| Checked | Name | Title |
|---|
| ☐ | SV-257777r1155676_rule | RHEL 9 must be a vendor-supported release. |
| ☐ | SV-257778r1134892_rule | RHEL 9 vendor packaged system security patches and updates must be installed and up to date. |
| ☐ | SV-257779r958390_rule | RHEL 9 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a command line user logon. |
| ☐ | SV-257781r991589_rule | The graphical display manager must not be the default target on RHEL 9 unless approved. |
| ☐ | SV-257782r991589_rule | RHEL 9 must enable the hardware random number generator entropy gatherer service. |
| ☐ | SV-257783r991562_rule | RHEL 9 systemd-journald service must be enabled. |
| ☐ | SV-257784r1208766_rule | The systemd Ctrl-Alt-Delete burst key sequence in RHEL 9 must be disabled. |
| ☐ | SV-257785r1044833_rule | The x86 Ctrl-Alt-Delete key sequence must be disabled on RHEL 9. |
| ☐ | SV-257786r1044834_rule | RHEL 9 debug-shell systemd service must be disabled. |
| ☐ | SV-257787r1184288_rule | RHEL 9 must require a boot loader superuser password. |
| ☐ | SV-257788r1044838_rule | RHEL 9 must disable the ability of systemd to spawn an interactive boot process. |
| ☐ | SV-257789r1137691_rule | RHEL 9 must require a unique superusers name upon booting into single-user and maintenance modes. |
| ☐ | SV-257790r991589_rule | RHEL 9 /boot/grub2/grub.cfg file must be group-owned by root. |
| ☐ | SV-257791r991589_rule | RHEL 9 /boot/grub2/grub.cfg file must be owned by root. |
| ☐ | SV-257792r1184289_rule | RHEL 9 must disable virtual system calls. |
| ☐ | SV-257793r1044843_rule | RHEL 9 must clear the page allocator to prevent use-after-free attacks. |
| ☐ | SV-257794r1069362_rule | RHEL 9 must clear memory when it is freed to prevent use-after-free attacks. |
| ☐ | SV-257795r1044845_rule | RHEL 9 must enable mitigations against processor-based vulnerabilities. |
| ☐ | SV-257796r1044847_rule | RHEL 9 must enable auditing of processes that start prior to the audit daemon. |
| ☐ | SV-257797r1198253_rule | RHEL 9 must restrict access to the kernel message buffer. |
| ☐ | SV-257798r1198253_rule | RHEL 9 must prevent kernel profiling by nonprivileged users. |
| ☐ | SV-257799r1155697_rule | RHEL 9 must prevent the loading of a new kernel for later execution. |
| ☐ | SV-257800r1198253_rule | RHEL 9 must restrict exposed kernel pointer addresses access. |
| ☐ | SV-257801r1155703_rule | RHEL 9 must enable kernel parameters to enforce discretionary access control (DAC) on hardlinks. |
| ☐ | SV-257802r1155706_rule | RHEL 9 must enable kernel parameters to enforce discretionary access (DAC) control on symlinks. |
| ☐ | SV-257803r1155668_rule | RHEL 9 must disable the kernel.core_pattern. |
| ☐ | SV-257804r1044853_rule | RHEL 9 must be configured to disable the Asynchronous Transfer Mode kernel module. |
| ☐ | SV-257805r1044856_rule | RHEL 9 must be configured to disable the Controller Area Network kernel module. |
| ☐ | SV-257806r1044859_rule | RHEL 9 must be configured to disable the FireWire kernel module. |
| ☐ | SV-257807r1044862_rule | RHEL 9 must disable the Stream Control Transmission Protocol (SCTP) kernel module. |
| ☐ | SV-257808r1044865_rule | RHEL 9 must disable the Transparent Inter Process Communication (TIPC) kernel module. |
| ☐ | SV-257809r1208769_rule | RHEL 9 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution. |
| ☐ | SV-257810r1198253_rule | RHEL 9 must disable access to network bpf system call from nonprivileged processes. |
| ☐ | SV-257811r1198253_rule | RHEL 9 must restrict usage of ptrace to descendant processes. |
| ☐ | SV-257812r1134897_rule | RHEL 9 must disable core dump backtraces. |
| ☐ | SV-257813r1134899_rule | RHEL 9 must disable storing core dumps. |
| ☐ | SV-257814r1156057_rule | RHEL 9 must disable core dumps for all users. |
| ☐ | SV-257815r1134903_rule | RHEL 9 must disable acquiring, saving, and processing core dumps. |
| ☐ | SV-257816r1155715_rule | RHEL 9 must disable the use of user namespaces. |
| ☐ | SV-257817r1069383_rule | RHEL 9 must implement nonexecutable data to protect its memory from unauthorized code execution. |
| ☐ | SV-257818r1044876_rule | The kdump service on RHEL 9 must be disabled. |
| ☐ | SV-257819r1015075_rule | RHEL 9 must ensure cryptographic verification of vendor software packages. |
| ☐ | SV-257820r1044878_rule | RHEL 9 must check the GPG signature of software packages originating from external software repositories before installation. |
| ☐ | SV-257821r1015077_rule | RHEL 9 must check the GPG signature of locally installed software packages before installation. |
| ☐ | SV-257822r1155615_rule | RHEL 9 must have GPG signature verification enabled for all software repositories. |
| ☐ | SV-257823r1155641_rule | RHEL 9 must be configured so that the cryptographic hashes of system files match vendor values. |
| ☐ | SV-257824r1044886_rule | RHEL 9 must remove all software components after updated versions have been installed. |
| ☐ | SV-257825r1184291_rule | RHEL 9 subscription-manager package must be installed. |
| ☐ | SV-257826r1208770_rule | RHEL 9 must not have a File Transfer Protocol (FTP) server package installed. |
| ☐ | SV-257827r1044892_rule | RHEL 9 must not have the sendmail package installed. |
| ☐ | SV-257828r1044894_rule | RHEL 9 must not have the nfs-utils package installed. |
| ☐ | SV-257829r1044896_rule | RHEL 9 must not have the ypserv package installed. |
| ☐ | SV-257830r1134906_rule | RHEL 9 must not install packages from the Extra Packages for Enterprise Linux (EPEL) repository. |
| ☐ | SV-257831r1044898_rule | RHEL 9 must not have the telnet-server package installed. |
| ☐ | SV-257832r1155653_rule | RHEL 9 must not have the gssproxy package installed. |
| ☐ | SV-257833r1044902_rule | RHEL 9 must not have the iprutils package installed. |
| ☐ | SV-257834r1044904_rule | RHEL 9 must not have the tuned package installed. |
| ☐ | SV-257835r1155679_rule | The Trivial File Transfer Protocol (TFTP) server must not be installed unless it is required, and if required, the RHEL 9 TFTP daemon must be configured to operate in secure mode. |
