Hardening campaign

beforeE279/527 passing (52%)before.json
afterB557/561 passing (99%)after.json

Scope delta

Every control's state before and after. The applicable set can grow when the baseline installs components (auditd, AIDE...), so compare transitions, not raw pass rates.

TransitionControls
Failed -> passed (fixed)243
Newly applicable -> passed33
New control -> passed4
Passed -> passed (held)277
Failed -> failed (still failing)4
Failed -> not applicable1
Passed -> not applicable1
Removed (was passing)1
Fixed (failed -> passed) 243

Gaps the remediation closed.

mediumaccount-disable-inactive-pwSet Account Expiration Following InactivityAccounts (login.defs)
mediumaudit-dac-modificationRecord Events that Modify the System's Discretionary Access Controls - chmodAudit (auditd)
mediumaudit-execution-chaclRecord Any Attempts to Run chaclAudit (auditd)
mediumaudit-file-deletion-eventsEnsure auditd Collects File Deletion Events by User - renameAudit (auditd)
mediumaudit-immutableMake the auditd Configuration ImmutableAudit (auditd)
mediumaudit-login-eventsRecord Attempts to Alter Logon and Logout Events - faillockAudit (auditd)
mediumaudit-mac-modificationRecord Events that Modify the System's Mandatory Access ControlsAudit (auditd)
mediumaudit-media-exportEnsure auditd Collects Information on Exporting to Media (successful)Audit (auditd)
mediumaudit-networkconfig-modificationRecord Events that Modify the System's Network EnvironmentAudit (auditd)
mediumaudit-session-eventsRecord Attempts to Alter Process and Session Initiation InformationAudit (auditd)
mediumaudit-suid-auid-privilege-functionRecord Events When Executables Are Run As Another UserAudit (auditd)
mediumaudit-sysadmin-actionsEnsure auditd Collects System Administrator ActionsAudit (auditd)
mediumaudit-timeRecord attempts to alter time through adjtimexAudit (auditd)
mediumaudit-time-clock-settimeRecord Attempts to Alter Time Through clock_settimeAudit (auditd)
mediumaudit-unsuccessful-file-modificationRecord Unsuccessful Access Attempts to Files - creatAudit (auditd)
mediumaudit-usergroup-modificationRecord Events that Modify User/Group Information - /etc/groupAudit (auditd)
mediumauditd-action-mail-acctConfigure auditd mail_acct Action on Low Disk SpaceAudit (auditd daemon)
mediumauditd-admin-space-left-actionConfigure auditd admin_space_left Action on Low Disk SpaceAudit (auditd daemon)
mediumauditd-disk-error-actionConfigure auditd Disk Error Action on Disk ErrorAudit (auditd daemon)
mediumauditd-disk-full-actionConfigure auditd Disk Full Action when Disk Space Is FullAudit (auditd daemon)
mediumauditd-max-log-fileConfigure auditd Max Log File SizeAudit (auditd daemon)
mediumauditd-max-log-file-actionConfigure auditd max_log_file_action Upon Reaching Maximum Log SizeAudit (auditd daemon)
mediumauditd-space-left-actionConfigure auditd space_left Action on Low Disk SpaceAudit (auditd daemon)
mediumbanner-issueEnsure Local Login Warning Banner Is Configured ProperlyBanners
lowcmdline-auditEnable Auditing for Processes Which Start Prior to the Audit DaemonKernel command line
lowcmdline-audit-backlog-limitExtend Audit Backlog Limit for the Audit DaemonKernel command line
highcmdline-l1tfConfigure L1 Terminal Fault mitigationsKernel command line
mediumcmdline-mceForce kernel panic on uncorrected MCEsKernel command line
mediumcmdline-mdsConfigure Microarchitectural Data Sampling mitigationKernel command line
mediumcmdline-page-alloc-shuffleEnable randomization of the page allocatorKernel command line
mediumcmdline-page-poisonEnable page allocator poisoningKernel command line
lowcmdline-ptiEnable Kernel Page-Table Isolation (KPTI)Kernel command line
lowcmdline-rng-core-default-qualityConfigure the confidence in TPM for entropyKernel command line
mediumcmdline-slab-nomergeDisable merging of slabs with similar sizeKernel command line
mediumcmdline-slub-debugEnable SLUB/SLAB allocator poisoningKernel command line
mediumcmdline-spec-store-bypass-disableConfigure Speculative Store Bypass MitigationKernel command line
highcmdline-spectre-v2Enforce Spectre v2 mitigationKernel command line
mediumfaillock-denyLock Accounts After Failed Password AttemptsAccounts (faillock)
mediumfaillock-unlock_timeSet Lockout Time for Failed Password AttemptsAccounts (faillock)
mediumfile-at-allow-existsEnsure that /etc/at.allow existsCron/at access control
mediumfile-cron-allow-existsEnsure that /etc/cron.allow existsCron/at access control
mediumfilegroupownerships-var-log-aptVerify Groupownership of Files in /var/log/aptFile ownership
mediumfileperm-cron-dVerify Permissions on cron.dFile permissions
mediumfileperm-cron-dailyVerify Permissions on cron.dailyFile permissions
mediumfileperm-cron-weeklyVerify Permissions on cron.weeklyFile permissions
mediumfileperm-grub2-cfgVerify /boot/grub/grub.cfg PermissionsFile permissions
mediumfileperm-sshd-configVerify Permissions on SSH Server config fileFile permissions
lowfileperm-systemmapVerify Permissions on System.map FilesFile permissions
mediumfindloop-file-groupownership-system-commands-dirsVerify that system commands files are group owned by root or a system accountFilesystem (scan)
mediumfindloop-permissions-local-var-logVerify permissions of log filesFilesystem (scan)
highfirewall-default-denyEnsure the Host Firewall Defaults to Deny (any backend)Firewall
highfirewall-presentA host firewall is installed and activeFirewall
highgrub-passwordSet Boot Loader Password in grub2Bootloader (grub)
mediumhome-files-permissionsAll User Files and Directories In The Home Directory Must Have Mode 0750 Or Less PermissiveAccounts (home dirs)
mediumjournald-compressEnsure journald is configured to compress large log filesLogging (journald)
mediumjournald-storageEnsure journald is configured to write log files to persistent diskLogging (journald)
lowkmod-cramfs-disabledDisable Mounting of cramfsKernel modules
mediumkmod-dccp-disabledDisable DCCP SupportKernel modules
lowkmod-freevxfs-disabledDisable Mounting of freevxfsKernel modules
lowkmod-hfs-disabledDisable Mounting of hfsKernel modules
lowkmod-hfsplus-disabledDisable Mounting of hfsplusKernel modules
lowkmod-jffs2-disabledDisable Mounting of jffs2Kernel modules
lowkmod-rds-disabledDisable RDS SupportKernel modules
mediumkmod-sctp-disabledDisable SCTP SupportKernel modules
lowkmod-squashfs-disabledDisable Mounting of squashfsKernel modules
lowkmod-tipc-disabledDisable TIPC SupportKernel modules
lowkmod-udf-disabledDisable Mounting of udfKernel modules
mediumkmod-usb-storage-disabledDisable Modprobe Loading of USB Storage DriverKernel modules
mediumlogging-presentA system logging daemon is activeLogging
mediumlogindefs-pass_max_daysSet Password Maximum AgeAccounts (login.defs)
mediumlogindefs-pass_min_daysSet Password Minimum AgeAccounts (login.defs)
mediumlogindefs-pass_min_lenMinimum password length (per-standard threshold)Accounts (login.defs)
mediumlogindefs-sha-crypt-roundsSet SHA_CRYPT minimum rounds in login.defsAccounts (login.defs)
mediummisc-accounts-tmoutSet Interactive Session TimeoutHardening (misc)
mediummisc-aide-build-databaseBuild and Test AIDE DatabaseHardening (misc)
mediummisc-aide-periodic-checking-systemd-timerConfigure Systemd Timer Execution of AIDEHardening (misc)
mediummisc-sshd-limit-user-accessLimit Users' SSH AccessHardening (misc)
mediummisc-use-pam-wheel-group-for-suEnforce Usage of pam_wheel with Group Parameter for su AuthenticationHardening (misc)
mediummount-dev-shm-nodevAdd nodev Option to /dev/shmMounts
mediummount-dev-shm-noexecAdd noexec Option to /dev/shmMounts
mediummount-dev-shm-nosuidAdd nosuid Option to /dev/shmMounts
mediummount-home-nodevAdd nodev Option to /homeMounts
mediummount-home-noexecAdd noexec Option to /homeMounts
