Guide to the Secure Configuration of Red Hat Enterprise Linux 7
Rules, Groups, and Values defined within the XCCDF Benchmark
-
Install tcp_wrappers Package
When network services are using the <code>xinetd</code> service, the <code>tcp_wrappers</code> package should be installed. The <code>tcp_wrappers<...Rule Medium Severity -
Uninstall xinetd Package
Thexinetd
package can be removed with the following command:$ sudo yum erase xinetd
Rule Low Severity -
Disable xinetd Service
Thexinetd
service can be disabled with the following command:$ sudo systemctl mask --now xinetd.service
Rule Medium Severity -
Ensure /etc/hosts.deny is configured
The file <code>/etc/hosts.deny</code> together with <code>/etc/hosts.allow</code> provides a simple access control mechanism for network services s...Rule Medium Severity -
Verify Group Ownership of /etc/hosts.allow
To properly set the group owner of/etc/hosts.allow
, run the command:$ sudo chgrp root /etc/hosts.allow
Rule Medium Severity -
Verify Group Ownership of /etc/hosts.deny
To properly set the group owner of/etc/hosts.deny
, run the command:$ sudo chgrp root /etc/hosts.deny
Rule Medium Severity -
Verify Ownership of /etc/hosts.allow
To properly set the owner of/etc/hosts.allow
, run the command:$ sudo chown root /etc/hosts.allow
Rule Medium Severity -
Verify Permissions on /etc/hosts.allow
To properly set the permissions of/etc/hosts.allow
, run the command:$ sudo chmod 0644 /etc/hosts.allow
Rule Medium Severity -
Verify Permissions on /etc/hosts.deny
To properly set the permissions of/etc/hosts.deny
, run the command:$ sudo chmod 0644 /etc/hosts.deny
Rule Medium Severity -
NIS
The Network Information Service (NIS), also known as 'Yellow Pages' (YP), and its successor NIS+ have been made obsolete by Kerberos, LDAP, and oth...Group
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.
Capacity
Modules