| ☐ | SV-257836r1044908_rule | RHEL 9 must not have the quagga package installed. |
| ☐ | SV-257837r1044910_rule | A graphical display manager must not be installed on RHEL 9 unless approved. |
| ☐ | SV-257838r1044912_rule | RHEL 9 must have the openssl-pkcs11 package installed. |
| ☐ | SV-257839r991589_rule | RHEL 9 must have the gnutls-utils package installed. |
| ☐ | SV-257840r991589_rule | RHEL 9 must have the nss-tools package installed. |
| ☐ | SV-257841r1044914_rule | RHEL 9 must have the rng-tools package installed. |
| ☐ | SV-257842r1044916_rule | RHEL 9 must have the s-nail package installed. |
| ☐ | SV-257843r991589_rule | A separate RHEL 9 file system must be used for user home directories (such as /home or an equivalent). |
| ☐ | SV-257844r1044918_rule | RHEL 9 must use a separate file system for /tmp. |
| ☐ | SV-257845r1044920_rule | RHEL 9 must use a separate file system for /var. |
| ☐ | SV-257846r1044922_rule | RHEL 9 must use a separate file system for /var/log. |
| ☐ | SV-257847r1044924_rule | RHEL 9 must use a separate file system for the system audit data path. |
| ☐ | SV-257848r1044926_rule | RHEL 9 must use a separate file system for /var/tmp. |
| ☐ | SV-257849r1044928_rule | RHEL 9 file system automount function must be disabled unless required. |
| ☐ | SV-257850r1044930_rule | RHEL 9 must prevent device files from being interpreted on file systems that contain user home directories. |
| ☐ | SV-257851r1044932_rule | RHEL 9 must prevent files with the setuid and setgid bit set from being executed on file systems that contain user home directories. |
| ☐ | SV-257852r991589_rule | RHEL 9 must prevent code from being executed on file systems that contain user home directories. |
| ☐ | SV-257854r1044934_rule | RHEL 9 must prevent special devices on file systems that are imported via Network File System (NFS). |
| ☐ | SV-257855r1044936_rule | RHEL 9 must prevent code from being executed on file systems that are imported via Network File System (NFS). |
| ☐ | SV-257856r1044938_rule | RHEL 9 must prevent files with the setuid and setgid bit set from being executed on file systems that are imported via Network File System (NFS). |
| ☐ | SV-257857r991589_rule | RHEL 9 must prevent code from being executed on file systems that are used with removable media. |
| ☐ | SV-257858r991589_rule | RHEL 9 must prevent special devices on file systems that are used with removable media. |
| ☐ | SV-257859r991589_rule | RHEL 9 must prevent files with the setuid and setgid bit set from being executed on file systems that are used with removable media. |
| ☐ | SV-257860r1044940_rule | RHEL 9 must mount /boot with the nodev option. |
| ☐ | SV-257861r1044941_rule | RHEL 9 must prevent files with the setuid and setgid bit set from being executed on the /boot directory. |
| ☐ | SV-257862r1184295_rule | RHEL 9 must prevent files with the setuid and setgid bit set from being executed on the /boot/efi directory. |
| ☐ | SV-257863r1155633_rule | RHEL 9 must mount /dev/shm with the nodev option. |
| ☐ | SV-257864r1155639_rule | RHEL 9 must mount /dev/shm with the noexec option. |
| ☐ | SV-257865r1184297_rule | RHEL 9 must mount /dev/shm with the nosuid option. |
| ☐ | SV-257866r958804_rule | RHEL 9 must mount /tmp with the nodev option. |
| ☐ | SV-257867r958804_rule | RHEL 9 must mount /tmp with the noexec option. |
| ☐ | SV-257868r958804_rule | RHEL 9 must mount /tmp with the nosuid option. |
| ☐ | SV-257869r1102009_rule | RHEL 9 must mount /var with the nodev option. |
| ☐ | SV-257870r958804_rule | RHEL 9 must mount /var/log with the nodev option. |
| ☐ | SV-257871r958804_rule | RHEL 9 must mount /var/log with the noexec option. |
| ☐ | SV-257872r958804_rule | RHEL 9 must mount /var/log with the nosuid option. |
| ☐ | SV-257873r958804_rule | RHEL 9 must mount /var/log/audit with the nodev option. |
| ☐ | SV-257874r958804_rule | RHEL 9 must mount /var/log/audit with the noexec option. |
| ☐ | SV-257875r958804_rule | RHEL 9 must mount /var/log/audit with the nosuid option. |
| ☐ | SV-257876r958804_rule | RHEL 9 must mount /var/tmp with the nodev option. |
| ☐ | SV-257877r958804_rule | RHEL 9 must mount /var/tmp with the noexec option. |
| ☐ | SV-257878r958804_rule | RHEL 9 must mount /var/tmp with the nosuid option. |
| ☐ | SV-257879r1045454_rule | RHEL 9 local disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at rest protection. |
| ☐ | SV-257880r1044951_rule | RHEL 9 must disable mounting of cramfs. |
| ☐ | SV-257881r1184299_rule | RHEL 9 must prevent special devices on non-root local partitions. |
| ☐ | SV-257882r991560_rule | RHEL 9 system commands must have mode 755 or less permissive. |
| ☐ | SV-257883r991560_rule | RHEL 9 library directories must have mode 755 or less permissive. |
| ☐ | SV-257884r1106306_rule | RHEL 9 library files must have mode 755 or less permissive. |
| ☐ | SV-257885r1044953_rule | RHEL 9 /var/log directory must have mode 0755 or less permissive. |
| ☐ | SV-257886r1044955_rule | RHEL 9 /var/log/messages file must have mode 0640 or less permissive. |
| ☐ | SV-257887r991557_rule | RHEL 9 audit tools must have a mode of 0755 or less permissive. |
| ☐ | SV-257888r1208771_rule | RHEL 9 permissions of cron configuration files and directories must not be modified from the operating system defaults. |
| ☐ | SV-257889r1184302_rule | All RHEL 9 local initialization files must have mode 0740 or less permissive. |
| ☐ | SV-257890r1184305_rule | All RHEL 9 local interactive user home directories must have mode 0750 or less permissive. |
| ☐ | SV-257891r991589_rule | RHEL 9 /etc/group file must have mode 0644 or less permissive to prevent unauthorized access. |
| ☐ | SV-257892r991589_rule | RHEL 9 /etc/group- file must have mode 0644 or less permissive to prevent unauthorized access. |
| ☐ | SV-257893r991589_rule | RHEL 9 /etc/gshadow file must have mode 0000 or less permissive to prevent unauthorized access. |