mediummount-home-nosuidAdd nosuid Option to /homeMounts
mediummount-opt-nosuidAdd nosuid Option to /optMounts
mediummount-srv-nosuidAdd nosuid Option to /srvMounts
mediummount-tmp-nodevAdd nodev Option to /tmpMounts
mediummount-tmp-noexecAdd noexec Option to /tmpMounts
mediummount-tmp-nosuidAdd nosuid Option to /tmpMounts
mediummount-var-log-audit-nodevAdd nodev Option to /var/log/auditMounts
mediummount-var-log-audit-noexecAdd noexec Option to /var/log/auditMounts
mediummount-var-log-audit-nosuidAdd nosuid Option to /var/log/auditMounts
mediummount-var-log-nodevAdd nodev Option to /var/logMounts
mediummount-var-log-noexecAdd noexec Option to /var/logMounts
mediummount-var-log-nosuidAdd nosuid Option to /var/logMounts
mediummount-var-nodevAdd nodev Option to /varMounts
mediummount-var-nosuidAdd nosuid Option to /varMounts
mediummount-var-tmp-nodevAdd nodev Option to /var/tmpMounts
mediummount-var-tmp-noexecAdd noexec Option to /var/tmpMounts
mediummount-var-tmp-nosuidAdd nosuid Option to /var/tmpMounts
mediumpam-faillock-auditAccount Lockouts Must Be LoggedAccounts (PAM modules)
mediumpam-faillock-deny-rootConfigure the root Account for Failed Password AttemptsAccounts (PAM modules)
mediumpam-faillock-enabledEnsure pam_faillock module is enabledAccounts (PAM modules)
mediumpam-faillock-root-unlock-timeSet the faillock Root Account Unlock TimeAccounts (faillock)
mediumpam-pwhistory-enabledVerify pam_pwhistory module is activatedAccounts (PAM modules)
mediumpam-pwhistory-enforceLimit Password ReuseAccounts (PAM modules)
mediumpam-pwhistory-use-authtokEnforce Password History with use_authtokAccounts (PAM modules)
mediumpam-pwquality-enabledVerify pam_pwquality module is activatedAccounts (PAM modules)
mediumpam-remember-pwhistory-rememberLimit Password ReuseAccounts (password history)
mediumpam-remember-unix-rememberLimit Password ReuseAccounts (password history)
mediumpam-unix-authtokRequire use_authtok for pam_unix.soAccounts (PAM modules)
highpam-unix-no-nullokDisallow Empty Passwords in pam_unix (no nullok)Accounts (PAM modules)
mediumpam-unix-rounds-password-authSet number of Password Hashing Rounds - password-authAccounts (PAM modules)
lowpartition-homeEnsure /home Located On Separate PartitionMounts
mediumpartition-optEnsure /opt Located On Separate PartitionMounts
mediumpartition-srvEnsure /srv Located On Separate PartitionMounts
lowpartition-tmpEnsure /tmp Located On Separate PartitionMounts
lowpartition-varEnsure /var Located On Separate PartitionMounts
lowpartition-var-logEnsure /var/log Located On Separate PartitionMounts
lowpartition-var-log-auditEnsure /var/log/audit Located On Separate PartitionMounts
mediumpartition-var-tmpEnsure /var/tmp Located On Separate PartitionMounts
mediumpkg-aide-installedInstall AIDEPackages
mediumpkg-apparmor-utils-installedEnsure AppArmor Utils is installedPackages
mediumpkg-apt-listbugs-installedInstall apt-listbugs (critical-bug warnings before APT)Packages
mediumpkg-apt-show-versions-installedInstall apt-show-versions (patch management)Packages
mediumpkg-audispd-plugins-installedEnsure the default plugins for the audit dispatcher are InstalledPackages
mediumpkg-audit-installedEnsure the audit Subsystem is InstalledPackages
mediumpkg-cron-installedInstall the cron servicePackages
mediumpkg-debsums-installedInstall debsums (verify installed package files)Packages
mediumpkg-fail2ban-installedInstall fail2ban (brute-force protection)Packages
mediumpkg-libpam-apparmor-installedInstall the pam_apparmor PackagePackages
mediumpkg-libpam-tmpdir-installedInstall libpam-tmpdir (per-session TMPDIR)Packages
mediumpkg-logrotate-installedEnsure logrotate is InstalledPackages
mediumpkg-needrestart-installedInstall needrestart (detect stale libraries after upgrades)Packages
mediumpkg-pam-pwquality-installedInstall pam_pwquality PackagePackages
