Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Review CIS RHEL7 v4.0.0 Section 4 - Access, Authentication and Authorization #11455

Merged
merged 36 commits into from
Jan 24, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
36 commits
Select commit Hold shift + click to select a range
f1a03be
Update CIS RHEL7 section 4.1.1
marcusburghardt Jan 18, 2024
683f74d
Update rules related to CIS RHEL7 4.1.1
marcusburghardt Jan 18, 2024
49d1f73
Update CIS RHEL7 section 4.1.2
marcusburghardt Jan 18, 2024
68832ef
Update rules related to CIS RHEL7 4.1.2
marcusburghardt Jan 18, 2024
2998bff
Update CIS RHEL7 section 4.2
marcusburghardt Jan 18, 2024
910dca7
Update rules related to CIS RHEL7 4.2
marcusburghardt Jan 18, 2024
ff6f626
Update CIS RHEL7 section 4.3
marcusburghardt Jan 18, 2024
b3c036b
Update rules related to CIS RHEL7 4.3
marcusburghardt Jan 18, 2024
d830db5
Enable rhel7 in rules required by CIS RHEL7
marcusburghardt Jan 18, 2024
db2f97c
Update CIS RHEL7 section 4.4.1
marcusburghardt Jan 18, 2024
0226f6e
Update rules related to CIS RHEL7 4.4.1
marcusburghardt Jan 18, 2024
7ab81e8
Update CIS RHEL7 section 4.4.2.1
marcusburghardt Jan 18, 2024
10c99b4
Update rules related to CIS RHEL7 4.4.2.1
marcusburghardt Jan 18, 2024
d8636c3
Update CIS RHEL7 section 4.4.2.2
marcusburghardt Jan 18, 2024
4c9855b
Update rules related to CIS RHEL7 4.4.2.2
marcusburghardt Jan 18, 2024
2c25074
Enable accounts_password_pam_dictcheck to rhel7
marcusburghardt Jan 18, 2024
9010165
Update CIS RHEL7 section 4.4.2.4
marcusburghardt Jan 18, 2024
5396d31
Update rules related to CIS RHEL7 4.4.2.4
marcusburghardt Jan 18, 2024
ec9e410
Update CIS RHEL7 section 4.5.1 and 4.5.2
marcusburghardt Jan 18, 2024
23e49bf
Update rules related to CIS RHEL7 4.5.1 and 4.5.2
marcusburghardt Jan 18, 2024
b2b6f78
Enable ensure_root_password_configured to rhel7
marcusburghardt Jan 18, 2024
e959bde
Update CIS RHEL7 section 4.5.3
marcusburghardt Jan 18, 2024
3a40c17
Update rules related to CIS RHEL7 4.5.3
marcusburghardt Jan 18, 2024
b119b8f
Removed CIS RHEL7 references in dropped rules
marcusburghardt Jan 18, 2024
61d971e
Update var_password_pam_remember for CIS RHEL7 4.0.0
marcusburghardt Jan 18, 2024
139e0ad
Update CIS RHEL7 version in header
marcusburghardt Jan 19, 2024
ad697b4
Fix wrong reference
marcusburghardt Jan 19, 2024
6294c3f
Update requirements status after review
marcusburghardt Jan 22, 2024
db51d12
Review sshd_approved_ciphers.var
marcusburghardt Jan 22, 2024
bab06e9
Review usage of sudo_require_reauthentication
marcusburghardt Jan 22, 2024
6a3ea7a
Fix rule section in CIS RHEL7 4.2.15
marcusburghardt Jan 22, 2024
c014abf
Update selection in CIS RHEL7 4.5.3.3
marcusburghardt Jan 22, 2024
4ec14d1
Include note in CIS RHEL7 4.5.3.3
marcusburghardt Jan 22, 2024
62c006c
Just minor update in the line format
marcusburghardt Jan 23, 2024
419d75a
Remove unnecessary space at the beginning
marcusburghardt Jan 23, 2024
dc5ad44
Fix regex for pam_wheel.so line with use_uid
marcusburghardt Jan 23, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
775 changes: 654 additions & 121 deletions controls/cis_rhel7.yml