| ☐ | SV-257894r991589_rule | RHEL 9 /etc/gshadow- file must have mode 0000 or less permissive to prevent unauthorized access. |
| ☐ | SV-257895r991589_rule | RHEL 9 /etc/passwd file must have mode 0644 or less permissive to prevent unauthorized access. |
| ☐ | SV-257896r991589_rule | RHEL 9 /etc/passwd- file must have mode 0644 or less permissive to prevent unauthorized access. |
| ☐ | SV-257897r991589_rule | RHEL 9 /etc/shadow- file must have mode 0000 or less permissive to prevent unauthorized access. |
| ☐ | SV-257898r991589_rule | RHEL 9 /etc/group file must be owned by root. |
| ☐ | SV-257899r991589_rule | RHEL 9 /etc/group file must be group-owned by root. |
| ☐ | SV-257900r991589_rule | RHEL 9 /etc/group- file must be owned by root. |
| ☐ | SV-257901r991589_rule | RHEL 9 /etc/group- file must be group-owned by root. |
| ☐ | SV-257902r991589_rule | RHEL 9 /etc/gshadow file must be owned by root. |
| ☐ | SV-257903r991589_rule | RHEL 9 /etc/gshadow file must be group-owned by root. |
| ☐ | SV-257904r991589_rule | RHEL 9 /etc/gshadow- file must be owned by root. |
| ☐ | SV-257905r991589_rule | RHEL 9 /etc/gshadow- file must be group-owned by root. |
| ☐ | SV-257906r991589_rule | RHEL 9 /etc/passwd file must be owned by root. |
| ☐ | SV-257907r991589_rule | RHEL 9 /etc/passwd file must be group-owned by root. |
| ☐ | SV-257908r991589_rule | RHEL 9 /etc/passwd- file must be owned by root. |
| ☐ | SV-257909r991589_rule | RHEL 9 /etc/passwd- file must be group-owned by root. |
| ☐ | SV-257910r991589_rule | RHEL 9 /etc/shadow file must be owned by root. |
| ☐ | SV-257911r991589_rule | RHEL 9 /etc/shadow file must be group-owned by root. |
| ☐ | SV-257912r991589_rule | RHEL 9 /etc/shadow- file must be owned by root. |
| ☐ | SV-257913r991589_rule | RHEL 9 /etc/shadow- file must be group-owned by root. |
| ☐ | SV-257914r1044969_rule | RHEL 9 /var/log directory must be owned by root. |
| ☐ | SV-257915r1044971_rule | RHEL 9 /var/log directory must be group-owned by root. |
| ☐ | SV-257916r1101916_rule | RHEL 9 /var/log/messages file must be owned by root. |
| ☐ | SV-257917r1101914_rule | RHEL 9 /var/log/messages file must be group-owned by root. |
| ☐ | SV-257918r1044977_rule | RHEL 9 system commands must be owned by root. |
| ☐ | SV-257919r1044979_rule | RHEL 9 system commands must be group-owned by root or a system account. |
| ☐ | SV-257920r1101926_rule | RHEL 9 library files must be owned by root. |
| ☐ | SV-257921r1106308_rule | RHEL 9 library files must be group-owned by root or a system account. |
| ☐ | SV-257922r1044988_rule | RHEL 9 library directories must be owned by root. |
| ☐ | SV-257923r1044991_rule | RHEL 9 library directories must be group-owned by root or a system account. |
| ☐ | SV-257924r991557_rule | RHEL 9 audit tools must be owned by root. |
| ☐ | SV-257925r991557_rule | RHEL 9 audit tools must be group-owned by root. |
| ☐ | SV-257926r991589_rule | RHEL 9 cron configuration files directory must be owned by root. |
| ☐ | SV-257927r991589_rule | RHEL 9 cron configuration files directory must be group-owned by root. |
| ☐ | SV-257928r1155576_rule | All RHEL 9 world-writable directories must be owned by root, sys, bin, or an application user. |
| ☐ | SV-257929r1137695_rule | A sticky bit must be set on all RHEL 9 public directories. |
| ☐ | SV-257930r991589_rule | All RHEL 9 local files and directories must have a valid group owner. |
| ☐ | SV-257931r991589_rule | All RHEL 9 local files and directories must have a valid owner. |
| ☐ | SV-257932r1014838_rule | RHEL 9 must be configured so that all system device files are correctly labeled to prevent unauthorized modification. |
| ☐ | SV-257934r991589_rule | RHEL 9 /etc/shadow file must have mode 0000 to prevent unauthorized access. |
| ☐ | SV-257935r1044994_rule | RHEL 9 must have the firewalld package installed. |
| ☐ | SV-257936r1044995_rule | The firewalld service on RHEL 9 must be active. |
| ☐ | SV-257937r1106310_rule | The RHEL 9 firewall must employ a deny-all, allow-by-exception policy for allowing connections to other systems. |
| ☐ | SV-257939r1044997_rule | RHEL 9 must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring rate-limiting measures on impacted network interfaces are implemented. |
| ☐ | SV-257940r1106312_rule | RHEL 9 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments. |
| ☐ | SV-257941r991589_rule | RHEL 9 network interfaces must not be in promiscuous mode. |
| ☐ | SV-257942r1155718_rule | RHEL 9 must enable hardening for the Berkeley Packet Filter just-in-time compiler. |
| ☐ | SV-257943r1045001_rule | RHEL 9 must have the chrony package installed. |
| ☐ | SV-257944r1038944_rule | RHEL 9 chronyd service must be enabled. |
| ☐ | SV-257945r1038944_rule | RHEL 9 must securely compare internal information system clocks at least every 24 hours. |
| ☐ | SV-257946r1184307_rule | RHEL 9 must disable the chrony daemon from acting as a server. |
| ☐ | SV-257947r958480_rule | RHEL 9 must disable network management of the chrony daemon. |
| ☐ | SV-257948r1045004_rule | RHEL 9 systems using Domain Name Servers (DNS) resolution must have at least two name servers configured. |
| ☐ | SV-257949r1134947_rule | RHEL 9 must configure a DNS processing mode in Network Manager. |
| ☐ | SV-257950r1045006_rule | RHEL 9 must not have unauthorized IP tunnels configured. |
| ☐ | SV-257951r1014843_rule | RHEL 9 must be configured to prevent unrestricted mail relaying. |
| ☐ | SV-257953r958424_rule | RHEL 9 must forward mail from postmaster to the root account using a postfix alias. |
| ☐ | SV-257954r1106315_rule | RHEL 9 libreswan package must be installed. |
| ☐ | SV-257955r991589_rule | There must be no shosts.equiv files on RHEL 9. |
| ☐ | SV-257956r991589_rule | There must be no .shosts files on RHEL 9. |
| ☐ | SV-257957r1155618_rule | RHEL 9 must be configured to use TCP syncookies. |
| ☐ | SV-257958r1155721_rule | RHEL 9 must ignore Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages. |
