You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: README.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -5,7 +5,7 @@ RHEL 8 DISA STIG
5
5
6
6
Configure a RHEL 8 system to be DISA STIG compliant. All findings will be audited by default. Non-disruptive CAT I, CAT II, and CAT III findings will be corrected by default. Disruptive finding remediation can be enabled by setting `rhel8stig_disruption_high` to `yes`.
7
7
8
-
This role is based on RHEL 8 DISA STIG: [Version 1, Rel .01 released on May 11, 2020](https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_8_V1R0-1_IDraftSTIG.zip).
8
+
This role is based on RHEL 8 DISA STIG: [Version 1, Rel 1 released on January 5, 2021](https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_8_V1R1_STIG.zip).
# !!!!!!!!!!!!!!!--------------!!!!!!!!!!!!!!!!!!CHANGE TO TRUE BEFORE FINALIZATION. SET TO FALSE TO PREVENT THE VAGRANT USER FROM AUTHENTICATING WHEN USING SUDO
108
+
rhel_08_010372: true
109
+
rhel_08_010373: true
110
+
rhel_08_010374: true
111
+
# !!!!!!!!!!!!!!!--------------!!!!!!!!!!!!!!!!!!CHANGE TO TRUE BEFORE FINALIZATION. SET TO FALSE TO PREVENT THE VAGRANT USER FROM AUTHENTICATING WHEN USING SUDO (380/381)
106
112
rhel_08_010380: false
113
+
rhel_08_010381: false
107
114
rhel_08_010390: true
108
115
rhel_08_010400: true
109
116
rhel_08_010410: true
110
117
rhel_08_010420: true
118
+
rhel_08_010421: true
119
+
rhel_08_010422: true
120
+
rhel_08_010423: true
111
121
rhel_08_010430: true
122
+
rhel_08_010450: true
112
123
rhel_08_010480: true
113
124
rhel_08_010490: true
114
125
rhel_08_010500: true
115
126
rhel_08_010510: true
116
127
rhel_08_010520: true
128
+
rhel_08_010521: true
129
+
rhel_08_010543: true
117
130
rhel_08_010550: true
118
131
rhel_08_010560: true
132
+
rhel_08_010561: true
119
133
rhel_08_010570: true
134
+
rhel_08_010571: true
120
135
rhel_08_010580: true
121
136
rhel_08_010590: true
122
137
rhel_08_010600: true
@@ -127,7 +142,12 @@ rhel_08_010640: true
127
142
rhel_08_010650: true
128
143
rhel_08_010660: true
129
144
rhel_08_010670: true
130
-
rhel_08_010680: false
145
+
rhel_08_010671: true
146
+
rhel_08_010672: true
147
+
rhel_08_010673: true
148
+
rhel_08_010674: true
149
+
rhel_08_010675: true
150
+
rhel_08_010680: true
131
151
rhel_08_010690: true
132
152
rhel_08_010700: true
133
153
rhel_08_010710: true
@@ -140,11 +160,25 @@ rhel_08_010770: true
140
160
rhel_08_010780: true
141
161
rhel_08_010790: true
142
162
rhel_08_010800: true
143
-
rhel_08_010810: true
163
+
rhel_08_010830: true
144
164
rhel_08_020000: true
145
165
rhel_08_020010: true
166
+
rhel_08_020011: true
167
+
rhel_08_020012: true
168
+
rhel_08_020013: true
169
+
rhel_08_020014: true
170
+
rhel_08_020015: true
171
+
rhel_08_020016: true
172
+
rhel_08_020017: true
173
+
rhel_08_020018: true
174
+
rhel_08_020019: true
175
+
rhel_08_020020: true
176
+
rhel_08_020021: true
177
+
rhel_08_020022: true
178
+
rhel_08_020023: true
146
179
rhel_08_020030: true
147
180
rhel_08_020040: true
181
+
rhel_08_020041: true
148
182
rhel_08_020050: true
149
183
rhel_08_020060: true
150
184
rhel_08_020070: true
@@ -164,6 +198,7 @@ rhel_08_020200: true
164
198
rhel_08_020210: true
165
199
rhel_08_020220: true
166
200
rhel_08_020230: true
