STIGQter STIGQter: STIG Summary:

Red Hat Enterprise Linux 8 Security Technical Implementation Guide

Version: 2

Release: 8 Benchmark Date: 01 Jul 2026

CheckedNameTitle
☐SV-230221r1017040_ruleRHEL 8 must be a vendor-supported release.
☐SV-230222r1184233_ruleRHEL 8 vendor packaged system security patches and updates must be installed and up to date.
☐SV-230223r1155356_ruleRHEL 8 must implement a FIPS 140-3-compliant systemwide cryptographic policy.
☐SV-230224r1044787_ruleAll RHEL 8 local disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at rest protection.
☐SV-230225r1184236_ruleRHEL 8 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a ssh logon.
☐SV-230226r1069298_ruleRHEL 8 must display the Standard Mandatory DoD Notice and Consent Banner before granting local or remote access to the system via a graphical user logon.
☐SV-230227r1017046_ruleRHEL 8 must display the Standard Mandatory DoD Notice and Consent Banner before granting local or remote access to the system via a command line user logon.
☐SV-230228r1069299_ruleAll RHEL 8 remote access methods must be monitored.
☐SV-230229r1017048_ruleRHEL 8, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
☐SV-230230r1069287_ruleRHEL 8, for certificate-based authentication, must enforce authorized access to the corresponding private key.
☐SV-230231r1017050_ruleRHEL 8 must encrypt all stored passwords with a FIPS 140-2 approved cryptographic hashing algorithm.
☐SV-230232r1208739_ruleRHEL 8 must employ FIPS 140-3-approved cryptographic hashing algorithms for all stored passwords.
☐SV-230233r1044790_ruleThe RHEL 8 shadow password suite must be configured to use a sufficient number of hashing rounds.
☐SV-230234r1137691_ruleRHEL 8 operating systems booted with United Extensible Firmware Interface (UEFI) must require authentication upon booting into single-user mode and maintenance.
☐SV-230235r1137691_ruleRHEL 8 operating systems booted with a BIOS must require authentication upon booting into single-user and maintenance modes.
☐SV-230236r1137691_ruleRHEL 8 operating systems must require authentication upon booting into rescue mode.
☐SV-230237r1017056_ruleThe RHEL 8 pam_unix.so module must be configured in the password-auth file to use a FIPS 140-2 approved cryptographic hashing algorithm for system authentication.
☐SV-230238r1017057_ruleRHEL 8 must prevent system daemons from using Kerberos for authentication.
☐SV-230239r1017058_ruleThe krb5-workstation package must not be installed on RHEL 8.
☐SV-230240r1017059_ruleRHEL 8 must use a Linux Security Module configured to enforce limits on system services.
☐SV-230241r1017060_ruleRHEL 8 must have policycoreutils package installed.
☐SV-230243r1137695_ruleA sticky bit must be set on all RHEL 8 public directories to prevent unauthorized and unintended information transferred via shared system resources.
☐SV-230244r1069300_ruleRHEL 8 must be configured so that all network connections associated with SSH traffic terminate after becoming unresponsive.
☐SV-230245r1017063_ruleThe RHEL 8 /var/log/messages file must have mode 0640 or less permissive.
☐SV-230246r1017064_ruleThe RHEL 8 /var/log/messages file must be owned by root.
☐SV-230247r1017065_ruleThe RHEL 8 /var/log/messages file must be group-owned by root.
☐SV-230248r1069291_ruleThe RHEL 8 /var/log directory must have mode 0755 or less permissive.
☐SV-230249r1017067_ruleThe RHEL 8 /var/log directory must be owned by root.
☐SV-230250r1017068_ruleThe RHEL 8 /var/log directory must be group-owned by root.
☐SV-230251r1184240_ruleThe RHEL 8 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.
☐SV-230252r1184241_ruleThe RHEL 8 SSH server must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.
☐SV-230253r1044799_ruleRHEL 8 must ensure the SSH server uses strong entropy.
☐SV-230257r1017077_ruleRHEL 8 system commands must have mode 755 or less permissive.
☐SV-230258r1017078_ruleRHEL 8 system commands must be owned by root.
☐SV-230259r1017079_ruleRHEL 8 system commands must be group-owned by root or a system account.
☐SV-230260r1101888_ruleRHEL 8 library files must have mode 755 or less permissive.
☐SV-230261r1101891_ruleRHEL 8 library files must be owned by root.
☐SV-230262r1155384_ruleRHEL 8 library files must be group-owned by root.
☐SV-230263r1017083_ruleThe RHEL 8 file integrity tool must notify the system administrator when changes to the baseline configuration or anomalies in the operation of any security functions are discovered within an organizationally defined frequency.
☐SV-230264r1017377_ruleRHEL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components from a repository without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.
☐SV-230265r1208742_ruleRHEL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components of local packages without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.
☐SV-230266r1184246_ruleRHEL 8 must prevent the loading of a new kernel for later execution.
☐SV-230267r1184249_ruleRHEL 8 must enable kernel parameters to enforce discretionary access control on symlinks.
☐SV-230268r1184252_ruleRHEL 8 must enable kernel parameters to enforce discretionary access control on hardlinks.
