Skip to content

CIS Red Hat Enterprise Linux 8 Benchmark for Level 2 - Workstation

Rules and Groups employed by this XCCDF Profile

  • Verify Group Who Owns /etc/shells File

    To properly set the group owner of /etc/shells, run the command:
    $ sudo chgrp root /etc/shells
    Rule Medium Severity
  • Verify Who Owns /etc/shells File

    To properly set the owner of /etc/shells, run the command:
    $ sudo chown root /etc/shells 
    Rule Medium Severity
  • Verify Permissions on /etc/shells File

    To properly set the permissions of /etc/shells, run the command:
    $ sudo chmod 0644 /etc/shells
    Rule Medium Severity
  • Ensure that /etc/cron.allow exists

    The file /etc/cron.allow should exist and should be used instead of /etc/cron.deny.
    Rule Medium Severity
  • Remove ftp Package

    FTP (File Transfer Protocol) is a traditional and widely used standard tool for transferring files between a server and clients over a network, especially where no authentication is necessary (perm...
    Rule Low Severity
  • Use Only Strong Key Exchange algorithms

    Limit the Key Exchange to strong algorithms. The following line in <code>/etc/ssh/sshd_config</code> demonstrates use of those: <pre>KexAlgorithms <xccdf-1.2:sub idref="xccdf_org.ssgproject.content...
    Rule Medium Severity
  • Use Only Strong MACs

    Limit the MACs to strong hash algorithms. The following line in <code>/etc/ssh/sshd_config</code> demonstrates use of those MACs: <pre>MACs <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_...
    Rule Medium Severity
  • Ensure Local Login Warning Banner Is Configured Properly

    To configure the system local login warning banner edit the <code>/etc/issue</code> file. The contents of this file is displayed to users prior to login to local terminals. Replace the default text...
    Rule Medium Severity
  • Ensure Remote Login Warning Banner Is Configured Properly

    To configure the system remote login warning banner edit the <code>/etc/issue.net</code> file. The contents of this file is displayed to users prior to login from remote connections. Replace the de...
    Rule Medium Severity
  • Ensure Message Of The Day Is Configured Properly

    To configure the system message of the day banner edit the <code>/etc/motd</code> file. Replace the default text with a message compliant with the local site policy. The message should not contain ...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules