An XCCDF Group - A logical subset of the XCCDF Benchmark
/usr/share/doc/aide-VERSION
aide
$ sudo dnf install aide
$ sudo /usr/sbin/aide --init
/var/lib/aide/aide.db.new.gz
/etc/aide.conf
/usr/sbin/aide
$ sudo cp /var/lib/aide/aide.db.new.gz /var/lib/aide/aide.db.gz
$ sudo /usr/sbin/aide --check
/etc/crontab
05 4 * * * root /usr/sbin/aide --check
05 4 * * 0 root /usr/sbin/aide --check
@daily
@weekly
| /bin/mail -s "$(hostname) - AIDE Integrity Check" root@localhost
05 4 * * * root /usr/sbin/aide --check | /bin/mail -s "$(hostname) - AIDE Integrity Check" root@localhost
acl
FIPSR
FIPSR = p+i+n+u+g+s+m+c+acl+selinux+xattrs+sha256
xattrs
/
/boot
swap
/home
/srv
/var
/var/log
/var/log/audit
/var/tmp
/tmp
systemd-tmpfiles
tmp.mount
Sudo
root
sudo
$ sudo dnf install sudo
/etc/sudoers.d
$ sudo chgrp root /etc/sudoers.d
$ sudo chown root /etc/sudoers.d
$ sudo chmod 0750 /etc/sudoers.d
/etc/sudoers
$ sudo chgrp root /etc/sudoers
$ sudo chown root /etc/sudoers
$ sudo chmod 0440 /etc/sudoers
/usr/bin/sudo
$ sudo chmod 4111 /usr/bin/sudo
NOEXEC
/etc/sudoers.d/
requiretty
use_pty
sudoers
ALL
dnf
dnf-automatic
$ sudo dnf install dnf-automatic
apply_updates
yes
[commands]
/etc/dnf/automatic.conf
upgrade_type
security
gpgcheck
/etc/dnf/dnf.conf
[main]
gpgcheck=1
localpkg_gpgcheck
1
/etc/yum.repos.d
gpgcheck=0
$ sudo uln_register
/media/cdrom
$ sudo rpm --import /media/cdrom/RPM-GPG-KEY-oracle
sudo rpm --import /etc/pki/rpm-gpg/RPM-GPG-KEY-oracle
$ sudo systemctl enable dnf-automatic.timer