Guide to the Secure Configuration of Red Hat Enterprise Linux 8

with profile [DRAFT] DISA STIG for Red Hat Enterprise Linux 8
This profile contains configuration checks that align to the [DRAFT] DISA STIG for Red Hat Enterprise Linux 8. In addition to being applicable to Red Hat Enterprise Linux 8, DISA recognizes this configuration baseline as applicable to the operating system tier of Red Hat technologies that are based on Red Hat Enterprise Linux 8, such as: - Red Hat Enterprise Linux Server - Red Hat Enterprise Linux Workstation and Desktop - Red Hat Enterprise Linux for HPC - Red Hat Storage - Red Hat Containers with a Red Hat Enterprise Linux 8 image
This guide presents a catalog of security-relevant configuration settings for Red Hat Enterprise Linux 8. It is a rendering of content structured in the eXtensible Configuration Checklist Description Format (XCCDF) in order to support security automation. The SCAP content is is available in the scap-security-guide package which is developed at https://www.open-scap.org/security-policies/scap-security-guide.

Providing system administrators with such guidance informs them how to securely configure systems under their control in a variety of network roles. Policy makers and baseline creators can use this catalog of settings, with its associated references to higher-level security control catalogs, in order to assist them in security baseline creation. This guide is a catalog, not a checklist, and satisfaction of every item is not likely to be possible or sensible in many operational scenarios. However, the XCCDF format enables granular selection and adjustment of settings, and their association with OVAL and OCIL content provides an automated checking capability. Transformations of this document, and its associated automated checking content, are capable of providing baselines that meet a diverse set of policy objectives. Some example XCCDF Profiles, which are selections of items that form checklists and can be used as baselines, are available with this guide. They can be processed, in an automated fashion, with tools that support the Security Content Automation Protocol (SCAP). The DISA STIG, which provides required settings for US Department of Defense systems, is one example of a baseline created from this guidance.
Do not attempt to implement any of the settings in this guide without first testing them in a non-operational environment. The creators of this guidance assume no responsibility whatsoever for its use by other parties, and makes no guarantees, expressed or implied, about its quality, reliability, or any other characteristic.

Evaluation Characteristics

Evaluation targetqe-engine.asrachmani.com
Benchmark URL/usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
Benchmark IDxccdf_org.ssgproject.content_benchmark_RHEL-8
Benchmark version0.1.48
Profile IDxccdf_org.ssgproject.content_profile_stig
Started at2020-09-29T11:21:17
Finished at2020-09-29T11:21:17
Performed byroot
Test systemcpe:/a:redhat:openscap:1.3.2

CPE Platforms

  • cpe:/o:redhat:enterprise_linux:8

Addresses

  • IPv4  127.0.0.1
  • IPv4  192.168.1.65
  • IPv6  0:0:0:0:0:0:0:1
  • IPv6  fe80:0:0:0:5054:ff:fe6f:7823
  • MAC  00:00:00:00:00:00
  • MAC  52:54:00:6F:78:23

Compliance and Scoring

The target system did not satisfy the conditions of 4 rules! Furthermore, the results of 18 rules were inconclusive. Please review rule results and consider applying remediation.

Rule results

168 passed
4 failed
25 other

Severity of failed rules

1 other
0 low
3 medium
0 high

Score

Scoring systemScoreMaximumPercent
urn:xccdf:scoring:default83.070435100.000000
83.07%

Rule Overview

Group rules by:
TitleSeverityResult
Guide to the Secure Configuration of Red Hat Enterprise Linux 8 4x fail 18x error 5x notchecked
System Settings 4x fail 12x error 5x notchecked
Installing and Maintaining Software 1x fail 6x error 1x notchecked
Sudo
Install sudo Packagemedium
pass
Disk Partitioning 1x notchecked
Ensure /var/log Located On Separate Partitionmedium
pass
Ensure /var/log/audit Located On Separate Partitionlow
pass
Ensure /home Located On Separate Partitionlow
pass
Ensure /var Located On Separate Partitionlow
pass
Encrypt Partitionshigh
notchecked
Updating Software 2x error
Install dnf-automatic Packagemedium
error
Ensure Red Hat GPG Key Installedhigh
fixed
Ensure gpgcheck Enabled for All yum Package Repositorieshigh
pass
Configure dnf-automatic to Install Available Updates Automaticallymedium
fixed
Ensure gpgcheck Enabled for Local Packageshigh
fixed
Ensure gpgcheck Enabled In Main yum Configurationhigh
pass
Configure dnf-automatic to Install Only Security Updateslow
fixed
Ensure yum Removes Previous Package Versionslow
pass
Enable dnf-automatic Timermedium
error
System Tooling / Utilities 2x error
Install openscap-scanner Packagemedium
pass
Install scap-security-guide Packagemedium
pass
Install dnf-plugin-subscription-manager Packagemedium
pass
Ensure gnutls-utils is installedmedium
pass
Install rng-tools Packagemedium
pass
Install subscription-manager Packagemedium
pass
Ensure nss-tools is installedmedium
error
Install libcap-ng-utils Packagemedium
error
Uninstall abrt-addon-python Packagelow
pass
Uninstall abrt-plugin-logger Packagelow
pass
Uninstall abrt-addon-kerneloops Packagelow
pass
Uninstall abrt-cli Packagelow
pass
Uninstall gssproxy Packagelow
fixed
Uninstall abrt-addon-ccpp Packagelow
pass
Uninstall tuned Packagelow
fixed
Uninstall abrt-plugin-sosreport Packagelow
pass
Uninstall pigz Packagelow
fixed
Uninstall krb5-workstation Packagemedium
pass
Uninstall abrt-plugin-rhtsupport Packagelow
pass
Uninstall iprutils Packagelow
fixed
System and Software Integrity 1x fail 2x error
Federal Information Processing Standard (FIPS) 1x fail 1x error
Enable Dracut FIPS Modulemedium
fail
Enable FIPS Modehigh
error
System Cryptographic Policies 1x error
Configure BIND to use System Crypto Policymedium
pass
Configure OpenSSL library to use System Crypto Policymedium
fixed
Configure Libreswan to use System Crypto Policymedium
pass
Configure System Cryptography Policyhigh
error
Configure Kerberos to use System Crypto Policymedium
pass
Software Integrity Checking
Verify Integrity with AIDE
Install AIDEmedium
pass
GRUB2 bootloader configuration
Enable Kernel Page-Table Isolation (KPTI)high
fixed
Set the UEFI Boot Loader Passwordmedium
pass
System Accounting with auditd 2x error
System Accounting with auditd 1x error
Configure audit according to OSPP requirementsmedium
error
Configure auditd Rules for Comprehensive Auditing
Record Events that Modify User/Group Information - /etc/passwdmedium
fixed
Configure auditd Data Retention
Set hostname as computer node name in audit logsmedium
fixed
Include Local Events in Audit Logsmedium
pass
Set number of records to cause an explicit flush to audit logsmedium
pass
Resolve information before writing to audit logsmedium
pass
Write Audit Logs to the Diskmedium
pass
Configure auditd flush prioritymedium
pass
Configure auditd to use audispd's syslog pluginmedium
fixed
Ensure the audit Subsystem is Installedmedium
pass
Install audispd-plugins Packagemedium
error
Enable auditd Servicehigh
pass
Enable Auditing for Processes Which Start Prior to the Audit Daemonmedium
fixed
Extend Audit Backlog Limit for the Audit Daemonmedium
fixed
Network Configuration and Firewalls
Uncommon Network Protocols
Disable SCTP Supportmedium
fixed
Disable CAN Supportmedium
fixed
Disable TIPC Supportmedium
fixed
Disable IEEE 1394 (FireWire) Supportmedium
fixed
Disable ATM Supportmedium
fixed
IPv6
Configure IPv6 Settings if Necessary
Disable Accepting ICMP Redirects for All IPv6 Interfacesmedium
fixed
Disable Accepting Router Advertisements on all IPv6 Interfaces by Defaultunknown
fixed
Configure Accepting Router Advertisements on All IPv6 Interfacesunknown
fixed
Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Defaultmedium
fixed
Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfacesmedium
fixed
Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfacesmedium
fixed
iptables and ip6tables
Install iptables Packagemedium
pass
Kernel Parameters Which Affect Networking
Network Related Kernel Runtime Parameters for Hosts and Routers
Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Defaultmedium
fixed
Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Defaultunknown
fixed
Disable Accepting ICMP Redirects for All IPv4 Interfacesmedium
fixed
Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfacesmedium
fixed
Enable Kernel Parameter to Use TCP Syncookies on IPv4 Interfacesmedium
fixed
Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Defaultmedium
fixed
Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfacesmedium
pass
Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfacesunknown
fixed
Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfacesmedium
pass
Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfacesunknown
fixed
Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfacesmedium
fixed
Configure Kernel Parameter for Accepting Secure Redirects By Defaultmedium
fixed
Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfacesmedium
fixed
Network Parameters for Hosts Only
Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Defaultmedium
fixed
Disable Kernel Parameter for IP Forwarding on IPv4 Interfacesmedium
fixed
Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfacesmedium
fixed
firewalld
Inspect and Activate Default firewalld Rules
Install firewalld Packagemedium
pass
Verify firewalld Enabledmedium
pass
Wireless Networking
Disable Wireless Through Software Configuration
Disable Bluetooth Kernel Modulemedium
fixed
Account and Access Control 4x notchecked
Protect Physical Console Access 1x notchecked
Configure Screen Locking 1x notchecked
Configure Smart Card Certificate Status Checkingmedium
notchecked
Configure Console Screen Locking
Install the tmux Packagemedium
pass
Configure tmux to lock session after inactivitymedium
fixed
Support session locking with tmuxmedium
fixed
Configure the tmux Lock Commandmedium
fixed
Prevent user from disabling the screen lockmedium
fixed
Disable debug-shell SystemD Servicemedium
pass
Require Authentication for Single User Modemedium
pass
Disable Ctrl-Alt-Del Reboot Activationhigh
fixed
Verify that Interactive Boot is Disabledmedium
pass
Disable Ctrl-Alt-Del Burst Actionhigh
fixed
Warning Banners for System Accesses
Enable GNOME3 Login Warning Bannermedium
notapplicable
Modify the System Login Bannermedium
fixed
Protect Accounts by Configuring PAM
Set Password Quality Requirements
Set Password Quality Requirements with pam_pwquality
Ensure PAM Enforces Password Requirements - Minimum Lowercase Charactersmedium
fixed
Ensure PAM Enforces Password Requirements - Minimum Uppercase Charactersmedium
fixed
Ensure PAM Enforces Password Requirements - Maximum Consecutive Repeating Characters from Same Character Classmedium
fixed
Ensure PAM Enforces Password Requirements - Minimum Different Charactersmedium
fixed
Ensure PAM Enforces Password Requirements - Minimum Digit Charactersmedium
fixed
Set Password Maximum Consecutive Repeating Charactersmedium
fixed
Ensure PAM Enforces Password Requirements - Minimum Lengthmedium
fixed
Ensure PAM Enforces Password Requirements - Minimum Special Charactersmedium
fixed
Set Lockouts for Failed Password Attempts
Set Deny For Failed Password Attemptsmedium
fixed
Set Interval For Counting Failed Password Attemptsmedium
fixed
Set Lockout Time for Failed Password Attemptsmedium
fixed
Limit Password Reusemedium
fixed
Secure Session Configuration Files for Login Accounts
Ensure that Users Have Sensible Umask Values
Ensure the Default Umask is Set Correctly in /etc/profileunknown
fixed
Ensure the Default Bash Umask is Set Correctlyunknown
fixed
Ensure the Default C Shell Umask is Set Correctlyunknown
fixed
Protect Accounts by Restricting Password-Based Login 3x notchecked
Set Password Expiration Parameters 2x notchecked
Set Existing Passwords Minimum Agemedium
notchecked
Set Existing Passwords Maximum Agemedium
notchecked
Restrict Root Logins
Verify Proper Storage and Existence of Password Hashes
Prevent Login to Accounts With Empty Passwordhigh
fixed
SELinux
Install policycoreutils Packagehigh
pass
Configure SELinux Policyhigh
pass
Ensure SELinux State is Enforcinghigh
pass
File Permissions and Masks 1x fail 3x error
Verify Permissions on Important Files and Directories
Restrict Partition Mount Options 1x fail 3x error
Add nodev Option to /var/logmedium
pass
Add nosuid Option to /var/logmedium
fixed
Add nodev Option to /bootmedium
fixed
Add nodev Option to /var/tmpunknown
error
Add nosuid Option to /dev/shmmedium
pass
Add nosuid Option to /var/tmpunknown
error
Add nosuid Option to /homeunknown
fixed
Add noexec Option to /tmpunknown
pass
Add nodev Option to /varmedium
pass
Add noexec Option to /var/log/auditmedium
fixed
Add nodev Option to /var/log/auditmedium
pass
Add nodev Option to /homeunknown
pass
Add noexec Option to /dev/shmmedium
fixed
Add nodev Option to /tmpunknown
pass
Add nodev Option to /dev/shmmedium
pass
Add nosuid Option to /bootmedium
fixed
Add nodev Option to Non-Root Local Partitionsunknown
fail
Add noexec Option to /var/logmedium
fixed
Add nosuid Option to /var/log/auditmedium
fixed
Add noexec Option to /var/tmpunknown
error
Add nosuid Option to /tmpunknown
pass
Restrict Programs from Dangerous Execution Patterns
Memory Poisoning
Enable page allocator poisoningmedium
fixed
Enable SLUB/SLAB allocator poisoningmedium
fixed
Enable ExecShield
Restrict Exposed Kernel Pointer Addresses Accessmedium
pass
Disable Core Dumps
Disable acquiring, saving, and processing core dumpsunknown
fixed
Disable core dump backtracesunknown
fixed
Disable Core Dumps for All Usersunknown
fixed
Disable storing core dumpunknown
fixed
Restrict usage of ptrace to descendant processesmedium
fixed
Harden the operation of the BPF just-in-time compilermedium
fixed
Disable Access to Network bpf() Syscall From Unprivileged Processesmedium
fixed
Disable vsyscallsinfo
informational
Restrict Access to Kernel Message Buffermedium
fixed
Disable Kernel Image Loadingmedium
fixed
Disable storing core dumpsunknown
fixed
Disallow kernel profiling by unprivileged usersmedium
fixed
Disable the use of user namespacesinfo
informational
Restrict Dynamic Mounting and Unmounting of Filesystems
Disable Mounting of cramfslow
fixed
Configure Syslog 2x fail 1x error
Rsyslog Logs Sent To Remote Host 2x fail
Configure CA certificate for rsyslog remote loggingmedium
fail
Configure TLS for rsyslog remote loggingmedium
fail
Ensure rsyslog is Installedmedium
pass
Ensure rsyslog-gnutls is installedmedium
error
Services 6x error
NFS and RPC
Uninstall nfs-utils Packagelow
fixed
Mail Server Software
Uninstall Sendmail Packagemedium
pass
Network Time Protocol
Disable chrony daemon from acting as serverunknown
fixed
Disable network management of chrony daemonunknown
fixed
Application Whitelisting Daemon 2x error
Install fapolicyd Packagemedium
error
Enable the File Access Policy Servicemedium
error
Base Services
Uninstall Automatic Bug Reporting Tool (abrt)medium
pass
Kerberos
Disable Kerberos by removing host keytabmedium
pass
SSH Server
Configure OpenSSH Server if Necessary
Enable SSH Warning Bannermedium
fixed
Set SSH Idle Timeout Intervalmedium
fixed
Disable Kerberos Authenticationmedium
pass
Disable GSSAPI Authenticationmedium
fixed
Force frequent session key renegotiationmedium
fixed
Enable Use of Strict Mode Checkingmedium
pass
Set SSH Client Alive Max Countmedium
fixed
Disable Host-Based Authenticationmedium
pass
Disable SSH Access via Empty Passwordshigh
pass
USBGuard daemon 4x error
Install usbguard Packagemedium
error
Enable the USBGuard Servicemedium
error
Authorize Human Interface Devices and USB hubs in USBGuard daemonmedium
error
Log USBGuard daemon audit events using Linux Auditmedium
error
System Security Services Daemon
Enable Smartcards in SSSDmedium
pass
Configure SSSD to Expire Offline Credentialsmedium
pass
Hardware RNG Entropy Gatherer Daemon
Enable the Hardware RNG Entropy Gatherer Servicemedium
pass

Result Details

Install sudo Packagexccdf_org.ssgproject.content_rule_package_sudo_installed mediumCCE-82214-8

Install sudo Package

Rule IDxccdf_org.ssgproject.content_rule_package_sudo_installed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_sudo_installed:def:1
Time2020-09-29T11:18:01
Severitymedium
Identifiers and References

Identifiers:  CCE-82214-8

References:  CM-6(a), SRG-OS-000324-GPOS-00125

Description

The sudo package can be installed with the following command:

$ sudo yum install sudo

Rationale

sudo is a program designed to allow a system administrator to give limited root privileges to users and log root activity. The basic philosophy is to give as few privileges as possible but still allow system users to get their work done.

OVAL test results details

package sudo is installed  oval:ssg-test_package_sudo_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
sudox86_64(none)5.el81.8.290:1.8.29-5.el8199e2f91fd431d51sudo-0:1.8.29-5.el8.x86_64
Ensure /var/log Located On Separate Partitionxccdf_org.ssgproject.content_rule_partition_for_var_log mediumCCE-80853-5

Ensure /var/log Located On Separate Partition

Rule IDxccdf_org.ssgproject.content_rule_partition_for_var_log
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-partition_for_var_log:def:1
Time2020-09-29T11:18:01
Severitymedium
Identifiers and References

Identifiers:  CCE-80853-5

References:  NT28(R12), NT28(R47), 1.1.11, 1, 12, 14, 15, 16, 3, 5, 6, 8, APO11.04, APO13.01, BAI03.05, DSS05.02, DSS05.04, DSS05.07, MEA02.01, 4.3.3.3.9, 4.3.3.5.8, 4.3.4.4.7, 4.4.2.1, 4.4.2.2, 4.4.2.4, SR 2.10, SR 2.11, SR 2.12, SR 2.8, SR 2.9, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 7.1, SR 7.6, A.12.4.1, A.12.4.2, A.12.4.3, A.12.4.4, A.12.7.1, A.13.1.1, A.13.2.1, A.14.1.3, CM-6(a), AU-4, SC-5(2), PR.PT-1, PR.PT-4, SRG-OS-000480-GPOS-00227

Description

System logs are stored in the /var/log directory. Ensure that it has its own partition or logical volume at installation time, or migrate it using LVM.

Rationale

Placing /var/log in its own partition enables better separation between log files and other files in /var/.

OVAL test results details

/var/log on own partition  oval:ssg-test_var_log_partition:tst:1  true

Following items have been found on the system:
Mount pointDeviceUuidFs typeMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsTotal spaceSpace usedSpace left
/var/log/dev/mapper/ovirt-log04ffc7a2-ee25-4207-a1ca-33a1ef8f9021xfsrwseclabelnodevrelatimeattr2inode64noquotabind2618880268152592065
Ensure /var/log/audit Located On Separate Partitionxccdf_org.ssgproject.content_rule_partition_for_var_log_audit lowCCE-80854-3

Ensure /var/log/audit Located On Separate Partition

Rule IDxccdf_org.ssgproject.content_rule_partition_for_var_log_audit
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-partition_for_var_log_audit:def:1
Time2020-09-29T11:18:01
Severitylow
Identifiers and References

Identifiers:  CCE-80854-3

References:  1.1.12, 1, 12, 13, 14, 15, 16, 2, 3, 5, 6, 8, APO11.04, APO13.01, BAI03.05, BAI04.04, DSS05.02, DSS05.04, DSS05.07, MEA02.01, CCI-000366, 164.312(a)(2)(ii), 4.3.3.3.9, 4.3.3.5.8, 4.3.4.4.7, 4.4.2.1, 4.4.2.2, 4.4.2.4, SR 2.10, SR 2.11, SR 2.12, SR 2.8, SR 2.9, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 7.1, SR 7.2, SR 7.6, A.12.1.3, A.12.4.1, A.12.4.2, A.12.4.3, A.12.4.4, A.12.7.1, A.13.1.1, A.13.2.1, A.14.1.3, A.17.2.1, CM-6(a), AU-4, SC-5(2), PR.DS-4, PR.PT-1, PR.PT-4, SRG-OS-000480-GPOS-00227, SRG-OS-000341-VMM-001220

Description

Audit logs are stored in the /var/log/audit directory. Ensure that it has its own partition or logical volume at installation time, or migrate it later using LVM. Make absolutely certain that it is large enough to store all audit logs that will be created by the auditing daemon.

Rationale

Placing /var/log/audit in its own partition enables better separation between audit files and other files, and helps ensure that auditing cannot be halted due to the partition running out of space.

OVAL test results details

/var/log/audit on own partition  oval:ssg-test_var_log_audit_partition:tst:1  true

Following items have been found on the system:
Mount pointDeviceUuidFs typeMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsTotal spaceSpace usedSpace left
/var/log/audit/dev/mapper/ovirt-audit3b01f699-5c60-4a28-8941-ddc1a0828164xfsrwseclabelnodevrelatimeattr2inode64noquotabind25958410105249479
Ensure /home Located On Separate Partitionxccdf_org.ssgproject.content_rule_partition_for_home lowCCE-81044-0

Ensure /home Located On Separate Partition

Rule IDxccdf_org.ssgproject.content_rule_partition_for_home
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-partition_for_home:def:1
Time2020-09-29T11:18:01
Severitylow
Identifiers and References

Identifiers:  CCE-81044-0

References:  NT28(R12), 1.1.13, 12, 15, 8, APO13.01, DSS05.02, CCI-000366, CCI-001208, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 7.1, SR 7.6, A.13.1.1, A.13.2.1, A.14.1.3, CM-6(a), SC-5(2), PR.PT-4, SRG-OS-000480-GPOS-00227

Description

If user home directories will be stored locally, create a separate partition for /home at installation time (or migrate it later using LVM). If /home will be mounted from another system such as an NFS server, then creating a separate partition is not necessary at installation time, and the mountpoint can instead be configured later.

Rationale

Ensuring that /home is mounted on its own partition enables the setting of more restrictive mount options, and also helps ensure that users cannot trivially fill partitions used for log or audit data storage.

OVAL test results details

/home on own partition  oval:ssg-test_home_partition:tst:1  true

Following items have been found on the system:
Mount pointDeviceUuidFs typeMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsTotal spaceSpace usedSpace left
/home/dev/mapper/ovirt-home934099b3-b298-4e85-a731-17c9495a92acxfsrwseclabelnodevrelatimeattr2inode64noquotabind25958410084249500
Ensure /var Located On Separate Partitionxccdf_org.ssgproject.content_rule_partition_for_var lowCCE-80852-7

Ensure /var Located On Separate Partition

Rule IDxccdf_org.ssgproject.content_rule_partition_for_var
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-partition_for_var:def:1
Time2020-09-29T11:18:01
Severitylow
Identifiers and References

Identifiers:  CCE-80852-7

References:  NT28(R12), 1.1.6, 12, 15, 8, APO13.01, DSS05.02, CCI-000366, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 7.1, SR 7.6, A.13.1.1, A.13.2.1, A.14.1.3, CM-6(a), SC-5(2), PR.PT-4, SRG-OS-000480-GPOS-00227, SRG-OS-000341-VMM-001220

Description

The /var directory is used by daemons and other system services to store frequently-changing data. Ensure that /var has its own partition or logical volume at installation time, or migrate it using LVM.

Rationale

Ensuring that /var is mounted on its own partition enables the setting of more restrictive mount options. This helps protect system services such as daemons or other programs which use it. It is not uncommon for the /var directory to contain world-writable directories installed by other software packages.

OVAL test results details

/var on own partition  oval:ssg-test_var_partition:tst:1  true

Following items have been found on the system:
Mount pointDeviceUuidFs typeMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsTotal spaceSpace usedSpace left
/var/dev/mapper/ovirt-var64bf7634-bdbb-40e1-a2b8-0b7865630c92xfsrwseclabelnodevrelatimeattr2inode64noquotabind5240320824325157888
Encrypt Partitionsxccdf_org.ssgproject.content_rule_encrypt_partitions highCCE-80789-1

Encrypt Partitions

Rule IDxccdf_org.ssgproject.content_rule_encrypt_partitions
Result
notchecked
Multi-check ruleno
Time2020-09-29T11:18:01
Severityhigh
Identifiers and References

Identifiers:  CCE-80789-1

References:  13, 14, APO01.06, BAI02.01, BAI06.01, DSS04.07, DSS05.03, DSS05.04, DSS05.07, DSS06.02, DSS06.06, 3.13.16, CCI-001199, CCI-002475, CCI-002476, 164.308(a)(1)(ii)(D), 164.308(b)(1), 164.310(d), 164.312(a)(1), 164.312(a)(2)(iii), 164.312(a)(2)(iv), 164.312(b), 164.312(c), 164.314(b)(2)(i), 164.312(d), SR 3.4, SR 4.1, SR 5.2, A.10.1.1, A.11.1.4, A.11.1.5, A.11.2.1, A.13.1.1, A.13.1.3, A.13.2.1, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3, A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, CM-6(a), SC-28, SC-28(1), SC-13, AU-9(3), PR.DS-1, PR.DS-5, SRG-OS-000405-GPOS-00184, SRG-OS-000185-GPOS-00079, SRG-OS-000404-GPOS-00183, SRG-OS-000404-VMM-001650, SRG-OS-000405-VMM-001660

Description

Red Hat Enterprise Linux 8 natively supports partition encryption through the Linux Unified Key Setup-on-disk-format (LUKS) technology. The easiest way to encrypt a partition is during installation time.

For manual installations, select the Encrypt checkbox during partition creation to encrypt the partition. When this option is selected the system will prompt for a passphrase to use in decrypting the partition. The passphrase will subsequently need to be entered manually every time the system boots.

For automated/unattended installations, it is possible to use Kickstart by adding the --encrypted and --passphrase= options to the definition of each partition to be encrypted. For example, the following line would encrypt the root partition:

part / --fstype=ext4 --size=100 --onpart=hda1 --encrypted --passphrase=PASSPHRASE
Any PASSPHRASE is stored in the Kickstart in plaintext, and the Kickstart must then be protected accordingly. Omitting the --passphrase= option from the partition definition will cause the installer to pause and interactively ask for the passphrase during installation.

By default, the Anaconda installer uses aes-xts-plain64 cipher with a minimum 512 bit key size which should be compatible with FIPS enabled.

Detailed information on encrypting partitions using LUKS or LUKS ciphers can be found on the Red Hat Enterprise Linux 8 Documentation web site:
https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Security_Guide/sec-Encryption.html.

Rationale

The risk of a system's physical compromise, particularly mobile systems such as laptops, places its data at risk of compromise. Encrypting this data mitigates the risk of its loss if the system is lost.

Evaluation messages
info 
No candidate or applicable check found.
Install dnf-automatic Packagexccdf_org.ssgproject.content_rule_package_dnf-automatic_installed mediumCCE-82985-3

Install dnf-automatic Package

Rule IDxccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
Result
error
Multi-check ruleno
OVAL Definition IDoval:ssg-package_dnf-automatic_installed:def:1
Time2020-09-29T11:18:07
Severitymedium
Identifiers and References

Identifiers:  CCE-82985-3

References:  SRG-OS-000191-GPOS-00080

Description

The dnf-automatic package can be installed with the following command:

$ sudo yum install dnf-automatic

Rationale

dnf-automatic is an alternative command line interface (CLI) to dnf upgrade suitable for automatic, regular execution.

Evaluation messages
info 
Fix execution completed and returned: 1
info 
Error: There are no enabled repositories in "/etc/yum.repos.d", "/etc/yum/repos.d", "/etc/distro.repos.d".
info 
Failed to verify applied fix: Checking engine returns: fail


Complexity:low
Disruption:low
Strategy:enable

if ! rpm -q --quiet "dnf-automatic" ; then
    yum install -y "dnf-automatic"
fi


Complexity:low
Disruption:low
Strategy:enable
- name: Ensure dnf-automatic is installed
  package:
    name: dnf-automatic
    state: present
  tags:
    - package_dnf-automatic_installed
    - medium_severity
    - enable_strategy
    - low_complexity
    - low_disruption
    - no_reboot_needed
    - CCE-82985-3


Complexity:low
Disruption:low
Strategy:enable
include install_dnf-automatic

class install_dnf-automatic {
  package { 'dnf-automatic':
    ensure => 'installed',
  }
}


Complexity:low
Disruption:low
Strategy:enable

package --add=dnf-automatic
OVAL test results details

package dnf-automatic is installed  oval:ssg-test_package_dnf-automatic_installed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_test_package_dnf-automatic_installed:obj:1 of type rpminfo_object
Name
dnf-automatic
Ensure Red Hat GPG Key Installedxccdf_org.ssgproject.content_rule_ensure_redhat_gpgkey_installed highCCE-80795-8

Ensure Red Hat GPG Key Installed

Rule IDxccdf_org.ssgproject.content_rule_ensure_redhat_gpgkey_installed
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-ensure_redhat_gpgkey_installed:def:1
Time2020-09-29T11:18:07
Severityhigh
Identifiers and References

Identifiers:  CCE-80795-8

References:  NT28(R15), 1.2.3, 11, 2, 3, 9, 5.10.4.1, APO01.06, BAI03.05, BAI06.01, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS06.02, 3.4.8, CCI-001749, 164.308(a)(1)(ii)(D), 164.312(b), 164.312(c)(1), 164.312(c)(2), 164.312(e)(2)(i), 4.3.4.3.2, 4.3.4.3.3, 4.3.4.4.4, SR 3.1, SR 3.3, SR 3.4, SR 3.8, SR 7.6, A.11.2.4, A.12.1.2, A.12.2.1, A.12.5.1, A.12.6.2, A.14.1.2, A.14.1.3, A.14.2.2, A.14.2.3, A.14.2.4, CM-5(3), SI-7, SC-12, SC-12(3), CM-6(a), PR.DS-6, PR.DS-8, PR.IP-1, FAU_GEN.1.1.c, Req-6.2, SRG-OS-000366-GPOS-00153, SRG-OS-000366-VMM-001430, SRG-OS-000370-VMM-001460, SRG-OS-000404-VMM-001650

Description

To ensure the system can cryptographically verify base software packages come from Red Hat (and to connect to the Red Hat Network to receive them), the Red Hat GPG key must properly be installed. To install the Red Hat GPG key, run:

$ sudo subscription-manager register
If the system is not connected to the Internet or an RHN Satellite, then install the Red Hat GPG key from trusted media such as the Red Hat installation CD-ROM or DVD. Assuming the disc is mounted in /media/cdrom, use the following command as the root user to import it into the keyring:
$ sudo rpm --import /media/cdrom/RPM-GPG-KEY
Alternatively, the key may be pre-loaded during the RHEL installation. In such cases, the key can be installed by running the following command:
sudo rpm --import /etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release

Rationale

Changes to software components can have significant effects on the overall security of the operating system. This requirement ensures the software has not been tampered with and that it has been provided by a trusted vendor. The Red Hat GPG key is necessary to cryptographically verify packages are from Red Hat.

Evaluation messages
info 
Fix execution completed and returned: 0
info 
gpg: directory '/root/.gnupg' created
gpg: keybox '/root/.gnupg/pubring.kbx' created
gpg: /root/.gnupg/trustdb.gpg: trustdb created
OVAL test results details

installed OS part of unix family  oval:ssg-test_rhel8_unix_family:tst:1  true

Following items have been found on the system:
Family
unix

installed OS part of unix family  oval:ssg-test_rhel8_unix_family:tst:1  true

Following items have been found on the system:
Family
unix

redhat-release is version 8  oval:ssg-test_rhel8:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
redhat-releasex86_64(none)25.0.el8rhgs8.20:8.2-25.0.el8rhgs0redhat-release-0:8.2-25.0.el8rhgs.x86_64

redhat-release is version 8  oval:ssg-test_rhel8:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
redhat-releasex86_64(none)25.0.el8rhgs8.20:8.2-25.0.el8rhgs0redhat-release-0:8.2-25.0.el8rhgs.x86_64

redhat-release-coreos is version 8  oval:ssg-test_rhel8_coreos:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel8_coreos:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/os-release^PRETTY_NAME="Red Hat Enterprise Linux CoreOS \d+\.(\d)\d+\.\d+\.\d+ \([\w\s]+\)"$1

redhat-release-coreos is version 8  oval:ssg-test_rhel8_coreos:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel8_coreos:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/os-release^PRETTY_NAME="Red Hat Enterprise Linux CoreOS \d+\.(\d)\d+\.\d+\.\d+ \([\w\s]+\)"$1

redhat-release-virtualization-host RPM package is installed  oval:ssg-test_rhvh4_version:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhvh4_version:obj:1 of type rpminfo_object
Name
redhat-release-virtualization-host

redhat-release-virtualization-host RPM package is installed  oval:ssg-test_rhvh4_version:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhvh4_version:obj:1 of type rpminfo_object
Name
redhat-release-virtualization-host

RHEVH base RHEL is version 8  oval:ssg-test_rhevh_rhel8_version:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhevh_rhel8_version:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/redhat-release^Red Hat Enterprise Linux release (\d)\.\d+$1

RHEVH base RHEL is version 8  oval:ssg-test_rhevh_rhel8_version:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhevh_rhel8_version:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/redhat-release^Red Hat Enterprise Linux release (\d)\.\d+$1

installed OS part of unix family  oval:ssg-test_rhel8_unix_family:tst:1  true

Following items have been found on the system:
Family
unix

installed OS part of unix family  oval:ssg-test_rhel8_unix_family:tst:1  true

Following items have been found on the system:
Family
unix

redhat-release is version 8  oval:ssg-test_rhel8:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
redhat-releasex86_64(none)25.0.el8rhgs8.20:8.2-25.0.el8rhgs0redhat-release-0:8.2-25.0.el8rhgs.x86_64

redhat-release is version 8  oval:ssg-test_rhel8:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
redhat-releasex86_64(none)25.0.el8rhgs8.20:8.2-25.0.el8rhgs0redhat-release-0:8.2-25.0.el8rhgs.x86_64

redhat-release-coreos is version 8  oval:ssg-test_rhel8_coreos:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel8_coreos:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/os-release^PRETTY_NAME="Red Hat Enterprise Linux CoreOS \d+\.(\d)\d+\.\d+\.\d+ \([\w\s]+\)"$1

redhat-release-coreos is version 8  oval:ssg-test_rhel8_coreos:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel8_coreos:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/os-release^PRETTY_NAME="Red Hat Enterprise Linux CoreOS \d+\.(\d)\d+\.\d+\.\d+ \([\w\s]+\)"$1

redhat-release-virtualization-host RPM package is installed  oval:ssg-test_rhvh4_version:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhvh4_version:obj:1 of type rpminfo_object
Name
redhat-release-virtualization-host

redhat-release-virtualization-host RPM package is installed  oval:ssg-test_rhvh4_version:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhvh4_version:obj:1 of type rpminfo_object
Name
redhat-release-virtualization-host

RHEVH base RHEL is version 8  oval:ssg-test_rhevh_rhel8_version:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhevh_rhel8_version:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/redhat-release^Red Hat Enterprise Linux release (\d)\.\d+$1

RHEVH base RHEL is version 8  oval:ssg-test_rhevh_rhel8_version:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhevh_rhel8_version:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/redhat-release^Red Hat Enterprise Linux release (\d)\.\d+$1

Red Hat release key package is installed  oval:ssg-test_package_gpgkey-fd431d51-4ae0493b_installed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_package_gpg-pubkey:obj:1 of type rpminfo_object
Name
gpg-pubkey

Red Hat auxiliary key package is installed  oval:ssg-test_package_gpgkey-d4082792-5b32db75_installed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_package_gpg-pubkey:obj:1 of type rpminfo_object
Name
gpg-pubkey
Ensure gpgcheck Enabled for All yum Package Repositoriesxccdf_org.ssgproject.content_rule_ensure_gpgcheck_never_disabled highCCE-80792-5

Ensure gpgcheck Enabled for All yum Package Repositories

Rule IDxccdf_org.ssgproject.content_rule_ensure_gpgcheck_never_disabled
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-ensure_gpgcheck_never_disabled:def:1
Time2020-09-29T11:18:01
Severityhigh
Identifiers and References

Identifiers:  CCE-80792-5

References:  NT28(R15), 11, 2, 3, 9, 5.10.4.1, APO01.06, BAI03.05, BAI06.01, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS06.02, 3.4.8, CCI-001749, 164.308(a)(1)(ii)(D), 164.312(b), 164.312(c)(1), 164.312(c)(2), 164.312(e)(2)(i), 4.3.4.3.2, 4.3.4.3.3, 4.3.4.4.4, SR 3.1, SR 3.3, SR 3.4, SR 3.8, SR 7.6, A.11.2.4, A.12.1.2, A.12.2.1, A.12.5.1, A.12.6.2, A.14.1.2, A.14.1.3, A.14.2.2, A.14.2.3, A.14.2.4, CM-5(3), SI-7, SC-12, SC-12(3), CM-6(a), SA-12, SA-12(10), CM-11(a), CM-11(b), PR.DS-6, PR.DS-8, PR.IP-1, FAU_GEN.1.1.c, Req-6.2, SRG-OS-000366-GPOS-00153, SRG-OS-000366-VMM-001430, SRG-OS-000370-VMM-001460, SRG-OS-000404-VMM-001650

Description

To ensure signature checking is not disabled for any repos, remove any lines from files in /etc/yum.repos.d of the form:

gpgcheck=0

Rationale

Verifying the authenticity of the software prior to installation validates the integrity of the patch or upgrade received from a vendor. This ensures the software has not been tampered with and that it has been provided by a trusted vendor. Self-signed certificates are disallowed by this requirement. Certificates used to verify the software must be from an approved Certificate Authority (CA)."

OVAL test results details

check for existence of gpgcheck=0 in /etc/yum.repos.d/ files  oval:ssg-test_ensure_gpgcheck_never_disabled:tst:1  true

No items have been found conforming to the following objects:
Object oval:ssg-obj_ensure_gpgcheck_never_disabled:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/yum.repos.d.*^\s*gpgcheck\s*=\s*0\s*$1
Configure dnf-automatic to Install Available Updates Automaticallyxccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates mediumCCE-82494-6

Configure dnf-automatic to Install Available Updates Automatically

Rule IDxccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-dnf-automatic_apply_updates:def:1
Time2020-09-29T11:18:07
Severitymedium
Identifiers and References

Identifiers:  CCE-82494-6

References:  SI-2(5), CM-6(a), SI-2(c), FMT_SMF_EXT.1, SRG-OS-000191-GPOS-00080

Description

To ensure that the packages comprising the available updates will be automatically installed by dnf-automatic, set apply_updates to yes under [commands] section in /etc/dnf/automatic.conf.

Rationale

Installing software updates is a fundamental mitigation against the exploitation of publicly-known vulnerabilities. If the most recent security patches and updates are not installed, unauthorized users may take advantage of weaknesses in the unpatched software. The lack of prompt attention to patching could result in a system compromise. The automated installation of updates ensures that recent security patches are applied in a timely manner.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

tests the value of apply_updates setting in the /etc/dnf/automatic.conf file  oval:ssg-test_dnf-automatic_apply_updates:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_dnf-automatic_apply_updates:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/dnf/automatic.conf^\s*\[commands\].*(?:\n\s*[^[\s].*)*\n^\s*apply_updates[ \t]*=[ \t]*(.+?)[ \t]*(?:$|#)1

The configuration file /etc/dnf/automatic.conf exists for dnf-automatic_apply_updates  oval:ssg-test_dnf-automatic_apply_updates_config_file_exists:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_dnf-automatic_apply_updates_config_file:obj:1 of type file_object
Filepath
^/etc/dnf/automatic.conf
Ensure gpgcheck Enabled for Local Packagesxccdf_org.ssgproject.content_rule_ensure_gpgcheck_local_packages highCCE-80791-7

Ensure gpgcheck Enabled for Local Packages

Rule IDxccdf_org.ssgproject.content_rule_ensure_gpgcheck_local_packages
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-ensure_gpgcheck_local_packages:def:1
Time2020-09-29T11:18:07
Severityhigh
Identifiers and References

Identifiers:  CCE-80791-7

References:  NT28(R15), 11, 3, 9, BAI10.01, BAI10.02, BAI10.03, BAI10.05, 3.4.8, CCI-001749, 164.308(a)(1)(ii)(D), 164.312(b), 164.312(c)(1), 164.312(c)(2), 164.312(e)(2)(i), 4.3.4.3.2, 4.3.4.3.3, SR 7.6, A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, CM-11(a), CM-11(b), CM-6(a), CM-5(3), SA-12, SA-12(10), PR.IP-1, FAU_GEN.1.1.c, SRG-OS-000366-GPOS-00153, SRG-OS-000366-VMM-001430, SRG-OS-000370-VMM-001460, SRG-OS-000404-VMM-001650

Description

yum should be configured to verify the signature(s) of local packages prior to installation. To configure yum to verify signatures of local packages, set the localpkg_gpgcheck to 1 in /etc/yum.conf.

Rationale

Changes to any software components can have significant effects to the overall security of the operating system. This requirement ensures the software has not been tampered and has been provided by a trusted vendor.

Accordingly, patches, service packs, device drivers, or operating system components must be signed with a certificate recognized and approved by the organization.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

check value of localpkg_gpgcheck in /etc/yum.conf  oval:ssg-test_yum_ensure_gpgcheck_local_packages:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_yum_ensure_gpgcheck_local_packages:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/yum.conf^\s*localpkg_gpgcheck\s*=\s*(1|True|yes)\s*$1
Ensure gpgcheck Enabled In Main yum Configurationxccdf_org.ssgproject.content_rule_ensure_gpgcheck_globally_activated highCCE-80790-9

Ensure gpgcheck Enabled In Main yum Configuration

Rule IDxccdf_org.ssgproject.content_rule_ensure_gpgcheck_globally_activated
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-ensure_gpgcheck_globally_activated:def:1
Time2020-09-29T11:18:01
Severityhigh
Identifiers and References

Identifiers:  CCE-80790-9

References:  NT28(R15), 1.2.2, 11, 2, 3, 9, 5.10.4.1, APO01.06, BAI03.05, BAI06.01, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS06.02, 3.4.8, CCI-001749, 164.308(a)(1)(ii)(D), 164.312(b), 164.312(c)(1), 164.312(c)(2), 164.312(e)(2)(i), 4.3.4.3.2, 4.3.4.3.3, 4.3.4.4.4, SR 3.1, SR 3.3, SR 3.4, SR 3.8, SR 7.6, A.11.2.4, A.12.1.2, A.12.2.1, A.12.5.1, A.12.6.2, A.14.1.2, A.14.1.3, A.14.2.2, A.14.2.3, A.14.2.4, CM-5(3), SI-7, SC-12, SC-12(3), CM-6(a), SA-12, SA-12(10), CM-11(a), CM-11(b), PR.DS-6, PR.DS-8, PR.IP-1, FAU_GEN.1.1.c, Req-6.2, SRG-OS-000366-GPOS-00153, SRG-OS-000366-VMM-001430, SRG-OS-000370-VMM-001460, SRG-OS-000404-VMM-001650

Description

The gpgcheck option controls whether RPM packages' signatures are always checked prior to installation. To configure yum to check package signatures before installing them, ensure the following line appears in /etc/yum.conf in the [main] section:

gpgcheck=1

Rationale

Changes to any software components can have significant effects on the overall security of the operating system. This requirement ensures the software has not been tampered with and that it has been provided by a trusted vendor.
Accordingly, patches, service packs, device drivers, or operating system components must be signed with a certificate recognized and approved by the organization.
Verifying the authenticity of the software prior to installation validates the integrity of the patch or upgrade received from a vendor. This ensures the software has not been tampered with and that it has been provided by a trusted vendor. Self-signed certificates are disallowed by this requirement. Certificates used to verify the software must be from an approved Certificate Authority (CA).

OVAL test results details

check value of gpgcheck in /etc/yum.conf  oval:ssg-test_ensure_gpgcheck_globally_activated:tst:1  true

Following items have been found on the system:
PathContent
/etc/yum.confgpgcheck=1
Configure dnf-automatic to Install Only Security Updatesxccdf_org.ssgproject.content_rule_dnf-automatic_security_updates_only lowCCE-82267-6

Configure dnf-automatic to Install Only Security Updates

Rule IDxccdf_org.ssgproject.content_rule_dnf-automatic_security_updates_only
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-dnf-automatic_security_updates_only:def:1
Time2020-09-29T11:18:07
Severitylow
Identifiers and References

Identifiers:  CCE-82267-6

References:  SI-2(5), CM-6(a), SI-2(c), FMT_SMF_EXT.1, SRG-OS-000191-GPOS-00080

Description

To configure dnf-automatic to install only security updates automatically, set upgrade_type to security under [commands] section in /etc/dnf/automatic.conf.

Rationale

By default, dnf-automatic installs all available updates. Reducing the amount of updated packages only to updates that were issued as a part of a security advisory increases the system stability.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

tests the value of upgrade_type setting in the /etc/dnf/automatic.conf file  oval:ssg-test_dnf-automatic_security_updates_only:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_dnf-automatic_security_updates_only:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/dnf/automatic.conf^\s*\[commands\].*(?:\n\s*[^[\s].*)*\n^\s*upgrade_type[ \t]*=[ \t]*(.+?)[ \t]*(?:$|#)1

The configuration file /etc/dnf/automatic.conf exists for dnf-automatic_security_updates_only  oval:ssg-test_dnf-automatic_security_updates_only_config_file_exists:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_dnf-automatic_security_updates_only_config_file:obj:1 of type file_object
Filepath
^/etc/dnf/automatic.conf
Ensure yum Removes Previous Package Versionsxccdf_org.ssgproject.content_rule_clean_components_post_updating lowCCE-82476-3

Ensure yum Removes Previous Package Versions

Rule IDxccdf_org.ssgproject.content_rule_clean_components_post_updating
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-clean_components_post_updating:def:1
Time2020-09-29T11:18:01
Severitylow
Identifiers and References

Identifiers:  CCE-82476-3

References:  18, 20, 4, APO12.01, APO12.02, APO12.03, APO12.04, BAI03.10, DSS05.01, DSS05.02, 3.4.8, CCI-002617, 4.2.3, 4.2.3.12, 4.2.3.7, 4.2.3.9, A.12.6.1, A.14.2.3, A.16.1.3, A.18.2.2, A.18.2.3, SI-2(6), CM-11(a), CM-11(b), CM-6(a), ID.RA-1, PR.IP-12, SRG-OS-000437-GPOS-00194, SRG-OS-000437-VMM-001760

Description

yum should be configured to remove previous software components after new versions have been installed. To configure yum to remove the previous software components after updating, set the clean_requirements_on_remove to 1 in /etc/yum.conf.

Rationale

Previous versions of software components that are not removed from the information system after updates have been installed may be exploited by some adversaries.

OVAL test results details

check value of clean_requirements_on_remove in /etc/yum.conf  oval:ssg-test_yum_clean_components_post_updating:tst:1  true

Following items have been found on the system:
PathContent
/etc/yum.confclean_requirements_on_remove=True
Enable dnf-automatic Timerxccdf_org.ssgproject.content_rule_timer_dnf-automatic_enabled mediumCCE-82360-9

Enable dnf-automatic Timer

Rule IDxccdf_org.ssgproject.content_rule_timer_dnf-automatic_enabled
Result
error
Multi-check ruleno
OVAL Definition IDoval:ssg-timer_dnf-automatic_enabled:def:1
Time2020-09-29T11:18:07
Severitymedium
Identifiers and References

Identifiers:  CCE-82360-9

References:  SI-2(5), CM-6(a), SI-2(c), FMT_SMF_EXT.1, SRG-OS-000191-GPOS-00080

Description

The dnf-automatic timer can be enabled with the following command:

$ sudo systemctl enable dnf-automatic.timer

Rationale

The dnf-automatic is an alternative command line interface (CLI) to dnf upgrade with specific facilities to make it suitable to be executed automatically and regularly from systemd timers, cron jobs and similar. The tool is controlled by dnf-automatic.timer SystemD timer.

Evaluation messages
info 
Fix execution completed and returned: 1
info 
Failed to start dnf-automatic.timer: Unit dnf-automatic.timer not found.
Failed to enable unit: Unit file dnf-automatic.timer does not exist.
info 
Failed to verify applied fix: Checking engine returns: fail


Complexity:low
Disruption:low
Strategy:enable

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" start 'dnf-automatic.timer'
"$SYSTEMCTL_EXEC" enable 'dnf-automatic.timer'


Complexity:low
Disruption:low
Strategy:enable
- name: Enable timer dnf-automatic
  block:

    - name: Gather the package facts
      package_facts:
        manager: auto

    - name: Enable timer dnf-automatic
      systemd:
        name: dnf-automatic.timer
        enabled: 'yes'
        state: started
      when:
        - '"dnf-automatic" in ansible_facts.packages'
  tags:
    - timer_dnf-automatic_enabled
    - medium_severity
    - enable_strategy
    - low_complexity
    - low_disruption
    - no_reboot_needed
    - CCE-82360-9
    - NIST-800-53-SI-2(5)
    - NIST-800-53-CM-6(a)
    - NIST-800-53-SI-2(c)
OVAL test results details

package dnf-automatic is installed  oval:ssg-test_package_dnf-automatic_installed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_test_package_dnf-automatic_installed:obj:1 of type rpminfo_object
Name
dnf-automatic

Test that the dnf-automatic timer is running  oval:ssg-test_timer_running_dnf-automatic:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_timer_running_dnf-automatic:obj:1 of type systemdunitproperty_object
UnitProperty
dnf-automatic\.timerActiveState

systemd test  oval:ssg-test_multi_user_wants_dnf-automatic:tst:1  false

Following items have been found on the system:
UnitDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependency
multi-user.targetbasic.targetvar.mount-.mountsysinit.targetdev-mqueue.mountsystemd-hwdb-update.servicecryptsetup.targetproc-sys-fs-binfmt_misc.automountsystemd-journal-flush.servicesystemd-random-seed.servicesystemd-update-utmp.servicesystemd-tmpfiles-setup.servicesystemd-udevd.servicedev-hugepages.mountlvm2-lvmpolld.socketselinux-autorelabel-mark.serviceloadmodules.servicelocal-fs.targethome.mount-.mountvar-log-audit.mountboot.mounttmp.mountvar.mountvar-log.mountsystemd-remount-fs.servicedracut-shutdown.servicesystemd-sysctl.servicesystemd-journal-catalog-update.servicesystemd-update-done.servicesystemd-journald.servicesys-kernel-debug.mountsystemd-machine-id-commit.serviceldconfig.servicerngd.servicesystemd-binfmt.servicenis-domainname.servicesys-kernel-config.mountsystemd-modules-load.servicesystemd-sysusers.servicesys-fs-fuse-connections.mountswap.targetdev-mapper-ovirt\x2dswap.swapsystemd-udev-trigger.serviceimport-state.servicesystemd-firstboot.servicekmod-static-nodes.servicesystemd-ask-password-console.pathsystemd-tmpfiles-setup-dev.servicelvm2-monitor.servicemicrocode.servicepaths.targettimers.targetfstrim.timerunbound-anchor.timersystemd-tmpfiles-clean.timerslices.target-.slicesystem.slicesockets.targetsystemd-udevd-kernel.socketdbus.socketsystemd-coredump.socketsystemd-initctl.socketsystemd-udevd-control.socketsystemd-journald-dev-log.socketpcscd.socketsssd-kcm.socketsystemd-journald.socketcockpit.socketdm-event.socketrpcbind.socketsssd.servicekdump.servicecrond.servicesystemd-ask-password-wall.pathsshd.servicesystemd-user-sessions.serviceauditd.servicenfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetirqbalance.serviceremote-fs.targetnfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetgetty.targetserial-getty@ttyS0.servicegetty@tty1.servicecloud-init.targetcloud-init-local.servicecloud-config.servicecloud-final.servicecloud-init.servicednf-makecache.timerfirewalld.servicerpcbind.servicesystemd-update-utmp-runlevel.servicechronyd.servicersyslog.servicetuned.servicesystemd-logind.serviceNetworkManager.servicedbus.service
Install openscap-scanner Packagexccdf_org.ssgproject.content_rule_package_openscap-scanner_installed mediumCCE-82220-5

Install openscap-scanner Package

Rule IDxccdf_org.ssgproject.content_rule_package_openscap-scanner_installed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_openscap-scanner_installed:def:1
Time2020-09-29T11:18:01
Severitymedium
Identifiers and References

Identifiers:  CCE-82220-5

References:  SRG-OS-000480-GPOS-00227, SRG-OS-000191-GPOS-00080

Description

The openscap-scanner package can be installed with the following command:

$ sudo yum install openscap-scanner

Rationale

openscap-scanner contains the oscap command line tool. This tool is a configuration and vulnerability scanner, capable of performing compliance checking using SCAP content.

OVAL test results details

package openscap-scanner is installed  oval:ssg-test_package_openscap-scanner_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
openscap-scannerx86_64(none)6.el81.3.20:1.3.2-6.el80openscap-scanner-0:1.3.2-6.el8.x86_64
Install scap-security-guide Packagexccdf_org.ssgproject.content_rule_package_scap-security-guide_installed mediumCCE-82949-9

Install scap-security-guide Package

Rule IDxccdf_org.ssgproject.content_rule_package_scap-security-guide_installed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_scap-security-guide_installed:def:1
Time2020-09-29T11:18:01
Severitymedium
Identifiers and References

Identifiers:  CCE-82949-9

References:  SRG-OS-000480-GPOS-00227

Description

The scap-security-guide package can be installed with the following command:

$ sudo yum install scap-security-guide

Rationale

The scap-security-guide package provides a guide for configuration of the system from the final system's security point of view. The guidance is specified in the Security Content Automation Protocol (SCAP) format and constitutes a catalog of practical hardening advice, linked to government requirements where applicable. The SCAP Security Guide project bridges the gap between generalized policy requirements and specific implementation guidelines. A system administrator can use the oscap CLI tool from the openscap-scanner package, or the SCAP Workbench GUI tool from the scap-workbench package, to verify that the system conforms to provided guidelines. Refer to the scap-security-guide(8) manual page for futher information.

OVAL test results details

package scap-security-guide is installed  oval:ssg-test_package_scap-security-guide_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
scap-security-guidenoarch(none)1.el8ev0.1.480:0.1.48-1.el8ev0scap-security-guide-0:0.1.48-1.el8ev.noarch
Install dnf-plugin-subscription-manager Packagexccdf_org.ssgproject.content_rule_package_dnf-plugin-subscription-manager_installed mediumCCE-82315-3

Install dnf-plugin-subscription-manager Package

Rule IDxccdf_org.ssgproject.content_rule_package_dnf-plugin-subscription-manager_installed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_dnf-plugin-subscription-manager_installed:def:1
Time2020-09-29T11:18:01
Severitymedium
Identifiers and References

Identifiers:  CCE-82315-3

References:  FPT_TUD_EXT.1, FPT_TUD_EXT.2

Description

The dnf-plugin-subscription-manager package can be installed with the following command:

$ sudo yum install dnf-plugin-subscription-manager

Rationale

This package provides plugins to interact with repositories and subscriptions from the Red Hat entitlement platform; contains subscription-manager and product-id plugins.

OVAL test results details

package dnf-plugin-subscription-manager is installed  oval:ssg-test_package_dnf-plugin-subscription-manager_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
dnf-plugin-subscription-managerx86_64(none)1.el8_21.26.170:1.26.17-1.el8_2199e2f91fd431d51dnf-plugin-subscription-manager-0:1.26.17-1.el8_2.x86_64
Ensure gnutls-utils is installedxccdf_org.ssgproject.content_rule_package_gnutls-utils_installed mediumCCE-82395-5

Ensure gnutls-utils is installed

Rule IDxccdf_org.ssgproject.content_rule_package_gnutls-utils_installed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_gnutls-utils_installed:def:1
Time2020-09-29T11:18:01
Severitymedium
Identifiers and References

Identifiers:  CCE-82395-5

References:  FMT_SMF_EXT.1

Description

The gnutls-utils package can be installed with the following command:

$ sudo yum install gnutls-utils

Rationale

GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, OpenPGP and other required structures. This package contains command line TLS client and server and certificate manipulation tools.

OVAL test results details

package gnutls-utils is installed  oval:ssg-test_package_gnutls-utils_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
gnutls-utilsx86_64(none)10.el8_23.6.80:3.6.8-10.el8_20gnutls-utils-0:3.6.8-10.el8_2.x86_64
Install rng-tools Packagexccdf_org.ssgproject.content_rule_package_rng-tools_installed mediumCCE-82968-9

Install rng-tools Package

Rule IDxccdf_org.ssgproject.content_rule_package_rng-tools_installed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_rng-tools_installed:def:1
Time2020-09-29T11:18:01
Severitymedium
Identifiers and References

Identifiers:  CCE-82968-9

References:  SRG-OS-000480-GPOS-00227

Description

The rng-tools package can be installed with the following command:

$ sudo yum install rng-tools

Rationale

rng-tools provides hardware random number generator tools, such as those used in the formation of x509/PKI certificates.

OVAL test results details

package rng-tools is installed  oval:ssg-test_package_rng-tools_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
rng-toolsx86_64(none)3.el86.80:6.8-3.el8199e2f91fd431d51rng-tools-0:6.8-3.el8.x86_64
Install subscription-manager Packagexccdf_org.ssgproject.content_rule_package_subscription-manager_installed mediumCCE-82316-1

Install subscription-manager Package

Rule IDxccdf_org.ssgproject.content_rule_package_subscription-manager_installed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_subscription-manager_installed:def:1
Time2020-09-29T11:18:01
Severitymedium
Identifiers and References

Identifiers:  CCE-82316-1

References:  FPT_TUD_EXT.1, FPT_TUD_EXT.2, SRG-OS-000366-GPOS-00153

Description

The subscription-manager package can be installed with the following command:

$ sudo yum install subscription-manager

Rationale

Red Hat Subscription Manager is a local service which tracks installed products and subscriptions on a local system to help manage subscription assignments. It communicates with the backend subscription service (the Customer Portal or an on-premise server such as Subscription Asset Manager) and works with content management tools such as yum.

OVAL test results details

package subscription-manager is installed  oval:ssg-test_package_subscription-manager_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
subscription-managerx86_64(none)1.el8_21.26.170:1.26.17-1.el8_2199e2f91fd431d51subscription-manager-0:1.26.17-1.el8_2.x86_64
Ensure nss-tools is installedxccdf_org.ssgproject.content_rule_package_nss-tools_installed mediumCCE-82396-3

Ensure nss-tools is installed

Rule IDxccdf_org.ssgproject.content_rule_package_nss-tools_installed
Result
error
Multi-check ruleno
OVAL Definition IDoval:ssg-package_nss-tools_installed:def:1
Time2020-09-29T11:18:08
Severitymedium
Identifiers and References

Identifiers:  CCE-82396-3

References:  FMT_SMF_EXT.1

Description

The nss-tools package can be installed with the following command:

$ sudo yum install nss-tools

Rationale

Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled client and server applications. Install the nss-tools package to install command-line tools to manipulate the NSS certificate and key database.

Evaluation messages
info 
Fix execution completed and returned: 1
info 
Error: There are no enabled repositories in "/etc/yum.repos.d", "/etc/yum/repos.d", "/etc/distro.repos.d".
info 
Failed to verify applied fix: Checking engine returns: fail


Complexity:low
Disruption:low
Strategy:enable

if ! rpm -q --quiet "nss-tools" ; then
    yum install -y "nss-tools"
fi


Complexity:low
Disruption:low
Strategy:enable
- name: Ensure nss-tools is installed
  package:
    name: nss-tools
    state: present
  tags:
    - package_nss-tools_installed
    - medium_severity
    - enable_strategy
    - low_complexity
    - low_disruption
    - no_reboot_needed
    - CCE-82396-3


Complexity:low
Disruption:low
Strategy:enable
include install_nss-tools

class install_nss-tools {
  package { 'nss-tools':
    ensure => 'installed',
  }
}


Complexity:low
Disruption:low
Strategy:enable

package --add=nss-tools
OVAL test results details

package nss-tools is installed  oval:ssg-test_package_nss-tools_installed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_test_package_nss-tools_installed:obj:1 of type rpminfo_object
Name
nss-tools
Install libcap-ng-utils Packagexccdf_org.ssgproject.content_rule_package_libcap-ng-utils_installed mediumCCE-82979-6

Install libcap-ng-utils Package

Rule IDxccdf_org.ssgproject.content_rule_package_libcap-ng-utils_installed
Result
error
Multi-check ruleno
OVAL Definition IDoval:ssg-package_libcap-ng-utils_installed:def:1
Time2020-09-29T11:18:09
Severitymedium
Identifiers and References

Identifiers:  CCE-82979-6

References:  SRG-OS-000445-GPOS-00199

Description

The libcap-ng-utils package can be installed with the following command:

$ sudo yum install libcap-ng-utils

Rationale

libcap-ng-utils contains applications to analyze the posix posix capabilities of all the programs running on a system. libcap-ng-utils also lets system operators set the file system based capabilities.

Evaluation messages
info 
Fix execution completed and returned: 1
info 
Error: There are no enabled repositories in "/etc/yum.repos.d", "/etc/yum/repos.d", "/etc/distro.repos.d".
info 
Failed to verify applied fix: Checking engine returns: fail


Complexity:low
Disruption:low
Strategy:enable

if ! rpm -q --quiet "libcap-ng-utils" ; then
    yum install -y "libcap-ng-utils"
fi


Complexity:low
Disruption:low
Strategy:enable
- name: Ensure libcap-ng-utils is installed
  package:
    name: libcap-ng-utils
    state: present
  tags:
    - package_libcap-ng-utils_installed
    - medium_severity
    - enable_strategy
    - low_complexity
    - low_disruption
    - no_reboot_needed
    - CCE-82979-6


Complexity:low
Disruption:low
Strategy:enable
include install_libcap-ng-utils

class install_libcap-ng-utils {
  package { 'libcap-ng-utils':
    ensure => 'installed',
  }
}


Complexity:low
Disruption:low
Strategy:enable

package --add=libcap-ng-utils
OVAL test results details

package libcap-ng-utils is installed  oval:ssg-test_package_libcap-ng-utils_installed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_test_package_libcap-ng-utils_installed:obj:1 of type rpminfo_object
Name
libcap-ng-utils
Uninstall abrt-addon-python Packagexccdf_org.ssgproject.content_rule_package_abrt-addon-python_removed lowCCE-82923-4

Uninstall abrt-addon-python Package

Rule IDxccdf_org.ssgproject.content_rule_package_abrt-addon-python_removed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_abrt-addon-python_removed:def:1
Time2020-09-29T11:18:01
Severitylow
Identifiers and References

Identifiers:  CCE-82923-4

References:  SRG-OS-000095-GPOS-00049

Description

The abrt-addon-python package can be removed with the following command:

$ sudo yum erase abrt-addon-python

Rationale

abrt-addon-python contains python hook and python analyzer plugin for handling uncaught exceptions in python programs.

OVAL test results details

package abrt-addon-python is removed  oval:ssg-test_package_abrt-addon-python_removed:tst:1  true

No items have been found conforming to the following objects:
Object oval:ssg-obj_test_package_abrt-addon-python_removed:obj:1 of type rpminfo_object
Name
abrt-addon-python
Uninstall abrt-plugin-logger Packagexccdf_org.ssgproject.content_rule_package_abrt-plugin-logger_removed lowCCE-82913-5

Uninstall abrt-plugin-logger Package

Rule IDxccdf_org.ssgproject.content_rule_package_abrt-plugin-logger_removed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_abrt-plugin-logger_removed:def:1
Time2020-09-29T11:18:01
Severitylow
Identifiers and References

Identifiers:  CCE-82913-5

References:  SRG-OS-000095-GPOS-00049

Description

The abrt-plugin-logger package can be removed with the following command:

$ sudo yum erase abrt-plugin-logger

Rationale

abrt-plugin-logger is an ABRT plugin which writes a report to a specified file.

OVAL test results details

package abrt-plugin-logger is removed  oval:ssg-test_package_abrt-plugin-logger_removed:tst:1  true

No items have been found conforming to the following objects:
Object oval:ssg-obj_test_package_abrt-plugin-logger_removed:obj:1 of type rpminfo_object
Name
abrt-plugin-logger
Uninstall abrt-addon-kerneloops Packagexccdf_org.ssgproject.content_rule_package_abrt-addon-kerneloops_removed lowCCE-82926-7

Uninstall abrt-addon-kerneloops Package

Rule IDxccdf_org.ssgproject.content_rule_package_abrt-addon-kerneloops_removed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_abrt-addon-kerneloops_removed:def:1
Time2020-09-29T11:18:01
Severitylow
Identifiers and References

Identifiers:  CCE-82926-7

References:  SRG-OS-000095-GPOS-00049

Description

The abrt-addon-kerneloops package can be removed with the following command:

$ sudo yum erase abrt-addon-kerneloops

Rationale

abrt-addon-kerneloops contains plugins for collecting kernel crash information and reporter plugin which sends this information to a specified server, usually to kerneloops.org.

OVAL test results details

package abrt-addon-kerneloops is removed  oval:ssg-test_package_abrt-addon-kerneloops_removed:tst:1  true

No items have been found conforming to the following objects:
Object oval:ssg-obj_test_package_abrt-addon-kerneloops_removed:obj:1 of type rpminfo_object
Name
abrt-addon-kerneloops
Uninstall abrt-cli Packagexccdf_org.ssgproject.content_rule_package_abrt-cli_removed lowCCE-82907-7

Uninstall abrt-cli Package

Rule IDxccdf_org.ssgproject.content_rule_package_abrt-cli_removed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_abrt-cli_removed:def:1
Time2020-09-29T11:18:01
Severitylow
Identifiers and References

Identifiers:  CCE-82907-7

References:  SRG-OS-000095-GPOS-00049

Description

The abrt-cli package can be removed with the following command:

$ sudo yum erase abrt-cli

Rationale

abrt-cli contains a command line client for controlling abrt daemon over sockets.

OVAL test results details

package abrt-cli is removed  oval:ssg-test_package_abrt-cli_removed:tst:1  true

No items have been found conforming to the following objects:
Object oval:ssg-obj_test_package_abrt-cli_removed:obj:1 of type rpminfo_object
Name
abrt-cli
Uninstall gssproxy Packagexccdf_org.ssgproject.content_rule_package_gssproxy_removed lowCCE-82943-2

Uninstall gssproxy Package

Rule IDxccdf_org.ssgproject.content_rule_package_gssproxy_removed
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-package_gssproxy_removed:def:1
Time2020-09-29T11:19:38
Severitylow
Identifiers and References

Identifiers:  CCE-82943-2

References:  SRG-OS-000095-GPOS-00049

Description

The gssproxy package can be removed with the following command:

$ sudo yum erase gssproxy

Rationale

gssproxy is a proxy for GSS API credential handling.