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.7
cis@alinux3: 5.1.7
cis@rhel7: 5.1.7
cis@rhel7: 4.1.1.7
cis@rhel8: 5.1.7
cis@rhel9: 5.1.7
cis@sle12: 5.1.7
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.4
cis@alinux3: 5.1.4
cis@rhel7: 5.1.4
cis@rhel7: 4.1.1.4
cis@rhel8: 5.1.4
cis@rhel9: 5.1.4
cis@sle12: 5.1.4
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.3
cis@alinux3: 5.1.3
cis@rhel7: 5.1.3
cis@rhel7: 4.1.1.3
cis@rhel8: 5.1.3
cis@rhel9: 5.1.3
cis@sle12: 5.1.3
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.6
cis@alinux3: 5.1.6
cis@rhel7: 5.1.6
cis@rhel7: 4.1.1.6
cis@rhel8: 5.1.6
cis@rhel9: 5.1.6
cis@sle12: 5.1.6
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.5
cis@alinux3: 5.1.5
cis@rhel7: 5.1.5
cis@rhel7: 4.1.1.5
cis@rhel8: 5.1.5
cis@rhel9: 5.1.5
cis@sle12: 5.1.5
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.2
cis@alinux3: 5.1.2
cis@rhel7: 5.1.2
cis@rhel7: 4.1.1.2
cis@rhel8: 5.1.2
cis@rhel9: 5.1.2
cis@sle12: 5.1.2
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.7
cis@alinux3: 5.1.7
cis@rhel7: 5.1.7
cis@rhel7: 4.1.1.7
cis@rhel8: 5.1.7
cis@rhel9: 5.1.7
cis@sle12: 5.1.7
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.4
cis@alinux3: 5.1.4
cis@rhel7: 5.1.4
cis@rhel7: 4.1.1.4
cis@rhel8: 5.1.4
cis@rhel9: 5.1.4
cis@sle12: 5.1.4
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.3
cis@alinux3: 5.1.3
cis@rhel7: 5.1.3
cis@rhel7: 4.1.1.3
cis@rhel8: 5.1.3
cis@rhel9: 5.1.3
cis@sle12: 5.1.3
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.6
cis@alinux3: 5.1.6
cis@rhel7: 5.1.6
cis@rhel7: 4.1.1.6
cis@rhel8: 5.1.6
cis@rhel9: 5.1.6
cis@sle12: 5.1.6
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.5
cis@alinux3: 5.1.5
cis@rhel7: 5.1.5
cis@rhel7: 4.1.1.5
cis@rhel8: 5.1.5
cis@rhel9: 5.1.5
cis@sle12: 5.1.5
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.2
cis@alinux3: 5.1.2
cis@rhel7: 5.1.2
cis@rhel7: 4.1.1.2
cis@rhel8: 5.1.2
cis@rhel9: 5.1.2
cis@sle12: 5.1.2
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.7
cis@alinux3: 5.1.7
cis@rhel7: 5.1.7
cis@rhel7: 4.1.1.7
cis@rhel8: 5.1.7
cis@rhel9: 5.1.7
cis@sle12: 5.1.7
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.4
cis@alinux3: 5.1.4
cis@rhel7: 5.1.4
cis@rhel7: 4.1.1.4
cis@rhel8: 5.1.4
cis@rhel9: 5.1.4
cis@sle12: 5.1.4
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.3
cis@alinux3: 5.1.3
cis@rhel7: 5.1.3
cis@rhel7: 4.1.1.3
cis@rhel8: 5.1.3
cis@rhel9: 5.1.3
cis@sle12: 5.1.3
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.6
cis@alinux3: 5.1.6
cis@rhel7: 5.1.6
cis@rhel7: 4.1.1.6
cis@rhel8: 5.1.6
cis@rhel9: 5.1.6
cis@sle12: 5.1.6
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.5
cis@alinux3: 5.1.5
cis@rhel7: 5.1.5
cis@rhel7: 4.1.1.5
cis@rhel8: 5.1.5
cis@rhel9: 5.1.5
cis@sle12: 5.1.5
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.2
cis@alinux3: 5.1.2
cis@rhel7: 5.1.2
cis@rhel7: 4.1.1.2
cis@rhel8: 5.1.2
cis@rhel9: 5.1.2
cis@sle12: 5.1.2
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ identifiers:
references:
cis@alinux2: 5.1.8
cis@alinux3: 5.1.8
cis@rhel7: 5.1.9
cis@rhel7: 4.1.2.1
cis@rhel8: 5.1.9
cis@rhel9: 5.1.9
cis@sle12: 5.1.9
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ identifiers:
cce@rhel9: CCE-86185-6

