STIGQter STIGQter: STIG Summary:

Red Hat Enterprise Linux 9 Security Technical Implementation Guide

Version: 2

Release: 9 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-257777r1155676_ruleRHEL 9 must be a vendor-supported release.
SV-257778r1134892_ruleRHEL 9 vendor packaged system security patches and updates must be installed and up to date.
SV-257779r958390_ruleRHEL 9 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a command line user logon.
SV-257781r991589_ruleThe graphical display manager must not be the default target on RHEL 9 unless approved.
SV-257782r991589_ruleRHEL 9 must enable the hardware random number generator entropy gatherer service.
SV-257783r991562_ruleRHEL 9 systemd-journald service must be enabled.
SV-257784r1208766_ruleThe systemd Ctrl-Alt-Delete burst key sequence in RHEL 9 must be disabled.
SV-257785r1044833_ruleThe x86 Ctrl-Alt-Delete key sequence must be disabled on RHEL 9.
SV-257786r1044834_ruleRHEL 9 debug-shell systemd service must be disabled.
SV-257787r1184288_ruleRHEL 9 must require a boot loader superuser password.
SV-257788r1044838_ruleRHEL 9 must disable the ability of systemd to spawn an interactive boot process.
SV-257789r1137691_ruleRHEL 9 must require a unique superusers name upon booting into single-user and maintenance modes.
SV-257790r991589_ruleRHEL 9 /boot/grub2/grub.cfg file must be group-owned by root.
SV-257791r991589_ruleRHEL 9 /boot/grub2/grub.cfg file must be owned by root.
SV-257792r1184289_ruleRHEL 9 must disable virtual system calls.
SV-257793r1044843_ruleRHEL 9 must clear the page allocator to prevent use-after-free attacks.
SV-257794r1069362_ruleRHEL 9 must clear memory when it is freed to prevent use-after-free attacks.
SV-257795r1044845_ruleRHEL 9 must enable mitigations against processor-based vulnerabilities.
SV-257796r1044847_ruleRHEL 9 must enable auditing of processes that start prior to the audit daemon.
SV-257797r1198253_ruleRHEL 9 must restrict access to the kernel message buffer.
SV-257798r1198253_ruleRHEL 9 must prevent kernel profiling by nonprivileged users.
SV-257799r1155697_ruleRHEL 9 must prevent the loading of a new kernel for later execution.
SV-257800r1198253_ruleRHEL 9 must restrict exposed kernel pointer addresses access.
SV-257801r1155703_ruleRHEL 9 must enable kernel parameters to enforce discretionary access control (DAC) on hardlinks.
SV-257802r1155706_ruleRHEL 9 must enable kernel parameters to enforce discretionary access (DAC) control on symlinks.
SV-257803r1155668_ruleRHEL 9 must disable the kernel.core_pattern.
SV-257804r1044853_ruleRHEL 9 must be configured to disable the Asynchronous Transfer Mode kernel module.
SV-257805r1044856_ruleRHEL 9 must be configured to disable the Controller Area Network kernel module.
SV-257806r1044859_ruleRHEL 9 must be configured to disable the FireWire kernel module.
SV-257807r1044862_ruleRHEL 9 must disable the Stream Control Transmission Protocol (SCTP) kernel module.
SV-257808r1044865_ruleRHEL 9 must disable the Transparent Inter Process Communication (TIPC) kernel module.
SV-257809r1208769_ruleRHEL 9 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution.
SV-257810r1198253_ruleRHEL 9 must disable access to network bpf system call from nonprivileged processes.
SV-257811r1198253_ruleRHEL 9 must restrict usage of ptrace to descendant processes.
SV-257812r1134897_ruleRHEL 9 must disable core dump backtraces.
SV-257813r1134899_ruleRHEL 9 must disable storing core dumps.
SV-257814r1156057_ruleRHEL 9 must disable core dumps for all users.
SV-257815r1134903_ruleRHEL 9 must disable acquiring, saving, and processing core dumps.
SV-257816r1155715_ruleRHEL 9 must disable the use of user namespaces.
SV-257817r1069383_ruleRHEL 9 must implement nonexecutable data to protect its memory from unauthorized code execution.
SV-257818r1044876_ruleThe kdump service on RHEL 9 must be disabled.
SV-257819r1015075_ruleRHEL 9 must ensure cryptographic verification of vendor software packages.
SV-257820r1044878_ruleRHEL 9 must check the GPG signature of software packages originating from external software repositories before installation.
SV-257821r1015077_ruleRHEL 9 must check the GPG signature of locally installed software packages before installation.
SV-257822r1155615_ruleRHEL 9 must have GPG signature verification enabled for all software repositories.
SV-257823r1155641_ruleRHEL 9 must be configured so that the cryptographic hashes of system files match vendor values.
SV-257824r1044886_ruleRHEL 9 must remove all software components after updated versions have been installed.
SV-257825r1184291_ruleRHEL 9 subscription-manager package must be installed.
SV-257826r1208770_ruleRHEL 9 must not have a File Transfer Protocol (FTP) server package installed.
SV-257827r1044892_ruleRHEL 9 must not have the sendmail package installed.
SV-257828r1044894_ruleRHEL 9 must not have the nfs-utils package installed.
SV-257829r1044896_ruleRHEL 9 must not have the ypserv package installed.
SV-257830r1134906_ruleRHEL 9 must not install packages from the Extra Packages for Enterprise Linux (EPEL) repository.
SV-257831r1044898_ruleRHEL 9 must not have the telnet-server package installed.
