Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add RHCOS STIG content and enable for NIST #6046

Merged
merged 4 commits into from
Dec 2, 2020
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,ol7,ol8,rhel7,rhel8
prodtype: fedora,ol7,ol8,rhel7,rhel8,rhcos4

title: 'Uninstall Sendmail Package'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,ol7,ol8,rhel7,rhel8,rhv4
prodtype: fedora,ol7,ol8,rhel7,rhel8,rhv4,rhcos4

title: 'Enable Smartcards in SSSD'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,ol7,ol8,rhel7,rhel8,rhv4
prodtype: fedora,ol7,ol8,rhel7,rhel8,rhv4,rhcos4

title: 'Configure SSSD to Expire Offline Credentials'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,ol8,rhel8
prodtype: fedora,ol8,rhel8,rhcos4

title: 'Support session locking with tmux'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,ol8,rhel8
prodtype: fedora,ol8,rhel8,rhcos4

title: 'Configure tmux to lock session after inactivity'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,ol8,rhel8
prodtype: fedora,ol8,rhel8,rhcos4

title: 'Configure the tmux Lock Command'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,ol8,rhel8,rhv4
prodtype: fedora,ol8,rhel8,rhv4,rhcos4

title: 'Install the tmux Package'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,ol7,ol8,rhel7,rhel8,rhv4,sle15,wrlinux1019
prodtype: fedora,ol7,ol8,rhel7,rhel8,rhv4,sle15,wrlinux1019,rhcos4

title: 'Set Interactive Session Timeout'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: ol8,rhel8
prodtype: ol8,rhel8,rhcos4

title: 'Configure auditing of unsuccessful file accesses'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: ol8,rhel8
prodtype: ol8,rhel8,rhcos4

title: 'Configure auditing of successful file accesses'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: ol8,rhel8,rhcos4
prodtype: ol8,rhel8,rhcos4,rhcos4

title: 'Configure basic parameters of Audit system'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: ol8,rhel8
prodtype: ol8,rhel8,rhcos4

title: 'Configure auditing of unsuccessful file creations'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: ol8,rhel8
prodtype: ol8,rhel8,rhcos4

title: 'Configure auditing of successful file creations'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: ol8,rhel8
prodtype: ol8,rhel8,rhcos4

title: 'Configure auditing of unsuccessful file deletions'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: ol8,rhel8
prodtype: ol8,rhel8,rhcos4

title: 'Configure auditing of successful file deletions'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: ol8,rhel8
prodtype: ol8,rhel8,rhcos4

title: 'Configure immutable Audit login UIDs'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: ol8,rhel8,rhcos4
prodtype: ol8,rhel8,rhcos4,rhcos4

title: 'Configure auditing of unsuccessful file modifications'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: ol8,rhel8
prodtype: ol8,rhel8,rhcos4

title: 'Configure auditing of successful file modifications'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: ol8,rhel8,rhcos4
prodtype: ol8,rhel8,rhcos4,rhcos4

title: 'Configure auditing of loading and unloading of kernel modules'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: ol8,rhel8,rhcos4
prodtype: ol8,rhel8,rhcos4,rhcos4

title: 'Perform general configuration of Audit for OSPP'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: ol8,rhel8
prodtype: ol8,rhel8,rhcos4

title: 'Configure auditing of unsuccessful ownership changes'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: ol8,rhel8
prodtype: ol8,rhel8,rhcos4

title: 'Configure auditing of successful ownership changes'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: ol8,rhel8
prodtype: ol8,rhel8,rhcos4

title: 'Configure auditing of unsuccessful permission changes'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: ol8,rhel8
prodtype: ol8,rhel8,rhcos4

title: 'Configure auditing of successful permission changes'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: ol7,ol8,rhel7,rhel8
prodtype: ol7,ol8,rhel7,rhel8,rhcos4

title: 'Configure audit according to OSPP requirements'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel8
prodtype: rhel8,rhcos4

