·parameter·specifies·how·often·the·session·key·is·renegotiated,·both·in····By·decreasing·the3305 ·························The·RekeyLimit·parameter·specifies·how·often·the·session·key·is·renegotiated,·both·in····By·decreasing·the
3306 ·························terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.·To·decrease·the····limit·based·on·the3306 ·························terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.·To·decrease·the····limit·based·on·the
3307 ········Configure········default·limits,·put·line·RekeyLimit·1G·1hour·to·file·/etc/ssh/ssh_config.d/02-rekey-·····amount·of·data·and3307 ········Configure········default·limits,·put·line·RekeyLimit·1G·1hour·to·file·/etc/ssh/ssh_config.d/02-rekey-·····amount·of·data·and
3308 ·····N/·session··········limit.conf.·Make·sure·that·there·is·no·other·RekeyLimit·configuration·preceding·the······enabling·time-based·var_ssh_client_rekey_limit_time=1hour3308 ·····N/·session··········limit.conf.·Make·sure·that·there·is·no·other·RekeyLimit·configuration·preceding·the······enabling·time-based·var_ssh_client_rekey_limit_size=1G
3309 ·····A··renegotiation····include·directive·in·the·main·config·file·/etc/ssh/ssh_config.·Check·also·other·files·in·limit,·effects·of···var_ssh_client_rekey_limit_size=1G3309 ·····A··renegotiation····include·directive·in·the·main·config·file·/etc/ssh/ssh_config.·Check·also·other·files·in·limit,·effects·of···var_ssh_client_rekey_limit_time=1hour
3310 ········for·SSH·client···/etc/ssh/ssh_config.d·directory.·Files·are·processed·according·to·lexicographical·order··potential·attacks3310 ········for·SSH·client···/etc/ssh/ssh_config.d·directory.·Files·are·processed·according·to·lexicographical·order··potential·attacks
3311 ·························of·file·names.·Make·sure·that·there·is·no·file·processed·before·02-rekey-limit.conf······against·encryption3311 ·························of·file·names.·Make·sure·that·there·is·no·file·processed·before·02-rekey-limit.conf······against·encryption
3312 ·························containing·definition·of·RekeyLimit.·····················································keys·are·limited.3312 ·························containing·definition·of·RekeyLimit.·····················································keys·are·limited.
3313 ··················································································································Some·SSH3313 ··················································································································Some·SSH
3314 ··················································································································implementations·use3314 ··················································································································implementations·use
3315 ··················································································································the·openssl·library3315 ··················································································································the·openssl·library
3316 ··················································································································for·entropy,·which3316 ··················································································································for·entropy,·which
9.46 MB
./usr/share/doc/ssg-nondebian/table-ol8-nistrefs.html
    
Offset 66, 15040 lines modifiedOffset 66, 15040 lines modified
00000410:·0a20·2020·203c·7468·3e52·6174·696f·6e61··.····<th>Rationa00000410:·0a20·2020·203c·7468·3e52·6174·696f·6e61··.····<th>Rationa
00000420:·6c65·3c2f·7468·3e0a·2020·3c2f·7468·6561··le</th>.··</thea00000420:·6c65·3c2f·7468·3e0a·2020·3c2f·7468·6561··le</th>.··</thea
00000430:·643e·0a20·203c·7462·6f64·793e·0a20·203c··d>.··<tbody>.··<00000430:·643e·0a20·203c·7462·6f64·793e·0a20·203c··d>.··<tbody>.··<
00000440:·7472·3e0a·2020·2020·2020·3c74·643e·4155··tr>.······<td>AU00000440:·7472·3e0a·2020·2020·2020·3c74·643e·4155··tr>.······<td>AU
00000450:·2d32·2861·293c·2f74·643e·0a20·2020·2020··-2(a)</td>.·····00000450:·2d32·2861·293c·2f74·643e·0a20·2020·2020··-2(a)</td>.·····
00000460:·203c·7464·3e43·6f6e·6669·6775·7265·2061···<td>Configure·a00000460:·203c·7464·3e43·6f6e·6669·6775·7265·2061···<td>Configure·a
Diff chunk too large, falling back to line-by-line diff (12426 lines added, 12426 lines removed)
00000470:·7564·6974·696e·6720·6f66·2075·6e73·7563··uditing·of·unsuc00000470:·7564·6974·696e·6720·6f66·2075·6e73·7563··uditing·of·unsuc
00000480:·6365·7373·6675·6c20·6669·6c65·2061·6363··cessful·file·acc00000480:·6365·7373·6675·6c20·6669·6c65·206d·6f64··cessful·file·mod
00000490:·6573·7365·733c·2f74·643e·0a20·2020·2020··esses</td>.·····00000490:·6966·6963·6174·696f·6e73·3c2f·7464·3e0a··ifications</td>.
000004a0:·203c·7464·2078·6d6c·3a6c·616e·673d·2265···<td·xml:lang="e000004a0:·2020·2020·2020·3c74·6420·786d·6c3a·6c61········<td·xml:la
000004b0:·6e2d·5553·223e·0a20·2020·2020·2020·2045··n-US">.········E000004b0:·6e67·3d22·656e·2d55·5322·3e0a·2020·2020··ng="en-US">.····
000004c0:·6e73·7572·6520·7468·6174·2075·6e73·7563··nsure·that·unsuc000004c0:·2020·2020·456e·7375·7265·2074·6861·7420······Ensure·that·
000004d0:·6365·7373·6675·6c20·6174·7465·6d70·7473··cessful·attempts000004d0:·756e·7375·6363·6573·7366·756c·2061·7474··unsuccessful·att
000004e0:·2074·6f20·6163·6365·7373·2061·2066·696c···to·access·a·fil000004e0:·656d·7074·7320·746f·206d·6f64·6966·7920··empts·to·modify·
000004f0:·6520·6172·6520·6175·6469·7465·642e·0a0a··e·are·audited...000004f0:·6120·6669·6c65·2061·7265·2061·7564·6974··a·file·are·audit
00000500:·5468·6520·666f·6c6c·6f77·696e·6720·7275··The·following·ru00000500:·6564·2e0a·0a54·6865·2066·6f6c·6c6f·7769··ed...The·followi
00000510:·6c65·7320·636f·6e66·6967·7572·6520·6175··les·configure·au00000510:·6e67·2072·756c·6573·2063·6f6e·6669·6775··ng·rules·configu
00000520:·6469·7420·6173·2064·6573·6372·6962·6564··dit·as·described00000520:·7265·2061·7564·6974·2061·7320·6465·7363··re·audit·as·desc
00000530:·2061·626f·7665·3a0a·3c70·7265·3e23·2320···above:.<pre>##·00000530:·7269·6265·6420·6162·6f76·653a·0a3c·7072··ribed·above:.<pr
00000540:·556e·7375·6363·6573·7366·756c·2066·696c··Unsuccessful·fil00000540:·653e·2323·2055·6e73·7563·6365·7373·6675··e>##·Unsuccessfu
00000550:·6520·6163·6365·7373·2028·616e·7920·6f74··e·access·(any·ot00000550:·6c20·6669·6c65·206d·6f64·6966·6963·6174··l·file·modificat
00000560:·6865·7220·6f70·656e·7329·2054·6869·7320··her·opens)·This·00000560:·696f·6e73·2028·6f70·656e·2066·6f72·2077··ions·(open·for·w
00000570:·6861·7320·746f·2067·6f20·6c61·7374·2e0a··has·to·go·last..00000570:·7269·7465·206f·7220·7472·756e·6361·7465··rite·or·truncate
00000580:·2d61·2061·6c77·6179·732c·6578·6974·202d··-a·always,exit·-00000580:·290a·2d61·2061·6c77·6179·732c·6578·6974··).-a·always,exit
00000590:·4620·6172·6368·3d62·3332·202d·5320·6f70··F·arch=b32·-S·op00000590:·202d·4620·6172·6368·3d62·3332·202d·5320···-F·arch=b32·-S·
000005a0:·656e·2c6f·7065·6e61·742c·6f70·656e·6174··en,openat,openat000005a0:·6f70·656e·6174·2c6f·7065·6e5f·6279·5f68··openat,open_by_h
000005b0:·322c·6f70·656e·5f62·795f·6861·6e64·6c65··2,open_by_handle000005b0:·616e·646c·655f·6174·202d·4620·6132·2661··andle_at·-F·a2&a
000005c0:·5f61·7420·2d46·2065·7869·743d·2d45·4143··_at·-F·exit=-EAC000005c0:·6d70·3b30·3130·3033·202d·4620·6578·6974··mp;01003·-F·exit
000005d0:·4345·5320·2d46·2061·7569·643e·3d31·3030··CES·-F·auid>=100000005d0:·3d2d·4541·4343·4553·202d·4620·6175·6964··=-EACCES·-F·auid
000005e0:·3020·2d46·2061·7569·6421·3d75·6e73·6574··0·-F·auid!=unset000005e0:·2667·743b·3d31·3030·3020·2d46·2061·7569··&gt;=1000·-F·aui
000005f0:·202d·4620·6b65·793d·756e·7375·6363·6573···-F·key=unsucces000005f0:·6421·3d75·6e73·6574·202d·4620·6b65·793d··d!=unset·-F·key=
00000600:·7366·756c·2d61·6363·6573·730a·2d61·2061··sful-access.-a·a00000600:·756e·7375·6363·6573·7366·756c·2d6d·6f64··unsuccessful-mod
00000610:·6c77·6179·732c·6578·6974·202d·4620·6172··lways,exit·-F·ar00000610:·6966·6963·6174·696f·6e0a·2d61·2061·6c77··ification.-a·alw
00000620:·6368·3d62·3634·202d·5320·6f70·656e·2c6f··ch=b64·-S·open,o00000620:·6179·732c·6578·6974·202d·4620·6172·6368··ays,exit·-F·arch
00000630:·7065·6e61·742c·6f70·656e·6174·322c·6f70··penat,openat2,op00000630:·3d62·3634·202d·5320·6f70·656e·6174·2c6f··=b64·-S·openat,o
00000640:·656e·5f62·795f·6861·6e64·6c65·5f61·7420··en_by_handle_at·00000640:·7065·6e5f·6279·5f68·616e·646c·655f·6174··pen_by_handle_at
00000650:·2d46·2065·7869·743d·2d45·4143·4345·5320··-F·exit=-EACCES·00000650:·202d·4620·6132·2661·6d70·3b30·3130·3033···-F·a2&amp;01003
00000660:·2d46·2061·7569·643e·3d31·3030·3020·2d46··-F·auid>=1000·-F00000660:·202d·4620·6578·6974·3d2d·4541·4343·4553···-F·exit=-EACCES
00000670:·2061·7569·6421·3d75·6e73·6574·202d·4620···auid!=unset·-F·00000670:·202d·4620·6175·6964·2667·743b·3d31·3030···-F·auid&gt;=100
00000680:·6b65·793d·756e·7375·6363·6573·7366·756c··key=unsuccessful00000680:·3020·2d46·2061·7569·6421·3d75·6e73·6574··0·-F·auid!=unset
00000690:·2d61·6363·6573·730a·2d61·2061·6c77·6179··-access.-a·alway00000690:·202d·4620·6b65·793d·756e·7375·6363·6573···-F·key=unsucces
000006a0:·732c·6578·6974·202d·4620·6172·6368·3d62··s,exit·-F·arch=b000006a0:·7366·756c·2d6d·6f64·6966·6963·6174·696f··sful-modificatio
000006b0:·3332·202d·5320·6f70·656e·2c6f·7065·6e61··32·-S·open,opena000006b0:·6e0a·2d61·2061·6c77·6179·732c·6578·6974··n.-a·always,exit
000006c0:·742c·6f70·656e·6174·322c·6f70·656e·5f62··t,openat2,open_b000006c0:·202d·4620·6172·6368·3d62·3332·202d·5320···-F·arch=b32·-S·
000006d0:·795f·6861·6e64·6c65·5f61·7420·2d46·2065··y_handle_at·-F·e000006d0:·6f70·656e·202d·4620·6131·2661·6d70·3b30··open·-F·a1&amp;0
000006e0:·7869·743d·2d45·5045·524d·202d·4620·6175··xit=-EPERM·-F·au000006e0:·3130·3033·202d·4620·6578·6974·3d2d·4541··1003·-F·exit=-EA
000006f0:·6964·3e3d·3130·3030·202d·4620·6175·6964··id>=1000·-F·auid000006f0:·4343·4553·202d·4620·6175·6964·2667·743b··CCES·-F·auid&gt;
00000700:·213d·756e·7365·7420·2d46·206b·6579·3d75··!=unset·-F·key=u00000700:·3d31·3030·3020·2d46·2061·7569·6421·3d75··=1000·-F·auid!=u
00000710:·6e73·7563·6365·7373·6675·6c2d·6163·6365··nsuccessful-acce00000710:·6e73·6574·202d·4620·6b65·793d·756e·7375··nset·-F·key=unsu
00000720:·7373·0a2d·6120·616c·7761·7973·2c65·7869··ss.-a·always,exi00000720:·6363·6573·7366·756c·2d6d·6f64·6966·6963··ccessful-modific
00000730:·7420·2d46·2061·7263·683d·6236·3420·2d53··t·-F·arch=b64·-S00000730:·6174·696f·6e0a·2d61·2061·6c77·6179·732c··ation.-a·always,
00000740:·206f·7065·6e2c·6f70·656e·6174·2c6f·7065···open,openat,ope00000740:·6578·6974·202d·4620·6172·6368·3d62·3634··exit·-F·arch=b64
00000750:·6e61·7432·2c6f·7065·6e5f·6279·5f68·616e··nat2,open_by_han00000750:·202d·5320·6f70·656e·202d·4620·6131·2661···-S·open·-F·a1&a
00000760:·646c·655f·6174·202d·4620·6578·6974·3d2d··dle_at·-F·exit=-00000760:·6d70·3b30·3130·3033·202d·4620·6578·6974··mp;01003·-F·exit
00000770:·4550·4552·4d20·2d46·2061·7569·643e·3d31··EPERM·-F·auid>=100000770:·3d2d·4541·4343·4553·202d·4620·6175·6964··=-EACCES·-F·auid
00000780:·3030·3020·2d46·2061·7569·6421·3d75·6e73··000·-F·auid!=uns00000780:·2667·743b·3d31·3030·3020·2d46·2061·7569··&gt;=1000·-F·aui
00000790:·6574·202d·4620·6b65·793d·756e·7375·6363··et·-F·key=unsucc00000790:·6421·3d75·6e73·6574·202d·4620·6b65·793d··d!=unset·-F·key=
000007a0:·6573·7366·756c·2d61·6363·6573·7320·2020··essful-access···000007a0:·756e·7375·6363·6573·7366·756c·2d6d·6f64··unsuccessful-mod
000007b0:·203c·2f70·7265·3e0a·0a4c·6f61·6420·6e65···</pre>..Load·ne000007b0:·6966·6963·6174·696f·6e0a·2d61·2061·6c77··ification.-a·alw
000007c0:·7720·4175·6469·7420·7275·6c65·7320·696e··w·Audit·rules·in000007c0:·6179·732c·6578·6974·202d·4620·6172·6368··ays,exit·-F·arch
000007d0:·746f·206b·6572·6e65·6c20·6279·2072·756e··to·kernel·by·run000007d0:·3d62·3332·202d·5320·7472·756e·6361·7465··=b32·-S·truncate
000007e0:·6e69·6e67·3a0a·3c70·7265·3e61·7567·656e··ning:.<pre>augen000007e0:·2c66·7472·756e·6361·7465·202d·4620·6578··,ftruncate·-F·ex
000007f0:·7275·6c65·7320·2d2d·6c6f·6164·3c2f·7072··rules·--load</pr000007f0:·6974·3d2d·4541·4343·4553·202d·4620·6175··it=-EACCES·-F·au
00000800:·653e·0a0a·4e6f·7465·3a20·5468·6973·2072··e>..Note:·This·r00000800:·6964·2667·743b·3d31·3030·3020·2d46·2061··id&gt;=1000·-F·a
00000810:·756c·6520·7573·6573·2061·2073·7065·6369··ule·uses·a·speci00000810:·7569·6421·3d75·6e73·6574·202d·4620·6b65··uid!=unset·-F·ke
00000820:·616c·2073·6574·206f·6620·4175·6469·7420··al·set·of·Audit·00000820:·793d·756e·7375·6363·6573·7366·756c·2d6d··y=unsuccessful-m
00000830:·7275·6c65·7320·746f·2063·6f6d·706c·7920··rules·to·comply·00000830:·6f64·6966·6963·6174·696f·6e0a·2d61·2061··odification.-a·a
00000840:·7769·7468·204f·5350·5020·342e·322e·312e··with·OSPP·4.2.1.00000840:·6c77·6179·732c·6578·6974·202d·4620·6172··lways,exit·-F·ar
00000850:·2059·6f75·206d·6179·2072·6575·7365·2074···You·may·reuse·t00000850:·6368·3d62·3634·202d·5320·7472·756e·6361··ch=b64·-S·trunca
00000860:·6869·7320·7275·6c65·2069·6e20·6469·6666··his·rule·in·diff00000860:·7465·2c66·7472·756e·6361·7465·202d·4620··te,ftruncate·-F·
00000870:·6572·656e·7420·7072·6f66·696c·6573·2e20··erent·profiles.·00000870:·6578·6974·3d2d·4541·4343·4553·202d·4620··exit=-EACCES·-F·
00000880:·4966·2079·6f75·2064·6563·6964·6520·746f··If·you·decide·to00000880:·6175·6964·2667·743b·3d31·3030·3020·2d46··auid&gt;=1000·-F
00000890:·2064·6f20·736f·2c20·6974·2069·7320·7265···do·so,·it·is·re00000890:·2061·7569·6421·3d75·6e73·6574·202d·4620···auid!=unset·-F·
000008a0:·636f·6d6d·656e·6465·6420·7468·6174·2079··commended·that·y000008a0:·6b65·793d·756e·7375·6363·6573·7366·756c··key=unsuccessful
000008b0:·6f75·2069·6e73·7065·6374·2063·6f6e·7465··ou·inspect·conte000008b0:·2d6d·6f64·6966·6963·6174·696f·6e0a·2d61··-modification.-a
000008c0:·6e74·7320·6f66·2074·6865·2066·696c·6520··nts·of·the·file·000008c0:·2061·6c77·6179·732c·6578·6974·202d·4620···always,exit·-F·
000008d0:·636c·6f73·656c·7920·616e·6420·6d61·6b65··closely·and·make000008d0:·6172·6368·3d62·3332·202d·5320·6f70·656e··arch=b32·-S·open
000008e0:·2073·7572·6520·7468·6174·2074·6865·7920···sure·that·they·000008e0:·6174·2c6f·7065·6e5f·6279·5f68·616e·646c··at,open_by_handl
000008f0:·6172·6520·616c·6c69·676e·6564·2077·6974··are·alligned·wit000008f0:·655f·6174·202d·4620·6132·2661·6d70·3b30··e_at·-F·a2&amp;0
00000900:·6820·796f·7572·206e·6565·6473·2e0a·2020··h·your·needs..··00000900:·3130·3033·202d·4620·6578·6974·3d2d·4550··1003·-F·exit=-EP
00000910:·2020·2020·3c2f·7464·3e0a·2020·2020·2020······</td>.······00000910:·4552·4d20·2d46·2061·7569·6426·6774·3b3d··ERM·-F·auid&gt;=
00000920:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en00000920:·3130·3030·202d·4620·6175·6964·213d·756e··1000·-F·auid!=un
00000930:·2d55·5322·3e0a·2020·2020·2020·2020·556e··-US">.········Un00000930:·7365·7420·2d46·206b·6579·3d75·6e73·7563··set·-F·key=unsuc
00000940:·7375·6363·6573·7366·756c·2061·7474·656d··successful·attem00000940:·6365·7373·6675·6c2d·6d6f·6469·6669·6361··cessful-modifica
00000950:·7074·7320·746f·2061·6363·6573·7320·6120··pts·to·access·a·00000950:·7469·6f6e·0a2d·6120·616c·7761·7973·2c65··tion.-a·always,e
00000960:·6669·6c65·206d·6967·6874·2062·6520·7369··file·might·be·si00000960:·7869·7420·2d46·2061·7263·683d·6236·3420··xit·-F·arch=b64·
00000970:·676e·7320·6f66·206d·616c·6963·696f·7573··gns·of·malicious00000970:·2d53·206f·7065·6e61·742c·6f70·656e·5f62··-S·openat,open_b
00000980:·2061·6374·6976·6974·7920·6861·7070·656e···activity·happen00000980:·795f·6861·6e64·6c65·5f61·7420·2d46·2061··y_handle_at·-F·a
00000990:·696e·6720·7769·7468·696e·2074·6865·2073··ing·within·the·s00000990:·3226·616d·703b·3031·3030·3320·2d46·2065··2&amp;01003·-F·e
000009a0:·7973·7465·6d2e·2041·7564·6974·696e·6720··ystem.·Auditing·000009a0:·7869·743d·2d45·5045·524d·202d·4620·6175··xit=-EPERM·-F·au
000009b0:·6f66·2073·7563·6820·6163·7469·7669·7469··of·such·activiti000009b0:·6964·2667·743b·3d31·3030·3020·2d46·2061··id&gt;=1000·-F·a
000009c0:·6573·2068·656c·7073·2069·6e20·7468·6569··es·helps·in·thei000009c0:·7569·6421·3d75·6e73·6574·202d·4620·6b65··uid!=unset·-F·ke
000009d0:·7220·6d6f·6e69·746f·7269·6e67·2061·6e64··r·monitoring·and000009d0:·793d·756e·7375·6363·6573·7366·756c·2d6d··y=unsuccessful-m
000009e0:·2069·6e76·6573·7469·6761·7469·6f6e·2e0a···investigation..000009e0:·6f64·6966·6963·6174·696f·6e0a·2d61·2061··odification.-a·a
000009f0:·2020·2020·2020·3c2f·7464·3e0a·2020·2020········</td>.····000009f0:·6c77·6179·732c·6578·6974·202d·4620·6172··lways,exit·-F·ar
00000a00:·3c2f·7472·3e0a·2020·2020·3c74·723e·0a20··</tr>.····<tr>.·00000a00:·6368·3d62·3332·202d·5320·6f70·656e·202d··ch=b32·-S·open·-
00000a10:·2020·2020·203c·7464·3e41·552d·3228·6429·······<td>AU-2(d)00000a10:·4620·6131·2661·6d70·3b30·3130·3033·202d··F·a1&amp;01003·-
00000a20:·3c62·722f·3e41·552d·3132·2863·293c·6272··<br/>AU-12(c)<br00000a20:·4620·6578·6974·3d2d·4550·4552·4d20·2d46··F·exit=-EPERM·-F
00000a30:·2f3e·434d·2d36·2861·293c·2f74·643e·0a20··/>CM-6(a)</td>.·00000a30:·2061·7569·6426·6774·3b3d·3130·3030·202d···auid&gt;=1000·-
00000a40:·2020·2020·203c·7464·3e52·6563·6f72·6420·······<td>Record·00000a40:·4620·6175·6964·213d·756e·7365·7420·2d46··F·auid!=unset·-F
00000a50:·556e·7375·6363·6573·7366·756c·2050·6572··Unsuccessful·Per00000a50:·206b·6579·3d75·6e73·7563·6365·7373·6675···key=unsuccessfu
00000a60:·6d69·7373·696f·6e20·4368·616e·6765·7320··mission·Changes·00000a60:·6c2d·6d6f·6469·6669·6361·7469·6f6e·0a2d··l-modification.-
00000a70:·746f·2046·696c·6573·202d·2073·6574·7861··to·Files·-·setxa00000a70:·6120·616c·7761·7973·2c65·7869·7420·2d46··a·always,exit·-F
00000a80:·7474·723c·2f74·643e·0a20·2020·2020·203c··ttr</td>.······<00000a80:·2061·7263·683d·6236·3420·2d53·206f·7065···arch=b64·-S·ope
00000a90:·7464·2078·6d6c·3a6c·616e·673d·2265·6e2d··td·xml:lang="en-00000a90:·6e20·2d46·2061·3126·616d·703b·3031·3030··n·-F·a1&amp;0100
00000aa0:·5553·223e·0a20·2020·2020·2020·2054·6865··US">.········The00000aa0:·3320·2d46·2065·7869·743d·2d45·5045·524d··3·-F·exit=-EPERM
00000ab0:·2061·7564·6974·2073·7973·7465·6d20·7368···audit·system·sh00000ab0:·202d·4620·6175·6964·2667·743b·3d31·3030···-F·auid&gt;=100
00000ac0:·6f75·6c64·2063·6f6c·6c65·6374·2075·6e73··ould·collect·uns00000ac0:·3020·2d46·2061·7569·6421·3d75·6e73·6574··0·-F·auid!=unset
00000ad0:·7563·6365·7373·6675·6c20·6669·6c65·2070··uccessful·file·p00000ad0:·202d·4620·6b65·793d·756e·7375·6363·6573···-F·key=unsucces
00000ae0:·6572·6d69·7373·696f·6e20·6368·616e·6765··ermission·change00000ae0:·7366·756c·2d6d·6f64·6966·6963·6174·696f··sful-modificatio
00000af0:·0a61·7474·656d·7074·7320·666f·7220·616c··.attempts·for·al00000af0:·6e0a·2d61·2061·6c77·6179·732c·6578·6974··n.-a·always,exit
00000b00:·6c20·7573·6572·7320·616e·6420·726f·6f74··l·users·and·root00000b00:·202d·4620·6172·6368·3d62·3332·202d·5320···-F·arch=b32·-S·
00000b10:·2e0a·4966·2074·6865·203c·7474·3e61·7564··..If·the·<tt>aud00000b10:·7472·756e·6361·7465·2c66·7472·756e·6361··truncate,ftrunca
00000b20:·6974·643c·2f74·743e·2064·6165·6d6f·6e20··itd</tt>·daemon·00000b20:·7465·202d·4620·6578·6974·3d2d·4550·4552··te·-F·exit=-EPER
00000b30:·6973·2063·6f6e·6669·6775·7265·640a·746f··is·configured.to00000b30:·4d20·2d46·2061·7569·6426·6774·3b3d·3130··M·-F·auid&gt;=10
00000b40:·2075·7365·2074·6865·203c·7474·3e61·7567···use·the·<tt>aug00000b40:·3030·202d·4620·6175·6964·213d·756e·7365··00·-F·auid!=unse
00000b50:·656e·7275·6c65·733c·2f74·743e·2070·726f··enrules</tt>·pro00000b50:·7420·2d46·206b·6579·3d75·6e73·7563·6365··t·-F·key=unsucce
00000b60:·6772·616d·2074·6f20·7265·6164·2061·7564··gram·to·read·aud00000b60:·7373·6675·6c2d·6d6f·6469·6669·6361·7469··ssful-modificati
00000b70:·6974·2072·756c·6573·2064·7572·696e·6720··it·rules·during·00000b70:·6f6e·0a2d·6120·616c·7761·7973·2c65·7869··on.-a·always,exi
00000b80:·6461·656d·6f6e·0a73·7461·7274·7570·2028··daemon.startup·(00000b80:·7420·2d46·2061·7263·683d·6236·3420·2d53··t·-F·arch=b64·-S
00000b90:·7468·6520·6465·6661·756c·7429·2c20·6164··the·default),·ad00000b90:·2074·7275·6e63·6174·652c·6674·7275·6e63···truncate,ftrunc
00000ba0:·6420·7468·6520·666f·6c6c·6f77·696e·6720··d·the·following·00000ba0:·6174·6520·2d46·2065·7869·743d·2d45·5045··ate·-F·exit=-EPE
00000bb0:·6c69·6e65·7320·746f·2061·2066·696c·6520··lines·to·a·file·00000bb0:·524d·202d·4620·6175·6964·2667·743b·3d31··RM·-F·auid&gt;=1
00000bc0:·7769·7468·2073·7566·6669·780a·3c74·743e··with·suffix.<tt>00000bc0:·3030·3020·2d46·2061·7569·6421·3d75·6e73··000·-F·auid!=uns
00000bd0:·2e72·756c·6573·3c2f·7474·3e20·696e·2074··.rules</tt>·in·t00000bd0:·6574·202d·4620·6b65·793d·756e·7375·6363··et·-F·key=unsucc
00000be0:·6865·2064·6972·6563·746f·7279·203c·7474··he·directory·<tt00000be0:·6573·7366·756c·2d6d·6f64·6966·6963·6174··essful-modificat
Max diff block lines reached; 5578172/7293538 bytes (76.48%) of diff not shown.
2.5 MB
html2text {}
Max HTML report size reached
790 KB
./usr/share/doc/ssg-nondebian/table-ol8-pcidssrefs.html
Ordering differences only
    
Offset 157, 28 lines modifiedOffset 157, 14 lines modified
157 default·zone·to·<tt>drop</tt>·implements·proper·design·for·a·firewall,·i.e.157 default·zone·to·<tt>drop</tt>·implements·proper·design·for·a·firewall,·i.e.
158 any·packets·which·are·not·explicitly·permitted·should·not·be158 any·packets·which·are·not·explicitly·permitted·should·not·be
159 accepted.159 accepted.
160 ······</td>160 ······</td>
161 ····</tr>161 ····</tr>
162 ····<tr>162 ····<tr>
163 ······<td>Req-1.4.1</td>163 ······<td>Req-1.4.1</td>
164 ······<td>Install·iptables·Package</td> 
165 ······<td·xml:lang="en-US"> 
166 ········The·<code>iptables</code>·package·can·be·installed·with·the·following·command: 
167 <pre> 
168 $·sudo·yum·install·iptables</pre> 
169 ······</td> 
170 ······<td·xml:lang="en-US"> 
171 ········<tt>iptables</tt>·controls·the·Linux·kernel·network·packet·filtering 
172 code.·<tt>iptables</tt>·allows·system·operators·to·set·up·firewalls·and·IP 
173 masquerading,·etc. 
174 ······</td> 
175 ····</tr> 
176 ····<tr> 
177 ······<td>Req-1.4.1</td> 
178 ······<td>Set·nftables·Configuration·for·Loopback·Traffic</td>164 ······<td>Set·nftables·Configuration·for·Loopback·Traffic</td>
179 ······<td·xml:lang="en-US">165 ······<td·xml:lang="en-US">
180 ········Configure·the·loopback·interface·to·accept·traffic.166 ········Configure·the·loopback·interface·to·accept·traffic.
181 Configure·all·other·interfaces·to·deny·traffic·to·the·loopback167 Configure·all·other·interfaces·to·deny·traffic·to·the·loopback
182 network.168 network.
183 ······</td>169 ······</td>
184 ······<td·xml:lang="en-US">170 ······<td·xml:lang="en-US">
Offset 187, 14 lines modifiedOffset 173, 28 lines modified
187 is·the·only·place·that·loopback·network·traffic·should·be·seen,173 is·the·only·place·that·loopback·network·traffic·should·be·seen,
188 all·other·interfaces·should·ignore·traffic·on·this·network·as·an174 all·other·interfaces·should·ignore·traffic·on·this·network·as·an
189 anti-spoofing·measure.175 anti-spoofing·measure.
190 ······</td>176 ······</td>
191 ····</tr>177 ····</tr>
192 ····<tr>178 ····<tr>
193 ······<td>Req-1.4.1</td>179 ······<td>Req-1.4.1</td>
 180 ······<td>Install·iptables·Package</td>
 181 ······<td·xml:lang="en-US">
 182 ········The·<code>iptables</code>·package·can·be·installed·with·the·following·command:
 183 <pre>
 184 $·sudo·yum·install·iptables</pre>
 185 ······</td>
 186 ······<td·xml:lang="en-US">
 187 ········<tt>iptables</tt>·controls·the·Linux·kernel·network·packet·filtering
 188 code.·<tt>iptables</tt>·allows·system·operators·to·set·up·firewalls·and·IP
 189 masquerading,·etc.
 190 ······</td>
 191 ····</tr>
 192 ····<tr>
 193 ······<td>Req-1.4.1</td>
194 ······<td>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</td>194 ······<td>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</td>
195 ······<td·xml:lang="en-US">195 ······<td·xml:lang="en-US">
196 ········To·set·the·runtime·status·of·the·<code>net.ipv4.tcp_syncookies</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1</pre>196 ········To·set·the·runtime·status·of·the·<code>net.ipv4.tcp_syncookies</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1</pre>
197 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.tcp_syncookies·=·1</pre>197 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.tcp_syncookies·=·1</pre>
198 ······</td>198 ······</td>
199 ······<td·xml:lang="en-US">199 ······<td·xml:lang="en-US">
200 ········A·TCP·SYN·flood·attack·can·cause·a·denial·of·service·by·filling·a200 ········A·TCP·SYN·flood·attack·can·cause·a·denial·of·service·by·filling·a
Offset 203, 14 lines modifiedOffset 203, 35 lines modified
203 verifying·the·initiator·is·attempting·a·valid·connection·and·is·not·a·flood203 verifying·the·initiator·is·attempting·a·valid·connection·and·is·not·a·flood
204 source.·This·feature·is·activated·when·a·flood·condition·is·detected,·and204 source.·This·feature·is·activated·when·a·flood·condition·is·detected,·and
205 enables·the·system·to·continue·servicing·valid·connection·requests.205 enables·the·system·to·continue·servicing·valid·connection·requests.
206 ······</td>206 ······</td>
207 ····</tr>207 ····</tr>
208 ····<tr>208 ····<tr>
209 ······<td>Req-1.4.2</td>209 ······<td>Req-1.4.2</td>
 210 ······<td>Disable·DCCP·Support</td>
 211 ······<td·xml:lang="en-US">
 212 ········The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a
 213 relatively·new·transport·layer·protocol,·designed·to·support
 214 streaming·media·and·telephony.
  
 215 To·configure·the·system·to·prevent·the·<code>dccp</code>
 216 kernel·module·from·being·loaded,·add·the·following·line·to·the·file·<code>/etc/modprobe.d/dccp.conf</code>:
 217 <pre>install·dccp·/bin/false</pre>
  
 218 To·configure·the·system·to·prevent·the·<code>dccp</code>·from·being·used,
 219 add·the·following·line·to·file·<code>/etc/modprobe.d/dccp.conf</code>:
 220 <pre>blacklist·dccp</pre>
 221 ······</td>
 222 ······<td·xml:lang="en-US">
 223 ········Disabling·DCCP·protects
 224 the·system·against·exploitation·of·any·flaws·in·its·implementation.
 225 ······</td>
 226 ····</tr>
 227 ····<tr>
 228 ······<td>Req-1.4.2</td>
210 ······<td>Disable·SCTP·Support</td>229 ······<td>Disable·SCTP·Support</td>
211 ······<td·xml:lang="en-US">230 ······<td·xml:lang="en-US">
212 ········The·Stream·Control·Transmission·Protocol·(SCTP)·is·a231 ········The·Stream·Control·Transmission·Protocol·(SCTP)·is·a
213 transport·layer·protocol,·designed·to·support·the·idea·of232 transport·layer·protocol,·designed·to·support·the·idea·of
214 message-oriented·communication,·with·several·streams·of·messages233 message-oriented·communication,·with·several·streams·of·messages
215 within·one·connection.234 within·one·connection.
  
Offset 224, 75 lines modifiedOffset 245, 58 lines modified
224 ······</td>245 ······</td>
225 ······<td·xml:lang="en-US">246 ······<td·xml:lang="en-US">
226 ········Disabling·SCTP·protects247 ········Disabling·SCTP·protects
227 the·system·against·exploitation·of·any·flaws·in·its·implementation.248 the·system·against·exploitation·of·any·flaws·in·its·implementation.
228 ······</td>249 ······</td>
229 ····</tr>250 ····</tr>
230 ····<tr>251 ····<tr>
231 ······<td>Req-1.4.2</td> 
232 ······<td>Disable·DCCP·Support</td> 
233 ······<td·xml:lang="en-US"> 
234 ········The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a 
235 relatively·new·transport·layer·protocol,·designed·to·support 
236 streaming·media·and·telephony. 
  
237 To·configure·the·system·to·prevent·the·<code>dccp</code> 
238 kernel·module·from·being·loaded,·add·the·following·line·to·the·file·<code>/etc/modprobe.d/dccp.conf</code>: 
239 <pre>install·dccp·/bin/false</pre> 
  
240 To·configure·the·system·to·prevent·the·<code>dccp</code>·from·being·used, 
241 add·the·following·line·to·file·<code>/etc/modprobe.d/dccp.conf</code>: 
242 <pre>blacklist·dccp</pre> 
243 ······</td> 
244 ······<td·xml:lang="en-US"> 
245 ········Disabling·DCCP·protects 
246 the·system·against·exploitation·of·any·flaws·in·its·implementation. 
247 ······</td> 
248 ····</tr> 
249 ····<tr> 
250 ······<td>Req-1.4.3</td>252 ······<td>Req-1.4.3</td>
251 ······<td>Disable·Kernel·Parameter·for·Accepting·Secure·ICMP·Redirects·on·all·IPv4·Interfaces</td>253 ······<td>Disable·Kernel·Parameter·for·Accepting·Secure·ICMP·Redirects·on·all·IPv4·Interfaces</td>
252 ······<td·xml:lang="en-US">254 ······<td·xml:lang="en-US">
253 ········To·set·the·runtime·status·of·the·<code>net.ipv4.conf.all.secure_redirects</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.conf.all.secure_redirects=0</pre>255 ········To·set·the·runtime·status·of·the·<code>net.ipv4.conf.all.secure_redirects</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.conf.all.secure_redirects=0</pre>
254 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.conf.all.secure_redirects·=·0</pre>256 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.conf.all.secure_redirects·=·0</pre>
Max diff block lines reached; 302504/307696 bytes (98.31%) of diff not shown.
489 KB
html2text {}
    
Offset 112, 23 lines modifiedOffset 112, 14 lines modified
112 ·········Incoming·Packets····firewalld.conf·to·be:··································drop·implements112 ·········Incoming·Packets····firewalld.conf·to·be:··································drop·implements
113 ·····························DefaultZone=drop·······································proper·design·for·a113 ·····························DefaultZone=drop·······································proper·design·for·a
114 ····················································································firewall,·i.e.·any114 ····················································································firewall,·i.e.·any
115 ····················································································packets·which·are115 ····················································································packets·which·are
116 ····················································································not·explicitly116 ····················································································not·explicitly
117 ····················································································permitted·should117 ····················································································permitted·should
118 ····················································································not·be·accepted.118 ····················································································not·be·accepted.
119 ····················································································iptables·controls 
120 ····················································································the·Linux·kernel 
121 ····················································································network·packet 
122 Req-·····Install·iptables····The·iptables·package·can·be·installed·with·the·········filtering·code. 
123 1.4.1····Package·············following·command:·····································iptables·allows 
124 ·····························$·sudo·yum·install·iptables····························system·operators·to 
125 ····················································································set·up·firewalls 
126 ····················································································and·IP 
127 ····················································································masquerading,·etc. 
128 ····················································································Loopback·traffic·is119 ····················································································Loopback·traffic·is
129 ····················································································generated·between120 ····················································································generated·between
130 ····················································································processes·on121 ····················································································processes·on
131 ····················································································machine·and·is122 ····················································································machine·and·is
132 ····················································································typically·critical123 ····················································································typically·critical
133 ····················································································to·operation·of·the124 ····················································································to·operation·of·the
134 ····················································································system.·The125 ····················································································system.·The
Offset 138, 14 lines modifiedOffset 129, 23 lines modified
138 ····················································································network·traffic129 ····················································································network·traffic
139 ····················································································should·be·seen,·all130 ····················································································should·be·seen,·all
140 ····················································································other·interfaces131 ····················································································other·interfaces
141 ····················································································should·ignore132 ····················································································should·ignore
142 ····················································································traffic·on·this133 ····················································································traffic·on·this
143 ····················································································network·as·an·anti-134 ····················································································network·as·an·anti-
144 ····················································································spoofing·measure.135 ····················································································spoofing·measure.
 136 ····················································································iptables·controls
 137 ····················································································the·Linux·kernel
 138 ····················································································network·packet
 139 Req-·····Install·iptables····The·iptables·package·can·be·installed·with·the·········filtering·code.
 140 1.4.1····Package·············following·command:·····································iptables·allows
 141 ·····························$·sudo·yum·install·iptables····························system·operators·to
 142 ····················································································set·up·firewalls
 143 ····················································································and·IP
 144 ····················································································masquerading,·etc.
145 ····················································································A·TCP·SYN·flood145 ····················································································A·TCP·SYN·flood
146 ····················································································attack·can·cause·a146 ····················································································attack·can·cause·a
147 ····················································································denial·of·service147 ····················································································denial·of·service
148 ····················································································by·filling·a148 ····················································································by·filling·a
149 ····················································································system's·TCP149 ····················································································system's·TCP
150 ····················································································connection·table150 ····················································································connection·table
151 ····················································································with·connections·in151 ····················································································with·connections·in
Offset 164, 90 lines modifiedOffset 164, 47 lines modified
164 ····················································································flood·condition·is164 ····················································································flood·condition·is
165 ····················································································detected,·and165 ····················································································detected,·and
166 ····················································································enables·the·system166 ····················································································enables·the·system
167 ····················································································to·continue167 ····················································································to·continue
168 ····················································································servicing·valid168 ····················································································servicing·valid
169 ····················································································connection169 ····················································································connection
170 ····················································································requests.170 ····················································································requests.
 171 ·····························The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a
 172 ·····························relatively·new·transport·layer·protocol,·designed·to
 173 ·····························support·streaming·media·and·telephony.·To·configure····Disabling·DCCP
 174 ·····························the·system·to·prevent·the·dccp·kernel·module·from······protects·the·system
 175 Req-·····Disable·DCCP········being·loaded,·add·the·following·line·to·the·file·/etc/·against
 176 1.4.2····Support·············modprobe.d/dccp.conf:··································exploitation·of·any
 177 ·····························install·dccp·/bin/false································flaws·in·its
 178 ·····························To·configure·the·system·to·prevent·the·dccp·from·being·implementation.
 179 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/
 180 ·····························dccp.conf:
 181 ·····························blacklist·dccp
171 ·····························The·Stream·Control·Transmission·Protocol·(SCTP)·is·a182 ·····························The·Stream·Control·Transmission·Protocol·(SCTP)·is·a
172 ·····························transport·layer·protocol,·designed·to·support·the·idea183 ·····························transport·layer·protocol,·designed·to·support·the·idea
173 ·····························of·message-oriented·communication,·with·several184 ·····························of·message-oriented·communication,·with·several
174 ·····························streams·of·messages·within·one·connection.·To··········Disabling·SCTP185 ·····························streams·of·messages·within·one·connection.·To··········Disabling·SCTP
175 ·····························configure·the·system·to·prevent·the·sctp·kernel·module·protects·the·system186 ·····························configure·the·system·to·prevent·the·sctp·kernel·module·protects·the·system
176 Req-·····Disable·SCTP········from·being·loaded,·add·the·following·line·to·the·file··against187 Req-·····Disable·SCTP········from·being·loaded,·add·the·following·line·to·the·file··against
177 1.4.2····Support·············/etc/modprobe.d/sctp.conf:·····························exploitation·of·any188 1.4.2····Support·············/etc/modprobe.d/sctp.conf:·····························exploitation·of·any
178 ·····························install·sctp·/bin/false································flaws·in·its189 ·····························install·sctp·/bin/false································flaws·in·its
179 ·····························To·configure·the·system·to·prevent·the·sctp·from·being·implementation.190 ·····························To·configure·the·system·to·prevent·the·sctp·from·being·implementation.
180 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/191 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/
181 ·····························sctp.conf:192 ·····························sctp.conf:
182 ·····························blacklist·sctp193 ·····························blacklist·sctp
183 ·····························The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a 
184 ·····························relatively·new·transport·layer·protocol,·designed·to 
185 ·····························support·streaming·media·and·telephony.·To·configure····Disabling·DCCP 
186 ·····························the·system·to·prevent·the·dccp·kernel·module·from······protects·the·system 
187 Req-·····Disable·DCCP········being·loaded,·add·the·following·line·to·the·file·/etc/·against 
188 1.4.2····Support·············modprobe.d/dccp.conf:··································exploitation·of·any 
189 ·····························install·dccp·/bin/false································flaws·in·its 
190 ·····························To·configure·the·system·to·prevent·the·dccp·from·being·implementation. 
191 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/ 
192 ·····························dccp.conf: 
193 ·····························blacklist·dccp 
194 ····················································································Accepting·"secure"194 ····················································································Accepting·"secure"
195 ·····························To·set·the·runtime·status·of·the·······················ICMP·redirects195 ·····························To·set·the·runtime·status·of·the·······················ICMP·redirects
196 ·········Disable·Kernel······net.ipv4.conf.all.secure_redirects·kernel·parameter,···(from·those196 ·········Disable·Kernel······net.ipv4.conf.all.secure_redirects·kernel·parameter,···(from·those
197 ·········Parameter·for·······run·the·following·command:·····························gateways·listed·as197 ·········Parameter·for·······run·the·following·command:·····························gateways·listed·as
198 Req-·····Accepting·Secure····$·sudo·sysctl·-w·net.ipv4.conf.all.secure_redirects=0··default·gateways)198 Req-·····Accepting·Secure····$·sudo·sysctl·-w·net.ipv4.conf.all.secure_redirects=0··default·gateways)
199 1.4.3····ICMP·Redirects·on···To·make·sure·that·the·setting·is·persistent,·add·the···has·few·legitimate199 1.4.3····ICMP·Redirects·on···To·make·sure·that·the·setting·is·persistent,·add·the···has·few·legitimate
200 ·········all·IPv4·Interfaces·following·line·to·a·file·in·the·directory·/etc/········uses.·It·should·be200 ·········all·IPv4·Interfaces·following·line·to·a·file·in·the·directory·/etc/········uses.·It·should·be
201 ·····························sysctl.d:··············································disabled·unless·it201 ·····························sysctl.d:··············································disabled·unless·it
202 ·····························net.ipv4.conf.all.secure_redirects·=·0·················is·absolutely202 ·····························net.ipv4.conf.all.secure_redirects·=·0·················is·absolutely
203 ····················································································required.203 ····················································································required.
204 ····················································································Responding·to 
205 ····················································································broadcast·(ICMP) 
206 ····················································································echoes·facilitates 
207 ·····························To·set·the·runtime·status·of·the·······················network·mapping·and 
208 ·····························net.ipv4.icmp_echo_ignore_broadcasts·kernel·parameter,·provides·a·vector 
209 ·········Enable·Kernel·······run·the·following·command:·····························for·amplification 
210 ·········Parameter·to·Ignore·$·sudo·sysctl·-········································attacks. 
211 Req-·····ICMP·Broadcast·Echo·w·net.ipv4.icmp_echo_ignore_broadcasts=1···············Ignoring·ICMP·echo 
212 1.4.3····Requests·on·IPv4····To·make·sure·that·the·setting·is·persistent,·add·the···requests·(pings) 
213 ·········Interfaces··········following·line·to·a·file·in·the·directory·/etc/········sent·to·broadcast 
214 ·····························sysctl.d:··············································or·multicast 
215 ·····························net.ipv4.icmp_echo_ignore_broadcasts·=·1···············addresses·makes·the 
216 ····················································································system·slightly 
217 ····················································································more·difficult·to 
218 ····················································································enumerate·on·the 
219 ····················································································network. 
220 ····················································································Enabling·reverse 
221 ····················································································path·filtering 
222 ····················································································drops·packets·with 
223 ····················································································source·addresses 
224 ····················································································that·should·not 
225 ·····························To·set·the·runtime·status·of·the·······················have·been·able·to 
226 ·········Enable·Kernel·······net.ipv4.conf.all.rp_filter·kernel·parameter,·run·the··be·received·on·the 
227 ·········Parameter·to·Use····following·command:·····································interface·they·were 
228 Req-·····Reverse·Path········$·sudo·sysctl·-w·net.ipv4.conf.all.rp_filter=1·········received·on.·It 
229 1.4.3····Filtering·on·all····To·make·sure·that·the·setting·is·persistent,·add·the···should·not·be·used 
230 ·········IPv4·Interfaces·····following·line·to·a·file·in·the·directory·/etc/········on·systems·which 
231 ·····························sysctl.d:··············································are·routers·for 
Max diff block lines reached; 487184/500865 bytes (97.27%) of diff not shown.
16.9 MB
./usr/share/doc/ssg-nondebian/table-rhcos4-nistrefs.html
    