mediumpkg-postfix-installedThe Postfix package is installedPackages
mediumpkg-rsync-removedUninstall rsync PackagePackages
mediumpkg-sssd-installedInstall the SSSD PackagePackages
mediumpkg-systemd-journal-remote-installedInstall systemd-journal-remote PackagePackages
mediumposture-core-dumps-limitsCore dumps disabled (limits hard core 0)Hardening (posture)
mediumposture-file-integrityA file integrity tool is installedHardening (posture)
mediumposture-malware-scannerAn anti-malware tool is installedHardening (posture)
lowposture-process-accountingProcess accounting enabledHardening (posture)
lowposture-sysstatSystem statistics collection (sysstat)Hardening (posture)
mediumpwquality-dcreditEnsure PAM Enforces Password Requirements - Minimum Digit CharactersPasswords (pwquality)
mediumpwquality-dictcheckEnsure PAM Enforces Password Requirements - Prevent the Use of Dictionary WordsPasswords (pwquality)
mediumpwquality-difokEnsure PAM Enforces Password Requirements - Minimum Different CharactersPasswords (pwquality)
mediumpwquality-enforce-rootEnforce Password Quality for the root UserPasswords (pwquality)
mediumpwquality-lcreditEnsure PAM Enforces Password Requirements - Minimum Lowercase CharactersPasswords (pwquality)
mediumpwquality-maxrepeatSet Password Maximum Consecutive Repeating CharactersPasswords (pwquality)
mediumpwquality-maxsequenceLimit the maximum number of sequential characters in passwordsPasswords (pwquality)
mediumpwquality-minclassEnsure PAM Enforces Password Requirements - Minimum Different CategoriesPasswords (pwquality)
mediumpwquality-minlenEnsure PAM Enforces Password Requirements - Minimum LengthPasswords (pwquality)
mediumpwquality-ocreditEnsure PAM Enforces Password Requirements - Minimum Special CharactersPasswords (pwquality)
mediumpwquality-retryEnsure PAM Enforces Password Requirements - Authentication Retry Prompts Permitted Per-SessionPasswords (pwquality)
mediumpwquality-ucreditEnsure PAM Enforces Password Requirements - Minimum Uppercase CharactersPasswords (pwquality)
mediumservice-auditd-enabledEnable auditd Servicesystemd services
mediumservice-cron-enabledEnable cron Servicesystemd services
mediumssh-disable-agent-forwardingDisable SSH Agent ForwardingSSH
mediumssh-disable-compressionDisable Compression Or Set Compression to delayedSSH
mediumssh-disable-forwardingDisable SSH ForwardingSSH
criticalssh-disable-root-loginDisable SSH Root LoginSSH
mediumssh-disable-tcp-forwardingDisable SSH TCP ForwardingSSH
mediumssh-disable-tcpkeepaliveDisable SSH TCPKeepAlive (use ClientAlive instead)SSH
mediumssh-disable-user-known-hostsDisable SSH Support for User Known HostsSSH
mediumssh-disable-x11-forwardingDisable SSH X11 ForwardingSSH
mediumssh-enable-warning-banner-netEnable SSH Warning BannerSSH
mediumssh-set-idle-timeoutSet SSH Client Alive IntervalSSH
mediumssh-set-login-grace-timeEnsure SSH LoginGraceTime is configuredSSH
mediumssh-set-loglevel-verboseSet SSH Daemon LogLevel to VERBOSESSH
mediumssh-set-max-auth-triesSet SSH authentication attempt limitSSH
mediumssh-set-maxstartupsEnsure SSH MaxStartups is configuredSSH
mediumssh-set-rekey-limitForce Frequent SSH Session Key RenegotiationSSH
mediumssh-use-strong-ciphersUse Only Strong CiphersSSH
mediumssh-use-strong-kexUse Only Strong Key Exchange algorithmsSSH
mediumssh-use-strong-macsUse Only Strong MACsSSH
lowsudo-custom-logfileEnsure Sudo Logfile Exists - sudo logfileSudo
mediumsudo-ignore-dotEnsure sudo Ignores Commands In Current Dir - sudo ignore_dotSudo
highsudo-noexecEnsure Privileged Escalated Commands Cannot Execute Other Commands - sudo NOEXECSudo
mediumsudo-requirettyEnsure Only Users Logged In To Real tty Can Execute Sudo - sudo requirettySudo
mediumsudo-umaskEnsure sudo umask is appropriate - sudo umaskSudo
mediumsysctl-dev-tty-ldisc-autoloadDisable Automatic Line Discipline AutoloadKernel & network (sysctl)
