STIGQter STIGQter: STIG Summary: Redis Enterprise 6.x Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

Database software, including DBMS configuration files, must be stored in dedicated directories, or DASD pools, separate from the host OS and other applications.

DISA Rule

SV-251212r960960_rule

Vulnerability Number

V-251212

Group Title

SRG-APP-000133-DB-000199

Rule Version

RD6X-00-007500

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To resolve this issue, perform one of the two following actions:
1. Install Redis Enterprise on a single tenant operating system.
2. Uninstall third-party applications that have been installed in the Redis Enterprise directories and install them in separate directories.

Check Contents

The default directories that Redis Enterprise Software uses for data and metadata are:

1. /var/opt/redislabs - Default storage location for the cluster data, system logs, backups and ephemeral, persisted data
2. /var/opt/redislabs/log - System logs for Redis Enterprise Software
3. /var/opt/redislabs/run - Socket files for Redis Enterprise Software
4. /etc/opt/redislabs - Default location for cluster manager configuration and certificates
5. /tmp - Temporary files
6. /opt/redislabs - Main installation directory for all Redis Enterprise Software binaries
7. /opt/redislabs/bin - Binaries for all the utilities for command line access and managements such as "rladmin" or "redis-cli"
8. /opt/redislabs/config - System configuration files
9. /opt/redislabs/lib - System library files
10. /opt/redislabs/sbin - System binaries for tweaking provisioning

To check this finding, examine the documentation for third-party applications and verify that no other applications are installed in these directories. It is recommended that Redis Enterprise be installed on a single tenant operating system.

If another application is using these directories on the host operating system, this is a finding.

Vulnerability Number

V-251212

Documentable

False

Rule Version

RD6X-00-007500

Severity Override Guidance

The default directories that Redis Enterprise Software uses for data and metadata are:

1. /var/opt/redislabs - Default storage location for the cluster data, system logs, backups and ephemeral, persisted data
2. /var/opt/redislabs/log - System logs for Redis Enterprise Software
3. /var/opt/redislabs/run - Socket files for Redis Enterprise Software
4. /etc/opt/redislabs - Default location for cluster manager configuration and certificates
5. /tmp - Temporary files
6. /opt/redislabs - Main installation directory for all Redis Enterprise Software binaries
7. /opt/redislabs/bin - Binaries for all the utilities for command line access and managements such as "rladmin" or "redis-cli"
8. /opt/redislabs/config - System configuration files
9. /opt/redislabs/lib - System library files
10. /opt/redislabs/sbin - System binaries for tweaking provisioning

To check this finding, examine the documentation for third-party applications and verify that no other applications are installed in these directories. It is recommended that Redis Enterprise be installed on a single tenant operating system.

If another application is using these directories on the host operating system, this is a finding.

Check Content Reference

M

Target Key

5443