Offset 69, 14995 lines modifiedOffset 69, 14995 lines modified
00000440:·6174·696f·6e61·6c65·3c2f·7468·3e0a·2020··ationale</th>.··00000440:·6174·696f·6e61·6c65·3c2f·7468·3e0a·2020··ationale</th>.··
00000450:·3c2f·7468·6561·643e·0a20·203c·7462·6f64··</thead>.··<tbod00000450:·3c2f·7468·6561·643e·0a20·203c·7462·6f64··</thead>.··<tbod
00000460:·793e·0a20·203c·7472·3e0a·2020·2020·2020··y>.··<tr>.······00000460:·793e·0a20·203c·7472·3e0a·2020·2020·2020··y>.··<tr>.······
00000470:·3c74·643e·4155·2d32·2861·293c·2f74·643e··<td>AU-2(a)</td>00000470:·3c74·643e·4155·2d32·2861·293c·2f74·643e··<td>AU-2(a)</td>
00000480:·0a20·2020·2020·203c·7464·3e43·6f6e·6669··.······<td>Confi00000480:·0a20·2020·2020·203c·7464·3e43·6f6e·6669··.······<td>Confi
00000490:·6775·7265·2061·7564·6974·696e·6720·6f66··gure·auditing·of00000490:·6775·7265·2061·7564·6974·696e·6720·6f66··gure·auditing·of
Diff chunk too large, falling back to line-by-line diff (6836 lines added, 6836 lines removed)
000004a0:·2075·6e73·7563·6365·7373·6675·6c20·6669···unsuccessful·fi000004a0:·2075·6e73·7563·6365·7373·6675·6c20·6669···unsuccessful·fi
000004b0:·6c65·2061·6363·6573·7365·733c·2f74·643e··le·accesses</td>000004b0:·6c65·206d·6f64·6966·6963·6174·696f·6e73··le·modifications
000004c0:·0a20·2020·2020·203c·7464·2078·6d6c·3a6c··.······<td·xml:l000004c0:·3c2f·7464·3e0a·2020·2020·2020·3c74·6420··</td>.······<td·
000004d0:·616e·673d·2265·6e2d·5553·223e·0a20·2020··ang="en-US">.···000004d0:·786d·6c3a·6c61·6e67·3d22·656e·2d55·5322··xml:lang="en-US"
000004e0:·2020·2020·2045·6e73·7572·6520·7468·6174·······Ensure·that000004e0:·3e0a·2020·2020·2020·2020·456e·7375·7265··>.········Ensure
000004f0:·2075·6e73·7563·6365·7373·6675·6c20·6174···unsuccessful·at000004f0:·2074·6861·7420·756e·7375·6363·6573·7366···that·unsuccessf
00000500:·7465·6d70·7473·2074·6f20·6163·6365·7373··tempts·to·access00000500:·756c·2061·7474·656d·7074·7320·746f·206d··ul·attempts·to·m
00000510:·2061·2066·696c·6520·6172·6520·6175·6469···a·file·are·audi00000510:·6f64·6966·7920·6120·6669·6c65·2061·7265··odify·a·file·are
00000520:·7465·642e·0a0a·5468·6520·666f·6c6c·6f77··ted...The·follow00000520:·2061·7564·6974·6564·2e0a·0a54·6865·2066···audited...The·f
00000530:·696e·6720·7275·6c65·7320·636f·6e66·6967··ing·rules·config00000530:·6f6c·6c6f·7769·6e67·2072·756c·6573·2063··ollowing·rules·c
00000540:·7572·6520·6175·6469·7420·6173·2064·6573··ure·audit·as·des00000540:·6f6e·6669·6775·7265·2061·7564·6974·2061··onfigure·audit·a
00000550:·6372·6962·6564·2061·626f·7665·3a0a·3c70··cribed·above:.<p00000550:·7320·6465·7363·7269·6265·6420·6162·6f76··s·described·abov
00000560:·7265·3e23·2320·556e·7375·6363·6573·7366··re>##·Unsuccessf00000560:·653a·0a3c·7072·653e·2323·2055·6e73·7563··e:.<pre>##·Unsuc
00000570:·756c·2066·696c·6520·6163·6365·7373·2028··ul·file·access·(00000570:·6365·7373·6675·6c20·6669·6c65·206d·6f64··cessful·file·mod
00000580:·616e·7920·6f74·6865·7220·6f70·656e·7329··any·other·opens)00000580:·6966·6963·6174·696f·6e73·2028·6f70·656e··ifications·(open
00000590:·2054·6869·7320·6861·7320·746f·2067·6f20···This·has·to·go·00000590:·2066·6f72·2077·7269·7465·206f·7220·7472···for·write·or·tr
000005a0:·6c61·7374·2e0a·2d61·2061·6c77·6179·732c··last..-a·always,000005a0:·756e·6361·7465·290a·2d61·2061·6c77·6179··uncate).-a·alway
000005b0:·6578·6974·202d·4620·6172·6368·3d62·3332··exit·-F·arch=b32000005b0:·732c·6578·6974·202d·4620·6172·6368·3d62··s,exit·-F·arch=b
000005c0:·202d·5320·6f70·656e·2c6f·7065·6e61·742c···-S·open,openat,000005c0:·3332·202d·5320·6f70·656e·6174·2c6f·7065··32·-S·openat,ope
000005d0:·6f70·656e·6174·322c·6f70·656e·5f62·795f··openat2,open_by_000005d0:·6e5f·6279·5f68·616e·646c·655f·6174·202d··n_by_handle_at·-
000005e0:·6861·6e64·6c65·5f61·7420·2d46·2065·7869··handle_at·-F·exi000005e0:·4620·6132·2661·6d70·3b30·3130·3033·202d··F·a2&amp;01003·-
000005f0:·743d·2d45·4143·4345·5320·2d46·2061·7569··t=-EACCES·-F·aui000005f0:·4620·6578·6974·3d2d·4541·4343·4553·202d··F·exit=-EACCES·-
00000600:·643e·3d31·3030·3020·2d46·2061·7569·6421··d>=1000·-F·auid!00000600:·4620·6175·6964·2667·743b·3d31·3030·3020··F·auid&gt;=1000·
00000610:·3d75·6e73·6574·202d·4620·6b65·793d·756e··=unset·-F·key=un00000610:·2d46·2061·7569·6421·3d75·6e73·6574·202d··-F·auid!=unset·-
00000620:·7375·6363·6573·7366·756c·2d61·6363·6573··successful-acces00000620:·4620·6b65·793d·756e·7375·6363·6573·7366··F·key=unsuccessf
00000630:·730a·2d61·2061·6c77·6179·732c·6578·6974··s.-a·always,exit00000630:·756c·2d6d·6f64·6966·6963·6174·696f·6e0a··ul-modification.
00000640:·202d·4620·6172·6368·3d62·3634·202d·5320···-F·arch=b64·-S·00000640:·2d61·2061·6c77·6179·732c·6578·6974·202d··-a·always,exit·-
00000650:·6f70·656e·2c6f·7065·6e61·742c·6f70·656e··open,openat,open00000650:·4620·6172·6368·3d62·3634·202d·5320·6f70··F·arch=b64·-S·op
00000660:·6174·322c·6f70·656e·5f62·795f·6861·6e64··at2,open_by_hand00000660:·656e·6174·2c6f·7065·6e5f·6279·5f68·616e··enat,open_by_han
00000670:·6c65·5f61·7420·2d46·2065·7869·743d·2d45··le_at·-F·exit=-E00000670:·646c·655f·6174·202d·4620·6132·2661·6d70··dle_at·-F·a2&amp
00000680:·4143·4345·5320·2d46·2061·7569·643e·3d31··ACCES·-F·auid>=100000680:·3b30·3130·3033·202d·4620·6578·6974·3d2d··;01003·-F·exit=-
00000690:·3030·3020·2d46·2061·7569·6421·3d75·6e73··000·-F·auid!=uns00000690:·4541·4343·4553·202d·4620·6175·6964·2667··EACCES·-F·auid&g
000006a0:·6574·202d·4620·6b65·793d·756e·7375·6363··et·-F·key=unsucc000006a0:·743b·3d31·3030·3020·2d46·2061·7569·6421··t;=1000·-F·auid!
000006b0:·6573·7366·756c·2d61·6363·6573·730a·2d61··essful-access.-a000006b0:·3d75·6e73·6574·202d·4620·6b65·793d·756e··=unset·-F·key=un
000006c0:·2061·6c77·6179·732c·6578·6974·202d·4620···always,exit·-F·000006c0:·7375·6363·6573·7366·756c·2d6d·6f64·6966··successful-modif
000006d0:·6172·6368·3d62·3332·202d·5320·6f70·656e··arch=b32·-S·open000006d0:·6963·6174·696f·6e0a·2d61·2061·6c77·6179··ication.-a·alway
000006e0:·2c6f·7065·6e61·742c·6f70·656e·6174·322c··,openat,openat2,000006e0:·732c·6578·6974·202d·4620·6172·6368·3d62··s,exit·-F·arch=b
000006f0:·6f70·656e·5f62·795f·6861·6e64·6c65·5f61··open_by_handle_a000006f0:·3332·202d·5320·6f70·656e·202d·4620·6131··32·-S·open·-F·a1
00000700:·7420·2d46·2065·7869·743d·2d45·5045·524d··t·-F·exit=-EPERM00000700:·2661·6d70·3b30·3130·3033·202d·4620·6578··&amp;01003·-F·ex
00000710:·202d·4620·6175·6964·3e3d·3130·3030·202d···-F·auid>=1000·-00000710:·6974·3d2d·4541·4343·4553·202d·4620·6175··it=-EACCES·-F·au
00000720:·4620·6175·6964·213d·756e·7365·7420·2d46··F·auid!=unset·-F00000720:·6964·2667·743b·3d31·3030·3020·2d46·2061··id&gt;=1000·-F·a
00000730:·206b·6579·3d75·6e73·7563·6365·7373·6675···key=unsuccessfu00000730:·7569·6421·3d75·6e73·6574·202d·4620·6b65··uid!=unset·-F·ke
00000740:·6c2d·6163·6365·7373·0a2d·6120·616c·7761··l-access.-a·alwa00000740:·793d·756e·7375·6363·6573·7366·756c·2d6d··y=unsuccessful-m
00000750:·7973·2c65·7869·7420·2d46·2061·7263·683d··ys,exit·-F·arch=00000750:·6f64·6966·6963·6174·696f·6e0a·2d61·2061··odification.-a·a
00000760:·6236·3420·2d53·206f·7065·6e2c·6f70·656e··b64·-S·open,open00000760:·6c77·6179·732c·6578·6974·202d·4620·6172··lways,exit·-F·ar
00000770:·6174·2c6f·7065·6e61·7432·2c6f·7065·6e5f··at,openat2,open_00000770:·6368·3d62·3634·202d·5320·6f70·656e·202d··ch=b64·-S·open·-
00000780:·6279·5f68·616e·646c·655f·6174·202d·4620··by_handle_at·-F·00000780:·4620·6131·2661·6d70·3b30·3130·3033·202d··F·a1&amp;01003·-
00000790:·6578·6974·3d2d·4550·4552·4d20·2d46·2061··exit=-EPERM·-F·a00000790:·4620·6578·6974·3d2d·4541·4343·4553·202d··F·exit=-EACCES·-
000007a0:·7569·643e·3d31·3030·3020·2d46·2061·7569··uid>=1000·-F·aui000007a0:·4620·6175·6964·2667·743b·3d31·3030·3020··F·auid&gt;=1000·
000007b0:·6421·3d75·6e73·6574·202d·4620·6b65·793d··d!=unset·-F·key=000007b0:·2d46·2061·7569·6421·3d75·6e73·6574·202d··-F·auid!=unset·-
000007c0:·756e·7375·6363·6573·7366·756c·2d61·6363··unsuccessful-acc000007c0:·4620·6b65·793d·756e·7375·6363·6573·7366··F·key=unsuccessf
000007d0:·6573·7320·2020·203c·2f70·7265·3e0a·0a4c··ess····</pre>..L000007d0:·756c·2d6d·6f64·6966·6963·6174·696f·6e0a··ul-modification.
000007e0:·6f61·6420·6e65·7720·4175·6469·7420·7275··oad·new·Audit·ru000007e0:·2d61·2061·6c77·6179·732c·6578·6974·202d··-a·always,exit·-
000007f0:·6c65·7320·696e·746f·206b·6572·6e65·6c20··les·into·kernel·000007f0:·4620·6172·6368·3d62·3332·202d·5320·7472··F·arch=b32·-S·tr
00000800:·6279·2072·756e·6e69·6e67·3a0a·3c70·7265··by·running:.<pre00000800:·756e·6361·7465·2c66·7472·756e·6361·7465··uncate,ftruncate
00000810:·3e61·7567·656e·7275·6c65·7320·2d2d·6c6f··>augenrules·--lo00000810:·202d·4620·6578·6974·3d2d·4541·4343·4553···-F·exit=-EACCES
00000820:·6164·3c2f·7072·653e·0a0a·4e6f·7465·3a20··ad</pre>..Note:·00000820:·202d·4620·6175·6964·2667·743b·3d31·3030···-F·auid&gt;=100
00000830:·5468·6973·2072·756c·6520·7573·6573·2061··This·rule·uses·a00000830:·3020·2d46·2061·7569·6421·3d75·6e73·6574··0·-F·auid!=unset
00000840:·2073·7065·6369·616c·2073·6574·206f·6620···special·set·of·00000840:·202d·4620·6b65·793d·756e·7375·6363·6573···-F·key=unsucces
00000850:·4175·6469·7420·7275·6c65·7320·746f·2063··Audit·rules·to·c00000850:·7366·756c·2d6d·6f64·6966·6963·6174·696f··sful-modificatio
00000860:·6f6d·706c·7920·7769·7468·204f·5350·5020··omply·with·OSPP·00000860:·6e0a·2d61·2061·6c77·6179·732c·6578·6974··n.-a·always,exit
00000870:·342e·322e·312e·2059·6f75·206d·6179·2072··4.2.1.·You·may·r00000870:·202d·4620·6172·6368·3d62·3634·202d·5320···-F·arch=b64·-S·
00000880:·6575·7365·2074·6869·7320·7275·6c65·2069··euse·this·rule·i00000880:·7472·756e·6361·7465·2c66·7472·756e·6361··truncate,ftrunca
00000890:·6e20·6469·6666·6572·656e·7420·7072·6f66··n·different·prof00000890:·7465·202d·4620·6578·6974·3d2d·4541·4343··te·-F·exit=-EACC
000008a0:·696c·6573·2e20·4966·2079·6f75·2064·6563··iles.·If·you·dec000008a0:·4553·202d·4620·6175·6964·2667·743b·3d31··ES·-F·auid&gt;=1
000008b0:·6964·6520·746f·2064·6f20·736f·2c20·6974··ide·to·do·so,·it000008b0:·3030·3020·2d46·2061·7569·6421·3d75·6e73··000·-F·auid!=uns
000008c0:·2069·7320·7265·636f·6d6d·656e·6465·6420···is·recommended·000008c0:·6574·202d·4620·6b65·793d·756e·7375·6363··et·-F·key=unsucc
000008d0:·7468·6174·2079·6f75·2069·6e73·7065·6374··that·you·inspect000008d0:·6573·7366·756c·2d6d·6f64·6966·6963·6174··essful-modificat
000008e0:·2063·6f6e·7465·6e74·7320·6f66·2074·6865···contents·of·the000008e0:·696f·6e0a·2d61·2061·6c77·6179·732c·6578··ion.-a·always,ex
000008f0:·2066·696c·6520·636c·6f73·656c·7920·616e···file·closely·an000008f0:·6974·202d·4620·6172·6368·3d62·3332·202d··it·-F·arch=b32·-
00000900:·6420·6d61·6b65·2073·7572·6520·7468·6174··d·make·sure·that00000900:·5320·6f70·656e·6174·2c6f·7065·6e5f·6279··S·openat,open_by
00000910:·2074·6865·7920·6172·6520·616c·6c69·676e···they·are·allign00000910:·5f68·616e·646c·655f·6174·202d·4620·6132··_handle_at·-F·a2
00000920:·6564·2077·6974·6820·796f·7572·206e·6565··ed·with·your·nee00000920:·2661·6d70·3b30·3130·3033·202d·4620·6578··&amp;01003·-F·ex
00000930:·6473·2e0a·2020·2020·2020·3c2f·7464·3e0a··ds..······</td>.00000930:·6974·3d2d·4550·4552·4d20·2d46·2061·7569··it=-EPERM·-F·aui
00000940:·2020·2020·2020·3c74·6420·786d·6c3a·6c61········<td·xml:la00000940:·6426·6774·3b3d·3130·3030·202d·4620·6175··d&gt;=1000·-F·au
00000950:·6e67·3d22·656e·2d55·5322·3e0a·2020·2020··ng="en-US">.····00000950:·6964·213d·756e·7365·7420·2d46·206b·6579··id!=unset·-F·key
00000960:·2020·2020·556e·7375·6363·6573·7366·756c······Unsuccessful00000960:·3d75·6e73·7563·6365·7373·6675·6c2d·6d6f··=unsuccessful-mo
00000970:·2061·7474·656d·7074·7320·746f·2061·6363···attempts·to·acc00000970:·6469·6669·6361·7469·6f6e·0a2d·6120·616c··dification.-a·al
00000980:·6573·7320·6120·6669·6c65·206d·6967·6874··ess·a·file·might00000980:·7761·7973·2c65·7869·7420·2d46·2061·7263··ways,exit·-F·arc
00000990:·2062·6520·7369·676e·7320·6f66·206d·616c···be·signs·of·mal00000990:·683d·6236·3420·2d53·206f·7065·6e61·742c··h=b64·-S·openat,
000009a0:·6963·696f·7573·2061·6374·6976·6974·7920··icious·activity·000009a0:·6f70·656e·5f62·795f·6861·6e64·6c65·5f61··open_by_handle_a
000009b0:·6861·7070·656e·696e·6720·7769·7468·696e··happening·within000009b0:·7420·2d46·2061·3226·616d·703b·3031·3030··t·-F·a2&amp;0100
000009c0:·2074·6865·2073·7973·7465·6d2e·2041·7564···the·system.·Aud000009c0:·3320·2d46·2065·7869·743d·2d45·5045·524d··3·-F·exit=-EPERM
000009d0:·6974·696e·6720·6f66·2073·7563·6820·6163··iting·of·such·ac000009d0:·202d·4620·6175·6964·2667·743b·3d31·3030···-F·auid&gt;=100
000009e0:·7469·7669·7469·6573·2068·656c·7073·2069··tivities·helps·i000009e0:·3020·2d46·2061·7569·6421·3d75·6e73·6574··0·-F·auid!=unset
000009f0:·6e20·7468·6569·7220·6d6f·6e69·746f·7269··n·their·monitori000009f0:·202d·4620·6b65·793d·756e·7375·6363·6573···-F·key=unsucces
00000a00:·6e67·2061·6e64·2069·6e76·6573·7469·6761··ng·and·investiga00000a00:·7366·756c·2d6d·6f64·6966·6963·6174·696f··sful-modificatio
00000a10:·7469·6f6e·2e0a·2020·2020·2020·3c2f·7464··tion..······</td00000a10:·6e0a·2d61·2061·6c77·6179·732c·6578·6974··n.-a·always,exit
00000a20:·3e0a·2020·2020·3c2f·7472·3e0a·2020·2020··>.····</tr>.····00000a20:·202d·4620·6172·6368·3d62·3332·202d·5320···-F·arch=b32·-S·
00000a30:·3c74·723e·0a20·2020·2020·203c·7464·3e41··<tr>.······<td>A00000a30:·6f70·656e·202d·4620·6131·2661·6d70·3b30··open·-F·a1&amp;0
00000a40:·552d·3228·6429·3c62·722f·3e41·552d·3132··U-2(d)<br/>AU-1200000a40:·3130·3033·202d·4620·6578·6974·3d2d·4550··1003·-F·exit=-EP
00000a50:·2863·293c·6272·2f3e·434d·2d36·2861·293c··(c)<br/>CM-6(a)<00000a50:·4552·4d20·2d46·2061·7569·6426·6774·3b3d··ERM·-F·auid&gt;=
00000a60:·2f74·643e·0a20·2020·2020·203c·7464·3e52··/td>.······<td>R00000a60:·3130·3030·202d·4620·6175·6964·213d·756e··1000·-F·auid!=un
00000a70:·6563·6f72·6420·556e·7375·6363·6573·7366··ecord·Unsuccessf00000a70:·7365·7420·2d46·206b·6579·3d75·6e73·7563··set·-F·key=unsuc
00000a80:·756c·2050·6572·6d69·7373·696f·6e20·4368··ul·Permission·Ch00000a80:·6365·7373·6675·6c2d·6d6f·6469·6669·6361··cessful-modifica
00000a90:·616e·6765·7320·746f·2046·696c·6573·202d··anges·to·Files·-00000a90:·7469·6f6e·0a2d·6120·616c·7761·7973·2c65··tion.-a·always,e
00000aa0:·2073·6574·7861·7474·723c·2f74·643e·0a20···setxattr</td>.·00000aa0:·7869·7420·2d46·2061·7263·683d·6236·3420··xit·-F·arch=b64·
00000ab0:·2020·2020·203c·7464·2078·6d6c·3a6c·616e·······<td·xml:lan00000ab0:·2d53·206f·7065·6e20·2d46·2061·3126·616d··-S·open·-F·a1&am
00000ac0:·673d·2265·6e2d·5553·223e·0a20·2020·2020··g="en-US">.·····00000ac0:·703b·3031·3030·3320·2d46·2065·7869·743d··p;01003·-F·exit=
00000ad0:·2020·2054·6865·2061·7564·6974·2073·7973·····The·audit·sys00000ad0:·2d45·5045·524d·202d·4620·6175·6964·2667··-EPERM·-F·auid&g
00000ae0:·7465·6d20·7368·6f75·6c64·2063·6f6c·6c65··tem·should·colle00000ae0:·743b·3d31·3030·3020·2d46·2061·7569·6421··t;=1000·-F·auid!
00000af0:·6374·2075·6e73·7563·6365·7373·6675·6c20··ct·unsuccessful·00000af0:·3d75·6e73·6574·202d·4620·6b65·793d·756e··=unset·-F·key=un
00000b00:·6669·6c65·2070·6572·6d69·7373·696f·6e20··file·permission·00000b00:·7375·6363·6573·7366·756c·2d6d·6f64·6966··successful-modif
00000b10:·6368·616e·6765·0a61·7474·656d·7074·7320··change.attempts·00000b10:·6963·6174·696f·6e0a·2d61·2061·6c77·6179··ication.-a·alway
00000b20:·666f·7220·616c·6c20·7573·6572·7320·616e··for·all·users·an00000b20:·732c·6578·6974·202d·4620·6172·6368·3d62··s,exit·-F·arch=b
00000b30:·6420·726f·6f74·2e0a·4966·2074·6865·203c··d·root..If·the·<00000b30:·3332·202d·5320·7472·756e·6361·7465·2c66··32·-S·truncate,f
00000b40:·7474·3e61·7564·6974·643c·2f74·743e·2064··tt>auditd</tt>·d00000b40:·7472·756e·6361·7465·202d·4620·6578·6974··truncate·-F·exit
00000b50:·6165·6d6f·6e20·6973·2063·6f6e·6669·6775··aemon·is·configu00000b50:·3d2d·4550·4552·4d20·2d46·2061·7569·6426··=-EPERM·-F·auid&
00000b60:·7265·640a·746f·2075·7365·2074·6865·203c··red.to·use·the·<00000b60:·6774·3b3d·3130·3030·202d·4620·6175·6964··gt;=1000·-F·auid
00000b70:·7474·3e61·7567·656e·7275·6c65·733c·2f74··tt>augenrules</t00000b70:·213d·756e·7365·7420·2d46·206b·6579·3d75··!=unset·-F·key=u
00000b80:·743e·2070·726f·6772·616d·2074·6f20·7265··t>·program·to·re00000b80:·6e73·7563·6365·7373·6675·6c2d·6d6f·6469··nsuccessful-modi
00000b90:·6164·2061·7564·6974·2072·756c·6573·2064··ad·audit·rules·d00000b90:·6669·6361·7469·6f6e·0a2d·6120·616c·7761··fication.-a·alwa
00000ba0:·7572·696e·6720·6461·656d·6f6e·0a73·7461··uring·daemon.sta00000ba0:·7973·2c65·7869·7420·2d46·2061·7263·683d··ys,exit·-F·arch=
00000bb0:·7274·7570·2028·7468·6520·6465·6661·756c··rtup·(the·defaul00000bb0:·6236·3420·2d53·2074·7275·6e63·6174·652c··b64·-S·truncate,
00000bc0:·7429·2c20·6164·6420·7468·6520·666f·6c6c··t),·add·the·foll00000bc0:·6674·7275·6e63·6174·6520·2d46·2065·7869··ftruncate·-F·exi
00000bd0:·6f77·696e·6720·6c69·6e65·7320·746f·2061··owing·lines·to·a00000bd0:·743d·2d45·5045·524d·202d·4620·6175·6964··t=-EPERM·-F·auid
00000be0:·2066·696c·6520·7769·7468·2073·7566·6669···file·with·suffi00000be0:·2667·743b·3d31·3030·3020·2d46·2061·7569··&gt;=1000·-F·aui
00000bf0:·780a·3c74·743e·2e72·756c·6573·3c2f·7474··x.<tt>.rules</tt00000bf0:·6421·3d75·6e73·6574·202d·4620·6b65·793d··d!=unset·-F·key=
00000c00:·3e20·696e·2074·6865·2064·6972·6563·746f··>·in·the·directo00000c00:·756e·7375·6363·6573·7366·756c·2d6d·6f64··unsuccessful-mod
00000c10:·7279·203c·7474·3e2f·6574·632f·6175·6469··ry·<tt>/etc/audi00000c10:·6966·6963·6174·696f·6e20·2020·203c·2f70··ification····</p
Max diff block lines reached; 6738963/7682909 bytes (87.71%) of diff not shown.
9.6 MB
html2text {}
Max HTML report size reached
3.56 MB
./usr/share/doc/ssg-nondebian/table-rhel8-anssirefs.html
    
Offset 64, 280 lines modifiedOffset 64, 280 lines modified
000003f0:·3c74·683e·5275·6c65·2054·6974·6c65·3c2f··<th>Rule·Title</000003f0:·3c74·683e·5275·6c65·2054·6974·6c65·3c2f··<th>Rule·Title</
00000400:·7468·3e0a·2020·2020·3c74·683e·4465·7363··th>.····<th>Desc00000400:·7468·3e0a·2020·2020·3c74·683e·4465·7363··th>.····<th>Desc
00000410:·7269·7074·696f·6e3c·2f74·683e·0a20·2020··ription</th>.···00000410:·7269·7074·696f·6e3c·2f74·683e·0a20·2020··ription</th>.···
00000420:·203c·7468·3e52·6174·696f·6e61·6c65·3c2f···<th>Rationale</00000420:·203c·7468·3e52·6174·696f·6e61·6c65·3c2f···<th>Rationale</
00000430:·7468·3e0a·2020·3c2f·7468·6561·643e·0a20··th>.··</thead>.·00000430:·7468·3e0a·2020·3c2f·7468·6561·643e·0a20··th>.··</thead>.·
00000440:·203c·7462·6f64·793e·0a20·203c·7472·3e0a···<tbody>.··<tr>.00000440:·203c·7462·6f64·793e·0a20·203c·7472·3e0a···<tbody>.··<tr>.
00000450:·2020·2020·2020·3c74·643e·5231·3c2f·7464········<td>R1</td00000450:·2020·2020·2020·3c74·643e·5231·3c2f·7464········<td>R1</td
00000460:·3e0a·2020·2020·2020·3c74·643e·456e·7375··>.······<td>Ensu00000460:·3e0a·2020·2020·2020·3c74·643e·496e·7374··>.······<td>Inst
00000470:·7265·2053·4d45·5020·6973·206e·6f74·2064··re·SMEP·is·not·d 
00000480:·6973·6162·6c65·6420·6475·7269·6e67·2062··isabled·during·b00000470:·616c·6c20·5041·4520·4b65·726e·656c·206f··all·PAE·Kernel·o
 00000480:·6e20·5375·7070·6f72·7465·6420·3332·2d62··n·Supported·32-b
 00000490:·6974·2078·3836·2053·7973·7465·6d73·3c2f··it·x86·Systems</
 000004a0:·7464·3e0a·2020·2020·2020·3c74·6420·786d··td>.······<td·xm
 000004b0:·6c3a·6c61·6e67·3d22·656e·2d55·5322·3e0a··l:lang="en-US">.
 000004c0:·2020·2020·2020·2020·5379·7374·656d·7320··········Systems·
 000004d0:·7468·6174·2061·7265·2075·7369·6e67·2074··that·are·using·t
 000004e0:·6865·2036·342d·6269·7420·7838·3620·6b65··he·64-bit·x86·ke
 000004f0:·726e·656c·2070·6163·6b61·6765·0a64·6f20··rnel·package.do·
 00000500:·6e6f·7420·6e65·6564·2074·6f20·696e·7374··not·need·to·inst
 00000510:·616c·6c20·7468·6520·6b65·726e·656c·2d50··all·the·kernel-P
 00000520:·4145·2070·6163·6b61·6765·2062·6563·6175··AE·package·becau
 00000530:·7365·2074·6865·2036·342d·6269·740a·7838··se·the·64-bit.x8
 00000540:·3620·6b65·726e·656c·2061·6c72·6561·6479··6·kernel·already
 00000550:·2069·6e63·6c75·6465·7320·7468·6973·2073···includes·this·s
 00000560:·7570·706f·7274·2e20·486f·7765·7665·722c··upport.·However,
 00000570:·2069·6620·7468·6520·7379·7374·656d·2069···if·the·system·i
 00000580:·730a·3332·2d62·6974·2061·6e64·2061·6c73··s.32-bit·and·als
 00000590:·6f20·7375·7070·6f72·7473·2074·6865·2050··o·supports·the·P
 000005a0:·4145·2061·6e64·204e·5820·6665·6174·7572··AE·and·NX·featur
 000005b0:·6573·2061·730a·6465·7465·726d·696e·6564··es·as.determined
 000005c0:·2069·6e20·7468·6520·7072·6576·696f·7573···in·the·previous
 000005d0:·2073·6563·7469·6f6e·2c20·7468·6520·6b65···section,·the·ke
 000005e0:·726e·656c·2d50·4145·2070·6163·6b61·6765··rnel-PAE·package
 000005f0:·2073·686f·756c·640a·6265·2069·6e73·7461···should.be·insta
 00000600:·6c6c·6564·2074·6f20·656e·6162·6c65·2058··lled·to·enable·X
 00000610:·4420·6f72·204e·5820·7375·7070·6f72·742e··D·or·NX·support.
 00000620:·0a54·6865·203c·636f·6465·3e6b·6572·6e65··.The·<code>kerne
 00000630:·6c2d·5041·453c·2f63·6f64·653e·2070·6163··l-PAE</code>·pac
 00000640:·6b61·6765·2063·616e·2062·6520·696e·7374··kage·can·be·inst
 00000650:·616c·6c65·6420·7769·7468·2074·6865·2066··alled·with·the·f
 00000660:·6f6c·6c6f·7769·6e67·2063·6f6d·6d61·6e64··ollowing·command
 00000670:·3a0a·3c70·7265·3e0a·2420·7375·646f·2079··:.<pre>.$·sudo·y
 00000680:·756d·2069·6e73·7461·6c6c·206b·6572·6e65··um·install·kerne
 00000690:·6c2d·5041·453c·2f70·7265·3e0a·5468·6520··l-PAE</pre>.The·
 000006a0:·696e·7374·616c·6c61·7469·6f6e·2070·726f··installation·pro
 000006b0:·6365·7373·2073·686f·756c·6420·616c·736f··cess·should·also
 000006c0:·2068·6176·6520·636f·6e66·6967·7572·6564···have·configured
 000006d0:·2074·6865·0a62·6f6f·746c·6f61·6465·7220···the.bootloader·
 000006e0:·746f·206c·6f61·6420·7468·6520·6e65·7720··to·load·the·new·
 000006f0:·6b65·726e·656c·2061·7420·626f·6f74·2e20··kernel·at·boot.·
 00000700:·5665·7269·6679·2074·6869·7320·6166·7465··Verify·this·afte
 00000710:·7220·7265·626f·6f74·0a61·6e64·206d·6f64··r·reboot.and·mod
 00000720:·6966·7920·3c74·743e·2f65·7463·2f64·6566··ify·<tt>/etc/def
 00000730:·6175·6c74·2f67·7275·623c·2f74·743e·2069··ault/grub</tt>·i
 00000740:·6620·6e65·6365·7373·6172·792e·0a20·2020··f·necessary..···
00000490:·6f6f·743c·2f74·643e·0a20·2020·2020·203c··oot</td>.······<00000750:·2020·203c·2f74·643e·0a20·2020·2020·203c·····</td>.······<
000004a0:·7464·2078·6d6c·3a6c·616e·673d·2265·6e2d··td·xml:lang="en-00000760:·7464·2078·6d6c·3a6c·616e·673d·2265·6e2d··td·xml:lang="en-
000004b0:·5553·223e·0a20·2020·2020·2020·2054·6865··US">.········The00000770:·5553·223e·0a20·2020·2020·2020·204f·6e20··US">.········On·
 00000780:·3332·2d62·6974·2073·7973·7465·6d73·2074··32-bit·systems·t
 00000790:·6861·7420·7375·7070·6f72·7420·7468·6520··hat·support·the·
 000007a0:·5844·206f·7220·4e58·2062·6974·2c20·7468··XD·or·NX·bit,·th
 000007b0:·6520·7665·6e64·6f72·2d73·7570·706c·6965··e·vendor-supplie
 000007c0:·640a·5041·4520·6b65·726e·656c·2069·7320··d.PAE·kernel·is·
 000007d0:·7265·7175·6972·6564·2074·6f20·656e·6162··required·to·enab
 000007e0:·6c65·2065·6974·6865·7220·4578·6563·7574··le·either·Execut
 000007f0:·6520·4469·7361·626c·6520·2858·4429·206f··e·Disable·(XD)·o
 00000800:·7220·4e6f·2045·7865·6375·7465·2028·4e58··r·No·Execute·(NX
 00000810:·2920·7375·7070·6f72·742e·0a20·2020·2020··)·support..·····
000004c0:·2053·4d45·5020·6973·2075·7365·6420·746f···SMEP·is·used·to 
000004d0:·2070·7265·7665·6e74·2074·6865·2073·7570···prevent·the·sup 
000004e0:·6572·7669·736f·7220·6d6f·6465·2066·726f··ervisor·mode·fro 
000004f0:·6d20·6578·6563·7574·696e·6720·7573·6572··m·executing·user 
00000500:·2073·7061·6365·2063·6f64·652c·0a69·7420···space·code,.it· 
00000510:·6973·2065·6e61·626c·6564·2062·7920·6465··is·enabled·by·de 
00000520:·6661·756c·7420·7369·6e63·6520·4c69·6e75··fault·since·Linu 
00000530:·7820·6b65·726e·656c·2033·2e30·2e20·4275··x·kernel·3.0.·Bu 
00000540:·7420·6974·2063·6f75·6c64·2062·6520·6469··t·it·could·be·di 
00000550:·7361·626c·6564·2074·6872·6f75·6768·0a6b··sabled·through.k 
00000560:·6572·6e65·6c20·626f·6f74·2070·6172·616d··ernel·boot·param 
00000570:·6574·6572·732e·0a0a·456e·7375·7265·2074··eters...Ensure·t 
00000580:·6861·7420·5375·7065·7276·6973·6f72·204d··hat·Supervisor·M 
00000590:·6f64·6520·4578·6563·7574·696f·6e20·5072··ode·Execution·Pr 
000005a0:·6576·656e·7469·6f6e·2028·534d·4550·2920··evention·(SMEP)· 
000005b0:·6973·206e·6f74·2064·6973·6162·6c65·6420··is·not·disabled· 
000005c0:·6279·0a74·6865·203c·7474·3e6e·6f73·6d65··by.the·<tt>nosme 
000005d0:·703c·2f74·743e·2062·6f6f·7420·7061·7261··p</tt>·boot·para 
000005e0:·6d65·6e74·6572·206f·7074·696f·6e2e·0a0a··menter·option... 
000005f0:·4368·6563·6b20·7468·6174·2074·6865·206c··Check·that·the·l 
00000600:·696e·6520·3c70·7265·3e47·5255·425f·434d··ine·<pre>GRUB_CM 
00000610:·444c·494e·455f·4c49·4e55·583d·222e·2e2e··DLINE_LINUX="... 
00000620:·223c·2f70·7265·3e20·7769·7468·696e·203c··"</pre>·within·< 
00000630:·7474·3e2f·6574·632f·6465·6661·756c·742f··tt>/etc/default/ 
00000640:·6772·7562·3c2f·7474·3e0a·646f·6573·6e27··grub</tt>.doesn' 
00000650:·7420·636f·6e74·6169·6e20·7468·6520·6172··t·contain·the·ar 
00000660:·6775·6d65·6e74·203c·7474·3e6e·6f73·6d65··gument·<tt>nosme 
00000670:·703c·2f74·743e·2e0a·5275·6e20·7468·6520··p</tt>..Run·the· 
00000680:·666f·6c6c·6f77·696e·6720·636f·6d6d·616e··following·comman 
00000690:·6420·746f·2075·7064·6174·6520·636f·6d6d··d·to·update·comm 
000006a0:·616e·6420·6c69·6e65·2066·6f72·2061·6c72··and·line·for·alr 
000006b0:·6561·6479·2069·6e73·7461·6c6c·6564·206b··eady·installed·k 
000006c0:·6572·6e65·6c73·3a0a·3c70·7265·3e23·2067··ernels:.<pre>#·g 
000006d0:·7275·6262·7920·2d2d·7570·6461·7465·2d6b··rubby·--update-k 
000006e0:·6572·6e65·6c3d·414c·4c20·2d2d·7265·6d6f··ernel=ALL·--remo 
000006f0:·7665·2d61·7267·733d·226e·6f73·6d65·7022··ve-args="nosmep" 
00000700:·3c2f·7072·653e·0a20·2020·2020·203c·2f74··</pre>.······</t 
00000710:·643e·0a20·2020·2020·203c·7464·2078·6d6c··d>.······<td·xml 
00000720:·3a6c·616e·673d·2265·6e2d·5553·223e·0a20··:lang="en-US">.· 
00000730:·2020·2020·2020·2044·6973·6162·6c69·6e67·········Disabling 
00000740:·2053·4d45·5020·6361·6e20·6661·6369·6c69···SMEP·can·facili 
00000750:·7461·7465·2065·7870·6c6f·6974·6174·696f··tate·exploitatio 
00000760:·6e20·6f66·2063·6572·7461·696e·2076·756c··n·of·certain·vul 
00000770:·6e65·7261·6269·6c69·7469·6573·2062·6563··nerabilities·bec 
00000780:·6175·7365·2069·7420·616c·6c6f·7773·0a74··ause·it·allows.t 
00000790:·6865·206b·6572·6e65·6c20·746f·2075·6e69··he·kernel·to·uni 
000007a0:·6e74·656e·7469·6f6e·616c·6c79·2065·7865··ntentionally·exe 
000007b0:·6375·7465·2063·6f64·6520·696e·206c·6573··cute·code·in·les 
000007c0:·7320·7072·6976·696c·6567·6564·206d·656d··s·privileged·mem 
000007d0:·6f72·7920·7370·6163·652e·0a20·2020·2020··ory·space..····· 
000007e0:·203c·2f74·643e·0a20·2020·203c·2f74·723e···</td>.····</tr>00000820:·203c·2f74·643e·0a20·2020·203c·2f74·723e···</td>.····</tr>
000007f0:·0a20·2020·203c·7472·3e0a·2020·2020·2020··.····<tr>.······00000830:·0a20·2020·203c·7472·3e0a·2020·2020·2020··.····<tr>.······
00000800:·3c74·643e·5231·3c2f·7464·3e0a·2020·2020··<td>R1</td>.····00000840:·3c74·643e·5231·3c2f·7464·3e0a·2020·2020··<td>R1</td>.····
 00000850:·2020·3c74·643e·456e·7375·7265·2053·4d41····<td>Ensure·SMA
 00000860:·5020·6973·206e·6f74·2064·6973·6162·6c65··P·is·not·disable
 00000870:·6420·6475·7269·6e67·2062·6f6f·743c·2f74··d·during·boot</t
00000810:·2020·3c74·643e·5072·6566·6572·2074·6f20····<td>Prefer·to· 
00000820:·7573·6520·6120·3634·2d62·6974·204f·7065··use·a·64-bit·Ope 
00000830:·7261·7469·6e67·2053·7973·7465·6d20·7768··rating·System·wh 
Max diff block lines reached; 3011567/3048021 bytes (98.80%) of diff not shown.
672 KB
html2text {}
    
Offset 1, 35 lines modifiedOffset 1, 13 lines modified
  
  
1 Rules·with·ANSSI·Reference·in·Guide·to·the·Secure·Configuration·of·Red·Hat1 Rules·with·ANSSI·Reference·in·Guide·to·the·Secure·Configuration·of·Red·Hat
2 Enterprise·Linux·82 Enterprise·Linux·8
  
  
3 ······························The·SMEP·is·used·to·prevent·the·supervisor 
4 ······························mode·from·executing·user·space·code,·it·is 
5 ······························enabled·by·default·since·Linux·kernel·3.0. 
6 ······························But·it·could·be·disabled·through·kernel·boot 
7 ······························parameters.·Ensure·that·Supervisor·Mode 
8 ······························Execution·Prevention·(SMEP)·is·not·disabled··Disabling·SMEP·can·facilitate 
9 ····Ensure·SMEP·is·not········by·the·nosmep·boot·paramenter·option.·Check··exploitation·of·certain 
10 R1··disabled·during·boot······that·the·line································vulnerabilities·because·it·allows·the 
11 ······························GRUB_CMDLINE_LINUX="..."·····················kernel·to·unintentionally·execute·code 
12 ······························within·/etc/default/grub·doesn't·contain·the·in·less·privileged·memory·space. 
13 ······························argument·nosmep.·Run·the·following·command 
14 ······························to·update·command·line·for·already·installed 
15 ······························kernels: 
16 ······························#·grubby·--update-kernel=ALL·--remove- 
17 ······························args="nosmep" 
18 ···········································································Use·of·a·64-bit·operating·system 
19 ···········································································offers·a·few·advantages,·like·a·larger 
20 ····Prefer·to·use·a·64-bit····Prefer·installation·of·64-bit·operating······address·space·range·for·Address·Space 
21 R1··Operating·System·when·····systems·when·the·CPU·supports·it.············Layout·Randomization·(ASLR)·and 
22 ····supported······························································systematic·presence·of·No·eXecute·and 
23 ···········································································Execute·Disable·(NX/XD)·protection 
24 ···········································································bits. 
25 ······························Systems·that·are·using·the·64-bit·x86·kernel3 ······························Systems·that·are·using·the·64-bit·x86·kernel
26 ······························package·do·not·need·to·install·the·kernel-4 ······························package·do·not·need·to·install·the·kernel-
27 ······························PAE·package·because·the·64-bit·x86·kernel5 ······························PAE·package·because·the·64-bit·x86·kernel
28 ······························already·includes·this·support.·However,·if6 ······························already·includes·this·support.·However,·if
29 ······························the·system·is·32-bit·and·also·supports·the7 ······························the·system·is·32-bit·and·also·supports·the
30 ······························PAE·and·NX·features·as·determined·in·the·····On·32-bit·systems·that·support·the·XD8 ······························PAE·and·NX·features·as·determined·in·the·····On·32-bit·systems·that·support·the·XD
31 ····Install·PAE·Kernel·on·····previous·section,·the·kernel-PAE·package·····or·NX·bit,·the·vendor-supplied·PAE9 ····Install·PAE·Kernel·on·····previous·section,·the·kernel-PAE·package·····or·NX·bit,·the·vendor-supplied·PAE
Offset 62, 31 lines modifiedOffset 40, 53 lines modified
62 ······························Advanced·Encryption·Standard·(AES)·or·New····utilizing·encryption·to·protect·data.40 ······························Advanced·Encryption·Standard·(AES)·or·New····utilizing·encryption·to·protect·data.
63 ····Install·the·dracut-fips-··Instructions·(AES-NI)·engine,·the·system·····The·operating·system·must·implement41 ····Install·the·dracut-fips-··Instructions·(AES-NI)·engine,·the·system·····The·operating·system·must·implement
64 R1··aesni·Package·············requires·that·the·dracut-fips-aesni·package··cryptographic·modules·adhering·to·the42 R1··aesni·Package·············requires·that·the·dracut-fips-aesni·package··cryptographic·modules·adhering·to·the
65 ······························be·installed.·The·dracut-fips-aesni·package··higher·standards·approved·by·the43 ······························be·installed.·The·dracut-fips-aesni·package··higher·standards·approved·by·the
66 ······························can·be·installed·with·the·following·command:·federal·government·since·this·provides44 ······························can·be·installed·with·the·following·command:·federal·government·since·this·provides
67 ······························$·sudo·yum·install·dracut-fips-aesni·········assurance·they·have·been·tested·and45 ······························$·sudo·yum·install·dracut-fips-aesni·········assurance·they·have·been·tested·and
68 ···········································································validated.46 ···········································································validated.
 47 ······························The·SMEP·is·used·to·prevent·the·supervisor
 48 ······························mode·from·executing·user·space·code,·it·is
 49 ······························enabled·by·default·since·Linux·kernel·3.0.
 50 ······························But·it·could·be·disabled·through·kernel·boot
 51 ······························parameters.·Ensure·that·Supervisor·Mode
 52 ······························Execution·Prevention·(SMEP)·is·not·disabled··Disabling·SMEP·can·facilitate
 53 ····Ensure·SMEP·is·not········by·the·nosmep·boot·paramenter·option.·Check··exploitation·of·certain
 54 R1··disabled·during·boot······that·the·line································vulnerabilities·because·it·allows·the
 55 ······························GRUB_CMDLINE_LINUX="..."·····················kernel·to·unintentionally·execute·code
 56 ······························within·/etc/default/grub·doesn't·contain·the·in·less·privileged·memory·space.
 57 ······························argument·nosmep.·Run·the·following·command
 58 ······························to·update·command·line·for·already·installed
 59 ······························kernels:
 60 ······························#·grubby·--update-kernel=ALL·--remove-
 61 ······························args="nosmep"
 62 ···········································································Use·of·a·64-bit·operating·system
 63 ···········································································offers·a·few·advantages,·like·a·larger
 64 ····Prefer·to·use·a·64-bit····Prefer·installation·of·64-bit·operating······address·space·range·for·Address·Space
 65 R1··Operating·System·when·····systems·when·the·CPU·supports·it.············Layout·Randomization·(ASLR)·and
 66 ····supported······························································systematic·presence·of·No·eXecute·and
 67 ···········································································Execute·Disable·(NX/XD)·protection
 68 ···········································································bits.
69 ······························The·grub2·boot·loader·should·have·a69 ······························The·grub2·boot·loader·should·have·a
70 ······························superuser·account·and·password·protection70 ······························superuser·account·and·password·protection
71 ······························enabled·to·protect·boot-time·settings.·······Password·protection·on·the·boot·loader71 ······························enabled·to·protect·boot-time·settings.·······Password·protection·on·the·boot·loader
72 ···········································································configuration·ensures·users·with72 ···········································································configuration·ensures·users·with
73 ····Set·Boot·Loader·Password··Since·plaintext·passwords·are·a·security·····physical·access·cannot·trivially·alter73 ····Set·the·UEFI·Boot·Loader··Since·plaintext·passwords·are·a·security·····physical·access·cannot·trivially·alter
74 R5··in·grub2··················risk,·generate·a·hash·for·the·password·by····important·bootloader·settings.·These74 R5··Password··················risk,·generate·a·hash·for·the·password·by····important·bootloader·settings.·These
75 ······························running·the·following·command:···············include·which·kernel·to·use,·and75 ······························running·the·following·command:···············include·which·kernel·to·use,·and
76 ······························#·grub2-setpassword··························whether·to·enter·single-user·mode.76 ······························#·grub2-setpassword··························whether·to·enter·single-user·mode.
77 ······························When·prompted,·enter·the·password·that·was77 ······························When·prompted,·enter·the·password·that·was
78 ······························selected.78 ······························selected.
  
79 ······························The·grub2·boot·loader·should·have·a79 ······························The·grub2·boot·loader·should·have·a
80 ······························superuser·account·and·password·protection80 ······························superuser·account·and·password·protection
81 ······························enabled·to·protect·boot-time·settings.·······Password·protection·on·the·boot·loader81 ······························enabled·to·protect·boot-time·settings.·······Password·protection·on·the·boot·loader
82 ···········································································configuration·ensures·users·with82 ···········································································configuration·ensures·users·with
83 ····Set·the·UEFI·Boot·Loader··Since·plaintext·passwords·are·a·security·····physical·access·cannot·trivially·alter83 ····Set·Boot·Loader·Password··Since·plaintext·passwords·are·a·security·····physical·access·cannot·trivially·alter
84 R5··Password··················risk,·generate·a·hash·for·the·password·by····important·bootloader·settings.·These84 R5··in·grub2··················risk,·generate·a·hash·for·the·password·by····important·bootloader·settings.·These
85 ······························running·the·following·command:···············include·which·kernel·to·use,·and85 ······························running·the·following·command:···············include·which·kernel·to·use,·and
86 ······························#·grub2-setpassword··························whether·to·enter·single-user·mode.86 ······························#·grub2-setpassword··························whether·to·enter·single-user·mode.
87 ······························When·prompted,·enter·the·password·that·was87 ······························When·prompted,·enter·the·password·that·was
88 ······························selected.88 ······························selected.
  
89 ······························On·x86·architecture·supporting·VT-d,·the89 ······························On·x86·architecture·supporting·VT-d,·the
90 ······························IOMMU·manages·the·access·control·policy90 ······························IOMMU·manages·the·access·control·policy
Offset 99, 77 lines modifiedOffset 99, 14 lines modified
99 ······························systems.·Modify·the·line·within·/etc/········hardware·devices.99 ······························systems.·Modify·the·line·within·/etc/········hardware·devices.
100 ······························default/grub·as·shown·below:100 ······························default/grub·as·shown·below:
101 ······························GRUB_CMDLINE_LINUX="...·iommu=force·..."101 ······························GRUB_CMDLINE_LINUX="...·iommu=force·..."
102 ······························Run·the·following·command·to·update·command102 ······························Run·the·following·command·to·update·command
103 ······························line·for·already·installed·kernels:103 ······························line·for·already·installed·kernels:
104 ······························#·grubby·--update-kernel=ALL·--104 ······························#·grubby·--update-kernel=ALL·--
105 ······························args="iommu=force"105 ······························args="iommu=force"
106 ······························To·enable·poisoning·of·SLUB/SLAB·objects, 
107 ······························add·the·argument·slub_debug=P·to·the·default 
108 ······························GRUB·2·command·line·for·the·Linux·operating··Poisoning·writes·an·arbitrary·value·to 
109 ······························system.·To·ensure·that·slub_debug=P·is·added·freed·objects,·so·any·modification·or 
110 ······························as·a·kernel·command·line·argument·to·newly···reference·to·that·object·after·being 
111 ······························installed·kernels,·add·slub_debug=P·to·the···freed·or·before·being·initialized·will 
112 R8··Enable·SLUB/SLAB··········default·Grub2·command·line·for·Linux·········be·detected·and·prevented.·This 
113 ····allocator·poisoning·······operating·systems.·Modify·the·line·within·/··prevents·many·types·of·use-after-free 
114 ······························etc/default/grub·as·shown·below:·············vulnerabilities·at·little·performance 
115 ······························GRUB_CMDLINE_LINUX="...·slub_debug=P·..."····cost.·Also·prevents·leak·of·data·and 
116 ······························Run·the·following·command·to·update·command··detection·of·corrupted·memory. 
117 ······························line·for·already·installed·kernels: 
118 ······························#·grubby·--update-kernel=ALL·-- 
119 ······························args="slub_debug=P" 
120 ······························L1·Terminal·Fault·(L1TF)·is·a·hardware 
121 ······························vulnerability·which·allows·unprivileged 
122 ······························speculative·access·to·data·which·is 
123 ······························available·in·the·Level·1·Data·Cache·when·the 
124 ······························page·table·entry·isn't·present.·Select·the 
125 ······························appropriate·mitigation·by·adding·the 
126 ······························argument·l1tf=flush·to·the·default·GRUB·2 
127 ······························command·line·for·the·Linux·operating·system. 
128 ······························To·ensure·that·l1tf=flush·is·added·as·a······The·L1TF·vulnerability·allows·an 
129 ······························kernel·command·line·argument·to·newly········attacker·to·bypass·memory·access 
130 ····Configure·L1·Terminal·····installed·kernels,·add·l1tf=flush·to·the·····security·controls·imposed·by·the 
131 R8··Fault·mitigations·········default·Grub2·command·line·for·Linux·········system·or·hypervisor.·The·L1TF 
132 ······························operating·systems.·Modify·the·line·within·/··vulnerability·allows·read·access·to 
133 ······························etc/default/grub·as·shown·below:·············any·physical·memory·location·that·is 
134 ······························GRUB_CMDLINE_LINUX="...·l1tf=flush·..."······cached·in·the·L1·Data·Cache. 
135 ······························Run·the·following·command·to·update·command 
Max diff block lines reached; 673286/687843 bytes (97.88%) of diff not shown.
1.39 MB
./usr/share/doc/ssg-nondebian/table-rhel8-cisrefs.html
    
Offset 1623, 144 lines modifiedOffset 1623, 144 lines modified
00006560:·6520·7468·6520·7379·7374·656d·2074·6f20··e·the·system·to·00006560:·6520·7468·6520·7379·7374·656d·2074·6f20··e·the·system·to·
00006570:·706f·7465·6e74·6961·6c20·636f·6d70·726f··potential·compro00006570:·706f·7465·6e74·6961·6c20·636f·6d70·726f··potential·compro
00006580:·6d69·7365·2e0a·2020·2020·2020·3c2f·7464··mise..······</td00006580:·6d69·7365·2e0a·2020·2020·2020·3c2f·7464··mise..······</td
00006590:·3e0a·2020·2020·3c2f·7472·3e0a·2020·2020··>.····</tr>.····00006590:·3e0a·2020·2020·3c2f·7472·3e0a·2020·2020··>.····</tr>.····
000065a0:·3c74·723e·0a20·2020·2020·203c·7464·3e31··<tr>.······<td>1000065a0:·3c74·723e·0a20·2020·2020·203c·7464·3e31··<tr>.······<td>1
000065b0:·2e32·2e32·3c2f·7464·3e0a·2020·2020·2020··.2.2</td>.······000065b0:·2e32·2e32·3c2f·7464·3e0a·2020·2020·2020··.2.2</td>.······
000065c0:·3c74·643e·456e·7375·7265·2067·7067·6368··<td>Ensure·gpgch000065c0:·3c74·643e·456e·7375·7265·2067·7067·6368··<td>Ensure·gpgch
000065d0:·6563·6b20·456e·6162·6c65·6420·666f·7220··eck·Enabled·for·000065d0:·6563·6b20·456e·6162·6c65·6420·496e·204d··eck·Enabled·In·M
 000065e0:·6169·6e20·7975·6d20·436f·6e66·6967·7572··ain·yum·Configur
 000065f0:·6174·696f·6e3c·2f74·643e·0a20·2020·2020··ation</td>.·····
 00006600:·203c·7464·2078·6d6c·3a6c·616e·673d·2265···<td·xml:lang="e
000065e0:·416c·6c20·7975·6d20·5061·636b·6167·6520··All·yum·Package· 
000065f0:·5265·706f·7369·746f·7269·6573·3c2f·7464··Repositories</td 
00006600:·3e0a·2020·2020·2020·3c74·6420·786d·6c3a··>.······<td·xml: 
00006610:·6c61·6e67·3d22·656e·2d55·5322·3e0a·2020··lang="en-US">.·· 
00006620:·2020·2020·2020·546f·2065·6e73·7572·6520········To·ensure· 
00006630:·7369·676e·6174·7572·6520·6368·6563·6b69··signature·checki 
00006640:·6e67·2069·7320·6e6f·7420·6469·7361·626c··ng·is·not·disabl 
00006650:·6564·2066·6f72·0a61·6e79·2072·6570·6f73··ed·for.any·repos 
00006660:·2c20·7265·6d6f·7665·2061·6e79·206c·696e··,·remove·any·lin 
00006670:·6573·2066·726f·6d20·6669·6c65·7320·696e··es·from·files·in 
00006680:·203c·7474·3e2f·6574·632f·7975·6d2e·7265···<tt>/etc/yum.re 
00006690:·706f·732e·643c·2f74·743e·206f·6620·7468··pos.d</tt>·of·th 
000066a0:·6520·666f·726d·3a0a·3c70·7265·3e67·7067··e·form:.<pre>gpg 
000066b0:·6368·6563·6b3d·303c·2f70·7265·3e0a·2020··check=0</pre>.·· 
000066c0:·2020·2020·3c2f·7464·3e0a·2020·2020·2020······</td>.······ 
000066d0:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en 
000066e0:·2d55·5322·3e0a·2020·2020·2020·2020·5665··-US">.········Ve00006610:·6e2d·5553·223e·0a20·2020·2020·2020·2054··n-US">.········T
000066f0:·7269·6679·696e·6720·7468·6520·6175·7468··rifying·the·auth 
00006700:·656e·7469·6369·7479·206f·6620·7468·6520··enticity·of·the· 
00006710:·736f·6674·7761·7265·2070·7269·6f72·2074··software·prior·t00006620:·6865·203c·7474·3e67·7067·6368·6563·6b3c··he·<tt>gpgcheck<
 00006630:·2f74·743e·206f·7074·696f·6e20·636f·6e74··/tt>·option·cont
 00006640:·726f·6c73·2077·6865·7468·6572·0a52·504d··rols·whether.RPM
 00006650:·2070·6163·6b61·6765·7327·2073·6967·6e61···packages'·signa
 00006660:·7475·7265·7320·6172·6520·616c·7761·7973··tures·are·always
 00006670:·2063·6865·636b·6564·2070·7269·6f72·2074···checked·prior·t
00006720:·6f20·696e·7374·616c·6c61·7469·6f6e·2076··o·installation·v00006680:·6f20·696e·7374·616c·6c61·7469·6f6e·2e0a··o·installation..
 00006690:·546f·2063·6f6e·6669·6775·7265·2079·756d··To·configure·yum
 000066a0:·2074·6f20·6368·6563·6b20·7061·636b·6167···to·check·packag
 000066b0:·6520·7369·676e·6174·7572·6573·2062·6566··e·signatures·bef
 000066c0:·6f72·6520·696e·7374·616c·6c69·6e67·0a74··ore·installing.t
 000066d0:·6865·6d2c·2065·6e73·7572·6520·7468·6520··hem,·ensure·the·
 000066e0:·666f·6c6c·6f77·696e·6720·6c69·6e65·2061··following·line·a
 000066f0:·7070·6561·7273·2069·6e20·3c74·743e·2f65··ppears·in·<tt>/e
 00006700:·7463·2f79·756d·2e63·6f6e·663c·2f74·743e··tc/yum.conf</tt>
 00006710:·2069·6e0a·7468·6520·3c74·743e·5b6d·6169···in.the·<tt>[mai
 00006720:·6e5d·3c2f·7474·3e20·7365·6374·696f·6e3a··n]</tt>·section:
 00006730:·0a3c·7072·653e·6770·6763·6865·636b·3d31··.<pre>gpgcheck=1
 00006740:·3c2f·7072·653e·0a20·2020·2020·203c·2f74··</pre>.······</t
 00006750:·643e·0a20·2020·2020·203c·7464·2078·6d6c··d>.······<td·xml
 00006760:·3a6c·616e·673d·2265·6e2d·5553·223e·0a20··:lang="en-US">.·
 00006770:·2020·2020·2020·2043·6861·6e67·6573·2074·········Changes·t
 00006780:·6f20·616e·7920·736f·6674·7761·7265·2063··o·any·software·c
 00006790:·6f6d·706f·6e65·6e74·7320·6361·6e20·6861··omponents·can·ha
 000067a0:·7665·2073·6967·6e69·6669·6361·6e74·2065··ve·significant·e
 000067b0:·6666·6563·7473·206f·6e20·7468·650a·6f76··ffects·on·the.ov
 000067c0:·6572·616c·6c20·7365·6375·7269·7479·206f··erall·security·o
 000067d0:·6620·7468·6520·6f70·6572·6174·696e·6720··f·the·operating·
 000067e0:·7379·7374·656d·2e20·5468·6973·2072·6571··system.·This·req
 000067f0:·7569·7265·6d65·6e74·2065·6e73·7572·6573··uirement·ensures
 00006800:·2074·6865·0a73·6f66·7477·6172·6520·6861···the.software·ha
 00006810:·7320·6e6f·7420·6265·656e·2074·616d·7065··s·not·been·tampe
 00006820:·7265·6420·7769·7468·2061·6e64·2074·6861··red·with·and·tha
 00006830:·7420·6974·2068·6173·2062·6565·6e20·7072··t·it·has·been·pr
 00006840:·6f76·6964·6564·2062·7920·610a·7472·7573··ovided·by·a.trus
 00006850:·7465·6420·7665·6e64·6f72·2e0a·3c62·7220··ted·vendor..<br·
 00006860:·2f3e·0a41·6363·6f72·6469·6e67·6c79·2c20··/>.Accordingly,·
 00006870:·7061·7463·6865·732c·2073·6572·7669·6365··patches,·service
 00006880:·2070·6163·6b73·2c20·6465·7669·6365·2064···packs,·device·d
 00006890:·7269·7665·7273·2c20·6f72·206f·7065·7261··rivers,·or·opera
 000068a0:·7469·6e67·2073·7973·7465·6d0a·636f·6d70··ting·system.comp
 000068b0:·6f6e·656e·7473·206d·7573·7420·6265·2073··onents·must·be·s
 000068c0:·6967·6e65·6420·7769·7468·2061·2063·6572··igned·with·a·cer
 000068d0:·7469·6669·6361·7465·2072·6563·6f67·6e69··tificate·recogni
 000068e0:·7a65·6420·616e·6420·6170·7072·6f76·6564··zed·and·approved
 000068f0:·2062·7920·7468·650a·6f72·6761·6e69·7a61···by·the.organiza
 00006900:·7469·6f6e·2e0a·3c62·7220·2f3e·5665·7269··tion..<br·/>Veri
 00006910:·6679·696e·6720·7468·6520·6175·7468·656e··fying·the·authen
 00006920:·7469·6369·7479·206f·6620·7468·6520·736f··ticity·of·the·so
 00006930:·6674·7761·7265·2070·7269·6f72·2074·6f20··ftware·prior·to·
 00006940:·696e·7374·616c·6c61·7469·6f6e·0a76·616c··installation.val
00006730:·616c·6964·6174·6573·0a74·6865·2069·6e74··alidates.the·int00006950:·6964·6174·6573·2074·6865·2069·6e74·6567··idates·the·integ
00006740:·6567·7269·7479·206f·6620·7468·6520·7061··egrity·of·the·pa00006960:·7269·7479·206f·6620·7468·6520·7061·7463··rity·of·the·patc
00006750:·7463·6820·6f72·2075·7067·7261·6465·2072··tch·or·upgrade·r00006970:·6820·6f72·2075·7067·7261·6465·2072·6563··h·or·upgrade·rec
00006760:·6563·6569·7665·6420·6672·6f6d·2061·2076··eceived·from·a·v00006980:·6569·7665·6420·6672·6f6d·2061·2076·656e··eived·from·a·ven
00006770:·656e·646f·722e·2054·6869·7320·656e·7375··endor.·This·ensu00006990:·646f·722e·0a54·6869·7320·656e·7375·7265··dor..This·ensure
00006780:·7265·730a·7468·6520·736f·6674·7761·7265··res.the·software000069a0:·7320·7468·6520·736f·6674·7761·7265·2068··s·the·software·h
00006790:·2068·6173·206e·6f74·2062·6565·6e20·7461···has·not·been·ta000069b0:·6173·206e·6f74·2062·6565·6e20·7461·6d70··as·not·been·tamp
000067a0:·6d70·6572·6564·2077·6974·6820·616e·6420··mpered·with·and·000069c0:·6572·6564·2077·6974·6820·616e·6420·7468··ered·with·and·th
000067b0:·7468·6174·2069·7420·6861·7320·6265·656e··that·it·has·been000069d0:·6174·2069·7420·6861·7320·6265·656e·0a70··at·it·has·been.p
000067c0:·2070·726f·7669·6465·6420·6279·2061·0a74···provided·by·a.t000069e0:·726f·7669·6465·6420·6279·2061·2074·7275··rovided·by·a·tru
000067d0:·7275·7374·6564·2076·656e·646f·722e·2053··rusted·vendor.·S000069f0:·7374·6564·2076·656e·646f·722e·2053·656c··sted·vendor.·Sel
000067e0:·656c·662d·7369·676e·6564·2063·6572·7469··elf-signed·certi00006a00:·662d·7369·676e·6564·2063·6572·7469·6669··f-signed·certifi
000067f0:·6669·6361·7465·7320·6172·6520·6469·7361··ficates·are·disa00006a10:·6361·7465·7320·6172·6520·6469·7361·6c6c··cates·are·disall
00006800:·6c6c·6f77·6564·2062·7920·7468·6973·0a72··llowed·by·this.r00006a20:·6f77·6564·2062·790a·7468·6973·2072·6571··owed·by.this·req
00006810:·6571·7569·7265·6d65·6e74·2e20·4365·7274··equirement.·Cert00006a30:·7569·7265·6d65·6e74·2e20·4365·7274·6966··uirement.·Certif
00006820:·6966·6963·6174·6573·2075·7365·6420·746f··ificates·used·to00006a40:·6963·6174·6573·2075·7365·6420·746f·2076··icates·used·to·v
00006830:·2076·6572·6966·7920·7468·6520·736f·6674···verify·the·soft00006a50:·6572·6966·7920·7468·6520·736f·6674·7761··erify·the·softwa
00006840:·7761·7265·206d·7573·7420·6265·2066·726f··ware·must·be·fro00006a60:·7265·206d·7573·7420·6265·2066·726f·6d20··re·must·be·from·
00006850:·6d20·616e·0a61·7070·726f·7665·6420·4365··m·an.approved·Ce00006a70:·616e·0a61·7070·726f·7665·6420·4365·7274··an.approved·Cert
00006860:·7274·6966·6963·6174·6520·4175·7468·6f72··rtificate·Author00006a80:·6966·6963·6174·6520·4175·7468·6f72·6974··ificate·Authorit
00006870:·6974·7920·2843·4129·2e22·0a20·2020·2020··ity·(CA).".·····00006a90:·7920·2843·4129·2e0a·2020·2020·2020·3c2f··y·(CA)..······</
 00006aa0:·7464·3e0a·2020·2020·3c2f·7472·3e0a·2020··td>.····</tr>.··
00006880:·203c·2f74·643e·0a20·2020·203c·2f74·723e···</td>.····</tr> 
00006890:·0a20·2020·203c·7472·3e0a·2020·2020·2020··.····<tr>.······ 
000068a0:·3c74·643e·312e·322e·323c·2f74·643e·0a20··<td>1.2.2</td>.· 
000068b0:·2020·2020·203c·7464·3e45·6e73·7572·6520·······<td>Ensure· 
000068c0:·6770·6763·6865·636b·2045·6e61·626c·6564··gpgcheck·Enabled 
000068d0:·2049·6e20·4d61·696e·2079·756d·2043·6f6e···In·Main·yum·Con 
000068e0:·6669·6775·7261·7469·6f6e·3c2f·7464·3e0a··figuration</td>. 
000068f0:·2020·2020·2020·3c74·6420·786d·6c3a·6c61········<td·xml:la 
00006900:·6e67·3d22·656e·2d55·5322·3e0a·2020·2020··ng="en-US">.···· 
00006910:·2020·2020·5468·6520·3c74·743e·6770·6763······The·<tt>gpgc 
00006920:·6865·636b·3c2f·7474·3e20·6f70·7469·6f6e··heck</tt>·option 
00006930:·2063·6f6e·7472·6f6c·7320·7768·6574·6865···controls·whethe 
00006940:·720a·5250·4d20·7061·636b·6167·6573·2720··r.RPM·packages'· 
00006950:·7369·676e·6174·7572·6573·2061·7265·2061··signatures·are·a 
00006960:·6c77·6179·7320·6368·6563·6b65·6420·7072··lways·checked·pr 
00006970:·696f·7220·746f·2069·6e73·7461·6c6c·6174··ior·to·installat 
00006980:·696f·6e2e·0a54·6f20·636f·6e66·6967·7572··ion..To·configur 
00006990:·6520·7975·6d20·746f·2063·6865·636b·2070··e·yum·to·check·p 
000069a0:·6163·6b61·6765·2073·6967·6e61·7475·7265··ackage·signature 
000069b0:·7320·6265·666f·7265·2069·6e73·7461·6c6c··s·before·install 
000069c0:·696e·670a·7468·656d·2c20·656e·7375·7265··ing.them,·ensure 
000069d0:·2074·6865·2066·6f6c·6c6f·7769·6e67·206c···the·following·l 
000069e0:·696e·6520·6170·7065·6172·7320·696e·203c··ine·appears·in·< 
000069f0:·7474·3e2f·6574·632f·7975·6d2e·636f·6e66··tt>/etc/yum.conf 
Max diff block lines reached; 1112284/1129974 bytes (98.43%) of diff not shown.
324 KB
html2text {}
    
