Item Search

NameAudit NamePluginCategory
GEN002751 - The audit system must be configured to audit account modification - flags uaDISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN002751 - The audit system must be configured to audit account modification - naflags +ua and -uaDISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN002752 - The audit system must be configured to audit account disabling - naflags uaDISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN002753 - The audit system must be configured to audit account termination - flags +ua and -uaDISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN003080 - Crontab files must have mode 0600 or less permissive.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN003090 - Crontab files must not have extended ACLs.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN003240 - The cron.allow file must be owned by root, bin, or sys.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN003430 - The 'at' directory must be group-owned by root, bin, or sys - at directory must be group-owned by root, bin, or sys.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN003601 - TCP backlog queue sizes must be set appropriately - tcp_conn_req_max_q0DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN003602 - The system must not process ICMP timestamp requests.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN003604 - The system must not respond to ICMP timestamp requests sent to a broadcast address - ip_respond_to_echo_broadcastDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN003606 - The system must prevent local applications from generating source-routed packets - ssrrDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN003623 - The system must use a separate file system for the system audit data path - /etc/vfstabDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN003660 - The system must log authentication informational data.DISA STIG Solaris 10 X86 v2r4Unix

AUDIT AND ACCOUNTABILITY

GEN003730 - The inetd.conf file must be group-owned by root, bin, or sys.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN003780 - The services file must have mode 0444 or less permissive.DISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN003810 - The portmap or rpcbind service must not be running unless needed.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN003825 - The rshd service must not be installed.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN003840 - The rexec daemon must not be running.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN004390 - The alias file must not have an extended ACL.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN004480 - The SMTP service log file must be owned by root - /var/log/syslogDISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN004500 - The SMTP service log file must have mode 0644 or less permissive - MAIL_LOGDISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN004580 - The system must not use .forward files.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN004900 - The ftpusers file must contain account names not allowed to use FTP.DISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN004930 - The ftpusers file must be group-owned by root, bin, or sys.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005220 - .Xauthority or X*.hosts (or equivalent) file(s) must be used to restrict access to the X server.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005320 - The snmpd.conf file must have mode 0600 or less permissive - /etc/sma/snmp/snmpd.confDISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN005320 - The snmpd.conf file must have mode 0600 or less permissive - /usr/sfw/lib/sma_snmp/snmpd.confDISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN005360 - The snmpd.conf files must be owned by root - /etc/snmp/conf/snmpd.confDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005360 - The snmpd.conf files must be owned by root - /var/sma_snmp/snmpd.confDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005400 - The /etc/syslog.conf file must be owned by root.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005521 - The SSH daemon must restrict login ability to specific users and/or groups.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005536 - The SSH daemon must perform strict mode checking of home directory configuration files.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005540 - The SSH daemon must be configured for IP filtering.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005570 - The system must be configured with a default gateway for IPv6 if the system uses IPv6, unless the system is a router.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005610 - The system must not have IP forwarding for IPv6 enabled, unless the system is an IPv6 router.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005820 - The NFS anonymous UID and GID must be configured to values that have no permissions.DISA STIG Solaris 10 X86 v2r4Unix

IDENTIFICATION AND AUTHENTICATION

GEN006140 - The smb.conf file must have mode 0644 or less permissive.DISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN006200 - The smbpasswd file must have mode 0600 or less permissive.DISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN006320 - The /etc/news/passwd.nntp file (or equivalent) must have mode 0600 or less permissive.DISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN006420 - NIS maps must be protected through hard-to-guess domain names.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN006570 - The file integrity tool must be configured to verify ACLs - configDISA STIG Solaris 10 X86 v2r4Unix

SYSTEM AND INFORMATION INTEGRITY

GEN006580 - The system must use an access control program.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN006640 - The system must use a virus scan program.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN007880 - The system must not send IPv6 ICMP redirects.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN007950 - The system must not respond to ICMPv6 echo requests sent to a broadcast address.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN007980 - If the system is using LDAP for authentication or account information, the system must use a TLS connection using FIPS 140-2 approved cryptographic algorithms - serversDISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN008460 - The system must have USB disabled unless needed.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN008800 - The system package management tool must cryptographically verify the authenticity of software packages during installation.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

UBTU-18-010113 - The Ubuntu operating system must prevent the use of dictionary words for passwords.DISA STIG Ubuntu 18.04 LTS v2r15Unix

CONFIGURATION MANAGEMENT