STIGQter STIGQter: STIG Summary:

SUSE Linux Enterprise Micro (SLEM) 5 Security Technical Implementation Guide

Version: 1

Release: 4 Benchmark Date: 01 Apr 2026

CheckedNameTitle
SV-261263r1155781_ruleSLEM 5 must be a vendor-supported release.
SV-261265r996289_ruleSLEM 5 must display the Standard Mandatory DOD Notice and Consent Banner before granting any local or remote connection to the system.
SV-261266r996292_ruleSLEM 5 must disable the x86 Ctrl-Alt-Delete key sequence.
SV-261267r1137691_ruleSLEM 5 with a basic input/output system (BIOS) must require authentication upon booting into single-user and maintenance modes.
SV-261268r1184366_ruleSLEM 5 with Unified Extensible Firmware Interface (UEFI) implemented must require authentication upon booting into single-user mode and maintenance.
SV-261269r1137695_ruleSLEM 5 must restrict access to the kernel message buffer.
SV-261270r996860_ruleSLEM 5 kernel core dumps must be disabled unless needed.
SV-261271r996306_ruleAddress space layout randomization (ASLR) must be implemented by SLEM 5 to protect memory from unauthorized code execution.
SV-261272r996309_ruleSLEM 5 must implement kptr-restrict to prevent the leaking of internal kernel addresses.
SV-261273r996311_ruleVendor-packaged SLEM 5 security patches and updates must be installed and up to date.
SV-261274r1186206_ruleThe SLEM 5 tool zypper must have gpgcheck enabled.
SV-261275r996314_ruleSLEM 5 must remove all outdated software components after updated versions have been installed.
SV-261276r996316_ruleSLEM 5 must use vlock to allow for session locking.
SV-261277r996318_ruleSLEM 5 must not have the telnet-server package installed.
SV-261278r1184371_ruleA separate file system must be used for SLEM 5 user home directories (such as /home or an equivalent).
SV-261279r996322_ruleSLEM 5 must use a separate file system for /var.
SV-261280r996324_ruleSLEM 5 must use a separate file system for the system audit data path.
SV-261281r996326_ruleSLEM 5 file systems that are being imported via Network File System (NFS) must be mounted to prevent files with the setuid and setgid bit set from being executed.
SV-261282r996328_ruleSLEM 5 file systems that are being imported via Network File System (NFS) must be mounted to prevent binary files from being executed.
SV-261283r996330_ruleSLEM 5 file systems that are used with removable media must be mounted to prevent files with the setuid and setgid bit set from being executed.
SV-261284r1184374_ruleAll SLEM 5 persistent disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at-rest protection.
SV-261285r996838_ruleSLEM 5 file systems that contain user home directories must be mounted to prevent files with the setuid and setgid bit set from being executed.
SV-261286r1155779_ruleSLEM 5 must disable the file system automounter.
SV-261287r1184377_ruleSLEM 5 must have directories that contain system commands set to a mode of 755 or less permissive.
SV-261288r1184380_ruleSLEM 5 must have system commands set to a mode of 755 or less permissive.
SV-261289r1184382_ruleSLEM 5 library directories must have mode 755 or less permissive.
SV-261290r1102096_ruleSLEM 5 library files must have mode 755 or less permissive.
SV-261291r1184385_ruleAll SLEM 5 local interactive user home directories must have mode 750 or less permissive.
SV-261292r1184388_ruleAll SLEM 5 local initialization files must have mode 740 or less permissive.
SV-261293r996357_ruleSLEM 5 SSH daemon public host key files must have mode 644 or less permissive.
SV-261294r996359_ruleSLEM 5 SSH daemon private host key files must have mode 640 or less permissive.
SV-261295r1102099_ruleSLEM 5 library files must be owned by root.
SV-261296r1102102_ruleSLEM 5 library files must be group-owned by root.
SV-261297r996368_ruleSLEM 5 library directories must be owned by root.
SV-261298r996371_ruleSLEM 5 library directories must be group-owned by root.
SV-261299r1184391_ruleSLEM 5 must have system commands owned by root.
SV-261300r1184394_ruleSLEM 5 must have system commands group-owned by root or a system account.
SV-261301r1184397_ruleSLEM 5 must have directories that contain system commands owned by root.
SV-261302r1184400_ruleSLEM 5 must have directories that contain system commands group-owned by root.
SV-261303r996382_ruleAll SLEM 5 files and directories must have a valid owner.
SV-261304r996384_ruleAll SLEM 5 files and directories must have a valid group owner.
SV-261305r1184403_ruleAll SLEM 5 local interactive user home directories must be group-owned by the home directory owner's primary group.