| ☐ | SV-257959r1155724_rule | RHEL 9 must not forward Internet Protocol version 4 (IPv4) source-routed packets. |
| ☐ | SV-257960r1155727_rule | RHEL 9 must log IPv4 packets with impossible addresses. |
| ☐ | SV-257961r1155730_rule | RHEL 9 must log IPv4 packets with impossible addresses by default. |
| ☐ | SV-257962r1155733_rule | RHEL 9 must use reverse path filtering on all IPv4 interfaces. |
| ☐ | SV-257963r1155736_rule | RHEL 9 must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted. |
| ☐ | SV-257964r1155739_rule | RHEL 9 must not forward IPv4 source-routed packets by default. |
| ☐ | SV-257965r1155646_rule | RHEL 9 must use a reverse-path filter for IPv4 network traffic when possible by default. |
| ☐ | SV-257966r1155742_rule | RHEL 9 must not respond to Internet Control Message Protocol (ICMP) echoes sent to a broadcast address. |
| ☐ | SV-257967r1155745_rule | RHEL 9 must limit the number of bogus Internet Control Message Protocol (ICMP) response errors logs. |
| ☐ | SV-257968r1155748_rule | RHEL 9 must not send Internet Control Message Protocol (ICMP) redirects. |
| ☐ | SV-257969r1155623_rule | RHEL 9 must not allow interfaces to perform Internet Control Message Protocol (ICMP) redirects by default. |
| ☐ | SV-257970r1155751_rule | RHEL 9 must not enable IPv4 packet forwarding unless the system is a router. |
| ☐ | SV-257971r1155754_rule | RHEL 9 must not accept router advertisements on all IPv6 interfaces. |
| ☐ | SV-257972r1155757_rule | RHEL 9 must ignore IPv6 Internet Control Message Protocol (ICMP) redirect messages. |
| ☐ | SV-257973r1155760_rule | RHEL 9 must not forward IPv6 source-routed packets. |
| ☐ | SV-257974r1155763_rule | RHEL 9 must not enable IPv6 packet forwarding unless the system is a router. |
| ☐ | SV-257975r1155766_rule | RHEL 9 must not accept router advertisements on all IPv6 interfaces by default. |
| ☐ | SV-257976r1155769_rule | RHEL 9 must prevent IPv6 Internet Control Message Protocol (ICMP) redirect messages from being accepted. |
| ☐ | SV-257977r1155772_rule | RHEL 9 must not forward IPv6 source-routed packets by default. |
| ☐ | SV-257978r1045013_rule | All RHEL 9 networked systems must have SSH installed. |
| ☐ | SV-257979r958908_rule | All RHEL 9 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission. |
| ☐ | SV-257980r1045016_rule | RHEL 9 must have the openssh-clients package installed. |
| ☐ | SV-257981r1101970_rule | RHEL 9 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a SSH logon. |
| ☐ | SV-257982r1045021_rule | RHEL 9 must log SSH connection attempts and failures to the server. |
| ☐ | SV-257983r1045024_rule | RHEL 9 SSHD must accept public key authentication. |
| ☐ | SV-257984r1045026_rule | RHEL 9 SSHD must not allow blank passwords. |
| ☐ | SV-257985r1069364_rule | RHEL 9 must not permit direct logons to the root account using remote access via SSH. |
| ☐ | SV-257986r1045030_rule | RHEL 9 must enable the Pluggable Authentication Module (PAM) interface for SSHD. |
| ☐ | SV-257989r1184309_rule | The RHEL 9 SSH server must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections. |
| ☐ | SV-257991r1184311_rule | The RHEL 9 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections. |
| ☐ | SV-257992r1045047_rule | RHEL 9 must not allow a noncertificate trusted host SSH logon to the system. |
| ☐ | SV-257993r1045049_rule | RHEL 9 must not allow users to override SSH environment variables. |
| ☐ | SV-257994r1045051_rule | RHEL 9 must force a frequent session key renegotiation for SSH connections to the server. |
| ☐ | SV-257995r1045053_rule | RHEL 9 must be configured so that all network connections associated with SSH traffic terminate after becoming unresponsive. |
| ☐ | SV-257996r1134915_rule | RHEL 9 must be configured so that all network connections associated with SSH traffic are terminated after 10 minutes of becoming unresponsive. |
| ☐ | SV-257997r1069370_rule | RHEL 9 SSH server configuration file must be group-owned by root. |
| ☐ | SV-257998r1082181_rule | The RHEL 9 SSH server configuration file must be owned by root. |
| ☐ | SV-257999r1155686_rule | RHEL 9 SSH server configuration files' permissions must not be modified. |
| ☐ | SV-258000r1208772_rule | RHEL 9 SSH private host key files must have mode 0600 or less permissive. |
| ☐ | SV-258001r991589_rule | RHEL 9 SSH public host key files must have mode 0644 or less permissive. |
| ☐ | SV-258003r1045065_rule | RHEL 9 SSH daemon must not allow GSSAPI authentication. |
| ☐ | SV-258004r1045067_rule | RHEL 9 SSH daemon must not allow Kerberos authentication. |
| ☐ | SV-258005r1045069_rule | RHEL 9 SSH daemon must not allow rhosts authentication. |
| ☐ | SV-258006r1045071_rule | RHEL 9 SSH daemon must not allow known hosts authentication. |
| ☐ | SV-258007r1045073_rule | RHEL 9 SSH daemon must disable remote X connections for interactive users. |
| ☐ | SV-258008r1045075_rule | RHEL 9 SSH daemon must perform strict mode checking of home directory configuration files. |
| ☐ | SV-258009r1045077_rule | RHEL 9 SSH daemon must display the date and time of the last successful account logon upon an SSH logon. |
| ☐ | SV-258011r1045079_rule | RHEL 9 SSH daemon must prevent remote hosts from connecting to the proxy display. |
| ☐ | SV-258012r1014855_rule | RHEL 9 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a graphical user logon. |
| ☐ | SV-258013r1045082_rule | RHEL 9 must prevent a user from overriding the banner-message-enable setting for the graphical user interface. |
| ☐ | SV-258014r1045084_rule | RHEL 9 must disable the graphical user interface automount function unless required. |
| ☐ | SV-258015r1045086_rule | RHEL 9 must prevent a user from overriding the disabling of the graphical user interface automount function. |
| ☐ | SV-258016r958804_rule | RHEL 9 must disable the graphical user interface autorun function unless required. |
| ☐ | SV-258017r1155688_rule | RHEL 9 must prevent a user from overriding the disabling of the graphical user interface autorun function. |