☐SV-230269r1184255_ruleRHEL 8 must restrict access to the kernel message buffer.
☐SV-230270r1184258_ruleRHEL 8 must prevent kernel profiling by unprivileged users.
☐SV-230271r1101896_ruleRHEL 8 must require users to provide a password for privilege escalation.
☐SV-230272r1101898_ruleRHEL 8 must require users to reauthenticate for privilege escalation.
☐SV-230273r1017381_ruleRHEL 8 must have the packages required for multifactor authentication installed.
☐SV-230274r1017089_ruleRHEL 8 must implement certificate status checking for multifactor authentication.
☐SV-230275r958816_ruleRHEL 8 must accept Personal Identity Verification (PIV) credentials.
☐SV-230276r958928_ruleRHEL 8 must implement non-executable data to protect its memory from unauthorized code execution.
☐SV-230277r1017090_ruleRHEL 8 must clear the page allocator to prevent use-after-free attacks.
☐SV-230278r1017091_ruleRHEL 8 must disable virtual syscalls.
☐SV-230279r1069286_ruleRHEL 8 must clear memory when it is freed to prevent use-after-free attacks.
☐SV-230280r1208745_ruleRHEL 8 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution.
☐SV-230281r958936_ruleYUM must remove all software components after updated versions have been installed on RHEL 8.
☐SV-230282r958944_ruleRHEL 8 must enable the SELinux targeted policy.
☐SV-230283r1017094_ruleThere must be no shosts.equiv files on the RHEL 8 operating system.
☐SV-230284r1017095_ruleThere must be no .shosts files on the RHEL 8 operating system.
☐SV-230285r1017096_ruleRHEL 8 must enable the hardware random number generator entropy gatherer service.
☐SV-230286r1017097_ruleThe RHEL 8 SSH public host key files must have mode 0644 or less permissive.
☐SV-230287r1208746_ruleThe RHEL 8 SSH private host key files must have mode 0600 or less permissive.
☐SV-230288r1069301_ruleThe RHEL 8 SSH daemon must perform strict mode checking of home directory configuration files.
☐SV-230290r1069302_ruleThe RHEL 8 SSH daemon must not allow authentication using known host’s authentication.
☐SV-230291r1069303_ruleThe RHEL 8 SSH daemon must not allow Kerberos authentication, except to fulfill documented and validated mission requirements.
☐SV-230292r1017103_ruleRHEL 8 must use a separate file system for /var.
☐SV-230293r1017104_ruleRHEL 8 must use a separate file system for /var/log.
☐SV-230294r1017105_ruleRHEL 8 must use a separate file system for the system audit data path.
☐SV-230295r1017106_ruleA separate RHEL 8 filesystem must be used for the /tmp directory.
☐SV-230296r1069322_ruleRHEL 8 must not permit direct logons to the root account using remote access via SSH.
☐SV-230298r1017108_ruleThe rsyslog service must be running in RHEL 8.
☐SV-230299r1017109_ruleRHEL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that contain user home directories.
☐SV-230300r1017110_ruleRHEL 8 must prevent files with the setuid and setgid bit set from being executed on the /boot directory.
☐SV-230301r1184262_ruleRHEL 8 must prevent special devices on non-root local partitions.
☐SV-230302r1017112_ruleRHEL 8 must prevent code from being executed on file systems that contain user home directories.
☐SV-230303r1017113_ruleRHEL 8 must prevent special devices on file systems that are used with removable media.
☐SV-230304r1017114_ruleRHEL 8 must prevent code from being executed on file systems that are used with removable media.
☐SV-230305r1017115_ruleRHEL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that are used with removable media.
☐SV-230306r1155386_ruleRHEL 8 must prevent code from being executed on file systems that are imported via Network File System (NFS).
☐SV-230307r1155388_ruleRHEL 8 must prevent special devices on file systems that are imported via Network File System (NFS).
☐SV-230308r1155390_ruleRHEL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that are imported via Network File System (NFS).
☐SV-230310r1155383_ruleRHEL 8 must disable kernel dumps unless needed.
☐SV-230311r1155408_ruleRHEL 8 must disable the kernel.core_pattern.
☐SV-230312r1134877_ruleRHEL 8 must disable acquiring, saving, and processing core dumps.
☐SV-230313r1155379_ruleRHEL 8 must disable core dumps for all users.
☐SV-230314r1134881_ruleRHEL 8 must disable storing core dumps.
☐SV-230315r1134883_ruleRHEL 8 must disable core dump backtraces.
☐SV-230316r1044801_ruleFor RHEL 8 systems using Domain Name Servers (DNS) resolution, at least two name servers must be configured.
☐SV-230317r1069320_ruleExecutable search paths within the initialization files of all local interactive RHEL 8 users must only contain paths that resolve to the system default or the users home directory.
☐SV-230318r1155352_ruleAll RHEL 8 world-writable directories must be owned by root, sys, bin, or an application user.
☐SV-230319r1017130_ruleAll RHEL 8 world-writable directories must be group-owned by root, sys, bin, or an application group.
☐SV-230320r1017131_ruleAll RHEL 8 local interactive users must have a home directory assigned in the /etc/passwd file.