Offset 367, 37 lines modifiedOffset 367, 14 lines modified
367 ······································The·noexec·mount·option·can·be·used·to·prevent·········directories·such·as367 ······································The·noexec·mount·option·can·be·used·to·prevent·········directories·such·as
368 1.1.3.5.4·········Add·noexec·Option···binaries·from·being·executed·out·of·/var/tmp.·Add·the··/var/tmp·should368 1.1.3.5.4·········Add·noexec·Option···binaries·from·being·executed·out·of·/var/tmp.·Add·the··/var/tmp·should
369 ··················to·/var/tmp·········noexec·option·to·the·fourth·column·of·/etc/fstab·for···never·be·necessary369 ··················to·/var/tmp·········noexec·option·to·the·fourth·column·of·/etc/fstab·for···never·be·necessary
370 ······································the·line·which·controls·mounting·of·/var/tmp.··········in·normal·operation370 ······································the·line·which·controls·mounting·of·/var/tmp.··········in·normal·operation
371 ·····························································································and·can·expose·the371 ·····························································································and·can·expose·the
372 ·····························································································system·to·potential372 ·····························································································system·to·potential
373 ·····························································································compromise.373 ·····························································································compromise.
374 ·····························································································Verifying·the 
375 ·····························································································authenticity·of·the 
376 ·····························································································software·prior·to 
377 ·····························································································installation 
378 ·····························································································validates·the 
379 ·····························································································integrity·of·the 
380 ·····························································································patch·or·upgrade 
381 ·····························································································received·from·a 
382 ·····························································································vendor.·This·ensures 
383 ··················Ensure·gpgcheck·····To·ensure·signature·checking·is·not·disabled·for·any···the·software·has·not 
384 ··················Enabled·for·All·yum·repos,·remove·any·lines·from·files·in·/etc/yum.repos.d·been·tampered·with 
385 1.2.2·············Package·············of·the·form:···········································and·that·it·has·been 
386 ··················Repositories········gpgcheck=0·············································provided·by·a 
387 ·····························································································trusted·vendor. 
388 ·····························································································Self-signed 
389 ·····························································································certificates·are 
390 ·····························································································disallowed·by·this 
391 ·····························································································requirement. 
392 ·····························································································Certificates·used·to 
393 ·····························································································verify·the·software 
394 ·····························································································must·be·from·an 
395 ·····························································································approved·Certificate 
396 ·····························································································Authority·(CA)." 
397 ·····························································································Changes·to·any374 ·····························································································Changes·to·any
398 ·····························································································software·components375 ·····························································································software·components
399 ·····························································································can·have·significant376 ·····························································································can·have·significant
400 ·····························································································effects·on·the377 ·····························································································effects·on·the
401 ·····························································································overall·security·of378 ·····························································································overall·security·of
402 ·····························································································the·operating379 ·····························································································the·operating
403 ·····························································································system.·This380 ·····························································································system.·This
Offset 437, 136 lines modifiedOffset 414, 159 lines modified
437 ·····························································································disallowed·by·this414 ·····························································································disallowed·by·this
438 ·····························································································requirement.415 ·····························································································requirement.
439 ·····························································································Certificates·used·to416 ·····························································································Certificates·used·to
440 ·····························································································verify·the·software417 ·····························································································verify·the·software
441 ·····························································································must·be·from·an418 ·····························································································must·be·from·an
442 ·····························································································approved·Certificate419 ·····························································································approved·Certificate
443 ·····························································································Authority·(CA).420 ·····························································································Authority·(CA).
 421 ·····························································································Verifying·the
 422 ·····························································································authenticity·of·the
 423 ·····························································································software·prior·to
 424 ·····························································································installation
 425 ·····························································································validates·the
 426 ·····························································································integrity·of·the
 427 ·····························································································patch·or·upgrade
 428 ·····························································································received·from·a
 429 ·····························································································vendor.·This·ensures
 430 ··················Ensure·gpgcheck·····To·ensure·signature·checking·is·not·disabled·for·any···the·software·has·not
 431 ··················Enabled·for·All·yum·repos,·remove·any·lines·from·files·in·/etc/yum.repos.d·been·tampered·with
 432 1.2.2·············Package·············of·the·form:···········································and·that·it·has·been
 433 ··················Repositories········gpgcheck=0·············································provided·by·a
 434 ·····························································································trusted·vendor.
 435 ·····························································································Self-signed
 436 ·····························································································certificates·are
 437 ·····························································································disallowed·by·this
 438 ·····························································································requirement.
 439 ·····························································································Certificates·used·to
 440 ·····························································································verify·the·software
 441 ·····························································································must·be·from·an
 442 ·····························································································approved·Certificate
 443 ·····························································································Authority·(CA)."
444 ·····························································································Password·protection444 ·····························································································Password·protection
445 ······································The·grub2·boot·loader·should·have·a·superuser·account··on·the·boot·loader445 ······································The·grub2·boot·loader·should·have·a·superuser·account··on·the·boot·loader
446 ······································and·password·protection·enabled·to·protect·boot-time···configuration446 ······································and·password·protection·enabled·to·protect·boot-time···configuration
447 ······································settings.··············································ensures·users·with447 ······································settings.··············································ensures·users·with
448 ·····························································································physical·access448 ·····························································································physical·access
449 1.3.1·············Set·Boot·Loader·····Since·plaintext·passwords·are·a·security·risk,·········cannot·trivially449 1.3.1·············Set·the·UEFI·Boot···Since·plaintext·passwords·are·a·security·risk,·········cannot·trivially
450 ··················Password·in·grub2···generate·a·hash·for·the·password·by·running·the········alter·important450 ··················Loader·Password·····generate·a·hash·for·the·password·by·running·the········alter·important
451 ······································following·command:·····································bootloader·settings.451 ······································following·command:·····································bootloader·settings.
452 ······································#·grub2-setpassword····································These·include·which452 ······································#·grub2-setpassword····································These·include·which
453 ······································When·prompted,·enter·the·password·that·was·selected.···kernel·to·use,·and453 ······································When·prompted,·enter·the·password·that·was·selected.···kernel·to·use,·and
454 ·····························································································whether·to·enter454 ·····························································································whether·to·enter
455 ·····························································································single-user·mode.455 ·····························································································single-user·mode.
456 ·····························································································Password·protection456 ·····························································································Password·protection
457 ······································The·grub2·boot·loader·should·have·a·superuser·account··on·the·boot·loader457 ······································The·grub2·boot·loader·should·have·a·superuser·account··on·the·boot·loader
458 ······································and·password·protection·enabled·to·protect·boot-time···configuration458 ······································and·password·protection·enabled·to·protect·boot-time···configuration
459 ······································settings.··············································ensures·users·with459 ······································settings.··············································ensures·users·with
460 ·····························································································physical·access460 ·····························································································physical·access
461 1.3.1·············Set·the·UEFI·Boot···Since·plaintext·passwords·are·a·security·risk,·········cannot·trivially461 1.3.1·············Set·Boot·Loader·····Since·plaintext·passwords·are·a·security·risk,·········cannot·trivially
462 ··················Loader·Password·····generate·a·hash·for·the·password·by·running·the········alter·important462 ··················Password·in·grub2···generate·a·hash·for·the·password·by·running·the········alter·important
463 ······································following·command:·····································bootloader·settings.463 ······································following·command:·····································bootloader·settings.
464 ······································#·grub2-setpassword····································These·include·which464 ······································#·grub2-setpassword····································These·include·which
465 ······································When·prompted,·enter·the·password·that·was·selected.···kernel·to·use,·and465 ······································When·prompted,·enter·the·password·that·was·selected.···kernel·to·use,·and
466 ·····························································································whether·to·enter466 ·····························································································whether·to·enter
467 ·····························································································single-user·mode.467 ·····························································································single-user·mode.
468 ·····························································································Only·root·should·be468 ·····························································································The·root·group·is·a
 469 ·····························································································highly-privileged
 470 ·····························································································group.·Furthermore,
 471 ·····························································································the·group-owner·of
 472 ·····························································································this·file·should·not
 473 ······································The·file·/boot/grub2/user.cfg·should·be·group-owned·by·have·any·access
 474 ··················Verify·/boot/grub2/·the·root·group·to·prevent·reading·or·modification·of···privileges·anyway.
 475 1.3.2·············user.cfg·Group······the·file.·To·properly·set·the·group·owner·of·/boot/····Non-root·users·who
 476 ··················Ownership···········grub2/user.cfg,·run·the·command:·······················read·the·boot
 477 ······································$·sudo·chgrp·root·/boot/grub2/user.cfg·················parameters·may·be
469 ·····························································································able·to·modify478 ·····························································································able·to·identify
470 ·····························································································important·boot 
471 ······································The·file·/boot/grub2/user.cfg·should·be·owned·by·the···parameters.·Also, 
472 ··················Verify·/boot/grub2/·root·user·to·prevent·reading·or·modification·of·the····non-root·users·who 
473 1.3.2·············user.cfg·User·······file.·To·properly·set·the·owner·of·/boot/grub2/········read·the·boot 
474 ··················Ownership···········user.cfg,·run·the·command:·····························parameters·may·be 
475 ······································$·sudo·chown·root·/boot/grub2/user.cfg·················able·to·identify 
476 ·····························································································weaknesses·in479 ·····························································································weaknesses·in
477 ·····························································································security·upon·boot480 ·····························································································security·upon·boot
478 ·····························································································and·be·able·to481 ·····························································································and·be·able·to
479 ·····························································································exploit·them.482 ·····························································································exploit·them.
480 ·····························································································The·root·group·is·a483 ·····························································································The·root·group·is·a
481 ······································The·file·/boot/grub2/grub.cfg·should·be·group-owned·by·highly-privileged 
482 ··················Verify·/boot/grub2/·the·root·group·to·prevent·destruction·or·modification··group.·Furthermore, 
483 1.3.2·············grub.cfg·Group······of·the·file.·To·properly·set·the·group·owner·of·/boot/·the·group-owner·of 
484 ··················Ownership···········grub2/grub.cfg,·run·the·command:·······················this·file·should·not 
485 ······································$·sudo·chgrp·root·/boot/grub2/grub.cfg·················have·any·access 
486 ·····························································································privileges·anyway. 
487 ······································File·permissions·for·/boot/efi/EFI/redhat/user.cfg·····Proper·permissions 
488 ··················Verify·/boot/efi/···should·be·set·to·600.·To·properly·set·the·permissions··ensure·that·only·the 
489 1.3.2·············EFI/redhat/user.cfg·of·/boot/efi/EFI/redhat/user.cfg,·run·the·command:·····root·user·can·read 
490 ··················Permissions·········$·sudo·chmod·600·/boot/efi/EFI/redhat/user.cfg·········or·modify·important 
491 ·····························································································boot·parameters. 
492 ··················Verify·the·UEFI·····The·file·/boot/efi/EFI/redhat/grub.cfg·should·be·owned·Only·root·should·be 
493 ··················Boot·Loader·········by·the·root·user·to·prevent·destruction·or·············able·to·modify 
Max diff block lines reached; 315722/332103 bytes (95.07%) of diff not shown.
1.24 MB
./usr/share/doc/ssg-nondebian/table-rhel8-cuirefs.html
Ordering differences only
    
Offset 40, 90 lines modifiedOffset 40, 14 lines modified
40 ····<th>Mapping</th>40 ····<th>Mapping</th>
41 ····<th>Rule·Title</th>41 ····<th>Rule·Title</th>
42 ····<th>Description</th>42 ····<th>Description</th>
43 ····<th>Rationale</th>43 ····<th>Rationale</th>
44 ··</thead>44 ··</thead>
45 ··<tbody>45 ··<tbody>
46 ··<tr>46 ··<tr>
47 ······<td>3.1.1<br/>3.1.5</td> 
48 ······<td>Verify·Only·Root·Has·UID·0</td> 
49 ······<td·xml:lang="en-US"> 
50 ········If·any·account·other·than·root·has·a·UID·of·0,·this·misconfiguration·should 
51 be·investigated·and·the·accounts·other·than·root·should·be·removed·or·have 
52 their·UID·changed. 
53 <br·/> 
54 If·the·account·is·associated·with·system·commands·or·applications·the·UID 
55 should·be·changed·to·one·greater·than·"0"·but·less·than·"1000." 
56 Otherwise·assign·a·UID·greater·than·"1000"·that·has·not·already·been 
57 assigned. 
58 ······</td> 
59 ······<td·xml:lang="en-US"> 
60 ········An·account·has·root·authority·if·it·has·a·UID·of·0.·Multiple·accounts 
61 with·a·UID·of·0·afford·more·opportunity·for·potential·intruders·to 
62 guess·a·password·for·a·privileged·account.·Proper·configuration·of 
63 sudo·is·recommended·to·afford·multiple·system·administrators 
64 access·to·root·privileges·in·an·accountable·manner. 
65 ······</td> 
66 ····</tr> 
67 ····<tr> 
68 ······<td>3.1.1<br/>3.1.5</td> 
69 ······<td>Disable·SSH·Root·Login</td> 
70 ······<td·xml:lang="en-US"> 
71 ········The·root·user·should·never·be·allowed·to·login·to·a 
72 system·directly·over·a·network. 
73 To·disable·root·login·via·SSH,·add·or·correct·the·following·line·in 
  
  
74 <tt>/etc/ssh/sshd_config</tt>: 
  
75 <pre>PermitRootLogin·no</pre> 
76 ······</td> 
77 ······<td·xml:lang="en-US"> 
78 ········Even·though·the·communications·channel·may·be·encrypted,·an·additional·layer·of 
79 security·is·gained·by·extending·the·policy·of·not·logging·directly·on·as·root. 
80 In·addition,·logging·in·with·a·user-specific·account·provides·individual 
81 accountability·of·actions·performed·on·the·system·and·also·helps·to·minimize 
82 direct·attack·attempts·on·root's·password. 
83 ······</td> 
84 ····</tr> 
85 ····<tr> 
86 ······<td>3.1.1<br/>3.4.5</td> 
87 ······<td>Require·Authentication·for·Emergency·Systemd·Target</td> 
88 ······<td·xml:lang="en-US"> 
89 ········Emergency·mode·is·intended·as·a·system·recovery 
90 method,·providing·a·single·user·root·access·to·the·system 
91 during·a·failed·boot·sequence. 
92 <br·/><br·/> 
93 By·default,·Emergency·mode·is·protected·by·requiring·a·password·and·is·set 
94 in·<tt>/usr/lib/systemd/system/emergency.service</tt>. 
95 ······</td> 
96 ······<td·xml:lang="en-US"> 
97 ········This·prevents·attackers·with·physical·access·from·trivially·bypassing·security 
98 on·the·machine·and·gaining·root·access.·Such·accesses·are·further·prevented 
99 by·configuring·the·bootloader·password. 
100 ······</td> 
101 ····</tr> 
102 ····<tr> 
103 ······<td>3.1.1</td> 
104 ······<td>Disable·GDM·Automatic·Login</td> 
105 ······<td·xml:lang="en-US"> 
106 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·automatically·login·without 
107 user·interaction·or·credentials.·User·should·always·be·required·to·authenticate·themselves 
108 to·the·system·that·they·are·authorized·to·use.·To·disable·user·ability·to·automatically 
109 login·to·the·system,·set·the·<tt>AutomaticLoginEnable</tt>·to·<tt>false</tt>·in·the 
110 <tt>[daemon]</tt>·section·in·<tt>/etc/gdm/custom.conf</tt>.·For·example: 
111 <pre>[daemon] 
112 AutomaticLoginEnable=false</pre> 
113 ······</td> 
114 ······<td·xml:lang="en-US"> 
115 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating 
116 system·security. 
117 ······</td> 
118 ····</tr> 
119 ····<tr> 
120 ······<td>3.1.1</td>47 ······<td>3.1.1</td>
121 ······<td>Disable·GDM·Guest·Login</td>48 ······<td>Disable·GDM·Guest·Login</td>
122 ······<td·xml:lang="en-US">49 ······<td·xml:lang="en-US">
123 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·login·without·credentials50 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·login·without·credentials
124 which·can·be·useful·for·public·kiosk·scenarios.·Allowing·users·to·login·without·credentials51 which·can·be·useful·for·public·kiosk·scenarios.·Allowing·users·to·login·without·credentials
125 or·"guest"·account·access·has·inherent·security·risks·and·should·be·disabled.·To·do·disable52 or·"guest"·account·access·has·inherent·security·risks·and·should·be·disabled.·To·do·disable
126 timed·logins·or·guest·account·access,·set·the·<tt>TimedLoginEnable</tt>·to·<tt>false</tt>·in53 timed·logins·or·guest·account·access,·set·the·<tt>TimedLoginEnable</tt>·to·<tt>false</tt>·in
Offset 153, 14 lines modifiedOffset 77, 57 lines modified
153 ······<td·xml:lang="en-US">77 ······<td·xml:lang="en-US">
154 ········If·an·account·has·an·empty·password,·anyone·could·log·in·and78 ········If·an·account·has·an·empty·password,·anyone·could·log·in·and
155 run·commands·with·the·privileges·of·that·account.·Accounts·with79 run·commands·with·the·privileges·of·that·account.·Accounts·with
156 empty·passwords·should·never·be·used·in·operational·environments.80 empty·passwords·should·never·be·used·in·operational·environments.
157 ······</td>81 ······</td>
158 ····</tr>82 ····</tr>
159 ····<tr>83 ····<tr>
 84 ······<td>3.1.1<br/>3.1.6</td>
 85 ······<td>Direct·root·Logins·Not·Allowed</td>
 86 ······<td·xml:lang="en-US">
 87 ········To·further·limit·access·to·the·<tt>root</tt>·account,·administrators
 88 can·disable·root·logins·at·the·console·by·editing·the·<tt>/etc/securetty</tt>·file.
 89 This·file·lists·all·devices·the·root·user·is·allowed·to·login·to.·If·the·file·does
 90 not·exist·at·all,·the·root·user·can·login·through·any·communication·device·on·the
 91 system,·whether·via·the·console·or·via·a·raw·network·interface.·This·is·dangerous
 92 as·user·can·login·to·the·system·as·root·via·Telnet,·which·sends·the·password·in
 93 plain·text·over·the·network.·By·default,·Red·Hat·Enterprise·Linux·8's
 94 <tt>/etc/securetty</tt>·file·only·allows·the·root·user·to·login·at·the·console
 95 physically·attached·to·the·system.·To·prevent·root·from·logging·in,·remove·the
 96 contents·of·this·file.·To·prevent·direct·root·logins,·remove·the·contents·of·this
 97 file·by·typing·the·following·command:
 98 <pre>
 99 $·sudo·echo·&gt;·/etc/securetty
 100 </pre>
 101 ······</td>
 102 ······<td·xml:lang="en-US">
 103 ········Disabling·direct·root·logins·ensures·proper·accountability·and·multifactor
 104 authentication·to·privileged·accounts.·Users·will·first·login,·then·escalate
 105 to·privileged·(root)·access·via·su·/·sudo.·This·is·required·for·FISMA·Low
 106 and·FISMA·Moderate·systems.
 107 ······</td>
 108 ····</tr>
 109 ····<tr>
 110 ······<td>3.1.1<br/>3.1.5</td>
 111 ······<td>Restrict·Virtual·Console·Root·Logins</td>
 112 ······<td·xml:lang="en-US">
Max diff block lines reached; 464798/470753 bytes (98.74%) of diff not shown.
812 KB
html2text {}
    
Offset 1, 73 lines modifiedOffset 1, 13 lines modified
  
  
1 Rules·with·NIST-800-171·Reference·in·Guide·to·the·Secure·Configuration·of·Red1 Rules·with·NIST-800-171·Reference·in·Guide·to·the·Secure·Configuration·of·Red
2 Hat·Enterprise·Linux·82 Hat·Enterprise·Linux·8
  
  
3 ······························································································An·account·has·root 
4 ······························································································authority·if·it·has 
5 ······························································································a·UID·of·0.·Multiple 
6 ······························································································accounts·with·a·UID 
7 ·······································If·any·account·other·than·root·has·a·UID·of·0,·this····of·0·afford·more 
8 ·······································misconfiguration·should·be·investigated·and·the········opportunity·for 
9 ·······································accounts·other·than·root·should·be·removed·or·have·····potential·intruders 
10 ·······································their·UID·changed.·····································to·guess·a·password 
11 3.1.1···Verify·Only·Root·Has·UID·0·····If·the·account·is·associated·with·system·commands·or···for·a·privileged 
12 3.1.5··································applications·the·UID·should·be·changed·to·one·greater··account.·Proper 
13 ·······································than·"0"·but·less·than·"1000."·Otherwise·assign·a·UID··configuration·of 
14 ·······································greater·than·"1000"·that·has·not·already·been··········sudo·is·recommended 
15 ·······································assigned.··············································to·afford·multiple 
16 ······························································································system 
17 ······························································································administrators 
18 ······························································································access·to·root 
19 ······························································································privileges·in·an 
20 ······························································································accountable·manner. 
21 ······························································································Even·though·the 
22 ······························································································communications 
23 ······························································································channel·may·be 
24 ······························································································encrypted,·an 
25 ······························································································additional·layer·of 
26 ······························································································security·is·gained 
27 ······························································································by·extending·the 
28 ······························································································policy·of·not 
29 ·······································The·root·user·should·never·be·allowed·to·login·to·a····logging·directly·on 
30 3.1.1··································system·directly·over·a·network.·To·disable·root·login··as·root.·In 
31 3.1.5···Disable·SSH·Root·Login·········via·SSH,·add·or·correct·the·following·line·in·/etc/····addition,·logging·in 
32 ·······································ssh/sshd_config:·······································with·a·user-specific 
33 ·······································PermitRootLogin·no·····································account·provides 
34 ······························································································individual 
35 ······························································································accountability·of 
36 ······························································································actions·performed·on 
37 ······························································································the·system·and·also 
38 ······························································································helps·to·minimize 
39 ······························································································direct·attack 
40 ······························································································attempts·on·root's 
41 ······························································································password. 
42 ······························································································This·prevents 
43 ······························································································attackers·with 
44 ·······································Emergency·mode·is·intended·as·a·system·recovery········physical·access·from 
45 ·······································method,·providing·a·single·user·root·access·to·the·····trivially·bypassing 
46 3.1.1···Require·Authentication·for·····system·during·a·failed·boot·sequence.··················security·on·the 
47 3.4.5···Emergency·Systemd·Target······························································machine·and·gaining 
48 ·······································By·default,·Emergency·mode·is·protected·by·requiring·a·root·access.·Such 
49 ·······································password·and·is·set·in·/usr/lib/systemd/system/········accesses·are·further 
50 ·······································emergency.service.·····································prevented·by 
51 ······························································································configuring·the 
52 ······························································································bootloader·password. 
53 ·······································The·GNOME·Display·Manager·(GDM)·can·allow·users·to 
54 ·······································automatically·login·without·user·interaction·or 
55 ·······································credentials.·User·should·always·be·required·to·········Failure·to·restrict 
56 ·······································authenticate·themselves·to·the·system·that·they·are····system·access·to 
57 3.1.1···Disable·GDM·Automatic·Login····authorized·to·use.·To·disable·user·ability·to··········authenticated·users 
58 ·······································automatically·login·to·the·system,·set·the·············negatively·impacts 
59 ·······································AutomaticLoginEnable·to·false·in·the·[daemon]·section··operating·system 
60 ·······································in·/etc/gdm/custom.conf.·For·example:··················security. 
61 ·······································[daemon] 
62 ·······································AutomaticLoginEnable=false 
63 ·······································The·GNOME·Display·Manager·(GDM)·can·allow·users·to3 ·······································The·GNOME·Display·Manager·(GDM)·can·allow·users·to
64 ·······································login·without·credentials·which·can·be·useful·for4 ·······································login·without·credentials·which·can·be·useful·for
65 ·······································public·kiosk·scenarios.·Allowing·users·to·login········Failure·to·restrict5 ·······································public·kiosk·scenarios.·Allowing·users·to·login········Failure·to·restrict
66 ·······································without·credentials·or·"guest"·account·access·has······system·access·to6 ·······································without·credentials·or·"guest"·account·access·has······system·access·to
67 3.1.1···Disable·GDM·Guest·Login········inherent·security·risks·and·should·be·disabled.·To·do··authenticated·users7 3.1.1···Disable·GDM·Guest·Login········inherent·security·risks·and·should·be·disabled.·To·do··authenticated·users
68 ·······································disable·timed·logins·or·guest·account·access,·set·the··negatively·impacts8 ·······································disable·timed·logins·or·guest·account·access,·set·the··negatively·impacts
69 ·······································TimedLoginEnable·to·false·in·the·[daemon]·section·in·/·operating·system9 ·······································TimedLoginEnable·to·false·in·the·[daemon]·section·in·/·operating·system
Offset 81, 162 lines modifiedOffset 21, 144 lines modified
81 3.1.1···Prevent·Login·to·Accounts·With·it·may·be·possible·to·log·into·the·account·without·····with·the·privileges21 3.1.1···Prevent·Login·to·Accounts·With·it·may·be·possible·to·log·into·the·account·without·····with·the·privileges
82 3.1.5···Empty·Password·················authentication.·Remove·any·instances·of·the·nullok·in··of·that·account.22 3.1.5···Empty·Password·················authentication.·Remove·any·instances·of·the·nullok·in··of·that·account.
83 ·······································/etc/pam.d/system-auth·and·/etc/pam.d/password-auth·to·Accounts·with·empty23 ·······································/etc/pam.d/system-auth·and·/etc/pam.d/password-auth·to·Accounts·with·empty
84 ·······································prevent·logins·with·empty·passwords.···················passwords·should24 ·······································prevent·logins·with·empty·passwords.···················passwords·should
85 ······························································································never·be·used·in25 ······························································································never·be·used·in
86 ······························································································operational26 ······························································································operational
87 ······························································································environments.27 ······························································································environments.
 28 ·······································To·further·limit·access·to·the·root·account,
 29 ·······································administrators·can·disable·root·logins·at·the·console··Disabling·direct
 30 ·······································by·editing·the·/etc/securetty·file.·This·file·lists····root·logins·ensures
 31 ·······································all·devices·the·root·user·is·allowed·to·login·to.·If···proper
 32 ·······································the·file·does·not·exist·at·all,·the·root·user·can······accountability·and
 33 ·······································login·through·any·communication·device·on·the·system,··multifactor
 34 ·······································whether·via·the·console·or·via·a·raw·network···········authentication·to
 35 3.1.1··································interface.·This·is·dangerous·as·user·can·login·to·the··privileged·accounts.
 36 3.1.6···Direct·root·Logins·Not·Allowed·system·as·root·via·Telnet,·which·sends·the·password·in·Users·will·first
 37 ·······································plain·text·over·the·network.·By·default,·Red·Hat·······login,·then·escalate
 38 ·······································Enterprise·Linux·8's·/etc/securetty·file·only·allows···to·privileged·(root)
 39 ·······································the·root·user·to·login·at·the·console·physically·······access·via·su·/
 40 ·······································attached·to·the·system.·To·prevent·root·from·logging···sudo.·This·is
 41 ·······································in,·remove·the·contents·of·this·file.·To·prevent·······required·for·FISMA
 42 ·······································direct·root·logins,·remove·the·contents·of·this·file···Low·and·FISMA
 43 ·······································by·typing·the·following·command:·······················Moderate·systems.
 44 ·······································$·sudo·echo·>·/etc/securetty
 45 ·······································To·restrict·root·logins·through·the·(deprecated)·······Preventing·direct
 46 ·······································virtual·console·devices,·ensure·lines·of·this·form·do··root·login·to
 47 ·······································not·appear·in·/etc/securetty:··························virtual·console
 48 3.1.1···Restrict·Virtual·Console·Root··vc/1···················································devices·helps·ensure
 49 3.1.5···Logins·························vc/2···················································accountability·for
 50 ·······································vc/3···················································actions·taken·on·the
 51 ·······································vc/4···················································system·using·the
 52 ······························································································root·account.
88 ·······································Disallow·SSH·login·with·empty·passwords.·The·default53 ·······································Disallow·SSH·login·with·empty·passwords.·The·default
89 ·······································SSH·configuration·disables·logins·with·empty···········Configuring·this54 ·······································SSH·configuration·disables·logins·with·empty···········Configuring·this
90 ·······································passwords.·The·appropriate·configuration·is·used·if·no·setting·for·the·SSH55 ·······································passwords.·The·appropriate·configuration·is·used·if·no·setting·for·the·SSH
91 ·······································value·is·set·for·PermitEmptyPasswords.·················daemon·provides56 ·······································value·is·set·for·PermitEmptyPasswords.·················daemon·provides
92 ·······································To·explicitly·disallow·SSH·login·from·accounts·with····additional·assurance57 ·······································To·explicitly·disallow·SSH·login·from·accounts·with····additional·assurance
93 3.1.1···Disable·SSH·Access·via·Empty···empty·passwords,·add·or·correct·the·following·line·in··that·remote·login58 3.1.1···Disable·SSH·Access·via·Empty···empty·passwords,·add·or·correct·the·following·line·in··that·remote·login
94 3.1.5···Passwords······················/etc/ssh/sshd_config:··································via·SSH·will·require59 3.1.5···Passwords······················/etc/ssh/sshd_config:··································via·SSH·will·require
95 ·······································PermitEmptyPasswords·no································a·password,·even·in60 ·······································PermitEmptyPasswords·no································a·password,·even·in
96 ·······································Any·accounts·with·empty·passwords·should·be·disabled···the·event·of61 ·······································Any·accounts·with·empty·passwords·should·be·disabled···the·event·of
97 ·······································immediately,·and·PAM·configuration·should·prevent······misconfiguration62 ·······································immediately,·and·PAM·configuration·should·prevent······misconfiguration
98 ·······································users·from·being·able·to·assign·themselves·empty·······elsewhere.63 ·······································users·from·being·able·to·assign·themselves·empty·······elsewhere.
99 ·······································passwords.64 ·······································passwords.
100 ·······································To·restrict·root·logins·through·the·(deprecated)·······Preventing·direct 
101 ·······································virtual·console·devices,·ensure·lines·of·this·form·do··root·login·to 
102 ·······································not·appear·in·/etc/securetty:··························virtual·console 
103 3.1.1···Restrict·Virtual·Console·Root··vc/1···················································devices·helps·ensure 
104 3.1.5···Logins·························vc/2···················································accountability·for65 ·······································The·GNOME·Display·Manager·(GDM)·can·allow·users·to
 66 ·······································automatically·login·without·user·interaction·or
 67 ·······································credentials.·User·should·always·be·required·to·········Failure·to·restrict
 68 ·······································authenticate·themselves·to·the·system·that·they·are····system·access·to
 69 3.1.1···Disable·GDM·Automatic·Login····authorized·to·use.·To·disable·user·ability·to··········authenticated·users
Max diff block lines reached; 814790/831379 bytes (98.00%) of diff not shown.
3.29 KB
./usr/share/doc/ssg-nondebian/table-rhel8-nistrefs-ospp.html
    
Offset 4111, 15 lines modifiedOffset 4111, 15 lines modified
4111 <pre>RekeyLimit·<tt>1G</tt>·<tt>1hour</tt></pre>4111 <pre>RekeyLimit·<tt>1G</tt>·<tt>1hour</tt></pre>
4112 ··</td>4112 ··</td>
4113 ··<td·xml:lang="en-US">4113 ··<td·xml:lang="en-US">
4114 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling4114 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling
4115 time-based·limit,·effects·of·potential·attacks·against4115 time-based·limit,·effects·of·potential·attacks·against
4116 encryption·keys·are·limited.4116 encryption·keys·are·limited.
4117 ··</td>4117 ··</td>
4118 ··<td>var_rekey_limit_size=1G<br/>var_rekey_limit_time=1hour</td>4118 ··<td>var_rekey_limit_time=1hour<br/>var_rekey_limit_size=1G</td>
4119 </tr>4119 </tr>
4120 <tr>4120 <tr>
4121 ··<td></td>4121 ··<td></td>
4122 ··<td>CCE-82462-3</td>4122 ··<td>CCE-82462-3</td>
4123 ··<td>SSH·server·uses·strong·entropy·to·seed</td>4123 ··<td>SSH·server·uses·strong·entropy·to·seed</td>
4124 ··<td·xml:lang="en-US">4124 ··<td·xml:lang="en-US">
4125 To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·<tt>/etc/sysconfig/sshd</tt>·file.4125 To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·<tt>/etc/sysconfig/sshd</tt>·file.
2.55 KB
html2text {}
    
Offset 3359, 16 lines modifiedOffset 3359, 16 lines modified
3359 ······················································································································generator·used·by3359 ······················································································································generator·used·by
3360 ······················································································································SSH·would·be·known3360 ······················································································································SSH·would·be·known
3361 ······················································································································to·potential3361 ······················································································································to·potential
3362 ······················································································································attackers.3362 ······················································································································attackers.
3363 ······················································································································By·decreasing·the3363 ······················································································································By·decreasing·the
3364 ·····························The·RekeyLimit·parameter·specifies·how·often·the·session·key·of·the·is·renegotiated,·····limit·based·on·the3364 ·····························The·RekeyLimit·parameter·specifies·how·often·the·session·key·of·the·is·renegotiated,·····limit·based·on·the
3365 ·····CCE-···Force·frequent···both·in·terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.············amount·of·data·and3365 ·····CCE-···Force·frequent···both·in·terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.············amount·of·data·and
3366 ·····82177-·session·key······To·decrease·the·default·limits,·add·or·correct·the·following·line·in·/etc/ssh/···········enabling·time-based·var_rekey_limit_size=1G3366 ·····82177-·session·key······To·decrease·the·default·limits,·add·or·correct·the·following·line·in·/etc/ssh/···········enabling·time-based·var_rekey_limit_time=1hour
3367 ·····7······renegotiation····sshd_config:·············································································limit,·effects·of···var_rekey_limit_time=1hour3367 ·····7······renegotiation····sshd_config:·············································································limit,·effects·of···var_rekey_limit_size=1G
3368 ·····························RekeyLimit·1G·1hour······································································potential·attacks3368 ·····························RekeyLimit·1G·1hour······································································potential·attacks
3369 ······················································································································against·encryption3369 ······················································································································against·encryption
3370 ······················································································································keys·are·limited.3370 ······················································································································keys·are·limited.
3371 ······················································································································SSH·implementation3371 ······················································································································SSH·implementation
3372 ······················································································································in·Red·Hat3372 ······················································································································in·Red·Hat
3373 ······················································································································Enterprise·Linux·83373 ······················································································································Enterprise·Linux·8
3374 ······················································································································uses·the·openssl3374 ······················································································································uses·the·openssl
3.7 KB
./usr/share/doc/ssg-nondebian/table-rhel8-nistrefs-stig.html
    
Offset 24853, 18 lines modifiedOffset 24853, 18 lines modified
00061140:·616e·6420·656e·6162·6c69·6e67·0a74·696d··and·enabling.tim00061140:·616e·6420·656e·6162·6c69·6e67·0a74·696d··and·enabling.tim
00061150:·652d·6261·7365·6420·6c69·6d69·742c·2065··e-based·limit,·e00061150:·652d·6261·7365·6420·6c69·6d69·742c·2065··e-based·limit,·e
00061160:·6666·6563·7473·206f·6620·706f·7465·6e74··ffects·of·potent00061160:·6666·6563·7473·206f·6620·706f·7465·6e74··ffects·of·potent
00061170:·6961·6c20·6174·7461·636b·7320·6167·6169··ial·attacks·agai00061170:·6961·6c20·6174·7461·636b·7320·6167·6169··ial·attacks·agai
00061180:·6e73·740a·656e·6372·7970·7469·6f6e·206b··nst.encryption·k00061180:·6e73·740a·656e·6372·7970·7469·6f6e·206b··nst.encryption·k
00061190:·6579·7320·6172·6520·6c69·6d69·7465·642e··eys·are·limited.00061190:·6579·7320·6172·6520·6c69·6d69·7465·642e··eys·are·limited.
000611a0:·0a20·203c·2f74·643e·0a20·203c·7464·3e76··.··</td>.··<td>v000611a0:·0a20·203c·2f74·643e·0a20·203c·7464·3e76··.··</td>.··<td>v
000611b0:·6172·5f72·656b·6579·5f6c·696d·6974·5f73··ar_rekey_limit_s000611b0:·6172·5f72·656b·6579·5f6c·696d·6974·5f74··ar_rekey_limit_t
000611c0:·697a·653d·3147·3c62·722f·3e76·6172·5f72··ize=1G<br/>var_r 
000611d0:·656b·6579·5f6c·696d·6974·5f74·696d·653d··ekey_limit_time=000611c0:·696d·653d·3168·6f75·723c·6272·2f3e·7661··ime=1hour<br/>va
 000611d0:·725f·7265·6b65·795f·6c69·6d69·745f·7369··r_rekey_limit_si
000611e0:·3168·6f75·723c·2f74·643e·0a3c·2f74·723e··1hour</td>.</tr>000611e0:·7a65·3d31·473c·2f74·643e·0a3c·2f74·723e··ze=1G</td>.</tr>
000611f0:·0a3c·7472·3e0a·2020·3c74·643e·3c2f·7464··.<tr>.··<td></td000611f0:·0a3c·7472·3e0a·2020·3c74·643e·3c2f·7464··.<tr>.··<td></td
00061200:·3e0a·2020·3c74·643e·4343·452d·3832·3436··>.··<td>CCE-824600061200:·3e0a·2020·3c74·643e·4343·452d·3832·3436··>.··<td>CCE-8246
00061210:·322d·333c·2f74·643e·0a20·203c·7464·3e53··2-3</td>.··<td>S00061210:·322d·333c·2f74·643e·0a20·203c·7464·3e53··2-3</td>.··<td>S
00061220:·5348·2073·6572·7665·7220·7573·6573·2073··SH·server·uses·s00061220:·5348·2073·6572·7665·7220·7573·6573·2073··SH·server·uses·s
00061230:·7472·6f6e·6720·656e·7472·6f70·7920·746f··trong·entropy·to00061230:·7472·6f6e·6720·656e·7472·6f70·7920·746f··trong·entropy·to
00061240:·2073·6565·643c·2f74·643e·0a20·203c·7464···seed</td>.··<td00061240:·2073·6565·643c·2f74·643e·0a20·203c·7464···seed</td>.··<td
00061250:·2078·6d6c·3a6c·616e·673d·2265·6e2d·5553···xml:lang="en-US00061250:·2078·6d6c·3a6c·616e·673d·2265·6e2d·5553···xml:lang="en-US
2.07 KB
html2text {}
    
Offset 7818, 16 lines modifiedOffset 7818, 16 lines modified
7818 ·····································corresponding·private·key.····························system·where·the7818 ·····································corresponding·private·key.····························system·where·the
7819 ···························································································associated·public7819 ···························································································associated·public
7820 ···························································································key·has·been7820 ···························································································key·has·been
7821 ···························································································installed.7821 ···························································································installed.
7822 ·····································The·RekeyLimit·parameter·specifies·how·often·the······By·decreasing·the7822 ·····································The·RekeyLimit·parameter·specifies·how·often·the······By·decreasing·the
7823 ·····································session·key·of·the·is·renegotiated,·both·in·terms·of··limit·based·on·the7823 ·····································session·key·of·the·is·renegotiated,·both·in·terms·of··limit·based·on·the
7824 ········CCE-···Force·frequent········amount·of·data·that·may·be·transmitted·and·the·time···amount·of·data·and7824 ········CCE-···Force·frequent········amount·of·data·that·may·be·transmitted·and·the·time···amount·of·data·and
7825 ········82177-·session·key···········elapsed.··············································enabling·time-based·var_rekey_limit_size=1G7825 ········82177-·session·key···········elapsed.··············································enabling·time-based·var_rekey_limit_time=1hour
7826 ········7······renegotiation·········To·decrease·the·default·limits,·add·or·correct·the····limit,·effects·of···var_rekey_limit_time=1hour7826 ········7······renegotiation·········To·decrease·the·default·limits,·add·or·correct·the····limit,·effects·of···var_rekey_limit_size=1G
7827 ·····································following·line·in·/etc/ssh/sshd_config:···············potential·attacks7827 ·····································following·line·in·/etc/ssh/sshd_config:···············potential·attacks
7828 ·····································RekeyLimit·1G·1hour···································against·encryption7828 ·····································RekeyLimit·1G·1hour···································against·encryption
7829 ···························································································keys·are·limited.7829 ···························································································keys·are·limited.
7830 ···························································································SSH·implementation7830 ···························································································SSH·implementation
7831 ···························································································in·Red·Hat7831 ···························································································in·Red·Hat
7832 ···························································································Enterprise·Linux·87832 ···························································································Enterprise·Linux·8
7833 ···························································································uses·the·openssl7833 ···························································································uses·the·openssl
9.47 MB
./usr/share/doc/ssg-nondebian/table-rhel8-nistrefs.html
    
Offset 68, 15044 lines modifiedOffset 68, 15044 lines modified
00000430:·3e52·6174·696f·6e61·6c65·3c2f·7468·3e0a··>Rationale</th>.00000430:·3e52·6174·696f·6e61·6c65·3c2f·7468·3e0a··>Rationale</th>.
00000440:·2020·3c2f·7468·6561·643e·0a20·203c·7462····</thead>.··<tb00000440:·2020·3c2f·7468·6561·643e·0a20·203c·7462····</thead>.··<tb
00000450:·6f64·793e·0a20·203c·7472·3e0a·2020·2020··ody>.··<tr>.····00000450:·6f64·793e·0a20·203c·7472·3e0a·2020·2020··ody>.··<tr>.····
00000460:·2020·3c74·643e·4155·2d32·2861·293c·2f74····<td>AU-2(a)</t00000460:·2020·3c74·643e·4155·2d32·2861·293c·2f74····<td>AU-2(a)</t
00000470:·643e·0a20·2020·2020·203c·7464·3e43·6f6e··d>.······<td>Con00000470:·643e·0a20·2020·2020·203c·7464·3e43·6f6e··d>.······<td>Con
00000480:·6669·6775·7265·2061·7564·6974·696e·6720··figure·auditing·00000480:·6669·6775·7265·2061·7564·6974·696e·6720··figure·auditing·
Diff chunk too large, falling back to line-by-line diff (7556 lines added, 7556 lines removed)
00000490:·6f66·2075·6e73·7563·6365·7373·6675·6c20··of·unsuccessful·00000490:·6f66·2075·6e73·7563·6365·7373·6675·6c20··of·unsuccessful·
000004a0:·6669·6c65·2061·6363·6573·7365·733c·2f74··file·accesses</t000004a0:·6669·6c65·206d·6f64·6966·6963·6174·696f··file·modificatio
000004b0:·643e·0a20·2020·2020·203c·7464·2078·6d6c··d>.······<td·xml000004b0:·6e73·3c2f·7464·3e0a·2020·2020·2020·3c74··ns</td>.······<t
000004c0:·3a6c·616e·673d·2265·6e2d·5553·223e·0a20··:lang="en-US">.·000004c0:·6420·786d·6c3a·6c61·6e67·3d22·656e·2d55··d·xml:lang="en-U
000004d0:·2020·2020·2020·2045·6e73·7572·6520·7468·········Ensure·th000004d0:·5322·3e0a·2020·2020·2020·2020·456e·7375··S">.········Ensu
000004e0:·6174·2075·6e73·7563·6365·7373·6675·6c20··at·unsuccessful·000004e0:·7265·2074·6861·7420·756e·7375·6363·6573··re·that·unsucces
000004f0:·6174·7465·6d70·7473·2074·6f20·6163·6365··attempts·to·acce000004f0:·7366·756c·2061·7474·656d·7074·7320·746f··sful·attempts·to
00000500:·7373·2061·2066·696c·6520·6172·6520·6175··ss·a·file·are·au00000500:·206d·6f64·6966·7920·6120·6669·6c65·2061···modify·a·file·a
00000510:·6469·7465·642e·0a0a·5468·6520·666f·6c6c··dited...The·foll00000510:·7265·2061·7564·6974·6564·2e0a·0a54·6865··re·audited...The
00000520:·6f77·696e·6720·7275·6c65·7320·636f·6e66··owing·rules·conf00000520:·2066·6f6c·6c6f·7769·6e67·2072·756c·6573···following·rules
00000530:·6967·7572·6520·6175·6469·7420·6173·2064··igure·audit·as·d00000530:·2063·6f6e·6669·6775·7265·2061·7564·6974···configure·audit
00000540:·6573·6372·6962·6564·2061·626f·7665·3a0a··escribed·above:.00000540:·2061·7320·6465·7363·7269·6265·6420·6162···as·described·ab
00000550:·3c70·7265·3e23·2320·556e·7375·6363·6573··<pre>##·Unsucces00000550:·6f76·653a·0a3c·7072·653e·2323·2055·6e73··ove:.<pre>##·Uns
00000560:·7366·756c·2066·696c·6520·6163·6365·7373··sful·file·access00000560:·7563·6365·7373·6675·6c20·6669·6c65·206d··uccessful·file·m
00000570:·2028·616e·7920·6f74·6865·7220·6f70·656e···(any·other·open00000570:·6f64·6966·6963·6174·696f·6e73·2028·6f70··odifications·(op
00000580:·7329·2054·6869·7320·6861·7320·746f·2067··s)·This·has·to·g00000580:·656e·2066·6f72·2077·7269·7465·206f·7220··en·for·write·or·
00000590:·6f20·6c61·7374·2e0a·2d61·2061·6c77·6179··o·last..-a·alway00000590:·7472·756e·6361·7465·290a·2d61·2061·6c77··truncate).-a·alw
000005a0:·732c·6578·6974·202d·4620·6172·6368·3d62··s,exit·-F·arch=b000005a0:·6179·732c·6578·6974·202d·4620·6172·6368··ays,exit·-F·arch
000005b0:·3332·202d·5320·6f70·656e·2c6f·7065·6e61··32·-S·open,opena000005b0:·3d62·3332·202d·5320·6f70·656e·6174·2c6f··=b32·-S·openat,o
000005c0:·742c·6f70·656e·6174·322c·6f70·656e·5f62··t,openat2,open_b000005c0:·7065·6e5f·6279·5f68·616e·646c·655f·6174··pen_by_handle_at
000005d0:·795f·6861·6e64·6c65·5f61·7420·2d46·2065··y_handle_at·-F·e000005d0:·202d·4620·6132·2661·6d70·3b30·3130·3033···-F·a2&amp;01003
000005e0:·7869·743d·2d45·4143·4345·5320·2d46·2061··xit=-EACCES·-F·a000005e0:·202d·4620·6578·6974·3d2d·4541·4343·4553···-F·exit=-EACCES
000005f0:·7569·643e·3d31·3030·3020·2d46·2061·7569··uid>=1000·-F·aui000005f0:·202d·4620·6175·6964·2667·743b·3d31·3030···-F·auid&gt;=100
00000600:·6421·3d75·6e73·6574·202d·4620·6b65·793d··d!=unset·-F·key=00000600:·3020·2d46·2061·7569·6421·3d75·6e73·6574··0·-F·auid!=unset
00000610:·756e·7375·6363·6573·7366·756c·2d61·6363··unsuccessful-acc00000610:·202d·4620·6b65·793d·756e·7375·6363·6573···-F·key=unsucces
00000620:·6573·730a·2d61·2061·6c77·6179·732c·6578··ess.-a·always,ex00000620:·7366·756c·2d6d·6f64·6966·6963·6174·696f··sful-modificatio
00000630:·6974·202d·4620·6172·6368·3d62·3634·202d··it·-F·arch=b64·-00000630:·6e0a·2d61·2061·6c77·6179·732c·6578·6974··n.-a·always,exit
00000640:·5320·6f70·656e·2c6f·7065·6e61·742c·6f70··S·open,openat,op00000640:·202d·4620·6172·6368·3d62·3634·202d·5320···-F·arch=b64·-S·
00000650:·656e·6174·322c·6f70·656e·5f62·795f·6861··enat2,open_by_ha00000650:·6f70·656e·6174·2c6f·7065·6e5f·6279·5f68··openat,open_by_h
00000660:·6e64·6c65·5f61·7420·2d46·2065·7869·743d··ndle_at·-F·exit=00000660:·616e·646c·655f·6174·202d·4620·6132·2661··andle_at·-F·a2&a
00000670:·2d45·4143·4345·5320·2d46·2061·7569·643e··-EACCES·-F·auid>00000670:·6d70·3b30·3130·3033·202d·4620·6578·6974··mp;01003·-F·exit
00000680:·3d31·3030·3020·2d46·2061·7569·6421·3d75··=1000·-F·auid!=u00000680:·3d2d·4541·4343·4553·202d·4620·6175·6964··=-EACCES·-F·auid
00000690:·6e73·6574·202d·4620·6b65·793d·756e·7375··nset·-F·key=unsu00000690:·2667·743b·3d31·3030·3020·2d46·2061·7569··&gt;=1000·-F·aui
000006a0:·6363·6573·7366·756c·2d61·6363·6573·730a··ccessful-access.000006a0:·6421·3d75·6e73·6574·202d·4620·6b65·793d··d!=unset·-F·key=
000006b0:·2d61·2061·6c77·6179·732c·6578·6974·202d··-a·always,exit·-000006b0:·756e·7375·6363·6573·7366·756c·2d6d·6f64··unsuccessful-mod
000006c0:·4620·6172·6368·3d62·3332·202d·5320·6f70··F·arch=b32·-S·op000006c0:·6966·6963·6174·696f·6e0a·2d61·2061·6c77··ification.-a·alw
000006d0:·656e·2c6f·7065·6e61·742c·6f70·656e·6174··en,openat,openat000006d0:·6179·732c·6578·6974·202d·4620·6172·6368··ays,exit·-F·arch
000006e0:·322c·6f70·656e·5f62·795f·6861·6e64·6c65··2,open_by_handle000006e0:·3d62·3332·202d·5320·6f70·656e·202d·4620··=b32·-S·open·-F·
000006f0:·5f61·7420·2d46·2065·7869·743d·2d45·5045··_at·-F·exit=-EPE000006f0:·6131·2661·6d70·3b30·3130·3033·202d·4620··a1&amp;01003·-F·
00000700:·524d·202d·4620·6175·6964·3e3d·3130·3030··RM·-F·auid>=100000000700:·6578·6974·3d2d·4541·4343·4553·202d·4620··exit=-EACCES·-F·
00000710:·202d·4620·6175·6964·213d·756e·7365·7420···-F·auid!=unset·00000710:·6175·6964·2667·743b·3d31·3030·3020·2d46··auid&gt;=1000·-F
00000720:·2d46·206b·6579·3d75·6e73·7563·6365·7373··-F·key=unsuccess00000720:·2061·7569·6421·3d75·6e73·6574·202d·4620···auid!=unset·-F·
00000730:·6675·6c2d·6163·6365·7373·0a2d·6120·616c··ful-access.-a·al00000730:·6b65·793d·756e·7375·6363·6573·7366·756c··key=unsuccessful
00000740:·7761·7973·2c65·7869·7420·2d46·2061·7263··ways,exit·-F·arc00000740:·2d6d·6f64·6966·6963·6174·696f·6e0a·2d61··-modification.-a
00000750:·683d·6236·3420·2d53·206f·7065·6e2c·6f70··h=b64·-S·open,op00000750:·2061·6c77·6179·732c·6578·6974·202d·4620···always,exit·-F·
00000760:·656e·6174·2c6f·7065·6e61·7432·2c6f·7065··enat,openat2,ope00000760:·6172·6368·3d62·3634·202d·5320·6f70·656e··arch=b64·-S·open
00000770:·6e5f·6279·5f68·616e·646c·655f·6174·202d··n_by_handle_at·-00000770:·202d·4620·6131·2661·6d70·3b30·3130·3033···-F·a1&amp;01003
00000780:·4620·6578·6974·3d2d·4550·4552·4d20·2d46··F·exit=-EPERM·-F00000780:·202d·4620·6578·6974·3d2d·4541·4343·4553···-F·exit=-EACCES
00000790:·2061·7569·643e·3d31·3030·3020·2d46·2061···auid>=1000·-F·a00000790:·202d·4620·6175·6964·2667·743b·3d31·3030···-F·auid&gt;=100
000007a0:·7569·6421·3d75·6e73·6574·202d·4620·6b65··uid!=unset·-F·ke000007a0:·3020·2d46·2061·7569·6421·3d75·6e73·6574··0·-F·auid!=unset
000007b0:·793d·756e·7375·6363·6573·7366·756c·2d61··y=unsuccessful-a000007b0:·202d·4620·6b65·793d·756e·7375·6363·6573···-F·key=unsucces
000007c0:·6363·6573·7320·2020·203c·2f70·7265·3e0a··ccess····</pre>.000007c0:·7366·756c·2d6d·6f64·6966·6963·6174·696f··sful-modificatio
000007d0:·0a4c·6f61·6420·6e65·7720·4175·6469·7420··.Load·new·Audit·000007d0:·6e0a·2d61·2061·6c77·6179·732c·6578·6974··n.-a·always,exit
000007e0:·7275·6c65·7320·696e·746f·206b·6572·6e65··rules·into·kerne000007e0:·202d·4620·6172·6368·3d62·3332·202d·5320···-F·arch=b32·-S·
000007f0:·6c20·6279·2072·756e·6e69·6e67·3a0a·3c70··l·by·running:.<p000007f0:·7472·756e·6361·7465·2c66·7472·756e·6361··truncate,ftrunca
00000800:·7265·3e61·7567·656e·7275·6c65·7320·2d2d··re>augenrules·--00000800:·7465·202d·4620·6578·6974·3d2d·4541·4343··te·-F·exit=-EACC
00000810:·6c6f·6164·3c2f·7072·653e·0a0a·4e6f·7465··load</pre>..Note00000810:·4553·202d·4620·6175·6964·2667·743b·3d31··ES·-F·auid&gt;=1
00000820:·3a20·5468·6973·2072·756c·6520·7573·6573··:·This·rule·uses00000820:·3030·3020·2d46·2061·7569·6421·3d75·6e73··000·-F·auid!=uns
00000830:·2061·2073·7065·6369·616c·2073·6574·206f···a·special·set·o00000830:·6574·202d·4620·6b65·793d·756e·7375·6363··et·-F·key=unsucc
00000840:·6620·4175·6469·7420·7275·6c65·7320·746f··f·Audit·rules·to00000840:·6573·7366·756c·2d6d·6f64·6966·6963·6174··essful-modificat
00000850:·2063·6f6d·706c·7920·7769·7468·204f·5350···comply·with·OSP00000850:·696f·6e0a·2d61·2061·6c77·6179·732c·6578··ion.-a·always,ex
00000860:·5020·342e·322e·312e·2059·6f75·206d·6179··P·4.2.1.·You·may00000860:·6974·202d·4620·6172·6368·3d62·3634·202d··it·-F·arch=b64·-
00000870:·2072·6575·7365·2074·6869·7320·7275·6c65···reuse·this·rule00000870:·5320·7472·756e·6361·7465·2c66·7472·756e··S·truncate,ftrun
00000880:·2069·6e20·6469·6666·6572·656e·7420·7072···in·different·pr00000880:·6361·7465·202d·4620·6578·6974·3d2d·4541··cate·-F·exit=-EA
00000890:·6f66·696c·6573·2e20·4966·2079·6f75·2064··ofiles.·If·you·d00000890:·4343·4553·202d·4620·6175·6964·2667·743b··CCES·-F·auid&gt;
000008a0:·6563·6964·6520·746f·2064·6f20·736f·2c20··ecide·to·do·so,·000008a0:·3d31·3030·3020·2d46·2061·7569·6421·3d75··=1000·-F·auid!=u
000008b0:·6974·2069·7320·7265·636f·6d6d·656e·6465··it·is·recommende000008b0:·6e73·6574·202d·4620·6b65·793d·756e·7375··nset·-F·key=unsu
000008c0:·6420·7468·6174·2079·6f75·2069·6e73·7065··d·that·you·inspe000008c0:·6363·6573·7366·756c·2d6d·6f64·6966·6963··ccessful-modific
000008d0:·6374·2063·6f6e·7465·6e74·7320·6f66·2074··ct·contents·of·t000008d0:·6174·696f·6e0a·2d61·2061·6c77·6179·732c··ation.-a·always,
000008e0:·6865·2066·696c·6520·636c·6f73·656c·7920··he·file·closely·000008e0:·6578·6974·202d·4620·6172·6368·3d62·3332··exit·-F·arch=b32
000008f0:·616e·6420·6d61·6b65·2073·7572·6520·7468··and·make·sure·th000008f0:·202d·5320·6f70·656e·6174·2c6f·7065·6e5f···-S·openat,open_
00000900:·6174·2074·6865·7920·6172·6520·616c·6c69··at·they·are·alli00000900:·6279·5f68·616e·646c·655f·6174·202d·4620··by_handle_at·-F·
00000910:·676e·6564·2077·6974·6820·796f·7572·206e··gned·with·your·n00000910:·6132·2661·6d70·3b30·3130·3033·202d·4620··a2&amp;01003·-F·
00000920:·6565·6473·2e0a·2020·2020·2020·3c2f·7464··eeds..······</td00000920:·6578·6974·3d2d·4550·4552·4d20·2d46·2061··exit=-EPERM·-F·a
00000930:·3e0a·2020·2020·2020·3c74·6420·786d·6c3a··>.······<td·xml:00000930:·7569·6426·6774·3b3d·3130·3030·202d·4620··uid&gt;=1000·-F·
00000940:·6c61·6e67·3d22·656e·2d55·5322·3e0a·2020··lang="en-US">.··00000940:·6175·6964·213d·756e·7365·7420·2d46·206b··auid!=unset·-F·k
00000950:·2020·2020·2020·556e·7375·6363·6573·7366········Unsuccessf00000950:·6579·3d75·6e73·7563·6365·7373·6675·6c2d··ey=unsuccessful-
00000960:·756c·2061·7474·656d·7074·7320·746f·2061··ul·attempts·to·a00000960:·6d6f·6469·6669·6361·7469·6f6e·0a2d·6120··modification.-a·
00000970:·6363·6573·7320·6120·6669·6c65·206d·6967··ccess·a·file·mig00000970:·616c·7761·7973·2c65·7869·7420·2d46·2061··always,exit·-F·a
00000980:·6874·2062·6520·7369·676e·7320·6f66·206d··ht·be·signs·of·m00000980:·7263·683d·6236·3420·2d53·206f·7065·6e61··rch=b64·-S·opena
00000990:·616c·6963·696f·7573·2061·6374·6976·6974··alicious·activit00000990:·742c·6f70·656e·5f62·795f·6861·6e64·6c65··t,open_by_handle
000009a0:·7920·6861·7070·656e·696e·6720·7769·7468··y·happening·with000009a0:·5f61·7420·2d46·2061·3226·616d·703b·3031··_at·-F·a2&amp;01
000009b0:·696e·2074·6865·2073·7973·7465·6d2e·2041··in·the·system.·A000009b0:·3030·3320·2d46·2065·7869·743d·2d45·5045··003·-F·exit=-EPE
000009c0:·7564·6974·696e·6720·6f66·2073·7563·6820··uditing·of·such·000009c0:·524d·202d·4620·6175·6964·2667·743b·3d31··RM·-F·auid&gt;=1
000009d0:·6163·7469·7669·7469·6573·2068·656c·7073··activities·helps000009d0:·3030·3020·2d46·2061·7569·6421·3d75·6e73··000·-F·auid!=uns
000009e0:·2069·6e20·7468·6569·7220·6d6f·6e69·746f···in·their·monito000009e0:·6574·202d·4620·6b65·793d·756e·7375·6363··et·-F·key=unsucc
000009f0:·7269·6e67·2061·6e64·2069·6e76·6573·7469··ring·and·investi000009f0:·6573·7366·756c·2d6d·6f64·6966·6963·6174··essful-modificat
00000a00:·6761·7469·6f6e·2e0a·2020·2020·2020·3c2f··gation..······</00000a00:·696f·6e0a·2d61·2061·6c77·6179·732c·6578··ion.-a·always,ex
00000a10:·7464·3e0a·2020·2020·3c2f·7472·3e0a·2020··td>.····</tr>.··00000a10:·6974·202d·4620·6172·6368·3d62·3332·202d··it·-F·arch=b32·-
00000a20:·2020·3c74·723e·0a20·2020·2020·203c·7464····<tr>.······<td00000a20:·5320·6f70·656e·202d·4620·6131·2661·6d70··S·open·-F·a1&amp
00000a30:·3e41·552d·3228·6429·3c62·722f·3e41·552d··>AU-2(d)<br/>AU-00000a30:·3b30·3130·3033·202d·4620·6578·6974·3d2d··;01003·-F·exit=-
00000a40:·3132·2863·293c·6272·2f3e·434d·2d36·2861··12(c)<br/>CM-6(a00000a40:·4550·4552·4d20·2d46·2061·7569·6426·6774··EPERM·-F·auid&gt
00000a50:·293c·2f74·643e·0a20·2020·2020·203c·7464··)</td>.······<td00000a50:·3b3d·3130·3030·202d·4620·6175·6964·213d··;=1000·-F·auid!=
00000a60:·3e52·6563·6f72·6420·556e·7375·6363·6573··>Record·Unsucces00000a60:·756e·7365·7420·2d46·206b·6579·3d75·6e73··unset·-F·key=uns
00000a70:·7366·756c·2050·6572·6d69·7373·696f·6e20··sful·Permission·00000a70:·7563·6365·7373·6675·6c2d·6d6f·6469·6669··uccessful-modifi
00000a80:·4368·616e·6765·7320·746f·2046·696c·6573··Changes·to·Files00000a80:·6361·7469·6f6e·0a2d·6120·616c·7761·7973··cation.-a·always
00000a90:·202d·2073·6574·7861·7474·723c·2f74·643e···-·setxattr</td>00000a90:·2c65·7869·7420·2d46·2061·7263·683d·6236··,exit·-F·arch=b6
00000aa0:·0a20·2020·2020·203c·7464·2078·6d6c·3a6c··.······<td·xml:l00000aa0:·3420·2d53·206f·7065·6e20·2d46·2061·3126··4·-S·open·-F·a1&
00000ab0:·616e·673d·2265·6e2d·5553·223e·0a20·2020··ang="en-US">.···00000ab0:·616d·703b·3031·3030·3320·2d46·2065·7869··amp;01003·-F·exi
00000ac0:·2020·2020·2054·6865·2061·7564·6974·2073·······The·audit·s00000ac0:·743d·2d45·5045·524d·202d·4620·6175·6964··t=-EPERM·-F·auid
00000ad0:·7973·7465·6d20·7368·6f75·6c64·2063·6f6c··ystem·should·col00000ad0:·2667·743b·3d31·3030·3020·2d46·2061·7569··&gt;=1000·-F·aui
00000ae0:·6c65·6374·2075·6e73·7563·6365·7373·6675··lect·unsuccessfu00000ae0:·6421·3d75·6e73·6574·202d·4620·6b65·793d··d!=unset·-F·key=
00000af0:·6c20·6669·6c65·2070·6572·6d69·7373·696f··l·file·permissio00000af0:·756e·7375·6363·6573·7366·756c·2d6d·6f64··unsuccessful-mod
00000b00:·6e20·6368·616e·6765·0a61·7474·656d·7074··n·change.attempt00000b00:·6966·6963·6174·696f·6e0a·2d61·2061·6c77··ification.-a·alw
00000b10:·7320·666f·7220·616c·6c20·7573·6572·7320··s·for·all·users·00000b10:·6179·732c·6578·6974·202d·4620·6172·6368··ays,exit·-F·arch
00000b20:·616e·6420·726f·6f74·2e0a·4966·2074·6865··and·root..If·the00000b20:·3d62·3332·202d·5320·7472·756e·6361·7465··=b32·-S·truncate
00000b30:·203c·7474·3e61·7564·6974·643c·2f74·743e···<tt>auditd</tt>00000b30:·2c66·7472·756e·6361·7465·202d·4620·6578··,ftruncate·-F·ex
00000b40:·2064·6165·6d6f·6e20·6973·2063·6f6e·6669···daemon·is·confi00000b40:·6974·3d2d·4550·4552·4d20·2d46·2061·7569··it=-EPERM·-F·aui
00000b50:·6775·7265·640a·746f·2075·7365·2074·6865··gured.to·use·the00000b50:·6426·6774·3b3d·3130·3030·202d·4620·6175··d&gt;=1000·-F·au
00000b60:·203c·7474·3e61·7567·656e·7275·6c65·733c···<tt>augenrules<00000b60:·6964·213d·756e·7365·7420·2d46·206b·6579··id!=unset·-F·key
00000b70:·2f74·743e·2070·726f·6772·616d·2074·6f20··/tt>·program·to·00000b70:·3d75·6e73·7563·6365·7373·6675·6c2d·6d6f··=unsuccessful-mo
00000b80:·7265·6164·2061·7564·6974·2072·756c·6573··read·audit·rules00000b80:·6469·6669·6361·7469·6f6e·0a2d·6120·616c··dification.-a·al
00000b90:·2064·7572·696e·6720·6461·656d·6f6e·0a73···during·daemon.s00000b90:·7761·7973·2c65·7869·7420·2d46·2061·7263··ways,exit·-F·arc
00000ba0:·7461·7274·7570·2028·7468·6520·6465·6661··tartup·(the·defa00000ba0:·683d·6236·3420·2d53·2074·7275·6e63·6174··h=b64·-S·truncat
00000bb0:·756c·7429·2c20·6164·6420·7468·6520·666f··ult),·add·the·fo00000bb0:·652c·6674·7275·6e63·6174·6520·2d46·2065··e,ftruncate·-F·e
00000bc0:·6c6c·6f77·696e·6720·6c69·6e65·7320·746f··llowing·lines·to00000bc0:·7869·743d·2d45·5045·524d·202d·4620·6175··xit=-EPERM·-F·au
00000bd0:·2061·2066·696c·6520·7769·7468·2073·7566···a·file·with·suf00000bd0:·6964·2667·743b·3d31·3030·3020·2d46·2061··id&gt;=1000·-F·a
00000be0:·6669·780a·3c74·743e·2e72·756c·6573·3c2f··fix.<tt>.rules</00000be0:·7569·6421·3d75·6e73·6574·202d·4620·6b65··uid!=unset·-F·ke
00000bf0:·7474·3e20·696e·2074·6865·2064·6972·6563··tt>·in·the·direc00000bf0:·793d·756e·7375·6363·6573·7366·756c·2d6d··y=unsuccessful-m
00000c00:·746f·7279·203c·7474·3e2f·6574·632f·6175··tory·<tt>/etc/au00000c00:·6f64·6966·6963·6174·696f·6e20·2020·203c··odification····<
Max diff block lines reached; 6258719/7302025 bytes (85.71%) of diff not shown.
2.5 MB
html2text {}
Max HTML report size reached
791 KB
./usr/share/doc/ssg-nondebian/table-rhel8-pcidssrefs.html
Ordering differences only
    
Offset 157, 28 lines modifiedOffset 157, 14 lines modified
157 default·zone·to·<tt>drop</tt>·implements·proper·design·for·a·firewall,·i.e.157 default·zone·to·<tt>drop</tt>·implements·proper·design·for·a·firewall,·i.e.
158 any·packets·which·are·not·explicitly·permitted·should·not·be158 any·packets·which·are·not·explicitly·permitted·should·not·be
159 accepted.159 accepted.
160 ······</td>160 ······</td>
161 ····</tr>161 ····</tr>
162 ····<tr>162 ····<tr>
163 ······<td>Req-1.4.1</td>163 ······<td>Req-1.4.1</td>
164 ······<td>Install·iptables·Package</td> 
165 ······<td·xml:lang="en-US"> 
166 ········The·<code>iptables</code>·package·can·be·installed·with·the·following·command: 
167 <pre> 
168 $·sudo·yum·install·iptables</pre> 
169 ······</td> 
170 ······<td·xml:lang="en-US"> 
171 ········<tt>iptables</tt>·controls·the·Linux·kernel·network·packet·filtering 
172 code.·<tt>iptables</tt>·allows·system·operators·to·set·up·firewalls·and·IP 
173 masquerading,·etc. 
174 ······</td> 
175 ····</tr> 
176 ····<tr> 
177 ······<td>Req-1.4.1</td> 
178 ······<td>Set·nftables·Configuration·for·Loopback·Traffic</td>164 ······<td>Set·nftables·Configuration·for·Loopback·Traffic</td>
179 ······<td·xml:lang="en-US">165 ······<td·xml:lang="en-US">
180 ········Configure·the·loopback·interface·to·accept·traffic.166 ········Configure·the·loopback·interface·to·accept·traffic.
181 Configure·all·other·interfaces·to·deny·traffic·to·the·loopback167 Configure·all·other·interfaces·to·deny·traffic·to·the·loopback
182 network.168 network.
183 ······</td>169 ······</td>
184 ······<td·xml:lang="en-US">170 ······<td·xml:lang="en-US">
Offset 187, 14 lines modifiedOffset 173, 28 lines modified
187 is·the·only·place·that·loopback·network·traffic·should·be·seen,173 is·the·only·place·that·loopback·network·traffic·should·be·seen,
188 all·other·interfaces·should·ignore·traffic·on·this·network·as·an174 all·other·interfaces·should·ignore·traffic·on·this·network·as·an
189 anti-spoofing·measure.175 anti-spoofing·measure.
190 ······</td>176 ······</td>
191 ····</tr>177 ····</tr>
192 ····<tr>178 ····<tr>
193 ······<td>Req-1.4.1</td>179 ······<td>Req-1.4.1</td>
 180 ······<td>Install·iptables·Package</td>
 181 ······<td·xml:lang="en-US">
 182 ········The·<code>iptables</code>·package·can·be·installed·with·the·following·command:
 183 <pre>
 184 $·sudo·yum·install·iptables</pre>
 185 ······</td>
 186 ······<td·xml:lang="en-US">
 187 ········<tt>iptables</tt>·controls·the·Linux·kernel·network·packet·filtering
 188 code.·<tt>iptables</tt>·allows·system·operators·to·set·up·firewalls·and·IP
 189 masquerading,·etc.
 190 ······</td>
 191 ····</tr>
 192 ····<tr>
 193 ······<td>Req-1.4.1</td>
194 ······<td>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</td>194 ······<td>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</td>
195 ······<td·xml:lang="en-US">195 ······<td·xml:lang="en-US">
196 ········To·set·the·runtime·status·of·the·<code>net.ipv4.tcp_syncookies</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1</pre>196 ········To·set·the·runtime·status·of·the·<code>net.ipv4.tcp_syncookies</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1</pre>
197 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.tcp_syncookies·=·1</pre>197 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.tcp_syncookies·=·1</pre>
198 ······</td>198 ······</td>
199 ······<td·xml:lang="en-US">199 ······<td·xml:lang="en-US">
200 ········A·TCP·SYN·flood·attack·can·cause·a·denial·of·service·by·filling·a200 ········A·TCP·SYN·flood·attack·can·cause·a·denial·of·service·by·filling·a
Offset 203, 14 lines modifiedOffset 203, 35 lines modified
203 verifying·the·initiator·is·attempting·a·valid·connection·and·is·not·a·flood203 verifying·the·initiator·is·attempting·a·valid·connection·and·is·not·a·flood
204 source.·This·feature·is·activated·when·a·flood·condition·is·detected,·and204 source.·This·feature·is·activated·when·a·flood·condition·is·detected,·and
205 enables·the·system·to·continue·servicing·valid·connection·requests.205 enables·the·system·to·continue·servicing·valid·connection·requests.
206 ······</td>206 ······</td>
207 ····</tr>207 ····</tr>
208 ····<tr>208 ····<tr>
209 ······<td>Req-1.4.2</td>209 ······<td>Req-1.4.2</td>
 210 ······<td>Disable·DCCP·Support</td>
 211 ······<td·xml:lang="en-US">
 212 ········The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a
 213 relatively·new·transport·layer·protocol,·designed·to·support
 214 streaming·media·and·telephony.
  