201
+
rhel_08_020231: true
167
202
rhel_08_020240: true
168
203
rhel_08_020250: true
169
204
rhel_08_020260: true
@@ -174,25 +209,33 @@ rhel_08_020300: true
174
209
rhel_08_020310: true
175
210
rhel_08_020320: true
176
211
rhel_08_020350: true
212
+
rhel_08_020351: true
213
+
rhel_08_020352: true
214
+
rhel_08_020353: true
177
215
rhel_08_030000: true
178
216
rhel_08_030010: true
179
217
rhel_08_030020: true
180
218
rhel_08_030030: true
181
219
rhel_08_030040: true
182
220
rhel_08_030050: true
183
221
rhel_08_030060: true
222
+
rhel_08_030061: true
223
+
rhel_08_030062: true
184
224
rhel_08_030070: true
185
225
rhel_08_030080: true
186
226
rhel_08_030090: true
187
227
rhel_08_030100: true
188
228
rhel_08_030110: true
189
-
### When logs folder is set to 600 per STIG auditd fails to start. Need to figure out perms
190
229
rhel_08_030120: true
230
+
rhel_08_030121: true
231
+
rhel_08_030122: true
191
232
rhel_08_030130: true
192
233
rhel_08_030140: true
193
234
rhel_08_030150: true
194
235
rhel_08_030160: true
195
236
rhel_08_030170: true
237
+
rhel_08_030171: true
238
+
rhel_08_030172: true
196
239
rhel_08_030180: true
197
240
rhel_08_030190: true
198
241
rhel_08_030200: true
@@ -206,12 +249,26 @@ rhel_08_030270: true
206
249
rhel_08_030280: true
207
250
rhel_08_030290: true
208
251
rhel_08_030300: true
252
+
rhel_08_030301: true
253
+
rhel_08_030302: true
209
254
rhel_08_030310: true
255
+
rhel_08_030311: true
256
+
rhel_08_030312: true
257
+
rhel_08_030313: true
258
+
rhel_08_030314: true
259
+
rhel_08_030315: true
260
+
rhel_08_030316: true
261
+
rhel_08_030317: true
210
262
rhel_08_030320: true
211
263
rhel_08_030330: true
212
264
rhel_08_030340: true
213
265
rhel_08_030350: true
214
266
rhel_08_030360: true
267
+
rhel_08_030361: true
268
+
rhel_08_030362: true
269
+
rhel_08_030363: true
270
+
rhel_08_030364: true
271
+
rhel_08_030365: true
215
272
rhel_08_030370: true
216
273
rhel_08_030380: true
217
274
rhel_08_030390: true
@@ -240,7 +297,6 @@ rhel_08_030610: true
240
297
rhel_08_030620: true
241
298
rhel_08_030630: true
242
299
rhel_08_030640: true
243
-
# !!!!!!!!!---------- handlers are overwriting the config change for this item
244
300
rhel_08_030650: true
245
301
rhel_08_030660: true
246
302
rhel_08_030670: true
@@ -251,45 +307,99 @@ rhel_08_030710: true
251
307
rhel_08_030720: true
252
308
rhel_08_030730: true
253
309
rhel_08_030740: true
310
+
rhel_08_040001: true
311
+
rhel_08_040002: true
312
+
rhel_08_040003: true
254
313
rhel_08_040020: true
255
314
rhel_08_040030: true
256
-
rhel_08_040040: true
257
-
rhel_08_040050: true
258
315
rhel_08_040070: true
259
316
rhel_08_040080: true
260
317
rhel_08_040090: true
261
318
rhel_08_040100: true
262
319
rhel_08_040110: true
320
+
rhel_08_040111: true
263
321
rhel_08_040120: true
322
+
rhel_08_040121: true
323
+
rhel_08_040122: true
324
+
rhel_08_040123: true
325
+
rhel_08_040124: true
326
+
rhel_08_040125: true
327
+
rhel_08_040126: true
328
+
rhel_08_040127: true
329
+
rhel_08_040128: true
330
+
rhel_08_040129: true
264
331
rhel_08_040130: true
332
+
rhel_08_040131: true
333
+
rhel_08_040132: true
334
+
rhel_08_040133: true
335
+
rhel_08_040134: true
336
+
rhel_08_040135: true
265
337
rhel_08_040140: true
266
