Solaris 11 SPARC Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
The delay between login prompts following a failed login attempt must be at least 4 seconds.
As an immediate return of an error message, coupled with the capability to try again, may facilitate automatic and rapid-fire brute-force password attacks by a malicious user.Rule Medium Severity -
SRG-OS-000028
Group -
The system must require users to re-authenticate to unlock a graphical desktop environment.
Allowing access to a graphical environment when the user is not attending the system can allow unauthorized users access to the system.Rule Medium Severity -
SRG-OS-000029
Group -
SRG-OS-000480
Group -
SRG-OS-000109
Group -
SRG-OS-000480
Group -
SRG-OS-000480
Group -
The default umask for FTP users must be 077.
Setting a very secure default value for umask ensures that users make a conscious choice about their file permissions.Rule Low Severity -
SRG-OS-000480
Group -
The value mesg n must be configured as the default setting for all users.
The "mesg n" command blocks attempts to use the "write" or "talk" commands to contact users at their terminals, but has the side effect of slightly strengthening permissions on the user's TTY device.Rule Low Severity -
SRG-OS-000003
Group -
User accounts must be locked after 35 days of inactivity.
Attackers that are able to exploit an inactive account can potentially obtain and maintain undetected access to an application. Owners of inactive accounts will not notice if unauthorized access to...Rule Medium Severity -
SRG-OS-000480
Group -
Login services for serial ports must be disabled.
Login services should not be enabled on any serial ports that are not strictly required to support the mission of the system. This action can be safely performed even when console access is provide...Rule Medium Severity -
SRG-OS-000480
Group -
Access to a domain console via telnet must be restricted to the local host.
Telnet is an insecure protocol.Rule Medium Severity -
SRG-OS-000480
Group -
Access to a logical domain console must be restricted to authorized users.
A logical domain is a discrete, logical grouping with its own operating system, resources, and identity within a single computer system. Access to the logical domain console provides system-level ...Rule Medium Severity -
SRG-OS-000480
Group
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.