references:
cis@rhel7: 5.1.8
cis@rhel7: 4.1.1.8
cis@rhel8: 5.1.8
cis@rhel9: 5.1.8

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ identifiers:
references:
cis@alinux2: 5.1.8
cis@alinux3: 5.1.8
cis@rhel7: 5.1.8
cis@rhel7: 4.1.1.8
cis@rhel8: 5.1.8
cis@rhel9: 5.1.8
cis@sle12: 5.1.8
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ identifiers:
references:
cis@alinux2: 5.1.8
cis@alinux3: 5.1.8
cis@rhel7: 5.1.9
cis@rhel7: 4.1.2.1
cis@rhel8: 5.1.9
cis@rhel9: 5.1.9
cis@sle12: 5.1.9
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.8
cis@alinux3: 5.1.8
cis@rhel7: 5.1.8
cis@rhel7: 4.1.1.8
cis@rhel8: 5.1.8
cis@rhel9: 5.1.8
cis@sle12: 5.1.8
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ identifiers:
references:
cis@alinux2: 5.1.8
cis@alinux3: 5.1.8
cis@rhel7: 5.1.9
cis@rhel7: 4.1.2.1
cis@rhel8: 5.1.9
cis@rhel9: 5.1.9
cis@sle12: 5.1.9
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ references:
cis-csc: 12,13,14,15,16,18,3,5
cis@alinux2: 5.1.8
cis@alinux3: 5.1.8
cis@rhel7: 5.1.8
cis@rhel7: 4.1.1.8
cis@rhel8: 5.1.8
cis@rhel9: 5.1.8
cis@sle12: 5.1.8
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ identifiers:
references:
cis@alinux2: 5.1.8
cis@alinux3: 5.1.8
cis@rhel7: 5.1.9
cis@rhel7: 4.1.2.1
cis@rhel8: 5.1.9
cis@rhel9: 5.1.9
cis@sle12: 5.1.9
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ identifiers:
references:
cis@alinux2: 5.1.8
cis@alinux3: 5.1.8
cis@rhel7: 5.1.8
cis@rhel7: 4.1.1.8
cis@rhel8: 5.1.8
cis@rhel9: 5.1.8
cis@sle12: 5.1.8
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ references:
cis-csc: 11,14,3,9
cis@alinux2: 5.1.2
cis@alinux3: 5.1.1
cis@rhel7: 5.1.1
cis@rhel7: 4.1.1.1
cis@rhel8: 5.1.1
cis@rhel9: 5.1.1
cobit5: BAI10.01,BAI10.02,BAI10.03,BAI10.05,DSS05.02,DSS05.05,DSS06.06
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ references:
cis-csc: 11,12,14,15,16,18,3,5,9
cis@alinux2: 5.2.9
cis@alinux3: 5.2.9
cis@rhel7: 4.2.9
cis@rhel7: 4.2.10
cis@rhel8: 5.2.8
cis@rhel9: 5.2.8
cis@sle12: 5.2.9
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ references:
cis-csc: 11,12,13,14,15,16,18,3,5,9
cis@alinux2: 5.2.11
cis@alinux3: 5.2.11
cis@rhel7: 4.2.11
cis@rhel7: 4.2.19
cis@rhel8: 5.2.9
cis@rhel9: 5.2.9
cis@sle12: 5.2.11
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,7 @@ identifiers:

