An XCCDF Group - A logical subset of the XCCDF Benchmark
prelink
$ apt-get remove prelink
$ rpm -qVa
rpm
/usr/share/doc/aide-VERSION
aide
$ apt-get install aide
$ sudo aideinit
/var/lib/aide/aide.db.new
/etc/aide.conf
/usr/bin/aide
$ sudo cp /var/lib/aide/aide.db.new /var/lib/aide/aide.db
$ sudo /usr/bin/aide --check
/etc/crontab
05 4 * * * root /usr/bin/aide --config /etc/aide/aide.conf --check
05 4 * * 0 root /usr/bin/aide --config /etc/aide/aide.conf --check
@daily
@weekly
/proc/sys/crypto/fips_enabled
cat /proc/sys/crypto/fips_enabled
update-crypto-policies
/etc/ssh/ssh_config.d/
05-redhat.conf
02-ospp.conf
mfetp
$ apt-get install mfetp
/
/boot
swap
Encrypt
--encrypted
--passphrase=
part / --fstype=ext4 --size=100 --onpart=hda1 --encrypted --passphrase=PASSPHRASE
Anaconda
aes-xts-plain64
512
/dev/shm
/home
/srv
/tmp
/var
/var/log
/var/log/audit
/var/tmp
gdm3
graphical.target
$ sudo apt remove gdm3
/etc/dconf/profile/user
user-db:user system-db:local system-db:site system-db:distro
dconf(1)
disable-user-list
true
/etc/dconf/db/gdm.d/00-security-settings
[org/gnome/login-screen] disable-user-list=true
/etc/dconf/db/gdm.d/locks/00-security-settings-lock
/org/gnome/login-screen/disable-user-list
dconf update
Enable
false
[xdmcp]
/etc/gdm/custom.conf
[xdmcp] Enable=false
automount
/etc/dconf/db/local.d/00-security-settings
[org/gnome/desktop/media-handling] automount=false
/etc/dconf/db/local.d/locks/00-security-settings-lock
/org/gnome/desktop/media-handling/automount
automount-open
[org/gnome/desktop/media-handling] automount-open=false
/org/gnome/desktop/media-handling/automount-open
autorun-never
[org/gnome/desktop/media-handling] autorun-never=true
/org/gnome/desktop/media-handling/autorun-never
lock-delay
uint32
[org/gnome/desktop/screensaver] lock-delay=uint32
lock-enabled
[org/gnome/desktop/screensaver] lock-enabled=true
/org/gnome/desktop/screensaver/lock-enabled
GNOME
Ctrl-Alt-Del
logout
''
[org/gnome/settings-daemon/plugins/media-keys] logout=''
/org/gnome/settings-daemon/plugins/media-keys/logout
Sudo
root
sudo
$ apt-get install sudo
NOEXEC
/etc/sudoers
/etc/sudoers.d/
requiretty
use_pty
!authenticate
NOPASSWD
timestamp_timeout
vdsm
sudoers
ALL
gnutls-utils
$ apt-get install gnutls-utils
nss-tools
$ apt-get install nss-tools
apt_get
::Remove-Unused-Dependencies
::Remove-Unused-Kernel-Packages
/etc/apt/apt.conf