Evaluation messages
info 
Fix execution completed and returned: 0
info 
Dependencies resolved.
=====================================================================================================================================
 Package                                            Arch    Version                                           Repository         Size
=====================================================================================================================================
Removing:
 gssproxy                                           x86_64  0.8.0-15.el8                                      @anaconda         266 k
Removing dependent packages:
 rhvm-branding-rhv                                  noarch  4.4.3-1.el8ev                                     @koji-override-1  364 k
Removing unused dependencies:
 adobe-mappings-cmap                                noarch  20171205-3.el8                                    @koji-override-1   13 M
 adobe-mappings-cmap-deprecated                     noarch  20171205-3.el8                                    @koji-override-1  583 k
 adobe-mappings-pdf                                 noarch  20180407-1.el8                                    @koji-override-1  4.2 M
 ansible                                            noarch  2.9.9-1.el8ae                                     @koji-override-1   96 M
 ansible-runner                                     noarch  1.4.5-1.el8ar                                     @koji-override-1    0  
 ansible-runner-service                             noarch  1.0.2-1.el8ev                                     @koji-override-1  252 k
 aopalliance                                        noarch  1.0-17.module+el8+2598+06babf2e                   @koji-override-1   11 k
 apache-commons-codec                               noarch  1.11-3.module+el8+2598+06babf2e                   @koji-override-1  361 k
 apache-commons-collections                         noarch  3.2.2-10.module+el8.1.0+3366+6dfb954c             @koji-override-1  616 k
 apache-commons-compress                            noarch  1.18-1.el8ev                                      @koji-override-1  593 k
 apache-commons-configuration                       noarch  1.10-1.el8ev                                      @koji-override-1  408 k
 apache-commons-io                                  noarch  1:2.6-3.module+el8+2598+06babf2e                  @koji-override-1  281 k
 apache-commons-jxpath                              noarch  1.3-29.el8ev                                      @koji-override-1  325 k
 apache-commons-lang                                noarch  2.6-21.module+el8.1.0+3366+6dfb954c               @koji-override-1  314 k
 apache-commons-logging                             noarch  1.2-13.module+el8+2598+06babf2e                   @koji-override-1  180 k
 apache-sshd                                        noarch  2.2.0-1.el8ev                                     @koji-override-1  3.3 M
 apr                                                x86_64  1.6.3-9.el8                                       @koji-override-1  293 k
 apr-util                                           x86_64  1.6.1-6.el8                                       @koji-override-1  230 k
 asciidoc                                           noarch  8.6.10-0.5.20180627gitf7c2274.el8                 @koji-override-1  790 k
 atk                                                x86_64  2.28.1-1.el8                                      @koji-override-1  1.2 M
 autogen-libopts                                    x86_64  5.18.12-7.el8                                     @koji-override-1  146 k
 bea-stax-api                                       noarch  1.2.0-16.module+el8.1.0+3366+6dfb954c             @koji-override-1   39 k
 boost-regex                                        x86_64  1.66.0-7.el8                                      @koji-override-1  1.1 M
 cockpit-dashboard                                  noarch  211.3-1.el8                                       @koji-override-1  172 k
 collectd                                           x86_64  5.11.0-2.el8ost                                   @koji-override-1  2.0 M
 collectd-disk                                      x86_64  5.11.0-2.el8ost                                   @koji-override-1   20 k
 collectd-postgresql                                x86_64  5.11.0-2.el8ost                                   @koji-override-1   48 k
 collectd-write_http                                x86_64  5.11.0-2.el8ost                                   @koji-override-1   40 k
 collectd-write_syslog                              x86_64  5.11.0-2.el8ost                                   @koji-override-1   19 k
 ctags                                              x86_64  5.8-22.el8                                        @koji-override-1  403 k
 docbook-dtds                                       noarch  1.0-69.el8                                        @koji-override-1  8.3 M
 docbook-style-xsl                                  noarch  1.79.2-7.el8                                      @koji-override-1   16 M
 eap7-FastInfoset                                   noarch  1.2.13-10.redhat_1.1.el8eap                       @koji-override-1  557 k
 eap7-activemq-artemis-cli                          noarch  2.9.0-4.redhat_00010.1.el8eap                     @koji-override-1  472 k
 eap7-activemq-artemis-commons                      noarch  2.9.0-4.redhat_00010.1.el8eap                     @koji-override-1  613 k
 eap7-activemq-artemis-core-client                  noarch  2.9.0-4.redhat_00010.1.el8eap                     @koji-override-1  1.2 M
 eap7-activemq-artemis-dto                          noarch  2.9.0-4.redhat_00010.1.el8eap                     @koji-override-1   54 k
 eap7-activemq-artemis-hornetq-protocol             noarch  2.9.0-4.redhat_00010.1.el8eap                     @koji-override-1   27 k
 eap7-activemq-artemis-hqclient-protocol            noarch  2.9.0-4.redhat_00010.1.el8eap                     @koji-override-1   37 k
 eap7-activemq-artemis-jdbc-store                   noarch  2.9.0-4.redhat_00010.1.el8eap                     @koji-override-1  158 k
 eap7-activemq-artemis-jms-client                   noarch  2.9.0-4.redhat_00010.1.el8eap                     @koji-override-1  312 k
 eap7-activemq-artemis-jms-server                   noarch  2.9.0-4.redhat_00010.1.el8eap                     @koji-override-1  211 k
 eap7-activemq-artemis-journal                      noarch  2.9.0-4.redhat_00010.1.el8eap                     @koji-override-1  353 k
 eap7-activemq-artemis-native                       noarch  1:1.0.0.00003-2.redhat_00001.1.el8eap             @koji-override-1   43 k
 eap7-activemq-artemis-ra                           noarch  2.9.0-4.redhat_00010.1.el8eap                     @koji-override-1  269 k
 eap7-activemq-artemis-selector                     noarch  2.9.0-4.redhat_00010.1.el8eap                     @koji-override-1  177 k
 eap7-activemq-artemis-server                       noarch  2.9.0-4.redhat_00010.1.el8eap                     @koji-override-1  2.9 M
 eap7-activemq-artemis-service-extensions           noarch  2.9.0-4.redhat_00010.1.el8eap                     @koji-override-1   64 k
 eap7-activemq-artemis-tools                        noarch  2.9.0-4.redhat_00010.1.el8eap                     @koji-override-1   29 k
 eap7-aesh-extensions                               noarch  1.8.0-1.redhat_00001.1.el8eap                     @koji-override-1  280 k
 eap7-aesh-readline                                 noarch  2.0.0-1.redhat_00001.1.el8eap                     @koji-override-1  527 k
 eap7-agroal-api                                    noarch  1.3.0-1.redhat_00001.1.el8eap                     @koji-override-1   65 k
 eap7-agroal-narayana                               noarch  1.3.0-1.redhat_00001.1.el8eap                     @koji-override-1   18 k
 eap7-agroal-pool                                   noarch  1.3.0-1.redhat_00001.1.el8eap                     @koji-override-1  134 k
 eap7-antlr                                         noarch  2.7.7-54.redhat_7.1.el8eap                        @koji-override-1  1.0 M
 eap7-apache-commons-beanutils                      noarch  1.9.4-1.redhat_00002.1.el8eap                     @koji-override-1  577 k
 eap7-apache-commons-cli                            noarch  1.3.1-3.redhat_2.1.el8eap                         @koji-override-1  142 k
 eap7-apache-commons-codec                          noarch  1.11.0-2.redhat_00001.1.el8eap                    @koji-override-1  682 k
 eap7-apache-commons-collections                    noarch  3.2.2-9.redhat_2.1.el8eap                         @koji-override-1  1.2 M
 eap7-apache-commons-io                             noarch  2.5.0-4.redhat_3.1.el8eap                         @koji-override-1  524 k
 eap7-apache-commons-lang                           noarch  3.9.0-1.redhat_00001.1.el8eap                     @koji-override-1  1.1 M
 eap7-apache-commons-lang2                          noarch  2.6.0-1.redhat_7.1.el8eap                         @koji-override-1  667 k
 eap7-apache-cxf                                    noarch  3.3.5-1.redhat_00001.1.el8eap                     @koji-override-1  2.4 M
 eap7-apache-cxf-rt                                 noarch  3.3.5-1.redhat_00001.1.el8eap                     @koji-override-1  5.8 M
 eap7-apache-cxf-services                           noarch  3.3.5-1.redhat_00001.1.el8eap                     @koji-override-1  664 k
 eap7-apache-cxf-tools                              noarch  3.3.5-1.redhat_00001.1.el8eap                     @koji-override-1  1.1 M
 eap7-apache-mime4j                                 noarch  0.6.0-4.redhat_7.1.el8eap                         @koji-override-1  697 k
 eap7-artemis-wildfly-integration                   noarch  1.0.2-4.redhat_1.1.el8eap                         @koji-override-1   70 k
 eap7-atinject                                      noarch  1.0.0-4.redhat_00002.1.el8eap                     @koji-override-1   34 k
 eap7-avro                                          noarch  1.7.6-7.redhat_2.1.el8eap                         @koji-override-1  776 k
 eap7-azure-storage                                 noarch  6.1.0-1.redhat_1.1.el8eap                         @koji-override-1  1.3 M
 eap7-bouncycastle-mail                             noarch  1.60.0-2.redhat_00002.1.el8eap                    @koji-override-1  205 k
 eap7-bouncycastle-pkix                             noarch  1.60.0-2.redhat_00002.1.el8eap                    @koji-override-1  1.4 M
 eap7-bouncycastle-prov                             noarch  1.60.0-2.redhat_00002.1.el8eap                    @koji-override-1  8.2 M
 eap7-byte-buddy                                    noarch  1.9.11-1.redhat_00002.1.el8eap                    @koji-override-1  4.3 M
 eap7-caffeine                                      noarch  2.6.2-3.redhat_1.1.el8eap                         @koji-override-1  1.3 M
 eap7-cal10n                                        noarch  0.8.1-6.redhat_1.1.el8eap                         @koji-override-1   75 k
 eap7-codehaus-jackson-core-asl                     noarch  1.9.13-10.redhat_00007.1.el8eap                   @koji-override-1  586 k
 eap7-codehaus-jackson-jaxrs                        noarch  1.9.13-10.redhat_00007.1.el8eap                   @koji-override-1   30 k
 eap7-codehaus-jackson-mapper-asl                   noarch  1.9.13-10.redhat_00007.1.el8eap                   @koji-override-1  1.3 M
 eap7-codehaus-jackson-xc                           noarch  1.9.13-10.redhat_00007.1.el8eap                   @koji-override-1   43 k
 eap7-codemodel                                     noarch  2.3.3-4.b02_redhat_00001.1.el8eap                 @koji-override-1  279 k
 eap7-commons-logging-jboss-logging                 noarch  1.0.0-1.Final_redhat_1.1.el8eap                   @koji-override-1   40 k
 eap7-cryptacular                                   noarch  1.2.4-1.redhat_00001.1.el8eap                     @koji-override-1  311 k
 eap7-cxf-xjc-boolean                               noarch  3.3.0-1.redhat_00001.1.el8eap                     @koji-override-1   27 k
 eap7-cxf-xjc-bug986                                noarch  3.3.0-1.redhat_00001.1.el8eap                     @koji-override-1   23 k
 eap7-cxf-xjc-dv                                    noarch  3.3.0-1.redhat_00001.1.el8eap                     @koji-override-1   33 k
 eap7-cxf-xjc-runtime                               noarch  3.3.0-1.redhat_00001.1.el8eap                     @koji-override-1   21 k
 eap7-cxf-xjc-ts                                    noarch  3.3.0-1.redhat_00001.1.el8eap                     @koji-override-1   24 k
 eap7-dom4j                                         noarch  2.1.1-2.redhat_00001.1.el8eap                     @koji-override-1  751 k
 eap7-ecj                                           noarch  4.6.1-3.redhat_1.1.el8eap                         @koji-override-1  4.0 M
 eap7-eclipse-jgit                                  noarch  5.0.2.201807311906-2.r_redhat_00001.1.el8eap      @koji-override-1  4.8 M
 eap7-glassfish-concurrent                          noarch  1.0.0-4.redhat_1.1.el8eap                         @koji-override-1   55 k
 eap7-glassfish-jaf                                 noarch  1.2.1-1.redhat_00002.1.el8eap                     @koji-override-1  134 k
 eap7-glassfish-javamail                            noarch  1.6.4-2.redhat_00001.1.el8eap                     @koji-override-1  732 k
 eap7-glassfish-jsf                                 noarch  2.3.9-10.SP09_redhat_00001.1.el8eap               @koji-override-1  4.8 M
 eap7-glassfish-json                                noarch  1.1.6-2.redhat_00001.1.el8eap                     @koji-override-1  216 k
 eap7-gnu-getopt                                    noarch  1.0.13-6.redhat_5.1.el8eap                        @koji-override-1   79 k
 eap7-gson                                          noarch  2.8.2-1.redhat_5.1.el8eap                         @koji-override-1  449 k
 eap7-guava                                         noarch  25.0.0-2.redhat_1.1.el8eap                        @koji-override-1  4.2 M
 eap7-h2database                                    noarch  1.4.193-6.redhat_2.1.el8eap                       @koji-override-1  3.4 M
 eap7-hal-console                                   noarch  3.2.8-1.Final_redhat_00001.1.el8eap               @koji-override-1   59 M
 eap7-hibernate-beanvalidation-api                  noarch  2.0.2-1.redhat_00001.1.el8eap                     @koji-override-1  198 k
 eap7-hibernate-commons-annotations                 noarch  5.0.5-1.Final_redhat_00002.1.el8eap               @koji-override-1  151 k
 eap7-hibernate-core                                noarch  5.3.16-1.Final_redhat_00001.1.el8eap              @koji-override-1   11 M
 eap7-hibernate-entitymanager                       noarch  5.3.16-1.Final_redhat_00001.1.el8eap              @koji-override-1  1.4 k
 eap7-hibernate-envers                              noarch  5.3.16-1.Final_redhat_00001.1.el8eap              @koji-override-1  812 k
 eap7-hibernate-search-backend-jms                  noarch  5.10.7-1.Final_redhat_00001.1.el8eap              @koji-override-1   30 k
 eap7-hibernate-search-engine                       noarch  5.10.7-1.Final_redhat_00001.1.el8eap              @koji-override-1  2.2 M
 eap7-hibernate-search-orm                          noarch  5.10.7-1.Final_redhat_00001.1.el8eap              @koji-override-1  265 k
 eap7-hibernate-search-serialization-avro           noarch  5.10.7-1.Final_redhat_00001.1.el8eap              @koji-override-1  124 k
 eap7-hibernate-validator                           noarch  6.0.18-1.Final_redhat_00001.1.el8eap              @koji-override-1  2.0 M
 eap7-hibernate-validator-cdi                       noarch  6.0.18-1.Final_redhat_00001.1.el8eap              @koji-override-1   63 k
 eap7-hornetq-commons                               noarch  2.4.7-7.Final_redhat_2.1.el8eap                   @koji-override-1  202 k
 eap7-hornetq-core-client                           noarch  2.4.7-7.Final_redhat_2.1.el8eap                   @koji-override-1  1.0 M
 eap7-hornetq-jms-client                            noarch  2.4.7-7.Final_redhat_2.1.el8eap                   @koji-override-1  242 k
 eap7-httpcomponents-asyncclient                    noarch  4.1.4-1.redhat_00001.1.el8eap                     @koji-override-1  344 k
 eap7-httpcomponents-client                         noarch  4.5.4-1.redhat_00001.1.el8eap                     @koji-override-1  1.7 M
 eap7-httpcomponents-core                           noarch  4.4.5-1.redhat_00001.1.el8eap                     @koji-override-1  1.5 M
 eap7-infinispan-cachestore-jdbc                    noarch  9.4.18-1.Final_redhat_00001.1.el8eap              @koji-override-1  191 k
 eap7-infinispan-cachestore-remote                  noarch  9.4.18-1.Final_redhat_00001.1.el8eap              @koji-override-1  145 k
 eap7-infinispan-client-hotrod                      noarch  9.4.18-1.Final_redhat_00001.1.el8eap              @koji-override-1  945 k
 eap7-infinispan-commons                            noarch  9.4.18-1.Final_redhat_00001.1.el8eap              @koji-override-1  843 k
 eap7-infinispan-core                               noarch  9.4.18-1.Final_redhat_00001.1.el8eap              @koji-override-1  6.5 M
 eap7-infinispan-hibernate-cache-commons            noarch  9.4.18-1.Final_redhat_00001.1.el8eap              @koji-override-1  226 k
 eap7-infinispan-hibernate-cache-spi                noarch  9.4.18-1.Final_redhat_00001.1.el8eap              @koji-override-1   10 k
 eap7-infinispan-hibernate-cache-v53                noarch  9.4.18-1.Final_redhat_00001.1.el8eap              @koji-override-1   96 k
 eap7-ironjacamar-common-api                        noarch  1.4.20-1.Final_redhat_00001.1.el8eap              @koji-override-1  306 k
 eap7-ironjacamar-common-impl                       noarch  1.4.20-1.Final_redhat_00001.1.el8eap              @koji-override-1  400 k
 eap7-ironjacamar-common-spi                        noarch  1.4.20-1.Final_redhat_00001.1.el8eap              @koji-override-1   12 k
 eap7-ironjacamar-core-api                          noarch  1.4.20-1.Final_redhat_00001.1.el8eap              @koji-override-1  152 k
 eap7-ironjacamar-core-impl                         noarch  1.4.20-1.Final_redhat_00001.1.el8eap              @koji-override-1  876 k
 eap7-ironjacamar-deployers-common                  noarch  1.4.20-1.Final_redhat_00001.1.el8eap              @koji-override-1  107 k
 eap7-ironjacamar-jdbc                              noarch  1.4.20-1.Final_redhat_00001.1.el8eap              @koji-override-1  435 k
 eap7-ironjacamar-validator                         noarch  1.4.20-1.Final_redhat_00001.1.el8eap              @koji-override-1  137 k
 eap7-istack-commons-runtime                        noarch  3.0.10-1.redhat_00001.1.el8eap                    @koji-override-1   58 k
 eap7-istack-commons-tools                          noarch  3.0.10-1.redhat_00001.1.el8eap                    @koji-override-1   46 k
 eap7-jackson-annotations                           noarch  2.10.3-1.redhat_00001.1.el8eap                    @koji-override-1  153 k
 eap7-jackson-core                                  noarch  2.10.3-1.redhat_00001.1.el8eap                    @koji-override-1  733 k
 eap7-jackson-coreutils                             noarch  1.0.0-1.redhat_1.1.el8eap                         @koji-override-1   50 k
 eap7-jackson-databind                              noarch  2.10.3-1.redhat_00001.1.el8eap                    @koji-override-1  2.5 M
 eap7-jackson-datatype-jdk8                         noarch  2.10.3-1.redhat_00001.1.el8eap                    @koji-override-1   76 k
 eap7-jackson-datatype-jsr310                       noarch  2.10.3-1.redhat_00001.1.el8eap                    @koji-override-1  196 k
 eap7-jackson-jaxrs-base                            noarch  2.10.3-1.redhat_00001.1.el8eap                    @koji-override-1   86 k
 eap7-jackson-jaxrs-json-provider                   noarch  2.10.3-1.redhat_00001.1.el8eap                    @koji-override-1   30 k
 eap7-jackson-module-jaxb-annotations               noarch  2.10.3-1.redhat_00001.1.el8eap                    @koji-override-1   68 k
 eap7-jaegertracing-jaeger-client-java-core         noarch  0.34.3-1.redhat_00001.1.el8eap                    @koji-override-1  217 k
 eap7-jaegertracing-jaeger-client-java-thrift       noarch  0.34.3-1.redhat_00001.1.el8eap                    @koji-override-1  862 k
 eap7-jakarta-el                                    noarch  3.0.3-1.redhat_00002.1.el8eap                     @koji-override-1  482 k
 eap7-jakarta-security-enterprise-api               noarch  1.0.2-3.redhat_00001.1.el8eap                     @koji-override-1  114 k
 eap7-jandex                                        noarch  2.1.2-1.Final_redhat_00001.1.el8eap               @koji-override-1  338 k
 eap7-jansi                                         noarch  1.18.0-1.redhat_00001.1.el8eap                    @koji-override-1  272 k
 eap7-jasypt                                        noarch  1.9.3-1.redhat_00001.1.el8eap                     @koji-override-1  382 k
 eap7-java-classmate                                noarch  1.3.4-1.redhat_1.1.el8eap                         @koji-override-1  128 k
 eap7-javaee-jpa-spec                               noarch  2.2.3-1.redhat_00001.1.el8eap                     @koji-override-1  421 k
 eap7-javaee-security-api                           noarch  1.0.0-2.redhat_1.1.el8eap                         @koji-override-1  142 k
 eap7-javaee-security-soteria-enterprise            noarch  1.0.1-3.redhat_00002.1.el8eap                     @koji-override-1  246 k
 eap7-javaewah                                      noarch  1.1.6-1.redhat_00001.1.el8eap                     @koji-override-1  269 k
 eap7-javapackages-tools                            noarch  3.4.1-5.15.6.el8eap                               @koji-override-1  145 k
 eap7-javassist                                     noarch  3.23.2-2.GA_redhat_00001.1.el8eap                 @koji-override-1  1.3 M
 eap7-jaxb-jxc                                      noarch  2.3.3-4.b02_redhat_00001.1.el8eap                 @koji-override-1  201 k
 eap7-jaxb-runtime                                  noarch  2.3.3-4.b02_redhat_00001.1.el8eap                 @koji-override-1  1.7 M
 eap7-jaxb-xjc                                      noarch  2.3.3-4.b02_redhat_00001.1.el8eap                 @koji-override-1  1.5 M
 eap7-jaxbintros                                    noarch  1.0.3-1.GA_redhat_00001.1.el8eap                  @koji-override-1   65 k
 eap7-jaxen                                         noarch  1.1.6-14.redhat_2.1.el8eap                        @koji-override-1  621 k
 eap7-jberet-core                                   noarch  1.3.5-1.Final_redhat_00001.1.el8eap               @koji-override-1  545 k
 eap7-jboss-aesh                                    noarch  2.4.0-1.redhat_00001.1.el8eap                     @koji-override-1  653 k
 eap7-jboss-annotations-api_1.3_spec                noarch  2.0.1-2.Final_redhat_00001.1.el8eap               @koji-override-1   65 k
 eap7-jboss-batch-api_1.0_spec                      noarch  2.0.0-1.Final_redhat_00001.1.el8eap               @koji-override-1  117 k
 eap7-jboss-classfilewriter                         noarch  1.2.4-1.Final_redhat_00001.1.el8eap               @koji-override-1  207 k
 eap7-jboss-common-beans                            noarch  2.0.1-1.Final_redhat_00001.1.el8eap               @koji-override-1   89 k
 eap7-jboss-concurrency-api_1.0_spec                noarch  2.0.0-1.Final_redhat_00001.1.el8eap               @koji-override-1   65 k
 eap7-jboss-connector-api_1.7_spec                  noarch  2.0.0-2.Final_redhat_00001.1.el8eap               @koji-override-1  199 k
 eap7-jboss-dmr                                     noarch  1.5.0-2.Final_redhat_1.1.el8eap                   @koji-override-1  567 k
 eap7-jboss-ejb-api_3.2_spec                        noarch  2.0.0-1.Final_redhat_00001.1.el8eap               @koji-override-1  175 k
 eap7-jboss-ejb-client                              noarch  4.0.31-1.Final_redhat_00001.1.el8eap              @koji-override-1  700 k
 eap7-jboss-ejb3-ext-api                            noarch  2.3.0-1.Final_redhat_00001.1.el8eap               @koji-override-1   29 k
 eap7-jboss-el-api_3.0_spec                         noarch  2.0.0-2.Final_redhat_00001.1.el8eap               @koji-override-1  219 k
 eap7-jboss-genericjms                              noarch  2.0.4-1.Final_redhat_00001.1.el8eap               @koji-override-1  395 k
 eap7-jboss-iiop-client                             noarch  1.0.1-3.Final_redhat_1.1.el8eap                   @koji-override-1   16 k
 eap7-jboss-interceptors-api_1.2_spec               noarch  2.0.0-3.Final_redhat_00002.1.el8eap               @koji-override-1   62 k
 eap7-jboss-invocation                              noarch  1.5.2-1.Final_redhat_00001.1.el8eap               @koji-override-1  140 k
 eap7-jboss-j2eemgmt-api_1.1_spec                   noarch  2.0.0-2.Final_redhat_00001.1.el8eap               @koji-override-1   53 k
 eap7-jboss-jacc-api_1.5_spec                       noarch  2.0.0-2.Final_redhat_00001.1.el8eap               @koji-override-1  137 k
 eap7-jboss-jaspi-api_1.1_spec                      noarch  2.0.1-2.Final_redhat_00001.1.el8eap               @koji-override-1  141 k
 eap7-jboss-jaxb-api_2.3_spec                       noarch  1.0.1-1.Final_redhat_1.1.el8eap                   @koji-override-1  410 k
 eap7-jboss-jaxrpc-api_1.1_spec                     noarch  2.0.0-1.Final_redhat_00001.1.el8eap               @koji-override-1   99 k
 eap7-jboss-jaxrs-api_2.1_spec                      noarch  2.0.1-1.Final_redhat_00001.1.el8eap               @koji-override-1  387 k
 eap7-jboss-jaxws-api_2.3_spec                      noarch  1.0.0-1.Final_redhat_1.1.el8eap                   @koji-override-1  224 k
 eap7-jboss-jms-api_2.0_spec                        noarch  2.0.0-1.Final_redhat_00001.1.el8eap               @koji-override-1  234 k
 eap7-jboss-jsf-api_2.3_spec                        noarch  3.0.0-3.SP02_redhat_00001.1.el8eap                @koji-override-1  1.8 M
 eap7-jboss-jsp-api_2.3_spec                        noarch  2.0.0-1.Final_redhat_00001.1.el8eap               @koji-override-1  148 k
 eap7-jboss-logging                                 noarch  3.4.1-2.Final_redhat_00001.1.el8eap               @koji-override-1  108 k
 eap7-jboss-logmanager                              noarch  2.1.14-1.Final_redhat_00001.1.el8eap              @koji-override-1  656 k
 eap7-jboss-marshalling                             noarch  2.0.9-1.Final_redhat_00001.1.el8eap               @koji-override-1  389 k
 eap7-jboss-marshalling-river                       noarch  2.0.9-1.Final_redhat_00001.1.el8eap               @koji-override-1  134 k
 eap7-jboss-metadata-appclient                      noarch  13.0.0-1.Final_redhat_00001.1.el8eap              @koji-override-1   55 k
 eap7-jboss-metadata-common                         noarch  13.0.0-1.Final_redhat_00001.1.el8eap              @koji-override-1  967 k
 eap7-jboss-metadata-ear                            noarch  13.0.0-1.Final_redhat_00001.1.el8eap              @koji-override-1  167 k
 eap7-jboss-metadata-ejb                            noarch  13.0.0-1.Final_redhat_00001.1.el8eap              @koji-override-1  1.0 M
 eap7-jboss-metadata-web                            noarch  13.0.0-1.Final_redhat_00001.1.el8eap              @koji-override-1  955 k
 eap7-jboss-modules                                 noarch  1.10.0-1.Final_redhat_00001.1.el8eap              @koji-override-1  849 k
 eap7-jboss-msc                                     noarch  1.4.11-1.Final_redhat_00001.1.el8eap              @koji-override-1  409 k
 eap7-jboss-openjdk-orb                             noarch  8.1.4-3.Final_redhat_00002.1.el8eap               @koji-override-1  7.8 M
 eap7-jboss-remoting                                noarch  5.0.18-1.Final_redhat_00001.1.el8eap              @koji-override-1  519 k
 eap7-jboss-remoting-jmx                            noarch  3.0.4-1.Final_redhat_00001.1.el8eap               @koji-override-1  433 k
 eap7-jboss-saaj-api_1.3_spec                       noarch  1.0.6-1.Final_redhat_1.1.el8eap                   @koji-override-1  151 k
 eap7-jboss-saaj-api_1.4_spec                       noarch  1.0.1-1.Final_redhat_00001.1.el8eap               @koji-override-1  107 k
 eap7-jboss-seam-int                                noarch  7.0.0-6.GA_redhat_2.1.el8eap                      @koji-override-1   22 k
 eap7-jboss-security-negotiation                    noarch  3.0.6-1.Final_redhat_00001.1.el8eap               @koji-override-1  274 k
 eap7-jboss-security-xacml                          noarch  2.0.8-17.Final_redhat_8.1.el8eap                  @koji-override-1  1.2 M
 eap7-jboss-server-migration                        noarch  1.7.1-5.Final_redhat_00006.1.el8eap               @koji-override-1    0  
 eap7-jboss-server-migration-cli                    noarch  1.7.1-5.Final_redhat_00006.1.el8eap               @koji-override-1  125 k
 eap7-jboss-server-migration-core                   noarch  1.7.1-5.Final_redhat_00006.1.el8eap               @koji-override-1  367 k
 eap7-jboss-server-migration-eap6.4                 noarch  1.7.1-5.Final_redhat_00006.1.el8eap               @koji-override-1   12 k
 eap7-jboss-server-migration-eap6.4-to-eap7.3       noarch  1.7.1-5.Final_redhat_00006.1.el8eap               @koji-override-1   26 k
 eap7-jboss-server-migration-eap7.0                 noarch  1.7.1-5.Final_redhat_00006.1.el8eap               @koji-override-1   29 k
 eap7-jboss-server-migration-eap7.1                 noarch  1.7.1-5.Final_redhat_00006.1.el8eap               @koji-override-1   39 k
 eap7-jboss-server-migration-eap7.2                 noarch  1.7.1-5.Final_redhat_00006.1.el8eap               @koji-override-1   17 k
 eap7-jboss-server-migration-eap7.2-to-eap7.3       noarch  1.7.1-5.Final_redhat_00006.1.el8eap               @koji-override-1   12 k
 eap7-jboss-server-migration-eap7.3-server          noarch  1.7.1-5.Final_redhat_00006.1.el8eap               @koji-override-1   17 k
 eap7-jboss-server-migration-wildfly10.0            noarch  1.7.1-5.Final_redhat_00006.1.el8eap               @koji-override-1  666 k
 eap7-jboss-server-migration-wildfly10.1            noarch  1.7.1-5.Final_redhat_00006.1.el8eap               @koji-override-1   54 k
 eap7-jboss-server-migration-wildfly11.0            noarch  1.7.1-5.Final_redhat_00006.1.el8eap               @koji-override-1   92 k
 eap7-jboss-server-migration-wildfly12.0            noarch  1.7.1-5.Final_redhat_00006.1.el8eap               @koji-override-1   16 k
 eap7-jboss-server-migration-wildfly13.0-server     noarch  1.7.1-5.Final_redhat_00006.1.el8eap               @koji-override-1   48 k
 eap7-jboss-server-migration-wildfly14.0-server     noarch  1.7.1-5.Final_redhat_00006.1.el8eap               @koji-override-1   29 k
 eap7-jboss-server-migration-wildfly15.0-server     noarch  1.7.1-5.Final_redhat_00006.1.el8eap               @koji-override-1   21 k
 eap7-jboss-server-migration-wildfly16.0-server     noarch  1.7.1-5.Final_redhat_00006.1.el8eap               @koji-override-1   13 k
 eap7-jboss-server-migration-wildfly17.0-server     noarch  1.7.1-5.Final_redhat_00006.1.el8eap               @koji-override-1   16 k
 eap7-jboss-server-migration-wildfly18.0-server     noarch  1.7.1-5.Final_redhat_00006.1.el8eap               @koji-override-1   13 k
 eap7-jboss-server-migration-wildfly8.2             noarch  1.7.1-5.Final_redhat_00006.1.el8eap               @koji-override-1   14 k
 eap7-jboss-server-migration-wildfly9.0             noarch  1.7.1-5.Final_redhat_00006.1.el8eap               @koji-override-1   12 k
 eap7-jboss-servlet-api_4.0_spec                    noarch  2.0.0-2.Final_redhat_00001.1.el8eap               @koji-override-1  254 k
 eap7-jboss-stdio                                   noarch  1.1.0-1.Final_redhat_00001.1.el8eap               @koji-override-1   37 k
 eap7-jboss-threads                                 noarch  2.3.3-1.Final_redhat_00001.1.el8eap               @koji-override-1  288 k
 eap7-jboss-transaction-api_1.3_spec                noarch  2.0.0-3.Final_redhat_00002.1.el8eap               @koji-override-1   48 k
 eap7-jboss-transaction-spi                         noarch  7.6.0-2.Final_redhat_1.1.el8eap                   @koji-override-1   85 k
 eap7-jboss-vfs                                     noarch  3.2.15-1.Final_redhat_00001.1.el8eap              @koji-override-1  250 k
 eap7-jboss-websocket-api_1.1_spec                  noarch  2.0.0-1.Final_redhat_00001.1.el8eap               @koji-override-1   78 k
 eap7-jboss-weld-3.1-api-weld-api                   noarch  3.1.0-6.SP2_redhat_00001.1.el8eap                 @koji-override-1   77 k
 eap7-jboss-weld-3.1-api-weld-spi                   noarch  3.1.0-6.SP2_redhat_00001.1.el8eap                 @koji-override-1  195 k
 eap7-jboss-xnio-base                               noarch  3.7.7-1.Final_redhat_00001.1.el8eap               @koji-override-1  1.1 M
 eap7-jbossws-api                                   noarch  1.1.2-1.Final_redhat_00001.1.el8eap               @koji-override-1  120 k
 eap7-jbossws-common                                noarch  3.2.3-1.Final_redhat_00001.1.el8eap               @koji-override-1  464 k
 eap7-jbossws-common-tools                          noarch  1.3.2-1.Final_redhat_00001.1.el8eap               @koji-override-1   66 k
 eap7-jbossws-cxf                                   noarch  5.3.0-1.Final_redhat_00001.1.el8eap               @koji-override-1  1.0 M
 eap7-jbossws-jaxws-undertow-httpspi                noarch  1.0.1-3.Final_redhat_1.1.el8eap                   @koji-override-1   23 k
 eap7-jbossws-spi                                   noarch  3.2.3-1.Final_redhat_00001.1.el8eap               @koji-override-1  295 k
 eap7-jcip-annotations                              noarch  1.0.0-5.redhat_8.1.el8eap                         @koji-override-1   10 k
 eap7-jettison                                      noarch  1.4.0-1.redhat_00001.1.el8eap                     @koji-override-1  173 k
 eap7-jgroups                                       noarch  4.1.4-1.Final_redhat_00001.1.el8eap               @koji-override-1  3.4 M
 eap7-jgroups-azure                                 noarch  1.2.1-1.Final_redhat_00001.1.el8eap               @koji-override-1   31 k
 eap7-jgroups-kubernetes                            noarch  1.0.13-1.Final_redhat_00001.1.el8eap              @koji-override-1  179 k
 eap7-joda-time                                     noarch  2.9.7-2.redhat_1.1.el8eap                         @koji-override-1  1.4 M
 eap7-jsch                                          noarch  0.1.54-7.redhat_00001.1.el8eap                    @koji-override-1  572 k
 eap7-json-patch                                    noarch  1.9.0-1.redhat_00002.1.el8eap                     @koji-override-1   83 k
 eap7-jsonb-spec                                    noarch  1.0.2-1.redhat_00001.1.el8eap                     @koji-override-1   79 k
 eap7-jsoup                                         noarch  1.8.3-4.redhat_2.1.el8eap                         @koji-override-1  453 k
 eap7-jul-to-slf4j-stub                             noarch  1.0.1-7.Final_redhat_3.1.el8eap                   @koji-override-1  8.2 k
 eap7-jzlib                                         noarch  1.1.1-7.redhat_00001.1.el8eap                     @koji-override-1  155 k
 eap7-log4j-jboss-logmanager                        noarch  1.2.0-1.Final_redhat_00001.1.el8eap               @koji-override-1  943 k
 eap7-lucene-analyzers-common                       noarch  5.5.5-3.redhat_2.1.el8eap                         @koji-override-1  3.0 M
 eap7-lucene-backward-codecs                        noarch  5.5.5-3.redhat_2.1.el8eap                         @koji-override-1  641 k
 eap7-lucene-core                                   noarch  5.5.5-3.redhat_2.1.el8eap                         @koji-override-1  4.0 M
 eap7-lucene-facet                                  noarch  5.5.5-3.redhat_2.1.el8eap                         @koji-override-1  314 k
 eap7-lucene-misc                                   noarch  5.5.5-3.redhat_2.1.el8eap                         @koji-override-1  276 k
 eap7-lucene-queries                                noarch  5.5.5-3.redhat_2.1.el8eap                         @koji-override-1  386 k
 eap7-lucene-queryparser                            noarch  5.5.5-3.redhat_2.1.el8eap                         @koji-override-1  779 k
 eap7-microprofile-config-api                       noarch  1.4.0-1.redhat_00003.1.el8eap                     @koji-override-1   43 k
 eap7-microprofile-health                           noarch  2.2.0-1.redhat_00001.1.el8eap                     @koji-override-1   49 k
 eap7-microprofile-metrics-api                      noarch  2.3.0-1.redhat_00001.1.el8eap                     @koji-override-1   80 k
 eap7-microprofile-opentracing-api                  noarch  1.3.3-1.redhat_00001.1.el8eap                     @koji-override-1   22 k
 eap7-microprofile-rest-client-api                  noarch  1.4.0-1.redhat_00004.1.el8eap                     @koji-override-1   53 k
 eap7-mod_cluster                                   noarch  1.4.1-1.Final_redhat_00001.1.el8eap               @koji-override-1  283 k
 eap7-mustache-java-compiler                        noarch  0.9.4-2.redhat_1.1.el8eap                         @koji-override-1  162 k
 eap7-narayana-compensations                        noarch  5.9.8-1.Final_redhat_00002.1.el8eap               @koji-override-1  121 k
 eap7-narayana-jbosstxbridge                        noarch  5.9.8-1.Final_redhat_00002.1.el8eap               @koji-override-1   90 k
 eap7-narayana-jbossxts                             noarch  5.9.8-1.Final_redhat_00002.1.el8eap               @koji-override-1  1.8 M
 eap7-narayana-jts-idlj                             noarch  5.9.8-1.Final_redhat_00002.1.el8eap               @koji-override-1  3.0 M
 eap7-narayana-jts-integration                      noarch  5.9.8-1.Final_redhat_00002.1.el8eap               @koji-override-1   97 k
 eap7-narayana-restat-api                           noarch  5.9.8-1.Final_redhat_00002.1.el8eap               @koji-override-1   71 k
 eap7-narayana-restat-bridge                        noarch  5.9.8-1.Final_redhat_00002.1.el8eap               @koji-override-1   46 k
 eap7-narayana-restat-integration                   noarch  5.9.8-1.Final_redhat_00002.1.el8eap               @koji-override-1   54 k
 eap7-narayana-restat-util                          noarch  5.9.8-1.Final_redhat_00002.1.el8eap               @koji-override-1   61 k
 eap7-narayana-txframework                          noarch  5.9.8-1.Final_redhat_00002.1.el8eap               @koji-override-1   83 k
 eap7-neethi                                        noarch  3.1.1-1.redhat_1.1.el8eap                         @koji-override-1  137 k
 eap7-netty-all                                     noarch  4.1.45-1.Final_redhat_00001.1.el8eap              @koji-override-1  7.2 M
 eap7-netty-xnio-transport                          noarch  0.1.6-1.Final_redhat_00001.1.el8eap               @koji-override-1  107 k
 eap7-objectweb-asm                                 noarch  7.1.0-1.redhat_00001.1.el8eap                     @koji-override-1  714 k
 eap7-okhttp                                        noarch  3.9.0-3.redhat_3.1.el8eap                         @koji-override-1  779 k
 eap7-okio                                          noarch  1.13.0-2.redhat_3.1.el8eap                        @koji-override-1  178 k
 eap7-opensaml-core                                 noarch  3.3.1-1.redhat_00002.1.el8eap                     @koji-override-1  373 k
 eap7-opensaml-profile-api                          noarch  3.3.1-1.redhat_00002.1.el8eap                     @koji-override-1   62 k
 eap7-opensaml-saml-api                             noarch  3.3.1-1.redhat_00002.1.el8eap                     @koji-override-1  917 k
 eap7-opensaml-saml-impl                            noarch  3.3.1-1.redhat_00002.1.el8eap                     @koji-override-1  2.3 M
 eap7-opensaml-security-api                         noarch  3.3.1-1.redhat_00002.1.el8eap                     @koji-override-1  138 k
 eap7-opensaml-security-impl                        noarch  3.3.1-1.redhat_00002.1.el8eap                     @koji-override-1  193 k
 eap7-opensaml-soap-api                             noarch  3.3.1-1.redhat_00002.1.el8eap                     @koji-override-1  383 k
 eap7-opensaml-xacml-api                            noarch  3.3.1-1.redhat_00002.1.el8eap                     @koji-override-1  112 k
 eap7-opensaml-xacml-impl                           noarch  3.3.1-1.redhat_00002.1.el8eap                     @koji-override-1  435 k
 eap7-opensaml-xacml-saml-api                       noarch  3.3.1-1.redhat_00002.1.el8eap                     @koji-override-1   19 k
 eap7-opensaml-xacml-saml-impl                      noarch  3.3.1-1.redhat_00002.1.el8eap                     @koji-override-1   56 k
 eap7-opensaml-xmlsec-api                           noarch  3.3.1-1.redhat_00002.1.el8eap                     @koji-override-1  464 k
 eap7-opensaml-xmlsec-impl                          noarch  3.3.1-1.redhat_00002.1.el8eap                     @koji-override-1  624 k
 eap7-opentracing-contrib-java-concurrent           noarch  0.2.1-1.redhat_00001.1.el8eap                     @koji-override-1   17 k
 eap7-opentracing-contrib-java-jaxrs                noarch  0.4.1-1.redhat_00006.1.el8eap                     @koji-override-1   62 k
 eap7-opentracing-contrib-java-tracerresolver       noarch  0.1.5-1.redhat_00001.1.el8eap                     @koji-override-1   16 k
 eap7-opentracing-contrib-java-web-servlet-filter   noarch  0.2.3-1.redhat_00001.1.el8eap                     @koji-override-1   27 k
 eap7-opentracing-interceptors                      noarch  0.0.4-1.redhat_00004.1.el8eap                     @koji-override-1   25 k
 eap7-opentracing-java-api                          noarch  0.31.0-1.redhat_00008.1.el8eap                    @koji-override-1   35 k
 eap7-opentracing-java-noop                         noarch  0.31.0-1.redhat_00008.1.el8eap                    @koji-override-1   17 k
 eap7-opentracing-java-util                         noarch  0.31.0-1.redhat_00008.1.el8eap                    @koji-override-1   16 k
 eap7-picketbox                                     noarch  5.0.3-7.Final_redhat_00006.1.el8eap               @koji-override-1  1.7 M
 eap7-picketbox-commons                             noarch  1.0.0-4.final_redhat_5.1.el8eap                   @koji-override-1   41 k
 eap7-picketbox-infinispan                          noarch  5.0.3-7.Final_redhat_00006.1.el8eap               @koji-override-1   35 k
 eap7-picketlink-api                                noarch  2.5.5-20.SP12_redhat_00009.1.el8eap               @koji-override-1  221 k
 eap7-picketlink-common                             noarch  2.5.5-20.SP12_redhat_00009.1.el8eap               @koji-override-1  266 k
 eap7-picketlink-config                             noarch  2.5.5-20.SP12_redhat_00009.1.el8eap               @koji-override-1  100 k
 eap7-picketlink-federation                         noarch  2.5.5-20.SP12_redhat_00009.1.el8eap               @koji-override-1  2.2 M
 eap7-picketlink-idm-api                            noarch  2.5.5-20.SP12_redhat_00009.1.el8eap               @koji-override-1  445 k
 eap7-picketlink-idm-impl                           noarch  2.5.5-20.SP12_redhat_00009.1.el8eap               @koji-override-1  419 k
 eap7-picketlink-idm-simple-schema                  noarch  2.5.5-20.SP12_redhat_00009.1.el8eap               @koji-override-1   39 k
 eap7-picketlink-impl                               noarch  2.5.5-20.SP12_redhat_00009.1.el8eap               @koji-override-1  163 k
 eap7-picketlink-wildfly8                           noarch  2.5.5-23.SP12_redhat_00012.1.el8eap               @koji-override-1  511 k
 eap7-python3-javapackages                          noarch  3.4.1-5.15.6.el8eap                               @koji-override-1   60 k
 eap7-reactive-streams                              noarch  1.0.2-2.redhat_1.1.el8eap                         @koji-override-1   79 k
 eap7-reactivex-rxjava                              noarch  2.2.5-1.redhat_00001.1.el8eap                     @koji-override-1  3.8 M
 eap7-relaxng-datatype                              noarch  2.3.3-4.b02_redhat_00001.1.el8eap                 @koji-override-1   47 k
 eap7-resteasy-atom-provider                        noarch  3.11.2-3.Final_redhat_00002.1.el8eap              @koji-override-1   85 k
 eap7-resteasy-cdi                                  noarch  3.11.2-3.Final_redhat_00002.1.el8eap              @koji-override-1   51 k
 eap7-resteasy-client                               noarch  3.11.2-3.Final_redhat_00002.1.el8eap              @koji-override-1  335 k
 eap7-resteasy-client-microprofile                  noarch  3.11.2-3.Final_redhat_00002.1.el8eap              @koji-override-1  122 k
 eap7-resteasy-crypto                               noarch  3.11.2-3.Final_redhat_00002.1.el8eap              @koji-override-1  153 k
 eap7-resteasy-jackson-provider                     noarch  3.11.2-3.Final_redhat_00002.1.el8eap              @koji-override-1   16 k
 eap7-resteasy-jackson2-provider                    noarch  3.11.2-3.Final_redhat_00002.1.el8eap              @koji-override-1   45 k
 eap7-resteasy-jaxb-provider                        noarch  3.11.2-3.Final_redhat_00002.1.el8eap              @koji-override-1  141 k
 eap7-resteasy-jaxrs                                noarch  3.11.2-3.Final_redhat_00002.1.el8eap              @koji-override-1  1.6 M
 eap7-resteasy-jettison-provider                    noarch  3.11.2-3.Final_redhat_00002.1.el8eap              @koji-override-1   63 k
 eap7-resteasy-jose-jwt                             noarch  3.11.2-3.Final_redhat_00002.1.el8eap              @koji-override-1  104 k
 eap7-resteasy-jsapi                                noarch  3.11.2-3.Final_redhat_00002.1.el8eap              @koji-override-1   55 k
 eap7-resteasy-json-binding-provider                noarch  3.11.2-3.Final_redhat_00002.1.el8eap              @koji-override-1   25 k
 eap7-resteasy-json-p-provider                      noarch  3.11.2-3.Final_redhat_00002.1.el8eap              @koji-override-1   22 k
 eap7-resteasy-multipart-provider                   noarch  3.11.2-3.Final_redhat_00002.1.el8eap              @koji-override-1  140 k
 eap7-resteasy-rxjava2                              noarch  3.11.2-3.Final_redhat_00002.1.el8eap              @koji-override-1   54 k
 eap7-resteasy-spring                               noarch  3.11.2-3.Final_redhat_00002.1.el8eap              @koji-override-1   97 k
 eap7-resteasy-validator-provider-11                noarch  3.11.2-3.Final_redhat_00002.1.el8eap              @koji-override-1   46 k
 eap7-resteasy-yaml-provider                        noarch  3.11.2-3.Final_redhat_00002.1.el8eap              @koji-override-1   18 k
 eap7-rngom                                         noarch  2.3.3-4.b02_redhat_00001.1.el8eap                 @koji-override-1  569 k
 eap7-runtime                                       x86_64  1-16.el8eap                                       @koji-override-1  311  
 eap7-shibboleth-java-support                       noarch  7.3.0-1.redhat_00001.1.el8eap                     @koji-override-1  471 k
 eap7-slf4j-api                                     noarch  1.7.22-4.redhat_2.1.el8eap                        @koji-override-1   93 k
 eap7-slf4j-ext                                     noarch  1.7.22-4.redhat_2.1.el8eap                        @koji-override-1   86 k
 eap7-slf4j-jboss-logmanager                        noarch  1.0.4-1.GA_redhat_00001.1.el8eap                  @koji-override-1   18 k
 eap7-smallrye-config                               noarch  1.6.2-3.redhat_00004.1.el8eap                     @koji-override-1  143 k
 eap7-smallrye-health                               noarch  2.2.0-1.redhat_00004.1.el8eap                     @koji-override-1   40 k
 eap7-smallrye-metrics                              noarch  2.4.0-1.redhat_00004.1.el8eap                     @koji-override-1  249 k
 eap7-smallrye-opentracing                          noarch  1.3.4-1.redhat_00004.1.el8eap                     @koji-override-1   28 k
 eap7-snakeyaml                                     noarch  1.24.0-2.redhat_00001.1.el8eap                    @koji-override-1  495 k
 eap7-stax-ex                                       noarch  1.7.8-1.redhat_00001.1.el8eap                     @koji-override-1  120 k
 eap7-stax2-api                                     noarch  4.2.0-1.redhat_00001.1.el8eap                     @koji-override-1  380 k
 eap7-staxmapper                                    noarch  1.3.0-2.Final_redhat_1.1.el8eap                   @koji-override-1   59 k
 eap7-sun-saaj-1.3-impl                             noarch  1.3.16-18.SP1_redhat_6.1.el8eap                   @koji-override-1  647 k
 eap7-sun-saaj-1.4-impl                             noarch  1.4.1-1.SP1_redhat_00001.1.el8eap                 @koji-override-1  1.0 M
 eap7-sun-ws-metadata-2.0-api                       noarch  1.0.0-7.MR1_redhat_8.1.el8eap                     @koji-override-1   63 k
 eap7-taglibs-standard-compat                       noarch  1.2.6-2.RC1_redhat_1.1.el8eap                     @koji-override-1  105 k
 eap7-taglibs-standard-impl                         noarch  1.2.6-2.RC1_redhat_1.1.el8eap                     @koji-override-1  438 k
 eap7-taglibs-standard-spec                         noarch  1.2.6-2.RC1_redhat_1.1.el8eap                     @koji-override-1  110 k
 eap7-thrift                                        noarch  0.13.0-1.redhat_00002.1.el8eap                    @koji-override-1  420 k
 eap7-txw2                                          noarch  2.3.3-4.b02_redhat_00001.1.el8eap                 @koji-override-1  140 k
 eap7-undertow                                      noarch  2.0.30-3.SP3_redhat_00001.1.el8eap                @koji-override-1  4.5 M
 eap7-undertow-jastow                               noarch  2.0.8-1.Final_redhat_00001.1.el8eap               @koji-override-1  1.0 M
 eap7-undertow-js                                   noarch  1.0.2-2.Final_redhat_1.1.el8eap                   @koji-override-1   73 k
 eap7-undertow-server                               noarch  1.6.1-1.Final_redhat_00001.1.el8eap               @koji-override-1  130 k
 eap7-vdx-core                                      noarch  1.1.6-2.redhat_1.1.el8eap                         @koji-override-1  155 k
 eap7-vdx-wildfly                                   noarch  1.1.6-2.redhat_1.1.el8eap                         @koji-override-1   20 k
 eap7-velocity                                      noarch  2.1.0-1.redhat_00001.1.el8eap                     @koji-override-1   78 k
 eap7-velocity-engine-core                          noarch  2.1.0-1.redhat_00001.1.el8eap                     @koji-override-1  955 k
 eap7-weld-cdi-2.0-api                              noarch  2.0.2-2.redhat_00002.1.el8eap                     @koji-override-1  301 k
 eap7-weld-core-impl                                noarch  3.1.4-1.Final_redhat_00001.1.el8eap               @koji-override-1  2.7 M
 eap7-weld-core-jsf                                 noarch  3.1.4-1.Final_redhat_00001.1.el8eap               @koji-override-1   35 k
 eap7-weld-ejb                                      noarch  3.1.4-1.Final_redhat_00001.1.el8eap               @koji-override-1  110 k
 eap7-weld-jta                                      noarch  3.1.4-1.Final_redhat_00001.1.el8eap               @koji-override-1   40 k
 eap7-weld-probe-core                               noarch  3.1.4-1.Final_redhat_00001.1.el8eap               @koji-override-1  1.5 M
 eap7-weld-web                                      noarch  3.1.4-1.Final_redhat_00001.1.el8eap               @koji-override-1  149 k
 eap7-wildfly                                       noarch  7.3.1-5.GA_redhat_00003.1.el8eap                  @koji-override-1   19 M
 eap7-wildfly-client-config                         noarch  1.0.1-2.Final_redhat_00001.1.el8eap               @koji-override-1   80 k
 eap7-wildfly-common                                noarch  1.5.1-1.Final_redhat_00001.1.el8eap               @koji-override-1  503 k
 eap7-wildfly-discovery-client                      noarch  1.2.0-1.Final_redhat_00001.1.el8eap               @koji-override-1  149 k
 eap7-wildfly-elytron                               noarch  1.10.6-1.Final_redhat_00001.1.el8eap              @koji-override-1  4.3 M
 eap7-wildfly-elytron-tool                          noarch  1.10.6-1.Final_redhat_00001.1.el8eap              @koji-override-1  1.3 M
 eap7-wildfly-http-client-common                    noarch  1.0.20-1.Final_redhat_00001.1.el8eap              @koji-override-1  106 k
 eap7-wildfly-http-ejb-client                       noarch  1.0.20-1.Final_redhat_00001.1.el8eap              @koji-override-1   90 k
 eap7-wildfly-http-naming-client                    noarch  1.0.20-1.Final_redhat_00001.1.el8eap              @koji-override-1   57 k
 eap7-wildfly-http-transaction-client               noarch  1.0.20-1.Final_redhat_00001.1.el8eap              @koji-override-1   54 k
 eap7-wildfly-modules                               noarch  7.3.1-5.GA_redhat_00003.1.el8eap                  @koji-override-1   56 M
 eap7-wildfly-naming-client                         noarch  1.0.12-1.Final_redhat_00001.1.el8eap              @koji-override-1  225 k
 eap7-wildfly-openssl-java                          noarch  1.0.9-2.SP03_redhat_00001.1.el8eap                @koji-override-1  265 k
 eap7-wildfly-openssl-linux-x86_64                  x86_64  1.0.9-2.SP03_redhat_00001.1.el8eap                @koji-override-1   68 k
 eap7-wildfly-transaction-client                    noarch  1.1.11-1.Final_redhat_00001.1.el8eap              @koji-override-1  295 k
 eap7-woodstox-core                                 noarch  6.0.3-1.redhat_00001.1.el8eap                     @koji-override-1  2.1 M
 eap7-ws-commons-XmlSchema                          noarch  2.2.4-1.redhat_00001.1.el8eap                     @koji-override-1  328 k
 eap7-wsdl4j                                        noarch  1.6.3-13.redhat_2.1.el8eap                        @koji-override-1  368 k
 eap7-wss4j-bindings                                noarch  2.2.5-1.redhat_00001.1.el8eap                     @koji-override-1  108 k
 eap7-wss4j-policy                                  noarch  2.2.5-1.redhat_00001.1.el8eap                     @koji-override-1  359 k
 eap7-wss4j-ws-security-common                      noarch  2.2.5-1.redhat_00001.1.el8eap                     @koji-override-1  510 k
 eap7-wss4j-ws-security-dom                         noarch  2.2.5-1.redhat_00001.1.el8eap                     @koji-override-1  591 k
 eap7-wss4j-ws-security-policy-stax                 noarch  2.2.5-1.redhat_00001.1.el8eap                     @koji-override-1  227 k
 eap7-wss4j-ws-security-stax                        noarch  2.2.5-1.redhat_00001.1.el8eap                     @koji-override-1  667 k
 eap7-xalan-j2                                      noarch  2.7.1-35.redhat_12.1.el8eap                       @koji-override-1  6.2 M
 eap7-xerces-j2                                     noarch  2.12.0-1.SP02_redhat_00001.1.el8eap               @koji-override-1  3.8 M
 eap7-xml-resolver                                  noarch  1.2.0-7.redhat_12.1.el8eap                        @koji-override-1  239 k
 eap7-xml-security                                  noarch  2.1.4-1.redhat_00001.1.el8eap                     @koji-override-1  2.0 M
 eap7-xom                                           noarch  1.2.10-4.redhat_1.1.el8eap                        @koji-override-1  610 k
 eap7-xsom                                          noarch  2.3.3-4.b02_redhat_00001.1.el8eap                 @koji-override-1  667 k
 eap7-yasson                                        noarch  1.0.5-1.redhat_00001.1.el8eap                     @koji-override-1  610 k
 ebay-cors-filter                                   noarch  1.0.1-4.el8ev                                     @koji-override-1  119 k
 engine-db-query                                    noarch  1.5.0-1.el8ev                                     @koji-override-1   41 k
 environment-modules                                x86_64  4.1.4-4.el8                                       @anaconda         1.0 M
 fribidi                                            x86_64  1.0.4-8.el8                                       @koji-override-1  312 k
 gd                                                 x86_64  2.2.5-6.el8                                       @koji-override-1  427 k
 gdk-pixbuf2-modules                                x86_64  2.36.12-5.el8                                     @koji-override-1  308 k
 giflib                                             x86_64  5.1.4-3.el8                                       @koji-override-1  103 k
 glassfish-fastinfoset                              noarch  1.2.13-9.module+el8.1.0+3366+6dfb954c             @koji-override-1  395 k
 glassfish-jaxb-api                                 noarch  2.2.12-8.module+el8.1.0+3366+6dfb954c             @koji-override-1  115 k
 glassfish-jaxb-core                                noarch  2.2.11-11.module+el8.1.0+3366+6dfb954c            @koji-override-1  236 k
 glassfish-jaxb-runtime                             noarch  2.2.11-11.module+el8.1.0+3366+6dfb954c            @koji-override-1  1.1 M
 glassfish-jaxb-txw2                                noarch  2.2.11-11.module+el8.1.0+3366+6dfb954c            @koji-override-1  153 k
 gnutls-dane                                        x86_64  3.6.8-10.el8_2                                    @koji-override-1   36 k
 gnutls-utils                                       x86_64  3.6.8-10.el8_2                                    @koji-override-1  1.4 M
 graphite2                                          x86_64  1.3.10-10.el8                                     @koji-override-1  262 k
 graphviz                                           x86_64  2.40.1-40.el8                                     @koji-override-1  7.4 M
 gtk-update-icon-cache                              x86_64  3.22.30-5.el8                                     @koji-override-1   59 k
 gtk2                                               x86_64  2.24.32-4.el8                                     @koji-override-1   13 M
 harfbuzz                                           x86_64  1.7.5-3.el8                                       @koji-override-1  740 k
 hicolor-icon-theme                                 noarch  0.17-2.el8                                        @koji-override-1   72 k
 httpcomponents-client                              noarch  4.5.5-4.module+el8+2598+06babf2e                  @koji-override-1  915 k
 httpcomponents-core                                noarch  4.4.10-3.module+el8+2598+06babf2e                 @koji-override-1  1.1 M
 httpd                                              x86_64  2.4.37-21.module+el8.2.0+5008+cca404a3            @koji-override-1  4.3 M
 httpd-filesystem                                   noarch  2.4.37-21.module+el8.2.0+5008+cca404a3            @koji-override-1  400  
 httpd-tools                                        x86_64  2.4.37-21.module+el8.2.0+5008+cca404a3            @koji-override-1  194 k
 insights-client                                    noarch  3.0.13-1.el8                                      @koji-override-1  1.2 M
 istack-commons-runtime                             noarch  2.21-9.el8+7                                      @koji-override-1   63 k
 jackson-annotations                                noarch  2.10.0-1.module+el8.2.0+5059+3eb3af25             @koji-override-1   82 k
 jackson-core                                       noarch  2.10.0-1.module+el8.2.0+5059+3eb3af25             @koji-override-1  376 k
 jackson-databind                                   noarch  2.10.0-1.module+el8.2.0+5059+3eb3af25             @koji-override-1  1.5 M
 jackson-jaxrs-json-provider                        noarch  2.9.9-1.module+el8.1.0+3832+9784644d              @koji-override-1   20 k
 jackson-jaxrs-providers                            noarch  2.9.9-1.module+el8.1.0+3832+9784644d              @koji-override-1   47 k
 jackson-module-jaxb-annotations                    noarch  2.7.6-4.module+el8.1.0+3366+6dfb954c              @koji-override-1   47 k
 jasper-libs                                        x86_64  2.0.14-4.el8                                      @koji-override-1  376 k
 java-1.8.0-openjdk                                 x86_64  1:1.8.0.252.b09-3.el8_2                           @koji-override-1  846 k
 java-client-kubevirt                               noarch  0.5.0-1.el8ev                                     @koji-override-1   26 M
 javapackages-tools                                 noarch  5.3.0-2.module+el8+2598+06babf2e                  @koji-override-1   63 k
 jbig2dec-libs                                      x86_64  0.14-2.el8                                        @koji-override-1  148 k
 jbigkit-libs                                       x86_64  2.1-14.el8                                        @koji-override-1  107 k
 jboss-annotations-1.2-api                          noarch  1.0.0-4.el8                                       @koji-override-1   64 k
 jboss-jaxrs-2.0-api                                noarch  1.0.0-6.el8                                       @koji-override-1  135 k
 jboss-logging                                      noarch  3.3.0-5.el8                                       @koji-override-1   78 k
 jboss-logging-tools                                noarch  2.0.1-6.el8                                       @koji-override-1  197 k
 jcl-over-slf4j                                     noarch  1.7.25-4.module+el8.1.0+3366+6dfb954c             @koji-override-1   19 k
 jdeparser                                          noarch  2.0.0-5.el8                                       @koji-override-1  242 k
 keyutils                                           x86_64  1.5.10-6.el8                                      @anaconda         114 k
 libXaw                                             x86_64  1.0.13-10.el8                                     @koji-override-1  508 k
 libXcomposite                                      x86_64  0.4.4-14.el8                                      @koji-override-1   35 k
 libXdamage                                         x86_64  1.1.4-14.el8                                      @koji-override-1   30 k
 libXft                                             x86_64  2.3.2-10.el8                                      @koji-override-1  132 k
 libXpm                                             x86_64  3.5.12-8.el8                                      @koji-override-1  118 k
 libXtst                                            x86_64  1.2.3-7.el8                                       @koji-override-1   34 k
 libdatrie                                          x86_64  0.2.9-7.el8                                       @koji-override-1   61 k
 libestr                                            x86_64  0.1.10-1.el8                                      @koji-override-1   45 k
 libfastjson                                        x86_64  0.99.8-2.el8                                      @koji-override-1   68 k
 libgfortran                                        x86_64  8.3.1-5.el8                                       @anaconda         2.5 M
 libgs                                              x86_64  9.25-5.el8_1.1                                    @koji-override-1   20 M
 libicu                                             x86_64  60.3-2.el8_1                                      @anaconda          32 M
 libidn                                             x86_64  1.34-5.el8                                        @koji-override-1  694 k
 libijs                                             x86_64  0.35-5.el8                                        @koji-override-1   59 k
 liblognorm                                         x86_64  2.0.5-1.el8                                       @koji-override-1  193 k
 libpaper                                           x86_64  1.1.24-22.el8                                     @koji-override-1   89 k
 libpq                                              x86_64  12.1-3.el8                                        @koji-override-1  808 k
 libquadmath                                        x86_64  8.3.1-5.el8                                       @anaconda         298 k
 librsvg2                                           x86_64  2.42.7-3.el8                                      @koji-override-1  1.7 M
 libsodium                                          x86_64  1.0.18-2.el8ev                                    @koji-override-1  598 k
 libthai                                            x86_64  0.1.27-2.el8                                      @koji-override-1  755 k
 libtiff                                            x86_64  4.0.9-17.el8                                      @koji-override-1  506 k
 libverto-libevent                                  x86_64  0.3.0-5.el8                                       @anaconda          12 k
 libwebp                                            x86_64  1.0.0-1.el8                                       @koji-override-1  826 k
 log4j12                                            noarch  1.2.17-22.el8ev                                   @koji-override-1  520 k
 logrotate                                          x86_64  3.14.0-3.el8                                      @anaconda         143 k
 mailcap                                            noarch  2.1.48-3.el8                                      @anaconda          71 k
 mod_http2                                          x86_64  1.11.3-3.module+el8.2.0+4377+dc421495             @koji-override-1  479 k
 mod_ssl                                            x86_64  1:2.4.37-21.module+el8.2.0+5008+cca404a3          @koji-override-1  262 k
 nfs-utils                                          x86_64  1:2.3.3-31.el8                                    @anaconda         1.4 M
 nodejs                                             x86_64  1:10.19.0-2.module+el8.2.0+6232+1df3dc5f          @koji-override-1   47 M
 novnc                                              noarch  1.1.0-1.el8ost                                    @koji-override-1  3.4 M
 npm                                                x86_64  1:6.13.4-1.10.19.0.2.module+el8.2.0+6232+1df3dc5f @koji-override-1   16 M
 ongres-scram                                       noarch  1.0.0~beta.2-5.el8                                @koji-override-1   44 k
 ongres-scram-client                                noarch  1.0.0~beta.2-5.el8                                @koji-override-1   20 k
 openblas                                           x86_64  0.3.3-5.el8                                       @koji-override-1   27 M
 openblas-threads                                   x86_64  0.3.3-5.el8                                       @koji-override-1   27 M
 openjpeg2                                          x86_64  2.3.1-6.el8                                       @koji-override-1  348 k
 openstack-java-cinder-client                       noarch  3.2.8-1.el8ev                                     @koji-override-1   43 k
 openstack-java-cinder-model                        noarch  3.2.8-1.el8ev                                     @koji-override-1   42 k
 openstack-java-client                              noarch  3.2.8-1.el8ev                                     @koji-override-1   28 k
 openstack-java-glance-client                       noarch  3.2.8-1.el8ev                                     @koji-override-1   36 k
 openstack-java-glance-model                        noarch  3.2.8-1.el8ev                                     @koji-override-1   26 k
 openstack-java-keystone-client                     noarch  3.2.8-1.el8ev                                     @koji-override-1   66 k
 openstack-java-keystone-model                      noarch  3.2.8-1.el8ev                                     @koji-override-1   68 k
 openstack-java-quantum-client                      noarch  3.2.8-1.el8ev                                     @koji-override-1   44 k
 openstack-java-quantum-model                       noarch  3.2.8-1.el8ev                                     @koji-override-1   39 k
 openstack-java-resteasy-connector                  noarch  3.2.8-1.el8ev                                     @koji-override-1   27 k
 ovirt-ansible-cluster-upgrade                      noarch  1.2.2-1.el8ev                                     @koji-override-1   28 k
 ovirt-ansible-disaster-recovery                    noarch  1.3.0-0.1.master.20200219155422.el8ev             @koji-override-1  149 k
 ovirt-ansible-engine-setup                         noarch  1.2.4-1.el8ev                                     @koji-override-1   32 k
 ovirt-ansible-hosted-engine-setup                  noarch  1.1.4-1.el8ev                                     @koji-override-1  180 k
 ovirt-ansible-image-template                       noarch  1.2.2-1.el8ev                                     @koji-override-1   35 k
 ovirt-ansible-infra                                noarch  1.2.1-1.el8ev                                     @koji-override-1   93 k
 ovirt-ansible-manageiq                             noarch  1.2.1-2.el8ev                                     @koji-override-1   47 k
 ovirt-ansible-repositories                         noarch  1.2.3-1.el8ev                                     @koji-override-1   23 k
 ovirt-ansible-roles                                noarch  1.2.3-1.el8ev                                     @koji-override-1   24 k
 ovirt-ansible-shutdown-env                         noarch  1.0.4-1.el8ev                                     @koji-override-1   21 k
 ovirt-ansible-vm-infra                             noarch  1.2.3-1.el8ev                                     @koji-override-1   59 k
 ovirt-cockpit-sso                                  noarch  0.1.4-1.el8ev                                     @koji-override-1   23 k
 ovirt-engine                                       noarch  4.4.1.2-0.10.el8ev                                @koji-override-1   38 M
 ovirt-engine-api-explorer                          noarch  0.0.6-1.el8ev                                     @koji-override-1  1.6 M
 ovirt-engine-backend                               noarch  4.4.1.2-0.10.el8ev                                @koji-override-1  8.1 M
 ovirt-engine-dbscripts                             noarch  4.4.1.2-0.10.el8ev                                @koji-override-1  1.6 M
 ovirt-engine-dwh                                   noarch  4.4.0.2-1.el8ev                                   @koji-override-1  3.0 M
 ovirt-engine-dwh-setup                             noarch  4.4.0.2-1.el8ev                                   @koji-override-1  234 k
 ovirt-engine-extension-aaa-jdbc                    noarch  1.2.0-1.el8ev                                     @koji-override-1  243 k
 ovirt-engine-metrics                               noarch  1.4.0.2-1.el8ev                                   @koji-override-1  414 k
 ovirt-engine-restapi                               noarch  4.4.1.2-0.10.el8ev                                @koji-override-1   25 M
 ovirt-engine-setup                                 noarch  4.4.1.2-0.10.el8ev                                @koji-override-1  671  
 ovirt-engine-setup-base                            noarch  4.4.1.2-0.10.el8ev                                @koji-override-1  319 k
 ovirt-engine-setup-plugin-cinderlib                noarch  4.4.1.2-0.10.el8ev                                @koji-override-1   66 k
 ovirt-engine-setup-plugin-imageio                  noarch  4.4.1.2-0.10.el8ev                                @koji-override-1   15 k
 ovirt-engine-setup-plugin-ovirt-engine             noarch  4.4.1.2-0.10.el8ev                                @koji-override-1  744 k
 ovirt-engine-setup-plugin-ovirt-engine-common      noarch  4.4.1.2-0.10.el8ev                                @koji-override-1  377 k
 ovirt-engine-setup-plugin-vmconsole-proxy-helper   noarch  4.4.1.2-0.10.el8ev                                @koji-override-1   60 k
 ovirt-engine-setup-plugin-websocket-proxy          noarch  4.4.1.2-0.10.el8ev                                @koji-override-1   51 k
 ovirt-engine-tools                                 noarch  4.4.1.2-0.10.el8ev                                @koji-override-1  450 k
 ovirt-engine-tools-backup                          noarch  4.4.1.2-0.10.el8ev                                @koji-override-1   73 k
 ovirt-engine-ui-extensions                         noarch  1.2.0-1.el8ev                                     @koji-override-1   38 M
 ovirt-engine-vmconsole-proxy-helper                noarch  4.4.1.2-0.10.el8ev                                @koji-override-1   16 k
 ovirt-engine-webadmin-portal                       noarch  4.4.1.2-0.10.el8ev                                @koji-override-1  292 M
 ovirt-engine-websocket-proxy                       noarch  4.4.1.2-0.10.el8ev                                @koji-override-1   36 k
 ovirt-imageio-common                               x86_64  2.0.6-0.el8ev                                     @koji-override-1  463 k
 ovirt-imageio-daemon                               x86_64  2.0.6-0.el8ev                                     @koji-override-1  4.4 k
 ovirt-log-collector                                noarch  4.4.1-3.el8ev                                     @koji-override-1  153 k
 ovirt-vmconsole                                    noarch  1.0.8-1.el8ev                                     @koji-override-1  261 k
 ovirt-vmconsole-proxy                              noarch  1.0.8-1.el8ev                                     @koji-override-1   36 k
 ovirt-web-ui                                       noarch  1.6.2-1.el8ev                                     @koji-override-1   70 M
 pango                                              x86_64  1.42.4-6.el8                                      @koji-override-1  942 k
 pciutils                                           x86_64  3.5.6-4.el8                                       @anaconda         220 k
 pki-servlet-4.0-api                                noarch  1:9.0.7-16.module+el8.1.0+3366+6dfb954c           @koji-override-1  329 k
 postgresql                                         x86_64  12.1-2.module+el8.1.1+4794+c82b6e09               @koji-override-1  5.7 M
 postgresql-contrib                                 x86_64  12.1-2.module+el8.1.1+4794+c82b6e09               @koji-override-1  3.4 M
 postgresql-jdbc                                    noarch  42.2.3-1.el8                                      @koji-override-1  747 k
 postgresql-server                                  x86_64  12.1-2.module+el8.1.1+4794+c82b6e09               @koji-override-1   24 M
 publicsuffix-list                                  noarch  20180723-1.el8                                    @anaconda         224 k
 python3-aniso8601                                  noarch  0.82-4.el8ost                                     @koji-override-1   96 k
 python3-ansible-runner                             noarch  1.4.5-1.el8ar                                     @koji-override-1  340 k
 python3-bcrypt                                     x86_64  3.1.6-2.el8ev                                     @koji-override-1   89 k
 python3-click                                      noarch  6.7-8.el8                                         @koji-override-1  521 k
 python3-daemon                                     noarch  2.1.2-9.el8ar                                     @koji-override-1  106 k
 python3-dnf-plugin-versionlock                     noarch  4.0.12-3.el8                                      @anaconda          23 k
 python3-docutils                                   noarch  0.14-12.module+el8.1.0+3334+5cb623d7              @koji-override-1  5.9 M
 python3-flask                                      noarch  1:1.0.2-2.el8ost                                  @koji-override-1  725 k
 python3-flask-restful                              noarch  0.3.6-8.el8ost                                    @koji-override-1  299 k
 python3-itsdangerous                               noarch  0.24-14.el8                                       @koji-override-1   93 k
 python3-jmespath                                   noarch  0.9.0-11.el8                                      @koji-override-1  117 k
 python3-lockfile                                   noarch  1:0.11.0-8.el8ar                                  @koji-override-1   81 k
 python3-lxml                                       x86_64  4.2.3-1.el8                                       @koji-override-1  4.8 M
 python3-m2crypto                                   x86_64  0.35.2-5.el8ev                                    @koji-override-1  1.4 M
 python3-magic                                      noarch  5.33-13.el8                                       @anaconda          19 k
 python3-mod_wsgi                                   x86_64  4.6.4-4.el8                                       @koji-override-1  9.5 M
 python3-notario                                    noarch  0.0.16-2.el8cp                                    @koji-override-1  351 k
 python3-numpy                                      x86_64  1:1.14.3-9.el8                                    @koji-override-1   16 M
 python3-ovirt-engine-lib                           noarch  4.4.1.2-0.10.el8ev                                @koji-override-1   54 k
 python3-ovirt-engine-sdk4                          x86_64  4.4.3-1.el8ev                                     @koji-override-1  5.5 M
 python3-ovirt-setup-lib                            noarch  1.3.0-1.el8ev                                     @koji-override-1   48 k
 python3-paramiko                                   noarch  2.4.3-2.el8ev                                     @koji-override-1  1.2 M
 python3-passlib                                    noarch  1.7.0-5.el8ost                                    @koji-override-1  3.7 M
 python3-pexpect                                    noarch  4.6-2.el8ost                                      @koji-override-1  519 k
 python3-psutil                                     x86_64  5.4.3-10.el8                                      @koji-override-1  2.0 M
 python3-psycopg2                                   x86_64  2.7.5-7.el8                                       @koji-override-1  544 k
 python3-ptyprocess                                 noarch  0.5.2-4.el8                                       @koji-override-1   87 k
 python3-pwquality                                  x86_64  1.4.0-9.el8                                       @anaconda          21 k
 python3-pyOpenSSL                                  noarch  18.0.0-1.el8                                      @koji-override-1  545 k
 python3-pycurl                                     x86_64  7.43.0.2-4.el8                                    @koji-override-1  767 k
 python3-pynacl                                     x86_64  1.3.0-5.el8ev                                     @koji-override-1  482 k
 python3-websocket-client                           noarch  0.54.0-1.el8ost                                   @koji-override-1  176 k
 python3-websockify                                 noarch  0.8.0-12.el8ev                                    @koji-override-1  133 k
 python3-werkzeug                                   noarch  0.16.0-1.el8ost                                   @koji-override-1  2.1 M
 quota                                              x86_64  1:4.04-10.el8                                     @anaconda         936 k
 quota-nls                                          noarch  1:4.04-10.el8                                     @anaconda         277 k
 redhat-storage-logos-httpd                         noarch  81.1-1.el8rhgs                                    @koji-override-1  3.3 k
 relaxngDatatype                                    noarch  2011.1-7.module+el8.1.0+3366+6dfb954c             @koji-override-1   30 k
 resteasy                                           noarch  3.0.26-3.module+el8.1.0+3366+6dfb954c             @koji-override-1  1.2 M
 rhv-log-collector-analyzer                         noarch  1.0.0-1.el8ev                                     @koji-override-1  379 k
 rhvm                                               noarch  4.4.1.2-0.10.el8ev                                @koji-override-1  671  
 rhvm-dependencies                                  noarch  4.4.0-1.el8ev                                     @koji-override-1   14 M
 rhvm-setup-plugins                                 noarch  4.4.2-1.el8ev                                     @koji-override-1   48 k
 rpcbind                                            x86_64  1.2.5-7.el8                                       @anaconda         108 k
 rsyslog                                            x86_64  8.1911.0-3.el8                                    @koji-override-1  2.3 M
 rsyslog-elasticsearch                              x86_64  8.1911.0-3.el8                                    @koji-override-1   49 k
 rsyslog-mmjsonparse                                x86_64  8.1911.0-3.el8                                    @koji-override-1   16 k
 rsyslog-mmnormalize                                x86_64  8.1911.0-3.el8                                    @koji-override-1   20 k
 scl-utils                                          x86_64  1:2.0.2-12.el8                                    @koji-override-1   62 k
 sgml-common                                        noarch  0.6.3-50.el8                                      @anaconda         168 k
 snmp4j                                             noarch  2.4.1-1.el8ev                                     @koji-override-1  532 k
 sos                                                noarch  3.8-6.el8_2                                       @anaconda         1.5 M
 source-highlight                                   x86_64  3.1.8-16.el8                                      @koji-override-1  3.2 M
 spice-client-win-x64                               noarch  8.0-1.el8                                         @koji-override-1   53 M
 spice-client-win-x86                               noarch  8.0-1.el8                                         @koji-override-1   51 M
 sshpass                                            x86_64  1.06-3.el8ae                                      @koji-override-1   40 k
 stax-ex                                            noarch  1.7.7-8.module+el8.1.0+3366+6dfb954c              @koji-override-1   80 k
 tcl                                                x86_64  1:8.6.8-2.el8                                     @anaconda         4.2 M
 ttmkfdir                                           x86_64  3.0.9-54.el8                                      @koji-override-1  128 k
 urw-base35-fonts                                   noarch  20170801-10.el8                                   @koji-override-1  5.3 k
 urw-base35-standard-symbols-ps-fonts               noarch  20170801-10.el8                                   @koji-override-1   44 k
 uuid                                               x86_64  1.6.2-42.el8                                      @koji-override-1  126 k
 vdsm-jsonrpc-java                                  noarch  1.5.4-1.el8ev                                     @koji-override-1  145 k
 vim-filesystem                                     noarch  2:8.0.1763-13.el8                                 @koji-override-1   40  
 ws-commons-util                                    noarch  1.0.2-1.el8ev                                     @koji-override-1   57 k
 xmlrpc-client                                      noarch  3.1.3-1.el8ev                                     @koji-override-1   68 k
 xmlrpc-common                                      noarch  3.1.3-1.el8ev                                     @koji-override-1  148 k
 xmlstreambuffer                                    noarch  1.5.4-8.module+el8.1.0+3366+6dfb954c              @koji-override-1  113 k
 xorg-x11-fonts-ISO8859-1-100dpi                    noarch  7.5-19.el8                                        @koji-override-1  1.0 M
 xorg-x11-fonts-Type1                               noarch  7.5-19.el8                                        @koji-override-1  863 k
 xsom                                               noarch  0-19.20110809svn.module+el8.1.0+3366+6dfb954c     @koji-override-1  452 k
 yajl                                               x86_64  2.1.0-10.el8                                      @koji-override-1   84 k

Transaction Summary
=====================================================================================================================================
Remove  633 Packages

Freed space: 1.5 G
Running transaction check
Transaction check succeeded.
Running transaction test
Transaction test succeeded.
Running transaction
  Preparing        :                                                        1/1 
  Running scriptlet: ovirt-engine-dwh-4.4.0.2-1.el8ev.noarch                1/1 
  Running scriptlet: ovirt-engine-dwh-4.4.0.2-1.el8ev.noarch              1/633 
  Erasing          : ovirt-engine-dwh-4.4.0.2-1.el8ev.noarch              1/633 
  Running scriptlet: ovirt-engine-dwh-4.4.0.2-1.el8ev.noarch              1/633 
  Erasing          : ovirt-engine-setup-plugin-imageio-4.4.1.2-0.10.e     2/633 
  Erasing          : rhvm-branding-rhv-4.4.3-1.el8ev.noarch               3/633 
  Running scriptlet: ovirt-engine-backend-4.4.1.2-0.10.el8ev.noarch       4/633 
  Erasing          : ovirt-engine-backend-4.4.1.2-0.10.el8ev.noarch       4/633 
  Running scriptlet: ovirt-engine-backend-4.4.1.2-0.10.el8ev.noarch       4/633 
  Erasing          : ovirt-engine-setup-plugin-cinderlib-4.4.1.2-0.10     5/633 
  Erasing          : ovirt-engine-setup-plugin-ovirt-engine-4.4.1.2-0     6/633 
  Erasing          : rhvm-setup-plugins-4.4.2-1.el8ev.noarch              7/633 
  Erasing          : ovirt-engine-setup-4.4.1.2-0.10.el8ev.noarch         8/633 
  Erasing          : ovirt-engine-ui-extensions-1.2.0-1.el8ev.noarch      9/633 
  Erasing          : ovirt-engine-webadmin-portal-4.4.1.2-0.10.el8ev.    10/633 
  Erasing          : rhv-log-collector-analyzer-1.0.0-1.el8ev.noarch     11/633 
  Running scriptlet: ovirt-engine-4.4.1.2-0.10.el8ev.noarch              12/633 
  Erasing          : ovirt-engine-4.4.1.2-0.10.el8ev.noarch              12/633 
  Running scriptlet: ovirt-engine-4.4.1.2-0.10.el8ev.noarch              12/633 
  Erasing          : rhvm-4.4.1.2-0.10.el8ev.noarch                      13/633 
  Erasing          : ovirt-ansible-roles-1.2.3-1.el8ev.noarch            14/633 
  Erasing          : ansible-runner-service-1.0.2-1.el8ev.noarch         15/633 
  Erasing          : ovirt-log-collector-4.4.1-3.el8ev.noarch            16/633 
  Erasing          : openstack-java-resteasy-connector-3.2.8-1.el8ev.    17/633 
  Erasing          : resteasy-3.0.26-3.module+el8.1.0+3366+6dfb954c.n    18/633 
  Running scriptlet: ovirt-engine-tools-4.4.1.2-0.10.el8ev.noarch        19/633 
  Erasing          : ovirt-engine-tools-4.4.1.2-0.10.el8ev.noarch        19/633 
warning: file /var/run/ovirt-engine/notifier: remove failed: No such file or directory

  Running scriptlet: ovirt-engine-tools-4.4.1.2-0.10.el8ev.noarch        19/633 
  Running scriptlet: ovirt-engine-websocket-proxy-4.4.1.2-0.10.el8ev.    20/633 
  Erasing          : ovirt-engine-websocket-proxy-4.4.1.2-0.10.el8ev.    20/633 
  Running scriptlet: ovirt-engine-websocket-proxy-4.4.1.2-0.10.el8ev.    20/633 
  Erasing          : ovirt-engine-metrics-1.4.0.2-1.el8ev.noarch         21/633 
  Erasing          : httpcomponents-client-4.5.5-4.module+el8+2598+06    22/633 
  Erasing          : ovirt-ansible-hosted-engine-setup-1.1.4-1.el8ev.    23/633 
  Running scriptlet: eap7-wildfly-7.3.1-5.GA_redhat_00003.1.el8eap.no    24/633 
  Erasing          : eap7-wildfly-7.3.1-5.GA_redhat_00003.1.el8eap.no    24/633 
  Running scriptlet: eap7-wildfly-7.3.1-5.GA_redhat_00003.1.el8eap.no    24/633 
  Erasing          : eap7-wildfly-modules-7.3.1-5.GA_redhat_00003.1.e    25/633 
  Erasing          : eap7-picketlink-federation-2.5.5-20.SP12_redhat_    26/633 
  Erasing          : eap7-wildfly-transaction-client-1.1.11-1.Final_r    27/633 
  Erasing          : eap7-wildfly-naming-client-1.0.12-1.Final_redhat    28/633 
  Erasing          : eap7-jboss-jsf-api_2.3_spec-3.0.0-3.SP02_redhat_    29/633 
  Erasing          : eap7-picketlink-impl-2.5.5-20.SP12_redhat_00009.    30/633 
  Erasing          : eap7-activemq-artemis-cli-2.9.0-4.redhat_00010.1    31/633 
  Erasing          : eap7-activemq-artemis-jms-server-2.9.0-4.redhat_    32/633 
  Erasing          : eap7-ironjacamar-validator-1.4.20-1.Final_redhat    33/633 
  Erasing          : eap7-jackson-datatype-jsr310-2.10.3-1.redhat_000    34/633 
  Erasing          : eap7-shibboleth-java-support-7.3.0-1.redhat_0000    35/633 
  Erasing          : asciidoc-8.6.10-0.5.20180627gitf7c2274.el8.noarc    36/633 
  Erasing          : ovirt-engine-dwh-setup-4.4.0.2-1.el8ev.noarch       37/633 
  Erasing          : ovirt-engine-extension-aaa-jdbc-1.2.0-1.el8ev.no    38/633 
  Erasing          : vdsm-jsonrpc-java-1.5.4-1.el8ev.noarch              39/633 
  Erasing          : eap7-picketlink-config-2.5.5-20.SP12_redhat_0000    40/633 
  Erasing          : eap7-picketlink-idm-impl-2.5.5-20.SP12_redhat_00    41/633 
  Erasing          : eap7-bouncycastle-mail-1.60.0-2.redhat_00002.1.e    42/633 
  Erasing          : eap7-codehaus-jackson-jaxrs-1.9.13-10.redhat_000    43/633 
  Erasing          : eap7-codehaus-jackson-xc-1.9.13-10.redhat_00007.    44/633 
  Erasing          : eap7-hibernate-envers-5.3.16-1.Final_redhat_0000    45/633 
  Erasing          : eap7-hibernate-search-orm-5.10.7-1.Final_redhat_    46/633 
  Erasing          : eap7-hibernate-search-serialization-avro-5.10.7-    47/633 
  Erasing          : eap7-httpcomponents-asyncclient-4.1.4-1.redhat_0    48/633 
  Erasing          : eap7-infinispan-cachestore-remote-9.4.18-1.Final    49/633 
  Erasing          : eap7-ironjacamar-core-impl-1.4.20-1.Final_redhat    50/633 
  Erasing          : eap7-ironjacamar-common-impl-1.4.20-1.Final_redh    51/633 
  Erasing          : eap7-jackson-datatype-jdk8-2.10.3-1.redhat_00001    52/633 
  Erasing          : eap7-jackson-module-jaxb-annotations-2.10.3-1.re    53/633 
  Erasing          : eap7-jackson-databind-2.10.3-1.redhat_00001.1.el    54/633 
  Erasing          : eap7-jboss-server-migration-eap7.1-1.7.1-5.Final    55/633 
  Erasing          : eap7-jboss-server-migration-eap7.0-1.7.1-5.Final    56/633 
  Erasing          : eap7-jgroups-azure-1.2.1-1.Final_redhat_00001.1.    57/633 
  Erasing          : eap7-azure-storage-6.1.0-1.redhat_1.1.el8eap.noa    58/633 
  Erasing          : eap7-lucene-queryparser-5.5.5-3.redhat_2.1.el8ea    59/633 
  Erasing          : eap7-opensaml-xacml-saml-impl-3.3.1-1.redhat_000    60/633 
  Erasing          : eap7-opensaml-saml-impl-3.3.1-1.redhat_00002.1.e    61/633 
  Erasing          : eap7-opensaml-xmlsec-impl-3.3.1-1.redhat_00002.1    62/633 
  Erasing          : eap7-opensaml-xacml-saml-api-3.3.1-1.redhat_0000    63/633 
  Erasing          : eap7-opensaml-saml-api-3.3.1-1.redhat_00002.1.el    64/633 
  Erasing          : eap7-opensaml-soap-api-3.3.1-1.redhat_00002.1.el    65/633 
  Erasing          : eap7-resteasy-atom-provider-3.11.2-3.Final_redha    66/633 
  Erasing          : eap7-resteasy-crypto-3.11.2-3.Final_redhat_00002    67/633 
  Erasing          : eap7-resteasy-multipart-provider-3.11.2-3.Final_    68/633 
  Erasing          : eap7-slf4j-ext-1.7.22-4.redhat_2.1.el8eap.noarch    69/633 
  Erasing          : eap7-taglibs-standard-compat-1.2.6-2.RC1_redhat_    70/633 
  Erasing          : eap7-weld-core-jsf-3.1.4-1.Final_redhat_00001.1.    71/633 
  Erasing          : eap7-weld-probe-core-3.1.4-1.Final_redhat_00001.    72/633 
  Erasing          : eap7-wss4j-ws-security-policy-stax-2.2.5-1.redha    73/633 
  Erasing          : eap7-wss4j-ws-security-stax-2.2.5-1.redhat_00001    74/633 
  Erasing          : eap7-xom-1.2.10-4.redhat_1.1.el8eap.noarch          75/633 
  Erasing          : glassfish-jaxb-runtime-2.2.11-11.module+el8.1.0+    76/633 
  Erasing          : glassfish-jaxb-core-2.2.11-11.module+el8.1.0+336    77/633 
  Erasing          : openstack-java-cinder-client-3.2.8-1.el8ev.noarc    78/633 
  Erasing          : openstack-java-glance-client-3.2.8-1.el8ev.noarc    79/633 
  Erasing          : openstack-java-keystone-client-3.2.8-1.el8ev.noa    80/633 
  Erasing          : openstack-java-quantum-client-3.2.8-1.el8ev.noar    81/633 
  Erasing          : ovirt-engine-vmconsole-proxy-helper-4.4.1.2-0.10    82/633 
  Erasing          : glassfish-fastinfoset-1.2.13-9.module+el8.1.0+33    83/633 
  Erasing          : eap7-wss4j-bindings-2.2.5-1.redhat_00001.1.el8ea    84/633 
  Erasing          : eap7-wss4j-policy-2.2.5-1.redhat_00001.1.el8eap.    85/633 
  Erasing          : eap7-neethi-3.1.1-1.redhat_1.1.el8eap.noarch        86/633 
  Erasing          : eap7-resteasy-client-3.11.2-3.Final_redhat_00002    87/633 
  Erasing          : eap7-opensaml-xmlsec-api-3.3.1-1.redhat_00002.1.    88/633 
  Erasing          : eap7-opensaml-profile-api-3.3.1-1.redhat_00002.1    89/633 
  Erasing          : eap7-opensaml-security-impl-3.3.1-1.redhat_00002    90/633 
  Erasing          : eap7-opensaml-security-api-3.3.1-1.redhat_00002.    91/633 
  Erasing          : eap7-jboss-server-migration-eap6.4-1.7.1-5.Final    92/633 
  Erasing          : eap7-jboss-server-migration-wildfly10.1-1.7.1-5.    93/633 
  Erasing          : eap7-jboss-server-migration-wildfly10.0-1.7.1-5.    94/633 
  Erasing          : eap7-infinispan-client-hotrod-9.4.18-1.Final_red    95/633 
  Erasing          : eap7-infinispan-core-9.4.18-1.Final_redhat_00001    96/633 
  Erasing          : eap7-hibernate-entitymanager-5.3.16-1.Final_redh    97/633 
  Erasing          : eap7-codehaus-jackson-mapper-asl-1.9.13-10.redha    98/633 
  Erasing          : eap7-bouncycastle-pkix-1.60.0-2.redhat_00002.1.e    99/633 
  Erasing          : eap7-activemq-artemis-dto-2.9.0-4.redhat_00010.1   100/633 
  Erasing          : eap7-picketlink-api-2.5.5-20.SP12_redhat_00009.1   101/633 
  Erasing          : eap7-picketlink-idm-api-2.5.5-20.SP12_redhat_000   102/633 
  Erasing          : eap7-picketlink-common-2.5.5-20.SP12_redhat_0000   103/633 
  Erasing          : eap7-jboss-marshalling-river-2.0.9-1.Final_redha   104/633 
  Erasing          : eap7-wildfly-client-config-1.0.1-2.Final_redhat_   105/633 
  Erasing          : eap7-activemq-artemis-hornetq-protocol-2.9.0-4.r   106/633 
  Erasing          : eap7-activemq-artemis-hqclient-protocol-2.9.0-4.   107/633 
  Erasing          : eap7-activemq-artemis-server-2.9.0-4.redhat_0001   108/633 
  Erasing          : eap7-activemq-artemis-jdbc-store-2.9.0-4.redhat_   109/633 
  Erasing          : eap7-activemq-artemis-ra-2.9.0-4.redhat_00010.1.   110/633 
  Erasing          : eap7-activemq-artemis-service-extensions-2.9.0-4   111/633 
  Erasing          : eap7-activemq-artemis-jms-client-2.9.0-4.redhat_   112/633 
  Erasing          : eap7-activemq-artemis-core-client-2.9.0-4.redhat   113/633 
  Erasing          : eap7-activemq-artemis-journal-2.9.0-4.redhat_000   114/633 
  Erasing          : eap7-activemq-artemis-commons-2.9.0-4.redhat_000   115/633 
  Erasing          : eap7-cxf-xjc-bug986-3.3.0-1.redhat_00001.1.el8ea   116/633 
  Erasing          : eap7-hibernate-search-backend-jms-5.10.7-1.Final   117/633 
  Erasing          : eap7-hibernate-search-engine-5.10.7-1.Final_redh   118/633 
  Erasing          : eap7-lucene-facet-5.5.5-3.redhat_2.1.el8eap.noar   119/633 
  Erasing          : eap7-lucene-queries-5.5.5-3.redhat_2.1.el8eap.no   120/633 
  Erasing          : eap7-hibernate-commons-annotations-5.0.5-1.Final   121/633 
  Erasing          : eap7-lucene-analyzers-common-5.5.5-3.redhat_2.1.   122/633 
  Erasing          : eap7-hibernate-validator-cdi-6.0.18-1.Final_redh   123/633 
  Erasing          : eap7-hibernate-validator-6.0.18-1.Final_redhat_0   124/633 
  Erasing          : eap7-hornetq-jms-client-2.4.7-7.Final_redhat_2.1   125/633 
  Erasing          : eap7-hornetq-core-client-2.4.7-7.Final_redhat_2.   126/633 
  Erasing          : eap7-jboss-server-migration-cli-1.7.1-5.Final_re   127/633 
  Erasing          : eap7-jboss-server-migration-wildfly8.2-1.7.1-5.F   128/633 
  Erasing          : eap7-jboss-server-migration-wildfly9.0-1.7.1-5.F   129/633 
  Erasing          : eap7-lucene-backward-codecs-5.5.5-3.redhat_2.1.e   130/633 
  Erasing          : eap7-lucene-misc-5.5.5-3.redhat_2.1.el8eap.noarc   131/633 
  Erasing          : eap7-mustache-java-compiler-0.9.4-2.redhat_1.1.e   132/633 
  Erasing          : eap7-narayana-restat-api-5.9.8-1.Final_redhat_00   133/633 
  Erasing          : eap7-opensaml-xacml-impl-3.3.1-1.redhat_00002.1.   134/633 
  Erasing          : eap7-opensaml-xacml-api-3.3.1-1.redhat_00002.1.e   135/633 
  Erasing          : eap7-opensaml-core-3.3.1-1.redhat_00002.1.el8eap   136/633 
  Erasing          : eap7-resteasy-cdi-3.11.2-3.Final_redhat_00002.1.   137/633 
  Erasing          : eap7-resteasy-jettison-provider-3.11.2-3.Final_r   138/633 
  Erasing          : eap7-resteasy-jose-jwt-3.11.2-3.Final_redhat_000   139/633 
  Erasing          : eap7-resteasy-jsapi-3.11.2-3.Final_redhat_00002.   140/633 
  Erasing          : eap7-resteasy-rxjava2-3.11.2-3.Final_redhat_0000   141/633 
  Erasing          : eap7-resteasy-spring-3.11.2-3.Final_redhat_00002   142/633 
  Erasing          : eap7-resteasy-yaml-provider-3.11.2-3.Final_redha   143/633 
  Erasing          : eap7-vdx-wildfly-1.1.6-2.redhat_1.1.el8eap.noarc   144/633 
  Erasing          : eap7-weld-ejb-3.1.4-1.Final_redhat_00001.1.el8ea   145/633 
  Erasing          : eap7-weld-jta-3.1.4-1.Final_redhat_00001.1.el8ea   146/633 
  Erasing          : eap7-weld-web-3.1.4-1.Final_redhat_00001.1.el8ea   147/633 
  Erasing          : eap7-weld-core-impl-3.1.4-1.Final_redhat_00001.1   148/633 
  Erasing          : eap7-wildfly-discovery-client-1.2.0-1.Final_redh   149/633 
  Erasing          : eap7-wildfly-common-1.5.1-1.Final_redhat_00001.1   150/633 
  Erasing          : eap7-wss4j-ws-security-dom-2.2.5-1.redhat_00001.   151/633 
  Erasing          : eap7-wss4j-ws-security-common-2.2.5-1.redhat_000   152/633 
  Erasing          : eap7-xml-security-2.1.4-1.redhat_00001.1.el8eap.   153/633 
  Erasing          : eap7-woodstox-core-6.0.3-1.redhat_00001.1.el8eap   154/633 
  Erasing          : ovirt-ansible-vm-infra-1.2.3-1.el8ev.noarch        155/633 
  Erasing          : ovirt-engine-tools-backup-4.4.1.2-0.10.el8ev.noa   156/633 
  Erasing          : jackson-jaxrs-json-provider-2.9.9-1.module+el8.1   157/633 
  Erasing          : jackson-module-jaxb-annotations-2.7.6-4.module+e   158/633 
  Erasing          : jackson-jaxrs-providers-2.9.9-1.module+el8.1.0+3   159/633 
  Erasing          : python3-flask-restful-0.3.6-8.el8ost.noarch        160/633 
  Erasing          : python3-flask-1:1.0.2-2.el8ost.noarch              161/633 
  Erasing          : apache-commons-configuration-1.10-1.el8ev.noarch   162/633 
  Erasing          : xmlrpc-client-3.1.3-1.el8ev.noarch                 163/633 
  Running scriptlet: insights-client-3.0.13-1.el8.noarch                164/633 
  Erasing          : insights-client-3.0.13-1.el8.noarch                164/633 
  Running scriptlet: insights-client-3.0.13-1.el8.noarch                164/633 
  Erasing          : novnc-1.1.0-1.el8ost.noarch                        165/633 
  Erasing          : xmlrpc-common-3.1.3-1.el8ev.noarch                 166/633 
  Erasing          : eap7-stax2-api-4.2.0-1.redhat_00001.1.el8eap.noa   167/633 
  Erasing          : eap7-apache-commons-codec-1.11.0-2.redhat_00001.   168/633 
  Erasing          : eap7-slf4j-api-1.7.22-4.redhat_2.1.el8eap.noarch   169/633 
  Erasing          : eap7-jasypt-1.9.3-1.redhat_00001.1.el8eap.noarch   170/633 
  Erasing          : eap7-jboss-logging-3.4.1-2.Final_redhat_00001.1.   171/633 
  Erasing          : eap7-weld-cdi-2.0-api-2.0.2-2.redhat_00002.1.el8   172/633 
  Erasing          : eap7-vdx-core-1.1.6-2.redhat_1.1.el8eap.noarch     173/633 
  Erasing          : eap7-resteasy-jaxrs-3.11.2-3.Final_redhat_00002.   174/633 
  Erasing          : eap7-resteasy-jackson-provider-3.11.2-3.Final_re   175/633 
  Erasing          : eap7-resteasy-jaxb-provider-3.11.2-3.Final_redha   176/633 
  Erasing          : eap7-joda-time-2.9.7-2.redhat_1.1.el8eap.noarch    177/633 
  Erasing          : eap7-narayana-restat-util-5.9.8-1.Final_redhat_0   178/633 
  Erasing          : eap7-guava-25.0.0-2.redhat_1.1.el8eap.noarch       179/633 
  Erasing          : eap7-lucene-core-5.5.5-3.redhat_2.1.el8eap.noarc   180/633 
  Erasing          : eap7-jboss-server-migration-core-1.7.1-5.Final_r   181/633 
  Erasing          : eap7-hornetq-commons-2.4.7-7.Final_redhat_2.1.el   182/633 
  Erasing          : eap7-java-classmate-1.3.4-1.redhat_1.1.el8eap.no   183/633 
  Erasing          : eap7-hibernate-beanvalidation-api-2.0.2-1.redhat   184/633 
  Erasing          : eap7-apache-commons-lang-3.9.0-1.redhat_00001.1.   185/633 
  Erasing          : eap7-apache-commons-beanutils-1.9.4-1.redhat_000   186/633 
  Erasing          : eap7-netty-all-4.1.45-1.Final_redhat_00001.1.el8   187/633 
  Erasing          : eap7-activemq-artemis-selector-2.9.0-4.redhat_00   188/633 
  Erasing          : eap7-jgroups-4.1.4-1.Final_redhat_00001.1.el8eap   189/633 
  Erasing          : eap7-atinject-1.0.0-4.redhat_00002.1.el8eap.noar   190/633 
  Erasing          : eap7-jboss-marshalling-2.0.9-1.Final_redhat_0000   191/633 
  Erasing          : eap7-bouncycastle-prov-1.60.0-2.redhat_00002.1.e   192/633 
  Erasing          : eap7-codehaus-jackson-core-asl-1.9.13-10.redhat_   193/633 
  Erasing          : eap7-hibernate-core-5.3.16-1.Final_redhat_00001.   194/633 
  Erasing          : eap7-infinispan-commons-9.4.18-1.Final_redhat_00   195/633 
  Erasing          : xmlstreambuffer-1.5.4-8.module+el8.1.0+3366+6dfb   196/633 
  Erasing          : stax-ex-1.7.7-8.module+el8.1.0+3366+6dfb954c.noa   197/633 
  Erasing          : xsom-0-19.20110809svn.module+el8.1.0+3366+6dfb95   198/633 
  Erasing          : ovirt-engine-setup-plugin-vmconsole-proxy-helper   199/633 
  Running scriptlet: ovirt-vmconsole-proxy-1.0.8-1.el8ev.noarch         200/633 
  Erasing          : ovirt-vmconsole-proxy-1.0.8-1.el8ev.noarch         200/633 
  Running scriptlet: ovirt-vmconsole-proxy-1.0.8-1.el8ev.noarch         200/633 
  Erasing          : openstack-java-client-3.2.8-1.el8ev.noarch         201/633 
  Erasing          : openstack-java-quantum-model-3.2.8-1.el8ev.noarc   202/633 
  Erasing          : openstack-java-keystone-model-3.2.8-1.el8ev.noar   203/633 
  Erasing          : openstack-java-glance-model-3.2.8-1.el8ev.noarch   204/633 
  Erasing          : openstack-java-cinder-model-3.2.8-1.el8ev.noarch   205/633 
  Erasing          : jackson-databind-2.10.0-1.module+el8.2.0+5059+3e   206/633 
  Erasing          : istack-commons-runtime-2.21-9.el8+7.noarch         207/633 
  Erasing          : eap7-jaxen-1.1.6-14.redhat_2.1.el8eap.noarch       208/633 
  Erasing          : eap7-xerces-j2-2.12.0-1.SP02_redhat_00001.1.el8e   209/633 
  Erasing          : eap7-taglibs-standard-impl-1.2.6-2.RC1_redhat_1.   210/633 
  Erasing          : eap7-taglibs-standard-spec-1.2.6-2.RC1_redhat_1.   211/633 
  Erasing          : eap7-cal10n-0.8.1-6.redhat_1.1.el8eap.noarch       212/633 
  Erasing          : eap7-httpcomponents-client-4.5.4-1.redhat_00001.   213/633 
  Erasing          : eap7-jackson-core-2.10.3-1.redhat_00001.1.el8eap   214/633 
  Erasing          : eap7-jackson-annotations-2.10.3-1.redhat_00001.1   215/633 
  Erasing          : eap7-ironjacamar-common-api-1.4.20-1.Final_redha   216/633 
  Erasing          : eap7-ironjacamar-common-spi-1.4.20-1.Final_redha   217/633 
  Erasing          : eap7-ironjacamar-core-api-1.4.20-1.Final_redhat_   218/633 
  Erasing          : eap7-httpcomponents-core-4.4.5-1.redhat_00001.1.   219/633 
  Erasing          : eap7-avro-1.7.6-7.redhat_2.1.el8eap.noarch         220/633 
  Erasing          : docbook-style-xsl-1.79.2-7.el8.noarch              221/633 
  Running scriptlet: docbook-style-xsl-1.79.2-7.el8.noarch              221/633 
  Erasing          : docbook-dtds-1.0-69.el8.noarch                     222/633 
  Running scriptlet: docbook-dtds-1.0-69.el8.noarch                     222/633 
  Erasing          : eap7-jboss-el-api_3.0_spec-2.0.0-2.Final_redhat_   223/633 
  Erasing          : eap7-jboss-jsp-api_2.3_spec-2.0.0-1.Final_redhat   224/633 
  Erasing          : eap7-glassfish-jsf-2.3.9-10.SP09_redhat_00001.1.   225/633 
  Erasing          : eap7-jboss-remoting-5.0.18-1.Final_redhat_00001.   226/633 
  Erasing          : eap7-wildfly-elytron-1.10.6-1.Final_redhat_00001   227/633 
  Erasing          : eap7-jboss-xnio-base-3.7.7-1.Final_redhat_00001.   228/633 
  Erasing          : eap7-jboss-security-xacml-2.0.8-17.Final_redhat_   229/633 
  Erasing          : eap7-picketlink-idm-simple-schema-2.5.5-20.SP12_   230/633 
  Erasing          : eap7-FastInfoset-1.2.13-10.redhat_1.1.el8eap.noa   231/633 
  Erasing          : eap7-activemq-artemis-native-1:1.0.0.00003-2.red   232/633 
  Erasing          : eap7-activemq-artemis-tools-2.9.0-4.redhat_00010   233/633 
  Erasing          : eap7-aesh-extensions-1.8.0-1.redhat_00001.1.el8e   234/633 
  Erasing          : eap7-aesh-readline-2.0.0-1.redhat_00001.1.el8eap   235/633 
  Erasing          : eap7-agroal-api-1.3.0-1.redhat_00001.1.el8eap.no   236/633 
  Erasing          : eap7-agroal-narayana-1.3.0-1.redhat_00001.1.el8e   237/633 
  Erasing          : eap7-agroal-pool-1.3.0-1.redhat_00001.1.el8eap.n   238/633 
  Erasing          : eap7-antlr-2.7.7-54.redhat_7.1.el8eap.noarch       239/633 
  Erasing          : eap7-apache-commons-cli-1.3.1-3.redhat_2.1.el8ea   240/633 
  Erasing          : eap7-apache-commons-collections-3.2.2-9.redhat_2   241/633 
  Erasing          : eap7-apache-commons-io-2.5.0-4.redhat_3.1.el8eap   242/633 
  Erasing          : eap7-apache-commons-lang2-2.6.0-1.redhat_7.1.el8   243/633 
  Erasing          : eap7-apache-cxf-3.3.5-1.redhat_00001.1.el8eap.no   244/633 
  Erasing          : eap7-apache-cxf-rt-3.3.5-1.redhat_00001.1.el8eap   245/633 
  Erasing          : eap7-apache-cxf-services-3.3.5-1.redhat_00001.1.   246/633 
  Erasing          : eap7-apache-cxf-tools-3.3.5-1.redhat_00001.1.el8   247/633 
  Erasing          : eap7-apache-mime4j-0.6.0-4.redhat_7.1.el8eap.noa   248/633 
  Erasing          : eap7-artemis-wildfly-integration-1.0.2-4.redhat_   249/633 
  Erasing          : eap7-byte-buddy-1.9.11-1.redhat_00002.1.el8eap.n   250/633 
  Erasing          : eap7-caffeine-2.6.2-3.redhat_1.1.el8eap.noarch     251/633 
  Erasing          : eap7-codemodel-2.3.3-4.b02_redhat_00001.1.el8eap   252/633 
  Erasing          : eap7-commons-logging-jboss-logging-1.0.0-1.Final   253/633 
  Erasing          : eap7-cryptacular-1.2.4-1.redhat_00001.1.el8eap.n   254/633 
  Erasing          : eap7-cxf-xjc-boolean-3.3.0-1.redhat_00001.1.el8e   255/633 
  Erasing          : eap7-cxf-xjc-dv-3.3.0-1.redhat_00001.1.el8eap.no   256/633 
  Erasing          : eap7-cxf-xjc-runtime-3.3.0-1.redhat_00001.1.el8e   257/633 
  Erasing          : eap7-cxf-xjc-ts-3.3.0-1.redhat_00001.1.el8eap.no   258/633 
  Erasing          : eap7-dom4j-2.1.1-2.redhat_00001.1.el8eap.noarch    259/633 
  Erasing          : eap7-ecj-4.6.1-3.redhat_1.1.el8eap.noarch          260/633 
  Erasing          : eap7-eclipse-jgit-5.0.2.201807311906-2.r_redhat_   261/633 
  Erasing          : eap7-glassfish-concurrent-1.0.0-4.redhat_1.1.el8   262/633 
  Erasing          : eap7-glassfish-jaf-1.2.1-1.redhat_00002.1.el8eap   263/633 
  Erasing          : eap7-glassfish-javamail-1.6.4-2.redhat_00001.1.e   264/633 
  Erasing          : eap7-glassfish-json-1.1.6-2.redhat_00001.1.el8ea   265/633 
  Erasing          : eap7-gnu-getopt-1.0.13-6.redhat_5.1.el8eap.noarc   266/633 
  Erasing          : eap7-gson-2.8.2-1.redhat_5.1.el8eap.noarch         267/633 
  Erasing          : eap7-h2database-1.4.193-6.redhat_2.1.el8eap.noar   268/633 
  Erasing          : eap7-hal-console-3.2.8-1.Final_redhat_00001.1.el   269/633 
  Erasing          : eap7-infinispan-cachestore-jdbc-9.4.18-1.Final_r   270/633 
  Erasing          : eap7-infinispan-hibernate-cache-commons-9.4.18-1   271/633 
  Erasing          : eap7-infinispan-hibernate-cache-spi-9.4.18-1.Fin   272/633 
  Erasing          : eap7-infinispan-hibernate-cache-v53-9.4.18-1.Fin   273/633 
  Erasing          : eap7-ironjacamar-deployers-common-1.4.20-1.Final   274/633 
  Erasing          : eap7-ironjacamar-jdbc-1.4.20-1.Final_redhat_0000   275/633 
  Erasing          : eap7-istack-commons-runtime-3.0.10-1.redhat_0000   276/633 
  Erasing          : eap7-istack-commons-tools-3.0.10-1.redhat_00001.   277/633 
  Erasing          : eap7-jackson-coreutils-1.0.0-1.redhat_1.1.el8eap   278/633 
  Erasing          : eap7-jackson-jaxrs-base-2.10.3-1.redhat_00001.1.   279/633 
  Erasing          : eap7-jackson-jaxrs-json-provider-2.10.3-1.redhat   280/633 
  Erasing          : eap7-jaegertracing-jaeger-client-java-core-0.34.   281/633 
  Erasing          : eap7-jaegertracing-jaeger-client-java-thrift-0.3   282/633 
  Erasing          : eap7-jakarta-el-3.0.3-1.redhat_00002.1.el8eap.no   283/633 
  Erasing          : eap7-jakarta-security-enterprise-api-1.0.2-3.red   284/633 
  Erasing          : eap7-jandex-2.1.2-1.Final_redhat_00001.1.el8eap.   285/633 
  Erasing          : eap7-jansi-1.18.0-1.redhat_00001.1.el8eap.noarch   286/633 
  Erasing          : eap7-javaee-jpa-spec-2.2.3-1.redhat_00001.1.el8e   287/633 
  Erasing          : eap7-javaee-security-api-1.0.0-2.redhat_1.1.el8e   288/633 
  Erasing          : eap7-javaee-security-soteria-enterprise-1.0.1-3.   289/633 
  Erasing          : eap7-javaewah-1.1.6-1.redhat_00001.1.el8eap.noar   290/633 
  Erasing          : eap7-javassist-3.23.2-2.GA_redhat_00001.1.el8eap   291/633 
  Erasing          : eap7-jaxb-jxc-2.3.3-4.b02_redhat_00001.1.el8eap.   292/633 
  Erasing          : eap7-jaxb-runtime-2.3.3-4.b02_redhat_00001.1.el8   293/633 
  Erasing          : eap7-jaxb-xjc-2.3.3-4.b02_redhat_00001.1.el8eap.   294/633 
  Erasing          : eap7-jaxbintros-1.0.3-1.GA_redhat_00001.1.el8eap   295/633 
  Erasing          : eap7-jberet-core-1.3.5-1.Final_redhat_00001.1.el   296/633 
  Erasing          : eap7-jboss-aesh-2.4.0-1.redhat_00001.1.el8eap.no   297/633 
  Erasing          : eap7-jboss-annotations-api_1.3_spec-2.0.1-2.Fina   298/633 
  Erasing          : eap7-jboss-batch-api_1.0_spec-2.0.0-1.Final_redh   299/633 
  Erasing          : eap7-jboss-classfilewriter-1.2.4-1.Final_redhat_   300/633 
  Erasing          : eap7-jboss-common-beans-2.0.1-1.Final_redhat_000   301/633 
  Erasing          : eap7-jboss-concurrency-api_1.0_spec-2.0.0-1.Fina   302/633 
  Erasing          : eap7-jboss-connector-api_1.7_spec-2.0.0-2.Final_   303/633 
  Erasing          : eap7-jboss-dmr-1.5.0-2.Final_redhat_1.1.el8eap.n   304/633 
  Erasing          : eap7-jboss-ejb-api_3.2_spec-2.0.0-1.Final_redhat   305/633 
  Erasing          : eap7-jboss-ejb-client-4.0.31-1.Final_redhat_0000   306/633 
  Erasing          : eap7-jboss-ejb3-ext-api-2.3.0-1.Final_redhat_000   307/633 
  Erasing          : eap7-jboss-genericjms-2.0.4-1.Final_redhat_00001   308/633 
  Erasing          : eap7-jboss-iiop-client-1.0.1-3.Final_redhat_1.1.   309/633 
  Erasing          : eap7-jboss-interceptors-api_1.2_spec-2.0.0-3.Fin   310/633 
  Erasing          : eap7-jboss-invocation-1.5.2-1.Final_redhat_00001   311/633 
  Erasing          : eap7-jboss-j2eemgmt-api_1.1_spec-2.0.0-2.Final_r   312/633 
  Erasing          : eap7-jboss-jacc-api_1.5_spec-2.0.0-2.Final_redha   313/633 
  Erasing          : eap7-jboss-jaspi-api_1.1_spec-2.0.1-2.Final_redh   314/633 
  Erasing          : eap7-jboss-jaxb-api_2.3_spec-1.0.1-1.Final_redha   315/633 
  Erasing          : eap7-jboss-jaxrpc-api_1.1_spec-2.0.0-1.Final_red   316/633 
  Erasing          : eap7-jboss-jaxrs-api_2.1_spec-2.0.1-1.Final_redh   317/633 
  Erasing          : eap7-jboss-jaxws-api_2.3_spec-1.0.0-1.Final_redh   318/633 
  Erasing          : eap7-jboss-jms-api_2.0_spec-2.0.0-1.Final_redhat   319/633 
  Erasing          : eap7-jboss-logmanager-2.1.14-1.Final_redhat_0000   320/633 
  Erasing          : eap7-jboss-metadata-appclient-13.0.0-1.Final_red   321/633 
  Erasing          : eap7-jboss-metadata-common-13.0.0-1.Final_redhat   322/633 
  Erasing          : eap7-jboss-metadata-ear-13.0.0-1.Final_redhat_00   323/633 
  Erasing          : eap7-jboss-metadata-ejb-13.0.0-1.Final_redhat_00   324/633 
  Erasing          : eap7-jboss-metadata-web-13.0.0-1.Final_redhat_00   325/633 
  Erasing          : eap7-jboss-modules-1.10.0-1.Final_redhat_00001.1   326/633 
  Erasing          : eap7-jboss-msc-1.4.11-1.Final_redhat_00001.1.el8   327/633 
  Erasing          : eap7-jboss-openjdk-orb-8.1.4-3.Final_redhat_0000   328/633 
  Erasing          : eap7-jboss-remoting-jmx-3.0.4-1.Final_redhat_000   329/633 
  Erasing          : eap7-jboss-saaj-api_1.3_spec-1.0.6-1.Final_redha   330/633 
  Erasing          : eap7-jboss-saaj-api_1.4_spec-1.0.1-1.Final_redha   331/633 
  Erasing          : eap7-jboss-seam-int-7.0.0-6.GA_redhat_2.1.el8eap   332/633 
  Erasing          : eap7-jboss-security-negotiation-3.0.6-1.Final_re   333/633 
  Erasing          : eap7-jboss-server-migration-eap6.4-to-eap7.3-1.7   334/633 
  Erasing          : eap7-jboss-server-migration-eap7.2-1.7.1-5.Final   335/633 
  Erasing          : eap7-jboss-server-migration-eap7.2-to-eap7.3-1.7   336/633 
  Erasing          : eap7-jboss-server-migration-eap7.3-server-1.7.1-   337/633 
  Erasing          : eap7-jboss-server-migration-wildfly11.0-1.7.1-5.   338/633 
  Erasing          : eap7-jboss-server-migration-wildfly12.0-1.7.1-5.   339/633 
  Erasing          : eap7-jboss-server-migration-wildfly13.0-server-1   340/633 
  Erasing          : eap7-jboss-server-migration-wildfly14.0-server-1   341/633 
  Erasing          : eap7-jboss-server-migration-wildfly15.0-server-1   342/633 
  Erasing          : eap7-jboss-server-migration-wildfly16.0-server-1   343/633 
  Erasing          : eap7-jboss-server-migration-wildfly17.0-server-1   344/633 
  Erasing          : eap7-jboss-server-migration-wildfly18.0-server-1   345/633 
  Erasing          : eap7-jboss-servlet-api_4.0_spec-2.0.0-2.Final_re   346/633 
  Erasing          : eap7-jboss-stdio-1.1.0-1.Final_redhat_00001.1.el   347/633 
  Erasing          : eap7-jboss-threads-2.3.3-1.Final_redhat_00001.1.   348/633 
  Erasing          : eap7-jboss-transaction-api_1.3_spec-2.0.0-3.Fina   349/633 
  Erasing          : eap7-jboss-transaction-spi-7.6.0-2.Final_redhat_   350/633 
  Erasing          : eap7-jboss-vfs-3.2.15-1.Final_redhat_00001.1.el8   351/633 
  Erasing          : eap7-jboss-websocket-api_1.1_spec-2.0.0-1.Final_   352/633 
  Erasing          : eap7-jboss-weld-3.1-api-weld-api-3.1.0-6.SP2_red   353/633 
  Erasing          : eap7-jboss-weld-3.1-api-weld-spi-3.1.0-6.SP2_red   354/633 
  Erasing          : eap7-jbossws-api-1.1.2-1.Final_redhat_00001.1.el   355/633 
  Erasing          : eap7-jbossws-common-3.2.3-1.Final_redhat_00001.1   356/633 
  Erasing          : eap7-jbossws-common-tools-1.3.2-1.Final_redhat_0   357/633 
  Erasing          : eap7-jbossws-cxf-5.3.0-1.Final_redhat_00001.1.el   358/633 
  Erasing          : eap7-jbossws-jaxws-undertow-httpspi-1.0.1-3.Fina   359/633 
  Erasing          : eap7-jbossws-spi-3.2.3-1.Final_redhat_00001.1.el   360/633 
  Erasing          : eap7-jcip-annotations-1.0.0-5.redhat_8.1.el8eap.   361/633 
  Erasing          : eap7-jettison-1.4.0-1.redhat_00001.1.el8eap.noar   362/633 
  Erasing          : eap7-jgroups-kubernetes-1.0.13-1.Final_redhat_00   363/633 
  Erasing          : eap7-jsch-0.1.54-7.redhat_00001.1.el8eap.noarch    364/633 
  Erasing          : eap7-json-patch-1.9.0-1.redhat_00002.1.el8eap.no   365/633 
  Erasing          : eap7-jsonb-spec-1.0.2-1.redhat_00001.1.el8eap.no   366/633 
  Erasing          : eap7-jsoup-1.8.3-4.redhat_2.1.el8eap.noarch        367/633 
  Erasing          : eap7-jul-to-slf4j-stub-1.0.1-7.Final_redhat_3.1.   368/633 
  Erasing          : eap7-jzlib-1.1.1-7.redhat_00001.1.el8eap.noarch    369/633 
  Erasing          : eap7-log4j-jboss-logmanager-1.2.0-1.Final_redhat   370/633 
  Erasing          : eap7-microprofile-config-api-1.4.0-1.redhat_0000   371/633 
  Erasing          : eap7-microprofile-health-2.2.0-1.redhat_00001.1.   372/633 
  Erasing          : eap7-microprofile-metrics-api-2.3.0-1.redhat_000   373/633 
  Erasing          : eap7-microprofile-opentracing-api-1.3.3-1.redhat   374/633 
  Erasing          : eap7-microprofile-rest-client-api-1.4.0-1.redhat   375/633 
  Erasing          : eap7-mod_cluster-1.4.1-1.Final_redhat_00001.1.el   376/633 
  Erasing          : eap7-narayana-compensations-5.9.8-1.Final_redhat   377/633 
  Erasing          : eap7-narayana-jbosstxbridge-5.9.8-1.Final_redhat   378/633 
  Erasing          : eap7-narayana-jbossxts-5.9.8-1.Final_redhat_0000   379/633 
  Erasing          : eap7-narayana-jts-idlj-5.9.8-1.Final_redhat_0000   380/633 
  Erasing          : eap7-narayana-jts-integration-5.9.8-1.Final_redh   381/633 
  Erasing          : eap7-narayana-restat-bridge-5.9.8-1.Final_redhat   382/633 
  Erasing          : eap7-narayana-restat-integration-5.9.8-1.Final_r   383/633 
  Erasing          : eap7-narayana-txframework-5.9.8-1.Final_redhat_0   384/633 
  Erasing          : eap7-netty-xnio-transport-0.1.6-1.Final_redhat_0   385/633 
  Erasing          : eap7-objectweb-asm-7.1.0-1.redhat_00001.1.el8eap   386/633 
  Erasing          : eap7-okhttp-3.9.0-3.redhat_3.1.el8eap.noarch       387/633 
  Erasing          : eap7-okio-1.13.0-2.redhat_3.1.el8eap.noarch        388/633 
  Erasing          : eap7-opentracing-contrib-java-concurrent-0.2.1-1   389/633 
  Erasing          : eap7-opentracing-contrib-java-jaxrs-0.4.1-1.redh   390/633 
  Erasing          : eap7-opentracing-contrib-java-tracerresolver-0.1   391/633 
  Erasing          : eap7-opentracing-contrib-java-web-servlet-filter   392/633 
  Erasing          : eap7-opentracing-interceptors-0.0.4-1.redhat_000   393/633 
  Erasing          : eap7-opentracing-java-api-0.31.0-1.redhat_00008.   394/633 
  Erasing          : eap7-opentracing-java-noop-0.31.0-1.redhat_00008   395/633 
  Erasing          : eap7-opentracing-java-util-0.31.0-1.redhat_00008   396/633 
  Erasing          : eap7-picketbox-5.0.3-7.Final_redhat_00006.1.el8e   397/633 
  Erasing          : eap7-picketbox-commons-1.0.0-4.final_redhat_5.1.   398/633 
  Erasing          : eap7-picketbox-infinispan-5.0.3-7.Final_redhat_0   399/633 
  Erasing          : eap7-picketlink-wildfly8-2.5.5-23.SP12_redhat_00   400/633 
  Erasing          : eap7-reactive-streams-1.0.2-2.redhat_1.1.el8eap.   401/633 
  Erasing          : eap7-reactivex-rxjava-2.2.5-1.redhat_00001.1.el8   402/633 
  Erasing          : eap7-relaxng-datatype-2.3.3-4.b02_redhat_00001.1   403/633 
  Erasing          : eap7-resteasy-client-microprofile-3.11.2-3.Final   404/633 
  Erasing          : eap7-resteasy-jackson2-provider-3.11.2-3.Final_r   405/633 
  Erasing          : eap7-resteasy-json-binding-provider-3.11.2-3.Fin   406/633 
  Erasing          : eap7-resteasy-json-p-provider-3.11.2-3.Final_red   407/633 
  Erasing          : eap7-resteasy-validator-provider-11-3.11.2-3.Fin   408/633 
  Erasing          : eap7-rngom-2.3.3-4.b02_redhat_00001.1.el8eap.noa   409/633 
  Erasing          : eap7-slf4j-jboss-logmanager-1.0.4-1.GA_redhat_00   410/633 
  Erasing          : eap7-smallrye-config-1.6.2-3.redhat_00004.1.el8e   411/633 
  Erasing          : eap7-smallrye-health-2.2.0-1.redhat_00004.1.el8e   412/633 
  Erasing          : eap7-smallrye-metrics-2.4.0-1.redhat_00004.1.el8   413/633 
  Erasing          : eap7-smallrye-opentracing-1.3.4-1.redhat_00004.1   414/633 
  Erasing          : eap7-snakeyaml-1.24.0-2.redhat_00001.1.el8eap.no   415/633 
  Erasing          : eap7-stax-ex-1.7.8-1.redhat_00001.1.el8eap.noarc   416/633 
  Erasing          : eap7-staxmapper-1.3.0-2.Final_redhat_1.1.el8eap.   417/633 
  Erasing          : eap7-sun-saaj-1.3-impl-1.3.16-18.SP1_redhat_6.1.   418/633 
  Erasing          : eap7-sun-saaj-1.4-impl-1.4.1-1.SP1_redhat_00001.   419/633 
  Erasing          : eap7-sun-ws-metadata-2.0-api-1.0.0-7.MR1_redhat_   420/633 
  Erasing          : eap7-thrift-0.13.0-1.redhat_00002.1.el8eap.noarc   421/633 
  Erasing          : eap7-txw2-2.3.3-4.b02_redhat_00001.1.el8eap.noar   422/633 
  Erasing          : eap7-undertow-2.0.30-3.SP3_redhat_00001.1.el8eap   423/633 
  Erasing          : eap7-undertow-jastow-2.0.8-1.Final_redhat_00001.   424/633 
  Erasing          : eap7-undertow-js-1.0.2-2.Final_redhat_1.1.el8eap   425/633 
  Erasing          : eap7-undertow-server-1.6.1-1.Final_redhat_00001.   426/633 
  Erasing          : eap7-velocity-engine-core-2.1.0-1.redhat_00001.1   427/633 
  Erasing          : eap7-wildfly-elytron-tool-1.10.6-1.Final_redhat_   428/633 
  Erasing          : eap7-wildfly-http-client-common-1.0.20-1.Final_r   429/633 
  Erasing          : eap7-wildfly-http-ejb-client-1.0.20-1.Final_redh   430/633 
  Erasing          : eap7-wildfly-http-naming-client-1.0.20-1.Final_r   431/633 
  Erasing          : eap7-wildfly-http-transaction-client-1.0.20-1.Fi   432/633 
  Erasing          : eap7-wildfly-openssl-java-1.0.9-2.SP03_redhat_00   433/633 
  Erasing          : eap7-ws-commons-XmlSchema-2.2.4-1.redhat_00001.1   434/633 
  Erasing          : eap7-wsdl4j-1.6.3-13.redhat_2.1.el8eap.noarch      435/633 
  Erasing          : eap7-xalan-j2-2.7.1-35.redhat_12.1.el8eap.noarch   436/633 
  Erasing          : eap7-xml-resolver-1.2.0-7.redhat_12.1.el8eap.noa   437/633 
  Erasing          : eap7-xsom-2.3.3-4.b02_redhat_00001.1.el8eap.noar   438/633 
  Erasing          : eap7-yasson-1.0.5-1.redhat_00001.1.el8eap.noarch   439/633 
  Erasing          : ovirt-ansible-engine-setup-1.2.4-1.el8ev.noarch    440/633 
  Erasing          : ovirt-ansible-image-template-1.2.2-1.el8ev.noarc   441/633 
  Erasing          : ovirt-engine-setup-plugin-websocket-proxy-4.4.1.   442/633 
  Erasing          : ovirt-engine-setup-plugin-ovirt-engine-common-4.   443/633 
  Erasing          : ovirt-engine-setup-base-4.4.1.2-0.10.el8ev.noarc   444/633 
  Erasing          : python3-ovirt-engine-lib-4.4.1.2-0.10.el8ev.noar   445/633 
  Erasing          : python3-paramiko-2.4.3-2.el8ev.noarch              446/633 
  Erasing          : jboss-logging-tools-2.0.1-6.el8.noarch             447/633 
  Erasing          : ansible-runner-1.4.5-1.el8ar.noarch                448/633 
  Erasing          : python3-ansible-runner-1.4.5-1.el8ar.noarch        449/633 
  Erasing          : python3-daemon-2.1.2-9.el8ar.noarch                450/633 
  Erasing          : python3-pexpect-4.6-2.el8ost.noarch                451/633 
  Erasing          : ovirt-ansible-cluster-upgrade-1.2.2-1.el8ev.noar   452/633 
  Erasing          : ovirt-ansible-disaster-recovery-1.3.0-0.1.master   453/633 
  Erasing          : ovirt-ansible-infra-1.2.1-1.el8ev.noarch           454/633 
  Erasing          : ovirt-ansible-manageiq-1.2.1-2.el8ev.noarch        455/633 
  Erasing          : ovirt-ansible-repositories-1.2.3-1.el8ev.noarch    456/633 
  Erasing          : ovirt-ansible-shutdown-env-1.0.4-1.el8ev.noarch    457/633 
  Erasing          : ansible-2.9.9-1.el8ae.noarch                       458/633 
  Erasing          : ovirt-cockpit-sso-0.1.4-1.el8ev.noarch             459/633 
warning: /usr/share/ovirt-cockpit-sso/config/cockpit/cockpit.conf saved as /usr/share/ovirt-cockpit-sso/config/cockpit/cockpit.conf.rpmsave

  Running scriptlet: ovirt-cockpit-sso-0.1.4-1.el8ev.noarch             459/633 
rm: cannot remove '/usr/share/ovirt-cockpit-sso/config/cockpit/ws-certs.d': No such file or directory
rm: cannot remove '/usr/share/ovirt-cockpit-sso/ca.pem': No such file or directory
Warning: NOT_ENABLED: 9986:tcp

  Running scriptlet: ovirt-imageio-daemon-2.0.6-0.el8ev.x86_64          460/633 
  Erasing          : ovirt-imageio-daemon-2.0.6-0.el8ev.x86_64          460/633 
  Running scriptlet: ovirt-imageio-daemon-2.0.6-0.el8ev.x86_64          460/633 
  Erasing          : postgresql-jdbc-42.2.3-1.el8.noarch                461/633 
  Erasing          : ongres-scram-client-1.0.0~beta.2-5.el8.noarch      462/633 
  Erasing          : python3-mod_wsgi-4.6.4-4.el8.x86_64                463/633 
  Erasing          : snmp4j-2.4.1-1.el8ev.noarch                        464/633 
  Erasing          : engine-db-query-1.5.0-1.el8ev.noarch               465/633 
  Running scriptlet: log4j12-1.2.17-22.el8ev.noarch                     466/633 
  Erasing          : log4j12-1.2.17-22.el8ev.noarch                     466/633 
  Running scriptlet: log4j12-1.2.17-22.el8ev.noarch                     466/633 
  Erasing          : ongres-scram-1.0.0~beta.2-5.el8.noarch             467/633 
  Erasing          : cockpit-dashboard-211.3-1.el8.noarch               468/633 
  Erasing          : python3-jmespath-0.9.0-11.el8.noarch               469/633 
  Erasing          : python3-ptyprocess-0.5.2-4.el8.noarch              470/633 
  Erasing          : python3-docutils-0.14-12.module+el8.1.0+3334+5cb   471/633 
  Erasing          : python3-lockfile-1:0.11.0-8.el8ar.noarch           472/633 
  Erasing          : jdeparser-2.0.0-5.el8.noarch                       473/633 
  Erasing          : python3-ovirt-setup-lib-1.3.0-1.el8ev.noarch       474/633 
  Erasing          : sgml-common-0.6.3-50.el8.noarch                    475/633 
  Erasing          : javapackages-tools-5.3.0-2.module+el8+2598+06bab   476/633 
  Erasing          : jackson-annotations-2.10.0-1.module+el8.2.0+5059   477/633 
  Erasing          : jackson-core-2.10.0-1.module+el8.2.0+5059+3eb3af   478/633 
  Erasing          : ovirt-vmconsole-1.0.8-1.el8ev.noarch               479/633 
  Running scriptlet: ovirt-vmconsole-1.0.8-1.el8ev.noarch               479/633 
  Erasing          : relaxngDatatype-2011.1-7.module+el8.1.0+3366+6df   480/633 
  Erasing          : bea-stax-api-1.2.0-16.module+el8.1.0+3366+6dfb95   481/633 
  Erasing          : ws-commons-util-1.0.2-1.el8ev.noarch               482/633 
  Erasing          : python3-websockify-0.8.0-12.el8ev.noarch           483/633 
  Erasing          : python3-magic-5.33-13.el8.noarch                   484/633 
  Erasing          : apache-commons-lang-2.6-21.module+el8.1.0+3366+6   485/633 
  Erasing          : apache-commons-logging-1.2-13.module+el8+2598+06   486/633 
  Erasing          : python3-click-6.7-8.el8.noarch                     487/633 
  Erasing          : python3-itsdangerous-0.24-14.el8.noarch            488/633 
  Erasing          : python3-werkzeug-0.16.0-1.el8ost.noarch            489/633 
  Erasing          : python3-aniso8601-0.82-4.el8ost.noarch             490/633 
  Erasing          : eap7-jboss-server-migration-1.7.1-5.Final_redhat   491/633 
  Erasing          : glassfish-jaxb-api-2.2.12-8.module+el8.1.0+3366+   492/633 
  Erasing          : glassfish-jaxb-txw2-2.2.11-11.module+el8.1.0+336   493/633 
  Erasing          : eap7-velocity-2.1.0-1.redhat_00001.1.el8eap.noar   494/633 
  Erasing          : apache-commons-codec-1.11-3.module+el8+2598+06ba   495/633 
  Erasing          : vim-filesystem-2:8.0.1763-13.el8.noarch            496/633 
  Erasing          : python3-passlib-1.7.0-5.el8ost.noarch              497/633 
  Erasing          : httpcomponents-core-4.4.10-3.module+el8+2598+06b   498/633 
  Erasing          : publicsuffix-list-20180723-1.el8.noarch            499/633 
  Erasing          : python3-websocket-client-0.54.0-1.el8ost.noarch    500/633 
  Erasing          : apache-commons-io-1:2.6-3.module+el8+2598+06babf   501/633 
  Erasing          : pki-servlet-4.0-api-1:9.0.7-16.module+el8.1.0+33   502/633 
  Erasing          : jboss-logging-3.3.0-5.el8.noarch                   503/633 
  Erasing          : jboss-annotations-1.2-api-1.0.0-4.el8.noarch       504/633 
  Erasing          : jboss-jaxrs-2.0-api-1.0.0-6.el8.noarch             505/633 
  Erasing          : sos-3.8-6.el8_2.noarch                             506/633 
  Erasing          : python3-notario-0.0.16-2.el8cp.noarch              507/633 
  Erasing          : python3-pyOpenSSL-18.0.0-1.el8.noarch              508/633 
  Erasing          : spice-client-win-x64-8.0-1.el8.noarch              509/633 
  Erasing          : spice-client-win-x86-8.0-1.el8.noarch              510/633 
  Erasing          : apache-commons-compress-1.18-1.el8ev.noarch        511/633 
  Erasing          : apache-commons-jxpath-1.3-29.el8ev.noarch          512/633 
  Erasing          : apache-sshd-2.2.0-1.el8ev.noarch                   513/633 
  Erasing          : jcl-over-slf4j-1.7.25-4.module+el8.1.0+3366+6dfb   514/633 
  Erasing          : ovirt-engine-api-explorer-0.0.6-1.el8ev.noarch     515/633 
  Erasing          : ovirt-engine-dbscripts-4.4.1.2-0.10.el8ev.noarch   516/633 
  Erasing          : ovirt-engine-restapi-4.4.1.2-0.10.el8ev.noarch     517/633 
  Erasing          : ovirt-web-ui-1.6.2-1.el8ev.noarch                  518/633 
  Erasing          : python3-dnf-plugin-versionlock-4.0.12-3.el8.noar   519/633 
  Erasing          : rhvm-dependencies-4.4.0-1.el8ev.noarch             520/633 
  Erasing          : aopalliance-1.0-17.module+el8+2598+06babf2e.noar   521/633 
  Erasing          : ebay-cors-filter-1.0.1-4.el8ev.noarch              522/633 
  Erasing          : java-client-kubevirt-0.5.0-1.el8ev.noarch          523/633 
  Erasing          : apache-commons-collections-3.2.2-10.module+el8.1   524/633 
  Erasing          : graphviz-2.40.1-40.el8.x86_64                      525/633 
  Running scriptlet: graphviz-2.40.1-40.el8.x86_64                      525/633 
  Erasing          : libgs-9.25-5.el8_1.1.x86_64                        526/633 
  Running scriptlet: postgresql-server-12.1-2.module+el8.1.1+4794+c82   527/633 
  Erasing          : postgresql-server-12.1-2.module+el8.1.1+4794+c82   527/633 
  Running scriptlet: postgresql-server-12.1-2.module+el8.1.1+4794+c82   527/633 
  Erasing          : java-1.8.0-openjdk-1:1.8.0.252.b09-3.el8_2.x86_6   528/633 
  Running scriptlet: java-1.8.0-openjdk-1:1.8.0.252.b09-3.el8_2.x86_6   528/633 
  Erasing          : gtk2-2.24.32-4.el8.x86_64                          529/633 
  Running scriptlet: gtk2-2.24.32-4.el8.x86_64                          529/633 
  Erasing          : gd-2.2.5-6.el8.x86_64                              530/633 
  Running scriptlet: gd-2.2.5-6.el8.x86_64                              530/633 
  Running scriptlet: nfs-utils-1:2.3.3-31.el8.x86_64                    531/633 
  Erasing          : nfs-utils-1:2.3.3-31.el8.x86_64                    531/633 
warning: file /var/lib/nfs/v4recovery: remove failed: No such file or directory
warning: file /var/lib/nfs/statd/sm.bak: remove failed: No such file or directory
warning: file /var/lib/nfs/statd/sm: remove failed: No such file or directory
warning: file /var/lib/nfs/statd: remove failed: No such file or directory
warning: directory /var/lib/nfs/rpc_pipefs: remove failed: Device or resource busy

  Running scriptlet: nfs-utils-1:2.3.3-31.el8.x86_64                    531/633 
  Erasing          : postgresql-contrib-12.1-2.module+el8.1.1+4794+c8   532/633 
  Erasing          : postgresql-12.1-2.module+el8.1.1+4794+c82b6e09.x   533/633 
  Erasing          : gnutls-utils-3.6.8-10.el8_2.x86_64                 534/633 
  Erasing          : gdk-pixbuf2-modules-2.36.12-5.el8.x86_64           535/633 
  Erasing          : librsvg2-2.42.7-3.el8.x86_64                       536/633 
  Erasing          : pango-1.42.4-6.el8.x86_64                          537/633 
  Running scriptlet: pango-1.42.4-6.el8.x86_64                          537/633 
  Erasing          : collectd-postgresql-5.11.0-2.el8ost.x86_64         538/633 
  Erasing          : rsyslog-mmnormalize-8.1911.0-3.el8.x86_64          539/633 
  Erasing          : mod_ssl-1:2.4.37-21.module+el8.2.0+5008+cca404a3   540/633 
  Running scriptlet: mod_ssl-1:2.4.37-21.module+el8.2.0+5008+cca404a3   540/633 
  Erasing          : xorg-x11-fonts-Type1-7.5-19.el8.noarch             541/633 
  Running scriptlet: xorg-x11-fonts-Type1-7.5-19.el8.noarch             541/633 
  Running scriptlet: httpd-2.4.37-21.module+el8.2.0+5008+cca404a3.x86   542/633 
  Erasing          : httpd-2.4.37-21.module+el8.2.0+5008+cca404a3.x86   542/633 
  Running scriptlet: httpd-2.4.37-21.module+el8.2.0+5008+cca404a3.x86   542/633 
  Erasing          : httpd-tools-2.4.37-21.module+el8.2.0+5008+cca404   543/633 
  Erasing          : liblognorm-2.0.5-1.el8.x86_64                      544/633 
  Running scriptlet: liblognorm-2.0.5-1.el8.x86_64                      544/633 
  Erasing          : libthai-0.1.27-2.el8.x86_64                        545/633 
  Running scriptlet: libthai-0.1.27-2.el8.x86_64                        545/633 
  Erasing          : python3-psycopg2-2.7.5-7.el8.x86_64                546/633 
  Running scriptlet: source-highlight-3.1.8-16.el8.x86_64               547/633 
  Erasing          : source-highlight-3.1.8-16.el8.x86_64               547/633 
  Running scriptlet: source-highlight-3.1.8-16.el8.x86_64               547/633 
  Erasing          : boost-regex-1.66.0-7.el8.x86_64                    548/633 
  Running scriptlet: boost-regex-1.66.0-7.el8.x86_64                    548/633 
  Erasing          : python3-numpy-1:1.14.3-9.el8.x86_64                549/633 
  Erasing          : openblas-0.3.3-5.el8.x86_64                        550/633 
  Running scriptlet: openblas-0.3.3-5.el8.x86_64                        550/633 
  Erasing          : openblas-threads-0.3.3-5.el8.x86_64                551/633 
  Running scriptlet: openblas-threads-0.3.3-5.el8.x86_64                551/633 
  Erasing          : libgfortran-8.3.1-5.el8.x86_64                     552/633 
  Running scriptlet: libgfortran-8.3.1-5.el8.x86_64                     552/633 
  Erasing          : collectd-write_http-5.11.0-2.el8ost.x86_64         553/633 
  Erasing          : rsyslog-mmjsonparse-8.1911.0-3.el8.x86_64          554/633 
  Erasing          : adobe-mappings-cmap-deprecated-20171205-3.el8.no   555/633 
  Erasing          : urw-base35-fonts-20170801-10.el8.noarch            556/633 
  Erasing          : apr-util-1.6.1-6.el8.x86_64                        557/633 
  Running scriptlet: apr-util-1.6.1-6.el8.x86_64                        557/633 
  Erasing          : harfbuzz-1.7.5-3.el8.x86_64                        558/633 
  Running scriptlet: harfbuzz-1.7.5-3.el8.x86_64                        558/633 
  Erasing          : libtiff-4.0.9-17.el8.x86_64                        559/633 
  Running scriptlet: gssproxy-0.8.0-15.el8.x86_64                       560/633 
  Erasing          : gssproxy-0.8.0-15.el8.x86_64                       560/633 
  Running scriptlet: gssproxy-0.8.0-15.el8.x86_64                       560/633 
  Erasing          : quota-1:4.04-10.el8.x86_64                         561/633 
  Erasing          : libXaw-1.0.13-10.el8.x86_64                        562/633 
  Erasing          : python3-pynacl-1.3.0-5.el8ev.x86_64                563/633 
  Erasing          : nodejs-1:10.19.0-2.module+el8.2.0+6232+1df3dc5f.   564/633 
  Erasing          : eap7-wildfly-openssl-linux-x86_64-1.0.9-2.SP03_r   565/633 
  Erasing          : eap7-python3-javapackages-3.4.1-5.15.6.el8eap.no   566/633 
  Erasing          : eap7-javapackages-tools-3.4.1-5.15.6.el8eap.noar   567/633 
  Erasing          : eap7-runtime-1-16.el8eap.x86_64                    568/633 
  Erasing          : scl-utils-1:2.0.2-12.el8.x86_64                    569/633 
  Erasing          : environment-modules-4.1.4-4.el8.x86_64             570/633 
  Running scriptlet: environment-modules-4.1.4-4.el8.x86_64             570/633 
  Erasing          : python3-ovirt-engine-sdk4-4.4.3-1.el8ev.x86_64     571/633 
  Erasing          : collectd-disk-5.11.0-2.el8ost.x86_64               572/633 
  Erasing          : collectd-write_syslog-5.11.0-2.el8ost.x86_64       573/633 
  Running scriptlet: collectd-5.11.0-2.el8ost.x86_64                    574/633 
  Erasing          : collectd-5.11.0-2.el8ost.x86_64                    574/633 
  Running scriptlet: collectd-5.11.0-2.el8ost.x86_64                    574/633 
  Erasing          : rsyslog-elasticsearch-8.1911.0-3.el8.x86_64        575/633 
  Erasing          : npm-1:6.13.4-1.10.19.0.2.module+el8.2.0+6232+1df   576/633 
  Erasing          : quota-nls-1:4.04-10.el8.noarch                     577/633 
  Erasing          : urw-base35-standard-symbols-ps-fonts-20170801-10   578/633 
  Running scriptlet: urw-base35-standard-symbols-ps-fonts-20170801-10   578/633 
  Erasing          : adobe-mappings-cmap-20171205-3.el8.noarch          579/633 
  Erasing          : mailcap-2.1.48-3.el8.noarch                        580/633 
  Erasing          : httpd-filesystem-2.4.37-21.module+el8.2.0+5008+c   581/633 
  Running scriptlet: httpd-filesystem-2.4.37-21.module+el8.2.0+5008+c   581/633 
  Erasing          : redhat-storage-logos-httpd-81.1-1.el8rhgs.noarch   582/633 
  Erasing          : hicolor-icon-theme-0.17-2.el8.noarch               583/633 
  Erasing          : adobe-mappings-pdf-20180407-1.el8.noarch           584/633 
  Erasing          : xorg-x11-fonts-ISO8859-1-100dpi-7.5-19.el8.noarc   585/633 
  Running scriptlet: xorg-x11-fonts-ISO8859-1-100dpi-7.5-19.el8.noarc   585/633 
  Running scriptlet: rsyslog-8.1911.0-3.el8.x86_64                      586/633 
  Erasing          : rsyslog-8.1911.0-3.el8.x86_64                      586/633 
  Running scriptlet: rsyslog-8.1911.0-3.el8.x86_64                      586/633 
  Erasing          : libestr-0.1.10-1.el8.x86_64                        587/633 
  Running scriptlet: libestr-0.1.10-1.el8.x86_64                        587/633 
  Erasing          : libfastjson-0.99.8-2.el8.x86_64                    588/633 
  Running scriptlet: libfastjson-0.99.8-2.el8.x86_64                    588/633 
  Erasing          : logrotate-3.14.0-3.el8.x86_64                      589/633 
  Erasing          : yajl-2.1.0-10.el8.x86_64                           590/633 
  Erasing          : python3-pycurl-7.43.0.2-4.el8.x86_64               591/633 
  Erasing          : tcl-1:8.6.8-2.el8.x86_64                           592/633 
  Running scriptlet: tcl-1:8.6.8-2.el8.x86_64                           592/633 
  Erasing          : python3-lxml-4.2.3-1.el8.x86_64                    593/633 
  Erasing          : libsodium-1.0.18-2.el8ev.x86_64                    594/633 
  Erasing          : libXpm-3.5.12-8.el8.x86_64                         595/633 
  Erasing          : libverto-libevent-0.3.0-5.el8.x86_64               596/633 
  Erasing          : jbigkit-libs-2.1-14.el8.x86_64                     597/633 
  Running scriptlet: jbigkit-libs-2.1-14.el8.x86_64                     597/633 
  Erasing          : graphite2-1.3.10-10.el8.x86_64                     598/633 
  Erasing          : apr-1.6.3-9.el8.x86_64                             599/633 
  Running scriptlet: apr-1.6.3-9.el8.x86_64                             599/633 
  Running scriptlet: libquadmath-8.3.1-5.el8.x86_64                     600/633 
  Erasing          : libquadmath-8.3.1-5.el8.x86_64                     600/633 
  Running scriptlet: libquadmath-8.3.1-5.el8.x86_64                     600/633 
  Erasing          : libicu-60.3-2.el8_1.x86_64                         601/633 
  Running scriptlet: libicu-60.3-2.el8_1.x86_64                         601/633 
  Erasing          : ctags-5.8-22.el8.x86_64                            602/633 
  Erasing          : libpq-12.1-3.el8.x86_64                            603/633 
  Erasing          : libdatrie-0.2.9-7.el8.x86_64                       604/633 
  Running scriptlet: libdatrie-0.2.9-7.el8.x86_64                       604/633 
  Erasing          : mod_http2-1.11.3-3.module+el8.2.0+4377+dc421495.   605/633 
  Erasing          : ttmkfdir-3.0.9-54.el8.x86_64                       606/633 
  Erasing          : fribidi-1.0.4-8.el8.x86_64                         607/633 
  Erasing          : libXft-2.3.2-10.el8.x86_64                         608/633 
  Erasing          : jasper-libs-2.0.14-4.el8.x86_64                    609/633 
  Erasing          : gnutls-dane-3.6.8-10.el8_2.x86_64                  610/633 
  Erasing          : autogen-libopts-5.18.12-7.el8.x86_64               611/633 
  Erasing          : uuid-1.6.2-42.el8.x86_64                           612/633 
  Running scriptlet: uuid-1.6.2-42.el8.x86_64                           612/633 
  Erasing          : keyutils-1.5.10-6.el8.x86_64                       613/633 
  Running scriptlet: rpcbind-1.2.5-7.el8.x86_64                         614/633 
  Erasing          : rpcbind-1.2.5-7.el8.x86_64                         614/633 
  Running scriptlet: rpcbind-1.2.5-7.el8.x86_64                         614/633 
  Erasing          : libwebp-1.0.0-1.el8.x86_64                         615/633 
  Erasing          : atk-2.28.1-1.el8.x86_64                            616/633 
  Erasing          : gtk-update-icon-cache-3.22.30-5.el8.x86_64         617/633 
  Erasing          : libXcomposite-0.4.4-14.el8.x86_64                  618/633 
  Erasing          : libXdamage-1.1.4-14.el8.x86_64                     619/633 
  Erasing          : libXtst-1.2.3-7.el8.x86_64                         620/633 
  Erasing          : giflib-5.1.4-3.el8.x86_64                          621/633 
  Running scriptlet: libidn-1.34-5.el8.x86_64                           622/633 
install-info: No such file or directory for /usr/share/info/libidn.info.gz

  Erasing          : libidn-1.34-5.el8.x86_64                           622/633 
  Erasing          : libijs-0.35-5.el8.x86_64                           623/633 
  Erasing          : jbig2dec-libs-0.14-2.el8.x86_64                    624/633 
  Running scriptlet: jbig2dec-libs-0.14-2.el8.x86_64                    624/633 
  Erasing          : openjpeg2-2.3.1-6.el8.x86_64                       625/633 
  Erasing          : libpaper-1.1.24-22.el8.x86_64                      626/633 
  Erasing          : ovirt-imageio-common-2.0.6-0.el8ev.x86_64          627/633 
  Erasing          : sshpass-1.06-3.el8ae.x86_64                        628/633 
  Erasing          : python3-psutil-5.4.3-10.el8.x86_64                 629/633 
  Erasing          : python3-bcrypt-3.1.6-2.el8ev.x86_64                630/633 
  Erasing          : python3-m2crypto-0.35.2-5.el8ev.x86_64             631/633 
  Erasing          : python3-pwquality-1.4.0-9.el8.x86_64               632/633 
  Erasing          : pciutils-3.5.6-4.el8.x86_64                        633/633 
  Running scriptlet: pciutils-3.5.6-4.el8.x86_64                        633/633 
  Verifying        : adobe-mappings-cmap-20171205-3.el8.noarch            1/633 
  Verifying        : adobe-mappings-cmap-deprecated-20171205-3.el8.no     2/633 
  Verifying        : adobe-mappings-pdf-20180407-1.el8.noarch             3/633 
  Verifying        : ansible-2.9.9-1.el8ae.noarch                         4/633 
  Verifying        : ansible-runner-1.4.5-1.el8ar.noarch                  5/633 
  Verifying        : ansible-runner-service-1.0.2-1.el8ev.noarch          6/633 
  Verifying        : aopalliance-1.0-17.module+el8+2598+06babf2e.noar     7/633 
  Verifying        : apache-commons-codec-1.11-3.module+el8+2598+06ba     8/633 
  Verifying        : apache-commons-collections-3.2.2-10.module+el8.1     9/633 
  Verifying        : apache-commons-compress-1.18-1.el8ev.noarch         10/633 
  Verifying        : apache-commons-configuration-1.10-1.el8ev.noarch    11/633 
  Verifying        : apache-commons-io-1:2.6-3.module+el8+2598+06babf    12/633 
  Verifying        : apache-commons-jxpath-1.3-29.el8ev.noarch           13/633 
  Verifying        : apache-commons-lang-2.6-21.module+el8.1.0+3366+6    14/633 
  Verifying        : apache-commons-logging-1.2-13.module+el8+2598+06    15/633 
  Verifying        : apache-sshd-2.2.0-1.el8ev.noarch                    16/633 
  Verifying        : apr-1.6.3-9.el8.x86_64                              17/633 
  Verifying        : apr-util-1.6.1-6.el8.x86_64                         18/633 
  Verifying        : asciidoc-8.6.10-0.5.20180627gitf7c2274.el8.noarc    19/633 
  Verifying        : atk-2.28.1-1.el8.x86_64                             20/633 
  Verifying        : autogen-libopts-5.18.12-7.el8.x86_64                21/633 
  Verifying        : bea-stax-api-1.2.0-16.module+el8.1.0+3366+6dfb95    22/633 
  Verifying        : boost-regex-1.66.0-7.el8.x86_64                     23/633 
  Verifying        : cockpit-dashboard-211.3-1.el8.noarch                24/633 
  Verifying        : collectd-5.11.0-2.el8ost.x86_64                     25/633 
  Verifying        : collectd-disk-5.11.0-2.el8ost.x86_64                26/633 
  Verifying        : collectd-postgresql-5.11.0-2.el8ost.x86_64          27/633 
  Verifying        : collectd-write_http-5.11.0-2.el8ost.x86_64          28/633 
  Verifying        : collectd-write_syslog-5.11.0-2.el8ost.x86_64        29/633 
  Verifying        : ctags-5.8-22.el8.x86_64                             30/633 
  Verifying        : docbook-dtds-1.0-69.el8.noarch                      31/633 
  Verifying        : docbook-style-xsl-1.79.2-7.el8.noarch               32/633 
  Verifying        : eap7-FastInfoset-1.2.13-10.redhat_1.1.el8eap.noa    33/633 
  Verifying        : eap7-activemq-artemis-cli-2.9.0-4.redhat_00010.1    34/633 
  Verifying        : eap7-activemq-artemis-commons-2.9.0-4.redhat_000    35/633 
  Verifying        : eap7-activemq-artemis-core-client-2.9.0-4.redhat    36/633 
  Verifying        : eap7-activemq-artemis-dto-2.9.0-4.redhat_00010.1    37/633 
  Verifying        : eap7-activemq-artemis-hornetq-protocol-2.9.0-4.r    38/633 
  Verifying        : eap7-activemq-artemis-hqclient-protocol-2.9.0-4.    39/633 
  Verifying        : eap7-activemq-artemis-jdbc-store-2.9.0-4.redhat_    40/633 
  Verifying        : eap7-activemq-artemis-jms-client-2.9.0-4.redhat_    41/633 
  Verifying        : eap7-activemq-artemis-jms-server-2.9.0-4.redhat_    42/633 
  Verifying        : eap7-activemq-artemis-journal-2.9.0-4.redhat_000    43/633 
  Verifying        : eap7-activemq-artemis-native-1:1.0.0.00003-2.red    44/633 
  Verifying        : eap7-activemq-artemis-ra-2.9.0-4.redhat_00010.1.    45/633 
  Verifying        : eap7-activemq-artemis-selector-2.9.0-4.redhat_00    46/633 
  Verifying        : eap7-activemq-artemis-server-2.9.0-4.redhat_0001    47/633 
  Verifying        : eap7-activemq-artemis-service-extensions-2.9.0-4    48/633 
  Verifying        : eap7-activemq-artemis-tools-2.9.0-4.redhat_00010    49/633 
  Verifying        : eap7-aesh-extensions-1.8.0-1.redhat_00001.1.el8e    50/633 
  Verifying        : eap7-aesh-readline-2.0.0-1.redhat_00001.1.el8eap    51/633 
  Verifying        : eap7-agroal-api-1.3.0-1.redhat_00001.1.el8eap.no    52/633 
  Verifying        : eap7-agroal-narayana-1.3.0-1.redhat_00001.1.el8e    53/633 
  Verifying        : eap7-agroal-pool-1.3.0-1.redhat_00001.1.el8eap.n    54/633 
  Verifying        : eap7-antlr-2.7.7-54.redhat_7.1.el8eap.noarch        55/633 
  Verifying        : eap7-apache-commons-beanutils-1.9.4-1.redhat_000    56/633 
  Verifying        : eap7-apache-commons-cli-1.3.1-3.redhat_2.1.el8ea    57/633 
  Verifying        : eap7-apache-commons-codec-1.11.0-2.redhat_00001.    58/633 
  Verifying        : eap7-apache-commons-collections-3.2.2-9.redhat_2    59/633 
  Verifying        : eap7-apache-commons-io-2.5.0-4.redhat_3.1.el8eap    60/633 
  Verifying        : eap7-apache-commons-lang-3.9.0-1.redhat_00001.1.    61/633 
  Verifying        : eap7-apache-commons-lang2-2.6.0-1.redhat_7.1.el8    62/633 
  Verifying        : eap7-apache-cxf-3.3.5-1.redhat_00001.1.el8eap.no    63/633 
  Verifying        : eap7-apache-cxf-rt-3.3.5-1.redhat_00001.1.el8eap    64/633 
  Verifying        : eap7-apache-cxf-services-3.3.5-1.redhat_00001.1.    65/633 
  Verifying        : eap7-apache-cxf-tools-3.3.5-1.redhat_00001.1.el8    66/633 
  Verifying        : eap7-apache-mime4j-0.6.0-4.redhat_7.1.el8eap.noa    67/633 
  Verifying        : eap7-artemis-wildfly-integration-1.0.2-4.redhat_    68/633 
  Verifying        : eap7-atinject-1.0.0-4.redhat_00002.1.el8eap.noar    69/633 
  Verifying        : eap7-avro-1.7.6-7.redhat_2.1.el8eap.noarch          70/633 
  Verifying        : eap7-azure-storage-6.1.0-1.redhat_1.1.el8eap.noa    71/633 
  Verifying        : eap7-bouncycastle-mail-1.60.0-2.redhat_00002.1.e    72/633 
  Verifying        : eap7-bouncycastle-pkix-1.60.0-2.redhat_00002.1.e    73/633 
  Verifying        : eap7-bouncycastle-prov-1.60.0-2.redhat_00002.1.e    74/633 
  Verifying        : eap7-byte-buddy-1.9.11-1.redhat_00002.1.el8eap.n    75/633 
  Verifying        : eap7-caffeine-2.6.2-3.redhat_1.1.el8eap.noarch      76/633 
  Verifying        : eap7-cal10n-0.8.1-6.redhat_1.1.el8eap.noarch        77/633 
  Verifying        : eap7-codehaus-jackson-core-asl-1.9.13-10.redhat_    78/633 
  Verifying        : eap7-codehaus-jackson-jaxrs-1.9.13-10.redhat_000    79/633 
  Verifying        : eap7-codehaus-jackson-mapper-asl-1.9.13-10.redha    80/633 
  Verifying        : eap7-codehaus-jackson-xc-1.9.13-10.redhat_00007.    81/633 
  Verifying        : eap7-codemodel-2.3.3-4.b02_redhat_00001.1.el8eap    82/633 
  Verifying        : eap7-commons-logging-jboss-logging-1.0.0-1.Final    83/633 
  Verifying        : eap7-cryptacular-1.2.4-1.redhat_00001.1.el8eap.n    84/633 
  Verifying        : eap7-cxf-xjc-boolean-3.3.0-1.redhat_00001.1.el8e    85/633 
  Verifying        : eap7-cxf-xjc-bug986-3.3.0-1.redhat_00001.1.el8ea    86/633 
  Verifying        : eap7-cxf-xjc-dv-3.3.0-1.redhat_00001.1.el8eap.no    87/633 
  Verifying        : eap7-cxf-xjc-runtime-3.3.0-1.redhat_00001.1.el8e    88/633 
  Verifying        : eap7-cxf-xjc-ts-3.3.0-1.redhat_00001.1.el8eap.no    89/633 
  Verifying        : eap7-dom4j-2.1.1-2.redhat_00001.1.el8eap.noarch     90/633 
  Verifying        : eap7-ecj-4.6.1-3.redhat_1.1.el8eap.noarch           91/633 
  Verifying        : eap7-eclipse-jgit-5.0.2.201807311906-2.r_redhat_    92/633 
  Verifying        : eap7-glassfish-concurrent-1.0.0-4.redhat_1.1.el8    93/633 
  Verifying        : eap7-glassfish-jaf-1.2.1-1.redhat_00002.1.el8eap    94/633 
  Verifying        : eap7-glassfish-javamail-1.6.4-2.redhat_00001.1.e    95/633 
  Verifying        : eap7-glassfish-jsf-2.3.9-10.SP09_redhat_00001.1.    96/633 
  Verifying        : eap7-glassfish-json-1.1.6-2.redhat_00001.1.el8ea    97/633 
  Verifying        : eap7-gnu-getopt-1.0.13-6.redhat_5.1.el8eap.noarc    98/633 
  Verifying        : eap7-gson-2.8.2-1.redhat_5.1.el8eap.noarch          99/633 
  Verifying        : eap7-guava-25.0.0-2.redhat_1.1.el8eap.noarch       100/633 
  Verifying        : eap7-h2database-1.4.193-6.redhat_2.1.el8eap.noar   101/633 
  Verifying        : eap7-hal-console-3.2.8-1.Final_redhat_00001.1.el   102/633 
  Verifying        : eap7-hibernate-beanvalidation-api-2.0.2-1.redhat   103/633 
  Verifying        : eap7-hibernate-commons-annotations-5.0.5-1.Final   104/633 
  Verifying        : eap7-hibernate-core-5.3.16-1.Final_redhat_00001.   105/633 
  Verifying        : eap7-hibernate-entitymanager-5.3.16-1.Final_redh   106/633 
  Verifying        : eap7-hibernate-envers-5.3.16-1.Final_redhat_0000   107/633 
  Verifying        : eap7-hibernate-search-backend-jms-5.10.7-1.Final   108/633 
  Verifying        : eap7-hibernate-search-engine-5.10.7-1.Final_redh   109/633 
  Verifying        : eap7-hibernate-search-orm-5.10.7-1.Final_redhat_   110/633 
  Verifying        : eap7-hibernate-search-serialization-avro-5.10.7-   111/633 
  Verifying        : eap7-hibernate-validator-6.0.18-1.Final_redhat_0   112/633 
  Verifying        : eap7-hibernate-validator-cdi-6.0.18-1.Final_redh   113/633 
  Verifying        : eap7-hornetq-commons-2.4.7-7.Final_redhat_2.1.el   114/633 
  Verifying        : eap7-hornetq-core-client-2.4.7-7.Final_redhat_2.   115/633 
  Verifying        : eap7-hornetq-jms-client-2.4.7-7.Final_redhat_2.1   116/633 
  Verifying        : eap7-httpcomponents-asyncclient-4.1.4-1.redhat_0   117/633 
  Verifying        : eap7-httpcomponents-client-4.5.4-1.redhat_00001.   118/633 
  Verifying        : eap7-httpcomponents-core-4.4.5-1.redhat_00001.1.   119/633 
  Verifying        : eap7-infinispan-cachestore-jdbc-9.4.18-1.Final_r   120/633 
  Verifying        : eap7-infinispan-cachestore-remote-9.4.18-1.Final   121/633 
  Verifying        : eap7-infinispan-client-hotrod-9.4.18-1.Final_red   122/633 
  Verifying        : eap7-infinispan-commons-9.4.18-1.Final_redhat_00   123/633 
  Verifying        : eap7-infinispan-core-9.4.18-1.Final_redhat_00001   124/633 
  Verifying        : eap7-infinispan-hibernate-cache-commons-9.4.18-1   125/633 
  Verifying        : eap7-infinispan-hibernate-cache-spi-9.4.18-1.Fin   126/633 
  Verifying        : eap7-infinispan-hibernate-cache-v53-9.4.18-1.Fin   127/633 
  Verifying        : eap7-ironjacamar-common-api-1.4.20-1.Final_redha   128/633 
  Verifying        : eap7-ironjacamar-common-impl-1.4.20-1.Final_redh   129/633 
  Verifying        : eap7-ironjacamar-common-spi-1.4.20-1.Final_redha   130/633 
  Verifying        : eap7-ironjacamar-core-api-1.4.20-1.Final_redhat_   131/633 
  Verifying        : eap7-ironjacamar-core-impl-1.4.20-1.Final_redhat   132/633 
  Verifying        : eap7-ironjacamar-deployers-common-1.4.20-1.Final   133/633 
  Verifying        : eap7-ironjacamar-jdbc-1.4.20-1.Final_redhat_0000   134/633 
  Verifying        : eap7-ironjacamar-validator-1.4.20-1.Final_redhat   135/633 
  Verifying        : eap7-istack-commons-runtime-3.0.10-1.redhat_0000   136/633 
  Verifying        : eap7-istack-commons-tools-3.0.10-1.redhat_00001.   137/633 
  Verifying        : eap7-jackson-annotations-2.10.3-1.redhat_00001.1   138/633 
  Verifying        : eap7-jackson-core-2.10.3-1.redhat_00001.1.el8eap   139/633 
  Verifying        : eap7-jackson-coreutils-1.0.0-1.redhat_1.1.el8eap   140/633 
  Verifying        : eap7-jackson-databind-2.10.3-1.redhat_00001.1.el   141/633 
  Verifying        : eap7-jackson-datatype-jdk8-2.10.3-1.redhat_00001   142/633 
  Verifying        : eap7-jackson-datatype-jsr310-2.10.3-1.redhat_000   143/633 
  Verifying        : eap7-jackson-jaxrs-base-2.10.3-1.redhat_00001.1.   144/633 
  Verifying        : eap7-jackson-jaxrs-json-provider-2.10.3-1.redhat   145/633 
  Verifying        : eap7-jackson-module-jaxb-annotations-2.10.3-1.re   146/633 
  Verifying        : eap7-jaegertracing-jaeger-client-java-core-0.34.   147/633 
  Verifying        : eap7-jaegertracing-jaeger-client-java-thrift-0.3   148/633 
  Verifying        : eap7-jakarta-el-3.0.3-1.redhat_00002.1.el8eap.no   149/633 
  Verifying        : eap7-jakarta-security-enterprise-api-1.0.2-3.red   150/633 
  Verifying        : eap7-jandex-2.1.2-1.Final_redhat_00001.1.el8eap.   151/633 
  Verifying        : eap7-jansi-1.18.0-1.redhat_00001.1.el8eap.noarch   152/633 
  Verifying        : eap7-jasypt-1.9.3-1.redhat_00001.1.el8eap.noarch   153/633 
  Verifying        : eap7-java-classmate-1.3.4-1.redhat_1.1.el8eap.no   154/633 
  Verifying        : eap7-javaee-jpa-spec-2.2.3-1.redhat_00001.1.el8e   155/633 
  Verifying        : eap7-javaee-security-api-1.0.0-2.redhat_1.1.el8e   156/633 
  Verifying        : eap7-javaee-security-soteria-enterprise-1.0.1-3.   157/633 
  Verifying        : eap7-javaewah-1.1.6-1.redhat_00001.1.el8eap.noar   158/633 
  Verifying        : eap7-javapackages-tools-3.4.1-5.15.6.el8eap.noar   159/633 
  Verifying        : eap7-javassist-3.23.2-2.GA_redhat_00001.1.el8eap   160/633 
  Verifying        : eap7-jaxb-jxc-2.3.3-4.b02_redhat_00001.1.el8eap.   161/633 
  Verifying        : eap7-jaxb-runtime-2.3.3-4.b02_redhat_00001.1.el8   162/633 
  Verifying        : eap7-jaxb-xjc-2.3.3-4.b02_redhat_00001.1.el8eap.   163/633 
  Verifying        : eap7-jaxbintros-1.0.3-1.GA_redhat_00001.1.el8eap   164/633 
  Verifying        : eap7-jaxen-1.1.6-14.redhat_2.1.el8eap.noarch       165/633 
  Verifying        : eap7-jberet-core-1.3.5-1.Final_redhat_00001.1.el   166/633 
  Verifying        : eap7-jboss-aesh-2.4.0-1.redhat_00001.1.el8eap.no   167/633 
  Verifying        : eap7-jboss-annotations-api_1.3_spec-2.0.1-2.Fina   168/633 
  Verifying        : eap7-jboss-batch-api_1.0_spec-2.0.0-1.Final_redh   169/633 
  Verifying        : eap7-jboss-classfilewriter-1.2.4-1.Final_redhat_   170/633 
  Verifying        : eap7-jboss-common-beans-2.0.1-1.Final_redhat_000   171/633 
  Verifying        : eap7-jboss-concurrency-api_1.0_spec-2.0.0-1.Fina   172/633 
  Verifying        : eap7-jboss-connector-api_1.7_spec-2.0.0-2.Final_   173/633 
  Verifying        : eap7-jboss-dmr-1.5.0-2.Final_redhat_1.1.el8eap.n   174/633 
  Verifying        : eap7-jboss-ejb-api_3.2_spec-2.0.0-1.Final_redhat   175/633 
  Verifying        : eap7-jboss-ejb-client-4.0.31-1.Final_redhat_0000   176/633 
  Verifying        : eap7-jboss-ejb3-ext-api-2.3.0-1.Final_redhat_000   177/633 
  Verifying        : eap7-jboss-el-api_3.0_spec-2.0.0-2.Final_redhat_   178/633 
  Verifying        : eap7-jboss-genericjms-2.0.4-1.Final_redhat_00001   179/633 
  Verifying        : eap7-jboss-iiop-client-1.0.1-3.Final_redhat_1.1.   180/633 
  Verifying        : eap7-jboss-interceptors-api_1.2_spec-2.0.0-3.Fin   181/633 
  Verifying        : eap7-jboss-invocation-1.5.2-1.Final_redhat_00001   182/633 
  Verifying        : eap7-jboss-j2eemgmt-api_1.1_spec-2.0.0-2.Final_r   183/633 
  Verifying        : eap7-jboss-jacc-api_1.5_spec-2.0.0-2.Final_redha   184/633 
  Verifying        : eap7-jboss-jaspi-api_1.1_spec-2.0.1-2.Final_redh   185/633 
  Verifying        : eap7-jboss-jaxb-api_2.3_spec-1.0.1-1.Final_redha   186/633 
  Verifying        : eap7-jboss-jaxrpc-api_1.1_spec-2.0.0-1.Final_red   187/633 
  Verifying        : eap7-jboss-jaxrs-api_2.1_spec-2.0.1-1.Final_redh   188/633 
  Verifying        : eap7-jboss-jaxws-api_2.3_spec-1.0.0-1.Final_redh   189/633 
  Verifying        : eap7-jboss-jms-api_2.0_spec-2.0.0-1.Final_redhat   190/633 
  Verifying        : eap7-jboss-jsf-api_2.3_spec-3.0.0-3.SP02_redhat_   191/633 
  Verifying        : eap7-jboss-jsp-api_2.3_spec-2.0.0-1.Final_redhat   192/633 
  Verifying        : eap7-jboss-logging-3.4.1-2.Final_redhat_00001.1.   193/633 
  Verifying        : eap7-jboss-logmanager-2.1.14-1.Final_redhat_0000   194/633 
  Verifying        : eap7-jboss-marshalling-2.0.9-1.Final_redhat_0000   195/633 
  Verifying        : eap7-jboss-marshalling-river-2.0.9-1.Final_redha   196/633 
  Verifying        : eap7-jboss-metadata-appclient-13.0.0-1.Final_red   197/633 
  Verifying        : eap7-jboss-metadata-common-13.0.0-1.Final_redhat   198/633 
  Verifying        : eap7-jboss-metadata-ear-13.0.0-1.Final_redhat_00   199/633 
  Verifying        : eap7-jboss-metadata-ejb-13.0.0-1.Final_redhat_00   200/633 
  Verifying        : eap7-jboss-metadata-web-13.0.0-1.Final_redhat_00   201/633 
  Verifying        : eap7-jboss-modules-1.10.0-1.Final_redhat_00001.1   202/633 
  Verifying        : eap7-jboss-msc-1.4.11-1.Final_redhat_00001.1.el8   203/633 
  Verifying        : eap7-jboss-openjdk-orb-8.1.4-3.Final_redhat_0000   204/633 
  Verifying        : eap7-jboss-remoting-5.0.18-1.Final_redhat_00001.   205/633 
  Verifying        : eap7-jboss-remoting-jmx-3.0.4-1.Final_redhat_000   206/633 
  Verifying        : eap7-jboss-saaj-api_1.3_spec-1.0.6-1.Final_redha   207/633 
  Verifying        : eap7-jboss-saaj-api_1.4_spec-1.0.1-1.Final_redha   208/633 
  Verifying        : eap7-jboss-seam-int-7.0.0-6.GA_redhat_2.1.el8eap   209/633 
  Verifying        : eap7-jboss-security-negotiation-3.0.6-1.Final_re   210/633 
  Verifying        : eap7-jboss-security-xacml-2.0.8-17.Final_redhat_   211/633 
  Verifying        : eap7-jboss-server-migration-1.7.1-5.Final_redhat   212/633 
  Verifying        : eap7-jboss-server-migration-cli-1.7.1-5.Final_re   213/633 
  Verifying        : eap7-jboss-server-migration-core-1.7.1-5.Final_r   214/633 
  Verifying        : eap7-jboss-server-migration-eap6.4-1.7.1-5.Final   215/633 
  Verifying        : eap7-jboss-server-migration-eap6.4-to-eap7.3-1.7   216/633 
  Verifying        : eap7-jboss-server-migration-eap7.0-1.7.1-5.Final   217/633 
  Verifying        : eap7-jboss-server-migration-eap7.1-1.7.1-5.Final   218/633 
  Verifying        : eap7-jboss-server-migration-eap7.2-1.7.1-5.Final   219/633 
  Verifying        : eap7-jboss-server-migration-eap7.2-to-eap7.3-1.7   220/633 
  Verifying        : eap7-jboss-server-migration-eap7.3-server-1.7.1-   221/633 
  Verifying        : eap7-jboss-server-migration-wildfly10.0-1.7.1-5.   222/633 
  Verifying        : eap7-jboss-server-migration-wildfly10.1-1.7.1-5.   223/633 
  Verifying        : eap7-jboss-server-migration-wildfly11.0-1.7.1-5.   224/633 
  Verifying        : eap7-jboss-server-migration-wildfly12.0-1.7.1-5.   225/633 
  Verifying        : eap7-jboss-server-migration-wildfly13.0-server-1   226/633 
  Verifying        : eap7-jboss-server-migration-wildfly14.0-server-1   227/633 
  Verifying        : eap7-jboss-server-migration-wildfly15.0-server-1   228/633 
  Verifying        : eap7-jboss-server-migration-wildfly16.0-server-1   229/633 
  Verifying        : eap7-jboss-server-migration-wildfly17.0-server-1   230/633 
  Verifying        : eap7-jboss-server-migration-wildfly18.0-server-1   231/633 
  Verifying        : eap7-jboss-server-migration-wildfly8.2-1.7.1-5.F   232/633 
  Verifying        : eap7-jboss-server-migration-wildfly9.0-1.7.1-5.F   233/633 
  Verifying        : eap7-jboss-servlet-api_4.0_spec-2.0.0-2.Final_re   234/633 
  Verifying        : eap7-jboss-stdio-1.1.0-1.Final_redhat_00001.1.el   235/633 
  Verifying        : eap7-jboss-threads-2.3.3-1.Final_redhat_00001.1.   236/633 
  Verifying        : eap7-jboss-transaction-api_1.3_spec-2.0.0-3.Fina   237/633 
  Verifying        : eap7-jboss-transaction-spi-7.6.0-2.Final_redhat_   238/633 
  Verifying        : eap7-jboss-vfs-3.2.15-1.Final_redhat_00001.1.el8   239/633 
  Verifying        : eap7-jboss-websocket-api_1.1_spec-2.0.0-1.Final_   240/633 
  Verifying        : eap7-jboss-weld-3.1-api-weld-api-3.1.0-6.SP2_red   241/633 
  Verifying        : eap7-jboss-weld-3.1-api-weld-spi-3.1.0-6.SP2_red   242/633 
  Verifying        : eap7-jboss-xnio-base-3.7.7-1.Final_redhat_00001.   243/633 
  Verifying        : eap7-jbossws-api-1.1.2-1.Final_redhat_00001.1.el   244/633 
  Verifying        : eap7-jbossws-common-3.2.3-1.Final_redhat_00001.1   245/633 
  Verifying        : eap7-jbossws-common-tools-1.3.2-1.Final_redhat_0   246/633 
  Verifying        : eap7-jbossws-cxf-5.3.0-1.Final_redhat_00001.1.el   247/633 
  Verifying        : eap7-jbossws-jaxws-undertow-httpspi-1.0.1-3.Fina   248/633 
  Verifying        : eap7-jbossws-spi-3.2.3-1.Final_redhat_00001.1.el   249/633 
  Verifying        : eap7-jcip-annotations-1.0.0-5.redhat_8.1.el8eap.   250/633 
  Verifying        : eap7-jettison-1.4.0-1.redhat_00001.1.el8eap.noar   251/633 
  Verifying        : eap7-jgroups-4.1.4-1.Final_redhat_00001.1.el8eap   252/633 
  Verifying        : eap7-jgroups-azure-1.2.1-1.Final_redhat_00001.1.   253/633 
  Verifying        : eap7-jgroups-kubernetes-1.0.13-1.Final_redhat_00   254/633 
  Verifying        : eap7-joda-time-2.9.7-2.redhat_1.1.el8eap.noarch    255/633 
  Verifying        : eap7-jsch-0.1.54-7.redhat_00001.1.el8eap.noarch    256/633 
  Verifying        : eap7-json-patch-1.9.0-1.redhat_00002.1.el8eap.no   257/633 
  Verifying        : eap7-jsonb-spec-1.0.2-1.redhat_00001.1.el8eap.no   258/633 
  Verifying        : eap7-jsoup-1.8.3-4.redhat_2.1.el8eap.noarch        259/633 
  Verifying        : eap7-jul-to-slf4j-stub-1.0.1-7.Final_redhat_3.1.   260/633 
  Verifying        : eap7-jzlib-1.1.1-7.redhat_00001.1.el8eap.noarch    261/633 
  Verifying        : eap7-log4j-jboss-logmanager-1.2.0-1.Final_redhat   262/633 
  Verifying        : eap7-lucene-analyzers-common-5.5.5-3.redhat_2.1.   263/633 
  Verifying        : eap7-lucene-backward-codecs-5.5.5-3.redhat_2.1.e   264/633 
  Verifying        : eap7-lucene-core-5.5.5-3.redhat_2.1.el8eap.noarc   265/633 
  Verifying        : eap7-lucene-facet-5.5.5-3.redhat_2.1.el8eap.noar   266/633 
  Verifying        : eap7-lucene-misc-5.5.5-3.redhat_2.1.el8eap.noarc   267/633 
  Verifying        : eap7-lucene-queries-5.5.5-3.redhat_2.1.el8eap.no   268/633 
  Verifying        : eap7-lucene-queryparser-5.5.5-3.redhat_2.1.el8ea   269/633 
  Verifying        : eap7-microprofile-config-api-1.4.0-1.redhat_0000   270/633 
  Verifying        : eap7-microprofile-health-2.2.0-1.redhat_00001.1.   271/633 
  Verifying        : eap7-microprofile-metrics-api-2.3.0-1.redhat_000   272/633 
  Verifying        : eap7-microprofile-opentracing-api-1.3.3-1.redhat   273/633 
  Verifying        : eap7-microprofile-rest-client-api-1.4.0-1.redhat   274/633 
  Verifying        : eap7-mod_cluster-1.4.1-1.Final_redhat_00001.1.el   275/633 
  Verifying        : eap7-mustache-java-compiler-0.9.4-2.redhat_1.1.e   276/633 
  Verifying        : eap7-narayana-compensations-5.9.8-1.Final_redhat   277/633 
  Verifying        : eap7-narayana-jbosstxbridge-5.9.8-1.Final_redhat   278/633 
  Verifying        : eap7-narayana-jbossxts-5.9.8-1.Final_redhat_0000   279/633 
  Verifying        : eap7-narayana-jts-idlj-5.9.8-1.Final_redhat_0000   280/633 
  Verifying        : eap7-narayana-jts-integration-5.9.8-1.Final_redh   281/633 
  Verifying        : eap7-narayana-restat-api-5.9.8-1.Final_redhat_00   282/633 
  Verifying        : eap7-narayana-restat-bridge-5.9.8-1.Final_redhat   283/633 
  Verifying        : eap7-narayana-restat-integration-5.9.8-1.Final_r   284/633 
  Verifying        : eap7-narayana-restat-util-5.9.8-1.Final_redhat_0   285/633 
  Verifying        : eap7-narayana-txframework-5.9.8-1.Final_redhat_0   286/633 
  Verifying        : eap7-neethi-3.1.1-1.redhat_1.1.el8eap.noarch       287/633 
  Verifying        : eap7-netty-all-4.1.45-1.Final_redhat_00001.1.el8   288/633 
  Verifying        : eap7-netty-xnio-transport-0.1.6-1.Final_redhat_0   289/633 
  Verifying        : eap7-objectweb-asm-7.1.0-1.redhat_00001.1.el8eap   290/633 
  Verifying        : eap7-okhttp-3.9.0-3.redhat_3.1.el8eap.noarch       291/633 
  Verifying        : eap7-okio-1.13.0-2.redhat_3.1.el8eap.noarch        292/633 
  Verifying        : eap7-opensaml-core-3.3.1-1.redhat_00002.1.el8eap   293/633 
  Verifying        : eap7-opensaml-profile-api-3.3.1-1.redhat_00002.1   294/633 
  Verifying        : eap7-opensaml-saml-api-3.3.1-1.redhat_00002.1.el   295/633 
  Verifying        : eap7-opensaml-saml-impl-3.3.1-1.redhat_00002.1.e   296/633 
  Verifying        : eap7-opensaml-security-api-3.3.1-1.redhat_00002.   297/633 
  Verifying        : eap7-opensaml-security-impl-3.3.1-1.redhat_00002   298/633 
  Verifying        : eap7-opensaml-soap-api-3.3.1-1.redhat_00002.1.el   299/633 
  Verifying        : eap7-opensaml-xacml-api-3.3.1-1.redhat_00002.1.e   300/633 
  Verifying        : eap7-opensaml-xacml-impl-3.3.1-1.redhat_00002.1.   301/633 
  Verifying        : eap7-opensaml-xacml-saml-api-3.3.1-1.redhat_0000   302/633 
  Verifying        : eap7-opensaml-xacml-saml-impl-3.3.1-1.redhat_000   303/633 
  Verifying        : eap7-opensaml-xmlsec-api-3.3.1-1.redhat_00002.1.   304/633 
  Verifying        : eap7-opensaml-xmlsec-impl-3.3.1-1.redhat_00002.1   305/633 
  Verifying        : eap7-opentracing-contrib-java-concurrent-0.2.1-1   306/633 
  Verifying        : eap7-opentracing-contrib-java-jaxrs-0.4.1-1.redh   307/633 
  Verifying        : eap7-opentracing-contrib-java-tracerresolver-0.1   308/633 
  Verifying        : eap7-opentracing-contrib-java-web-servlet-filter   309/633 
  Verifying        : eap7-opentracing-interceptors-0.0.4-1.redhat_000   310/633 
  Verifying        : eap7-opentracing-java-api-0.31.0-1.redhat_00008.   311/633 
  Verifying        : eap7-opentracing-java-noop-0.31.0-1.redhat_00008   312/633 
  Verifying        : eap7-opentracing-java-util-0.31.0-1.redhat_00008   313/633 
  Verifying        : eap7-picketbox-5.0.3-7.Final_redhat_00006.1.el8e   314/633 
  Verifying        : eap7-picketbox-commons-1.0.0-4.final_redhat_5.1.   315/633 
  Verifying        : eap7-picketbox-infinispan-5.0.3-7.Final_redhat_0   316/633 
  Verifying        : eap7-picketlink-api-2.5.5-20.SP12_redhat_00009.1   317/633 
  Verifying        : eap7-picketlink-common-2.5.5-20.SP12_redhat_0000   318/633 
  Verifying        : eap7-picketlink-config-2.5.5-20.SP12_redhat_0000   319/633 
  Verifying        : eap7-picketlink-federation-2.5.5-20.SP12_redhat_   320/633 
  Verifying        : eap7-picketlink-idm-api-2.5.5-20.SP12_redhat_000   321/633 
  Verifying        : eap7-picketlink-idm-impl-2.5.5-20.SP12_redhat_00   322/633 
  Verifying        : eap7-picketlink-idm-simple-schema-2.5.5-20.SP12_   323/633 
  Verifying        : eap7-picketlink-impl-2.5.5-20.SP12_redhat_00009.   324/633 
  Verifying        : eap7-picketlink-wildfly8-2.5.5-23.SP12_redhat_00   325/633 
  Verifying        : eap7-python3-javapackages-3.4.1-5.15.6.el8eap.no   326/633 
  Verifying        : eap7-reactive-streams-1.0.2-2.redhat_1.1.el8eap.   327/633 
  Verifying        : eap7-reactivex-rxjava-2.2.5-1.redhat_00001.1.el8   328/633 
  Verifying        : eap7-relaxng-datatype-2.3.3-4.b02_redhat_00001.1   329/633 
  Verifying        : eap7-resteasy-atom-provider-3.11.2-3.Final_redha   330/633 
  Verifying        : eap7-resteasy-cdi-3.11.2-3.Final_redhat_00002.1.   331/633 
  Verifying        : eap7-resteasy-client-3.11.2-3.Final_redhat_00002   332/633 
  Verifying        : eap7-resteasy-client-microprofile-3.11.2-3.Final   333/633 
  Verifying        : eap7-resteasy-crypto-3.11.2-3.Final_redhat_00002   334/633 
  Verifying        : eap7-resteasy-jackson-provider-3.11.2-3.Final_re   335/633 
  Verifying        : eap7-resteasy-jackson2-provider-3.11.2-3.Final_r   336/633 
  Verifying        : eap7-resteasy-jaxb-provider-3.11.2-3.Final_redha   337/633 
  Verifying        : eap7-resteasy-jaxrs-3.11.2-3.Final_redhat_00002.   338/633 
  Verifying        : eap7-resteasy-jettison-provider-3.11.2-3.Final_r   339/633 
  Verifying        : eap7-resteasy-jose-jwt-3.11.2-3.Final_redhat_000   340/633 
  Verifying        : eap7-resteasy-jsapi-3.11.2-3.Final_redhat_00002.   341/633 
  Verifying        : eap7-resteasy-json-binding-provider-3.11.2-3.Fin   342/633 
  Verifying        : eap7-resteasy-json-p-provider-3.11.2-3.Final_red   343/633 
  Verifying        : eap7-resteasy-multipart-provider-3.11.2-3.Final_   344/633 
  Verifying        : eap7-resteasy-rxjava2-3.11.2-3.Final_redhat_0000   345/633 
  Verifying        : eap7-resteasy-spring-3.11.2-3.Final_redhat_00002   346/633 
  Verifying        : eap7-resteasy-validator-provider-11-3.11.2-3.Fin   347/633 
  Verifying        : eap7-resteasy-yaml-provider-3.11.2-3.Final_redha   348/633 
  Verifying        : eap7-rngom-2.3.3-4.b02_redhat_00001.1.el8eap.noa   349/633 
  Verifying        : eap7-runtime-1-16.el8eap.x86_64                    350/633 
  Verifying        : eap7-shibboleth-java-support-7.3.0-1.redhat_0000   351/633 
  Verifying        : eap7-slf4j-api-1.7.22-4.redhat_2.1.el8eap.noarch   352/633 
  Verifying        : eap7-slf4j-ext-1.7.22-4.redhat_2.1.el8eap.noarch   353/633 
  Verifying        : eap7-slf4j-jboss-logmanager-1.0.4-1.GA_redhat_00   354/633 
  Verifying        : eap7-smallrye-config-1.6.2-3.redhat_00004.1.el8e   355/633 
  Verifying        : eap7-smallrye-health-2.2.0-1.redhat_00004.1.el8e   356/633 
  Verifying        : eap7-smallrye-metrics-2.4.0-1.redhat_00004.1.el8   357/633 
  Verifying        : eap7-smallrye-opentracing-1.3.4-1.redhat_00004.1   358/633 
  Verifying        : eap7-snakeyaml-1.24.0-2.redhat_00001.1.el8eap.no   359/633 
  Verifying        : eap7-stax-ex-1.7.8-1.redhat_00001.1.el8eap.noarc   360/633 
  Verifying        : eap7-stax2-api-4.2.0-1.redhat_00001.1.el8eap.noa   361/633 
  Verifying        : eap7-staxmapper-1.3.0-2.Final_redhat_1.1.el8eap.   362/633 
  Verifying        : eap7-sun-saaj-1.3-impl-1.3.16-18.SP1_redhat_6.1.   363/633 
  Verifying        : eap7-sun-saaj-1.4-impl-1.4.1-1.SP1_redhat_00001.   364/633 
  Verifying        : eap7-sun-ws-metadata-2.0-api-1.0.0-7.MR1_redhat_   365/633 
  Verifying        : eap7-taglibs-standard-compat-1.2.6-2.RC1_redhat_   366/633 
  Verifying        : eap7-taglibs-standard-impl-1.2.6-2.RC1_redhat_1.   367/633 
  Verifying        : eap7-taglibs-standard-spec-1.2.6-2.RC1_redhat_1.   368/633 
  Verifying        : eap7-thrift-0.13.0-1.redhat_00002.1.el8eap.noarc   369/633 
  Verifying        : eap7-txw2-2.3.3-4.b02_redhat_00001.1.el8eap.noar   370/633 
  Verifying        : eap7-undertow-2.0.30-3.SP3_redhat_00001.1.el8eap   371/633 
  Verifying        : eap7-undertow-jastow-2.0.8-1.Final_redhat_00001.   372/633 
  Verifying        : eap7-undertow-js-1.0.2-2.Final_redhat_1.1.el8eap   373/633 
  Verifying        : eap7-undertow-server-1.6.1-1.Final_redhat_00001.   374/633 
  Verifying        : eap7-vdx-core-1.1.6-2.redhat_1.1.el8eap.noarch     375/633 
  Verifying        : eap7-vdx-wildfly-1.1.6-2.redhat_1.1.el8eap.noarc   376/633 
  Verifying        : eap7-velocity-2.1.0-1.redhat_00001.1.el8eap.noar   377/633 
  Verifying        : eap7-velocity-engine-core-2.1.0-1.redhat_00001.1   378/633 
  Verifying        : eap7-weld-cdi-2.0-api-2.0.2-2.redhat_00002.1.el8   379/633 
  Verifying        : eap7-weld-core-impl-3.1.4-1.Final_redhat_00001.1   380/633 
  Verifying        : eap7-weld-core-jsf-3.1.4-1.Final_redhat_00001.1.   381/633 
  Verifying        : eap7-weld-ejb-3.1.4-1.Final_redhat_00001.1.el8ea   382/633 
  Verifying        : eap7-weld-jta-3.1.4-1.Final_redhat_00001.1.el8ea   383/633 
  Verifying        : eap7-weld-probe-core-3.1.4-1.Final_redhat_00001.   384/633 
  Verifying        : eap7-weld-web-3.1.4-1.Final_redhat_00001.1.el8ea   385/633 
  Verifying        : eap7-wildfly-7.3.1-5.GA_redhat_00003.1.el8eap.no   386/633 
  Verifying        : eap7-wildfly-client-config-1.0.1-2.Final_redhat_   387/633 
  Verifying        : eap7-wildfly-common-1.5.1-1.Final_redhat_00001.1   388/633 
  Verifying        : eap7-wildfly-discovery-client-1.2.0-1.Final_redh   389/633 
  Verifying        : eap7-wildfly-elytron-1.10.6-1.Final_redhat_00001   390/633 
  Verifying        : eap7-wildfly-elytron-tool-1.10.6-1.Final_redhat_   391/633 
  Verifying        : eap7-wildfly-http-client-common-1.0.20-1.Final_r   392/633 
  Verifying        : eap7-wildfly-http-ejb-client-1.0.20-1.Final_redh   393/633 
  Verifying        : eap7-wildfly-http-naming-client-1.0.20-1.Final_r   394/633 
  Verifying        : eap7-wildfly-http-transaction-client-1.0.20-1.Fi   395/633 
  Verifying        : eap7-wildfly-modules-7.3.1-5.GA_redhat_00003.1.e   396/633 
  Verifying        : eap7-wildfly-naming-client-1.0.12-1.Final_redhat   397/633 
  Verifying        : eap7-wildfly-openssl-java-1.0.9-2.SP03_redhat_00   398/633 
  Verifying        : eap7-wildfly-openssl-linux-x86_64-1.0.9-2.SP03_r   399/633 
  Verifying        : eap7-wildfly-transaction-client-1.1.11-1.Final_r   400/633 
  Verifying        : eap7-woodstox-core-6.0.3-1.redhat_00001.1.el8eap   401/633 
  Verifying        : eap7-ws-commons-XmlSchema-2.2.4-1.redhat_00001.1   402/633 
  Verifying        : eap7-wsdl4j-1.6.3-13.redhat_2.1.el8eap.noarch      403/633 
  Verifying        : eap7-wss4j-bindings-2.2.5-1.redhat_00001.1.el8ea   404/633 
  Verifying        : eap7-wss4j-policy-2.2.5-1.redhat_00001.1.el8eap.   405/633 
  Verifying        : eap7-wss4j-ws-security-common-2.2.5-1.redhat_000   406/633 
  Verifying        : eap7-wss4j-ws-security-dom-2.2.5-1.redhat_00001.   407/633 
  Verifying        : eap7-wss4j-ws-security-policy-stax-2.2.5-1.redha   408/633 
  Verifying        : eap7-wss4j-ws-security-stax-2.2.5-1.redhat_00001   409/633 
  Verifying        : eap7-xalan-j2-2.7.1-35.redhat_12.1.el8eap.noarch   410/633 
  Verifying        : eap7-xerces-j2-2.12.0-1.SP02_redhat_00001.1.el8e   411/633 
  Verifying        : eap7-xml-resolver-1.2.0-7.redhat_12.1.el8eap.noa   412/633 
  Verifying        : eap7-xml-security-2.1.4-1.redhat_00001.1.el8eap.   413/633 
  Verifying        : eap7-xom-1.2.10-4.redhat_1.1.el8eap.noarch         414/633 
  Verifying        : eap7-xsom-2.3.3-4.b02_redhat_00001.1.el8eap.noar   415/633 
  Verifying        : eap7-yasson-1.0.5-1.redhat_00001.1.el8eap.noarch   416/633 
  Verifying        : ebay-cors-filter-1.0.1-4.el8ev.noarch              417/633 
  Verifying        : engine-db-query-1.5.0-1.el8ev.noarch               418/633 
  Verifying        : environment-modules-4.1.4-4.el8.x86_64             419/633 
  Verifying        : fribidi-1.0.4-8.el8.x86_64                         420/633 
  Verifying        : gd-2.2.5-6.el8.x86_64                              421/633 
  Verifying        : gdk-pixbuf2-modules-2.36.12-5.el8.x86_64           422/633 
  Verifying        : giflib-5.1.4-3.el8.x86_64                          423/633 
  Verifying        : glassfish-fastinfoset-1.2.13-9.module+el8.1.0+33   424/633 
  Verifying        : glassfish-jaxb-api-2.2.12-8.module+el8.1.0+3366+   425/633 
  Verifying        : glassfish-jaxb-core-2.2.11-11.module+el8.1.0+336   426/633 
  Verifying        : glassfish-jaxb-runtime-2.2.11-11.module+el8.1.0+   427/633 
  Verifying        : glassfish-jaxb-txw2-2.2.11-11.module+el8.1.0+336   428/633 
  Verifying        : gnutls-dane-3.6.8-10.el8_2.x86_64                  429/633 
  Verifying        : gnutls-utils-3.6.8-10.el8_2.x86_64                 430/633 
  Verifying        : graphite2-1.3.10-10.el8.x86_64                     431/633 
  Verifying        : graphviz-2.40.1-40.el8.x86_64                      432/633 
  Verifying        : gssproxy-0.8.0-15.el8.x86_64                       433/633 
  Verifying        : gtk-update-icon-cache-3.22.30-5.el8.x86_64         434/633 
  Verifying        : gtk2-2.24.32-4.el8.x86_64                          435/633 
  Verifying        : harfbuzz-1.7.5-3.el8.x86_64                        436/633 
  Verifying        : hicolor-icon-theme-0.17-2.el8.noarch               437/633 
  Verifying        : httpcomponents-client-4.5.5-4.module+el8+2598+06   438/633 
  Verifying        : httpcomponents-core-4.4.10-3.module+el8+2598+06b   439/633 
  Verifying        : httpd-2.4.37-21.module+el8.2.0+5008+cca404a3.x86   440/633 
  Verifying        : httpd-filesystem-2.4.37-21.module+el8.2.0+5008+c   441/633 
  Verifying        : httpd-tools-2.4.37-21.module+el8.2.0+5008+cca404   442/633 
  Verifying        : insights-client-3.0.13-1.el8.noarch                443/633 
  Verifying        : istack-commons-runtime-2.21-9.el8+7.noarch         444/633 
  Verifying        : jackson-annotations-2.10.0-1.module+el8.2.0+5059   445/633 
  Verifying        : jackson-core-2.10.0-1.module+el8.2.0+5059+3eb3af   446/633 
  Verifying        : jackson-databind-2.10.0-1.module+el8.2.0+5059+3e   447/633 
  Verifying        : jackson-jaxrs-json-provider-2.9.9-1.module+el8.1   448/633 
  Verifying        : jackson-jaxrs-providers-2.9.9-1.module+el8.1.0+3   449/633 
  Verifying        : jackson-module-jaxb-annotations-2.7.6-4.module+e   450/633 
  Verifying        : jasper-libs-2.0.14-4.el8.x86_64                    451/633 
  Verifying        : java-1.8.0-openjdk-1:1.8.0.252.b09-3.el8_2.x86_6   452/633 
  Verifying        : java-client-kubevirt-0.5.0-1.el8ev.noarch          453/633 
  Verifying        : javapackages-tools-5.3.0-2.module+el8+2598+06bab   454/633 
  Verifying        : jbig2dec-libs-0.14-2.el8.x86_64                    455/633 
  Verifying        : jbigkit-libs-2.1-14.el8.x86_64                     456/633 
  Verifying        : jboss-annotations-1.2-api-1.0.0-4.el8.noarch       457/633 
  Verifying        : jboss-jaxrs-2.0-api-1.0.0-6.el8.noarch             458/633 
  Verifying        : jboss-logging-3.3.0-5.el8.noarch                   459/633 
  Verifying        : jboss-logging-tools-2.0.1-6.el8.noarch             460/633 
  Verifying        : jcl-over-slf4j-1.7.25-4.module+el8.1.0+3366+6dfb   461/633 
  Verifying        : jdeparser-2.0.0-5.el8.noarch                       462/633 
  Verifying        : keyutils-1.5.10-6.el8.x86_64                       463/633 
  Verifying        : libXaw-1.0.13-10.el8.x86_64                        464/633 
  Verifying        : libXcomposite-0.4.4-14.el8.x86_64                  465/633 
  Verifying        : libXdamage-1.1.4-14.el8.x86_64                     466/633 
  Verifying        : libXft-2.3.2-10.el8.x86_64                         467/633 
  Verifying        : libXpm-3.5.12-8.el8.x86_64                         468/633 
  Verifying        : libXtst-1.2.3-7.el8.x86_64                         469/633 
  Verifying        : libdatrie-0.2.9-7.el8.x86_64                       470/633 
  Verifying        : libestr-0.1.10-1.el8.x86_64                        471/633 
  Verifying        : libfastjson-0.99.8-2.el8.x86_64                    472/633 
  Verifying        : libgfortran-8.3.1-5.el8.x86_64                     473/633 
  Verifying        : libgs-9.25-5.el8_1.1.x86_64                        474/633 
  Verifying        : libicu-60.3-2.el8_1.x86_64                         475/633 
  Verifying        : libidn-1.34-5.el8.x86_64                           476/633 
  Verifying        : libijs-0.35-5.el8.x86_64                           477/633 
  Verifying        : liblognorm-2.0.5-1.el8.x86_64                      478/633 
  Verifying        : libpaper-1.1.24-22.el8.x86_64                      479/633 
  Verifying        : libpq-12.1-3.el8.x86_64                            480/633 
  Verifying        : libquadmath-8.3.1-5.el8.x86_64                     481/633 
  Verifying        : librsvg2-2.42.7-3.el8.x86_64                       482/633 
  Verifying        : libsodium-1.0.18-2.el8ev.x86_64                    483/633 
  Verifying        : libthai-0.1.27-2.el8.x86_64                        484/633 
  Verifying        : libtiff-4.0.9-17.el8.x86_64                        485/633 
  Verifying        : libverto-libevent-0.3.0-5.el8.x86_64               486/633 
  Verifying        : libwebp-1.0.0-1.el8.x86_64                         487/633 
  Verifying        : log4j12-1.2.17-22.el8ev.noarch                     488/633 
  Verifying        : logrotate-3.14.0-3.el8.x86_64                      489/633 
  Verifying        : mailcap-2.1.48-3.el8.noarch                        490/633 
  Verifying        : mod_http2-1.11.3-3.module+el8.2.0+4377+dc421495.   491/633 
  Verifying        : mod_ssl-1:2.4.37-21.module+el8.2.0+5008+cca404a3   492/633 
  Verifying        : nfs-utils-1:2.3.3-31.el8.x86_64                    493/633 
  Verifying        : nodejs-1:10.19.0-2.module+el8.2.0+6232+1df3dc5f.   494/633 
  Verifying        : novnc-1.1.0-1.el8ost.noarch                        495/633 
  Verifying        : npm-1:6.13.4-1.10.19.0.2.module+el8.2.0+6232+1df   496/633 
  Verifying        : ongres-scram-1.0.0~beta.2-5.el8.noarch             497/633 
  Verifying        : ongres-scram-client-1.0.0~beta.2-5.el8.noarch      498/633 
  Verifying        : openblas-0.3.3-5.el8.x86_64                        499/633 
  Verifying        : openblas-threads-0.3.3-5.el8.x86_64                500/633 
  Verifying        : openjpeg2-2.3.1-6.el8.x86_64                       501/633 
  Verifying        : openstack-java-cinder-client-3.2.8-1.el8ev.noarc   502/633 
  Verifying        : openstack-java-cinder-model-3.2.8-1.el8ev.noarch   503/633 
  Verifying        : openstack-java-client-3.2.8-1.el8ev.noarch         504/633 
  Verifying        : openstack-java-glance-client-3.2.8-1.el8ev.noarc   505/633 
  Verifying        : openstack-java-glance-model-3.2.8-1.el8ev.noarch   506/633 
  Verifying        : openstack-java-keystone-client-3.2.8-1.el8ev.noa   507/633 
  Verifying        : openstack-java-keystone-model-3.2.8-1.el8ev.noar   508/633 
  Verifying        : openstack-java-quantum-client-3.2.8-1.el8ev.noar   509/633 
  Verifying        : openstack-java-quantum-model-3.2.8-1.el8ev.noarc   510/633 
  Verifying        : openstack-java-resteasy-connector-3.2.8-1.el8ev.   511/633 
  Verifying        : ovirt-ansible-cluster-upgrade-1.2.2-1.el8ev.noar   512/633 
  Verifying        : ovirt-ansible-disaster-recovery-1.3.0-0.1.master   513/633 
  Verifying        : ovirt-ansible-engine-setup-1.2.4-1.el8ev.noarch    514/633 
  Verifying        : ovirt-ansible-hosted-engine-setup-1.1.4-1.el8ev.   515/633 
  Verifying        : ovirt-ansible-image-template-1.2.2-1.el8ev.noarc   516/633 
  Verifying        : ovirt-ansible-infra-1.2.1-1.el8ev.noarch           517/633 
  Verifying        : ovirt-ansible-manageiq-1.2.1-2.el8ev.noarch        518/633 
  Verifying        : ovirt-ansible-repositories-1.2.3-1.el8ev.noarch    519/633 
  Verifying        : ovirt-ansible-roles-1.2.3-1.el8ev.noarch           520/633 
  Verifying        : ovirt-ansible-shutdown-env-1.0.4-1.el8ev.noarch    521/633 
  Verifying        : ovirt-ansible-vm-infra-1.2.3-1.el8ev.noarch        522/633 
  Verifying        : ovirt-cockpit-sso-0.1.4-1.el8ev.noarch             523/633 
  Verifying        : ovirt-engine-4.4.1.2-0.10.el8ev.noarch             524/633 
  Verifying        : ovirt-engine-api-explorer-0.0.6-1.el8ev.noarch     525/633 
  Verifying        : ovirt-engine-backend-4.4.1.2-0.10.el8ev.noarch     526/633 
  Verifying        : ovirt-engine-dbscripts-4.4.1.2-0.10.el8ev.noarch   527/633 
  Verifying        : ovirt-engine-dwh-4.4.0.2-1.el8ev.noarch            528/633 
  Verifying        : ovirt-engine-dwh-setup-4.4.0.2-1.el8ev.noarch      529/633 
  Verifying        : ovirt-engine-extension-aaa-jdbc-1.2.0-1.el8ev.no   530/633 
  Verifying        : ovirt-engine-metrics-1.4.0.2-1.el8ev.noarch        531/633 
  Verifying        : ovirt-engine-restapi-4.4.1.2-0.10.el8ev.noarch     532/633 
  Verifying        : ovirt-engine-setup-4.4.1.2-0.10.el8ev.noarch       533/633 
  Verifying        : ovirt-engine-setup-base-4.4.1.2-0.10.el8ev.noarc   534/633 
  Verifying        : ovirt-engine-setup-plugin-cinderlib-4.4.1.2-0.10   535/633 
  Verifying        : ovirt-engine-setup-plugin-imageio-4.4.1.2-0.10.e   536/633 
  Verifying        : ovirt-engine-setup-plugin-ovirt-engine-4.4.1.2-0   537/633 
  Verifying        : ovirt-engine-setup-plugin-ovirt-engine-common-4.   538/633 
  Verifying        : ovirt-engine-setup-plugin-vmconsole-proxy-helper   539/633 
  Verifying        : ovirt-engine-setup-plugin-websocket-proxy-4.4.1.   540/633 
  Verifying        : ovirt-engine-tools-4.4.1.2-0.10.el8ev.noarch       541/633 
  Verifying        : ovirt-engine-tools-backup-4.4.1.2-0.10.el8ev.noa   542/633 
  Verifying        : ovirt-engine-ui-extensions-1.2.0-1.el8ev.noarch    543/633 
  Verifying        : ovirt-engine-vmconsole-proxy-helper-4.4.1.2-0.10   544/633 
  Verifying        : ovirt-engine-webadmin-portal-4.4.1.2-0.10.el8ev.   545/633 
  Verifying        : ovirt-engine-websocket-proxy-4.4.1.2-0.10.el8ev.   546/633 
  Verifying        : ovirt-imageio-common-2.0.6-0.el8ev.x86_64          547/633 
  Verifying        : ovirt-imageio-daemon-2.0.6-0.el8ev.x86_64          548/633 
  Verifying        : ovirt-log-collector-4.4.1-3.el8ev.noarch           549/633 
  Verifying        : ovirt-vmconsole-1.0.8-1.el8ev.noarch               550/633 
  Verifying        : ovirt-vmconsole-proxy-1.0.8-1.el8ev.noarch         551/633 
  Verifying        : ovirt-web-ui-1.6.2-1.el8ev.noarch                  552/633 
  Verifying        : pango-1.42.4-6.el8.x86_64                          553/633 
  Verifying        : pciutils-3.5.6-4.el8.x86_64                        554/633 
  Verifying        : pki-servlet-4.0-api-1:9.0.7-16.module+el8.1.0+33   555/633 
  Verifying        : postgresql-12.1-2.module+el8.1.1+4794+c82b6e09.x   556/633 
  Verifying        : postgresql-contrib-12.1-2.module+el8.1.1+4794+c8   557/633 
  Verifying        : postgresql-jdbc-42.2.3-1.el8.noarch                558/633 
  Verifying        : postgresql-server-12.1-2.module+el8.1.1+4794+c82   559/633 
  Verifying        : publicsuffix-list-20180723-1.el8.noarch            560/633 
  Verifying        : python3-aniso8601-0.82-4.el8ost.noarch             561/633 
  Verifying        : python3-ansible-runner-1.4.5-1.el8ar.noarch        562/633 
  Verifying        : python3-bcrypt-3.1.6-2.el8ev.x86_64                563/633 
  Verifying        : python3-click-6.7-8.el8.noarch                     564/633 
  Verifying        : python3-daemon-2.1.2-9.el8ar.noarch                565/633 
  Verifying        : python3-dnf-plugin-versionlock-4.0.12-3.el8.noar   566/633 
  Verifying        : python3-docutils-0.14-12.module+el8.1.0+3334+5cb   567/633 
  Verifying        : python3-flask-1:1.0.2-2.el8ost.noarch              568/633 
  Verifying        : python3-flask-restful-0.3.6-8.el8ost.noarch        569/633 
  Verifying        : python3-itsdangerous-0.24-14.el8.noarch            570/633 
  Verifying        : python3-jmespath-0.9.0-11.el8.noarch               571/633 
  Verifying        : python3-lockfile-1:0.11.0-8.el8ar.noarch           572/633 
  Verifying        : python3-lxml-4.2.3-1.el8.x86_64                    573/633 
  Verifying        : python3-m2crypto-0.35.2-5.el8ev.x86_64             574/633 
  Verifying        : python3-magic-5.33-13.el8.noarch                   575/633 
  Verifying        : python3-mod_wsgi-4.6.4-4.el8.x86_64                576/633 
  Verifying        : python3-notario-0.0.16-2.el8cp.noarch              577/633 
  Verifying        : python3-numpy-1:1.14.3-9.el8.x86_64                578/633 
  Verifying        : python3-ovirt-engine-lib-4.4.1.2-0.10.el8ev.noar   579/633 
  Verifying        : python3-ovirt-engine-sdk4-4.4.3-1.el8ev.x86_64     580/633 
  Verifying        : python3-ovirt-setup-lib-1.3.0-1.el8ev.noarch       581/633 
  Verifying        : python3-paramiko-2.4.3-2.el8ev.noarch              582/633 
  Verifying        : python3-passlib-1.7.0-5.el8ost.noarch              583/633 
  Verifying        : python3-pexpect-4.6-2.el8ost.noarch                584/633 
  Verifying        : python3-psutil-5.4.3-10.el8.x86_64                 585/633 
  Verifying        : python3-psycopg2-2.7.5-7.el8.x86_64                586/633 
  Verifying        : python3-ptyprocess-0.5.2-4.el8.noarch              587/633 
  Verifying        : python3-pwquality-1.4.0-9.el8.x86_64               588/633 
  Verifying        : python3-pyOpenSSL-18.0.0-1.el8.noarch              589/633 
  Verifying        : python3-pycurl-7.43.0.2-4.el8.x86_64               590/633 
  Verifying        : python3-pynacl-1.3.0-5.el8ev.x86_64                591/633 
  Verifying        : python3-websocket-client-0.54.0-1.el8ost.noarch    592/633 
  Verifying        : python3-websockify-0.8.0-12.el8ev.noarch           593/633 
  Verifying        : python3-werkzeug-0.16.0-1.el8ost.noarch            594/633 
  Verifying        : quota-1:4.04-10.el8.x86_64                         595/633 
  Verifying        : quota-nls-1:4.04-10.el8.noarch                     596/633 
  Verifying        : redhat-storage-logos-httpd-81.1-1.el8rhgs.noarch   597/633 
  Verifying        : relaxngDatatype-2011.1-7.module+el8.1.0+3366+6df   598/633 
  Verifying        : resteasy-3.0.26-3.module+el8.1.0+3366+6dfb954c.n   599/633 
  Verifying        : rhv-log-collector-analyzer-1.0.0-1.el8ev.noarch    600/633 
  Verifying        : rhvm-4.4.1.2-0.10.el8ev.noarch                     601/633 
  Verifying        : rhvm-branding-rhv-4.4.3-1.el8ev.noarch             602/633 
  Verifying        : rhvm-dependencies-4.4.0-1.el8ev.noarch             603/633 
  Verifying        : rhvm-setup-plugins-4.4.2-1.el8ev.noarch            604/633 
  Verifying        : rpcbind-1.2.5-7.el8.x86_64                         605/633 
  Verifying        : rsyslog-8.1911.0-3.el8.x86_64                      606/633 
  Verifying        : rsyslog-elasticsearch-8.1911.0-3.el8.x86_64        607/633 
  Verifying        : rsyslog-mmjsonparse-8.1911.0-3.el8.x86_64          608/633 
  Verifying        : rsyslog-mmnormalize-8.1911.0-3.el8.x86_64          609/633 
  Verifying        : scl-utils-1:2.0.2-12.el8.x86_64                    610/633 
  Verifying        : sgml-common-0.6.3-50.el8.noarch                    611/633 
  Verifying        : snmp4j-2.4.1-1.el8ev.noarch                        612/633 
  Verifying        : sos-3.8-6.el8_2.noarch                             613/633 
  Verifying        : source-highlight-3.1.8-16.el8.x86_64               614/633 
  Verifying        : spice-client-win-x64-8.0-1.el8.noarch              615/633 
  Verifying        : spice-client-win-x86-8.0-1.el8.noarch              616/633 
  Verifying        : sshpass-1.06-3.el8ae.x86_64                        617/633 
  Verifying        : stax-ex-1.7.7-8.module+el8.1.0+3366+6dfb954c.noa   618/633 
  Verifying        : tcl-1:8.6.8-2.el8.x86_64                           619/633 
  Verifying        : ttmkfdir-3.0.9-54.el8.x86_64                       620/633 
  Verifying        : urw-base35-fonts-20170801-10.el8.noarch            621/633 
  Verifying        : urw-base35-standard-symbols-ps-fonts-20170801-10   622/633 
  Verifying        : uuid-1.6.2-42.el8.x86_64                           623/633 
  Verifying        : vdsm-jsonrpc-java-1.5.4-1.el8ev.noarch             624/633 
  Verifying        : vim-filesystem-2:8.0.1763-13.el8.noarch            625/633 
  Verifying        : ws-commons-util-1.0.2-1.el8ev.noarch               626/633 
  Verifying        : xmlrpc-client-3.1.3-1.el8ev.noarch                 627/633 
  Verifying        : xmlrpc-common-3.1.3-1.el8ev.noarch                 628/633 
  Verifying        : xmlstreambuffer-1.5.4-8.module+el8.1.0+3366+6dfb   629/633 
  Verifying        : xorg-x11-fonts-ISO8859-1-100dpi-7.5-19.el8.noarc   630/633 
  Verifying        : xorg-x11-fonts-Type1-7.5-19.el8.noarch             631/633 
  Verifying        : xsom-0-19.20110809svn.module+el8.1.0+3366+6dfb95   632/633 
  Verifying        : yajl-2.1.0-10.el8.x86_64                           633/633 

