Hardening campaign
beforeEbefore.json
→
afterBafter.json
Scope delta
Every control's state before and after. The applicable set can grow when the baseline installs components (auditd, AIDE...), so compare transitions, not raw pass rates.
| Transition | Controls |
|---|---|
| Failed -> passed (fixed) | 243 |
| Newly applicable -> passed | 33 |
| New control -> passed | 4 |
| Passed -> passed (held) | 277 |
| Failed -> failed (still failing) | 4 |
| Failed -> not applicable | 1 |
| Passed -> not applicable | 1 |
| Removed (was passing) | 1 |
Fixed (failed -> passed) 243
Gaps the remediation closed.
| medium | account-disable-inactive-pw | Set Account Expiration Following Inactivity | Accounts (login.defs) |
| medium | audit-dac-modification | Record Events that Modify the System's Discretionary Access Controls - chmod | Audit (auditd) |
| medium | audit-execution-chacl | Record Any Attempts to Run chacl | Audit (auditd) |
| medium | audit-file-deletion-events | Ensure auditd Collects File Deletion Events by User - rename | Audit (auditd) |
| medium | audit-immutable | Make the auditd Configuration Immutable | Audit (auditd) |
| medium | audit-login-events | Record Attempts to Alter Logon and Logout Events - faillock | Audit (auditd) |
| medium | audit-mac-modification | Record Events that Modify the System's Mandatory Access Controls | Audit (auditd) |
| medium | audit-media-export | Ensure auditd Collects Information on Exporting to Media (successful) | Audit (auditd) |
| medium | audit-networkconfig-modification | Record Events that Modify the System's Network Environment | Audit (auditd) |
| medium | audit-session-events | Record Attempts to Alter Process and Session Initiation Information | Audit (auditd) |
| medium | audit-suid-auid-privilege-function | Record Events When Executables Are Run As Another User | Audit (auditd) |
| medium | audit-sysadmin-actions | Ensure auditd Collects System Administrator Actions | Audit (auditd) |
| medium | audit-time | Record attempts to alter time through adjtimex | Audit (auditd) |
| medium | audit-time-clock-settime | Record Attempts to Alter Time Through clock_settime | Audit (auditd) |
| medium | audit-unsuccessful-file-modification | Record Unsuccessful Access Attempts to Files - creat | Audit (auditd) |
| medium | audit-usergroup-modification | Record Events that Modify User/Group Information - /etc/group | Audit (auditd) |
| medium | auditd-action-mail-acct | Configure auditd mail_acct Action on Low Disk Space | Audit (auditd daemon) |
| medium | auditd-admin-space-left-action | Configure auditd admin_space_left Action on Low Disk Space | Audit (auditd daemon) |
| medium | auditd-disk-error-action | Configure auditd Disk Error Action on Disk Error | Audit (auditd daemon) |
| medium | auditd-disk-full-action | Configure auditd Disk Full Action when Disk Space Is Full | Audit (auditd daemon) |
| medium | auditd-max-log-file | Configure auditd Max Log File Size | Audit (auditd daemon) |
| medium | auditd-max-log-file-action | Configure auditd max_log_file_action Upon Reaching Maximum Log Size | Audit (auditd daemon) |
| medium | auditd-space-left-action | Configure auditd space_left Action on Low Disk Space | Audit (auditd daemon) |
| medium | banner-issue | Ensure Local Login Warning Banner Is Configured Properly | Banners |
| low | cmdline-audit | Enable Auditing for Processes Which Start Prior to the Audit Daemon | Kernel command line |
| low | cmdline-audit-backlog-limit | Extend Audit Backlog Limit for the Audit Daemon | Kernel command line |
| high | cmdline-l1tf | Configure L1 Terminal Fault mitigations | Kernel command line |
| medium | cmdline-mce | Force kernel panic on uncorrected MCEs | Kernel command line |
| medium | cmdline-mds | Configure Microarchitectural Data Sampling mitigation | Kernel command line |
| medium | cmdline-page-alloc-shuffle | Enable randomization of the page allocator | Kernel command line |
| medium | cmdline-page-poison | Enable page allocator poisoning | Kernel command line |
| low | cmdline-pti | Enable Kernel Page-Table Isolation (KPTI) | Kernel command line |
| low | cmdline-rng-core-default-quality | Configure the confidence in TPM for entropy | Kernel command line |
| medium | cmdline-slab-nomerge | Disable merging of slabs with similar size | Kernel command line |
| medium | cmdline-slub-debug | Enable SLUB/SLAB allocator poisoning | Kernel command line |
| medium | cmdline-spec-store-bypass-disable | Configure Speculative Store Bypass Mitigation | Kernel command line |
| high | cmdline-spectre-v2 | Enforce Spectre v2 mitigation | Kernel command line |
| medium | faillock-deny | Lock Accounts After Failed Password Attempts | Accounts (faillock) |
| medium | faillock-unlock_time | Set Lockout Time for Failed Password Attempts | Accounts (faillock) |
| medium | file-at-allow-exists | Ensure that /etc/at.allow exists | Cron/at access control |
| medium | file-cron-allow-exists | Ensure that /etc/cron.allow exists | Cron/at access control |
| medium | filegroupownerships-var-log-apt | Verify Groupownership of Files in /var/log/apt | File ownership |
| medium | fileperm-cron-d | Verify Permissions on cron.d | File permissions |
| medium | fileperm-cron-daily | Verify Permissions on cron.daily | File permissions |
| medium | fileperm-cron-weekly | Verify Permissions on cron.weekly | File permissions |
| medium | fileperm-grub2-cfg | Verify /boot/grub/grub.cfg Permissions | File permissions |
| medium | fileperm-sshd-config | Verify Permissions on SSH Server config file | File permissions |
| low | fileperm-systemmap | Verify Permissions on System.map Files | File permissions |
| medium | findloop-file-groupownership-system-commands-dirs | Verify that system commands files are group owned by root or a system account | Filesystem (scan) |
| medium | findloop-permissions-local-var-log | Verify permissions of log files | Filesystem (scan) |
| high | firewall-default-deny | Ensure the Host Firewall Defaults to Deny (any backend) | Firewall |
| high | firewall-present | A host firewall is installed and active | Firewall |
| high | grub-password | Set Boot Loader Password in grub2 | Bootloader (grub) |
| medium | home-files-permissions | All User Files and Directories In The Home Directory Must Have Mode 0750 Or Less Permissive | Accounts (home dirs) |
| medium | journald-compress | Ensure journald is configured to compress large log files | Logging (journald) |
| medium | journald-storage | Ensure journald is configured to write log files to persistent disk | Logging (journald) |
| low | kmod-cramfs-disabled | Disable Mounting of cramfs | Kernel modules |
| medium | kmod-dccp-disabled | Disable DCCP Support | Kernel modules |
| low | kmod-freevxfs-disabled | Disable Mounting of freevxfs | Kernel modules |
| low | kmod-hfs-disabled | Disable Mounting of hfs | Kernel modules |
| low | kmod-hfsplus-disabled | Disable Mounting of hfsplus | Kernel modules |
| low | kmod-jffs2-disabled | Disable Mounting of jffs2 | Kernel modules |
| low | kmod-rds-disabled | Disable RDS Support | Kernel modules |
| medium | kmod-sctp-disabled | Disable SCTP Support | Kernel modules |
| low | kmod-squashfs-disabled | Disable Mounting of squashfs | Kernel modules |
| low | kmod-tipc-disabled | Disable TIPC Support | Kernel modules |
| low | kmod-udf-disabled | Disable Mounting of udf | Kernel modules |
| medium | kmod-usb-storage-disabled | Disable Modprobe Loading of USB Storage Driver | Kernel modules |
| medium | logging-present | A system logging daemon is active | Logging |
| medium | logindefs-pass_max_days | Set Password Maximum Age | Accounts (login.defs) |
| medium | logindefs-pass_min_days | Set Password Minimum Age | Accounts (login.defs) |
| medium | logindefs-pass_min_len | Minimum password length (per-standard threshold) | Accounts (login.defs) |
| medium | logindefs-sha-crypt-rounds | Set SHA_CRYPT minimum rounds in login.defs | Accounts (login.defs) |
| medium | misc-accounts-tmout | Set Interactive Session Timeout | Hardening (misc) |
| medium | misc-aide-build-database | Build and Test AIDE Database | Hardening (misc) |
| medium | misc-aide-periodic-checking-systemd-timer | Configure Systemd Timer Execution of AIDE | Hardening (misc) |
| medium | misc-sshd-limit-user-access | Limit Users' SSH Access | Hardening (misc) |
| medium | misc-use-pam-wheel-group-for-su | Enforce Usage of pam_wheel with Group Parameter for su Authentication | Hardening (misc) |