☐SV-230321r1017132_ruleAll RHEL 8 local interactive user home directories must have mode 0750 or less permissive.
☐SV-230322r1017133_ruleAll RHEL 8 local interactive user home directories must be group-owned by the home directory owner’s primary group.
☐SV-230323r1017134_ruleAll RHEL 8 local interactive user home directories defined in the /etc/passwd file must exist.
☐SV-230324r1017135_ruleAll RHEL 8 local interactive user accounts must be assigned a home directory upon creation.
☐SV-230325r1017136_ruleAll RHEL 8 local initialization files must have mode 0740 or less permissive.
☐SV-230326r1069284_ruleAll RHEL 8 local files and directories must have a valid owner.
☐SV-230327r1069285_ruleAll RHEL 8 local files and directories must have a valid group owner.
☐SV-230328r1155410_ruleA separate RHEL 8 filesystem must be used for user home directories (such as /home or an equivalent).
☐SV-230329r1017140_ruleUnattended or automatic logon via the RHEL 8 graphical user interface must not be allowed.
☐SV-230330r1069305_ruleRHEL 8 must not allow users to override SSH environment variables.
☐SV-230332r1184264_ruleRHEL 8 must automatically lock an account when three unsuccessful logon attempts occur.
☐SV-230333r1017145_ruleRHEL 8 must automatically lock an account when three unsuccessful logon attempts occur.
☐SV-230334r1184266_ruleRHEL 8 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period.
☐SV-230335r1017147_ruleRHEL 8 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period.
☐SV-230336r1184268_ruleRHEL 8 must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.
☐SV-230337r1134885_ruleRHEL 8 must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.
☐SV-230338r1184270_ruleRHEL 8 must ensure account lockouts persist.
☐SV-230339r1017151_ruleRHEL 8 must ensure account lockouts persist.
☐SV-230340r1184272_ruleRHEL 8 must prevent system messages from being presented when three unsuccessful logon attempts occur.
☐SV-230341r1017153_ruleRHEL 8 must prevent system messages from being presented when three unsuccessful logon attempts occur.
☐SV-230342r1184274_ruleRHEL 8 must log user name information when unsuccessful logon attempts occur.
☐SV-230343r1017155_ruleRHEL 8 must log user name information when unsuccessful logon attempts occur.
☐SV-230344r1184276_ruleRHEL 8 must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.
☐SV-230345r1017157_ruleRHEL 8 must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.
☐SV-230346r1069306_ruleRHEL 8 must limit the number of concurrent sessions to ten for all accounts and/or account types.
☐SV-230347r1017160_ruleRHEL 8 must enable a user session lock until that user re-establishes access using established identification and authentication procedures for graphical user sessions.
☐SV-230351r1017164_ruleRHEL 8 must be able to initiate directly a session lock for all connection types using smartcard when the smartcard is removed.
☐SV-230352r1208749_ruleRHEL 8 must automatically lock graphical user sessions after 10 minutes of inactivity.
☐SV-230354r1069323_ruleRHEL 8 must prevent a user from overriding the session lock-delay setting for the graphical user interface.
☐SV-230355r1017168_ruleRHEL 8 must map the authenticated identity to the user or group account for PKI-based authentication.
☐SV-230356r982195_ruleRHEL 8 must ensure the password complexity module is enabled in the password-auth file.
☐SV-230357r1017169_ruleRHEL 8 must enforce password complexity by requiring that at least one uppercase character be used.
☐SV-230358r1017170_ruleRHEL 8 must enforce password complexity by requiring that at least one lower-case character be used.
☐SV-230359r1017171_ruleRHEL 8 must enforce password complexity by requiring that at least one numeric character be used.
☐SV-230360r1017172_ruleRHEL 8 must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed.
☐SV-230361r1017173_ruleRHEL 8 must require the maximum number of repeating characters be limited to three when passwords are changed.
☐SV-230362r1017174_ruleRHEL 8 must require the change of at least four character classes when passwords are changed.
☐SV-230363r1017175_ruleRHEL 8 must require the change of at least 8 characters when passwords are changed.
☐SV-230364r1017176_ruleRHEL 8 passwords must have a 24 hours/1 day minimum password lifetime restriction in /etc/shadow.
☐SV-230365r1017177_ruleRHEL 8 passwords for new users or password changes must have a 24 hours/1 day minimum password lifetime restriction in /etc/login.defs.
☐SV-230366r1038967_ruleRHEL 8 user account passwords must have a 60-day maximum password lifetime restriction.
☐SV-230367r1038967_ruleRHEL 8 user account passwords must be configured so that existing passwords are restricted to a 60-day maximum lifetime.
☐SV-230369r1017181_ruleRHEL 8 passwords must have a minimum of 15 characters.
☐SV-230370r1017182_ruleRHEL 8 passwords for new users must have a minimum of 15 characters.
☐SV-230371r1017183_ruleRHEL 8 duplicate User IDs (UIDs) must not exist for interactive users.
☐SV-230372r1017184_ruleRHEL 8 must implement smart card logon for multifactor authentication for access to interactive accounts.
☐SV-230373r1017185_ruleRHEL 8 account identifiers (individuals, groups, roles, and devices) must be disabled after 35 days of inactivity.