SV-261306r996389_ruleAll SLEM 5 world-writable directories must be group-owned by root, sys, bin, or an application group.
SV-261307r1137695_ruleThe sticky bit must be set on all SLEM 5 world-writable directories.
SV-261308r996395_ruleSLEM 5 must prevent unauthorized users from accessing system error messages.
SV-261309r996398_ruleSLEM 5 must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
SV-261310r996401_ruleSLEM 5 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.
SV-261311r1038944_ruleSLEM 5 clock must, for networked systems, be synchronized to an authoritative DOD time source at least every 24 hours.
SV-261312r996406_ruleSLEM 5 must not have network interfaces in promiscuous mode unless approved and documented.
SV-261313r996409_ruleSLEM 5 must not forward Internet Protocol version 4 (IPv4) source-routed packets.
SV-261314r996412_ruleSLEM 5 must not forward Internet Protocol version 4 (IPv4) source-routed packets by default.
SV-261315r996415_ruleSLEM 5 must prevent Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages from being accepted.
SV-261316r996418_ruleSLEM 5 must not allow interfaces to accept Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages by default.
SV-261317r996421_ruleSLEM 5 must not send Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirects.
SV-261318r996424_ruleSLEM 5 must not allow interfaces to send Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages by default.
SV-261319r996427_ruleSLEM 5 must not be performing Internet Protocol version 4 (IPv4) packet forwarding unless the system is a router.
SV-261320r996861_ruleSLEM 5 must be configured to use TCP syncookies.
SV-261321r996433_ruleSLEM 5 must not forward Internet Protocol version 6 (IPv6) source-routed packets.
SV-261322r996436_ruleSLEM 5 must not forward Internet Protocol version 6 (IPv6) source-routed packets by default.
SV-261323r996439_ruleSLEM 5 must prevent Internet Protocol version 6 (IPv6) Internet Control Message Protocol (ICMP) redirect messages from being accepted.
SV-261324r996442_ruleSLEM 5 must not allow interfaces to accept Internet Protocol version 6 (IPv6) Internet Control Message Protocol (ICMP) redirect messages by default.
SV-261325r996445_ruleSLEM 5 must not be performing Internet Protocol version 6 (IPv6) packet forwarding unless the system is a router.
SV-261326r996448_ruleSLEM 5 must not be performing Internet Protocol version 6 (IPv6) packet forwarding by default unless the system is a router.
SV-261327r996450_ruleSLEM 5 must have SSH installed to protect the confidentiality and integrity of transmitted information.
SV-261328r996453_ruleSLEM 5 must use SSH to protect the confidentiality and integrity of transmitted information.
SV-261329r1186207_ruleSLEM 5 must display the Standard Mandatory DOD Notice and Consent Banner before granting access via SSH.
SV-261330r996457_ruleSLEM 5 must not allow unattended or automatic logon via SSH.
SV-261331r996459_ruleSLEM 5 must be configured so that all network connections associated with SSH traffic terminate after becoming unresponsive.
SV-261332r996462_ruleSLEM 5 must be configured so that all network connections associated with SSH traffic are terminated after 10 minutes of becoming unresponsive.
SV-261333r996464_ruleSLEM 5 SSH daemon must disable forwarded remote X connections for interactive users, unless to fulfill documented and validated mission requirements.
SV-261334r996467_ruleSLEM 5 must implement DOD-approved encryption to protect the confidentiality of SSH remote connections.
SV-261335r996469_ruleSLEM 5 SSH daemon must be configured to only use Message Authentication Codes (MACs) employing FIPS 140-2/140-3 approved cryptographic hash algorithms.
SV-261336r996472_ruleSLEM 5 SSH server must be configured to use only FIPS 140-2/140-3 validated key exchange algorithms.
SV-261337r996844_ruleSLEM 5 must deny direct logons to the root account using remote access via SSH.
SV-261338r996845_ruleSLEM 5 must log SSH connection attempts and failures to the server.
SV-261339r996480_ruleSLEM 5 must display the date and time of the last successful account logon upon an SSH logon.
SV-261340r996483_ruleSLEM 5 SSH daemon must be configured to not allow authentication using known hosts authentication.
SV-261341r996486_ruleSLEM 5 SSH daemon must perform strict mode checking of home directory configuration files.
SV-261342r996488_ruleSLEM 5, for PKI-based authentication, must enforce authorized access to the corresponding private key.
SV-261343r996489_ruleThere must be no .shosts files on SLEM 5.
SV-261344r996490_ruleThere must be no shosts.equiv files on SLEM 5.
SV-261345r996493_ruleSLEM 5 must not allow unattended or automatic logon via the graphical user interface (GUI).