| medium | mount-dev-shm-nodev | Add nodev Option to /dev/shm | Mounts |
| medium | mount-dev-shm-noexec | Add noexec Option to /dev/shm | Mounts |
| medium | mount-dev-shm-nosuid | Add nosuid Option to /dev/shm | Mounts |
| medium | mount-home-nodev | Add nodev Option to /home | Mounts |
| medium | mount-home-noexec | Add noexec Option to /home | Mounts |
| medium | mount-home-nosuid | Add nosuid Option to /home | Mounts |
| medium | mount-opt-nosuid | Add nosuid Option to /opt | Mounts |
| medium | mount-srv-nosuid | Add nosuid Option to /srv | Mounts |
| medium | mount-tmp-nodev | Add nodev Option to /tmp | Mounts |
| medium | mount-tmp-noexec | Add noexec Option to /tmp | Mounts |
| medium | mount-tmp-nosuid | Add nosuid Option to /tmp | Mounts |
| medium | mount-var-log-audit-nodev | Add nodev Option to /var/log/audit | Mounts |
| medium | mount-var-log-audit-noexec | Add noexec Option to /var/log/audit | Mounts |
| medium | mount-var-log-audit-nosuid | Add nosuid Option to /var/log/audit | Mounts |
| medium | mount-var-log-nodev | Add nodev Option to /var/log | Mounts |
| medium | mount-var-log-noexec | Add noexec Option to /var/log | Mounts |
| medium | mount-var-log-nosuid | Add nosuid Option to /var/log | Mounts |
| medium | mount-var-nodev | Add nodev Option to /var | Mounts |
| medium | mount-var-nosuid | Add nosuid Option to /var | Mounts |
| medium | mount-var-tmp-nodev | Add nodev Option to /var/tmp | Mounts |
| medium | mount-var-tmp-noexec | Add noexec Option to /var/tmp | Mounts |
| medium | mount-var-tmp-nosuid | Add nosuid Option to /var/tmp | Mounts |
| medium | pam-faillock-audit | Account Lockouts Must Be Logged | Accounts (PAM modules) |
| medium | pam-faillock-deny-root | Configure the root Account for Failed Password Attempts | Accounts (PAM modules) |
| medium | pam-faillock-enabled | Ensure pam_faillock module is enabled | Accounts (PAM modules) |
| medium | pam-faillock-root-unlock-time | Set the faillock Root Account Unlock Time | Accounts (faillock) |
| medium | pam-pwhistory-enabled | Verify pam_pwhistory module is activated | Accounts (PAM modules) |
| medium | pam-pwhistory-enforce | Limit Password Reuse | Accounts (PAM modules) |
| medium | pam-pwhistory-use-authtok | Enforce Password History with use_authtok | Accounts (PAM modules) |
| medium | pam-pwquality-enabled | Verify pam_pwquality module is activated | Accounts (PAM modules) |
| medium | pam-remember-pwhistory-remember | Limit Password Reuse | Accounts (password history) |
| medium | pam-remember-unix-remember | Limit Password Reuse | Accounts (password history) |
| medium | pam-unix-authtok | Require use_authtok for pam_unix.so | Accounts (PAM modules) |
| high | pam-unix-no-nullok | Disallow Empty Passwords in pam_unix (no nullok) | Accounts (PAM modules) |
| medium | pam-unix-rounds-password-auth | Set number of Password Hashing Rounds - password-auth | Accounts (PAM modules) |
| low | partition-home | Ensure /home Located On Separate Partition | Mounts |
| medium | partition-opt | Ensure /opt Located On Separate Partition | Mounts |
| medium | partition-srv | Ensure /srv Located On Separate Partition | Mounts |
| low | partition-tmp | Ensure /tmp Located On Separate Partition | Mounts |
| low | partition-var | Ensure /var Located On Separate Partition | Mounts |
| low | partition-var-log | Ensure /var/log Located On Separate Partition | Mounts |
| low | partition-var-log-audit | Ensure /var/log/audit Located On Separate Partition | Mounts |
| medium | partition-var-tmp | Ensure /var/tmp Located On Separate Partition | Mounts |
| medium | pkg-aide-installed | Install AIDE | Packages |
| medium | pkg-apparmor-utils-installed | Ensure AppArmor Utils is installed | Packages |
| medium | pkg-apt-listbugs-installed | Install apt-listbugs (critical-bug warnings before APT) | Packages |
| medium | pkg-apt-show-versions-installed | Install apt-show-versions (patch management) | Packages |
| medium | pkg-audispd-plugins-installed | Ensure the default plugins for the audit dispatcher are Installed | Packages |
| medium | pkg-audit-installed | Ensure the audit Subsystem is Installed | Packages |