SV-257832r1155653_ruleRHEL 9 must not have the gssproxy package installed.
SV-257833r1044902_ruleRHEL 9 must not have the iprutils package installed.
SV-257834r1044904_ruleRHEL 9 must not have the tuned package installed.
SV-257835r1155679_ruleThe Trivial File Transfer Protocol (TFTP) server must not be installed unless it is required, and if required, the RHEL 9 TFTP daemon must be configured to operate in secure mode.
SV-257836r1044908_ruleRHEL 9 must not have the quagga package installed.
SV-257837r1044910_ruleA graphical display manager must not be installed on RHEL 9 unless approved.
SV-257838r1044912_ruleRHEL 9 must have the openssl-pkcs11 package installed.
SV-257839r991589_ruleRHEL 9 must have the gnutls-utils package installed.
SV-257840r991589_ruleRHEL 9 must have the nss-tools package installed.
SV-257841r1044914_ruleRHEL 9 must have the rng-tools package installed.
SV-257842r1044916_ruleRHEL 9 must have the s-nail package installed.
SV-257843r991589_ruleA separate RHEL 9 file system must be used for user home directories (such as /home or an equivalent).
SV-257844r1044918_ruleRHEL 9 must use a separate file system for /tmp.
SV-257845r1044920_ruleRHEL 9 must use a separate file system for /var.
SV-257846r1044922_ruleRHEL 9 must use a separate file system for /var/log.
SV-257847r1044924_ruleRHEL 9 must use a separate file system for the system audit data path.
SV-257848r1044926_ruleRHEL 9 must use a separate file system for /var/tmp.
SV-257849r1044928_ruleRHEL 9 file system automount function must be disabled unless required.
SV-257850r1044930_ruleRHEL 9 must prevent device files from being interpreted on file systems that contain user home directories.
SV-257851r1044932_ruleRHEL 9 must prevent files with the setuid and setgid bit set from being executed on file systems that contain user home directories.
SV-257852r991589_ruleRHEL 9 must prevent code from being executed on file systems that contain user home directories.
SV-257854r1044934_ruleRHEL 9 must prevent special devices on file systems that are imported via Network File System (NFS).
SV-257855r1044936_ruleRHEL 9 must prevent code from being executed on file systems that are imported via Network File System (NFS).
SV-257856r1044938_ruleRHEL 9 must prevent files with the setuid and setgid bit set from being executed on file systems that are imported via Network File System (NFS).
SV-257857r991589_ruleRHEL 9 must prevent code from being executed on file systems that are used with removable media.
SV-257858r991589_ruleRHEL 9 must prevent special devices on file systems that are used with removable media.
SV-257859r991589_ruleRHEL 9 must prevent files with the setuid and setgid bit set from being executed on file systems that are used with removable media.
SV-257860r1044940_ruleRHEL 9 must mount /boot with the nodev option.
SV-257861r1044941_ruleRHEL 9 must prevent files with the setuid and setgid bit set from being executed on the /boot directory.
SV-257862r1184295_ruleRHEL 9 must prevent files with the setuid and setgid bit set from being executed on the /boot/efi directory.
SV-257863r1155633_ruleRHEL 9 must mount /dev/shm with the nodev option.
SV-257864r1155639_ruleRHEL 9 must mount /dev/shm with the noexec option.
SV-257865r1184297_ruleRHEL 9 must mount /dev/shm with the nosuid option.
SV-257866r958804_ruleRHEL 9 must mount /tmp with the nodev option.
SV-257867r958804_ruleRHEL 9 must mount /tmp with the noexec option.
SV-257868r958804_ruleRHEL 9 must mount /tmp with the nosuid option.
SV-257869r1102009_ruleRHEL 9 must mount /var with the nodev option.
SV-257870r958804_ruleRHEL 9 must mount /var/log with the nodev option.
SV-257871r958804_ruleRHEL 9 must mount /var/log with the noexec option.
SV-257872r958804_ruleRHEL 9 must mount /var/log with the nosuid option.
SV-257873r958804_ruleRHEL 9 must mount /var/log/audit with the nodev option.
SV-257874r958804_ruleRHEL 9 must mount /var/log/audit with the noexec option.
SV-257875r958804_ruleRHEL 9 must mount /var/log/audit with the nosuid option.
SV-257876r958804_ruleRHEL 9 must mount /var/tmp with the nodev option.
SV-257877r958804_ruleRHEL 9 must mount /var/tmp with the noexec option.
SV-257878r958804_ruleRHEL 9 must mount /var/tmp with the nosuid option.
SV-257879r1045454_ruleRHEL 9 local disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at rest protection.
SV-257880r1044951_ruleRHEL 9 must disable mounting of cramfs.
SV-257881r1184299_ruleRHEL 9 must prevent special devices on non-root local partitions.
SV-257882r991560_ruleRHEL 9 system commands must have mode 755 or less permissive.
SV-257883r991560_ruleRHEL 9 library directories must have mode 755 or less permissive.
SV-257884r1106306_ruleRHEL 9 library files must have mode 755 or less permissive.
SV-257885r1044953_ruleRHEL 9 /var/log directory must have mode 0755 or less permissive.
SV-257886r1044955_ruleRHEL 9 /var/log/messages file must have mode 0640 or less permissive.
SV-257887r991557_ruleRHEL 9 audit tools must have a mode of 0755 or less permissive.
SV-257888r1208771_ruleRHEL 9 permissions of cron configuration files and directories must not be modified from the operating system defaults.
SV-257889r1184302_ruleAll RHEL 9 local initialization files must have mode 0740 or less permissive.