| ☐ | SV-258018r1045090_rule | RHEL 9 must not allow unattended or automatic logon via the graphical user interface. |
| ☐ | SV-258019r1045092_rule | RHEL 9 must be able to initiate directly a session lock for all connection types using smart card when the smart card is removed. |
| ☐ | SV-258020r1045094_rule | RHEL 9 must prevent a user from overriding the disabling of the graphical user smart card removal action. |
| ☐ | SV-258021r1015088_rule | RHEL 9 must enable a user session lock until that user re-establishes access using established identification and authentication procedures for graphical user sessions. |
| ☐ | SV-258022r1045097_rule | RHEL 9 must prevent a user from overriding the screensaver lock-enabled setting for the graphical user interface. |
| ☐ | SV-258023r1155656_rule | RHEL 9 must automatically lock graphical user sessions after 10 minutes of inactivity. |
| ☐ | SV-258024r1045100_rule | RHEL 9 must prevent a user from overriding the session idle-delay setting for the graphical user interface. |
| ☐ | SV-258025r958402_rule | RHEL 9 must initiate a session lock for graphical user interfaces when the screensaver is activated. |
| ☐ | SV-258026r1045103_rule | RHEL 9 must prevent a user from overriding the session lock-delay setting for the graphical user interface. |
| ☐ | SV-258027r1045106_rule | RHEL 9 must conceal, via the session lock, information previously visible on the display with a publicly viewable image. |
| ☐ | SV-258028r991589_rule | RHEL 9 effective dconf policy must match the policy keyfiles. |
| ☐ | SV-258029r1045109_rule | RHEL 9 must disable the ability of a user to restart the system from the login screen. |
| ☐ | SV-258030r1045112_rule | RHEL 9 must prevent a user from overriding the disable-restart-buttons setting for the graphical user interface. |
| ☐ | SV-258031r1134920_rule | RHEL 9 must disable the ability of a user to accidentally press Ctrl-Alt-Del and cause a system to shut down or reboot. |
| ☐ | SV-258032r1045117_rule | RHEL 9 must prevent a user from overriding the Ctrl-Alt-Del sequence settings for the graphical user interface. |
| ☐ | SV-258033r1045120_rule | RHEL 9 must disable the user list at logon for graphical user interfaces. |
| ☐ | SV-258034r1051267_rule | RHEL 9 must be configured to disable USB mass storage. |
| ☐ | SV-258035r1045125_rule | RHEL 9 must have the USBGuard package installed. |
| ☐ | SV-258036r1014861_rule | RHEL 9 must have the USBGuard package enabled. |
| ☐ | SV-258037r1014863_rule | RHEL 9 must enable Linux audit logging for the USBGuard daemon. |
| ☐ | SV-258038r1045128_rule | RHEL 9 must block unauthorized peripherals before establishing a connection. |
| ☐ | SV-258039r1045131_rule | RHEL 9 Bluetooth must be disabled. |
| ☐ | SV-258040r991568_rule | RHEL 9 wireless network adapters must be disabled. |
| ☐ | SV-258041r1038967_rule | RHEL 9 user account passwords for new users or password changes must have a 60-day maximum password lifetime restriction in /etc/login.defs. |
| ☐ | SV-258042r1045133_rule | RHEL 9 user account passwords must have a 60-day maximum password lifetime restriction. |
| ☐ | SV-258043r991589_rule | All RHEL 9 local interactive user accounts must be assigned a home directory upon creation. |
| ☐ | SV-258044r1184313_rule | RHEL 9 must set the umask value to 077 for all local interactive user accounts. |
| ☐ | SV-258045r958482_rule | RHEL 9 duplicate User IDs (UIDs) must not exist for interactive users. |
| ☐ | SV-258046r991589_rule | RHEL 9 system accounts must not have an interactive login shell. |
| ☐ | SV-258047r1101951_rule | RHEL 9 must automatically expire temporary accounts within 72 hours. |
| ☐ | SV-258048r1069380_rule | All RHEL 9 interactive users must have a primary group that exists. |
| ☐ | SV-258049r1015092_rule | RHEL 9 must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity. |
| ☐ | SV-258050r1045137_rule | Executable search paths within the initialization files of all local interactive RHEL 9 users must only contain paths that resolve to the system default or the users home directory. |
| ☐ | SV-258051r991589_rule | All RHEL 9 local interactive users must have a home directory assigned in the /etc/passwd file. |
| ☐ | SV-258052r1184315_rule | All RHEL 9 local interactive user home directories defined in the /etc/passwd file must exist. |
| ☐ | SV-258053r1208773_rule | All RHEL 9 local interactive user home directories must be group-owned by the home directory owner's primary group. |
| ☐ | SV-258054r958736_rule | RHEL 9 must automatically lock an account when three unsuccessful logon attempts occur. |
| ☐ | SV-258055r1045140_rule | RHEL 9 must automatically lock the root account until the root account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period. |
| ☐ | SV-258056r1045143_rule | RHEL 9 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period. |
| ☐ | SV-258057r1045146_rule | RHEL 9 must maintain an account lock until the locked account is released by an administrator. |
| ☐ | SV-258058r1045148_rule | RHEL 9 must not have unauthorized accounts. |
| ☐ | SV-258059r991589_rule | The root account must be the only account having unrestricted access to RHEL 9 system. |
| ☐ | SV-258060r1045150_rule | RHEL 9 must ensure account lockouts persist. |
| ☐ | SV-258061r958482_rule | RHEL 9 groups must have unique Group ID (GID). |
| ☐ | SV-258068r1101950_rule | RHEL 9 must automatically exit interactive command shell user sessions after 10 minutes of inactivity. |
| ☐ | SV-258069r958398_rule | RHEL 9 must limit the number of concurrent sessions to ten for all accounts and/or account types. |
| ☐ | SV-258070r1045153_rule | RHEL 9 must log username information when unsuccessful logon attempts occur. |
| ☐ | SV-258071r991588_rule | RHEL 9 must enforce a delay of at least four seconds between logon prompts following a failed logon attempt. |
| ☐ | SV-258072r1184320_rule | RHEL 9 must define default permissions for the bash shell. |
| ☐ | SV-258073r1184322_rule | RHEL 9 must define default permissions for the c shell. |
| ☐ | SV-258074r991590_rule | RHEL 9 must define default permissions for all authenticated users in such a way that the user can only read and modify their own files. |
| ☐ | SV-258075r1184324_rule | RHEL 9 must define default permissions for the system default profile. |
| ☐ | SV-258077r1155659_rule | RHEL 9 must terminate idle user sessions. |
| ☐ | SV-258078r958944_rule | RHEL 9 must use a Linux Security Module configured to enforce limits on system services. |
| ☐ | SV-258079r1045159_rule | RHEL 9 must enable the SELinux targeted policy. |
| ☐ | SV-258080r1045162_rule | RHEL 9 must configure SELinux context type to allow the use of a nondefault faillock tally directory. |
| ☐ | SV-258081r1045164_rule | RHEL 9 must have policycoreutils package installed. |
| ☐ | SV-258082r1045166_rule | RHEL 9 policycoreutils-python-utils package must be installed. |
| ☐ | SV-258083r1045168_rule | RHEL 9 must have the sudo package installed. |
| ☐ | SV-258084r1050789_rule | RHEL 9 must require reauthentication when using the "sudo" command. |
| ☐ | SV-258085r1045173_rule | RHEL 9 must use the invoking user's password for privilege escalation when using "sudo". |
| ☐ | SV-258086r1102063_rule | RHEL 9 must require users to reauthenticate for privilege escalation. |
| ☐ | SV-258087r1102071_rule | RHEL 9 must restrict privilege elevation to authorized personnel. |
| ☐ | SV-258088r1155643_rule | RHEL 9 must restrict the use of the "su" command. |
| ☐ | SV-258089r1045179_rule | RHEL 9 fapolicy module must be installed. |
| ☐ | SV-258090r958808_rule | RHEL 9 fapolicy module must be enabled. |
| ☐ | SV-258091r1208774_rule | RHEL 9 must ensure the password complexity module in the system-auth file is configured for three retries or less. |
| ☐ | SV-258094r1045187_rule | RHEL 9 must not allow blank or null passwords. |
| ☐ | SV-258095r1045189_rule | RHEL 9 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file. |
| ☐ | SV-258096r1045191_rule | RHEL 9 must configure the use of the pam_faillock.so module in the /etc/pam.d/password-auth file. |
| ☐ | SV-258097r1045193_rule | RHEL 9 must ensure the password complexity module is enabled in the password-auth file. |
| ☐ | SV-258098r1045195_rule | RHEL 9 must ensure the password complexity module is enabled in the system-auth file. |
| ☐ | SV-258099r1045198_rule | RHEL 9 password-auth must be configured to use a sufficient number of hashing rounds. |
| ☐ | SV-258100r1045201_rule | RHEL 9 system-auth must be configured to use a sufficient number of hashing rounds. |
| ☐ | SV-258101r1045204_rule | RHEL 9 must enforce password complexity rules for the root account. |
| ☐ | SV-258102r1045207_rule | RHEL 9 must enforce password complexity by requiring that at least one lowercase character be used. |
| ☐ | SV-258103r1045210_rule | RHEL 9 must enforce password complexity by requiring that at least one numeric character be used. |
| ☐ | SV-258104r1015104_rule | RHEL 9 passwords for new users or password changes must have a 24 hours minimum password lifetime restriction in /etc/login.defs. |
| ☐ | SV-258105r1045212_rule | RHEL 9 passwords must have a 24 hours minimum password lifetime restriction in /etc/shadow. |
| ☐ | SV-258106r1102061_rule | RHEL 9 must require users to provide a password for privilege escalation. |
| ☐ | SV-258107r1045218_rule | RHEL 9 passwords must be created with a minimum of 15 characters. |
| ☐ | SV-258109r1045220_rule | RHEL 9 must enforce password complexity by requiring that at least one special character be used. |
| ☐ | SV-258110r1045223_rule | RHEL 9 must prevent the use of dictionary words for passwords. |
| ☐ | SV-258111r1045226_rule | RHEL 9 must enforce password complexity by requiring that at least one uppercase character be used. |
| ☐ | SV-258112r1045229_rule | RHEL 9 must require the change of at least eight characters when passwords are changed. |
| ☐ | SV-258113r1045232_rule | RHEL 9 must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed. |
| ☐ | SV-258114r1045235_rule | RHEL 9 must require the maximum number of repeating characters be limited to three when passwords are changed. |
| ☐ | SV-258115r1045238_rule | RHEL 9 must require the change of at least four character classes when passwords are changed. |
| ☐ | SV-258116r1045240_rule | RHEL 9 must be configured so that user and group account administration utilities are configured to store only encrypted representations of passwords. |
| ☐ | SV-258117r1015116_rule | RHEL 9 must be configured to use the shadow file to store only encrypted representations of passwords. |
| ☐ | SV-258118r1050789_rule | RHEL 9 must not be configured to bypass password requirements for privilege escalation. |
| ☐ | SV-258120r991589_rule | RHEL 9 must not have accounts configured with blank or null passwords. |
| ☐ | SV-258121r1155682_rule | RHEL 9 must use the common access card (CAC) smart card driver. |
| ☐ | SV-258122r1045246_rule | RHEL 9 must enable certificate based smart card authentication. |
| ☐ | SV-258123r1134923_rule | RHEL 9 must implement certificate status checking for multifactor authentication. |
| ☐ | SV-258124r1045250_rule | RHEL 9 must have the pcsc-lite package installed. |
| ☐ | SV-258125r1208775_rule | The pcscd socket on RHEL 9 must be active. |
| ☐ | SV-258126r1045255_rule | RHEL 9 must have the opensc package installed. |
| ☐ | SV-258127r1155648_rule | RHEL 9, for PKI-based authentication, must enforce authorized access to the corresponding private key. |
| ☐ | SV-258128r1155626_rule | RHEL 9 must require authentication to access emergency mode. |
| ☐ | SV-258129r1155628_rule | RHEL 9 must require authentication to access single-user mode. |
| ☐ | SV-258131r1134927_rule | RHEL 9, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor. |
| ☐ | SV-258132r1134929_rule | RHEL 9 must map the authenticated identity to the user or group account for PKI-based authentication. |