references:
cis-csc: 11,3,9
cis@rhel7: 4.2.9
cobit5: BAI10.01,BAI10.02,BAI10.03,BAI10.05
cui: 3.1.12
disa: CCI-000318,CCI-000368,CCI-001812,CCI-001813,CCI-001814,CCI-000366
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ references:
cis-csc: 11,12,14,15,16,18,3,5,9
cis@alinux2: 5.2.8
cis@alinux3: 5.2.8
cis@rhel7: 4.2.8
cis@rhel7: 4.2.11
cis@rhel8: 5.2.11
cis@rhel9: 5.2.11
cis@sle12: 5.2.8
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ references:
cis-csc: 1,11,12,13,14,15,16,18,3,5
cis@alinux2: 5.2.10
cis@alinux3: 5.2.10
cis@rhel7: 4.2.10
cis@rhel7: 4.2.20
cis@rhel8: 5.2.7
cis@rhel9: 5.2.7
cis@sle12: 5.2.10
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ identifiers:

references:
cis@alinux3: 5.2.17
cis@rhel7: 4.2.20
cis@rhel7: 4.2.8
cis@rhel8: 5.2.13
cis@rhel9: 5.2.13
cis@sle12: 5.2.20
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ identifiers:
references:
cis@alinux2: 5.2.6
cis@alinux3: 5.2.6
cis@rhel7: 4.2.6
cis@rhel7: 4.2.8
cis@rhel8: 5.2.12
cis@rhel9: 5.2.12
cis@sle12: 5.2.6
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ references:
cis-csc: 11,3,9
cis@alinux2: 5.2.12
cis@alinux3: 5.2.12
cis@rhel7: 4.2.12
cis@rhel7: 4.2.21
cis@rhel8: 5.2.10
cis@rhel9: 5.2.10
cis@sle12: 5.2.12
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ identifiers:
cce@sle15: CCE-91333-5

references:
cis@rhel7: 4.2.19
cis@rhel7: 4.2.22
cis@rhel8: 5.2.6
cis@rhel9: 5.2.6
cis@sle12: 5.2.19
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ identifiers:

references:
ccn@rhel9: A.11.SEC-RHEL4
cis@rhel7: 4.2.18
cis@rhel7: 4.2.5
cis@rhel8: 5.2.15
cis@rhel9: 5.2.15
cis@ubuntu2004: 5.2.18
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ references:
cis-csc: 1,12,13,14,15,16,18,3,5,7,8
cis@alinux2: 5.2.14
cis@alinux3: 5.2.13
cis@rhel7: 4.2.16
cis@rhel7: 4.2.7
cis@rhel8: 5.2.20
cis@rhel9: 5.2.20
cis@sle12: 5.2.16
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ references:
cis-csc: 1,12,13,14,15,16,18,3,5,7,8
cis@alinux2: 5.2.14
cis@alinux3: 5.2.13
cis@rhel7: 4.2.16
cis@rhel7: 4.2.7
cis@rhel8: 5.2.20
cis@rhel9: 5.2.20
cis@sle12: 5.2.16
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ identifiers:
references:
cis@alinux2: 5.2.15
cis@alinux3: 5.2.14
cis@rhel7: 4.2.17
cis@rhel7: 4.2.13
cis@rhel8: 5.2.19
cis@rhel9: 5.2.19
cis@sle12: 5.2.17
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ references:
cis@alinux3: 5.2.5
cis@debian10: 9.3.2
cis@debian11: 9.3.2
cis@rhel7: 5.3.5
cis@rhel7: 4.2.14
cis@rhel8: 5.2.5
cis@rhel9: 5.2.5
cis@sle12: 5.2.5
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,7 @@ identifiers:
references:
cis@alinux2: 5.2.5
cis@alinux3: 5.2.5
cis@rhel7: 4.2.5
cis@rhel7: 4.2.14
cis@rhel8: 5.2.5
cis@rhel9: 5.2.5
cis@sle12: 5.2.5
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ references:
cis@alinux2: 5.2.7
cis@alinux3: 5.2.7
cis@debian11: 9.3.5
cis@rhel7: 4.2.7
cis@rhel7: 4.2.16
cis@rhel8: 5.2.16
cis@rhel9: 5.2.16
cis@sle12: 5.2.7
Expand Down
Loading
Loading