 215 To·configure·the·system·to·prevent·the·<code>dccp</code>
 216 kernel·module·from·being·loaded,·add·the·following·line·to·the·file·<code>/etc/modprobe.d/dccp.conf</code>:
 217 <pre>install·dccp·/bin/false</pre>
  
 218 To·configure·the·system·to·prevent·the·<code>dccp</code>·from·being·used,
 219 add·the·following·line·to·file·<code>/etc/modprobe.d/dccp.conf</code>:
 220 <pre>blacklist·dccp</pre>
 221 ······</td>
 222 ······<td·xml:lang="en-US">
 223 ········Disabling·DCCP·protects
 224 the·system·against·exploitation·of·any·flaws·in·its·implementation.
 225 ······</td>
 226 ····</tr>
 227 ····<tr>
 228 ······<td>Req-1.4.2</td>
210 ······<td>Disable·SCTP·Support</td>229 ······<td>Disable·SCTP·Support</td>
211 ······<td·xml:lang="en-US">230 ······<td·xml:lang="en-US">
212 ········The·Stream·Control·Transmission·Protocol·(SCTP)·is·a231 ········The·Stream·Control·Transmission·Protocol·(SCTP)·is·a
213 transport·layer·protocol,·designed·to·support·the·idea·of232 transport·layer·protocol,·designed·to·support·the·idea·of
214 message-oriented·communication,·with·several·streams·of·messages233 message-oriented·communication,·with·several·streams·of·messages
215 within·one·connection.234 within·one·connection.
  
Offset 224, 75 lines modifiedOffset 245, 58 lines modified
224 ······</td>245 ······</td>
225 ······<td·xml:lang="en-US">246 ······<td·xml:lang="en-US">
226 ········Disabling·SCTP·protects247 ········Disabling·SCTP·protects
227 the·system·against·exploitation·of·any·flaws·in·its·implementation.248 the·system·against·exploitation·of·any·flaws·in·its·implementation.
228 ······</td>249 ······</td>
229 ····</tr>250 ····</tr>
230 ····<tr>251 ····<tr>
231 ······<td>Req-1.4.2</td> 
232 ······<td>Disable·DCCP·Support</td> 
233 ······<td·xml:lang="en-US"> 
234 ········The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a 
235 relatively·new·transport·layer·protocol,·designed·to·support 
236 streaming·media·and·telephony. 
  
237 To·configure·the·system·to·prevent·the·<code>dccp</code> 
238 kernel·module·from·being·loaded,·add·the·following·line·to·the·file·<code>/etc/modprobe.d/dccp.conf</code>: 
239 <pre>install·dccp·/bin/false</pre> 
  
240 To·configure·the·system·to·prevent·the·<code>dccp</code>·from·being·used, 
241 add·the·following·line·to·file·<code>/etc/modprobe.d/dccp.conf</code>: 
242 <pre>blacklist·dccp</pre> 
243 ······</td> 
244 ······<td·xml:lang="en-US"> 
245 ········Disabling·DCCP·protects 
246 the·system·against·exploitation·of·any·flaws·in·its·implementation. 
247 ······</td> 
248 ····</tr> 
249 ····<tr> 
250 ······<td>Req-1.4.3</td>252 ······<td>Req-1.4.3</td>
251 ······<td>Disable·Kernel·Parameter·for·Accepting·Secure·ICMP·Redirects·on·all·IPv4·Interfaces</td>253 ······<td>Disable·Kernel·Parameter·for·Accepting·Secure·ICMP·Redirects·on·all·IPv4·Interfaces</td>
252 ······<td·xml:lang="en-US">254 ······<td·xml:lang="en-US">
253 ········To·set·the·runtime·status·of·the·<code>net.ipv4.conf.all.secure_redirects</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.conf.all.secure_redirects=0</pre>255 ········To·set·the·runtime·status·of·the·<code>net.ipv4.conf.all.secure_redirects</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.conf.all.secure_redirects=0</pre>
254 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.conf.all.secure_redirects·=·0</pre>256 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.conf.all.secure_redirects·=·0</pre>
Max diff block lines reached; 303188/308380 bytes (98.32%) of diff not shown.
490 KB
html2text {}
    
Offset 112, 23 lines modifiedOffset 112, 14 lines modified
112 ·········Incoming·Packets····firewalld.conf·to·be:··································drop·implements112 ·········Incoming·Packets····firewalld.conf·to·be:··································drop·implements
113 ·····························DefaultZone=drop·······································proper·design·for·a113 ·····························DefaultZone=drop·······································proper·design·for·a
114 ····················································································firewall,·i.e.·any114 ····················································································firewall,·i.e.·any
115 ····················································································packets·which·are115 ····················································································packets·which·are
116 ····················································································not·explicitly116 ····················································································not·explicitly
117 ····················································································permitted·should117 ····················································································permitted·should
118 ····················································································not·be·accepted.118 ····················································································not·be·accepted.
119 ····················································································iptables·controls 
120 ····················································································the·Linux·kernel 
121 ····················································································network·packet 
122 Req-·····Install·iptables····The·iptables·package·can·be·installed·with·the·········filtering·code. 
123 1.4.1····Package·············following·command:·····································iptables·allows 
124 ·····························$·sudo·yum·install·iptables····························system·operators·to 
125 ····················································································set·up·firewalls 
126 ····················································································and·IP 
127 ····················································································masquerading,·etc. 
128 ····················································································Loopback·traffic·is119 ····················································································Loopback·traffic·is
129 ····················································································generated·between120 ····················································································generated·between
130 ····················································································processes·on121 ····················································································processes·on
131 ····················································································machine·and·is122 ····················································································machine·and·is
132 ····················································································typically·critical123 ····················································································typically·critical
133 ····················································································to·operation·of·the124 ····················································································to·operation·of·the
134 ····················································································system.·The125 ····················································································system.·The
Offset 138, 14 lines modifiedOffset 129, 23 lines modified
138 ····················································································network·traffic129 ····················································································network·traffic
139 ····················································································should·be·seen,·all130 ····················································································should·be·seen,·all
140 ····················································································other·interfaces131 ····················································································other·interfaces
141 ····················································································should·ignore132 ····················································································should·ignore
142 ····················································································traffic·on·this133 ····················································································traffic·on·this
143 ····················································································network·as·an·anti-134 ····················································································network·as·an·anti-
144 ····················································································spoofing·measure.135 ····················································································spoofing·measure.
 136 ····················································································iptables·controls
 137 ····················································································the·Linux·kernel
 138 ····················································································network·packet
 139 Req-·····Install·iptables····The·iptables·package·can·be·installed·with·the·········filtering·code.
 140 1.4.1····Package·············following·command:·····································iptables·allows
 141 ·····························$·sudo·yum·install·iptables····························system·operators·to
 142 ····················································································set·up·firewalls
 143 ····················································································and·IP
 144 ····················································································masquerading,·etc.
145 ····················································································A·TCP·SYN·flood145 ····················································································A·TCP·SYN·flood
146 ····················································································attack·can·cause·a146 ····················································································attack·can·cause·a
147 ····················································································denial·of·service147 ····················································································denial·of·service
148 ····················································································by·filling·a148 ····················································································by·filling·a
149 ····················································································system's·TCP149 ····················································································system's·TCP
150 ····················································································connection·table150 ····················································································connection·table
151 ····················································································with·connections·in151 ····················································································with·connections·in
Offset 164, 90 lines modifiedOffset 164, 47 lines modified
164 ····················································································flood·condition·is164 ····················································································flood·condition·is
165 ····················································································detected,·and165 ····················································································detected,·and
166 ····················································································enables·the·system166 ····················································································enables·the·system
167 ····················································································to·continue167 ····················································································to·continue
168 ····················································································servicing·valid168 ····················································································servicing·valid
169 ····················································································connection169 ····················································································connection
170 ····················································································requests.170 ····················································································requests.
 171 ·····························The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a
 172 ·····························relatively·new·transport·layer·protocol,·designed·to
 173 ·····························support·streaming·media·and·telephony.·To·configure····Disabling·DCCP
 174 ·····························the·system·to·prevent·the·dccp·kernel·module·from······protects·the·system
 175 Req-·····Disable·DCCP········being·loaded,·add·the·following·line·to·the·file·/etc/·against
 176 1.4.2····Support·············modprobe.d/dccp.conf:··································exploitation·of·any
 177 ·····························install·dccp·/bin/false································flaws·in·its
 178 ·····························To·configure·the·system·to·prevent·the·dccp·from·being·implementation.
 179 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/
 180 ·····························dccp.conf:
 181 ·····························blacklist·dccp
171 ·····························The·Stream·Control·Transmission·Protocol·(SCTP)·is·a182 ·····························The·Stream·Control·Transmission·Protocol·(SCTP)·is·a
172 ·····························transport·layer·protocol,·designed·to·support·the·idea183 ·····························transport·layer·protocol,·designed·to·support·the·idea
173 ·····························of·message-oriented·communication,·with·several184 ·····························of·message-oriented·communication,·with·several
174 ·····························streams·of·messages·within·one·connection.·To··········Disabling·SCTP185 ·····························streams·of·messages·within·one·connection.·To··········Disabling·SCTP
175 ·····························configure·the·system·to·prevent·the·sctp·kernel·module·protects·the·system186 ·····························configure·the·system·to·prevent·the·sctp·kernel·module·protects·the·system
176 Req-·····Disable·SCTP········from·being·loaded,·add·the·following·line·to·the·file··against187 Req-·····Disable·SCTP········from·being·loaded,·add·the·following·line·to·the·file··against
177 1.4.2····Support·············/etc/modprobe.d/sctp.conf:·····························exploitation·of·any188 1.4.2····Support·············/etc/modprobe.d/sctp.conf:·····························exploitation·of·any
178 ·····························install·sctp·/bin/false································flaws·in·its189 ·····························install·sctp·/bin/false································flaws·in·its
179 ·····························To·configure·the·system·to·prevent·the·sctp·from·being·implementation.190 ·····························To·configure·the·system·to·prevent·the·sctp·from·being·implementation.
180 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/191 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/
181 ·····························sctp.conf:192 ·····························sctp.conf:
182 ·····························blacklist·sctp193 ·····························blacklist·sctp
183 ·····························The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a 
184 ·····························relatively·new·transport·layer·protocol,·designed·to 
185 ·····························support·streaming·media·and·telephony.·To·configure····Disabling·DCCP 
186 ·····························the·system·to·prevent·the·dccp·kernel·module·from······protects·the·system 
187 Req-·····Disable·DCCP········being·loaded,·add·the·following·line·to·the·file·/etc/·against 
188 1.4.2····Support·············modprobe.d/dccp.conf:··································exploitation·of·any 
189 ·····························install·dccp·/bin/false································flaws·in·its 
190 ·····························To·configure·the·system·to·prevent·the·dccp·from·being·implementation. 
191 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/ 
192 ·····························dccp.conf: 
193 ·····························blacklist·dccp 
194 ····················································································Accepting·"secure"194 ····················································································Accepting·"secure"
195 ·····························To·set·the·runtime·status·of·the·······················ICMP·redirects195 ·····························To·set·the·runtime·status·of·the·······················ICMP·redirects
196 ·········Disable·Kernel······net.ipv4.conf.all.secure_redirects·kernel·parameter,···(from·those196 ·········Disable·Kernel······net.ipv4.conf.all.secure_redirects·kernel·parameter,···(from·those
197 ·········Parameter·for·······run·the·following·command:·····························gateways·listed·as197 ·········Parameter·for·······run·the·following·command:·····························gateways·listed·as
198 Req-·····Accepting·Secure····$·sudo·sysctl·-w·net.ipv4.conf.all.secure_redirects=0··default·gateways)198 Req-·····Accepting·Secure····$·sudo·sysctl·-w·net.ipv4.conf.all.secure_redirects=0··default·gateways)
199 1.4.3····ICMP·Redirects·on···To·make·sure·that·the·setting·is·persistent,·add·the···has·few·legitimate199 1.4.3····ICMP·Redirects·on···To·make·sure·that·the·setting·is·persistent,·add·the···has·few·legitimate
200 ·········all·IPv4·Interfaces·following·line·to·a·file·in·the·directory·/etc/········uses.·It·should·be200 ·········all·IPv4·Interfaces·following·line·to·a·file·in·the·directory·/etc/········uses.·It·should·be
201 ·····························sysctl.d:··············································disabled·unless·it201 ·····························sysctl.d:··············································disabled·unless·it
202 ·····························net.ipv4.conf.all.secure_redirects·=·0·················is·absolutely202 ·····························net.ipv4.conf.all.secure_redirects·=·0·················is·absolutely
203 ····················································································required.203 ····················································································required.
204 ····················································································Responding·to 
205 ····················································································broadcast·(ICMP) 
206 ····················································································echoes·facilitates 
207 ·····························To·set·the·runtime·status·of·the·······················network·mapping·and 
208 ·····························net.ipv4.icmp_echo_ignore_broadcasts·kernel·parameter,·provides·a·vector 
209 ·········Enable·Kernel·······run·the·following·command:·····························for·amplification 
210 ·········Parameter·to·Ignore·$·sudo·sysctl·-········································attacks. 
211 Req-·····ICMP·Broadcast·Echo·w·net.ipv4.icmp_echo_ignore_broadcasts=1···············Ignoring·ICMP·echo 
212 1.4.3····Requests·on·IPv4····To·make·sure·that·the·setting·is·persistent,·add·the···requests·(pings) 
213 ·········Interfaces··········following·line·to·a·file·in·the·directory·/etc/········sent·to·broadcast 
214 ·····························sysctl.d:··············································or·multicast 
215 ·····························net.ipv4.icmp_echo_ignore_broadcasts·=·1···············addresses·makes·the 
216 ····················································································system·slightly 
217 ····················································································more·difficult·to 
218 ····················································································enumerate·on·the 
219 ····················································································network. 
220 ····················································································Enabling·reverse 
221 ····················································································path·filtering 
222 ····················································································drops·packets·with 
223 ····················································································source·addresses 
224 ····················································································that·should·not 
225 ·····························To·set·the·runtime·status·of·the·······················have·been·able·to 
226 ·········Enable·Kernel·······net.ipv4.conf.all.rp_filter·kernel·parameter,·run·the··be·received·on·the 
227 ·········Parameter·to·Use····following·command:·····································interface·they·were 
228 Req-·····Reverse·Path········$·sudo·sysctl·-w·net.ipv4.conf.all.rp_filter=1·········received·on.·It 
229 1.4.3····Filtering·on·all····To·make·sure·that·the·setting·is·persistent,·add·the···should·not·be·used 
230 ·········IPv4·Interfaces·····following·line·to·a·file·in·the·directory·/etc/········on·systems·which 
231 ·····························sysctl.d:··············································are·routers·for 
Max diff block lines reached; 488215/501896 bytes (97.27%) of diff not shown.
1.16 KB
./usr/share/scap-security-guide/tailoring/rhel8_stig_delta_tailoring.xml
1.02 KB
./usr/share/scap-security-guide/tailoring/rhel8_stig_delta_tailoring.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">
3 ··<xccdf-1.2:version·time="2026-01-08T18:18:57.428803+00:00">1</xccdf-1.2:version>3 ··<xccdf-1.2:version·time="2024-12-06T12:37:58.090255+00:00">1</xccdf-1.2:version>
4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">
5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>
6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the
7 DISA·STIG·for·Red·Hat·Enterprise·Linux·8·V1R14.7 DISA·STIG·for·Red·Hat·Enterprise·Linux·8·V1R14.
  
8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·8,·DISA·recognizes·this8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·8,·DISA·recognizes·this
9 configuration·baseline·as·applicable·to·the·operating·system·tier·of9 configuration·baseline·as·applicable·to·the·operating·system·tier·of
1.53 MB
./usr/share/xml/scap/ssg/content/ssg-al2023-ds.xml
1.53 MB
./usr/share/xml/scap/ssg/content/ssg-al2023-ds.xml
    
Offset 19, 25 lines modifiedOffset 19, 25 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-al2023-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-al2023-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-cpe-dictionary.xml"·timestamp="2024-11-02T06:39:34">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-cpe-dictionary.xml"·timestamp="2024-11-03T08:39:34">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:amazon:amazon_linux:2023">28 ······<cpe-dict:cpe-item·name="cpe:/o:amazon:amazon_linux:2023">
29 ········<cpe-dict:title·xml:lang="en-us">Amazon·Linux·2023</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Amazon·Linux·2023</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml">oval:ssg-installed_OS_is_al2023:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml">oval:ssg-installed_OS_is_al2023:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-xccdf.xml"·timestamp="2024-11-02T06:39:34">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-al2023-xccdf.xml"·timestamp="2024-11-03T08:39:34">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_AL-2023"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_AL-2023"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Linux·2023</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Linux·2023</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Amazon·Linux·2023.·It·is·a·rendering·of40 configuration·settings·for·Amazon·Linux·2023.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
42 in·order·to·support·security·automation.··The·SCAP·content·is42 in·order·to·support·security·automation.··The·SCAP·content·is
43 is·available·in·the43 is·available·in·the
Offset 105, 163 lines modifiedOffset 105, 163 lines modified
105 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>105 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
106 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>106 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
107 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
110 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>110 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
111 ······<cpe-lang:platform-specification>111 ······<cpe-lang:platform-specification>
112 ········<cpe-lang:platform·id="package_shadow-utils"> 
113 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
114 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/> 
115 ··········</cpe-lang:logical-test> 
116 ········</cpe-lang:platform> 
117 ········<cpe-lang:platform·id="machine">112 ········<cpe-lang:platform·id="ipv6_enabled">
118 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
119 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
120 ··········</cpe-lang:logical-test> 
121 ········</cpe-lang:platform> 
122 ········<cpe-lang:platform·id="machine_and_mount_home"> 
123 ··········<cpe-lang:logical-test·operator="AND"·negate="false">113 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
124 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
125 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_home:def:1"/>114 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
126 ··········</cpe-lang:logical-test>115 ··········</cpe-lang:logical-test>
127 ········</cpe-lang:platform>116 ········</cpe-lang:platform>
128 ········<cpe-lang:platform·id="machine_and_mount_var-log">117 ········<cpe-lang:platform·id="package_dnf">
129 ··········<cpe-lang:logical-test·operator="AND"·negate="false">118 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>119 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_dnf:def:1"/>
131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/> 
132 ··········</cpe-lang:logical-test>120 ··········</cpe-lang:logical-test>
133 ········</cpe-lang:platform>121 ········</cpe-lang:platform>
134 ········<cpe-lang:platform·id="package_sudo">122 ········<cpe-lang:platform·id="grub2">
135 ··········<cpe-lang:logical-test·operator="AND"·negate="false">123 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
136 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>124 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
137 ··········</cpe-lang:logical-test>125 ··········</cpe-lang:logical-test>
138 ········</cpe-lang:platform>126 ········</cpe-lang:platform>
139 ········<cpe-lang:platform·id="machine_and_mount_var-log-audit">127 ········<cpe-lang:platform·id="machine">
140 ··········<cpe-lang:logical-test·operator="AND"·negate="false">128 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
141 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>129 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
142 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log-audit:def:1"/> 
143 ··········</cpe-lang:logical-test>130 ··········</cpe-lang:logical-test>
144 ········</cpe-lang:platform>131 ········</cpe-lang:platform>
145 ········<cpe-lang:platform·id="machine_and_service_disabled_iptables_and_service_disabled_ufw">132 ········<cpe-lang:platform·id="machine_and_mount_tmp">
146 ··········<cpe-lang:logical-test·operator="AND"·negate="false">133 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
147 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>134 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
148 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_iptables:def:1"/> 
149 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
150 ··········</cpe-lang:logical-test>136 ··········</cpe-lang:logical-test>
151 ········</cpe-lang:platform>137 ········</cpe-lang:platform>
152 ········<cpe-lang:platform·id="not_aarch64_arch">138 ········<cpe-lang:platform·id="not_aarch64_arch">
153 ··········<cpe-lang:logical-test·operator="AND"·negate="true">139 ··········<cpe-lang:logical-test·operator="AND"·negate="true">
154 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
155 ··········</cpe-lang:logical-test>141 ··········</cpe-lang:logical-test>
156 ········</cpe-lang:platform>142 ········</cpe-lang:platform>
157 ········<cpe-lang:platform·id="package_nftables">143 ········<cpe-lang:platform·id="machine_and_mount_var">
158 ··········<cpe-lang:logical-test·operator="AND"·negate="false">144 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 145 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
159 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>
160 ··········</cpe-lang:logical-test>147 ··········</cpe-lang:logical-test>
161 ········</cpe-lang:platform>148 ········</cpe-lang:platform>
162 ········<cpe-lang:platform·id="package_firewalld">149 ········<cpe-lang:platform·id="machine_and_package_snmpd">
163 ··········<cpe-lang:logical-test·operator="AND"·negate="false">150 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
164 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>152 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>
165 ··········</cpe-lang:logical-test>153 ··········</cpe-lang:logical-test>
166 ········</cpe-lang:platform>154 ········</cpe-lang:platform>
167 ········<cpe-lang:platform·id="package_systemd">155 ········<cpe-lang:platform·id="package_pam">
168 ··········<cpe-lang:logical-test·operator="AND"·negate="false">156 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
169 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>157 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
170 ··········</cpe-lang:logical-test>158 ··········</cpe-lang:logical-test>
171 ········</cpe-lang:platform>159 ········</cpe-lang:platform>
172 ········<cpe-lang:platform·id="package_postfix">160 ········<cpe-lang:platform·id="package_firewalld">
173 ··········<cpe-lang:logical-test·operator="AND"·negate="false">161 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
174 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>162 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
175 ··········</cpe-lang:logical-test>163 ··········</cpe-lang:logical-test>
176 ········</cpe-lang:platform>164 ········</cpe-lang:platform>
177 ········<cpe-lang:platform·id="non-uefi">165 ········<cpe-lang:platform·id="machine_and_package_firewalld_and_package_nftables">
178 ··········<cpe-lang:logical-test·operator="AND"·negate="false">166 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
179 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>167 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
 168 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
 169 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
180 ··········</cpe-lang:logical-test>170 ··········</cpe-lang:logical-test>
181 ········</cpe-lang:platform>171 ········</cpe-lang:platform>
182 ········<cpe-lang:platform·id="grub2">172 ········<cpe-lang:platform·id="package_audit">
183 ··········<cpe-lang:logical-test·operator="AND"·negate="false">173 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
184 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>174 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>
185 ··········</cpe-lang:logical-test>175 ··········</cpe-lang:logical-test>
186 ········</cpe-lang:platform>176 ········</cpe-lang:platform>
187 ········<cpe-lang:platform·id="machine_and_mount_var-tmp">177 ········<cpe-lang:platform·id="machine_and_mount_var-tmp">
188 ··········<cpe-lang:logical-test·operator="AND"·negate="false">178 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
189 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>179 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
190 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>180 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
191 ··········</cpe-lang:logical-test>181 ··········</cpe-lang:logical-test>
192 ········</cpe-lang:platform>182 ········</cpe-lang:platform>
193 ········<cpe-lang:platform·id="package_rsh-server">183 ········<cpe-lang:platform·id="non-uefi">
194 ··········<cpe-lang:logical-test·operator="AND"·negate="false">184 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
195 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>185 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>
196 ··········</cpe-lang:logical-test>186 ··········</cpe-lang:logical-test>
197 ········</cpe-lang:platform>187 ········</cpe-lang:platform>
198 ········<cpe-lang:platform·id="package_chrony">188 ········<cpe-lang:platform·id="package_sudo">
199 ··········<cpe-lang:logical-test·operator="AND"·negate="false">189 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
200 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>190 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
201 ··········</cpe-lang:logical-test>191 ··········</cpe-lang:logical-test>
Max diff block lines reached; 1591473/1605294 bytes (99.14%) of diff not shown.
722 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-ocil.xml
722 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-ocil.xml
Ordering differences only
    
Offset 3, 3927 lines modifiedOffset 3, 3927 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_groupownership_ocil:questionnaire:1"> 
11 ······<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·Group</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_passwordauth_ocil:questionnaire:1">
 11 ······<ocil:title>Set·PAM''s·Password·Hashing·Algorithm·-·password-auth</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_groupownership_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_passwordauth_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-package_nftables_installed_ocil:questionnaire:1">
17 ······<ocil:title>Ensure·the·Default·Bash·Umask·is·Set·Correctly</ocil:title>17 ······<ocil:title>Install·nftables·Package</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-package_nftables_installed_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_at_deny_not_exist_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_crontab_ocil:questionnaire:1">
23 ······<ocil:title>Ensure·that·/etc/at.deny·does·not·exist</ocil:title>23 ······<ocil:title>Verify·Permissions·on·crontab</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_at_deny_not_exist_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_permissions_crontab_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_kernel_module_loading_delete_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1">
29 ······<ocil:title>Ensure·auditd·Collects·Information·on·Kernel·Module·Unloading·-·delete_module</ocil:title>29 ······<ocil:title>Ensure·/dev/shm·is·configured</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_delete_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-account_password_pam_faillock_password_auth_ocil:questionnaire:1"> 
35 ······<ocil:title>Configure·the·Use·of·the·pam_faillock.so·Module·in·the·/etc/pam.d/password-auth·File.</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-package_xorg-x11-server-common_removed_ocil:questionnaire:1">
 35 ······<ocil:title>Remove·the·X·Windows·Package·Group</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
 37 ········<ocil:test_action_ref>ocil:ssg-package_xorg-x11-server-common_removed_action:testaction:1</ocil:test_action_ref>
 38 ······</ocil:actions>
 39 ····</ocil:questionnaire>
 40 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_admin_space_left_action_ocil:questionnaire:1">
 41 ······<ocil:title>Configure·auditd·admin_space_left·Action·on·Low·Disk·Space</ocil:title>
 42 ······<ocil:actions>
 43 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_admin_space_left_action_action:testaction:1</ocil:test_action_ref>
 44 ······</ocil:actions>
 45 ····</ocil:questionnaire>
 46 ····<ocil:questionnaire·id="ocil:ssg-package_cups_removed_ocil:questionnaire:1">
 47 ······<ocil:title>Uninstall·CUPS·Package</ocil:title>
 48 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-account_password_pam_faillock_password_auth_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-package_cups_removed_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>50 ······</ocil:actions>
39 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_pwhistory_remember_password_auth_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_pwhistory_remember_password_auth_ocil:questionnaire:1">
41 ······<ocil:title>Limit·Password·Reuse:·password-auth</ocil:title>53 ······<ocil:title>Limit·Password·Reuse:·password-auth</ocil:title>
42 ······<ocil:actions>54 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwhistory_remember_password_auth_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwhistory_remember_password_auth_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>56 ······</ocil:actions>
45 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-aide_periodic_cron_checking_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-package_samba_removed_ocil:questionnaire:1">
47 ······<ocil:title>Configure·Periodic·Execution·of·AIDE</ocil:title>59 ······<ocil:title>Uninstall·Samba·Package</ocil:title>
48 ······<ocil:actions>60 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-aide_periodic_cron_checking_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-package_samba_removed_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>62 ······</ocil:actions>
51 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_passwd_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_passwd_ocil:questionnaire:1">
53 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/passwd</ocil:title>65 ······<ocil:title>Verify·Permissions·on·passwd·File</ocil:title>
54 ······<ocil:actions>66 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_passwd_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_passwd_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>68 ······</ocil:actions>
57 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_remote_loghost_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-grub2_audit_backlog_limit_argument_ocil:questionnaire:1">
59 ······<ocil:title>Ensure·Logs·Sent·To·Remote·Host</ocil:title>71 ······<ocil:title>Extend·Audit·Backlog·Limit·for·the·Audit·Daemon</ocil:title>
60 ······<ocil:actions>72 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-rsyslog_remote_loghost_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-grub2_audit_backlog_limit_argument_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>74 ······</ocil:actions>
63 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_nosuid_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_verbose_ocil:questionnaire:1">
65 ······<ocil:title>Add·nosuid·Option·to·/var/log</ocil:title>77 ······<ocil:title>Set·SSH·Daemon·LogLevel·to·VERBOSE</ocil:title>
66 ······<ocil:actions>78 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_log_nosuid_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_verbose_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>80 ······</ocil:actions>
69 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_gshadow_ocil:questionnaire:1">
71 ······<ocil:title>Ensure·/dev/shm·is·configured</ocil:title>83 ······<ocil:title>Verify·Permissions·on·gshadow·File</ocil:title>
72 ······<ocil:actions>84 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_gshadow_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>86 ······</ocil:actions>
75 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-package_samba_removed_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chcon_ocil:questionnaire:1">
77 ······<ocil:title>Uninstall·Samba·Package</ocil:title>89 ······<ocil:title>Record·Any·Attempts·to·Run·chcon</ocil:title>
78 ······<ocil:actions>90 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-package_samba_removed_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chcon_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>92 ······</ocil:actions>
81 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-package_xorg-x11-server-common_removed_ocil:questionnaire:1"> 
83 ······<ocil:title>Remove·the·X·Windows·Package·Group</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_last_change_is_in_past_ocil:questionnaire:1">
 95 ······<ocil:title>Ensure·all·users·last·password·change·date·is·in·the·past</ocil:title>
84 ······<ocil:actions>96 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-package_xorg-x11-server-common_removed_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-accounts_password_last_change_is_in_past_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>98 ······</ocil:actions>
87 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-dir_perms_world_writable_sticky_bits_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_rename_ocil:questionnaire:1">
89 ······<ocil:title>Verify·that·All·World-Writable·Directories·Have·Sticky·Bits·Set</ocil:title>101 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·rename</ocil:title>
90 ······<ocil:actions>102 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-dir_perms_world_writable_sticky_bits_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rename_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>104 ······</ocil:actions>
93 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_hourly_ocil:questionnaire:1"> 
95 ······<ocil:title>Verify·Group·Who·Owns·cron.hourly</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_set_warn_age_existing_ocil:questionnaire:1">
 107 ······<ocil:title>Set·Existing·Passwords·Warning·Age</ocil:title>
96 ······<ocil:actions>108 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_hourly_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-accounts_password_set_warn_age_existing_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>110 ······</ocil:actions>
99 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_kmod_ocil:questionnaire:1"> 
101 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·kmod</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_ocil:questionnaire:1">
 113 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·ICMP·Redirects·by·Default·on·IPv6·Interfaces</ocil:title>
102 ······<ocil:actions>114 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_kmod_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>116 ······</ocil:actions>
105 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_motd_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-package_httpd_removed_ocil:questionnaire:1">
107 ······<ocil:title>Verify·Group·Ownership·of·Message·of·the·Day·Banner</ocil:title>119 ······<ocil:title>Uninstall·httpd·Package</ocil:title>
108 ······<ocil:actions>120 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_motd_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-package_httpd_removed_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>122 ······</ocil:actions>
111 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_redirects_ocil:questionnaire:1"> 
Max diff block lines reached; 726706/738776 bytes (98.37%) of diff not shown.
797 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-xccdf.xml
797 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_AL-2023"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_AL-2023"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Linux·2023</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Linux·2023</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·Amazon·Linux·2023.·It·is·a·rendering·of7 configuration·settings·for·Amazon·Linux·2023.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
Offset 72, 163 lines modifiedOffset 72, 163 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="package_shadow-utils"> 
80 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/> 
82 ······</cpe-lang:logical-test> 
83 ····</cpe-lang:platform> 
84 ····<cpe-lang:platform·id="machine">79 ····<cpe-lang:platform·id="ipv6_enabled">
85 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
87 ······</cpe-lang:logical-test> 
88 ····</cpe-lang:platform> 
89 ····<cpe-lang:platform·id="machine_and_mount_home"> 
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_home:def:1"/>81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
93 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
94 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
95 ····<cpe-lang:platform·id="machine_and_mount_var-log">84 ····<cpe-lang:platform·id="package_dnf">
96 ······<cpe-lang:logical-test·operator="AND"·negate="false">85 ······<cpe-lang:logical-test·operator="AND"·negate="false">
97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_dnf:def:1"/>
98 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/> 
99 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
100 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
101 ····<cpe-lang:platform·id="package_sudo">89 ····<cpe-lang:platform·id="grub2">
102 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
103 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
104 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
105 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
106 ····<cpe-lang:platform·id="machine_and_mount_var-log-audit">94 ····<cpe-lang:platform·id="machine">
107 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
109 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log-audit:def:1"/> 
110 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
111 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
112 ····<cpe-lang:platform·id="machine_and_service_disabled_iptables_and_service_disabled_ufw">99 ····<cpe-lang:platform·id="machine_and_mount_tmp">
113 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
114 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
115 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_iptables:def:1"/> 
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
117 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="not_aarch64_arch">105 ····<cpe-lang:platform·id="not_aarch64_arch">
120 ······<cpe-lang:logical-test·operator="AND"·negate="true">106 ······<cpe-lang:logical-test·operator="AND"·negate="true">
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
122 ······</cpe-lang:logical-test>108 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>109 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="package_nftables">110 ····<cpe-lang:platform·id="machine_and_mount_var">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">111 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>
127 ······</cpe-lang:logical-test>114 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>115 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="package_firewalld">116 ····<cpe-lang:platform·id="machine_and_package_snmpd">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">117 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>
132 ······</cpe-lang:logical-test>120 ······</cpe-lang:logical-test>
133 ····</cpe-lang:platform>121 ····</cpe-lang:platform>
134 ····<cpe-lang:platform·id="package_systemd">122 ····<cpe-lang:platform·id="package_pam">
135 ······<cpe-lang:logical-test·operator="AND"·negate="false">123 ······<cpe-lang:logical-test·operator="AND"·negate="false">
136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>124 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
137 ······</cpe-lang:logical-test>125 ······</cpe-lang:logical-test>
138 ····</cpe-lang:platform>126 ····</cpe-lang:platform>
139 ····<cpe-lang:platform·id="package_postfix">127 ····<cpe-lang:platform·id="package_firewalld">
140 ······<cpe-lang:logical-test·operator="AND"·negate="false">128 ······<cpe-lang:logical-test·operator="AND"·negate="false">
141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>129 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
142 ······</cpe-lang:logical-test>130 ······</cpe-lang:logical-test>
143 ····</cpe-lang:platform>131 ····</cpe-lang:platform>
144 ····<cpe-lang:platform·id="non-uefi">132 ····<cpe-lang:platform·id="machine_and_package_firewalld_and_package_nftables">
145 ······<cpe-lang:logical-test·operator="AND"·negate="false">133 ······<cpe-lang:logical-test·operator="AND"·negate="false">
146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>134 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
 135 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
 136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
147 ······</cpe-lang:logical-test>137 ······</cpe-lang:logical-test>
148 ····</cpe-lang:platform>138 ····</cpe-lang:platform>
149 ····<cpe-lang:platform·id="grub2">139 ····<cpe-lang:platform·id="package_audit">
150 ······<cpe-lang:logical-test·operator="AND"·negate="false">140 ······<cpe-lang:logical-test·operator="AND"·negate="false">
151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>
152 ······</cpe-lang:logical-test>142 ······</cpe-lang:logical-test>
153 ····</cpe-lang:platform>143 ····</cpe-lang:platform>
154 ····<cpe-lang:platform·id="machine_and_mount_var-tmp">144 ····<cpe-lang:platform·id="machine_and_mount_var-tmp">
155 ······<cpe-lang:logical-test·operator="AND"·negate="false">145 ······<cpe-lang:logical-test·operator="AND"·negate="false">
156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>
158 ······</cpe-lang:logical-test>148 ······</cpe-lang:logical-test>
159 ····</cpe-lang:platform>149 ····</cpe-lang:platform>
160 ····<cpe-lang:platform·id="package_rsh-server">150 ····<cpe-lang:platform·id="non-uefi">
161 ······<cpe-lang:logical-test·operator="AND"·negate="false">151 ······<cpe-lang:logical-test·operator="AND"·negate="false">
162 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>
163 ······</cpe-lang:logical-test>153 ······</cpe-lang:logical-test>
164 ····</cpe-lang:platform>154 ····</cpe-lang:platform>
165 ····<cpe-lang:platform·id="package_chrony">155 ····<cpe-lang:platform·id="package_sudo">
166 ······<cpe-lang:logical-test·operator="AND"·negate="false">156 ······<cpe-lang:logical-test·operator="AND"·negate="false">
167 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
168 ······</cpe-lang:logical-test>158 ······</cpe-lang:logical-test>
169 ····</cpe-lang:platform>159 ····</cpe-lang:platform>
170 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">160 ····<cpe-lang:platform·id="package_postfix">
171 ······<cpe-lang:logical-test·operator="AND"·negate="false">161 ······<cpe-lang:logical-test·operator="AND"·negate="false">
172 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
173 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
174 ········</cpe-lang:logical-test> 
175 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
176 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>162 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
177 ········</cpe-lang:logical-test> 
178 ······</cpe-lang:logical-test>163 ······</cpe-lang:logical-test>
179 ····</cpe-lang:platform>164 ····</cpe-lang:platform>
180 ····<cpe-lang:platform·id="package_audit">165 ····<cpe-lang:platform·id="package_chrony">
181 ······<cpe-lang:logical-test·operator="AND"·negate="false">166 ······<cpe-lang:logical-test·operator="AND"·negate="false">
182 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>167 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
183 ······</cpe-lang:logical-test>168 ······</cpe-lang:logical-test>
Max diff block lines reached; 802023/815680 bytes (98.33%) of diff not shown.
1.48 MB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ds.xml
1.48 MB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ds.xml
    
Offset 19, 25 lines modifiedOffset 19, 25 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux2-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux2-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-cpe-dictionary.xml"·timestamp="2024-11-02T06:39:34">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-cpe-dictionary.xml"·timestamp="2024-11-03T08:39:34">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:2">28 ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:2">
29 ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·2</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·2</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml">oval:ssg-installed_OS_is_alinux2:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml">oval:ssg-installed_OS_is_alinux2:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-xccdf.xml"·timestamp="2024-11-02T06:39:34">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux2-xccdf.xml"·timestamp="2024-11-03T08:39:34">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-2"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-2"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·2</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·2</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Alibaba·Cloud·Linux·2.·It·is·a·rendering·of40 configuration·settings·for·Alibaba·Cloud·Linux·2.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
42 in·order·to·support·security·automation.··The·SCAP·content·is42 in·order·to·support·security·automation.··The·SCAP·content·is
43 is·available·in·the43 is·available·in·the
Offset 104, 198 lines modifiedOffset 104, 198 lines modified
104 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>104 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
105 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>105 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
106 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>106 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
107 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
110 ······<cpe-lang:platform-specification>110 ······<cpe-lang:platform-specification>
111 ········<cpe-lang:platform·id="package_shadow-utils">111 ········<cpe-lang:platform·id="ipv6_enabled">
112 ··········<cpe-lang:logical-test·operator="AND"·negate="false">112 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
113 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>113 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
114 ··········</cpe-lang:logical-test>114 ··········</cpe-lang:logical-test>
115 ········</cpe-lang:platform>115 ········</cpe-lang:platform>
116 ········<cpe-lang:platform·id="package_ntp">116 ········<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
117 ··········<cpe-lang:logical-test·operator="AND"·negate="false">117 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
 118 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
118 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>119 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
119 ··········</cpe-lang:logical-test>120 ··········</cpe-lang:logical-test>
120 ········</cpe-lang:platform>121 ········</cpe-lang:platform>
121 ········<cpe-lang:platform·id="aarch64_arch">122 ········<cpe-lang:platform·id="grub2">
122 ··········<cpe-lang:logical-test·operator="AND"·negate="false">123 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
123 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>124 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
124 ··········</cpe-lang:logical-test>125 ··········</cpe-lang:logical-test>
125 ········</cpe-lang:platform>126 ········</cpe-lang:platform>
126 ········<cpe-lang:platform·id="machine">127 ········<cpe-lang:platform·id="machine">
127 ··········<cpe-lang:logical-test·operator="AND"·negate="false">128 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
128 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>129 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
129 ··········</cpe-lang:logical-test>130 ··········</cpe-lang:logical-test>
130 ········</cpe-lang:platform>131 ········</cpe-lang:platform>
131 ········<cpe-lang:platform·id="x86_64_arch"> 
132 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
133 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/> 
134 ··········</cpe-lang:logical-test> 
135 ········</cpe-lang:platform> 
136 ········<cpe-lang:platform·id="package_logrotate"> 
137 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
138 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/> 
139 ··········</cpe-lang:logical-test> 
140 ········</cpe-lang:platform> 
141 ········<cpe-lang:platform·id="package_sudo">132 ········<cpe-lang:platform·id="package_iptables">
142 ··········<cpe-lang:logical-test·operator="AND"·negate="false">133 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
143 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>134 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
144 ··········</cpe-lang:logical-test>135 ··········</cpe-lang:logical-test>
145 ········</cpe-lang:platform>136 ········</cpe-lang:platform>
146 ········<cpe-lang:platform·id="machine_and_package_ufw">137 ········<cpe-lang:platform·id="machine_and_package_ufw">
147 ··········<cpe-lang:logical-test·operator="AND"·negate="false">138 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
148 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>139 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
149 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
150 ··········</cpe-lang:logical-test>141 ··········</cpe-lang:logical-test>
151 ········</cpe-lang:platform>142 ········</cpe-lang:platform>
152 ········<cpe-lang:platform·id="not_aarch64_arch">143 ········<cpe-lang:platform·id="not_aarch64_arch">
153 ··········<cpe-lang:logical-test·operator="AND"·negate="true">144 ··········<cpe-lang:logical-test·operator="AND"·negate="true">
154 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>145 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
155 ··········</cpe-lang:logical-test>146 ··········</cpe-lang:logical-test>
156 ········</cpe-lang:platform>147 ········</cpe-lang:platform>
 148 ········<cpe-lang:platform·id="machine_and_not_rhcos4-rhel9_and_service_disabled_nftables_and_service_disabled_ufw">
 149 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 150 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 151 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_OS_is_rhcos4_rhel9:def:1"/>
 152 ············</cpe-lang:logical-test>
 153 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
 154 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_nftables:def:1"/>
 155 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>
 156 ··········</cpe-lang:logical-test>
 157 ········</cpe-lang:platform>
 158 ········<cpe-lang:platform·id="package_ntp">
 159 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 160 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
 161 ··········</cpe-lang:logical-test>
 162 ········</cpe-lang:platform>
157 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">163 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
158 ··········<cpe-lang:logical-test·operator="AND"·negate="false">164 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
159 ············<cpe-lang:logical-test·operator="AND"·negate="true">165 ············<cpe-lang:logical-test·operator="AND"·negate="true">
160 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>166 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
161 ············</cpe-lang:logical-test>167 ············</cpe-lang:logical-test>
162 ············<cpe-lang:logical-test·operator="AND"·negate="true">168 ············<cpe-lang:logical-test·operator="AND"·negate="true">
163 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>169 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
164 ············</cpe-lang:logical-test>170 ············</cpe-lang:logical-test>
165 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
166 ··········</cpe-lang:logical-test>172 ··········</cpe-lang:logical-test>
167 ········</cpe-lang:platform>173 ········</cpe-lang:platform>
168 ········<cpe-lang:platform·id="package_yum">174 ········<cpe-lang:platform·id="package_pam">
169 ··········<cpe-lang:logical-test·operator="AND"·negate="false">175 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
170 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/>176 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
171 ··········</cpe-lang:logical-test>177 ··········</cpe-lang:logical-test>
172 ········</cpe-lang:platform>178 ········</cpe-lang:platform>
173 ········<cpe-lang:platform·id="package_firewalld">179 ········<cpe-lang:platform·id="package_firewalld">
174 ··········<cpe-lang:logical-test·operator="AND"·negate="false">180 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
175 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>181 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
176 ··········</cpe-lang:logical-test>182 ··········</cpe-lang:logical-test>
177 ········</cpe-lang:platform>183 ········</cpe-lang:platform>
178 ········<cpe-lang:platform·id="package_systemd">184 ········<cpe-lang:platform·id="package_logrotate">
179 ··········<cpe-lang:logical-test·operator="AND"·negate="false">185 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
180 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>186 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
181 ··········</cpe-lang:logical-test> 
182 ········</cpe-lang:platform> 
183 ········<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch"> 
184 ··········<cpe-lang:logical-test·operator="OR"·negate="false"> 
185 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
186 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/> 
187 ··········</cpe-lang:logical-test>187 ··········</cpe-lang:logical-test>
188 ········</cpe-lang:platform>188 ········</cpe-lang:platform>
Max diff block lines reached; 1543906/1556240 bytes (99.21%) of diff not shown.
860 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ocil.xml
860 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ocil.xml
Ordering differences only
    
Offset 3, 6396 lines modifiedOffset 3, 6292 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_table_isolation_ocil:questionnaire:1"> 
11 ······<ocil:title>Remove·the·kernel·mapping·in·user·mode</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_table_isolation_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_info_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_config_ocil:questionnaire:1">
 11 ······<ocil:title>Verify·Permissions·on·SSH·Server·config·file</ocil:title>
17 ······<ocil:title>Set·LogLevel·to·INFO</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_info_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-service_auditd_enabled_ocil:questionnaire:1"> 
23 ······<ocil:title>Enable·auditd·Service</ocil:title> 
24 ······<ocil:actions>12 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-service_auditd_enabled_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_config_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>14 ······</ocil:actions>
27 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-file_owner_crontab_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_daily_ocil:questionnaire:1">
29 ······<ocil:title>Verify·Owner·on·crontab</ocil:title>17 ······<ocil:title>Verify·Permissions·on·cron.daily</ocil:title>
30 ······<ocil:actions>18 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_owner_crontab_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_daily_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>20 ······</ocil:actions>
33 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_ipv6_option_disabled_ocil:questionnaire:1">
35 ······<ocil:title>Ensure·syslog-ng·is·Installed</ocil:title>23 ······<ocil:title>Disable·IPv6·Networking·Support·Automatic·Loading</ocil:title>
36 ······<ocil:actions>24 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-kernel_module_ipv6_option_disabled_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>26 ······</ocil:actions>
39 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_systemmap_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_passwd_ocil:questionnaire:1">
41 ······<ocil:title>Verify·Permissions·on·System.map·Files</ocil:title>29 ······<ocil:title>Verify·User·Who·Owns·passwd·File</ocil:title>
42 ······<ocil:actions>30 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-file_permissions_systemmap_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_passwd_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>32 ······</ocil:actions>
45 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_allow_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ia32_emulation_ocil:questionnaire:1">
47 ······<ocil:title>Verify·Permissions·on·/etc/cron.allow·file</ocil:title>35 ······<ocil:title>Disable·IA32·emulation</ocil:title>
48 ······<ocil:actions>36 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_allow_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-kernel_config_ia32_emulation_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>38 ······</ocil:actions>
51 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_kexec_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-selinux_policytype_ocil:questionnaire:1">
53 ······<ocil:title>Disable·kexec·system·call</ocil:title>41 ······<ocil:title>Configure·SELinux·Policy</ocil:title>
54 ······<ocil:actions>42 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-kernel_config_kexec_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-selinux_policytype_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>44 ······</ocil:actions>
57 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-sudoers_explicit_command_args_ocil:questionnaire:1"> 
59 ······<ocil:title>Explicit·arguments·in·sudo·specifications</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-chronyd_or_ntpd_specify_remote_server_ocil:questionnaire:1">
 47 ······<ocil:title>Specify·a·Remote·NTP·Server</ocil:title>
60 ······<ocil:actions>48 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-sudoers_explicit_command_args_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-chronyd_or_ntpd_specify_remote_server_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>50 ······</ocil:actions>
63 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_login_events_tallylog_ocil:questionnaire:1"> 
65 ······<ocil:title>Record·Attempts·to·Alter·Logon·and·Logout·Events·-·tallylog</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_groupownership_ocil:questionnaire:1">
 53 ······<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·Group</ocil:title>
66 ······<ocil:actions>54 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_login_events_tallylog_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_groupownership_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>56 ······</ocil:actions>
69 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lchown_ocil:questionnaire:1"> 
71 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lchown</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
 59 ······<ocil:title>Enable·systemd-journald·Service</ocil:title>
72 ······<ocil:actions>60 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lchown_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>62 ······</ocil:actions>
75 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_writable_hooks_ocil:questionnaire:1">
77 ······<ocil:title>Configure·System·to·Forward·All·Mail·For·The·Root·Account</ocil:title>65 ······<ocil:title>Disable·mutable·hooks</ocil:title>
78 ······<ocil:actions>66 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_writable_hooks_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>68 ······</ocil:actions>
81 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_panic_on_oops_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_umount_ocil:questionnaire:1">
83 ······<ocil:title>Kernel·panic·on·oops</ocil:title>71 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·umount</ocil:title>
84 ······<ocil:actions>72 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_panic_on_oops_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_umount_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>74 ······</ocil:actions>
87 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_ocil:questionnaire:1">
89 ······<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>77 ······<ocil:title>Enable·different·security·models</ocil:title>
90 ······<ocil:actions>78 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>80 ······</ocil:actions>
93 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_seccomp_filter_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_bug_ocil:questionnaire:1">
95 ······<ocil:title>Enable·use·of·Berkeley·Packet·Filter·with·seccomp</ocil:title>83 ······<ocil:title>Enable·support·for·BUG()</ocil:title>
96 ······<ocil:actions>84 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_filter_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_bug_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>86 ······</ocil:actions>
99 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_admin_space_left_action_ocil:questionnaire:1"> 
101 ······<ocil:title>Configure·auditd·admin_space_left·Action·on·Low·Disk·Space</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-grub2_disable_recovery_ocil:questionnaire:1">
 89 ······<ocil:title>Disable·Recovery·Booting</ocil:title>
102 ······<ocil:actions>90 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_admin_space_left_action_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-grub2_disable_recovery_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>92 ······</ocil:actions>
105 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-dir_perms_world_writable_sticky_bits_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-restrict_serial_port_logins_ocil:questionnaire:1">
107 ······<ocil:title>Verify·that·All·World-Writable·Directories·Have·Sticky·Bits·Set</ocil:title>95 ······<ocil:title>Restrict·Serial·Port·Root·Logins</ocil:title>
108 ······<ocil:actions>96 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-dir_perms_world_writable_sticky_bits_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-restrict_serial_port_logins_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>98 ······</ocil:actions>
111 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_at_allow_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-service_autofs_disabled_ocil:questionnaire:1">
113 ······<ocil:title>Verify·Group·Who·Owns·/etc/at.allow·file</ocil:title>101 ······<ocil:title>Disable·the·Automounter</ocil:title>
114 ······<ocil:actions>102 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_at_allow_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-service_autofs_disabled_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>104 ······</ocil:actions>
117 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_poweroff_ocil:questionnaire:1"> 
119 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·poweroff</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-grub2_l1tf_argument_ocil:questionnaire:1">
 107 ······<ocil:title>Configure·L1·Terminal·Fault·mitigations</ocil:title>
120 ······<ocil:actions>108 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_poweroff_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-grub2_l1tf_argument_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>110 ······</ocil:actions>
123 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
Max diff block lines reached; 868829/880800 bytes (98.64%) of diff not shown.
606 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-xccdf.xml
606 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_ALINUX-2"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_ALINUX-2"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·2</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·2</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·Alibaba·Cloud·Linux·2.·It·is·a·rendering·of7 configuration·settings·for·Alibaba·Cloud·Linux·2.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
Offset 71, 198 lines modifiedOffset 71, 198 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="package_shadow-utils">78 ····<cpe-lang:platform·id="ipv6_enabled">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
81 ······</cpe-lang:logical-test>81 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>82 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="package_ntp">83 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
84 ······<cpe-lang:logical-test·operator="AND"·negate="false">84 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
86 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
87 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
88 ····<cpe-lang:platform·id="aarch64_arch">89 ····<cpe-lang:platform·id="grub2">
89 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
91 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
92 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
93 ····<cpe-lang:platform·id="machine">94 ····<cpe-lang:platform·id="machine">
94 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
96 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
97 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
98 ····<cpe-lang:platform·id="x86_64_arch"> 
99 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/> 
101 ······</cpe-lang:logical-test> 
102 ····</cpe-lang:platform> 
103 ····<cpe-lang:platform·id="package_logrotate"> 
104 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/> 
106 ······</cpe-lang:logical-test> 
107 ····</cpe-lang:platform> 
108 ····<cpe-lang:platform·id="package_sudo">99 ····<cpe-lang:platform·id="package_iptables">
109 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
111 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
112 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
113 ····<cpe-lang:platform·id="machine_and_package_ufw">104 ····<cpe-lang:platform·id="machine_and_package_ufw">
114 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
115 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
117 ······</cpe-lang:logical-test>108 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>109 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="not_aarch64_arch">110 ····<cpe-lang:platform·id="not_aarch64_arch">
120 ······<cpe-lang:logical-test·operator="AND"·negate="true">111 ······<cpe-lang:logical-test·operator="AND"·negate="true">
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
122 ······</cpe-lang:logical-test>113 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>114 ····</cpe-lang:platform>
 115 ····<cpe-lang:platform·id="machine_and_not_rhcos4-rhel9_and_service_disabled_nftables_and_service_disabled_ufw">
 116 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 117 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 118 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_OS_is_rhcos4_rhel9:def:1"/>
 119 ········</cpe-lang:logical-test>
 120 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
 121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_nftables:def:1"/>
 122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>
 123 ······</cpe-lang:logical-test>
 124 ····</cpe-lang:platform>
 125 ····<cpe-lang:platform·id="package_ntp">
 126 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
 128 ······</cpe-lang:logical-test>
 129 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">130 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">131 ······<cpe-lang:logical-test·operator="AND"·negate="false">
126 ········<cpe-lang:logical-test·operator="AND"·negate="true">132 ········<cpe-lang:logical-test·operator="AND"·negate="true">
127 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>133 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
128 ········</cpe-lang:logical-test>134 ········</cpe-lang:logical-test>
129 ········<cpe-lang:logical-test·operator="AND"·negate="true">135 ········<cpe-lang:logical-test·operator="AND"·negate="true">
130 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>136 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
131 ········</cpe-lang:logical-test>137 ········</cpe-lang:logical-test>
132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
133 ······</cpe-lang:logical-test>139 ······</cpe-lang:logical-test>
134 ····</cpe-lang:platform>140 ····</cpe-lang:platform>
135 ····<cpe-lang:platform·id="package_yum">141 ····<cpe-lang:platform·id="package_pam">
136 ······<cpe-lang:logical-test·operator="AND"·negate="false">142 ······<cpe-lang:logical-test·operator="AND"·negate="false">
137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/>143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
138 ······</cpe-lang:logical-test>144 ······</cpe-lang:logical-test>
139 ····</cpe-lang:platform>145 ····</cpe-lang:platform>
140 ····<cpe-lang:platform·id="package_firewalld">146 ····<cpe-lang:platform·id="package_firewalld">
141 ······<cpe-lang:logical-test·operator="AND"·negate="false">147 ······<cpe-lang:logical-test·operator="AND"·negate="false">
142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
143 ······</cpe-lang:logical-test>149 ······</cpe-lang:logical-test>
144 ····</cpe-lang:platform>150 ····</cpe-lang:platform>
145 ····<cpe-lang:platform·id="package_systemd">151 ····<cpe-lang:platform·id="package_logrotate">
146 ······<cpe-lang:logical-test·operator="AND"·negate="false">152 ······<cpe-lang:logical-test·operator="AND"·negate="false">
147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
148 ······</cpe-lang:logical-test> 
149 ····</cpe-lang:platform> 
150 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch"> 
151 ······<cpe-lang:logical-test·operator="OR"·negate="false"> 
152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/> 
154 ······</cpe-lang:logical-test>154 ······</cpe-lang:logical-test>
155 ····</cpe-lang:platform>155 ····</cpe-lang:platform>
156 ····<cpe-lang:platform·id="package_gdm">156 ····<cpe-lang:platform·id="package_audit">
157 ······<cpe-lang:logical-test·operator="AND"·negate="false">157 ······<cpe-lang:logical-test·operator="AND"·negate="false">
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>
159 ······</cpe-lang:logical-test>159 ······</cpe-lang:logical-test>
160 ····</cpe-lang:platform>160 ····</cpe-lang:platform>
161 ····<cpe-lang:platform·id="package_postfix">161 ····<cpe-lang:platform·id="package_yum">
162 ······<cpe-lang:logical-test·operator="AND"·negate="false">162 ······<cpe-lang:logical-test·operator="AND"·negate="false">
163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/>
164 ······</cpe-lang:logical-test>164 ······</cpe-lang:logical-test>
165 ····</cpe-lang:platform>165 ····</cpe-lang:platform>
166 ····<cpe-lang:platform·id="machine_and_not_rhcos4-rhel9_and_service_disabled_nftables_and_service_disabled_ufw">166 ····<cpe-lang:platform·id="machine_and_package_chrony_or_package_ntp">
167 ······<cpe-lang:logical-test·operator="AND"·negate="false">167 ······<cpe-lang:logical-test·operator="AND"·negate="false">
168 ········<cpe-lang:logical-test·operator="AND"·negate="true">168 ········<cpe-lang:logical-test·operator="OR"·negate="false">
 169 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
169 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_OS_is_rhcos4_rhel9:def:1"/>170 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
Max diff block lines reached; 608110/620639 bytes (97.98%) of diff not shown.
1.45 MB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ds.xml
1.45 MB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ds.xml
    