☐SV-230374r1069293_ruleRHEL 8 must automatically expire temporary accounts within 72 hours.
☐SV-230375r1017187_ruleAll RHEL 8 passwords must contain at least one special character.
☐SV-230376r1069307_ruleRHEL 8 must prohibit the use of cached authentications after one day.
☐SV-230377r1017188_ruleRHEL 8 must prevent the use of dictionary words for passwords.
☐SV-230378r1017189_ruleRHEL 8 must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.
☐SV-230379r1017190_ruleRHEL 8 must not have unnecessary accounts.
☐SV-230380r1069308_ruleRHEL 8 must not allow accounts configured with blank or null passwords.
☐SV-230382r1069309_ruleRHEL 8 must display the date and time of the last successful account logon upon an SSH logon.
☐SV-230383r1017192_ruleRHEL 8 must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.
☐SV-230384r1017193_ruleRHEL 8 must set the umask value to 077 for all local interactive user accounts.
☐SV-230385r1017194_ruleRHEL 8 must define default permissions for logon and non-logon shells.
☐SV-230386r958730_ruleThe RHEL 8 audit system must be configured to audit the execution of privileged functions and prevent all software from executing at higher privilege levels than users executing the software.
☐SV-230387r1017195_ruleCron logging must be implemented in RHEL 8.
☐SV-230388r1017196_ruleThe RHEL 8 System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) must be alerted of an audit processing failure event.
☐SV-230389r1017197_ruleThe RHEL 8 Information System Security Officer (ISSO) and System Administrator (SA) (at a minimum) must have mail aliases to be notified of an audit processing failure.
☐SV-230390r1038966_ruleThe RHEL 8 System must take appropriate action when an audit processing failure occurs.
☐SV-230392r1038966_ruleThe RHEL 8 audit system must take appropriate action when the audit storage volume is full.
☐SV-230393r1017200_ruleThe RHEL 8 audit system must audit local events.
☐SV-230394r958754_ruleRHEL 8 must label all off-loaded audit logs before sending them to the central log server.
☐SV-230395r1017201_ruleRHEL 8 must resolve audit information before writing to disk.
☐SV-230396r1017202_ruleRHEL 8 audit logs must have a mode of 0600 or less permissive to prevent unauthorized read access.
☐SV-230397r1017203_ruleRHEL 8 audit logs must be owned by root to prevent unauthorized read access.
☐SV-230398r1017204_ruleRHEL 8 audit logs must be group-owned by root to prevent unauthorized read access.
☐SV-230399r1017205_ruleRHEL 8 audit log directory must be owned by root to prevent unauthorized read access.
☐SV-230400r1017206_ruleRHEL 8 audit log directory must be group-owned by root to prevent unauthorized read access.
☐SV-230401r1017207_ruleRHEL 8 audit log directory must have a mode of 0700 or less permissive to prevent unauthorized read access.
☐SV-230402r1017208_ruleRHEL 8 audit system must protect auditing rules from unauthorized change.
☐SV-230403r1017209_ruleRHEL 8 audit system must protect logon UIDs from unauthorized change.
☐SV-230404r1017210_ruleRHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
☐SV-230405r1017211_ruleRHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.
☐SV-230406r1017212_ruleRHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
☐SV-230407r1017213_ruleRHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
☐SV-230408r1017214_ruleRHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
☐SV-230409r1017215_ruleRHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.
☐SV-230410r1017216_ruleRHEL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/.
☐SV-230411r1017217_ruleThe RHEL 8 audit package must be installed.
☐SV-230412r1017218_ruleSuccessful/unsuccessful uses of the su command in RHEL 8 must generate an audit record.
☐SV-230413r1017219_ruleThe RHEL 8 audit system must be configured to audit any usage of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls.
☐SV-230418r1017220_ruleSuccessful/unsuccessful uses of the chage command in RHEL 8 must generate an audit record.
☐SV-230419r1017221_ruleSuccessful/unsuccessful uses of the chcon command in RHEL 8 must generate an audit record.
☐SV-230421r1017222_ruleSuccessful/unsuccessful uses of the ssh-agent in RHEL 8 must generate an audit record.
☐SV-230422r1017223_ruleSuccessful/unsuccessful uses of the passwd command in RHEL 8 must generate an audit record.
☐SV-230423r1017224_ruleSuccessful/unsuccessful uses of the mount command in RHEL 8 must generate an audit record.
☐SV-230424r1017225_ruleSuccessful/unsuccessful uses of the umount command in RHEL 8 must generate an audit record.
☐SV-230425r1017226_ruleSuccessful/unsuccessful uses of the mount syscall in RHEL 8 must generate an audit record.
☐SV-230426r1017227_ruleSuccessful/unsuccessful uses of the unix_update in RHEL 8 must generate an audit record.
☐SV-230427r1017228_ruleSuccessful/unsuccessful uses of postdrop in RHEL 8 must generate an audit record.
☐SV-230428r1017229_ruleSuccessful/unsuccessful uses of postqueue in RHEL 8 must generate an audit record.
☐SV-230429r1017230_ruleSuccessful/unsuccessful uses of semanage in RHEL 8 must generate an audit record.