mediumsysctl-fs-protected_fifosEnable Kernel Parameter to Enforce DAC on FIFOsKernel & network (sysctl)
mediumsysctl-fs-suid_dumpableDisable Core Dumps for SUID programsKernel & network (sysctl)
lowsysctl-kernel-dmesg_restrictRestrict Access to Kernel Message BufferKernel & network (sysctl)
mediumsysctl-kernel-kptr_restrictRestrict Exposed Kernel Pointer Addresses AccessKernel & network (sysctl)
mediumsysctl-kernel-panic_on_oopsKernel panic on oopsKernel & network (sysctl)
mediumsysctl-kernel-perf_cpu_time_max_percentLimit CPU consumption of the Perf systemKernel & network (sysctl)
mediumsysctl-kernel-perf_event_max_sample_rateLimit sampling frequency of the Perf systemKernel & network (sysctl)
lowsysctl-kernel-perf_event_paranoidDisallow kernel profiling by unprivileged usersKernel & network (sysctl)
mediumsysctl-kernel-randomize_va_spaceEnable Randomized Layout of Virtual Address SpaceKernel & network (sysctl)
mediumsysctl-kernel-sysrqDisallow magic SysRq keyKernel & network (sysctl)
mediumsysctl-kernel-unprivileged_bpf_disabledDisable Access to Network bpf() Syscall From Unprivileged ProcessesKernel & network (sysctl)
mediumsysctl-kernel-yama-ptrace_scopeRestrict usage of ptrace to descendant processesKernel & network (sysctl)
mediumsysctl-net-core-bpf_jit_hardenHarden the operation of the BPF just-in-time compilerKernel & network (sysctl)
mediumsysctl-net-ipv4-conf-all-accept_localDisable Accepting Packets Routed Between Local InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv4-conf-all-accept_redirectsDisable Accepting ICMP Redirects for All IPv4 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv4-conf-all-accept_source_routeDisable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv4-conf-all-arp_filterConfigure ARP filtering for All IPv4 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv4-conf-all-arp_ignoreConfigure Response Mode of ARP Requests for All IPv4 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv4-conf-all-drop_gratuitous_arpDrop Gratuitous ARP frames on All IPv4 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv4-conf-all-log_martiansEnable Kernel Parameter to Log Martian Packets on all IPv4 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv4-conf-all-route_localnetPrevent Routing External Traffic to Local Loopback on All IPv4 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv4-conf-all-rp_filterEnable Kernel Parameter to Use Reverse Path Filtering on all IPv4 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv4-conf-all-secure_redirectsDisable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv4-conf-all-send_redirectsDisable Kernel Parameter for Sending ICMP Redirects on all IPv4 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv4-conf-all-shared_mediaConfigure Sending and Accepting Shared Media Redirects for All IPv4 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv4-conf-default-accept_redirectsDisable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv4-conf-default-accept_source_routeDisable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by DefaultKernel & network (sysctl)
mediumsysctl-net-ipv4-conf-default-log_martiansEnable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces by DefaultKernel & network (sysctl)
mediumsysctl-net-ipv4-conf-default-rp_filterEnable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by DefaultKernel & network (sysctl)
mediumsysctl-net-ipv4-conf-default-secure_redirectsConfigure Kernel Parameter for Accepting Secure Redirects By DefaultKernel & network (sysctl)
mediumsysctl-net-ipv4-conf-default-send_redirectsDisable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by DefaultKernel & network (sysctl)
mediumsysctl-net-ipv4-conf-default-shared_mediaConfigure Sending and Accepting Shared Media Redirects by DefaultKernel & network (sysctl)