| ☐ | SV-258133r1045263_rule | RHEL 9 must prohibit the use of cached authenticators after one day. |
| ☐ | SV-258134r1155620_rule | RHEL 9 must have the AIDE package installed. |
| ☐ | SV-258135r1045267_rule | RHEL 9 must routinely check the baseline configuration for unauthorized changes and notify the system administrator when anomalies in the operation of any security functions are discovered. |
| ☐ | SV-258136r1045270_rule | RHEL 9 must use a file integrity tool that is configured to use FIPS 140-3-approved cryptographic hashes for validating file contents and directories. |
| ☐ | SV-258137r1102081_rule | RHEL 9 must use cryptographic mechanisms to protect the integrity of audit tools. |
| ☐ | SV-258138r1045274_rule | RHEL 9 must be configured so that the file integrity tool verifies Access Control Lists (ACLs). |
| ☐ | SV-258139r1045276_rule | RHEL 9 must be configured so that the file integrity tool verifies extended attributes. |
| ☐ | SV-258140r1106460_rule | RHEL 9 must have the rsyslog package installed. |
| ☐ | SV-258141r1045280_rule | RHEL 9 must have the packages required for encrypting offloaded audit logs installed. |
| ☐ | SV-258142r991589_rule | The rsyslog service on RHEL 9 must be active. |
| ☐ | SV-258143r1184329_rule | RHEL 9 must be configured so that the rsyslog daemon does not accept log messages from other servers unless the server is being used for log aggregation. |
| ☐ | SV-258144r1045286_rule | All RHEL 9 remote access methods must be monitored. |
| ☐ | SV-258146r1045288_rule | RHEL 9 must authenticate the remote logging server for offloading audit logs via rsyslog. |
| ☐ | SV-258147r1045290_rule | RHEL 9 must encrypt the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog. |
| ☐ | SV-258148r1045292_rule | RHEL 9 must encrypt via the gtls driver the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog. |
| ☐ | SV-258149r1155580_rule | RHEL 9 must be configured to forward audit records via TCP to a different system or media from the system being audited via rsyslog. |
| ☐ | SV-258150r1045296_rule | RHEL 9 must use cron logging. |
| ☐ | SV-258151r1045298_rule | RHEL 9 audit package must be installed. |
| ☐ | SV-258152r1015127_rule | RHEL 9 audit service must be enabled. |
| ☐ | SV-258153r1038966_rule | RHEL 9 audit system must take appropriate action when an error writing to the audit storage volume occurs. |
| ☐ | SV-258154r1038966_rule | RHEL 9 audit system must take appropriate action when the audit storage volume is full. |
| ☐ | SV-258155r1045300_rule | RHEL 9 must allocate audit record storage capacity to store at least one week's worth of audit records. |
| ☐ | SV-258156r1106364_rule | RHEL 9 must take action when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity. |
| ☐ | SV-258157r1134932_rule | RHEL 9 must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume reaches 75 percent utilization. |
| ☐ | SV-258158r971542_rule | RHEL 9 must take action when allocated audit record storage volume reaches 95 percent of the audit record storage capacity. |
| ☐ | SV-258159r971542_rule | RHEL 9 must take action when allocated audit record storage volume reaches 95 percent of the repository maximum audit record storage capacity. |
| ☐ | SV-258160r1038966_rule | RHEL 9 audit system must take appropriate action when the audit files have reached maximum size. |
| ☐ | SV-258161r958416_rule | RHEL 9 must label all offloaded audit logs before sending them to the central log server. |
| ☐ | SV-258162r1184331_rule | RHEL 9 must take appropriate action when the internal event queue is full. |
| ☐ | SV-258163r958424_rule | RHEL 9 System Administrator (SA) and/or information system security officer (ISSO) (at a minimum) must be alerted of an audit processing failure event. |
| ☐ | SV-258164r1045301_rule | RHEL 9 audit system must audit local events. |
| ☐ | SV-258165r958434_rule | RHEL 9 audit logs must be group-owned by root or by a restricted logging group to prevent unauthorized read access. |
| ☐ | SV-258166r1045303_rule | RHEL 9 audit log directory must be owned by root to prevent unauthorized read access. |
| ☐ | SV-258167r1155630_rule | RHEL 9 audit logs file must have mode 0600 or less permissive to prevent unauthorized access to the audit log. |
| ☐ | SV-258168r958428_rule | RHEL 9 must periodically flush audit records to disk to prevent the loss of audit records. |
| ☐ | SV-258169r991556_rule | RHEL 9 must produce audit records containing information to establish the identity of any individual or process associated with the event. |
| ☐ | SV-258170r991589_rule | RHEL 9 must write audit records to disk. |
| ☐ | SV-258171r1208777_rule | RHEL 9 must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited. |
| ☐ | SV-258173r1101933_rule | RHEL 9 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon. |
| ☐ | SV-258174r958424_rule | RHEL 9 must have mail aliases to notify the information system security officer (ISSO) and system administrator (SA) (at a minimum) in the event of an audit processing failure. |
| ☐ | SV-258175r1045310_rule | RHEL 9 audispd-plugins package must be installed. |
| ☐ | SV-258176r1155595_rule | RHEL 9 must audit uses of the "execve" system call. |
| ☐ | SV-258177r1155597_rule | RHEL 9 must audit all uses of the chmod, fchmod, and fchmodat system calls. |
| ☐ | SV-258178r1155599_rule | RHEL 9 must audit all uses of the chown, fchown, fchownat, and lchown system calls. |
| ☐ | SV-258179r1155601_rule | RHEL 9 must audit all uses of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls. |
| ☐ | SV-258180r1045325_rule | RHEL 9 must audit all uses of umount system calls. |
| ☐ | SV-258181r1045328_rule | RHEL 9 must audit all uses of the chacl command. |
| ☐ | SV-258182r1045331_rule | RHEL 9 must audit all uses of the setfacl command. |
| ☐ | SV-258183r1045334_rule | RHEL 9 must audit all uses of the chcon command. |
| ☐ | SV-258184r1045337_rule | RHEL 9 must audit all uses of the semanage command. |
| ☐ | SV-258185r1045340_rule | RHEL 9 must audit all uses of the setfiles command. |