338
rhel_08_040150: true
267
339
rhel_08_040160: true
340
+
rhel_08_040161: true
341
+
rhel_08_040162: true
342
+
rhel_08_040180: true
268
343
rhel_08_040210: true
269
344
rhel_08_040220: true
270
345
rhel_08_040230: true
271
346
rhel_08_040240: true
272
347
rhel_08_040250: true
273
348
rhel_08_040260: true
349
+
rhel_08_040261: true
350
+
rhel_08_040262: true
274
351
rhel_08_040270: true
275
352
rhel_08_040280: true
353
+
rhel_08_040281: true
354
+
rhel_08_040282: true
355
+
rhel_08_040283: true
356
+
rhel_08_040284: true
357
+
rhel_08_040285: true
276
358
rhel_08_040290: true
277
359
rhel_08_040320: true
278
360
rhel_08_040330: true
361
+
rhel_08_040340: true
362
+
rhel_08_040341: true
279
363
rhel_08_040350: true
364
+
rhel_08_040370: true
365
+
rhel_08_040380: true
366
+
rhel_08_040390: true
280
367
281
368
# CAT 3 rules
369
+
rhel_08_010171: true
370
+
rhel_08_010292: true
371
+
rhel_08_010375: true
372
+
rhel_08_010376: true
282
373
rhel_08_010440: true
283
-
rhel_08_010530: true
374
+
rhel_08_010471: true
284
375
rhel_08_010540: true
285
-
rhel_08_020020: true
376
+
rhel_08_010541: true
377
+
rhel_08_010542: true
378
+
rhel_08_020024: true
379
+
rhel_08_020042: true
286
380
rhel_08_020340: true
381
+
rhel_08_030063: true
382
+
rhel_08_030601: true
383
+
rhel_08_030602: true
384
+
rhel_08_030603: true
385
+
rhel_08_030741: true
386
+
rhel_08_030742: true
387
+
rhel_08_040004: true
388
+
rhel_08_040021: true
389
+
rhel_08_040022: true
390
+
rhel_08_040023: true
391
+
rhel_08_040024: true
392
+
rhel_08_040025: true
393
+
rhel_08_040026: true
287
394
rhel_08_040300: true
288
395
rhel_08_040310: true
289
396
290
397
# Whether or not to run tasks related to auditing/patching the desktop environment
291
398
rhel8stig_gui: false
292
399
400
+
# Whether or not you need kdump. False will disable service and true will leave service
401
+
rhel8stig_kdump_needed: false
402
+
293
403
# Whether to configure dconf rules unconditionally (ignoring presence of dconf
294
404
# or rhel8stig_gui)
295
405
rhel8stig_always_configure_dconf: false
@@ -444,13 +554,15 @@ rhel8stig_pam_pwhistory:
444
554
remember: 5
445
555
retries: 3
446
556
447
-
# RHEL-08-010320
448
-
# RHEL-08-010330
557
+
# RHEL-08-020010
558
+
# RHEL-08-020011
559
+
# RHEL-08-020012
560
+
# RHEL-08-020013
449
561
# pam_faillock settings - accounts must be locked for max time period after 3 unsuccessful attempts within 15 minutes.
450
562
rhel8stig_pam_faillock:
451
563
attempts: 3
452
564
interval: 900
453
-
unlock_time: 900
565
+
unlock_time: 0
454
566
fail_for_root: yes
455
567
456
568
# RHEL-08-030670
@@ -493,7 +605,9 @@ rhel8stig_login_defaults:
493
605
create_home: 'yes'
494
606
495
607
# RHEL-08-030690 uncomment and set the value to a remote IP address that can receive audit logs
# This will be the CRYPTO_POLICY settings in the opensshserver.conf file. It will be a string for the entirety of the setting
696
+
# to conform to STIG standard control RHEL-08-010290 this variable must contain oCiphers=aes256-ctr,aes192-ctr,aes128-ctr -oMACS=hmac-sha2-512,hmac-sha2-256 settings
697
+
# to conform to STIG standard control RHEL-08-010291 this variable must cotnain oCiphers=aes256-ctr,aes192-ctr,aes128-ctr
0 commit comments