mediumsysctl-net-ipv4-icmp_echo_ignore_broadcastsEnable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv4-icmp_ignore_bogus_error_responsesEnable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv4-ip_forwardDisable Kernel Parameter for IP Forwarding on IPv4 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv4-ip_local_port_rangeSet Kernel Parameter to Increase Local Port RangeKernel & network (sysctl)
mediumsysctl-net-ipv4-tcp_rfc1337Enable Kernel Parameter to Use TCP RFC 1337 on IPv4 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv4-tcp_syncookiesEnable Kernel Parameter to Use TCP Syncookies on Network InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv6-conf-all-accept_raConfigure Accepting Router Advertisements on All IPv6 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv6-conf-all-accept_ra_defrtrConfigure Accepting Default Router in Router Advertisements on All IPv6 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv6-conf-all-accept_ra_pinfoConfigure Accepting Prefix Information in Router Advertisements on All IPv6 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv6-conf-all-accept_ra_rtr_prefConfigure Accepting Router Preference in Router Advertisements on All IPv6 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv6-conf-all-accept_redirectsDisable Accepting ICMP Redirects for All IPv6 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv6-conf-all-accept_source_routeDisable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv6-conf-all-autoconfConfigure Auto Configuration on All IPv6 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv6-conf-all-forwardingDisable Kernel Parameter for IPv6 ForwardingKernel & network (sysctl)
mediumsysctl-net-ipv6-conf-all-max_addressesConfigure Maximum Number of Autoconfigured Addresses on All IPv6 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv6-conf-all-router_solicitationsConfigure Denying Router Solicitations on All IPv6 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv6-conf-default-accept_raDisable Accepting Router Advertisements on all IPv6 Interfaces by DefaultKernel & network (sysctl)
mediumsysctl-net-ipv6-conf-default-accept_ra_defrtrConfigure Accepting Default Router in Router Advertisements on All IPv6 Interfaces By DefaultKernel & network (sysctl)
mediumsysctl-net-ipv6-conf-default-accept_ra_pinfoConfigure Accepting Prefix Information in Router Advertisements on All IPv6 Interfaces By DefaultKernel & network (sysctl)
mediumsysctl-net-ipv6-conf-default-accept_ra_rtr_prefConfigure Accepting Router Preference in Router Advertisements on All IPv6 Interfaces By DefaultKernel & network (sysctl)
mediumsysctl-net-ipv6-conf-default-accept_redirectsDisable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 InterfacesKernel & network (sysctl)
mediumsysctl-net-ipv6-conf-default-accept_source_routeDisable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by DefaultKernel & network (sysctl)
mediumsysctl-net-ipv6-conf-default-autoconfConfigure Auto Configuration on All IPv6 Interfaces By DefaultKernel & network (sysctl)
mediumsysctl-net-ipv6-conf-default-max_addressesConfigure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces By DefaultKernel & network (sysctl)
mediumsysctl-net-ipv6-conf-default-router_solicitationsConfigure Denying Router Solicitations on All IPv6 Interfaces By DefaultKernel & network (sysctl)
mediumsysctl-vm-mmap_min_addrPrevent applications from mapping low portion of virtual memoryKernel & network (sysctl)
mediumumask-etc-bashrcEnsure the Default Bash Umask is Set Correctly (077)Accounts (umask)
mediumumask-etc-login-defsEnsure the Default Umask is Set Correctly in login.defs (077)Accounts (umask)
mediumumask-etc-profileEnsure the Default Umask is Set Correctly in /etc/profile (077)Accounts (umask)
Still failing (failed -> failed) 4

Gaps the remediation did not close (manual, install-time or kernel-build).

