An XCCDF Group - A logical subset of the XCCDF Benchmark
/etc/issue
$ sudo chgrp root /etc/issue
/etc/issue.net
$ sudo chgrp root /etc/issue.net
/etc/motd
$ sudo chgrp root /etc/motd
$ sudo chown root /etc/issue
$ sudo chown root /etc/issue.net
$ sudo chown root /etc/motd
$ sudo chmod 0644 /etc/issue
$ sudo chmod 0644 /etc/issue.net
$ sudo chmod 0644 /etc/motd
/etc/pam.d
/etc/pam.d/login
/etc/pam.d/system-auth
/etc/security/opasswd
pam_faillock
/usr/share/doc/pam-VERSION/txts/README.pam_faillock
remember
pam_unix
pam_pwhistory
pam_faillock.so
/etc/security/faillock.conf
deny = <count>
authselect
authconfig
unlock_time=<interval-in-seconds>
interval-in-seconds
unlock_time
0
faillock
pam_pwquality
pam_pwquality(8)
password requisite pam_pwquality.so try_first_pass local_users_only retry=3 authtok_type=
/etc/security/pwquality.conf
difok = 4 minlen = 14 dcredit = -1 ucredit = -1 lcredit = -1 ocredit = -1 maxrepeat = 3
dcredit
dictcheck
1
enforce_for_root
root
lcredit
minclass
* Upper-case characters * Lower-case characters * Digits * Special characters (for example, punctuation)
minlen
minlen=
ocredit=
ocredit
pam_pwquality.so
retry=
ucredit=
ucredit
/etc/shadow
/etc/pam.d/password-auth
password
pam_unix.so
password sufficient pam_unix.so other arguments...
debug-shell
systemctl
tty9
CTRL-ALT-F9
$ sudo systemctl mask --now debug-shell.service
/usr/lib/systemd/system/emergency.service
/etc/passwd
NUM_DAYS
USER
$ sudo chage -I NUM_DAYS USER
-E
/etc/default/useradd
YYYY-MM-DD
$ sudo chage -E YYYY-MM-DD USER
$ sudo getent passwd | awk -F: '{ print $1}' | uniq -d
/etc/login.defs
passwd
su
login
login.defs(5)
PASS_MAX_DAYS
-M
PASS_MIN_DAYS
-m
PASS_WARN_AGE
-W
$ sudo chage -M 180 -m 7 -W 7 USER
.forward
.netrc
sudo
/etc/securetty
/dev/console
/dev/tty*
/dev/vc/*
wheel
/etc/pam.d/su
auth required pam_wheel.so use_uid
TMOUT
/etc/profile
/etc/profile.d/tmout.sh
typeset -xr TMOUT=
declare -xr TMOUT=
typeset
$ sudo mkdir /home/USER
umask
/etc/bashrc