| ☐ | SV-258186r1045343_rule | RHEL 9 must audit all uses of the setsebool command. |
| ☐ | SV-258187r1155603_rule | RHEL 9 must audit all uses of the rename, unlink, rmdir, renameat, and unlinkat system calls. |
| ☐ | SV-258188r1155605_rule | RHEL 9 must audit all uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls. |
| ☐ | SV-258189r1155607_rule | RHEL 9 must audit all uses of the delete_module system call. |
| ☐ | SV-258190r1155609_rule | RHEL 9 must audit all uses of the init_module and finit_module system calls. |
| ☐ | SV-258191r1045358_rule | RHEL 9 must audit all uses of the chage command. |
| ☐ | SV-258192r1045361_rule | RHEL 9 must audit all uses of the chsh command. |
| ☐ | SV-258193r1045364_rule | RHEL 9 must audit all uses of the crontab command. |
| ☐ | SV-258194r1045367_rule | RHEL 9 must audit all uses of the gpasswd command. |
| ☐ | SV-258195r1045370_rule | RHEL 9 must audit all uses of the kmod command. |
| ☐ | SV-258196r1045373_rule | RHEL 9 must audit all uses of the newgrp command. |
| ☐ | SV-258197r1045376_rule | RHEL 9 must audit all uses of the pam_timestamp_check command. |
| ☐ | SV-258198r1045379_rule | RHEL 9 must audit all uses of the passwd command. |
| ☐ | SV-258199r1045382_rule | RHEL 9 must audit all uses of the postdrop command. |
| ☐ | SV-258200r1045385_rule | RHEL 9 must audit all uses of the postqueue command. |
| ☐ | SV-258201r1045388_rule | RHEL 9 must audit all uses of the ssh-agent command. |
| ☐ | SV-258202r1045391_rule | RHEL 9 must audit all uses of the ssh-keysign command. |
| ☐ | SV-258203r1045394_rule | RHEL 9 must audit all uses of the su command. |
| ☐ | SV-258204r1045397_rule | RHEL 9 must audit all uses of the sudo command. |
| ☐ | SV-258205r1045400_rule | RHEL 9 must audit all uses of the sudoedit command. |
| ☐ | SV-258206r1045403_rule | RHEL 9 must audit all uses of the unix_chkpwd command. |
| ☐ | SV-258207r1045406_rule | RHEL 9 must audit all uses of the unix_update command. |
| ☐ | SV-258208r1045409_rule | RHEL 9 must audit all uses of the userhelper command. |
| ☐ | SV-258209r1045412_rule | RHEL 9 must audit all uses of the usermod command. |
| ☐ | SV-258210r1045415_rule | RHEL 9 must audit all uses of the mount command. |
| ☐ | SV-258211r1045418_rule | Successful/unsuccessful uses of the init command in RHEL 9 must generate an audit record. |
| ☐ | SV-258212r1045421_rule | Successful/unsuccessful uses of the poweroff command in RHEL 9 must generate an audit record. |
| ☐ | SV-258213r1045424_rule | Successful/unsuccessful uses of the reboot command in RHEL 9 must generate an audit record. |
| ☐ | SV-258214r1045427_rule | Successful/unsuccessful uses of the shutdown command in RHEL 9 must generate an audit record. |
| ☐ | SV-258215r1155611_rule | Successful/unsuccessful uses of the umount system call in RHEL 9 must generate an audit record. |
| ☐ | SV-258216r1155613_rule | Successful/unsuccessful uses of the umount2 system call in RHEL 9 must generate an audit record. |
| ☐ | SV-258217r1210919_rule | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers. |
| ☐ | SV-258218r1210920_rule | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/directory. |
| ☐ | SV-258219r1210921_rule | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group. |
| ☐ | SV-258220r1210922_rule | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow. |
| ☐ | SV-258221r1210923_rule | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd. |
| ☐ | SV-258222r1210924_rule | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd. |
| ☐ | SV-258223r1210925_rule | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow. |
| ☐ | SV-258224r1210926_rule | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/faillock. |
| ☐ | SV-258225r1210927_rule | RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/lastlog. |
| ☐ | SV-258227r1014992_rule | RHEL 9 must take appropriate action when a critical audit processing failure occurs. |
| ☐ | SV-258228r991572_rule | RHEL 9 audit system must protect logon UIDs from unauthorized change. |
| ☐ | SV-258229r958434_rule | RHEL 9 audit system must protect auditing rules from unauthorized change. |
| ☐ | SV-258230r1184334_rule | RHEL 9 must enable FIPS mode. |
| ☐ | SV-258231r1208790_rule | RHEL 9 must employ FIPS 140-3-approved cryptographic hashing algorithms for all stored passwords. |
| ☐ | SV-258232r1184335_rule | RHEL 9 IP tunnels must use FIPS 140-3 approved cryptographic algorithms. |
| ☐ | SV-258233r1015136_rule | RHEL 9 pam_unix.so module must be configured in the password-auth file to use a FIPS 140-3 approved cryptographic hashing algorithm for system authentication. |
| ☐ | SV-258234r1184292_rule | RHEL 9 must have the crypto-policies package installed. |
| ☐ | SV-258236r1101920_rule | RHEL 9 cryptographic policy must not be overridden. |
| ☐ | SV-258241r1184293_rule | RHEL 9 must implement a FIPS 140-3-compliant systemwide cryptographic policy. |
| ☐ | SV-258242r1184336_rule | RHEL 9 must implement DOD-approved encryption in the bind package. |
| ☐ | SV-270174r1044831_rule | RHEL 9 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via a graphical user logon. |
| ☐ | SV-270175r1137691_rule | RHEL 9 "/etc/audit/" must be owned by root. |
| ☐ | SV-270176r1137691_rule | RHEL 9 "/etc/audit/" must be group-owned by root. |
| ☐ | SV-270177r1184308_rule | The RHEL 9 SSH client must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. |
| ☐ | SV-270178r1184310_rule | The RHEL 9 SSH client must be configured to use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. |
| ☐ | SV-270180r1184327_rule | The RHEL 9 fapolicy module must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs. |
| ☐ | SV-272488r1155665_rule | RHEL 9 must have the Postfix package installed. |
| ☐ | SV-272496r1155582_rule | RHEL 9 must elevate the SELinux context when an administrator calls the sudo command. |
| ☐ | SV-279936r1210929_rule | RHEL 9 must audit any script or executable called by cron as root or by any privileged user. |