Removed:
  adobe-mappings-cmap-20171205-3.el8.noarch                                     
  adobe-mappings-cmap-deprecated-20171205-3.el8.noarch                          
  adobe-mappings-pdf-20180407-1.el8.noarch                                      
  ansible-2.9.9-1.el8ae.noarch                                                  
  ansible-runner-1.4.5-1.el8ar.noarch                                           
  ansible-runner-service-1.0.2-1.el8ev.noarch                                   
  aopalliance-1.0-17.module+el8+2598+06babf2e.noarch                            
  apache-commons-codec-1.11-3.module+el8+2598+06babf2e.noarch                   
  apache-commons-collections-3.2.2-10.module+el8.1.0+3366+6dfb954c.noarch       
  apache-commons-compress-1.18-1.el8ev.noarch                                   
  apache-commons-configuration-1.10-1.el8ev.noarch                              
  apache-commons-io-1:2.6-3.module+el8+2598+06babf2e.noarch                     
  apache-commons-jxpath-1.3-29.el8ev.noarch                                     
  apache-commons-lang-2.6-21.module+el8.1.0+3366+6dfb954c.noarch                
  apache-commons-logging-1.2-13.module+el8+2598+06babf2e.noarch                 
  apache-sshd-2.2.0-1.el8ev.noarch                                              
  apr-1.6.3-9.el8.x86_64                                                        
  apr-util-1.6.1-6.el8.x86_64                                                   
  asciidoc-8.6.10-0.5.20180627gitf7c2274.el8.noarch                             
  atk-2.28.1-1.el8.x86_64                                                       
  autogen-libopts-5.18.12-7.el8.x86_64                                          
  bea-stax-api-1.2.0-16.module+el8.1.0+3366+6dfb954c.noarch                     
  boost-regex-1.66.0-7.el8.x86_64                                               
  cockpit-dashboard-211.3-1.el8.noarch                                          
  collectd-5.11.0-2.el8ost.x86_64                                               
  collectd-disk-5.11.0-2.el8ost.x86_64                                          
  collectd-postgresql-5.11.0-2.el8ost.x86_64                                    
  collectd-write_http-5.11.0-2.el8ost.x86_64                                    
  collectd-write_syslog-5.11.0-2.el8ost.x86_64                                  
  ctags-5.8-22.el8.x86_64                                                       
  docbook-dtds-1.0-69.el8.noarch                                                
  docbook-style-xsl-1.79.2-7.el8.noarch                                         
  eap7-FastInfoset-1.2.13-10.redhat_1.1.el8eap.noarch                           
  eap7-activemq-artemis-cli-2.9.0-4.redhat_00010.1.el8eap.noarch                
  eap7-activemq-artemis-commons-2.9.0-4.redhat_00010.1.el8eap.noarch            
  eap7-activemq-artemis-core-client-2.9.0-4.redhat_00010.1.el8eap.noarch        
  eap7-activemq-artemis-dto-2.9.0-4.redhat_00010.1.el8eap.noarch                
  eap7-activemq-artemis-hornetq-protocol-2.9.0-4.redhat_00010.1.el8eap.noarch   
  eap7-activemq-artemis-hqclient-protocol-2.9.0-4.redhat_00010.1.el8eap.noarch  
  eap7-activemq-artemis-jdbc-store-2.9.0-4.redhat_00010.1.el8eap.noarch         
  eap7-activemq-artemis-jms-client-2.9.0-4.redhat_00010.1.el8eap.noarch         
  eap7-activemq-artemis-jms-server-2.9.0-4.redhat_00010.1.el8eap.noarch         
  eap7-activemq-artemis-journal-2.9.0-4.redhat_00010.1.el8eap.noarch            
  eap7-activemq-artemis-native-1:1.0.0.00003-2.redhat_00001.1.el8eap.noarch     
  eap7-activemq-artemis-ra-2.9.0-4.redhat_00010.1.el8eap.noarch                 
  eap7-activemq-artemis-selector-2.9.0-4.redhat_00010.1.el8eap.noarch           
  eap7-activemq-artemis-server-2.9.0-4.redhat_00010.1.el8eap.noarch             
  eap7-activemq-artemis-service-extensions-2.9.0-4.redhat_00010.1.el8eap.noarch 
  eap7-activemq-artemis-tools-2.9.0-4.redhat_00010.1.el8eap.noarch              
  eap7-aesh-extensions-1.8.0-1.redhat_00001.1.el8eap.noarch                     
  eap7-aesh-readline-2.0.0-1.redhat_00001.1.el8eap.noarch                       
  eap7-agroal-api-1.3.0-1.redhat_00001.1.el8eap.noarch                          
  eap7-agroal-narayana-1.3.0-1.redhat_00001.1.el8eap.noarch                     
  eap7-agroal-pool-1.3.0-1.redhat_00001.1.el8eap.noarch                         
  eap7-antlr-2.7.7-54.redhat_7.1.el8eap.noarch                                  
  eap7-apache-commons-beanutils-1.9.4-1.redhat_00002.1.el8eap.noarch            
  eap7-apache-commons-cli-1.3.1-3.redhat_2.1.el8eap.noarch                      
  eap7-apache-commons-codec-1.11.0-2.redhat_00001.1.el8eap.noarch               
  eap7-apache-commons-collections-3.2.2-9.redhat_2.1.el8eap.noarch              
  eap7-apache-commons-io-2.5.0-4.redhat_3.1.el8eap.noarch                       
  eap7-apache-commons-lang-3.9.0-1.redhat_00001.1.el8eap.noarch                 
  eap7-apache-commons-lang2-2.6.0-1.redhat_7.1.el8eap.noarch                    
  eap7-apache-cxf-3.3.5-1.redhat_00001.1.el8eap.noarch                          
  eap7-apache-cxf-rt-3.3.5-1.redhat_00001.1.el8eap.noarch                       
  eap7-apache-cxf-services-3.3.5-1.redhat_00001.1.el8eap.noarch                 
  eap7-apache-cxf-tools-3.3.5-1.redhat_00001.1.el8eap.noarch                    
  eap7-apache-mime4j-0.6.0-4.redhat_7.1.el8eap.noarch                           
  eap7-artemis-wildfly-integration-1.0.2-4.redhat_1.1.el8eap.noarch             
  eap7-atinject-1.0.0-4.redhat_00002.1.el8eap.noarch                            
  eap7-avro-1.7.6-7.redhat_2.1.el8eap.noarch                                    
  eap7-azure-storage-6.1.0-1.redhat_1.1.el8eap.noarch                           
  eap7-bouncycastle-mail-1.60.0-2.redhat_00002.1.el8eap.noarch                  
  eap7-bouncycastle-pkix-1.60.0-2.redhat_00002.1.el8eap.noarch                  
  eap7-bouncycastle-prov-1.60.0-2.redhat_00002.1.el8eap.noarch                  
  eap7-byte-buddy-1.9.11-1.redhat_00002.1.el8eap.noarch                         
  eap7-caffeine-2.6.2-3.redhat_1.1.el8eap.noarch                                
  eap7-cal10n-0.8.1-6.redhat_1.1.el8eap.noarch                                  
  eap7-codehaus-jackson-core-asl-1.9.13-10.redhat_00007.1.el8eap.noarch         
  eap7-codehaus-jackson-jaxrs-1.9.13-10.redhat_00007.1.el8eap.noarch            
  eap7-codehaus-jackson-mapper-asl-1.9.13-10.redhat_00007.1.el8eap.noarch       
  eap7-codehaus-jackson-xc-1.9.13-10.redhat_00007.1.el8eap.noarch               
  eap7-codemodel-2.3.3-4.b02_redhat_00001.1.el8eap.noarch                       
  eap7-commons-logging-jboss-logging-1.0.0-1.Final_redhat_1.1.el8eap.noarch     
  eap7-cryptacular-1.2.4-1.redhat_00001.1.el8eap.noarch                         
  eap7-cxf-xjc-boolean-3.3.0-1.redhat_00001.1.el8eap.noarch                     
  eap7-cxf-xjc-bug986-3.3.0-1.redhat_00001.1.el8eap.noarch                      
  eap7-cxf-xjc-dv-3.3.0-1.redhat_00001.1.el8eap.noarch                          
  eap7-cxf-xjc-runtime-3.3.0-1.redhat_00001.1.el8eap.noarch                     
  eap7-cxf-xjc-ts-3.3.0-1.redhat_00001.1.el8eap.noarch                          
  eap7-dom4j-2.1.1-2.redhat_00001.1.el8eap.noarch                               
  eap7-ecj-4.6.1-3.redhat_1.1.el8eap.noarch                                     
  eap7-eclipse-jgit-5.0.2.201807311906-2.r_redhat_00001.1.el8eap.noarch         
  eap7-glassfish-concurrent-1.0.0-4.redhat_1.1.el8eap.noarch                    
  eap7-glassfish-jaf-1.2.1-1.redhat_00002.1.el8eap.noarch                       
  eap7-glassfish-javamail-1.6.4-2.redhat_00001.1.el8eap.noarch                  
  eap7-glassfish-jsf-2.3.9-10.SP09_redhat_00001.1.el8eap.noarch                 
  eap7-glassfish-json-1.1.6-2.redhat_00001.1.el8eap.noarch                      
  eap7-gnu-getopt-1.0.13-6.redhat_5.1.el8eap.noarch                             
  eap7-gson-2.8.2-1.redhat_5.1.el8eap.noarch                                    
  eap7-guava-25.0.0-2.redhat_1.1.el8eap.noarch                                  
  eap7-h2database-1.4.193-6.redhat_2.1.el8eap.noarch                            
  eap7-hal-console-3.2.8-1.Final_redhat_00001.1.el8eap.noarch                   
  eap7-hibernate-beanvalidation-api-2.0.2-1.redhat_00001.1.el8eap.noarch        
  eap7-hibernate-commons-annotations-5.0.5-1.Final_redhat_00002.1.el8eap.noarch 
  eap7-hibernate-core-5.3.16-1.Final_redhat_00001.1.el8eap.noarch               
  eap7-hibernate-entitymanager-5.3.16-1.Final_redhat_00001.1.el8eap.noarch      
  eap7-hibernate-envers-5.3.16-1.Final_redhat_00001.1.el8eap.noarch             
  eap7-hibernate-search-backend-jms-5.10.7-1.Final_redhat_00001.1.el8eap.noarch 
  eap7-hibernate-search-engine-5.10.7-1.Final_redhat_00001.1.el8eap.noarch      
  eap7-hibernate-search-orm-5.10.7-1.Final_redhat_00001.1.el8eap.noarch         
  eap7-hibernate-search-serialization-avro-5.10.7-1.Final_redhat_00001.1.el8eap.noarch
  eap7-hibernate-validator-6.0.18-1.Final_redhat_00001.1.el8eap.noarch          
  eap7-hibernate-validator-cdi-6.0.18-1.Final_redhat_00001.1.el8eap.noarch      
  eap7-hornetq-commons-2.4.7-7.Final_redhat_2.1.el8eap.noarch                   
  eap7-hornetq-core-client-2.4.7-7.Final_redhat_2.1.el8eap.noarch               
  eap7-hornetq-jms-client-2.4.7-7.Final_redhat_2.1.el8eap.noarch                
  eap7-httpcomponents-asyncclient-4.1.4-1.redhat_00001.1.el8eap.noarch          
  eap7-httpcomponents-client-4.5.4-1.redhat_00001.1.el8eap.noarch               
  eap7-httpcomponents-core-4.4.5-1.redhat_00001.1.el8eap.noarch                 
  eap7-infinispan-cachestore-jdbc-9.4.18-1.Final_redhat_00001.1.el8eap.noarch   
  eap7-infinispan-cachestore-remote-9.4.18-1.Final_redhat_00001.1.el8eap.noarch 
  eap7-infinispan-client-hotrod-9.4.18-1.Final_redhat_00001.1.el8eap.noarch     
  eap7-infinispan-commons-9.4.18-1.Final_redhat_00001.1.el8eap.noarch           
  eap7-infinispan-core-9.4.18-1.Final_redhat_00001.1.el8eap.noarch              
  eap7-infinispan-hibernate-cache-commons-9.4.18-1.Final_redhat_00001.1.el8eap.noarch
  eap7-infinispan-hibernate-cache-spi-9.4.18-1.Final_redhat_00001.1.el8eap.noarch
  eap7-infinispan-hibernate-cache-v53-9.4.18-1.Final_redhat_00001.1.el8eap.noarch
  eap7-ironjacamar-common-api-1.4.20-1.Final_redhat_00001.1.el8eap.noarch       
  eap7-ironjacamar-common-impl-1.4.20-1.Final_redhat_00001.1.el8eap.noarch      
  eap7-ironjacamar-common-spi-1.4.20-1.Final_redhat_00001.1.el8eap.noarch       
  eap7-ironjacamar-core-api-1.4.20-1.Final_redhat_00001.1.el8eap.noarch         
  eap7-ironjacamar-core-impl-1.4.20-1.Final_redhat_00001.1.el8eap.noarch        
  eap7-ironjacamar-deployers-common-1.4.20-1.Final_redhat_00001.1.el8eap.noarch 
  eap7-ironjacamar-jdbc-1.4.20-1.Final_redhat_00001.1.el8eap.noarch             
  eap7-ironjacamar-validator-1.4.20-1.Final_redhat_00001.1.el8eap.noarch        
  eap7-istack-commons-runtime-3.0.10-1.redhat_00001.1.el8eap.noarch             
  eap7-istack-commons-tools-3.0.10-1.redhat_00001.1.el8eap.noarch               
  eap7-jackson-annotations-2.10.3-1.redhat_00001.1.el8eap.noarch                
  eap7-jackson-core-2.10.3-1.redhat_00001.1.el8eap.noarch                       
  eap7-jackson-coreutils-1.0.0-1.redhat_1.1.el8eap.noarch                       
  eap7-jackson-databind-2.10.3-1.redhat_00001.1.el8eap.noarch                   
  eap7-jackson-datatype-jdk8-2.10.3-1.redhat_00001.1.el8eap.noarch              
  eap7-jackson-datatype-jsr310-2.10.3-1.redhat_00001.1.el8eap.noarch            
  eap7-jackson-jaxrs-base-2.10.3-1.redhat_00001.1.el8eap.noarch                 
  eap7-jackson-jaxrs-json-provider-2.10.3-1.redhat_00001.1.el8eap.noarch        
  eap7-jackson-module-jaxb-annotations-2.10.3-1.redhat_00001.1.el8eap.noarch    
  eap7-jaegertracing-jaeger-client-java-core-0.34.3-1.redhat_00001.1.el8eap.noarch
  eap7-jaegertracing-jaeger-client-java-thrift-0.34.3-1.redhat_00001.1.el8eap.noarch
  eap7-jakarta-el-3.0.3-1.redhat_00002.1.el8eap.noarch                          
  eap7-jakarta-security-enterprise-api-1.0.2-3.redhat_00001.1.el8eap.noarch     
  eap7-jandex-2.1.2-1.Final_redhat_00001.1.el8eap.noarch                        
  eap7-jansi-1.18.0-1.redhat_00001.1.el8eap.noarch                              
  eap7-jasypt-1.9.3-1.redhat_00001.1.el8eap.noarch                              
  eap7-java-classmate-1.3.4-1.redhat_1.1.el8eap.noarch                          
  eap7-javaee-jpa-spec-2.2.3-1.redhat_00001.1.el8eap.noarch                     
  eap7-javaee-security-api-1.0.0-2.redhat_1.1.el8eap.noarch                     
  eap7-javaee-security-soteria-enterprise-1.0.1-3.redhat_00002.1.el8eap.noarch  
  eap7-javaewah-1.1.6-1.redhat_00001.1.el8eap.noarch                            
  eap7-javapackages-tools-3.4.1-5.15.6.el8eap.noarch                            
  eap7-javassist-3.23.2-2.GA_redhat_00001.1.el8eap.noarch                       
  eap7-jaxb-jxc-2.3.3-4.b02_redhat_00001.1.el8eap.noarch                        
  eap7-jaxb-runtime-2.3.3-4.b02_redhat_00001.1.el8eap.noarch                    
  eap7-jaxb-xjc-2.3.3-4.b02_redhat_00001.1.el8eap.noarch                        
  eap7-jaxbintros-1.0.3-1.GA_redhat_00001.1.el8eap.noarch                       
  eap7-jaxen-1.1.6-14.redhat_2.1.el8eap.noarch                                  
  eap7-jberet-core-1.3.5-1.Final_redhat_00001.1.el8eap.noarch                   
  eap7-jboss-aesh-2.4.0-1.redhat_00001.1.el8eap.noarch                          
  eap7-jboss-annotations-api_1.3_spec-2.0.1-2.Final_redhat_00001.1.el8eap.noarch
  eap7-jboss-batch-api_1.0_spec-2.0.0-1.Final_redhat_00001.1.el8eap.noarch      
  eap7-jboss-classfilewriter-1.2.4-1.Final_redhat_00001.1.el8eap.noarch         
  eap7-jboss-common-beans-2.0.1-1.Final_redhat_00001.1.el8eap.noarch            
  eap7-jboss-concurrency-api_1.0_spec-2.0.0-1.Final_redhat_00001.1.el8eap.noarch
  eap7-jboss-connector-api_1.7_spec-2.0.0-2.Final_redhat_00001.1.el8eap.noarch  
  eap7-jboss-dmr-1.5.0-2.Final_redhat_1.1.el8eap.noarch                         
  eap7-jboss-ejb-api_3.2_spec-2.0.0-1.Final_redhat_00001.1.el8eap.noarch        
  eap7-jboss-ejb-client-4.0.31-1.Final_redhat_00001.1.el8eap.noarch             
  eap7-jboss-ejb3-ext-api-2.3.0-1.Final_redhat_00001.1.el8eap.noarch            
  eap7-jboss-el-api_3.0_spec-2.0.0-2.Final_redhat_00001.1.el8eap.noarch         
  eap7-jboss-genericjms-2.0.4-1.Final_redhat_00001.1.el8eap.noarch              
  eap7-jboss-iiop-client-1.0.1-3.Final_redhat_1.1.el8eap.noarch                 
  eap7-jboss-interceptors-api_1.2_spec-2.0.0-3.Final_redhat_00002.1.el8eap.noarch
  eap7-jboss-invocation-1.5.2-1.Final_redhat_00001.1.el8eap.noarch              
  eap7-jboss-j2eemgmt-api_1.1_spec-2.0.0-2.Final_redhat_00001.1.el8eap.noarch   
  eap7-jboss-jacc-api_1.5_spec-2.0.0-2.Final_redhat_00001.1.el8eap.noarch       
  eap7-jboss-jaspi-api_1.1_spec-2.0.1-2.Final_redhat_00001.1.el8eap.noarch      
  eap7-jboss-jaxb-api_2.3_spec-1.0.1-1.Final_redhat_1.1.el8eap.noarch           
  eap7-jboss-jaxrpc-api_1.1_spec-2.0.0-1.Final_redhat_00001.1.el8eap.noarch     
  eap7-jboss-jaxrs-api_2.1_spec-2.0.1-1.Final_redhat_00001.1.el8eap.noarch      
  eap7-jboss-jaxws-api_2.3_spec-1.0.0-1.Final_redhat_1.1.el8eap.noarch          
  eap7-jboss-jms-api_2.0_spec-2.0.0-1.Final_redhat_00001.1.el8eap.noarch        
  eap7-jboss-jsf-api_2.3_spec-3.0.0-3.SP02_redhat_00001.1.el8eap.noarch         
  eap7-jboss-jsp-api_2.3_spec-2.0.0-1.Final_redhat_00001.1.el8eap.noarch        
  eap7-jboss-logging-3.4.1-2.Final_redhat_00001.1.el8eap.noarch                 
  eap7-jboss-logmanager-2.1.14-1.Final_redhat_00001.1.el8eap.noarch             
  eap7-jboss-marshalling-2.0.9-1.Final_redhat_00001.1.el8eap.noarch             
  eap7-jboss-marshalling-river-2.0.9-1.Final_redhat_00001.1.el8eap.noarch       
  eap7-jboss-metadata-appclient-13.0.0-1.Final_redhat_00001.1.el8eap.noarch     
  eap7-jboss-metadata-common-13.0.0-1.Final_redhat_00001.1.el8eap.noarch        
  eap7-jboss-metadata-ear-13.0.0-1.Final_redhat_00001.1.el8eap.noarch           
  eap7-jboss-metadata-ejb-13.0.0-1.Final_redhat_00001.1.el8eap.noarch           
  eap7-jboss-metadata-web-13.0.0-1.Final_redhat_00001.1.el8eap.noarch           
  eap7-jboss-modules-1.10.0-1.Final_redhat_00001.1.el8eap.noarch                
  eap7-jboss-msc-1.4.11-1.Final_redhat_00001.1.el8eap.noarch                    
  eap7-jboss-openjdk-orb-8.1.4-3.Final_redhat_00002.1.el8eap.noarch             
  eap7-jboss-remoting-5.0.18-1.Final_redhat_00001.1.el8eap.noarch               
  eap7-jboss-remoting-jmx-3.0.4-1.Final_redhat_00001.1.el8eap.noarch            
  eap7-jboss-saaj-api_1.3_spec-1.0.6-1.Final_redhat_1.1.el8eap.noarch           
  eap7-jboss-saaj-api_1.4_spec-1.0.1-1.Final_redhat_00001.1.el8eap.noarch       
  eap7-jboss-seam-int-7.0.0-6.GA_redhat_2.1.el8eap.noarch                       
  eap7-jboss-security-negotiation-3.0.6-1.Final_redhat_00001.1.el8eap.noarch    
  eap7-jboss-security-xacml-2.0.8-17.Final_redhat_8.1.el8eap.noarch             
  eap7-jboss-server-migration-1.7.1-5.Final_redhat_00006.1.el8eap.noarch        
  eap7-jboss-server-migration-cli-1.7.1-5.Final_redhat_00006.1.el8eap.noarch    
  eap7-jboss-server-migration-core-1.7.1-5.Final_redhat_00006.1.el8eap.noarch   
  eap7-jboss-server-migration-eap6.4-1.7.1-5.Final_redhat_00006.1.el8eap.noarch 
  eap7-jboss-server-migration-eap6.4-to-eap7.3-1.7.1-5.Final_redhat_00006.1.el8eap.noarch
  eap7-jboss-server-migration-eap7.0-1.7.1-5.Final_redhat_00006.1.el8eap.noarch 
  eap7-jboss-server-migration-eap7.1-1.7.1-5.Final_redhat_00006.1.el8eap.noarch 
  eap7-jboss-server-migration-eap7.2-1.7.1-5.Final_redhat_00006.1.el8eap.noarch 
  eap7-jboss-server-migration-eap7.2-to-eap7.3-1.7.1-5.Final_redhat_00006.1.el8eap.noarch
  eap7-jboss-server-migration-eap7.3-server-1.7.1-5.Final_redhat_00006.1.el8eap.noarch
  eap7-jboss-server-migration-wildfly10.0-1.7.1-5.Final_redhat_00006.1.el8eap.noarch
  eap7-jboss-server-migration-wildfly10.1-1.7.1-5.Final_redhat_00006.1.el8eap.noarch
  eap7-jboss-server-migration-wildfly11.0-1.7.1-5.Final_redhat_00006.1.el8eap.noarch
  eap7-jboss-server-migration-wildfly12.0-1.7.1-5.Final_redhat_00006.1.el8eap.noarch
  eap7-jboss-server-migration-wildfly13.0-server-1.7.1-5.Final_redhat_00006.1.el8eap.noarch
  eap7-jboss-server-migration-wildfly14.0-server-1.7.1-5.Final_redhat_00006.1.el8eap.noarch
  eap7-jboss-server-migration-wildfly15.0-server-1.7.1-5.Final_redhat_00006.1.el8eap.noarch
  eap7-jboss-server-migration-wildfly16.0-server-1.7.1-5.Final_redhat_00006.1.el8eap.noarch
  eap7-jboss-server-migration-wildfly17.0-server-1.7.1-5.Final_redhat_00006.1.el8eap.noarch
  eap7-jboss-server-migration-wildfly18.0-server-1.7.1-5.Final_redhat_00006.1.el8eap.noarch
  eap7-jboss-server-migration-wildfly8.2-1.7.1-5.Final_redhat_00006.1.el8eap.noarch
  eap7-jboss-server-migration-wildfly9.0-1.7.1-5.Final_redhat_00006.1.el8eap.noarch
  eap7-jboss-servlet-api_4.0_spec-2.0.0-2.Final_redhat_00001.1.el8eap.noarch    
  eap7-jboss-stdio-1.1.0-1.Final_redhat_00001.1.el8eap.noarch                   
  eap7-jboss-threads-2.3.3-1.Final_redhat_00001.1.el8eap.noarch                 
  eap7-jboss-transaction-api_1.3_spec-2.0.0-3.Final_redhat_00002.1.el8eap.noarch
  eap7-jboss-transaction-spi-7.6.0-2.Final_redhat_1.1.el8eap.noarch             
  eap7-jboss-vfs-3.2.15-1.Final_redhat_00001.1.el8eap.noarch                    
  eap7-jboss-websocket-api_1.1_spec-2.0.0-1.Final_redhat_00001.1.el8eap.noarch  
  eap7-jboss-weld-3.1-api-weld-api-3.1.0-6.SP2_redhat_00001.1.el8eap.noarch     
  eap7-jboss-weld-3.1-api-weld-spi-3.1.0-6.SP2_redhat_00001.1.el8eap.noarch     
  eap7-jboss-xnio-base-3.7.7-1.Final_redhat_00001.1.el8eap.noarch               
  eap7-jbossws-api-1.1.2-1.Final_redhat_00001.1.el8eap.noarch                   
  eap7-jbossws-common-3.2.3-1.Final_redhat_00001.1.el8eap.noarch                
  eap7-jbossws-common-tools-1.3.2-1.Final_redhat_00001.1.el8eap.noarch          
  eap7-jbossws-cxf-5.3.0-1.Final_redhat_00001.1.el8eap.noarch                   
  eap7-jbossws-jaxws-undertow-httpspi-1.0.1-3.Final_redhat_1.1.el8eap.noarch    
  eap7-jbossws-spi-3.2.3-1.Final_redhat_00001.1.el8eap.noarch                   
  eap7-jcip-annotations-1.0.0-5.redhat_8.1.el8eap.noarch                        
  eap7-jettison-1.4.0-1.redhat_00001.1.el8eap.noarch                            
  eap7-jgroups-4.1.4-1.Final_redhat_00001.1.el8eap.noarch                       
  eap7-jgroups-azure-1.2.1-1.Final_redhat_00001.1.el8eap.noarch                 
  eap7-jgroups-kubernetes-1.0.13-1.Final_redhat_00001.1.el8eap.noarch           
  eap7-joda-time-2.9.7-2.redhat_1.1.el8eap.noarch                               
  eap7-jsch-0.1.54-7.redhat_00001.1.el8eap.noarch                               
  eap7-json-patch-1.9.0-1.redhat_00002.1.el8eap.noarch                          
  eap7-jsonb-spec-1.0.2-1.redhat_00001.1.el8eap.noarch                          
  eap7-jsoup-1.8.3-4.redhat_2.1.el8eap.noarch                                   
  eap7-jul-to-slf4j-stub-1.0.1-7.Final_redhat_3.1.el8eap.noarch                 
  eap7-jzlib-1.1.1-7.redhat_00001.1.el8eap.noarch                               
  eap7-log4j-jboss-logmanager-1.2.0-1.Final_redhat_00001.1.el8eap.noarch        
  eap7-lucene-analyzers-common-5.5.5-3.redhat_2.1.el8eap.noarch                 
  eap7-lucene-backward-codecs-5.5.5-3.redhat_2.1.el8eap.noarch                  
  eap7-lucene-core-5.5.5-3.redhat_2.1.el8eap.noarch                             
  eap7-lucene-facet-5.5.5-3.redhat_2.1.el8eap.noarch                            
  eap7-lucene-misc-5.5.5-3.redhat_2.1.el8eap.noarch                             
  eap7-lucene-queries-5.5.5-3.redhat_2.1.el8eap.noarch                          
  eap7-lucene-queryparser-5.5.5-3.redhat_2.1.el8eap.noarch                      
  eap7-microprofile-config-api-1.4.0-1.redhat_00003.1.el8eap.noarch             
  eap7-microprofile-health-2.2.0-1.redhat_00001.1.el8eap.noarch                 
  eap7-microprofile-metrics-api-2.3.0-1.redhat_00001.1.el8eap.noarch            
  eap7-microprofile-opentracing-api-1.3.3-1.redhat_00001.1.el8eap.noarch        
  eap7-microprofile-rest-client-api-1.4.0-1.redhat_00004.1.el8eap.noarch        
  eap7-mod_cluster-1.4.1-1.Final_redhat_00001.1.el8eap.noarch                   
  eap7-mustache-java-compiler-0.9.4-2.redhat_1.1.el8eap.noarch                  
  eap7-narayana-compensations-5.9.8-1.Final_redhat_00002.1.el8eap.noarch        
  eap7-narayana-jbosstxbridge-5.9.8-1.Final_redhat_00002.1.el8eap.noarch        
  eap7-narayana-jbossxts-5.9.8-1.Final_redhat_00002.1.el8eap.noarch             
  eap7-narayana-jts-idlj-5.9.8-1.Final_redhat_00002.1.el8eap.noarch             
  eap7-narayana-jts-integration-5.9.8-1.Final_redhat_00002.1.el8eap.noarch      
  eap7-narayana-restat-api-5.9.8-1.Final_redhat_00002.1.el8eap.noarch           
  eap7-narayana-restat-bridge-5.9.8-1.Final_redhat_00002.1.el8eap.noarch        
  eap7-narayana-restat-integration-5.9.8-1.Final_redhat_00002.1.el8eap.noarch   
  eap7-narayana-restat-util-5.9.8-1.Final_redhat_00002.1.el8eap.noarch          
  eap7-narayana-txframework-5.9.8-1.Final_redhat_00002.1.el8eap.noarch          
  eap7-neethi-3.1.1-1.redhat_1.1.el8eap.noarch                                  
  eap7-netty-all-4.1.45-1.Final_redhat_00001.1.el8eap.noarch                    
  eap7-netty-xnio-transport-0.1.6-1.Final_redhat_00001.1.el8eap.noarch          
  eap7-objectweb-asm-7.1.0-1.redhat_00001.1.el8eap.noarch                       
  eap7-okhttp-3.9.0-3.redhat_3.1.el8eap.noarch                                  
  eap7-okio-1.13.0-2.redhat_3.1.el8eap.noarch                                   
  eap7-opensaml-core-3.3.1-1.redhat_00002.1.el8eap.noarch                       
  eap7-opensaml-profile-api-3.3.1-1.redhat_00002.1.el8eap.noarch                
  eap7-opensaml-saml-api-3.3.1-1.redhat_00002.1.el8eap.noarch                   
  eap7-opensaml-saml-impl-3.3.1-1.redhat_00002.1.el8eap.noarch                  
  eap7-opensaml-security-api-3.3.1-1.redhat_00002.1.el8eap.noarch               
  eap7-opensaml-security-impl-3.3.1-1.redhat_00002.1.el8eap.noarch              
  eap7-opensaml-soap-api-3.3.1-1.redhat_00002.1.el8eap.noarch                   
  eap7-opensaml-xacml-api-3.3.1-1.redhat_00002.1.el8eap.noarch                  
  eap7-opensaml-xacml-impl-3.3.1-1.redhat_00002.1.el8eap.noarch                 
  eap7-opensaml-xacml-saml-api-3.3.1-1.redhat_00002.1.el8eap.noarch             
  eap7-opensaml-xacml-saml-impl-3.3.1-1.redhat_00002.1.el8eap.noarch            
  eap7-opensaml-xmlsec-api-3.3.1-1.redhat_00002.1.el8eap.noarch                 
  eap7-opensaml-xmlsec-impl-3.3.1-1.redhat_00002.1.el8eap.noarch                
  eap7-opentracing-contrib-java-concurrent-0.2.1-1.redhat_00001.1.el8eap.noarch 
  eap7-opentracing-contrib-java-jaxrs-0.4.1-1.redhat_00006.1.el8eap.noarch      
  eap7-opentracing-contrib-java-tracerresolver-0.1.5-1.redhat_00001.1.el8eap.noarch
  eap7-opentracing-contrib-java-web-servlet-filter-0.2.3-1.redhat_00001.1.el8eap.noarch
  eap7-opentracing-interceptors-0.0.4-1.redhat_00004.1.el8eap.noarch            
  eap7-opentracing-java-api-0.31.0-1.redhat_00008.1.el8eap.noarch               
  eap7-opentracing-java-noop-0.31.0-1.redhat_00008.1.el8eap.noarch              
  eap7-opentracing-java-util-0.31.0-1.redhat_00008.1.el8eap.noarch              
  eap7-picketbox-5.0.3-7.Final_redhat_00006.1.el8eap.noarch                     
  eap7-picketbox-commons-1.0.0-4.final_redhat_5.1.el8eap.noarch                 
  eap7-picketbox-infinispan-5.0.3-7.Final_redhat_00006.1.el8eap.noarch          
  eap7-picketlink-api-2.5.5-20.SP12_redhat_00009.1.el8eap.noarch                
  eap7-picketlink-common-2.5.5-20.SP12_redhat_00009.1.el8eap.noarch             
  eap7-picketlink-config-2.5.5-20.SP12_redhat_00009.1.el8eap.noarch             
  eap7-picketlink-federation-2.5.5-20.SP12_redhat_00009.1.el8eap.noarch         
  eap7-picketlink-idm-api-2.5.5-20.SP12_redhat_00009.1.el8eap.noarch            
  eap7-picketlink-idm-impl-2.5.5-20.SP12_redhat_00009.1.el8eap.noarch           
  eap7-picketlink-idm-simple-schema-2.5.5-20.SP12_redhat_00009.1.el8eap.noarch  
  eap7-picketlink-impl-2.5.5-20.SP12_redhat_00009.1.el8eap.noarch               
  eap7-picketlink-wildfly8-2.5.5-23.SP12_redhat_00012.1.el8eap.noarch           
  eap7-python3-javapackages-3.4.1-5.15.6.el8eap.noarch                          
  eap7-reactive-streams-1.0.2-2.redhat_1.1.el8eap.noarch                        
  eap7-reactivex-rxjava-2.2.5-1.redhat_00001.1.el8eap.noarch                    
  eap7-relaxng-datatype-2.3.3-4.b02_redhat_00001.1.el8eap.noarch                
  eap7-resteasy-atom-provider-3.11.2-3.Final_redhat_00002.1.el8eap.noarch       
  eap7-resteasy-cdi-3.11.2-3.Final_redhat_00002.1.el8eap.noarch                 
  eap7-resteasy-client-3.11.2-3.Final_redhat_00002.1.el8eap.noarch              
  eap7-resteasy-client-microprofile-3.11.2-3.Final_redhat_00002.1.el8eap.noarch 
  eap7-resteasy-crypto-3.11.2-3.Final_redhat_00002.1.el8eap.noarch              
  eap7-resteasy-jackson-provider-3.11.2-3.Final_redhat_00002.1.el8eap.noarch    
  eap7-resteasy-jackson2-provider-3.11.2-3.Final_redhat_00002.1.el8eap.noarch   
  eap7-resteasy-jaxb-provider-3.11.2-3.Final_redhat_00002.1.el8eap.noarch       
  eap7-resteasy-jaxrs-3.11.2-3.Final_redhat_00002.1.el8eap.noarch               
  eap7-resteasy-jettison-provider-3.11.2-3.Final_redhat_00002.1.el8eap.noarch   
  eap7-resteasy-jose-jwt-3.11.2-3.Final_redhat_00002.1.el8eap.noarch            
  eap7-resteasy-jsapi-3.11.2-3.Final_redhat_00002.1.el8eap.noarch               
  eap7-resteasy-json-binding-provider-3.11.2-3.Final_redhat_00002.1.el8eap.noarch
  eap7-resteasy-json-p-provider-3.11.2-3.Final_redhat_00002.1.el8eap.noarch     
  eap7-resteasy-multipart-provider-3.11.2-3.Final_redhat_00002.1.el8eap.noarch  
  eap7-resteasy-rxjava2-3.11.2-3.Final_redhat_00002.1.el8eap.noarch             
  eap7-resteasy-spring-3.11.2-3.Final_redhat_00002.1.el8eap.noarch              
  eap7-resteasy-validator-provider-11-3.11.2-3.Final_redhat_00002.1.el8eap.noarch
  eap7-resteasy-yaml-provider-3.11.2-3.Final_redhat_00002.1.el8eap.noarch       
  eap7-rngom-2.3.3-4.b02_redhat_00001.1.el8eap.noarch                           
  eap7-runtime-1-16.el8eap.x86_64                                               
  eap7-shibboleth-java-support-7.3.0-1.redhat_00001.1.el8eap.noarch             
  eap7-slf4j-api-1.7.22-4.redhat_2.1.el8eap.noarch                              
  eap7-slf4j-ext-1.7.22-4.redhat_2.1.el8eap.noarch                              
  eap7-slf4j-jboss-logmanager-1.0.4-1.GA_redhat_00001.1.el8eap.noarch           
  eap7-smallrye-config-1.6.2-3.redhat_00004.1.el8eap.noarch                     
  eap7-smallrye-health-2.2.0-1.redhat_00004.1.el8eap.noarch                     
  eap7-smallrye-metrics-2.4.0-1.redhat_00004.1.el8eap.noarch                    
  eap7-smallrye-opentracing-1.3.4-1.redhat_00004.1.el8eap.noarch                
  eap7-snakeyaml-1.24.0-2.redhat_00001.1.el8eap.noarch                          
  eap7-stax-ex-1.7.8-1.redhat_00001.1.el8eap.noarch                             
  eap7-stax2-api-4.2.0-1.redhat_00001.1.el8eap.noarch                           
  eap7-staxmapper-1.3.0-2.Final_redhat_1.1.el8eap.noarch                        
  eap7-sun-saaj-1.3-impl-1.3.16-18.SP1_redhat_6.1.el8eap.noarch                 
  eap7-sun-saaj-1.4-impl-1.4.1-1.SP1_redhat_00001.1.el8eap.noarch               
  eap7-sun-ws-metadata-2.0-api-1.0.0-7.MR1_redhat_8.1.el8eap.noarch             
  eap7-taglibs-standard-compat-1.2.6-2.RC1_redhat_1.1.el8eap.noarch             
  eap7-taglibs-standard-impl-1.2.6-2.RC1_redhat_1.1.el8eap.noarch               
  eap7-taglibs-standard-spec-1.2.6-2.RC1_redhat_1.1.el8eap.noarch               
  eap7-thrift-0.13.0-1.redhat_00002.1.el8eap.noarch                             
  eap7-txw2-2.3.3-4.b02_redhat_00001.1.el8eap.noarch                            
  eap7-undertow-2.0.30-3.SP3_redhat_00001.1.el8eap.noarch                       
  eap7-undertow-jastow-2.0.8-1.Final_redhat_00001.1.el8eap.noarch               
  eap7-undertow-js-1.0.2-2.Final_redhat_1.1.el8eap.noarch                       
  eap7-undertow-server-1.6.1-1.Final_redhat_00001.1.el8eap.noarch               
  eap7-vdx-core-1.1.6-2.redhat_1.1.el8eap.noarch                                
  eap7-vdx-wildfly-1.1.6-2.redhat_1.1.el8eap.noarch                             
  eap7-velocity-2.1.0-1.redhat_00001.1.el8eap.noarch                            
  eap7-velocity-engine-core-2.1.0-1.redhat_00001.1.el8eap.noarch                
  eap7-weld-cdi-2.0-api-2.0.2-2.redhat_00002.1.el8eap.noarch                    
  eap7-weld-core-impl-3.1.4-1.Final_redhat_00001.1.el8eap.noarch                
  eap7-weld-core-jsf-3.1.4-1.Final_redhat_00001.1.el8eap.noarch                 
  eap7-weld-ejb-3.1.4-1.Final_redhat_00001.1.el8eap.noarch                      
  eap7-weld-jta-3.1.4-1.Final_redhat_00001.1.el8eap.noarch                      
  eap7-weld-probe-core-3.1.4-1.Final_redhat_00001.1.el8eap.noarch               
  eap7-weld-web-3.1.4-1.Final_redhat_00001.1.el8eap.noarch                      
  eap7-wildfly-7.3.1-5.GA_redhat_00003.1.el8eap.noarch                          
  eap7-wildfly-client-config-1.0.1-2.Final_redhat_00001.1.el8eap.noarch         
  eap7-wildfly-common-1.5.1-1.Final_redhat_00001.1.el8eap.noarch                
  eap7-wildfly-discovery-client-1.2.0-1.Final_redhat_00001.1.el8eap.noarch      
  eap7-wildfly-elytron-1.10.6-1.Final_redhat_00001.1.el8eap.noarch              
  eap7-wildfly-elytron-tool-1.10.6-1.Final_redhat_00001.1.el8eap.noarch         
  eap7-wildfly-http-client-common-1.0.20-1.Final_redhat_00001.1.el8eap.noarch   
  eap7-wildfly-http-ejb-client-1.0.20-1.Final_redhat_00001.1.el8eap.noarch      
  eap7-wildfly-http-naming-client-1.0.20-1.Final_redhat_00001.1.el8eap.noarch   
  eap7-wildfly-http-transaction-client-1.0.20-1.Final_redhat_00001.1.el8eap.noarch
  eap7-wildfly-modules-7.3.1-5.GA_redhat_00003.1.el8eap.noarch                  
  eap7-wildfly-naming-client-1.0.12-1.Final_redhat_00001.1.el8eap.noarch        
  eap7-wildfly-openssl-java-1.0.9-2.SP03_redhat_00001.1.el8eap.noarch           
  eap7-wildfly-openssl-linux-x86_64-1.0.9-2.SP03_redhat_00001.1.el8eap.x86_64   
  eap7-wildfly-transaction-client-1.1.11-1.Final_redhat_00001.1.el8eap.noarch   
  eap7-woodstox-core-6.0.3-1.redhat_00001.1.el8eap.noarch                       
  eap7-ws-commons-XmlSchema-2.2.4-1.redhat_00001.1.el8eap.noarch                
  eap7-wsdl4j-1.6.3-13.redhat_2.1.el8eap.noarch                                 
  eap7-wss4j-bindings-2.2.5-1.redhat_00001.1.el8eap.noarch                      
  eap7-wss4j-policy-2.2.5-1.redhat_00001.1.el8eap.noarch                        
  eap7-wss4j-ws-security-common-2.2.5-1.redhat_00001.1.el8eap.noarch            
  eap7-wss4j-ws-security-dom-2.2.5-1.redhat_00001.1.el8eap.noarch               
  eap7-wss4j-ws-security-policy-stax-2.2.5-1.redhat_00001.1.el8eap.noarch       
  eap7-wss4j-ws-security-stax-2.2.5-1.redhat_00001.1.el8eap.noarch              
  eap7-xalan-j2-2.7.1-35.redhat_12.1.el8eap.noarch                              
  eap7-xerces-j2-2.12.0-1.SP02_redhat_00001.1.el8eap.noarch                     
  eap7-xml-resolver-1.2.0-7.redhat_12.1.el8eap.noarch                           
  eap7-xml-security-2.1.4-1.redhat_00001.1.el8eap.noarch                        
  eap7-xom-1.2.10-4.redhat_1.1.el8eap.noarch                                    
  eap7-xsom-2.3.3-4.b02_redhat_00001.1.el8eap.noarch                            
  eap7-yasson-1.0.5-1.redhat_00001.1.el8eap.noarch                              
  ebay-cors-filter-1.0.1-4.el8ev.noarch                                         
  engine-db-query-1.5.0-1.el8ev.noarch                                          
  environment-modules-4.1.4-4.el8.x86_64                                        
  fribidi-1.0.4-8.el8.x86_64                                                    
  gd-2.2.5-6.el8.x86_64                                                         
  gdk-pixbuf2-modules-2.36.12-5.el8.x86_64                                      
  giflib-5.1.4-3.el8.x86_64                                                     
  glassfish-fastinfoset-1.2.13-9.module+el8.1.0+3366+6dfb954c.noarch            
  glassfish-jaxb-api-2.2.12-8.module+el8.1.0+3366+6dfb954c.noarch               
  glassfish-jaxb-core-2.2.11-11.module+el8.1.0+3366+6dfb954c.noarch             
  glassfish-jaxb-runtime-2.2.11-11.module+el8.1.0+3366+6dfb954c.noarch          
  glassfish-jaxb-txw2-2.2.11-11.module+el8.1.0+3366+6dfb954c.noarch             
  gnutls-dane-3.6.8-10.el8_2.x86_64                                             
  gnutls-utils-3.6.8-10.el8_2.x86_64                                            
  graphite2-1.3.10-10.el8.x86_64                                                
  graphviz-2.40.1-40.el8.x86_64                                                 
  gssproxy-0.8.0-15.el8.x86_64                                                  
  gtk-update-icon-cache-3.22.30-5.el8.x86_64                                    
  gtk2-2.24.32-4.el8.x86_64                                                     
  harfbuzz-1.7.5-3.el8.x86_64                                                   
  hicolor-icon-theme-0.17-2.el8.noarch                                          
  httpcomponents-client-4.5.5-4.module+el8+2598+06babf2e.noarch                 
  httpcomponents-core-4.4.10-3.module+el8+2598+06babf2e.noarch                  
  httpd-2.4.37-21.module+el8.2.0+5008+cca404a3.x86_64                           
  httpd-filesystem-2.4.37-21.module+el8.2.0+5008+cca404a3.noarch                
  httpd-tools-2.4.37-21.module+el8.2.0+5008+cca404a3.x86_64                     
  insights-client-3.0.13-1.el8.noarch                                           
  istack-commons-runtime-2.21-9.el8+7.noarch                                    
  jackson-annotations-2.10.0-1.module+el8.2.0+5059+3eb3af25.noarch              
  jackson-core-2.10.0-1.module+el8.2.0+5059+3eb3af25.noarch                     
  jackson-databind-2.10.0-1.module+el8.2.0+5059+3eb3af25.noarch                 
  jackson-jaxrs-json-provider-2.9.9-1.module+el8.1.0+3832+9784644d.noarch       
  jackson-jaxrs-providers-2.9.9-1.module+el8.1.0+3832+9784644d.noarch           
  jackson-module-jaxb-annotations-2.7.6-4.module+el8.1.0+3366+6dfb954c.noarch   
  jasper-libs-2.0.14-4.el8.x86_64                                               
  java-1.8.0-openjdk-1:1.8.0.252.b09-3.el8_2.x86_64                             
  java-client-kubevirt-0.5.0-1.el8ev.noarch                                     
  javapackages-tools-5.3.0-2.module+el8+2598+06babf2e.noarch                    
  jbig2dec-libs-0.14-2.el8.x86_64                                               
  jbigkit-libs-2.1-14.el8.x86_64                                                
  jboss-annotations-1.2-api-1.0.0-4.el8.noarch                                  
  jboss-jaxrs-2.0-api-1.0.0-6.el8.noarch                                        
  jboss-logging-3.3.0-5.el8.noarch                                              
  jboss-logging-tools-2.0.1-6.el8.noarch                                        
  jcl-over-slf4j-1.7.25-4.module+el8.1.0+3366+6dfb954c.noarch                   
  jdeparser-2.0.0-5.el8.noarch                                                  
  keyutils-1.5.10-6.el8.x86_64                                                  
  libXaw-1.0.13-10.el8.x86_64                                                   
  libXcomposite-0.4.4-14.el8.x86_64                                             
  libXdamage-1.1.4-14.el8.x86_64                                                
  libXft-2.3.2-10.el8.x86_64                                                    
  libXpm-3.5.12-8.el8.x86_64                                                    
  libXtst-1.2.3-7.el8.x86_64                                                    
  libdatrie-0.2.9-7.el8.x86_64                                                  
  libestr-0.1.10-1.el8.x86_64                                                   
  libfastjson-0.99.8-2.el8.x86_64                                               
  libgfortran-8.3.1-5.el8.x86_64                                                
  libgs-9.25-5.el8_1.1.x86_64                                                   
  libicu-60.3-2.el8_1.x86_64                                                    
  libidn-1.34-5.el8.x86_64                                                      
  libijs-0.35-5.el8.x86_64                                                      
  liblognorm-2.0.5-1.el8.x86_64                                                 
  libpaper-1.1.24-22.el8.x86_64                                                 
  libpq-12.1-3.el8.x86_64                                                       
  libquadmath-8.3.1-5.el8.x86_64                                                
  librsvg2-2.42.7-3.el8.x86_64                                                  
  libsodium-1.0.18-2.el8ev.x86_64                                               
  libthai-0.1.27-2.el8.x86_64                                                   
  libtiff-4.0.9-17.el8.x86_64                                                   
  libverto-libevent-0.3.0-5.el8.x86_64                                          
  libwebp-1.0.0-1.el8.x86_64                                                    
  log4j12-1.2.17-22.el8ev.noarch                                                
  logrotate-3.14.0-3.el8.x86_64                                                 
  mailcap-2.1.48-3.el8.noarch                                                   
  mod_http2-1.11.3-3.module+el8.2.0+4377+dc421495.x86_64                        
  mod_ssl-1:2.4.37-21.module+el8.2.0+5008+cca404a3.x86_64                       
  nfs-utils-1:2.3.3-31.el8.x86_64                                               
  nodejs-1:10.19.0-2.module+el8.2.0+6232+1df3dc5f.x86_64                        
  novnc-1.1.0-1.el8ost.noarch                                                   
  npm-1:6.13.4-1.10.19.0.2.module+el8.2.0+6232+1df3dc5f.x86_64                  
  ongres-scram-1.0.0~beta.2-5.el8.noarch                                        
  ongres-scram-client-1.0.0~beta.2-5.el8.noarch                                 
  openblas-0.3.3-5.el8.x86_64                                                   
  openblas-threads-0.3.3-5.el8.x86_64                                           
  openjpeg2-2.3.1-6.el8.x86_64                                                  
  openstack-java-cinder-client-3.2.8-1.el8ev.noarch                             
  openstack-java-cinder-model-3.2.8-1.el8ev.noarch                              
  openstack-java-client-3.2.8-1.el8ev.noarch                                    
  openstack-java-glance-client-3.2.8-1.el8ev.noarch                             
  openstack-java-glance-model-3.2.8-1.el8ev.noarch                              
  openstack-java-keystone-client-3.2.8-1.el8ev.noarch                           
  openstack-java-keystone-model-3.2.8-1.el8ev.noarch                            
  openstack-java-quantum-client-3.2.8-1.el8ev.noarch                            
  openstack-java-quantum-model-3.2.8-1.el8ev.noarch                             
  openstack-java-resteasy-connector-3.2.8-1.el8ev.noarch                        
  ovirt-ansible-cluster-upgrade-1.2.2-1.el8ev.noarch                            
  ovirt-ansible-disaster-recovery-1.3.0-0.1.master.20200219155422.el8ev.noarch  
  ovirt-ansible-engine-setup-1.2.4-1.el8ev.noarch                               
  ovirt-ansible-hosted-engine-setup-1.1.4-1.el8ev.noarch                        
  ovirt-ansible-image-template-1.2.2-1.el8ev.noarch                             
  ovirt-ansible-infra-1.2.1-1.el8ev.noarch                                      
  ovirt-ansible-manageiq-1.2.1-2.el8ev.noarch                                   
  ovirt-ansible-repositories-1.2.3-1.el8ev.noarch                               
  ovirt-ansible-roles-1.2.3-1.el8ev.noarch                                      
  ovirt-ansible-shutdown-env-1.0.4-1.el8ev.noarch                               
  ovirt-ansible-vm-infra-1.2.3-1.el8ev.noarch                                   
  ovirt-cockpit-sso-0.1.4-1.el8ev.noarch                                        
  ovirt-engine-4.4.1.2-0.10.el8ev.noarch                                        
  ovirt-engine-api-explorer-0.0.6-1.el8ev.noarch                                
  ovirt-engine-backend-4.4.1.2-0.10.el8ev.noarch                                
  ovirt-engine-dbscripts-4.4.1.2-0.10.el8ev.noarch                              
  ovirt-engine-dwh-4.4.0.2-1.el8ev.noarch                                       
  ovirt-engine-dwh-setup-4.4.0.2-1.el8ev.noarch                                 
  ovirt-engine-extension-aaa-jdbc-1.2.0-1.el8ev.noarch                          
  ovirt-engine-metrics-1.4.0.2-1.el8ev.noarch                                   
  ovirt-engine-restapi-4.4.1.2-0.10.el8ev.noarch                                
  ovirt-engine-setup-4.4.1.2-0.10.el8ev.noarch                                  
  ovirt-engine-setup-base-4.4.1.2-0.10.el8ev.noarch                             
  ovirt-engine-setup-plugin-cinderlib-4.4.1.2-0.10.el8ev.noarch                 
  ovirt-engine-setup-plugin-imageio-4.4.1.2-0.10.el8ev.noarch                   
  ovirt-engine-setup-plugin-ovirt-engine-4.4.1.2-0.10.el8ev.noarch              
  ovirt-engine-setup-plugin-ovirt-engine-common-4.4.1.2-0.10.el8ev.noarch       
  ovirt-engine-setup-plugin-vmconsole-proxy-helper-4.4.1.2-0.10.el8ev.noarch    
  ovirt-engine-setup-plugin-websocket-proxy-4.4.1.2-0.10.el8ev.noarch           
  ovirt-engine-tools-4.4.1.2-0.10.el8ev.noarch                                  
  ovirt-engine-tools-backup-4.4.1.2-0.10.el8ev.noarch                           
  ovirt-engine-ui-extensions-1.2.0-1.el8ev.noarch                               
  ovirt-engine-vmconsole-proxy-helper-4.4.1.2-0.10.el8ev.noarch                 
  ovirt-engine-webadmin-portal-4.4.1.2-0.10.el8ev.noarch                        
  ovirt-engine-websocket-proxy-4.4.1.2-0.10.el8ev.noarch                        
  ovirt-imageio-common-2.0.6-0.el8ev.x86_64                                     
  ovirt-imageio-daemon-2.0.6-0.el8ev.x86_64                                     
  ovirt-log-collector-4.4.1-3.el8ev.noarch                                      
  ovirt-vmconsole-1.0.8-1.el8ev.noarch                                          
  ovirt-vmconsole-proxy-1.0.8-1.el8ev.noarch                                    
  ovirt-web-ui-1.6.2-1.el8ev.noarch                                             
  pango-1.42.4-6.el8.x86_64                                                     
  pciutils-3.5.6-4.el8.x86_64                                                   
  pki-servlet-4.0-api-1:9.0.7-16.module+el8.1.0+3366+6dfb954c.noarch            
  postgresql-12.1-2.module+el8.1.1+4794+c82b6e09.x86_64                         
  postgresql-contrib-12.1-2.module+el8.1.1+4794+c82b6e09.x86_64                 
  postgresql-jdbc-42.2.3-1.el8.noarch                                           
  postgresql-server-12.1-2.module+el8.1.1+4794+c82b6e09.x86_64                  
  publicsuffix-list-20180723-1.el8.noarch                                       
  python3-aniso8601-0.82-4.el8ost.noarch                                        
  python3-ansible-runner-1.4.5-1.el8ar.noarch                                   
  python3-bcrypt-3.1.6-2.el8ev.x86_64                                           
  python3-click-6.7-8.el8.noarch                                                
  python3-daemon-2.1.2-9.el8ar.noarch                                           
  python3-dnf-plugin-versionlock-4.0.12-3.el8.noarch                            
  python3-docutils-0.14-12.module+el8.1.0+3334+5cb623d7.noarch                  
  python3-flask-1:1.0.2-2.el8ost.noarch                                         
  python3-flask-restful-0.3.6-8.el8ost.noarch                                   
  python3-itsdangerous-0.24-14.el8.noarch                                       
  python3-jmespath-0.9.0-11.el8.noarch                                          
  python3-lockfile-1:0.11.0-8.el8ar.noarch                                      
  python3-lxml-4.2.3-1.el8.x86_64                                               
  python3-m2crypto-0.35.2-5.el8ev.x86_64                                        
  python3-magic-5.33-13.el8.noarch                                              
  python3-mod_wsgi-4.6.4-4.el8.x86_64                                           
  python3-notario-0.0.16-2.el8cp.noarch                                         
  python3-numpy-1:1.14.3-9.el8.x86_64                                           
  python3-ovirt-engine-lib-4.4.1.2-0.10.el8ev.noarch                            
  python3-ovirt-engine-sdk4-4.4.3-1.el8ev.x86_64                                
  python3-ovirt-setup-lib-1.3.0-1.el8ev.noarch                                  
  python3-paramiko-2.4.3-2.el8ev.noarch                                         
  python3-passlib-1.7.0-5.el8ost.noarch                                         
  python3-pexpect-4.6-2.el8ost.noarch                                           
  python3-psutil-5.4.3-10.el8.x86_64                                            
  python3-psycopg2-2.7.5-7.el8.x86_64                                           
  python3-ptyprocess-0.5.2-4.el8.noarch                                         
  python3-pwquality-1.4.0-9.el8.x86_64                                          
  python3-pyOpenSSL-18.0.0-1.el8.noarch                                         
  python3-pycurl-7.43.0.2-4.el8.x86_64                                          
  python3-pynacl-1.3.0-5.el8ev.x86_64                                           
  python3-websocket-client-0.54.0-1.el8ost.noarch                               
  python3-websockify-0.8.0-12.el8ev.noarch                                      
  python3-werkzeug-0.16.0-1.el8ost.noarch                                       
  quota-1:4.04-10.el8.x86_64                                                    
  quota-nls-1:4.04-10.el8.noarch                                                
  redhat-storage-logos-httpd-81.1-1.el8rhgs.noarch                              
  relaxngDatatype-2011.1-7.module+el8.1.0+3366+6dfb954c.noarch                  
  resteasy-3.0.26-3.module+el8.1.0+3366+6dfb954c.noarch                         
  rhv-log-collector-analyzer-1.0.0-1.el8ev.noarch                               
  rhvm-4.4.1.2-0.10.el8ev.noarch                                                
  rhvm-branding-rhv-4.4.3-1.el8ev.noarch                                        
  rhvm-dependencies-4.4.0-1.el8ev.noarch                                        
  rhvm-setup-plugins-4.4.2-1.el8ev.noarch                                       
  rpcbind-1.2.5-7.el8.x86_64                                                    
  rsyslog-8.1911.0-3.el8.x86_64                                                 
  rsyslog-elasticsearch-8.1911.0-3.el8.x86_64                                   
  rsyslog-mmjsonparse-8.1911.0-3.el8.x86_64                                     
  rsyslog-mmnormalize-8.1911.0-3.el8.x86_64                                     
  scl-utils-1:2.0.2-12.el8.x86_64                                               
  sgml-common-0.6.3-50.el8.noarch                                               
  snmp4j-2.4.1-1.el8ev.noarch                                                   
  sos-3.8-6.el8_2.noarch                                                        
  source-highlight-3.1.8-16.el8.x86_64                                          
  spice-client-win-x64-8.0-1.el8.noarch                                         
  spice-client-win-x86-8.0-1.el8.noarch                                         
  sshpass-1.06-3.el8ae.x86_64                                                   
  stax-ex-1.7.7-8.module+el8.1.0+3366+6dfb954c.noarch                           
  tcl-1:8.6.8-2.el8.x86_64                                                      
  ttmkfdir-3.0.9-54.el8.x86_64                                                  
  urw-base35-fonts-20170801-10.el8.noarch                                       
  urw-base35-standard-symbols-ps-fonts-20170801-10.el8.noarch                   
  uuid-1.6.2-42.el8.x86_64                                                      
  vdsm-jsonrpc-java-1.5.4-1.el8ev.noarch                                        
  vim-filesystem-2:8.0.1763-13.el8.noarch                                       
  ws-commons-util-1.0.2-1.el8ev.noarch                                          
  xmlrpc-client-3.1.3-1.el8ev.noarch                                            
  xmlrpc-common-3.1.3-1.el8ev.noarch                                            
  xmlstreambuffer-1.5.4-8.module+el8.1.0+3366+6dfb954c.noarch                   
  xorg-x11-fonts-ISO8859-1-100dpi-7.5-19.el8.noarch                             
  xorg-x11-fonts-Type1-7.5-19.el8.noarch                                        
  xsom-0-19.20110809svn.module+el8.1.0+3366+6dfb954c.noarch                     
  yajl-2.1.0-10.el8.x86_64                                                      

Complete!
OVAL test results details

package gssproxy is removed  oval:ssg-test_package_gssproxy_removed:tst:1  false

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
gssproxyx86_64(none)15.el80.8.00:0.8.0-15.el8199e2f91fd431d51gssproxy-0:0.8.0-15.el8.x86_64
Uninstall abrt-addon-ccpp Packagexccdf_org.ssgproject.content_rule_package_abrt-addon-ccpp_removed lowCCE-82919-2

Uninstall abrt-addon-ccpp Package

Rule IDxccdf_org.ssgproject.content_rule_package_abrt-addon-ccpp_removed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_abrt-addon-ccpp_removed:def:1
Time2020-09-29T11:18:01
Severitylow
Identifiers and References

Identifiers:  CCE-82919-2

References:  SRG-OS-000095-GPOS-00049

Description

The abrt-addon-ccpp package can be removed with the following command:

$ sudo yum erase abrt-addon-ccpp

Rationale

abrt-addon-ccpp contains hooks for C/C++ crashed programs and abrt's C/C++ analyzer plugin.

OVAL test results details

package abrt-addon-ccpp is removed  oval:ssg-test_package_abrt-addon-ccpp_removed:tst:1  true

No items have been found conforming to the following objects:
Object oval:ssg-obj_test_package_abrt-addon-ccpp_removed:obj:1 of type rpminfo_object
Name
abrt-addon-ccpp
Uninstall tuned Packagexccdf_org.ssgproject.content_rule_package_tuned_removed lowCCE-82904-4

Uninstall tuned Package

Rule IDxccdf_org.ssgproject.content_rule_package_tuned_removed
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-package_tuned_removed:def:1
Time2020-09-29T11:19:41
Severitylow
Identifiers and References

Identifiers:  CCE-82904-4

References:  SRG-OS-000095-GPOS-00049

Description

The tuned package can be removed with the following command:

$ sudo yum erase tuned

Rationale

tuned contains a daemon that tunes the system settings dynamically. It does so by monitoring the usage of several system components periodically. Based on that information, components will then be put into lower or higher power savings modes to adapt to the current usage.

Evaluation messages
info 
Fix execution completed and returned: 0
info 
Dependencies resolved.
================================================================================
 Package               Arch    Version                  Repository         Size
================================================================================
Removing:
 tuned                 noarch  2.13.0-6.el8             @anaconda         729 k
Removing unused dependencies:
 hdparm                x86_64  9.54-2.el8               @anaconda         184 k
 python3-linux-procfs  noarch  0.6-7.el8                @anaconda          91 k
 python3-perf          x86_64  4.18.0-193.7.1.el8_2     @koji-override-1  332 k
 python3-pyudev        noarch  0.21.0-7.el8             @anaconda         315 k
 python3-schedutils    x86_64  0.6-6.el8                @anaconda          44 k

Transaction Summary
================================================================================
Remove  6 Packages

Freed space: 1.7 M
Running transaction check
Transaction check succeeded.
Running transaction test
Transaction test succeeded.
Running transaction
  Preparing        :                                                        1/1 
  Running scriptlet: tuned-2.13.0-6.el8.noarch                              1/1 
  Running scriptlet: tuned-2.13.0-6.el8.noarch                              1/6 
  Erasing          : tuned-2.13.0-6.el8.noarch                              1/6 
warning: /etc/tuned/profile_mode saved as /etc/tuned/profile_mode.rpmsave
warning: /etc/tuned/active_profile saved as /etc/tuned/active_profile.rpmsave

  Running scriptlet: tuned-2.13.0-6.el8.noarch                              1/6 
  Erasing          : python3-linux-procfs-0.6-7.el8.noarch                  2/6 
  Erasing          : python3-pyudev-0.21.0-7.el8.noarch                     3/6 
  Erasing          : hdparm-9.54-2.el8.x86_64                               4/6 
  Erasing          : python3-perf-4.18.0-193.7.1.el8_2.x86_64               5/6 
  Erasing          : python3-schedutils-0.6-6.el8.x86_64                    6/6 
  Running scriptlet: python3-schedutils-0.6-6.el8.x86_64                    6/6 
  Verifying        : hdparm-9.54-2.el8.x86_64                               1/6 
  Verifying        : python3-linux-procfs-0.6-7.el8.noarch                  2/6 
  Verifying        : python3-perf-4.18.0-193.7.1.el8_2.x86_64               3/6 
  Verifying        : python3-pyudev-0.21.0-7.el8.noarch                     4/6 
  Verifying        : python3-schedutils-0.6-6.el8.x86_64                    5/6 
  Verifying        : tuned-2.13.0-6.el8.noarch                              6/6 

Removed:
  hdparm-9.54-2.el8.x86_64                                                      
  python3-linux-procfs-0.6-7.el8.noarch                                         
  python3-perf-4.18.0-193.7.1.el8_2.x86_64                                      
  python3-pyudev-0.21.0-7.el8.noarch                                            
  python3-schedutils-0.6-6.el8.x86_64                                           
  tuned-2.13.0-6.el8.noarch                                                     

Complete!
OVAL test results details

package tuned is removed  oval:ssg-test_package_tuned_removed:tst:1  false

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
tunednoarch(none)6.el82.13.00:2.13.0-6.el8199e2f91fd431d51tuned-0:2.13.0-6.el8.noarch
Uninstall abrt-plugin-sosreport Packagexccdf_org.ssgproject.content_rule_package_abrt-plugin-sosreport_removed lowCCE-82910-1

Uninstall abrt-plugin-sosreport Package

Rule IDxccdf_org.ssgproject.content_rule_package_abrt-plugin-sosreport_removed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_abrt-plugin-sosreport_removed:def:1
Time2020-09-29T11:18:01
Severitylow
Identifiers and References

Identifiers:  CCE-82910-1

References:  SRG-OS-000095-GPOS-00049

Description

The abrt-plugin-sosreport package can be removed with the following command:

$ sudo yum erase abrt-plugin-sosreport

Rationale

abrt-plugin-sosreport provides a plugin to include an sosreport in an ABRT report.

OVAL test results details

package abrt-plugin-sosreport is removed  oval:ssg-test_package_abrt-plugin-sosreport_removed:tst:1  true

No items have been found conforming to the following objects:
Object oval:ssg-obj_test_package_abrt-plugin-sosreport_removed:obj:1 of type rpminfo_object
Name
abrt-plugin-sosreport
Uninstall pigz Packagexccdf_org.ssgproject.content_rule_package_pigz_removed lowCCE-82397-1

Uninstall pigz Package

Rule IDxccdf_org.ssgproject.content_rule_package_pigz_removed
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-package_pigz_removed:def:1
Time2020-09-29T11:19:43
Severitylow
Identifiers and References

Identifiers:  CCE-82397-1

Description

The pigz package can be removed with the following command:

$ sudo yum erase pigz

Rationale

Binaries shipped in pigz package in Red Hat Enterprise Linux 8 have not been compiled using recommended compiler flags. The binaries are compiled without sufficient stack protection and its address space layout randomization (ASLR) is weak.

Evaluation messages
info 
Fix execution completed and returned: 0
info 
Dependencies resolved.
================================================================================
 Package        Architecture     Version              Repository           Size
================================================================================
Removing:
 pigz           x86_64           2.4-4.el8            @anaconda           137 k

Transaction Summary
================================================================================
Remove  1 Package

Freed space: 137 k
Running transaction check
Transaction check succeeded.
Running transaction test
Transaction test succeeded.
Running transaction
  Preparing        :                                                        1/1 
  Erasing          : pigz-2.4-4.el8.x86_64                                  1/1 
  Running scriptlet: pigz-2.4-4.el8.x86_64                                  1/1 
  Verifying        : pigz-2.4-4.el8.x86_64                                  1/1 

Removed:
  pigz-2.4-4.el8.x86_64                                                         

Complete!
OVAL test results details

package pigz is removed  oval:ssg-test_package_pigz_removed:tst:1  false

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
pigzx86_64(none)4.el82.40:2.4-4.el8199e2f91fd431d51pigz-0:2.4-4.el8.x86_64
Uninstall krb5-workstation Packagexccdf_org.ssgproject.content_rule_package_krb5-workstation_removed mediumCCE-82931-7

Uninstall krb5-workstation Package

Rule IDxccdf_org.ssgproject.content_rule_package_krb5-workstation_removed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_krb5-workstation_removed:def:1
Time2020-09-29T11:18:01
Severitymedium
Identifiers and References

Identifiers:  CCE-82931-7

References:  SRG-OS-000095-GPOS-00049, SRG-OS-000120-GPOS-00061

Description

The krb5-workstation package can be removed with the following command:

$ sudo yum erase krb5-workstation

Rationale

Kerberos is a network authentication system. The krb5-workstation package contains the basic Kerberos programs (kinit, klist, kdestroy, kpasswd). Currently, Kerberos does not utilize FIPS 140-2 cryptography and is not permitted on Government networks, nor is it permitted in many regulatory environments such as HIPAA.

OVAL test results details

package krb5-workstation is removed  oval:ssg-test_package_krb5-workstation_removed:tst:1  true

No items have been found conforming to the following objects:
Object oval:ssg-obj_test_package_krb5-workstation_removed:obj:1 of type rpminfo_object
Name
krb5-workstation
Uninstall abrt-plugin-rhtsupport Packagexccdf_org.ssgproject.content_rule_package_abrt-plugin-rhtsupport_removed lowCCE-82916-8

Uninstall abrt-plugin-rhtsupport Package

Rule IDxccdf_org.ssgproject.content_rule_package_abrt-plugin-rhtsupport_removed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_abrt-plugin-rhtsupport_removed:def:1
Time2020-09-29T11:18:01
Severitylow
Identifiers and References

Identifiers:  CCE-82916-8

References:  SRG-OS-000095-GPOS-00049

Description

The abrt-plugin-rhtsupport package can be removed with the following command:

$ sudo yum erase abrt-plugin-rhtsupport

Rationale

abrt-plugin-rhtsupport is a ABRT plugin to report bugs into the Red Hat Support system.

OVAL test results details

package abrt-plugin-rhtsupport is removed  oval:ssg-test_package_abrt-plugin-rhtsupport_removed:tst:1  true

No items have been found conforming to the following objects:
Object oval:ssg-obj_test_package_abrt-plugin-rhtsupport_removed:obj:1 of type rpminfo_object
Name
abrt-plugin-rhtsupport
Uninstall iprutils Packagexccdf_org.ssgproject.content_rule_package_iprutils_removed lowCCE-82946-5

Uninstall iprutils Package

Rule IDxccdf_org.ssgproject.content_rule_package_iprutils_removed
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-package_iprutils_removed:def:1
Time2020-09-29T11:19:46
Severitylow
Identifiers and References

Identifiers:  CCE-82946-5

References:  SRG-OS-000095-GPOS-00049

Description

The iprutils package can be removed with the following command:

$ sudo yum erase iprutils

Rationale

iprutils provides a suite of utlilities to manage and configure SCSI devices supported by the ipr SCSI storage device driver.

Evaluation messages
info 
Fix execution completed and returned: 0
info 
Dependencies resolved.
================================================================================
 Package          Architecture   Version                Repository         Size
================================================================================
Removing:
 iprutils         x86_64         2.4.18.1-1.el8         @anaconda         995 k

Transaction Summary
================================================================================
Remove  1 Package

Freed space: 995 k
Running transaction check
Transaction check succeeded.
Running transaction test
Transaction test succeeded.
Running transaction
  Preparing        :                                                        1/1 
  Running scriptlet: iprutils-2.4.18.1-1.el8.x86_64                         1/1 
  Erasing          : iprutils-2.4.18.1-1.el8.x86_64                         1/1 
  Running scriptlet: iprutils-2.4.18.1-1.el8.x86_64                         1/1 
  Verifying        : iprutils-2.4.18.1-1.el8.x86_64                         1/1 

Removed:
  iprutils-2.4.18.1-1.el8.x86_64                                                

Complete!
OVAL test results details

package iprutils is removed  oval:ssg-test_package_iprutils_removed:tst:1  false

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
iprutilsx86_64(none)1.el82.4.18.10:2.4.18.1-1.el8199e2f91fd431d51iprutils-0:2.4.18.1-1.el8.x86_64
Enable Dracut FIPS Modulexccdf_org.ssgproject.content_rule_enable_dracut_fips_module mediumCCE-82155-3

Enable Dracut FIPS Module

Rule IDxccdf_org.ssgproject.content_rule_enable_dracut_fips_module
Result
fail
Multi-check ruleno
OVAL Definition IDoval:ssg-enable_dracut_fips_module:def:1
Time2020-09-29T11:19:46
Severitymedium
Identifiers and References

Identifiers:  CCE-82155-3

References:  CCI-000068, CCI-000803, CCI-002450, SC-12(2), SC-12(3), IA-7, SC-13, CM-6(a), SC-12, SRG-OS-000478-GPOS-00223, SRG-OS-000120-VMM-000600, SRG-OS-000478-VMM-001980, SRG-OS-000396-VMM-001590

Description

To enable FIPS mode, run the following command:

fips-mode-setup --enable
To enable FIPS, the system requires that the fips module is added in dracut configuration. Check if /etc/dracut.conf.d/40-fips.conf contain add_dracutmodules+=" fips "

Rationale

Use of weak or untested encryption algorithms undermines the purposes of utilizing encryption to protect data. The operating system must implement cryptographic modules adhering to the higher standards approved by the federal government since this provides assurance they have been tested and validated.

Warnings
warning  The system needs to be rebooted for these changes to take effect.
warning  System Crypto Modules must be provided by a vendor that undergoes FIPS-140 certifications. FIPS-140 is applicable to all Federal agencies that use cryptographic-based security systems to protect sensitive information in computer and telecommunication systems (including voice systems) as defined in Section 5131 of the Information Technology Management Reform Act of 1996, Public Law 104-106. This standard shall be used in designing and implementing cryptographic modules that Federal departments and agencies operate or are operated for them under contract. See https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf To meet this, the system has to have cryptographic software provided by a vendor that has undergone this certification. This means providing documentation, test results, design information, and independent third party review by an accredited lab. While open source software is capable of meeting this, it does not meet FIPS-140 unless the vendor submits to this process.
Evaluation messages
info 
No suitable fix found.
OVAL test results details

add_dracutmodules contains fips  oval:ssg-test_enable_dracut_fips_module:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_enable_dracut_fips_module:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/dracut.conf.d/40-fips.conf^\s*add_dracutmodules\+="\s*(\w*)\s*"\s*(?:#.*)?$1
Enable FIPS Modexccdf_org.ssgproject.content_rule_enable_fips_mode highCCE-80942-6

Enable FIPS Mode

Rule IDxccdf_org.ssgproject.content_rule_enable_fips_mode
Result
error
Multi-check ruleno
OVAL Definition IDoval:ssg-enable_fips_mode:def:1
Time2020-09-29T11:21:04
Severityhigh
Identifiers and References

Identifiers:  CCE-80942-6

References:  CCI-000068, CCI-000803, CCI-002450, SC-12(2), SC-12(3), IA-7, SC-13, CM-6(a), SC-12, SRG-OS-000478-GPOS-00223, SRG-OS-000396-GPOS-00176, SRG-OS-000120-VMM-000600, SRG-OS-000478-VMM-001980, SRG-OS-000396-VMM-001590

Description

To enable FIPS mode, run the following command:

fips-mode-setup --enable

The fips-mode-setup command will configure the system in FIPS mode by automatically configuring the following:
  • Setting the kernel FIPS mode flag (/proc/sys/crypto/fips_enabled) to 1
  • Creating /etc/system-fips
  • Setting the system crypto policy in /etc/crypto-policies/config to FIPS
  • Loading the Dracut fips module
Furthermore, the system running in FIPS mode should be FIPS certified by NIST.

Rationale

Use of weak or untested encryption algorithms undermines the purposes of utilizing encryption to protect data. The operating system must implement cryptographic modules adhering to the higher standards approved by the federal government since this provides assurance they have been tested and validated.

Warnings
warning  The system needs to be rebooted for these changes to take effect.
warning  System Crypto Modules must be provided by a vendor that undergoes FIPS-140 certifications. FIPS-140 is applicable to all Federal agencies that use cryptographic-based security systems to protect sensitive information in computer and telecommunication systems (including voice systems) as defined in Section 5131 of the Information Technology Management Reform Act of 1996, Public Law 104-106. This standard shall be used in designing and implementing cryptographic modules that Federal departments and agencies operate or are operated for them under contract. See https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf To meet this, the system has to have cryptographic software provided by a vendor that has undergone this certification. This means providing documentation, test results, design information, and independent third party review by an accredited lab. While open source software is capable of meeting this, it does not meet FIPS-140 unless the vendor submits to this process.
Evaluation messages
info 
Fix execution completed and returned: 0
info 
Kernel initramdisks are being regenerated. This might take some time.
Setting system policy to FIPS
Note: System-wide crypto policies are applied on application start-up.
It is recommended to restart the system for the change of policies
to fully take place.
FIPS mode will be enabled.
Please reboot the system for the setting to take effect.
info 
Failed to verify applied fix: Checking engine returns: fail



fips-mode-setup --enable


Complexity:medium
Disruption:medium
Reboot:true
Strategy:restrict
- name: enable fips mode
  command: /usr/bin/fips-mode-setup --enable
  when: ansible_virtualization_role != "guest" or ansible_virtualization_type != "docker"
  tags:
    - enable_fips_mode
    - high_severity
    - restrict_strategy
    - medium_complexity
    - medium_disruption
    - reboot_required
    - CCE-80942-6
    - NIST-800-53-SC-12(2)
    - NIST-800-53-SC-12(3)
    - NIST-800-53-IA-7
    - NIST-800-53-SC-13
    - NIST-800-53-CM-6(a)
    - NIST-800-53-SC-12
OVAL test results details

/etc/system-fips exists  oval:ssg-test_etc_system_fips:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_etc_system_fips:obj:1 of type file_object
Filepath
/etc/system-fips

kernel runtime parameter crypto.fips_enabled set to 1  oval:ssg-test_sysctl_crypto_fips_enabled:tst:1  false

Following items have been found on the system:
NameValue
crypto.fips_enabled0

add_dracutmodules contains fips  oval:ssg-test_enable_dracut_fips_module:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_enable_dracut_fips_module:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/dracut.conf.d/40-fips.conf^\s*add_dracutmodules\+="\s*(\w*)\s*"\s*(?:#.*)?$1

check for crypto policy correctly configured in /etc/crypto-policies/config  oval:ssg-test_configure_crypto_policy:tst:1  false

Following items have been found on the system:
PathContent
/etc/crypto-policies/configDEFAULT

check for crypto policy correctly configured in /etc/crypto-policies/state/current  oval:ssg-test_configure_crypto_policy_current:tst:1  false

Following items have been found on the system:
PathContent
/etc/crypto-policies/state/currentDEFAULT

Check if update-crypto-policies has been run  oval:ssg-test_crypto_policies_updated:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-variable_crypto_policies_config_file_age:var:126342411

Check if /etc/crypto-policies/back-ends/nss.config exists  oval:ssg-test_crypto_policy_nss_config:tst:1  true

Following items have been found on the system:
PathTypeUIDGIDSize (B)Permissions
/etc/crypto-policies/back-ends/nss.configsymbolic link0042rwxrwxrwx 

Test installed OS is part of the unix family  oval:ssg-test_unix_family:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-object_unix_family:obj:1 of type family_object

Test installed OS is part of the unix family  oval:ssg-test_unix_family:tst:1  true

Following items have been found on the system:
Family
unix

Test installed OS is part of the unix family  oval:ssg-test_unix_family:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-object_unix_family:obj:1 of type family_object

Test installed OS is part of the unix family  oval:ssg-test_unix_family:tst:1  true

Following items have been found on the system:
Family
unix

redhat-release-client is version 6  oval:ssg-test_rhel_client:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel_client:obj:1 of type rpminfo_object
Name
redhat-release-client

redhat-release-client is version 6  oval:ssg-test_rhel_client:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel_client:obj:1 of type rpminfo_object
Name
redhat-release-client

redhat-release-workstation is version 6  oval:ssg-test_rhel_workstation:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel_workstation:obj:1 of type rpminfo_object
Name
redhat-release-workstation

redhat-release-workstation is version 6  oval:ssg-test_rhel_workstation:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel_workstation:obj:1 of type rpminfo_object
Name
redhat-release-workstation

redhat-release-server is version 6  oval:ssg-test_rhel_server:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel_server:obj:1 of type rpminfo_object
Name
redhat-release-server

redhat-release-server is version 6  oval:ssg-test_rhel_server:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel_server:obj:1 of type rpminfo_object
Name
redhat-release-server

redhat-release-computenode is version 6  oval:ssg-test_rhel_computenode:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel_computenode:obj:1 of type rpminfo_object
Name
redhat-release-computenode

redhat-release-computenode is version 6  oval:ssg-test_rhel_computenode:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel_computenode:obj:1 of type rpminfo_object
Name
redhat-release-computenode

Test installed OS is part of the unix family  oval:ssg-test_unix_family:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-object_unix_family:obj:1 of type family_object

Test installed OS is part of the unix family  oval:ssg-test_unix_family:tst:1  true

Following items have been found on the system:
Family
unix

Test installed OS is part of the unix family  oval:ssg-test_unix_family:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-object_unix_family:obj:1 of type family_object

Test installed OS is part of the unix family  oval:ssg-test_unix_family:tst:1  true

Following items have been found on the system:
Family
unix

redhat-release-client is version 6  oval:ssg-test_rhel_client:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel_client:obj:1 of type rpminfo_object
Name
redhat-release-client

redhat-release-client is version 6  oval:ssg-test_rhel_client:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel_client:obj:1 of type rpminfo_object
Name
redhat-release-client

redhat-release-workstation is version 6  oval:ssg-test_rhel_workstation:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel_workstation:obj:1 of type rpminfo_object
Name
redhat-release-workstation

redhat-release-workstation is version 6  oval:ssg-test_rhel_workstation:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel_workstation:obj:1 of type rpminfo_object
Name
redhat-release-workstation

redhat-release-server is version 6  oval:ssg-test_rhel_server:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel_server:obj:1 of type rpminfo_object
Name
redhat-release-server

redhat-release-server is version 6  oval:ssg-test_rhel_server:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel_server:obj:1 of type rpminfo_object
Name
redhat-release-server

redhat-release-computenode is version 6  oval:ssg-test_rhel_computenode:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel_computenode:obj:1 of type rpminfo_object
Name
redhat-release-computenode

redhat-release-computenode is version 6  oval:ssg-test_rhel_computenode:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel_computenode:obj:1 of type rpminfo_object
Name
redhat-release-computenode

installed OS part of unix family  oval:ssg-test_rhel7_unix_family:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel7_unix_family:obj:1 of type family_object

installed OS part of unix family  oval:ssg-test_rhel7_unix_family:tst:1  true

Following items have been found on the system:
Family
unix

redhat-release-client is version 7  oval:ssg-test_rhel7_client:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel7_client:obj:1 of type rpminfo_object
Name
redhat-release-client

redhat-release-client is version 7  oval:ssg-test_rhel7_client:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel7_client:obj:1 of type rpminfo_object
Name
redhat-release-client

redhat-release-workstation is version 7  oval:ssg-test_rhel7_workstation:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel7_workstation:obj:1 of type rpminfo_object
Name
redhat-release-workstation

redhat-release-workstation is version 7  oval:ssg-test_rhel7_workstation:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel7_workstation:obj:1 of type rpminfo_object
Name
redhat-release-workstation

redhat-release-server is version 7  oval:ssg-test_rhel7_server:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel7_server:obj:1 of type rpminfo_object
Name
redhat-release-server

redhat-release-server is version 7  oval:ssg-test_rhel7_server:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel7_server:obj:1 of type rpminfo_object
Name
redhat-release-server

redhat-release-computenode is version 7  oval:ssg-test_rhel7_computenode:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel7_computenode:obj:1 of type rpminfo_object
Name
redhat-release-computenode

redhat-release-computenode is version 7  oval:ssg-test_rhel7_computenode:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel7_computenode:obj:1 of type rpminfo_object
Name
redhat-release-computenode

redhat-release-virtualization-host RPM package is installed  oval:ssg-test_rhvh4_version:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhvh4_version:obj:1 of type rpminfo_object
Name
redhat-release-virtualization-host

redhat-release-virtualization-host RPM package is installed  oval:ssg-test_rhvh4_version:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhvh4_version:obj:1 of type rpminfo_object
Name
redhat-release-virtualization-host

RHEVH base RHEL is version 7  oval:ssg-test_rhevh_rhel7_version:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhevh_rhel7_version:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/redhat-release^Red Hat Enterprise Linux release (\d)\.\d+$1

RHEVH base RHEL is version 7  oval:ssg-test_rhevh_rhel7_version:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhevh_rhel7_version:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/redhat-release^Red Hat Enterprise Linux release (\d)\.\d+$1

installed OS part of unix family  oval:ssg-test_rhel7_unix_family:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel7_unix_family:obj:1 of type family_object

installed OS part of unix family  oval:ssg-test_rhel7_unix_family:tst:1  true

Following items have been found on the system:
Family
unix

redhat-release-client is version 7  oval:ssg-test_rhel7_client:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel7_client:obj:1 of type rpminfo_object
Name
redhat-release-client

redhat-release-client is version 7  oval:ssg-test_rhel7_client:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel7_client:obj:1 of type rpminfo_object
Name
redhat-release-client

redhat-release-workstation is version 7  oval:ssg-test_rhel7_workstation:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel7_workstation:obj:1 of type rpminfo_object
Name
redhat-release-workstation

redhat-release-workstation is version 7  oval:ssg-test_rhel7_workstation:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel7_workstation:obj:1 of type rpminfo_object
Name
redhat-release-workstation

redhat-release-server is version 7  oval:ssg-test_rhel7_server:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel7_server:obj:1 of type rpminfo_object
Name
redhat-release-server

redhat-release-server is version 7  oval:ssg-test_rhel7_server:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel7_server:obj:1 of type rpminfo_object
Name
redhat-release-server

redhat-release-computenode is version 7  oval:ssg-test_rhel7_computenode:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel7_computenode:obj:1 of type rpminfo_object
Name
redhat-release-computenode

redhat-release-computenode is version 7  oval:ssg-test_rhel7_computenode:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel7_computenode:obj:1 of type rpminfo_object
Name
redhat-release-computenode

redhat-release-virtualization-host RPM package is installed  oval:ssg-test_rhvh4_version:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhvh4_version:obj:1 of type rpminfo_object
Name
redhat-release-virtualization-host

redhat-release-virtualization-host RPM package is installed  oval:ssg-test_rhvh4_version:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhvh4_version:obj:1 of type rpminfo_object
Name
redhat-release-virtualization-host

RHEVH base RHEL is version 7  oval:ssg-test_rhevh_rhel7_version:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhevh_rhel7_version:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/redhat-release^Red Hat Enterprise Linux release (\d)\.\d+$1

RHEVH base RHEL is version 7  oval:ssg-test_rhevh_rhel7_version:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhevh_rhel7_version:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/redhat-release^Red Hat Enterprise Linux release (\d)\.\d+$1

installed OS part of unix family  oval:ssg-test_rhel8_unix_family:tst:1  true

Following items have been found on the system:
Family
unix

installed OS part of unix family  oval:ssg-test_rhel8_unix_family:tst:1  true

Following items have been found on the system:
Family
unix

redhat-release is version 8  oval:ssg-test_rhel8:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
redhat-releasex86_64(none)25.0.el8rhgs8.20:8.2-25.0.el8rhgs0redhat-release-0:8.2-25.0.el8rhgs.x86_64

redhat-release is version 8  oval:ssg-test_rhel8:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
redhat-releasex86_64(none)25.0.el8rhgs8.20:8.2-25.0.el8rhgs0redhat-release-0:8.2-25.0.el8rhgs.x86_64

redhat-release-coreos is version 8  oval:ssg-test_rhel8_coreos:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel8_coreos:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/os-release^PRETTY_NAME="Red Hat Enterprise Linux CoreOS \d+\.(\d)\d+\.\d+\.\d+ \([\w\s]+\)"$1

redhat-release-coreos is version 8  oval:ssg-test_rhel8_coreos:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel8_coreos:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/os-release^PRETTY_NAME="Red Hat Enterprise Linux CoreOS \d+\.(\d)\d+\.\d+\.\d+ \([\w\s]+\)"$1

redhat-release-virtualization-host RPM package is installed  oval:ssg-test_rhvh4_version:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhvh4_version:obj:1 of type rpminfo_object
Name
redhat-release-virtualization-host

redhat-release-virtualization-host RPM package is installed  oval:ssg-test_rhvh4_version:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhvh4_version:obj:1 of type rpminfo_object
Name
redhat-release-virtualization-host

RHEVH base RHEL is version 8  oval:ssg-test_rhevh_rhel8_version:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhevh_rhel8_version:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/redhat-release^Red Hat Enterprise Linux release (\d)\.\d+$1

RHEVH base RHEL is version 8  oval:ssg-test_rhevh_rhel8_version:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhevh_rhel8_version:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/redhat-release^Red Hat Enterprise Linux release (\d)\.\d+$1

installed OS part of unix family  oval:ssg-test_rhel8_unix_family:tst:1  true

Following items have been found on the system:
Family
unix

installed OS part of unix family  oval:ssg-test_rhel8_unix_family:tst:1  true

Following items have been found on the system:
Family
unix

redhat-release is version 8  oval:ssg-test_rhel8:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
redhat-releasex86_64(none)25.0.el8rhgs8.20:8.2-25.0.el8rhgs0redhat-release-0:8.2-25.0.el8rhgs.x86_64

redhat-release is version 8  oval:ssg-test_rhel8:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
redhat-releasex86_64(none)25.0.el8rhgs8.20:8.2-25.0.el8rhgs0redhat-release-0:8.2-25.0.el8rhgs.x86_64

redhat-release-coreos is version 8  oval:ssg-test_rhel8_coreos:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel8_coreos:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/os-release^PRETTY_NAME="Red Hat Enterprise Linux CoreOS \d+\.(\d)\d+\.\d+\.\d+ \([\w\s]+\)"$1

redhat-release-coreos is version 8  oval:ssg-test_rhel8_coreos:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhel8_coreos:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/os-release^PRETTY_NAME="Red Hat Enterprise Linux CoreOS \d+\.(\d)\d+\.\d+\.\d+ \([\w\s]+\)"$1

redhat-release-virtualization-host RPM package is installed  oval:ssg-test_rhvh4_version:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhvh4_version:obj:1 of type rpminfo_object
Name
redhat-release-virtualization-host

redhat-release-virtualization-host RPM package is installed  oval:ssg-test_rhvh4_version:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhvh4_version:obj:1 of type rpminfo_object
Name
redhat-release-virtualization-host

RHEVH base RHEL is version 8  oval:ssg-test_rhevh_rhel8_version:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhevh_rhel8_version:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/redhat-release^Red Hat Enterprise Linux release (\d)\.\d+$1

RHEVH base RHEL is version 8  oval:ssg-test_rhevh_rhel8_version:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rhevh_rhel8_version:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/redhat-release^Red Hat Enterprise Linux release (\d)\.\d+$1

Test installed OS is part of the unix family  oval:ssg-test_unix_family:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-object_unix_family:obj:1 of type family_object

Test installed OS is part of the unix family  oval:ssg-test_unix_family:tst:1  true

Following items have been found on the system:
Family
unix

Test installed OS is part of the unix family  oval:ssg-test_unix_family:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-object_unix_family:obj:1 of type family_object

Test installed OS is part of the unix family  oval:ssg-test_unix_family:tst:1  true

Following items have been found on the system:
Family
unix

oraclelinux-release is version 7  oval:ssg-test_ol7_system:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-obj_ol7_system:obj:1 of type rpminfo_object
Name
oraclelinux-release

oraclelinux-release is version 7  oval:ssg-test_ol7_system:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_ol7_system:obj:1 of type rpminfo_object
Name
oraclelinux-release

Test installed OS is part of the unix family  oval:ssg-test_unix_family:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-object_unix_family:obj:1 of type family_object

Test installed OS is part of the unix family  oval:ssg-test_unix_family:tst:1  true

Following items have been found on the system:
Family
unix

Test installed OS is part of the unix family  oval:ssg-test_unix_family:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-object_unix_family:obj:1 of type family_object

Test installed OS is part of the unix family  oval:ssg-test_unix_family:tst:1  true

Following items have been found on the system:
Family
unix

oraclelinux-release is version 7  oval:ssg-test_ol7_system:tst:1  not evaluated

No items have been found conforming to the following objects:
Object oval:ssg-obj_ol7_system:obj:1 of type rpminfo_object
Name
oraclelinux-release

oraclelinux-release is version 7  oval:ssg-test_ol7_system:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_ol7_system:obj:1 of type rpminfo_object
Name
oraclelinux-release

tests if var_system_crypto_policy is set to FIPS  oval:ssg-test_system_crypto_policy_value:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-var_system_crypto_policy:var:1FIPS:OSPP
Configure BIND to use System Crypto Policyxccdf_org.ssgproject.content_rule_configure_bind_crypto_policy mediumCCE-80934-3

Configure BIND to use System Crypto Policy

Rule IDxccdf_org.ssgproject.content_rule_configure_bind_crypto_policy
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-configure_bind_crypto_policy:def:1
Time2020-09-29T11:18:01
Severitymedium
Identifiers and References

Identifiers:  CCE-80934-3

References:  SC-13, SC-12(2), SC-12(3), SRG-OS-000423-GPOS-00187, SRG-OS-000426-GPOS-00190

Description

Crypto Policies provide a centralized control over crypto algorithms usage of many packages. BIND is supported by crypto policy, but the BIND configuration may be set up to ignore it. To check that Crypto Policies settings are configured correctly, ensure that the /etc/named.conf includes the appropriate configuration: In the options section of /etc/named.conf, make sure that the following line is not commented out or superseded by later includes: include "/etc/crypto-policies/back-ends/bind.config";

Rationale

Overriding the system crypto policy makes the behavior of the BIND service violate expectations, and makes system configuration more fragmented.

OVAL test results details

package bind is removed  oval:ssg-test_package_bind_removed:tst:1  true

No items have been found conforming to the following objects:
Object oval:ssg-obj_test_package_bind_removed:obj:1 of type rpminfo_object
Name
bind

Check that the configuration includes the policy config file.  oval:ssg-test_configure_bind_crypto_policy:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_configure_bind_crypto_policy:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/named.conf^\s*include\s+"/etc/crypto-policies/back-ends/bind.config"\s*;\s*$1
Configure OpenSSL library to use System Crypto Policyxccdf_org.ssgproject.content_rule_configure_openssl_crypto_policy mediumCCE-80938-4

Configure OpenSSL library to use System Crypto Policy

Rule IDxccdf_org.ssgproject.content_rule_configure_openssl_crypto_policy
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-configure_openssl_crypto_policy:def:1
Time2020-09-29T11:21:04
Severitymedium
Identifiers and References

Identifiers:  CCE-80938-4

References:  AC-17(a), AC-17(2), CM-6(a), MA-4(6), SC-13, SC-12(2), SC-12(3), SRG-OS-000250-GPOS-00093

Description

Crypto Policies provide a centralized control over crypto algorithms usage of many packages. OpenSSL is supported by crypto policy, but the OpenSSL configuration may be set up to ignore it. To check that Crypto Policies settings are configured correctly, you have to examine the OpenSSL config file available under /etc/pki/tls/openssl.cnf. This file has the ini format, and it enables crypto policy support if there is a [ crypto_policy ] section that contains the .include /etc/crypto-policies/back-ends/openssl.config directive.

Rationale

Overriding the system crypto policy makes the behavior of the Java runtime violates expectations, and makes system configuration more fragmented.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

Check that the configuration mandates usage of system-wide crypto policies.  oval:ssg-test_configure_openssl_crypto_policy:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_configure_openssl_crypto_policy:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/pki/tls/openssl.cnf^\s*\[\s*crypto_policy\s*\]\s*\n*\s*\.include\s*/etc/crypto-policies/back-ends/openssl.config\s*$1
Configure Libreswan to use System Crypto Policyxccdf_org.ssgproject.content_rule_configure_libreswan_crypto_policy mediumCCE-80937-6

Configure Libreswan to use System Crypto Policy

Rule IDxccdf_org.ssgproject.content_rule_configure_libreswan_crypto_policy
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-configure_libreswan_crypto_policy:def:1
Time2020-09-29T11:18:01
Severitymedium
Identifiers and References

Identifiers:  CCE-80937-6

References:  CM-6(a), MA-4(6), SC-13, SC-12(2), SC-12(3), SRG-OS-000033-GPOS-00014

Description

Crypto Policies provide a centralized control over crypto algorithms usage of many packages. Libreswan is supported by system crypto policy, but the Libreswan configuration may be set up to ignore it. To check that Crypto Policies settings are configured correctly, ensure that the /etc/ipsec.conf includes the appropriate configuration file. In /etc/ipsec.conf, make sure that the following line is not commented out or superseded by later includes: include /etc/crypto-policies/back-ends/libreswan.config

Rationale

Overriding the system crypto policy makes the behavior of the Libreswan service violate expectations, and makes system configuration more fragmented.

OVAL test results details

package libreswan is installed  oval:ssg-test_package_libreswan_installed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_test_package_libreswan_installed:obj:1 of type rpminfo_object
Name
libreswan

Check that the libreswan configuration includes the crypto policy config file  oval:ssg-test_configure_libreswan_crypto_policy:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_configure_libreswan_crypto_policy:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/ipsec.conf^\s*include\s+/etc/crypto-policies/back-ends/libreswan.config\s*(?:#.*)?$1
Configure System Cryptography Policyxccdf_org.ssgproject.content_rule_configure_crypto_policy highCCE-80935-0

Configure System Cryptography Policy

Rule IDxccdf_org.ssgproject.content_rule_configure_crypto_policy
Result
error
Multi-check ruleno
OVAL Definition IDoval:ssg-configure_crypto_policy:def:1
Time2020-09-29T11:21:05
Severityhigh
Identifiers and References

Identifiers:  CCE-80935-0

References:  AC-17(a), AC-17(2), CM-6(a), MA-4(6), SC-13, SC-12(2), SC-12(3), SRG-OS-000396-GPOS-00176, SRG-OS-000393-GPOS-00173, SRG-OS-000394-GPOS-00174

Description

To configure the system cryptography policy to use ciphers only from the FIPS:OSPP policy, run the following command:

$ sudo update-crypto-policies --set FIPS:OSPP
The rule checks if settings for selected crypto policy are configured as expected. Configuration files in the /etc/crypto-policies/back-ends are either symlinks to correct files provided by Crypto-policies package or they are regular files in case crypto policy customizations are applied. Crypto policies may be customized by crypto policy modules, in which case it is delimited from the base policy using a colon.

Rationale

Centralized cryptographic policies simplify applying secure ciphers across an operating system and the applications that run on that operating system. Use of weak or untested encryption algorithms undermines the purposes of utilizing encryption to protect data.

Warnings
warning  The system needs to be rebooted for these changes to take effect.
warning  System Crypto Modules must be provided by a vendor that undergoes FIPS-140 certifications. FIPS-140 is applicable to all Federal agencies that use cryptographic-based security systems to protect sensitive information in computer and telecommunication systems (including voice systems) as defined in Section 5131 of the Information Technology Management Reform Act of 1996, Public Law 104-106. This standard shall be used in designing and implementing cryptographic modules that Federal departments and agencies operate or are operated for them under contract. See https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf To meet this, the system has to have cryptographic software provided by a vendor that has undergone this certification. This means providing documentation, test results, design information, and independent third party review by an accredited lab. While open source software is capable of meeting this, it does not meet FIPS-140 unless the vendor submits to this process.
Evaluation messages
info 
Fix execution completed and returned: 0
info 
Setting system policy to FIPS:OSPP
Note: System-wide crypto policies are applied on application start-up.
It is recommended to restart the system for the change of policies
to fully take place.
info 
Failed to verify applied fix: Checking engine returns: fail



var_system_crypto_policy="FIPS:OSPP"

update-crypto-policies --set ${var_system_crypto_policy}


Complexity:low
Disruption:low
Strategy:restrict
- name: XCCDF Value var_system_crypto_policy # promote to variable
  set_fact:
    var_system_crypto_policy: !!str FIPS:OSPP
  tags:
    - always

- name: Configure System Cryptography Policy
  lineinfile:
    path: /etc/crypto-policies/config
    regexp: ^(?!#)(\S+)$
    line: '{{ var_system_crypto_policy }}'
    create: true
  tags:
    - configure_crypto_policy
    - high_severity
    - restrict_strategy
    - low_complexity
    - low_disruption
    - no_reboot_needed
    - CCE-80935-0
    - NIST-800-53-AC-17(a)
    - NIST-800-53-AC-17(2)
    - NIST-800-53-CM-6(a)
    - NIST-800-53-MA-4(6)
    - NIST-800-53-SC-13
    - NIST-800-53-SC-12(2)
    - NIST-800-53-SC-12(3)

- name: Verify that Crypto Policy is Set (runtime)
  command: /usr/bin/update-crypto-policies --set {{ var_system_crypto_policy }}
  tags:
    - configure_crypto_policy
    - high_severity
    - restrict_strategy
    - low_complexity
    - low_disruption
    - no_reboot_needed
    - CCE-80935-0
    - NIST-800-53-AC-17(a)
    - NIST-800-53-AC-17(2)
    - NIST-800-53-CM-6(a)
    - NIST-800-53-MA-4(6)
    - NIST-800-53-SC-13
    - NIST-800-53-SC-12(2)
    - NIST-800-53-SC-12(3)
OVAL test results details

check for crypto policy correctly configured in /etc/crypto-policies/config  oval:ssg-test_configure_crypto_policy:tst:1  false

Following items have been found on the system:
PathContent
/etc/crypto-policies/configDEFAULT

check for crypto policy correctly configured in /etc/crypto-policies/state/current  oval:ssg-test_configure_crypto_policy_current:tst:1  false

Following items have been found on the system:
PathContent
/etc/crypto-policies/state/currentDEFAULT

Check if update-crypto-policies has been run  oval:ssg-test_crypto_policies_updated:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-variable_crypto_policies_config_file_age:var:126342411

Check if /etc/crypto-policies/back-ends/nss.config exists  oval:ssg-test_crypto_policy_nss_config:tst:1  true

Following items have been found on the system:
PathTypeUIDGIDSize (B)Permissions
/etc/crypto-policies/back-ends/nss.configsymbolic link0042rwxrwxrwx 
Configure Kerberos to use System Crypto Policyxccdf_org.ssgproject.content_rule_configure_kerberos_crypto_policy mediumCCE-80936-8

Configure Kerberos to use System Crypto Policy

Rule IDxccdf_org.ssgproject.content_rule_configure_kerberos_crypto_policy
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-configure_kerberos_crypto_policy:def:1
Time2020-09-29T11:18:01
Severitymedium
Identifiers and References

Identifiers:  CCE-80936-8

References:  SC-13, SC-12(2), SC-12(3), SRG-OS-000120-GPOS-00061

Description

Crypto Policies provide a centralized control over crypto algorithms usage of many packages. Kerberos is supported by crypto policy, but it's configuration may be set up to ignore it. To check that Crypto Policies settings for Kerberos are configured correctly, examine that there is a symlink at /etc/krb5.conf.d/crypto-policies targeting /etc/cypto-policies/back-ends/krb5.config. If the symlink exists, kerberos is configured to use the system-wide crypto policy settings.