| medium | pkg-cron-installed | Install the cron service | Packages |
| medium | pkg-debsums-installed | Install debsums (verify installed package files) | Packages |
| medium | pkg-fail2ban-installed | Install fail2ban (brute-force protection) | Packages |
| medium | pkg-libpam-apparmor-installed | Install the pam_apparmor Package | Packages |
| medium | pkg-libpam-tmpdir-installed | Install libpam-tmpdir (per-session TMPDIR) | Packages |
| medium | pkg-logrotate-installed | Ensure logrotate is Installed | Packages |
| medium | pkg-needrestart-installed | Install needrestart (detect stale libraries after upgrades) | Packages |
| medium | pkg-pam-pwquality-installed | Install pam_pwquality Package | Packages |
| medium | pkg-postfix-installed | The Postfix package is installed | Packages |
| medium | pkg-rsync-removed | Uninstall rsync Package | Packages |
| medium | pkg-sssd-installed | Install the SSSD Package | Packages |
| medium | pkg-systemd-journal-remote-installed | Install systemd-journal-remote Package | Packages |
| medium | posture-core-dumps-limits | Core dumps disabled (limits hard core 0) | Hardening (posture) |
| medium | posture-file-integrity | A file integrity tool is installed | Hardening (posture) |
| medium | posture-malware-scanner | An anti-malware tool is installed | Hardening (posture) |
| low | posture-process-accounting | Process accounting enabled | Hardening (posture) |
| low | posture-sysstat | System statistics collection (sysstat) | Hardening (posture) |
| medium | pwquality-dcredit | Ensure PAM Enforces Password Requirements - Minimum Digit Characters | Passwords (pwquality) |
| medium | pwquality-dictcheck | Ensure PAM Enforces Password Requirements - Prevent the Use of Dictionary Words | Passwords (pwquality) |
| medium | pwquality-difok | Ensure PAM Enforces Password Requirements - Minimum Different Characters | Passwords (pwquality) |
| medium | pwquality-enforce-root | Enforce Password Quality for the root User | Passwords (pwquality) |
| medium | pwquality-lcredit | Ensure PAM Enforces Password Requirements - Minimum Lowercase Characters | Passwords (pwquality) |
| medium | pwquality-maxrepeat | Set Password Maximum Consecutive Repeating Characters | Passwords (pwquality) |
| medium | pwquality-maxsequence | Limit the maximum number of sequential characters in passwords | Passwords (pwquality) |
| medium | pwquality-minclass | Ensure PAM Enforces Password Requirements - Minimum Different Categories | Passwords (pwquality) |
| medium | pwquality-minlen | Ensure PAM Enforces Password Requirements - Minimum Length | Passwords (pwquality) |
| medium | pwquality-ocredit | Ensure PAM Enforces Password Requirements - Minimum Special Characters | Passwords (pwquality) |
| medium | pwquality-retry | Ensure PAM Enforces Password Requirements - Authentication Retry Prompts Permitted Per-Session | Passwords (pwquality) |
| medium | pwquality-ucredit | Ensure PAM Enforces Password Requirements - Minimum Uppercase Characters | Passwords (pwquality) |
| medium | service-auditd-enabled | Enable auditd Service | systemd services |
| medium | service-cron-enabled | Enable cron Service | systemd services |
| medium | ssh-disable-agent-forwarding | Disable SSH Agent Forwarding | SSH |
| medium | ssh-disable-compression | Disable Compression Or Set Compression to delayed | SSH |
| medium | ssh-disable-forwarding | Disable SSH Forwarding | SSH |
| critical | ssh-disable-root-login | Disable SSH Root Login | SSH |
| medium | ssh-disable-tcp-forwarding | Disable SSH TCP Forwarding | SSH |
| medium | ssh-disable-tcpkeepalive | Disable SSH TCPKeepAlive (use ClientAlive instead) | SSH |
| medium | ssh-disable-user-known-hosts | Disable SSH Support for User Known Hosts | SSH |
| medium | ssh-disable-x11-forwarding | Disable SSH X11 Forwarding | SSH |
| medium | ssh-enable-warning-banner-net | Enable SSH Warning Banner | SSH |
| medium | ssh-set-idle-timeout | Set SSH Client Alive Interval | SSH |
| medium | ssh-set-login-grace-time | Ensure SSH LoginGraceTime is configured | SSH |
| medium | ssh-set-loglevel-verbose | Set SSH Daemon LogLevel to VERBOSE | SSH |
| medium | ssh-set-max-auth-tries | Set SSH authentication attempt limit | SSH |
| medium | ssh-set-maxstartups | Ensure SSH MaxStartups is configured | SSH |
| medium | ssh-set-rekey-limit | Force Frequent SSH Session Key Renegotiation | SSH |
| medium | ssh-use-strong-ciphers | Use Only Strong Ciphers | SSH |
| medium | ssh-use-strong-kex | Use Only Strong Key Exchange algorithms | SSH |
| medium | ssh-use-strong-macs | Use Only Strong MACs | SSH |
| low | sudo-custom-logfile | Ensure Sudo Logfile Exists - sudo logfile | Sudo |
| medium | sudo-ignore-dot | Ensure sudo Ignores Commands In Current Dir - sudo ignore_dot | Sudo |
| high | sudo-noexec | Ensure Privileged Escalated Commands Cannot Execute Other Commands - sudo NOEXEC | Sudo |
| medium | sudo-requiretty | Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo requiretty | Sudo |
| medium | sudo-umask | Ensure sudo umask is appropriate - sudo umask | Sudo |
| medium | sysctl-dev-tty-ldisc-autoload | Disable Automatic Line Discipline Autoload | Kernel & network (sysctl) |
| medium | sysctl-fs-protected_fifos | Enable Kernel Parameter to Enforce DAC on FIFOs | Kernel & network (sysctl) |
| medium | sysctl-fs-suid_dumpable | Disable Core Dumps for SUID programs | Kernel & network (sysctl) |
| low | sysctl-kernel-dmesg_restrict | Restrict Access to Kernel Message Buffer | Kernel & network (sysctl) |
| medium | sysctl-kernel-kptr_restrict | Restrict Exposed Kernel Pointer Addresses Access | Kernel & network (sysctl) |
| medium | sysctl-kernel-panic_on_oops | Kernel panic on oops | Kernel & network (sysctl) |
| medium | sysctl-kernel-perf_cpu_time_max_percent | Limit CPU consumption of the Perf system | Kernel & network (sysctl) |
| medium | sysctl-kernel-perf_event_max_sample_rate | Limit sampling frequency of the Perf system | Kernel & network (sysctl) |
| low | sysctl-kernel-perf_event_paranoid | Disallow kernel profiling by unprivileged users | Kernel & network (sysctl) |
| medium | sysctl-kernel-randomize_va_space | Enable Randomized Layout of Virtual Address Space | Kernel & network (sysctl) |
| medium | sysctl-kernel-sysrq | Disallow magic SysRq key | Kernel & network (sysctl) |
| medium | sysctl-kernel-unprivileged_bpf_disabled | Disable Access to Network bpf() Syscall From Unprivileged Processes | Kernel & network (sysctl) |
| medium | sysctl-kernel-yama-ptrace_scope | Restrict usage of ptrace to descendant processes | Kernel & network (sysctl) |
| medium | sysctl-net-core-bpf_jit_harden | Harden the operation of the BPF just-in-time compiler | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-conf-all-accept_local | Disable Accepting Packets Routed Between Local Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-conf-all-accept_redirects | Disable Accepting ICMP Redirects for All IPv4 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-conf-all-accept_source_route | Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-conf-all-arp_filter | Configure ARP filtering for All IPv4 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-conf-all-arp_ignore | Configure Response Mode of ARP Requests for All IPv4 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-conf-all-drop_gratuitous_arp | Drop Gratuitous ARP frames on All IPv4 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-conf-all-log_martians | Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-conf-all-route_localnet | Prevent Routing External Traffic to Local Loopback on All IPv4 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-conf-all-rp_filter | Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-conf-all-secure_redirects | Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-conf-all-send_redirects | Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-conf-all-shared_media | Configure Sending and Accepting Shared Media Redirects for All IPv4 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-conf-default-accept_redirects | Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-conf-default-accept_source_route | Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-conf-default-log_martians | Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces by Default | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-conf-default-rp_filter | Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-conf-default-secure_redirects | Configure Kernel Parameter for Accepting Secure Redirects By Default | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-conf-default-send_redirects | Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-conf-default-shared_media | Configure Sending and Accepting Shared Media Redirects by Default | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-icmp_echo_ignore_broadcasts | Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-icmp_ignore_bogus_error_responses | Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-ip_forward | Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-ip_local_port_range | Set Kernel Parameter to Increase Local Port Range | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-tcp_rfc1337 | Enable Kernel Parameter to Use TCP RFC 1337 on IPv4 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv4-tcp_syncookies | Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv6-conf-all-accept_ra | Configure Accepting Router Advertisements on All IPv6 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv6-conf-all-accept_ra_defrtr | Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv6-conf-all-accept_ra_pinfo | Configure Accepting Prefix Information in Router Advertisements on All IPv6 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv6-conf-all-accept_ra_rtr_pref | Configure Accepting Router Preference in Router Advertisements on All IPv6 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv6-conf-all-accept_redirects | Disable Accepting ICMP Redirects for All IPv6 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv6-conf-all-accept_source_route | Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv6-conf-all-autoconf | Configure Auto Configuration on All IPv6 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv6-conf-all-forwarding | Disable Kernel Parameter for IPv6 Forwarding | Kernel & network (sysctl) |
| medium | sysctl-net-ipv6-conf-all-max_addresses | Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv6-conf-all-router_solicitations | Configure Denying Router Solicitations on All IPv6 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv6-conf-default-accept_ra | Disable Accepting Router Advertisements on all IPv6 Interfaces by Default | Kernel & network (sysctl) |
| medium | sysctl-net-ipv6-conf-default-accept_ra_defrtr | Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces By Default | Kernel & network (sysctl) |
| medium | sysctl-net-ipv6-conf-default-accept_ra_pinfo | Configure Accepting Prefix Information in Router Advertisements on All IPv6 Interfaces By Default | Kernel & network (sysctl) |
| medium | sysctl-net-ipv6-conf-default-accept_ra_rtr_pref | Configure Accepting Router Preference in Router Advertisements on All IPv6 Interfaces By Default | Kernel & network (sysctl) |
| medium | sysctl-net-ipv6-conf-default-accept_redirects | Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces | Kernel & network (sysctl) |
| medium | sysctl-net-ipv6-conf-default-accept_source_route | Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default | Kernel & network (sysctl) |
| medium | sysctl-net-ipv6-conf-default-autoconf | Configure Auto Configuration on All IPv6 Interfaces By Default | Kernel & network (sysctl) |
| medium | sysctl-net-ipv6-conf-default-max_addresses | Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces By Default | Kernel & network (sysctl) |
| medium | sysctl-net-ipv6-conf-default-router_solicitations | Configure Denying Router Solicitations on All IPv6 Interfaces By Default | Kernel & network (sysctl) |
| medium | sysctl-vm-mmap_min_addr | Prevent applications from mapping low portion of virtual memory | Kernel & network (sysctl) |
| medium | umask-etc-bashrc | Ensure the Default Bash Umask is Set Correctly (077) | Accounts (umask) |
| medium | umask-etc-login-defs | Ensure the Default Umask is Set Correctly in login.defs (077) | Accounts (umask) |
| medium | umask-etc-profile | Ensure the Default Umask is Set Correctly in /etc/profile (077) | Accounts (umask) |
Still failing (failed -> failed) 4
Gaps the remediation did not close (manual, install-time or kernel-build).
| low | kmod-overlayfs-disabled | Ensure overlayfs kernel module is not available | Kernel modules |
| medium | mount-boot-noexec | Add noexec Option to /boot | Mounts |
| medium | mount-boot-nosuid | Add nosuid Option to /boot | Mounts |
| medium | partition-boot | Ensure /boot Located On Separate Partition | Mounts |
Newly applicable, passing 37
Controls the baseline made evaluable and that now pass.
| medium | filegroupowner-at-allow | Verify Group Who Owns /etc/at.allow file | File ownership |
| medium | filegroupowner-cron-allow | Verify Group Who Owns /etc/cron.allow file | File ownership |
| medium | filegroupowner-cron-hourly | Verify Group Who Owns cron.hourly | File ownership |
| medium | filegroupowner-cron-monthly | Verify Group Who Owns cron.monthly | File ownership |
| medium | filegroupowner-crontab | Verify Group Who Owns Crontab | File ownership |
| medium | filegroupowner-var-log-auth | Verify Group Who Owns /var/log/auth.log File | File ownership |
| medium | filegroupowner-var-log-syslog | Verify Group Who Owns /var/log/syslog File | File ownership |
| medium | filegroupownership-audit-binaries | Verify that audit tools are owned by group root | File ownership |
| medium | filegroupownership-audit-configuration | Audit Configuration Files Must Be Owned By Group root | File ownership |
| medium | fileowner-at-allow | Verify User Who Owns /etc/at.allow file | File ownership |
| medium | fileowner-cron-allow | Verify User Who Owns /etc/cron.allow file | File ownership |
| medium | fileowner-cron-hourly | Verify Owner on cron.hourly | File ownership |
| medium | fileowner-cron-monthly | Verify Owner on cron.monthly | File ownership |
| medium | fileowner-crontab | Verify Owner on crontab | File ownership |
| medium | fileowner-var-log-auth | Verify User Who Owns /var/log/auth.log File | File ownership |
| medium | fileowner-var-log-syslog | Verify User Who Owns /var/log/syslog File | File ownership |
| medium | fileownership-audit-binaries | Verify that audit tools are owned by root | File ownership |
| medium | fileownership-audit-configuration | Audit Configuration Files Must Be Owned By Root | File ownership |
| medium | fileperm-at-allow | Verify Permissions on /etc/at.allow file | File permissions |
| medium | fileperm-audit-binaries | Verify that audit tools Have Mode 0755 or less | File permissions |
| medium | fileperm-cron-allow | Verify Permissions on /etc/cron.allow file | File permissions |
| medium | fileperm-cron-hourly | Verify Permissions on cron.hourly | File permissions |
| medium | fileperm-cron-monthly | Verify Permissions on cron.monthly | File permissions |
| medium | fileperm-crontab | Verify Permissions on crontab | File permissions |
| medium | fileperm-etc-audit-auditd | Verify Permissions on /etc/audit/auditd.conf | File permissions |
| medium | fileperm-etc-audit-rules | Verify Permissions on /etc/audit/audit.rules | File permissions |
| medium | fileperm-var-log-audit | System Audit Logs Must Have Mode 0750 or Less Permissive | File permissions |
| medium | fileperm-var-log-auth | Verify Permissions on /var/log/auth.log File | File permissions |
| medium | fileperm-var-log-cloud-init | Verify Permissions on /var/log/cloud-init.log(.*) Files | File permissions |
| medium | fileperm-var-log-sssd | Verify Permissions of Files in /var/log/sssd | File permissions |
| medium | fileperm-var-log-syslog | Verify Permissions on /var/log/syslog File | File permissions |
| medium | groupownerships-var-log-sssd | Verify Grouponwership of Files in /var/log/sssd | File ownership |
| medium | ownerships-var-log-sssd | Verify Ownership of Files in /var/log/sssd | File ownership |
| medium | growth-journal-bounded | The systemd journal is bounded (SystemMaxUse) | Hardening (posture) |
| medium | growth-logrotate-active | Log rotation actually runs (logrotate is scheduled) | Hardening (posture) |
| low | growth-tmp-cleaned | Temporary filesystems are cleaned (systemd-tmpfiles) | Hardening (posture) |
| high | journald-forward-to-running-syslog | journald forwards to the syslog daemon that is actually running | Hardening (posture) |