DRAFT - CIS Red Hat Enterprise Linux 10 Benchmark for Level 2 - Workstation
Rules and Groups employed by this XCCDF Profile
-
Ensure gpgcheck Enabled In Main dnf Configuration
The <code>gpgcheck</code> option controls whether RPM packages' signatures are always checked prior to installation. To configure dnf to check pack...Rule High Severity -
Account and Access Control
In traditional Unix security, if an attacker gains shell access to a certain login account, they can perform any action or access any file to which...Group -
Enable authselect
Configure user authentication setup to use the <code>authselect</code> tool. If authselect profile is selected, the rule will enable the <xccdf-1.2...Rule Medium Severity -
Warning Banners for System Accesses
Each system should expose as little information about itself as possible. <br> <br> System banners, which are typically displayed jus...Group -
Ensure Local Login Warning Banner Is Configured Properly
To configure the system local login warning banner edit the <code>/etc/issue</code> file. The contents of this file is displayed to users prior to ...Rule Medium Severity -
Ensure Remote Login Warning Banner Is Configured Properly
To configure the system remote login warning banner edit the <code>/etc/issue.net</code> file. The contents of this file is displayed to users prio...Rule Medium Severity -
Ensure Message Of The Day Is Configured Properly
To configure the system message of the day banner edit the <code>/etc/motd</code> file. Replace the default text with a message compliant with the ...Rule Medium Severity -
Verify Group Ownership of System Login Banner
To properly set the group owner of/etc/issue
, run the command:$ sudo chgrp root /etc/issue
Rule Medium Severity -
Verify Group Ownership of System Login Banner for Remote Connections
To properly set the group owner of/etc/issue.net
, run the command:$ sudo chgrp root /etc/issue.net
Rule Medium Severity -
Verify Group Ownership of Message of the Day Banner
To properly set the group owner of/etc/motd
, run the command:$ sudo chgrp root /etc/motd
Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.
Capacity
Modules