SV-257890r1184305_ruleAll RHEL 9 local interactive user home directories must have mode 0750 or less permissive.
SV-257891r991589_ruleRHEL 9 /etc/group file must have mode 0644 or less permissive to prevent unauthorized access.
SV-257892r991589_ruleRHEL 9 /etc/group- file must have mode 0644 or less permissive to prevent unauthorized access.
SV-257893r991589_ruleRHEL 9 /etc/gshadow file must have mode 0000 or less permissive to prevent unauthorized access.
SV-257894r991589_ruleRHEL 9 /etc/gshadow- file must have mode 0000 or less permissive to prevent unauthorized access.
SV-257895r991589_ruleRHEL 9 /etc/passwd file must have mode 0644 or less permissive to prevent unauthorized access.
SV-257896r991589_ruleRHEL 9 /etc/passwd- file must have mode 0644 or less permissive to prevent unauthorized access.
SV-257897r991589_ruleRHEL 9 /etc/shadow- file must have mode 0000 or less permissive to prevent unauthorized access.
SV-257898r991589_ruleRHEL 9 /etc/group file must be owned by root.
SV-257899r991589_ruleRHEL 9 /etc/group file must be group-owned by root.
SV-257900r991589_ruleRHEL 9 /etc/group- file must be owned by root.
SV-257901r991589_ruleRHEL 9 /etc/group- file must be group-owned by root.
SV-257902r991589_ruleRHEL 9 /etc/gshadow file must be owned by root.
SV-257903r991589_ruleRHEL 9 /etc/gshadow file must be group-owned by root.
SV-257904r991589_ruleRHEL 9 /etc/gshadow- file must be owned by root.
SV-257905r991589_ruleRHEL 9 /etc/gshadow- file must be group-owned by root.
SV-257906r991589_ruleRHEL 9 /etc/passwd file must be owned by root.
SV-257907r991589_ruleRHEL 9 /etc/passwd file must be group-owned by root.
SV-257908r991589_ruleRHEL 9 /etc/passwd- file must be owned by root.
SV-257909r991589_ruleRHEL 9 /etc/passwd- file must be group-owned by root.
SV-257910r991589_ruleRHEL 9 /etc/shadow file must be owned by root.
SV-257911r991589_ruleRHEL 9 /etc/shadow file must be group-owned by root.
SV-257912r991589_ruleRHEL 9 /etc/shadow- file must be owned by root.
SV-257913r991589_ruleRHEL 9 /etc/shadow- file must be group-owned by root.
SV-257914r1044969_ruleRHEL 9 /var/log directory must be owned by root.
SV-257915r1044971_ruleRHEL 9 /var/log directory must be group-owned by root.
SV-257916r1101916_ruleRHEL 9 /var/log/messages file must be owned by root.
SV-257917r1101914_ruleRHEL 9 /var/log/messages file must be group-owned by root.
SV-257918r1044977_ruleRHEL 9 system commands must be owned by root.
SV-257919r1044979_ruleRHEL 9 system commands must be group-owned by root or a system account.
SV-257920r1101926_ruleRHEL 9 library files must be owned by root.
SV-257921r1106308_ruleRHEL 9 library files must be group-owned by root or a system account.
SV-257922r1044988_ruleRHEL 9 library directories must be owned by root.
SV-257923r1044991_ruleRHEL 9 library directories must be group-owned by root or a system account.
SV-257924r991557_ruleRHEL 9 audit tools must be owned by root.
SV-257925r991557_ruleRHEL 9 audit tools must be group-owned by root.
SV-257926r991589_ruleRHEL 9 cron configuration files directory must be owned by root.
SV-257927r991589_ruleRHEL 9 cron configuration files directory must be group-owned by root.
SV-257928r1155576_ruleAll RHEL 9 world-writable directories must be owned by root, sys, bin, or an application user.
SV-257929r1137695_ruleA sticky bit must be set on all RHEL 9 public directories.
SV-257930r991589_ruleAll RHEL 9 local files and directories must have a valid group owner.
SV-257931r991589_ruleAll RHEL 9 local files and directories must have a valid owner.
SV-257932r1014838_ruleRHEL 9 must be configured so that all system device files are correctly labeled to prevent unauthorized modification.
SV-257934r991589_ruleRHEL 9 /etc/shadow file must have mode 0000 to prevent unauthorized access.
SV-257935r1044994_ruleRHEL 9 must have the firewalld package installed.
SV-257936r1044995_ruleThe firewalld service on RHEL 9 must be active.
SV-257937r1106310_ruleThe RHEL 9 firewall must employ a deny-all, allow-by-exception policy for allowing connections to other systems.
SV-257939r1044997_ruleRHEL 9 must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring rate-limiting measures on impacted network interfaces are implemented.
SV-257940r1106312_ruleRHEL 9 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.
SV-257941r991589_ruleRHEL 9 network interfaces must not be in promiscuous mode.
SV-257942r1155718_ruleRHEL 9 must enable hardening for the Berkeley Packet Filter just-in-time compiler.
SV-257943r1045001_ruleRHEL 9 must have the chrony package installed.
SV-257944r1038944_ruleRHEL 9 chronyd service must be enabled.
SV-257945r1038944_ruleRHEL 9 must securely compare internal information system clocks at least every 24 hours.
SV-257946r1184307_ruleRHEL 9 must disable the chrony daemon from acting as a server.
SV-257947r958480_ruleRHEL 9 must disable network management of the chrony daemon.