☐SV-230430r1017231_ruleSuccessful/unsuccessful uses of setfiles in RHEL 8 must generate an audit record.
☐SV-230431r1017232_ruleSuccessful/unsuccessful uses of userhelper in RHEL 8 must generate an audit record.
☐SV-230432r1017233_ruleSuccessful/unsuccessful uses of setsebool in RHEL 8 must generate an audit record.
☐SV-230433r1017234_ruleSuccessful/unsuccessful uses of unix_chkpwd in RHEL 8 must generate an audit record.
☐SV-230434r1017235_ruleSuccessful/unsuccessful uses of the ssh-keysign in RHEL 8 must generate an audit record.
☐SV-230435r1017236_ruleSuccessful/unsuccessful uses of the setfacl command in RHEL 8 must generate an audit record.
☐SV-230436r1017237_ruleSuccessful/unsuccessful uses of the pam_timestamp_check command in RHEL 8 must generate an audit record.
☐SV-230437r1017238_ruleSuccessful/unsuccessful uses of the newgrp command in RHEL 8 must generate an audit record.
☐SV-230438r1017241_ruleSuccessful/unsuccessful uses of the init_module and finit_module system calls in RHEL 8 must generate an audit record.
☐SV-230439r1017243_ruleSuccessful/unsuccessful uses of the rename, unlink, rmdir, renameat, and unlinkat system calls in RHEL 8 must generate an audit record.
☐SV-230444r1017244_ruleSuccessful/unsuccessful uses of the gpasswd command in RHEL 8 must generate an audit record.
☐SV-230446r1017245_ruleSuccessful/unsuccessful uses of the delete_module command in RHEL 8 must generate an audit record.
☐SV-230447r1017246_ruleSuccessful/unsuccessful uses of the crontab command in RHEL 8 must generate an audit record.
☐SV-230448r1017247_ruleSuccessful/unsuccessful uses of the chsh command in RHEL 8 must generate an audit record.
☐SV-230449r1017249_ruleSuccessful/unsuccessful uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls in RHEL 8 must generate an audit record.
☐SV-230455r1017251_ruleSuccessful/unsuccessful uses of the chown, fchown, fchownat, and lchown system calls in RHEL 8 must generate an audit record.
☐SV-230456r1017253_ruleSuccessful/unsuccessful uses of the chmod, fchmod, and fchmodat system calls in RHEL 8 must generate an audit record.
☐SV-230462r1017254_ruleSuccessful/unsuccessful uses of the sudo command in RHEL 8 must generate an audit record.
☐SV-230463r1017255_ruleSuccessful/unsuccessful uses of the usermod command in RHEL 8 must generate an audit record.
☐SV-230464r1017256_ruleSuccessful/unsuccessful uses of the chacl command in RHEL 8 must generate an audit record.
☐SV-230465r1017257_ruleSuccessful/unsuccessful uses of the kmod command in RHEL 8 must generate an audit record.
☐SV-230466r1017258_ruleSuccessful/unsuccessful modifications to the faillock log file in RHEL 8 must generate an audit record.
☐SV-230467r1017259_ruleSuccessful/unsuccessful modifications to the lastlog file in RHEL 8 must generate an audit record.
☐SV-230468r1017260_ruleRHEL 8 must enable auditing of processes that start prior to the audit daemon.
☐SV-230469r958752_ruleRHEL 8 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.
☐SV-230470r1017261_ruleRHEL 8 must enable Linux audit logging for the USBGuard daemon.
☐SV-230471r1208750_ruleRHEL 8 must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.
☐SV-230472r1017263_ruleRHEL 8 audit tools must have a mode of 0755 or less permissive.
☐SV-230473r1017264_ruleRHEL 8 audit tools must be owned by root.
☐SV-230474r1017265_ruleRHEL 8 audit tools must be group-owned by root.
☐SV-230475r1017266_ruleRHEL 8 must use cryptographic mechanisms to protect the integrity of audit tools.
☐SV-230476r958752_ruleRHEL 8 must allocate audit record storage capacity to store at least one week of audit records, when audit records are not immediately sent to a central audit record storage facility.
☐SV-230477r1017267_ruleRHEL 8 must have the packages required for offloading audit logs installed.
☐SV-230478r1017268_ruleRHEL 8 must have the packages required for encrypting offloaded audit logs installed.
☐SV-230479r958754_ruleThe RHEL 8 audit records must be off-loaded onto a different system or storage media from the system being audited.
☐SV-230480r958754_ruleRHEL 8 must take appropriate action when the internal event queue is full.
☐SV-230481r958754_ruleRHEL 8 must encrypt the transfer of audit records off-loaded onto a different system or media from the system being audited.
☐SV-230482r1069330_ruleRHEL 8 must authenticate the remote logging server for off-loading audit logs.
☐SV-230483r971542_ruleRHEL 8 must take action when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity.
☐SV-230484r1038944_ruleRHEL 8 must securely compare internal information system clocks at least every 24 hours with a server synchronized to an authoritative time source, such as the United States Naval Observatory (USNO) time servers, or a time server designated for the appropriate DoD network (NIPRNet/SIPRNet), and/or the Global Positioning System (GPS).
☐SV-230485r1017269_ruleRHEL 8 must disable the chrony daemon from acting as a server.
☐SV-230486r1017270_ruleRHEL 8 must disable network management of the chrony daemon.
☐SV-230487r1017271_ruleRHEL 8 must not have the telnet-server package installed.
☐SV-230488r1017272_ruleRHEL 8 must not have any automated bug reporting tools installed.
☐SV-230489r1017273_ruleRHEL 8 must not have the sendmail package installed.
☐SV-230491r1017274_ruleRHEL 8 must enable mitigations against processor-based vulnerabilities.
☐SV-230492r1184277_ruleRHEL 8 must not install packages from the Extra Packages for Enterprise Linux (EPEL) repository.
☐SV-230493r1184280_ruleRHEL 8 must cover or disable the built-in or attached camera when not in use.
☐SV-230494r1069310_ruleRHEL 8 must disable the asynchronous transfer mode (ATM) protocol.
☐SV-230495r1069311_ruleRHEL 8 must disable the controller area network (CAN) protocol.
☐SV-230496r1069312_ruleRHEL 8 must disable the stream control transmission protocol (SCTP).
☐SV-230497r1069313_ruleRHEL 8 must disable the transparent inter-process communication (TIPC) protocol.
☐SV-230498r1069314_ruleRHEL 8 must disable mounting of cramfs.
☐SV-230499r1069315_ruleRHEL 8 must disable IEEE 1394 (FireWire) Support.
☐SV-230500r1101900_ruleRHEL 8 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.
☐SV-230502r1155393_ruleThe RHEL 8 file system automounter must be disabled.
☐SV-230503r1069316_ruleRHEL 8 must be configured to disable USB mass storage.
☐SV-230504r958672_ruleA RHEL 8 firewall must employ a deny-all, allow-by-exception policy for allowing connections to other systems.
☐SV-230505r958672_ruleA firewall must be installed on RHEL 8.
☐SV-230506r1017286_ruleRHEL 8 wireless network adapters must be disabled.
☐SV-230507r1017287_ruleRHEL 8 Bluetooth must be disabled.
☐SV-230508r958804_ruleRHEL 8 must mount /dev/shm with the nodev option.
☐SV-230509r958804_ruleRHEL 8 must mount /dev/shm with the nosuid option.
☐SV-230510r958804_ruleRHEL 8 must mount /dev/shm with the noexec option.
☐SV-230511r958804_ruleRHEL 8 must mount /tmp with the nodev option.
☐SV-230512r958804_ruleRHEL 8 must mount /tmp with the nosuid option.
☐SV-230513r958804_ruleRHEL 8 must mount /tmp with the noexec option.
☐SV-230514r958804_ruleRHEL 8 must mount /var/log with the nodev option.
☐SV-230515r958804_ruleRHEL 8 must mount /var/log with the nosuid option.
☐SV-230516r958804_ruleRHEL 8 must mount /var/log with the noexec option.
☐SV-230517r958804_ruleRHEL 8 must mount /var/log/audit with the nodev option.
☐SV-230518r958804_ruleRHEL 8 must mount /var/log/audit with the nosuid option.
☐SV-230519r958804_ruleRHEL 8 must mount /var/log/audit with the noexec option.
☐SV-230520r958804_ruleRHEL 8 must mount /var/tmp with the nodev option.
☐SV-230521r958804_ruleRHEL 8 must mount /var/tmp with the nosuid option.
☐SV-230522r958804_ruleRHEL 8 must mount /var/tmp with the noexec option.
☐SV-230523r958804_ruleThe RHEL 8 fapolicy module must be installed.
☐SV-230524r1155418_ruleRHEL 8 must block unauthorized peripherals before establishing a connection.
☐SV-230525r958902_ruleA firewall must be able to protect against or limit the effects of Denial of Service (DoS) attacks by ensuring RHEL 8 can implement rate-limiting measures on impacted network interfaces.
☐SV-230526r958908_ruleAll RHEL 8 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
☐SV-230527r1017288_ruleRHEL 8 must force a frequent session key renegotiation for SSH connections to the server.
☐SV-230529r1017289_ruleThe x86 Ctrl-Alt-Delete key sequence must be disabled on RHEL 8.
☐SV-230530r1069317_ruleThe x86 Ctrl-Alt-Delete key sequence in RHEL 8 must be disabled if a graphical user interface is installed.
☐SV-230531r1208754_ruleThe systemd Ctrl-Alt-Delete burst key sequence in RHEL 8 must be disabled.
☐SV-230532r1017294_ruleThe debug-shell systemd service must be disabled on RHEL 8.
☐SV-230533r1017295_ruleThe Trivial File Transfer Protocol (TFTP) server package must not be installed if not required for RHEL 8 operational support.
☐SV-230534r1017296_ruleThe root account must be the only account having unrestricted access to the RHEL 8 system.
☐SV-230535r1017297_ruleRHEL 8 must prevent IPv6 Internet Control Message Protocol (ICMP) redirect messages from being accepted.
☐SV-230536r1208868_ruleRHEL 8 must not allow IPv4 ICMP redirect messages.
☐SV-230537r1017299_ruleRHEL 8 must not respond to Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.