lowkmod-overlayfs-disabledEnsure overlayfs kernel module is not availableKernel modules
mediummount-boot-noexecAdd noexec Option to /bootMounts
mediummount-boot-nosuidAdd nosuid Option to /bootMounts
mediumpartition-bootEnsure /boot Located On Separate PartitionMounts
Newly applicable, passing 37

Controls the baseline made evaluable and that now pass.

mediumfilegroupowner-at-allowVerify Group Who Owns /etc/at.allow fileFile ownership
mediumfilegroupowner-cron-allowVerify Group Who Owns /etc/cron.allow fileFile ownership
mediumfilegroupowner-cron-hourlyVerify Group Who Owns cron.hourlyFile ownership
mediumfilegroupowner-cron-monthlyVerify Group Who Owns cron.monthlyFile ownership
mediumfilegroupowner-crontabVerify Group Who Owns CrontabFile ownership
mediumfilegroupowner-var-log-authVerify Group Who Owns /var/log/auth.log FileFile ownership
mediumfilegroupowner-var-log-syslogVerify Group Who Owns /var/log/syslog FileFile ownership
mediumfilegroupownership-audit-binariesVerify that audit tools are owned by group rootFile ownership
mediumfilegroupownership-audit-configurationAudit Configuration Files Must Be Owned By Group rootFile ownership
mediumfileowner-at-allowVerify User Who Owns /etc/at.allow fileFile ownership
mediumfileowner-cron-allowVerify User Who Owns /etc/cron.allow fileFile ownership
mediumfileowner-cron-hourlyVerify Owner on cron.hourlyFile ownership
mediumfileowner-cron-monthlyVerify Owner on cron.monthlyFile ownership
mediumfileowner-crontabVerify Owner on crontabFile ownership
mediumfileowner-var-log-authVerify User Who Owns /var/log/auth.log FileFile ownership
mediumfileowner-var-log-syslogVerify User Who Owns /var/log/syslog FileFile ownership
mediumfileownership-audit-binariesVerify that audit tools are owned by rootFile ownership
mediumfileownership-audit-configurationAudit Configuration Files Must Be Owned By RootFile ownership
mediumfileperm-at-allowVerify Permissions on /etc/at.allow fileFile permissions
mediumfileperm-audit-binariesVerify that audit tools Have Mode 0755 or lessFile permissions
mediumfileperm-cron-allowVerify Permissions on /etc/cron.allow fileFile permissions
mediumfileperm-cron-hourlyVerify Permissions on cron.hourlyFile permissions
mediumfileperm-cron-monthlyVerify Permissions on cron.monthlyFile permissions
mediumfileperm-crontabVerify Permissions on crontabFile permissions
mediumfileperm-etc-audit-auditdVerify Permissions on /etc/audit/auditd.confFile permissions
mediumfileperm-etc-audit-rulesVerify Permissions on /etc/audit/audit.rulesFile permissions
mediumfileperm-var-log-auditSystem Audit Logs Must Have Mode 0750 or Less PermissiveFile permissions
mediumfileperm-var-log-authVerify Permissions on /var/log/auth.log FileFile permissions
mediumfileperm-var-log-cloud-initVerify Permissions on /var/log/cloud-init.log(.*) FilesFile permissions
mediumfileperm-var-log-sssdVerify Permissions of Files in /var/log/sssdFile permissions
mediumfileperm-var-log-syslogVerify Permissions on /var/log/syslog FileFile permissions
mediumgroupownerships-var-log-sssdVerify Grouponwership of Files in /var/log/sssdFile ownership
mediumownerships-var-log-sssdVerify Ownership of Files in /var/log/sssdFile ownership
mediumgrowth-journal-boundedThe systemd journal is bounded (SystemMaxUse)Hardening (posture)
mediumgrowth-logrotate-activeLog rotation actually runs (logrotate is scheduled)Hardening (posture)
lowgrowth-tmp-cleanedTemporary filesystems are cleaned (systemd-tmpfiles)Hardening (posture)
highjournald-forward-to-running-syslogjournald forwards to the syslog daemon that is actually runningHardening (posture)