SV-257948r1045004_ruleRHEL 9 systems using Domain Name Servers (DNS) resolution must have at least two name servers configured.
SV-257949r1134947_ruleRHEL 9 must configure a DNS processing mode in Network Manager.
SV-257950r1045006_ruleRHEL 9 must not have unauthorized IP tunnels configured.
SV-257951r1014843_ruleRHEL 9 must be configured to prevent unrestricted mail relaying.
SV-257953r958424_ruleRHEL 9 must forward mail from postmaster to the root account using a postfix alias.
SV-257954r1106315_ruleRHEL 9 libreswan package must be installed.
SV-257955r991589_ruleThere must be no shosts.equiv files on RHEL 9.
SV-257956r991589_ruleThere must be no .shosts files on RHEL 9.
SV-257957r1155618_ruleRHEL 9 must be configured to use TCP syncookies.
SV-257958r1155721_ruleRHEL 9 must ignore Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages.
SV-257959r1155724_ruleRHEL 9 must not forward Internet Protocol version 4 (IPv4) source-routed packets.
SV-257960r1155727_ruleRHEL 9 must log IPv4 packets with impossible addresses.
SV-257961r1155730_ruleRHEL 9 must log IPv4 packets with impossible addresses by default.
SV-257962r1155733_ruleRHEL 9 must use reverse path filtering on all IPv4 interfaces.
SV-257963r1155736_ruleRHEL 9 must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted.
SV-257964r1155739_ruleRHEL 9 must not forward IPv4 source-routed packets by default.
SV-257965r1155646_ruleRHEL 9 must use a reverse-path filter for IPv4 network traffic when possible by default.
SV-257966r1155742_ruleRHEL 9 must not respond to Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.
SV-257967r1155745_ruleRHEL 9 must limit the number of bogus Internet Control Message Protocol (ICMP) response errors logs.
SV-257968r1155748_ruleRHEL 9 must not send Internet Control Message Protocol (ICMP) redirects.
SV-257969r1155623_ruleRHEL 9 must not allow interfaces to perform Internet Control Message Protocol (ICMP) redirects by default.
SV-257970r1155751_ruleRHEL 9 must not enable IPv4 packet forwarding unless the system is a router.
SV-257971r1155754_ruleRHEL 9 must not accept router advertisements on all IPv6 interfaces.
SV-257972r1155757_ruleRHEL 9 must ignore IPv6 Internet Control Message Protocol (ICMP) redirect messages.
SV-257973r1155760_ruleRHEL 9 must not forward IPv6 source-routed packets.
SV-257974r1155763_ruleRHEL 9 must not enable IPv6 packet forwarding unless the system is a router.
SV-257975r1155766_ruleRHEL 9 must not accept router advertisements on all IPv6 interfaces by default.
SV-257976r1155769_ruleRHEL 9 must prevent IPv6 Internet Control Message Protocol (ICMP) redirect messages from being accepted.
SV-257977r1155772_ruleRHEL 9 must not forward IPv6 source-routed packets by default.
SV-257978r1045013_ruleAll RHEL 9 networked systems must have SSH installed.
SV-257979r958908_ruleAll RHEL 9 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
SV-257980r1045016_ruleRHEL 9 must have the openssh-clients package installed.
SV-257981r1101970_ruleRHEL 9 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a SSH logon.
SV-257982r1045021_ruleRHEL 9 must log SSH connection attempts and failures to the server.
SV-257983r1045024_ruleRHEL 9 SSHD must accept public key authentication.
SV-257984r1045026_ruleRHEL 9 SSHD must not allow blank passwords.
SV-257985r1069364_ruleRHEL 9 must not permit direct logons to the root account using remote access via SSH.
SV-257986r1045030_ruleRHEL 9 must enable the Pluggable Authentication Module (PAM) interface for SSHD.
SV-257989r1184309_ruleThe RHEL 9 SSH server must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.
SV-257991r1184311_ruleThe RHEL 9 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.
SV-257992r1045047_ruleRHEL 9 must not allow a noncertificate trusted host SSH logon to the system.
SV-257993r1045049_ruleRHEL 9 must not allow users to override SSH environment variables.
SV-257994r1045051_ruleRHEL 9 must force a frequent session key renegotiation for SSH connections to the server.
SV-257995r1045053_ruleRHEL 9 must be configured so that all network connections associated with SSH traffic terminate after becoming unresponsive.
SV-257996r1134915_ruleRHEL 9 must be configured so that all network connections associated with SSH traffic are terminated after 10 minutes of becoming unresponsive.
SV-257997r1069370_ruleRHEL 9 SSH server configuration file must be group-owned by root.
SV-257998r1082181_ruleThe RHEL 9 SSH server configuration file must be owned by root.
SV-257999r1155686_ruleRHEL 9 SSH server configuration files' permissions must not be modified.
SV-258000r1208772_ruleRHEL 9 SSH private host key files must have mode 0600 or less permissive.
SV-258001r991589_ruleRHEL 9 SSH public host key files must have mode 0644 or less permissive.
SV-258003r1045065_ruleRHEL 9 SSH daemon must not allow GSSAPI authentication.
SV-258004r1045067_ruleRHEL 9 SSH daemon must not allow Kerberos authentication.
SV-258005r1045069_ruleRHEL 9 SSH daemon must not allow rhosts authentication.
SV-258006r1045071_ruleRHEL 9 SSH daemon must not allow known hosts authentication.
SV-258007r1045073_ruleRHEL 9 SSH daemon must disable remote X connections for interactive users.
SV-258008r1045075_ruleRHEL 9 SSH daemon must perform strict mode checking of home directory configuration files.