☐SV-230538r1017300_ruleRHEL 8 must not forward IPv6 source-routed packets.
☐SV-230539r1017301_ruleRHEL 8 must not forward IPv6 source-routed packets by default.
☐SV-230540r1017302_ruleRHEL 8 must not enable IPv6 packet forwarding unless the system is a router.
☐SV-230541r1017303_ruleRHEL 8 must not accept router advertisements on all IPv6 interfaces.
☐SV-230542r1017304_ruleRHEL 8 must not accept router advertisements on all IPv6 interfaces by default.
☐SV-230543r1017305_ruleRHEL 8 must not allow interfaces to perform Internet Control Message Protocol (ICMP) redirects by default.
☐SV-230544r1017306_ruleRHEL 8 must ignore IPv6 Internet Control Message Protocol (ICMP) redirect messages.
☐SV-230545r1017307_ruleRHEL 8 must disable access to network bpf syscall from unprivileged processes.
☐SV-230546r1155413_ruleRHEL 8 must restrict usage of ptrace to descendant processes.
☐SV-230547r1184283_ruleRHEL 8 must restrict exposed kernel pointer addresses access.
☐SV-230548r1017310_ruleRHEL 8 must disable the use of user namespaces.
☐SV-230549r1208761_ruleRHEL 8 must use reverse path filtering on all IPv4 interfaces.
☐SV-230550r1017312_ruleRHEL 8 must be configured to prevent unrestricted mail relaying.
☐SV-230551r1017313_ruleThe RHEL 8 file integrity tool must be configured to verify extended attributes.
☐SV-230552r1101902_ruleThe RHEL 8 file integrity tool must be configured to verify Access Control Lists (ACLs).
☐SV-230553r1017315_ruleThe graphical display manager must not be installed on RHEL 8 unless approved.
☐SV-230554r1017316_ruleRHEL 8 network interfaces must not be in promiscuous mode.
☐SV-230555r1017317_ruleRHEL 8 remote X connections for interactive users must be disabled unless to fulfill documented and validated mission requirements.
☐SV-230556r1017318_ruleThe RHEL 8 SSH daemon must prevent remote hosts from connecting to the proxy display.
☐SV-230557r1088855_ruleIf the Trivial File Transfer Protocol (TFTP) server is required, the RHEL 8 TFTP daemon must be configured to operate in secure mode.
☐SV-230558r1017320_ruleA File Transfer Protocol (FTP) server package must not be installed unless mission essential on RHEL 8.
☐SV-230559r1155398_ruleThe gssproxy package must not be installed unless mission essential on RHEL 8.
☐SV-230560r1017321_ruleThe iprutils package must not be installed unless mission essential on RHEL 8.
☐SV-230561r1017322_ruleThe tuned package must not be installed unless mission essential on RHEL 8.
☐SV-237640r1017323_ruleThe krb5-server package must not be installed on RHEL 8.
☐SV-237641r1101904_ruleRHEL 8 must restrict privilege elevation to authorized personnel.
☐SV-237642r991589_ruleRHEL 8 must use the invoking user's password for privilege escalation when using "sudo".
☐SV-237643r1050789_ruleRHEL 8 must require re-authentication when using the "sudo" command.
☐SV-244519r1017326_ruleRHEL 8 must display a banner before granting local or remote access to the system via a graphical user logon.
☐SV-244521r1137691_ruleRHEL 8 operating systems booted with United Extensible Firmware Interface (UEFI) must require a unique superusers name upon booting into single-user mode and maintenance.
☐SV-244522r1137691_ruleRHEL 8 operating systems booted with a BIOS must require a unique superusers name upon booting into single-user and maintenance modes.
☐SV-244523r1137691_ruleRHEL 8 operating systems must require authentication upon booting into emergency mode.
☐SV-244524r1017330_ruleThe RHEL 8 pam_unix.so module must be configured in the system-auth file to use a FIPS 140-2 approved cryptographic hashing algorithm for system authentication.
☐SV-244525r1017331_ruleRHEL 8 must be configured so that all network connections associated with SSH traffic are terminated after 10 minutes of becoming unresponsive.
☐SV-244527r1017333_ruleRHEL 8 must have the packages required to use the hardware random number generator entropy gatherer service.
☐SV-244528r1017335_ruleThe RHEL 8 SSH daemon must not allow GSSAPI authentication, except to fulfill documented and validated mission requirements.
☐SV-244529r1017336_ruleRHEL 8 must use a separate file system for /var/tmp.
☐SV-244530r1184260_ruleRHEL 8 must prevent files with the setuid and setgid bit set from being executed on the /boot/efi directory.
☐SV-244531r1017338_ruleAll RHEL 8 local interactive user home directory files must have mode 0750 or less permissive.
☐SV-244532r1101906_ruleRHEL 8 must be configured so that all files and directories contained in local interactive user home directories are group-owned by a group of which the home directory owner is a member.
☐SV-244533r1069318_ruleRHEL 8 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file.
☐SV-244534r1069319_ruleRHEL 8 must configure the use of the pam_faillock.so module in the /etc/pam.d/password-auth file.
☐SV-244535r1017342_ruleRHEL 8 must initiate a session lock for graphical user interfaces when the screensaver is activated.