Offset 19, 25 lines modifiedOffset 19, 25 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-alinux3-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-alinux3-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-cpe-dictionary.xml"·timestamp="2024-11-02T06:39:34">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-cpe-dictionary.xml"·timestamp="2024-11-03T08:39:34">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:3">28 ······<cpe-dict:cpe-item·name="cpe:/o:alinux:alibaba_cloud_linux:3">
29 ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·3</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Alibaba·Cloud·Linux·3</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml">oval:ssg-installed_OS_is_alinux3:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml">oval:ssg-installed_OS_is_alinux3:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-xccdf.xml"·timestamp="2024-11-02T06:39:34">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-alinux3-xccdf.xml"·timestamp="2024-11-03T08:39:34">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-3"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ALINUX-3"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·3</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·3</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Alibaba·Cloud·Linux·3.·It·is·a·rendering·of40 configuration·settings·for·Alibaba·Cloud·Linux·3.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
42 in·order·to·support·security·automation.··The·SCAP·content·is42 in·order·to·support·security·automation.··The·SCAP·content·is
43 is·available·in·the43 is·available·in·the
Offset 104, 42 lines modifiedOffset 104, 38 lines modified
104 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>104 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
105 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>105 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
106 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>106 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
107 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
110 ······<cpe-lang:platform-specification>110 ······<cpe-lang:platform-specification>
111 ········<cpe-lang:platform·id="package_shadow-utils">111 ········<cpe-lang:platform·id="ipv6_enabled">
112 ··········<cpe-lang:logical-test·operator="AND"·negate="false">112 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
113 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>113 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
114 ··········</cpe-lang:logical-test>114 ··········</cpe-lang:logical-test>
115 ········</cpe-lang:platform>115 ········</cpe-lang:platform>
116 ········<cpe-lang:platform·id="aarch64_arch">116 ········<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
117 ··········<cpe-lang:logical-test·operator="AND"·negate="false">117 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
118 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>118 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 119 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
119 ··········</cpe-lang:logical-test>120 ··········</cpe-lang:logical-test>
120 ········</cpe-lang:platform>121 ········</cpe-lang:platform>
121 ········<cpe-lang:platform·id="machine">122 ········<cpe-lang:platform·id="grub2">
122 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
123 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
124 ··········</cpe-lang:logical-test> 
125 ········</cpe-lang:platform> 
126 ········<cpe-lang:platform·id="x86_64_arch"> 
127 ··········<cpe-lang:logical-test·operator="AND"·negate="false">123 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
128 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>124 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
129 ··········</cpe-lang:logical-test>125 ··········</cpe-lang:logical-test>
130 ········</cpe-lang:platform>126 ········</cpe-lang:platform>
131 ········<cpe-lang:platform·id="package_logrotate">127 ········<cpe-lang:platform·id="machine">
132 ··········<cpe-lang:logical-test·operator="AND"·negate="false">128 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
133 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>129 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
134 ··········</cpe-lang:logical-test>130 ··········</cpe-lang:logical-test>
135 ········</cpe-lang:platform>131 ········</cpe-lang:platform>
136 ········<cpe-lang:platform·id="package_sudo">132 ········<cpe-lang:platform·id="package_iptables">
137 ··········<cpe-lang:logical-test·operator="AND"·negate="false">133 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
138 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>134 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
139 ··········</cpe-lang:logical-test>135 ··········</cpe-lang:logical-test>
140 ········</cpe-lang:platform>136 ········</cpe-lang:platform>
141 ········<cpe-lang:platform·id="machine_and_package_ufw">137 ········<cpe-lang:platform·id="machine_and_package_ufw">
142 ··········<cpe-lang:logical-test·operator="AND"·negate="false">138 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
143 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>139 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
144 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
145 ··········</cpe-lang:logical-test>141 ··········</cpe-lang:logical-test>
Offset 156, 134 lines modifiedOffset 152, 138 lines modified
156 ············</cpe-lang:logical-test>152 ············</cpe-lang:logical-test>
157 ············<cpe-lang:logical-test·operator="AND"·negate="true">153 ············<cpe-lang:logical-test·operator="AND"·negate="true">
158 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>154 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
159 ············</cpe-lang:logical-test>155 ············</cpe-lang:logical-test>
160 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
161 ··········</cpe-lang:logical-test>157 ··········</cpe-lang:logical-test>
162 ········</cpe-lang:platform>158 ········</cpe-lang:platform>
163 ········<cpe-lang:platform·id="package_yum">159 ········<cpe-lang:platform·id="package_pam">
164 ··········<cpe-lang:logical-test·operator="AND"·negate="false">160 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
165 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/>161 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
166 ··········</cpe-lang:logical-test>162 ··········</cpe-lang:logical-test>
167 ········</cpe-lang:platform>163 ········</cpe-lang:platform>
168 ········<cpe-lang:platform·id="package_firewalld">164 ········<cpe-lang:platform·id="package_firewalld">
169 ··········<cpe-lang:logical-test·operator="AND"·negate="false">165 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
170 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>166 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
171 ··········</cpe-lang:logical-test>167 ··········</cpe-lang:logical-test>
172 ········</cpe-lang:platform>168 ········</cpe-lang:platform>
173 ········<cpe-lang:platform·id="package_systemd">169 ········<cpe-lang:platform·id="machine_and_package_firewalld_and_package_nftables">
174 ··········<cpe-lang:logical-test·operator="AND"·negate="false">170 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
175 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>172 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
 173 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
176 ··········</cpe-lang:logical-test>174 ··········</cpe-lang:logical-test>
177 ········</cpe-lang:platform>175 ········</cpe-lang:platform>
178 ········<cpe-lang:platform·id="wifi-iface">176 ········<cpe-lang:platform·id="package_logrotate">
179 ··········<cpe-lang:logical-test·operator="AND"·negate="false">177 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
180 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>178 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
181 ··········</cpe-lang:logical-test> 
182 ········</cpe-lang:platform> 
183 ········<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch"> 
184 ··········<cpe-lang:logical-test·operator="OR"·negate="false"> 
185 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
186 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/> 
187 ··········</cpe-lang:logical-test>179 ··········</cpe-lang:logical-test>
188 ········</cpe-lang:platform>180 ········</cpe-lang:platform>
189 ········<cpe-lang:platform·id="package_gdm">181 ········<cpe-lang:platform·id="package_audit">
190 ··········<cpe-lang:logical-test·operator="AND"·negate="false">182 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
191 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>183 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>
192 ··········</cpe-lang:logical-test>184 ··········</cpe-lang:logical-test>
193 ········</cpe-lang:platform>185 ········</cpe-lang:platform>
194 ········<cpe-lang:platform·id="package_postfix">186 ········<cpe-lang:platform·id="package_yum">
195 ··········<cpe-lang:logical-test·operator="AND"·negate="false">187 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
196 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>188 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/>
197 ··········</cpe-lang:logical-test>189 ··········</cpe-lang:logical-test>
198 ········</cpe-lang:platform>190 ········</cpe-lang:platform>
199 ········<cpe-lang:platform·id="non-uefi">191 ········<cpe-lang:platform·id="non-uefi">
200 ··········<cpe-lang:logical-test·operator="AND"·negate="false">192 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
201 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>193 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>
202 ··········</cpe-lang:logical-test>194 ··········</cpe-lang:logical-test>
203 ········</cpe-lang:platform>195 ········</cpe-lang:platform>
204 ········<cpe-lang:platform·id="grub2">196 ········<cpe-lang:platform·id="package_sudo">
205 ··········<cpe-lang:logical-test·operator="AND"·negate="false">197 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
206 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>198 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
207 ··········</cpe-lang:logical-test>199 ··········</cpe-lang:logical-test>
208 ········</cpe-lang:platform>200 ········</cpe-lang:platform>
209 ········<cpe-lang:platform·id="package_chrony">201 ········<cpe-lang:platform·id="machine_and_package_autofs">
210 ··········<cpe-lang:logical-test·operator="AND"·negate="false">202 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
Max diff block lines reached; 1507813/1521593 bytes (99.09%) of diff not shown.
857 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ocil.xml
857 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ocil.xml
Ordering differences only
    
Offset 3, 3659 lines modifiedOffset 3, 3659 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-package_ntp_installed_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-grub2_nosmap_argument_absent_ocil:questionnaire:1">
11 ······<ocil:title>Install·the·ntp·service</ocil:title>11 ······<ocil:title>Ensure·SMAP·is·not·disabled·during·boot</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-package_ntp_installed_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-grub2_nosmap_argument_absent_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-configure_ssh_crypto_policy_ocil:questionnaire:1"> 
17 ······<ocil:title>Configure·SSH·to·use·System·Crypto·Policy</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmodat_ocil:questionnaire:1">
 17 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmodat</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-configure_ssh_crypto_policy_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmodat_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_group_ocil:questionnaire:1"> 
23 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/group</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_suid_dumpable_ocil:questionnaire:1">
 23 ······<ocil:title>Disable·Core·Dumps·for·SUID·programs</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_group_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_suid_dumpable_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_symlinks_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_hourly_ocil:questionnaire:1">
29 ······<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Symlinks</ocil:title>29 ······<ocil:title>Verify·Group·Who·Owns·cron.hourly</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_symlinks_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_hourly_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-auditd_overflow_action_ocil:questionnaire:1"> 
35 ······<ocil:title>Appropriate·Action·Must·be·Setup·When·the·Internal·Audit·Event·Queue·is·Full</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_ocil:questionnaire:1">
 35 ······<ocil:title>Configure·ARP·filtering·for·All·IPv4·Interfaces</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-auditd_overflow_action_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-service_cron_enabled_ocil:questionnaire:1"> 
41 ······<ocil:title>Enable·cron·Service</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_ocil:questionnaire:1">
 41 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·openat</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-service_cron_enabled_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_settimeofday_ocil:questionnaire:1"> 
47 ······<ocil:title>Record·attempts·to·alter·time·through·settimeofday</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_at_allow_ocil:questionnaire:1">
 47 ······<ocil:title>Verify·Permissions·on·/etc/at.allow·file</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_settimeofday_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-file_permissions_at_allow_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-enable_dconf_user_profile_ocil:questionnaire:1">
53 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lremovexattr</ocil:title>53 ······<ocil:title>Configure·GNOME3·DConf·User·Profile</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lremovexattr_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-enable_dconf_user_profile_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-service_nftables_disabled_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">
59 ······<ocil:title>Verify·nftables·Service·is·Disabled</ocil:title>59 ······<ocil:title>Enable·module·signature·verification</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-service_nftables_disabled_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_binary_dirs_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_strictmodes_ocil:questionnaire:1">
65 ······<ocil:title>Verify·that·System·Executables·Have·Restrictive·Permissions</ocil:title>65 ······<ocil:title>Enable·Use·of·Strict·Mode·Checking</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_permissions_binary_dirs_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_strictmodes_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_ocil:questionnaire:1"> 
71 ······<ocil:title>Disable·Accepting·Packets·Routed·Between·Local·Interfaces</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_sshd_pub_key_ocil:questionnaire:1">
 71 ······<ocil:title>Verify·Group·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_group_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_d_ocil:questionnaire:1">
77 ······<ocil:title>Verify·User·Who·Owns·Backup·group·File</ocil:title>77 ······<ocil:title>Verify·Group·Who·Owns·cron.d</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_group_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_d_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_gssapi_auth_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-rpm_verify_ownership_ocil:questionnaire:1">
83 ······<ocil:title>Enable·GSSAPI·Authentication</ocil:title>83 ······<ocil:title>Verify·and·Correct·Ownership·with·RPM</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_gssapi_auth_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-rpm_verify_ownership_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_mac_modification_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-grub2_enable_selinux_ocil:questionnaire:1">
89 ······<ocil:title>Record·Events·that·Modify·the·System's·Mandatory·Access·Controls</ocil:title>89 ······<ocil:title>Ensure·SELinux·Not·Disabled·in·/etc/default/grub</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_mac_modification_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-grub2_enable_selinux_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_shadow_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-selinux_confinement_of_daemons_ocil:questionnaire:1">
95 ······<ocil:title>Verify·Permissions·on·Backup·shadow·File</ocil:title>95 ······<ocil:title>Ensure·No·Daemons·are·Unconfined·by·SELinux</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-selinux_confinement_of_daemons_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_x11_forwarding_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_tipc_disabled_ocil:questionnaire:1">
101 ······<ocil:title>Enable·Encrypted·X11·Forwarding</ocil:title>101 ······<ocil:title>Disable·TIPC·Support</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_x11_forwarding_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-kernel_module_tipc_disabled_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_passwd_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_allow_ocil:questionnaire:1">
107 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/passwd</ocil:title>107 ······<ocil:title>Verify·Permissions·on·/etc/cron.allow·file</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_passwd_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_allow_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_login_events_lastlog_ocil:questionnaire:1"> 
113 ······<ocil:title>Record·Attempts·to·Alter·Logon·and·Logout·Events·-·lastlog</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-configure_user_data_backups_ocil:questionnaire:1">
 113 ······<ocil:title>Configure·Backups·of·User·Data</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_login_events_lastlog_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-configure_user_data_backups_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_shadow_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_pam_ocil:questionnaire:1">
119 ······<ocil:title>Verify·Group·Who·Owns·Backup·shadow·File</ocil:title>119 ······<ocil:title>Enable·PAM</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_pam_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
Max diff block lines reached; 865403/877731 bytes (98.60%) of diff not shown.
575 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-xccdf.xml
575 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_ALINUX-3"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_ALINUX-3"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·3</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Alibaba·Cloud·Linux·3</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·Alibaba·Cloud·Linux·3.·It·is·a·rendering·of7 configuration·settings·for·Alibaba·Cloud·Linux·3.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
Offset 71, 42 lines modifiedOffset 71, 38 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="package_shadow-utils">78 ····<cpe-lang:platform·id="ipv6_enabled">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
81 ······</cpe-lang:logical-test>81 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>82 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="aarch64_arch">83 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
84 ······<cpe-lang:logical-test·operator="AND"·negate="false">84 ······<cpe-lang:logical-test·operator="OR"·negate="false">
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
86 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
87 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
88 ····<cpe-lang:platform·id="machine">89 ····<cpe-lang:platform·id="grub2">
89 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
91 ······</cpe-lang:logical-test> 
92 ····</cpe-lang:platform> 
93 ····<cpe-lang:platform·id="x86_64_arch"> 
94 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
96 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
97 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
98 ····<cpe-lang:platform·id="package_logrotate">94 ····<cpe-lang:platform·id="machine">
99 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
101 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
102 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
103 ····<cpe-lang:platform·id="package_sudo">99 ····<cpe-lang:platform·id="package_iptables">
104 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
106 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
107 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
108 ····<cpe-lang:platform·id="machine_and_package_ufw">104 ····<cpe-lang:platform·id="machine_and_package_ufw">
109 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
112 ······</cpe-lang:logical-test>108 ······</cpe-lang:logical-test>
Offset 123, 134 lines modifiedOffset 119, 138 lines modified
123 ········</cpe-lang:logical-test>119 ········</cpe-lang:logical-test>
124 ········<cpe-lang:logical-test·operator="AND"·negate="true">120 ········<cpe-lang:logical-test·operator="AND"·negate="true">
125 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>121 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
126 ········</cpe-lang:logical-test>122 ········</cpe-lang:logical-test>
127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
128 ······</cpe-lang:logical-test>124 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>125 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="package_yum">126 ····<cpe-lang:platform·id="package_pam">
131 ······<cpe-lang:logical-test·operator="AND"·negate="false">127 ······<cpe-lang:logical-test·operator="AND"·negate="false">
132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/>128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
133 ······</cpe-lang:logical-test>129 ······</cpe-lang:logical-test>
134 ····</cpe-lang:platform>130 ····</cpe-lang:platform>
135 ····<cpe-lang:platform·id="package_firewalld">131 ····<cpe-lang:platform·id="package_firewalld">
136 ······<cpe-lang:logical-test·operator="AND"·negate="false">132 ······<cpe-lang:logical-test·operator="AND"·negate="false">
137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
138 ······</cpe-lang:logical-test>134 ······</cpe-lang:logical-test>
139 ····</cpe-lang:platform>135 ····</cpe-lang:platform>
140 ····<cpe-lang:platform·id="package_systemd">136 ····<cpe-lang:platform·id="machine_and_package_firewalld_and_package_nftables">
141 ······<cpe-lang:logical-test·operator="AND"·negate="false">137 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>139 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
 140 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
143 ······</cpe-lang:logical-test>141 ······</cpe-lang:logical-test>
144 ····</cpe-lang:platform>142 ····</cpe-lang:platform>
145 ····<cpe-lang:platform·id="wifi-iface">143 ····<cpe-lang:platform·id="package_logrotate">
146 ······<cpe-lang:logical-test·operator="AND"·negate="false">144 ······<cpe-lang:logical-test·operator="AND"·negate="false">
147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
148 ······</cpe-lang:logical-test> 
149 ····</cpe-lang:platform> 
150 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch"> 
151 ······<cpe-lang:logical-test·operator="OR"·negate="false"> 
152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/> 
154 ······</cpe-lang:logical-test>146 ······</cpe-lang:logical-test>
155 ····</cpe-lang:platform>147 ····</cpe-lang:platform>
156 ····<cpe-lang:platform·id="package_gdm">148 ····<cpe-lang:platform·id="package_audit">
157 ······<cpe-lang:logical-test·operator="AND"·negate="false">149 ······<cpe-lang:logical-test·operator="AND"·negate="false">
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>
159 ······</cpe-lang:logical-test>151 ······</cpe-lang:logical-test>
160 ····</cpe-lang:platform>152 ····</cpe-lang:platform>
161 ····<cpe-lang:platform·id="package_postfix">153 ····<cpe-lang:platform·id="package_yum">
162 ······<cpe-lang:logical-test·operator="AND"·negate="false">154 ······<cpe-lang:logical-test·operator="AND"·negate="false">
163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/>
164 ······</cpe-lang:logical-test>156 ······</cpe-lang:logical-test>
165 ····</cpe-lang:platform>157 ····</cpe-lang:platform>
166 ····<cpe-lang:platform·id="non-uefi">158 ····<cpe-lang:platform·id="non-uefi">
167 ······<cpe-lang:logical-test·operator="AND"·negate="false">159 ······<cpe-lang:logical-test·operator="AND"·negate="false">
168 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>
169 ······</cpe-lang:logical-test>161 ······</cpe-lang:logical-test>
170 ····</cpe-lang:platform>162 ····</cpe-lang:platform>
171 ····<cpe-lang:platform·id="grub2">163 ····<cpe-lang:platform·id="package_sudo">
172 ······<cpe-lang:logical-test·operator="AND"·negate="false">164 ······<cpe-lang:logical-test·operator="AND"·negate="false">
173 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
174 ······</cpe-lang:logical-test>166 ······</cpe-lang:logical-test>
175 ····</cpe-lang:platform>167 ····</cpe-lang:platform>
176 ····<cpe-lang:platform·id="package_chrony">168 ····<cpe-lang:platform·id="machine_and_package_autofs">
177 ······<cpe-lang:logical-test·operator="AND"·negate="false">169 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
178 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>171 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
 172 ······</cpe-lang:logical-test>
 173 ····</cpe-lang:platform>
 174 ····<cpe-lang:platform·id="package_postfix">
 175 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 176 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
179 ······</cpe-lang:logical-test>177 ······</cpe-lang:logical-test>
180 ····</cpe-lang:platform>178 ····</cpe-lang:platform>
181 ····<cpe-lang:platform·id="package_bind">179 ····<cpe-lang:platform·id="package_bind">
182 ······<cpe-lang:logical-test·operator="AND"·negate="false">180 ······<cpe-lang:logical-test·operator="AND"·negate="false">
183 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_bind:def:1"/>181 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_bind:def:1"/>
184 ······</cpe-lang:logical-test>182 ······</cpe-lang:logical-test>
185 ····</cpe-lang:platform>183 ····</cpe-lang:platform>
186 ····<cpe-lang:platform·id="machine_and_package_iptables_and_service_disabled_firewalld">184 ····<cpe-lang:platform·id="machine_and_package_iptables_and_service_disabled_firewalld">
Max diff block lines reached; 576230/588799 bytes (97.87%) of diff not shown.
1.71 MB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ds.xml
1.71 MB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ds.xml
    
Offset 19, 25 lines modifiedOffset 19, 25 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis23-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis23-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-cpe-dictionary.xml"·timestamp="2024-11-02T06:39:34">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-cpe-dictionary.xml"·timestamp="2024-11-03T08:39:34">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:23">28 ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:23">
29 ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·23</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·23</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml">oval:ssg-installed_OS_is_anolis23:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml">oval:ssg-installed_OS_is_anolis23:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-xccdf.xml"·timestamp="2024-11-02T06:39:34">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis23-xccdf.xml"·timestamp="2024-11-03T08:39:34">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-23"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-23"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·23</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·23</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Anolis·OS·23.·It·is·a·rendering·of40 configuration·settings·for·Anolis·OS·23.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
42 in·order·to·support·security·automation.··The·SCAP·content·is42 in·order·to·support·security·automation.··The·SCAP·content·is
43 is·available·in·the43 is·available·in·the
Offset 104, 218 lines modifiedOffset 104, 218 lines modified
104 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>104 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
105 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>105 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
106 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>106 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
107 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
110 ······<cpe-lang:platform-specification>110 ······<cpe-lang:platform-specification>
111 ········<cpe-lang:platform·id="package_shadow-utils">111 ········<cpe-lang:platform·id="ipv6_enabled">
112 ··········<cpe-lang:logical-test·operator="AND"·negate="false">112 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
113 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>113 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
114 ··········</cpe-lang:logical-test>114 ··········</cpe-lang:logical-test>
115 ········</cpe-lang:platform>115 ········</cpe-lang:platform>
116 ········<cpe-lang:platform·id="aarch64_arch">116 ········<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
117 ··········<cpe-lang:logical-test·operator="AND"·negate="false">117 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
118 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>118 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 119 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
119 ··········</cpe-lang:logical-test>120 ··········</cpe-lang:logical-test>
120 ········</cpe-lang:platform>121 ········</cpe-lang:platform>
121 ········<cpe-lang:platform·id="machine">122 ········<cpe-lang:platform·id="grub2">
122 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
123 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
124 ··········</cpe-lang:logical-test> 
125 ········</cpe-lang:platform> 
126 ········<cpe-lang:platform·id="x86_64_arch"> 
127 ··········<cpe-lang:logical-test·operator="AND"·negate="false">123 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
128 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>124 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
129 ··········</cpe-lang:logical-test>125 ··········</cpe-lang:logical-test>
130 ········</cpe-lang:platform>126 ········</cpe-lang:platform>
131 ········<cpe-lang:platform·id="package_logrotate">127 ········<cpe-lang:platform·id="machine">
132 ··········<cpe-lang:logical-test·operator="AND"·negate="false">128 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
133 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>129 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
134 ··········</cpe-lang:logical-test>130 ··········</cpe-lang:logical-test>
135 ········</cpe-lang:platform>131 ········</cpe-lang:platform>
136 ········<cpe-lang:platform·id="package_sudo">132 ········<cpe-lang:platform·id="package_iptables">
137 ··········<cpe-lang:logical-test·operator="AND"·negate="false">133 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
138 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>134 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
139 ··········</cpe-lang:logical-test>135 ··········</cpe-lang:logical-test>
140 ········</cpe-lang:platform>136 ········</cpe-lang:platform>
141 ········<cpe-lang:platform·id="machine_and_package_ufw">137 ········<cpe-lang:platform·id="machine_and_package_ufw">
142 ··········<cpe-lang:logical-test·operator="AND"·negate="false">138 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
143 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>139 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
144 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
145 ··········</cpe-lang:logical-test>141 ··········</cpe-lang:logical-test>
146 ········</cpe-lang:platform>142 ········</cpe-lang:platform>
147 ········<cpe-lang:platform·id="not_aarch64_arch">143 ········<cpe-lang:platform·id="not_aarch64_arch">
148 ··········<cpe-lang:logical-test·operator="AND"·negate="true">144 ··········<cpe-lang:logical-test·operator="AND"·negate="true">
149 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>145 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
150 ··········</cpe-lang:logical-test>146 ··········</cpe-lang:logical-test>
151 ········</cpe-lang:platform>147 ········</cpe-lang:platform>
 148 ········<cpe-lang:platform·id="machine_and_not_rhcos4-rhel9_and_service_disabled_nftables_and_service_disabled_ufw">
 149 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 150 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 151 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_OS_is_rhcos4_rhel9:def:1"/>
 152 ············</cpe-lang:logical-test>
 153 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
 154 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_nftables:def:1"/>
 155 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>
 156 ··········</cpe-lang:logical-test>
 157 ········</cpe-lang:platform>
152 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">158 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
153 ··········<cpe-lang:logical-test·operator="AND"·negate="false">159 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
154 ············<cpe-lang:logical-test·operator="AND"·negate="true">160 ············<cpe-lang:logical-test·operator="AND"·negate="true">
155 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>161 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
156 ············</cpe-lang:logical-test>162 ············</cpe-lang:logical-test>
157 ············<cpe-lang:logical-test·operator="AND"·negate="true">163 ············<cpe-lang:logical-test·operator="AND"·negate="true">
158 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>164 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
159 ············</cpe-lang:logical-test>165 ············</cpe-lang:logical-test>
160 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>166 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
161 ··········</cpe-lang:logical-test>167 ··········</cpe-lang:logical-test>
162 ········</cpe-lang:platform>168 ········</cpe-lang:platform>
163 ········<cpe-lang:platform·id="package_yum">169 ········<cpe-lang:platform·id="machine_and_package_snmpd">
164 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
165 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/> 
166 ··········</cpe-lang:logical-test> 
167 ········</cpe-lang:platform> 
168 ········<cpe-lang:platform·id="package_firewalld"> 
169 ··········<cpe-lang:logical-test·operator="AND"·negate="false">170 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
170 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>172 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>
171 ··········</cpe-lang:logical-test>173 ··········</cpe-lang:logical-test>
172 ········</cpe-lang:platform>174 ········</cpe-lang:platform>
173 ········<cpe-lang:platform·id="package_systemd">175 ········<cpe-lang:platform·id="package_pam">
174 ··········<cpe-lang:logical-test·operator="AND"·negate="false">176 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
175 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>177 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
176 ··········</cpe-lang:logical-test>178 ··········</cpe-lang:logical-test>
177 ········</cpe-lang:platform>179 ········</cpe-lang:platform>
178 ········<cpe-lang:platform·id="wifi-iface">180 ········<cpe-lang:platform·id="package_firewalld">
179 ··········<cpe-lang:logical-test·operator="AND"·negate="false">181 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
180 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>182 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
181 ··········</cpe-lang:logical-test>183 ··········</cpe-lang:logical-test>
182 ········</cpe-lang:platform>184 ········</cpe-lang:platform>
183 ········<cpe-lang:platform·id="machine_and_package_squid">185 ········<cpe-lang:platform·id="package_logrotate">
184 ··········<cpe-lang:logical-test·operator="AND"·negate="false">186 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
185 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
186 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>187 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
187 ··········</cpe-lang:logical-test> 
188 ········</cpe-lang:platform> 
189 ········<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch"> 
190 ··········<cpe-lang:logical-test·operator="OR"·negate="false"> 
191 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
192 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/> 
Max diff block lines reached; 1777094/1790138 bytes (99.27%) of diff not shown.
993 KB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ocil.xml
992 KB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ocil.xml
Ordering differences only
    
Offset 3, 8376 lines modifiedOffset 3, 7985 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_fs_ocil:questionnaire:1"> 
11 ······<ocil:title>Disable·kernel·debugfs</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_fs_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-auditd_local_events_ocil:questionnaire:1"> 
17 ······<ocil:title>Include·Local·Events·in·Audit·Logs</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-auditd_local_events_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_ocil:questionnaire:1"> 
23 ······<ocil:title>Configure·Sending·and·Accepting·Shared·Media·Redirects·by·Default</ocil:title> 
24 ······<ocil:actions> 
25 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_action:testaction:1</ocil:test_action_ref> 
26 ······</ocil:actions> 
27 ····</ocil:questionnaire> 
28 ····<ocil:questionnaire·id="ocil:ssg-sshd_do_not_permit_user_env_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_systemmap_ocil:questionnaire:1">
29 ······<ocil:title>Do·Not·Allow·SSH·Environment·Options</ocil:title>11 ······<ocil:title>Verify·Permissions·on·System.map·Files</ocil:title>
30 ······<ocil:actions>12 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sshd_do_not_permit_user_env_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_permissions_systemmap_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>14 ······</ocil:actions>
33 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-auditd_write_logs_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-audit_privileged_commands_poweroff_ocil:questionnaire:1">
35 ······<ocil:title>Write·Audit·Logs·to·the·Disk</ocil:title>17 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·poweroff</ocil:title>
36 ······<ocil:actions>18 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-auditd_write_logs_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_privileged_commands_poweroff_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>20 ······</ocil:actions>
39 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_gshadow_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-chronyd_specify_remote_server_ocil:questionnaire:1">
41 ······<ocil:title>Verify·Group·Who·Owns·gshadow·File</ocil:title>23 ······<ocil:title>A·remote·time·server·for·Chrony·is·configured</ocil:title>
42 ······<ocil:actions>24 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_gshadow_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-chronyd_specify_remote_server_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>26 ······</ocil:actions>
45 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_seccomp_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_binary_dirs_ocil:questionnaire:1">
47 ······<ocil:title>Enable·seccomp·to·safely·compute·untrusted·bytecode</ocil:title>29 ······<ocil:title>Verify·that·System·Executables·Have·Restrictive·Permissions</ocil:title>
48 ······<ocil:actions>30 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_permissions_binary_dirs_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>32 ······</ocil:actions>
51 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-service_chronyd_enabled_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_remote_loghost_ocil:questionnaire:1">
53 ······<ocil:title>The·Chronyd·service·is·enabled</ocil:title>35 ······<ocil:title>Ensure·Logs·Sent·To·Remote·Host</ocil:title>
54 ······<ocil:actions>36 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-service_chronyd_enabled_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-rsyslog_remote_loghost_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>38 ······</ocil:actions>
57 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-service_iptables_enabled_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_motd_ocil:questionnaire:1">
59 ······<ocil:title>Verify·iptables·Enabled</ocil:title>41 ······<ocil:title>Verify·permissions·on·Message·of·the·Day·Banner</ocil:title>
60 ······<ocil:actions>42 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-service_iptables_enabled_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_motd_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>44 ······</ocil:actions>
63 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_ocil:questionnaire:1"> 
65 ······<ocil:title>Enable·Kernel·Parameter·to·Ignore·ICMP·Broadcast·Echo·Requests·on·IPv4·Interfaces</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_rename_ocil:questionnaire:1">
 47 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·rename</ocil:title>
66 ······<ocil:actions>48 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rename_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>50 ······</ocil:actions>
69 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-securetty_root_login_console_only_ocil:questionnaire:1">
71 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User</ocil:title>53 ······<ocil:title>Restrict·Virtual·Console·Root·Logins</ocil:title>
72 ······<ocil:actions>54 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-securetty_root_login_console_only_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>56 ······</ocil:actions>
75 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_ocil:questionnaire:1"> 
77 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·ICMP·Redirects·by·Default·on·IPv6·Interfaces</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_groupownership_ocil:questionnaire:1">
 59 ······<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·Group</ocil:title>
78 ······<ocil:actions>60 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_groupownership_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>62 ······</ocil:actions>
81 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-grub2_uefi_password_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">
83 ······<ocil:title>Set·the·UEFI·Boot·Loader·Password</ocil:title>65 ······<ocil:title>Enable·module·signature·verification</ocil:title>
84 ······<ocil:actions>66 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-grub2_uefi_password_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>68 ······</ocil:actions>
87 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_sshd_config_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-service_firewalld_enabled_ocil:questionnaire:1">
89 ······<ocil:title>Verify·Group·Who·Owns·SSH·Server·config·file</ocil:title>71 ······<ocil:title>Verify·firewalld·Enabled</ocil:title>
90 ······<ocil:actions>72 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_sshd_config_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-service_firewalld_enabled_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>74 ······</ocil:actions>
93 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_ocil:questionnaire:1"> 
95 ······<ocil:title>Disable·Accepting·Router·Advertisements·on·all·IPv6·Interfaces·by·Default</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_ocil:questionnaire:1">
 77 ······<ocil:title>Verify·Permissions·on·/var/log·Directory</ocil:title>
96 ······<ocil:actions>78 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>80 ······</ocil:actions>
99 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sshd_rekey_limit_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1">
101 ······<ocil:title>Force·frequent·session·key·renegotiation</ocil:title>83 ······<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title>
102 ······<ocil:actions>84 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sshd_rekey_limit_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>86 ······</ocil:actions>
105 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_home_dirs_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_home_dirs_ocil:questionnaire:1">
107 ······<ocil:title>Ensure·that·User·Home·Directories·are·not·Group-Writable·or·World-Readable</ocil:title>89 ······<ocil:title>Ensure·that·User·Home·Directories·are·not·Group-Writable·or·World-Readable</ocil:title>
108 ······<ocil:actions>90 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_home_dirs_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_permissions_home_dirs_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>92 ······</ocil:actions>
111 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_all_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-dir_ownership_binary_dirs_ocil:questionnaire:1">
113 ······<ocil:title>Enable·automatic·signing·of·all·modules</ocil:title>95 ······<ocil:title>Verify·that·System·Executable·Have·Root·Ownership</ocil:title>
114 ······<ocil:actions>96 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_all_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-dir_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>98 ······</ocil:actions>
117 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-auditd_freq_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_sg_ocil:questionnaire:1">
119 ······<ocil:title>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</ocil:title>101 ······<ocil:title>Enable·checks·on·scatter-gather·(SG)·table·operations</ocil:title>
120 ······<ocil:actions>102 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-auditd_freq_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_sg_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>104 ······</ocil:actions>
123 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_passwd_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_panic_timeout_ocil:questionnaire:1">
125 ······<ocil:title>Verify·User·Who·Owns·passwd·File</ocil:title>107 ······<ocil:title>Kernel·panic·timeout</ocil:title>
126 ······<ocil:actions>108 ······<ocil:actions>
Max diff block lines reached; 1004376/1016150 bytes (98.84%) of diff not shown.
696 KB
./usr/share/xml/scap/ssg/content/ssg-anolis23-xccdf.xml
696 KB
./usr/share/xml/scap/ssg/content/ssg-anolis23-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-23"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-23"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·23</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·23</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·Anolis·OS·23.·It·is·a·rendering·of7 configuration·settings·for·Anolis·OS·23.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
Offset 71, 218 lines modifiedOffset 71, 218 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="package_shadow-utils">78 ····<cpe-lang:platform·id="ipv6_enabled">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
81 ······</cpe-lang:logical-test>81 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>82 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="aarch64_arch">83 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
84 ······<cpe-lang:logical-test·operator="AND"·negate="false">84 ······<cpe-lang:logical-test·operator="OR"·negate="false">
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
86 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
87 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
88 ····<cpe-lang:platform·id="machine">89 ····<cpe-lang:platform·id="grub2">
89 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
91 ······</cpe-lang:logical-test> 
92 ····</cpe-lang:platform> 
93 ····<cpe-lang:platform·id="x86_64_arch"> 
94 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
96 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
97 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
98 ····<cpe-lang:platform·id="package_logrotate">94 ····<cpe-lang:platform·id="machine">
99 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
101 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
102 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
103 ····<cpe-lang:platform·id="package_sudo">99 ····<cpe-lang:platform·id="package_iptables">
104 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
106 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
107 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
108 ····<cpe-lang:platform·id="machine_and_package_ufw">104 ····<cpe-lang:platform·id="machine_and_package_ufw">
109 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
112 ······</cpe-lang:logical-test>108 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>109 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="not_aarch64_arch">110 ····<cpe-lang:platform·id="not_aarch64_arch">
115 ······<cpe-lang:logical-test·operator="AND"·negate="true">111 ······<cpe-lang:logical-test·operator="AND"·negate="true">
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
117 ······</cpe-lang:logical-test>113 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>114 ····</cpe-lang:platform>
 115 ····<cpe-lang:platform·id="machine_and_not_rhcos4-rhel9_and_service_disabled_nftables_and_service_disabled_ufw">
 116 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 117 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 118 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_OS_is_rhcos4_rhel9:def:1"/>
 119 ········</cpe-lang:logical-test>
 120 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
 121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_nftables:def:1"/>
 122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>
 123 ······</cpe-lang:logical-test>
 124 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">125 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">126 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:logical-test·operator="AND"·negate="true">127 ········<cpe-lang:logical-test·operator="AND"·negate="true">
122 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>128 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
123 ········</cpe-lang:logical-test>129 ········</cpe-lang:logical-test>
124 ········<cpe-lang:logical-test·operator="AND"·negate="true">130 ········<cpe-lang:logical-test·operator="AND"·negate="true">
125 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>131 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
126 ········</cpe-lang:logical-test>132 ········</cpe-lang:logical-test>
127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
128 ······</cpe-lang:logical-test>134 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>135 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="package_yum">136 ····<cpe-lang:platform·id="machine_and_package_snmpd">
131 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/> 
133 ······</cpe-lang:logical-test> 
134 ····</cpe-lang:platform> 
135 ····<cpe-lang:platform·id="package_firewalld"> 
136 ······<cpe-lang:logical-test·operator="AND"·negate="false">137 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>139 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>
138 ······</cpe-lang:logical-test>140 ······</cpe-lang:logical-test>
139 ····</cpe-lang:platform>141 ····</cpe-lang:platform>
140 ····<cpe-lang:platform·id="package_systemd">142 ····<cpe-lang:platform·id="package_pam">
141 ······<cpe-lang:logical-test·operator="AND"·negate="false">143 ······<cpe-lang:logical-test·operator="AND"·negate="false">
142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>144 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
143 ······</cpe-lang:logical-test>145 ······</cpe-lang:logical-test>
144 ····</cpe-lang:platform>146 ····</cpe-lang:platform>
145 ····<cpe-lang:platform·id="wifi-iface">147 ····<cpe-lang:platform·id="package_firewalld">
146 ······<cpe-lang:logical-test·operator="AND"·negate="false">148 ······<cpe-lang:logical-test·operator="AND"·negate="false">
147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
148 ······</cpe-lang:logical-test>150 ······</cpe-lang:logical-test>
149 ····</cpe-lang:platform>151 ····</cpe-lang:platform>
150 ····<cpe-lang:platform·id="machine_and_package_squid">152 ····<cpe-lang:platform·id="package_logrotate">
151 ······<cpe-lang:logical-test·operator="AND"·negate="false">153 ······<cpe-lang:logical-test·operator="AND"·negate="false">
152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
154 ······</cpe-lang:logical-test> 
155 ····</cpe-lang:platform> 
156 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch"> 
157 ······<cpe-lang:logical-test·operator="OR"·negate="false"> 
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/> 
160 ······</cpe-lang:logical-test>155 ······</cpe-lang:logical-test>
161 ····</cpe-lang:platform>156 ····</cpe-lang:platform>
162 ····<cpe-lang:platform·id="package_gdm">157 ····<cpe-lang:platform·id="package_audit">
163 ······<cpe-lang:logical-test·operator="AND"·negate="false">158 ······<cpe-lang:logical-test·operator="AND"·negate="false">
164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>
165 ······</cpe-lang:logical-test>160 ······</cpe-lang:logical-test>
166 ····</cpe-lang:platform>161 ····</cpe-lang:platform>
167 ····<cpe-lang:platform·id="package_postfix">162 ····<cpe-lang:platform·id="package_yum">
168 ······<cpe-lang:logical-test·operator="AND"·negate="false">163 ······<cpe-lang:logical-test·operator="AND"·negate="false">
169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/>
170 ······</cpe-lang:logical-test>165 ······</cpe-lang:logical-test>
171 ····</cpe-lang:platform>166 ····</cpe-lang:platform>
172 ····<cpe-lang:platform·id="machine_and_not_rhcos4-rhel9_and_service_disabled_nftables_and_service_disabled_ufw">167 ····<cpe-lang:platform·id="non-uefi">
173 ······<cpe-lang:logical-test·operator="AND"·negate="false">168 ······<cpe-lang:logical-test·operator="AND"·negate="false">
174 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
Max diff block lines reached; 698986/712714 bytes (98.07%) of diff not shown.
1.7 MB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ds.xml
1.7 MB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ds.xml
    
Offset 19, 25 lines modifiedOffset 19, 25 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-anolis8-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-anolis8-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-cpe-dictionary.xml"·timestamp="2024-11-02T06:39:34">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-cpe-dictionary.xml"·timestamp="2024-11-03T08:39:34">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:8">28 ······<cpe-dict:cpe-item·name="cpe:/o:anolis:anolis_os:8">
29 ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·8</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Anolis·OS·8</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml">oval:ssg-installed_OS_is_anolis8:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml">oval:ssg-installed_OS_is_anolis8:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-xccdf.xml"·timestamp="2024-11-02T06:39:34">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-anolis8-xccdf.xml"·timestamp="2024-11-03T08:39:34">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·8</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·8</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Anolis·OS·8.·It·is·a·rendering·of40 configuration·settings·for·Anolis·OS·8.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
42 in·order·to·support·security·automation.··The·SCAP·content·is42 in·order·to·support·security·automation.··The·SCAP·content·is
43 is·available·in·the43 is·available·in·the
Offset 104, 218 lines modifiedOffset 104, 218 lines modified
104 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>104 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
105 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>105 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
106 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>106 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
107 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
110 ······<cpe-lang:platform-specification>110 ······<cpe-lang:platform-specification>
111 ········<cpe-lang:platform·id="package_shadow-utils">111 ········<cpe-lang:platform·id="ipv6_enabled">
112 ··········<cpe-lang:logical-test·operator="AND"·negate="false">112 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
113 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>113 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
114 ··········</cpe-lang:logical-test>114 ··········</cpe-lang:logical-test>
115 ········</cpe-lang:platform>115 ········</cpe-lang:platform>
116 ········<cpe-lang:platform·id="aarch64_arch">116 ········<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
117 ··········<cpe-lang:logical-test·operator="AND"·negate="false">117 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
118 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>118 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 119 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
119 ··········</cpe-lang:logical-test>120 ··········</cpe-lang:logical-test>
120 ········</cpe-lang:platform>121 ········</cpe-lang:platform>
121 ········<cpe-lang:platform·id="machine">122 ········<cpe-lang:platform·id="grub2">
122 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
123 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
124 ··········</cpe-lang:logical-test> 
125 ········</cpe-lang:platform> 
126 ········<cpe-lang:platform·id="x86_64_arch"> 
127 ··········<cpe-lang:logical-test·operator="AND"·negate="false">123 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
128 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>124 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
129 ··········</cpe-lang:logical-test>125 ··········</cpe-lang:logical-test>
130 ········</cpe-lang:platform>126 ········</cpe-lang:platform>
131 ········<cpe-lang:platform·id="package_logrotate">127 ········<cpe-lang:platform·id="machine">
132 ··········<cpe-lang:logical-test·operator="AND"·negate="false">128 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
133 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>129 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
134 ··········</cpe-lang:logical-test>130 ··········</cpe-lang:logical-test>
135 ········</cpe-lang:platform>131 ········</cpe-lang:platform>
136 ········<cpe-lang:platform·id="package_sudo">132 ········<cpe-lang:platform·id="package_iptables">
137 ··········<cpe-lang:logical-test·operator="AND"·negate="false">133 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
138 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>134 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
139 ··········</cpe-lang:logical-test>135 ··········</cpe-lang:logical-test>
140 ········</cpe-lang:platform>136 ········</cpe-lang:platform>
141 ········<cpe-lang:platform·id="machine_and_package_ufw">137 ········<cpe-lang:platform·id="machine_and_package_ufw">
142 ··········<cpe-lang:logical-test·operator="AND"·negate="false">138 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
143 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>139 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
144 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
145 ··········</cpe-lang:logical-test>141 ··········</cpe-lang:logical-test>
146 ········</cpe-lang:platform>142 ········</cpe-lang:platform>
147 ········<cpe-lang:platform·id="not_aarch64_arch">143 ········<cpe-lang:platform·id="not_aarch64_arch">
148 ··········<cpe-lang:logical-test·operator="AND"·negate="true">144 ··········<cpe-lang:logical-test·operator="AND"·negate="true">
149 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>145 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
150 ··········</cpe-lang:logical-test>146 ··········</cpe-lang:logical-test>
151 ········</cpe-lang:platform>147 ········</cpe-lang:platform>
 148 ········<cpe-lang:platform·id="machine_and_not_rhcos4-rhel9_and_service_disabled_nftables_and_service_disabled_ufw">
 149 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 150 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 151 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_OS_is_rhcos4_rhel9:def:1"/>
 152 ············</cpe-lang:logical-test>
 153 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
 154 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_nftables:def:1"/>
 155 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>
 156 ··········</cpe-lang:logical-test>
 157 ········</cpe-lang:platform>
152 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">158 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
153 ··········<cpe-lang:logical-test·operator="AND"·negate="false">159 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
154 ············<cpe-lang:logical-test·operator="AND"·negate="true">160 ············<cpe-lang:logical-test·operator="AND"·negate="true">
155 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>161 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
156 ············</cpe-lang:logical-test>162 ············</cpe-lang:logical-test>
157 ············<cpe-lang:logical-test·operator="AND"·negate="true">163 ············<cpe-lang:logical-test·operator="AND"·negate="true">
158 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>164 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
159 ············</cpe-lang:logical-test>165 ············</cpe-lang:logical-test>
160 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>166 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
161 ··········</cpe-lang:logical-test>167 ··········</cpe-lang:logical-test>
162 ········</cpe-lang:platform>168 ········</cpe-lang:platform>
163 ········<cpe-lang:platform·id="package_yum">169 ········<cpe-lang:platform·id="machine_and_package_snmpd">
164 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
165 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/> 
166 ··········</cpe-lang:logical-test> 
167 ········</cpe-lang:platform> 
168 ········<cpe-lang:platform·id="package_firewalld"> 
169 ··········<cpe-lang:logical-test·operator="AND"·negate="false">170 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
170 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>172 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>
171 ··········</cpe-lang:logical-test>173 ··········</cpe-lang:logical-test>
172 ········</cpe-lang:platform>174 ········</cpe-lang:platform>
173 ········<cpe-lang:platform·id="package_systemd">175 ········<cpe-lang:platform·id="package_pam">
174 ··········<cpe-lang:logical-test·operator="AND"·negate="false">176 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
175 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>177 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
176 ··········</cpe-lang:logical-test>178 ··········</cpe-lang:logical-test>
177 ········</cpe-lang:platform>179 ········</cpe-lang:platform>
178 ········<cpe-lang:platform·id="wifi-iface">180 ········<cpe-lang:platform·id="package_firewalld">
179 ··········<cpe-lang:logical-test·operator="AND"·negate="false">181 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
180 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>182 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
181 ··········</cpe-lang:logical-test>183 ··········</cpe-lang:logical-test>
182 ········</cpe-lang:platform>184 ········</cpe-lang:platform>
183 ········<cpe-lang:platform·id="machine_and_package_squid">185 ········<cpe-lang:platform·id="package_logrotate">
184 ··········<cpe-lang:logical-test·operator="AND"·negate="false">186 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
185 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
186 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>187 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
187 ··········</cpe-lang:logical-test> 
188 ········</cpe-lang:platform> 
189 ········<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch"> 
190 ··········<cpe-lang:logical-test·operator="OR"·negate="false"> 
191 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
192 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/> 
Max diff block lines reached; 1773329/1786322 bytes (99.27%) of diff not shown.
990 KB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ocil.xml
990 KB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ocil.xml
Ordering differences only
    
Offset 3, 2893 lines modifiedOffset 3, 2893 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_hash_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_maxstartups_ocil:questionnaire:1">
11 ······<ocil:title>Specify·the·hash·to·use·when·signing·modules</ocil:title>11 ······<ocil:title>Ensure·SSH·MaxStartups·is·configured</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_hash_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-sshd_set_maxstartups_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-service_cron_enabled_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_allow_ocil:questionnaire:1">
17 ······<ocil:title>Enable·cron·Service</ocil:title>17 ······<ocil:title>Verify·Group·Who·Owns·/etc/cron.allow·file</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-service_cron_enabled_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_allow_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fsetxattr_ocil:questionnaire:1"> 
23 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fsetxattr</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_syn_cookies_ocil:questionnaire:1">
 23 ······<ocil:title>Enable·TCP/IP·syncookie·support</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fsetxattr_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-kernel_config_syn_cookies_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_all_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-grub2_mce_argument_ocil:questionnaire:1">
29 ······<ocil:title>Enable·automatic·signing·of·all·modules</ocil:title>29 ······<ocil:title>Force·kernel·panic·on·uncorrected·MCEs</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_all_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-grub2_mce_argument_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1"> 
35 ······<ocil:title>Configure·auditd·to·use·audispd's·syslog·plugin</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-file_cron_deny_not_exist_ocil:questionnaire:1">
 35 ······<ocil:title>Ensure·that·/etc/cron.deny·does·not·exist</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_syslog_plugin_activated_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_cron_deny_not_exist_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_tcp_forwarding_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-accounts_tmout_ocil:questionnaire:1">
41 ······<ocil:title>Disable·SSH·TCP·Forwarding</ocil:title>41 ······<ocil:title>Set·Interactive·Session·Timeout</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_tcp_forwarding_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-accounts_tmout_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1"> 
47 ······<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_tcp_syncookies_ocil:questionnaire:1">
 47 ······<ocil:title>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_tcp_syncookies_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_groupownership_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_passwd_ocil:questionnaire:1">
53 ······<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·Group</ocil:title>53 ······<ocil:title>Verify·Permissions·on·Backup·passwd·File</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_groupownership_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_efi_grub2_cfg_ocil:questionnaire:1"> 
59 ······<ocil:title>Verify·the·UEFI·Boot·Loader·grub.cfg·Permissions</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-harden_ssh_client_crypto_policy_ocil:questionnaire:1">
 59 ······<ocil:title>Harden·SSH·client·Crypto·Policy</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_permissions_efi_grub2_cfg_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-harden_ssh_client_crypto_policy_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-package_gnutls-utils_installed_ocil:questionnaire:1"> 
65 ······<ocil:title>Ensure·gnutls-utils·is·installed</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1">
 65 ······<ocil:title>Configure·auditd·space_left·Action·on·Low·Disk·Space</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-package_gnutls-utils_installed_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_home_directories_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_sshd_private_key_ocil:questionnaire:1">
71 ······<ocil:title>All·Interactive·User·Home·Directories·Must·Be·Group-Owned·By·The·Primary·Group</ocil:title>71 ······<ocil:title>Verify·Group·Ownership·on·SSH·Server·Private·*_key·Key·Files</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_home_directories_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_sshd_private_key_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_cron_deny_not_exist_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">
77 ······<ocil:title>Ensure·that·/etc/cron.deny·does·not·exist</ocil:title>77 ······<ocil:title>Disable·XDMCP·in·GDM</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_cron_deny_not_exist_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lsetxattr_ocil:questionnaire:1"> 
83 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lsetxattr</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_notifiers_ocil:questionnaire:1">
 83 ······<ocil:title>Enable·checks·on·notifier·call·chains</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_notifiers_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_daily_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_stime_ocil:questionnaire:1">
89 ······<ocil:title>Verify·Owner·on·cron.daily</ocil:title>89 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·stime</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_daily_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_stime_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-selinux_not_disabled_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-selinux_not_disabled_ocil:questionnaire:1">
95 ······<ocil:title>Ensure·SELinux·is·Not·Disabled</ocil:title>95 ······<ocil:title>Ensure·SELinux·is·Not·Disabled</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-selinux_not_disabled_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-selinux_not_disabled_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-service_autofs_disabled_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_crontab_ocil:questionnaire:1">
101 ······<ocil:title>Disable·the·Automounter</ocil:title>101 ······<ocil:title>Verify·Permissions·on·crontab</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-service_autofs_disabled_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-file_permissions_crontab_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_ocil:questionnaire:1">
107 ······<ocil:title>Ensure·Rsyslog·Encrypts·Off-Loaded·Audit·Records</ocil:title>107 ······<ocil:title>Disable·IPv6·Addressing·on·IPv6·Interfaces·by·Default</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_monthly_ocil:questionnaire:1"> 
113 ······<ocil:title>Verify·Group·Who·Owns·cron.monthly</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-sudoers_explicit_command_args_ocil:questionnaire:1">
 113 ······<ocil:title>Explicit·arguments·in·sudo·specifications</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_monthly_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-sudoers_explicit_command_args_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_ocil:questionnaire:1"> 
119 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv6·Interfaces·by·Default</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1">
 119 ······<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 1001333/1013402 bytes (98.81%) of diff not shown.
696 KB
./usr/share/xml/scap/ssg/content/ssg-anolis8-xccdf.xml
696 KB
./usr/share/xml/scap/ssg/content/ssg-anolis8-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_ANOLIS-8"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·8</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Anolis·OS·8</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·Anolis·OS·8.·It·is·a·rendering·of7 configuration·settings·for·Anolis·OS·8.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
Offset 71, 218 lines modifiedOffset 71, 218 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="package_shadow-utils">78 ····<cpe-lang:platform·id="ipv6_enabled">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
81 ······</cpe-lang:logical-test>81 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>82 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="aarch64_arch">83 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
84 ······<cpe-lang:logical-test·operator="AND"·negate="false">84 ······<cpe-lang:logical-test·operator="OR"·negate="false">
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
86 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
87 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
88 ····<cpe-lang:platform·id="machine">89 ····<cpe-lang:platform·id="grub2">
89 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
91 ······</cpe-lang:logical-test> 
92 ····</cpe-lang:platform> 
93 ····<cpe-lang:platform·id="x86_64_arch"> 
94 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
96 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
97 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
98 ····<cpe-lang:platform·id="package_logrotate">94 ····<cpe-lang:platform·id="machine">
99 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
101 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
102 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
103 ····<cpe-lang:platform·id="package_sudo">99 ····<cpe-lang:platform·id="package_iptables">
104 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
106 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
107 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
108 ····<cpe-lang:platform·id="machine_and_package_ufw">104 ····<cpe-lang:platform·id="machine_and_package_ufw">
109 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
112 ······</cpe-lang:logical-test>108 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>109 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="not_aarch64_arch">110 ····<cpe-lang:platform·id="not_aarch64_arch">
115 ······<cpe-lang:logical-test·operator="AND"·negate="true">111 ······<cpe-lang:logical-test·operator="AND"·negate="true">
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
117 ······</cpe-lang:logical-test>113 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>114 ····</cpe-lang:platform>
 115 ····<cpe-lang:platform·id="machine_and_not_rhcos4-rhel9_and_service_disabled_nftables_and_service_disabled_ufw">
 116 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 117 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 118 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_OS_is_rhcos4_rhel9:def:1"/>
 119 ········</cpe-lang:logical-test>
 120 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
 121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_nftables:def:1"/>
 122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>
 123 ······</cpe-lang:logical-test>
 124 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">125 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">126 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:logical-test·operator="AND"·negate="true">127 ········<cpe-lang:logical-test·operator="AND"·negate="true">
122 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>128 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
123 ········</cpe-lang:logical-test>129 ········</cpe-lang:logical-test>
124 ········<cpe-lang:logical-test·operator="AND"·negate="true">130 ········<cpe-lang:logical-test·operator="AND"·negate="true">
125 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>131 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
126 ········</cpe-lang:logical-test>132 ········</cpe-lang:logical-test>
127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
128 ······</cpe-lang:logical-test>134 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>135 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="package_yum">136 ····<cpe-lang:platform·id="machine_and_package_snmpd">
131 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/> 
133 ······</cpe-lang:logical-test> 
134 ····</cpe-lang:platform> 
135 ····<cpe-lang:platform·id="package_firewalld"> 
136 ······<cpe-lang:logical-test·operator="AND"·negate="false">137 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>139 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>
138 ······</cpe-lang:logical-test>140 ······</cpe-lang:logical-test>
139 ····</cpe-lang:platform>141 ····</cpe-lang:platform>
140 ····<cpe-lang:platform·id="package_systemd">142 ····<cpe-lang:platform·id="package_pam">
141 ······<cpe-lang:logical-test·operator="AND"·negate="false">143 ······<cpe-lang:logical-test·operator="AND"·negate="false">
142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>144 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
143 ······</cpe-lang:logical-test>145 ······</cpe-lang:logical-test>
144 ····</cpe-lang:platform>146 ····</cpe-lang:platform>
145 ····<cpe-lang:platform·id="wifi-iface">147 ····<cpe-lang:platform·id="package_firewalld">
146 ······<cpe-lang:logical-test·operator="AND"·negate="false">148 ······<cpe-lang:logical-test·operator="AND"·negate="false">
147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
148 ······</cpe-lang:logical-test>150 ······</cpe-lang:logical-test>
149 ····</cpe-lang:platform>151 ····</cpe-lang:platform>
150 ····<cpe-lang:platform·id="machine_and_package_squid">152 ····<cpe-lang:platform·id="package_logrotate">
151 ······<cpe-lang:logical-test·operator="AND"·negate="false">153 ······<cpe-lang:logical-test·operator="AND"·negate="false">
152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
154 ······</cpe-lang:logical-test> 
155 ····</cpe-lang:platform> 
156 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch"> 
157 ······<cpe-lang:logical-test·operator="OR"·negate="false"> 
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/> 
160 ······</cpe-lang:logical-test>155 ······</cpe-lang:logical-test>
161 ····</cpe-lang:platform>156 ····</cpe-lang:platform>
162 ····<cpe-lang:platform·id="package_gdm">157 ····<cpe-lang:platform·id="package_audit">
163 ······<cpe-lang:logical-test·operator="AND"·negate="false">158 ······<cpe-lang:logical-test·operator="AND"·negate="false">
164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>
165 ······</cpe-lang:logical-test>160 ······</cpe-lang:logical-test>
166 ····</cpe-lang:platform>161 ····</cpe-lang:platform>
167 ····<cpe-lang:platform·id="package_postfix">162 ····<cpe-lang:platform·id="package_yum">
168 ······<cpe-lang:logical-test·operator="AND"·negate="false">163 ······<cpe-lang:logical-test·operator="AND"·negate="false">
169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/>
170 ······</cpe-lang:logical-test>165 ······</cpe-lang:logical-test>
171 ····</cpe-lang:platform>166 ····</cpe-lang:platform>
172 ····<cpe-lang:platform·id="machine_and_not_rhcos4-rhel9_and_service_disabled_nftables_and_service_disabled_ufw">167 ····<cpe-lang:platform·id="non-uefi">
173 ······<cpe-lang:logical-test·operator="AND"·negate="false">168 ······<cpe-lang:logical-test·operator="AND"·negate="false">
174 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
Max diff block lines reached; 698486/712168 bytes (98.08%) of diff not shown.
12.6 MB
./usr/share/xml/scap/ssg/content/ssg-centos8-ds.xml
12.6 MB
./usr/share/xml/scap/ssg/content/ssg-centos8-ds.xml
Max HTML report size reached
8.95 MB
./usr/share/xml/scap/ssg/content/ssg-centos8-xccdf.xml
8.95 MB
./usr/share/xml/scap/ssg/content/ssg-centos8-xccdf.xml
Max HTML report size reached
8.58 MB
./usr/share/xml/scap/ssg/content/ssg-cs10-ds.xml
8.58 MB
./usr/share/xml/scap/ssg/content/ssg-cs10-ds.xml
Max HTML report size reached
6.35 MB
./usr/share/xml/scap/ssg/content/ssg-cs10-xccdf.xml
6.35 MB
./usr/share/xml/scap/ssg/content/ssg-cs10-xccdf.xml
Max HTML report size reached
12.3 MB
./usr/share/xml/scap/ssg/content/ssg-cs9-ds.xml
12.3 MB
./usr/share/xml/scap/ssg/content/ssg-cs9-ds.xml
Max HTML report size reached
8.84 MB
./usr/share/xml/scap/ssg/content/ssg-cs9-xccdf.xml
8.84 MB
./usr/share/xml/scap/ssg/content/ssg-cs9-xccdf.xml
Max HTML report size reached
8.51 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ds.xml
8.51 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ds.xml
Max HTML report size reached
1.98 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ocil.xml
1.98 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ocil.xml
Max HTML report size reached
6.29 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-xccdf.xml
6.29 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-xccdf.xml
Max HTML report size reached
5.89 KB
./usr/share/xml/scap/ssg/content/ssg-macos1015-ds.xml
5.79 KB
./usr/share/xml/scap/ssg/content/ssg-macos1015-ds.xml
    
Offset 19, 25 lines modifiedOffset 19, 25 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-dictionary.xml"·timestamp="2024-11-02T06:39:34">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-dictionary.xml"·timestamp="2024-11-03T08:39:34">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:apple:macos:10.15">28 ······<cpe-dict:cpe-item·name="cpe:/o:apple:macos:10.15">
29 ········<cpe-dict:title·xml:lang="en-us">Apple·macOS·10.15</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Apple·macOS·10.15</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-macos1015-cpe-oval.xml">oval:ssg-installed_OS_is_macos1015:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-macos1015-cpe-oval.xml">oval:ssg-installed_OS_is_macos1015:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-xccdf.xml"·timestamp="2024-11-02T06:39:34">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-xccdf.xml"·timestamp="2024-11-03T08:39:34">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_macOS-1015"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_macOS-1015"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Apple·macOS·10.15</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Apple·macOS·10.15</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Apple·macOS·10.15.·It·is·a·rendering·of40 configuration·settings·for·Apple·macOS·10.15.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
42 in·order·to·support·security·automation.42 in·order·to·support·security·automation.
43 ········<html:br/>43 ········<html:br/>
Offset 554, 15 lines modifiedOffset 554, 15 lines modified
554 ··············<xccdf-1.2:check-content-ref·href="ssg-macos1015-ocil.xml"·name="ocil:ssg-audit_failure_halt_ocil:questionnaire:1"/>554 ··············<xccdf-1.2:check-content-ref·href="ssg-macos1015-ocil.xml"·name="ocil:ssg-audit_failure_halt_ocil:questionnaire:1"/>
555 ············</xccdf-1.2:check>555 ············</xccdf-1.2:check>
556 ··········</xccdf-1.2:Rule>556 ··········</xccdf-1.2:Rule>
557 ········</xccdf-1.2:Group>557 ········</xccdf-1.2:Group>
558 ······</xccdf-1.2:Group>558 ······</xccdf-1.2:Group>
559 ····</xccdf-1.2:Benchmark>559 ····</xccdf-1.2:Benchmark>
560 ··</ds:component>560 ··</ds:component>
561 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-oval.xml"·timestamp="2024-11-02T06:39:34">561 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-oval.xml"·timestamp="2024-11-03T08:39:34">
562 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">562 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
563 ······<oval-def:generator>563 ······<oval-def:generator>
564 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>564 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
565 ········<oval:product_version>ssg:·[0,·1,·74],·python:·3.12.7</oval:product_version>565 ········<oval:product_version>ssg:·[0,·1,·74],·python:·3.12.7</oval:product_version>
566 ········<oval:schema_version>5.11</oval:schema_version>566 ········<oval:schema_version>5.11</oval:schema_version>
567 ········<oval:timestamp>2024-11-02T18:39:34</oval:timestamp>567 ········<oval:timestamp>2024-11-02T18:39:34</oval:timestamp>
568 ······</oval-def:generator>568 ······</oval-def:generator>
Offset 591, 15 lines modifiedOffset 591, 15 lines modified
591 ··········<ind:filepath>/etc/security/audit_control</ind:filepath>591 ··········<ind:filepath>/etc/security/audit_control</ind:filepath>
592 ··········<ind:pattern·operation="pattern·match">^policy:.*,ahlt.*$</ind:pattern>592 ··········<ind:pattern·operation="pattern·match">^policy:.*,ahlt.*$</ind:pattern>
593 ··········<ind:instance·datatype="int">1</ind:instance>593 ··········<ind:instance·datatype="int">1</ind:instance>
594 ········</ind:textfilecontent54_object>594 ········</ind:textfilecontent54_object>
595 ······</oval-def:objects>595 ······</oval-def:objects>
596 ····</oval-def:oval_definitions>596 ····</oval-def:oval_definitions>
597 ··</ds:component>597 ··</ds:component>
598 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-ocil.xml"·timestamp="2024-11-02T06:39:34">598 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-ocil.xml"·timestamp="2024-11-03T08:39:34">
599 ····<ocil:ocil>599 ····<ocil:ocil>
600 ······<ocil:generator>600 ······<ocil:generator>
601 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>601 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
602 ········<ocil:product_version>ssg:·0.1.74</ocil:product_version>602 ········<ocil:product_version>ssg:·0.1.74</ocil:product_version>
603 ········<ocil:schema_version>2.0</ocil:schema_version>603 ········<ocil:schema_version>2.0</ocil:schema_version>
604 ········<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>604 ········<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
605 ······</ocil:generator>605 ······</ocil:generator>
Offset 650, 15 lines modifiedOffset 650, 15 lines modified
650 $·sudo·grep·-E·&quot;^policy.*ahlt&quot;·/etc/security/audit_control650 $·sudo·grep·-E·&quot;^policy.*ahlt&quot;·/etc/security/audit_control
651 The·output·should·contain·ahlt651 The·output·should·contain·ahlt
652 ······Is·it·the·case·that·auditing·is·not·configured·to·shut·down·on·audit·failure?</ocil:question_text>652 ······Is·it·the·case·that·auditing·is·not·configured·to·shut·down·on·audit·failure?</ocil:question_text>
653 ········</ocil:boolean_question>653 ········</ocil:boolean_question>
654 ······</ocil:questions>654 ······</ocil:questions>
655 ····</ocil:ocil>655 ····</ocil:ocil>
656 ··</ds:component>656 ··</ds:component>
657 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"·timestamp="2024-11-02T06:39:34">657 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"·timestamp="2024-11-03T08:39:34">
658 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">658 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
659 ······<oval-def:generator>659 ······<oval-def:generator>
660 ········<oval:product_name>build_cpe.py·from·SCAP·Security·Guide</oval:product_name>660 ········<oval:product_name>build_cpe.py·from·SCAP·Security·Guide</oval:product_name>
661 ········<oval:product_version>ssg:·[0,·1,·74],·python:·3.12.7</oval:product_version>661 ········<oval:product_version>ssg:·[0,·1,·74],·python:·3.12.7</oval:product_version>
662 ········<oval:schema_version>5.11</oval:schema_version>662 ········<oval:schema_version>5.11</oval:schema_version>
663 ········<oval:timestamp>2024-11-02T18:39:34</oval:timestamp>663 ········<oval:timestamp>2024-11-02T18:39:34</oval:timestamp>
664 ······</oval-def:generator>664 ······</oval-def:generator>
1.17 KB
./usr/share/xml/scap/ssg/content/ssg-macos1015-xccdf.xml
1.06 KB
./usr/share/xml/scap/ssg/content/ssg-macos1015-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_macOS-1015"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_macOS-1015"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Apple·macOS·10.15</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Apple·macOS·10.15</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·Apple·macOS·10.15.·It·is·a·rendering·of7 configuration·settings·for·Apple·macOS·10.15.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.9 in·order·to·support·security·automation.
10 ····<html:br/>10 ····<html:br/>
891 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ds.xml
891 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-ocp4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-ocp4-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-cpe-dictionary.xml"·timestamp="2024-11-02T06:39:34">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-cpe-dictionary.xml"·timestamp="2024-11-03T08:39:34">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.1">28 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.1">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.10">32 ······<cpe-dict:cpe-item·name="cpe:/a:redhat:openshift_container_platform:4.10">
33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4.10</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4.10</cpe-dict:title>
Offset 111, 17 lines modifiedOffset 111, 17 lines modified
111 ······</cpe-dict:cpe-item>111 ······</cpe-dict:cpe-item>
112 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:openshift_container_platform_node:4">112 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:openshift_container_platform_node:4">
113 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4·Node</cpe-dict:title>113 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·OpenShift·Container·Platform·4·Node</cpe-dict:title>
114 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4_node:def:1</cpe-dict:check>114 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml">oval:ssg-installed_app_is_ocp4_node:def:1</cpe-dict:check>
115 ······</cpe-dict:cpe-item>115 ······</cpe-dict:cpe-item>
116 ····</cpe-dict:cpe-list>116 ····</cpe-dict:cpe-list>
117 ··</ds:component>117 ··</ds:component>
118 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-xccdf.xml"·timestamp="2024-11-02T06:39:34">118 ··<ds:component·id="scap_org.open-scap_comp_ssg-ocp4-xccdf.xml"·timestamp="2024-11-03T08:39:34">
119 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OCP-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">119 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OCP-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
120 ······<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>120 ······<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
121 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·OpenShift·Container·Platform·4</xccdf-1.2:title>121 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·OpenShift·Container·Platform·4</xccdf-1.2:title>
122 ······<xccdf-1.2:description>122 ······<xccdf-1.2:description>
123 ········This·guide·presents·a·catalog·of·security-relevant123 ········This·guide·presents·a·catalog·of·security-relevant
124 configuration·settings·for·Red·Hat·OpenShift·Container·Platform·4.·It·is·a·rendering·of124 configuration·settings·for·Red·Hat·OpenShift·Container·Platform·4.·It·is·a·rendering·of
125 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)125 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
126 in·order·to·support·security·automation.··The·SCAP·content·is126 in·order·to·support·security·automation.··The·SCAP·content·is
127 is·available·in·the127 is·available·in·the
Offset 189, 196 lines modifiedOffset 189, 196 lines modified
189 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>189 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
190 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>190 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
191 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>191 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
192 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>192 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
193 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform">stigid</xccdf-1.2:reference>193 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform">stigid</xccdf-1.2:reference>
194 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>194 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
195 ······<cpe-lang:platform-specification>195 ······<cpe-lang:platform-specification>
196 ········<cpe-lang:platform·id="ocp4-node-on-ovn">196 ········<cpe-lang:platform·id="ocp4-node-on-sdn">
197 ··········<cpe-lang:logical-test·operator="AND"·negate="false">197 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
198 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node_on_openshift-ovn:def:1"/>198 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node_on_openshift-sdn:def:1"/>
199 ··········</cpe-lang:logical-test>199 ··········</cpe-lang:logical-test>
200 ········</cpe-lang:platform>200 ········</cpe-lang:platform>
201 ········<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.8_or_ocp4.9">201 ········<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.6_or_ocp4.7_or_ocp4.8">
202 ··········<cpe-lang:logical-test·operator="AND"·negate="false">202 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
203 ············<cpe-lang:logical-test·operator="AND"·negate="true">203 ············<cpe-lang:logical-test·operator="AND"·negate="true">
204 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>204 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>
205 ············</cpe-lang:logical-test>205 ············</cpe-lang:logical-test>
206 ············<cpe-lang:logical-test·operator="OR"·negate="false">206 ············<cpe-lang:logical-test·operator="OR"·negate="false">
 207 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/>
 208 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_7:def:1"/>
207 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_8:def:1"/>209 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_8:def:1"/>
208 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_9:def:1"/> 
209 ············</cpe-lang:logical-test>210 ············</cpe-lang:logical-test>
210 ··········</cpe-lang:logical-test>211 ··········</cpe-lang:logical-test>
211 ········</cpe-lang:platform>212 ········</cpe-lang:platform>
212 ········<cpe-lang:platform·id="ocp4-on-hypershift"> 
213 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
214 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift:def:1"/> 
215 ··········</cpe-lang:logical-test> 
216 ········</cpe-lang:platform> 
217 ········<cpe-lang:platform·id="not_ocp4-on-hypershift"> 
218 ··········<cpe-lang:logical-test·operator="AND"·negate="true"> 
219 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift:def:1"/> 
220 ··········</cpe-lang:logical-test> 
221 ········</cpe-lang:platform> 
222 ········<cpe-lang:platform·id="ocp4-on-sdn">213 ········<cpe-lang:platform·id="ocp4-node">
223 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
224 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_openshiftsdn:def:1"/> 
225 ··········</cpe-lang:logical-test> 
226 ········</cpe-lang:platform> 
227 ········<cpe-lang:platform·id="not_s390x_arch_and_ocp4-node"> 
228 ··········<cpe-lang:logical-test·operator="AND"·negate="false">214 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
229 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/> 
230 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node:def:1"/>215 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node:def:1"/>
231 ··········</cpe-lang:logical-test>216 ··········</cpe-lang:logical-test>
232 ········</cpe-lang:platform>217 ········</cpe-lang:platform>
233 ········<cpe-lang:platform·id="ocp4.16">218 ········<cpe-lang:platform·id="ocp4.11_or_ocp4.12_or_ocp4.13_or_ocp4.14_or_ocp4.15">
234 ··········<cpe-lang:logical-test·operator="AND"·negate="false">219 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
235 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_16:def:1"/>220 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_11:def:1"/>
236 ··········</cpe-lang:logical-test> 
237 ········</cpe-lang:platform> 
238 ········<cpe-lang:platform·id="ocp4-node-on-sdn"> 
239 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
240 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node_on_openshift-sdn:def:1"/>221 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_12:def:1"/>
 222 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_13:def:1"/>
 223 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_14:def:1"/>
 224 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_15:def:1"/>
241 ··········</cpe-lang:logical-test>225 ··········</cpe-lang:logical-test>
242 ········</cpe-lang:platform>226 ········</cpe-lang:platform>
243 ········<cpe-lang:platform·id="ocp4-node_and_s390x_arch">227 ········<cpe-lang:platform·id="ocp4-node_and_s390x_arch">
244 ··········<cpe-lang:logical-test·operator="AND"·negate="false">228 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
245 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node:def:1"/>229 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node:def:1"/>
246 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>230 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
247 ··········</cpe-lang:logical-test>231 ··········</cpe-lang:logical-test>
248 ········</cpe-lang:platform>232 ········</cpe-lang:platform>
249 ········<cpe-lang:platform·id="ocp4-master-node">233 ········<cpe-lang:platform·id="ocp4.6_or_ocp4.7">
250 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
251 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-node_is_ocp4_master_node:def:1"/> 
252 ··········</cpe-lang:logical-test> 
253 ········</cpe-lang:platform> 
254 ········<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.12_or_ocp4.13"> 
255 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
256 ············<cpe-lang:logical-test·operator="AND"·negate="true"> 
257 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/> 
258 ············</cpe-lang:logical-test> 
259 ············<cpe-lang:logical-test·operator="OR"·negate="false">234 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
260 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_12:def:1"/>235 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/>
261 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_13:def:1"/>236 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_7:def:1"/>
262 ············</cpe-lang:logical-test> 
263 ··········</cpe-lang:logical-test>237 ··········</cpe-lang:logical-test>
264 ········</cpe-lang:platform>238 ········</cpe-lang:platform>
265 ········<cpe-lang:platform·id="ocp4.6_or_ocp4.7_or_ocp4.8">239 ········<cpe-lang:platform·id="ocp4.6_or_ocp4.7_or_ocp4.8">
266 ··········<cpe-lang:logical-test·operator="OR"·negate="false">240 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
267 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/>241 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/>
268 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_7:def:1"/>242 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_7:def:1"/>
269 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_8:def:1"/>243 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_8:def:1"/>
270 ··········</cpe-lang:logical-test>244 ··········</cpe-lang:logical-test>
271 ········</cpe-lang:platform>245 ········</cpe-lang:platform>
272 ········<cpe-lang:platform·id="ocp4-on-azure">246 ········<cpe-lang:platform·id="not_s390x_arch_and_ocp4-node">
273 ··········<cpe-lang:logical-test·operator="AND"·negate="false">247 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 248 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
274 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_azure:def:1"/>249 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node:def:1"/>
275 ··········</cpe-lang:logical-test>250 ··········</cpe-lang:logical-test>
Max diff block lines reached; 898692/911887 bytes (98.55%) of diff not shown.
827 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ocil.xml
827 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ocil.xml
Ordering differences only
    
Offset 3, 5486 lines modifiedOffset 3, 5149 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-general_namespace_separation_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-general_apply_scc_ocil:questionnaire:1">
11 ······<ocil:title>Each·Namespace·should·only·host·one·application</ocil:title>11 ······<ocil:title>Apply·Security·Context·to·Your·Pods·and·Containers</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-general_namespace_separation_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-general_apply_scc_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-file_owner_ovs_sys_id_conf_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-banner_or_login_template_set_ocil:questionnaire:1">
17 ······<ocil:title>Verify·User·Who·Owns·The·Open·vSwitch·Persistent·System·ID</ocil:title>17 ······<ocil:title>Ensure·that·a·OpenShift·OAuth·login·template·or·a·classification·banner·is·set</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-file_owner_ovs_sys_id_conf_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-banner_or_login_template_set_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-general_configure_imagepolicywebhook_ocil:questionnaire:1"> 
23 ······<ocil:title>Manage·Image·Provenance·Using·ImagePolicyWebhook</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-api_server_etcd_cert_ocil:questionnaire:1">
 23 ······<ocil:title>Configure·the·etcd·Certificate·for·the·API·Server</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-general_configure_imagepolicywebhook_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-api_server_etcd_cert_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-api_server_admission_control_plugin_alwayspullimages_ocil:questionnaire:1"> 
29 ······<ocil:title>Ensure·that·the·Admission·Control·Plugin·AlwaysPullImages·is·not·set</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-etcd_client_cert_auth_ocil:questionnaire:1">
 29 ······<ocil:title>Enable·The·Client·Certificate·Authentication</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-api_server_admission_control_plugin_alwayspullimages_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-etcd_client_cert_auth_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-api_server_bind_address_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-file_owner_worker_service_ocil:questionnaire:1">
35 ······<ocil:title>Ensure·that·the·bindAddress·is·set·to·a·relevant·secure·port</ocil:title>35 ······<ocil:title>Verify·User·Who·Owns·The·OpenShift·Node·Service·File</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-api_server_bind_address_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_owner_worker_service_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-file_owner_ovs_conf_db_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-kubelet_configure_tls_key_pre_4_9_ocil:questionnaire:1">
41 ······<ocil:title>Verify·User·Who·Owns·The·Open·vSwitch·Configuration·Database</ocil:title>41 ······<ocil:title>Ensure·That·The·kubelet·Server·Key·Is·Correctly·Set</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-file_owner_ovs_conf_db_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-kubelet_configure_tls_key_pre_4_9_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-reject_unsigned_images_by_default_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-ocp_allowed_registries_ocil:questionnaire:1">
47 ······<ocil:title>Ensure·the·Container·Runtime·rejects·unsigned·images·by·default</ocil:title>47 ······<ocil:title>Allowed·registries·are·configured</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-reject_unsigned_images_by_default_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-ocp_allowed_registries_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_protect_kernel_sysctl_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-project_template_resource_quota_ocil:questionnaire:1">
53 ······<ocil:title>kubelet·-·Set·Up·Sysctl·to·Enable·Protect·Kernel·Defaults</ocil:title>53 ······<ocil:title>Ensure·that·project·templates·autocreate·Resource·Quotas</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_protect_kernel_sysctl_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-project_template_resource_quota_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_controller_manager_kubeconfig_ocil:questionnaire:1"> 
59 ······<ocil:title>Verify·Group·Who·Owns·The·OpenShift·Controller·Manager·Kubeconfig·File</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-liveness_readiness_probe_in_workload_ocil:questionnaire:1">
 59 ······<ocil:title>Ensure·that·all·workloads·have·liveness·and·readiness·probes</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_controller_manager_kubeconfig_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-liveness_readiness_probe_in_workload_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-classification_banner_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-file_owner_kubeconfig_ocil:questionnaire:1">
65 ······<ocil:title>Enable·Classification·Banner·on·OpenShift·Console</ocil:title>65 ······<ocil:title>Verify·User·Who·Owns·The·OpenShift·Admin·Kubeconfig·File</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-classification_banner_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_owner_kubeconfig_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_kubelet_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_owner_kubelet_ocil:questionnaire:1">
71 ······<ocil:title>Verify·Permissions·on·The·Kubelet·Configuration·File</ocil:title>71 ······<ocil:title>Verify·User·Who·Owns·The·Kubelet·Configuration·File</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_permissions_kubelet_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_owner_kubelet_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-openshift_api_server_audit_log_path_ocil:questionnaire:1"> 
77 ······<ocil:title>Configure·the·Audit·Log·Path</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_kube_controller_manager_ocil:questionnaire:1">
 77 ······<ocil:title>Verify·Group·Who·Owns·The·Kubernetes·Controller·Manager·Pod·Specification·File</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-openshift_api_server_audit_log_path_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_kube_controller_manager_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_server_cert_rotation_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-kubelet_configure_tls_cipher_suites_ingresscontroller_ocil:questionnaire:1">
83 ······<ocil:title>kubelet·-·Enable·Server·Certificate·Rotation</ocil:title>83 ······<ocil:title>Ensure·that·the·Ingress·Controller·only·makes·use·of·Strong·Cryptographic·Ciphers</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_server_cert_rotation_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-kubelet_configure_tls_cipher_suites_ingresscontroller_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_oauth_audit_ocil:questionnaire:1"> 
89 ······<ocil:title>OAuth·Audit·Logs·Must·Have·Mode·0600</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-kubelet_eviction_thresholds_set_hard_imagefs_available_ocil:questionnaire:1">
 89 ······<ocil:title>Ensure·Eviction·threshold·Settings·Are·Set·-·evictionHard:·imagefs.available</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_oauth_audit_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-kubelet_eviction_thresholds_set_hard_imagefs_available_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-etcd_peer_key_file_ocil:questionnaire:1"> 
95 ······<ocil:title>Ensure·That·The·etcd·Peer·Key·File·Is·Correctly·Set</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_ovs_sys_id_conf_s390x_ocil:questionnaire:1">
 95 ······<ocil:title>Verify·Group·Who·Owns·The·Open·vSwitch·Persistent·System·ID</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-etcd_peer_key_file_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_ovs_sys_id_conf_s390x_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-kubelet_eviction_thresholds_set_soft_memory_available_ocil:questionnaire:1"> 
101 ······<ocil:title>Ensure·Eviction·threshold·Settings·Are·Set·-·evictionSoft:·memory.available</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-api_server_api_priority_v1beta2_flowschema_catch_all_ocil:questionnaire:1">
 101 ······<ocil:title>Ensure·catch-all·FlowSchema·object·for·API·Priority·and·Fairness·Exists</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-kubelet_eviction_thresholds_set_soft_memory_available_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-api_server_api_priority_v1beta2_flowschema_catch_all_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-ocp_api_server_audit_log_maxbackup_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-api_server_audit_log_path_ocil:questionnaire:1">
107 ······<ocil:title>Configure·the·OpenShift·API·Server·Maximum·Retained·Audit·Logs</ocil:title>107 ······<ocil:title>Configure·the·Audit·Log·Path</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-ocp_api_server_audit_log_maxbackup_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-api_server_audit_log_path_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-api_server_api_priority_flowschema_catch_all_ocil:questionnaire:1"> 
113 ······<ocil:title>Ensure·catch-all·FlowSchema·object·for·API·Priority·and·Fairness·Exists</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-file_owner_proxy_kubeconfig_ocil:questionnaire:1">
 113 ······<ocil:title>Verify·User·Who·Owns·The·Worker·Proxy·Kubeconfig·File</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-api_server_api_priority_flowschema_catch_all_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-file_owner_proxy_kubeconfig_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-rbac_pod_creation_access_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etcd_data_files_ocil:questionnaire:1">
119 ······<ocil:title>Minimize·Access·to·Pod·Creation</ocil:title>119 ······<ocil:title>Verify·User·Who·Owns·The·Etcd·Write-Ahead-Log·Files</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-rbac_pod_creation_access_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-file_owner_etcd_data_files_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 833650/846668 bytes (98.46%) of diff not shown.
27.3 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-xccdf.xml
27.2 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_OCP-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_OCP-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·OpenShift·Container·Platform·4</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·OpenShift·Container·Platform·4</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·Red·Hat·OpenShift·Container·Platform·4.·It·is·a·rendering·of7 configuration·settings·for·Red·Hat·OpenShift·Container·Platform·4.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
Offset 72, 196 lines modifiedOffset 72, 196 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="ocp4-node-on-ovn">79 ····<cpe-lang:platform·id="ocp4-node-on-sdn">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node_on_openshift-ovn:def:1"/>81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node_on_openshift-sdn:def:1"/>
82 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
83 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
84 ····<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.8_or_ocp4.9">84 ····<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.6_or_ocp4.7_or_ocp4.8">
85 ······<cpe-lang:logical-test·operator="AND"·negate="false">85 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ········<cpe-lang:logical-test·operator="AND"·negate="true">86 ········<cpe-lang:logical-test·operator="AND"·negate="true">
87 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>87 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>
88 ········</cpe-lang:logical-test>88 ········</cpe-lang:logical-test>
89 ········<cpe-lang:logical-test·operator="OR"·negate="false">89 ········<cpe-lang:logical-test·operator="OR"·negate="false">
 90 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/>
 91 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_7:def:1"/>
90 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_8:def:1"/>92 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_8:def:1"/>
91 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_9:def:1"/> 
92 ········</cpe-lang:logical-test>93 ········</cpe-lang:logical-test>
93 ······</cpe-lang:logical-test>94 ······</cpe-lang:logical-test>
94 ····</cpe-lang:platform>95 ····</cpe-lang:platform>
95 ····<cpe-lang:platform·id="ocp4-on-hypershift"> 
96 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift:def:1"/> 
98 ······</cpe-lang:logical-test> 
99 ····</cpe-lang:platform> 
100 ····<cpe-lang:platform·id="not_ocp4-on-hypershift"> 
101 ······<cpe-lang:logical-test·operator="AND"·negate="true"> 
102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift:def:1"/> 
103 ······</cpe-lang:logical-test> 
104 ····</cpe-lang:platform> 
105 ····<cpe-lang:platform·id="ocp4-on-sdn">96 ····<cpe-lang:platform·id="ocp4-node">
106 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_openshiftsdn:def:1"/> 
108 ······</cpe-lang:logical-test> 
109 ····</cpe-lang:platform> 
110 ····<cpe-lang:platform·id="not_s390x_arch_and_ocp4-node"> 
111 ······<cpe-lang:logical-test·operator="AND"·negate="false">97 ······<cpe-lang:logical-test·operator="AND"·negate="false">
112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/> 
113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node:def:1"/>98 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node:def:1"/>
114 ······</cpe-lang:logical-test>99 ······</cpe-lang:logical-test>
115 ····</cpe-lang:platform>100 ····</cpe-lang:platform>
116 ····<cpe-lang:platform·id="ocp4.16">101 ····<cpe-lang:platform·id="ocp4.11_or_ocp4.12_or_ocp4.13_or_ocp4.14_or_ocp4.15">
117 ······<cpe-lang:logical-test·operator="AND"·negate="false">102 ······<cpe-lang:logical-test·operator="OR"·negate="false">
118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_16:def:1"/>103 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_11:def:1"/>
119 ······</cpe-lang:logical-test> 
120 ····</cpe-lang:platform> 
121 ····<cpe-lang:platform·id="ocp4-node-on-sdn"> 
122 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node_on_openshift-sdn:def:1"/>104 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_12:def:1"/>
 105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_13:def:1"/>
 106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_14:def:1"/>
 107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_15:def:1"/>
124 ······</cpe-lang:logical-test>108 ······</cpe-lang:logical-test>
125 ····</cpe-lang:platform>109 ····</cpe-lang:platform>
126 ····<cpe-lang:platform·id="ocp4-node_and_s390x_arch">110 ····<cpe-lang:platform·id="ocp4-node_and_s390x_arch">
127 ······<cpe-lang:logical-test·operator="AND"·negate="false">111 ······<cpe-lang:logical-test·operator="AND"·negate="false">
128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node:def:1"/>112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node:def:1"/>
129 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
130 ······</cpe-lang:logical-test>114 ······</cpe-lang:logical-test>
131 ····</cpe-lang:platform>115 ····</cpe-lang:platform>
132 ····<cpe-lang:platform·id="ocp4-master-node">116 ····<cpe-lang:platform·id="ocp4.6_or_ocp4.7">
133 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
134 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-node_is_ocp4_master_node:def:1"/> 
135 ······</cpe-lang:logical-test> 
136 ····</cpe-lang:platform> 
137 ····<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.12_or_ocp4.13"> 
138 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
139 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
140 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/> 
141 ········</cpe-lang:logical-test> 
142 ········<cpe-lang:logical-test·operator="OR"·negate="false">117 ······<cpe-lang:logical-test·operator="OR"·negate="false">
143 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_12:def:1"/>118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/>
144 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_13:def:1"/>119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_7:def:1"/>
145 ········</cpe-lang:logical-test> 
146 ······</cpe-lang:logical-test>120 ······</cpe-lang:logical-test>
147 ····</cpe-lang:platform>121 ····</cpe-lang:platform>
148 ····<cpe-lang:platform·id="ocp4.6_or_ocp4.7_or_ocp4.8">122 ····<cpe-lang:platform·id="ocp4.6_or_ocp4.7_or_ocp4.8">
149 ······<cpe-lang:logical-test·operator="OR"·negate="false">123 ······<cpe-lang:logical-test·operator="OR"·negate="false">
150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/>124 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/>
151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_7:def:1"/>125 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_7:def:1"/>
152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_8:def:1"/>126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_8:def:1"/>
153 ······</cpe-lang:logical-test>127 ······</cpe-lang:logical-test>
154 ····</cpe-lang:platform>128 ····</cpe-lang:platform>
155 ····<cpe-lang:platform·id="ocp4-on-azure">129 ····<cpe-lang:platform·id="not_s390x_arch_and_ocp4-node">
156 ······<cpe-lang:logical-test·operator="AND"·negate="false">130 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_azure:def:1"/>132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node:def:1"/>
158 ······</cpe-lang:logical-test>133 ······</cpe-lang:logical-test>
159 ····</cpe-lang:platform>134 ····</cpe-lang:platform>
160 ····<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.6_or_ocp4.7_or_ocp4.8">135 ····<cpe-lang:platform·id="not_ocp4-on-hypershift">
 136 ······<cpe-lang:logical-test·operator="AND"·negate="true">
 137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift:def:1"/>
 138 ······</cpe-lang:logical-test>
 139 ····</cpe-lang:platform>
 140 ····<cpe-lang:platform·id="not_ocp4-on-hypershift_and_not_ocp4-on-hypershift-hosted">
161 ······<cpe-lang:logical-test·operator="AND"·negate="false">141 ······<cpe-lang:logical-test·operator="AND"·negate="false">
162 ········<cpe-lang:logical-test·operator="AND"·negate="true">142 ········<cpe-lang:logical-test·operator="AND"·negate="true">
163 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>143 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift:def:1"/>
164 ········</cpe-lang:logical-test>144 ········</cpe-lang:logical-test>
165 ········<cpe-lang:logical-test·operator="OR"·negate="false">145 ········<cpe-lang:logical-test·operator="AND"·negate="true">
166 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/>146 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>
167 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_7:def:1"/> 
168 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_8:def:1"/> 
169 ········</cpe-lang:logical-test>147 ········</cpe-lang:logical-test>
170 ······</cpe-lang:logical-test>148 ······</cpe-lang:logical-test>
171 ····</cpe-lang:platform>149 ····</cpe-lang:platform>
172 ····<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.6">150 ····<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.8_or_ocp4.9">
173 ······<cpe-lang:logical-test·operator="AND"·negate="false">151 ······<cpe-lang:logical-test·operator="AND"·negate="false">
174 ········<cpe-lang:logical-test·operator="AND"·negate="true">152 ········<cpe-lang:logical-test·operator="AND"·negate="true">
175 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>153 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>
176 ········</cpe-lang:logical-test>154 ········</cpe-lang:logical-test>
Max diff block lines reached; 13590/27713 bytes (49.04%) of diff not shown.
8.75 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ds.xml
8.75 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ds.xml
Max HTML report size reached
2.11 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ocil.xml
2.11 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ocil.xml
Max HTML report size reached
6.49 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-xccdf.xml
6.49 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-xccdf.xml
Max HTML report size reached
9.94 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ds.xml
9.94 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ds.xml
Max HTML report size reached
2.49 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ocil.xml
2.49 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ocil.xml
Max HTML report size reached
7.15 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-xccdf.xml
7.15 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-xccdf.xml
Max HTML report size reached
7.96 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ds.xml
7.96 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ds.xml
Max HTML report size reached
1.95 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ocil.xml
1.95 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ocil.xml
Max HTML report size reached
5.79 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-xccdf.xml
5.79 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-xccdf.xml
Max HTML report size reached
1.58 MB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ds.xml
1.58 MB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openembedded-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openembedded-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-cpe-dictionary.xml"·timestamp="2024-11-02T06:39:34">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-cpe-dictionary.xml"·timestamp="2024-11-03T08:39:34">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:harden:">28 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:harden:">
29 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Harden·distribution</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Harden·distribution</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_oeharden:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_oeharden:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:nodistro:">32 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:nodistro:">
33 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·nodistro</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·nodistro</cpe-dict:title>
Offset 39, 17 lines modifiedOffset 39, 17 lines modified
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:poky:">40 ······<cpe-dict:cpe-item·name="cpe:/o:openembedded:poky:">
41 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Poky·reference·distribution</cpe-dict:title>41 ········<cpe-dict:title·xml:lang="en-us">OpenEmbedded·Poky·reference·distribution</cpe-dict:title>
42 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_poky:def:1</cpe-dict:check>42 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml">oval:ssg-installed_OS_is_poky:def:1</cpe-dict:check>
43 ······</cpe-dict:cpe-item>43 ······</cpe-dict:cpe-item>
44 ····</cpe-dict:cpe-list>44 ····</cpe-dict:cpe-list>
45 ··</ds:component>45 ··</ds:component>
46 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-xccdf.xml"·timestamp="2024-11-02T06:39:34">46 ··<ds:component·id="scap_org.open-scap_comp_ssg-openembedded-xccdf.xml"·timestamp="2024-11-03T08:39:34">
47 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEMBEDDED"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">47 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEMBEDDED"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
48 ······<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>48 ······<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
49 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·OpenEmbedded</xccdf-1.2:title>49 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·OpenEmbedded</xccdf-1.2:title>
50 ······<xccdf-1.2:description>50 ······<xccdf-1.2:description>
51 ········This·guide·presents·a·catalog·of·security-relevant51 ········This·guide·presents·a·catalog·of·security-relevant
52 configuration·settings·for·OpenEmbedded.·It·is·a·rendering·of52 configuration·settings·for·OpenEmbedded.·It·is·a·rendering·of
53 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)53 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
54 in·order·to·support·security·automation.··The·SCAP·content·is54 in·order·to·support·security·automation.··The·SCAP·content·is
55 is·available·in·the55 is·available·in·the
Offset 116, 200 lines modifiedOffset 116, 200 lines modified
116 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>116 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
117 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>117 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
118 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>118 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
119 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>119 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
120 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>120 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
121 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>121 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
122 ······<cpe-lang:platform-specification>122 ······<cpe-lang:platform-specification>
123 ········<cpe-lang:platform·id="package_shadow-utils">123 ········<cpe-lang:platform·id="ipv6_enabled">
124 ··········<cpe-lang:logical-test·operator="AND"·negate="false">124 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
125 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>125 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
126 ··········</cpe-lang:logical-test>126 ··········</cpe-lang:logical-test>
127 ········</cpe-lang:platform>127 ········</cpe-lang:platform>
128 ········<cpe-lang:platform·id="aarch64_arch">128 ········<cpe-lang:platform·id="package_dnf">
129 ··········<cpe-lang:logical-test·operator="AND"·negate="false">129 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_dnf:def:1"/>
131 ··········</cpe-lang:logical-test>131 ··········</cpe-lang:logical-test>
132 ········</cpe-lang:platform>132 ········</cpe-lang:platform>
133 ········<cpe-lang:platform·id="machine">133 ········<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
134 ··········<cpe-lang:logical-test·operator="AND"·negate="false">134 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
 135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>136 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
136 ··········</cpe-lang:logical-test>137 ··········</cpe-lang:logical-test>
137 ········</cpe-lang:platform>138 ········</cpe-lang:platform>
138 ········<cpe-lang:platform·id="x86_64_arch">139 ········<cpe-lang:platform·id="grub2">
139 ··········<cpe-lang:logical-test·operator="AND"·negate="false">140 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>141 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
141 ··········</cpe-lang:logical-test>142 ··········</cpe-lang:logical-test>
142 ········</cpe-lang:platform>143 ········</cpe-lang:platform>
143 ········<cpe-lang:platform·id="package_logrotate">144 ········<cpe-lang:platform·id="machine">
144 ··········<cpe-lang:logical-test·operator="AND"·negate="false">145 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
145 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
146 ··········</cpe-lang:logical-test>147 ··········</cpe-lang:logical-test>
147 ········</cpe-lang:platform>148 ········</cpe-lang:platform>
148 ········<cpe-lang:platform·id="package_sudo">149 ········<cpe-lang:platform·id="package_iptables">
149 ··········<cpe-lang:logical-test·operator="AND"·negate="false">150 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
150 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
151 ··········</cpe-lang:logical-test>152 ··········</cpe-lang:logical-test>
152 ········</cpe-lang:platform>153 ········</cpe-lang:platform>
153 ········<cpe-lang:platform·id="machine_and_package_ufw">154 ········<cpe-lang:platform·id="machine_and_package_ufw">
154 ··········<cpe-lang:logical-test·operator="AND"·negate="false">155 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
155 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>157 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
157 ··········</cpe-lang:logical-test>158 ··········</cpe-lang:logical-test>
158 ········</cpe-lang:platform>159 ········</cpe-lang:platform>
159 ········<cpe-lang:platform·id="not_aarch64_arch">160 ········<cpe-lang:platform·id="not_aarch64_arch">
160 ··········<cpe-lang:logical-test·operator="AND"·negate="true">161 ··········<cpe-lang:logical-test·operator="AND"·negate="true">
161 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>162 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
162 ··········</cpe-lang:logical-test>163 ··········</cpe-lang:logical-test>
163 ········</cpe-lang:platform>164 ········</cpe-lang:platform>
 165 ········<cpe-lang:platform·id="machine_and_not_rhcos4-rhel9_and_service_disabled_nftables_and_service_disabled_ufw">
 166 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 167 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 168 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_OS_is_rhcos4_rhel9:def:1"/>
 169 ············</cpe-lang:logical-test>
 170 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
 171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_nftables:def:1"/>
 172 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>
 173 ··········</cpe-lang:logical-test>
 174 ········</cpe-lang:platform>
164 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">175 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
165 ··········<cpe-lang:logical-test·operator="AND"·negate="false">176 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
166 ············<cpe-lang:logical-test·operator="AND"·negate="true">177 ············<cpe-lang:logical-test·operator="AND"·negate="true">
167 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>178 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
168 ············</cpe-lang:logical-test>179 ············</cpe-lang:logical-test>
169 ············<cpe-lang:logical-test·operator="AND"·negate="true">180 ············<cpe-lang:logical-test·operator="AND"·negate="true">
170 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>181 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
171 ············</cpe-lang:logical-test>182 ············</cpe-lang:logical-test>
172 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>183 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
173 ··········</cpe-lang:logical-test>184 ··········</cpe-lang:logical-test>
174 ········</cpe-lang:platform>185 ········</cpe-lang:platform>
175 ········<cpe-lang:platform·id="package_firewalld"> 
176 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
177 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
178 ··········</cpe-lang:logical-test> 
179 ········</cpe-lang:platform> 
180 ········<cpe-lang:platform·id="package_systemd"> 
181 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
182 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/> 
183 ··········</cpe-lang:logical-test> 
184 ········</cpe-lang:platform> 
185 ········<cpe-lang:platform·id="wifi-iface"> 
186 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
187 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/> 
188 ··········</cpe-lang:logical-test> 
189 ········</cpe-lang:platform> 
190 ········<cpe-lang:platform·id="machine_and_package_squid">186 ········<cpe-lang:platform·id="machine_and_package_snmpd">
191 ··········<cpe-lang:logical-test·operator="AND"·negate="false">187 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
192 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>188 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
193 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>189 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>
194 ··········</cpe-lang:logical-test>190 ··········</cpe-lang:logical-test>
195 ········</cpe-lang:platform>191 ········</cpe-lang:platform>
196 ········<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">192 ········<cpe-lang:platform·id="package_pam">
197 ··········<cpe-lang:logical-test·operator="OR"·negate="false">193 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
Max diff block lines reached; 1638803/1652091 bytes (99.20%) of diff not shown.
899 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ocil.xml
899 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ocil.xml
Ordering differences only
    
Offset 3, 4793 lines modifiedOffset 3, 4793 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_writable_hooks_ocil:questionnaire:1"> 
11 ······<ocil:title>Disable·mutable·hooks</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_group_ocil:questionnaire:1">
 11 ······<ocil:title>Verify·User·Who·Owns·Backup·group·File</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_writable_hooks_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_group_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-coredump_disable_backtraces_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1">
17 ······<ocil:title>Disable·core·dump·backtraces</ocil:title>17 ······<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-coredump_disable_backtraces_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_all_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_ocil:questionnaire:1">
23 ······<ocil:title>Enable·automatic·signing·of·all·modules</ocil:title>23 ······<ocil:title>Disable·IPv6·Addressing·on·All·IPv6·Interfaces</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_all_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_groupownership_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_ocil:questionnaire:1">
29 ······<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·Group</ocil:title>29 ······<ocil:title>Disable·SSH·Support·for·.rhosts·Files</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_groupownership_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_crontab_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_group_ocil:questionnaire:1">
35 ······<ocil:title>Verify·Permissions·on·crontab</ocil:title>35 ······<ocil:title>Verify·Group·Who·Owns·Backup·group·File</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_permissions_crontab_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_group_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_panic_on_oops_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_icmp_ignore_bogus_error_responses_ocil:questionnaire:1">
41 ······<ocil:title>Kernel·panic·on·oops</ocil:title>41 ······<ocil:title>Enable·Kernel·Parameter·to·Ignore·Bogus·ICMP·Error·Responses·on·IPv4·Interfaces</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_panic_on_oops_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_icmp_ignore_bogus_error_responses_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-file_cron_deny_not_exist_ocil:questionnaire:1"> 
47 ······<ocil:title>Ensure·that·/etc/cron.deny·does·not·exist</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_minclass_ocil:questionnaire:1">
 47 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Different·Categories</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-file_cron_deny_not_exist_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_minclass_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_monthly_ocil:questionnaire:1"> 
53 ······<ocil:title>Verify·Group·Who·Owns·cron.monthly</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_list_ocil:questionnaire:1">
 53 ······<ocil:title>Enable·checks·on·linked·list·manipulation</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_monthly_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_list_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1"> 
59 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·setxattr</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-sudo_custom_logfile_ocil:questionnaire:1">
 59 ······<ocil:title>Ensure·Sudo·Logfile·Exists·-·sudo·logfile</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_setxattr_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sudo_custom_logfile_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_acpi_custom_method_ocil:questionnaire:1"> 
65 ······<ocil:title>Do·not·allow·ACPI·methods·to·be·inserted/replaced·at·run·time</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_var_log_messages_ocil:questionnaire:1">
 65 ······<ocil:title>Verify·Permissions·on·/var/log/messages·File</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-kernel_config_acpi_custom_method_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_permissions_var_log_messages_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_suid_dumpable_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_issue_ocil:questionnaire:1">
71 ······<ocil:title>Disable·Core·Dumps·for·SUID·programs</ocil:title>71 ······<ocil:title>Verify·Group·Ownership·of·System·Login·Banner</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_suid_dumpable_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_issue_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sudo_vdsm_nopasswd_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-accounts_polyinstantiated_var_tmp_ocil:questionnaire:1">
77 ······<ocil:title>Only·the·VDSM·User·Can·Use·sudo·NOPASSWD</ocil:title>77 ······<ocil:title>Configure·Polyinstantiation·of·/var/tmp·Directories</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sudo_vdsm_nopasswd_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_var_tmp_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_sshd_private_key_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-file_cron_deny_not_exist_ocil:questionnaire:1">
83 ······<ocil:title>Verify·Group·Ownership·on·SSH·Server·Private·*_key·Key·Files</ocil:title>83 ······<ocil:title>Ensure·that·/etc/cron.deny·does·not·exist</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_sshd_private_key_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_cron_deny_not_exist_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_warning_banner_net_ocil:questionnaire:1">
89 ······<ocil:title>Ensure·syslog-ng·is·Installed</ocil:title>89 ······<ocil:title>Enable·SSH·Warning·Banner</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_net_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1"> 
95 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·!authenticate</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_passwd_ocil:questionnaire:1">
 95 ······<ocil:title>Verify·Permissions·on·passwd·File</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-sudo_remove_no_authenticate_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_passwd_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_use_pty_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-sudoers_no_root_target_ocil:questionnaire:1">
101 ······<ocil:title>Ensure·Only·Users·Logged·In·To·Real·tty·Can·Execute·Sudo·-·sudo·use_pty</ocil:title>101 ······<ocil:title>Don't·target·root·user·in·the·sudoers·file</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-sudo_add_use_pty_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-sudoers_no_root_target_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1"> 
107 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·chown</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_passwd_ocil:questionnaire:1">
 107 ······<ocil:title>Verify·Group·Who·Owns·Backup·passwd·File</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_unmap_kernel_at_el0_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_ocil:questionnaire:1">
113 ······<ocil:title>Unmap·kernel·when·running·in·userspace·(aka·KAISER)</ocil:title>113 ······<ocil:title>Disable·Accepting·Router·Advertisements·on·all·IPv6·Interfaces·by·Default</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-kernel_config_unmap_kernel_at_el0_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-service_sshd_disabled_ocil:questionnaire:1"> 
119 ······<ocil:title>Disable·SSH·Server·If·Possible</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_systemauth_ocil:questionnaire:1">
 119 ······<ocil:title>Set·PAM''s·Password·Hashing·Algorithm</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-service_sshd_disabled_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_systemauth_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 908356/920780 bytes (98.65%) of diff not shown.
655 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-xccdf.xml
655 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_OPENEMBEDDED"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_OPENEMBEDDED"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·OpenEmbedded</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·OpenEmbedded</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·OpenEmbedded.·It·is·a·rendering·of7 configuration·settings·for·OpenEmbedded.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
Offset 71, 200 lines modifiedOffset 71, 200 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="package_shadow-utils">78 ····<cpe-lang:platform·id="ipv6_enabled">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
81 ······</cpe-lang:logical-test>81 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>82 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="aarch64_arch">83 ····<cpe-lang:platform·id="package_dnf">
84 ······<cpe-lang:logical-test·operator="AND"·negate="false">84 ······<cpe-lang:logical-test·operator="AND"·negate="false">
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_dnf:def:1"/>
86 ······</cpe-lang:logical-test>86 ······</cpe-lang:logical-test>
87 ····</cpe-lang:platform>87 ····</cpe-lang:platform>
88 ····<cpe-lang:platform·id="machine">88 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
89 ······<cpe-lang:logical-test·operator="AND"·negate="false">89 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
91 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
92 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
93 ····<cpe-lang:platform·id="x86_64_arch">94 ····<cpe-lang:platform·id="grub2">
94 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
96 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
97 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
98 ····<cpe-lang:platform·id="package_logrotate">99 ····<cpe-lang:platform·id="machine">
99 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
101 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
102 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
103 ····<cpe-lang:platform·id="package_sudo">104 ····<cpe-lang:platform·id="package_iptables">
104 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
106 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
107 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
108 ····<cpe-lang:platform·id="machine_and_package_ufw">109 ····<cpe-lang:platform·id="machine_and_package_ufw">
109 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
112 ······</cpe-lang:logical-test>113 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>114 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="not_aarch64_arch">115 ····<cpe-lang:platform·id="not_aarch64_arch">
115 ······<cpe-lang:logical-test·operator="AND"·negate="true">116 ······<cpe-lang:logical-test·operator="AND"·negate="true">
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
117 ······</cpe-lang:logical-test>118 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>119 ····</cpe-lang:platform>
 120 ····<cpe-lang:platform·id="machine_and_not_rhcos4-rhel9_and_service_disabled_nftables_and_service_disabled_ufw">
 121 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 122 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 123 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_OS_is_rhcos4_rhel9:def:1"/>
 124 ········</cpe-lang:logical-test>
 125 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
 126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_nftables:def:1"/>
 127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>
 128 ······</cpe-lang:logical-test>
 129 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">130 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">131 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:logical-test·operator="AND"·negate="true">132 ········<cpe-lang:logical-test·operator="AND"·negate="true">
122 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>133 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
123 ········</cpe-lang:logical-test>134 ········</cpe-lang:logical-test>
124 ········<cpe-lang:logical-test·operator="AND"·negate="true">135 ········<cpe-lang:logical-test·operator="AND"·negate="true">
125 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>136 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
126 ········</cpe-lang:logical-test>137 ········</cpe-lang:logical-test>
127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
128 ······</cpe-lang:logical-test>139 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>140 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="package_firewalld"> 
131 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
133 ······</cpe-lang:logical-test> 
134 ····</cpe-lang:platform> 
135 ····<cpe-lang:platform·id="package_systemd"> 
136 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/> 
138 ······</cpe-lang:logical-test> 
139 ····</cpe-lang:platform> 
140 ····<cpe-lang:platform·id="wifi-iface"> 
141 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/> 
143 ······</cpe-lang:logical-test> 
144 ····</cpe-lang:platform> 
145 ····<cpe-lang:platform·id="machine_and_package_squid">141 ····<cpe-lang:platform·id="machine_and_package_snmpd">
146 ······<cpe-lang:logical-test·operator="AND"·negate="false">142 ······<cpe-lang:logical-test·operator="AND"·negate="false">
147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_squid:def:1"/>144 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>
149 ······</cpe-lang:logical-test>145 ······</cpe-lang:logical-test>
150 ····</cpe-lang:platform>146 ····</cpe-lang:platform>
151 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">147 ····<cpe-lang:platform·id="package_pam">
152 ······<cpe-lang:logical-test·operator="OR"·negate="false">148 ······<cpe-lang:logical-test·operator="AND"·negate="false">
153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
155 ······</cpe-lang:logical-test>150 ······</cpe-lang:logical-test>
156 ····</cpe-lang:platform>151 ····</cpe-lang:platform>
157 ····<cpe-lang:platform·id="package_gdm">152 ····<cpe-lang:platform·id="package_firewalld">
158 ······<cpe-lang:logical-test·operator="AND"·negate="false">153 ······<cpe-lang:logical-test·operator="AND"·negate="false">
159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
160 ······</cpe-lang:logical-test>155 ······</cpe-lang:logical-test>
161 ····</cpe-lang:platform>156 ····</cpe-lang:platform>
162 ····<cpe-lang:platform·id="package_postfix">157 ····<cpe-lang:platform·id="package_logrotate">
163 ······<cpe-lang:logical-test·operator="AND"·negate="false">158 ······<cpe-lang:logical-test·operator="AND"·negate="false">
164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
165 ······</cpe-lang:logical-test>160 ······</cpe-lang:logical-test>
166 ····</cpe-lang:platform>161 ····</cpe-lang:platform>
167 ····<cpe-lang:platform·id="machine_and_not_rhcos4-rhel9_and_service_disabled_nftables_and_service_disabled_ufw">162 ····<cpe-lang:platform·id="package_audit">
168 ······<cpe-lang:logical-test·operator="AND"·negate="false">163 ······<cpe-lang:logical-test·operator="AND"·negate="false">
169 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
170 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_OS_is_rhcos4_rhel9:def:1"/> 
171 ········</cpe-lang:logical-test> 
172 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
173 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_nftables:def:1"/> 
174 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>
175 ······</cpe-lang:logical-test>165 ······</cpe-lang:logical-test>
Max diff block lines reached; 657497/670944 bytes (98.00%) of diff not shown.
1000 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ds.xml
1000 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-openeuler2203-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-openeuler2203-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-cpe-dictionary.xml"·timestamp="2024-11-02T06:39:34">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-cpe-dictionary.xml"·timestamp="2024-11-03T08:39:34">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS:ga:server">28 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS:ga:server">
29 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP1:ga:server">32 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP1:ga:server">
33 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP1</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP1</cpe-dict:title>
Offset 35, 17 lines modifiedOffset 35, 17 lines modified
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP2:ga:server">36 ······<cpe-dict:cpe-item·name="cpe:/o:openEuler:openEuler:22.03LTS_SP2:ga:server">
37 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP2</cpe-dict:title>37 ········<cpe-dict:title·xml:lang="en-us">openEuler·22.03·LTS·SP2</cpe-dict:title>
38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check>38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml">oval:ssg-installed_OS_is_openeuler2203:def:1</cpe-dict:check>
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ····</cpe-dict:cpe-list>40 ····</cpe-dict:cpe-list>
41 ··</ds:component>41 ··</ds:component>
42 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-xccdf.xml"·timestamp="2024-11-02T06:39:34">42 ··<ds:component·id="scap_org.open-scap_comp_ssg-openeuler2203-xccdf.xml"·timestamp="2024-11-03T08:39:34">
43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEULER2203"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENEULER2203"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
44 ······<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>44 ······<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openEuler·2203</xccdf-1.2:title>45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openEuler·2203</xccdf-1.2:title>
46 ······<xccdf-1.2:description>46 ······<xccdf-1.2:description>
47 ········This·guide·presents·a·catalog·of·security-relevant47 ········This·guide·presents·a·catalog·of·security-relevant
48 configuration·settings·for·openEuler·2203.·It·is·a·rendering·of48 configuration·settings·for·openEuler·2203.·It·is·a·rendering·of
49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
50 in·order·to·support·security·automation.··The·SCAP·content·is50 in·order·to·support·security·automation.··The·SCAP·content·is
51 is·available·in·the51 is·available·in·the
Offset 112, 146 lines modifiedOffset 112, 146 lines modified
112 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>112 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
113 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>113 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
114 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>114 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
115 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>115 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
116 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>116 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
117 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>117 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
118 ······<cpe-lang:platform-specification>118 ······<cpe-lang:platform-specification>
119 ········<cpe-lang:platform·id="package_shadow-utils">119 ········<cpe-lang:platform·id="ipv6_enabled">
120 ··········<cpe-lang:logical-test·operator="AND"·negate="false">120 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
121 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>121 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
122 ··········</cpe-lang:logical-test>122 ··········</cpe-lang:logical-test>
123 ········</cpe-lang:platform>123 ········</cpe-lang:platform>
124 ········<cpe-lang:platform·id="package_ntp">124 ········<cpe-lang:platform·id="package_dnf">
125 ··········<cpe-lang:logical-test·operator="AND"·negate="false">125 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
126 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>126 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_dnf:def:1"/>
127 ··········</cpe-lang:logical-test>127 ··········</cpe-lang:logical-test>
128 ········</cpe-lang:platform>128 ········</cpe-lang:platform>
129 ········<cpe-lang:platform·id="machine_and_package_nftables_and_service_disabled_firewalld">129 ········<cpe-lang:platform·id="grub2">
130 ··········<cpe-lang:logical-test·operator="AND"·negate="false">130 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
132 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
133 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
134 ··········</cpe-lang:logical-test>132 ··········</cpe-lang:logical-test>
135 ········</cpe-lang:platform>133 ········</cpe-lang:platform>
136 ········<cpe-lang:platform·id="machine">134 ········<cpe-lang:platform·id="machine">
137 ··········<cpe-lang:logical-test·operator="AND"·negate="false">135 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
138 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>136 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
139 ··········</cpe-lang:logical-test>137 ··········</cpe-lang:logical-test>
140 ········</cpe-lang:platform>138 ········</cpe-lang:platform>
141 ········<cpe-lang:platform·id="package_sudo">139 ········<cpe-lang:platform·id="package_iptables">
142 ··········<cpe-lang:logical-test·operator="AND"·negate="false">140 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
143 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>141 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
144 ··········</cpe-lang:logical-test>142 ··········</cpe-lang:logical-test>
145 ········</cpe-lang:platform>143 ········</cpe-lang:platform>
146 ········<cpe-lang:platform·id="not_aarch64_arch">144 ········<cpe-lang:platform·id="not_aarch64_arch">
147 ··········<cpe-lang:logical-test·operator="AND"·negate="true">145 ··········<cpe-lang:logical-test·operator="AND"·negate="true">
148 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
149 ··········</cpe-lang:logical-test>147 ··········</cpe-lang:logical-test>
150 ········</cpe-lang:platform>148 ········</cpe-lang:platform>
 149 ········<cpe-lang:platform·id="package_ntp">
 150 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
 152 ··········</cpe-lang:logical-test>
 153 ········</cpe-lang:platform>
151 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">154 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
152 ··········<cpe-lang:logical-test·operator="AND"·negate="false">155 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
153 ············<cpe-lang:logical-test·operator="AND"·negate="true">156 ············<cpe-lang:logical-test·operator="AND"·negate="true">
154 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>157 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
155 ············</cpe-lang:logical-test>158 ············</cpe-lang:logical-test>
156 ············<cpe-lang:logical-test·operator="AND"·negate="true">159 ············<cpe-lang:logical-test·operator="AND"·negate="true">
157 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>160 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
158 ············</cpe-lang:logical-test>161 ············</cpe-lang:logical-test>
159 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>162 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
160 ··········</cpe-lang:logical-test>163 ··········</cpe-lang:logical-test>
161 ········</cpe-lang:platform>164 ········</cpe-lang:platform>
 165 ········<cpe-lang:platform·id="package_pam">
 166 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 167 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
 168 ··········</cpe-lang:logical-test>
 169 ········</cpe-lang:platform>
162 ········<cpe-lang:platform·id="package_firewalld">170 ········<cpe-lang:platform·id="package_firewalld">
163 ··········<cpe-lang:logical-test·operator="AND"·negate="false">171 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
164 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>172 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
165 ··········</cpe-lang:logical-test>173 ··········</cpe-lang:logical-test>
166 ········</cpe-lang:platform>174 ········</cpe-lang:platform>
167 ········<cpe-lang:platform·id="wifi-iface">175 ········<cpe-lang:platform·id="package_audit">
168 ··········<cpe-lang:logical-test·operator="AND"·negate="false">176 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 177 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>
 178 ··········</cpe-lang:logical-test>
 179 ········</cpe-lang:platform>
 180 ········<cpe-lang:platform·id="machine_and_package_nftables_and_service_disabled_firewalld">
 181 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
169 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>182 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
 183 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 184 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
170 ··········</cpe-lang:logical-test>185 ··········</cpe-lang:logical-test>
171 ········</cpe-lang:platform>186 ········</cpe-lang:platform>
172 ········<cpe-lang:platform·id="non-uefi">187 ········<cpe-lang:platform·id="non-uefi">
173 ··········<cpe-lang:logical-test·operator="AND"·negate="false">188 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
174 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>189 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>
175 ··········</cpe-lang:logical-test>190 ··········</cpe-lang:logical-test>
176 ········</cpe-lang:platform>191 ········</cpe-lang:platform>
177 ········<cpe-lang:platform·id="grub2">192 ········<cpe-lang:platform·id="uefi">
178 ··········<cpe-lang:logical-test·operator="AND"·negate="false">193 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
179 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>194 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
180 ··········</cpe-lang:logical-test>195 ··········</cpe-lang:logical-test>
181 ········</cpe-lang:platform>196 ········</cpe-lang:platform>
182 ········<cpe-lang:platform·id="package_chrony">197 ········<cpe-lang:platform·id="package_sudo">
183 ··········<cpe-lang:logical-test·operator="AND"·negate="false">198 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
184 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>199 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
185 ··········</cpe-lang:logical-test>200 ··········</cpe-lang:logical-test>
186 ········</cpe-lang:platform>201 ········</cpe-lang:platform>
187 ········<cpe-lang:platform·id="machine_and_package_iptables_and_service_disabled_firewalld">202 ········<cpe-lang:platform·id="machine_and_package_iptables_and_service_disabled_firewalld">
Max diff block lines reached; 1014859/1027245 bytes (98.79%) of diff not shown.
528 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ocil.xml
528 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ocil.xml
Ordering differences only
    