SV-258009r1045077_ruleRHEL 9 SSH daemon must display the date and time of the last successful account logon upon an SSH logon.
SV-258011r1045079_ruleRHEL 9 SSH daemon must prevent remote hosts from connecting to the proxy display.
SV-258012r1014855_ruleRHEL 9 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a graphical user logon.
SV-258013r1045082_ruleRHEL 9 must prevent a user from overriding the banner-message-enable setting for the graphical user interface.
SV-258014r1045084_ruleRHEL 9 must disable the graphical user interface automount function unless required.
SV-258015r1045086_ruleRHEL 9 must prevent a user from overriding the disabling of the graphical user interface automount function.
SV-258016r958804_ruleRHEL 9 must disable the graphical user interface autorun function unless required.
SV-258017r1155688_ruleRHEL 9 must prevent a user from overriding the disabling of the graphical user interface autorun function.
SV-258018r1045090_ruleRHEL 9 must not allow unattended or automatic logon via the graphical user interface.
SV-258019r1045092_ruleRHEL 9 must be able to initiate directly a session lock for all connection types using smart card when the smart card is removed.
SV-258020r1045094_ruleRHEL 9 must prevent a user from overriding the disabling of the graphical user smart card removal action.
SV-258021r1015088_ruleRHEL 9 must enable a user session lock until that user re-establishes access using established identification and authentication procedures for graphical user sessions.
SV-258022r1045097_ruleRHEL 9 must prevent a user from overriding the screensaver lock-enabled setting for the graphical user interface.
SV-258023r1155656_ruleRHEL 9 must automatically lock graphical user sessions after 10 minutes of inactivity.
SV-258024r1045100_ruleRHEL 9 must prevent a user from overriding the session idle-delay setting for the graphical user interface.
SV-258025r958402_ruleRHEL 9 must initiate a session lock for graphical user interfaces when the screensaver is activated.
SV-258026r1045103_ruleRHEL 9 must prevent a user from overriding the session lock-delay setting for the graphical user interface.
SV-258027r1045106_ruleRHEL 9 must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
SV-258028r991589_ruleRHEL 9 effective dconf policy must match the policy keyfiles.
SV-258029r1045109_ruleRHEL 9 must disable the ability of a user to restart the system from the login screen.
SV-258030r1045112_ruleRHEL 9 must prevent a user from overriding the disable-restart-buttons setting for the graphical user interface.
SV-258031r1134920_ruleRHEL 9 must disable the ability of a user to accidentally press Ctrl-Alt-Del and cause a system to shut down or reboot.
SV-258032r1045117_ruleRHEL 9 must prevent a user from overriding the Ctrl-Alt-Del sequence settings for the graphical user interface.
SV-258033r1045120_ruleRHEL 9 must disable the user list at logon for graphical user interfaces.
SV-258034r1051267_ruleRHEL 9 must be configured to disable USB mass storage.
SV-258035r1045125_ruleRHEL 9 must have the USBGuard package installed.
SV-258036r1014861_ruleRHEL 9 must have the USBGuard package enabled.
SV-258037r1014863_ruleRHEL 9 must enable Linux audit logging for the USBGuard daemon.
SV-258038r1045128_ruleRHEL 9 must block unauthorized peripherals before establishing a connection.
SV-258039r1045131_ruleRHEL 9 Bluetooth must be disabled.
SV-258040r991568_ruleRHEL 9 wireless network adapters must be disabled.
SV-258041r1038967_ruleRHEL 9 user account passwords for new users or password changes must have a 60-day maximum password lifetime restriction in /etc/login.defs.
SV-258042r1045133_ruleRHEL 9 user account passwords must have a 60-day maximum password lifetime restriction.
SV-258043r991589_ruleAll RHEL 9 local interactive user accounts must be assigned a home directory upon creation.
SV-258044r1184313_ruleRHEL 9 must set the umask value to 077 for all local interactive user accounts.
SV-258045r958482_ruleRHEL 9 duplicate User IDs (UIDs) must not exist for interactive users.
SV-258046r991589_ruleRHEL 9 system accounts must not have an interactive login shell.
SV-258047r1101951_ruleRHEL 9 must automatically expire temporary accounts within 72 hours.
SV-258048r1069380_ruleAll RHEL 9 interactive users must have a primary group that exists.
SV-258049r1015092_ruleRHEL 9 must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity.
SV-258050r1045137_ruleExecutable search paths within the initialization files of all local interactive RHEL 9 users must only contain paths that resolve to the system default or the users home directory.
SV-258051r991589_ruleAll RHEL 9 local interactive users must have a home directory assigned in the /etc/passwd file.
SV-258052r1184315_ruleAll RHEL 9 local interactive user home directories defined in the /etc/passwd file must exist.
SV-258053r1208773_ruleAll RHEL 9 local interactive user home directories must be group-owned by the home directory owner's primary group.
SV-258054r958736_ruleRHEL 9 must automatically lock an account when three unsuccessful logon attempts occur.
SV-258055r1045140_ruleRHEL 9 must automatically lock the root account until the root account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.
SV-258056r1045143_ruleRHEL 9 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period.
SV-258057r1045146_ruleRHEL 9 must maintain an account lock until the locked account is released by an administrator.
SV-258058r1045148_ruleRHEL 9 must not have unauthorized accounts.
SV-258059r991589_ruleThe root account must be the only account having unrestricted access to RHEL 9 system.
SV-258060r1045150_ruleRHEL 9 must ensure account lockouts persist.