☐SV-244536r1017343_ruleRHEL 8 must disable the user list at logon for graphical user interfaces.
☐SV-244538r1069324_ruleRHEL 8 must prevent a user from overriding the session idle-delay setting for the graphical user interface.
☐SV-244539r1069325_ruleRHEL 8 must prevent a user from overriding the screensaver lock-enabled setting for the graphical user interface.
☐SV-244541r1017347_ruleRHEL 8 must not allow blank or null passwords in the password-auth file.
☐SV-244542r1017348_ruleRHEL 8 audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.
☐SV-244543r971542_ruleRHEL 8 must notify the System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) when allocated audit record storage volume 75 percent utilization.
☐SV-244544r958672_ruleA firewall must be active on RHEL 8.
☐SV-244545r958804_ruleThe RHEL 8 fapolicy module must be enabled.
☐SV-244546r1208752_ruleThe RHEL 8 fapolicy module must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
☐SV-244547r1014811_ruleRHEL 8 must have the USBGuard installed.
☐SV-244548r1014815_ruleRHEL 8 must enable the USBGuard.
☐SV-244549r958908_ruleAll RHEL 8 networked systems must have SSH installed.
☐SV-244550r1017350_ruleRHEL 8 must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted.
☐SV-244551r1017351_ruleRHEL 8 must not forward IPv4 source-routed packets.
☐SV-244552r1017352_ruleRHEL 8 must not forward IPv4 source-routed packets by default.
☐SV-244553r1017353_ruleRHEL 8 must ignore IPv4 Internet Control Message Protocol (ICMP) redirect messages.
☐SV-244554r1210517_ruleRHEL 8 must enable hardening for the Berkeley Packet Filter Just-in-time compiler.
☐SV-250315r1017356_ruleRHEL 8 systems, versions 8.2 and above, must configure SELinux context type to allow the use of a non-default faillock tally directory.
☐SV-250316r1017357_ruleRHEL 8 systems below version 8.2 must configure SELinux context type to allow the use of a non-default faillock tally directory.
☐SV-250317r1017358_ruleRHEL 8 must not enable IPv4 packet forwarding unless the system is a router.
☐SV-251706r1017359_ruleThe RHEL 8 operating system must not have accounts configured with blank or null passwords.
☐SV-251707r1017360_ruleRHEL 8 library directories must have mode 755 or less permissive.
☐SV-251708r1017362_ruleRHEL 8 library directories must be owned by root.
☐SV-251709r1017364_ruleRHEL 8 library directories must be group-owned by root or a system account.
☐SV-251710r958944_ruleThe RHEL 8 operating system must use a file integrity tool to verify correct operation of all security functions.
☐SV-251711r1017365_ruleRHEL 8 must specify the default "include" directory for the /etc/sudoers file.
☐SV-251712r1050789_ruleThe RHEL 8 operating system must not be configured to bypass password requirements for privilege escalation.
☐SV-251713r1017366_ruleRHEL 8 must ensure the password complexity module is enabled in the system-auth file.
☐SV-251716r1069329_ruleRHEL 8 systems, version 8.4 and above, must ensure the password complexity module is configured for three retries or less.
☐SV-251718r1017371_ruleThe graphical display manager must not be the default target on RHEL 8 unless approved.
☐SV-254520r1069331_ruleRHEL 8 must prevent nonprivileged users from executing privileged functions, including disabling, circumventing, or altering implemented security safeguards/countermeasures.
☐SV-256973r1017373_ruleRHEL 8 must ensure cryptographic verification of vendor software packages.
☐SV-256974r1069321_ruleRHEL 8 must be configured to allow sending email notifications of unauthorized configuration changes to designated personnel.
☐SV-257258r1069328_ruleRHEL 8.7 and higher must terminate idle user sessions.
☐SV-268322r1017568_ruleRHEL 8 must not allow blank or null passwords in the system-auth file.
☐SV-272482r1208740_ruleThe RHEL 8 SSH client must be configured to use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.
☐SV-272483r1184243_ruleThe RHEL 8 SSH client must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.
☐SV-272484r1134875_ruleRHEL 8 must elevate the SELinux context when an administrator calls the sudo command.
☐SV-274877r1155381_ruleRHEL 8 must audit any script or executable called by cron as root or by any privileged user.
☐SV-279929r1156340_ruleRHEL 8 must automatically exit interactive command shell user sessions after 10 minutes of inactivity.
☐SV-279930r1184239_ruleRHEL 8 IP tunnels must use FIPS 140-3-approved cryptographic algorithms.
☐SV-279931r1184237_ruleRHEL 8 must implement DOD-approved encryption in the bind package.
☐SV-279932r1156349_ruleRHEL 8 cryptographic policy must not be overridden.
☐SV-279933r1156352_ruleRHEL 8 must have the crypto-policies package installed.
☐SV-284947r1210519_ruleRHEL 8 must use a reverse-path filter for IPv4 network traffic, when possible, by default.
☐SV-284948r1208757_ruleRHEL 8 must log IPv4 packets with impossible addresses.
☐SV-284949r1208759_ruleRHEL 8 must log IPv4 packets with impossible addresses by default.