Rationale

Overriding the system crypto policy makes the behavior of Kerberos violate expectations, and makes system configuration more fragmented.

OVAL test results details

Check if kerberos configuration symlink and crypto policy kerberos backend symlink point to same file  oval:ssg-test_configure_kerberos_crypto_policy_symlink:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-var_symlink_kerberos_crypto_policy_configuration:var:1/usr/share/crypto-policies/DEFAULT/krb5.txt

Check if kerberos configuration symlink links to the crypto-policy backend file  oval:ssg-test_configure_kerberos_crypto_policy_nosymlink:tst:1  false

Following items have been found on the system:
Var refValue
oval:ssg-var_symlink_kerberos_crypto_policy_configuration:var:1/usr/share/crypto-policies/DEFAULT/krb5.txt
Install AIDExccdf_org.ssgproject.content_rule_package_aide_installed mediumCCE-80844-4

Install AIDE

Rule IDxccdf_org.ssgproject.content_rule_package_aide_installed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_aide_installed:def:1
Time2020-09-29T11:18:01
Severitymedium
Identifiers and References

Identifiers:  CCE-80844-4

References:  NT28(R51), 1.3.1, 1, 11, 12, 13, 14, 15, 16, 2, 3, 5, 7, 8, 9, 5.10.1.3, APO01.06, BAI01.06, BAI02.01, BAI03.05, BAI06.01, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS01.03, DSS03.05, DSS04.07, DSS05.02, DSS05.03, DSS05.05, DSS05.07, DSS06.02, DSS06.06, 4.3.4.3.2, 4.3.4.3.3, 4.3.4.4.4, SR 3.1, SR 3.3, SR 3.4, SR 3.8, SR 4.1, SR 6.2, SR 7.6, A.11.2.4, A.12.1.2, A.12.2.1, A.12.4.1, A.12.5.1, A.12.6.2, A.14.1.2, A.14.1.3, A.14.2.2, A.14.2.3, A.14.2.4, A.14.2.7, A.15.2.1, A.8.2.3, CM-6(a), DE.CM-1, DE.CM-7, PR.DS-1, PR.DS-6, PR.DS-8, PR.IP-1, PR.IP-3, Req-11.5, SRG-OS-000363-GPOS-00150

Description

The aide package can be installed with the following command:

$ sudo yum install aide

Rationale

The AIDE package must be installed if it is to be available for integrity checking.

OVAL test results details

package aide is installed  oval:ssg-test_package_aide_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
aidex86_64(none)11.el80.160:0.16-11.el80aide-0:0.16-11.el8.x86_64
Enable Kernel Page-Table Isolation (KPTI)xccdf_org.ssgproject.content_rule_grub2_pti_argument highCCE-82194-2

Enable Kernel Page-Table Isolation (KPTI)

Rule IDxccdf_org.ssgproject.content_rule_grub2_pti_argument
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-grub2_pti_argument:def:1
Time2020-09-29T11:21:05
Severityhigh
Identifiers and References

Identifiers:  CCE-82194-2

References:  SRG-OS-000433-GPOS-00193

Description

To enable Kernel page-table isolation, add the argument pti=on to the default GRUB 2 command line for the Linux operating system in /etc/default/grub, in the manner below:

GRUB_CMDLINE_LINUX="pti=on"

Rationale

Kernel page-table isolation is a kernel feature that mitigates the Meltdown security vulnerability and hardens the kernel against attempts to bypass kernel address space layout randomization (KASLR).

Warnings
warning  The GRUB 2 configuration file, grub.cfg, is automatically updated each time a new kernel is installed. Note that any changes to /etc/default/grub require rebuilding the grub.cfg file. To update the GRUB 2 configuration file manually, use the
grub2-mkconfig -o
command as follows:
  • On BIOS-based machines, issue the following command as root:
    ~]# grub2-mkconfig -o /boot/grub2/grub.cfg
  • On UEFI-based machines, issue the following command as root:
    ~]# grub2-mkconfig -o /boot/efi/EFI/redhat/grub.cfg
Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

check forkernel command line parameters pti=on in /boot/grub2/grubenv for all kernels  oval:ssg-test_grub2_pti_argument_grub_env:tst:1  false

Following items have been found on the system:
PathContent
/boot/grub2/grubenvkernelopts=root=/dev/mapper/ovirt-root ro console=tty0 console=ttyS0 crashkernel=auto resume=/dev/mapper/ovirt-swap rd.lvm.lv=ovirt/root rd.lvm.lv=ovirt/swap
Set the UEFI Boot Loader Passwordxccdf_org.ssgproject.content_rule_grub2_uefi_password mediumCCE-80829-5

Set the UEFI Boot Loader Password

Rule IDxccdf_org.ssgproject.content_rule_grub2_uefi_password
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-grub2_uefi_password:def:1
Time2020-09-29T11:18:01
Severitymedium
Identifiers and References

Identifiers:  CCE-80829-5

References:  NT28(R17), 1.4.2, 11, 12, 14, 15, 16, 18, 3, 5, DSS05.02, DSS05.04, DSS05.05, DSS05.07, DSS06.03, DSS06.06, 3.4.5, CCI-000213, 164.308(a)(1)(ii)(B), 164.308(a)(7)(i), 164.308(a)(7)(ii)(A), 164.310(a)(1), 164.310(a)(2)(i), 164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(b), 164.310(c), 164.310(d)(1), 164.310(d)(2)(iii), 4.3.3.2.2, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, A.6.1.2, A.7.1.1, A.9.1.2, A.9.2.1, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, CM-6(a), PR.AC-4, PR.AC-6, PR.PT-3, FIA_AFL.1, SRG-OS-000080-GPOS-00048

Description

The grub2 boot loader should have a superuser account and password protection enabled to protect boot-time settings.

To do so, select a superuser account name and password and and modify the /etc/grub.d/01_users configuration file with the new account name.

Since plaintext passwords are a security risk, generate a hash for the pasword by running the following command:

$ grub2-setpassword
When prompted, enter the password that was selected.

NOTE: It is recommended not to use common administrator account names like root, admin, or administrator for the grub2 superuser account.

Change the superuser to a different username (The default is 'root').
$ sed -i s/root/bootuser/g /etc/grub.d/01_users


To meet FISMA Moderate, the bootloader superuser account and password MUST differ from the root account and password. Once the superuser account and password have been added, update the grub.cfg file by running:
grub2-mkconfig -o /boot/efi/EFI/redhat/grub.cfg
NOTE: Do NOT manually add the superuser account and password to the grub.cfg file as the grub2-mkconfig command overwrites this file.

Rationale

Password protection on the boot loader configuration ensures users with physical access cannot trivially alter important bootloader settings. These include which kernel to use, and whether to enter single-user mode.

Warnings
warning  To prevent hard-coded passwords, automatic remediation of this control is not available. Remediation must be automated as a component of machine provisioning, or followed manually as outlined above.
OVAL test results details

/boot/efi/EFI/redhat/grub.cfg does not exist  oval:ssg-test_bootloader_uefi_grub_cfg:tst:1  true

No items have been found conforming to the following objects:
Object oval:ssg-object_bootloader_uefi_grub_cfg:obj:1 of type file_object
Filepath
^/boot/efi/EFI/(redhat|fedora)/grub.cfg$

make sure a password is defined in /boot/efi/EFI/redhat/user.cfg  oval:ssg-test_grub2_uefi_password_usercfg:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_grub2_uefi_password_usercfg:obj:1 of type textfilecontent54_object
FilepathPatternInstance
^/boot/efi/EFI/(redhat|fedora)/user.cfg$^[\s]*GRUB2_PASSWORD=grub\.pbkdf2\.sha512.*$1

make sure a password is defined in /boot/efi/EFI/redhat/grub.cfg  oval:ssg-test_grub2_uefi_password_grubcfg:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_grub2_uefi_password_grubcfg:obj:1 of type textfilecontent54_object
FilepathPatternInstance
^/boot/efi/EFI/(redhat|fedora)/grub.cfg$^[\s]*password_pbkdf2[\s]+.*[\s]+grub\.pbkdf2\.sha512.*$1

superuser is defined in /boot/efi/EFI/redhat/grub.cfg. Superuser is not root, admin, or administrator  oval:ssg-test_bootloader_uefi_superuser:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_bootloader_uefi_superuser:obj:1 of type textfilecontent54_object
FilepathPatternInstance
^/boot/efi/EFI/(redhat|fedora)/grub.cfg$^[\s]*set[\s]+superusers=\"(?i)(?!root|admin|administrator)(?-i).*\"$1
Configure audit according to OSPP requirementsxccdf_org.ssgproject.content_rule_audit_rules_for_ospp mediumCCE-82309-6

Configure audit according to OSPP requirements

Rule IDxccdf_org.ssgproject.content_rule_audit_rules_for_ospp
Result
error
Multi-check ruleno
OVAL Definition IDoval:ssg-audit_rules_for_ospp:def:1
Time2020-09-29T11:21:06
Severitymedium
Identifiers and References

Identifiers:  CCE-82309-6

References:  NONE, FAU_GEN.1.1.c, SRG-OS-000004-GPOS-00004, SRG-OS-000240-GPOS-00090, SRG-OS-000241-GPOS-00091, SRG-OS-000303-GPOS-00120, SRG-OS-000476-GPOS-00221, SRG-OS-000327-GPOS-00127, SRG-OS-000064-GPOS-00033, SRG-OS-000365-GPOS-00152, SRG-OS-000458-GPOS-00203, SRG-OS-000461-GPOS-00205, SRG-OS-000462-GPOS-00206, SRG-OS-000463-GPOS-00207, SRG-OS-000465-GPOS-00209, SRG-OS-000466-GPOS-00210, SRG-OS-000467-GPOS-00211, SRG-OS-000468-GPOS-00212, SRG-OS-000470-GPOS-00214, SRG-OS-000471-GPOS-00215, SRG-OS-000471-GPOS-00216, SRG-OS-000472-GPOS-00217, SRG-OS-000474-GPOS-00219, SRG-OS-000475-GPOS-00220, SRG-OS-000477-GPOS-00222

Description

Configure audit to meet requirements for Operating System Protection Profile (OSPP) v4.2.1. Audit defines groups of rules in /usr/share/doc/audit/rules to satisfy specific policies. To fulfill requirements for compliance with OSPP v4.2.1, the following files are necessary:

  • /usr/share/doc/audit/rules/10-base-config.rules
  • /usr/share/doc/audit/rules/11-loginuid.rules
  • /usr/share/doc/audit/rules/30-ospp-v42.rules
  • /usr/share/doc/audit/rules/43-module-load.rules
Copy the files from /usr/share/doc/audit/rules to /etc/audit/rules.d:
cp /usr/share/doc/audit*/rules/{10-base-config,11-loginuid,30-ospp-v42,43-module-load}.rules /etc/audit/rules.d/

Rationale

The audit rules defined in /usr/share/doc/audit/rules are the recommended way to meet compliance with OSPP v4.2.1.

Evaluation messages
info 
Fix execution completed and returned: 0
info 
cp: cannot stat '/usr/share/doc/audit*/rules/10-base-config.rules': No such file or directory
cp: cannot stat '/usr/share/doc/audit*/rules/11-loginuid.rules': No such file or directory
cp: cannot stat '/usr/share/doc/audit*/rules/30-ospp-v42.rules': No such file or directory
cp: cannot stat '/usr/share/doc/audit*/rules/43-module-load.rules': No such file or directory
/sbin/augenrules: No change
No rules
enabled 1
failure 1
pid 898
rate_limit 0
backlog_limit 8192
lost 0
backlog 0
backlog_wait_time 60000
enabled 1
failure 1
pid 898
rate_limit 0
backlog_limit 8192
lost 0
backlog 1
backlog_wait_time 60000
enabled 1
failure 1
pid 898
rate_limit 0
backlog_limit 8192
lost 0
backlog 0
backlog_wait_time 60000
info 
Failed to verify applied fix: Checking engine returns: fail



cp /usr/share/doc/audit*/rules/10-base-config.rules /etc/audit/rules.d
cp /usr/share/doc/audit*/rules/11-loginuid.rules /etc/audit/rules.d
cp /usr/share/doc/audit*/rules/30-ospp-v42.rules /etc/audit/rules.d
cp /usr/share/doc/audit*/rules/43-module-load.rules /etc/audit/rules.d

augenrules --load
OVAL test results details

Compare 10-base-config.rules file in /etc/audit/rules.d against file in /usr/share/doc/audit/  oval:ssg-test_compare_10-base-config:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_etc_10-base-config:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/audit/rules.d/10-base-config.rules(?:.*\n)*1

Compare 11-loginuid.rules file in /etc/audit/rules.d against file in /usr/share/doc/audit/  oval:ssg-test_compare_11-loginuid:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_etc_11-loginuid:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/audit/rules.d/11-loginuid.rules(?:.*\n)*1

Compare 30-ospp-v42.rules file in /etc/audit/rules.d against file in /usr/share/doc/audit/  oval:ssg-test_compare_30-ospp-v42:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_etc_30-ospp-v42:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/audit/rules.d/30-ospp-v42.rules(?:.*\n)*1

Compare 43-module-load.rules file in /etc/audit/rules.d against file in /usr/share/doc/audit/  oval:ssg-test_compare_43-module-load:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_etc_43-module-load:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/audit/rules.d/43-module-load.rules(?:.*\n)*1
Record Events that Modify User/Group Information - /etc/passwdxccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_passwd mediumCCE-80761-0

Record Events that Modify User/Group Information - /etc/passwd

Rule IDxccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_passwd
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-audit_rules_usergroup_modification_passwd:def:1
Time2020-09-29T11:21:06
Severitymedium
Identifiers and References

Identifiers:  CCE-80761-0

References:  5.2.5, 1, 11, 12, 13, 14, 15, 16, 18, 19, 2, 3, 4, 5, 6, 7, 8, 9, 5.4.1.1, APO10.01, APO10.03, APO10.04, APO10.05, APO11.04, APO12.06, APO13.01, BAI03.05, BAI08.02, DSS01.03, DSS01.04, DSS02.02, DSS02.04, DSS02.07, DSS03.01, DSS03.05, DSS05.02, DSS05.03, DSS05.04, DSS05.05, DSS05.07, DSS06.03, MEA01.01, MEA01.02, MEA01.03, MEA01.04, MEA01.05, MEA02.01, 3.1.7, CCI-000018, CCI-000172, CCI-001403, CCI-001404, CCI-001405, CCI-001683, CCI-001684, CCI-001685, CCI-001686, CCI-002130, CCI-002132, 164.308(a)(1)(ii)(D), 164.308(a)(3)(ii)(A), 164.308(a)(5)(ii)(C), 164.312(a)(2)(i), 164.312(b), 164.312(d), 164.312(e), 4.2.3.10, 4.3.2.6.7, 4.3.3.2.2, 4.3.3.3.9, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.8, 4.3.3.6.6, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.4.7, 4.3.4.5.6, 4.3.4.5.7, 4.3.4.5.8, 4.4.2.1, 4.4.2.2, 4.4.2.4, SR 1.1, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.10, SR 2.11, SR 2.12, SR 2.6, SR 2.8, SR 2.9, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 6.1, SR 6.2, SR 7.1, SR 7.6, A.11.2.6, A.12.4.1, A.12.4.2, A.12.4.3, A.12.4.4, A.12.7.1, A.13.1.1, A.13.2.1, A.14.1.3, A.14.2.7, A.15.2.1, A.15.2.2, A.16.1.4, A.16.1.5, A.16.1.7, A.6.1.2, A.6.2.1, A.6.2.2, A.7.1.1, A.9.1.2, A.9.2.1, A.9.2.2, A.9.2.3, A.9.2.4, A.9.2.6, A.9.3.1, A.9.4.1, A.9.4.2, A.9.4.3, A.9.4.4, A.9.4.5, AC-2(4), AU-2(d), AU-12(c), AC-6(9), CM-6(a), DE.AE-3, DE.AE-5, DE.CM-1, DE.CM-3, DE.CM-7, ID.SC-4, PR.AC-1, PR.AC-3, PR.AC-4, PR.AC-6, PR.PT-1, PR.PT-4, RS.AN-1, RS.AN-4, FAU_GEN.1.1.c, Req-10.2.5, SRG-OS-000004-GPOS-00004, SRG-OS-000239-GPOS-00089, SRG-OS-000240-GPOS-00090, SRG-OS-000241-GPOS-00091, SRG-OS-000303-GPOS-00120, SRG-OS-000476-GPOS-00221, SRG-OS-000274-GPOS-00104, SRG-OS-000275-GPOS-00105, SRG-OS-000276-GPOS-00106, SRG-OS-000277-GPOS-00107, SRG-OS-000004-VMM-000040, SRG-OS-000239-VMM-000810, SRG-OS-000240-VMM-000820, SRG-OS-000241-VMM-000830, SRG-OS-000274-VMM-000960, SRG-OS-000275-VMM-000970, SRG-OS-000276-VMM-000980, SRG-OS-000277-VMM-000990, SRG-OS-000303-VMM-001090, SRG-OS-000304-VMM-001100, SRG-OS-000476-VMM-001960

Description

If the auditd daemon is configured to use the augenrules program to read audit rules during daemon startup (the default), add the following lines to a file with suffix .rules in the directory /etc/audit/rules.d, in order to capture events that modify account changes:

-w /etc/passwd -p wa -k audit_rules_usergroup_modification


If the auditd daemon is configured to use the auditctl utility to read audit rules during daemon startup, add the following lines to /etc/audit/audit.rules file, in order to capture events that modify account changes:

-w /etc/passwd -p wa -k audit_rules_usergroup_modification

Rationale

In addition to auditing new user and group accounts, these watches will alert the system administrator(s) to any modifications. Any unexpected users, groups, or modifications should be investigated for legitimacy.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

audit augenrules  oval:ssg-test_audit_rules_augenrules:tst:1  true

Following items have been found on the system:
PathContent
/usr/lib/systemd/system/auditd.serviceExecStartPost=-/sbin/augenrules --load

audit augenrules passwd  oval:ssg-test_audit_rules_usergroup_modification_passwd_augen:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_audit_rules_usergroup_modification_passwd_augen:obj:1 of type textfilecontent54_object
FilepathPatternInstance
^/etc/audit/rules\.d/.*\.rules$^\-w[\s]+\/etc\/passwd[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b[\s]+(-k[\s]+|-F[\s]+key=)\w+[\s]*$1

audit auditctl  oval:ssg-test_audit_rules_auditctl:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_audit_rules_auditctl:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/usr/lib/systemd/system/auditd.service^ExecStartPost=\-\/sbin\/auditctl.*$1

audit passwd  oval:ssg-test_audit_rules_usergroup_modification_passwd_auditctl:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_audit_rules_usergroup_modification_passwd_auditctl:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/audit/audit.rules^\-w[\s]+\/etc\/passwd[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b[\s]+(-k[\s]+|-F[\s]+key=)\w+[\s]*$1
Set hostname as computer node name in audit logsxccdf_org.ssgproject.content_rule_auditd_name_format mediumCCE-82897-0

Set hostname as computer node name in audit logs

Rule IDxccdf_org.ssgproject.content_rule_auditd_name_format
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-auditd_name_format:def:1
Time2020-09-29T11:21:06
Severitymedium
Identifiers and References

Identifiers:  CCE-82897-0

References:  FAU_GEN.1, SRG-OS-000039-GPOS-00017

Description

To configure Audit daemon to use value returned by gethostname syscall as computer node name in the audit events, set name_format to hostname in /etc/audit/auditd.conf.

Rationale

If option name_format is left at its default value of none, audit events from different computers may be hard to distinguish.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

tests the value of name_format setting in the /etc/audit/auditd.conf file  oval:ssg-test_auditd_name_format:tst:1  false

Following items have been found on the system:
PathContent
/etc/audit/auditd.confname_format = NONE
Include Local Events in Audit Logsxccdf_org.ssgproject.content_rule_auditd_local_events mediumCCE-82233-8

Include Local Events in Audit Logs

Rule IDxccdf_org.ssgproject.content_rule_auditd_local_events
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-auditd_local_events:def:1
Time2020-09-29T11:18:02
Severitymedium
Identifiers and References

Identifiers:  CCE-82233-8

References:  FAU_GEN.1.1.c, SRG-OS-000062-GPOS-00031

Description

To configure Audit daemon to include local events in Audit logs, set local_events to yes in /etc/audit/auditd.conf. This is the default setting.

Rationale

If option local_events isn't set to yes only events from network will be aggregated.

OVAL test results details

tests the value of local_events setting in the /etc/audit/auditd.conf file  oval:ssg-test_auditd_local_events:tst:1  true

Following items have been found on the system:
PathContent
/etc/audit/auditd.conflocal_events = yes

tests the absence of local_events setting in the /etc/audit/auditd.conf file  oval:ssg-test_auditd_local_events_default_not_overriden:tst:1  false

Following items have been found on the system:
PathContent
/etc/audit/auditd.conflocal_events =
Set number of records to cause an explicit flush to audit logsxccdf_org.ssgproject.content_rule_auditd_freq mediumCCE-82258-5

Set number of records to cause an explicit flush to audit logs

Rule IDxccdf_org.ssgproject.content_rule_auditd_freq
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-auditd_freq:def:1
Time2020-09-29T11:18:02
Severitymedium
Identifiers and References

Identifiers:  CCE-82258-5

References:  FAU_GEN.1, SRG-OS-000051-GPOS-00024

Description

To configure Audit daemon to issue an explicit flush to disk command after writing 50 records, set freq to 50 in /etc/audit/auditd.conf.

Rationale

If option freq isn't set to 50, the flush to disk may happen after higher number of records, increasing the danger of audit loss.

OVAL test results details

tests the value of freq setting in the /etc/audit/auditd.conf file  oval:ssg-test_auditd_freq:tst:1  true

Following items have been found on the system:
PathContent
/etc/audit/auditd.conffreq = 50
Resolve information before writing to audit logsxccdf_org.ssgproject.content_rule_auditd_log_format mediumCCE-82201-5

Resolve information before writing to audit logs

Rule IDxccdf_org.ssgproject.content_rule_auditd_log_format
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-auditd_log_format:def:1
Time2020-09-29T11:18:02
Severitymedium
Identifiers and References

Identifiers:  CCE-82201-5

References:  FAU_GEN.1, SRG-OS-000255-GPOS-00096

Description

To configure Audit daemon to resolve all uid, gid, syscall, architecture, and socket address information before writing the events to disk, set log_format to ENRICHED in /etc/audit/auditd.conf.

Rationale

If option log_format isn't set to ENRICHED, the audit records will be stored in a format exactly as the kernel sends them.

OVAL test results details

tests the value of log_format setting in the /etc/audit/auditd.conf file  oval:ssg-test_auditd_log_format:tst:1  true

Following items have been found on the system:
PathContent
/etc/audit/auditd.conflog_format = ENRICHED
Write Audit Logs to the Diskxccdf_org.ssgproject.content_rule_auditd_write_logs mediumCCE-82366-6

Write Audit Logs to the Disk

Rule IDxccdf_org.ssgproject.content_rule_auditd_write_logs
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-auditd_write_logs:def:1
Time2020-09-29T11:18:02
Severitymedium
Identifiers and References

Identifiers:  CCE-82366-6

References:  FAU_GEN.1.1.c, SRG-OS-000480-GPOS-00227

Description

To configure Audit daemon to write Audit logs to the disk, set write_logs to yes in /etc/audit/auditd.conf. This is the default setting.

Rationale

If write_logs isn't set to yes, the Audit logs will not be written to the disk.

OVAL test results details

tests the value of write_logs setting in the /etc/audit/auditd.conf file  oval:ssg-test_auditd_write_logs:tst:1  true

Following items have been found on the system:
PathContent
/etc/audit/auditd.confwrite_logs = yes

tests the absence of write_logs setting in the /etc/audit/auditd.conf file  oval:ssg-test_auditd_write_logs_default_not_overriden:tst:1  false

Following items have been found on the system:
PathContent
/etc/audit/auditd.confwrite_logs =
Configure auditd flush priorityxccdf_org.ssgproject.content_rule_auditd_data_retention_flush mediumCCE-80680-2

Configure auditd flush priority

Rule IDxccdf_org.ssgproject.content_rule_auditd_data_retention_flush
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-auditd_data_retention_flush:def:1
Time2020-09-29T11:18:02
Severitymedium
Identifiers and References

Identifiers:  CCE-80680-2

References:  1, 12, 13, 14, 15, 16, 2, 3, 5, 6, 7, 8, 9, APO10.01, APO10.03, APO10.04, APO10.05, APO11.04, BAI03.05, DSS01.03, DSS03.05, DSS05.02, DSS05.04, DSS05.05, DSS05.07, MEA01.01, MEA01.02, MEA01.03, MEA01.04, MEA01.05, MEA02.01, 3.3.1, CCI-001576, 164.308(a)(1)(ii)(D), 164.308(a)(3)(ii)(A), 164.308(a)(5)(ii)(C), 164.312(a)(2)(i), 164.312(b), 164.312(d), 164.312(e), 4.3.2.6.7, 4.3.3.3.9, 4.3.3.5.8, 4.3.4.4.7, 4.4.2.1, 4.4.2.2, 4.4.2.4, SR 2.10, SR 2.11, SR 2.12, SR 2.8, SR 2.9, SR 6.1, SR 6.2, A.12.4.1, A.12.4.2, A.12.4.3, A.12.4.4, A.12.7.1, A.14.2.7, A.15.2.1, A.15.2.2, AU-11, CM-6(a), DE.CM-1, DE.CM-3, DE.CM-7, ID.SC-4, PR.PT-1, SRG-OS-000480-GPOS-00227

Description

The auditd service can be configured to synchronously write audit event data to disk. Add or correct the following line in /etc/audit/auditd.conf to ensure that audit event data is fully synchronized with the log files on the disk:

flush = incremental_async

Rationale

Audit data should be synchronously written to disk to ensure log integrity. These parameters assure that all audit event data is fully synchronized with the log files on the disk.

OVAL test results details

test the value of flush parameter in /etc/audit/auditd.conf  oval:ssg-test_auditd_data_retention_flush:tst:1  true

Following items have been found on the system:
PathContent
/etc/audit/auditd.confflush = INCREMENTAL_ASYNC
Configure auditd to use audispd's syslog pluginxccdf_org.ssgproject.content_rule_auditd_audispd_syslog_plugin_activated mediumCCE-80677-8

Configure auditd to use audispd's syslog plugin

Rule IDxccdf_org.ssgproject.content_rule_auditd_audispd_syslog_plugin_activated
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-auditd_audispd_syslog_plugin_activated:def:1
Time2020-09-29T11:21:06
Severitymedium
Identifiers and References

Identifiers:  CCE-80677-8

References:  1, 11, 12, 13, 14, 15, 16, 19, 3, 4, 5, 6, 7, 8, 5.4.1.1, APO11.04, APO12.06, BAI03.05, BAI08.02, DSS02.02, DSS02.04, DSS02.07, DSS03.01, DSS05.04, DSS05.07, MEA02.01, 3.3.1, CCI-000136, 164.308(a)(1)(ii)(D), 164.308(a)(5)(ii)(B), 164.308(a)(5)(ii)(C), 164.308(a)(6)(ii), 164.308(a)(8), 164.310(d)(2)(iii), 164.312(b), 164.314(a)(2)(i)(C), 164.314(a)(2)(iii), 4.2.3.10, 4.3.3.3.9, 4.3.3.5.8, 4.3.4.4.7, 4.3.4.5.6, 4.3.4.5.7, 4.3.4.5.8, 4.4.2.1, 4.4.2.2, 4.4.2.4, SR 2.10, SR 2.11, SR 2.12, SR 2.8, SR 2.9, SR 6.1, A.12.4.1, A.12.4.2, A.12.4.3, A.12.4.4, A.12.7.1, A.16.1.4, A.16.1.5, A.16.1.7, AU-4(1), CM-6(a), DE.AE-3, DE.AE-5, PR.PT-1, RS.AN-1, RS.AN-4, FAU_GEN.1.1.c, Req-10.5.3, SRG-OS-000479-GPOS-00224, SRG-OS-000342-GPOS-00133, SRG-OS-000051-VMM-000230, SRG-OS-000058-VMM-000270, SRG-OS-000059-VMM-000280, SRG-OS-000479-VMM-001990, SRG-OS-000479-VMM-001990

Description

To configure the auditd service to use the syslog plug-in of the audispd audit event multiplexor, set the active line in /etc/audit/plugins.d/syslog.conf to yes. Restart the auditd service:

$ sudo service auditd restart

Rationale

The auditd service does not include the ability to send audit records to a centralized server for management directly. It does, however, include a plug-in for audit event multiplexor (audispd) to pass audit records to the local syslog server

Evaluation messages
info 
Fix execution completed and returned: 0
info 
grep: /etc/audit/plugins.d/syslog.conf: No such file or directory
OVAL test results details

audispd syslog plugin activated  oval:ssg-test_auditd_audispd_syslog_plugin_activated:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_auditd_audispd_syslog_plugin_activated:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/audit/plugins.d/syslog.conf^[ ]*active[ ]+=[ ]+yes[ ]*$1
Ensure the audit Subsystem is Installedxccdf_org.ssgproject.content_rule_package_audit_installed mediumCCE-81043-2

Ensure the audit Subsystem is Installed

Rule IDxccdf_org.ssgproject.content_rule_package_audit_installed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_audit_installed:def:1
Time2020-09-29T11:18:01
Severitymedium
Identifiers and References

Identifiers:  CCE-81043-2

References:  NT28(R50), AC-7(a), AU-7(1), AU-7(2), AU-14, AU-12(2), AU-2(a), CM-6(a), SRG-OS-000480-GPOS-00227, SRG-OS-000122-GPOS-00063

Description

The audit package should be installed.

Rationale

The auditd service is an access monitoring and accounting daemon, watching system calls to audit any access, in comparison with potential local access control policy such as SELinux policy.

OVAL test results details

package audit is installed  oval:ssg-test_package_audit_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
auditx86_64(none)0.17.20191104git1c2f876.el83.00:3.0-0.17.20191104git1c2f876.el8199e2f91fd431d51audit-0:3.0-0.17.20191104git1c2f876.el8.x86_64
Install audispd-plugins Packagexccdf_org.ssgproject.content_rule_package_audispd-plugins_installed mediumCCE-82953-1

Install audispd-plugins Package

Rule IDxccdf_org.ssgproject.content_rule_package_audispd-plugins_installed
Result
error
Multi-check ruleno
OVAL Definition IDoval:ssg-package_audispd-plugins_installed:def:1
Time2020-09-29T11:21:06
Severitymedium
Identifiers and References

Identifiers:  CCE-82953-1

References:  SRG-OS-000342-GPOS-00133

Description

The audispd-plugins package can be installed with the following command:

$ sudo yum install audispd-plugins

Rationale

audispd-plugins provides plugins for the real-time interface to the audit subsystem, audispd. These plugins can do things like relay events to remote machines or analyze events for suspicious behavior.

Evaluation messages
info 
Fix execution completed and returned: 1
info 
Error: There are no enabled repositories in "/etc/yum.repos.d", "/etc/yum/repos.d", "/etc/distro.repos.d".
info 
Failed to verify applied fix: Checking engine returns: fail


Complexity:low
Disruption:low
Strategy:enable

if ! rpm -q --quiet "audispd-plugins" ; then
    yum install -y "audispd-plugins"
fi


Complexity:low
Disruption:low
Strategy:enable
- name: Ensure audispd-plugins is installed
  package:
    name: audispd-plugins
    state: present
  when: ansible_virtualization_role != "guest" or ansible_virtualization_type != "docker"
  tags:
    - package_audispd-plugins_installed
    - medium_severity
    - enable_strategy
    - low_complexity
    - low_disruption
    - no_reboot_needed
    - CCE-82953-1


Complexity:low
Disruption:low
Strategy:enable
include install_audispd-plugins

class install_audispd-plugins {
  package { 'audispd-plugins':
    ensure => 'installed',
  }
}


Complexity:low
Disruption:low
Strategy:enable

package --add=audispd-plugins
OVAL test results details

package audispd-plugins is installed  oval:ssg-test_package_audispd-plugins_installed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_test_package_audispd-plugins_installed:obj:1 of type rpminfo_object
Name
audispd-plugins
Enable auditd Servicexccdf_org.ssgproject.content_rule_service_auditd_enabled highCCE-80872-5

Enable auditd Service

Rule IDxccdf_org.ssgproject.content_rule_service_auditd_enabled
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-service_auditd_enabled:def:1
Time2020-09-29T11:18:02
Severityhigh
Identifiers and References

Identifiers:  CCE-80872-5

References:  4.1.2, 1, 11, 12, 13, 14, 15, 16, 19, 2, 3, 4, 5, 6, 7, 8, 9, 5.4.1.1, APO10.01, APO10.03, APO10.04, APO10.05, APO11.04, APO12.06, APO13.01, BAI03.05, BAI08.02, DSS01.03, DSS01.04, DSS02.02, DSS02.04, DSS02.07, DSS03.01, DSS03.05, DSS05.02, DSS05.03, DSS05.04, DSS05.05, DSS05.07, MEA01.01, MEA01.02, MEA01.03, MEA01.04, MEA01.05, MEA02.01, 3.3.1, 3.3.2, 3.3.6, CCI-000126, CCI-000130, CCI-000131, CCI-000132, CCI-000133, CCI-000134, 164.308(a)(1)(ii)(D), 164.308(a)(5)(ii)(C), 164.310(a)(2)(iv), 164.310(d)(2)(iii), 164.312(b), 4.2.3.10, 4.3.2.6.7, 4.3.3.3.9, 4.3.3.5.8, 4.3.3.6.6, 4.3.4.4.7, 4.3.4.5.6, 4.3.4.5.7, 4.3.4.5.8, 4.4.2.1, 4.4.2.2, 4.4.2.4, SR 1.13, SR 2.10, SR 2.11, SR 2.12, SR 2.6, SR 2.8, SR 2.9, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 6.1, SR 6.2, SR 7.1, SR 7.6, A.11.2.6, A.12.4.1, A.12.4.2, A.12.4.3, A.12.4.4, A.12.7.1, A.13.1.1, A.13.2.1, A.14.1.3, A.14.2.7, A.15.2.1, A.15.2.2, A.16.1.4, A.16.1.5, A.16.1.7, A.6.2.1, A.6.2.2, AC-2(g), AU-3, AU-10, AU-2(d), AU-12(c), AU-14(1), AC-6(9), CM-6(a), DE.AE-3, DE.AE-5, DE.CM-1, DE.CM-3, DE.CM-7, ID.SC-4, PR.AC-3, PR.PT-1, PR.PT-4, RS.AN-1, RS.AN-4, Req-10.1, SRG-OS-000037-GPOS-00015, SRG-OS-000038-GPOS-00016, SRG-OS-000039-GPOS-00017, SRG-OS-000040-GPOS-00018, SRG-OS-000042-GPOS-00021, SRG-OS-000255-GPOS-00096, SRG-OS-000037-VMM-000150, SRG-OS-000063-VMM-000310, SRG-OS-000038-VMM-000160, SRG-OS-000039-VMM-000170, SRG-OS-000040-VMM-000180, SRG-OS-000041-VMM-000190

Description

The auditd service is an essential userspace component of the Linux Auditing System, as it is responsible for writing audit records to disk. The auditd service can be enabled with the following command:

$ sudo systemctl enable auditd.service

Rationale

Without establishing what type of events occurred, it would be difficult to establish, correlate, and investigate the events leading up to an outage or attack. Ensuring the auditd service is active ensures audit records generated by the kernel are appropriately recorded.

Additionally, a properly configured audit subsystem ensures that actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.

OVAL test results details

package audit is installed  oval:ssg-test_service_auditd_package_audit_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
auditx86_64(none)0.17.20191104git1c2f876.el83.00:3.0-0.17.20191104git1c2f876.el8199e2f91fd431d51audit-0:3.0-0.17.20191104git1c2f876.el8.x86_64

Test that the auditd service is running  oval:ssg-test_service_running_auditd:tst:1  true

Following items have been found on the system:
UnitPropertyValue
auditd.serviceActiveStateactive

systemd test  oval:ssg-test_multi_user_wants_auditd:tst:1  true

Following items have been found on the system:
UnitDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependency
multi-user.targetbasic.targetvar.mount-.mountsysinit.targetdev-mqueue.mountsystemd-hwdb-update.servicecryptsetup.targetproc-sys-fs-binfmt_misc.automountsystemd-journal-flush.servicesystemd-random-seed.servicesystemd-update-utmp.servicesystemd-tmpfiles-setup.servicesystemd-udevd.servicedev-hugepages.mountlvm2-lvmpolld.socketselinux-autorelabel-mark.serviceloadmodules.servicelocal-fs.targethome.mount-.mountvar-log-audit.mountboot.mounttmp.mountvar.mountvar-log.mountsystemd-remount-fs.servicedracut-shutdown.servicesystemd-sysctl.servicesystemd-journal-catalog-update.servicesystemd-update-done.servicesystemd-journald.servicesys-kernel-debug.mountsystemd-machine-id-commit.serviceldconfig.servicerngd.servicesystemd-binfmt.servicenis-domainname.servicesys-kernel-config.mountsystemd-modules-load.servicesystemd-sysusers.servicesys-fs-fuse-connections.mountswap.targetdev-mapper-ovirt\x2dswap.swapsystemd-udev-trigger.serviceimport-state.servicesystemd-firstboot.servicekmod-static-nodes.servicesystemd-ask-password-console.pathsystemd-tmpfiles-setup-dev.servicelvm2-monitor.servicemicrocode.servicepaths.targettimers.targetfstrim.timerunbound-anchor.timersystemd-tmpfiles-clean.timerslices.target-.slicesystem.slicesockets.targetsystemd-udevd-kernel.socketdbus.socketsystemd-coredump.socketsystemd-initctl.socketsystemd-udevd-control.socketsystemd-journald-dev-log.socketpcscd.socketsssd-kcm.socketsystemd-journald.socketcockpit.socketdm-event.socketrpcbind.socketsssd.servicekdump.servicecrond.servicesystemd-ask-password-wall.pathsshd.servicesystemd-user-sessions.serviceauditd.servicenfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetirqbalance.serviceremote-fs.targetnfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetgetty.targetserial-getty@ttyS0.servicegetty@tty1.servicecloud-init.targetcloud-init-local.servicecloud-config.servicecloud-final.servicecloud-init.servicednf-makecache.timerfirewalld.servicerpcbind.servicesystemd-update-utmp-runlevel.servicechronyd.servicersyslog.servicetuned.servicesystemd-logind.serviceNetworkManager.servicedbus.service

systemd test  oval:ssg-test_multi_user_wants_auditd_socket:tst:1  false

Following items have been found on the system:
UnitDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependency
multi-user.targetbasic.targetvar.mount-.mountsysinit.targetdev-mqueue.mountsystemd-hwdb-update.servicecryptsetup.targetproc-sys-fs-binfmt_misc.automountsystemd-journal-flush.servicesystemd-random-seed.servicesystemd-update-utmp.servicesystemd-tmpfiles-setup.servicesystemd-udevd.servicedev-hugepages.mountlvm2-lvmpolld.socketselinux-autorelabel-mark.serviceloadmodules.servicelocal-fs.targethome.mount-.mountvar-log-audit.mountboot.mounttmp.mountvar.mountvar-log.mountsystemd-remount-fs.servicedracut-shutdown.servicesystemd-sysctl.servicesystemd-journal-catalog-update.servicesystemd-update-done.servicesystemd-journald.servicesys-kernel-debug.mountsystemd-machine-id-commit.serviceldconfig.servicerngd.servicesystemd-binfmt.servicenis-domainname.servicesys-kernel-config.mountsystemd-modules-load.servicesystemd-sysusers.servicesys-fs-fuse-connections.mountswap.targetdev-mapper-ovirt\x2dswap.swapsystemd-udev-trigger.serviceimport-state.servicesystemd-firstboot.servicekmod-static-nodes.servicesystemd-ask-password-console.pathsystemd-tmpfiles-setup-dev.servicelvm2-monitor.servicemicrocode.servicepaths.targettimers.targetfstrim.timerunbound-anchor.timersystemd-tmpfiles-clean.timerslices.target-.slicesystem.slicesockets.targetsystemd-udevd-kernel.socketdbus.socketsystemd-coredump.socketsystemd-initctl.socketsystemd-udevd-control.socketsystemd-journald-dev-log.socketpcscd.socketsssd-kcm.socketsystemd-journald.socketcockpit.socketdm-event.socketrpcbind.socketsssd.servicekdump.servicecrond.servicesystemd-ask-password-wall.pathsshd.servicesystemd-user-sessions.serviceauditd.servicenfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetirqbalance.serviceremote-fs.targetnfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetgetty.targetserial-getty@ttyS0.servicegetty@tty1.servicecloud-init.targetcloud-init-local.servicecloud-config.servicecloud-final.servicecloud-init.servicednf-makecache.timerfirewalld.servicerpcbind.servicesystemd-update-utmp-runlevel.servicechronyd.servicersyslog.servicetuned.servicesystemd-logind.serviceNetworkManager.servicedbus.service
Enable Auditing for Processes Which Start Prior to the Audit Daemonxccdf_org.ssgproject.content_rule_grub2_audit_argument mediumCCE-80825-3

Enable Auditing for Processes Which Start Prior to the Audit Daemon

Rule IDxccdf_org.ssgproject.content_rule_grub2_audit_argument
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-grub2_audit_argument:def:1
Time2020-09-29T11:21:06
Severitymedium
Identifiers and References

Identifiers:  CCE-80825-3

References:  4.1.3, 1, 11, 12, 13, 14, 15, 16, 19, 3, 4, 5, 6, 7, 8, 5.4.1.1, APO10.01, APO10.03, APO10.04, APO10.05, APO11.04, APO12.06, APO13.01, BAI03.05, BAI08.02, DSS01.04, DSS02.02, DSS02.04, DSS02.07, DSS03.01, DSS05.02, DSS05.03, DSS05.04, DSS05.07, MEA01.01, MEA01.02, MEA01.03, MEA01.04, MEA01.05, MEA02.01, 3.3.1, CCI-001464, CCI-000130, 164.308(a)(1)(ii)(D), 164.308(a)(5)(ii)(C), 164.310(a)(2)(iv), 164.310(d)(2)(iii), 164.312(b), 4.2.3.10, 4.3.2.6.7, 4.3.3.3.9, 4.3.3.5.8, 4.3.3.6.6, 4.3.4.4.7, 4.3.4.5.6, 4.3.4.5.7, 4.3.4.5.8, 4.4.2.1, 4.4.2.2, 4.4.2.4, SR 1.13, SR 2.10, SR 2.11, SR 2.12, SR 2.6, SR 2.8, SR 2.9, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 6.1, SR 7.1, SR 7.6, A.11.2.6, A.12.4.1, A.12.4.2, A.12.4.3, A.12.4.4, A.12.7.1, A.13.1.1, A.13.2.1, A.14.1.3, A.15.2.1, A.15.2.2, A.16.1.4, A.16.1.5, A.16.1.7, A.6.2.1, A.6.2.2, AC-17(1), AU-14(1), AU-10, CM-6(a), IR-5(1), DE.AE-3, DE.AE-5, ID.SC-4, PR.AC-3, PR.PT-1, PR.PT-4, RS.AN-1, RS.AN-4, Req-10.3, SRG-OS-000254-GPOS-00095, SRG-OS-000254-VMM-000880

Description

To ensure all processes can be audited, even those which start prior to the audit daemon, add the argument audit=1 to the default GRUB 2 command line for the Linux operating system in /boot/grub2/grubenv, in the manner below:

# grub2-editenv - set "$(grub2-editenv - list | grep kernelopts) audit=1"

Rationale

Each process on the system carries an "auditable" flag which indicates whether its activities can be audited. Although auditd takes care of enabling this for all processes which launch after it does, adding the kernel argument ensures it is set for every process during boot.

Warnings
warning  The GRUB 2 configuration file, grub.cfg, is automatically updated each time a new kernel is installed. Note that any changes to /etc/default/grub require rebuilding the grub.cfg file. To update the GRUB 2 configuration file manually, use the
grub2-mkconfig -o
command as follows:
  • On BIOS-based machines, issue the following command as root:
    ~]# grub2-mkconfig -o /boot/grub2/grub.cfg
  • On UEFI-based machines, issue the following command as root:
    ~]# grub2-mkconfig -o /boot/efi/EFI/redhat/grub.cfg
Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

check forkernel command line parameters audit=1 in /boot/grub2/grubenv for all kernels  oval:ssg-test_grub2_audit_argument_grub_env:tst:1  false

Following items have been found on the system:
PathContent
/boot/grub2/grubenvkernelopts=root=/dev/mapper/ovirt-root ro console=tty0 console=ttyS0 crashkernel=auto resume=/dev/mapper/ovirt-swap rd.lvm.lv=ovirt/root rd.lvm.lv=ovirt/swap
Extend Audit Backlog Limit for the Audit Daemonxccdf_org.ssgproject.content_rule_grub2_audit_backlog_limit_argument mediumCCE-80943-4

Extend Audit Backlog Limit for the Audit Daemon

Rule IDxccdf_org.ssgproject.content_rule_grub2_audit_backlog_limit_argument
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-grub2_audit_backlog_limit_argument:def:1
Time2020-09-29T11:21:06
Severitymedium
Identifiers and References

Identifiers:  CCE-80943-4

References:  SRG-OS-000254-GPOS-00095

Description

To improve the kernel capacity to queue all log events, even those which occurred prior to the audit daemon, add the argument audit_backlog_limit=8192 to the default GRUB 2 command line for the Linux operating system in /etc/default/grub, in the manner below:

GRUB_CMDLINE_LINUX="crashkernel=auto rd.lvm.lv=VolGroup/LogVol06 rd.lvm.lv=VolGroup/lv_swap rhgb quiet rd.shell=0 audit=1 audit_backlog_limit=8192"

Rationale

audit_backlog_limit sets the queue length for audit events awaiting transfer to the audit daemon. Until the audit daemon is up and running, all log messages are stored in this queue. If the queue is overrun during boot process, the action defined by audit failure flag is taken.

Warnings
warning  The GRUB 2 configuration file, grub.cfg, is automatically updated each time a new kernel is installed. Note that any changes to /etc/default/grub require rebuilding the grub.cfg file. To update the GRUB 2 configuration file manually, use the
grub2-mkconfig -o
command as follows:
  • On BIOS-based machines, issue the following command as root:
    ~]# grub2-mkconfig -o /boot/grub2/grub.cfg
  • On UEFI-based machines, issue the following command as root:
    ~]# grub2-mkconfig -o /boot/efi/EFI/redhat/grub.cfg
Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

check forkernel command line parameters audit_backlog_limit=8192 in /boot/grub2/grubenv for all kernels  oval:ssg-test_grub2_audit_backlog_limit_argument_grub_env:tst:1  false

Following items have been found on the system:
PathContent
/boot/grub2/grubenvkernelopts=root=/dev/mapper/ovirt-root ro console=tty0 console=ttyS0 crashkernel=auto resume=/dev/mapper/ovirt-swap rd.lvm.lv=ovirt/root rd.lvm.lv=ovirt/swap
Disable SCTP Supportxccdf_org.ssgproject.content_rule_kernel_module_sctp_disabled mediumCCE-80834-5

Disable SCTP Support

Rule IDxccdf_org.ssgproject.content_rule_kernel_module_sctp_disabled
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-kernel_module_sctp_disabled:def:1
Time2020-09-29T11:21:06
Severitymedium
Identifiers and References

Identifiers:  CCE-80834-5

References:  3.5.2, 11, 14, 3, 9, 5.10.1, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS05.02, DSS05.05, DSS06.06, 3.4.6, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 7.6, A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, A.9.1.2, CM-7(a), CM-7(b), CM-6(a), PR.IP-1, PR.PT-3, SRG-OS-000095-GPOS-00049

Description

The Stream Control Transmission Protocol (SCTP) is a transport layer protocol, designed to support the idea of message-oriented communication, with several streams of messages within one connection. To configure the system to prevent the sctp kernel module from being loaded, add the following line to a file in the directory /etc/modprobe.d:

install sctp /bin/true

Rationale

Disabling SCTP protects the system against exploitation of any flaws in its implementation.

Evaluation messages
info 
Fix execution completed and returned: 0
info 
grep: /etc/modprobe.d/sctp.conf: No such file or directory
OVAL test results details

kernel module sctp disabled  oval:ssg-test_kernmod_sctp_disabled:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_sctp_disabled:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/modprobe.d^.*\.conf$^\s*install\s+sctp\s+(/bin/false|/bin/true)$1

kernel module sctp disabled in /etc/modprobe.conf  oval:ssg-test_kernmod_sctp_modprobeconf:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_sctp_modprobeconf:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/modprobe.conf^\s*install\s+sctp\s+(/bin/false|/bin/true)$1

kernel module sctp disabled in /etc/modules-load.d  oval:ssg-test_kernmod_sctp_etcmodules-load:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_sctp_etcmodules-load:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/modules-load.d^.*\.conf$^\s*install\s+sctp\s+(/bin/false|/bin/true)$1

kernel module sctp disabled in /run/modules-load.d  oval:ssg-test_kernmod_sctp_runmodules-load:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_sctp_runmodules-load:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/modules-load.d^.*\.conf$^\s*install\s+sctp\s+(/bin/false|/bin/true)$1

kernel module sctp disabled in /usr/lib/modules-load.d  oval:ssg-test_kernmod_sctp_libmodules-load:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_sctp_libmodules-load:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/modules-load.d^.*\.conf$^\s*install\s+sctp\s+(/bin/false|/bin/true)$1

kernel module sctp disabled in /run/modprobe.d  oval:ssg-test_kernmod_sctp_runmodprobed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_sctp_runmodprobed:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/modprobe.d^.*\.conf$^\s*install\s+sctp\s+(/bin/false|/bin/true)$1

kernel module sctp disabled in /usr/lib/modprobe.d  oval:ssg-test_kernmod_sctp_libmodprobed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_sctp_libmodprobed:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/modprobe.d^.*\.conf$^\s*install\s+sctp\s+(/bin/false|/bin/true)$1
Disable CAN Supportxccdf_org.ssgproject.content_rule_kernel_module_can_disabled mediumCCE-82059-7

Disable CAN Support

Rule IDxccdf_org.ssgproject.content_rule_kernel_module_can_disabled
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-kernel_module_can_disabled:def:1
Time2020-09-29T11:21:06
Severitymedium
Identifiers and References

Identifiers:  CCE-82059-7

References:  FMT_SMF_EXT.1, SRG-OS-000095-GPOS-00049

Description

The Controller Area Network (CAN) is a serial communications protocol which was initially developed for automotive and is now also used in marine, industrial, and medical applications. To configure the system to prevent the can kernel module from being loaded, add the following line to a file in the directory /etc/modprobe.d:

install can /bin/true

Rationale

Disabling CAN protects the system against exploitation of any flaws in its implementation.

Evaluation messages
info 
Fix execution completed and returned: 0
info 
grep: /etc/modprobe.d/can.conf: No such file or directory
OVAL test results details

kernel module can disabled  oval:ssg-test_kernmod_can_disabled:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_can_disabled:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/modprobe.d^.*\.conf$^\s*install\s+can\s+(/bin/false|/bin/true)$1

kernel module can disabled in /etc/modprobe.conf  oval:ssg-test_kernmod_can_modprobeconf:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_can_modprobeconf:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/modprobe.conf^\s*install\s+can\s+(/bin/false|/bin/true)$1

kernel module can disabled in /etc/modules-load.d  oval:ssg-test_kernmod_can_etcmodules-load:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_can_etcmodules-load:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/modules-load.d^.*\.conf$^\s*install\s+can\s+(/bin/false|/bin/true)$1

kernel module can disabled in /run/modules-load.d  oval:ssg-test_kernmod_can_runmodules-load:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_can_runmodules-load:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/modules-load.d^.*\.conf$^\s*install\s+can\s+(/bin/false|/bin/true)$1

kernel module can disabled in /usr/lib/modules-load.d  oval:ssg-test_kernmod_can_libmodules-load:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_can_libmodules-load:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/modules-load.d^.*\.conf$^\s*install\s+can\s+(/bin/false|/bin/true)$1

kernel module can disabled in /run/modprobe.d  oval:ssg-test_kernmod_can_runmodprobed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_can_runmodprobed:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/modprobe.d^.*\.conf$^\s*install\s+can\s+(/bin/false|/bin/true)$1

kernel module can disabled in /usr/lib/modprobe.d  oval:ssg-test_kernmod_can_libmodprobed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_can_libmodprobed:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/modprobe.d^.*\.conf$^\s*install\s+can\s+(/bin/false|/bin/true)$1
Disable TIPC Supportxccdf_org.ssgproject.content_rule_kernel_module_tipc_disabled mediumCCE-82297-3

Disable TIPC Support

Rule IDxccdf_org.ssgproject.content_rule_kernel_module_tipc_disabled
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-kernel_module_tipc_disabled:def:1
Time2020-09-29T11:21:06
Severitymedium
Identifiers and References

Identifiers:  CCE-82297-3

References:  11, 14, 3, 9, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS05.02, DSS05.05, DSS06.06, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 7.6, A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, A.9.1.2, CM-7(a), CM-7(b), CM-6(a), PR.IP-1, PR.PT-3, FMT_SMF_EXT.1, SRG-OS-000095-GPOS-00049

Description

The Transparent Inter-Process Communication (TIPC) protocol is designed to provide communications between nodes in a cluster. To configure the system to prevent the tipc kernel module from being loaded, add the following line to a file in the directory /etc/modprobe.d:

install tipc /bin/true

Rationale

Disabling TIPC protects the system against exploitation of any flaws in its implementation.

Warnings
warning  This configuration baseline was created to deploy the base operating system for general purpose workloads. When the operating system is configured for certain purposes, such as a node in High Performance Computing cluster, it is expected that the tipc kernel module will be loaded.
Evaluation messages
info 
Fix execution completed and returned: 0
info 
grep: /etc/modprobe.d/tipc.conf: No such file or directory
OVAL test results details

kernel module tipc disabled  oval:ssg-test_kernmod_tipc_disabled:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_tipc_disabled:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/modprobe.d^.*\.conf$^\s*install\s+tipc\s+(/bin/false|/bin/true)$1

kernel module tipc disabled in /etc/modprobe.conf  oval:ssg-test_kernmod_tipc_modprobeconf:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_tipc_modprobeconf:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/modprobe.conf^\s*install\s+tipc\s+(/bin/false|/bin/true)$1

kernel module tipc disabled in /etc/modules-load.d  oval:ssg-test_kernmod_tipc_etcmodules-load:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_tipc_etcmodules-load:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/modules-load.d^.*\.conf$^\s*install\s+tipc\s+(/bin/false|/bin/true)$1

kernel module tipc disabled in /run/modules-load.d  oval:ssg-test_kernmod_tipc_runmodules-load:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_tipc_runmodules-load:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/modules-load.d^.*\.conf$^\s*install\s+tipc\s+(/bin/false|/bin/true)$1

kernel module tipc disabled in /usr/lib/modules-load.d  oval:ssg-test_kernmod_tipc_libmodules-load:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_tipc_libmodules-load:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/modules-load.d^.*\.conf$^\s*install\s+tipc\s+(/bin/false|/bin/true)$1

kernel module tipc disabled in /run/modprobe.d  oval:ssg-test_kernmod_tipc_runmodprobed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_tipc_runmodprobed:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/modprobe.d^.*\.conf$^\s*install\s+tipc\s+(/bin/false|/bin/true)$1

kernel module tipc disabled in /usr/lib/modprobe.d  oval:ssg-test_kernmod_tipc_libmodprobed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_tipc_libmodprobed:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/modprobe.d^.*\.conf$^\s*install\s+tipc\s+(/bin/false|/bin/true)$1
Disable IEEE 1394 (FireWire) Supportxccdf_org.ssgproject.content_rule_kernel_module_firewire-core_disabled mediumCCE-82005-0

Disable IEEE 1394 (FireWire) Support

Rule IDxccdf_org.ssgproject.content_rule_kernel_module_firewire-core_disabled
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-kernel_module_firewire-core_disabled:def:1
Time2020-09-29T11:21:06
Severitymedium
Identifiers and References

Identifiers:  CCE-82005-0

References:  FMT_SMF_EXT.1, SRG-OS-000095-GPOS-00049

Description

The IEEE 1394 (FireWire) is a serial bus standard for high-speed real-time communication. To configure the system to prevent the firewire-core kernel module from being loaded, add the following line to a file in the directory /etc/modprobe.d:

install firewire-core /bin/true

Rationale

Disabling FireWire protects the system against exploitation of any flaws in its implementation.

Evaluation messages
info 
Fix execution completed and returned: 0
info 
grep: /etc/modprobe.d/firewire-core.conf: No such file or directory
OVAL test results details

kernel module firewire-core disabled  oval:ssg-test_kernmod_firewire-core_disabled:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_firewire-core_disabled:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/modprobe.d^.*\.conf$^\s*install\s+firewire-core\s+(/bin/false|/bin/true)$1

kernel module firewire-core disabled in /etc/modprobe.conf  oval:ssg-test_kernmod_firewire-core_modprobeconf:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_firewire-core_modprobeconf:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/modprobe.conf^\s*install\s+firewire-core\s+(/bin/false|/bin/true)$1

kernel module firewire-core disabled in /etc/modules-load.d  oval:ssg-test_kernmod_firewire-core_etcmodules-load:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_firewire-core_etcmodules-load:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/modules-load.d^.*\.conf$^\s*install\s+firewire-core\s+(/bin/false|/bin/true)$1

kernel module firewire-core disabled in /run/modules-load.d  oval:ssg-test_kernmod_firewire-core_runmodules-load:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_firewire-core_runmodules-load:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/modules-load.d^.*\.conf$^\s*install\s+firewire-core\s+(/bin/false|/bin/true)$1

kernel module firewire-core disabled in /usr/lib/modules-load.d  oval:ssg-test_kernmod_firewire-core_libmodules-load:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_firewire-core_libmodules-load:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/modules-load.d^.*\.conf$^\s*install\s+firewire-core\s+(/bin/false|/bin/true)$1

kernel module firewire-core disabled in /run/modprobe.d  oval:ssg-test_kernmod_firewire-core_runmodprobed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_firewire-core_runmodprobed:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/modprobe.d^.*\.conf$^\s*install\s+firewire-core\s+(/bin/false|/bin/true)$1

kernel module firewire-core disabled in /usr/lib/modprobe.d  oval:ssg-test_kernmod_firewire-core_libmodprobed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_firewire-core_libmodprobed:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/modprobe.d^.*\.conf$^\s*install\s+firewire-core\s+(/bin/false|/bin/true)$1
Disable ATM Supportxccdf_org.ssgproject.content_rule_kernel_module_atm_disabled mediumCCE-82028-2

Disable ATM Support

Rule IDxccdf_org.ssgproject.content_rule_kernel_module_atm_disabled
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-kernel_module_atm_disabled:def:1
Time2020-09-29T11:21:06
Severitymedium
Identifiers and References

Identifiers:  CCE-82028-2

References:  FMT_SMF_EXT.1, SRG-OS-000095-GPOS-00049

Description

The Asynchronous Transfer Mode (ATM) is a protocol operating on network, data link, and physical layers, based on virtual circuits and virtual paths. To configure the system to prevent the atm kernel module from being loaded, add the following line to a file in the directory /etc/modprobe.d:

install atm /bin/true

Rationale

Disabling ATM protects the system against exploitation of any flaws in its implementation.

Evaluation messages
info 
Fix execution completed and returned: 0
info 
grep: /etc/modprobe.d/atm.conf: No such file or directory
OVAL test results details

kernel module atm disabled  oval:ssg-test_kernmod_atm_disabled:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_atm_disabled:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/modprobe.d^.*\.conf$^\s*install\s+atm\s+(/bin/false|/bin/true)$1

kernel module atm disabled in /etc/modprobe.conf  oval:ssg-test_kernmod_atm_modprobeconf:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_atm_modprobeconf:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/modprobe.conf^\s*install\s+atm\s+(/bin/false|/bin/true)$1

kernel module atm disabled in /etc/modules-load.d  oval:ssg-test_kernmod_atm_etcmodules-load:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_atm_etcmodules-load:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/modules-load.d^.*\.conf$^\s*install\s+atm\s+(/bin/false|/bin/true)$1

kernel module atm disabled in /run/modules-load.d  oval:ssg-test_kernmod_atm_runmodules-load:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_atm_runmodules-load:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/modules-load.d^.*\.conf$^\s*install\s+atm\s+(/bin/false|/bin/true)$1

kernel module atm disabled in /usr/lib/modules-load.d  oval:ssg-test_kernmod_atm_libmodules-load:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_atm_libmodules-load:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/modules-load.d^.*\.conf$^\s*install\s+atm\s+(/bin/false|/bin/true)$1

kernel module atm disabled in /run/modprobe.d  oval:ssg-test_kernmod_atm_runmodprobed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_atm_runmodprobed:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/modprobe.d^.*\.conf$^\s*install\s+atm\s+(/bin/false|/bin/true)$1

kernel module atm disabled in /usr/lib/modprobe.d  oval:ssg-test_kernmod_atm_libmodprobed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_atm_libmodprobed:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/modprobe.d^.*\.conf$^\s*install\s+atm\s+(/bin/false|/bin/true)$1
Disable Accepting ICMP Redirects for All IPv6 Interfacesxccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_redirects mediumCCE-81009-3

Disable Accepting ICMP Redirects for All IPv6 Interfaces

Rule IDxccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_redirects
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_net_ipv6_conf_all_accept_redirects:def:1
Time2020-09-29T11:21:06
Severitymedium
Identifiers and References

Identifiers:  CCE-81009-3

References:  NT28(R22), 3.3.2, 11, 14, 3, 9, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS05.02, DSS05.05, DSS06.06, 3.1.20, CCI-001551, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 7.6, A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, A.9.1.2, CM-7(a), CM-7(b), CM-6(a), PR.IP-1, PR.PT-3, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the net.ipv6.conf.all.accept_redirects kernel parameter, run the following command:

$ sudo sysctl -w net.ipv6.conf.all.accept_redirects=0
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
net.ipv6.conf.all.accept_redirects = 0

Rationale

An illicit ICMP redirect message could result in a man-in-the-middle attack.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

net.ipv6.conf.all.disable_ipv6 static configuration  oval:ssg-test_static_sysctl_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

net.ipv6.conf.all.disable_ipv6 static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

net.ipv6.conf.all.disable_ipv6 static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

net.ipv6.conf.all.disable_ipv6 static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

kernel runtime parameter net.ipv6.conf.all.disable_ipv6 set to 1  oval:ssg-test_sysctl_runtime_net_ipv6_conf_all_disable_ipv6:tst:1  false

Following items have been found on the system:
NameValue
net.ipv6.conf.all.disable_ipv60

net.ipv6.conf.all.accept_redirects static configuration  oval:ssg-test_static_sysctl_net_ipv6_conf_all_accept_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv6_conf_all_accept_redirects:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf(?:^|.*\n)[^#]*net.ipv6.conf.all.accept_redirects[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv6.conf.all.accept_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv6_conf_all_accept_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv6_conf_all_accept_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv6.conf.all.accept_redirects[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv6.conf.all.accept_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv6_conf_all_accept_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv6_conf_all_accept_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv6.conf.all.accept_redirects[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv6.conf.all.accept_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv6_conf_all_accept_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv6_conf_all_accept_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv6.conf.all.accept_redirects[\s]*=[\s]*(\d+)[\s]*\n1

kernel runtime parameter net.ipv6.conf.all.accept_redirects set to the appropriate value  oval:ssg-test_sysctl_runtime_net_ipv6_conf_all_accept_redirects:tst:1  false

Following items have been found on the system:
NameValue
net.ipv6.conf.all.accept_redirects1
Disable Accepting Router Advertisements on all IPv6 Interfaces by Defaultxccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra unknownCCE-81007-7

Disable Accepting Router Advertisements on all IPv6 Interfaces by Default

Rule IDxccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_net_ipv6_conf_default_accept_ra:def:1
Time2020-09-29T11:21:06
Severityunknown
Identifiers and References

Identifiers:  CCE-81007-7

References:  3.3.1, 11, 14, 3, 9, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS05.02, DSS05.05, DSS06.06, 3.1.20, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 7.6, A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, A.9.1.2, CM-7(a), CM-7(b), CM-6(a), PR.IP-1, PR.PT-3, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the net.ipv6.conf.default.accept_ra kernel parameter, run the following command:

$ sudo sysctl -w net.ipv6.conf.default.accept_ra=0
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
net.ipv6.conf.default.accept_ra = 0

Rationale

An illicit router advertisement message could result in a man-in-the-middle attack.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

net.ipv6.conf.all.disable_ipv6 static configuration  oval:ssg-test_static_sysctl_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

net.ipv6.conf.all.disable_ipv6 static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

net.ipv6.conf.all.disable_ipv6 static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

net.ipv6.conf.all.disable_ipv6 static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

kernel runtime parameter net.ipv6.conf.all.disable_ipv6 set to 1  oval:ssg-test_sysctl_runtime_net_ipv6_conf_all_disable_ipv6:tst:1  false

Following items have been found on the system:
NameValue
net.ipv6.conf.all.disable_ipv60

net.ipv6.conf.default.accept_ra static configuration  oval:ssg-test_static_sysctl_net_ipv6_conf_default_accept_ra:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv6_conf_default_accept_ra:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf(?:^|.*\n)[^#]*net.ipv6.conf.default.accept_ra[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv6.conf.default.accept_ra static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv6_conf_default_accept_ra:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv6_conf_default_accept_ra:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv6.conf.default.accept_ra[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv6.conf.default.accept_ra static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv6_conf_default_accept_ra:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv6_conf_default_accept_ra:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv6.conf.default.accept_ra[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv6.conf.default.accept_ra static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv6_conf_default_accept_ra:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv6_conf_default_accept_ra:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv6.conf.default.accept_ra[\s]*=[\s]*(\d+)[\s]*\n1

kernel runtime parameter net.ipv6.conf.default.accept_ra set to the appropriate value  oval:ssg-test_sysctl_runtime_net_ipv6_conf_default_accept_ra:tst:1  false

Following items have been found on the system:
NameValue
net.ipv6.conf.default.accept_ra1
Configure Accepting Router Advertisements on All IPv6 Interfacesxccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra unknownCCE-81006-9

Configure Accepting Router Advertisements on All IPv6 Interfaces

Rule IDxccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_net_ipv6_conf_all_accept_ra:def:1
Time2020-09-29T11:21:07
Severityunknown
Identifiers and References

Identifiers:  CCE-81006-9

References:  3.3.1, 11, 14, 3, 9, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS05.02, DSS05.05, DSS06.06, 3.1.20, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 7.6, A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, A.9.1.2, CM-7(a), CM-7(b), CM-6(a), PR.IP-1, PR.PT-3, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the net.ipv6.conf.all.accept_ra kernel parameter, run the following command:

$ sudo sysctl -w net.ipv6.conf.all.accept_ra=0
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
net.ipv6.conf.all.accept_ra = 0

Rationale

An illicit router advertisement message could result in a man-in-the-middle attack.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

net.ipv6.conf.all.disable_ipv6 static configuration  oval:ssg-test_static_sysctl_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

net.ipv6.conf.all.disable_ipv6 static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

net.ipv6.conf.all.disable_ipv6 static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

net.ipv6.conf.all.disable_ipv6 static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

kernel runtime parameter net.ipv6.conf.all.disable_ipv6 set to 1  oval:ssg-test_sysctl_runtime_net_ipv6_conf_all_disable_ipv6:tst:1  false

Following items have been found on the system:
NameValue
net.ipv6.conf.all.disable_ipv60

net.ipv6.conf.all.accept_ra static configuration  oval:ssg-test_static_sysctl_net_ipv6_conf_all_accept_ra:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv6_conf_all_accept_ra:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf(?:^|.*\n)[^#]*net.ipv6.conf.all.accept_ra[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv6.conf.all.accept_ra static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv6_conf_all_accept_ra:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv6_conf_all_accept_ra:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv6.conf.all.accept_ra[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv6.conf.all.accept_ra static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv6_conf_all_accept_ra:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv6_conf_all_accept_ra:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv6.conf.all.accept_ra[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv6.conf.all.accept_ra static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv6_conf_all_accept_ra:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv6_conf_all_accept_ra:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv6.conf.all.accept_ra[\s]*=[\s]*(\d+)[\s]*\n1

kernel runtime parameter net.ipv6.conf.all.accept_ra set to the appropriate value  oval:ssg-test_sysctl_runtime_net_ipv6_conf_all_accept_ra:tst:1  false

Following items have been found on the system:
NameValue
net.ipv6.conf.all.accept_ra1
Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Defaultxccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_source_route mediumCCE-81015-0

Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default

Rule IDxccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_source_route
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_net_ipv6_conf_default_accept_source_route:def:1
Time2020-09-29T11:21:07
Severitymedium
Identifiers and References

Identifiers:  CCE-81015-0

References:  NT28(R22), 1, 12, 13, 14, 15, 16, 18, 4, 6, 8, 9, APO01.06, APO13.01, DSS01.05, DSS03.01, DSS05.02, DSS05.04, DSS05.07, DSS06.02, 3.1.20, CCI-000366, 4.2.3.4, 4.3.3.4, 4.4.3.3, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 7.1, SR 7.6, A.10.1.1, A.11.1.4, A.11.1.5, A.11.2.1, A.12.1.1, A.12.1.2, A.13.1.1, A.13.1.2, A.13.1.3, A.13.2.1, A.13.2.2, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3, A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, CM-7(a), CM-7(b), CM-6(a), DE.AE-1, ID.AM-3, PR.AC-5, PR.DS-5, PR.PT-4, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the net.ipv6.conf.default.accept_source_route kernel parameter, run the following command:

$ sudo sysctl -w net.ipv6.conf.default.accept_source_route=0
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
net.ipv6.conf.default.accept_source_route = 0

Rationale

Source-routed packets allow the source of the packet to suggest routers forward the packet along a different path than configured on the router, which can be used to bypass network security measures. This requirement applies only to the forwarding of source-routerd traffic, such as when IPv6 forwarding is enabled and the system is functioning as a router. Accepting source-routed packets in the IPv6 protocol has few legitimate uses. It should be disabled unless it is absolutely required.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

net.ipv6.conf.all.disable_ipv6 static configuration  oval:ssg-test_static_sysctl_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

net.ipv6.conf.all.disable_ipv6 static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

net.ipv6.conf.all.disable_ipv6 static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

net.ipv6.conf.all.disable_ipv6 static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

kernel runtime parameter net.ipv6.conf.all.disable_ipv6 set to 1  oval:ssg-test_sysctl_runtime_net_ipv6_conf_all_disable_ipv6:tst:1  false

Following items have been found on the system:
NameValue
net.ipv6.conf.all.disable_ipv60

net.ipv6.conf.default.accept_source_route static configuration  oval:ssg-test_static_sysctl_net_ipv6_conf_default_accept_source_route:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv6_conf_default_accept_source_route:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf(?:^|.*\n)[^#]*net.ipv6.conf.default.accept_source_route[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv6.conf.default.accept_source_route static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv6_conf_default_accept_source_route:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv6_conf_default_accept_source_route:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv6.conf.default.accept_source_route[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv6.conf.default.accept_source_route static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv6_conf_default_accept_source_route:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv6_conf_default_accept_source_route:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv6.conf.default.accept_source_route[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv6.conf.default.accept_source_route static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv6_conf_default_accept_source_route:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv6_conf_default_accept_source_route:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv6.conf.default.accept_source_route[\s]*=[\s]*(\d+)[\s]*\n1

kernel runtime parameter net.ipv6.conf.default.accept_source_route set to the appropriate value  oval:ssg-test_sysctl_runtime_net_ipv6_conf_default_accept_source_route:tst:1  true

Following items have been found on the system:
NameValue
net.ipv6.conf.default.accept_source_route0
Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfacesxccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_redirects mediumCCE-81010-1

Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces

Rule IDxccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_redirects
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_net_ipv6_conf_default_accept_redirects:def:1
Time2020-09-29T11:21:07
Severitymedium
Identifiers and References

Identifiers:  CCE-81010-1

References:  NT28(R22), 3.3.2, 11, 14, 3, 9, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS05.02, DSS05.05, DSS06.06, 3.1.20, CCI-001551, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 7.6, A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, A.9.1.2, CM-7(a), CM-7(b), CM-6(a), PR.IP-1, PR.PT-3, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the net.ipv6.conf.default.accept_redirects kernel parameter, run the following command:

$ sudo sysctl -w net.ipv6.conf.default.accept_redirects=0
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
net.ipv6.conf.default.accept_redirects = 0

Rationale

An illicit ICMP redirect message could result in a man-in-the-middle attack.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

net.ipv6.conf.all.disable_ipv6 static configuration  oval:ssg-test_static_sysctl_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

net.ipv6.conf.all.disable_ipv6 static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

net.ipv6.conf.all.disable_ipv6 static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

net.ipv6.conf.all.disable_ipv6 static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

kernel runtime parameter net.ipv6.conf.all.disable_ipv6 set to 1  oval:ssg-test_sysctl_runtime_net_ipv6_conf_all_disable_ipv6:tst:1  false

Following items have been found on the system:
NameValue
net.ipv6.conf.all.disable_ipv60

net.ipv6.conf.default.accept_redirects static configuration  oval:ssg-test_static_sysctl_net_ipv6_conf_default_accept_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv6_conf_default_accept_redirects:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf(?:^|.*\n)[^#]*net.ipv6.conf.default.accept_redirects[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv6.conf.default.accept_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv6_conf_default_accept_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv6_conf_default_accept_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv6.conf.default.accept_redirects[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv6.conf.default.accept_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv6_conf_default_accept_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv6_conf_default_accept_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv6.conf.default.accept_redirects[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv6.conf.default.accept_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv6_conf_default_accept_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv6_conf_default_accept_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv6.conf.default.accept_redirects[\s]*=[\s]*(\d+)[\s]*\n1

kernel runtime parameter net.ipv6.conf.default.accept_redirects set to the appropriate value  oval:ssg-test_sysctl_runtime_net_ipv6_conf_default_accept_redirects:tst:1  false

Following items have been found on the system:
NameValue
net.ipv6.conf.default.accept_redirects1
Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfacesxccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_source_route mediumCCE-81013-5

Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces

Rule IDxccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_source_route
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_net_ipv6_conf_all_accept_source_route:def:1
Time2020-09-29T11:21:07
Severitymedium
Identifiers and References

Identifiers:  CCE-81013-5

References:  NT28(R22), 1, 12, 13, 14, 15, 16, 18, 4, 6, 8, 9, APO01.06, APO13.01, DSS01.05, DSS03.01, DSS05.02, DSS05.04, DSS05.07, DSS06.02, 3.1.20, CCI-000366, 4.2.3.4, 4.3.3.4, 4.4.3.3, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 7.1, SR 7.6, A.10.1.1, A.11.1.4, A.11.1.5, A.11.2.1, A.12.1.1, A.12.1.2, A.13.1.1, A.13.1.2, A.13.1.3, A.13.2.1, A.13.2.2, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3, A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, CM-7(a), CM-7(b), CM-6(a), DE.AE-1, ID.AM-3, PR.AC-5, PR.DS-5, PR.PT-4, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the net.ipv6.conf.all.accept_source_route kernel parameter, run the following command:

$ sudo sysctl -w net.ipv6.conf.all.accept_source_route=0
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
net.ipv6.conf.all.accept_source_route = 0

Rationale

Source-routed packets allow the source of the packet to suggest routers forward the packet along a different path than configured on the router, which can be used to bypass network security measures. This requirement applies only to the forwarding of source-routerd traffic, such as when IPv6 forwarding is enabled and the system is functioning as a router.

Accepting source-routed packets in the IPv6 protocol has few legitimate uses. It should be disabled unless it is absolutely required.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

net.ipv6.conf.all.disable_ipv6 static configuration  oval:ssg-test_static_sysctl_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

net.ipv6.conf.all.disable_ipv6 static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

net.ipv6.conf.all.disable_ipv6 static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

net.ipv6.conf.all.disable_ipv6 static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv6_conf_all_disable_ipv6:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv6_conf_all_disable_ipv6:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*1[\s]*$1

kernel runtime parameter net.ipv6.conf.all.disable_ipv6 set to 1  oval:ssg-test_sysctl_runtime_net_ipv6_conf_all_disable_ipv6:tst:1  false

Following items have been found on the system:
NameValue
net.ipv6.conf.all.disable_ipv60

net.ipv6.conf.all.accept_source_route static configuration  oval:ssg-test_static_sysctl_net_ipv6_conf_all_accept_source_route:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv6_conf_all_accept_source_route:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf(?:^|.*\n)[^#]*net.ipv6.conf.all.accept_source_route[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv6.conf.all.accept_source_route static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv6_conf_all_accept_source_route:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv6_conf_all_accept_source_route:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv6.conf.all.accept_source_route[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv6.conf.all.accept_source_route static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv6_conf_all_accept_source_route:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv6_conf_all_accept_source_route:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv6.conf.all.accept_source_route[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv6.conf.all.accept_source_route static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv6_conf_all_accept_source_route:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv6_conf_all_accept_source_route:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv6.conf.all.accept_source_route[\s]*=[\s]*(\d+)[\s]*\n1

kernel runtime parameter net.ipv6.conf.all.accept_source_route set to the appropriate value  oval:ssg-test_sysctl_runtime_net_ipv6_conf_all_accept_source_route:tst:1  true

Following items have been found on the system:
NameValue
net.ipv6.conf.all.accept_source_route0
Install iptables Packagexccdf_org.ssgproject.content_rule_package_iptables_installed mediumCCE-82982-0

Install iptables Package

Rule IDxccdf_org.ssgproject.content_rule_package_iptables_installed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_iptables_installed:def:1
Time2020-09-29T11:18:02
Severitymedium
Identifiers and References

Identifiers:  CCE-82982-0

References:  CM-6(a), SRG-OS-000480-GPOS-00227

Description

The iptables package can be installed with the following command:

$ sudo yum install iptables

Rationale

iptables controls the Linux kernel network packet filtering code. iptables allows system operators to set up firewalls and IP masquerading, etc.

OVAL test results details

package iptables is installed  oval:ssg-test_package_iptables_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
iptablesx86_64(none)10.el81.8.40:1.8.4-10.el8199e2f91fd431d51iptables-0:1.8.4-10.el8.x86_64
Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Defaultxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_rp_filter mediumCCE-81022-6

Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default

Rule IDxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_rp_filter
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_net_ipv4_conf_default_rp_filter:def:1
Time2020-09-29T11:21:07
Severitymedium
Identifiers and References

Identifiers:  CCE-81022-6

References:  NT28(R22), 3.2.7, 1, 12, 13, 14, 15, 16, 18, 2, 4, 6, 7, 8, 9, APO01.06, APO13.01, BAI04.04, DSS01.03, DSS01.05, DSS03.01, DSS03.05, DSS05.02, DSS05.04, DSS05.07, DSS06.02, 3.1.20, 4.2.3.4, 4.3.3.4, 4.4.3.3, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 6.2, SR 7.1, SR 7.2, SR 7.6, A.10.1.1, A.11.1.4, A.11.1.5, A.11.2.1, A.12.1.1, A.12.1.2, A.12.1.3, A.13.1.1, A.13.1.2, A.13.1.3, A.13.2.1, A.13.2.2, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3, A.17.2.1, A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, CM-7(a), CM-7(b), CM-6(a), SC-7(a), DE.AE-1, DE.CM-1, ID.AM-3, PR.AC-5, PR.DS-4, PR.DS-5, PR.PT-4, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the net.ipv4.conf.default.rp_filter kernel parameter, run the following command:

$ sudo sysctl -w net.ipv4.conf.default.rp_filter=1
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
net.ipv4.conf.default.rp_filter = 1

Rationale

Enabling reverse path filtering drops packets with source addresses that should not have been able to be received on the interface they were received on. It should not be used on systems which are routers for complicated networks, but is helpful for end hosts and routers serving small networks.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

net.ipv4.conf.default.rp_filter static configuration  oval:ssg-test_static_sysctl_net_ipv4_conf_default_rp_filter:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv4_conf_default_rp_filter:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf(?:^|.*\n)[^#]*net.ipv4.conf.default.rp_filter[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.default.rp_filter static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv4_conf_default_rp_filter:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv4_conf_default_rp_filter:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.default.rp_filter[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.default.rp_filter static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv4_conf_default_rp_filter:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv4_conf_default_rp_filter:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.default.rp_filter[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.default.rp_filter static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv4_conf_default_rp_filter:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv4_conf_default_rp_filter:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.default.rp_filter[\s]*=[\s]*(\d+)[\s]*\n1

kernel runtime parameter net.ipv4.conf.default.rp_filter set to the appropriate value  oval:ssg-test_sysctl_runtime_net_ipv4_conf_default_rp_filter:tst:1  false

Following items have been found on the system:
NameValue
net.ipv4.conf.default.rp_filter0
Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Defaultxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_log_martians unknownCCE-81020-0

Enable Kernel Paremeter to Log Martian Packets on all IPv4 Interfaces by Default

Rule IDxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_log_martians
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_net_ipv4_conf_default_log_martians:def:1
Time2020-09-29T11:21:07
Severityunknown
Identifiers and References

Identifiers:  CCE-81020-0

References:  3.2.4, 1, 11, 12, 13, 14, 15, 16, 2, 3, 7, 8, 9, APO13.01, BAI04.04, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS01.03, DSS01.04, DSS03.05, DSS05.02, DSS05.03, DSS05.05, DSS05.07, DSS06.06, 3.1.20, CCI-000126, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 6.2, SR 7.1, SR 7.2, SR 7.6, A.11.2.6, A.12.1.2, A.12.1.3, A.12.5.1, A.12.6.2, A.13.1.1, A.13.2.1, A.14.1.3, A.14.2.2, A.14.2.3, A.14.2.4, A.17.2.1, A.6.2.1, A.6.2.2, A.9.1.2, CM-7(a), CM-7(b), SC-5(3)(a), DE.CM-1, PR.AC-3, PR.DS-4, PR.IP-1, PR.PT-3, PR.PT-4, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the net.ipv4.conf.default.log_martians kernel parameter, run the following command:

$ sudo sysctl -w net.ipv4.conf.default.log_martians=1
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
net.ipv4.conf.default.log_martians = 1

Rationale

The presence of "martian" packets (which have impossible addresses) as well as spoofed packets, source-routed packets, and redirects could be a sign of nefarious network activity. Logging these packets enables this activity to be detected.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

net.ipv4.conf.default.log_martians static configuration  oval:ssg-test_static_sysctl_net_ipv4_conf_default_log_martians:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv4_conf_default_log_martians:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf(?:^|.*\n)[^#]*net.ipv4.conf.default.log_martians[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.default.log_martians static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv4_conf_default_log_martians:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv4_conf_default_log_martians:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.default.log_martians[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.default.log_martians static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv4_conf_default_log_martians:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv4_conf_default_log_martians:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.default.log_martians[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.default.log_martians static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv4_conf_default_log_martians:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv4_conf_default_log_martians:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.default.log_martians[\s]*=[\s]*(\d+)[\s]*\n1

kernel runtime parameter net.ipv4.conf.default.log_martians set to the appropriate value  oval:ssg-test_sysctl_runtime_net_ipv4_conf_default_log_martians:tst:1  false

Following items have been found on the system:
NameValue
net.ipv4.conf.default.log_martians0
Disable Accepting ICMP Redirects for All IPv4 Interfacesxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_redirects mediumCCE-80917-8

Disable Accepting ICMP Redirects for All IPv4 Interfaces

Rule IDxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_redirects
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_net_ipv4_conf_all_accept_redirects:def:1
Time2020-09-29T11:21:07
Severitymedium
Identifiers and References

Identifiers:  CCE-80917-8

References:  NT28(R22), 3.2.2, 1, 11, 12, 13, 14, 15, 16, 2, 3, 7, 8, 9, 5.10.1.1, APO13.01, BAI04.04, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS01.03, DSS03.05, DSS05.02, DSS05.05, DSS05.07, DSS06.06, 3.1.20, CCI-000366, CCI-001503, CCI-001551, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 6.2, SR 7.1, SR 7.2, SR 7.6, A.12.1.2, A.12.1.3, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, A.17.2.1, A.9.1.2, CM-7(a), CM-7(b), CM-6(a), SC-7(a), DE.CM-1, PR.DS-4, PR.IP-1, PR.PT-3, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the net.ipv4.conf.all.accept_redirects kernel parameter, run the following command:

$ sudo sysctl -w net.ipv4.conf.all.accept_redirects=0
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
net.ipv4.conf.all.accept_redirects = 0

Rationale

ICMP redirect messages are used by routers to inform hosts that a more direct route exists for a particular destination. These messages modify the host's route table and are unauthenticated. An illicit ICMP redirect message could result in a man-in-the-middle attack.
This feature of the IPv4 protocol has few legitimate uses. It should be disabled unless absolutely required."

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

net.ipv4.conf.all.accept_redirects static configuration  oval:ssg-test_static_sysctl_net_ipv4_conf_all_accept_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv4_conf_all_accept_redirects:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf(?:^|.*\n)[^#]*net.ipv4.conf.all.accept_redirects[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.all.accept_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv4_conf_all_accept_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv4_conf_all_accept_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.all.accept_redirects[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.all.accept_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv4_conf_all_accept_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv4_conf_all_accept_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.all.accept_redirects[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.all.accept_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv4_conf_all_accept_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv4_conf_all_accept_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.all.accept_redirects[\s]*=[\s]*(\d+)[\s]*\n1

kernel runtime parameter net.ipv4.conf.all.accept_redirects set to the appropriate value  oval:ssg-test_sysctl_runtime_net_ipv4_conf_all_accept_redirects:tst:1  false

Following items have been found on the system:
NameValue
net.ipv4.conf.all.accept_redirects1
Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfacesxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_echo_ignore_broadcasts mediumCCE-80922-8

Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces

Rule IDxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_echo_ignore_broadcasts
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts:def:1
Time2020-09-29T11:21:07
Severitymedium
Identifiers and References

Identifiers:  CCE-80922-8

References:  3.2.5, 1, 11, 12, 13, 14, 15, 16, 18, 2, 3, 4, 6, 7, 8, 9, 5.10.1.1, APO01.06, APO13.01, BAI04.04, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS01.03, DSS01.05, DSS03.01, DSS03.05, DSS05.02, DSS05.04, DSS05.05, DSS05.07, DSS06.02, DSS06.06, 3.1.20, CCI-000366, 4.2.3.4, 4.3.3.4, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, 4.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 6.2, SR 7.1, SR 7.2, SR 7.6, A.10.1.1, A.11.1.4, A.11.1.5, A.11.2.1, A.12.1.1, A.12.1.2, A.12.1.3, A.12.5.1, A.12.6.2, A.13.1.1, A.13.1.2, A.13.1.3, A.13.2.1, A.13.2.2, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3, A.14.2.2, A.14.2.3, A.14.2.4, A.17.2.1, A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, CM-7(a), CM-7(b), SC-5, DE.AE-1, DE.CM-1, ID.AM-3, PR.AC-5, PR.DS-4, PR.DS-5, PR.IP-1, PR.PT-3, PR.PT-4, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the net.ipv4.icmp_echo_ignore_broadcasts kernel parameter, run the following command:

$ sudo sysctl -w net.ipv4.icmp_echo_ignore_broadcasts=1
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
net.ipv4.icmp_echo_ignore_broadcasts = 1

Rationale

Responding to broadcast (ICMP) echoes facilitates network mapping and provides a vector for amplification attacks.
Ignoring ICMP echo requests (pings) sent to broadcast or multicast addresses makes the system slightly more difficult to enumerate on the network.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

net.ipv4.icmp_echo_ignore_broadcasts static configuration  oval:ssg-test_static_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf(?:^|.*\n)[^#]*net.ipv4.icmp_echo_ignore_broadcasts[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.icmp_echo_ignore_broadcasts static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv4_icmp_echo_ignore_broadcasts:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv4_icmp_echo_ignore_broadcasts:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.icmp_echo_ignore_broadcasts[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.icmp_echo_ignore_broadcasts static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv4_icmp_echo_ignore_broadcasts:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv4_icmp_echo_ignore_broadcasts:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.icmp_echo_ignore_broadcasts[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.icmp_echo_ignore_broadcasts static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv4_icmp_echo_ignore_broadcasts:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv4_icmp_echo_ignore_broadcasts:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.icmp_echo_ignore_broadcasts[\s]*=[\s]*(\d+)[\s]*\n1

kernel runtime parameter net.ipv4.icmp_echo_ignore_broadcasts set to the appropriate value  oval:ssg-test_sysctl_runtime_net_ipv4_icmp_echo_ignore_broadcasts:tst:1  true

Following items have been found on the system:
NameValue
net.ipv4.icmp_echo_ignore_broadcasts1
Enable Kernel Parameter to Use TCP Syncookies on IPv4 Interfacesxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_tcp_syncookies mediumCCE-80923-6

Enable Kernel Parameter to Use TCP Syncookies on IPv4 Interfaces

Rule IDxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_tcp_syncookies
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_net_ipv4_tcp_syncookies:def:1
Time2020-09-29T11:21:07
Severitymedium
Identifiers and References

Identifiers:  CCE-80923-6

References:  NT28(R22), 3.2.8, 1, 12, 13, 14, 15, 16, 18, 2, 4, 6, 7, 8, 9, 5.10.1.1, APO01.06, APO13.01, BAI04.04, DSS01.03, DSS01.05, DSS03.01, DSS03.05, DSS05.02, DSS05.04, DSS05.07, DSS06.02, 3.1.20, CCI-000366, 4.2.3.4, 4.3.3.4, 4.4.3.3, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 6.2, SR 7.1, SR 7.2, SR 7.6, A.10.1.1, A.11.1.4, A.11.1.5, A.11.2.1, A.12.1.1, A.12.1.2, A.12.1.3, A.13.1.1, A.13.1.2, A.13.1.3, A.13.2.1, A.13.2.2, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3, A.17.2.1, A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, CM-7(a), CM-7(b), SC-5(1), SC-5(2), SC-5(3)(a), CM-6(a), DE.AE-1, DE.CM-1, ID.AM-3, PR.AC-5, PR.DS-4, PR.DS-5, PR.PT-4, SRG-OS-000480-GPOS-00227, SRG-OS-000420-GPOS-00186, SRG-OS-000142-GPOS-00071

Description

To set the runtime status of the net.ipv4.tcp_syncookies kernel parameter, run the following command:

$ sudo sysctl -w net.ipv4.tcp_syncookies=1
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
net.ipv4.tcp_syncookies = 1

Rationale

A TCP SYN flood attack can cause a denial of service by filling a system's TCP connection table with connections in the SYN_RCVD state. Syncookies can be used to track a connection when a subsequent ACK is received, verifying the initiator is attempting a valid connection and is not a flood source. This feature is activated when a flood condition is detected, and enables the system to continue servicing valid connection requests.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

net.ipv4.tcp_syncookies static configuration  oval:ssg-test_static_sysctl_net_ipv4_tcp_syncookies:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv4_tcp_syncookies:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf(?:^|.*\n)[^#]*net.ipv4.tcp_syncookies[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.tcp_syncookies static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv4_tcp_syncookies:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv4_tcp_syncookies:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.tcp_syncookies[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.tcp_syncookies static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv4_tcp_syncookies:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv4_tcp_syncookies:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.tcp_syncookies[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.tcp_syncookies static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv4_tcp_syncookies:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv4_tcp_syncookies:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.tcp_syncookies[\s]*=[\s]*(\d+)[\s]*\n1

kernel runtime parameter net.ipv4.tcp_syncookies set to the appropriate value  oval:ssg-test_sysctl_runtime_net_ipv4_tcp_syncookies:tst:1  true

Following items have been found on the system:
NameValue
net.ipv4.tcp_syncookies1
Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Defaultxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_source_route mediumCCE-80920-2

Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default

Rule IDxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_source_route
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_net_ipv4_conf_default_accept_source_route:def:1
Time2020-09-29T11:21:07
Severitymedium
Identifiers and References

Identifiers:  CCE-80920-2

References:  NT28(R22), 3.2.1, 1, 11, 12, 13, 14, 15, 16, 18, 2, 3, 4, 6, 7, 8, 9, 5.10.1.1, APO01.06, APO13.01, BAI04.04, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS01.03, DSS01.05, DSS03.01, DSS03.05, DSS05.02, DSS05.04, DSS05.05, DSS05.07, DSS06.02, DSS06.06, 3.1.20, CCI-000366, CCI-001551, 4.2.3.4, 4.3.3.4, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, 4.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 6.2, SR 7.1, SR 7.2, SR 7.6, A.10.1.1, A.11.1.4, A.11.1.5, A.11.2.1, A.12.1.1, A.12.1.2, A.12.1.3, A.12.5.1, A.12.6.2, A.13.1.1, A.13.1.2, A.13.1.3, A.13.2.1, A.13.2.2, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3, A.14.2.2, A.14.2.3, A.14.2.4, A.17.2.1, A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, CM-7(a), CM-7(b), SC-5, SC-7(a), DE.AE-1, DE.CM-1, ID.AM-3, PR.AC-5, PR.DS-4, PR.DS-5, PR.IP-1, PR.PT-3, PR.PT-4, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the net.ipv4.conf.default.accept_source_route kernel parameter, run the following command:

$ sudo sysctl -w net.ipv4.conf.default.accept_source_route=0
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
net.ipv4.conf.default.accept_source_route = 0

Rationale

Source-routed packets allow the source of the packet to suggest routers forward the packet along a different path than configured on the router, which can be used to bypass network security measures.
Accepting source-routed packets in the IPv4 protocol has few legitimate uses. It should be disabled unless it is absolutely required, such as when IPv4 forwarding is enabled and the system is legitimately functioning as a router.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

net.ipv4.conf.default.accept_source_route static configuration  oval:ssg-test_static_sysctl_net_ipv4_conf_default_accept_source_route:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv4_conf_default_accept_source_route:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf(?:^|.*\n)[^#]*net.ipv4.conf.default.accept_source_route[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.default.accept_source_route static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv4_conf_default_accept_source_route:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv4_conf_default_accept_source_route:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.default.accept_source_route[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.default.accept_source_route static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv4_conf_default_accept_source_route:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv4_conf_default_accept_source_route:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.default.accept_source_route[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.default.accept_source_route static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv4_conf_default_accept_source_route:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv4_conf_default_accept_source_route:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.default.accept_source_route[\s]*=[\s]*(\d+)[\s]*\n1

kernel runtime parameter net.ipv4.conf.default.accept_source_route set to the appropriate value  oval:ssg-test_sysctl_runtime_net_ipv4_conf_default_accept_source_route:tst:1  false

Following items have been found on the system:
NameValue
net.ipv4.conf.default.accept_source_route1
Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfacesxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_rp_filter mediumCCE-81021-8

Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces

Rule IDxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_rp_filter
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_net_ipv4_conf_all_rp_filter:def:1
Time2020-09-29T11:18:02
Severitymedium
Identifiers and References

Identifiers:  CCE-81021-8

References:  NT28(R22), 3.2.7, 1, 12, 13, 14, 15, 16, 18, 2, 4, 6, 7, 8, 9, APO01.06, APO13.01, BAI04.04, DSS01.03, DSS01.05, DSS03.01, DSS03.05, DSS05.02, DSS05.04, DSS05.07, DSS06.02, 3.1.20, CCI-001551, 4.2.3.4, 4.3.3.4, 4.4.3.3, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 6.2, SR 7.1, SR 7.2, SR 7.6, A.10.1.1, A.11.1.4, A.11.1.5, A.11.2.1, A.12.1.1, A.12.1.2, A.12.1.3, A.13.1.1, A.13.1.2, A.13.1.3, A.13.2.1, A.13.2.2, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3, A.17.2.1, A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, CM-7(a), CM-7(b), CM-6(a), SC-7(a), DE.AE-1, DE.CM-1, ID.AM-3, PR.AC-5, PR.DS-4, PR.DS-5, PR.PT-4, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the net.ipv4.conf.all.rp_filter kernel parameter, run the following command:

$ sudo sysctl -w net.ipv4.conf.all.rp_filter=1
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
net.ipv4.conf.all.rp_filter = 1

Rationale

Enabling reverse path filtering drops packets with source addresses that should not have been able to be received on the interface they were received on. It should not be used on systems which are routers for complicated networks, but is helpful for end hosts and routers serving small networks.

OVAL test results details

net.ipv4.conf.all.rp_filter static configuration  oval:ssg-test_static_sysctl_net_ipv4_conf_all_rp_filter:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv4_conf_all_rp_filter:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf(?:^|.*\n)[^#]*net.ipv4.conf.all.rp_filter[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.all.rp_filter static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv4_conf_all_rp_filter:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv4_conf_all_rp_filter:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.all.rp_filter[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.all.rp_filter static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv4_conf_all_rp_filter:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv4_conf_all_rp_filter:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.all.rp_filter[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.all.rp_filter static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv4_conf_all_rp_filter:tst:1  true

Following items have been found on the system:
PathContent
/usr/lib/sysctl.d/50-default.conf# Source route verification net.ipv4.conf.all.rp_filter = 1

kernel runtime parameter net.ipv4.conf.all.rp_filter set to the appropriate value  oval:ssg-test_sysctl_runtime_net_ipv4_conf_all_rp_filter:tst:1  true

Following items have been found on the system:
NameValue
net.ipv4.conf.all.rp_filter1
Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfacesxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_log_martians unknownCCE-81018-4

Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces

Rule IDxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_log_martians
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_net_ipv4_conf_all_log_martians:def:1
Time2020-09-29T11:21:07
Severityunknown
Identifiers and References

Identifiers:  CCE-81018-4

References:  NT28(R22), 3.2.4, 1, 11, 12, 13, 14, 15, 16, 2, 3, 7, 8, 9, APO13.01, BAI04.04, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS01.03, DSS01.04, DSS03.05, DSS05.02, DSS05.03, DSS05.05, DSS05.07, DSS06.06, 3.1.20, CCI-000126, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 6.2, SR 7.1, SR 7.2, SR 7.6, A.11.2.6, A.12.1.2, A.12.1.3, A.12.5.1, A.12.6.2, A.13.1.1, A.13.2.1, A.14.1.3, A.14.2.2, A.14.2.3, A.14.2.4, A.17.2.1, A.6.2.1, A.6.2.2, A.9.1.2, CM-7(a), CM-7(b), SC-5(3)(a), DE.CM-1, PR.AC-3, PR.DS-4, PR.IP-1, PR.PT-3, PR.PT-4, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the net.ipv4.conf.all.log_martians kernel parameter, run the following command:

$ sudo sysctl -w net.ipv4.conf.all.log_martians=1
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
net.ipv4.conf.all.log_martians = 1

Rationale

The presence of "martian" packets (which have impossible addresses) as well as spoofed packets, source-routed packets, and redirects could be a sign of nefarious network activity. Logging these packets enables this activity to be detected.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

net.ipv4.conf.all.log_martians static configuration  oval:ssg-test_static_sysctl_net_ipv4_conf_all_log_martians:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv4_conf_all_log_martians:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf(?:^|.*\n)[^#]*net.ipv4.conf.all.log_martians[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.all.log_martians static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv4_conf_all_log_martians:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv4_conf_all_log_martians:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.all.log_martians[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.all.log_martians static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv4_conf_all_log_martians:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv4_conf_all_log_martians:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.all.log_martians[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.all.log_martians static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv4_conf_all_log_martians:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv4_conf_all_log_martians:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.all.log_martians[\s]*=[\s]*(\d+)[\s]*\n1

kernel runtime parameter net.ipv4.conf.all.log_martians set to the appropriate value  oval:ssg-test_sysctl_runtime_net_ipv4_conf_all_log_martians:tst:1  false

Following items have been found on the system:
NameValue
net.ipv4.conf.all.log_martians0
Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfacesxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_source_route mediumCCE-81011-9

Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces

Rule IDxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_source_route
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_net_ipv4_conf_all_accept_source_route:def:1
Time2020-09-29T11:18:02
Severitymedium
Identifiers and References

Identifiers:  CCE-81011-9

References:  NT28(R22), 3.2.1, 1, 11, 12, 13, 14, 15, 16, 18, 2, 3, 4, 6, 7, 8, 9, APO01.06, APO13.01, BAI04.04, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS01.03, DSS01.05, DSS03.01, DSS03.05, DSS05.02, DSS05.04, DSS05.05, DSS05.07, DSS06.02, DSS06.06, 3.1.20, CCI-000366, 4.2.3.4, 4.3.3.4, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, 4.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 6.2, SR 7.1, SR 7.2, SR 7.6, A.10.1.1, A.11.1.4, A.11.1.5, A.11.2.1, A.12.1.1, A.12.1.2, A.12.1.3, A.12.5.1, A.12.6.2, A.13.1.1, A.13.1.2, A.13.1.3, A.13.2.1, A.13.2.2, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3, A.14.2.2, A.14.2.3, A.14.2.4, A.17.2.1, A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, CM-7(a), CM-7(b), SC-5CM-6(a), SC-7(a), DE.AE-1, DE.CM-1, ID.AM-3, PR.AC-5, PR.DS-4, PR.DS-5, PR.IP-1, PR.PT-3, PR.PT-4, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the net.ipv4.conf.all.accept_source_route kernel parameter, run the following command:

$ sudo sysctl -w net.ipv4.conf.all.accept_source_route=0
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
net.ipv4.conf.all.accept_source_route = 0

Rationale

Source-routed packets allow the source of the packet to suggest routers forward the packet along a different path than configured on the router, which can be used to bypass network security measures. This requirement applies only to the forwarding of source-routerd traffic, such as when IPv4 forwarding is enabled and the system is functioning as a router.

Accepting source-routed packets in the IPv4 protocol has few legitimate uses. It should be disabled unless it is absolutely required.

OVAL test results details

net.ipv4.conf.all.accept_source_route static configuration  oval:ssg-test_static_sysctl_net_ipv4_conf_all_accept_source_route:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv4_conf_all_accept_source_route:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf(?:^|.*\n)[^#]*net.ipv4.conf.all.accept_source_route[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.all.accept_source_route static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv4_conf_all_accept_source_route:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv4_conf_all_accept_source_route:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.all.accept_source_route[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.all.accept_source_route static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv4_conf_all_accept_source_route:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv4_conf_all_accept_source_route:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.all.accept_source_route[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.all.accept_source_route static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv4_conf_all_accept_source_route:tst:1  true

Following items have been found on the system:
PathContent
/usr/lib/sysctl.d/50-default.conf# Do not accept source routing net.ipv4.conf.all.accept_source_route = 0

kernel runtime parameter net.ipv4.conf.all.accept_source_route set to the appropriate value  oval:ssg-test_sysctl_runtime_net_ipv4_conf_all_accept_source_route:tst:1  true

Following items have been found on the system:
NameValue
net.ipv4.conf.all.accept_source_route0
Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfacesxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_ignore_bogus_error_responses unknownCCE-81023-4

Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces

Rule IDxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_ignore_bogus_error_responses
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_net_ipv4_icmp_ignore_bogus_error_responses:def:1
Time2020-09-29T11:21:07
Severityunknown
Identifiers and References

Identifiers:  CCE-81023-4

References:  NT28(R22), 3.2.6, 1, 11, 12, 13, 14, 15, 16, 2, 3, 7, 8, 9, APO13.01, BAI04.04, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS01.03, DSS03.05, DSS05.02, DSS05.05, DSS05.07, DSS06.06, 3.1.20, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 6.2, SR 7.1, SR 7.2, SR 7.6, A.12.1.2, A.12.1.3, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, A.17.2.1, A.9.1.2, CM-7(a), CM-7(b), SC-5, DE.CM-1, PR.DS-4, PR.IP-1, PR.PT-3, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the net.ipv4.icmp_ignore_bogus_error_responses kernel parameter, run the following command:

$ sudo sysctl -w net.ipv4.icmp_ignore_bogus_error_responses=1
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
net.ipv4.icmp_ignore_bogus_error_responses = 1

Rationale

Ignoring bogus ICMP error responses reduces log size, although some activity would not be logged.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

net.ipv4.icmp_ignore_bogus_error_responses static configuration  oval:ssg-test_static_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf(?:^|.*\n)[^#]*net.ipv4.icmp_ignore_bogus_error_responses[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.icmp_ignore_bogus_error_responses static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv4_icmp_ignore_bogus_error_responses:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv4_icmp_ignore_bogus_error_responses:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.icmp_ignore_bogus_error_responses[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.icmp_ignore_bogus_error_responses static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv4_icmp_ignore_bogus_error_responses:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv4_icmp_ignore_bogus_error_responses:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.icmp_ignore_bogus_error_responses[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.icmp_ignore_bogus_error_responses static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv4_icmp_ignore_bogus_error_responses:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv4_icmp_ignore_bogus_error_responses:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.icmp_ignore_bogus_error_responses[\s]*=[\s]*(\d+)[\s]*\n1

kernel runtime parameter net.ipv4.icmp_ignore_bogus_error_responses set to the appropriate value  oval:ssg-test_sysctl_runtime_net_ipv4_icmp_ignore_bogus_error_responses:tst:1  true

Following items have been found on the system:
NameValue
net.ipv4.icmp_ignore_bogus_error_responses1
Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfacesxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_redirects mediumCCE-80919-4

Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces

Rule IDxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_redirects
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_net_ipv4_conf_default_accept_redirects:def:1
Time2020-09-29T11:21:08
Severitymedium
Identifiers and References

Identifiers:  CCE-80919-4

References:  NT28(R22), 3.2.2, 1, 11, 12, 13, 14, 15, 16, 18, 2, 3, 4, 6, 7, 8, 9, 5.10.1.1, APO01.06, APO13.01, BAI04.04, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS01.03, DSS01.05, DSS03.01, DSS03.05, DSS05.02, DSS05.04, DSS05.05, DSS05.07, DSS06.02, DSS06.06, 3.1.20, CCI-001551, 4.2.3.4, 4.3.3.4, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, 4.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 6.2, SR 7.1, SR 7.2, SR 7.6, A.10.1.1, A.11.1.4, A.11.1.5, A.11.2.1, A.12.1.1, A.12.1.2, A.12.1.3, A.12.5.1, A.12.6.2, A.13.1.1, A.13.1.2, A.13.1.3, A.13.2.1, A.13.2.2, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3, A.14.2.2, A.14.2.3, A.14.2.4, A.17.2.1, A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, CM-7(a), CM-7(b), CM-6(a), SC-7(a), DE.AE-1, DE.CM-1, ID.AM-3, PR.AC-5, PR.DS-4, PR.DS-5, PR.IP-1, PR.PT-3, PR.PT-4, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the net.ipv4.conf.default.accept_redirects kernel parameter, run the following command:

$ sudo sysctl -w net.ipv4.conf.default.accept_redirects=0
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
net.ipv4.conf.default.accept_redirects = 0

Rationale

ICMP redirect messages are used by routers to inform hosts that a more direct route exists for a particular destination. These messages modify the host's route table and are unauthenticated. An illicit ICMP redirect message could result in a man-in-the-middle attack.
This feature of the IPv4 protocol has few legitimate uses. It should be disabled unless absolutely required.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

net.ipv4.conf.default.accept_redirects static configuration  oval:ssg-test_static_sysctl_net_ipv4_conf_default_accept_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv4_conf_default_accept_redirects:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf(?:^|.*\n)[^#]*net.ipv4.conf.default.accept_redirects[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.default.accept_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv4_conf_default_accept_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv4_conf_default_accept_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.default.accept_redirects[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.default.accept_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv4_conf_default_accept_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv4_conf_default_accept_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.default.accept_redirects[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.default.accept_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv4_conf_default_accept_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv4_conf_default_accept_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.default.accept_redirects[\s]*=[\s]*(\d+)[\s]*\n1

kernel runtime parameter net.ipv4.conf.default.accept_redirects set to the appropriate value  oval:ssg-test_sysctl_runtime_net_ipv4_conf_default_accept_redirects:tst:1  false

Following items have been found on the system:
NameValue
net.ipv4.conf.default.accept_redirects1
Configure Kernel Parameter for Accepting Secure Redirects By Defaultxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_secure_redirects mediumCCE-81017-6

Configure Kernel Parameter for Accepting Secure Redirects By Default

Rule IDxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_secure_redirects
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_net_ipv4_conf_default_secure_redirects:def:1
Time2020-09-29T11:21:08
Severitymedium
Identifiers and References

Identifiers:  CCE-81017-6

References:  NT28(R22), 3.2.3, 1, 11, 12, 13, 14, 15, 16, 18, 2, 3, 4, 6, 7, 8, 9, APO01.06, APO13.01, BAI04.04, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS01.03, DSS01.05, DSS03.01, DSS03.05, DSS05.02, DSS05.04, DSS05.05, DSS05.07, DSS06.02, DSS06.06, 3.1.20, CCI-001551, 4.2.3.4, 4.3.3.4, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, 4.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 6.2, SR 7.1, SR 7.2, SR 7.6, A.10.1.1, A.11.1.4, A.11.1.5, A.11.2.1, A.12.1.1, A.12.1.2, A.12.1.3, A.12.5.1, A.12.6.2, A.13.1.1, A.13.1.2, A.13.1.3, A.13.2.1, A.13.2.2, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3, A.14.2.2, A.14.2.3, A.14.2.4, A.17.2.1, A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, CM-7(a), CM-7(b), SC-5, SC-7(a), DE.AE-1, DE.CM-1, ID.AM-3, PR.AC-5, PR.DS-4, PR.DS-5, PR.IP-1, PR.PT-3, PR.PT-4, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the net.ipv4.conf.default.secure_redirects kernel parameter, run the following command:

$ sudo sysctl -w net.ipv4.conf.default.secure_redirects=0
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
net.ipv4.conf.default.secure_redirects = 0

Rationale

Accepting "secure" ICMP redirects (from those gateways listed as default gateways) has few legitimate uses. It should be disabled unless it is absolutely required.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

net.ipv4.conf.default.secure_redirects static configuration  oval:ssg-test_static_sysctl_net_ipv4_conf_default_secure_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv4_conf_default_secure_redirects:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf(?:^|.*\n)[^#]*net.ipv4.conf.default.secure_redirects[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.default.secure_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv4_conf_default_secure_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv4_conf_default_secure_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.default.secure_redirects[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.default.secure_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv4_conf_default_secure_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv4_conf_default_secure_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.default.secure_redirects[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.default.secure_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv4_conf_default_secure_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv4_conf_default_secure_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.default.secure_redirects[\s]*=[\s]*(\d+)[\s]*\n1

kernel runtime parameter net.ipv4.conf.default.secure_redirects set to the appropriate value  oval:ssg-test_sysctl_runtime_net_ipv4_conf_default_secure_redirects:tst:1  false

Following items have been found on the system:
NameValue
net.ipv4.conf.default.secure_redirects1
Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfacesxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_secure_redirects mediumCCE-81016-8

Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces

Rule IDxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_secure_redirects
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_net_ipv4_conf_all_secure_redirects:def:1
Time2020-09-29T11:21:08
Severitymedium
Identifiers and References

Identifiers:  CCE-81016-8

References:  NT28(R22), 3.2.3, 1, 11, 12, 13, 14, 15, 16, 18, 2, 3, 4, 6, 7, 8, 9, APO01.06, APO13.01, BAI04.04, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS01.03, DSS01.05, DSS03.01, DSS03.05, DSS05.02, DSS05.04, DSS05.05, DSS05.07, DSS06.02, DSS06.06, 3.1.20, CCI-001503, CCI-001551, 4.2.3.4, 4.3.3.4, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, 4.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 6.2, SR 7.1, SR 7.2, SR 7.6, A.10.1.1, A.11.1.4, A.11.1.5, A.11.2.1, A.12.1.1, A.12.1.2, A.12.1.3, A.12.5.1, A.12.6.2, A.13.1.1, A.13.1.2, A.13.1.3, A.13.2.1, A.13.2.2, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3, A.14.2.2, A.14.2.3, A.14.2.4, A.17.2.1, A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, CM-7(a), CM-7(b), CM-6(a), SC-7(a), DE.AE-1, DE.CM-1, ID.AM-3, PR.AC-5, PR.DS-4, PR.DS-5, PR.IP-1, PR.PT-3, PR.PT-4, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the net.ipv4.conf.all.secure_redirects kernel parameter, run the following command:

$ sudo sysctl -w net.ipv4.conf.all.secure_redirects=0
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
net.ipv4.conf.all.secure_redirects = 0

Rationale

Accepting "secure" ICMP redirects (from those gateways listed as default gateways) has few legitimate uses. It should be disabled unless it is absolutely required.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

net.ipv4.conf.all.secure_redirects static configuration  oval:ssg-test_static_sysctl_net_ipv4_conf_all_secure_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv4_conf_all_secure_redirects:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf(?:^|.*\n)[^#]*net.ipv4.conf.all.secure_redirects[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.all.secure_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv4_conf_all_secure_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv4_conf_all_secure_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.all.secure_redirects[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.all.secure_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv4_conf_all_secure_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv4_conf_all_secure_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.all.secure_redirects[\s]*=[\s]*(\d+)[\s]*\n1

net.ipv4.conf.all.secure_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv4_conf_all_secure_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv4_conf_all_secure_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$(?:^|.*\n)[^#]*net.ipv4.conf.all.secure_redirects[\s]*=[\s]*(\d+)[\s]*\n1

kernel runtime parameter net.ipv4.conf.all.secure_redirects set to the appropriate value  oval:ssg-test_sysctl_runtime_net_ipv4_conf_all_secure_redirects:tst:1  false

Following items have been found on the system:
NameValue
net.ipv4.conf.all.secure_redirects1
Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Defaultxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_send_redirects mediumCCE-80921-0

Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default

Rule IDxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_send_redirects
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_net_ipv4_conf_default_send_redirects:def:1
Time2020-09-29T11:21:08
Severitymedium
Identifiers and References

Identifiers:  CCE-80921-0

References:  NT28(R22), 3.1.2, 1, 11, 12, 13, 14, 15, 16, 18, 2, 3, 4, 6, 7, 8, 9, 5.10.1.1, APO01.06, APO13.01, BAI04.04, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS01.03, DSS01.05, DSS03.01, DSS03.05, DSS05.02, DSS05.04, DSS05.05, DSS05.07, DSS06.02, DSS06.06, 3.1.20, CCI-000366, 4.2.3.4, 4.3.3.4, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, 4.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 6.2, SR 7.1, SR 7.2, SR 7.6, A.10.1.1, A.11.1.4, A.11.1.5, A.11.2.1, A.12.1.1, A.12.1.2, A.12.1.3, A.12.5.1, A.12.6.2, A.13.1.1, A.13.1.2, A.13.1.3, A.13.2.1, A.13.2.2, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3, A.14.2.2, A.14.2.3, A.14.2.4, A.17.2.1, A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, CM-7(a), CM-7(b), SC-5CM-6(a), SC-7(a), DE.AE-1, DE.CM-1, ID.AM-3, PR.AC-5, PR.DS-4, PR.DS-5, PR.IP-1, PR.PT-3, PR.PT-4, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the net.ipv4.conf.default.send_redirects kernel parameter, run the following command:

$ sudo sysctl -w net.ipv4.conf.default.send_redirects=0
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
net.ipv4.conf.default.send_redirects = 0

Rationale

ICMP redirect messages are used by routers to inform hosts that a more direct route exists for a particular destination. These messages contain information from the system's route table possibly revealing portions of the network topology.
The ability to send ICMP redirects is only appropriate for systems acting as routers.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

net.ipv4.conf.default.send_redirects static configuration  oval:ssg-test_static_sysctl_net_ipv4_conf_default_send_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv4_conf_default_send_redirects:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf^[\s]*net.ipv4.conf.default.send_redirects[\s]*=[\s]*0[\s]*$1

net.ipv4.conf.default.send_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv4_conf_default_send_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv4_conf_default_send_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$^[\s]*net.ipv4.conf.default.send_redirects[\s]*=[\s]*0[\s]*$1

net.ipv4.conf.default.send_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv4_conf_default_send_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv4_conf_default_send_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$^[\s]*net.ipv4.conf.default.send_redirects[\s]*=[\s]*0[\s]*$1

net.ipv4.conf.default.send_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv4_conf_default_send_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv4_conf_default_send_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$^[\s]*net.ipv4.conf.default.send_redirects[\s]*=[\s]*0[\s]*$1

kernel runtime parameter net.ipv4.conf.default.send_redirects set to 0  oval:ssg-test_sysctl_runtime_net_ipv4_conf_default_send_redirects:tst:1  false

Following items have been found on the system:
NameValue
net.ipv4.conf.default.send_redirects1
Disable Kernel Parameter for IP Forwarding on IPv4 Interfacesxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_ip_forward mediumCCE-81024-2

Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces

Rule IDxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_ip_forward
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_net_ipv4_ip_forward:def:1
Time2020-09-29T11:21:08
Severitymedium
Identifiers and References

Identifiers:  CCE-81024-2

References:  NT28(R22), 3.1.1, 1, 11, 12, 13, 14, 15, 16, 2, 3, 7, 8, 9, APO13.01, BAI04.04, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS01.03, DSS03.05, DSS05.02, DSS05.05, DSS05.07, DSS06.06, 3.1.20, CCI-000366, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 6.2, SR 7.1, SR 7.2, SR 7.6, A.12.1.2, A.12.1.3, A.12.5.1, A.12.6.2, A.13.1.1, A.13.2.1, A.14.1.3, A.14.2.2, A.14.2.3, A.14.2.4, A.17.2.1, A.9.1.2, CM-7(a), CM-7(b), SC-5CM-6(a), SC-7(a), DE.CM-1, PR.DS-4, PR.IP-1, PR.PT-3, PR.PT-4, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the net.ipv4.ip_forward kernel parameter, run the following command:

$ sudo sysctl -w net.ipv4.ip_forward=0
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
net.ipv4.ip_forward = 0

Rationale

Routing protocol daemons are typically used on routers to exchange network topology information with other routers. If this capability is used when not required, system network information may be unnecessarily transmitted across the network.

Warnings
warning  Certain technologies such as virtual machines, containers, etc. rely on IPv4 forwarding to enable and use networking. Disabling IPv4 forwarding would cause those technologies to stop working. Therefore, this rule should not be used in profiles or benchmarks that target usage of IPv4 forwarding.
Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

net.ipv4.ip_forward static configuration  oval:ssg-test_static_sysctl_net_ipv4_ip_forward:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv4_ip_forward:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf^[\s]*net.ipv4.ip_forward[\s]*=[\s]*0[\s]*$1

net.ipv4.ip_forward static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv4_ip_forward:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv4_ip_forward:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$^[\s]*net.ipv4.ip_forward[\s]*=[\s]*0[\s]*$1

net.ipv4.ip_forward static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv4_ip_forward:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv4_ip_forward:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$^[\s]*net.ipv4.ip_forward[\s]*=[\s]*0[\s]*$1

net.ipv4.ip_forward static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv4_ip_forward:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv4_ip_forward:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$^[\s]*net.ipv4.ip_forward[\s]*=[\s]*0[\s]*$1

kernel runtime parameter net.ipv4.ip_forward set to 0  oval:ssg-test_sysctl_runtime_net_ipv4_ip_forward:tst:1  true

Following items have been found on the system:
NameValue
net.ipv4.ip_forward0
Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfacesxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_send_redirects mediumCCE-80918-6

Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces

Rule IDxccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_send_redirects
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_net_ipv4_conf_all_send_redirects:def:1
Time2020-09-29T11:21:08
Severitymedium
Identifiers and References

Identifiers:  CCE-80918-6

References:  NT28(R22), 3.1.2, 1, 11, 12, 13, 14, 15, 16, 18, 2, 3, 4, 6, 7, 8, 9, 5.10.1.1, APO01.06, APO13.01, BAI04.04, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS01.03, DSS01.05, DSS03.01, DSS03.05, DSS05.02, DSS05.04, DSS05.05, DSS05.07, DSS06.02, DSS06.06, 3.1.20, CCI-000366, 4.2.3.4, 4.3.3.4, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, 4.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 6.2, SR 7.1, SR 7.2, SR 7.6, A.10.1.1, A.11.1.4, A.11.1.5, A.11.2.1, A.12.1.1, A.12.1.2, A.12.1.3, A.12.5.1, A.12.6.2, A.13.1.1, A.13.1.2, A.13.1.3, A.13.2.1, A.13.2.2, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3, A.14.2.2, A.14.2.3, A.14.2.4, A.17.2.1, A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, CM-7(a), CM-7(b), SC-5CM-6(a), SC-7(a), DE.AE-1, DE.CM-1, ID.AM-3, PR.AC-5, PR.DS-4, PR.DS-5, PR.IP-1, PR.PT-3, PR.PT-4, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the net.ipv4.conf.all.send_redirects kernel parameter, run the following command:

$ sudo sysctl -w net.ipv4.conf.all.send_redirects=0
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
net.ipv4.conf.all.send_redirects = 0

Rationale

ICMP redirect messages are used by routers to inform hosts that a more direct route exists for a particular destination. These messages contain information from the system's route table possibly revealing portions of the network topology.
The ability to send ICMP redirects is only appropriate for systems acting as routers.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

net.ipv4.conf.all.send_redirects static configuration  oval:ssg-test_static_sysctl_net_ipv4_conf_all_send_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_ipv4_conf_all_send_redirects:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf^[\s]*net.ipv4.conf.all.send_redirects[\s]*=[\s]*0[\s]*$1

net.ipv4.conf.all.send_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_ipv4_conf_all_send_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_ipv4_conf_all_send_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$^[\s]*net.ipv4.conf.all.send_redirects[\s]*=[\s]*0[\s]*$1

net.ipv4.conf.all.send_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_ipv4_conf_all_send_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_ipv4_conf_all_send_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$^[\s]*net.ipv4.conf.all.send_redirects[\s]*=[\s]*0[\s]*$1

net.ipv4.conf.all.send_redirects static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_ipv4_conf_all_send_redirects:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_ipv4_conf_all_send_redirects:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$^[\s]*net.ipv4.conf.all.send_redirects[\s]*=[\s]*0[\s]*$1

kernel runtime parameter net.ipv4.conf.all.send_redirects set to 0  oval:ssg-test_sysctl_runtime_net_ipv4_conf_all_send_redirects:tst:1  false

Following items have been found on the system:
NameValue
net.ipv4.conf.all.send_redirects1
Install firewalld Packagexccdf_org.ssgproject.content_rule_package_firewalld_installed mediumCCE-82998-6

Install firewalld Package

Rule IDxccdf_org.ssgproject.content_rule_package_firewalld_installed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_firewalld_installed:def:1
Time2020-09-29T11:18:02
Severitymedium
Identifiers and References

Identifiers:  CCE-82998-6

References:  CM-6(a), SRG-OS-000480-GPOS-00227, SRG-OS-000298-GPOS-00116

Description

The firewalld package can be installed with the following command:

$ sudo yum install firewalld

Rationale

The firewalld package should be installed to provide access control methods.

OVAL test results details

package firewalld is installed  oval:ssg-test_package_firewalld_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
firewalldnoarch(none)4.el80.8.00:0.8.0-4.el8199e2f91fd431d51firewalld-0:0.8.0-4.el8.noarch
Verify firewalld Enabledxccdf_org.ssgproject.content_rule_service_firewalld_enabled mediumCCE-80877-4

Verify firewalld Enabled

Rule IDxccdf_org.ssgproject.content_rule_service_firewalld_enabled
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-service_firewalld_enabled:def:1
Time2020-09-29T11:18:02
Severitymedium
Identifiers and References

Identifiers:  CCE-80877-4

References:  4.7, 11, 3, 9, BAI10.01, BAI10.02, BAI10.03, BAI10.05, 3.1.3, 3.4.7, CCI-000366, 4.3.4.3.2, 4.3.4.3.3, SR 7.6, A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, AC-4, CM-7(b), CA-3(5), SC-7(21), CM-6(a), PR.IP-1, FMT_MOF_EXT.1, SRG-OS-000480-GPOS-00227

Description

The firewalld service can be enabled with the following command:

$ sudo systemctl enable firewalld.service

Rationale

Access control methods provide the ability to enhance system security posture by restricting services and known good IP addresses and address ranges. This prevents connections from unknown hosts and protocols.

OVAL test results details

package firewalld is installed  oval:ssg-test_service_firewalld_package_firewalld_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
firewalldnoarch(none)4.el80.8.00:0.8.0-4.el8199e2f91fd431d51firewalld-0:0.8.0-4.el8.noarch

Test that the firewalld service is running  oval:ssg-test_service_running_firewalld:tst:1  true

Following items have been found on the system:
UnitPropertyValue
firewalld.serviceActiveStateactive

systemd test  oval:ssg-test_multi_user_wants_firewalld:tst:1  true

Following items have been found on the system:
UnitDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependency
multi-user.targetbasic.targetvar.mount-.mountsysinit.targetdev-mqueue.mountsystemd-hwdb-update.servicecryptsetup.targetproc-sys-fs-binfmt_misc.automountsystemd-journal-flush.servicesystemd-random-seed.servicesystemd-update-utmp.servicesystemd-tmpfiles-setup.servicesystemd-udevd.servicedev-hugepages.mountlvm2-lvmpolld.socketselinux-autorelabel-mark.serviceloadmodules.servicelocal-fs.targethome.mount-.mountvar-log-audit.mountboot.mounttmp.mountvar.mountvar-log.mountsystemd-remount-fs.servicedracut-shutdown.servicesystemd-sysctl.servicesystemd-journal-catalog-update.servicesystemd-update-done.servicesystemd-journald.servicesys-kernel-debug.mountsystemd-machine-id-commit.serviceldconfig.servicerngd.servicesystemd-binfmt.servicenis-domainname.servicesys-kernel-config.mountsystemd-modules-load.servicesystemd-sysusers.servicesys-fs-fuse-connections.mountswap.targetdev-mapper-ovirt\x2dswap.swapsystemd-udev-trigger.serviceimport-state.servicesystemd-firstboot.servicekmod-static-nodes.servicesystemd-ask-password-console.pathsystemd-tmpfiles-setup-dev.servicelvm2-monitor.servicemicrocode.servicepaths.targettimers.targetfstrim.timerunbound-anchor.timersystemd-tmpfiles-clean.timerslices.target-.slicesystem.slicesockets.targetsystemd-udevd-kernel.socketdbus.socketsystemd-coredump.socketsystemd-initctl.socketsystemd-udevd-control.socketsystemd-journald-dev-log.socketpcscd.socketsssd-kcm.socketsystemd-journald.socketcockpit.socketdm-event.socketrpcbind.socketsssd.servicekdump.servicecrond.servicesystemd-ask-password-wall.pathsshd.servicesystemd-user-sessions.serviceauditd.servicenfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetirqbalance.serviceremote-fs.targetnfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetgetty.targetserial-getty@ttyS0.servicegetty@tty1.servicecloud-init.targetcloud-init-local.servicecloud-config.servicecloud-final.servicecloud-init.servicednf-makecache.timerfirewalld.servicerpcbind.servicesystemd-update-utmp-runlevel.servicechronyd.servicersyslog.servicetuned.servicesystemd-logind.serviceNetworkManager.servicedbus.service

systemd test  oval:ssg-test_multi_user_wants_firewalld_socket:tst:1  false

Following items have been found on the system:
UnitDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependency
multi-user.targetbasic.targetvar.mount-.mountsysinit.targetdev-mqueue.mountsystemd-hwdb-update.servicecryptsetup.targetproc-sys-fs-binfmt_misc.automountsystemd-journal-flush.servicesystemd-random-seed.servicesystemd-update-utmp.servicesystemd-tmpfiles-setup.servicesystemd-udevd.servicedev-hugepages.mountlvm2-lvmpolld.socketselinux-autorelabel-mark.serviceloadmodules.servicelocal-fs.targethome.mount-.mountvar-log-audit.mountboot.mounttmp.mountvar.mountvar-log.mountsystemd-remount-fs.servicedracut-shutdown.servicesystemd-sysctl.servicesystemd-journal-catalog-update.servicesystemd-update-done.servicesystemd-journald.servicesys-kernel-debug.mountsystemd-machine-id-commit.serviceldconfig.servicerngd.servicesystemd-binfmt.servicenis-domainname.servicesys-kernel-config.mountsystemd-modules-load.servicesystemd-sysusers.servicesys-fs-fuse-connections.mountswap.targetdev-mapper-ovirt\x2dswap.swapsystemd-udev-trigger.serviceimport-state.servicesystemd-firstboot.servicekmod-static-nodes.servicesystemd-ask-password-console.pathsystemd-tmpfiles-setup-dev.servicelvm2-monitor.servicemicrocode.servicepaths.targettimers.targetfstrim.timerunbound-anchor.timersystemd-tmpfiles-clean.timerslices.target-.slicesystem.slicesockets.targetsystemd-udevd-kernel.socketdbus.socketsystemd-coredump.socketsystemd-initctl.socketsystemd-udevd-control.socketsystemd-journald-dev-log.socketpcscd.socketsssd-kcm.socketsystemd-journald.socketcockpit.socketdm-event.socketrpcbind.socketsssd.servicekdump.servicecrond.servicesystemd-ask-password-wall.pathsshd.servicesystemd-user-sessions.serviceauditd.servicenfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetirqbalance.serviceremote-fs.targetnfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetgetty.targetserial-getty@ttyS0.servicegetty@tty1.servicecloud-init.targetcloud-init-local.servicecloud-config.servicecloud-final.servicecloud-init.servicednf-makecache.timerfirewalld.servicerpcbind.servicesystemd-update-utmp-runlevel.servicechronyd.servicersyslog.servicetuned.servicesystemd-logind.serviceNetworkManager.servicedbus.service
Disable Bluetooth Kernel Modulexccdf_org.ssgproject.content_rule_kernel_module_bluetooth_disabled mediumCCE-80832-9

Disable Bluetooth Kernel Module

Rule IDxccdf_org.ssgproject.content_rule_kernel_module_bluetooth_disabled
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-kernel_module_bluetooth_disabled:def:1
Time2020-09-29T11:21:08
Severitymedium
Identifiers and References

Identifiers:  CCE-80832-9

References:  11, 12, 14, 15, 3, 8, 9, 5.13.1.3, APO13.01, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS01.04, DSS05.02, DSS05.03, DSS05.05, DSS06.06, 3.1.16, CCI-000085, CCI-001551, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 7.1, SR 7.6, A.11.2.6, A.12.1.2, A.12.5.1, A.12.6.2, A.13.1.1, A.13.2.1, A.14.1.3, A.14.2.2, A.14.2.3, A.14.2.4, A.6.2.1, A.6.2.2, A.9.1.2, AC-18(a), AC-18(3), CM-7(a), CM-7(b), CM-6(a), MP-7, PR.AC-3, PR.IP-1, PR.PT-3, PR.PT-4, SRG-OS-000095-GPOS-00049

Description

The kernel's module loading system can be configured to prevent loading of the Bluetooth module. Add the following to the appropriate /etc/modprobe.d configuration file to prevent the loading of the Bluetooth module:

install bluetooth /bin/true

Rationale

If Bluetooth functionality must be disabled, preventing the kernel from loading the kernel module provides an additional safeguard against its activation.

Evaluation messages
info 
Fix execution completed and returned: 0
info 
grep: /etc/modprobe.d/bluetooth.conf: No such file or directory
OVAL test results details

kernel module bluetooth disabled  oval:ssg-test_kernmod_bluetooth_disabled:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_bluetooth_disabled:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/modprobe.d^.*\.conf$^\s*install\s+bluetooth\s+(/bin/false|/bin/true)$1

kernel module bluetooth disabled in /etc/modprobe.conf  oval:ssg-test_kernmod_bluetooth_modprobeconf:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_bluetooth_modprobeconf:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/modprobe.conf^\s*install\s+bluetooth\s+(/bin/false|/bin/true)$1

kernel module bluetooth disabled in /etc/modules-load.d  oval:ssg-test_kernmod_bluetooth_etcmodules-load:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_bluetooth_etcmodules-load:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/modules-load.d^.*\.conf$^\s*install\s+bluetooth\s+(/bin/false|/bin/true)$1

kernel module bluetooth disabled in /run/modules-load.d  oval:ssg-test_kernmod_bluetooth_runmodules-load:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_bluetooth_runmodules-load:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/modules-load.d^.*\.conf$^\s*install\s+bluetooth\s+(/bin/false|/bin/true)$1

kernel module bluetooth disabled in /usr/lib/modules-load.d  oval:ssg-test_kernmod_bluetooth_libmodules-load:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_bluetooth_libmodules-load:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/modules-load.d^.*\.conf$^\s*install\s+bluetooth\s+(/bin/false|/bin/true)$1

kernel module bluetooth disabled in /run/modprobe.d  oval:ssg-test_kernmod_bluetooth_runmodprobed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_bluetooth_runmodprobed:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/modprobe.d^.*\.conf$^\s*install\s+bluetooth\s+(/bin/false|/bin/true)$1

kernel module bluetooth disabled in /usr/lib/modprobe.d  oval:ssg-test_kernmod_bluetooth_libmodprobed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_bluetooth_libmodprobed:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/modprobe.d^.*\.conf$^\s*install\s+bluetooth\s+(/bin/false|/bin/true)$1
Configure Smart Card Certificate Status Checkingxccdf_org.ssgproject.content_rule_smartcard_configure_cert_checking mediumCCE-82475-5

Configure Smart Card Certificate Status Checking

Rule IDxccdf_org.ssgproject.content_rule_smartcard_configure_cert_checking
Result
notchecked
Multi-check ruleno
Time2020-09-29T11:18:02
Severitymedium
Identifiers and References

Identifiers:  CCE-82475-5

References:  CCI-001954, SRG-OS-000375-GPOS-00160, SRG-OS-000384-GPOS-00167

Description

Configure the operating system to do certificate status checking for PKI authentication. Modify all of the cert_policy lines in /etc/pam_pkcs11/pam_pkcs11.conf to include ocsp_on like so:

cert_policy = ca, ocsp_on, signature;

Rationale

Using an authentication device, such as a CAC or token that is separate from the information system, ensures that even if the information system is compromised, that compromise will not affect credentials stored on the authentication device.

Multifactor solutions that require devices separate from information systems gaining access include, for example, hardware tokens providing time-based or challenge-response authenticators and smart cards such as the U.S. Government Personal Identity Verification card and the DoD Common Access Card.

Evaluation messages
info 
No candidate or applicable check found.
Install the tmux Packagexccdf_org.ssgproject.content_rule_package_tmux_installed mediumCCE-80644-8

Install the tmux Package

Rule IDxccdf_org.ssgproject.content_rule_package_tmux_installed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_tmux_installed:def:1
Time2020-09-29T11:18:02
Severitymedium
Identifiers and References

Identifiers:  CCE-80644-8

References:  1, 12, 15, 16, DSS05.04, DSS05.10, DSS06.10, 3.1.10, CCI-000058, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, SR 1.1, SR 1.10, SR 1.2, SR 1.5, SR 1.7, SR 1.8, SR 1.9, A.18.1.4, A.9.2.1, A.9.2.4, A.9.3.1, A.9.4.2, A.9.4.3, CM-6(a), PR.AC-7, FMT_MOF_EXT.1, SRG-OS-000030-GPOS-00011, SRG-OS-000030-VMM-000110

Description

To enable console screen locking, install the tmux package. The tmux package can be installed with the following command:

$ sudo yum install tmux
Instruct users to begin new terminal sessions with the following command:
$ tmux
The console can now be locked with the following key combination:
ctrl+b :lock-session

Rationale

A session time-out lock is a temporary action taken when a user stops work and moves away from the immediate physical vicinity of the information system but does not logout because of the temporary nature of the absence. Rather than relying on the user to manually lock their operation system session prior to vacating the vicinity, operating systems need to be able to identify when a user's session has idled and take action to initiate the session lock.

The tmux package allows for a session lock to be implemented and configured.

OVAL test results details

package tmux is installed  oval:ssg-test_package_tmux_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
tmuxx86_64(none)1.el82.70:2.7-1.el8199e2f91fd431d51tmux-0:2.7-1.el8.x86_64
Configure tmux to lock session after inactivityxccdf_org.ssgproject.content_rule_configure_tmux_lock_after_time mediumCCE-82199-1

Configure tmux to lock session after inactivity

Rule IDxccdf_org.ssgproject.content_rule_configure_tmux_lock_after_time
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-configure_tmux_lock_after_time:def:1
Time2020-09-29T11:21:09
Severitymedium
Identifiers and References

Identifiers:  CCE-82199-1

References:  FMT_SMF_EXT.1, SRG-OS-000029-GPOS-00010

Description

To enable console screen locking in tmux terminal multiplexer after a period of inactivity, the lock-after-time option has to be set to nonzero value in /etc/tmux.conf.

Rationale

Locking the session after a period of inactivity limits the potential exposure if the session is left unattended.

Evaluation messages
info 
Fix execution completed and returned: 0
info 
grep: /etc/tmux.conf: No such file or directory
OVAL test results details

check lock-after-time is set to 900 in /etc/tmux.conf  oval:ssg-test_configure_tmux_lock_after_time:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_configure_tmux_lock_after_time:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/tmux.conf^\s*set\s+-g\s+lock-after-time\s+900\s*(?:#.*)?$1
Support session locking with tmuxxccdf_org.ssgproject.content_rule_configure_bashrc_exec_tmux mediumCCE-82266-8

Support session locking with tmux

Rule IDxccdf_org.ssgproject.content_rule_configure_bashrc_exec_tmux
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-configure_bashrc_exec_tmux:def:1
Time2020-09-29T11:21:09
Severitymedium
Identifiers and References

Identifiers:  CCE-82266-8

References:  FMT_SMF_EXT.1, SRG-OS-000031-GPOS-00012

Description

The tmux terminal multiplexer is used to implement automatic session locking. It should be started from /etc/bashrc.

Rationale

Unlike bash itself, the tmux terminal multiplexer provides a mechanism to lock sessions after period of inactivity.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

check tmux is configured to exec on the last line of /etc/bashrc  oval:ssg-test_configure_bashrc_exec_tmux:tst:1  false

Following items have been found on the system:
PathContent
/etc/bashrc# /etc/bashrc # System wide functions and aliases # Environment stuff goes in /etc/profile # It's NOT a good idea to change this file unless you know what you # are doing. It's much better to create a custom.sh shell script in # /etc/profile.d/ to make custom changes to your environment, as this # will prevent the need for merging in future updates. # Prevent doublesourcing if [ -z "$BASHRCSOURCED" ]; then BASHRCSOURCED="Y" # are we an interactive shell? if [ "$PS1" ]; then if [ -z "$PROMPT_COMMAND" ]; then case $TERM in xterm*|vte*) if [ -e /etc/sysconfig/bash-prompt-xterm ]; then PROMPT_COMMAND=/etc/sysconfig/bash-prompt-xterm elif [ "${VTE_VERSION:-0}" -ge 3405 ]; then PROMPT_COMMAND="__vte_prompt_command" else PROMPT_COMMAND='printf "\033]0;%s@%s:%s\007" "${USER}" "${HOSTNAME%%.*}" "${PWD/#$HOME/\~}"' fi ;; screen*) if [ -e /etc/sysconfig/bash-prompt-screen ]; then PROMPT_COMMAND=/etc/sysconfig/bash-prompt-screen else PROMPT_COMMAND='printf "\033k%s@%s:%s\033\\" "${USER}" "${HOSTNAME%%.*}" "${PWD/#$HOME/\~}"' fi ;; *) [ -e /etc/sysconfig/bash-prompt-default ] && PROMPT_COMMAND=/etc/sysconfig/bash-prompt-default ;; esac fi # Turn on parallel history shopt -s histappend history -a # Turn on checkwinsize shopt -s checkwinsize [ "$PS1" = "\\s-\\v\\\$ " ] && PS1="[\u@\h \W]\\$ " # You might want to have e.g. tty in prompt (e.g. more virtual machines) # and console windows # If you want to do so, just add e.g. # if [ "$PS1" ]; then # PS1="[\u@\h:\l \W]\\$ " # fi # to your custom modification shell script in /etc/profile.d/ directory fi if ! shopt -q login_shell ; then # We're not a login shell # Need to redefine pathmunge, it gets undefined at the end of /etc/profile pathmunge () { case ":${PATH}:" in *:"$1":*) ;; *) if [ "$2" = "after" ] ; then PATH=$PATH:$1 else PATH=$1:$PATH fi esac } # By default, we want umask to get set. This sets it for non-login shell. # Current threshold for system reserved uid/gids is 200 # You could check uidgid reservation validity in # /usr/share/doc/setup-*/uidgid file if [ $UID -gt 199 ] && [ "`/usr/bin/id -gn`" = "`/usr/bin/id -un`" ]; then umask 002 else umask 022 fi SHELL=/bin/bash # Only display echos from profile.d scripts if we are no login shell # and interactive - otherwise just process them to set envvars for i in /etc/profile.d/*.sh; do if [ -r "$i" ]; then if [ "$PS1" ]; then . "$i" else . "$i" >/dev/null fi fi done unset i unset -f pathmunge fi fi # vim:ts=4:sw=4
Configure the tmux Lock Commandxccdf_org.ssgproject.content_rule_configure_tmux_lock_command mediumCCE-80940-0

Configure the tmux Lock Command

Rule IDxccdf_org.ssgproject.content_rule_configure_tmux_lock_command
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-configure_tmux_lock_command:def:1
Time2020-09-29T11:21:09
Severitymedium
Identifiers and References

Identifiers:  CCE-80940-0

References:  CCI-000056, CCI-000058, AC-11(a), AC-11(b), CM-6(a), SRG-OS-000028-GPOS-00009, SRG-OS-000028-VMM-000090, SRG-OS-000030-VMM-000110

Description

To enable console screen locking in tmux terminal multiplexer, the vlock command must be configured to be used as a locking mechanism. Add the following line to /etc/tmux.conf:

set -g lock-command vlock
. The console can now be locked with the following key combination:
ctrl+b :lock-session

Rationale

The tmux package allows for a session lock to be implemented and configured. However, the session lock is implemented by an external command. The tmux default configuration does not contain an effective session lock.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

check lock-command is set to vlock in /etc/tmux.conf  oval:ssg-test_configure_tmux_lock_command:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_configure_tmux_lock_command:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/tmux.conf^\s*set\s+-g\s+lock-command\s+vlock\s*(?:#.*)?$1
Prevent user from disabling the screen lockxccdf_org.ssgproject.content_rule_no_tmux_in_shells mediumCCE-82361-7

Prevent user from disabling the screen lock

Rule IDxccdf_org.ssgproject.content_rule_no_tmux_in_shells
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-no_tmux_in_shells:def:1
Time2020-09-29T11:21:09
Severitymedium
Identifiers and References

Identifiers:  CCE-82361-7

References:  FMT_SMF_EXT.1, SRG-OS-000324-GPOS-00125

Description

The tmux terminal multiplexer is used to implement autimatic session locking. It should not be listed in /etc/shells.

Rationale

Not listing tmux among permitted shells prevents malicious program running as user from lowering security by disabling the screen lock.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

check that tmux is not listed in /etc/shells  oval:ssg-test_no_tmux_in_shells:tst:1  false

Following items have been found on the system:
PathContent
/etc/shellstmux
Disable debug-shell SystemD Servicexccdf_org.ssgproject.content_rule_service_debug-shell_disabled mediumCCE-80876-6

Disable debug-shell SystemD Service

Rule IDxccdf_org.ssgproject.content_rule_service_debug-shell_disabled
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-service_debug-shell_disabled:def:1
Time2020-09-29T11:18:02
Severitymedium
Identifiers and References

Identifiers:  CCE-80876-6

References:  3.4.5, 164.308(a)(1)(ii)(B), 164.308(a)(7)(i), 164.308(a)(7)(ii)(A), 164.310(a)(1), 164.310(a)(2)(i), 164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(b), 164.310(c), 164.310(d)(1), 164.310(d)(2)(iii), FIA_AFL.1, SRG-OS-000324-GPOS-00125

Description

SystemD's debug-shell service is intended to diagnose SystemD related boot issues with various systemctl commands. Once enabled and following a system reboot, the root shell will be available on tty9 which is access by pressing CTRL-ALT-F9. The debug-shell service should only be used for SystemD related issues and should otherwise be disabled.

By default, the debug-shell SystemD service is already disabled. The debug-shell service can be disabled with the following command:

$ sudo systemctl disable debug-shell.service
The debug-shell service can be masked with the following command:
$ sudo systemctl mask debug-shell.service

Rationale

This prevents attackers with physical access from trivially bypassing security on the machine through valid troubleshooting configurations and gaining root access when the system is rebooted.

OVAL test results details

package systemd is removed  oval:ssg-test_service_debug-shell_package_systemd_removed:tst:1  false

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
systemdx86_64(none)31.el8_2.22390:239-31.el8_2.2199e2f91fd431d51systemd-0:239-31.el8_2.2.x86_64

Test that the debug-shell service is not running  oval:ssg-test_service_not_running_debug-shell:tst:1  true

No items have been found conforming to the following objects:
Object oval:ssg-obj_service_not_running_debug-shell:obj:1 of type systemdunitproperty_object
UnitProperty
^debug-shell\.(service|socket)$ActiveState

Test that the property LoadState from the service debug-shell is masked  oval:ssg-test_service_loadstate_is_masked_debug-shell:tst:1  true

No items have been found conforming to the following objects:
Object oval:ssg-obj_service_loadstate_is_masked_debug-shell:obj:1 of type systemdunitproperty_object
UnitProperty
^debug-shell\.(service|socket)$LoadState

Test that the property FragmentPath from the service debug-shell is set to /dev/null  oval:ssg-test_service_fragmentpath_is_dev_null_debug-shell:tst:1  true

No items have been found conforming to the following objects:
Object oval:ssg-obj_service_fragmentpath_is_dev_null_debug-shell:obj:1 of type systemdunitproperty_object
UnitProperty
^debug-shell\.(service|socket)$FragmentPath
Require Authentication for Single User Modexccdf_org.ssgproject.content_rule_require_singleuser_auth mediumCCE-80855-0

Require Authentication for Single User Mode

Rule IDxccdf_org.ssgproject.content_rule_require_singleuser_auth
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-require_singleuser_auth:def:1
Time2020-09-29T11:18:02
Severitymedium
Identifiers and References

Identifiers:  CCE-80855-0

References:  1.5.3, 1, 11, 12, 14, 15, 16, 18, 3, 5, DSS05.02, DSS05.04, DSS05.05, DSS05.07, DSS05.10, DSS06.03, DSS06.06, DSS06.10, 3.1.1, 3.4.5, CCI-000213, 164.308(a)(1)(ii)(B), 164.308(a)(7)(i), 164.308(a)(7)(ii)(A), 164.310(a)(1), 164.310(a)(2)(i), 164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(b), 164.310(c), 164.310(d)(1), 164.310(d)(2)(iii), 4.3.3.2.2, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, A.18.1.4, A.6.1.2, A.7.1.1, A.9.1.2, A.9.2.1, A.9.2.2, A.9.2.3, A.9.2.4, A.9.2.6, A.9.3.1, A.9.4.1, A.9.4.2, A.9.4.3, A.9.4.4, A.9.4.5, IA-2, AC-3, CM-6(a), PR.AC-1, PR.AC-4, PR.AC-6, PR.AC-7, PR.PT-3, FIA_AFL.1, SRG-OS-000080-GPOS-00048

Description

Single-user mode is intended as a system recovery method, providing a single user root access to the system by providing a boot option at startup. By default, no authentication is performed if single-user mode is selected.

By default, single-user mode is protected by requiring a password and is set in /usr/lib/systemd/system/rescue.service.

Rationale

This prevents attackers with physical access from trivially bypassing security on the machine and gaining root access. Such accesses are further prevented by configuring the bootloader password.

OVAL test results details

Tests that /usr/lib/systemd/systemd-sulogin-shell was not removed from the default systemd rescue.service to ensure that a password must be entered to access single user mode  oval:ssg-test_require_rescue_service:tst:1  true

Following items have been found on the system:
PathContent
/usr/lib/systemd/system/rescue.serviceExecStart=-/usr/lib/systemd/systemd-sulogin-shell rescue

Tests that the systemd rescue.service is in the runlevel1.target  oval:ssg-test_require_rescue_service_runlevel1:tst:1  true

Following items have been found on the system:
PathContent
/usr/lib/systemd/system/runlevel1.targetRequires=sysinit.target rescue.service

look for runlevel1.target in /etc/systemd/system  oval:ssg-test_no_custom_runlevel1_target:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_no_custom_runlevel1_target:obj:1 of type file_object
BehaviorsPathFilename
no value/etc/systemd/system^runlevel1.target$

look for rescue.service in /etc/systemd/system  oval:ssg-test_no_custom_rescue_service:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_no_custom_rescue_service:obj:1 of type file_object
BehaviorsPathFilename
no value/etc/systemd/system^rescue.service$
Disable Ctrl-Alt-Del Reboot Activationxccdf_org.ssgproject.content_rule_disable_ctrlaltdel_reboot highCCE-80785-9

Disable Ctrl-Alt-Del Reboot Activation

Rule IDxccdf_org.ssgproject.content_rule_disable_ctrlaltdel_reboot
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-disable_ctrlaltdel_reboot:def:1
Time2020-09-29T11:21:09
Severityhigh
Identifiers and References

Identifiers:  CCE-80785-9

References:  12, 13, 14, 15, 16, 18, 3, 5, APO01.06, DSS05.04, DSS05.07, DSS06.02, 3.4.5, CCI-000366, 164.308(a)(1)(ii)(B), 164.308(a)(7)(i), 164.308(a)(7)(ii)(A), 164.310(a)(1), 164.310(a)(2)(i), 164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(b), 164.310(c), 164.310(d)(1), 164.310(d)(2)(iii), 4.3.3.7.3, SR 2.1, SR 5.2, A.10.1.1, A.11.1.4, A.11.1.5, A.11.2.1, A.13.1.1, A.13.1.3, A.13.2.1, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3, A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, CM-6(a), AC-6(1), PR.AC-4, PR.DS-5, SRG-OS-000324-GPOS-00125

Description

By default, SystemD will reboot the system if the Ctrl-Alt-Del key sequence is pressed.

To configure the system to ignore the Ctrl-Alt-Del key sequence from the command line instead of rebooting the system, do either of the following:

ln -sf /dev/null /etc/systemd/system/ctrl-alt-del.target
or
systemctl mask ctrl-alt-del.target


Do not simply delete the /usr/lib/systemd/system/ctrl-alt-del.service file, as this file may be restored during future system updates.

Rationale

A locally logged-in user who presses Ctrl-Alt-Del, when at the console, can reboot the system. If accidentally pressed, as could happen in the case of mixed OS environment, this can create the risk of short-term loss of availability of systems due to unintentional reboot.

Warnings
warning  Disabling the Ctrl-Alt-Del key sequence in /etc/init/control-alt-delete.conf DOES NOT disable the Ctrl-Alt-Del key sequence if running in runlevel 6 (e.g. in GNOME, KDE, etc.)! The Ctrl-Alt-Del key sequence will only be disabled if running in the non-graphical runlevel 3.
Evaluation messages
info 
Fix execution completed and returned: 0
info 
Created symlink /etc/systemd/system/ctrl-alt-del.target → /dev/null.
OVAL test results details

Disable Ctrl-Alt-Del key sequence override exists  oval:ssg-test_disable_ctrlaltdel_exists:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_disable_ctrlaltdel_exists:obj:1 of type symlink_object
Filepath
/etc/systemd/system/ctrl-alt-del.target
Verify that Interactive Boot is Disabledxccdf_org.ssgproject.content_rule_grub2_disable_interactive_boot mediumCCE-80826-1

Verify that Interactive Boot is Disabled

Rule IDxccdf_org.ssgproject.content_rule_grub2_disable_interactive_boot
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-grub2_disable_interactive_boot:def:1
Time2020-09-29T11:18:02
Severitymedium
Identifiers and References

Identifiers:  CCE-80826-1

References:  11, 12, 14, 15, 16, 18, 3, 5, DSS05.02, DSS05.04, DSS05.05, DSS05.07, DSS06.03, DSS06.06, 3.1.2, 3.4.5, CCI-000213, 164.308(a)(1)(ii)(B), 164.308(a)(7)(i), 164.308(a)(7)(ii)(A), 164.310(a)(1), 164.310(a)(2)(i), 164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(b), 164.310(c), 164.310(d)(1), 164.310(d)(2)(iii), 4.3.3.2.2, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, A.6.1.2, A.7.1.1, A.9.1.2, A.9.2.1, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, SC-2(1), CM-6(a), PR.AC-4, PR.AC-6, PR.PT-3, FIA_AFL.1, SRG-OS-000480-GPOS-00227

Description

Red Hat Enterprise Linux 8 systems support an "interactive boot" option that can be used to prevent services from being started. On a Red Hat Enterprise Linux 8 system, interactive boot can be enabled by providing a 1, yes, true, or on value to the systemd.confirm_spawn kernel argument in /etc/default/grub. Remove any instance of

systemd.confirm_spawn=(1|yes|true|on)
from the kernel arguments in that file to disable interactive boot. It is also required to change the runtime configuration, run:
/sbin/grubby --update-kernel=ALL --remove-args="systemd.confirm_spawn"

Rationale

Using interactive boot, the console user could disable auditing, firewalls, or other services, weakening system security.

OVAL test results details

Check systemd.confirm_spawn=(1|true|yes|on) not in GRUB_CMDLINE_LINUX  oval:ssg-test_grub2_disable_interactive_boot_grub_cmdline_linux:tst:1  true

No items have been found conforming to the following objects:
Object oval:ssg-object_grub2_disable_interactive_boot_grub_cmdline_linux:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/default/grub^\s*GRUB_CMDLINE_LINUX=".*systemd.confirm_spawn=(?:1|yes|true|on).*$1

Check systemd.confirm_spawn=(1|true|yes|on) not in GRUB_CMDLINE_LINUX_DEFAULT  oval:ssg-test_grub2_disable_interactive_boot_grub_cmdline_linux_default:tst:1  true

No items have been found conforming to the following objects:
Object oval:ssg-object_grub2_disable_interactive_boot_grub_cmdline_linux_default:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/default/grub^\s*GRUB_CMDLINE_LINUX_DEFAULT=".*systemd.confirm_spawn=(?:1|yes|true|on).*$1

Check for GRUB_DISABLE_RECOVERY=true in /etc/default/grub  oval:ssg-test_bootloader_disable_recovery_set_to_true:tst:1  true

Following items have been found on the system:
PathContent
/etc/default/grubGRUB_DISABLE_RECOVERY="true"
Disable Ctrl-Alt-Del Burst Actionxccdf_org.ssgproject.content_rule_disable_ctrlaltdel_burstaction highCCE-80784-2

Disable Ctrl-Alt-Del Burst Action

Rule IDxccdf_org.ssgproject.content_rule_disable_ctrlaltdel_burstaction
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-disable_ctrlaltdel_burstaction:def:1
Time2020-09-29T11:21:09
Severityhigh
Identifiers and References

Identifiers:  CCE-80784-2

References:  12, 13, 14, 15, 16, 18, 3, 5, APO01.06, DSS05.04, DSS05.07, DSS06.02, 3.4.5, CCI-000366, 164.308(a)(1)(ii)(B), 164.308(a)(7)(i), 164.308(a)(7)(ii)(A), 164.310(a)(1), 164.310(a)(2)(i), 164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(b), 164.310(c), 164.310(d)(1), 164.310(d)(2)(iii), 4.3.3.7.3, SR 2.1, SR 5.2, A.10.1.1, A.11.1.4, A.11.1.5, A.11.2.1, A.13.1.1, A.13.1.3, A.13.2.1, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3, A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, CM-6(a), AC-6(1), CM-6(a), PR.AC-4, PR.DS-5, SRG-OS-000324-GPOS-00125

Description

By default, SystemD will reboot the system if the Ctrl-Alt-Del key sequence is pressed Ctrl-Alt-Delete more than 7 times in 2 seconds.

To configure the system to ignore the CtrlAltDelBurstAction setting, add or modify the following to /etc/systemd/system.conf:

CtrlAltDelBurstAction=none

Rationale

A locally logged-in user who presses Ctrl-Alt-Del, when at the console, can reboot the system. If accidentally pressed, as could happen in the case of mixed OS environment, this can create the risk of short-term loss of availability of systems due to unintentional reboot.

Warnings
warning  Disabling the Ctrl-Alt-Del key sequence in /etc/init/control-alt-delete.conf DOES NOT disable the Ctrl-Alt-Del key sequence if running in runlevel 6 (e.g. in GNOME, KDE, etc.)! The Ctrl-Alt-Del key sequence will only be disabled if running in the non-graphical runlevel 3.
Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

check if CtrlAltDelBurstAction is set to none  oval:ssg-test_disable_ctrlaltdel_burstaction:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_disable_ctrlaltdel_burstaction:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/systemd/system.conf^[\s]*CtrlAltDelBurstAction[\s]*=[\s]*none$1
Enable GNOME3 Login Warning Bannerxccdf_org.ssgproject.content_rule_dconf_gnome_banner_enabled mediumCCE-80768-5

Enable GNOME3 Login Warning Banner

Rule IDxccdf_org.ssgproject.content_rule_dconf_gnome_banner_enabled
Result
notapplicable
Multi-check ruleno
Time2020-09-29T11:18:02
Severitymedium
Identifiers and References

Identifiers:  CCE-80768-5

References:  1.7.2, 1, 12, 15, 16, DSS05.04, DSS05.10, DSS06.10, 3.1.9, CCI-000048, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, SR 1.1, SR 1.10, SR 1.2, SR 1.5, SR 1.7, SR 1.8, SR 1.9, A.18.1.4, A.9.2.1, A.9.2.4, A.9.3.1, A.9.4.2, A.9.4.3, AC-8(a), AC-8(b), AC-8(c), PR.AC-7, FMT_MOF_EXT.1, SRG-OS-000023-GPOS-00006, SRG-OS-000024-GPOS-00007, SRG-OS-000228-GPOS-00088

Description

In the default graphical environment, displaying a login warning banner in the GNOME Display Manager's login screen can be enabled on the login screen by setting banner-message-enable to true.

To enable, add or edit banner-message-enable to /etc/dconf/db/gdm.d/00-security-settings. For example:

[org/gnome/login-screen]
banner-message-enable=true
Once the setting has been added, add a lock to /etc/dconf/db/gdm.d/locks/00-security-settings-lock to prevent user modification. For example:
/org/gnome/login-screen/banner-message-enable
After the settings have been set, run dconf update. The banner text must also be set.

Rationale

Display of a standardized and approved use notification before granting access to the operating system ensures privacy and security notification verbiage used is consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance.

For U.S. Government systems, system use notifications are required only for access via login interfaces with human users and are not required when such human interfaces do not exist.

Modify the System Login Bannerxccdf_org.ssgproject.content_rule_banner_etc_issue mediumCCE-80763-6

Modify the System Login Banner

Rule IDxccdf_org.ssgproject.content_rule_banner_etc_issue
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-banner_etc_issue:def:1
Time2020-09-29T11:21:09
Severitymedium
Identifiers and References

Identifiers:  CCE-80763-6

References:  1.7.1.2, 1, 12, 15, 16, DSS05.04, DSS05.10, DSS06.10, 3.1.9, CCI-000048, CCI-000050, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, SR 1.1, SR 1.10, SR 1.2, SR 1.5, SR 1.7, SR 1.8, SR 1.9, A.18.1.4, A.9.2.1, A.9.2.4, A.9.3.1, A.9.4.2, A.9.4.3, AC-8(a), AC-8(c), PR.AC-7, FMT_MOF_EXT.1, SRG-OS-000023-GPOS-00006, SRG-OS-000024-GPOS-00007, SRG-OS-000023-VMM-000060, SRG-OS-000024-VMM-000070

Description

To configure the system login banner edit /etc/issue. Replace the default text with a message compliant with the local site policy or a legal disclaimer. The DoD required text is either:

You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device attached to this IS), you consent to the following conditions:
-The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations.
-At any time, the USG may inspect and seize data stored on this IS.
-Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG-authorized purpose.
-This IS includes security measures (e.g., authentication and access controls) to protect USG interests -- not for your personal benefit or privacy.
-Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details.


OR:

I've read & consent to terms in IS user agreem't.

Rationale

Display of a standardized and approved use notification before granting access to the operating system ensures privacy and security notification verbiage used is consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance.

System use notifications are required only for access via login interfaces with human users and are not required when such human interfaces do not exist.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

correct banner in /etc/issue  oval:ssg-test_banner_etc_issue:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_banner_etc_issue:obj:1 of type textfilecontent54_object
FilepathPatternInstance
(^You[\s\n]+are[\s\n]+accessing[\s\n]+a[\s\n]+U.S.[\s\n]+Government[\s\n]+\(USG\)[\s\n]+Information[\s\n]+System[\s\n]+\(IS\)[\s\n]+that[\s\n]+is[\s\n]+provided[\s\n]+for[\s\n]+USG-authorized[\s\n]+use[\s\n]+only.[\s\n]*By[\s\n]+using[\s\n]+this[\s\n]+IS[\s\n]+\(which[\s\n]+includes[\s\n]+any[\s\n]+device[\s\n]+attached[\s\n]+to[\s\n]+this[\s\n]+IS\),[\s\n]+you[\s\n]+consent[\s\n]+to[\s\n]+the[\s\n]+following[\s\n]+conditions\:(\\n)*(\n)*-[\s\n]*The[\s\n]+USG[\s\n]+routinely[\s\n]+intercepts[\s\n]+and[\s\n]+monitors[\s\n]+communications[\s\n]+on[\s\n]+this[\s\n]+IS[\s\n]+for[\s\n]+purposes[\s\n]+including,[\s\n]+but[\s\n]+not[\s\n]+limited[\s\n]+to,[\s\n]+penetration[\s\n]+testing,[\s\n]+COMSEC[\s\n]+monitoring,[\s\n]+network[\s\n]+operations[\s\n]+and[\s\n]+defense,[\s\n]+personnel[\s\n]+misconduct[\s\n]+\(PM\),[\s\n]+law[\s\n]+enforcement[\s\n]+\(LE\),[\s\n]+and[\s\n]+counterintelligence[\s\n]+\(CI\)[\s\n]+investigations.(\\n)*(\n)*-[\s\n]*At[\s\n]+any[\s\n]+time,[\s\n]+the[\s\n]+USG[\s\n]+may[\s\n]+inspect[\s\n]+and[\s\n]+seize[\s\n]+data[\s\n]+stored[\s\n]+on[\s\n]+this[\s\n]+IS.(\\n)*(\n)*-[\s\n]*Communications[\s\n]+using,[\s\n]+or[\s\n]+data[\s\n]+stored[\s\n]+on,[\s\n]+this[\s\n]+IS[\s\n]+are[\s\n]+not[\s\n]+private,[\s\n]+are[\s\n]+subject[\s\n]+to[\s\n]+routine[\s\n]+monitoring,[\s\n]+interception,[\s\n]+and[\s\n]+search,[\s\n]+and[\s\n]+may[\s\n]+be[\s\n]+disclosed[\s\n]+or[\s\n]+used[\s\n]+for[\s\n]+any[\s\n]+USG-authorized[\s\n]+purpose.(\\n)*(\n)*-[\s\n]*This[\s\n]+IS[\s\n]+includes[\s\n]+security[\s\n]+measures[\s\n]+\(e.g.,[\s\n]+authentication[\s\n]+and[\s\n]+access[\s\n]+controls\)[\s\n]+to[\s\n]+protect[\s\n]+USG[\s\n]+interests--not[\s\n]+for[\s\n]+your[\s\n]+personal[\s\n]+benefit[\s\n]+or[\s\n]+privacy.(\\n)*(\n)*-[\s\n]*Notwithstanding[\s\n]+the[\s\n]+above,[\s\n]+using[\s\n]+this[\s\n]+IS[\s\n]+does[\s\n]+not[\s\n]+constitute[\s\n]+consent[\s\n]+to[\s\n]+PM,[\s\n]+LE[\s\n]+or[\s\n]+CI[\s\n]+investigative[\s\n]+searching[\s\n]+or[\s\n]+monitoring[\s\n]+of[\s\n]+the[\s\n]+content[\s\n]+of[\s\n]+privileged[\s\n]+communications,[\s\n]+or[\s\n]+work[\s\n]+product,[\s\n]+related[\s\n]+to[\s\n]+personal[\s\n]+representation[\s\n]+or[\s\n]+services[\s\n]+by[\s\n]+attorneys,[\s\n]+psychotherapists,[\s\n]+or[\s\n]+clergy,[\s\n]+and[\s\n]+their[\s\n]+assistants.[\s\n]+Such[\s\n]+communications[\s\n]+and[\s\n]+work[\s\n]+product[\s\n]+are[\s\n]+private[\s\n]+and[\s\n]+confidential.[\s\n]+See[\s\n]+User[\s\n]+Agreement[\s\n]+for[\s\n]+details.$|^I\'ve[\s\n]+read[\s\n]+\&[\s\n]+consent[\s\n]+to[\s\n]+terms[\s\n]+in[\s\n]+IS[\s\n]+user[\s\n]+agreem\'t$)/etc/issue1
Ensure PAM Enforces Password Requirements - Minimum Lowercase Charactersxccdf_org.ssgproject.content_rule_accounts_password_pam_lcredit mediumCCE-80655-4

Ensure PAM Enforces Password Requirements - Minimum Lowercase Characters

Rule IDxccdf_org.ssgproject.content_rule_accounts_password_pam_lcredit
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-accounts_password_pam_lcredit:def:1
Time2020-09-29T11:21:09
Severitymedium
Identifiers and References

Identifiers:  CCE-80655-4

References:  1, 12, 15, 16, 5, DSS05.04, DSS05.05, DSS05.07, DSS05.10, DSS06.03, DSS06.10, CCI-000193, 4.3.3.2.2, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.2, 4.3.3.7.4, SR 1.1, SR 1.10, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.7, SR 1.8, SR 1.9, SR 2.1, A.18.1.4, A.7.1.1, A.9.2.1, A.9.2.2, A.9.2.3, A.9.2.4, A.9.2.6, A.9.3.1, A.9.4.2, A.9.4.3, IA-5(c), IA-5(1)(a), CM-6(a), IA-5(4), PR.AC-1, PR.AC-6, PR.AC-7, FMT_MOF_EXT.1, Req-8.2.3, SRG-OS-000070-GPOS-00038, SRG-OS-000070-VMM-000370

Description

The pam_pwquality module's lcredit parameter controls requirements for usage of lowercase letters in a password. When set to a negative number, any password will be required to contain that many lowercase characters. When set to a positive number, pam_pwquality will grant +1 additional length credit for each lowercase character. Modify the lcredit setting in /etc/security/pwquality.conf to require the use of a lowercase character in passwords.

Rationale

Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks.

Password complexity is one factor of several that determines how long it takes to crack a password. The more complex the password, the greater the number of possble combinations that need to be tested before the password is compromised. Requiring a minimum number of lowercase characters makes password guessing attacks more difficult by ensuring a larger search space.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

check the configuration of /etc/pam.d/system-auth  oval:ssg-test_password_pam_pwquality:tst:1  true

Following items have been found on the system:
PathContent
/etc/pam.d/system-auth password requisite pam_pwquality.so try_first_pass local_users_only

check the configuration of /etc/security/pwquality.conf  oval:ssg-test_password_pam_pwquality_lcredit:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_password_pam_pwquality_lcredit:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/security/pwquality.conf^lcredit[\s]*=[\s]*(-?\d+)(?:[\s]|$)1
Ensure PAM Enforces Password Requirements - Minimum Uppercase Charactersxccdf_org.ssgproject.content_rule_accounts_password_pam_ucredit mediumCCE-80665-3

Ensure PAM Enforces Password Requirements - Minimum Uppercase Characters

Rule IDxccdf_org.ssgproject.content_rule_accounts_password_pam_ucredit
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-accounts_password_pam_ucredit:def:1
Time2020-09-29T11:21:09
Severitymedium
Identifiers and References

Identifiers:  CCE-80665-3

References:  6.3.2, 1, 12, 15, 16, 5, DSS05.04, DSS05.05, DSS05.07, DSS05.10, DSS06.03, DSS06.10, CCI-000192, 4.3.3.2.2, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.2, 4.3.3.7.4, SR 1.1, SR 1.10, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.7, SR 1.8, SR 1.9, SR 2.1, A.18.1.4, A.7.1.1, A.9.2.1, A.9.2.2, A.9.2.3, A.9.2.4, A.9.2.6, A.9.3.1, A.9.4.2, A.9.4.3, IA-5(c), IA-5(1)(a), CM-6(a), IA-5(4), PR.AC-1, PR.AC-6, PR.AC-7, FMT_MOF_EXT.1, Req-8.2.3, SRG-OS-000069-GPOS-00037, SRG-OS-000069-VMM-000360

Description

The pam_pwquality module's ucredit= parameter controls requirements for usage of uppercase letters in a password. When set to a negative number, any password will be required to contain that many uppercase characters. When set to a positive number, pam_pwquality will grant +1 additional length credit for each uppercase character. Modify the ucredit setting in /etc/security/pwquality.conf to require the use of an uppercase character in passwords.

Rationale

Use of a complex password helps to increase the time and resources reuiqred to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks.

Password complexity is one factor of several that determines how long it takes to crack a password. The more complex the password, the greater the number of possible combinations that need to be tested before the password is compromised.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

check the configuration of /etc/pam.d/system-auth  oval:ssg-test_password_pam_pwquality:tst:1  true

Following items have been found on the system:
PathContent
/etc/pam.d/system-auth password requisite pam_pwquality.so try_first_pass local_users_only

check the configuration of /etc/security/pwquality.conf  oval:ssg-test_password_pam_pwquality_ucredit:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_password_pam_pwquality_ucredit:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/security/pwquality.conf^ucredit[\s]*=[\s]*(-?\d+)(?:[\s]|$)1
Ensure PAM Enforces Password Requirements - Maximum Consecutive Repeating Characters from Same Character Classxccdf_org.ssgproject.content_rule_accounts_password_pam_maxclassrepeat mediumCCE-81034-1

Ensure PAM Enforces Password Requirements - Maximum Consecutive Repeating Characters from Same Character Class

Rule IDxccdf_org.ssgproject.content_rule_accounts_password_pam_maxclassrepeat
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-accounts_password_pam_maxclassrepeat:def:1
Time2020-09-29T11:21:09
Severitymedium
Identifiers and References

Identifiers:  CCE-81034-1

References:  1, 12, 15, 16, 5, DSS05.04, DSS05.05, DSS05.07, DSS05.10, DSS06.03, DSS06.10, CCI-000195, 4.3.3.2.2, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.2, 4.3.3.7.4, SR 1.1, SR 1.10, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.7, SR 1.8, SR 1.9, SR 2.1, A.18.1.4, A.7.1.1, A.9.2.1, A.9.2.2, A.9.2.3, A.9.2.4, A.9.2.6, A.9.3.1, A.9.4.2, A.9.4.3, IA-5(c), IA-5(1)(a), CM-6(a), IA-5(4), PR.AC-1, PR.AC-6, PR.AC-7, SRG-OS-000072-GPOS-00040

Description

The pam_pwquality module's maxclassrepeat parameter controls requirements for consecutive repeating characters from the same character class. When set to a positive number, it will reject passwords which contain more than that number of consecutive characters from the same character class. Modify the maxclassrepeat setting in /etc/security/pwquality.conf to equal 4 to prevent a run of (4 + 1) or more identical characters.

Rationale

Use of a complex password helps to increase the time and resources required to comrpomise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks.
Password complexity is one factor of several that determines how long it takes to crack a password. The more complex a password, the greater the number of possible combinations that need to be tested before the password is compromised.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

check the configuration of /etc/pam.d/system-auth  oval:ssg-test_password_pam_pwquality:tst:1  true

Following items have been found on the system:
PathContent
/etc/pam.d/system-auth password requisite pam_pwquality.so try_first_pass local_users_only

check the configuration of /etc/security/pwquality.conf  oval:ssg-test_password_pam_pwquality_maxclassrepeat:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_password_pam_pwquality_maxclassrepeat:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/security/pwquality.conf^maxclassrepeat[\s]*=[\s]*(\d+)(?:[\s]|$)1
Ensure PAM Enforces Password Requirements - Minimum Different Charactersxccdf_org.ssgproject.content_rule_accounts_password_pam_difok mediumCCE-80654-7

Ensure PAM Enforces Password Requirements - Minimum Different Characters

Rule IDxccdf_org.ssgproject.content_rule_accounts_password_pam_difok
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-accounts_password_pam_difok:def:1
Time2020-09-29T11:21:09
Severitymedium
Identifiers and References

Identifiers:  CCE-80654-7

References:  1, 12, 15, 16, 5, 5.6.2.1.1, DSS05.04, DSS05.05, DSS05.07, DSS05.10, DSS06.03, DSS06.10, CCI-000195, 4.3.3.2.2, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.2, 4.3.3.7.4, SR 1.1, SR 1.10, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.7, SR 1.8, SR 1.9, SR 2.1, A.18.1.4, A.7.1.1, A.9.2.1, A.9.2.2, A.9.2.3, A.9.2.4, A.9.2.6, A.9.3.1, A.9.4.2, A.9.4.3, IA-5(c), IA-5(1)(b), CM-6(a), IA-5(4), PR.AC-1, PR.AC-6, PR.AC-7, SRG-OS-000072-GPOS-00040, SRG-OS-000072-VMM-000390

Description

The pam_pwquality module's difok parameter sets the number of characters in a password that must not be present in and old password during a password change.

Modify the difok setting in /etc/security/pwquality.conf to equal 4 to require differing characters when changing passwords.

Rationale

Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute–force attacks.

Password complexity is one factor of several that determines how long it takes to crack a password. The more complex the password, the greater the number of possible combinations that need to be tested before the password is compromised.

Requiring a minimum number of different characters during password changes ensures that newly changed passwords should not resemble previously compromised ones. Note that passwords which are changed on compromised systems will still be compromised, however.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

check the configuration of /etc/pam.d/system-auth  oval:ssg-test_password_pam_pwquality:tst:1  true

Following items have been found on the system:
PathContent
/etc/pam.d/system-auth password requisite pam_pwquality.so try_first_pass local_users_only

check the configuration of /etc/security/pwquality.conf  oval:ssg-test_password_pam_pwquality_difok:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_password_pam_pwquality_difok:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/security/pwquality.conf^difok[\s]*=[\s]*(\d+)(?:[\s]|$)1
Ensure PAM Enforces Password Requirements - Minimum Digit Charactersxccdf_org.ssgproject.content_rule_accounts_password_pam_dcredit mediumCCE-80653-9

Ensure PAM Enforces Password Requirements - Minimum Digit Characters

Rule IDxccdf_org.ssgproject.content_rule_accounts_password_pam_dcredit
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-accounts_password_pam_dcredit:def:1
Time2020-09-29T11:21:09
Severitymedium
Identifiers and References

Identifiers:  CCE-80653-9

References:  6.3.2, 1, 12, 15, 16, 5, DSS05.04, DSS05.05, DSS05.07, DSS05.10, DSS06.03, DSS06.10, CCI-000194, 4.3.3.2.2, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.2, 4.3.3.7.4, SR 1.1, SR 1.10, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.7, SR 1.8, SR 1.9, SR 2.1, A.18.1.4, A.7.1.1, A.9.2.1, A.9.2.2, A.9.2.3, A.9.2.4, A.9.2.6, A.9.3.1, A.9.4.2, A.9.4.3, IA-5(c), IA-5(1)(a), CM-6(a), IA-5(4), PR.AC-1, PR.AC-6, PR.AC-7, FMT_MOF_EXT.1, Req-8.2.3, SRG-OS-000071-GPOS-00039, SRG-OS-000071-VMM-000380

Description

The pam_pwquality module's dcredit parameter controls requirements for usage of digits in a password. When set to a negative number, any password will be required to contain that many digits. When set to a positive number, pam_pwquality will grant +1 additional length credit for each digit. Modify the dcredit setting in /etc/security/pwquality.conf to require the use of a digit in passwords.

Rationale

Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks.

Password complexity is one factor of several that determines how long it takes to crack a password. The more complex the password, the greater the number of possible combinations that need to be tested before the password is compromised. Requiring digits makes password guessing attacks more difficult by ensuring a larger search space.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

check the configuration of /etc/pam.d/system-auth  oval:ssg-test_password_pam_pwquality:tst:1  true

Following items have been found on the system:
PathContent
/etc/pam.d/system-auth password requisite pam_pwquality.so try_first_pass local_users_only

check the configuration of /etc/security/pwquality.conf  oval:ssg-test_password_pam_pwquality_dcredit:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_password_pam_pwquality_dcredit:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/security/pwquality.conf^dcredit[\s]*=[\s]*(-?\d+)(?:[\s]|$)1
Set Password Maximum Consecutive Repeating Charactersxccdf_org.ssgproject.content_rule_accounts_password_pam_maxrepeat mediumCCE-82066-2

Set Password Maximum Consecutive Repeating Characters

Rule IDxccdf_org.ssgproject.content_rule_accounts_password_pam_maxrepeat
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-accounts_password_pam_maxrepeat:def:1
Time2020-09-29T11:21:09
Severitymedium
Identifiers and References

Identifiers:  CCE-82066-2

References:  1, 12, 15, 16, 5, DSS05.04, DSS05.05, DSS05.07, DSS05.10, DSS06.03, DSS06.10, CCI-000195, 4.3.3.2.2, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.2, 4.3.3.7.4, SR 1.1, SR 1.10, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.7, SR 1.8, SR 1.9, SR 2.1, A.18.1.4, A.7.1.1, A.9.2.1, A.9.2.2, A.9.2.3, A.9.2.4, A.9.2.6, A.9.3.1, A.9.4.2, A.9.4.3, IA-5(c), CM-6(a), IA-5(4), PR.AC-1, PR.AC-6, PR.AC-7, SRG-OS-000072-GPOS-00040

Description

The pam_pwquality module's maxrepeat parameter controls requirements for consecutive repeating characters. When set to a positive number, it will reject passwords which contain more than that number of consecutive characters. Modify the maxrepeat setting in /etc/security/pwquality.conf to equal 3 to prevent a run of (3 + 1) or more identical characters.

Rationale

Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks.

Password complexity is one factor of several that determines how long it takes to crack a password. The more complex the password, the greater the number of possible combinations that need to be tested before the password is compromised.

Passwords with excessive repeating characters may be more vulnerable to password-guessing attacks.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

check the configuration of /etc/pam.d/system-auth  oval:ssg-test_password_pam_pwquality:tst:1  true

Following items have been found on the system:
PathContent
/etc/pam.d/system-auth password requisite pam_pwquality.so try_first_pass local_users_only

check the configuration of /etc/security/pwquality.conf  oval:ssg-test_password_pam_pwquality_maxrepeat:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_password_pam_pwquality_maxrepeat:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/security/pwquality.conf^maxrepeat[\s]*=[\s]*(\d+)(?:[\s]|$)1
Ensure PAM Enforces Password Requirements - Minimum Lengthxccdf_org.ssgproject.content_rule_accounts_password_pam_minlen mediumCCE-80656-2

Ensure PAM Enforces Password Requirements - Minimum Length

Rule IDxccdf_org.ssgproject.content_rule_accounts_password_pam_minlen
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-accounts_password_pam_minlen:def:1
Time2020-09-29T11:21:09
Severitymedium
Identifiers and References

Identifiers:  CCE-80656-2

References:  6.3.2, 1, 12, 15, 16, 5, 5.6.2.1.1, DSS05.04, DSS05.05, DSS05.07, DSS05.10, DSS06.03, DSS06.10, CCI-000205, 4.3.3.2.2, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.2, 4.3.3.7.4, SR 1.1, SR 1.10, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.7, SR 1.8, SR 1.9, SR 2.1, A.18.1.4, A.7.1.1, A.9.2.1, A.9.2.2, A.9.2.3, A.9.2.4, A.9.2.6, A.9.3.1, A.9.4.2, A.9.4.3, IA-5(c), IA-5(1)(a), CM-6(a), IA-5(4), PR.AC-1, PR.AC-6, PR.AC-7, FMT_MOF_EXT.1, Req-8.2.3, SRG-OS-000078-GPOS-00046, SRG-OS-000072-VMM-000390, SRG-OS-000078-VMM-000450

Description

The pam_pwquality module's minlen parameter controls requirements for minimum characters required in a password. Add minlen=12 after pam_pwquality to set minimum password length requirements.

Rationale

The shorter the password, the lower the number of possible combinations that need to be tested before the password is compromised.
Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. Password length is one factor of several that helps to determine strength and how long it takes to crack a password. Use of more characters in a password helps to exponentially increase the time and/or resources required to compromose the password.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

check the configuration of /etc/pam.d/system-auth  oval:ssg-test_password_pam_pwquality:tst:1  true

Following items have been found on the system:
PathContent
/etc/pam.d/system-auth password requisite pam_pwquality.so try_first_pass local_users_only

check the configuration of /etc/security/pwquality.conf  oval:ssg-test_password_pam_pwquality_minlen:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_password_pam_pwquality_minlen:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/security/pwquality.conf^minlen[\s]*=[\s]*(\d+)(?:[\s]|$)1
Ensure PAM Enforces Password Requirements - Minimum Special Charactersxccdf_org.ssgproject.content_rule_accounts_password_pam_ocredit mediumCCE-80663-8

Ensure PAM Enforces Password Requirements - Minimum Special Characters

Rule IDxccdf_org.ssgproject.content_rule_accounts_password_pam_ocredit
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-accounts_password_pam_ocredit:def:1
Time2020-09-29T11:21:09
Severitymedium
Identifiers and References

Identifiers:  CCE-80663-8

References:  1, 12, 15, 16, 5, DSS05.04, DSS05.05, DSS05.07, DSS05.10, DSS06.03, DSS06.10, CCI-001619, 4.3.3.2.2, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.2, 4.3.3.7.4, SR 1.1, SR 1.10, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.7, SR 1.8, SR 1.9, SR 2.1, A.18.1.4, A.7.1.1, A.9.2.1, A.9.2.2, A.9.2.3, A.9.2.4, A.9.2.6, A.9.3.1, A.9.4.2, A.9.4.3, IA-5(c), IA-5(1)(a), CM-6(a), IA-5(4), PR.AC-1, PR.AC-6, PR.AC-7, FMT_MOF_EXT.1, SRG-OS-000266-GPOS-00101, SRG-OS-000266-VMM-000940

Description

The pam_pwquality module's ocredit= parameter controls requirements for usage of special (or "other") characters in a password. When set to a negative number, any password will be required to contain that many special characters. When set to a positive number, pam_pwquality will grant +1 additional length credit for each special character. Modify the ocredit setting in /etc/security/pwquality.conf to equal -1 to require use of a special character in passwords.

Rationale

Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks.

Password complexity is one factor of several that determines how long it takes to crack a password. The more complex the password, the greater the number of possble combinations that need to be tested before the password is compromised. Requiring a minimum number of special characters makes password guessing attacks more difficult by ensuring a larger search space.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

check the configuration of /etc/pam.d/system-auth  oval:ssg-test_password_pam_pwquality:tst:1  true

Following items have been found on the system:
PathContent
/etc/pam.d/system-auth password requisite pam_pwquality.so try_first_pass local_users_only

check the configuration of /etc/security/pwquality.conf  oval:ssg-test_password_pam_pwquality_ocredit:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_password_pam_pwquality_ocredit:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/security/pwquality.conf^ocredit[\s]*=[\s]*(-?\d+)(?:[\s]|$)1
Set Deny For Failed Password Attemptsxccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny mediumCCE-80667-9

Set Deny For Failed Password Attempts

Rule IDxccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-accounts_passwords_pam_faillock_deny:def:1
Time2020-09-29T11:21:09
Severitymedium
Identifiers and References

Identifiers:  CCE-80667-9

References:  5.3.2, 1, 12, 15, 16, 5.5.3, DSS05.04, DSS05.10, DSS06.10, 3.1.8, CCI-002238, CCI-000044, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, SR 1.1, SR 1.10, SR 1.2, SR 1.5, SR 1.7, SR 1.8, SR 1.9, A.18.1.4, A.9.2.1, A.9.2.4, A.9.3.1, A.9.4.2, A.9.4.3, CM-6(a), AC-7(a), PR.AC-7, FMT_MOF_EXT.1, Req-8.1.6, SRG-OS-000329-GPOS-00128, SRG-OS-000021-GPOS-00005, SRG-OS-000021-VMM-000050

Description

To configure the system to lock out accounts after a number of incorrect login attempts using pam_faillock.so, modify the content of both /etc/pam.d/system-auth and /etc/pam.d/password-auth as follows:

  • add the following line immediately before the pam_unix.so statement in the AUTH section:
    auth required pam_faillock.so preauth silent deny=3 unlock_time=0 fail_interval=900
  • add the following line immediately after the pam_unix.so statement in the AUTH section:
    auth [default=die] pam_faillock.so authfail deny=3 unlock_time=0 fail_interval=900
  • add the following line immediately before the pam_unix.so statement in the ACCOUNT section:
    account required pam_faillock.so

Rationale

Locking out user accounts after a number of incorrect attempts prevents direct password guessing attacks.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

Check pam_faillock.so preauth silent present, with correct deny value, and is followed by pam_unix.  oval:ssg-test_accounts_passwords_pam_faillock_preauth_silent_system-auth:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_accounts_passwords_pam_faillock_preauth_silent_system-auth:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/pam.d/system-auth[\n][\s]*auth[\s]+required[\s]+pam_faillock\.so[\s]+preauth[\s]+[^\n]*silent[\s]+[^\n]*deny=([0-9]+)[\s]*(?s).*[\n][\s]*auth[^\n]+pam_unix\.so[^\n]*[\n]1

Check if pam_faillock.so is called in account phase before pam_unix  oval:ssg-test_accounts_passwords_pam_faillock_account_phase_system-auth:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_accounts_passwords_pam_faillock_account_phase_system-auth:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/pam.d/system-auth[\n][\s]*account[\s]+required[\s]+pam_faillock\.so[^\n]*[\n][\s]*account[\s]+required[\s]+pam_unix\.so[^\n]*[\n]1

Check pam_faillock.so preauth silent present in /etc/pam.d/password-auth, has correct deny value, and is followed by pam_unix  oval:ssg-test_accounts_passwords_pam_faillock_preauth_silent_password-auth:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_accounts_passwords_pam_faillock_preauth_silent_password-auth:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/pam.d/password-auth[\n][\s]*auth[\s]+required[\s]+pam_faillock\.so[\s]+preauth[\s]+[^\n]*silent[\s]+[^\n]*deny=([0-9]+)[\s]*(?s).*[\n][\s]*auth[^\n]+pam_unix\.so[^\n]*[\n]1

Check if pam_faillock_so is called in account phase before pam_unix.  oval:ssg-test_accounts_passwords_pam_faillock_account_phase_password-auth:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_accounts_passwords_pam_faillock_account_phase_password-auth:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/pam.d/password-auth[\n][\s]*account[\s]+required[\s]+pam_faillock\.so[^\n]*[\n][\s]*account[\s]+required[\s]+pam_unix\.so[^\n]*[\n]1

Checks if pam_faillock authfail is hit even if pam_unix skips lines by defaulting, and also authfail deny value  oval:ssg-test_accounts_passwords_pam_faillock_numeric_default_check_system-auth:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_accounts_passwords_pam_faillock_when_lines_skipped_system-auth:obj:1 of type textfilecontent54_object
FilepathPatternInstance
3Referenced variable has no values (oval:ssg-var_accounts_passwords_pam_faillock_preauth_default_lin/etc/pam.d/system-auth1

Check control values of pam_unix, that it is followed by pam_faillock.so authfail and deny value of pam_faillock.so authfail  oval:ssg-test_accounts_passwords_pam_faillock_authfail_deny_system-auth:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_accounts_passwords_pam_faillock_authfail_deny_system-auth:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/pam.d/system-auth[\n][\s]*auth[\s]+(?:(?:sufficient)|(?:\[[^\]]*default=ignore[^\]]*\]))[^\n]+pam_unix\.so(?:.*[\n])*auth[\s]+\[default=die\][\s]+pam_faillock\.so[\s]+authfail[^\n]+deny=([0-9]+)1

Checks if pam_faillock authfail is hit even if pam_unix skips lines by defaulting, and also authfail deny value  oval:ssg-test_accounts_passwords_pam_faillock_numeric_default_check_password-auth:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_accounts_passwords_pam_faillock_when_lines_skipped_password-auth:obj:1 of type textfilecontent54_object
FilepathPatternInstance
3Referenced variable has no values (oval:ssg-var_accounts_passwords_pam_faillock_preauth_default_lin/etc/pam.d/password-auth1

Check pam_faillock authfail is present after pam_unix, check pam_unix has proper control values, and authfail deny value is correct.  oval:ssg-test_accounts_passwords_pam_faillock_authfail_deny_password-auth:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_accounts_passwords_pam_faillock_authfail_deny_password-auth:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/pam.d/password-auth[\n][\s]*auth[\s]+(?:(?:sufficient)|(?:\[[^\]]*default=ignore[[^\]]*\]))[\s]+pam_unix\.so(?:.*[\n])*[^\n]*auth[\s]+\[default=die\][\s]+pam_faillock\.so[\s]+authfail[\s]+[^\n]*deny=([0-9]+)1
Set Interval For Counting Failed Password Attemptsxccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_interval mediumCCE-80669-5

Set Interval For Counting Failed Password Attempts

Rule IDxccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_interval
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-accounts_passwords_pam_faillock_interval:def:1
Time2020-09-29T11:21:09
Severitymedium
Identifiers and References

Identifiers:  CCE-80669-5

References:  1, 12, 15, 16, DSS05.04, DSS05.10, DSS06.10, CCI-002238, CCI-000044, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, SR 1.1, SR 1.10, SR 1.2, SR 1.5, SR 1.7, SR 1.8, SR 1.9, A.18.1.4, A.9.2.1, A.9.2.4, A.9.3.1, A.9.4.2, A.9.4.3, CM-6(a), AC-7(a), PR.AC-7, FMT_MOF_EXT.1, SRG-OS-000329-GPOS-00128, SRG-OS-000021-GPOS-00005, SRG-OS-000021-VMM-000050

Description

Utilizing pam_faillock.so, the fail_interval directive configures the system to lock out an account after a number of incorrect login attempts within a specified time period. Modify the content of both /etc/pam.d/system-auth and /etc/pam.d/password-auth as follows:

  • Add the following line immediately before the pam_unix.so statement in the AUTH section:
    auth required pam_faillock.so preauth silent deny=3 unlock_time=0 fail_interval=900
  • Add the following line immediately after the pam_unix.so statement in the AUTH section:
    auth [default=die] pam_faillock.so authfail deny=3 unlock_time=0 fail_interval=900
    
  • Add the following line immediately before the pam_unix.so statement in the ACCOUNT section:
    account required pam_faillock.so

Rationale

By limiting the number of failed logon attempts the risk of unauthorized system access via user password guessing, otherwise known as brute-forcing, is reduced. Limits are imposed by locking the account.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

check maximum preauth fail_interval allowed in /etc/pam.d/system-auth  oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_system-auth:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_system-auth:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/pam.d/system-auth^\s*auth\s+(?:(?:required))\s+pam_faillock\.so\s+preauth.*fail_interval=([0-9]*).*$1

check maximum authfail fail_interval allowed in /etc/pam.d/system-auth  oval:ssg-test_accounts_passwords_pam_faillock_authfail_fail_interval_system-auth:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_accounts_passwords_pam_faillock_authfail_fail_interval_system-auth:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/pam.d/system-auth^\s*auth\s+(?:(?:sufficient)|(?:\[default=die\]))\s+pam_faillock\.so\s+authfail.*fail_interval=([0-9]*).*$1

check maximum authfail fail_interval allowed in /etc/pam.d/password-auth  oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_password-auth:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_password-auth:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/pam.d/password-auth^\s*auth\s+(?:(?:sufficient)|(?:\[default=die\]))\s+pam_faillock\.so\s+authfail.*fail_interval=([0-9]*).*$1

check maximum preauth fail_interval allowed in /etc/pam.d/password-auth  oval:ssg-test_accounts_passwords_pam_faillock_preauth_fail_interval_password-auth:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_accounts_passwords_pam_faillock_preauth_fail_interval_password-auth:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/pam.d/password-auth^\s*auth\s+(?:(?:required))\s+pam_faillock\.so\s+preauth.*fail_interval=([0-9]*).*$1

check if pam_faillock.so is required in account section in /etc/pam.d/password-auth  oval:ssg-test_accounts_passwords_pam_faillock_account_requires_password-auth:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_accounts_passwords_pam_faillock_account_requires_password-auth:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/pam.d/password-auth^\s*account\s+required\s+pam_faillock\.so.*$1

check if pam_faillock.so is required in account section in /etc/pam.d/system-auth  oval:ssg-test_accounts_passwords_pam_faillock_account_requires_system-auth:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_accounts_passwords_pam_faillock_account_requires_system-auth:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/pam.d/system-auth^\s*account\s+required\s+pam_faillock\.so.*$1
Set Lockout Time for Failed Password Attemptsxccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_unlock_time mediumCCE-80670-3

Set Lockout Time for Failed Password Attempts

Rule IDxccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_unlock_time
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-accounts_passwords_pam_faillock_unlock_time:def:1
Time2020-09-29T11:21:09
Severitymedium
Identifiers and References

Identifiers:  CCE-80670-3

References:  5.3.2, 1, 12, 15, 16, 5.5.3, DSS05.04, DSS05.10, DSS06.10, 3.1.8, CCI-002238, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, SR 1.1, SR 1.10, SR 1.2, SR 1.5, SR 1.7, SR 1.8, SR 1.9, A.18.1.4, A.9.2.1, A.9.2.4, A.9.3.1, A.9.4.2, A.9.4.3, CM-6(a), AC-7(b), PR.AC-7, FMT_MOF_EXT.1, Req-8.1.7, SRG-OS-000329-GPOS-00128, SRG-OS-000021-GPOS-00005, SRG-OS-000329-VMM-001180

Description

To configure the system to lock out accounts after a number of incorrect login attempts and require an administrator to unlock the account using pam_faillock.so, modify the content of both /etc/pam.d/system-auth and /etc/pam.d/password-auth as follows:

  • add the following line immediately before the pam_unix.so statement in the AUTH section:
    auth required pam_faillock.so preauth silent deny=3 unlock_time=0 fail_interval=900
  • add the following line immediately after the pam_unix.so statement in the AUTH section:
    auth [default=die] pam_faillock.so authfail deny=3 unlock_time=0 fail_interval=900
  • add the following line immediately before the pam_unix.so statement in the ACCOUNT section:
    account required pam_faillock.so
If unlock_time is set to 0, manual intervention by an administrator is required to unlock a user.

