Skip to content

Solaris 11 SPARC Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • Duplicate user names must not exist.

    <VulnDiscussion>If a user is assigned a duplicate user name, it will create and have access to files with the first UID for that username in ...
    Rule Medium Severity
  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group
  • The root account must be the only account with GID of 0.

    &lt;VulnDiscussion&gt;All accounts with a GID of 0 have root group privileges and must be limited to the group account only.&lt;/VulnDiscussion&gt;...
    Rule Medium Severity
  • SRG-OS-000206

    <GroupDescription></GroupDescription>
    Group
  • SRG-OS-000404

    <GroupDescription></GroupDescription>
    Group
  • The system must disable accounts after three consecutive unsuccessful login attempts.

    &lt;VulnDiscussion&gt;Allowing continued access to accounts on the system exposes them to brute-force password-guessing attacks.&lt;/VulnDiscussion...
    Rule Medium Severity
  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group
  • SRG-OS-000003

    <GroupDescription></GroupDescription>
    Group
  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group
  • The rhost-based authentication for SSH must be disabled.

    &lt;VulnDiscussion&gt;Setting this parameter forces users to enter a password when authenticating with SSH.&lt;/VulnDiscussion&gt;&lt;FalsePositive...
    Rule Medium Severity
  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group
  • Direct root account login must not be permitted for SSH access.

    &lt;VulnDiscussion&gt;The system should not allow users to log in as the root user directly, as audited actions would be non-attributable to a spec...
    Rule Medium Severity
  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group
  • Login must not be permitted with empty/null passwords for SSH.

    &lt;VulnDiscussion&gt;Permitting login without a password is inherently risky.&lt;/VulnDiscussion&gt;&lt;FalsePositives&gt;&lt;/FalsePositives&gt;&...
    Rule High Severity
  • SRG-OS-000163

    <GroupDescription></GroupDescription>
    Group
  • The system must ignore ICMP redirect messages.

    &lt;VulnDiscussion&gt;Ignoring ICMP redirect messages reduces the likelihood of denial of service attacks.&lt;/VulnDiscussion&gt;&lt;FalsePositives...
    Rule Low Severity
  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group
  • The operating system must reveal error messages only to authorized personnel.

    &lt;VulnDiscussion&gt;Proper file permissions and ownership ensures that only designated personnel in the organization can access error messages.&l...
    Rule Low Severity
  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group
  • The audit system must be configured to audit all administrative, privileged, and security actions.

    &lt;VulnDiscussion&gt;Without auditing, individual system accesses cannot be tracked, and malicious activity cannot be detected and traced back to ...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules