An XCCDF Group - A logical subset of the XCCDF Benchmark
$ rpm -qVa
rpm
$ rpm -Va --noconfig | grep '^..5'
$ rpm -qf FILENAME
$ sudo yum reinstall PACKAGENAME
$ sudo rpm -Uvh PACKAGENAME
$ sudo rpm -Va | awk '{ if (substr($0,2,1)=="M") print $NF }'
$ sudo rpm --setperms PACKAGENAME
/usr/share/doc/aide-VERSION
update-crypto-policies
/etc/named.conf
options
include "/etc/crypto-policies/back-ends/bind.config";
$ sudo update-crypto-policies --set
/etc/crypto-policies/back-ends
/etc/ipsec.conf
include /etc/crypto-policies/back-ends/libreswan.config
/etc/pki/tls/openssl.cnf
ini
[ crypto_policy ]
.include /etc/crypto-policies/back-ends/opensslcnf.config
CRYPTO_POLICY
/etc/sysconfig/sshd
/etc/ssh/ssh_config.d/
05-redhat.conf
02-ospp.conf
/
/boot
swap
/dev/shm
/home
/srv
/tmp
/var
/var/log
/var/log/audit
dconf(1)
Enable
false
[xdmcp]
/etc/gdm/custom.conf
[xdmcp] Enable=false
Sudo
root
sudo
NOEXEC
/etc/sudoers
/etc/sudoers.d/
requiretty
use_pty
!authenticate
NOPASSWD
vdsm
sudoers
ALL
gnutls-utils
$ sudo yum install gnutls-utils
nss-tools
$ sudo yum install nss-tools
yum
gpgcheck
/etc/yum.conf
[main]
gpgcheck=1
$ sudo subscription-manager register
/media/cdrom
$ sudo rpm --import /media/cdrom/RPM-GPG-KEY
sudo rpm --import /etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release