Rationale

Locking out user accounts after a number of incorrect attempts prevents direct password guessing attacks. Ensuring that an administrator is involved in unlocking locked accounts draws appropriate attention to such situations.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

check preauth maximum failed login attempts allowed in /etc/pam.d/system-auth  oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_system-auth:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_system-auth:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/pam.d/system-auth^\s*auth\s+(?:(?:required))\s+pam_faillock\.so\s+preauth.*unlock_time=([0-9]*).*$1

check authfail maximum failed login attempts allowed in /etc/pam.d/system-auth  oval:ssg-test_accounts_passwords_pam_faillock_authfail_unlock_time_system-auth:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_accounts_passwords_pam_faillock_authfail_unlock_time_system-auth:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/pam.d/system-auth^\s*auth\s+(?:(?:sufficient)|(?:\[default=die\]))\s+pam_faillock\.so\s+authfail.*unlock_time=([0-9]*).*$1

check authfail maximum failed login attempts allowed in /etc/pam.d/password-auth  oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_password-auth:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_password-auth:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/pam.d/password-auth^\s*auth\s+(?:(?:sufficient)|(?:\[default=die\]))\s+pam_faillock\.so\s+authfail.*unlock_time=([0-9]*).*$1

check preauth maximum failed login attempts allowed in /etc/pam.d/password-auth  oval:ssg-test_accounts_passwords_pam_faillock_preauth_unlock_time_password-auth:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_accounts_passwords_pam_faillock_preauth_unlock_time_password-auth:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/pam.d/password-auth^\s*auth\s+(?:(?:required))\s+pam_faillock\.so\s+preauth.*unlock_time=([0-9]*).*$1
Limit Password Reusexccdf_org.ssgproject.content_rule_accounts_password_pam_unix_remember mediumCCE-80666-1

Limit Password Reuse

Rule IDxccdf_org.ssgproject.content_rule_accounts_password_pam_unix_remember
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-accounts_password_pam_unix_remember:def:1
Time2020-09-29T11:21:09
Severitymedium
Identifiers and References

Identifiers:  CCE-80666-1

References:  5.3.3, 1, 12, 15, 16, 5, 5.6.2.1.1, DSS05.04, DSS05.05, DSS05.07, DSS05.10, DSS06.03, DSS06.10, 3.5.8, CCI-000200, 4.3.3.2.2, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.2, 4.3.3.7.4, SR 1.1, SR 1.10, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.7, SR 1.8, SR 1.9, SR 2.1, A.18.1.4, A.7.1.1, A.9.2.1, A.9.2.2, A.9.2.3, A.9.2.4, A.9.2.6, A.9.3.1, A.9.4.2, A.9.4.3, IA-5(f), IA-5(1)(e), PR.AC-1, PR.AC-6, PR.AC-7, Req-8.2.5, SRG-OS-000077-GPOS-00045, SRG-OS-000077-VMM-000440

Description

Do not allow users to reuse recent passwords. This can be accomplished by using the remember option for the pam_unix or pam_pwhistory PAM modules.

In the file /etc/pam.d/system-auth, append remember=5 to the line which refers to the pam_unix.so or pam_pwhistory.somodule, as shown below:

  • for the pam_unix.so case:
    password sufficient pam_unix.so ...existing_options... remember=5
  • for the pam_pwhistory.so case:
    password requisite pam_pwhistory.so ...existing_options... remember=5
The DoD STIG requirement is 5 passwords.

Rationale

Preventing re-use of previous passwords helps ensure that a compromised password is not re-used by a user.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

Test if remember attribute of pam_unix.so is set correctly in /etc/pam.d/system-auth  oval:ssg-test_accounts_password_pam_unix_remember:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_accounts_password_pam_unix_remember:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/pam.d/system-auth^\s*password\s+(?:(?:sufficient)|(?:required))\s+pam_unix\.so.*remember=([0-9]*).*$1

Test if remember attribute of pam_pwhistory.so is set correctly in /etc/pam.d/system-auth  oval:ssg-test_accounts_password_pam_pwhistory_remember:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_accounts_password_pam_pwhistory_remember:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/pam.d/system-auth^\s*password\s+(?:(?:requisite)|(?:required))\s+pam_pwhistory\.so.*remember=([0-9]*).*$1
Ensure the Default Umask is Set Correctly in /etc/profilexccdf_org.ssgproject.content_rule_accounts_umask_etc_profile unknownCCE-81035-8

Ensure the Default Umask is Set Correctly in /etc/profile

Rule IDxccdf_org.ssgproject.content_rule_accounts_umask_etc_profile
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-accounts_umask_etc_profile:def:1
Time2020-09-29T11:21:09
Severityunknown
Identifiers and References

Identifiers:  CCE-81035-8

References:  NT28(R35), 5.4.4, 18, APO13.01, BAI03.01, BAI03.02, BAI03.03, CCI-000366, 4.3.4.3.3, A.14.1.1, A.14.2.1, A.14.2.5, A.6.1.5, AC-6(1), CM-6(a), PR.IP-2, SRG-OS-000480-GPOS-00228

Description

To ensure the default umask controlled by /etc/profile is set properly, add or correct the umask setting in /etc/profile to read as follows:

umask 027

Rationale

The umask value influences the permissions assigned to files when they are created. A misconfigured umask value could result in files with excessive permissions that can be read or written to by unauthorized users.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

Verify the existence of var_accounts_user_umask_as_number variable  oval:ssg-test_existence_of_var_accounts_user_umask_as_number_variable:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-var_accounts_user_umask_umask_as_number:var:123

Test the retrieved /etc/profile umask value(s) match the var_accounts_user_umask requirement  oval:ssg-tst_accounts_umask_etc_profile:tst:1  false

Following items have been found on the system:
Var refValueValueValueValueValueValueValueValue
oval:ssg-var_etc_profile_umask_as_number:var:1181822181822
Ensure the Default Bash Umask is Set Correctlyxccdf_org.ssgproject.content_rule_accounts_umask_etc_bashrc unknownCCE-81036-6

Ensure the Default Bash Umask is Set Correctly

Rule IDxccdf_org.ssgproject.content_rule_accounts_umask_etc_bashrc
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-accounts_umask_etc_bashrc:def:1
Time2020-09-29T11:21:09
Severityunknown
Identifiers and References

Identifiers:  CCE-81036-6

References:  5.4.4, 18, APO13.01, BAI03.01, BAI03.02, BAI03.03, CCI-000366, 4.3.4.3.3, A.14.1.1, A.14.2.1, A.14.2.5, A.6.1.5, AC-6(1), CM-6(a), PR.IP-2, SRG-OS-000480-GPOS-00228

Description

To ensure the default umask for users of the Bash shell is set properly, add or correct the umask setting in /etc/bashrc to read as follows:

umask 027

Rationale

The umask value influences the permissions assigned to files when they are created. A misconfigured umask value could result in files with excessive permissions that can be read or written to by unauthorized users.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

Verify the existence of var_accounts_user_umask_as_number variable  oval:ssg-test_existence_of_var_accounts_user_umask_as_number_variable:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-var_accounts_user_umask_umask_as_number:var:123

Test the retrieved /etc/bashrc umask value(s) match the var_accounts_user_umask requirement  oval:ssg-tst_accounts_umask_etc_bashrc:tst:1  false

Following items have been found on the system:
Var refValueValueValueValueValueValueValueValue
oval:ssg-var_etc_bashrc_umask_as_number:var:1221818221818
Ensure the Default C Shell Umask is Set Correctlyxccdf_org.ssgproject.content_rule_accounts_umask_etc_csh_cshrc unknownCCE-81037-4

Ensure the Default C Shell Umask is Set Correctly

Rule IDxccdf_org.ssgproject.content_rule_accounts_umask_etc_csh_cshrc
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-accounts_umask_etc_csh_cshrc:def:1
Time2020-09-29T11:21:09
Severityunknown
Identifiers and References

Identifiers:  CCE-81037-4

References:  18, APO13.01, BAI03.01, BAI03.02, BAI03.03, CCI-000366, 4.3.4.3.3, A.14.1.1, A.14.2.1, A.14.2.5, A.6.1.5, AC-6(1), CM-6(a), PR.IP-2, SRG-OS-000480-GPOS-00228

Description

To ensure the default umask for users of the C shell is set properly, add or correct the umask setting in /etc/csh.cshrc to read as follows:

umask 027

Rationale

The umask value influences the permissions assigned to files when they are created. A misconfigured umask value could result in files with excessive permissions that can be read or written to by unauthorized users.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

Verify the existence of var_accounts_user_umask_as_number variable  oval:ssg-test_existence_of_var_accounts_user_umask_as_number_variable:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-var_accounts_user_umask_umask_as_number:var:123

Test the retrieved /etc/csh.cshrc umask value(s) match the var_accounts_user_umask requirement  oval:ssg-tst_accounts_umask_etc_csh_cshrc:tst:1  false

Following items have been found on the system:
Var refValueValueValueValueValueValueValueValue
oval:ssg-var_etc_csh_cshrc_umask_as_number:var:1221818221818
Set Existing Passwords Minimum Agexccdf_org.ssgproject.content_rule_accounts_password_set_min_life_existing mediumCCE-82472-2

Set Existing Passwords Minimum Age

Rule IDxccdf_org.ssgproject.content_rule_accounts_password_set_min_life_existing
Result
notchecked
Multi-check ruleno
Time2020-09-29T11:18:02
Severitymedium
Identifiers and References

Identifiers:  CCE-82472-2

References:  CCI-000198, IA-5(f), IA-5(1)(d), CM-6(a), SRG-OS-000075-GPOS-00043, SRG-OS-000075-VMM000420

Description

Configure non-compliant accounts to enforce a 24 hours/1 day minimum password lifetime by running the following command:

$ sudo chage -m 1 USER

Rationale

Enforcing a minimum password lifetime helps to prevent repeated password changes to defeat the password reuse or history enforcement requirement. If users are allowed to immediately and continually change their password, the password could be repeatedly changed in a short period of time to defeat the organization's policy regarding password reuse.

Evaluation messages
info 
No candidate or applicable check found.
Set Existing Passwords Maximum Agexccdf_org.ssgproject.content_rule_accounts_password_set_max_life_existing mediumCCE-82473-0

Set Existing Passwords Maximum Age

Rule IDxccdf_org.ssgproject.content_rule_accounts_password_set_max_life_existing
Result
notchecked
Multi-check ruleno
Time2020-09-29T11:18:02
Severitymedium
Identifiers and References

Identifiers:  CCE-82473-0

References:  CCI-000199, IA-5(f), IA-5(1)(d), CM-6(a), SRG-OS-000076-GPOS-00044, SRG-OS-000076-VMM-000430

Description

Configure non-compliant accounts to enforce a 60-day maximum password lifetime restriction by running the following command:

$ sudo chage -M 60 USER

Rationale

Any password, no matter how complex, can eventually be cracked. Therefore, passwords need to be changed periodically. If the operating system does not limit the lifetime of passwords and force users to change their passwords, there is the risk that the operating system passwords could be compromised.

Evaluation messages
info 
No candidate or applicable check found.
Prevent Login to Accounts With Empty Passwordxccdf_org.ssgproject.content_rule_no_empty_passwords highCCE-80841-0

Prevent Login to Accounts With Empty Password

Rule IDxccdf_org.ssgproject.content_rule_no_empty_passwords
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-no_empty_passwords:def:1
Time2020-09-29T11:21:09
Severityhigh
Identifiers and References

Identifiers:  CCE-80841-0

References:  1, 12, 13, 14, 15, 16, 18, 3, 5, 5.5.2, APO01.06, DSS05.04, DSS05.05, DSS05.07, DSS05.10, DSS06.02, DSS06.03, DSS06.10, 3.1.1, 3.1.5, CCI-000366, 164.308(a)(1)(ii)(B), 164.308(a)(7)(i), 164.308(a)(7)(ii)(A), 164.310(a)(1), 164.310(a)(2)(i), 164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(b), 164.310(c), 164.310(d)(1), 164.310(d)(2)(iii), 4.3.3.2.2, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, SR 1.1, SR 1.10, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 5.2, A.10.1.1, A.11.1.4, A.11.1.5, A.11.2.1, A.13.1.1, A.13.1.3, A.13.2.1, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3, A.18.1.4, A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.1, A.9.2.2, A.9.2.3, A.9.2.4, A.9.2.6, A.9.3.1, A.9.4.1, A.9.4.2, A.9.4.3, A.9.4.4, A.9.4.5, IA-5(1)(a), IA-5(c), CM-6(a), PR.AC-1, PR.AC-4, PR.AC-6, PR.AC-7, PR.DS-5, FIA_AFL.1, Req-8.2.3, SRG-OS-000480-GPOS-00227

Description

If an account is configured for password authentication but does not have an assigned password, it may be possible to log into the account without authentication. Remove any instances of the nullok option in /etc/pam.d/system-auth to prevent logins with empty passwords.

Rationale

If an account has an empty password, anyone could log in and run commands with the privileges of that account. Accounts with empty passwords should never be used in operational environments.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

make sure nullok is not used in /etc/pam.d/system-auth  oval:ssg-test_no_empty_passwords:tst:1  false

Following items have been found on the system:
PathContent
/etc/pam.d/system-auth auth required pam_env.so auth required pam_faildelay.so delay=2000000 auth [default=1 ignore=ignore success=ok] pam_succeed_if.so uid >= 1000 quiet auth [default=1 ignore=ignore success=ok] pam_localuser.so auth sufficient pam_unix.so nullok try_first_pass auth requisite pam_succeed_if.so uid >= 1000 quiet_success auth sufficient pam_sss.so forward_pass auth required pam_deny.so account required pam_unix.so account sufficient pam_localuser.so account sufficient pam_succeed_if.so uid < 1000 quiet account [default=bad success=ok user_unknown=ignore] pam_sss.so account required pam_permit.so password requisite pam_pwquality.so try_first_pass local_users_only password sufficient pam_unix.so sha512 shadow nullok try_first_pass use_authtok
Install policycoreutils Packagexccdf_org.ssgproject.content_rule_package_policycoreutils_installed highCCE-82976-2

Install policycoreutils Package

Rule IDxccdf_org.ssgproject.content_rule_package_policycoreutils_installed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_policycoreutils_installed:def:1
Time2020-09-29T11:18:03
Severityhigh
Identifiers and References

Identifiers:  CCE-82976-2

References:  SRG-OS-000480-GPOS-00227

Description

The policycoreutils package can be installed with the following command:

$ sudo yum install policycoreutils

Rationale

Security-enhanced Linux is a feature of the Linux kernel and a number of utilities with enhanced security functionality designed to add mandatory access controls to Linux. The Security-enhanced Linux kernel contains new architectural components originally developed to improve security of the Flask operating system. These architectural components provide general support for the enforcement of many kinds of mandatory access control policies, including those based on the concepts of Type Enforcement, Role-based Access Control, and Multi-level Security. policycoreutils contains the policy core utilities that are required for basic operation of an SELinux-enabled system. These utilities include load_policy to load SELinux policies, setfiles to label filesystems, newrole to switch roles, and run_init to run /etc/init.d scripts in the proper context.

OVAL test results details

package policycoreutils is installed  oval:ssg-test_package_policycoreutils_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
policycoreutilsx86_64(none)9.el82.90:2.9-9.el8199e2f91fd431d51policycoreutils-0:2.9-9.el8.x86_64
Configure SELinux Policyxccdf_org.ssgproject.content_rule_selinux_policytype highCCE-80868-3

Configure SELinux Policy

Rule IDxccdf_org.ssgproject.content_rule_selinux_policytype
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-selinux_policytype:def:1
Time2020-09-29T11:18:03
Severityhigh
Identifiers and References

Identifiers:  CCE-80868-3

References:  NT28(R66), 1.6.1.3, 1, 11, 12, 13, 14, 15, 16, 18, 3, 4, 5, 6, 8, 9, APO01.06, APO11.04, APO13.01, BAI03.05, DSS01.05, DSS03.01, DSS05.02, DSS05.04, DSS05.05, DSS05.07, DSS06.02, DSS06.03, DSS06.06, MEA02.01, 3.1.2, 3.7.2, CCI-002696, 164.308(a)(1)(ii)(D), 164.308(a)(3), 164.308(a)(4), 164.310(b), 164.310(c), 164.312(a), 164.312(e), 4.2.3.4, 4.3.3.2.2, 4.3.3.3.9, 4.3.3.4, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.4.7, 4.4.2.1, 4.4.2.2, 4.4.2.4, 4.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.10, SR 2.11, SR 2.12, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 2.8, SR 2.9, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 7.1, SR 7.6, A.10.1.1, A.11.1.4, A.11.1.5, A.11.2.1, A.12.1.1, A.12.1.2, A.12.4.1, A.12.4.2, A.12.4.3, A.12.4.4, A.12.7.1, A.13.1.1, A.13.1.2, A.13.1.3, A.13.2.1, A.13.2.2, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3, A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.1, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, AC-3, AC-3(3)(a), AU-9, SC-7(21), DE.AE-1, ID.AM-3, PR.AC-4, PR.AC-5, PR.AC-6, PR.DS-5, PR.PT-1, PR.PT-3, PR.PT-4, SRG-OS-000445-GPOS-00199, SRG-OS-000445-VMM-001780

Description

The SELinux targeted policy is appropriate for general-purpose desktops and servers, as well as systems in many other roles. To configure the system to use this policy, add or correct the following line in /etc/selinux/config:

SELINUXTYPE=targeted
Other policies, such as mls, provide additional security labeling and greater confinement but are not compatible with many general-purpose use cases.

Rationale

Setting the SELinux policy to targeted or a more specialized policy ensures the system will confine processes that are likely to be targeted for exploitation, such as network or system services.

Note: During the development or debugging of SELinux modules, it is common to temporarily place non-production systems in permissive mode. In such temporary cases, SELinux policies should be developed, and once work is completed, the system should be reconfigured to targeted.

OVAL test results details

Tests the value of the ^[\s]*SELINUXTYPE[\s]*=[\s]*([^#]*) expression in the /etc/selinux/config file  oval:ssg-test_selinux_policy:tst:1  true

Following items have been found on the system:
PathContent
/etc/selinux/configSELINUXTYPE=targeted
Ensure SELinux State is Enforcingxccdf_org.ssgproject.content_rule_selinux_state highCCE-80869-1

Ensure SELinux State is Enforcing

Rule IDxccdf_org.ssgproject.content_rule_selinux_state
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-selinux_state:def:1
Time2020-09-29T11:18:03
Severityhigh
Identifiers and References

Identifiers:  CCE-80869-1

References:  NT28(R4), 1.6.1.2, 1, 11, 12, 13, 14, 15, 16, 18, 3, 4, 5, 6, 8, 9, APO01.06, APO11.04, APO13.01, BAI03.05, DSS01.05, DSS03.01, DSS05.02, DSS05.04, DSS05.05, DSS05.07, DSS06.02, DSS06.03, DSS06.06, MEA02.01, 3.1.2, 3.7.2, CCI-002165, CCI-002696, 164.308(a)(1)(ii)(D), 164.308(a)(3), 164.308(a)(4), 164.310(b), 164.310(c), 164.312(a), 164.312(e), 4.2.3.4, 4.3.3.2.2, 4.3.3.3.9, 4.3.3.4, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.4.7, 4.4.2.1, 4.4.2.2, 4.4.2.4, 4.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.10, SR 2.11, SR 2.12, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 2.8, SR 2.9, SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 7.1, SR 7.6, A.10.1.1, A.11.1.4, A.11.1.5, A.11.2.1, A.12.1.1, A.12.1.2, A.12.4.1, A.12.4.2, A.12.4.3, A.12.4.4, A.12.7.1, A.13.1.1, A.13.1.2, A.13.1.3, A.13.2.1, A.13.2.2, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3, A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.1, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, AC-3, AC-3(3)(a), AU-9, SC-7(21), DE.AE-1, ID.AM-3, PR.AC-4, PR.AC-5, PR.AC-6, PR.DS-5, PR.PT-1, PR.PT-3, PR.PT-4, SRG-OS-000445-GPOS-00199, SRG-OS-000445-VMM-001780

Description

The SELinux state should be set to enforcing at system boot time. In the file /etc/selinux/config, add or correct the following line to configure the system to boot into enforcing mode:

SELINUX=enforcing

Rationale

Setting the SELinux state to enforcing ensures SELinux is able to confine potentially compromised processes to the security policy, which is designed to prevent them from causing damage to the system or further elevating their privileges.

OVAL test results details

/selinux/enforce is 1  oval:ssg-test_etc_selinux_config:tst:1  true

Following items have been found on the system:
PathContent
/etc/selinux/configSELINUX=enforcing
Add nodev Option to /var/logxccdf_org.ssgproject.content_rule_mount_option_var_log_nodev mediumCCE-82077-9

Add nodev Option to /var/log

Rule IDxccdf_org.ssgproject.content_rule_mount_option_var_log_nodev
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-mount_option_var_log_nodev:def:1
Time2020-09-29T11:18:03
Severitymedium
Identifiers and References

Identifiers:  CCE-82077-9

References:  CM-7(a), CM-7(b), CM-6(a), AC-6, AC-6(1), MP-7, PR.IP-1, PR.PT-2, PR.PT-3

Description

The nodev mount option can be used to prevent device files from being created in /var/log. Legitimate character and block devices should exist only in the /dev directory on the root partition or within chroot jails built for system services. Add the nodev option to the fourth column of /etc/fstab for the line which controls mounting of /var/log.

Rationale

The only legitimate location for device files is the /dev directory located on the root partition. The only exception to this is chroot jails.

OVAL test results details

nodev on /var/log  oval:ssg-test_var_log_partition_nodev:tst:1  true

Following items have been found on the system:
Mount pointDeviceUuidFs typeMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsTotal spaceSpace usedSpace left
/var/log/dev/mapper/ovirt-log04ffc7a2-ee25-4207-a1ca-33a1ef8f9021xfsrwseclabelnodevrelatimeattr2inode64noquotabind2618880268152592065
Add nosuid Option to /var/logxccdf_org.ssgproject.content_rule_mount_option_var_log_nosuid mediumCCE-82065-4

Add nosuid Option to /var/log

Rule IDxccdf_org.ssgproject.content_rule_mount_option_var_log_nosuid
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-mount_option_var_log_nosuid:def:1
Time2020-09-29T11:21:10
Severitymedium
Identifiers and References

Identifiers:  CCE-82065-4

References:  CM-7(a), CM-7(b), CM-6(a), AC-6, AC-6(1), MP-7, PR.IP-1, PR.PT-2, PR.PT-3, SRG-OS-000368-GPOS-00154

Description

The nosuid mount option can be used to prevent execution of setuid programs in /var/log. The SUID and SGID permissions should not be required in directories containing log files. Add the nosuid option to the fourth column of /etc/fstab for the line which controls mounting of /var/log.

Rationale

The presence of SUID and SGID executables should be tightly controlled. Users should not be able to execute SUID or SGID binaries from partitions designated for log files.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

nosuid on /var/log  oval:ssg-test_var_log_partition_nosuid:tst:1  false

Following items have been found on the system:
Mount pointDeviceUuidFs typeMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsTotal spaceSpace usedSpace left
/var/log/dev/mapper/ovirt-log04ffc7a2-ee25-4207-a1ca-33a1ef8f9021xfsrwseclabelnodevrelatimeattr2inode64noquotabind2618880268152592065
Add nodev Option to /bootxccdf_org.ssgproject.content_rule_mount_option_boot_nodev mediumCCE-82941-6

Add nodev Option to /boot

Rule IDxccdf_org.ssgproject.content_rule_mount_option_boot_nodev
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-mount_option_boot_nodev:def:1
Time2020-09-29T11:21:10
Severitymedium
Identifiers and References

Identifiers:  CCE-82941-6

References:  CM-7(a), CM-7(b), CM-6(a), AC-6, AC-6(1), MP-7, PR.IP-1, PR.PT-2, PR.PT-3, SRG-OS-000368-GPOS-00154

Description

The nodev mount option can be used to prevent device files from being created in /boot. Legitimate character and block devices should exist only in the /dev directory on the root partition or within chroot jails built for system services. Add the nodev option to the fourth column of /etc/fstab for the line which controls mounting of /boot.

Rationale

The only legitimate location for device files is the /dev directory located on the root partition. The only exception to this is chroot jails.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

nodev on /boot  oval:ssg-test_boot_partition_nodev:tst:1  false

Following items have been found on the system:
Mount pointDeviceUuidFs typeMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsTotal spaceSpace usedSpace left
/boot/dev/vda1135e3d07-8003-46c7-a76a-829e7270155cxfsrwseclabelrelatimeattr2inode64noquotabind25958442374217210
Add nodev Option to /var/tmpxccdf_org.ssgproject.content_rule_mount_option_var_tmp_nodev unknownCCE-82068-8

Add nodev Option to /var/tmp

Rule IDxccdf_org.ssgproject.content_rule_mount_option_var_tmp_nodev
Result
error
Multi-check ruleno
OVAL Definition IDoval:ssg-mount_option_var_tmp_nodev:def:1
Time2020-09-29T11:21:10
Severityunknown
Identifiers and References

Identifiers:  CCE-82068-8

References:  NT28(R12), 1.1.8, SRG-OS-000368-GPOS-00154

Description

The nodev mount option can be used to prevent device files from being created in /var/tmp. Legitimate character and block devices should not exist within temporary directories like /var/tmp. Add the nodev option to the fourth column of /etc/fstab for the line which controls mounting of /var/tmp.

Rationale

The only legitimate location for device files is the /dev directory located on the root partition. The only exception to this is chroot jails.

Evaluation messages
info 
Fix execution completed and returned: 1
info 
The mount point '/var/tmp' is not even in /etc/fstab, so we can't set up mount options
Not remediating, because there is no record of /var/tmp in /etc/fstab
info 
Failed to verify applied fix: Checking engine returns: fail


function include_mount_options_functions {
	:
}

# $1: type of filesystem
# $2: new mount point option
# $3: filesystem of new mount point (used when adding new entry in fstab)
# $4: mount type of new mount point (used when adding new entry in fstab)
function ensure_mount_option_for_vfstype {
        local _vfstype="$1" _new_opt="$2" _filesystem=$3 _type=$4 _vfstype_points=()
        readarray -t _vfstype_points < <(grep -E "[[:space:]]${_vfstype}[[:space:]]" /etc/fstab | awk '{print $2}')

        for _vfstype_point in "${_vfstype_points[@]}"
        do
                ensure_mount_option_in_fstab "$_vfstype_point" "$_new_opt" "$_filesystem" "$_type"
        done
}

# $1: mount point
# $2: new mount point option
# $3: device or virtual string (used when adding new entry in fstab)
# $4: mount type of mount point (used when adding new entry in fstab)
function ensure_mount_option_in_fstab {
	local _mount_point="$1" _new_opt="$2" _device=$3 _type=$4
	local _mount_point_match_regexp="" _previous_mount_opts=""
	_mount_point_match_regexp="$(get_mount_point_regexp "$_mount_point")"

	if [ "$(grep -c "$_mount_point_match_regexp" /etc/fstab)" -eq 0 ]; then
		# runtime opts without some automatic kernel/userspace-added defaults
		_previous_mount_opts=$(grep "$_mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
					| sed -E "s/(rw|defaults|seclabel|${_new_opt})(,|$)//g;s/,$//")
		[ "$_previous_mount_opts" ] && _previous_mount_opts+=","
		echo "${_device} ${_mount_point} ${_type} defaults,${_previous_mount_opts}${_new_opt} 0 0" >> /etc/fstab
	elif [ "$(grep "$_mount_point_match_regexp" /etc/fstab | grep -c "$_new_opt")" -eq 0 ]; then
		_previous_mount_opts=$(grep "$_mount_point_match_regexp" /etc/fstab | awk '{print $4}')
		sed -i "s|\(${_mount_point_match_regexp}.*${_previous_mount_opts}\)|\1,${_new_opt}|" /etc/fstab
	fi
}

# $1: mount point
function get_mount_point_regexp {
		printf "[[:space:]]%s[[:space:]]" "$1"
}

# $1: mount point
function assert_mount_point_in_fstab {
	local _mount_point_match_regexp
	_mount_point_match_regexp="$(get_mount_point_regexp "$1")"
	grep "$_mount_point_match_regexp" -q /etc/fstab \
		|| { echo "The mount point '$1' is not even in /etc/fstab, so we can't set up mount options" >&2; return 1; }
}

# $1: mount point
function remove_defaults_from_fstab_if_overriden {
	local _mount_point_match_regexp
	_mount_point_match_regexp="$(get_mount_point_regexp "$1")"
	if grep "$_mount_point_match_regexp" /etc/fstab | grep -q "defaults,"
	then
		sed -i "s|\(${_mount_point_match_regexp}.*\)defaults,|\1|" /etc/fstab
	fi
}

# $1: mount point
function ensure_partition_is_mounted {
	local _mount_point="$1"
	mkdir -p "$_mount_point" || return 1
	if mountpoint -q "$_mount_point"; then
		mount -o remount --target "$_mount_point"
	else
		mount --target "$_mount_point"
	fi
}
include_mount_options_functions

function perform_remediation {
	# test "$mount_has_to_exist" = 'yes'
	if test "yes" = 'yes'; then
		assert_mount_point_in_fstab /var/tmp || { echo "Not remediating, because there is no record of /var/tmp in /etc/fstab" >&2; return 1; }
	fi

	ensure_mount_option_in_fstab "/var/tmp" "nodev" "" ""

	ensure_partition_is_mounted "/var/tmp"
}

perform_remediation


Complexity:low
Disruption:high
Strategy:configure
- name: get back mount information associated to mountpoint
  command: findmnt --fstab '/var/tmp'
  register: device_name
  failed_when: device_name.rc > 1
  changed_when: false
  when: ansible_virtualization_role != "guest" or ansible_virtualization_type != "docker"
  tags:
    - mount_option_var_tmp_nodev
    - unknown_severity
    - configure_strategy
    - low_complexity
    - high_disruption
    - no_reboot_needed
    - CCE-82068-8

- name: create mount_info dictionary variable
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
    - '{{ device_name.stdout_lines[0].split() | list | lower }}'
    - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
    - device_name.stdout is defined and device_name.stdout_lines is defined
    - (device_name.stdout | length > 0)
    - ansible_virtualization_role != "guest" or ansible_virtualization_type != "docker"
  tags:
    - mount_option_var_tmp_nodev
    - unknown_severity
    - configure_strategy
    - low_complexity
    - high_disruption
    - no_reboot_needed
    - CCE-82068-8

- name: Ensure permission nodev are set on /var/tmp
  mount:
    path: /var/tmp
    src: '{{ mount_info.source }}'
    opts: '{{ mount_info.options }},nodev'
    state: mounted
    fstype: '{{ mount_info.fstype }}'
  when:
    - device_name.stdout is defined
    - (device_name.stdout | length > 0)
    - ansible_virtualization_role != "guest" or ansible_virtualization_type != "docker"
  tags:
    - mount_option_var_tmp_nodev
    - unknown_severity
    - configure_strategy
    - low_complexity
    - high_disruption
    - no_reboot_needed
    - CCE-82068-8


Complexity:low
Disruption:high
Strategy:enable

part /var/tmp --mountoptions="nodev"
OVAL test results details

nodev on /var/tmp  oval:ssg-test_var_tmp_partition_nodev:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_var_tmp_partition_nodev:obj:1 of type partition_object
Mount point
/var/tmp
Add nosuid Option to /dev/shmxccdf_org.ssgproject.content_rule_mount_option_dev_shm_nosuid mediumCCE-80839-4

Add nosuid Option to /dev/shm

Rule IDxccdf_org.ssgproject.content_rule_mount_option_dev_shm_nosuid
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-mount_option_dev_shm_nosuid:def:1
Time2020-09-29T11:18:03
Severitymedium
Identifiers and References

Identifiers:  CCE-80839-4

References:  1.1.16, 11, 13, 14, 3, 8, 9, APO13.01, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS05.02, DSS05.05, DSS05.06, DSS06.06, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 7.6, A.11.2.9, A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, A.8.2.1, A.8.2.2, A.8.2.3, A.8.3.1, A.8.3.3, A.9.1.2, CM-7(a), CM-7(b), CM-6(a), AC-6, AC-6(1), MP-7, PR.IP-1, PR.PT-2, PR.PT-3, SRG-OS-000368-GPOS-00154

Description

The nosuid mount option can be used to prevent execution of setuid programs in /dev/shm. The SUID and SGID permissions should not be required in these world-writable directories. Add the nosuid option to the fourth column of /etc/fstab for the line which controls mounting of /dev/shm.

Rationale

The presence of SUID and SGID executables should be tightly controlled. Users should not be able to execute SUID or SGID binaries from temporary storage partitions.

OVAL test results details

nosuid on /dev/shm  oval:ssg-test_dev_shm_partition_nosuid:tst:1  true

Following items have been found on the system:
Mount pointDeviceUuidFs typeMount optionsMount optionsMount optionsMount optionsTotal spaceSpace usedSpace left
/dev/shmtmpfstmpfsrwseclabelnosuidnodev4836090483609
Add nosuid Option to /var/tmpxccdf_org.ssgproject.content_rule_mount_option_var_tmp_nosuid unknownCCE-82154-6

Add nosuid Option to /var/tmp

Rule IDxccdf_org.ssgproject.content_rule_mount_option_var_tmp_nosuid
Result
error
Multi-check ruleno
OVAL Definition IDoval:ssg-mount_option_var_tmp_nosuid:def:1
Time2020-09-29T11:21:10
Severityunknown
Identifiers and References

Identifiers:  CCE-82154-6

References:  NT28(R12), 1.1.9, SRG-OS-000368-GPOS-00154

Description

The nosuid mount option can be used to prevent execution of setuid programs in /var/tmp. The SUID and SGID permissions should not be required in these world-writable directories. Add the nosuid option to the fourth column of /etc/fstab for the line which controls mounting of /var/tmp.

Rationale

The presence of SUID and SGID executables should be tightly controlled. Users should not be able to execute SUID or SGID binaries from temporary storage partitions.

Evaluation messages
info 
Fix execution completed and returned: 1
info 
The mount point '/var/tmp' is not even in /etc/fstab, so we can't set up mount options
Not remediating, because there is no record of /var/tmp in /etc/fstab
info 
Failed to verify applied fix: Checking engine returns: fail


function include_mount_options_functions {
	:
}

# $1: type of filesystem
# $2: new mount point option
# $3: filesystem of new mount point (used when adding new entry in fstab)
# $4: mount type of new mount point (used when adding new entry in fstab)
function ensure_mount_option_for_vfstype {
        local _vfstype="$1" _new_opt="$2" _filesystem=$3 _type=$4 _vfstype_points=()
        readarray -t _vfstype_points < <(grep -E "[[:space:]]${_vfstype}[[:space:]]" /etc/fstab | awk '{print $2}')

        for _vfstype_point in "${_vfstype_points[@]}"
        do
                ensure_mount_option_in_fstab "$_vfstype_point" "$_new_opt" "$_filesystem" "$_type"
        done
}

# $1: mount point
# $2: new mount point option
# $3: device or virtual string (used when adding new entry in fstab)
# $4: mount type of mount point (used when adding new entry in fstab)
function ensure_mount_option_in_fstab {
	local _mount_point="$1" _new_opt="$2" _device=$3 _type=$4
	local _mount_point_match_regexp="" _previous_mount_opts=""
	_mount_point_match_regexp="$(get_mount_point_regexp "$_mount_point")"

	if [ "$(grep -c "$_mount_point_match_regexp" /etc/fstab)" -eq 0 ]; then
		# runtime opts without some automatic kernel/userspace-added defaults
		_previous_mount_opts=$(grep "$_mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
					| sed -E "s/(rw|defaults|seclabel|${_new_opt})(,|$)//g;s/,$//")
		[ "$_previous_mount_opts" ] && _previous_mount_opts+=","
		echo "${_device} ${_mount_point} ${_type} defaults,${_previous_mount_opts}${_new_opt} 0 0" >> /etc/fstab
	elif [ "$(grep "$_mount_point_match_regexp" /etc/fstab | grep -c "$_new_opt")" -eq 0 ]; then
		_previous_mount_opts=$(grep "$_mount_point_match_regexp" /etc/fstab | awk '{print $4}')
		sed -i "s|\(${_mount_point_match_regexp}.*${_previous_mount_opts}\)|\1,${_new_opt}|" /etc/fstab
	fi
}

# $1: mount point
function get_mount_point_regexp {
		printf "[[:space:]]%s[[:space:]]" "$1"
}

# $1: mount point
function assert_mount_point_in_fstab {
	local _mount_point_match_regexp
	_mount_point_match_regexp="$(get_mount_point_regexp "$1")"
	grep "$_mount_point_match_regexp" -q /etc/fstab \
		|| { echo "The mount point '$1' is not even in /etc/fstab, so we can't set up mount options" >&2; return 1; }
}

# $1: mount point
function remove_defaults_from_fstab_if_overriden {
	local _mount_point_match_regexp
	_mount_point_match_regexp="$(get_mount_point_regexp "$1")"
	if grep "$_mount_point_match_regexp" /etc/fstab | grep -q "defaults,"
	then
		sed -i "s|\(${_mount_point_match_regexp}.*\)defaults,|\1|" /etc/fstab
	fi
}

# $1: mount point
function ensure_partition_is_mounted {
	local _mount_point="$1"
	mkdir -p "$_mount_point" || return 1
	if mountpoint -q "$_mount_point"; then
		mount -o remount --target "$_mount_point"
	else
		mount --target "$_mount_point"
	fi
}
include_mount_options_functions

function perform_remediation {
	# test "$mount_has_to_exist" = 'yes'
	if test "yes" = 'yes'; then
		assert_mount_point_in_fstab /var/tmp || { echo "Not remediating, because there is no record of /var/tmp in /etc/fstab" >&2; return 1; }
	fi

	ensure_mount_option_in_fstab "/var/tmp" "nosuid" "" ""

	ensure_partition_is_mounted "/var/tmp"
}

perform_remediation


Complexity:low
Disruption:high
Strategy:configure
- name: get back mount information associated to mountpoint
  command: findmnt --fstab '/var/tmp'
  register: device_name
  failed_when: device_name.rc > 1
  changed_when: false
  when: ansible_virtualization_role != "guest" or ansible_virtualization_type != "docker"
  tags:
    - mount_option_var_tmp_nosuid
    - unknown_severity
    - configure_strategy
    - low_complexity
    - high_disruption
    - no_reboot_needed
    - CCE-82154-6

- name: create mount_info dictionary variable
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
    - '{{ device_name.stdout_lines[0].split() | list | lower }}'
    - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
    - device_name.stdout is defined and device_name.stdout_lines is defined
    - (device_name.stdout | length > 0)
    - ansible_virtualization_role != "guest" or ansible_virtualization_type != "docker"
  tags:
    - mount_option_var_tmp_nosuid
    - unknown_severity
    - configure_strategy
    - low_complexity
    - high_disruption
    - no_reboot_needed
    - CCE-82154-6

- name: Ensure permission nosuid are set on /var/tmp
  mount:
    path: /var/tmp
    src: '{{ mount_info.source }}'
    opts: '{{ mount_info.options }},nosuid'
    state: mounted
    fstype: '{{ mount_info.fstype }}'
  when:
    - device_name.stdout is defined
    - (device_name.stdout | length > 0)
    - ansible_virtualization_role != "guest" or ansible_virtualization_type != "docker"
  tags:
    - mount_option_var_tmp_nosuid
    - unknown_severity
    - configure_strategy
    - low_complexity
    - high_disruption
    - no_reboot_needed
    - CCE-82154-6


Complexity:low
Disruption:high
Strategy:enable

part /var/tmp --mountoptions="nosuid"
OVAL test results details

nosuid on /var/tmp  oval:ssg-test_var_tmp_partition_nosuid:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_var_tmp_partition_nosuid:obj:1 of type partition_object
Mount point
/var/tmp
Add nosuid Option to /homexccdf_org.ssgproject.content_rule_mount_option_home_nosuid unknownCCE-81050-7

Add nosuid Option to /home

Rule IDxccdf_org.ssgproject.content_rule_mount_option_home_nosuid
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-mount_option_home_nosuid:def:1
Time2020-09-29T11:21:10
Severityunknown
Identifiers and References

Identifiers:  CCE-81050-7

References:  NT28(R12), 1.1.3, 11, 13, 14, 3, 8, 9, APO13.01, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS05.02, DSS05.05, DSS05.06, DSS06.06, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 7.6, A.11.2.9, A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, A.8.2.1, A.8.2.2, A.8.2.3, A.8.3.1, A.8.3.3, A.9.1.2, CM-7(a), CM-7(b), CM-6(a), AC-6, AC-6(1), MP-7, PR.IP-1, PR.PT-2, PR.PT-3, SRG-OS-000368-GPOS-00154

Description

The nosuid mount option can be used to prevent execution of setuid programs in /home. The SUID and SGID permissions should not be required in these user data directories. Add the nosuid option to the fourth column of /etc/fstab for the line which controls mounting of /home.

Rationale

The presence of SUID and SGID executables should be tightly controlled. Users should not be able to execute SUID or SGID binaries from user home directory partitions.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

nosuid on /home  oval:ssg-test_home_partition_nosuid:tst:1  false

Following items have been found on the system:
Mount pointDeviceUuidFs typeMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsTotal spaceSpace usedSpace left
/home/dev/mapper/ovirt-home934099b3-b298-4e85-a731-17c9495a92acxfsrwseclabelnodevrelatimeattr2inode64noquotabind25958410084249500
Add noexec Option to /tmpxccdf_org.ssgproject.content_rule_mount_option_tmp_noexec unknownCCE-82139-7

Add noexec Option to /tmp

Rule IDxccdf_org.ssgproject.content_rule_mount_option_tmp_noexec
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-mount_option_tmp_noexec:def:1
Time2020-09-29T11:18:03
Severityunknown
Identifiers and References

Identifiers:  CCE-82139-7

References:  NT28(R12), 1.1.5, 11, 13, 14, 3, 8, 9, APO13.01, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS05.02, DSS05.05, DSS05.06, DSS06.06, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 7.6, A.11.2.9, A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, A.8.2.1, A.8.2.2, A.8.2.3, A.8.3.1, A.8.3.3, A.9.1.2, CM-7(a), CM-7(b), CM-6(a), AC-6, AC-6(1), MP-7, PR.IP-1, PR.PT-2, PR.PT-3, SRG-OS-000368-GPOS-00154

Description

The noexec mount option can be used to prevent binaries from being executed out of /tmp. Add the noexec option to the fourth column of /etc/fstab for the line which controls mounting of /tmp.

Rationale

Allowing users to execute binaries from world-writable directories such as /tmp should never be necessary in normal operation and can expose the system to potential compromise.

OVAL test results details

noexec on /tmp  oval:ssg-test_tmp_partition_noexec:tst:1  true

Following items have been found on the system:
Mount pointDeviceUuidFs typeMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsTotal spaceSpace usedSpace left
/tmp/dev/mapper/ovirt-tmpfe226ba1-b167-4b0f-81b2-d06bb6c1dd78xfsrwseclabelnosuidnodevnoexecrelatimeattr2inode64noquotabind52172811962509766
Add nodev Option to /varxccdf_org.ssgproject.content_rule_mount_option_var_nodev mediumCCE-82062-1

Add nodev Option to /var

Rule IDxccdf_org.ssgproject.content_rule_mount_option_var_nodev
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-mount_option_var_nodev:def:1
Time2020-09-29T11:18:03
Severitymedium
Identifiers and References

Identifiers:  CCE-82062-1

References:  CM-7(a), CM-7(b), CM-6(a), AC-6, AC-6(1), MP-7, PR.IP-1, PR.PT-2, PR.PT-3, SRG-OS-000368-GPOS-00154

Description

The nodev mount option can be used to prevent device files from being created in /var. Legitimate character and block devices should exist only in the /dev directory on the root partition or within chroot jails built for system services. Add the nodev option to the fourth column of /etc/fstab for the line which controls mounting of /var.

Rationale

The only legitimate location for device files is the /dev directory located on the root partition. The only exception to this is chroot jails.

OVAL test results details

nodev on /var  oval:ssg-test_var_partition_nodev:tst:1  true

Following items have been found on the system:
Mount pointDeviceUuidFs typeMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsTotal spaceSpace usedSpace left
/var/dev/mapper/ovirt-var64bf7634-bdbb-40e1-a2b8-0b7865630c92xfsrwseclabelnodevrelatimeattr2inode64noquotabind5240320827455157575
Add noexec Option to /var/log/auditxccdf_org.ssgproject.content_rule_mount_option_var_log_audit_noexec mediumCCE-82975-4

Add noexec Option to /var/log/audit

Rule IDxccdf_org.ssgproject.content_rule_mount_option_var_log_audit_noexec
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-mount_option_var_log_audit_noexec:def:1
Time2020-09-29T11:21:10
Severitymedium
Identifiers and References

Identifiers:  CCE-82975-4

References:  CM-7(a), CM-7(b), CM-6(a), AC-6, AC-6(1), MP-7, PR.IP-1, PR.PT-2, PR.PT-3, SRG-OS-000368-GPOS-00154

Description

The noexec mount option can be used to prevent binaries from being executed out of /var/log/audit. Add the noexec option to the fourth column of /etc/fstab for the line which controls mounting of /var/log/audit.

Rationale

Allowing users to execute binaries from directories containing audit log files such as /var/log/audit should never be necessary in normal operation and can expose the system to potential compromise.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

noexec on /var/log/audit  oval:ssg-test_var_log_audit_partition_noexec:tst:1  false

Following items have been found on the system:
Mount pointDeviceUuidFs typeMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsTotal spaceSpace usedSpace left
/var/log/audit/dev/mapper/ovirt-audit3b01f699-5c60-4a28-8941-ddc1a0828164xfsrwseclabelnodevrelatimeattr2inode64noquotabind25958410105249479
Add nodev Option to /var/log/auditxccdf_org.ssgproject.content_rule_mount_option_var_log_audit_nodev mediumCCE-82080-3

Add nodev Option to /var/log/audit

Rule IDxccdf_org.ssgproject.content_rule_mount_option_var_log_audit_nodev
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-mount_option_var_log_audit_nodev:def:1
Time2020-09-29T11:18:03
Severitymedium
Identifiers and References

Identifiers:  CCE-82080-3

References:  CM-7(a), CM-7(b), CM-6(a), AC-6, AC-6(1), MP-7, PR.IP-1, PR.PT-2, PR.PT-3, SRG-OS-000368-GPOS-00154

Description

The nodev mount option can be used to prevent device files from being created in /var/log/audit. Legitimate character and block devices should exist only in the /dev directory on the root partition or within chroot jails built for system services. Add the nodev option to the fourth column of /etc/fstab for the line which controls mounting of /var/log/audit.

Rationale

The only legitimate location for device files is the /dev directory located on the root partition. The only exception to this is chroot jails.

OVAL test results details

nodev on /var/log/audit  oval:ssg-test_var_log_audit_partition_nodev:tst:1  true

Following items have been found on the system:
Mount pointDeviceUuidFs typeMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsTotal spaceSpace usedSpace left
/var/log/audit/dev/mapper/ovirt-audit3b01f699-5c60-4a28-8941-ddc1a0828164xfsrwseclabelnodevrelatimeattr2inode64noquotabind25958410105249479
Add nodev Option to /homexccdf_org.ssgproject.content_rule_mount_option_home_nodev unknownCCE-81048-1

Add nodev Option to /home

Rule IDxccdf_org.ssgproject.content_rule_mount_option_home_nodev
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-mount_option_home_nodev:def:1
Time2020-09-29T11:18:03
Severityunknown
Identifiers and References

Identifiers:  CCE-81048-1

References:  NT28(R12), 1.1.14, SRG-OS-000368-GPOS-00154

Description

The nodev mount option can be used to prevent device files from being created in /home. Legitimate character and block devices should exist only in the /dev directory on the root partition or within chroot jails built for system services. Add the nodev option to the fourth column of /etc/fstab for the line which controls mounting of /home.

Rationale

The only legitimate location for device files is the /dev directory located on the root partition. The only exception to this is chroot jails.

OVAL test results details

nodev on /home  oval:ssg-test_home_partition_nodev:tst:1  true

Following items have been found on the system:
Mount pointDeviceUuidFs typeMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsTotal spaceSpace usedSpace left
/home/dev/mapper/ovirt-home934099b3-b298-4e85-a731-17c9495a92acxfsrwseclabelnodevrelatimeattr2inode64noquotabind25958410084249500
Add noexec Option to /dev/shmxccdf_org.ssgproject.content_rule_mount_option_dev_shm_noexec mediumCCE-80838-6

Add noexec Option to /dev/shm

Rule IDxccdf_org.ssgproject.content_rule_mount_option_dev_shm_noexec
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-mount_option_dev_shm_noexec:def:1
Time2020-09-29T11:21:10
Severitymedium
Identifiers and References

Identifiers:  CCE-80838-6

References:  1.1.17, 11, 13, 14, 3, 8, 9, APO13.01, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS05.02, DSS05.05, DSS05.06, DSS06.06, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 7.6, A.11.2.9, A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, A.8.2.1, A.8.2.2, A.8.2.3, A.8.3.1, A.8.3.3, A.9.1.2, CM-7(a), CM-7(b), CM-6(a), AC-6, AC-6(1), MP-7, PR.IP-1, PR.PT-2, PR.PT-3, SRG-OS-000368-GPOS-00154

Description

The noexec mount option can be used to prevent binaries from being executed out of /dev/shm. It can be dangerous to allow the execution of binaries from world-writable temporary storage directories such as /dev/shm. Add the noexec option to the fourth column of /etc/fstab for the line which controls mounting of /dev/shm.

Rationale

Allowing users to execute binaries from world-writable directories such as /dev/shm can expose the system to potential compromise.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

noexec on /dev/shm  oval:ssg-test_dev_shm_partition_noexec:tst:1  false

Following items have been found on the system:
Mount pointDeviceUuidFs typeMount optionsMount optionsMount optionsMount optionsTotal spaceSpace usedSpace left
/dev/shmtmpfstmpfsrwseclabelnosuidnodev4836090483609
Add nodev Option to /tmpxccdf_org.ssgproject.content_rule_mount_option_tmp_nodev unknownCCE-82623-0

Add nodev Option to /tmp

Rule IDxccdf_org.ssgproject.content_rule_mount_option_tmp_nodev
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-mount_option_tmp_nodev:def:1
Time2020-09-29T11:18:03
Severityunknown
Identifiers and References

Identifiers:  CCE-82623-0

References:  NT28(R12), 1.1.3, 11, 13, 14, 3, 8, 9, APO13.01, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS05.02, DSS05.05, DSS05.06, DSS06.06, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 7.6, A.11.2.9, A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, A.8.2.1, A.8.2.2, A.8.2.3, A.8.3.1, A.8.3.3, A.9.1.2, CM-7(a), CM-7(b), CM-6(a), AC-6, AC-6(1), MP-7, PR.IP-1, PR.PT-2, PR.PT-3, SRG-OS-000368-GPOS-00154

Description

The nodev mount option can be used to prevent device files from being created in /tmp. Legitimate character and block devices should not exist within temporary directories like /tmp. Add the nodev option to the fourth column of /etc/fstab for the line which controls mounting of /tmp.

Rationale

The only legitimate location for device files is the /dev directory located on the root partition. The only exception to this is chroot jails.

OVAL test results details

nodev on /tmp  oval:ssg-test_tmp_partition_nodev:tst:1  true

Following items have been found on the system:
Mount pointDeviceUuidFs typeMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsTotal spaceSpace usedSpace left
/tmp/dev/mapper/ovirt-tmpfe226ba1-b167-4b0f-81b2-d06bb6c1dd78xfsrwseclabelnosuidnodevnoexecrelatimeattr2inode64noquotabind52172811962509766
Add nodev Option to /dev/shmxccdf_org.ssgproject.content_rule_mount_option_dev_shm_nodev mediumCCE-80837-8

Add nodev Option to /dev/shm

Rule IDxccdf_org.ssgproject.content_rule_mount_option_dev_shm_nodev
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-mount_option_dev_shm_nodev:def:1
Time2020-09-29T11:18:03
Severitymedium
Identifiers and References

Identifiers:  CCE-80837-8

References:  1.1.15, 11, 13, 14, 3, 8, 9, APO13.01, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS05.02, DSS05.05, DSS05.06, DSS06.06, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 7.6, A.11.2.9, A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, A.8.2.1, A.8.2.2, A.8.2.3, A.8.3.1, A.8.3.3, A.9.1.2, CM-7(a), CM-7(b), CM-6(a), AC-6, AC-6(1), MP-7, PR.IP-1, PR.PT-2, PR.PT-3, SRG-OS-000368-GPOS-00154

Description

The nodev mount option can be used to prevent creation of device files in /dev/shm. Legitimate character and block devices should not exist within temporary directories like /dev/shm. Add the nodev option to the fourth column of /etc/fstab for the line which controls mounting of /dev/shm.

Rationale

The only legitimate location for device files is the /dev directory located on the root partition. The only exception to this is chroot jails.

OVAL test results details

nodev on /dev/shm  oval:ssg-test_dev_shm_partition_nodev:tst:1  true

Following items have been found on the system:
Mount pointDeviceUuidFs typeMount optionsMount optionsMount optionsMount optionsTotal spaceSpace usedSpace left
/dev/shmtmpfstmpfsrwseclabelnosuidnodev4836090483609
Add nosuid Option to /bootxccdf_org.ssgproject.content_rule_mount_option_boot_nosuid mediumCCE-81033-3

Add nosuid Option to /boot

Rule IDxccdf_org.ssgproject.content_rule_mount_option_boot_nosuid
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-mount_option_boot_nosuid:def:1
Time2020-09-29T11:21:10
Severitymedium
Identifiers and References

Identifiers:  CCE-81033-3

References:  CM-7(a), CM-7(b), CM-6(a), AC-6, AC-6(1), MP-7, PR.IP-1, PR.PT-2, PR.PT-3, SRG-OS-000368-GPOS-00154

Description

The nosuid mount option can be used to prevent execution of setuid programs in /boot. The SUID and SGID permissions should not be required on the boot partition. Add the nosuid option to the fourth column of /etc/fstab for the line which controls mounting of /boot.

Rationale

The presence of SUID and SGID executables should be tightly controlled. Users should not be able to execute SUID or SGID binaries from boot partitions.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

nosuid on /boot  oval:ssg-test_boot_partition_nosuid:tst:1  false

Following items have been found on the system:
Mount pointDeviceUuidFs typeMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsTotal spaceSpace usedSpace left
/boot/dev/vda1135e3d07-8003-46c7-a76a-829e7270155cxfsrwseclabelrelatimeattr2inode64noquotabind25958442374217210
Add nodev Option to Non-Root Local Partitionsxccdf_org.ssgproject.content_rule_mount_option_nodev_nonroot_local_partitions unknownCCE-82069-6

Add nodev Option to Non-Root Local Partitions

Rule IDxccdf_org.ssgproject.content_rule_mount_option_nodev_nonroot_local_partitions
Result
fail
Multi-check ruleno
OVAL Definition IDoval:ssg-mount_option_nodev_nonroot_local_partitions:def:1
Time2020-09-29T11:21:10
Severityunknown
Identifiers and References

Identifiers:  CCE-82069-6

References:  1.1.11, 11, 14, 3, 9, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS05.02, DSS05.05, DSS06.06, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 7.6, A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, A.9.1.2, CM-7(a), CM-7(b), CM-6(a), AC-6, AC-6(1), MP-7, PR.IP-1, PR.PT-3, SRG-OS-000368-GPOS-00154

Description

The nodev mount option prevents files from being interpreted as character or block devices. Legitimate character and block devices should exist only in the /dev directory on the root partition or within chroot jails built for system services. Add the nodev option to the fourth column of /etc/fstab for the line which controls mounting of any non-root local partitions.

Rationale

The nodev mount option prevents files from being interpreted as character or block devices. The only legitimate location for device files is the /dev directory located on the root partition. The only exception to this is chroot jails, for which it is not advised to set nodev on these filesystems.

Evaluation messages
info 
No suitable fix found.
OVAL test results details

nodev on local filesystems  oval:ssg-test_nodev_nonroot_local_partitions:tst:1  true

Following items have been found on the system:
Mount pointDeviceUuidFs typeMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsTotal spaceSpace usedSpace left
/boot/dev/vda1135e3d07-8003-46c7-a76a-829e7270155cxfsrwseclabelrelatimeattr2inode64noquotabind25958442374217210
Add noexec Option to /var/logxccdf_org.ssgproject.content_rule_mount_option_var_log_noexec mediumCCE-82008-4

Add noexec Option to /var/log

Rule IDxccdf_org.ssgproject.content_rule_mount_option_var_log_noexec
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-mount_option_var_log_noexec:def:1
Time2020-09-29T11:21:10
Severitymedium
Identifiers and References

Identifiers:  CCE-82008-4

References:  CM-7(a), CM-7(b), CM-6(a), AC-6, AC-6(1), MP-7, PR.IP-1, PR.PT-2, PR.PT-3, SRG-OS-000368-GPOS-00154

Description

The noexec mount option can be used to prevent binaries from being executed out of /var/log. Add the noexec option to the fourth column of /etc/fstab for the line which controls mounting of /var/log.

Rationale

Allowing users to execute binaries from directories containing log files such as /var/log should never be necessary in normal operation and can expose the system to potential compromise.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

noexec on /var/log  oval:ssg-test_var_log_partition_noexec:tst:1  false

Following items have been found on the system:
Mount pointDeviceUuidFs typeMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsTotal spaceSpace usedSpace left
/var/log/dev/mapper/ovirt-log04ffc7a2-ee25-4207-a1ca-33a1ef8f9021xfsrwseclabelnodevrelatimeattr2inode64noquotabind2618880268152592065
Add nosuid Option to /var/log/auditxccdf_org.ssgproject.content_rule_mount_option_var_log_audit_nosuid mediumCCE-82921-8

Add nosuid Option to /var/log/audit

Rule IDxccdf_org.ssgproject.content_rule_mount_option_var_log_audit_nosuid
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-mount_option_var_log_audit_nosuid:def:1
Time2020-09-29T11:21:10
Severitymedium
Identifiers and References

Identifiers:  CCE-82921-8

References:  CM-7(a), CM-7(b), CM-6(a), AC-6, AC-6(1), MP-7, PR.IP-1, PR.PT-2, PR.PT-3, SRG-OS-000368-GPOS-00154

Description

The nosuid mount option can be used to prevent execution of setuid programs in /var/log/audit. The SUID and SGID permissions should not be required in directories containing audit log files. Add the nosuid option to the fourth column of /etc/fstab for the line which controls mounting of /var/log/audit.

Rationale

The presence of SUID and SGID executables should be tightly controlled. Users should not be able to execute SUID or SGID binaries from partitions designated for audit log files.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

nosuid on /var/log/audit  oval:ssg-test_var_log_audit_partition_nosuid:tst:1  false

Following items have been found on the system:
Mount pointDeviceUuidFs typeMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsTotal spaceSpace usedSpace left
/var/log/audit/dev/mapper/ovirt-audit3b01f699-5c60-4a28-8941-ddc1a0828164xfsrwseclabelnodevrelatimeattr2inode64noquotabind25958410105249479
Add noexec Option to /var/tmpxccdf_org.ssgproject.content_rule_mount_option_var_tmp_noexec unknownCCE-82151-2

Add noexec Option to /var/tmp

Rule IDxccdf_org.ssgproject.content_rule_mount_option_var_tmp_noexec
Result
error
Multi-check ruleno
OVAL Definition IDoval:ssg-mount_option_var_tmp_noexec:def:1
Time2020-09-29T11:21:10
Severityunknown
Identifiers and References

Identifiers:  CCE-82151-2

References:  NT28(R12), 1.1.10, SRG-OS-000368-GPOS-00154

Description

The noexec mount option can be used to prevent binaries from being executed out of /var/tmp. Add the noexec option to the fourth column of /etc/fstab for the line which controls mounting of /var/tmp.

Rationale

Allowing users to execute binaries from world-writable directories such as /var/tmp should never be necessary in normal operation and can expose the system to potential compromise.

Evaluation messages
info 
Fix execution completed and returned: 1
info 
The mount point '/var/tmp' is not even in /etc/fstab, so we can't set up mount options
Not remediating, because there is no record of /var/tmp in /etc/fstab
info 
Failed to verify applied fix: Checking engine returns: fail


function include_mount_options_functions {
	:
}

# $1: type of filesystem
# $2: new mount point option
# $3: filesystem of new mount point (used when adding new entry in fstab)
# $4: mount type of new mount point (used when adding new entry in fstab)
function ensure_mount_option_for_vfstype {
        local _vfstype="$1" _new_opt="$2" _filesystem=$3 _type=$4 _vfstype_points=()
        readarray -t _vfstype_points < <(grep -E "[[:space:]]${_vfstype}[[:space:]]" /etc/fstab | awk '{print $2}')

        for _vfstype_point in "${_vfstype_points[@]}"
        do
                ensure_mount_option_in_fstab "$_vfstype_point" "$_new_opt" "$_filesystem" "$_type"
        done
}

# $1: mount point
# $2: new mount point option
# $3: device or virtual string (used when adding new entry in fstab)
# $4: mount type of mount point (used when adding new entry in fstab)
function ensure_mount_option_in_fstab {
	local _mount_point="$1" _new_opt="$2" _device=$3 _type=$4
	local _mount_point_match_regexp="" _previous_mount_opts=""
	_mount_point_match_regexp="$(get_mount_point_regexp "$_mount_point")"

	if [ "$(grep -c "$_mount_point_match_regexp" /etc/fstab)" -eq 0 ]; then
		# runtime opts without some automatic kernel/userspace-added defaults
		_previous_mount_opts=$(grep "$_mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
					| sed -E "s/(rw|defaults|seclabel|${_new_opt})(,|$)//g;s/,$//")
		[ "$_previous_mount_opts" ] && _previous_mount_opts+=","
		echo "${_device} ${_mount_point} ${_type} defaults,${_previous_mount_opts}${_new_opt} 0 0" >> /etc/fstab
	elif [ "$(grep "$_mount_point_match_regexp" /etc/fstab | grep -c "$_new_opt")" -eq 0 ]; then
		_previous_mount_opts=$(grep "$_mount_point_match_regexp" /etc/fstab | awk '{print $4}')
		sed -i "s|\(${_mount_point_match_regexp}.*${_previous_mount_opts}\)|\1,${_new_opt}|" /etc/fstab
	fi
}

# $1: mount point
function get_mount_point_regexp {
		printf "[[:space:]]%s[[:space:]]" "$1"
}

# $1: mount point
function assert_mount_point_in_fstab {
	local _mount_point_match_regexp
	_mount_point_match_regexp="$(get_mount_point_regexp "$1")"
	grep "$_mount_point_match_regexp" -q /etc/fstab \
		|| { echo "The mount point '$1' is not even in /etc/fstab, so we can't set up mount options" >&2; return 1; }
}

# $1: mount point
function remove_defaults_from_fstab_if_overriden {
	local _mount_point_match_regexp
	_mount_point_match_regexp="$(get_mount_point_regexp "$1")"
	if grep "$_mount_point_match_regexp" /etc/fstab | grep -q "defaults,"
	then
		sed -i "s|\(${_mount_point_match_regexp}.*\)defaults,|\1|" /etc/fstab
	fi
}

# $1: mount point
function ensure_partition_is_mounted {
	local _mount_point="$1"
	mkdir -p "$_mount_point" || return 1
	if mountpoint -q "$_mount_point"; then
		mount -o remount --target "$_mount_point"
	else
		mount --target "$_mount_point"
	fi
}
include_mount_options_functions

function perform_remediation {
	# test "$mount_has_to_exist" = 'yes'
	if test "yes" = 'yes'; then
		assert_mount_point_in_fstab /var/tmp || { echo "Not remediating, because there is no record of /var/tmp in /etc/fstab" >&2; return 1; }
	fi

	ensure_mount_option_in_fstab "/var/tmp" "noexec" "" ""

	ensure_partition_is_mounted "/var/tmp"
}

perform_remediation


Complexity:low
Disruption:high
Strategy:configure
- name: get back mount information associated to mountpoint
  command: findmnt --fstab '/var/tmp'
  register: device_name
  failed_when: device_name.rc > 1
  changed_when: false
  when: ansible_virtualization_role != "guest" or ansible_virtualization_type != "docker"
  tags:
    - mount_option_var_tmp_noexec
    - unknown_severity
    - configure_strategy
    - low_complexity
    - high_disruption
    - no_reboot_needed
    - CCE-82151-2

- name: create mount_info dictionary variable
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
    - '{{ device_name.stdout_lines[0].split() | list | lower }}'
    - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
    - device_name.stdout is defined and device_name.stdout_lines is defined
    - (device_name.stdout | length > 0)
    - ansible_virtualization_role != "guest" or ansible_virtualization_type != "docker"
  tags:
    - mount_option_var_tmp_noexec
    - unknown_severity
    - configure_strategy
    - low_complexity
    - high_disruption
    - no_reboot_needed
    - CCE-82151-2

- name: Ensure permission noexec are set on /var/tmp
  mount:
    path: /var/tmp
    src: '{{ mount_info.source }}'
    opts: '{{ mount_info.options }},noexec'
    state: mounted
    fstype: '{{ mount_info.fstype }}'
  when:
    - device_name.stdout is defined
    - (device_name.stdout | length > 0)
    - ansible_virtualization_role != "guest" or ansible_virtualization_type != "docker"
  tags:
    - mount_option_var_tmp_noexec
    - unknown_severity
    - configure_strategy
    - low_complexity
    - high_disruption
    - no_reboot_needed
    - CCE-82151-2


Complexity:low
Disruption:high
Strategy:enable

part /var/tmp --mountoptions="noexec"
OVAL test results details

noexec on /var/tmp  oval:ssg-test_var_tmp_partition_noexec:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_var_tmp_partition_noexec:obj:1 of type partition_object
Mount point
/var/tmp
Add nosuid Option to /tmpxccdf_org.ssgproject.content_rule_mount_option_tmp_nosuid unknownCCE-82140-5

Add nosuid Option to /tmp

Rule IDxccdf_org.ssgproject.content_rule_mount_option_tmp_nosuid
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-mount_option_tmp_nosuid:def:1
Time2020-09-29T11:18:03
Severityunknown
Identifiers and References

Identifiers:  CCE-82140-5

References:  NT28(R12), 1.1.4, 11, 13, 14, 3, 8, 9, APO13.01, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS05.02, DSS05.05, DSS05.06, DSS06.06, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 7.6, A.11.2.9, A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, A.8.2.1, A.8.2.2, A.8.2.3, A.8.3.1, A.8.3.3, A.9.1.2, CM-7(a), CM-7(b), CM-6(a), AC-6, AC-6(1), MP-7, PR.IP-1, PR.PT-2, PR.PT-3, SRG-OS-000368-GPOS-00154

Description

The nosuid mount option can be used to prevent execution of setuid programs in /tmp. The SUID and SGID permissions should not be required in these world-writable directories. Add the nosuid option to the fourth column of /etc/fstab for the line which controls mounting of /tmp.

Rationale

The presence of SUID and SGID executables should be tightly controlled. Users should not be able to execute SUID or SGID binaries from temporary storage partitions.

OVAL test results details

nosuid on /tmp  oval:ssg-test_tmp_partition_nosuid:tst:1  true

Following items have been found on the system:
Mount pointDeviceUuidFs typeMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsMount optionsTotal spaceSpace usedSpace left
/tmp/dev/mapper/ovirt-tmpfe226ba1-b167-4b0f-81b2-d06bb6c1dd78xfsrwseclabelnosuidnodevnoexecrelatimeattr2inode64noquotabind52172811962509766
Enable page allocator poisoningxccdf_org.ssgproject.content_rule_grub2_page_poison_argument mediumCCE-80944-2

Enable page allocator poisoning

Rule IDxccdf_org.ssgproject.content_rule_grub2_page_poison_argument
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-grub2_page_poison_argument:def:1
Time2020-09-29T11:21:11
Severitymedium
Identifiers and References

Identifiers:  CCE-80944-2

References:  SRG-OS-000480-GPOS-00227

Description

To enable poisoning of free pages, add the argument page_poison=1 to the default GRUB 2 command line for the Linux operating system in /etc/default/grub, in the manner below:

GRUB_CMDLINE_LINUX="page_poison=1"

Rationale

Poisoning writes an arbitrary value to freed pages, so any modification or reference to that page after being freed or before being initialized will be detected and prevented. This prevents many types of use-after-free vulnerabilities at little performance cost. Also prevents leak of data and detection of corrupted memory.

Warnings
warning  The GRUB 2 configuration file, grub.cfg, is automatically updated each time a new kernel is installed. Note that any changes to /etc/default/grub require rebuilding the grub.cfg file. To update the GRUB 2 configuration file manually, use the
grub2-mkconfig -o
command as follows:
  • On BIOS-based machines, issue the following command as root:
    ~]# grub2-mkconfig -o /boot/grub2/grub.cfg
  • On UEFI-based machines, issue the following command as root:
    ~]# grub2-mkconfig -o /boot/efi/EFI/redhat/grub.cfg
Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

check forkernel command line parameters page_poison=1 in /boot/grub2/grubenv for all kernels  oval:ssg-test_grub2_page_poison_argument_grub_env:tst:1  false

Following items have been found on the system:
PathContent
/boot/grub2/grubenvkernelopts=root=/dev/mapper/ovirt-root ro console=tty0 console=ttyS0 crashkernel=auto resume=/dev/mapper/ovirt-swap rd.lvm.lv=ovirt/root rd.lvm.lv=ovirt/swap
Enable SLUB/SLAB allocator poisoningxccdf_org.ssgproject.content_rule_grub2_slub_debug_argument mediumCCE-80945-9

Enable SLUB/SLAB allocator poisoning

Rule IDxccdf_org.ssgproject.content_rule_grub2_slub_debug_argument
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-grub2_slub_debug_argument:def:1
Time2020-09-29T11:21:11
Severitymedium
Identifiers and References

Identifiers:  CCE-80945-9

References:  SRG-OS-000433-GPOS-00192

Description

To enable poisoning of SLUB/SLAB objects, add the argument slub_debug=P to the default GRUB 2 command line for the Linux operating system in /etc/default/grub, in the manner below:

GRUB_CMDLINE_LINUX="slub_debug=P"

Rationale

Poisoning writes an arbitrary value to freed objects, so any modification or reference to that object after being freed or before being initialized will be detected and prevented. This prevents many types of use-after-free vulnerabilities at little performance cost. Also prevents leak of data and detection of corrupted memory.

Warnings
warning  The GRUB 2 configuration file, grub.cfg, is automatically updated each time a new kernel is installed. Note that any changes to /etc/default/grub require rebuilding the grub.cfg file. To update the GRUB 2 configuration file manually, use the
grub2-mkconfig -o
command as follows:
  • On BIOS-based machines, issue the following command as root:
    ~]# grub2-mkconfig -o /boot/grub2/grub.cfg
  • On UEFI-based machines, issue the following command as root:
    ~]# grub2-mkconfig -o /boot/efi/EFI/redhat/grub.cfg
Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

check forkernel command line parameters slub_debug=P in /boot/grub2/grubenv for all kernels  oval:ssg-test_grub2_slub_debug_argument_grub_env:tst:1  false

Following items have been found on the system:
PathContent
/boot/grub2/grubenvkernelopts=root=/dev/mapper/ovirt-root ro console=tty0 console=ttyS0 crashkernel=auto resume=/dev/mapper/ovirt-swap rd.lvm.lv=ovirt/root rd.lvm.lv=ovirt/swap
Restrict Exposed Kernel Pointer Addresses Accessxccdf_org.ssgproject.content_rule_sysctl_kernel_kptr_restrict mediumCCE-80915-2

Restrict Exposed Kernel Pointer Addresses Access

Rule IDxccdf_org.ssgproject.content_rule_sysctl_kernel_kptr_restrict
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_kernel_kptr_restrict:def:1
Time2020-09-29T11:18:03
Severitymedium
Identifiers and References

Identifiers:  CCE-80915-2

References:  NT28(R23), SC-30, SC-30(2), SC-30(5), CM-6(a), SRG-OS-000132-GPOS-00067

Description

To set the runtime status of the kernel.kptr_restrict kernel parameter, run the following command:

$ sudo sysctl -w kernel.kptr_restrict=1
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
kernel.kptr_restrict = 1

Rationale

Exposing kernel pointers (through procfs or seq_printf()) exposes kernel writeable structures that can contain functions pointers. If a write vulnereability occurs in the kernel allowing a write access to any of this structure, the kernel can be compromise. This option disallow any program withtout the CAP_SYSLOG capability from getting the kernel pointers addresses, replacing them with 0.

OVAL test results details

kernel.kptr_restrict static configuration  oval:ssg-test_static_sysctl_kernel_kptr_restrict:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_kernel_kptr_restrict:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf^[\s]*kernel.kptr_restrict[\s]*=[\s]*1[\s]*$1

kernel.kptr_restrict static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_kernel_kptr_restrict:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_kernel_kptr_restrict:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$^[\s]*kernel.kptr_restrict[\s]*=[\s]*1[\s]*$1

kernel.kptr_restrict static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_kernel_kptr_restrict:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_kernel_kptr_restrict:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$^[\s]*kernel.kptr_restrict[\s]*=[\s]*1[\s]*$1

kernel.kptr_restrict static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_kernel_kptr_restrict:tst:1  true

Following items have been found on the system:
PathContent
/usr/lib/sysctl.d/50-default.confkernel.kptr_restrict = 1

kernel runtime parameter kernel.kptr_restrict set to 1  oval:ssg-test_sysctl_runtime_kernel_kptr_restrict:tst:1  true

Following items have been found on the system:
NameValue
kernel.kptr_restrict1
Disable acquiring, saving, and processing core dumpsxccdf_org.ssgproject.content_rule_service_systemd-coredump_disabled unknownCCE-82881-4

Disable acquiring, saving, and processing core dumps

Rule IDxccdf_org.ssgproject.content_rule_service_systemd-coredump_disabled
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-service_systemd-coredump_disabled:def:1
Time2020-09-29T11:21:14
Severityunknown
Identifiers and References

Identifiers:  CCE-82881-4

References:  FMT_SMF_EXT.1, SRG-OS-000480-GPOS-00227

Description

The systemd-coredump.socket unit is a socket activation of the systemd-coredump@.service which processes core dumps. By masking the unit, core dump processing is disabled.

Rationale

A core dump includes a memory image taken at the time the operating system terminates an application. The memory image could contain sensitive data and is generally useful only for developers trying to debug problems.

Evaluation messages
info 
Fix execution completed and returned: 0
info 
Failed to stop systemd-coredump.service: Unit systemd-coredump.service not loaded.
Failed to disable unit: Unit file systemd-coredump.service does not exist.
Unit systemd-coredump.service does not exist, proceeding anyway.
Created symlink /etc/systemd/system/systemd-coredump.service → /dev/null.
Created symlink /etc/systemd/system/systemd-coredump.socket → /dev/null.
Failed to reset failed state of unit systemd-coredump.service: Unit systemd-coredump.service not loaded.
OVAL test results details

package systemd is removed  oval:ssg-test_service_systemd-coredump_package_systemd_removed:tst:1  false

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
systemdx86_64(none)31.el8_2.22390:239-31.el8_2.2199e2f91fd431d51systemd-0:239-31.el8_2.2.x86_64

Test that the systemd-coredump service is not running  oval:ssg-test_service_not_running_systemd-coredump:tst:1  false

Following items have been found on the system:
UnitPropertyValue
systemd-coredump.socketActiveStateactive

Test that the property LoadState from the service systemd-coredump is masked  oval:ssg-test_service_loadstate_is_masked_systemd-coredump:tst:1  false

Following items have been found on the system:
UnitPropertyValue
systemd-coredump.socketLoadStateloaded

Test that the property FragmentPath from the service systemd-coredump is set to /dev/null  oval:ssg-test_service_fragmentpath_is_dev_null_systemd-coredump:tst:1  false

Following items have been found on the system:
UnitPropertyValue
systemd-coredump.socketFragmentPath/usr/lib/systemd/system/systemd-coredump.socket
Disable core dump backtracesxccdf_org.ssgproject.content_rule_coredump_disable_backtraces unknownCCE-82251-0

Disable core dump backtraces

Rule IDxccdf_org.ssgproject.content_rule_coredump_disable_backtraces
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-coredump_disable_backtraces:def:1
Time2020-09-29T11:21:14
Severityunknown
Identifiers and References

Identifiers:  CCE-82251-0

References:  FMT_SMF_EXT.1, SRG-OS-000480-GPOS-00227

Description

The ProcessSizeMax option in [Coredump] section of /etc/systemd/coredump.conf specifies the maximum size in bytes of a core which will be processed. Core dumps exceeding this size may be stored, but the backtrace will not be generated.

Rationale

A core dump includes a memory image taken at the time the operating system terminates an application. The memory image could contain sensitive data and is generally useful only for developers or system operators trying to debug problems. Enabling core dumps on production systems is not recommended, however there may be overriding operational requirements to enable advanced debuging. Permitting temporary enablement of core dumps during such situations should be reviewed through local needs and policy.

Warnings
warning  If the /etc/systemd/coredump.conf file does not already contain the [Coredump] section, the value will not be configured correctly.
Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

tests the value of ProcessSizeMax setting in the /etc/systemd/coredump.conf file  oval:ssg-test_coredump_disable_backtraces:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_coredump_disable_backtraces:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/systemd/coredump.conf^\s*\[Coredump\].*(?:\n\s*[^[\s].*)*\n^[ \t]*(?i)ProcessSizeMax(?-i)[ \t]*=[ \t]*(.+?)[ \t]*(?:$|#)1
Disable Core Dumps for All Usersxccdf_org.ssgproject.content_rule_disable_users_coredumps unknownCCE-81038-2

Disable Core Dumps for All Users

Rule IDxccdf_org.ssgproject.content_rule_disable_users_coredumps
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-disable_users_coredumps:def:1
Time2020-09-29T11:21:14
Severityunknown
Identifiers and References

Identifiers:  CCE-81038-2

References:  1.5.1, 1, 12, 13, 15, 16, 2, 7, 8, APO13.01, BAI04.04, DSS01.03, DSS03.05, DSS05.07, SR 6.2, SR 7.1, SR 7.2, A.12.1.3, A.17.2.1, DE.CM-1, PR.DS-4, SRG-OS-000480-GPOS-00227

Description

To disable core dumps for all users, add the following line to /etc/security/limits.conf:

*     hard   core    0

Rationale

A core dump includes a memory image taken at the time the operating system terminates an application. The memory image could contain sensitive data and is generally useful only for developers trying to debug problems.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

Tests the value of the ^[\s]*\*[\s]+(hard|-)[\s]+core[\s]+([\d]+) setting in the /etc/security/limits.d directory  oval:ssg-test_core_dumps_limits_d:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_core_dumps_limits_d:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/security/limits.d^.*\.conf$^[\s]*\*[\s]+(?:hard|-)[\s]+core[\s]+([\d]+)1

Tests for existance of the ^[\s]*\*[\s]+(hard|-)[\s]+core setting in the /etc/security/limits.d directory  oval:ssg-test_core_dumps_limits_d_exists:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_core_dumps_limits_d_exists:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/security/limits.d^.*\.conf$^[\s]*\*[\s]+(?:hard|-)[\s]+core1

Tests the value of the ^[\s]*\*[\s]+(hard|-)[\s]+core[\s]+([\d]+) setting in the /etc/security/limits.conf file  oval:ssg-test_core_dumps_limitsconf:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_core_dumps_limitsconf:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/security/limits.conf^[\s]*\*[\s]+(?:hard|-)[\s]+core[\s]+([\d]+)1
Disable storing core dumpxccdf_org.ssgproject.content_rule_coredump_disable_storage unknownCCE-82252-8

Disable storing core dump

Rule IDxccdf_org.ssgproject.content_rule_coredump_disable_storage
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-coredump_disable_storage:def:1
Time2020-09-29T11:21:14
Severityunknown
Identifiers and References

Identifiers:  CCE-82252-8

References:  FMT_SMF_EXT.1, SRG-OS-000480-GPOS-00227

Description

The Storage option in [Coredump] section of /etc/systemd/coredump.conf can be set to none to disable storing core dumps permanently.

Rationale

A core dump includes a memory image taken at the time the operating system terminates an application. The memory image could contain sensitive data and is generally useful only for developers or system operators trying to debug problems. Enabling core dumps on production systems is not recommended, however there may be overriding operational requirements to enable advanced debuging. Permitting temporary enablement of core dumps during such situations should be reviewed through local needs and policy.

Warnings
warning  If the /etc/systemd/coredump.conf file does not already contain the [Coredump] section, the value will not be configured correctly.
Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

tests the value of Storage setting in the /etc/systemd/coredump.conf file  oval:ssg-test_coredump_disable_storage:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_coredump_disable_storage:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/systemd/coredump.conf^\s*\[Coredump\].*(?:\n\s*[^[\s].*)*\n^[ \t]*(?i)Storage(?-i)[ \t]*=[ \t]*(.+?)[ \t]*(?:$|#)1
Restrict usage of ptrace to descendant processesxccdf_org.ssgproject.content_rule_sysctl_kernel_yama_ptrace_scope mediumCCE-80953-3

Restrict usage of ptrace to descendant processes

Rule IDxccdf_org.ssgproject.content_rule_sysctl_kernel_yama_ptrace_scope
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_kernel_yama_ptrace_scope:def:1
Time2020-09-29T11:21:10
Severitymedium
Identifiers and References

Identifiers:  CCE-80953-3

References:  NT28(R25), SRG-OS-000132-GPOS-00067

Description

To set the runtime status of the kernel.yama.ptrace_scope kernel parameter, run the following command:

$ sudo sysctl -w kernel.yama.ptrace_scope=1
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
kernel.yama.ptrace_scope = 1

Rationale

Unrestricted usage of ptrace allows compromised binaries to run ptrace on another processes of the user. Like this, the attacker can steal sensitive information from the target processes (e.g. SSH sessions, web browser, ...) without any additional assistance from the user (i.e. without resorting to phishing).

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

kernel.yama.ptrace_scope static configuration  oval:ssg-test_static_sysctl_kernel_yama_ptrace_scope:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_kernel_yama_ptrace_scope:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf^[\s]*kernel.yama.ptrace_scope[\s]*=[\s]*1[\s]*$1

kernel.yama.ptrace_scope static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_kernel_yama_ptrace_scope:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_kernel_yama_ptrace_scope:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$^[\s]*kernel.yama.ptrace_scope[\s]*=[\s]*1[\s]*$1

kernel.yama.ptrace_scope static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_kernel_yama_ptrace_scope:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_kernel_yama_ptrace_scope:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$^[\s]*kernel.yama.ptrace_scope[\s]*=[\s]*1[\s]*$1

kernel.yama.ptrace_scope static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_kernel_yama_ptrace_scope:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_kernel_yama_ptrace_scope:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$^[\s]*kernel.yama.ptrace_scope[\s]*=[\s]*1[\s]*$1

kernel runtime parameter kernel.yama.ptrace_scope set to 1  oval:ssg-test_sysctl_runtime_kernel_yama_ptrace_scope:tst:1  false

Following items have been found on the system:
NameValue
kernel.yama.ptrace_scope0
Harden the operation of the BPF just-in-time compilerxccdf_org.ssgproject.content_rule_sysctl_net_core_bpf_jit_harden mediumCCE-82934-1

Harden the operation of the BPF just-in-time compiler

Rule IDxccdf_org.ssgproject.content_rule_sysctl_net_core_bpf_jit_harden
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_net_core_bpf_jit_harden:def:1
Time2020-09-29T11:21:10
Severitymedium
Identifiers and References

Identifiers:  CCE-82934-1

References:  FMT_SMF_EXT.1, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the net.core.bpf_jit_harden kernel parameter, run the following command:

$ sudo sysctl -w net.core.bpf_jit_harden=2
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
net.core.bpf_jit_harden = 2

Rationale

When hardened, the extended Berkeley Packet Filter just-in-time compiler will randomize any kernel addresses in the BPF programs and maps, and will not expose the JIT addresses in /proc/kallsyms.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

net.core.bpf_jit_harden static configuration  oval:ssg-test_static_sysctl_net_core_bpf_jit_harden:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_net_core_bpf_jit_harden:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf^[\s]*net.core.bpf_jit_harden[\s]*=[\s]*2[\s]*$1

net.core.bpf_jit_harden static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_net_core_bpf_jit_harden:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_net_core_bpf_jit_harden:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$^[\s]*net.core.bpf_jit_harden[\s]*=[\s]*2[\s]*$1

net.core.bpf_jit_harden static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_net_core_bpf_jit_harden:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_net_core_bpf_jit_harden:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$^[\s]*net.core.bpf_jit_harden[\s]*=[\s]*2[\s]*$1

net.core.bpf_jit_harden static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_net_core_bpf_jit_harden:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_net_core_bpf_jit_harden:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$^[\s]*net.core.bpf_jit_harden[\s]*=[\s]*2[\s]*$1

kernel runtime parameter net.core.bpf_jit_harden set to 2  oval:ssg-test_sysctl_runtime_net_core_bpf_jit_harden:tst:1  false

Following items have been found on the system:
NameValue
net.core.bpf_jit_harden1
Disable Access to Network bpf() Syscall From Unprivileged Processesxccdf_org.ssgproject.content_rule_sysctl_kernel_unprivileged_bpf_disabled mediumCCE-82974-7

Disable Access to Network bpf() Syscall From Unprivileged Processes

Rule IDxccdf_org.ssgproject.content_rule_sysctl_kernel_unprivileged_bpf_disabled
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_kernel_unprivileged_bpf_disabled:def:1
Time2020-09-29T11:21:10
Severitymedium
Identifiers and References

Identifiers:  CCE-82974-7

References:  FMT_SMF_EXT.1, SRG-OS-000132-GPOS-00067

Description

To set the runtime status of the kernel.unprivileged_bpf_disabled kernel parameter, run the following command:

$ sudo sysctl -w kernel.unprivileged_bpf_disabled=1
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
kernel.unprivileged_bpf_disabled = 1

Rationale

Loading and accessing the packet filters programs and maps using the bpf() syscall has the potential of revealing sensitive information about the kernel state.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

kernel.unprivileged_bpf_disabled static configuration  oval:ssg-test_static_sysctl_kernel_unprivileged_bpf_disabled:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_kernel_unprivileged_bpf_disabled:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf^[\s]*kernel.unprivileged_bpf_disabled[\s]*=[\s]*1[\s]*$1

kernel.unprivileged_bpf_disabled static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_kernel_unprivileged_bpf_disabled:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_kernel_unprivileged_bpf_disabled:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$^[\s]*kernel.unprivileged_bpf_disabled[\s]*=[\s]*1[\s]*$1

kernel.unprivileged_bpf_disabled static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_kernel_unprivileged_bpf_disabled:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_kernel_unprivileged_bpf_disabled:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$^[\s]*kernel.unprivileged_bpf_disabled[\s]*=[\s]*1[\s]*$1

kernel.unprivileged_bpf_disabled static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_kernel_unprivileged_bpf_disabled:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_kernel_unprivileged_bpf_disabled:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$^[\s]*kernel.unprivileged_bpf_disabled[\s]*=[\s]*1[\s]*$1

kernel runtime parameter kernel.unprivileged_bpf_disabled set to 1  oval:ssg-test_sysctl_runtime_kernel_unprivileged_bpf_disabled:tst:1  true

Following items have been found on the system:
NameValue
kernel.unprivileged_bpf_disabled1
Disable vsyscallsxccdf_org.ssgproject.content_rule_grub2_vsyscall_argument infoCCE-80946-7

Disable vsyscalls

Rule IDxccdf_org.ssgproject.content_rule_grub2_vsyscall_argument
Result
informational
Multi-check ruleno
OVAL Definition IDoval:ssg-grub2_vsyscall_argument:def:1
Time2020-09-29T11:18:03
Severityinfo
Identifiers and References

Identifiers:  CCE-80946-7

References:  SRG-OS-000480-GPOS-00227

Description

To disable use of virtual syscalls, add the argument vsyscall=none to the default GRUB 2 command line for the Linux operating system in /etc/default/grub, in the manner below:

GRUB_CMDLINE_LINUX="vsyscall=none"

Rationale

Virtual Syscalls provide an opportunity of attack for a user who has control of the return instruction pointer.

Warnings
warning  The GRUB 2 configuration file, grub.cfg, is automatically updated each time a new kernel is installed. Note that any changes to /etc/default/grub require rebuilding the grub.cfg file. To update the GRUB 2 configuration file manually, use the
grub2-mkconfig -o
command as follows:
  • On BIOS-based machines, issue the following command as root:
    ~]# grub2-mkconfig -o /boot/grub2/grub.cfg
  • On UEFI-based machines, issue the following command as root:
    ~]# grub2-mkconfig -o /boot/efi/EFI/redhat/grub.cfg
OVAL test results details

check forkernel command line parameters vsyscall=none in /boot/grub2/grubenv for all kernels  oval:ssg-test_grub2_vsyscall_argument_grub_env:tst:1  false

Following items have been found on the system:
PathContent
/boot/grub2/grubenvkernelopts=root=/dev/mapper/ovirt-root ro console=tty0 console=ttyS0 crashkernel=auto resume=/dev/mapper/ovirt-swap rd.lvm.lv=ovirt/root rd.lvm.lv=ovirt/swap
Restrict Access to Kernel Message Bufferxccdf_org.ssgproject.content_rule_sysctl_kernel_dmesg_restrict mediumCCE-80913-7

Restrict Access to Kernel Message Buffer

Rule IDxccdf_org.ssgproject.content_rule_sysctl_kernel_dmesg_restrict
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_kernel_dmesg_restrict:def:1
Time2020-09-29T11:21:10
Severitymedium
Identifiers and References

Identifiers:  CCE-80913-7

References:  NT28(R23), 3.1.5, CCI-001314, 164.308(a)(1)(ii)(D), 164.308(a)(3), 164.308(a)(4), 164.310(b), 164.310(c), 164.312(a), 164.312(e), SI-11(a), SI-11(b), SRG-OS-000132-GPOS-00067

Description

To set the runtime status of the kernel.dmesg_restrict kernel parameter, run the following command:

$ sudo sysctl -w kernel.dmesg_restrict=1
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
kernel.dmesg_restrict = 1

Rationale

Unprivileged access to the kernel syslog can expose sensitive kernel address information.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

kernel.dmesg_restrict static configuration  oval:ssg-test_static_sysctl_kernel_dmesg_restrict:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_kernel_dmesg_restrict:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf^[\s]*kernel.dmesg_restrict[\s]*=[\s]*1[\s]*$1

kernel.dmesg_restrict static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_kernel_dmesg_restrict:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_kernel_dmesg_restrict:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$^[\s]*kernel.dmesg_restrict[\s]*=[\s]*1[\s]*$1

kernel.dmesg_restrict static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_kernel_dmesg_restrict:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_kernel_dmesg_restrict:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$^[\s]*kernel.dmesg_restrict[\s]*=[\s]*1[\s]*$1

kernel.dmesg_restrict static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_kernel_dmesg_restrict:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_kernel_dmesg_restrict:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$^[\s]*kernel.dmesg_restrict[\s]*=[\s]*1[\s]*$1

kernel runtime parameter kernel.dmesg_restrict set to 1  oval:ssg-test_sysctl_runtime_kernel_dmesg_restrict:tst:1  false

Following items have been found on the system:
NameValue
kernel.dmesg_restrict0
Disable Kernel Image Loadingxccdf_org.ssgproject.content_rule_sysctl_kernel_kexec_load_disabled mediumCCE-80952-5

Disable Kernel Image Loading

Rule IDxccdf_org.ssgproject.content_rule_sysctl_kernel_kexec_load_disabled
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_kernel_kexec_load_disabled:def:1
Time2020-09-29T11:21:11
Severitymedium
Identifiers and References

Identifiers:  CCE-80952-5

References:  SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the kernel.kexec_load_disabled kernel parameter, run the following command:

$ sudo sysctl -w kernel.kexec_load_disabled=1
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
kernel.kexec_load_disabled = 1

Rationale

Disabling kexec_load allows greater control of the kernel memory. It makes it impossible to load another kernel image after it has been disabled.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

kernel.kexec_load_disabled static configuration  oval:ssg-test_static_sysctl_kernel_kexec_load_disabled:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_kernel_kexec_load_disabled:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf^[\s]*kernel.kexec_load_disabled[\s]*=[\s]*1[\s]*$1

kernel.kexec_load_disabled static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_kernel_kexec_load_disabled:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_kernel_kexec_load_disabled:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$^[\s]*kernel.kexec_load_disabled[\s]*=[\s]*1[\s]*$1

kernel.kexec_load_disabled static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_kernel_kexec_load_disabled:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_kernel_kexec_load_disabled:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$^[\s]*kernel.kexec_load_disabled[\s]*=[\s]*1[\s]*$1

kernel.kexec_load_disabled static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_kernel_kexec_load_disabled:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_kernel_kexec_load_disabled:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$^[\s]*kernel.kexec_load_disabled[\s]*=[\s]*1[\s]*$1

kernel runtime parameter kernel.kexec_load_disabled set to 1  oval:ssg-test_sysctl_runtime_kernel_kexec_load_disabled:tst:1  false

Following items have been found on the system:
NameValue
kernel.kexec_load_disabled0
Disable storing core dumpsxccdf_org.ssgproject.content_rule_sysctl_kernel_core_pattern unknownCCE-82215-5

Disable storing core dumps

Rule IDxccdf_org.ssgproject.content_rule_sysctl_kernel_core_pattern
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_kernel_core_pattern:def:1
Time2020-09-29T11:21:11
Severityunknown
Identifiers and References

Identifiers:  CCE-82215-5

References:  FMT_SMF_EXT.1, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the kernel.core_pattern kernel parameter, run the following command:

$ sudo sysctl -w kernel.core_pattern=|/bin/false
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
kernel.core_pattern = |/bin/false

Rationale

A core dump includes a memory image taken at the time the operating system terminates an application. The memory image could contain sensitive data and is generally useful only for developers trying to debug problems.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

kernel.core_pattern static configuration  oval:ssg-test_static_sysctl_kernel_core_pattern:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_kernel_core_pattern:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf^[\s]*kernel.core_pattern[\s]*=[\s]*|/bin/false[\s]*$1

kernel.core_pattern static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_kernel_core_pattern:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_kernel_core_pattern:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$^[\s]*kernel.core_pattern[\s]*=[\s]*|/bin/false[\s]*$1

kernel.core_pattern static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_kernel_core_pattern:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_kernel_core_pattern:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$^[\s]*kernel.core_pattern[\s]*=[\s]*|/bin/false[\s]*$1

kernel.core_pattern static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_kernel_core_pattern:tst:1  true

Following items have been found on the system:
PathContent
/usr/lib/sysctl.d/50-coredump.conf kernel.core_pattern=

kernel runtime parameter kernel.core_pattern set to |/bin/false  oval:ssg-test_sysctl_runtime_kernel_core_pattern:tst:1  false

Following items have been found on the system:
NameValue
kernel.core_pattern|/usr/lib/systemd/systemd-coredump %P %u %g %s %t %c %h %e
Disallow kernel profiling by unprivileged usersxccdf_org.ssgproject.content_rule_sysctl_kernel_perf_event_paranoid mediumCCE-81054-9

Disallow kernel profiling by unprivileged users

Rule IDxccdf_org.ssgproject.content_rule_sysctl_kernel_perf_event_paranoid
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_kernel_perf_event_paranoid:def:1
Time2020-09-29T11:21:11
Severitymedium
Identifiers and References

Identifiers:  CCE-81054-9

References:  NT28(R23), FMT_SMF_EXT.1, SRG-OS-000132-GPOS-00067

Description

To set the runtime status of the kernel.perf_event_paranoid kernel parameter, run the following command:

$ sudo sysctl -w kernel.perf_event_paranoid=2
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
kernel.perf_event_paranoid = 2

Rationale

Kernel profiling can reveal sensitive information about kernel behaviour.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

kernel.perf_event_paranoid static configuration  oval:ssg-test_static_sysctl_kernel_perf_event_paranoid:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_kernel_perf_event_paranoid:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf^[\s]*kernel.perf_event_paranoid[\s]*=[\s]*2[\s]*$1

kernel.perf_event_paranoid static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_kernel_perf_event_paranoid:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_kernel_perf_event_paranoid:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$^[\s]*kernel.perf_event_paranoid[\s]*=[\s]*2[\s]*$1

kernel.perf_event_paranoid static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_kernel_perf_event_paranoid:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_kernel_perf_event_paranoid:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$^[\s]*kernel.perf_event_paranoid[\s]*=[\s]*2[\s]*$1

kernel.perf_event_paranoid static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_kernel_perf_event_paranoid:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_kernel_perf_event_paranoid:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$^[\s]*kernel.perf_event_paranoid[\s]*=[\s]*2[\s]*$1

kernel runtime parameter kernel.perf_event_paranoid set to 2  oval:ssg-test_sysctl_runtime_kernel_perf_event_paranoid:tst:1  true

Following items have been found on the system:
NameValue
kernel.perf_event_paranoid2
Disable the use of user namespacesxccdf_org.ssgproject.content_rule_sysctl_user_max_user_namespaces infoCCE-82211-4

Disable the use of user namespaces

Rule IDxccdf_org.ssgproject.content_rule_sysctl_user_max_user_namespaces
Result
informational
Multi-check ruleno
OVAL Definition IDoval:ssg-sysctl_user_max_user_namespaces:def:1
Time2020-09-29T11:18:03
Severityinfo
Identifiers and References

Identifiers:  CCE-82211-4

References:  SC-39, CM-6(a), FMT_SMF_EXT.1, SRG-OS-000480-GPOS-00227

Description

To set the runtime status of the user.max_user_namespaces kernel parameter, run the following command:

$ sudo sysctl -w user.max_user_namespaces=0
If this is not the system default value, add the following line to a file in the directory /etc/sysctl.d:
user.max_user_namespaces = 0
When containers are deployed on the machine, the value should be set to large non-zero value.