Offset 3, 1565 lines modifiedOffset 3, 1565 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_user_known_hosts_ocil:questionnaire:1">
11 ······<ocil:title>Disable·Kernel·Parameter·for·Sending·ICMP·Redirects·on·all·IPv4·Interfaces·by·Default</ocil:title>11 ······<ocil:title>Disable·SSH·Support·for·User·Known·Hosts</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_user_known_hosts_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_weekly_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_allow_ocil:questionnaire:1">
17 ······<ocil:title>Verify·Owner·on·cron.weekly</ocil:title>17 ······<ocil:title>Verify·Permissions·on·/etc/cron.allow·file</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_weekly_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_allow_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-package_openldap-clients_removed_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-grub2_nosmap_argument_absent_ocil:questionnaire:1">
23 ······<ocil:title>Ensure·LDAP·client·is·not·installed</ocil:title>23 ······<ocil:title>Ensure·SMAP·is·not·disabled·during·boot</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-package_openldap-clients_removed_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-grub2_nosmap_argument_absent_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_motd_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_d_ocil:questionnaire:1">
29 ······<ocil:title>Verify·Group·Ownership·of·Message·of·the·Day·Banner</ocil:title>29 ······<ocil:title>Verify·Group·Who·Owns·cron.d</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_motd_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_d_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1">
35 ······<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title>35 ······<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_sudo_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_login_grace_time_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·sudo</ocil:title>41 ······<ocil:title>Ensure·SSH·LoginGraceTime·is·configured</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_sudo_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sshd_set_login_grace_time_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_gshadow_ocil:questionnaire:1">
47 ······<ocil:title>Verify·Owner·on·cron.monthly</ocil:title>47 ······<ocil:title>Verify·Permissions·on·gshadow·File</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-file_owner_cron_monthly_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_gshadow_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_sysrq_ocil:questionnaire:1">
53 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Secure·ICMP·Redirects·on·all·IPv4·Interfaces</ocil:title>53 ······<ocil:title>Disallow·magic·SysRq·key</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_sysrq_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-set_password_hashing_algorithm_passwordauth_ocil:questionnaire:1"> 
59 ······<ocil:title>Set·PAM''s·Password·Hashing·Algorithm·-·password-auth</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_num_logs_ocil:questionnaire:1">
 59 ······<ocil:title>Configure·auditd·Number·of·Logs·Retained</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_passwordauth_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_num_logs_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sshd_allow_only_protocol2_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_at_allow_ocil:questionnaire:1">
65 ······<ocil:title>Allow·Only·SSH·Protocol·2</ocil:title>65 ······<ocil:title>Verify·Group·Who·Owns·/etc/at.allow·file</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sshd_allow_only_protocol2_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_at_allow_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_passwd_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_ocil:questionnaire:1">
71 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/passwd</ocil:title>71 ······<ocil:title>Configure·auditd·Max·Log·File·Size</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_passwd_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_error_action_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-file_owner_at_allow_ocil:questionnaire:1">
77 ······<ocil:title>Configure·auditd·Disk·Error·Action·on·Disk·Error</ocil:title>77 ······<ocil:title>Verify·User·Who·Owns·/etc/at.allow·file</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-file_owner_at_allow_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-file_owner_backup_etc_group_ocil:questionnaire:1"> 
83 ······<ocil:title>Verify·User·Who·Owns·Backup·group·File</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-service_rsyslog_enabled_ocil:questionnaire:1">
 83 ······<ocil:title>Enable·rsyslog·Service</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_group_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-service_rsyslog_enabled_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-grub2_uefi_password_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-xwindows_remove_packages_ocil:questionnaire:1">
89 ······<ocil:title>Set·the·UEFI·Boot·Loader·Password</ocil:title>89 ······<ocil:title>Disable·graphical·user·interface</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-grub2_uefi_password_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-xwindows_remove_packages_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-service_crond_enabled_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_immutable_ocil:questionnaire:1">
95 ······<ocil:title>Enable·cron·Service</ocil:title>95 ······<ocil:title>Make·the·auditd·Configuration·Immutable</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-service_crond_enabled_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_immutable_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-service_nfs_disabled_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_cron_daily_ocil:questionnaire:1">
101 ······<ocil:title>Disable·Network·File·System·(nfs)</ocil:title>101 ······<ocil:title>Verify·Group·Who·Owns·cron.daily</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-service_nfs_disabled_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_cron_daily_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-service_rsyslog_enabled_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1">
107 ······<ocil:title>Enable·rsyslog·Service</ocil:title>107 ······<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-service_rsyslog_enabled_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_logging_configured_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-selinux_state_ocil:questionnaire:1">
113 ······<ocil:title>Ensure·logging·is·configured</ocil:title>113 ······<ocil:title>Ensure·SELinux·State·is·Enforcing</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-rsyslog_logging_configured_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-grub2_audit_argument_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-grub2_uefi_password_ocil:questionnaire:1">
119 ······<ocil:title>Enable·Auditing·for·Processes·Which·Start·Prior·to·the·Audit·Daemon</ocil:title>119 ······<ocil:title>Set·the·UEFI·Boot·Loader·Password</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-grub2_audit_argument_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-grub2_uefi_password_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_hardlinks_ocil:questionnaire:1">124 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_logging_configured_ocil:questionnaire:1">
125 ······<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Hardlinks</ocil:title>125 ······<ocil:title>Ensure·logging·is·configured</ocil:title>
126 ······<ocil:actions>126 ······<ocil:actions>
127 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_hardlinks_action:testaction:1</ocil:test_action_ref>127 ········<ocil:test_action_ref>ocil:ssg-rsyslog_logging_configured_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 528459/540843 bytes (97.71%) of diff not shown.
439 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-xccdf.xml
439 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_OPENEULER2203"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_OPENEULER2203"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openEuler·2203</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openEuler·2203</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·openEuler·2203.·It·is·a·rendering·of7 configuration·settings·for·openEuler·2203.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
Offset 71, 146 lines modifiedOffset 71, 146 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="package_shadow-utils">78 ····<cpe-lang:platform·id="ipv6_enabled">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
81 ······</cpe-lang:logical-test>81 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>82 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="package_ntp">83 ····<cpe-lang:platform·id="package_dnf">
84 ······<cpe-lang:logical-test·operator="AND"·negate="false">84 ······<cpe-lang:logical-test·operator="AND"·negate="false">
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_dnf:def:1"/>
86 ······</cpe-lang:logical-test>86 ······</cpe-lang:logical-test>
87 ····</cpe-lang:platform>87 ····</cpe-lang:platform>
88 ····<cpe-lang:platform·id="machine_and_package_nftables_and_service_disabled_firewalld">88 ····<cpe-lang:platform·id="grub2">
89 ······<cpe-lang:logical-test·operator="AND"·negate="false">89 ······<cpe-lang:logical-test·operator="AND"·negate="false">
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
93 ······</cpe-lang:logical-test>91 ······</cpe-lang:logical-test>
94 ····</cpe-lang:platform>92 ····</cpe-lang:platform>
95 ····<cpe-lang:platform·id="machine">93 ····<cpe-lang:platform·id="machine">
96 ······<cpe-lang:logical-test·operator="AND"·negate="false">94 ······<cpe-lang:logical-test·operator="AND"·negate="false">
97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
98 ······</cpe-lang:logical-test>96 ······</cpe-lang:logical-test>
99 ····</cpe-lang:platform>97 ····</cpe-lang:platform>
100 ····<cpe-lang:platform·id="package_sudo">98 ····<cpe-lang:platform·id="package_iptables">
101 ······<cpe-lang:logical-test·operator="AND"·negate="false">99 ······<cpe-lang:logical-test·operator="AND"·negate="false">
102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
103 ······</cpe-lang:logical-test>101 ······</cpe-lang:logical-test>
104 ····</cpe-lang:platform>102 ····</cpe-lang:platform>
105 ····<cpe-lang:platform·id="not_aarch64_arch">103 ····<cpe-lang:platform·id="not_aarch64_arch">
106 ······<cpe-lang:logical-test·operator="AND"·negate="true">104 ······<cpe-lang:logical-test·operator="AND"·negate="true">
107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
108 ······</cpe-lang:logical-test>106 ······</cpe-lang:logical-test>
109 ····</cpe-lang:platform>107 ····</cpe-lang:platform>
 108 ····<cpe-lang:platform·id="package_ntp">
 109 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
 111 ······</cpe-lang:logical-test>
 112 ····</cpe-lang:platform>
110 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">113 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
111 ······<cpe-lang:logical-test·operator="AND"·negate="false">114 ······<cpe-lang:logical-test·operator="AND"·negate="false">
112 ········<cpe-lang:logical-test·operator="AND"·negate="true">115 ········<cpe-lang:logical-test·operator="AND"·negate="true">
113 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>116 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
114 ········</cpe-lang:logical-test>117 ········</cpe-lang:logical-test>
115 ········<cpe-lang:logical-test·operator="AND"·negate="true">118 ········<cpe-lang:logical-test·operator="AND"·negate="true">
116 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>119 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
117 ········</cpe-lang:logical-test>120 ········</cpe-lang:logical-test>
118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
119 ······</cpe-lang:logical-test>122 ······</cpe-lang:logical-test>
120 ····</cpe-lang:platform>123 ····</cpe-lang:platform>
 124 ····<cpe-lang:platform·id="package_pam">
 125 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
 127 ······</cpe-lang:logical-test>
 128 ····</cpe-lang:platform>
121 ····<cpe-lang:platform·id="package_firewalld">129 ····<cpe-lang:platform·id="package_firewalld">
122 ······<cpe-lang:logical-test·operator="AND"·negate="false">130 ······<cpe-lang:logical-test·operator="AND"·negate="false">
123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
124 ······</cpe-lang:logical-test>132 ······</cpe-lang:logical-test>
125 ····</cpe-lang:platform>133 ····</cpe-lang:platform>
126 ····<cpe-lang:platform·id="wifi-iface">134 ····<cpe-lang:platform·id="package_audit">
127 ······<cpe-lang:logical-test·operator="AND"·negate="false">135 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>
 137 ······</cpe-lang:logical-test>
 138 ····</cpe-lang:platform>
 139 ····<cpe-lang:platform·id="machine_and_package_nftables_and_service_disabled_firewalld">
 140 ······<cpe-lang:logical-test·operator="AND"·negate="false">
128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
 142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
129 ······</cpe-lang:logical-test>144 ······</cpe-lang:logical-test>
130 ····</cpe-lang:platform>145 ····</cpe-lang:platform>
131 ····<cpe-lang:platform·id="non-uefi">146 ····<cpe-lang:platform·id="non-uefi">
132 ······<cpe-lang:logical-test·operator="AND"·negate="false">147 ······<cpe-lang:logical-test·operator="AND"·negate="false">
133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>
134 ······</cpe-lang:logical-test>149 ······</cpe-lang:logical-test>
135 ····</cpe-lang:platform>150 ····</cpe-lang:platform>
136 ····<cpe-lang:platform·id="grub2">151 ····<cpe-lang:platform·id="uefi">
137 ······<cpe-lang:logical-test·operator="AND"·negate="false">152 ······<cpe-lang:logical-test·operator="AND"·negate="false">
138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
139 ······</cpe-lang:logical-test>154 ······</cpe-lang:logical-test>
140 ····</cpe-lang:platform>155 ····</cpe-lang:platform>
141 ····<cpe-lang:platform·id="package_chrony">156 ····<cpe-lang:platform·id="package_sudo">
142 ······<cpe-lang:logical-test·operator="AND"·negate="false">157 ······<cpe-lang:logical-test·operator="AND"·negate="false">
143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
144 ······</cpe-lang:logical-test>159 ······</cpe-lang:logical-test>
145 ····</cpe-lang:platform>160 ····</cpe-lang:platform>
146 ····<cpe-lang:platform·id="machine_and_package_iptables_and_service_disabled_firewalld">161 ····<cpe-lang:platform·id="machine_and_package_iptables_and_service_disabled_firewalld">
147 ······<cpe-lang:logical-test·operator="AND"·negate="false">162 ······<cpe-lang:logical-test·operator="AND"·negate="false">
148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
151 ······</cpe-lang:logical-test>166 ······</cpe-lang:logical-test>
152 ····</cpe-lang:platform>167 ····</cpe-lang:platform>
153 ····<cpe-lang:platform·id="package_audit"> 
154 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/> 
156 ······</cpe-lang:logical-test> 
157 ····</cpe-lang:platform> 
158 ····<cpe-lang:platform·id="package_pam">168 ····<cpe-lang:platform·id="package_chrony">
159 ······<cpe-lang:logical-test·operator="AND"·negate="false">169 ······<cpe-lang:logical-test·operator="AND"·negate="false">
160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
161 ······</cpe-lang:logical-test>171 ······</cpe-lang:logical-test>
162 ····</cpe-lang:platform>172 ····</cpe-lang:platform>
163 ····<cpe-lang:platform·id="package_bash">173 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">
164 ······<cpe-lang:logical-test·operator="AND"·negate="false">174 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 175 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 176 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 177 ········</cpe-lang:logical-test>
 178 ········<cpe-lang:logical-test·operator="AND"·negate="true">
165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>179 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
Max diff block lines reached; 436482/448980 bytes (97.22%) of diff not shown.
1.11 MB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ds.xml
1.11 MB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-opensuse-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-opensuse-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-cpe-dictionary.xml"·timestamp="2024-11-02T06:39:34">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-cpe-dictionary.xml"·timestamp="2024-11-03T08:39:34">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:15.0">28 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:15.0">
29 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·15.0</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·15.0</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap15:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap15:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.1">32 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.1">
33 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.1</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.1</cpe-dict:title>
Offset 39, 17 lines modifiedOffset 39, 17 lines modified
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.3">40 ······<cpe-dict:cpe-item·name="cpe:/o:opensuse:leap:42.3">
41 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.3</cpe-dict:title>41 ········<cpe-dict:title·xml:lang="en-us">openSUSE·Leap·42.3</cpe-dict:title>
42 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap42:def:1</cpe-dict:check>42 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml">oval:ssg-installed_OS_is_opensuse_leap42:def:1</cpe-dict:check>
43 ······</cpe-dict:cpe-item>43 ······</cpe-dict:cpe-item>
44 ····</cpe-dict:cpe-list>44 ····</cpe-dict:cpe-list>
45 ··</ds:component>45 ··</ds:component>
46 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-xccdf.xml"·timestamp="2024-11-02T06:39:34">46 ··<ds:component·id="scap_org.open-scap_comp_ssg-opensuse-xccdf.xml"·timestamp="2024-11-03T08:39:34">
47 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENSUSE"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">47 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_OPENSUSE"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
48 ······<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>48 ······<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
49 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openSUSE</xccdf-1.2:title>49 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openSUSE</xccdf-1.2:title>
50 ······<xccdf-1.2:description>50 ······<xccdf-1.2:description>
51 ········This·guide·presents·a·catalog·of·security-relevant51 ········This·guide·presents·a·catalog·of·security-relevant
52 configuration·settings·for·openSUSE.·It·is·a·rendering·of52 configuration·settings·for·openSUSE.·It·is·a·rendering·of
53 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)53 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
54 in·order·to·support·security·automation.··The·SCAP·content·is54 in·order·to·support·security·automation.··The·SCAP·content·is
55 is·available·in·the55 is·available·in·the
Offset 116, 42 lines modifiedOffset 116, 33 lines modified
116 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>116 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
117 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>117 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
118 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>118 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
119 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>119 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
120 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>120 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
121 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>121 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
122 ······<cpe-lang:platform-specification>122 ······<cpe-lang:platform-specification>
123 ········<cpe-lang:platform·id="package_shadow-utils">123 ········<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
124 ··········<cpe-lang:logical-test·operator="AND"·negate="false">124 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
125 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>125 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 126 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
126 ··········</cpe-lang:logical-test>127 ··········</cpe-lang:logical-test>
127 ········</cpe-lang:platform>128 ········</cpe-lang:platform>
128 ········<cpe-lang:platform·id="aarch64_arch">129 ········<cpe-lang:platform·id="grub2">
129 ··········<cpe-lang:logical-test·operator="AND"·negate="false">130 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
131 ··········</cpe-lang:logical-test>132 ··········</cpe-lang:logical-test>
132 ········</cpe-lang:platform>133 ········</cpe-lang:platform>
133 ········<cpe-lang:platform·id="machine">134 ········<cpe-lang:platform·id="machine">
134 ··········<cpe-lang:logical-test·operator="AND"·negate="false">135 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>136 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
136 ··········</cpe-lang:logical-test>137 ··········</cpe-lang:logical-test>
137 ········</cpe-lang:platform>138 ········</cpe-lang:platform>
138 ········<cpe-lang:platform·id="x86_64_arch"> 
139 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/> 
141 ··········</cpe-lang:logical-test> 
142 ········</cpe-lang:platform> 
143 ········<cpe-lang:platform·id="package_logrotate"> 
144 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
145 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/> 
146 ··········</cpe-lang:logical-test> 
147 ········</cpe-lang:platform> 
148 ········<cpe-lang:platform·id="package_sudo">139 ········<cpe-lang:platform·id="package_iptables">
149 ··········<cpe-lang:logical-test·operator="AND"·negate="false">140 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
150 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>141 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
151 ··········</cpe-lang:logical-test>142 ··········</cpe-lang:logical-test>
152 ········</cpe-lang:platform>143 ········</cpe-lang:platform>
153 ········<cpe-lang:platform·id="machine_and_package_ufw">144 ········<cpe-lang:platform·id="machine_and_package_ufw">
154 ··········<cpe-lang:logical-test·operator="AND"·negate="false">145 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
155 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>147 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
157 ··········</cpe-lang:logical-test>148 ··········</cpe-lang:logical-test>
Offset 168, 92 lines modifiedOffset 159, 101 lines modified
168 ············</cpe-lang:logical-test>159 ············</cpe-lang:logical-test>
169 ············<cpe-lang:logical-test·operator="AND"·negate="true">160 ············<cpe-lang:logical-test·operator="AND"·negate="true">
170 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>161 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
171 ············</cpe-lang:logical-test>162 ············</cpe-lang:logical-test>
172 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>163 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
173 ··········</cpe-lang:logical-test>164 ··········</cpe-lang:logical-test>
174 ········</cpe-lang:platform>165 ········</cpe-lang:platform>
175 ········<cpe-lang:platform·id="package_systemd"> 
176 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
177 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/> 
178 ··········</cpe-lang:logical-test> 
179 ········</cpe-lang:platform> 
180 ········<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch"> 
181 ··········<cpe-lang:logical-test·operator="OR"·negate="false"> 
182 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
183 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/> 
184 ··········</cpe-lang:logical-test> 
185 ········</cpe-lang:platform> 
186 ········<cpe-lang:platform·id="package_gdm">166 ········<cpe-lang:platform·id="package_pam">
187 ··········<cpe-lang:logical-test·operator="AND"·negate="false">167 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
188 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>168 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
189 ··········</cpe-lang:logical-test>169 ··········</cpe-lang:logical-test>
190 ········</cpe-lang:platform>170 ········</cpe-lang:platform>
191 ········<cpe-lang:platform·id="package_postfix">171 ········<cpe-lang:platform·id="package_logrotate">
192 ··········<cpe-lang:logical-test·operator="AND"·negate="false">172 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
193 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>173 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
194 ··········</cpe-lang:logical-test>174 ··········</cpe-lang:logical-test>
195 ········</cpe-lang:platform>175 ········</cpe-lang:platform>
196 ········<cpe-lang:platform·id="grub2">176 ········<cpe-lang:platform·id="package_audit">
197 ··········<cpe-lang:logical-test·operator="AND"·negate="false">177 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
198 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>178 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>
199 ··········</cpe-lang:logical-test>179 ··········</cpe-lang:logical-test>
200 ········</cpe-lang:platform>180 ········</cpe-lang:platform>
201 ········<cpe-lang:platform·id="package_rsh-server">181 ········<cpe-lang:platform·id="package_sudo">
202 ··········<cpe-lang:logical-test·operator="AND"·negate="false">182 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
203 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>183 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
204 ··········</cpe-lang:logical-test>184 ··········</cpe-lang:logical-test>
205 ········</cpe-lang:platform>185 ········</cpe-lang:platform>
206 ········<cpe-lang:platform·id="package_chrony">186 ········<cpe-lang:platform·id="package_postfix">
207 ··········<cpe-lang:logical-test·operator="AND"·negate="false">187 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
208 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>188 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
209 ··········</cpe-lang:logical-test>189 ··········</cpe-lang:logical-test>
210 ········</cpe-lang:platform>190 ········</cpe-lang:platform>
211 ········<cpe-lang:platform·id="machine_and_package_iptables_and_service_disabled_firewalld">191 ········<cpe-lang:platform·id="machine_and_package_iptables_and_service_disabled_firewalld">
212 ··········<cpe-lang:logical-test·operator="AND"·negate="false">192 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
213 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>193 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
214 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>194 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
215 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>195 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
216 ··········</cpe-lang:logical-test>196 ··········</cpe-lang:logical-test>
Max diff block lines reached; 1148839/1161268 bytes (98.93%) of diff not shown.
646 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ocil.xml
645 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ocil.xml
Ordering differences only
    
Offset 3, 2145 lines modifiedOffset 3, 2145 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sudoers_no_command_negation_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_ocil:questionnaire:1">
11 ······<ocil:title>Don't·define·allowed·commands·in·sudoers·by·means·of·exclusion</ocil:title>11 ······<ocil:title>Configure·auditd·Max·Log·File·Size</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-sudoers_no_command_negation_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1"> 
17 ······<ocil:title>Disallow·Configuration·to·Bypass·Password·Requirements·for·Privilege·Escalation</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-securetty_root_login_console_only_ocil:questionnaire:1">
 17 ······<ocil:title>Restrict·Virtual·Console·Root·Logins</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-disallow_bypass_password_sudo_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-securetty_root_login_console_only_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_files_groupownership_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_gssapi_auth_ocil:questionnaire:1">
23 ······<ocil:title>Ensure·Log·Files·Are·Owned·By·Appropriate·Group</ocil:title>23 ······<ocil:title>Disable·GSSAPI·Authentication</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-rsyslog_files_groupownership_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_gssapi_auth_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_strictmodes_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-accounts_root_gid_zero_ocil:questionnaire:1">
29 ······<ocil:title>Enable·Use·of·Strict·Mode·Checking</ocil:title>29 ······<ocil:title>Verify·Root·Has·A·Primary·GID·0</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_strictmodes_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-accounts_root_gid_zero_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_max_log_file_action_ocil:questionnaire:1"> 
35 ······<ocil:title>Configure·auditd·max_log_file_action·Upon·Reaching·Maximum·Log·Size</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-grub2_disable_recovery_ocil:questionnaire:1">
 35 ······<ocil:title>Disable·Recovery·Booting</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-grub2_disable_recovery_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_kexec_ocil:questionnaire:1">
41 ······<ocil:title>Set·SSH·authentication·attempt·limit</ocil:title>41 ······<ocil:title>Disable·kexec·system·call</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-kernel_config_kexec_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_admin_space_left_action_ocil:questionnaire:1"> 
47 ······<ocil:title>Configure·auditd·admin_space_left·Action·on·Low·Disk·Space</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_x86_vsyscall_emulation_ocil:questionnaire:1">
 47 ······<ocil:title>Disable·x86·vsyscall·emulation</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_admin_space_left_action_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-kernel_config_x86_vsyscall_emulation_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_default_mmap_min_addr_ocil:questionnaire:1"> 
53 ······<ocil:title>Configure·Low·Address·Space·To·Protect·From·User·Allocation</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_sshd_pub_key_ocil:questionnaire:1">
 53 ······<ocil:title>Verify·Ownership·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-kernel_config_default_mmap_min_addr_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-file_ownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-package_openssh-server_installed_ocil:questionnaire:1"> 
59 ······<ocil:title>Install·the·OpenSSH·Server·Package</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_module_sig_key_ocil:questionnaire:1">
 59 ······<ocil:title>Specify·module·signing·key·to·use</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-package_openssh-server_installed_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_key_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-sshd_print_last_log_ocil:questionnaire:1">
65 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lremovexattr</ocil:title>65 ······<ocil:title>Enable·SSH·Print·Last·Log</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lremovexattr_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sshd_print_last_log_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_ocil:questionnaire:1"> 
71 ······<ocil:title>Ensure·Rsyslog·Authenticates·Off-Loaded·Audit·Records</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_stime_ocil:questionnaire:1">
 71 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·stime</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_stime_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-service_cron_enabled_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_no_sanity_ocil:questionnaire:1">
77 ······<ocil:title>Enable·cron·Service</ocil:title>77 ······<ocil:title>Enable·poison·without·sanity·check</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-service_cron_enabled_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_no_sanity_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_login_grace_time_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1">
83 ······<ocil:title>Ensure·SSH·LoginGraceTime·is·configured</ocil:title>83 ······<ocil:title>Record·Attempts·to·Alter·the·localtime·File</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sshd_set_login_grace_time_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1"> 
89 ······<ocil:title>Configure·auditd·space_left·Action·on·Low·Disk·Space</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-grub2_nosmap_argument_absent_ocil:questionnaire:1">
 89 ······<ocil:title>Ensure·SMAP·is·not·disabled·during·boot</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-grub2_nosmap_argument_absent_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-service_iptables_enabled_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-coredump_disable_storage_ocil:questionnaire:1">
95 ······<ocil:title>Verify·iptables·Enabled</ocil:title>95 ······<ocil:title>Disable·storing·core·dump</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-service_iptables_enabled_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-coredump_disable_storage_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-package_logrotate_installed_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-grub2_l1tf_argument_ocil:questionnaire:1">
101 ······<ocil:title>Ensure·logrotate·is·Installed</ocil:title>101 ······<ocil:title>Configure·L1·Terminal·Fault·mitigations</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-package_logrotate_installed_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-grub2_l1tf_argument_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_noexec_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-sudo_require_authentication_ocil:questionnaire:1">
107 ······<ocil:title>Ensure·Privileged·Escalated·Commands·Cannot·Execute·Other·Commands·-·sudo·NOEXEC</ocil:title>107 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sudo_add_noexec_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-sudo_require_authentication_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-file_groupownership_audit_configuration_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_ocil:questionnaire:1">
113 ······<ocil:title>Audit·Configuration·Files·Must·Be·Owned·By·Group·root</ocil:title>113 ······<ocil:title>Configure·System·to·Forward·All·Mail·For·The·Root·Account</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-file_groupownership_audit_configuration_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-auditd_write_logs_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-package_gnutls-utils_installed_ocil:questionnaire:1">
119 ······<ocil:title>Write·Audit·Logs·to·the·Disk</ocil:title>119 ······<ocil:title>Ensure·gnutls-utils·is·installed</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-auditd_write_logs_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-package_gnutls-utils_installed_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
Max diff block lines reached; 648470/660821 bytes (98.13%) of diff not shown.
445 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-xccdf.xml
445 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_OPENSUSE"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_OPENSUSE"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openSUSE</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·openSUSE</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·openSUSE.·It·is·a·rendering·of7 configuration·settings·for·openSUSE.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
Offset 71, 42 lines modifiedOffset 71, 33 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="package_shadow-utils">78 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="OR"·negate="false">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
81 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="aarch64_arch">84 ····<cpe-lang:platform·id="grub2">
84 ······<cpe-lang:logical-test·operator="AND"·negate="false">85 ······<cpe-lang:logical-test·operator="AND"·negate="false">
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
86 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
87 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
88 ····<cpe-lang:platform·id="machine">89 ····<cpe-lang:platform·id="machine">
89 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
91 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
92 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
93 ····<cpe-lang:platform·id="x86_64_arch"> 
94 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/> 
96 ······</cpe-lang:logical-test> 
97 ····</cpe-lang:platform> 
98 ····<cpe-lang:platform·id="package_logrotate"> 
99 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/> 
101 ······</cpe-lang:logical-test> 
102 ····</cpe-lang:platform> 
103 ····<cpe-lang:platform·id="package_sudo">94 ····<cpe-lang:platform·id="package_iptables">
104 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
106 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
107 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
108 ····<cpe-lang:platform·id="machine_and_package_ufw">99 ····<cpe-lang:platform·id="machine_and_package_ufw">
109 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
112 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
Offset 123, 92 lines modifiedOffset 114, 101 lines modified
123 ········</cpe-lang:logical-test>114 ········</cpe-lang:logical-test>
124 ········<cpe-lang:logical-test·operator="AND"·negate="true">115 ········<cpe-lang:logical-test·operator="AND"·negate="true">
125 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>116 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
126 ········</cpe-lang:logical-test>117 ········</cpe-lang:logical-test>
127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
128 ······</cpe-lang:logical-test>119 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>120 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="package_systemd"> 
131 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/> 
133 ······</cpe-lang:logical-test> 
134 ····</cpe-lang:platform> 
135 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch"> 
136 ······<cpe-lang:logical-test·operator="OR"·negate="false"> 
137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/> 
139 ······</cpe-lang:logical-test> 
140 ····</cpe-lang:platform> 
141 ····<cpe-lang:platform·id="package_gdm">121 ····<cpe-lang:platform·id="package_pam">
142 ······<cpe-lang:logical-test·operator="AND"·negate="false">122 ······<cpe-lang:logical-test·operator="AND"·negate="false">
143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
144 ······</cpe-lang:logical-test>124 ······</cpe-lang:logical-test>
145 ····</cpe-lang:platform>125 ····</cpe-lang:platform>
146 ····<cpe-lang:platform·id="package_postfix">126 ····<cpe-lang:platform·id="package_logrotate">
147 ······<cpe-lang:logical-test·operator="AND"·negate="false">127 ······<cpe-lang:logical-test·operator="AND"·negate="false">
148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
149 ······</cpe-lang:logical-test>129 ······</cpe-lang:logical-test>
150 ····</cpe-lang:platform>130 ····</cpe-lang:platform>
151 ····<cpe-lang:platform·id="grub2">131 ····<cpe-lang:platform·id="package_audit">
152 ······<cpe-lang:logical-test·operator="AND"·negate="false">132 ······<cpe-lang:logical-test·operator="AND"·negate="false">
153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>
154 ······</cpe-lang:logical-test>134 ······</cpe-lang:logical-test>
155 ····</cpe-lang:platform>135 ····</cpe-lang:platform>
156 ····<cpe-lang:platform·id="package_rsh-server">136 ····<cpe-lang:platform·id="package_sudo">
157 ······<cpe-lang:logical-test·operator="AND"·negate="false">137 ······<cpe-lang:logical-test·operator="AND"·negate="false">
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
159 ······</cpe-lang:logical-test>139 ······</cpe-lang:logical-test>
160 ····</cpe-lang:platform>140 ····</cpe-lang:platform>
161 ····<cpe-lang:platform·id="package_chrony">141 ····<cpe-lang:platform·id="package_postfix">
162 ······<cpe-lang:logical-test·operator="AND"·negate="false">142 ······<cpe-lang:logical-test·operator="AND"·negate="false">
163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
164 ······</cpe-lang:logical-test>144 ······</cpe-lang:logical-test>
165 ····</cpe-lang:platform>145 ····</cpe-lang:platform>
166 ····<cpe-lang:platform·id="machine_and_package_iptables_and_service_disabled_firewalld">146 ····<cpe-lang:platform·id="machine_and_package_iptables_and_service_disabled_firewalld">
167 ······<cpe-lang:logical-test·operator="AND"·negate="false">147 ······<cpe-lang:logical-test·operator="AND"·negate="false">
168 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
171 ······</cpe-lang:logical-test>151 ······</cpe-lang:logical-test>
172 ····</cpe-lang:platform>152 ····</cpe-lang:platform>
173 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">153 ····<cpe-lang:platform·id="package_chrony">
 154 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
 156 ······</cpe-lang:logical-test>
 157 ····</cpe-lang:platform>
 158 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">
174 ······<cpe-lang:logical-test·operator="AND"·negate="false">159 ······<cpe-lang:logical-test·operator="AND"·negate="false">
175 ········<cpe-lang:logical-test·operator="AND"·negate="true">160 ········<cpe-lang:logical-test·operator="AND"·negate="true">
176 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>161 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
177 ········</cpe-lang:logical-test>162 ········</cpe-lang:logical-test>
178 ········<cpe-lang:logical-test·operator="AND"·negate="true">163 ········<cpe-lang:logical-test·operator="AND"·negate="true">
179 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>164 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
180 ········</cpe-lang:logical-test>165 ········</cpe-lang:logical-test>
181 ······</cpe-lang:logical-test>166 ······</cpe-lang:logical-test>
182 ····</cpe-lang:platform>167 ····</cpe-lang:platform>
183 ····<cpe-lang:platform·id="package_audit">168 ····<cpe-lang:platform·id="package_gdm">
184 ······<cpe-lang:logical-test·operator="AND"·negate="false">169 ······<cpe-lang:logical-test·operator="AND"·negate="false">
185 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
186 ······</cpe-lang:logical-test>171 ······</cpe-lang:logical-test>
187 ····</cpe-lang:platform>172 ····</cpe-lang:platform>
188 ····<cpe-lang:platform·id="package_pam">173 ····<cpe-lang:platform·id="package_shadow-utils">
189 ······<cpe-lang:logical-test·operator="AND"·negate="false">174 ······<cpe-lang:logical-test·operator="AND"·negate="false">
Max diff block lines reached; 442514/455343 bytes (97.18%) of diff not shown.
1.66 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ds.xml
1.66 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ds.xml
    
Offset 19, 25 lines modifiedOffset 19, 25 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-rhcos4-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-rhcos4-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-cpe-dictionary.xml"·timestamp="2024-11-02T06:39:34">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-cpe-dictionary.xml"·timestamp="2024-11-03T08:39:34">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux_coreos:4">28 ······<cpe-dict:cpe-item·name="cpe:/o:redhat:enterprise_linux_coreos:4">
29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·CoreOS·4</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Red·Hat·Enterprise·Linux·CoreOS·4</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml">oval:ssg-installed_OS_is_rhcos4:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml">oval:ssg-installed_OS_is_rhcos4:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-xccdf.xml"·timestamp="2024-11-02T06:39:34">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-rhcos4-xccdf.xml"·timestamp="2024-11-03T08:39:34">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHCOS-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_RHCOS-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·CoreOS·4</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·CoreOS·4</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Red·Hat·Enterprise·Linux·CoreOS·4.·It·is·a·rendering·of40 configuration·settings·for·Red·Hat·Enterprise·Linux·CoreOS·4.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
42 in·order·to·support·security·automation.··The·SCAP·content·is42 in·order·to·support·security·automation.··The·SCAP·content·is
43 is·available·in·the43 is·available·in·the
Offset 104, 336 lines modifiedOffset 104, 336 lines modified
104 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>104 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
105 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>105 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
106 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>106 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
107 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform">stigid</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform">stigid</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
110 ······<cpe-lang:platform-specification>110 ······<cpe-lang:platform-specification>
111 ········<cpe-lang:platform·id="machine_and_not_s390x_arch">111 ········<cpe-lang:platform·id="ipv6_enabled">
112 ··········<cpe-lang:logical-test·operator="AND"·negate="false">112 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
113 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>113 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
114 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/> 
115 ··········</cpe-lang:logical-test>114 ··········</cpe-lang:logical-test>
116 ········</cpe-lang:platform>115 ········</cpe-lang:platform>
117 ········<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">116 ········<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
118 ··········<cpe-lang:logical-test·operator="AND"·negate="false">117 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
 118 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
119 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>119 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
120 ··········</cpe-lang:logical-test>120 ··········</cpe-lang:logical-test>
121 ········</cpe-lang:platform>121 ········</cpe-lang:platform>
122 ········<cpe-lang:platform·id="package_shadow-utils">122 ········<cpe-lang:platform·id="grub2">
123 ··········<cpe-lang:logical-test·operator="AND"·negate="false">123 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
124 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>124 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
125 ··········</cpe-lang:logical-test>125 ··········</cpe-lang:logical-test>
126 ········</cpe-lang:platform>126 ········</cpe-lang:platform>
127 ········<cpe-lang:platform·id="package_apparmor">127 ········<cpe-lang:platform·id="machine">
128 ··········<cpe-lang:logical-test·operator="AND"·negate="false">128 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
129 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_apparmor:def:1"/>129 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
130 ··········</cpe-lang:logical-test>130 ··········</cpe-lang:logical-test>
131 ········</cpe-lang:platform>131 ········</cpe-lang:platform>
132 ········<cpe-lang:platform·id="package_ntp">132 ········<cpe-lang:platform·id="machine_and_mount_tmp">
133 ··········<cpe-lang:logical-test·operator="AND"·negate="false">133 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 134 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
134 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
135 ··········</cpe-lang:logical-test>136 ··········</cpe-lang:logical-test>
136 ········</cpe-lang:platform>137 ········</cpe-lang:platform>
137 ········<cpe-lang:platform·id="rhcos4-rhel9">138 ········<cpe-lang:platform·id="package_iptables">
138 ··········<cpe-lang:logical-test·operator="AND"·negate="false">139 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
139 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_OS_is_rhcos4_rhel9:def:1"/>140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
140 ··········</cpe-lang:logical-test>141 ··········</cpe-lang:logical-test>
141 ········</cpe-lang:platform>142 ········</cpe-lang:platform>
142 ········<cpe-lang:platform·id="aarch64_arch">143 ········<cpe-lang:platform·id="machine_and_package_ufw">
143 ··········<cpe-lang:logical-test·operator="AND"·negate="false">144 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 145 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
 146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 147 ··········</cpe-lang:logical-test>
 148 ········</cpe-lang:platform>
 149 ········<cpe-lang:platform·id="not_aarch64_arch">
 150 ··········<cpe-lang:logical-test·operator="AND"·negate="true">
144 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
145 ··········</cpe-lang:logical-test>152 ··········</cpe-lang:logical-test>
146 ········</cpe-lang:platform>153 ········</cpe-lang:platform>
147 ········<cpe-lang:platform·id="machine">154 ········<cpe-lang:platform·id="machine_and_not_rhcos4-rhel9_and_service_disabled_nftables_and_service_disabled_ufw">
148 ··········<cpe-lang:logical-test·operator="AND"·negate="false">155 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 156 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 157 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_OS_is_rhcos4_rhel9:def:1"/>
 158 ············</cpe-lang:logical-test>
149 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>159 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
 160 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_nftables:def:1"/>
 161 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>
150 ··········</cpe-lang:logical-test>162 ··········</cpe-lang:logical-test>
151 ········</cpe-lang:platform>163 ········</cpe-lang:platform>
152 ········<cpe-lang:platform·id="x86_64_arch">164 ········<cpe-lang:platform·id="krb5_server_older_than_1_17-18_and_krb5_workstation_older_than_1_17-18">
153 ··········<cpe-lang:logical-test·operator="AND"·negate="false">165 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
154 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>166 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-krb5_server_older_than_1_17_18:def:1"/>
 167 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-krb5_workstation_older_than_1_17_18:def:1"/>
155 ··········</cpe-lang:logical-test>168 ··········</cpe-lang:logical-test>
156 ········</cpe-lang:platform>169 ········</cpe-lang:platform>
157 ········<cpe-lang:platform·id="package_libreswan">170 ········<cpe-lang:platform·id="package_ntp">
158 ··········<cpe-lang:logical-test·operator="AND"·negate="false">171 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
159 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_libreswan:def:1"/>172 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
160 ··········</cpe-lang:logical-test>173 ··········</cpe-lang:logical-test>
161 ········</cpe-lang:platform>174 ········</cpe-lang:platform>
162 ········<cpe-lang:platform·id="package_sssd">175 ········<cpe-lang:platform·id="machine_and_mount_var">
163 ··········<cpe-lang:logical-test·operator="AND"·negate="false">176 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 177 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
164 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>178 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>
165 ··········</cpe-lang:logical-test>179 ··········</cpe-lang:logical-test>
166 ········</cpe-lang:platform>180 ········</cpe-lang:platform>
167 ········<cpe-lang:platform·id="package_tmux">181 ········<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
168 ··········<cpe-lang:logical-test·operator="AND"·negate="false">182 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 183 ············<cpe-lang:logical-test·operator="AND"·negate="true">
 184 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 185 ············</cpe-lang:logical-test>
 186 ············<cpe-lang:logical-test·operator="AND"·negate="true">
169 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_tmux:def:1"/>187 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 188 ············</cpe-lang:logical-test>
 189 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
170 ··········</cpe-lang:logical-test>190 ··········</cpe-lang:logical-test>
171 ········</cpe-lang:platform>191 ········</cpe-lang:platform>
172 ········<cpe-lang:platform·id="package_logrotate">192 ········<cpe-lang:platform·id="package_pam">
173 ··········<cpe-lang:logical-test·operator="AND"·negate="false">193 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
174 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>194 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
175 ··········</cpe-lang:logical-test>195 ··········</cpe-lang:logical-test>
176 ········</cpe-lang:platform>196 ········</cpe-lang:platform>
177 ········<cpe-lang:platform·id="machine_and_mount_home">197 ········<cpe-lang:platform·id="package_firewalld">
178 ··········<cpe-lang:logical-test·operator="AND"·negate="false">198 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
179 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
180 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_home:def:1"/>199 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
181 ··········</cpe-lang:logical-test>200 ··········</cpe-lang:logical-test>
182 ········</cpe-lang:platform>201 ········</cpe-lang:platform>
183 ········<cpe-lang:platform·id="not_aarch64_arch_and_machine_and_not_ppc64le_arch">202 ········<cpe-lang:platform·id="machine_and_not_osbuild">
Max diff block lines reached; 1727789/1742073 bytes (99.18%) of diff not shown.
1.55 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ocil.xml
1.55 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ocil.xml
Ordering differences only
    
Offset 3, 7545 lines modifiedOffset 3, 7545 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_noexec_ocil:questionnaire:1"> 
11 ······<ocil:title>Ensure·Privileged·Escalated·Commands·Cannot·Execute·Other·Commands·-·sudo·NOEXEC</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-sudo_add_noexec_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_log_nodev_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_ocil:questionnaire:1">
17 ······<ocil:title>Add·nodev·Option·to·/var/log</ocil:title>11 ······<ocil:title>Verify·User·Who·Owns·/var/log·Directory</ocil:title>
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_log_nodev_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-service_chronyd_enabled_ocil:questionnaire:1"> 
23 ······<ocil:title>The·Chronyd·service·is·enabled</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_fchmodat_ocil:questionnaire:1">
 17 ······<ocil:title>Record·Unsuccessful·Permission·Changes·to·Files·-·fchmodat</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-service_chronyd_enabled_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_fchmodat_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-configure_bind_crypto_policy_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-audit_owner_change_success_ocil:questionnaire:1">
29 ······<ocil:title>Configure·BIND·to·use·System·Crypto·Policy</ocil:title>23 ······<ocil:title>Configure·auditing·of·successful·ownership·changes</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-configure_bind_crypto_policy_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-audit_owner_change_success_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-service_cron_enabled_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_ocil:questionnaire:1">
35 ······<ocil:title>Enable·cron·Service</ocil:title>29 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-service_cron_enabled_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_sestatus_conf_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1">
41 ······<ocil:title>Verify·User·Who·Owns·/etc/sestatus.conf·File</ocil:title>35 ······<ocil:title>Disable·X11·Forwarding</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_sestatus_conf_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_fremovexattr_ocil:questionnaire:1"> 
47 ······<ocil:title>Record·Unsuccessful·Permission·Changes·to·Files·-·fremovexattr</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-package_sendmail_removed_ocil:questionnaire:1">
 41 ······<ocil:title>Uninstall·Sendmail·Package</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-package_sendmail_removed_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-package_logrotate_installed_ocil:questionnaire:1">
53 ······<ocil:title>Disable·Accepting·ICMP·Redirects·for·All·IPv4·Interfaces</ocil:title>47 ······<ocil:title>Ensure·logrotate·is·Installed</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-package_logrotate_installed_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_ipsec_secrets_ocil:questionnaire:1"> 
59 ······<ocil:title>Verify·Permissions·On·/etc/ipsec.secrets·File</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-grub2_slab_nomerge_argument_ocil:questionnaire:1">
 53 ······<ocil:title>Disable·merging·of·slabs·with·similar·size</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_ipsec_secrets_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-grub2_slab_nomerge_argument_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-service_sshd_disabled_ocil:questionnaire:1"> 
65 ······<ocil:title>Disable·SSH·Server·If·Possible</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1">
 59 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv4·Interfaces</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-service_sshd_disabled_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-package_bind_removed_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-file_ownership_audit_configuration_ocil:questionnaire:1">
71 ······<ocil:title>Uninstall·bind·Package</ocil:title>65 ······<ocil:title>Audit·Configuration·Files·Must·Be·Owned·By·Root</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-package_bind_removed_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-file_ownership_audit_configuration_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_write_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_chrony_keys_ocil:questionnaire:1">
77 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·write</ocil:title>71 ······<ocil:title>Verify·User·Who·Owns·/etc/chrony.keys·File</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_write_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_chrony_keys_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_disk_full_action_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-service_cron_enabled_ocil:questionnaire:1">
83 ······<ocil:title>Configure·audispd's·Plugin·disk_full_action·When·Disk·Is·Full</ocil:title>77 ······<ocil:title>Enable·cron·Service</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_disk_full_action_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-service_cron_enabled_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-bios_enable_execution_restrictions_ocil:questionnaire:1"> 
89 ······<ocil:title>Enable·NX·or·XD·Support·in·the·BIOS</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_etc_passwd_open_by_handle_at_ocil:questionnaire:1">
 83 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·via·open_by_handle_at·syscall·-·/etc/passwd</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-bios_enable_execution_restrictions_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_etc_passwd_open_by_handle_at_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-directory_owner_etc_sysctld_ocil:questionnaire:1">
95 ······<ocil:title>Disable·X11·Forwarding</ocil:title>89 ······<ocil:title>Verify·User·Who·Owns·/etc/sysctl.d·Directory</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-directory_owner_etc_sysctld_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-enable_fips_mode_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-ensure_logrotate_activated_ocil:questionnaire:1">
101 ······<ocil:title>Enable·FIPS·Mode</ocil:title>95 ······<ocil:title>Ensure·Logrotate·Runs·Periodically</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-enable_fips_mode_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-ensure_logrotate_activated_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-dir_permissions_binary_dirs_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_can_disabled_ocil:questionnaire:1">
107 ······<ocil:title>Verify·that·System·Executable·Directories·Have·Restrictive·Permissions</ocil:title>101 ······<ocil:title>Disable·CAN·Support</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-dir_permissions_binary_dirs_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-kernel_module_can_disabled_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_user_cfg_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-package_cron_installed_ocil:questionnaire:1">
113 ······<ocil:title>Verify·/boot/grub2/user.cfg·Group·Ownership</ocil:title>107 ······<ocil:title>Install·the·cron·service</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_user_cfg_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-package_cron_installed_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-auditd_freq_ocil:questionnaire:1">
119 ······<ocil:title>Ensure·the·Default·Bash·Umask·is·Set·Correctly</ocil:title>113 ······<ocil:title>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-auditd_freq_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
123 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_clock_settime_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_ocil:questionnaire:1">
Max diff block lines reached; 1614665/1627045 bytes (99.24%) of diff not shown.
43.2 KB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-xccdf.xml
43.1 KB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_RHCOS-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_RHCOS-4"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·CoreOS·4</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Red·Hat·Enterprise·Linux·CoreOS·4</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·Red·Hat·Enterprise·Linux·CoreOS·4.·It·is·a·rendering·of7 configuration·settings·for·Red·Hat·Enterprise·Linux·CoreOS·4.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
Offset 71, 336 lines modifiedOffset 71, 336 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="machine_and_not_s390x_arch">78 ····<cpe-lang:platform·id="ipv6_enabled">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/> 
82 ······</cpe-lang:logical-test>81 ······</cpe-lang:logical-test>
83 ····</cpe-lang:platform>82 ····</cpe-lang:platform>
84 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">83 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
85 ······<cpe-lang:logical-test·operator="AND"·negate="false">84 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
87 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="package_shadow-utils">89 ····<cpe-lang:platform·id="grub2">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
92 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="package_apparmor">94 ····<cpe-lang:platform·id="machine">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_apparmor:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
97 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="package_ntp">99 ····<cpe-lang:platform·id="machine_and_mount_tmp">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
102 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
103 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
104 ····<cpe-lang:platform·id="rhcos4-rhel9">105 ····<cpe-lang:platform·id="package_iptables">
105 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_OS_is_rhcos4_rhel9:def:1"/>107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
107 ······</cpe-lang:logical-test>108 ······</cpe-lang:logical-test>
108 ····</cpe-lang:platform>109 ····</cpe-lang:platform>
109 ····<cpe-lang:platform·id="aarch64_arch">110 ····<cpe-lang:platform·id="machine_and_package_ufw">
110 ······<cpe-lang:logical-test·operator="AND"·negate="false">111 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
 113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 114 ······</cpe-lang:logical-test>
 115 ····</cpe-lang:platform>
 116 ····<cpe-lang:platform·id="not_aarch64_arch">
 117 ······<cpe-lang:logical-test·operator="AND"·negate="true">
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
112 ······</cpe-lang:logical-test>119 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>120 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="machine">121 ····<cpe-lang:platform·id="machine_and_not_rhcos4-rhel9_and_service_disabled_nftables_and_service_disabled_ufw">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">122 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 123 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 124 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_OS_is_rhcos4_rhel9:def:1"/>
 125 ········</cpe-lang:logical-test>
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
 127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_nftables:def:1"/>
 128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>
117 ······</cpe-lang:logical-test>129 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>130 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="x86_64_arch">131 ····<cpe-lang:platform·id="krb5_server_older_than_1_17-18_and_krb5_workstation_older_than_1_17-18">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">132 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-krb5_server_older_than_1_17_18:def:1"/>
 134 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-krb5_workstation_older_than_1_17_18:def:1"/>
122 ······</cpe-lang:logical-test>135 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>136 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="package_libreswan">137 ····<cpe-lang:platform·id="package_ntp">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">138 ······<cpe-lang:logical-test·operator="AND"·negate="false">
126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_libreswan:def:1"/>139 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
127 ······</cpe-lang:logical-test>140 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>141 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="package_sssd">142 ····<cpe-lang:platform·id="machine_and_mount_var">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">143 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 144 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_sssd:def:1"/>145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>
132 ······</cpe-lang:logical-test>146 ······</cpe-lang:logical-test>
133 ····</cpe-lang:platform>147 ····</cpe-lang:platform>
134 ····<cpe-lang:platform·id="package_tmux">148 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
135 ······<cpe-lang:logical-test·operator="AND"·negate="false">149 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 150 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 151 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 152 ········</cpe-lang:logical-test>
 153 ········<cpe-lang:logical-test·operator="AND"·negate="true">
136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_tmux:def:1"/>154 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 155 ········</cpe-lang:logical-test>
 156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
137 ······</cpe-lang:logical-test>157 ······</cpe-lang:logical-test>
138 ····</cpe-lang:platform>158 ····</cpe-lang:platform>
139 ····<cpe-lang:platform·id="package_logrotate">159 ····<cpe-lang:platform·id="package_pam">
140 ······<cpe-lang:logical-test·operator="AND"·negate="false">160 ······<cpe-lang:logical-test·operator="AND"·negate="false">
141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
142 ······</cpe-lang:logical-test>162 ······</cpe-lang:logical-test>
143 ····</cpe-lang:platform>163 ····</cpe-lang:platform>
144 ····<cpe-lang:platform·id="machine_and_mount_home">164 ····<cpe-lang:platform·id="package_firewalld">
145 ······<cpe-lang:logical-test·operator="AND"·negate="false">165 ······<cpe-lang:logical-test·operator="AND"·negate="false">
146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_home:def:1"/>166 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
148 ······</cpe-lang:logical-test>167 ······</cpe-lang:logical-test>
149 ····</cpe-lang:platform>168 ····</cpe-lang:platform>
150 ····<cpe-lang:platform·id="not_aarch64_arch_and_machine_and_not_ppc64le_arch">169 ····<cpe-lang:platform·id="machine_and_not_osbuild">
151 ······<cpe-lang:logical-test·operator="AND"·negate="false">170 ······<cpe-lang:logical-test·operator="AND"·negate="false">
152 ········<cpe-lang:logical-test·operator="AND"·negate="true">171 ········<cpe-lang:logical-test·operator="AND"·negate="true">
153 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>172 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>
154 ········</cpe-lang:logical-test> 
155 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
156 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/> 
157 ········</cpe-lang:logical-test>173 ········</cpe-lang:logical-test>
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>174 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
159 ······</cpe-lang:logical-test>175 ······</cpe-lang:logical-test>
160 ····</cpe-lang:platform>176 ····</cpe-lang:platform>
161 ····<cpe-lang:platform·id="machine_and_mount_var-log">177 ····<cpe-lang:platform·id="package_logrotate">
162 ······<cpe-lang:logical-test·operator="AND"·negate="false">178 ······<cpe-lang:logical-test·operator="AND"·negate="false">
163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>179 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
165 ······</cpe-lang:logical-test>180 ······</cpe-lang:logical-test>
Max diff block lines reached; 29714/44026 bytes (67.49%) of diff not shown.
8.7 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ds.xml
8.7 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ds.xml
Max HTML report size reached
1.98 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ocil.xml
1.98 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ocil.xml
Max HTML report size reached
6.45 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-xccdf.xml
6.45 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-xccdf.xml
Max HTML report size reached
12.6 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
12.6 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
Max HTML report size reached
3.28 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ocil.xml
3.28 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ocil.xml
Max HTML report size reached
8.98 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-xccdf.xml
8.98 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-xccdf.xml
Max HTML report size reached
12.4 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml
12.4 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml
Max HTML report size reached
3.12 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ocil.xml
3.12 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ocil.xml
Max HTML report size reached
8.91 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-xccdf.xml
8.91 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-xccdf.xml
Max HTML report size reached
6.41 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ds.xml
6.41 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ds.xml
Max HTML report size reached
1.51 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ocil.xml
1.51 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ocil.xml
Ordering differences only
    
Offset 3, 5211 lines modifiedOffset 3, 5211 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_disk_error_action_stig_ocil:questionnaire:1"> 
11 ······<ocil:title>Configure·auditd·Disk·Error·Action·on·Disk·Error</ocil:title>10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_ocil:questionnaire:1">
 11 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·open</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_stig_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-service_xinetd_disabled_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-configure_ssh_crypto_policy_ocil:questionnaire:1">
17 ······<ocil:title>Disable·xinetd·Service</ocil:title>17 ······<ocil:title>Configure·SSH·to·use·System·Crypto·Policy</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-service_xinetd_disabled_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-configure_ssh_crypto_policy_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-sebool_cron_system_cronjob_use_shares_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_group_ocil:questionnaire:1">
23 ······<ocil:title>Disable·the·cron_system_cronjob_use_shares·SELinux·Boolean</ocil:title>23 ······<ocil:title>Verify·User·Who·Owns·group·File</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-sebool_cron_system_cronjob_use_shares_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_group_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_ocil:questionnaire:1"> 
29 ······<ocil:title>Set·Lockout·Time·for·Failed·Password·Attempts</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_syn_cookies_ocil:questionnaire:1">
 29 ······<ocil:title>Enable·TCP/IP·syncookie·support</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_unlock_time_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_syn_cookies_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_successful_file_modification_fchmodat_ocil:questionnaire:1"> 
35 ······<ocil:title>Record·Successful·Permission·Changes·to·Files·-·fchmodat</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-accounts_minimum_age_login_defs_ocil:questionnaire:1">
 35 ······<ocil:title>Set·Password·Minimum·Age</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fchmodat_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-accounts_minimum_age_login_defs_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-package_chrony_installed_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_interactive_users_ocil:questionnaire:1">
41 ······<ocil:title>The·Chrony·package·is·installed</ocil:title>41 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·For·Interactive·Users</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-package_chrony_installed_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_interactive_users_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-sebool_secadm_exec_content_ocil:questionnaire:1">
47 ······<ocil:title>Disable·SSH·Support·for·.rhosts·Files</ocil:title>47 ······<ocil:title>Enable·the·secadm_exec_content·SELinux·Boolean</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-sebool_secadm_exec_content_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sebool_mock_enable_homedirs_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-installed_OS_is_FIPS_certified_ocil:questionnaire:1">
53 ······<ocil:title>Disable·the·mock_enable_homedirs·SELinux·Boolean</ocil:title>53 ······<ocil:title>The·Installed·Operating·System·Is·FIPS·140-2·Certified</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sebool_mock_enable_homedirs_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-installed_OS_is_FIPS_certified_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmod_ocil:questionnaire:1">
59 ······<ocil:title>Disable·Host-Based·Authentication</ocil:title>59 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmod</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmod_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_profile_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-sudo_vdsm_nopasswd_ocil:questionnaire:1">
65 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·/etc/profile</ocil:title>65 ······<ocil:title>Only·the·VDSM·User·Can·Use·sudo·NOPASSWD</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_profile_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sudo_vdsm_nopasswd_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-account_use_centralized_automated_auth_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-account_passwords_pam_faillock_audit_ocil:questionnaire:1">
71 ······<ocil:title>Use·Centralized·and·Automated·Authentication</ocil:title>71 ······<ocil:title>Account·Lockouts·Must·Be·Logged</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-account_use_centralized_automated_auth_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_audit_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_immutable_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-aide_verify_ext_attributes_ocil:questionnaire:1">
77 ······<ocil:title>Make·the·auditd·Configuration·Immutable</ocil:title>77 ······<ocil:title>Configure·AIDE·to·Verify·Extended·Attributes</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_immutable_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-aide_verify_ext_attributes_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-grub2_uefi_password_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-mount_option_var_noexec_ocil:questionnaire:1">
83 ······<ocil:title>Set·the·UEFI·Boot·Loader·Password</ocil:title>83 ······<ocil:title>Add·noexec·Option·to·/var</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-grub2_uefi_password_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-mount_option_var_noexec_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chcon_ocil:questionnaire:1"> 
89 ······<ocil:title>Record·Any·Attempts·to·Run·chcon</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_local_packages_ocil:questionnaire:1">
 89 ······<ocil:title>Ensure·gpgcheck·Enabled·for·Local·Packages</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chcon_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_local_packages_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_crontab_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-install_hids_ocil:questionnaire:1">
95 ······<ocil:title>Verify·Group·Who·Owns·Crontab</ocil:title>95 ······<ocil:title>Install·Intrusion·Detection·Software</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_crontab_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-install_hids_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_unsuccessful_file_modification_creat_ocil:questionnaire:1">
101 ······<ocil:title>Ensure·auditd·Collects·Unauthorized·Access·Attempts·to·Files·(unsuccessful)</ocil:title>101 ······<ocil:title>Record·Unsuccessful·Access·Attempts·to·Files·-·creat</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_creat_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sudoers_no_root_target_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_table_isolation_ocil:questionnaire:1">
107 ······<ocil:title>Don't·target·root·user·in·the·sudoers·file</ocil:title>107 ······<ocil:title>Remove·the·kernel·mapping·in·user·mode</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sudoers_no_root_target_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_table_isolation_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-gid_passwd_group_same_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_passwd_ocil:questionnaire:1">
113 ······<ocil:title>All·GIDs·referenced·in·/etc/passwd·must·be·defined·in·/etc/group</ocil:title>113 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/passwd</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-gid_passwd_group_same_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_passwd_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_binfmt_misc_ocil:questionnaire:1"> 
119 ······<ocil:title>Disable·kernel·support·for·MISC·binaries</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_shadow_ocil:questionnaire:1">
 119 ······<ocil:title>Verify·Permissions·on·Backup·shadow·File</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-kernel_config_binfmt_misc_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_memory_ocil:questionnaire:1"> 
Max diff block lines reached; 1571107/1583860 bytes (99.19%) of diff not shown.
4.74 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-xccdf.xml
4.74 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-xccdf.xml
Max HTML report size reached
7.02 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ds.xml
7.02 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ds.xml
Max HTML report size reached
1.72 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ocil.xml
1.72 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ocil.xml
Ordering differences only
    