title: 'Enable Auditing to Start Prior to the Audit Daemon in zIPL'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel8
prodtype: rhel8,rhcos4

title: 'Extend Audit Backlog Limit for the Audit Daemon in zIPL'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel8
prodtype: rhel8,rhcos4

title: 'Ensure all zIPL boot entries are BLS compliant'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel8
prodtype: rhel8,rhcos4

title: 'Ensure zIPL bootmap is up to date'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel8
prodtype: rhel8,rhcos4

title: 'Ensure SELinux Not Disabled in zIPL'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel8
prodtype: rhel8,rhcos4

title: 'Enable page allocator poisoning in zIPL'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel8
prodtype: rhel8,rhcos4

title: 'Enable SLUB/SLAB allocator poisoning in zIPL'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel8
prodtype: rhel8,rhcos4

title: 'Disable vsyscalls in zIPL'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,ol7,ol8,rhel7,rhel8
prodtype: fedora,ol7,ol8,rhel7,rhel8,rhcos4

title: 'Add nodev Option to /boot'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,ol7,ol8,rhel7,rhel8
prodtype: fedora,ol7,ol8,rhel7,rhel8,rhcos4

title: 'Add nosuid Option to /boot'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: ol7,ol8,rhel7,rhel8,rhv4,wrlinux1019
prodtype: ol7,ol8,rhel7,rhel8,rhv4,wrlinux1019,rhcos4

title: 'Add nosuid Option to /home'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,ol7,ol8,rhel7,rhel8
prodtype: fedora,ol7,ol8,rhel7,rhel8,rhcos4

title: 'Add nodev Option to Non-Root Local Partitions'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,ol7,ol8,rhel7,rhel8,sle15,ubuntu1804
prodtype: fedora,ol7,ol8,rhel7,rhel8,sle15,ubuntu1804,rhcos4

title: 'Add nodev Option to /tmp'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,ol7,ol8,rhel7,rhel8,sle15
prodtype: fedora,ol7,ol8,rhel7,rhel8,sle15,rhcos4

title: 'Add noexec Option to /tmp'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,ol7,ol8,rhel7,rhel8,sle15,ubuntu1804
prodtype: fedora,ol7,ol8,rhel7,rhel8,sle15,ubuntu1804,rhcos4

title: 'Add nosuid Option to /tmp'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,ol7,ol8,rhel7,rhel8
prodtype: fedora,ol7,ol8,rhel7,rhel8,rhcos4

title: 'Add nodev Option to /var/log/audit'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,ol7,ol8,rhel7,rhel8
prodtype: fedora,ol7,ol8,rhel7,rhel8,rhcos4

title: 'Add noexec Option to /var/log/audit'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,ol7,ol8,rhel7,rhel8
prodtype: fedora,ol7,ol8,rhel7,rhel8,rhcos4

title: 'Add nosuid Option to /var/log/audit'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,ol7,ol8,rhel7,rhel8
prodtype: fedora,ol7,ol8,rhel7,rhel8,rhcos4

title: 'Add nodev Option to /var/log'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,ol7,ol8,rhel7,rhel8
prodtype: fedora,ol7,ol8,rhel7,rhel8,rhcos4

title: 'Add noexec Option to /var/log'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,ol7,ol8,rhel7,rhel8
prodtype: fedora,ol7,ol8,rhel7,rhel8,rhcos4

title: 'Add nosuid Option to /var/log'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,ol7,ol8,rhel7,rhel8
prodtype: fedora,ol7,ol8,rhel7,rhel8,rhcos4

title: 'Add nodev Option to /var'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: fedora,rhel7,rhel8
prodtype: fedora,rhel7,rhel8,rhcos4

title: 'Add nosuid Option to /var'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: ol7,ol8,rhel7,rhel8,rhv4
prodtype: ol7,ol8,rhel7,rhel8,rhv4,rhcos4

title: 'Encrypt Partitions'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: rhel8
prodtype: rhel8,rhcos4

title: 'Configure session renegotiation for SSH client'

Expand Down
Loading