Rationale

User namespaces are used primarily for Linux containers. The value 0 disallows the use of user namespaces.

Warnings
warning  This configuration baseline was created to deploy the base operating system for general purpose workloads. When the operating system is configured for certain purposes, such as to host Linux Containers, it is expected that user.max_user_namespaces will be enabled.
OVAL test results details

user.max_user_namespaces static configuration  oval:ssg-test_static_sysctl_user_max_user_namespaces:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_sysctl_user_max_user_namespaces:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sysctl.conf^[\s]*user.max_user_namespaces[\s]*=[\s]*0[\s]*$1

user.max_user_namespaces static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_etc_sysctld_user_max_user_namespaces:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_etc_sysctld_user_max_user_namespaces:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/sysctl.d^.*\.conf$^[\s]*user.max_user_namespaces[\s]*=[\s]*0[\s]*$1

user.max_user_namespaces static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_run_sysctld_user_max_user_namespaces:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_run_sysctld_user_max_user_namespaces:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/sysctl.d^.*\.conf$^[\s]*user.max_user_namespaces[\s]*=[\s]*0[\s]*$1

user.max_user_namespaces static configuration in /etc/sysctl.d/*.conf  oval:ssg-test_static_usr_lib_sysctld_user_max_user_namespaces:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_static_usr_lib_sysctld_user_max_user_namespaces:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/sysctl.d^.*\.conf$^[\s]*user.max_user_namespaces[\s]*=[\s]*0[\s]*$1

kernel runtime parameter user.max_user_namespaces set to 0  oval:ssg-test_sysctl_runtime_user_max_user_namespaces:tst:1  false

Following items have been found on the system:
NameValue
user.max_user_namespaces14976
Disable Mounting of cramfsxccdf_org.ssgproject.content_rule_kernel_module_cramfs_disabled lowCCE-81031-7

Disable Mounting of cramfs

Rule IDxccdf_org.ssgproject.content_rule_kernel_module_cramfs_disabled
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-kernel_module_cramfs_disabled:def:1
Time2020-09-29T11:21:14
Severitylow
Identifiers and References

Identifiers:  CCE-81031-7

References:  1.1.1.1, 11, 14, 3, 9, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS05.02, DSS05.05, DSS06.06, 3.4.6, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 7.6, A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, A.9.1.2, CM-7(a), CM-7(b), CM-6(a), PR.IP-1, PR.PT-3, SRG-OS-000095-GPOS-00049

Description

To configure the system to prevent the cramfs kernel module from being loaded, add the following line to a file in the directory /etc/modprobe.d:

install cramfs /bin/true
This effectively prevents usage of this uncommon filesystem.

Rationale

Linux kernel modules which implement filesystems that are not needed by the local system should be disabled.

Evaluation messages
info 
Fix execution completed and returned: 0
info 
grep: /etc/modprobe.d/cramfs.conf: No such file or directory
OVAL test results details

kernel module cramfs disabled  oval:ssg-test_kernmod_cramfs_disabled:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_cramfs_disabled:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/modprobe.d^.*\.conf$^\s*install\s+cramfs\s+(/bin/false|/bin/true)$1

kernel module cramfs disabled in /etc/modprobe.conf  oval:ssg-test_kernmod_cramfs_modprobeconf:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_cramfs_modprobeconf:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/modprobe.conf^\s*install\s+cramfs\s+(/bin/false|/bin/true)$1

kernel module cramfs disabled in /etc/modules-load.d  oval:ssg-test_kernmod_cramfs_etcmodules-load:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_cramfs_etcmodules-load:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/etc/modules-load.d^.*\.conf$^\s*install\s+cramfs\s+(/bin/false|/bin/true)$1

kernel module cramfs disabled in /run/modules-load.d  oval:ssg-test_kernmod_cramfs_runmodules-load:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_cramfs_runmodules-load:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/modules-load.d^.*\.conf$^\s*install\s+cramfs\s+(/bin/false|/bin/true)$1

kernel module cramfs disabled in /usr/lib/modules-load.d  oval:ssg-test_kernmod_cramfs_libmodules-load:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_cramfs_libmodules-load:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/modules-load.d^.*\.conf$^\s*install\s+cramfs\s+(/bin/false|/bin/true)$1

kernel module cramfs disabled in /run/modprobe.d  oval:ssg-test_kernmod_cramfs_runmodprobed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_cramfs_runmodprobed:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/run/modprobe.d^.*\.conf$^\s*install\s+cramfs\s+(/bin/false|/bin/true)$1

kernel module cramfs disabled in /usr/lib/modprobe.d  oval:ssg-test_kernmod_cramfs_libmodprobed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_kernmod_cramfs_libmodprobed:obj:1 of type textfilecontent54_object
PathFilenamePatternInstance
/usr/lib/modprobe.d^.*\.conf$^\s*install\s+cramfs\s+(/bin/false|/bin/true)$1
Configure CA certificate for rsyslog remote loggingxccdf_org.ssgproject.content_rule_rsyslog_remote_tls_cacert mediumCCE-82458-1

Configure CA certificate for rsyslog remote logging

Rule IDxccdf_org.ssgproject.content_rule_rsyslog_remote_tls_cacert
Result
fail
Multi-check ruleno
OVAL Definition IDoval:ssg-rsyslog_remote_tls_cacert:def:1
Time2020-09-29T11:21:15
Severitymedium
Identifiers and References

Identifiers:  CCE-82458-1

References:  FMT_SMF_EXT.1, SRG-OS-000480-GPOS-00227

Description

Configure CA certificate for rsyslog logging to remote server using Transport Layer Security (TLS) using correct path for the DefaultNetstreamDriverCAFile global option in /etc/rsyslog.conf, for example with the following command:

echo 'global(DefaultNetstreamDriverCAFile="/etc/pki/tls/cert.pem")' >> /etc/rsyslog.conf
Replace the /etc/pki/tls/cert.pem in the above command with the path to the file with CA certificate generated for the purpose of remote logging.

Rationale

The CA certificate needs to be set or rsyslog.service fails to start with

error: ca certificate is not set, cannot continue

Evaluation messages
info 
No suitable fix found.
OVAL test results details

tests the DefaultNetstreamDriverCAFile configuration  oval:ssg-test_rsyslog_remote_tls_cacert:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rsyslog_remote_tls_cacert:obj:1 of type textfilecontent54_object
FilepathPatternInstance
^/etc/rsyslog\.(conf|d/.+\.conf)$^\s*global\(DefaultNetstreamDriverCAFile="(.+?)"\)\s*\n0
Configure TLS for rsyslog remote loggingxccdf_org.ssgproject.content_rule_rsyslog_remote_tls mediumCCE-82457-3

Configure TLS for rsyslog remote logging

Rule IDxccdf_org.ssgproject.content_rule_rsyslog_remote_tls
Result
fail
Multi-check ruleno
OVAL Definition IDoval:ssg-rsyslog_remote_tls:def:1
Time2020-09-29T11:21:15
Severitymedium
Identifiers and References

Identifiers:  CCE-82457-3

References:  AU-9(3), CM-6(a), FMT_SMF_EXT.1, SRG-OS-000480-GPOS-00227, SRG-OS-000120-GPOS-00061

Description

Configure rsyslog to use Transport Layer Security (TLS) support for logging to remote server for the Forwarding Output Module in /etc/rsyslog.conf using action. You can use the following command:

echo 'action(type="omfwd" protocol="tcp" Target="<remote system>" port="6514"
    StreamDriver="gtls" StreamDriverMode="1" StreamDriverAuthMode="x509/name")' >> /etc/rsyslog.conf
Replace the <remote system> in the above command with an IP address or a host name of the remote logging server.

Rationale

For protection of data being logged, the connection to the remote logging server needs to be authenticated and encrypted.

Evaluation messages
info 
No suitable fix found.
OVAL test results details

tests the omfwd action configuration  oval:ssg-test_rsyslog_remote_tls:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_rsyslog_remote_tls:obj:1 of type textfilecontent54_object
BehaviorsFilepathPatternInstance
no value^/etc/rsyslog\.(conf|d/.+\.conf)$^\s*action\(type="omfwd"(.+?)\)0
Ensure rsyslog is Installedxccdf_org.ssgproject.content_rule_package_rsyslog_installed mediumCCE-80847-7

Ensure rsyslog is Installed

Rule IDxccdf_org.ssgproject.content_rule_package_rsyslog_installed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_rsyslog_installed:def:1
Time2020-09-29T11:18:03
Severitymedium
Identifiers and References

Identifiers:  CCE-80847-7

References:  NT28(R5), NT28(R46), 4.2.3, 1, 14, 15, 16, 3, 5, 6, APO11.04, BAI03.05, DSS05.04, DSS05.07, MEA02.01, CCI-001311, CCI-001312, 164.312(a)(2)(ii), 4.3.3.3.9, 4.3.3.5.8, 4.3.4.4.7, 4.4.2.1, 4.4.2.2, 4.4.2.4, SR 2.10, SR 2.11, SR 2.12, SR 2.8, SR 2.9, A.12.4.1, A.12.4.2, A.12.4.3, A.12.4.4, A.12.7.1, CM-6(a), PR.PT-1, SRG-OS-000479-GPOS-00224, SRG-OS-000051-GPOS-00024

Description

Rsyslog is installed by default. The rsyslog package can be installed with the following command:

 $ sudo yum install rsyslog

Rationale

The rsyslog package provides the rsyslog daemon, which provides system logging services.

OVAL test results details

package rsyslog is installed  oval:ssg-test_package_rsyslog_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
rsyslogx86_64(none)3.el88.1911.00:8.1911.0-3.el80rsyslog-0:8.1911.0-3.el8.x86_64
Ensure rsyslog-gnutls is installedxccdf_org.ssgproject.content_rule_package_rsyslog-gnutls_installed mediumCCE-82859-0

Ensure rsyslog-gnutls is installed

Rule IDxccdf_org.ssgproject.content_rule_package_rsyslog-gnutls_installed
Result
error
Multi-check ruleno
OVAL Definition IDoval:ssg-package_rsyslog-gnutls_installed:def:1
Time2020-09-29T11:21:15
Severitymedium
Identifiers and References

Identifiers:  CCE-82859-0

References:  FMT_SMF_EXT.1, SRG-OS-000480-GPOS-00227, SRG-OS-000120-GPOS-00061

Description

TLS protocol support for rsyslog is installed. The rsyslog-gnutls package can be installed with the following command:

$ sudo yum install rsyslog-gnutls

Rationale

The rsyslog-gnutls package provides Transport Layer Security (TLS) support for the rsyslog daemon, which enables secure remote logging.

Evaluation messages
info 
Fix execution completed and returned: 1
info 
Error: There are no enabled repositories in "/etc/yum.repos.d", "/etc/yum/repos.d", "/etc/distro.repos.d".
info 
Failed to verify applied fix: Checking engine returns: fail


Complexity:low
Disruption:low
Strategy:enable

if ! rpm -q --quiet "rsyslog-gnutls" ; then
    yum install -y "rsyslog-gnutls"
fi


Complexity:low
Disruption:low
Strategy:enable
- name: Ensure rsyslog-gnutls is installed
  package:
    name: rsyslog-gnutls
    state: present
  when: ansible_virtualization_role != "guest" or ansible_virtualization_type != "docker"
  tags:
    - package_rsyslog-gnutls_installed
    - medium_severity
    - enable_strategy
    - low_complexity
    - low_disruption
    - no_reboot_needed
    - CCE-82859-0


Complexity:low
Disruption:low
Strategy:enable
include install_rsyslog-gnutls

class install_rsyslog-gnutls {
  package { 'rsyslog-gnutls':
    ensure => 'installed',
  }
}


Complexity:low
Disruption:low
Strategy:enable

package --add=rsyslog-gnutls
OVAL test results details

package rsyslog-gnutls is installed  oval:ssg-test_package_rsyslog-gnutls_installed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_test_package_rsyslog-gnutls_installed:obj:1 of type rpminfo_object
Name
rsyslog-gnutls
Uninstall nfs-utils Packagexccdf_org.ssgproject.content_rule_package_nfs-utils_removed lowCCE-82932-5

Uninstall nfs-utils Package

Rule IDxccdf_org.ssgproject.content_rule_package_nfs-utils_removed
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-package_nfs-utils_removed:def:1
Time2020-09-29T11:21:15
Severitylow
Identifiers and References

Identifiers:  CCE-82932-5

References:  SRG-OS-000095-GPOS-00049

Description

The nfs-utils package can be removed with the following command:

$ sudo yum erase nfs-utils

Rationale

nfs-utils provides a daemon for the kernel NFS server and related tools. This package also contains the showmount program. showmount queries the mount daemon on a remote host for information about the Network File System (NFS) server on the remote host. For example, showmount can display the clients which are mounted on that host.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

package nfs-utils is removed  oval:ssg-test_package_nfs-utils_removed:tst:1  false

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
nfs-utilsx86_64131.el82.3.31:2.3.3-31.el8199e2f91fd431d51nfs-utils-1:2.3.3-31.el8.x86_64
Uninstall Sendmail Packagexccdf_org.ssgproject.content_rule_package_sendmail_removed mediumCCE-81039-0

Uninstall Sendmail Package

Rule IDxccdf_org.ssgproject.content_rule_package_sendmail_removed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_sendmail_removed:def:1
Time2020-09-29T11:18:03
Severitymedium
Identifiers and References

Identifiers:  CCE-81039-0

References:  NT28(R1), 11, 14, 3, 9, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS05.02, DSS05.05, DSS06.06, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 7.6, A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, A.9.1.2, CM-7(a), CM-7(b), CM-6(a), PR.IP-1, PR.PT-3, SRG-OS-000480-GPOS-00227

Description

Sendmail is not the default mail transfer agent and is not installed by default. The sendmail package can be removed with the following command:

$ sudo yum erase sendmail

Rationale

The sendmail software was not developed with security in mind and its design prevents it from being effectively contained by SELinux. Postfix should be used instead.

OVAL test results details

package sendmail is removed  oval:ssg-test_package_sendmail_removed:tst:1  true

No items have been found conforming to the following objects:
Object oval:ssg-obj_test_package_sendmail_removed:obj:1 of type rpminfo_object
Name
sendmail
Disable chrony daemon from acting as serverxccdf_org.ssgproject.content_rule_chronyd_client_only unknownCCE-82988-7

Disable chrony daemon from acting as server

Rule IDxccdf_org.ssgproject.content_rule_chronyd_client_only
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-chronyd_client_only:def:1
Time2020-09-29T11:21:15
Severityunknown
Identifiers and References

Identifiers:  CCE-82988-7

References:  FMT_SMF_EXT.1, SRG-OS-000096-GPOS-00050

Description

The port option in /etc/chrony.conf can be set to 0 to make chrony daemon to never open any listening port for server operation and to operate strictly in a client-only mode.

Rationale

Minimizing the exposure of the server functionality of the chrony daemon diminishes the attack surface.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

package chrony is installed  oval:ssg-test_service_chronyd_package_chrony_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
chronyx86_64(none)1.el83.50:3.5-1.el8199e2f91fd431d51chrony-0:3.5-1.el8.x86_64

Test that the chronyd service is running  oval:ssg-test_service_running_chronyd:tst:1  true

Following items have been found on the system:
UnitPropertyValue
chronyd.serviceActiveStateactive

systemd test  oval:ssg-test_multi_user_wants_chronyd:tst:1  true

Following items have been found on the system:
UnitDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependency
multi-user.targetbasic.targetvar.mount-.mountsysinit.targetdev-mqueue.mountsystemd-hwdb-update.servicecryptsetup.targetproc-sys-fs-binfmt_misc.automountsystemd-journal-flush.servicesystemd-random-seed.servicesystemd-update-utmp.servicesystemd-tmpfiles-setup.servicesystemd-udevd.servicedev-hugepages.mountlvm2-lvmpolld.socketselinux-autorelabel-mark.serviceloadmodules.servicelocal-fs.targethome.mount-.mountvar-log-audit.mountboot.mounttmp.mountvar.mountvar-log.mountsystemd-remount-fs.servicedracut-shutdown.servicesystemd-sysctl.servicesystemd-journal-catalog-update.servicesystemd-update-done.servicesystemd-journald.servicesys-kernel-debug.mountsystemd-machine-id-commit.serviceldconfig.servicerngd.servicesystemd-binfmt.servicenis-domainname.servicesys-kernel-config.mountsystemd-modules-load.servicesystemd-sysusers.servicesys-fs-fuse-connections.mountswap.targetdev-mapper-ovirt\x2dswap.swapsystemd-udev-trigger.serviceimport-state.servicesystemd-firstboot.servicekmod-static-nodes.servicesystemd-ask-password-console.pathsystemd-tmpfiles-setup-dev.servicelvm2-monitor.servicemicrocode.servicepaths.targettimers.targetfstrim.timerunbound-anchor.timersystemd-tmpfiles-clean.timerslices.target-.slicesystem.slicesockets.targetsystemd-udevd-kernel.socketdbus.socketsystemd-coredump.socketsystemd-initctl.socketsystemd-udevd-control.socketsystemd-journald-dev-log.socketpcscd.socketsssd-kcm.socketsystemd-journald.socketcockpit.socketdm-event.socketrpcbind.socketsssd.servicekdump.servicecrond.servicesystemd-ask-password-wall.pathsshd.servicesystemd-user-sessions.serviceauditd.servicenfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetirqbalance.serviceremote-fs.targetnfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetgetty.targetserial-getty@ttyS0.servicegetty@tty1.servicecloud-init.targetcloud-init-local.servicecloud-config.servicecloud-final.servicecloud-init.servicednf-makecache.timerfirewalld.servicerpcbind.servicesystemd-update-utmp-runlevel.servicechronyd.servicersyslog.servicetuned.servicesystemd-logind.serviceNetworkManager.servicedbus.service

systemd test  oval:ssg-test_multi_user_wants_chronyd_socket:tst:1  false

Following items have been found on the system:
UnitDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependency
multi-user.targetbasic.targetvar.mount-.mountsysinit.targetdev-mqueue.mountsystemd-hwdb-update.servicecryptsetup.targetproc-sys-fs-binfmt_misc.automountsystemd-journal-flush.servicesystemd-random-seed.servicesystemd-update-utmp.servicesystemd-tmpfiles-setup.servicesystemd-udevd.servicedev-hugepages.mountlvm2-lvmpolld.socketselinux-autorelabel-mark.serviceloadmodules.servicelocal-fs.targethome.mount-.mountvar-log-audit.mountboot.mounttmp.mountvar.mountvar-log.mountsystemd-remount-fs.servicedracut-shutdown.servicesystemd-sysctl.servicesystemd-journal-catalog-update.servicesystemd-update-done.servicesystemd-journald.servicesys-kernel-debug.mountsystemd-machine-id-commit.serviceldconfig.servicerngd.servicesystemd-binfmt.servicenis-domainname.servicesys-kernel-config.mountsystemd-modules-load.servicesystemd-sysusers.servicesys-fs-fuse-connections.mountswap.targetdev-mapper-ovirt\x2dswap.swapsystemd-udev-trigger.serviceimport-state.servicesystemd-firstboot.servicekmod-static-nodes.servicesystemd-ask-password-console.pathsystemd-tmpfiles-setup-dev.servicelvm2-monitor.servicemicrocode.servicepaths.targettimers.targetfstrim.timerunbound-anchor.timersystemd-tmpfiles-clean.timerslices.target-.slicesystem.slicesockets.targetsystemd-udevd-kernel.socketdbus.socketsystemd-coredump.socketsystemd-initctl.socketsystemd-udevd-control.socketsystemd-journald-dev-log.socketpcscd.socketsssd-kcm.socketsystemd-journald.socketcockpit.socketdm-event.socketrpcbind.socketsssd.servicekdump.servicecrond.servicesystemd-ask-password-wall.pathsshd.servicesystemd-user-sessions.serviceauditd.servicenfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetirqbalance.serviceremote-fs.targetnfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetgetty.targetserial-getty@ttyS0.servicegetty@tty1.servicecloud-init.targetcloud-init-local.servicecloud-config.servicecloud-final.servicecloud-init.servicednf-makecache.timerfirewalld.servicerpcbind.servicesystemd-update-utmp-runlevel.servicechronyd.servicersyslog.servicetuned.servicesystemd-logind.serviceNetworkManager.servicedbus.service

check if port is 0 in /etc/chrony.conf  oval:ssg-test_chronyd_client_only:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_chronyd_port_value:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/chrony.conf^\s*port[\s]+(\S+)1
Disable network management of chrony daemonxccdf_org.ssgproject.content_rule_chronyd_no_chronyc_network unknownCCE-82840-0

Disable network management of chrony daemon

Rule IDxccdf_org.ssgproject.content_rule_chronyd_no_chronyc_network
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-chronyd_no_chronyc_network:def:1
Time2020-09-29T11:21:15
Severityunknown
Identifiers and References

Identifiers:  CCE-82840-0

References:  FMT_SMF_EXT.1, SRG-OS-000096-GPOS-00050

Description

The cmdport option in /etc/chrony.conf can be set to 0 to stop chrony daemon from listening on the UDP port 323 for management connections made by chronyc.

Rationale

Not exposing the management interface of the chrony daemon on the network diminishes the attack space.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

package chrony is installed  oval:ssg-test_service_chronyd_package_chrony_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
chronyx86_64(none)1.el83.50:3.5-1.el8199e2f91fd431d51chrony-0:3.5-1.el8.x86_64

Test that the chronyd service is running  oval:ssg-test_service_running_chronyd:tst:1  true

Following items have been found on the system:
UnitPropertyValue
chronyd.serviceActiveStateactive

systemd test  oval:ssg-test_multi_user_wants_chronyd:tst:1  true

Following items have been found on the system:
UnitDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependency
multi-user.targetbasic.targetvar.mount-.mountsysinit.targetdev-mqueue.mountsystemd-hwdb-update.servicecryptsetup.targetproc-sys-fs-binfmt_misc.automountsystemd-journal-flush.servicesystemd-random-seed.servicesystemd-update-utmp.servicesystemd-tmpfiles-setup.servicesystemd-udevd.servicedev-hugepages.mountlvm2-lvmpolld.socketselinux-autorelabel-mark.serviceloadmodules.servicelocal-fs.targethome.mount-.mountvar-log-audit.mountboot.mounttmp.mountvar.mountvar-log.mountsystemd-remount-fs.servicedracut-shutdown.servicesystemd-sysctl.servicesystemd-journal-catalog-update.servicesystemd-update-done.servicesystemd-journald.servicesys-kernel-debug.mountsystemd-machine-id-commit.serviceldconfig.servicerngd.servicesystemd-binfmt.servicenis-domainname.servicesys-kernel-config.mountsystemd-modules-load.servicesystemd-sysusers.servicesys-fs-fuse-connections.mountswap.targetdev-mapper-ovirt\x2dswap.swapsystemd-udev-trigger.serviceimport-state.servicesystemd-firstboot.servicekmod-static-nodes.servicesystemd-ask-password-console.pathsystemd-tmpfiles-setup-dev.servicelvm2-monitor.servicemicrocode.servicepaths.targettimers.targetfstrim.timerunbound-anchor.timersystemd-tmpfiles-clean.timerslices.target-.slicesystem.slicesockets.targetsystemd-udevd-kernel.socketdbus.socketsystemd-coredump.socketsystemd-initctl.socketsystemd-udevd-control.socketsystemd-journald-dev-log.socketpcscd.socketsssd-kcm.socketsystemd-journald.socketcockpit.socketdm-event.socketrpcbind.socketsssd.servicekdump.servicecrond.servicesystemd-ask-password-wall.pathsshd.servicesystemd-user-sessions.serviceauditd.servicenfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetirqbalance.serviceremote-fs.targetnfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetgetty.targetserial-getty@ttyS0.servicegetty@tty1.servicecloud-init.targetcloud-init-local.servicecloud-config.servicecloud-final.servicecloud-init.servicednf-makecache.timerfirewalld.servicerpcbind.servicesystemd-update-utmp-runlevel.servicechronyd.servicersyslog.servicetuned.servicesystemd-logind.serviceNetworkManager.servicedbus.service

systemd test  oval:ssg-test_multi_user_wants_chronyd_socket:tst:1  false

Following items have been found on the system:
UnitDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependency
multi-user.targetbasic.targetvar.mount-.mountsysinit.targetdev-mqueue.mountsystemd-hwdb-update.servicecryptsetup.targetproc-sys-fs-binfmt_misc.automountsystemd-journal-flush.servicesystemd-random-seed.servicesystemd-update-utmp.servicesystemd-tmpfiles-setup.servicesystemd-udevd.servicedev-hugepages.mountlvm2-lvmpolld.socketselinux-autorelabel-mark.serviceloadmodules.servicelocal-fs.targethome.mount-.mountvar-log-audit.mountboot.mounttmp.mountvar.mountvar-log.mountsystemd-remount-fs.servicedracut-shutdown.servicesystemd-sysctl.servicesystemd-journal-catalog-update.servicesystemd-update-done.servicesystemd-journald.servicesys-kernel-debug.mountsystemd-machine-id-commit.serviceldconfig.servicerngd.servicesystemd-binfmt.servicenis-domainname.servicesys-kernel-config.mountsystemd-modules-load.servicesystemd-sysusers.servicesys-fs-fuse-connections.mountswap.targetdev-mapper-ovirt\x2dswap.swapsystemd-udev-trigger.serviceimport-state.servicesystemd-firstboot.servicekmod-static-nodes.servicesystemd-ask-password-console.pathsystemd-tmpfiles-setup-dev.servicelvm2-monitor.servicemicrocode.servicepaths.targettimers.targetfstrim.timerunbound-anchor.timersystemd-tmpfiles-clean.timerslices.target-.slicesystem.slicesockets.targetsystemd-udevd-kernel.socketdbus.socketsystemd-coredump.socketsystemd-initctl.socketsystemd-udevd-control.socketsystemd-journald-dev-log.socketpcscd.socketsssd-kcm.socketsystemd-journald.socketcockpit.socketdm-event.socketrpcbind.socketsssd.servicekdump.servicecrond.servicesystemd-ask-password-wall.pathsshd.servicesystemd-user-sessions.serviceauditd.servicenfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetirqbalance.serviceremote-fs.targetnfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetgetty.targetserial-getty@ttyS0.servicegetty@tty1.servicecloud-init.targetcloud-init-local.servicecloud-config.servicecloud-final.servicecloud-init.servicednf-makecache.timerfirewalld.servicerpcbind.servicesystemd-update-utmp-runlevel.servicechronyd.servicersyslog.servicetuned.servicesystemd-logind.serviceNetworkManager.servicedbus.service

check if cmdport is 0 in /etc/chrony.conf  oval:ssg-test_chronyd_no_chronyc_network:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_chronyd_cmdport_value:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/chrony.conf^\s*cmdport[\s]+(\S+)1
Install fapolicyd Packagexccdf_org.ssgproject.content_rule_package_fapolicyd_installed mediumCCE-82191-8

Install fapolicyd Package

Rule IDxccdf_org.ssgproject.content_rule_package_fapolicyd_installed
Result
error
Multi-check ruleno
OVAL Definition IDoval:ssg-package_fapolicyd_installed:def:1
Time2020-09-29T11:21:16
Severitymedium
Identifiers and References

Identifiers:  CCE-82191-8

References:  CM-6(a), SI-4(22), SRG-OS-000370-GPOS-00155

Description

The fapolicyd package can be installed with the following command:

$ sudo yum install fapolicyd

Rationale

fapolicyd (File Access Policy Daemon) implements application whitelisting to decide file access rights.

Evaluation messages
info 
Fix execution completed and returned: 1
info 
Error: There are no enabled repositories in "/etc/yum.repos.d", "/etc/yum/repos.d", "/etc/distro.repos.d".
info 
Failed to verify applied fix: Checking engine returns: fail


Complexity:low
Disruption:low
Strategy:enable

if ! rpm -q --quiet "fapolicyd" ; then
    yum install -y "fapolicyd"
fi


Complexity:low
Disruption:low
Strategy:enable
- name: Ensure fapolicyd is installed
  package:
    name: fapolicyd
    state: present
  when: ansible_virtualization_role != "guest" or ansible_virtualization_type != "docker"
  tags:
    - package_fapolicyd_installed
    - medium_severity
    - enable_strategy
    - low_complexity
    - low_disruption
    - no_reboot_needed
    - CCE-82191-8
    - NIST-800-53-CM-6(a)
    - NIST-800-53-SI-4(22)


Complexity:low
Disruption:low
Strategy:enable
include install_fapolicyd

class install_fapolicyd {
  package { 'fapolicyd':
    ensure => 'installed',
  }
}


Complexity:low
Disruption:low
Strategy:enable

package --add=fapolicyd
OVAL test results details

package fapolicyd is installed  oval:ssg-test_package_fapolicyd_installed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_test_package_fapolicyd_installed:obj:1 of type rpminfo_object
Name
fapolicyd
Enable the File Access Policy Servicexccdf_org.ssgproject.content_rule_service_fapolicyd_enabled mediumCCE-82249-4

Enable the File Access Policy Service

Rule IDxccdf_org.ssgproject.content_rule_service_fapolicyd_enabled
Result
error
Multi-check ruleno
OVAL Definition IDoval:ssg-service_fapolicyd_enabled:def:1
Time2020-09-29T11:21:16
Severitymedium
Identifiers and References

Identifiers:  CCE-82249-4

References:  CM-6(a), SI-4(22), FMT_SMF_EXT.1, SRG-OS-000370-GPOS-00155

Description

The File Access Policy service should be enabled. The fapolicyd service can be enabled with the following command:

$ sudo systemctl enable fapolicyd.service

Rationale

The fapolicyd service (File Access Policy Daemon) implements application whitelisting to decide file access rights.

Evaluation messages
info 
Fix execution completed and returned: 1
info 
Failed to start fapolicyd.service: Unit fapolicyd.service not found.
Failed to enable unit: Unit file fapolicyd.service does not exist.
info 
Failed to verify applied fix: Checking engine returns: fail


Complexity:low
Disruption:low
Strategy:enable

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" start 'fapolicyd.service'
"$SYSTEMCTL_EXEC" enable 'fapolicyd.service'


Complexity:low
Disruption:low
Strategy:enable
- name: Enable service fapolicyd
  block:

    - name: Gather the package facts
      package_facts:
        manager: auto

    - name: Enable service fapolicyd
      service:
        name: fapolicyd
        enabled: 'yes'
        state: started
      when:
        - '"fapolicyd" in ansible_facts.packages'
  when: ansible_virtualization_role != "guest" or ansible_virtualization_type != "docker"
  tags:
    - service_fapolicyd_enabled
    - medium_severity
    - enable_strategy
    - low_complexity
    - low_disruption
    - no_reboot_needed
    - CCE-82249-4
    - NIST-800-53-CM-6(a)
    - NIST-800-53-SI-4(22)


Complexity:low
Disruption:low
Strategy:enable
include enable_fapolicyd

class enable_fapolicyd {
  service {'fapolicyd':
    enable => true,
    ensure => 'running',
  }
}
OVAL test results details

package fapolicyd is installed  oval:ssg-test_service_fapolicyd_package_fapolicyd_installed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_test_service_fapolicyd_package_fapolicyd_installed:obj:1 of type rpminfo_object
Name
fapolicyd

Test that the fapolicyd service is running  oval:ssg-test_service_running_fapolicyd:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_service_running_fapolicyd:obj:1 of type systemdunitproperty_object
UnitProperty
^fapolicyd\.(socket|service)$ActiveState

systemd test  oval:ssg-test_multi_user_wants_fapolicyd:tst:1  false

Following items have been found on the system:
UnitDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependency
multi-user.targetbasic.targetvar.mount-.mountsysinit.targetdev-mqueue.mountsystemd-hwdb-update.servicecryptsetup.targetproc-sys-fs-binfmt_misc.automountsystemd-journal-flush.servicesystemd-random-seed.servicesystemd-update-utmp.servicesystemd-tmpfiles-setup.servicesystemd-udevd.servicedev-hugepages.mountlvm2-lvmpolld.socketselinux-autorelabel-mark.serviceloadmodules.servicelocal-fs.targethome.mount-.mountvar-log-audit.mountboot.mounttmp.mountvar.mountvar-log.mountsystemd-remount-fs.servicedracut-shutdown.servicesystemd-sysctl.servicesystemd-journal-catalog-update.servicesystemd-update-done.servicesystemd-journald.servicesys-kernel-debug.mountsystemd-machine-id-commit.serviceldconfig.servicerngd.servicesystemd-binfmt.servicenis-domainname.servicesys-kernel-config.mountsystemd-modules-load.servicesystemd-sysusers.servicesys-fs-fuse-connections.mountswap.targetdev-mapper-ovirt\x2dswap.swapsystemd-udev-trigger.serviceimport-state.servicesystemd-firstboot.servicekmod-static-nodes.servicesystemd-ask-password-console.pathsystemd-tmpfiles-setup-dev.servicelvm2-monitor.servicemicrocode.servicepaths.targettimers.targetfstrim.timerunbound-anchor.timersystemd-tmpfiles-clean.timerslices.target-.slicesystem.slicesockets.targetsystemd-udevd-kernel.socketdbus.socketsystemd-coredump.socketsystemd-initctl.socketsystemd-udevd-control.socketsystemd-journald-dev-log.socketpcscd.socketsssd-kcm.socketsystemd-journald.socketcockpit.socketdm-event.socketrpcbind.socketsssd.servicekdump.servicecrond.servicesystemd-ask-password-wall.pathsshd.servicesystemd-user-sessions.serviceauditd.servicenfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetirqbalance.serviceremote-fs.targetnfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetgetty.targetserial-getty@ttyS0.servicegetty@tty1.servicecloud-init.targetcloud-init-local.servicecloud-config.servicecloud-final.servicecloud-init.servicednf-makecache.timerfirewalld.servicerpcbind.servicesystemd-update-utmp-runlevel.servicechronyd.servicersyslog.servicetuned.servicesystemd-logind.serviceNetworkManager.servicedbus.service

systemd test  oval:ssg-test_multi_user_wants_fapolicyd_socket:tst:1  false

Following items have been found on the system:
UnitDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependency
multi-user.targetbasic.targetvar.mount-.mountsysinit.targetdev-mqueue.mountsystemd-hwdb-update.servicecryptsetup.targetproc-sys-fs-binfmt_misc.automountsystemd-journal-flush.servicesystemd-random-seed.servicesystemd-update-utmp.servicesystemd-tmpfiles-setup.servicesystemd-udevd.servicedev-hugepages.mountlvm2-lvmpolld.socketselinux-autorelabel-mark.serviceloadmodules.servicelocal-fs.targethome.mount-.mountvar-log-audit.mountboot.mounttmp.mountvar.mountvar-log.mountsystemd-remount-fs.servicedracut-shutdown.servicesystemd-sysctl.servicesystemd-journal-catalog-update.servicesystemd-update-done.servicesystemd-journald.servicesys-kernel-debug.mountsystemd-machine-id-commit.serviceldconfig.servicerngd.servicesystemd-binfmt.servicenis-domainname.servicesys-kernel-config.mountsystemd-modules-load.servicesystemd-sysusers.servicesys-fs-fuse-connections.mountswap.targetdev-mapper-ovirt\x2dswap.swapsystemd-udev-trigger.serviceimport-state.servicesystemd-firstboot.servicekmod-static-nodes.servicesystemd-ask-password-console.pathsystemd-tmpfiles-setup-dev.servicelvm2-monitor.servicemicrocode.servicepaths.targettimers.targetfstrim.timerunbound-anchor.timersystemd-tmpfiles-clean.timerslices.target-.slicesystem.slicesockets.targetsystemd-udevd-kernel.socketdbus.socketsystemd-coredump.socketsystemd-initctl.socketsystemd-udevd-control.socketsystemd-journald-dev-log.socketpcscd.socketsssd-kcm.socketsystemd-journald.socketcockpit.socketdm-event.socketrpcbind.socketsssd.servicekdump.servicecrond.servicesystemd-ask-password-wall.pathsshd.servicesystemd-user-sessions.serviceauditd.servicenfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetirqbalance.serviceremote-fs.targetnfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetgetty.targetserial-getty@ttyS0.servicegetty@tty1.servicecloud-init.targetcloud-init-local.servicecloud-config.servicecloud-final.servicecloud-init.servicednf-makecache.timerfirewalld.servicerpcbind.servicesystemd-update-utmp-runlevel.servicechronyd.servicersyslog.servicetuned.servicesystemd-logind.serviceNetworkManager.servicedbus.service
Uninstall Automatic Bug Reporting Tool (abrt)xccdf_org.ssgproject.content_rule_package_abrt_removed mediumCCE-80948-3

Uninstall Automatic Bug Reporting Tool (abrt)

Rule IDxccdf_org.ssgproject.content_rule_package_abrt_removed
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-package_abrt_removed:def:1
Time2020-09-29T11:18:03
Severitymedium
Identifiers and References

Identifiers:  CCE-80948-3

References:  SRG-OS-000095-GPOS-00049

Description

The Automatic Bug Reporting Tool (abrt) collects and reports crash data when an application crash is detected. Using a variety of plugins, abrt can email crash reports to system administrators, log crash reports to files, or forward crash reports to a centralized issue tracking system such as RHTSupport. The abrt package can be removed with the following command:

$ sudo yum erase abrt

Rationale

Mishandling crash data could expose sensitive information about vulnerabilities in software executing on the system, as well as sensitive information from within a process's address space or registers.

OVAL test results details

package abrt is removed  oval:ssg-test_package_abrt_removed:tst:1  true

No items have been found conforming to the following objects:
Object oval:ssg-obj_test_package_abrt_removed:obj:1 of type rpminfo_object
Name
abrt
Disable Kerberos by removing host keytabxccdf_org.ssgproject.content_rule_kerberos_disable_no_keytab mediumCCE-82175-1

Disable Kerberos by removing host keytab

Rule IDxccdf_org.ssgproject.content_rule_kerberos_disable_no_keytab
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-kerberos_disable_no_keytab:def:1
Time2020-09-29T11:18:04
Severitymedium
Identifiers and References

Identifiers:  CCE-82175-1

References:  FCS_CKM.1, SRG-OS-000120-GPOS-00061

Description

Kerberos is not an approved key distribution method for Common Criteria. To prevent using Kerberos by system daemons, remove the Kerberos keytab files, especially /etc/krb5.keytab.

Rationale

The key derivation function (KDF) in Kerberos is not FIPS compatible.

OVAL test results details

Ensure a keytab file exists  oval:ssg-test_kerberos_disable_no_keytab:tst:1  true

No items have been found conforming to the following objects:
Object oval:ssg-obj_kerberos_disable_no_keytab:obj:1 of type file_object
Filepath
^/etc/.+\.keytab$
Enable SSH Warning Bannerxccdf_org.ssgproject.content_rule_sshd_enable_warning_banner mediumCCE-80905-3

Enable SSH Warning Banner

Rule IDxccdf_org.ssgproject.content_rule_sshd_enable_warning_banner
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sshd_enable_warning_banner:def:1
Time2020-09-29T11:21:16
Severitymedium
Identifiers and References

Identifiers:  CCE-80905-3

References:  5.2.16, 1, 12, 15, 16, 5.5.6, DSS05.04, DSS05.10, DSS06.10, 3.1.9, CCI-000048, CCI-000050, CCI-001384, CCI-001385, CCI-001386, CCI-001387, CCI-001388, 164.308(a)(4)(i), 164.308(b)(1), 164.308(b)(3), 164.310(b), 164.312(e)(1), 164.312(e)(2)(ii), 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, SR 1.1, SR 1.10, SR 1.2, SR 1.5, SR 1.7, SR 1.8, SR 1.9, A.18.1.4, A.9.2.1, A.9.2.4, A.9.3.1, A.9.4.2, A.9.4.3, AC-8(a), AC-8(c), AC-17(a), CM-6(a), PR.AC-7, FMT_MOF_EXT.1, SRG-OS-000023-GPOS-00006, SRG-OS-000024-GPOS-00007, SRG-OS-000228-GPOS-00088, SRG-OS-000023-VMM-000060, SRG-OS-000024-VMM-000070

Description

To enable the warning banner and ensure it is consistent across the system, add or correct the following line in /etc/ssh/sshd_config:

Banner /etc/issue
Another section contains information on how to create an appropriate system-wide warning banner.

Rationale

The warning message reinforces policy awareness during the logon process and facilitates possible legal action against attackers. Alternatively, systems whose ownership should not be obvious should ensure usage of a banner that does not provide easy attribution.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

Verify if Profile set Value sshd_required as not required  oval:ssg-test_sshd_not_required:tst:1  false

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

Verify if Value of sshd_required is the default  oval:ssg-test_sshd_requirement_unset:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

package openssh-server is removed  oval:ssg-test_package_openssh-server_removed:tst:1  false

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
openssh-serverx86_64(none)4.el8_18.0p10:8.0p1-4.el8_1199e2f91fd431d51openssh-server-0:8.0p1-4.el8_1.x86_64

Verify if Profile set Value sshd_required as required  oval:ssg-test_sshd_required:tst:1  false

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

Verify if Value of sshd_required is the default  oval:ssg-test_sshd_requirement_unset:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

package openssh-server is installed  oval:ssg-test_package_openssh-server_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
openssh-serverx86_64(none)4.el8_18.0p10:8.0p1-4.el8_1199e2f91fd431d51openssh-server-0:8.0p1-4.el8_1.x86_64

tests the value of Banner setting in the /etc/ssh/sshd_config file  oval:ssg-test_sshd_enable_warning_banner:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_sshd_enable_warning_banner:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/ssh/sshd_config^[ \t]*(?i)Banner(?-i)[ \t]+(.+?)[ \t]*(?:$|#)1
Set SSH Idle Timeout Intervalxccdf_org.ssgproject.content_rule_sshd_set_idle_timeout mediumCCE-80906-1

Set SSH Idle Timeout Interval

Rule IDxccdf_org.ssgproject.content_rule_sshd_set_idle_timeout
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sshd_set_idle_timeout:def:1
Time2020-09-29T11:21:16
Severitymedium
Identifiers and References

Identifiers:  CCE-80906-1

References:  NT28(R29), 5.2.12, 1, 12, 13, 14, 15, 16, 18, 3, 5, 7, 8, 5.5.6, APO13.01, BAI03.01, BAI03.02, BAI03.03, DSS01.03, DSS03.05, DSS05.04, DSS05.05, DSS05.07, DSS05.10, DSS06.03, DSS06.10, 3.1.11, CCI-000879, CCI-001133, CCI-002361, 4.3.3.2.2, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 6.2, A.12.4.1, A.12.4.3, A.14.1.1, A.14.2.1, A.14.2.5, A.18.1.4, A.6.1.2, A.6.1.5, A.7.1.1, A.9.1.2, A.9.2.1, A.9.2.2, A.9.2.3, A.9.2.4, A.9.2.6, A.9.3.1, A.9.4.1, A.9.4.2, A.9.4.3, A.9.4.4, A.9.4.5, CM-6(a), AC-17(a), AC-2(5), AC-12, AC-17(a), SC-10, CM-6(a), DE.CM-1, DE.CM-3, PR.AC-1, PR.AC-4, PR.AC-6, PR.AC-7, PR.IP-2, Req-8.1.8, SRG-OS-000163-GPOS-00072, SRG-OS-000279-GPOS-00109, SRG-OS-000126-GPOS-00066, SRG-OS-000395-GPOS-00175, SRG-OS-000480-VMM-002000

Description

SSH allows administrators to set an idle timeout interval. After this interval has passed, the idle user will be automatically logged out.

To set an idle timeout interval, edit the following line in /etc/ssh/sshd_config as follows:

ClientAliveInterval 840


The timeout interval is given in seconds. For example, have a timeout of 10 minutes, set interval to 600.

If a shorter timeout has already been set for the login shell, that value will preempt any SSH setting made in /etc/ssh/sshd_config. Keep in mind that some processes may stop SSH from correctly detecting that the user is idle.

Rationale

Terminating an idle ssh session within a short time period reduces the window of opportunity for unauthorized personnel to take control of a management session enabled on the console or console port that has been let unattended.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

Verify if Profile set Value sshd_required as not required  oval:ssg-test_sshd_not_required:tst:1  false

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

Verify if Value of sshd_required is the default  oval:ssg-test_sshd_requirement_unset:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

package openssh-server is removed  oval:ssg-test_package_openssh-server_removed:tst:1  false

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
openssh-serverx86_64(none)4.el8_18.0p10:8.0p1-4.el8_1199e2f91fd431d51openssh-server-0:8.0p1-4.el8_1.x86_64

Verify if Profile set Value sshd_required as required  oval:ssg-test_sshd_required:tst:1  false

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

Verify if Value of sshd_required is the default  oval:ssg-test_sshd_requirement_unset:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

package openssh-server is installed  oval:ssg-test_package_openssh-server_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
openssh-serverx86_64(none)4.el8_18.0p10:8.0p1-4.el8_1199e2f91fd431d51openssh-server-0:8.0p1-4.el8_1.x86_64

timeout is configured  oval:ssg-test_sshd_idle_timeout:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_sshd_idle_timeout:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/ssh/sshd_config^[\s]*(?i)ClientAliveInterval[\s]+(\d+)[\s]*(?:#.*)?$1
Disable Kerberos Authenticationxccdf_org.ssgproject.content_rule_sshd_disable_kerb_auth mediumCCE-80898-0

Disable Kerberos Authentication

Rule IDxccdf_org.ssgproject.content_rule_sshd_disable_kerb_auth
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-sshd_disable_kerb_auth:def:1
Time2020-09-29T11:18:04
Severitymedium
Identifiers and References

Identifiers:  CCE-80898-0

References:  11, 3, 9, BAI10.01, BAI10.02, BAI10.03, BAI10.05, 3.1.12, CCI-000368, CCI-000318, CCI-001812, CCI-001813, CCI-001814, 164.308(a)(4)(i), 164.308(b)(1), 164.308(b)(3), 164.310(b), 164.312(e)(1), 164.312(e)(2)(ii), 4.3.4.3.2, 4.3.4.3.3, SR 7.6, A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, AC-17(a), CM-7(a), CM-7(b), CM-6(a), PR.IP-1, FIA_AFL.1, SRG-OS-000364-GPOS-00151, SRG-OS-000480-VMM-002000

Description

Unless needed, SSH should not permit extraneous or unnecessary authentication mechanisms like Kerberos. To disable Kerberos authentication, add or correct the following line in the /etc/ssh/sshd_config file:

KerberosAuthentication no

Rationale

Kerberos authentication for SSH is often implemented using GSSAPI. If Kerberos is enabled through SSH, the SSH daemon provides a means of access to the system's Kerberos implementation. Vulnerabilities in the system's Kerberos implementations may be subject to exploitation.

OVAL test results details

Verify if Profile set Value sshd_required as not required  oval:ssg-test_sshd_not_required:tst:1  false

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

Verify if Value of sshd_required is the default  oval:ssg-test_sshd_requirement_unset:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

package openssh-server is removed  oval:ssg-test_package_openssh-server_removed:tst:1  false

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
openssh-serverx86_64(none)4.el8_18.0p10:8.0p1-4.el8_1199e2f91fd431d51openssh-server-0:8.0p1-4.el8_1.x86_64

Verify if Profile set Value sshd_required as required  oval:ssg-test_sshd_required:tst:1  false

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

Verify if Value of sshd_required is the default  oval:ssg-test_sshd_requirement_unset:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

package openssh-server is installed  oval:ssg-test_package_openssh-server_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
openssh-serverx86_64(none)4.el8_18.0p10:8.0p1-4.el8_1199e2f91fd431d51openssh-server-0:8.0p1-4.el8_1.x86_64

tests the value of KerberosAuthentication setting in the /etc/ssh/sshd_config file  oval:ssg-test_sshd_disable_kerb_auth:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_sshd_disable_kerb_auth:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/ssh/sshd_config^[ \t]*(?i)KerberosAuthentication(?-i)[ \t]+(.+?)[ \t]*(?:$|#)1

tests the absence of KerberosAuthentication setting in the /etc/ssh/sshd_config file  oval:ssg-test_sshd_disable_kerb_auth_default_not_overriden:tst:1  true

No items have been found conforming to the following objects:
Object oval:ssg-obj_sshd_disable_kerb_auth_default_not_overriden:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/ssh/sshd_config^[ \t]*(?i)KerberosAuthentication(?-i)[ \t]+1
Disable GSSAPI Authenticationxccdf_org.ssgproject.content_rule_sshd_disable_gssapi_auth mediumCCE-80897-2

Disable GSSAPI Authentication

Rule IDxccdf_org.ssgproject.content_rule_sshd_disable_gssapi_auth
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sshd_disable_gssapi_auth:def:1
Time2020-09-29T11:21:16
Severitymedium
Identifiers and References

Identifiers:  CCE-80897-2

References:  11, 3, 9, BAI10.01, BAI10.02, BAI10.03, BAI10.05, 3.1.12, CCI-000368, CCI-000318, CCI-001812, CCI-001813, CCI-001814, 164.308(a)(4)(i), 164.308(b)(1), 164.308(b)(3), 164.310(b), 164.312(e)(1), 164.312(e)(2)(ii), 4.3.4.3.2, 4.3.4.3.3, SR 7.6, A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, CM-7(a), CM-7(b), CM-6(a), AC-17(a), PR.IP-1, FIA_AFL.1, SRG-OS-000364-GPOS-00151, SRG-OS-000480-VMM-002000

Description

Unless needed, SSH should not permit extraneous or unnecessary authentication mechanisms like GSSAPI. To disable GSSAPI authentication, add or correct the following line in the /etc/ssh/sshd_config file:

GSSAPIAuthentication no

Rationale

GSSAPI authentication is used to provide additional authentication mechanisms to applications. Allowing GSSAPI authentication through SSH exposes the system's GSSAPI to remote hosts, increasing the attack surface of the system.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

Verify if Profile set Value sshd_required as not required  oval:ssg-test_sshd_not_required:tst:1  false

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

Verify if Value of sshd_required is the default  oval:ssg-test_sshd_requirement_unset:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

package openssh-server is removed  oval:ssg-test_package_openssh-server_removed:tst:1  false

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
openssh-serverx86_64(none)4.el8_18.0p10:8.0p1-4.el8_1199e2f91fd431d51openssh-server-0:8.0p1-4.el8_1.x86_64

Verify if Profile set Value sshd_required as required  oval:ssg-test_sshd_required:tst:1  false

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

Verify if Value of sshd_required is the default  oval:ssg-test_sshd_requirement_unset:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

package openssh-server is installed  oval:ssg-test_package_openssh-server_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
openssh-serverx86_64(none)4.el8_18.0p10:8.0p1-4.el8_1199e2f91fd431d51openssh-server-0:8.0p1-4.el8_1.x86_64

tests the value of GSSAPIAuthentication setting in the /etc/ssh/sshd_config file  oval:ssg-test_sshd_disable_gssapi_auth:tst:1  false

Following items have been found on the system:
PathContent
/etc/ssh/sshd_configGSSAPIAuthentication yes

tests the absence of GSSAPIAuthentication setting in the /etc/ssh/sshd_config file  oval:ssg-test_sshd_disable_gssapi_auth_default_not_overriden:tst:1  false

Following items have been found on the system:
PathContent
/etc/ssh/sshd_configGSSAPIAuthentication
Force frequent session key renegotiationxccdf_org.ssgproject.content_rule_sshd_rekey_limit mediumCCE-82177-7

Force frequent session key renegotiation

Rule IDxccdf_org.ssgproject.content_rule_sshd_rekey_limit
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sshd_rekey_limit:def:1
Time2020-09-29T11:21:16
Severitymedium
Identifiers and References

Identifiers:  CCE-82177-7

References:  FCS_SSHS_EXT.1, SRG-OS-000480-GPOS-00227

Description

The RekeyLimit parameter specifies how often the session key of the is renegotiated, both in terms of amount of data that may be transmitted and the time elapsed. To decrease the default limits, put line RekeyLimit 512M 1h to file /etc/ssh/sshd_config.

Rationale

By decreasing the limit based on the amount of data and enabling time-based limit, effects of potential attacks against encryption keys are limited.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

Verify if Profile set Value sshd_required as not required  oval:ssg-test_sshd_not_required:tst:1  false

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

Verify if Value of sshd_required is the default  oval:ssg-test_sshd_requirement_unset:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

package openssh-server is removed  oval:ssg-test_package_openssh-server_removed:tst:1  false

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
openssh-serverx86_64(none)4.el8_18.0p10:8.0p1-4.el8_1199e2f91fd431d51openssh-server-0:8.0p1-4.el8_1.x86_64

Verify if Profile set Value sshd_required as required  oval:ssg-test_sshd_required:tst:1  false

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

Verify if Value of sshd_required is the default  oval:ssg-test_sshd_requirement_unset:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

package openssh-server is installed  oval:ssg-test_package_openssh-server_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
openssh-serverx86_64(none)4.el8_18.0p10:8.0p1-4.el8_1199e2f91fd431d51openssh-server-0:8.0p1-4.el8_1.x86_64

tests the value of RekeyLimit setting in the /etc/ssh/sshd_config file  oval:ssg-test_sshd_rekey_limit:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_sshd_rekey_limit:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/ssh/sshd_config^[ \t]*(?i)RekeyLimit(?-i)[ \t]+(.+?)[ \t]*(?:$|#)1
Enable Use of Strict Mode Checkingxccdf_org.ssgproject.content_rule_sshd_enable_strictmodes mediumCCE-80904-6

Enable Use of Strict Mode Checking

Rule IDxccdf_org.ssgproject.content_rule_sshd_enable_strictmodes
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-sshd_enable_strictmodes:def:1
Time2020-09-29T11:18:04
Severitymedium
Identifiers and References

Identifiers:  CCE-80904-6

References:  12, 13, 14, 15, 16, 18, 3, 5, APO01.06, DSS05.04, DSS05.07, DSS06.02, 3.1.12, CCI-000366, 164.308(a)(4)(i), 164.308(b)(1), 164.308(b)(3), 164.310(b), 164.312(e)(1), 164.312(e)(2)(ii), 4.3.3.7.3, SR 2.1, SR 5.2, A.10.1.1, A.11.1.4, A.11.1.5, A.11.2.1, A.13.1.1, A.13.1.3, A.13.2.1, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3, A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, AC-6, AC-17(a), CM-6(a), PR.AC-4, PR.DS-5, SRG-OS-000480-GPOS-00227, SRG-OS-000480-VMM-002000

Description

SSHs StrictModes option checks file and ownership permissions in the user's home directory .ssh folder before accepting login. If world- writable permissions are found, logon is rejected. To enable StrictModes in SSH, add or correct the following line in the /etc/ssh/sshd_config file:

StrictModes yes

Rationale

If other users have access to modify user-specific SSH configuration files, they may be able to log into the system as another user.

OVAL test results details

Verify if Profile set Value sshd_required as not required  oval:ssg-test_sshd_not_required:tst:1  false

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

Verify if Value of sshd_required is the default  oval:ssg-test_sshd_requirement_unset:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

package openssh-server is removed  oval:ssg-test_package_openssh-server_removed:tst:1  false

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
openssh-serverx86_64(none)4.el8_18.0p10:8.0p1-4.el8_1199e2f91fd431d51openssh-server-0:8.0p1-4.el8_1.x86_64

Verify if Profile set Value sshd_required as required  oval:ssg-test_sshd_required:tst:1  false

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

Verify if Value of sshd_required is the default  oval:ssg-test_sshd_requirement_unset:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

package openssh-server is installed  oval:ssg-test_package_openssh-server_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
openssh-serverx86_64(none)4.el8_18.0p10:8.0p1-4.el8_1199e2f91fd431d51openssh-server-0:8.0p1-4.el8_1.x86_64

tests the value of StrictModes setting in the /etc/ssh/sshd_config file  oval:ssg-test_sshd_enable_strictmodes:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_sshd_enable_strictmodes:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/ssh/sshd_config^[ \t]*(?i)StrictModes(?-i)[ \t]+(.+?)[ \t]*(?:$|#)1

tests the absence of StrictModes setting in the /etc/ssh/sshd_config file  oval:ssg-test_sshd_enable_strictmodes_default_not_overriden:tst:1  true

No items have been found conforming to the following objects:
Object oval:ssg-obj_sshd_enable_strictmodes_default_not_overriden:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/ssh/sshd_config^[ \t]*(?i)StrictModes(?-i)[ \t]+1
Set SSH Client Alive Max Countxccdf_org.ssgproject.content_rule_sshd_set_keepalive mediumCCE-80907-9

Set SSH Client Alive Max Count

Rule IDxccdf_org.ssgproject.content_rule_sshd_set_keepalive
Result
fixed
Multi-check ruleno
OVAL Definition IDoval:ssg-sshd_set_keepalive:def:1
Time2020-09-29T11:21:16
Severitymedium
Identifiers and References

Identifiers:  CCE-80907-9

References:  5.2.12, 1, 12, 13, 14, 15, 16, 18, 3, 5, 7, 8, 5.5.6, APO13.01, BAI03.01, BAI03.02, BAI03.03, DSS01.03, DSS03.05, DSS05.04, DSS05.05, DSS05.07, DSS05.10, DSS06.03, DSS06.10, 3.1.11, CCI-000879, CCI-001133, CCI-002361, 164.308(a)(4)(i), 164.308(b)(1), 164.308(b)(3), 164.310(b), 164.312(e)(1), 164.312(e)(2)(ii), 4.3.3.2.2, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 6.2, A.12.4.1, A.12.4.3, A.14.1.1, A.14.2.1, A.14.2.5, A.18.1.4, A.6.1.2, A.6.1.5, A.7.1.1, A.9.1.2, A.9.2.1, A.9.2.2, A.9.2.3, A.9.2.4, A.9.2.6, A.9.3.1, A.9.4.1, A.9.4.2, A.9.4.3, A.9.4.4, A.9.4.5, AC-2(5), AC-12, AC-17(a), SC-10, CM-6(a), DE.CM-1, DE.CM-3, PR.AC-1, PR.AC-4, PR.AC-6, PR.AC-7, PR.IP-2, SRG-OS-000163-GPOS-00072, SRG-OS-000279-GPOS-00109, SRG-OS-000480-VMM-002000

Description

To ensure the SSH idle timeout occurs precisely when the ClientAliveInterval is set, edit /etc/ssh/sshd_config as follows:

ClientAliveCountMax 0

Rationale

This ensures a user login will be terminated as soon as the ClientAliveInterval is reached.

Evaluation messages
info 
Fix execution completed and returned: 0
OVAL test results details

Verify if Profile set Value sshd_required as not required  oval:ssg-test_sshd_not_required:tst:1  false

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

Verify if Value of sshd_required is the default  oval:ssg-test_sshd_requirement_unset:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

package openssh-server is removed  oval:ssg-test_package_openssh-server_removed:tst:1  false

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
openssh-serverx86_64(none)4.el8_18.0p10:8.0p1-4.el8_1199e2f91fd431d51openssh-server-0:8.0p1-4.el8_1.x86_64

Verify if Profile set Value sshd_required as required  oval:ssg-test_sshd_required:tst:1  false

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

Verify if Value of sshd_required is the default  oval:ssg-test_sshd_requirement_unset:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

package openssh-server is installed  oval:ssg-test_package_openssh-server_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
openssh-serverx86_64(none)4.el8_18.0p10:8.0p1-4.el8_1199e2f91fd431d51openssh-server-0:8.0p1-4.el8_1.x86_64

Tests the value of the ClientAliveCountMax setting in the /etc/ssh/sshd_config file  oval:ssg-test_sshd_clientalivecountmax:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_sshd_clientalivecountmax:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/ssh/sshd_config^[\s]*(?i)ClientAliveCountMax[\s]+([\d]+)[\s]*(?:#.*)?$1
Disable Host-Based Authenticationxccdf_org.ssgproject.content_rule_disable_host_auth mediumCCE-80786-7

Disable Host-Based Authentication

Rule IDxccdf_org.ssgproject.content_rule_disable_host_auth
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-disable_host_auth:def:1
Time2020-09-29T11:18:04
Severitymedium
Identifiers and References

Identifiers:  CCE-80786-7

References:  5.2.7, 11, 12, 14, 15, 16, 18, 3, 5, 9, 5.5.6, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS05.02, DSS05.04, DSS05.05, DSS05.07, DSS06.03, DSS06.06, 3.1.12, CCI-000366, 164.308(a)(4)(i), 164.308(b)(1), 164.308(b)(3), 164.310(b), 164.312(e)(1), 164.312(e)(2)(ii), 4.3.3.2.2, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 7.6, A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, A.6.1.2, A.7.1.1, A.9.1.2, A.9.2.1, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, AC-3, AC-17(a), CM-7(a), CM-7(b), CM-6(a), PR.AC-4, PR.AC-6, PR.IP-1, PR.PT-3, FIA_AFL.1, SRG-OS-000480-GPOS-00229, SRG-OS-000480-VMM-002000

Description

SSH's cryptographic host-based authentication is more secure than .rhosts authentication. However, it is not recommended that hosts unilaterally trust one another, even within an organization.

To disable host-based authentication, add or correct the following line in /etc/ssh/sshd_config:

HostbasedAuthentication no

Rationale

SSH trust relationships mean a compromise on one host can allow an attacker to move trivially to other hosts.

OVAL test results details

Verify if Profile set Value sshd_required as not required  oval:ssg-test_sshd_not_required:tst:1  false

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

Verify if Value of sshd_required is the default  oval:ssg-test_sshd_requirement_unset:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

package openssh-server is removed  oval:ssg-test_package_openssh-server_removed:tst:1  false

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
openssh-serverx86_64(none)4.el8_18.0p10:8.0p1-4.el8_1199e2f91fd431d51openssh-server-0:8.0p1-4.el8_1.x86_64

Verify if Profile set Value sshd_required as required  oval:ssg-test_sshd_required:tst:1  false

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

Verify if Value of sshd_required is the default  oval:ssg-test_sshd_requirement_unset:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

package openssh-server is installed  oval:ssg-test_package_openssh-server_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
openssh-serverx86_64(none)4.el8_18.0p10:8.0p1-4.el8_1199e2f91fd431d51openssh-server-0:8.0p1-4.el8_1.x86_64

tests the value of HostbasedAuthentication setting in the /etc/ssh/sshd_config file  oval:ssg-test_disable_host_auth:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_disable_host_auth:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/ssh/sshd_config^[ \t]*(?i)HostbasedAuthentication(?-i)[ \t]+(.+?)[ \t]*(?:$|#)1

tests the absence of HostbasedAuthentication setting in the /etc/ssh/sshd_config file  oval:ssg-test_disable_host_auth_default_not_overriden:tst:1  true

No items have been found conforming to the following objects:
Object oval:ssg-obj_disable_host_auth_default_not_overriden:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/ssh/sshd_config^[ \t]*(?i)HostbasedAuthentication(?-i)[ \t]+1
Disable SSH Access via Empty Passwordsxccdf_org.ssgproject.content_rule_sshd_disable_empty_passwords highCCE-80896-4

Disable SSH Access via Empty Passwords

Rule IDxccdf_org.ssgproject.content_rule_sshd_disable_empty_passwords
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-sshd_disable_empty_passwords:def:1
Time2020-09-29T11:18:04
Severityhigh
Identifiers and References

Identifiers:  CCE-80896-4

References:  NT007(R17), 5.2.9, 11, 12, 13, 14, 15, 16, 18, 3, 5, 9, 5.5.6, APO01.06, BAI10.01, BAI10.02, BAI10.03, BAI10.05, DSS05.02, DSS05.04, DSS05.05, DSS05.07, DSS06.02, DSS06.03, DSS06.06, 3.1.1, 3.1.5, CCI-000366, 164.308(a)(4)(i), 164.308(b)(1), 164.308(b)(3), 164.310(b), 164.312(e)(1), 164.312(e)(2)(ii), 4.3.3.2.2, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4, 4.3.4.3.2, 4.3.4.3.3, SR 1.1, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7, SR 5.2, SR 7.6, A.10.1.1, A.11.1.4, A.11.1.5, A.11.2.1, A.12.1.2, A.12.5.1, A.12.6.2, A.13.1.1, A.13.1.3, A.13.2.1, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3, A.14.2.2, A.14.2.3, A.14.2.4, A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.1, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, AC-17(a), CM-7(a), CM-7(b), CM-6(a), PR.AC-4, PR.AC-6, PR.DS-5, PR.IP-1, PR.PT-3, FIA_AFL.1, SRG-OS-000480-GPOS-00229, SRG-OS-000480-VMM-002000

Description

To explicitly disallow SSH login from accounts with empty passwords, add or correct the following line in /etc/ssh/sshd_config:

PermitEmptyPasswords no

Any accounts with empty passwords should be disabled immediately, and PAM configuration should prevent users from being able to assign themselves empty passwords.

Rationale

Configuring this setting for the SSH daemon provides additional assurance that remote login via SSH will require a password, even in the event of misconfiguration elsewhere.

OVAL test results details

Verify if Profile set Value sshd_required as not required  oval:ssg-test_sshd_not_required:tst:1  false

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

Verify if Value of sshd_required is the default  oval:ssg-test_sshd_requirement_unset:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

package openssh-server is removed  oval:ssg-test_package_openssh-server_removed:tst:1  false

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
openssh-serverx86_64(none)4.el8_18.0p10:8.0p1-4.el8_1199e2f91fd431d51openssh-server-0:8.0p1-4.el8_1.x86_64

Verify if Profile set Value sshd_required as required  oval:ssg-test_sshd_required:tst:1  false

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

Verify if Value of sshd_required is the default  oval:ssg-test_sshd_requirement_unset:tst:1  true

Following items have been found on the system:
Var refValue
oval:ssg-sshd_required:var:10

package openssh-server is installed  oval:ssg-test_package_openssh-server_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
openssh-serverx86_64(none)4.el8_18.0p10:8.0p1-4.el8_1199e2f91fd431d51openssh-server-0:8.0p1-4.el8_1.x86_64

tests the value of PermitEmptyPasswords setting in the /etc/ssh/sshd_config file  oval:ssg-test_sshd_disable_empty_passwords:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_sshd_disable_empty_passwords:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/ssh/sshd_config^[ \t]*(?i)PermitEmptyPasswords(?-i)[ \t]+(.+?)[ \t]*(?:$|#)1

tests the absence of PermitEmptyPasswords setting in the /etc/ssh/sshd_config file  oval:ssg-test_sshd_disable_empty_passwords_default_not_overriden:tst:1  true

No items have been found conforming to the following objects:
Object oval:ssg-obj_sshd_disable_empty_passwords_default_not_overriden:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/ssh/sshd_config^[ \t]*(?i)PermitEmptyPasswords(?-i)[ \t]+1
Install usbguard Packagexccdf_org.ssgproject.content_rule_package_usbguard_installed mediumCCE-82959-8

Install usbguard Package

Rule IDxccdf_org.ssgproject.content_rule_package_usbguard_installed
Result
error
Multi-check ruleno
OVAL Definition IDoval:ssg-package_usbguard_installed:def:1
Time2020-09-29T11:21:17
Severitymedium
Identifiers and References

Identifiers:  CCE-82959-8

References:  SRG-OS-000378-GPOS-00163

Description

The usbguard package can be installed with the following command:

$ sudo yum install usbguard

Rationale

usbguard is a software framework that helps to protect against rogue USB devices by implementing basic whitelisting/blacklisting capabilities based on USB device attributes.

Evaluation messages
info 
Fix execution completed and returned: 1
info 
Error: There are no enabled repositories in "/etc/yum.repos.d", "/etc/yum/repos.d", "/etc/distro.repos.d".
info 
Failed to verify applied fix: Checking engine returns: fail


Complexity:low
Disruption:low
Strategy:enable

if ! rpm -q --quiet "usbguard" ; then
    yum install -y "usbguard"
fi


Complexity:low
Disruption:low
Strategy:enable
- name: Ensure usbguard is installed
  package:
    name: usbguard
    state: present
  tags:
    - package_usbguard_installed
    - medium_severity
    - enable_strategy
    - low_complexity
    - low_disruption
    - no_reboot_needed
    - CCE-82959-8


Complexity:low
Disruption:low
Strategy:enable
include install_usbguard

class install_usbguard {
  package { 'usbguard':
    ensure => 'installed',
  }
}


Complexity:low
Disruption:low
Strategy:enable

package --add=usbguard
OVAL test results details

package usbguard is installed  oval:ssg-test_package_usbguard_installed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_test_package_usbguard_installed:obj:1 of type rpminfo_object
Name
usbguard
Enable the USBGuard Servicexccdf_org.ssgproject.content_rule_service_usbguard_enabled mediumCCE-82853-3

Enable the USBGuard Service

Rule IDxccdf_org.ssgproject.content_rule_service_usbguard_enabled
Result
error
Multi-check ruleno
OVAL Definition IDoval:ssg-service_usbguard_enabled:def:1
Time2020-09-29T11:21:17
Severitymedium
Identifiers and References

Identifiers:  CCE-82853-3

References:  FMT_SMF_EXT.1, SRG-OS-000378-GPOS-00163

Description

The USBGuard service should be enabled. The usbguard service can be enabled with the following command:

$ sudo systemctl enable usbguard.service

Rationale

The usbguard service must be running in order to enforce the USB device authorization policy for all USB devices.

Evaluation messages
info 
Fix execution completed and returned: 1
info 
Failed to start usbguard.service: Unit usbguard.service not found.
Failed to enable unit: Unit file usbguard.service does not exist.
info 
Failed to verify applied fix: Checking engine returns: fail


Complexity:low
Disruption:low
Strategy:enable

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" start 'usbguard.service'
"$SYSTEMCTL_EXEC" enable 'usbguard.service'


Complexity:low
Disruption:low
Strategy:enable
- name: Enable service usbguard
  block:

    - name: Gather the package facts
      package_facts:
        manager: auto

    - name: Enable service usbguard
      service:
        name: usbguard
        enabled: 'yes'
        state: started
      when:
        - '"usbguard" in ansible_facts.packages'
  when: ansible_virtualization_role != "guest" or ansible_virtualization_type != "docker"
  tags:
    - service_usbguard_enabled
    - medium_severity
    - enable_strategy
    - low_complexity
    - low_disruption
    - no_reboot_needed
    - CCE-82853-3


Complexity:low
Disruption:low
Strategy:enable
include enable_usbguard

class enable_usbguard {
  service {'usbguard':
    enable => true,
    ensure => 'running',
  }
}
OVAL test results details

package usbguard is installed  oval:ssg-test_service_usbguard_package_usbguard_installed:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_test_service_usbguard_package_usbguard_installed:obj:1 of type rpminfo_object
Name
usbguard

Test that the usbguard service is running  oval:ssg-test_service_running_usbguard:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_service_running_usbguard:obj:1 of type systemdunitproperty_object
UnitProperty
^usbguard\.(socket|service)$ActiveState

systemd test  oval:ssg-test_multi_user_wants_usbguard:tst:1  false

Following items have been found on the system:
UnitDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependency
multi-user.targetbasic.targetvar.mount-.mountsysinit.targetdev-mqueue.mountsystemd-hwdb-update.servicecryptsetup.targetproc-sys-fs-binfmt_misc.automountsystemd-journal-flush.servicesystemd-random-seed.servicesystemd-update-utmp.servicesystemd-tmpfiles-setup.servicesystemd-udevd.servicedev-hugepages.mountlvm2-lvmpolld.socketselinux-autorelabel-mark.serviceloadmodules.servicelocal-fs.targethome.mount-.mountvar-log-audit.mountboot.mounttmp.mountvar.mountvar-log.mountsystemd-remount-fs.servicedracut-shutdown.servicesystemd-sysctl.servicesystemd-journal-catalog-update.servicesystemd-update-done.servicesystemd-journald.servicesys-kernel-debug.mountsystemd-machine-id-commit.serviceldconfig.servicerngd.servicesystemd-binfmt.servicenis-domainname.servicesys-kernel-config.mountsystemd-modules-load.servicesystemd-sysusers.servicesys-fs-fuse-connections.mountswap.targetdev-mapper-ovirt\x2dswap.swapsystemd-udev-trigger.serviceimport-state.servicesystemd-firstboot.servicekmod-static-nodes.servicesystemd-ask-password-console.pathsystemd-tmpfiles-setup-dev.servicelvm2-monitor.servicemicrocode.servicepaths.targettimers.targetfstrim.timerunbound-anchor.timersystemd-tmpfiles-clean.timerslices.target-.slicesystem.slicesockets.targetsystemd-udevd-kernel.socketdbus.socketsystemd-coredump.socketsystemd-initctl.socketsystemd-udevd-control.socketsystemd-journald-dev-log.socketpcscd.socketsssd-kcm.socketsystemd-journald.socketcockpit.socketdm-event.socketrpcbind.socketsssd.servicekdump.servicecrond.servicesystemd-ask-password-wall.pathsshd.servicesystemd-user-sessions.serviceauditd.servicenfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetirqbalance.serviceremote-fs.targetnfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetgetty.targetserial-getty@ttyS0.servicegetty@tty1.servicecloud-init.targetcloud-init-local.servicecloud-config.servicecloud-final.servicecloud-init.servicednf-makecache.timerfirewalld.servicerpcbind.servicesystemd-update-utmp-runlevel.servicechronyd.servicersyslog.servicetuned.servicesystemd-logind.serviceNetworkManager.servicedbus.service

systemd test  oval:ssg-test_multi_user_wants_usbguard_socket:tst:1  false

Following items have been found on the system:
UnitDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependency
multi-user.targetbasic.targetvar.mount-.mountsysinit.targetdev-mqueue.mountsystemd-hwdb-update.servicecryptsetup.targetproc-sys-fs-binfmt_misc.automountsystemd-journal-flush.servicesystemd-random-seed.servicesystemd-update-utmp.servicesystemd-tmpfiles-setup.servicesystemd-udevd.servicedev-hugepages.mountlvm2-lvmpolld.socketselinux-autorelabel-mark.serviceloadmodules.servicelocal-fs.targethome.mount-.mountvar-log-audit.mountboot.mounttmp.mountvar.mountvar-log.mountsystemd-remount-fs.servicedracut-shutdown.servicesystemd-sysctl.servicesystemd-journal-catalog-update.servicesystemd-update-done.servicesystemd-journald.servicesys-kernel-debug.mountsystemd-machine-id-commit.serviceldconfig.servicerngd.servicesystemd-binfmt.servicenis-domainname.servicesys-kernel-config.mountsystemd-modules-load.servicesystemd-sysusers.servicesys-fs-fuse-connections.mountswap.targetdev-mapper-ovirt\x2dswap.swapsystemd-udev-trigger.serviceimport-state.servicesystemd-firstboot.servicekmod-static-nodes.servicesystemd-ask-password-console.pathsystemd-tmpfiles-setup-dev.servicelvm2-monitor.servicemicrocode.servicepaths.targettimers.targetfstrim.timerunbound-anchor.timersystemd-tmpfiles-clean.timerslices.target-.slicesystem.slicesockets.targetsystemd-udevd-kernel.socketdbus.socketsystemd-coredump.socketsystemd-initctl.socketsystemd-udevd-control.socketsystemd-journald-dev-log.socketpcscd.socketsssd-kcm.socketsystemd-journald.socketcockpit.socketdm-event.socketrpcbind.socketsssd.servicekdump.servicecrond.servicesystemd-ask-password-wall.pathsshd.servicesystemd-user-sessions.serviceauditd.servicenfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetirqbalance.serviceremote-fs.targetnfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetgetty.targetserial-getty@ttyS0.servicegetty@tty1.servicecloud-init.targetcloud-init-local.servicecloud-config.servicecloud-final.servicecloud-init.servicednf-makecache.timerfirewalld.servicerpcbind.servicesystemd-update-utmp-runlevel.servicechronyd.servicersyslog.servicetuned.servicesystemd-logind.serviceNetworkManager.servicedbus.service
Authorize Human Interface Devices and USB hubs in USBGuard daemonxccdf_org.ssgproject.content_rule_usbguard_allow_hid_and_hub mediumCCE-82368-2

Authorize Human Interface Devices and USB hubs in USBGuard daemon

Rule IDxccdf_org.ssgproject.content_rule_usbguard_allow_hid_and_hub
Result
error
Multi-check ruleno
OVAL Definition IDoval:ssg-usbguard_allow_hid_and_hub:def:1
Time2020-09-29T11:21:17
Severitymedium
Identifiers and References

Identifiers:  CCE-82368-2

References:  FMT_SMF_EXT.1, SRG-OS-000114-GPOS-00059

Description

To allow authorization of USB devices combining human interface device and hub capabilities by USBGuard daemon, add the line allow with-interface match_all { 03:*:* 09:00:* } to /etc/usbguard/rules.conf.

Rationale

Without allowing Human Interface Devices, it might not be possible to interact with the system. Without allowing hubs, it might not be possible to use any USB devices on the system.

Warnings
warning  This rule should be understood primarily as a convenience administration feature. This rule ensures that if the USBGuard default rules.conf file is present, it will alter it so that USB human interface devices and hubs are allowed. However, if the rules.conf file is altered by system administrator, the rule does not check if USB human interface devices and hubs are allowed. This assumes that an administrator modified the file with some purpose in mind.
Evaluation messages
info 
Fix execution completed and returned: 1
info 
/tmp/oscap.ojojh1/fix-XXXxbDNm: line 4: /etc/usbguard/rules.conf: No such file or directory
info 
Failed to verify applied fix: Checking engine returns: fail


#!/bin/bash


echo "allow with-interface match-all { 03:*:* 09:00:* }" >> /etc/usbguard/rules.conf
OVAL test results details

Check that /etc/usbguard/rules.conf contains at least one non whitespace character and exists  oval:ssg-test_usbguard_rules_nonempty:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_usbguard_rules_nonempty:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/usbguard/rules.conf^.*\S+.*$1
Log USBGuard daemon audit events using Linux Auditxccdf_org.ssgproject.content_rule_configure_usbguard_auditbackend mediumCCE-82168-6

Log USBGuard daemon audit events using Linux Audit

Rule IDxccdf_org.ssgproject.content_rule_configure_usbguard_auditbackend
Result
error
Multi-check ruleno
OVAL Definition IDoval:ssg-configure_usbguard_auditbackend:def:1
Time2020-09-29T11:21:17
Severitymedium
Identifiers and References

Identifiers:  CCE-82168-6

References:  FMT_SMF_EXT.1, SRG-OS-000062-GPOS-00031

Description

To configure USBGuard daemon to log via Linux Audit (as opposed directly to a file), AuditBackend option in /etc/usbguard/usbguard-daemon.conf needs to be set to LinuxAudit.

Rationale

Using the Linux Audit logging allows for centralized trace of events.

Evaluation messages
info 
Fix execution completed and returned: 1
info 
touch: cannot touch '/etc/usbguard/usbguard-daemon.conf': No such file or directory
cp: cannot stat '/etc/usbguard/usbguard-daemon.conf': No such file or directory
/tmp/oscap.eJ2dmI/fix-XXRGBPU3: line 8: /etc/usbguard/usbguard-daemon.conf: No such file or directory
rm: cannot remove '/etc/usbguard/usbguard-daemon.conf.bak': No such file or directory
info 
Failed to verify applied fix: Checking engine returns: fail


Complexity:low
Disruption:low
Strategy:restrict
if [ -e "/etc/usbguard/usbguard-daemon.conf" ] ; then
    LC_ALL=C sed -i "/^\s*AuditBackend=/d" "/etc/usbguard/usbguard-daemon.conf"
else
    touch "/etc/usbguard/usbguard-daemon.conf"
fi
cp "/etc/usbguard/usbguard-daemon.conf" "/etc/usbguard/usbguard-daemon.conf.bak"
# Insert at the end of the file
printf '%s\n' "AuditBackend=LinuxAudit" >> "/etc/usbguard/usbguard-daemon.conf"
# Clean up after ourselves.
rm "/etc/usbguard/usbguard-daemon.conf.bak"
OVAL test results details

tests the value of AuditBackend setting in the /etc/usbguard/usbguard-daemon.conf file  oval:ssg-test_configure_usbguard_auditbackend:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_configure_usbguard_auditbackend:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/usbguard/usbguard-daemon.conf^[ \t]*AuditBackend=(.+?)[ \t]*(?:$|#)1

The configuration file /etc/usbguard/usbguard-daemon.conf exists for configure_usbguard_auditbackend  oval:ssg-test_configure_usbguard_auditbackend_config_file_exists:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_configure_usbguard_auditbackend_config_file:obj:1 of type file_object
Filepath
^/etc/usbguard/usbguard-daemon.conf
Enable Smartcards in SSSDxccdf_org.ssgproject.content_rule_sssd_enable_smartcards mediumCCE-80909-5

Enable Smartcards in SSSD

Rule IDxccdf_org.ssgproject.content_rule_sssd_enable_smartcards
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-sssd_enable_smartcards:def:1
Time2020-09-29T11:18:04
Severitymedium
Identifiers and References

Identifiers:  CCE-80909-5

References:  CCI-001954, SRG-OS-000375-GPOS-00160, SRG-OS-000107-VMM-000530

Description

SSSD should be configured to authenticate access to the system using smart cards. To enable smart cards in SSSD, set pam_cert_auth to true under the [pam] section in /etc/sssd/sssd.conf. For example:

[pam]
pam_cert_auth = true

Rationale

Using an authentication device, such as a CAC or token that is separate from the information system, ensures that even if the information system is compromised, that compromise will not affect credentials stored on the authentication device.

Multifactor solutions that require devices separate from information systems gaining access include, for example, hardware tokens providing time-based or challenge-response authenticators and smart cards such as the U.S. Government Personal Identity Verification card and the DoD Common Access Card.

OVAL test results details

package sssd-common is removed  oval:ssg-test_service_sssd_package_sssd-common_removed:tst:1  false

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
sssd-commonx86_64(none)20.el82.2.30:2.2.3-20.el8199e2f91fd431d51sssd-common-0:2.2.3-20.el8.x86_64

Test that the sssd service is not running  oval:ssg-test_service_not_running_sssd:tst:1  false

Following items have been found on the system:
UnitPropertyValue
sssd.serviceActiveStateactive

Test that the property LoadState from the service sssd is masked  oval:ssg-test_service_loadstate_is_masked_sssd:tst:1  false

Following items have been found on the system:
UnitPropertyValue
sssd.serviceLoadStateloaded

Test that the property FragmentPath from the service sssd is set to /dev/null  oval:ssg-test_service_fragmentpath_is_dev_null_sssd:tst:1  false

Following items have been found on the system:
UnitPropertyValue
sssd.serviceFragmentPath/usr/lib/systemd/system/sssd.service

Testing if /etc/sssd/sssd.conf exists  oval:ssg-test_sssd_conf_exists:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_sssd_conf_exists:obj:1 of type file_object
Filepath
/etc/sssd/sssd.conf

tests the value of pam_cert_auth setting in the /etc/sssd/sssd.conf file  oval:ssg-test_sssd_enable_smartcards:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_sssd_enable_smartcards:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sssd/sssd.conf^[\s]*\[pam](?:[^\n\[]*\n+)+?[\s]*pam_cert_auth[\s]*=[\s]*true$1
Configure SSSD to Expire Offline Credentialsxccdf_org.ssgproject.content_rule_sssd_offline_cred_expiration mediumCCE-82460-7

Configure SSSD to Expire Offline Credentials

Rule IDxccdf_org.ssgproject.content_rule_sssd_offline_cred_expiration
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-sssd_offline_cred_expiration:def:1
Time2020-09-29T11:18:04
Severitymedium
Identifiers and References

Identifiers:  CCE-82460-7

References:  1, 12, 15, 16, 5, DSS05.04, DSS05.05, DSS05.07, DSS05.10, DSS06.03, DSS06.10, CCI-002007, 4.3.3.2.2, 4.3.3.5.1, 4.3.3.5.2, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.2, 4.3.3.7.4, SR 1.1, SR 1.10, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.7, SR 1.8, SR 1.9, SR 2.1, A.18.1.4, A.7.1.1, A.9.2.1, A.9.2.2, A.9.2.3, A.9.2.4, A.9.2.6, A.9.3.1, A.9.4.2, A.9.4.3, CM-6(a), IA-5(13), PR.AC-1, PR.AC-6, PR.AC-7, SRG-OS-000383-GPOS-00166, SRG-OS-000383-VMM-001570

Description

SSSD should be configured to expire offline credentials after 1 day. To configure SSSD to expire offline credentials, set offline_credentials_expiration to 1 under the [pam] section in /etc/sssd/sssd.conf. For example:

[pam]
offline_credentials_expiration = 1

Rationale

If cached authentication information is out-of-date, the validity of the authentication information may be questionable.

OVAL test results details

package sssd-common is removed  oval:ssg-test_service_sssd_package_sssd-common_removed:tst:1  false

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
sssd-commonx86_64(none)20.el82.2.30:2.2.3-20.el8199e2f91fd431d51sssd-common-0:2.2.3-20.el8.x86_64

Test that the sssd service is not running  oval:ssg-test_service_not_running_sssd:tst:1  false

Following items have been found on the system:
UnitPropertyValue
sssd.serviceActiveStateactive

Test that the property LoadState from the service sssd is masked  oval:ssg-test_service_loadstate_is_masked_sssd:tst:1  false

Following items have been found on the system:
UnitPropertyValue
sssd.serviceLoadStateloaded

Test that the property FragmentPath from the service sssd is set to /dev/null  oval:ssg-test_service_fragmentpath_is_dev_null_sssd:tst:1  false

Following items have been found on the system:
UnitPropertyValue
sssd.serviceFragmentPath/usr/lib/systemd/system/sssd.service

Testing if /etc/sssd/sssd.conf exists  oval:ssg-test_sssd_conf_exists:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-object_sssd_conf_exists:obj:1 of type file_object
Filepath
/etc/sssd/sssd.conf

tests the value of offline_credentials_expiration setting in the /etc/sssd/sssd.conf file  oval:ssg-test_sssd_offline_cred_expiration:tst:1  false

No items have been found conforming to the following objects:
Object oval:ssg-obj_sssd_offline_cred_expiration:obj:1 of type textfilecontent54_object
FilepathPatternInstance
/etc/sssd/sssd.conf^[\s]*\[pam](?:[^\n\[]*\n+)+?[\s]*offline_credentials_expiration[\s]*=[\s]*1$1
Enable the Hardware RNG Entropy Gatherer Servicexccdf_org.ssgproject.content_rule_service_rngd_enabled mediumCCE-82831-9

Enable the Hardware RNG Entropy Gatherer Service

Rule IDxccdf_org.ssgproject.content_rule_service_rngd_enabled
Result
pass
Multi-check ruleno
OVAL Definition IDoval:ssg-service_rngd_enabled:def:1
Time2020-09-29T11:18:04
Severitymedium
Identifiers and References

Identifiers:  CCE-82831-9

References:  FCS_RBG_EXT.1, SRG-OS-000480-GPOS-00227

Description

The Hardware RNG Entropy Gatherer service should be enabled. The rngd service can be enabled with the following command:

$ sudo systemctl enable rngd.service

Rationale

The rngd service feeds random data from hardware device to kernel random device.

OVAL test results details

package rng-tools is installed  oval:ssg-test_service_rngd_package_rng-tools_installed:tst:1  true

Following items have been found on the system:
NameArchEpochReleaseVersionEvrSignature keyidExtended name
rng-toolsx86_64(none)3.el86.80:6.8-3.el8199e2f91fd431d51rng-tools-0:6.8-3.el8.x86_64

Test that the rngd service is running  oval:ssg-test_service_running_rngd:tst:1  true

Following items have been found on the system:
UnitPropertyValue
rngd.serviceActiveStateactive

systemd test  oval:ssg-test_multi_user_wants_rngd:tst:1  true

Following items have been found on the system:
UnitDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependency
multi-user.targetbasic.targetvar.mount-.mountsysinit.targetdev-mqueue.mountsystemd-hwdb-update.servicecryptsetup.targetproc-sys-fs-binfmt_misc.automountsystemd-journal-flush.servicesystemd-random-seed.servicesystemd-update-utmp.servicesystemd-tmpfiles-setup.servicesystemd-udevd.servicedev-hugepages.mountlvm2-lvmpolld.socketselinux-autorelabel-mark.serviceloadmodules.servicelocal-fs.targethome.mount-.mountvar-log-audit.mountboot.mounttmp.mountvar.mountvar-log.mountsystemd-remount-fs.servicedracut-shutdown.servicesystemd-sysctl.servicesystemd-journal-catalog-update.servicesystemd-update-done.servicesystemd-journald.servicesys-kernel-debug.mountsystemd-machine-id-commit.serviceldconfig.servicerngd.servicesystemd-binfmt.servicenis-domainname.servicesys-kernel-config.mountsystemd-modules-load.servicesystemd-sysusers.servicesys-fs-fuse-connections.mountswap.targetdev-mapper-ovirt\x2dswap.swapsystemd-udev-trigger.serviceimport-state.servicesystemd-firstboot.servicekmod-static-nodes.servicesystemd-ask-password-console.pathsystemd-tmpfiles-setup-dev.servicelvm2-monitor.servicemicrocode.servicepaths.targettimers.targetfstrim.timerunbound-anchor.timersystemd-tmpfiles-clean.timerslices.target-.slicesystem.slicesockets.targetsystemd-udevd-kernel.socketdbus.socketsystemd-coredump.socketsystemd-initctl.socketsystemd-udevd-control.socketsystemd-journald-dev-log.socketpcscd.socketsssd-kcm.socketsystemd-journald.socketcockpit.socketdm-event.socketrpcbind.socketsssd.servicekdump.servicecrond.servicesystemd-ask-password-wall.pathsshd.servicesystemd-user-sessions.serviceauditd.servicenfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetirqbalance.serviceremote-fs.targetnfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetgetty.targetserial-getty@ttyS0.servicegetty@tty1.servicecloud-init.targetcloud-init-local.servicecloud-config.servicecloud-final.servicecloud-init.servicednf-makecache.timerfirewalld.servicerpcbind.servicesystemd-update-utmp-runlevel.servicechronyd.servicersyslog.servicetuned.servicesystemd-logind.serviceNetworkManager.servicedbus.service

systemd test  oval:ssg-test_multi_user_wants_rngd_socket:tst:1  false

Following items have been found on the system:
UnitDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependencyDependency
multi-user.targetbasic.targetvar.mount-.mountsysinit.targetdev-mqueue.mountsystemd-hwdb-update.servicecryptsetup.targetproc-sys-fs-binfmt_misc.automountsystemd-journal-flush.servicesystemd-random-seed.servicesystemd-update-utmp.servicesystemd-tmpfiles-setup.servicesystemd-udevd.servicedev-hugepages.mountlvm2-lvmpolld.socketselinux-autorelabel-mark.serviceloadmodules.servicelocal-fs.targethome.mount-.mountvar-log-audit.mountboot.mounttmp.mountvar.mountvar-log.mountsystemd-remount-fs.servicedracut-shutdown.servicesystemd-sysctl.servicesystemd-journal-catalog-update.servicesystemd-update-done.servicesystemd-journald.servicesys-kernel-debug.mountsystemd-machine-id-commit.serviceldconfig.servicerngd.servicesystemd-binfmt.servicenis-domainname.servicesys-kernel-config.mountsystemd-modules-load.servicesystemd-sysusers.servicesys-fs-fuse-connections.mountswap.targetdev-mapper-ovirt\x2dswap.swapsystemd-udev-trigger.serviceimport-state.servicesystemd-firstboot.servicekmod-static-nodes.servicesystemd-ask-password-console.pathsystemd-tmpfiles-setup-dev.servicelvm2-monitor.servicemicrocode.servicepaths.targettimers.targetfstrim.timerunbound-anchor.timersystemd-tmpfiles-clean.timerslices.target-.slicesystem.slicesockets.targetsystemd-udevd-kernel.socketdbus.socketsystemd-coredump.socketsystemd-initctl.socketsystemd-udevd-control.socketsystemd-journald-dev-log.socketpcscd.socketsssd-kcm.socketsystemd-journald.socketcockpit.socketdm-event.socketrpcbind.socketsssd.servicekdump.servicecrond.servicesystemd-ask-password-wall.pathsshd.servicesystemd-user-sessions.serviceauditd.servicenfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetirqbalance.serviceremote-fs.targetnfs-client.targetrpc-statd-notify.serviceauth-rpcgss-module.serviceremote-fs-pre.targetgetty.targetserial-getty@ttyS0.servicegetty@tty1.servicecloud-init.targetcloud-init-local.servicecloud-config.servicecloud-final.servicecloud-init.servicednf-makecache.timerfirewalld.servicerpcbind.servicesystemd-update-utmp-runlevel.servicechronyd.servicersyslog.servicetuned.servicesystemd-logind.serviceNetworkManager.servicedbus.service
Red Hat and Red Hat Enterprise Linux are either registered trademarks or trademarks of Red Hat, Inc. in the United States and other countries. All other names are registered trademarks or trademarks of their respective companies.