SV-258061r958482_ruleRHEL 9 groups must have unique Group ID (GID).
SV-258068r1101950_ruleRHEL 9 must automatically exit interactive command shell user sessions after 10 minutes of inactivity.
SV-258069r958398_ruleRHEL 9 must limit the number of concurrent sessions to ten for all accounts and/or account types.
SV-258070r1045153_ruleRHEL 9 must log username information when unsuccessful logon attempts occur.
SV-258071r991588_ruleRHEL 9 must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.
SV-258072r1184320_ruleRHEL 9 must define default permissions for the bash shell.
SV-258073r1184322_ruleRHEL 9 must define default permissions for the c shell.
SV-258074r991590_ruleRHEL 9 must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.
SV-258075r1184324_ruleRHEL 9 must define default permissions for the system default profile.
SV-258077r1155659_ruleRHEL 9 must terminate idle user sessions.
SV-258078r958944_ruleRHEL 9 must use a Linux Security Module configured to enforce limits on system services.
SV-258079r1045159_ruleRHEL 9 must enable the SELinux targeted policy.
SV-258080r1045162_ruleRHEL 9 must configure SELinux context type to allow the use of a nondefault faillock tally directory.
SV-258081r1045164_ruleRHEL 9 must have policycoreutils package installed.
SV-258082r1045166_ruleRHEL 9 policycoreutils-python-utils package must be installed.
SV-258083r1045168_ruleRHEL 9 must have the sudo package installed.
SV-258084r1050789_ruleRHEL 9 must require reauthentication when using the "sudo" command.
SV-258085r1045173_ruleRHEL 9 must use the invoking user's password for privilege escalation when using "sudo".
SV-258086r1102063_ruleRHEL 9 must require users to reauthenticate for privilege escalation.
SV-258087r1102071_ruleRHEL 9 must restrict privilege elevation to authorized personnel.
SV-258088r1155643_ruleRHEL 9 must restrict the use of the "su" command.
SV-258089r1045179_ruleRHEL 9 fapolicy module must be installed.
SV-258090r958808_ruleRHEL 9 fapolicy module must be enabled.
SV-258091r1208774_ruleRHEL 9 must ensure the password complexity module in the system-auth file is configured for three retries or less.
SV-258094r1045187_ruleRHEL 9 must not allow blank or null passwords.
SV-258095r1045189_ruleRHEL 9 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file.
SV-258096r1045191_ruleRHEL 9 must configure the use of the pam_faillock.so module in the /etc/pam.d/password-auth file.
SV-258097r1045193_ruleRHEL 9 must ensure the password complexity module is enabled in the password-auth file.
SV-258098r1045195_ruleRHEL 9 must ensure the password complexity module is enabled in the system-auth file.
SV-258099r1045198_ruleRHEL 9 password-auth must be configured to use a sufficient number of hashing rounds.
SV-258100r1045201_ruleRHEL 9 system-auth must be configured to use a sufficient number of hashing rounds.
SV-258101r1045204_ruleRHEL 9 must enforce password complexity rules for the root account.
SV-258102r1045207_ruleRHEL 9 must enforce password complexity by requiring that at least one lowercase character be used.
SV-258103r1045210_ruleRHEL 9 must enforce password complexity by requiring that at least one numeric character be used.
SV-258104r1015104_ruleRHEL 9 passwords for new users or password changes must have a 24 hours minimum password lifetime restriction in /etc/login.defs.
SV-258105r1045212_ruleRHEL 9 passwords must have a 24 hours minimum password lifetime restriction in /etc/shadow.
SV-258106r1102061_ruleRHEL 9 must require users to provide a password for privilege escalation.
SV-258107r1045218_ruleRHEL 9 passwords must be created with a minimum of 15 characters.
SV-258109r1045220_ruleRHEL 9 must enforce password complexity by requiring that at least one special character be used.
SV-258110r1045223_ruleRHEL 9 must prevent the use of dictionary words for passwords.
SV-258111r1045226_ruleRHEL 9 must enforce password complexity by requiring that at least one uppercase character be used.
SV-258112r1045229_ruleRHEL 9 must require the change of at least eight characters when passwords are changed.
SV-258113r1045232_ruleRHEL 9 must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed.
SV-258114r1045235_ruleRHEL 9 must require the maximum number of repeating characters be limited to three when passwords are changed.
SV-258115r1045238_ruleRHEL 9 must require the change of at least four character classes when passwords are changed.
SV-258116r1045240_ruleRHEL 9 must be configured so that user and group account administration utilities are configured to store only encrypted representations of passwords.
SV-258117r1015116_ruleRHEL 9 must be configured to use the shadow file to store only encrypted representations of passwords.
SV-258118r1050789_ruleRHEL 9 must not be configured to bypass password requirements for privilege escalation.
SV-258120r991589_ruleRHEL 9 must not have accounts configured with blank or null passwords.
SV-258121r1155682_ruleRHEL 9 must use the common access card (CAC) smart card driver.
SV-258122r1045246_ruleRHEL 9 must enable certificate based smart card authentication.
SV-258123r1134923_ruleRHEL 9 must implement certificate status checking for multifactor authentication.
SV-258124r1045250_ruleRHEL 9 must have the pcsc-lite package installed.
SV-258125r1208775_ruleThe pcscd socket on RHEL 9 must be active.
SV-258126r1045255_ruleRHEL 9 must have the opensc package installed.
SV-258127r1155648_ruleRHEL 9, for PKI-based authentication, must enforce authorized access to the corresponding private key.
SV-258128r1155626_ruleRHEL 9 must require authentication to access emergency mode.
SV-258129r1155628_ruleRHEL 9 must require authentication to access single-user mode.
SV-258131r1134927_ruleRHEL 9, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
SV-258132r1134929_ruleRHEL 9 must map the authenticated identity to the user or group account for PKI-based authentication.
SV-258133r1045263_ruleRHEL 9 must prohibit the use of cached authenticators after one day.
SV-258134r1155620_ruleRHEL 9 must have the AIDE package installed.
SV-258135r1045267_ruleRHEL 9 must routinely check the baseline configuration for unauthorized changes and notify the system administrator when anomalies in the operation of any security functions are discovered.
SV-258136r1045270_ruleRHEL 9 must use a file integrity tool that is configured to use FIPS 140-3-approved cryptographic hashes for validating file contents and directories.
SV-258137r1102081_ruleRHEL 9 must use cryptographic mechanisms to protect the integrity of audit tools.
SV-258138r1045274_ruleRHEL 9 must be configured so that the file integrity tool verifies Access Control Lists (ACLs).
SV-258139r1045276_ruleRHEL 9 must be configured so that the file integrity tool verifies extended attributes.
SV-258140r1106460_ruleRHEL 9 must have the rsyslog package installed.
SV-258141r1045280_ruleRHEL 9 must have the packages required for encrypting offloaded audit logs installed.
SV-258142r991589_ruleThe rsyslog service on RHEL 9 must be active.
SV-258143r1184329_ruleRHEL 9 must be configured so that the rsyslog daemon does not accept log messages from other servers unless the server is being used for log aggregation.
SV-258144r1045286_ruleAll RHEL 9 remote access methods must be monitored.
SV-258146r1045288_ruleRHEL 9 must authenticate the remote logging server for offloading audit logs via rsyslog.
SV-258147r1045290_ruleRHEL 9 must encrypt the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog.
SV-258148r1045292_ruleRHEL 9 must encrypt via the gtls driver the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog.
SV-258149r1155580_ruleRHEL 9 must be configured to forward audit records via TCP to a different system or media from the system being audited via rsyslog.
SV-258150r1045296_ruleRHEL 9 must use cron logging.
SV-258151r1045298_ruleRHEL 9 audit package must be installed.
SV-258152r1015127_ruleRHEL 9 audit service must be enabled.
SV-258153r1038966_ruleRHEL 9 audit system must take appropriate action when an error writing to the audit storage volume occurs.
SV-258154r1038966_ruleRHEL 9 audit system must take appropriate action when the audit storage volume is full.
SV-258155r1045300_ruleRHEL 9 must allocate audit record storage capacity to store at least one week's worth of audit records.
SV-258156r1106364_ruleRHEL 9 must take action when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity.
SV-258157r1134932_ruleRHEL 9 must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume reaches 75 percent utilization.
SV-258158r971542_ruleRHEL 9 must take action when allocated audit record storage volume reaches 95 percent of the audit record storage capacity.
SV-258159r971542_ruleRHEL 9 must take action when allocated audit record storage volume reaches 95 percent of the repository maximum audit record storage capacity.
SV-258160r1038966_ruleRHEL 9 audit system must take appropriate action when the audit files have reached maximum size.
SV-258161r958416_ruleRHEL 9 must label all offloaded audit logs before sending them to the central log server.
SV-258162r1184331_ruleRHEL 9 must take appropriate action when the internal event queue is full.
SV-258163r958424_ruleRHEL 9 System Administrator (SA) and/or information system security officer (ISSO) (at a minimum) must be alerted of an audit processing failure event.
SV-258164r1045301_ruleRHEL 9 audit system must audit local events.
SV-258165r958434_ruleRHEL 9 audit logs must be group-owned by root or by a restricted logging group to prevent unauthorized read access.
SV-258166r1045303_ruleRHEL 9 audit log directory must be owned by root to prevent unauthorized read access.
SV-258167r1155630_ruleRHEL 9 audit logs file must have mode 0600 or less permissive to prevent unauthorized access to the audit log.
SV-258168r958428_ruleRHEL 9 must periodically flush audit records to disk to prevent the loss of audit records.
SV-258169r991556_ruleRHEL 9 must produce audit records containing information to establish the identity of any individual or process associated with the event.
SV-258170r991589_ruleRHEL 9 must write audit records to disk.
SV-258171r1208777_ruleRHEL 9 must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.
SV-258173r1101933_ruleRHEL 9 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.
SV-258174r958424_ruleRHEL 9 must have mail aliases to notify the information system security officer (ISSO) and system administrator (SA) (at a minimum) in the event of an audit processing failure.
SV-258175r1045310_ruleRHEL 9 audispd-plugins package must be installed.
SV-258176r1155595_ruleRHEL 9 must audit uses of the "execve" system call.
SV-258177r1155597_ruleRHEL 9 must audit all uses of the chmod, fchmod, and fchmodat system calls.
SV-258178r1155599_ruleRHEL 9 must audit all uses of the chown, fchown, fchownat, and lchown system calls.
SV-258179r1155601_ruleRHEL 9 must audit all uses of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls.
SV-258180r1045325_ruleRHEL 9 must audit all uses of umount system calls.
SV-258181r1045328_ruleRHEL 9 must audit all uses of the chacl command.
SV-258182r1045331_ruleRHEL 9 must audit all uses of the setfacl command.
SV-258183r1045334_ruleRHEL 9 must audit all uses of the chcon command.
SV-258184r1045337_ruleRHEL 9 must audit all uses of the semanage command.
