Item Search

NameAudit NamePluginCategory
GEN000000-SOL00540 - The /etc/zones directory, and its contents, must be owned by root - /etc/zonesDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000000-SOL00540 - The /etc/zones directory, and its contents, must be owned by root - /etc/zones/*DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000000-SOL00600 - The /etc/zones directory, and its contents, must not have an extended ACL.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000452 - The system must display the date and time of the last successful account login upon login.DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN000460 - The system must disable accounts after three consecutive unsuccessful login attempts - LOCK_AFTER_RETRIESDISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN000460 - The system must disable accounts after three consecutive unsuccessful login attempts - RETRIESDISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN001060 - The system must log successful and unsuccessful access to the root account - /etc/default/suDISA STIG Solaris 10 SPARC v2r4Unix

AUDIT AND ACCOUNTABILITY

GEN001060 - The system must log successful and unsuccessful access to the root account - /var/adm/sulogDISA STIG Solaris 10 SPARC v2r4Unix

AUDIT AND ACCOUNTABILITY

GEN001120 - The system must not permit root logins using remote access programs such as SSH.DISA STIG Solaris 10 SPARC v2r4Unix

IDENTIFICATION AND AUTHENTICATION

GEN001140 - System files and directories must not have uneven access permissions - /etc/*DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN001140 - System files and directories must not have uneven access permissions - /usr/ucb/*DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN001180 - All network services daemon files must have mode 0755 or less permissive - /usr/sbin/*DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN001180 - All network services daemon files must have mode 0755 or less permissive - sshdDISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN001190 - All network services daemon files must not have extended ACLs - /usr/apache/bin/httpdDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001240 - System files, programs, and directories must be group-owned by a system group - usr/sbin/*DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001260 - System log files must have mode 0640 or less permissive - /var/logDISA STIG Solaris 10 SPARC v2r4Unix

SYSTEM AND INFORMATION INTEGRITY

GEN001280 - Manual page files must have mode 0655 or less permissive - /usr/sfw/man/*DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN001280 - Manual page files must have mode 0655 or less permissive - /usr/sfw/share/man/*DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN001310 - All library files must not have extended ACLs.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001361 - NIS/NIS+/yp command files must not have extended ACLs.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001374 - The /etc/nsswitch.conf file must not have an extended ACL.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001392 - The /etc/group file must be group-owned by root, bin, or sys.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001490 - User's home directories must not have extended ACLs.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001520 - All interactive user's home directories must be group-owned by the home directory owner's primary group.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001550 - All files and directories contained in user home directories must be group-owned by a group of which the home directory's owner is a member.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001570 - All files and directories contained in user home directories must not have extended ACLs.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001720 - All global initialization files must have mode 0644 or less permissive - /etc/.loginDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001720 - All global initialization files must have mode 0644 or less permissive - /etc/bashrcDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001720 - All global initialization files must have mode 0644 or less permissive - /etc/environmentDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001720 - All global initialization files must have mode 0644 or less permissive - /etc/profileDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001810 - Skeleton files must not have extended ACLs.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001830 - All skeleton files (typically in /etc/skel) must be group-owned by root, bin, or sys.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001980 - The .rhosts, .shosts, hosts.equiv, shosts.equiv, /etc/passwd, /etc/shadow, and/or /etc/group files must not contain a plus (+) without defining entries for NIS+ netgroups - /etc/ssh/shosts.equivDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN002040 - There must be no .rhosts, .shosts, hosts.equiv, or shosts.equiv files on the system.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN002210 - All shell files must be group-owned by root, bin, or sys.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN002690 - System audit logs must be group-owned by root, bin, or sys.DISA STIG Solaris 10 SPARC v2r4Unix

AUDIT AND ACCOUNTABILITY

GEN002715 - System audit tool executables must be owned by root - /usr/sbin/bsmrecordDISA STIG Solaris 10 SPARC v2r4Unix

AUDIT AND ACCOUNTABILITY

GEN002716 - System audit tool executables must be group-owned by root, bin, or sys - /usr/sbin/auditconfigDISA STIG Solaris 10 SPARC v2r4Unix

AUDIT AND ACCOUNTABILITY

GEN002717 - System audit tool executables must have mode 0750 or less permissive - /usr/sbin/auditconfigDISA STIG Solaris 10 SPARC v2r4Unix

AUDIT AND ACCOUNTABILITY

GEN002750 - The audit system must be configured to audit account creation - flags +ua and -uaDISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN002751 - The audit system must be configured to audit account modification - naflags +ua and -uaDISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN002752 - The audit system must be configured to audit account disabling - flags uaDISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN002760 - The audit system must be configured to audit all administrative, privileged, and security actions - flags amDISA STIG Solaris 10 SPARC v2r4Unix

AUDIT AND ACCOUNTABILITY

GEN003050 - Crontab files must be group-owned by root, sys, or the crontab creator's primary group.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN003160 - Cron logging must be implemented - log existsDISA STIG Solaris 10 SPARC v2r4Unix

AUDIT AND ACCOUNTABILITY

GEN003180 - The cronlog file must have mode 0600 or less permissive.DISA STIG Solaris 10 SPARC v2r4Unix

AUDIT AND ACCOUNTABILITY

GEN003190 - The cron log files must not have extended ACLs.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN003410 - The 'at' directory must not have an extended ACL - at directory must not have an extended ACL.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN003420 - The 'at' directory must be owned by root, bin, or sys - at directory must be owned by root, bin, or sys.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN003480 - The at.deny file must be owned by root, bin, or sys.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT