Ensure GNOME Screen Lock is Enabled. Details The operating system should enable a user session lock until that user re-establishes access using established identification and authentication...
Ensure GNOME Screensaver period of inactivity is configured. Details The operating system must initiate a screensaver after a 15-minute period of inactivity for graphical user interfaces. Rationale: A...
Ensure host-based intrusion detection tool is used – MFEhiplsm process Details The operating system must have a host-based intrusion detection tool installed. Rationale: Adding host-based intrusion detection tools can provide...
Ensure kernel core dumps are disabled. Details The operating system must disable Kernel core dumps unless needed. Rationale: Kernel core dumps may contain the full contents...
Ensure ldap_tls_cacert is set for LDAP – config Details The operating system must implement cryptography to protect the integrity of Lightweight Directory Access Protocol (LDAP) communications is set...
Ensure ldap_tls_cacert is set for LDAP – file Details The operating system must implement cryptography to protect the integrity of Lightweight Directory Access Protocol (LDAP) communications is set...
Ensure ldap_id_use_start_tls is set for LDAP. Details The operating system must implement cryptography to protect the integrity of Lightweight Directory Access Protocol (LDAP) authentication communications setting...
Ensure NFS is configured to use RPCSEC_GSS. Details The operating system must be configured so that the Network File System (NFS) is configured to use RPCSEC_GSS. Rationale:...
Ensure NIST FIPS-validated cryptography is configured – grub Details The operating system must implement NIST FIPS-validated cryptography for the following: provision digital signatures generate cryptographic hashes protect data...
Ensure NIST FIPS-validated cryptography is configured – installed Details The operating system must implement NIST FIPS-validated cryptography for the following: provision digital signatures generate cryptographic hashes protect data...