SV-261346r1184409_ruleSLEM 5 wireless network adapters must be disabled unless approved and documented.
SV-261347r996498_ruleSLEM 5 must disable the USB mass storage kernel module.
SV-261348r996500_ruleAll SLEM 5 local interactive user accounts, upon creation, must be assigned a home directory.
SV-261349r996502_ruleSLEM 5 default permissions must be defined in such a way that all authenticated users can only read and modify their own files.
SV-261350r996504_ruleSLEM 5 shadow password suite must be configured to enforce a delay of at least five seconds between logon prompts following a failed logon attempt.
SV-261351r1184412_ruleAll SLEM 5 local interactive users must have a home directory assigned in the /etc/passwd file.
SV-261352r1184415_ruleAll SLEM 5 local interactive user home directories defined in the /etc/passwd file must exist.
SV-261353r1184417_ruleAll SLEM 5 local interactive user initialization files executable search paths must contain only paths that resolve to the users' home directory.
SV-261354r996514_ruleAll SLEM 5 local initialization files must not execute world-writable programs.
SV-261355r996516_ruleSLEM 5 must automatically expire temporary accounts within 72 hours.
SV-261356r996518_ruleSLEM 5 must never automatically remove or disable emergency administrator accounts.
SV-261357r996521_ruleSLEM 5 must not have unnecessary accounts.
SV-261358r996829_ruleSLEM 5 must not have unnecessary account capabilities.
SV-261359r996526_ruleSLEM 5 root account must be the only account with unrestricted access to the system.
SV-261360r996529_ruleSLEM 5 must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity after password expiration.
SV-261361r996530_ruleSLEM 5 must not have duplicate User IDs (UIDs) for interactive users.
SV-261363r996536_ruleSLEM 5 must initiate a session lock after a 15-minute period of inactivity.
SV-261364r996863_ruleSLEM 5 must lock an account after three consecutive invalid access attempts.
SV-261365r996541_ruleSLEM 5 must enforce a delay of at least five seconds between logon prompts following a failed logon attempt via pluggable authentication modules (PAM).
SV-261367r996839_ruleSLEM 5 must limit the number of concurrent sessions to 10 for all accounts and/or account types.
SV-261368r996548_ruleSLEM 5 must have policycoreutils package installed.
SV-261369r996549_ruleSLEM 5 must use a Linux Security Module configured to enforce limits on system services.
SV-261370r996551_ruleSLEM 5 must enable the SELinux targeted policy.
SV-261371r996554_ruleSLEM 5 must prevent nonprivileged users from executing privileged functions, including disabling, circumventing, or altering implemented security safeguards/countermeasures.
SV-261372r1184420_ruleSLEM 5 must use the invoking user's password for privilege escalation when using "sudo".
SV-261373r1050789_ruleSLEM 5 must reauthenticate users when changing authenticators, roles, or escalating privileges.
SV-261374r1050789_ruleSLEM 5 must require reauthentication when using the "sudo" command.
SV-261375r996562_ruleSLEM 5 must restrict privilege elevation to authorized personnel.
SV-261376r996564_ruleSLEM 5 must specify the default "include" directory for the /etc/sudoers file.
SV-261377r996566_ruleSLEM 5 must enforce passwords that contain at least one uppercase character.
SV-261378r996568_ruleSLEM 5 must enforce passwords that contain at least one lowercase character.
SV-261379r996570_ruleSLEM 5 must enforce passwords that contain at least one numeric character.
SV-261380r996572_ruleSLEM 5 must enforce passwords that contain at least one special character.
SV-261381r996574_ruleSLEM 5 must prevent the use of dictionary words for passwords.
SV-261382r996577_ruleSLEM 5 must employ passwords with a minimum of 15 characters.
SV-261383r996580_ruleSLEM 5 must require the change of at least eight of the total number of characters when passwords are changed.
SV-261384r996583_ruleSLEM 5 must not allow passwords to be reused for a minimum of five generations.
SV-261385r996586_ruleSLEM 5 must configure the Linux Pluggable Authentication Modules (PAM) to only store encrypted representations of passwords.
SV-261386r996587_ruleSLEM 5 must not be configured to allow blank or null passwords.
SV-261387r996588_ruleSLEM 5 must not have accounts configured with blank or null passwords.
SV-261388r1184422_ruleSLEM 5 must employ user passwords with a minimum lifetime of 24 hours (one day).
SV-261389r1038967_ruleSLEM 5 must employ user passwords with a maximum lifetime of 60 days.
SV-261390r996595_ruleSLEM 5 must employ a password history file.
SV-261391r996598_ruleSLEM 5 must employ FIPS 140-2/140-3-approved cryptographic hashing algorithms for system authentication.
SV-261392r1184425_ruleSLEM 5 shadow password suite must be configured to use a sufficient number of hashing rounds.
SV-261393r996602_ruleSLEM 5 must employ FIPS 140-2/140-3 approved cryptographic hashing algorithm for system authentication (login.defs).
SV-261394r996604_ruleSLEM 5 must be configured to create or update passwords with a minimum lifetime of 24 hours (one day).
SV-261395r1038967_ruleSLEM 5 must be configured to create or update passwords with a maximum lifetime of 60 days.
SV-261396r996610_ruleSLEM 5 must have the packages required for multifactor authentication to be installed.
SV-261397r996612_ruleSLEM 5 must implement multifactor authentication for access to privileged accounts via pluggable authentication modules (PAM).
SV-261398r996615_ruleSLEM 5 must implement certificate status checking for multifactor authentication.
SV-261399r996617_ruleIf Network Security Services (NSS) is being used by SLEM 5 it must prohibit the use of cached authentications after one day.
SV-261400r996619_ruleSLEM 5 must configure the Linux Pluggable Authentication Modules (PAM) to prohibit the use of cached offline authentications after one day.
SV-261401r996622_ruleSLEM 5, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
SV-261402r996624_ruleSLEM 5 must be configured to not overwrite Pluggable Authentication Modules (PAM) configuration on package changes.
SV-261403r996627_ruleSLEM 5 must use a file integrity tool to verify correct operation of all security functions.
SV-261404r996629_ruleSLEM 5 file integrity tool must be configured to verify Access Control Lists (ACLs).
SV-261405r996631_ruleSLEM 5 file integrity tool must be configured to verify extended attributes.
SV-261406r996634_ruleSLEM 5 file integrity tool must be configured to protect the integrity of the audit tools.
SV-261407r996637_ruleAdvanced Intrusion Detection Environment (AIDE) must verify the baseline SLEM 5 configuration at least weekly.
SV-261408r996640_ruleSLEM 5 must notify the system administrator (SA) when Advanced Intrusion Detection Environment (AIDE) discovers anomalies in the operation of any security functions.
SV-261409r996643_ruleSLEM 5 must offload rsyslog messages for networked systems in real time and offload standalone systems at least weekly.
SV-261410r996645_ruleSLEM 5 must have the auditing package installed.
SV-261411r996646_ruleSLEM 5 audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.
SV-261412r996649_ruleThe audit-audispd-plugins package must be installed on SLEM 5.
SV-261413r996652_ruleSLEM 5 must allocate audit record storage capacity to store at least one week of audit records when audit records are not immediately sent to a central audit record storage facility.
SV-261414r996654_ruleSLEM 5 auditd service must notify the system administrator (SA) and information system security officer (ISSO) immediately when audit storage capacity is 75 percent full.
SV-261415r1038966_ruleSLEM 5 audit system must take appropriate action when the audit storage volume is full.
SV-261416r996660_ruleSLEM 5 must offload audit records onto a different system or media from the system being audited.
SV-261417r996662_ruleAudispd must take appropriate action when SLEM 5 audit storage is full.
SV-261418r996665_ruleSLEM 5 must protect audit rules from unauthorized modification.
SV-261419r996668_ruleSLEM 5 audit tools must have the proper permissions configured to protect against unauthorized access.
SV-261420r996670_ruleSLEM 5 audit tools must have the proper permissions applied to protect against unauthorized access.
SV-261421r996672_ruleSLEM 5 audit event multiplexor must be configured to use Kerberos.
SV-261422r996674_ruleAudispd must offload audit records onto a different system or media from SLEM 5 being audited.
SV-261423r996677_ruleThe information system security officer (ISSO) and system administrator (SA), at a minimum, must have mail aliases to be notified of a SLEM 5 audit processing failure.
SV-261424r996679_ruleThe information system security officer (ISSO) and system administrator (SA), at a minimum, must be alerted of a SLEM 5 audit processing failure event.
SV-261425r996682_ruleSLEM 5 must generate audit records for all uses of the "chacl" command.
SV-261426r996685_ruleSLEM 5 must generate audit records for all uses of the "chage" command.
SV-261427r996688_ruleSLEM 5 must generate audit records for all uses of the "chcon" command.
SV-261428r996691_ruleSLEM 5 must generate audit records for all uses of the "chfn" command.
SV-261429r996694_ruleSLEM 5 must generate audit records for all uses of the "chmod" command.
SV-261430r996697_ruleSLEM 5 must generate audit records for a uses of the "chsh" command.