SV-258185r1045340_ruleRHEL 9 must audit all uses of the setfiles command.
SV-258186r1045343_ruleRHEL 9 must audit all uses of the setsebool command.
SV-258187r1155603_ruleRHEL 9 must audit all uses of the rename, unlink, rmdir, renameat, and unlinkat system calls.
SV-258188r1155605_ruleRHEL 9 must audit all uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls.
SV-258189r1155607_ruleRHEL 9 must audit all uses of the delete_module system call.
SV-258190r1155609_ruleRHEL 9 must audit all uses of the init_module and finit_module system calls.
SV-258191r1045358_ruleRHEL 9 must audit all uses of the chage command.
SV-258192r1045361_ruleRHEL 9 must audit all uses of the chsh command.
SV-258193r1045364_ruleRHEL 9 must audit all uses of the crontab command.
SV-258194r1045367_ruleRHEL 9 must audit all uses of the gpasswd command.
SV-258195r1045370_ruleRHEL 9 must audit all uses of the kmod command.
SV-258196r1045373_ruleRHEL 9 must audit all uses of the newgrp command.
SV-258197r1045376_ruleRHEL 9 must audit all uses of the pam_timestamp_check command.
SV-258198r1045379_ruleRHEL 9 must audit all uses of the passwd command.
SV-258199r1045382_ruleRHEL 9 must audit all uses of the postdrop command.
SV-258200r1045385_ruleRHEL 9 must audit all uses of the postqueue command.
SV-258201r1045388_ruleRHEL 9 must audit all uses of the ssh-agent command.
SV-258202r1045391_ruleRHEL 9 must audit all uses of the ssh-keysign command.
SV-258203r1045394_ruleRHEL 9 must audit all uses of the su command.
SV-258204r1045397_ruleRHEL 9 must audit all uses of the sudo command.
SV-258205r1045400_ruleRHEL 9 must audit all uses of the sudoedit command.
SV-258206r1045403_ruleRHEL 9 must audit all uses of the unix_chkpwd command.
SV-258207r1045406_ruleRHEL 9 must audit all uses of the unix_update command.
SV-258208r1045409_ruleRHEL 9 must audit all uses of the userhelper command.
SV-258209r1045412_ruleRHEL 9 must audit all uses of the usermod command.
SV-258210r1045415_ruleRHEL 9 must audit all uses of the mount command.
SV-258211r1045418_ruleSuccessful/unsuccessful uses of the init command in RHEL 9 must generate an audit record.
SV-258212r1045421_ruleSuccessful/unsuccessful uses of the poweroff command in RHEL 9 must generate an audit record.
SV-258213r1045424_ruleSuccessful/unsuccessful uses of the reboot command in RHEL 9 must generate an audit record.
SV-258214r1045427_ruleSuccessful/unsuccessful uses of the shutdown command in RHEL 9 must generate an audit record.
SV-258215r1155611_ruleSuccessful/unsuccessful uses of the umount system call in RHEL 9 must generate an audit record.
SV-258216r1155613_ruleSuccessful/unsuccessful uses of the umount2 system call in RHEL 9 must generate an audit record.
SV-258217r1210919_ruleRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.
SV-258218r1210920_ruleRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/directory.
SV-258219r1210921_ruleRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
SV-258220r1210922_ruleRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
SV-258221r1210923_ruleRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.
SV-258222r1210924_ruleRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
SV-258223r1210925_ruleRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
SV-258224r1210926_ruleRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/faillock.
SV-258225r1210927_ruleRHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/lastlog.
SV-258227r1014992_ruleRHEL 9 must take appropriate action when a critical audit processing failure occurs.
SV-258228r991572_ruleRHEL 9 audit system must protect logon UIDs from unauthorized change.
SV-258229r958434_ruleRHEL 9 audit system must protect auditing rules from unauthorized change.
SV-258230r1184334_ruleRHEL 9 must enable FIPS mode.
SV-258231r1208790_ruleRHEL 9 must employ FIPS 140-3-approved cryptographic hashing algorithms for all stored passwords.
SV-258232r1184335_ruleRHEL 9 IP tunnels must use FIPS 140-3 approved cryptographic algorithms.
SV-258233r1015136_ruleRHEL 9 pam_unix.so module must be configured in the password-auth file to use a FIPS 140-3 approved cryptographic hashing algorithm for system authentication.
SV-258234r1184292_ruleRHEL 9 must have the crypto-policies package installed.
SV-258236r1101920_ruleRHEL 9 cryptographic policy must not be overridden.
SV-258241r1184293_ruleRHEL 9 must implement a FIPS 140-3-compliant systemwide cryptographic policy.
SV-258242r1184336_ruleRHEL 9 must implement DOD-approved encryption in the bind package.
SV-270174r1044831_ruleRHEL 9 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a graphical user logon.
SV-270175r1137691_ruleRHEL 9 "/etc/audit/" must be owned by root.
SV-270176r1137691_ruleRHEL 9 "/etc/audit/" must be group-owned by root.
SV-270177r1184308_ruleThe RHEL 9 SSH client must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.
SV-270178r1184310_ruleThe RHEL 9 SSH client must be configured to use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.
SV-270180r1184327_ruleThe RHEL 9 fapolicy module must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
SV-272488r1155665_ruleRHEL 9 must have the Postfix package installed.
SV-272496r1155582_ruleRHEL 9 must elevate the SELinux context when an administrator calls the sudo command.
SV-279936r1210929_ruleRHEL 9 must audit any script or executable called by cron as root or by any privileged user.