Offset 3, 6522 lines modifiedOffset 3, 6522 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sshd_do_not_permit_user_env_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-rpm_verify_hashes_ocil:questionnaire:1">
11 ······<ocil:title>Do·Not·Allow·SSH·Environment·Options</ocil:title>11 ······<ocil:title>Verify·File·Hashes·with·RPM</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-sshd_do_not_permit_user_env_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-rpm_verify_hashes_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_ocil:questionnaire:1"> 
17 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv6·Interfaces·by·Default</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_cron_hourly_ocil:questionnaire:1">
 17 ······<ocil:title>Verify·Permissions·on·cron.hourly</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-file_permissions_cron_hourly_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-directory_owner_etc_iptables_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_systemmap_ocil:questionnaire:1">
23 ······<ocil:title>Verify·User·Who·Owns·/etc/iptables·Directory</ocil:title>23 ······<ocil:title>Verify·Group·Who·Owns·System.map·Files</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-directory_owner_etc_iptables_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_systemmap_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_ocil:questionnaire:1"> 
29 ······<ocil:title>Configure·Accepting·Prefix·Information·in·Router·Advertisements·on·All·IPv6·Interfaces·By·Default</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_security_dmesg_restrict_ocil:questionnaire:1">
 29 ······<ocil:title>Restrict·unprivileged·access·to·the·kernel·syslog</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-kernel_config_security_dmesg_restrict_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-xwindows_remove_packages_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-sebool_selinuxuser_execstack_ocil:questionnaire:1">
35 ······<ocil:title>Disable·graphical·user·interface</ocil:title>35 ······<ocil:title>Disable·the·selinuxuser_execstack·SELinux·Boolean</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-xwindows_remove_packages_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_execstack_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-ensure_pam_wheel_group_empty_ocil:questionnaire:1"> 
41 ······<ocil:title>Ensure·the·Group·Used·by·pam_wheel.so·Module·Exists·on·System·and·is·Empty</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_default_router_solicitations_ocil:questionnaire:1">
 41 ······<ocil:title>Configure·Denying·Router·Solicitations·on·All·IPv6·Interfaces·By·Default</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-ensure_pam_wheel_group_empty_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_router_solicitations_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-directory_groupowner_etc_ipsecd_ocil:questionnaire:1"> 
47 ······<ocil:title>Verify·Group·Who·Owns·/etc/ipsec.d·Directory</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-cracklib_accounts_password_pam_retry_ocil:questionnaire:1">
 47 ······<ocil:title>Set·Password·Retry·Limit</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-directory_groupowner_etc_ipsecd_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-cracklib_accounts_password_pam_retry_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_never_disabled_ocil:questionnaire:1"> 
53 ······<ocil:title>Ensure·gpgcheck·Enabled·for·All·zypper·Package·Repositories</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchmodat_ocil:questionnaire:1">
 53 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchmodat</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_never_disabled_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmodat_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_passwd_ocil:questionnaire:1"> 
59 ······<ocil:title>Verify·Permissions·on·passwd·File</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
 59 ······<ocil:title>Enable·systemd-journald·Service</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_passwd_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_symlinks_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1">
65 ······<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Symlinks</ocil:title>65 ······<ocil:title>Disable·X11·Forwarding</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_symlinks_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-installed_OS_is_FIPS_certified_ocil:questionnaire:1"> 
71 ······<ocil:title>The·Installed·Operating·System·Is·FIPS·140-2·Certified</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-accounts_users_home_files_permissions_ocil:questionnaire:1">
 71 ······<ocil:title>All·User·Files·and·Directories·In·The·Home·Directory·Must·Have·Mode·0750·Or·Less·Permissive</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-installed_OS_is_FIPS_certified_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-accounts_users_home_files_permissions_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_acpi_custom_method_ocil:questionnaire:1"> 
77 ······<ocil:title>Do·not·allow·ACPI·methods·to·be·inserted/replaced·at·run·time</ocil:title>76 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_tcp_forwarding_ocil:questionnaire:1">
 77 ······<ocil:title>Disable·SSH·TCP·Forwarding</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_acpi_custom_method_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_tcp_forwarding_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-configure_user_data_backups_ocil:questionnaire:1"> 
83 ······<ocil:title>Configure·Backups·of·User·Data</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_passwd_ocil:questionnaire:1">
 83 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·passwd</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-configure_user_data_backups_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_passwd_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-root_permissions_syslibrary_files_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-no_user_host_based_files_ocil:questionnaire:1">
 89 ······<ocil:title>Remove·User·Host-Based·Authentication·Files</ocil:title>
89 ······<ocil:title>Verify·the·system-wide·library·files·in·directories 
90 &quot;/lib&quot;,·&quot;/lib64&quot;,·&quot;/usr/lib/&quot;·and·&quot;/usr/lib64&quot;·are·group-owned·by·root.</ocil:title> 
91 ······<ocil:actions>90 ······<ocil:actions>
92 ········<ocil:test_action_ref>ocil:ssg-root_permissions_syslibrary_files_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-no_user_host_based_files_action:testaction:1</ocil:test_action_ref>
93 ······</ocil:actions>92 ······</ocil:actions>
94 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
95 ····<ocil:questionnaire·id="ocil:ssg-grub2_systemd_debug-shell_argument_absent_ocil:questionnaire:1"> 
96 ······<ocil:title>Ensure·debug-shell·service·is·not·enabled·during·boot</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-file_owner_user_cfg_ocil:questionnaire:1">
 95 ······<ocil:title>Verify·/boot/grub2/user.cfg·User·Ownership</ocil:title>
97 ······<ocil:actions>96 ······<ocil:actions>
98 ········<ocil:test_action_ref>ocil:ssg-grub2_systemd_debug-shell_argument_absent_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-file_owner_user_cfg_action:testaction:1</ocil:test_action_ref>
99 ······</ocil:actions>98 ······</ocil:actions>
100 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
101 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_ocil:questionnaire:1"> 
102 ······<ocil:title>Configure·Accepting·Router·Preference·in·Router·Advertisements·on·All·IPv6·Interfaces</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_uvcvideo_disabled_ocil:questionnaire:1">
 101 ······<ocil:title>Disable·the·uvcvideo·module</ocil:title>
103 ······<ocil:actions>102 ······<ocil:actions>
104 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-kernel_module_uvcvideo_disabled_action:testaction:1</ocil:test_action_ref>
105 ······</ocil:actions>104 ······</ocil:actions>
106 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
107 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_usergroup_modification_opasswd_ocil:questionnaire:1"> 
108 ······<ocil:title>Record·Events·that·Modify·User/Group·Information·-·/etc/security/opasswd</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_gssapi_auth_ocil:questionnaire:1">
 107 ······<ocil:title>Disable·GSSAPI·Authentication</ocil:title>
109 ······<ocil:actions>108 ······<ocil:actions>
110 ········<ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_opasswd_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_gssapi_auth_action:testaction:1</ocil:test_action_ref>
111 ······</ocil:actions>110 ······</ocil:actions>
112 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
113 ····<ocil:questionnaire·id="ocil:ssg-package_ypbind_removed_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_passwd_ocil:questionnaire:1">
114 ······<ocil:title>Remove·NIS·Client</ocil:title>113 ······<ocil:title>Verify·Permissions·on·Backup·passwd·File</ocil:title>
115 ······<ocil:actions>114 ······<ocil:actions>
116 ········<ocil:test_action_ref>ocil:ssg-package_ypbind_removed_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 1794971/1807196 bytes (99.32%) of diff not shown.
5.09 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-xccdf.xml
5.09 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-xccdf.xml
Max HTML report size reached
7.46 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ds.xml
7.46 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ds.xml
Max HTML report size reached
1.81 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ocil.xml
1.81 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ocil.xml
Max HTML report size reached
5.45 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-xccdf.xml
5.45 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-xccdf.xml
Max HTML report size reached
741 KB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ds.xml
741 KB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-slmicro5-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-slmicro5-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-cpe-dictionary.xml"·timestamp="2024-11-02T06:39:34">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-cpe-dictionary.xml"·timestamp="2024-11-03T08:39:34">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.3">28 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.3">
29 ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.3</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.3</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.4">32 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-micro:5.4">
33 ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.4</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">SLE·Micro·5.4</cpe-dict:title>
Offset 39, 17 lines modifiedOffset 39, 17 lines modified
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-microos:5.2">40 ······<cpe-dict:cpe-item·name="cpe:/o:suse:sle-microos:5.2">
41 ········<cpe-dict:title·xml:lang="en-us">SLE·MicroOS·5.2</cpe-dict:title>41 ········<cpe-dict:title·xml:lang="en-us">SLE·MicroOS·5.2</cpe-dict:title>
42 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check>42 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml">oval:ssg-installed_OS_is_slmicro5:def:1</cpe-dict:check>
43 ······</cpe-dict:cpe-item>43 ······</cpe-dict:cpe-item>
44 ····</cpe-dict:cpe-list>44 ····</cpe-dict:cpe-list>
45 ··</ds:component>45 ··</ds:component>
46 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-xccdf.xml"·timestamp="2024-11-02T06:39:34">46 ··<ds:component·id="scap_org.open-scap_comp_ssg-slmicro5-xccdf.xml"·timestamp="2024-11-03T08:39:34">
47 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLMICRO5"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">47 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_SLMICRO5"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
48 ······<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>48 ······<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
49 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·Micro·5</xccdf-1.2:title>49 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·Micro·5</xccdf-1.2:title>
50 ······<xccdf-1.2:description>50 ······<xccdf-1.2:description>
51 ········This·guide·presents·a·catalog·of·security-relevant51 ········This·guide·presents·a·catalog·of·security-relevant
52 configuration·settings·for·SUSE·Linux·Enterprise·Micro·5.·It·is·a·rendering·of52 configuration·settings·for·SUSE·Linux·Enterprise·Micro·5.·It·is·a·rendering·of
53 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)53 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
54 in·order·to·support·security·automation.··The·SCAP·content·is54 in·order·to·support·security·automation.··The·SCAP·content·is
55 is·available·in·the55 is·available·in·the
Offset 116, 32 lines modifiedOffset 116, 32 lines modified
116 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>116 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
117 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>117 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
118 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>118 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
119 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>119 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
120 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>120 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
121 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>121 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
122 ······<cpe-lang:platform-specification>122 ······<cpe-lang:platform-specification>
123 ········<cpe-lang:platform·id="package_shadow-utils">123 ········<cpe-lang:platform·id="machine">
124 ··········<cpe-lang:logical-test·operator="AND"·negate="false">124 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
125 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>125 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
126 ··········</cpe-lang:logical-test>126 ··········</cpe-lang:logical-test>
127 ········</cpe-lang:platform>127 ········</cpe-lang:platform>
128 ········<cpe-lang:platform·id="machine">128 ········<cpe-lang:platform·id="package_pam">
129 ··········<cpe-lang:logical-test·operator="AND"·negate="false">129 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>130 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
131 ··········</cpe-lang:logical-test>131 ··········</cpe-lang:logical-test>
132 ········</cpe-lang:platform>132 ········</cpe-lang:platform>
133 ········<cpe-lang:platform·id="package_audit">133 ········<cpe-lang:platform·id="package_audit">
134 ··········<cpe-lang:logical-test·operator="AND"·negate="false">134 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>
136 ··········</cpe-lang:logical-test>136 ··········</cpe-lang:logical-test>
137 ········</cpe-lang:platform>137 ········</cpe-lang:platform>
138 ········<cpe-lang:platform·id="package_pam">138 ········<cpe-lang:platform·id="package_shadow-utils">
139 ··········<cpe-lang:logical-test·operator="AND"·negate="false">139 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>140 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
141 ··········</cpe-lang:logical-test>141 ··········</cpe-lang:logical-test>
142 ········</cpe-lang:platform>142 ········</cpe-lang:platform>
143 ······</cpe-lang:platform-specification>143 ······</cpe-lang:platform-specification>
144 ······<xccdf-1.2:platform·idref="cpe:/o:suse:sle-microos:5.2"/>144 ······<xccdf-1.2:platform·idref="cpe:/o:suse:sle-microos:5.2"/>
145 ······<xccdf-1.2:platform·idref="cpe:/o:suse:sle-micro:5.3"/>145 ······<xccdf-1.2:platform·idref="cpe:/o:suse:sle-micro:5.3"/>
146 ······<xccdf-1.2:platform·idref="cpe:/o:suse:sle-micro:5.4"/>146 ······<xccdf-1.2:platform·idref="cpe:/o:suse:sle-micro:5.4"/>
147 ······<xccdf-1.2:platform·idref="cpe:/o:suse:sle-micro:5.5"/>147 ······<xccdf-1.2:platform·idref="cpe:/o:suse:sle-micro:5.5"/>
Offset 704, 61 lines modifiedOffset 704, 14 lines modified
704 ················<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00226</xccdf-1.2:reference>704 ················<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00226</xccdf-1.2:reference>
705 ················<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">SLEM-05-412025</xccdf-1.2:reference>705 ················<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">SLEM-05-412025</xccdf-1.2:reference>
706 ················<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">SV-261365r996541_rule</xccdf-1.2:reference>706 ················<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">SV-261365r996541_rule</xccdf-1.2:reference>
707 ················<xccdf-1.2:rationale>Limiting·the·number·of·logon·attempts·over·a·certain·time·interval·reduces707 ················<xccdf-1.2:rationale>Limiting·the·number·of·logon·attempts·over·a·certain·time·interval·reduces
708 the·chances·that·an·unauthorized·user·may·gain·access·to·an·account.</xccdf-1.2:rationale>708 the·chances·that·an·unauthorized·user·may·gain·access·to·an·account.</xccdf-1.2:rationale>
709 ················<xccdf-1.2:platform·idref="#package_pam"/>709 ················<xccdf-1.2:platform·idref="#package_pam"/>
710 ················<xccdf-1.2:ident·system="https://ncp.nist.gov/cce">CCE-94092-4</xccdf-1.2:ident>710 ················<xccdf-1.2:ident·system="https://ncp.nist.gov/cce">CCE-94092-4</xccdf-1.2:ident>
711 ················<xccdf-1.2:fix·system="urn:xccdf:fix:script:sh"·id="accounts_passwords_pam_faildelay_delay"> 
712 ··················#·Remediation·is·applicable·only·in·certain·platforms 
713 if·rpm·--quiet·-q·pam;·then 
  
714 var_password_pam_delay=' 
715 ··················<xccdf-1.2:sub·idref="xccdf_org.ssgproject.content_value_var_password_pam_delay"·use="legacy"/> 
716 ··················' 
  
  
717 if·[·-e·&quot;/etc/pam.d/common-auth&quot;·]·;·then 
718 ····valueRegex=&quot;$var_password_pam_delay&quot;·defaultValue=&quot;$var_password_pam_delay&quot; 
719 ····#·non-empty·values·need·to·be·preceded·by·an·equals·sign 
720 ····[·-n·&quot;${valueRegex}&quot;·]·&amp;&amp;·valueRegex=&quot;=${valueRegex}&quot; 
721 ····#·add·an·equals·sign·to·non-empty·values 
722 ····[·-n·&quot;${defaultValue}&quot;·]·&amp;&amp;·defaultValue=&quot;=${defaultValue}&quot; 
  
723 ····#·fix·'type'·if·it's·wrong 
724 ····if·grep·-q·-P·&quot;^\\s*(?&quot;'!'&quot;auth\\s)[[:alnum:]]+\\s+[[:alnum:]]+\\s+pam_faildelay.so&quot;·&lt;·&quot;/etc/pam.d/common-auth&quot;·;·then 
725 ········sed·--follow-symlinks·-i·-E·-e·&quot;s/^(\\s*)[[:alnum:]]+(\\s+[[:alnum:]]+\\s+pam_faildelay.so)/\\1auth\\2/&quot;·&quot;/etc/pam.d/common-auth&quot; 
726 ····fi 
  
727 ····#·fix·'control'·if·it's·wrong 
728 ····if·grep·-q·-P·&quot;^\\s*auth\\s+(?&quot;'!'&quot;required)[[:alnum:]]+\\s+pam_faildelay.so&quot;·&lt;·&quot;/etc/pam.d/common-auth&quot;·;·then 
729 ········sed·--follow-symlinks·-i·-E·-e·&quot;s/^(\\s*auth\\s+)[[:alnum:]]+(\\s+pam_faildelay.so)/\\1required\\2/&quot;·&quot;/etc/pam.d/common-auth&quot; 
730 ····fi 
  
731 ····#·fix·the·value·for·'option'·if·one·exists·but·does·not·match·'valueRegex' 
732 ····if·grep·-q·-P·&quot;^\\s*auth\\s+required\\s+pam_faildelay.so(\\s.+)?\\s+delay(?&quot;'!'&quot;${valueRegex}(\\s|\$))&quot;·&lt;·&quot;/etc/pam.d/common-auth&quot;·;·then 
733 ········sed·--follow-symlinks·-i·-E·-e·&quot;s/^(\\s*auth\\s+required\\s+pam_faildelay.so(\\s.+)?\\s)delay=[^[:space:]]*/\\1delay${defaultValue}/&quot;·&quot;/etc/pam.d/common-auth&quot; 
  
734 ····#·add·'option=default'·if·option·is·not·set 
735 ····elif·grep·-q·-E·&quot;^\\s*auth\\s+required\\s+pam_faildelay.so&quot;·&lt;·&quot;/etc/pam.d/common-auth&quot;·&amp;&amp; 
736 ············grep····-E·&quot;^\\s*auth\\s+required\\s+pam_faildelay.so&quot;·&lt;·&quot;/etc/pam.d/common-auth&quot;·|·grep·-q·-E·-v·&quot;\\sdelay(=|\\s|\$)&quot;·;·then 
  
737 ········sed·--follow-symlinks·-i·-E·-e·&quot;s/^(\\s*auth\\s+required\\s+pam_faildelay.so[^\\n]*)/\\1·delay${defaultValue}/&quot;·&quot;/etc/pam.d/common-auth&quot; 
738 ····#·add·a·new·entry·if·none·exists 
739 ····elif·!·grep·-q·-P·&quot;^\\s*auth\\s+required\\s+pam_faildelay.so(\\s.+)?\\s+delay${valueRegex}(\\s|\$)&quot;·&lt;·&quot;/etc/pam.d/common-auth&quot;·;·then 
740 ········echo·&quot;auth·required·pam_faildelay.so·delay${defaultValue}&quot;·&gt;&gt;·&quot;/etc/pam.d/common-auth&quot; 
741 ····fi 
742 else 
743 ····echo·&quot;/etc/pam.d/common-auth·doesn't·exist&quot;·&gt;&amp;2 
744 fi 
  
745 else 
746 ····&gt;&amp;2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
747 fi 
748 ················</xccdf-1.2:fix> 
749 ················<xccdf-1.2:fix·system="urn:xccdf:fix:script:ansible"·id="accounts_passwords_pam_faildelay_delay"·complexity="low"·disruption="low"·reboot="false"·strategy="restrict">711 ················<xccdf-1.2:fix·system="urn:xccdf:fix:script:ansible"·id="accounts_passwords_pam_faildelay_delay"·complexity="low"·disruption="low"·reboot="false"·strategy="restrict">
750 ··················-·name:·Gather·the·package·facts712 ··················-·name:·Gather·the·package·facts
751 ··package_facts:713 ··package_facts:
752 ····manager:·auto714 ····manager:·auto
753 ··tags:715 ··tags:
754 ··-·CCE-94092-4716 ··-·CCE-94092-4
Max diff block lines reached; 748548/758802 bytes (98.65%) of diff not shown.
93.2 KB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ocil.xml
93.1 KB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ocil.xml
Ordering differences only
    
Offset 3, 309 lines modifiedOffset 3, 309 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sshd_print_last_log_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_modprobe_ocil:questionnaire:1">
11 ······<ocil:title>Enable·SSH·Print·Last·Log</ocil:title>11 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·modprobe</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-sshd_print_last_log_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_modprobe_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chacl_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_ssh_agent_ocil:questionnaire:1">
17 ······<ocil:title>Record·Any·Attempts·to·Run·chacl</ocil:title>17 ······<ocil:title>Record·Any·Attempts·to·Run·ssh-agent</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chacl_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_ssh_agent_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_kmod_ocil:questionnaire:1"> 
23 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·kmod</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1">
 23 ······<ocil:title>Disable·X11·Forwarding</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_kmod_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_passwd_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_passwd_ocil:questionnaire:1">
29 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·passwd</ocil:title>29 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·passwd</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_passwd_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_passwd_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_strictmodes_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_verbose_ocil:questionnaire:1">
35 ······<ocil:title>Enable·Use·of·Strict·Mode·Checking</ocil:title>35 ······<ocil:title>Set·SSH·Daemon·LogLevel·to·VERBOSE</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_strictmodes_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_verbose_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_tally2_file_selinux_ocil:questionnaire:1"> 
41 ······<ocil:title>An·SELinux·Context·must·be·configured·for·default·pam_tally2·file·option</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_user_known_hosts_ocil:questionnaire:1">
 41 ······<ocil:title>Disable·SSH·Support·for·User·Known·Hosts</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_tally2_file_selinux_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_user_known_hosts_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_tally2_file_ocil:questionnaire:1"> 
47 ······<ocil:title>SLEM·5·must·use·the·default·pam_tally2·tally·directory.</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_semanage_ocil:questionnaire:1">
 47 ······<ocil:title>Record·Any·Attempts·to·Run·semanage</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_tally2_file_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_semanage_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_rm_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-selinux_state_ocil:questionnaire:1">
53 ······<ocil:title>Record·Any·Attempts·to·Run·rm</ocil:title>53 ······<ocil:title>Ensure·SELinux·State·is·Enforcing</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_rm_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_setfacl_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-accounts_logon_fail_delay_ocil:questionnaire:1">
59 ······<ocil:title>Record·Any·Attempts·to·Run·setfacl</ocil:title>59 ······<ocil:title>Ensure·the·Logon·Failure·Delay·is·Set·Correctly·in·login.defs</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_setfacl_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-accounts_logon_fail_delay_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_semanage_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_insmod_ocil:questionnaire:1">
65 ······<ocil:title>Record·Any·Attempts·to·Run·semanage</ocil:title>65 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·insmod</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_semanage_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_insmod_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1"> 
71 ······<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_rmmod_ocil:questionnaire:1">
 71 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·rmmod</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_rmmod_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_chfn_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_chfn_ocil:questionnaire:1">
77 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·chfn</ocil:title>77 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·chfn</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_chfn_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_chfn_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-installed_OS_is_vendor_supported_ocil:questionnaire:1"> 
83 ······<ocil:title>The·Installed·Operating·System·Is·Vendor·Supported</ocil:title> 
84 ······<ocil:actions> 
85 ········<ocil:test_action_ref>ocil:ssg-installed_OS_is_vendor_supported_action:testaction:1</ocil:test_action_ref> 
86 ······</ocil:actions> 
87 ····</ocil:questionnaire> 
88 ····<ocil:questionnaire·id="ocil:ssg-selinux_state_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_crontab_ocil:questionnaire:1">
89 ······<ocil:title>Ensure·SELinux·State·is·Enforcing</ocil:title>83 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·crontab</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_crontab_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_newgrp_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_newgrp_ocil:questionnaire:1">
95 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·newgrp</ocil:title>89 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·newgrp</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_newgrp_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_newgrp_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_insmod_ocil:questionnaire:1"> 
101 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·insmod</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1">
 95 ······<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_insmod_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_sudoedit_ocil:questionnaire:1"> 
107 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·sudoedit</ocil:title>100 ····<ocil:questionnaire·id="ocil:ssg-accounts_passwords_pam_tally2_file_ocil:questionnaire:1">
 101 ······<ocil:title>SLEM·5·must·use·the·default·pam_tally2·tally·directory.</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_sudoedit_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_tally2_file_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_chsh_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_setfacl_ocil:questionnaire:1">
113 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·chsh</ocil:title>107 ······<ocil:title>Record·Any·Attempts·to·Run·setfacl</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_chsh_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_setfacl_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_ssh_keysign_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_execution_chmod_ocil:questionnaire:1">
119 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands·-·ssh-keysign</ocil:title>113 ······<ocil:title>Record·Any·Attempts·to·Run·chmod</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_ssh_keysign_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-audit_rules_execution_chmod_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
123 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
Max diff block lines reached; 83049/95157 bytes (87.28%) of diff not shown.
627 KB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-xccdf.xml
626 KB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_SLMICRO5"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_SLMICRO5"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·Micro·5</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·SUSE·Linux·Enterprise·Micro·5</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·SUSE·Linux·Enterprise·Micro·5.·It·is·a·rendering·of7 configuration·settings·for·SUSE·Linux·Enterprise·Micro·5.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
Offset 71, 32 lines modifiedOffset 71, 32 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="package_shadow-utils">78 ····<cpe-lang:platform·id="machine">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
81 ······</cpe-lang:logical-test>81 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>82 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="machine">83 ····<cpe-lang:platform·id="package_pam">
84 ······<cpe-lang:logical-test·operator="AND"·negate="false">84 ······<cpe-lang:logical-test·operator="AND"·negate="false">
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
86 ······</cpe-lang:logical-test>86 ······</cpe-lang:logical-test>
87 ····</cpe-lang:platform>87 ····</cpe-lang:platform>
88 ····<cpe-lang:platform·id="package_audit">88 ····<cpe-lang:platform·id="package_audit">
89 ······<cpe-lang:logical-test·operator="AND"·negate="false">89 ······<cpe-lang:logical-test·operator="AND"·negate="false">
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>
91 ······</cpe-lang:logical-test>91 ······</cpe-lang:logical-test>
92 ····</cpe-lang:platform>92 ····</cpe-lang:platform>
93 ····<cpe-lang:platform·id="package_pam">93 ····<cpe-lang:platform·id="package_shadow-utils">
94 ······<cpe-lang:logical-test·operator="AND"·negate="false">94 ······<cpe-lang:logical-test·operator="AND"·negate="false">
95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
96 ······</cpe-lang:logical-test>96 ······</cpe-lang:logical-test>
97 ····</cpe-lang:platform>97 ····</cpe-lang:platform>
98 ··</cpe-lang:platform-specification>98 ··</cpe-lang:platform-specification>
99 ··<xccdf-1.2:platform·idref="cpe:/o:suse:sle-microos:5.2"/>99 ··<xccdf-1.2:platform·idref="cpe:/o:suse:sle-microos:5.2"/>
100 ··<xccdf-1.2:platform·idref="cpe:/o:suse:sle-micro:5.3"/>100 ··<xccdf-1.2:platform·idref="cpe:/o:suse:sle-micro:5.3"/>
101 ··<xccdf-1.2:platform·idref="cpe:/o:suse:sle-micro:5.4"/>101 ··<xccdf-1.2:platform·idref="cpe:/o:suse:sle-micro:5.4"/>
102 ··<xccdf-1.2:platform·idref="cpe:/o:suse:sle-micro:5.5"/>102 ··<xccdf-1.2:platform·idref="cpe:/o:suse:sle-micro:5.5"/>
Offset 659, 61 lines modifiedOffset 659, 14 lines modified
659 ············<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00226</xccdf-1.2:reference>659 ············<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00226</xccdf-1.2:reference>
660 ············<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">SLEM-05-412025</xccdf-1.2:reference>660 ············<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">SLEM-05-412025</xccdf-1.2:reference>
661 ············<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">SV-261365r996541_rule</xccdf-1.2:reference>661 ············<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">SV-261365r996541_rule</xccdf-1.2:reference>
662 ············<xccdf-1.2:rationale>Limiting·the·number·of·logon·attempts·over·a·certain·time·interval·reduces662 ············<xccdf-1.2:rationale>Limiting·the·number·of·logon·attempts·over·a·certain·time·interval·reduces
663 the·chances·that·an·unauthorized·user·may·gain·access·to·an·account.</xccdf-1.2:rationale>663 the·chances·that·an·unauthorized·user·may·gain·access·to·an·account.</xccdf-1.2:rationale>
664 ············<xccdf-1.2:platform·idref="#package_pam"/>664 ············<xccdf-1.2:platform·idref="#package_pam"/>
665 ············<xccdf-1.2:ident·system="https://ncp.nist.gov/cce">CCE-94092-4</xccdf-1.2:ident>665 ············<xccdf-1.2:ident·system="https://ncp.nist.gov/cce">CCE-94092-4</xccdf-1.2:ident>
666 ············<xccdf-1.2:fix·system="urn:xccdf:fix:script:sh"·id="accounts_passwords_pam_faildelay_delay"> 
667 ··············#·Remediation·is·applicable·only·in·certain·platforms 
668 if·rpm·--quiet·-q·pam;·then 
  
669 var_password_pam_delay=' 
670 ··············<xccdf-1.2:sub·idref="xccdf_org.ssgproject.content_value_var_password_pam_delay"·use="legacy"/> 
671 ··············' 
  
  
672 if·[·-e·&quot;/etc/pam.d/common-auth&quot;·]·;·then 
673 ····valueRegex=&quot;$var_password_pam_delay&quot;·defaultValue=&quot;$var_password_pam_delay&quot; 
674 ····#·non-empty·values·need·to·be·preceded·by·an·equals·sign 
675 ····[·-n·&quot;${valueRegex}&quot;·]·&amp;&amp;·valueRegex=&quot;=${valueRegex}&quot; 
676 ····#·add·an·equals·sign·to·non-empty·values 
677 ····[·-n·&quot;${defaultValue}&quot;·]·&amp;&amp;·defaultValue=&quot;=${defaultValue}&quot; 
  
678 ····#·fix·'type'·if·it's·wrong 
679 ····if·grep·-q·-P·&quot;^\\s*(?&quot;'!'&quot;auth\\s)[[:alnum:]]+\\s+[[:alnum:]]+\\s+pam_faildelay.so&quot;·&lt;·&quot;/etc/pam.d/common-auth&quot;·;·then 
680 ········sed·--follow-symlinks·-i·-E·-e·&quot;s/^(\\s*)[[:alnum:]]+(\\s+[[:alnum:]]+\\s+pam_faildelay.so)/\\1auth\\2/&quot;·&quot;/etc/pam.d/common-auth&quot; 
681 ····fi 
  
682 ····#·fix·'control'·if·it's·wrong 
683 ····if·grep·-q·-P·&quot;^\\s*auth\\s+(?&quot;'!'&quot;required)[[:alnum:]]+\\s+pam_faildelay.so&quot;·&lt;·&quot;/etc/pam.d/common-auth&quot;·;·then 
684 ········sed·--follow-symlinks·-i·-E·-e·&quot;s/^(\\s*auth\\s+)[[:alnum:]]+(\\s+pam_faildelay.so)/\\1required\\2/&quot;·&quot;/etc/pam.d/common-auth&quot; 
685 ····fi 
  
686 ····#·fix·the·value·for·'option'·if·one·exists·but·does·not·match·'valueRegex' 
687 ····if·grep·-q·-P·&quot;^\\s*auth\\s+required\\s+pam_faildelay.so(\\s.+)?\\s+delay(?&quot;'!'&quot;${valueRegex}(\\s|\$))&quot;·&lt;·&quot;/etc/pam.d/common-auth&quot;·;·then 
688 ········sed·--follow-symlinks·-i·-E·-e·&quot;s/^(\\s*auth\\s+required\\s+pam_faildelay.so(\\s.+)?\\s)delay=[^[:space:]]*/\\1delay${defaultValue}/&quot;·&quot;/etc/pam.d/common-auth&quot; 
  
689 ····#·add·'option=default'·if·option·is·not·set 
690 ····elif·grep·-q·-E·&quot;^\\s*auth\\s+required\\s+pam_faildelay.so&quot;·&lt;·&quot;/etc/pam.d/common-auth&quot;·&amp;&amp; 
691 ············grep····-E·&quot;^\\s*auth\\s+required\\s+pam_faildelay.so&quot;·&lt;·&quot;/etc/pam.d/common-auth&quot;·|·grep·-q·-E·-v·&quot;\\sdelay(=|\\s|\$)&quot;·;·then 
  
692 ········sed·--follow-symlinks·-i·-E·-e·&quot;s/^(\\s*auth\\s+required\\s+pam_faildelay.so[^\\n]*)/\\1·delay${defaultValue}/&quot;·&quot;/etc/pam.d/common-auth&quot; 
693 ····#·add·a·new·entry·if·none·exists 
694 ····elif·!·grep·-q·-P·&quot;^\\s*auth\\s+required\\s+pam_faildelay.so(\\s.+)?\\s+delay${valueRegex}(\\s|\$)&quot;·&lt;·&quot;/etc/pam.d/common-auth&quot;·;·then 
695 ········echo·&quot;auth·required·pam_faildelay.so·delay${defaultValue}&quot;·&gt;&gt;·&quot;/etc/pam.d/common-auth&quot; 
696 ····fi 
697 else 
698 ····echo·&quot;/etc/pam.d/common-auth·doesn't·exist&quot;·&gt;&amp;2 
699 fi 
  
700 else 
701 ····&gt;&amp;2·echo·'Remediation·is·not·applicable,·nothing·was·done' 
702 fi 
703 ············</xccdf-1.2:fix> 
704 ············<xccdf-1.2:fix·system="urn:xccdf:fix:script:ansible"·id="accounts_passwords_pam_faildelay_delay"·complexity="low"·disruption="low"·reboot="false"·strategy="restrict">666 ············<xccdf-1.2:fix·system="urn:xccdf:fix:script:ansible"·id="accounts_passwords_pam_faildelay_delay"·complexity="low"·disruption="low"·reboot="false"·strategy="restrict">
705 ··············-·name:·Gather·the·package·facts667 ··············-·name:·Gather·the·package·facts
706 ··package_facts:668 ··package_facts:
707 ····manager:·auto669 ····manager:·auto
708 ··tags:670 ··tags:
709 ··-·CCE-94092-4671 ··-·CCE-94092-4
710 ··-·DISA-STIG-SLEM-05-412025672 ··-·DISA-STIG-SLEM-05-412025
Offset 846, 14 lines modifiedOffset 799, 61 lines modified
846 ··-·accounts_passwords_pam_faildelay_delay799 ··-·accounts_passwords_pam_faildelay_delay
847 ··-·low_complexity800 ··-·low_complexity
848 ··-·low_disruption801 ··-·low_disruption
849 ··-·medium_severity802 ··-·medium_severity
850 ··-·no_reboot_needed803 ··-·no_reboot_needed
851 ··-·restrict_strategy804 ··-·restrict_strategy
852 ············</xccdf-1.2:fix>805 ············</xccdf-1.2:fix>
 806 ············<xccdf-1.2:fix·system="urn:xccdf:fix:script:sh"·id="accounts_passwords_pam_faildelay_delay">
 807 ··············#·Remediation·is·applicable·only·in·certain·platforms
 808 if·rpm·--quiet·-q·pam;·then
  
 809 var_password_pam_delay='
 810 ··············<xccdf-1.2:sub·idref="xccdf_org.ssgproject.content_value_var_password_pam_delay"·use="legacy"/>
 811 ··············'
  
  
 812 if·[·-e·&quot;/etc/pam.d/common-auth&quot;·]·;·then
 813 ····valueRegex=&quot;$var_password_pam_delay&quot;·defaultValue=&quot;$var_password_pam_delay&quot;
 814 ····#·non-empty·values·need·to·be·preceded·by·an·equals·sign
 815 ····[·-n·&quot;${valueRegex}&quot;·]·&amp;&amp;·valueRegex=&quot;=${valueRegex}&quot;
 816 ····#·add·an·equals·sign·to·non-empty·values
Max diff block lines reached; 629711/641352 bytes (98.18%) of diff not shown.
1.2 MB
./usr/share/xml/scap/ssg/content/ssg-uos20-ds.xml
1.2 MB
./usr/share/xml/scap/ssg/content/ssg-uos20-ds.xml
    
Offset 19, 25 lines modifiedOffset 19, 25 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-uos20-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-uos20-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-uos20-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-uos20-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-uos20-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-uos20-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-uos20-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-uos20-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-uos20-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-uos20-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-uos20-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-uos20-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-uos20-cpe-dictionary.xml"·timestamp="2024-11-02T06:39:34">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-uos20-cpe-dictionary.xml"·timestamp="2024-11-03T08:39:34">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:uos:uniontech_os_server:20">28 ······<cpe-dict:cpe-item·name="cpe:/o:uos:uniontech_os_server:20">
29 ········<cpe-dict:title·xml:lang="en-us">UnionTech·OS·Server·20</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">UnionTech·OS·Server·20</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml">oval:ssg-installed_OS_is_uos20:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml">oval:ssg-installed_OS_is_uos20:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-uos20-xccdf.xml"·timestamp="2024-11-02T06:39:34">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-uos20-xccdf.xml"·timestamp="2024-11-03T08:39:34">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UOS-20"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_UOS-20"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·UnionTech·OS·Server·20</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·UnionTech·OS·Server·20</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·UnionTech·OS·Server·20.·It·is·a·rendering·of40 configuration·settings·for·UnionTech·OS·Server·20.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
42 in·order·to·support·security·automation.··The·SCAP·content·is42 in·order·to·support·security·automation.··The·SCAP·content·is
43 is·available·in·the43 is·available·in·the
Offset 104, 42 lines modifiedOffset 104, 33 lines modified
104 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>104 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
105 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>105 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
106 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>106 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
107 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>107 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>108 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>109 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
110 ······<cpe-lang:platform-specification>110 ······<cpe-lang:platform-specification>
111 ········<cpe-lang:platform·id="package_shadow-utils">111 ········<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
112 ··········<cpe-lang:logical-test·operator="AND"·negate="false">112 ··········<cpe-lang:logical-test·operator="OR"·negate="false">
113 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>113 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 114 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
114 ··········</cpe-lang:logical-test>115 ··········</cpe-lang:logical-test>
115 ········</cpe-lang:platform>116 ········</cpe-lang:platform>
116 ········<cpe-lang:platform·id="aarch64_arch">117 ········<cpe-lang:platform·id="grub2">
117 ··········<cpe-lang:logical-test·operator="AND"·negate="false">118 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
118 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>119 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
119 ··········</cpe-lang:logical-test>120 ··········</cpe-lang:logical-test>
120 ········</cpe-lang:platform>121 ········</cpe-lang:platform>
121 ········<cpe-lang:platform·id="machine">122 ········<cpe-lang:platform·id="machine">
122 ··········<cpe-lang:logical-test·operator="AND"·negate="false">123 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
123 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>124 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
124 ··········</cpe-lang:logical-test>125 ··········</cpe-lang:logical-test>
125 ········</cpe-lang:platform>126 ········</cpe-lang:platform>
126 ········<cpe-lang:platform·id="x86_64_arch"> 
127 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
128 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/> 
129 ··········</cpe-lang:logical-test> 
130 ········</cpe-lang:platform> 
131 ········<cpe-lang:platform·id="package_logrotate"> 
132 ··········<cpe-lang:logical-test·operator="AND"·negate="false"> 
133 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/> 
134 ··········</cpe-lang:logical-test> 
135 ········</cpe-lang:platform> 
136 ········<cpe-lang:platform·id="package_sudo">127 ········<cpe-lang:platform·id="package_iptables">
137 ··········<cpe-lang:logical-test·operator="AND"·negate="false">128 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
138 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>129 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
139 ··········</cpe-lang:logical-test>130 ··········</cpe-lang:logical-test>
140 ········</cpe-lang:platform>131 ········</cpe-lang:platform>
141 ········<cpe-lang:platform·id="machine_and_package_ufw">132 ········<cpe-lang:platform·id="machine_and_package_ufw">
142 ··········<cpe-lang:logical-test·operator="AND"·negate="false">133 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
143 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>134 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
144 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>135 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
145 ··········</cpe-lang:logical-test>136 ··········</cpe-lang:logical-test>
Offset 156, 108 lines modifiedOffset 147, 117 lines modified
156 ············</cpe-lang:logical-test>147 ············</cpe-lang:logical-test>
157 ············<cpe-lang:logical-test·operator="AND"·negate="true">148 ············<cpe-lang:logical-test·operator="AND"·negate="true">
158 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>149 ··············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
159 ············</cpe-lang:logical-test>150 ············</cpe-lang:logical-test>
160 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>151 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
161 ··········</cpe-lang:logical-test>152 ··········</cpe-lang:logical-test>
162 ········</cpe-lang:platform>153 ········</cpe-lang:platform>
163 ········<cpe-lang:platform·id="package_yum">154 ········<cpe-lang:platform·id="package_pam">
164 ··········<cpe-lang:logical-test·operator="AND"·negate="false">155 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
165 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/>156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
166 ··········</cpe-lang:logical-test>157 ··········</cpe-lang:logical-test>
167 ········</cpe-lang:platform>158 ········</cpe-lang:platform>
168 ········<cpe-lang:platform·id="package_systemd">159 ········<cpe-lang:platform·id="package_logrotate">
169 ··········<cpe-lang:logical-test·operator="AND"·negate="false">160 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
170 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>161 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
171 ··········</cpe-lang:logical-test> 
172 ········</cpe-lang:platform> 
173 ········<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch"> 
174 ··········<cpe-lang:logical-test·operator="OR"·negate="false"> 
175 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
176 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/> 
177 ··········</cpe-lang:logical-test>162 ··········</cpe-lang:logical-test>
178 ········</cpe-lang:platform>163 ········</cpe-lang:platform>
179 ········<cpe-lang:platform·id="package_gdm">164 ········<cpe-lang:platform·id="package_audit">
180 ··········<cpe-lang:logical-test·operator="AND"·negate="false">165 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
181 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>166 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>
182 ··········</cpe-lang:logical-test>167 ··········</cpe-lang:logical-test>
183 ········</cpe-lang:platform>168 ········</cpe-lang:platform>
184 ········<cpe-lang:platform·id="package_postfix">169 ········<cpe-lang:platform·id="package_yum">
185 ··········<cpe-lang:logical-test·operator="AND"·negate="false">170 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
186 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>171 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/>
187 ··········</cpe-lang:logical-test>172 ··········</cpe-lang:logical-test>
188 ········</cpe-lang:platform>173 ········</cpe-lang:platform>
189 ········<cpe-lang:platform·id="grub2">174 ········<cpe-lang:platform·id="package_sudo">
190 ··········<cpe-lang:logical-test·operator="AND"·negate="false">175 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
191 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>176 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
192 ··········</cpe-lang:logical-test>177 ··········</cpe-lang:logical-test>
193 ········</cpe-lang:platform>178 ········</cpe-lang:platform>
194 ········<cpe-lang:platform·id="package_rsh-server">179 ········<cpe-lang:platform·id="machine_and_package_autofs">
195 ··········<cpe-lang:logical-test·operator="AND"·negate="false">180 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 181 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
196 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>182 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
197 ··········</cpe-lang:logical-test>183 ··········</cpe-lang:logical-test>
198 ········</cpe-lang:platform>184 ········</cpe-lang:platform>
199 ········<cpe-lang:platform·id="package_chrony">185 ········<cpe-lang:platform·id="package_postfix">
200 ··········<cpe-lang:logical-test·operator="AND"·negate="false">186 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
201 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>187 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
202 ··········</cpe-lang:logical-test>188 ··········</cpe-lang:logical-test>
203 ········</cpe-lang:platform>189 ········</cpe-lang:platform>
204 ········<cpe-lang:platform·id="package_bind">190 ········<cpe-lang:platform·id="package_bind">
205 ··········<cpe-lang:logical-test·operator="AND"·negate="false">191 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
206 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_bind:def:1"/>192 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_bind:def:1"/>
207 ··········</cpe-lang:logical-test>193 ··········</cpe-lang:logical-test>
208 ········</cpe-lang:platform>194 ········</cpe-lang:platform>
209 ········<cpe-lang:platform·id="machine_and_package_iptables_and_service_disabled_firewalld">195 ········<cpe-lang:platform·id="machine_and_package_iptables_and_service_disabled_firewalld">
210 ··········<cpe-lang:logical-test·operator="AND"·negate="false">196 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
211 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>197 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
Max diff block lines reached; 1241434/1254299 bytes (98.97%) of diff not shown.
708 KB
./usr/share/xml/scap/ssg/content/ssg-uos20-ocil.xml
707 KB
./usr/share/xml/scap/ssg/content/ssg-uos20-ocil.xml
Ordering differences only
    
Offset 3, 7654 lines modifiedOffset 3, 7654 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.74</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>7 ····<ocil:timestamp>2024-11-02T18:39:34</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-package_MFEhiplsm_installed_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_login_defs_ocil:questionnaire:1">
11 ······<ocil:title>Install·the·Host·Intrusion·Prevention·System·(HIPS)·Module</ocil:title>11 ······<ocil:title>Ensure·the·Default·Umask·is·Set·Correctly·in·login.defs</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-package_MFEhiplsm_installed_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_login_defs_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_gshadow_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-service_iptables_enabled_ocil:questionnaire:1">
17 ······<ocil:title>Verify·Permissions·on·gshadow·File</ocil:title>17 ······<ocil:title>Verify·iptables·Enabled</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_gshadow_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-service_iptables_enabled_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_shadow_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_rhosts_ocil:questionnaire:1">
23 ······<ocil:title>Verify·Permissions·on·Backup·shadow·File</ocil:title>23 ······<ocil:title>Disable·SSH·Support·for·.rhosts·Files</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_systemmap_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-sysctl_fs_protected_symlinks_ocil:questionnaire:1">
29 ······<ocil:title>Verify·Permissions·on·System.map·Files</ocil:title>29 ······<ocil:title>Enable·Kernel·Parameter·to·Enforce·DAC·on·Symlinks</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-file_permissions_systemmap_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_symlinks_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_shadow_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_requiretty_ocil:questionnaire:1">
35 ······<ocil:title>Verify·User·Who·Owns·shadow·File</ocil:title>35 ······<ocil:title>Ensure·Only·Users·Logged·In·To·Real·tty·Can·Execute·Sudo·-·sudo·requiretty</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_shadow_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sudo_add_requiretty_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-accounts_logon_fail_delay_ocil:questionnaire:1"> 
41 ······<ocil:title>Ensure·the·Logon·Failure·Delay·is·Set·Correctly·in·login.defs</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_group_ocil:questionnaire:1">
 41 ······<ocil:title>Verify·Permissions·on·group·File</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-accounts_logon_fail_delay_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_group_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ia32_emulation_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1">
47 ······<ocil:title>Disable·IA32·emulation</ocil:title>47 ······<ocil:title>Ensure·syslog-ng·is·Installed</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-kernel_config_ia32_emulation_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-accounts_minimum_age_login_defs_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_ocil:questionnaire:1">
53 ······<ocil:title>Set·Password·Minimum·Age</ocil:title>53 ······<ocil:title>Ensure·/var·Located·On·Separate·Partition</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-accounts_minimum_age_login_defs_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-service_ntpdate_disabled_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-sshd_allow_only_protocol2_ocil:questionnaire:1">
59 ······<ocil:title>Disable·ntpdate·Service·(ntpdate)</ocil:title>59 ······<ocil:title>Allow·Only·SSH·Protocol·2</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-service_ntpdate_disabled_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-sshd_allow_only_protocol2_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_default_mmap_min_addr_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_ocil:questionnaire:1">
65 ······<ocil:title>Configure·Low·Address·Space·To·Protect·From·User·Allocation</ocil:title>65 ······<ocil:title>Disable·IPv6·Addressing·on·All·IPv6·Interfaces</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-kernel_config_default_mmap_min_addr_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-display_login_attempts_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_lchown_ocil:questionnaire:1">
71 ······<ocil:title>Ensure·PAM·Displays·Last·Logon/Access·Notification</ocil:title>71 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·lchown</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-display_login_attempts_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lchown_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_etc_group_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_randomize_base_ocil:questionnaire:1">
77 ······<ocil:title>Verify·Group·Who·Owns·group·File</ocil:title>77 ······<ocil:title>Randomize·the·address·of·the·kernel·image·(KASLR)</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_etc_group_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-kernel_config_randomize_base_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_ocil:questionnaire:1"> 
83 ······<ocil:title>Configure·Sending·and·Accepting·Shared·Media·Redirects·for·All·IPv4·Interfaces</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-account_passwords_pam_faillock_dir_ocil:questionnaire:1">
 83 ······<ocil:title>Account·Lockouts·Must·Persist</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_dir_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-rpm_verify_hashes_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_shadow_ocil:questionnaire:1">
89 ······<ocil:title>Verify·File·Hashes·with·RPM</ocil:title>89 ······<ocil:title>Verify·Permissions·on·Backup·shadow·File</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-rpm_verify_hashes_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_legacy_ptys_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_postmaster_ocil:questionnaire:1">
95 ······<ocil:title>Disable·legacy·(BSD)·PTY·support</ocil:title>95 ······<ocil:title>Configure·System·to·Forward·All·Mail·From·Postmaster·to·The·Root·Account</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-kernel_config_legacy_ptys_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_postmaster_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_group_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-accounts_minimum_age_login_defs_ocil:questionnaire:1">
101 ······<ocil:title>Verify·User·Who·Owns·group·File</ocil:title>101 ······<ocil:title>Set·Password·Minimum·Age</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_group_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-accounts_minimum_age_login_defs_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_backup_etc_shadow_ocil:questionnaire:1"> 
107 ······<ocil:title>Verify·User·Who·Owns·Backup·shadow·File</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_page_poisoning_zero_ocil:questionnaire:1">
 107 ······<ocil:title>Use·zero·for·poisoning·instead·of·debugging·value</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_zero_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-configure_openssl_crypto_policy_ocil:questionnaire:1">
113 ······<ocil:title>Limit·Users'·SSH·Access</ocil:title>113 ······<ocil:title>Configure·OpenSSL·library·to·use·System·Crypto·Policy</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-sshd_limit_user_access_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-configure_openssl_crypto_policy_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_ocil:questionnaire:1">
119 ······<ocil:title>Disable·XDMCP·in·GDM</ocil:title>119 ······<ocil:title>Verify·Group·Who·Owns·/var/log·Directory</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>122 ······</ocil:actions>
123 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_private_key_ocil:questionnaire:1">124 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_unauthorized_world_writable_ocil:questionnaire:1">
125 ······<ocil:title>Verify·Permissions·on·SSH·Server·Private·*_key·Key·Files</ocil:title>125 ······<ocil:title>Ensure·No·World-Writable·Files·Exist</ocil:title>
126 ······<ocil:actions>126 ······<ocil:actions>
Max diff block lines reached; 711439/724280 bytes (98.23%) of diff not shown.
474 KB
./usr/share/xml/scap/ssg/content/ssg-uos20-xccdf.xml
474 KB
./usr/share/xml/scap/ssg/content/ssg-uos20-xccdf.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_UOS-20"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">2 <xccdf-1.2:Benchmark·xmlns:cpe-lang="http://cpe.mitre.org/language/2.0"·xmlns:dc="http://purl.org/dc/elements/1.1/"·xmlns:html="http://www.w3.org/1999/xhtml"·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"·id="xccdf_org.ssgproject.content_benchmark_UOS-20"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
3 ··<xccdf-1.2:status·date="2026-01-08">draft</xccdf-1.2:status>3 ··<xccdf-1.2:status·date="2024-12-07">draft</xccdf-1.2:status>
4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·UnionTech·OS·Server·20</xccdf-1.2:title>4 ··<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·UnionTech·OS·Server·20</xccdf-1.2:title>
5 ··<xccdf-1.2:description>5 ··<xccdf-1.2:description>
6 ····This·guide·presents·a·catalog·of·security-relevant6 ····This·guide·presents·a·catalog·of·security-relevant
7 configuration·settings·for·UnionTech·OS·Server·20.·It·is·a·rendering·of7 configuration·settings·for·UnionTech·OS·Server·20.·It·is·a·rendering·of
8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)8 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
9 in·order·to·support·security·automation.··The·SCAP·content·is9 in·order·to·support·security·automation.··The·SCAP·content·is
10 is·available·in·the10 is·available·in·the
Offset 71, 42 lines modifiedOffset 71, 33 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="package_shadow-utils">78 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="OR"·negate="false">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
81 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="aarch64_arch">84 ····<cpe-lang:platform·id="grub2">
84 ······<cpe-lang:logical-test·operator="AND"·negate="false">85 ······<cpe-lang:logical-test·operator="AND"·negate="false">
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
86 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
87 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
88 ····<cpe-lang:platform·id="machine">89 ····<cpe-lang:platform·id="machine">
89 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
91 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
92 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
93 ····<cpe-lang:platform·id="x86_64_arch"> 
94 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/> 
96 ······</cpe-lang:logical-test> 
97 ····</cpe-lang:platform> 
98 ····<cpe-lang:platform·id="package_logrotate"> 
99 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/> 
101 ······</cpe-lang:logical-test> 
102 ····</cpe-lang:platform> 
103 ····<cpe-lang:platform·id="package_sudo">94 ····<cpe-lang:platform·id="package_iptables">
104 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
106 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
107 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
108 ····<cpe-lang:platform·id="machine_and_package_ufw">99 ····<cpe-lang:platform·id="machine_and_package_ufw">
109 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
112 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
Offset 123, 108 lines modifiedOffset 114, 117 lines modified
123 ········</cpe-lang:logical-test>114 ········</cpe-lang:logical-test>
124 ········<cpe-lang:logical-test·operator="AND"·negate="true">115 ········<cpe-lang:logical-test·operator="AND"·negate="true">
125 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>116 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
126 ········</cpe-lang:logical-test>117 ········</cpe-lang:logical-test>
127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
128 ······</cpe-lang:logical-test>119 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>120 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="package_yum">121 ····<cpe-lang:platform·id="package_pam">
131 ······<cpe-lang:logical-test·operator="AND"·negate="false">122 ······<cpe-lang:logical-test·operator="AND"·negate="false">
132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/>123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
133 ······</cpe-lang:logical-test>124 ······</cpe-lang:logical-test>
134 ····</cpe-lang:platform>125 ····</cpe-lang:platform>
135 ····<cpe-lang:platform·id="package_systemd">126 ····<cpe-lang:platform·id="package_logrotate">
136 ······<cpe-lang:logical-test·operator="AND"·negate="false">127 ······<cpe-lang:logical-test·operator="AND"·negate="false">
137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
138 ······</cpe-lang:logical-test> 
139 ····</cpe-lang:platform> 
140 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch"> 
141 ······<cpe-lang:logical-test·operator="OR"·negate="false"> 
142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/> 
144 ······</cpe-lang:logical-test>129 ······</cpe-lang:logical-test>
145 ····</cpe-lang:platform>130 ····</cpe-lang:platform>
146 ····<cpe-lang:platform·id="package_gdm">131 ····<cpe-lang:platform·id="package_audit">
147 ······<cpe-lang:logical-test·operator="AND"·negate="false">132 ······<cpe-lang:logical-test·operator="AND"·negate="false">
148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>
149 ······</cpe-lang:logical-test>134 ······</cpe-lang:logical-test>
150 ····</cpe-lang:platform>135 ····</cpe-lang:platform>
151 ····<cpe-lang:platform·id="package_postfix">136 ····<cpe-lang:platform·id="package_yum">
152 ······<cpe-lang:logical-test·operator="AND"·negate="false">137 ······<cpe-lang:logical-test·operator="AND"·negate="false">
153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_yum:def:1"/>
154 ······</cpe-lang:logical-test>139 ······</cpe-lang:logical-test>
155 ····</cpe-lang:platform>140 ····</cpe-lang:platform>
156 ····<cpe-lang:platform·id="grub2">141 ····<cpe-lang:platform·id="package_sudo">
157 ······<cpe-lang:logical-test·operator="AND"·negate="false">142 ······<cpe-lang:logical-test·operator="AND"·negate="false">
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
159 ······</cpe-lang:logical-test>144 ······</cpe-lang:logical-test>
160 ····</cpe-lang:platform>145 ····</cpe-lang:platform>
161 ····<cpe-lang:platform·id="package_rsh-server">146 ····<cpe-lang:platform·id="machine_and_package_autofs">
162 ······<cpe-lang:logical-test·operator="AND"·negate="false">147 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_autofs:def:1"/>
164 ······</cpe-lang:logical-test>150 ······</cpe-lang:logical-test>
165 ····</cpe-lang:platform>151 ····</cpe-lang:platform>
166 ····<cpe-lang:platform·id="package_chrony">152 ····<cpe-lang:platform·id="package_postfix">
167 ······<cpe-lang:logical-test·operator="AND"·negate="false">153 ······<cpe-lang:logical-test·operator="AND"·negate="false">
168 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
169 ······</cpe-lang:logical-test>155 ······</cpe-lang:logical-test>
170 ····</cpe-lang:platform>156 ····</cpe-lang:platform>
171 ····<cpe-lang:platform·id="package_bind">157 ····<cpe-lang:platform·id="package_bind">
172 ······<cpe-lang:logical-test·operator="AND"·negate="false">158 ······<cpe-lang:logical-test·operator="AND"·negate="false">
173 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_bind:def:1"/>159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_bind:def:1"/>
174 ······</cpe-lang:logical-test>160 ······</cpe-lang:logical-test>
175 ····</cpe-lang:platform>161 ····</cpe-lang:platform>
176 ····<cpe-lang:platform·id="machine_and_package_iptables_and_service_disabled_firewalld">162 ····<cpe-lang:platform·id="machine_and_package_iptables_and_service_disabled_firewalld">
177 ······<cpe-lang:logical-test·operator="AND"·negate="false">163 ······<cpe-lang:logical-test·operator="AND"·negate="false">
178 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
179 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
180 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>166 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
181 ······</cpe-lang:logical-test>167 ······</cpe-lang:logical-test>
182 ····</cpe-lang:platform>168 ····</cpe-lang:platform>
183 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">169 ····<cpe-lang:platform·id="package_chrony">
 170 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 171 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
 172 ······</cpe-lang:logical-test>
 173 ····</cpe-lang:platform>
 174 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">
184 ······<cpe-lang:logical-test·operator="AND"·negate="false">175 ······<cpe-lang:logical-test·operator="AND"·negate="false">
185 ········<cpe-lang:logical-test·operator="AND"·negate="true">176 ········<cpe-lang:logical-test·operator="AND"·negate="true">
186 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>177 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-uos20-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
187 ········</cpe-lang:logical-test>178 ········</cpe-lang:logical-test>
188 ········<cpe-lang:logical-test·operator="AND"·negate="true">179 ········<cpe-lang:logical-test·operator="AND"·negate="true">
Max diff block lines reached; 472023/484905 bytes (97.34%) of diff not shown.