SV-261431r996700_ruleSLEM 5 must generate audit records for all uses of the "crontab" command.
SV-261432r996703_ruleSLEM 5 must generate audit records for all uses of the "gpasswd" command.
SV-261433r996706_ruleSLEM 5 must generate audit records for all uses of the "insmod" command.
SV-261434r996709_ruleSLEM 5 must generate audit records for all uses of the "kmod" command.
SV-261435r996712_ruleSLEM 5 must generate audit records for all uses of the "modprobe" command.
SV-261436r996715_ruleSLEM 5 must generate audit records for all uses of the "newgrp" command.
SV-261437r996718_ruleSLEM 5 must generate audit records for all uses of the "pam_timestamp_check" command.
SV-261438r996721_ruleSLEM 5 must generate audit records for all uses of the "passwd" command.
SV-261439r996724_ruleSLEM 5 must generate audit records for all uses of the "rm" command.
SV-261440r996727_ruleSLEM 5 must generate audit records for all uses of the "rmmod" command.
SV-261441r996730_ruleSLEM 5 must generate audit records for all uses of the "setfacl" command.
SV-261442r996733_ruleSLEM 5 must generate audit records for all uses of the "ssh-agent" command.
SV-261443r996736_ruleSLEM 5 must generate audit records for all uses of the "ssh-keysign" command.
SV-261444r996739_ruleSLEM 5 must generate audit records for all uses of the "su" command.
SV-261445r996742_ruleSLEM 5 must generate audit records for all uses of the "sudo" command.
SV-261446r996745_ruleSLEM 5 must generate audit records for all uses of the "sudoedit" command.
SV-261447r996748_ruleSLEM 5 must generate audit records for all uses of the "unix_chkpwd" or "unix2_chkpwd" commands.
SV-261448r996751_ruleSLEM 5 must generate audit records for all uses of the "usermod" command.
SV-261449r996754_ruleSLEM 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
SV-261450r996757_ruleSLEM 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.
SV-261451r996760_ruleSLEM 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
SV-261452r996763_ruleSLEM 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
SV-261453r996848_ruleSLEM 5 must generate audit records for all uses of the "chmod", "fchmod" and "fchmodat" system calls.
SV-261454r996769_ruleSLEM 5 must generate audit records for all uses of the "chown", "fchown", "fchownat", and "lchown" system calls.
SV-261455r996772_ruleSLEM 5 must generate audit records for all uses of the "creat", "open", "openat", "open_by_handle_at", "truncate", and "ftruncate" system calls.
SV-261456r996775_ruleSLEM 5 must generate audit records for all uses of the "delete_module" system call.
SV-261457r996778_ruleSLEM 5 must generate audit records for all uses of the "init_module" and "finit_module" system calls.
SV-261458r996781_ruleSLEM 5 must generate audit records for all uses of the "mount" system call.
SV-261459r996784_ruleSLEM 5 must generate audit records for all uses of the "setxattr", "fsetxattr", "lsetxattr", "removexattr", "fremovexattr", and "lremovexattr" system calls.
SV-261460r996787_ruleSLEM 5 must generate audit records for all uses of the "umount" system call.
SV-261461r996790_ruleSLEM 5 must generate audit records for all uses of the "unlink", "unlinkat", "rename", "renameat", and "rmdir" system calls.
SV-261462r996793_ruleSLEM 5 must generate audit records for all uses of privileged functions.
SV-261463r996796_ruleSLEM 5 must generate audit records for all modifications to the "lastlog" file.
SV-261464r996799_ruleSLEM 5 must generate audit records for all modifications to the "tallylog" file must generate an audit record.
SV-261465r996802_ruleSLEM 5 must audit all uses of the sudoers file and all files in the "/etc/sudoers.d/" directory.
SV-261466r996805_ruleSuccessful/unsuccessful uses of "setfiles" in SLEM 5 must generate an audit record.
SV-261467r996808_ruleSuccessful/unsuccessful uses of "semanage" in SLEM 5 must generate an audit record.
SV-261468r997405_ruleSuccessful/unsuccessful uses of "setsebool" in SLEM 5 must generate an audit record.
SV-261469r996814_ruleSLEM 5 must generate audit records for the "/run/utmp file".
SV-261470r996817_ruleSLEM 5 must generate audit records for the "/var/log/btmp" file.
SV-261471r996820_ruleSLEM 5 must generate audit records for the "/var/log/wtmp" file.
SV-261472r996865_ruleSLEM 5 must not disable syscall auditing.
SV-261473r996824_ruleFIPS 140-2/140-3 mode must be enabled on SLEM 5.