Ensure no unconfined services exist Details Unconfined processes run in unconfined domains Rationale: For unconfined processes, SELinux policy rules are applied, but policy rules exist...
Ensure RDS is disabled – lsmod Details The Reliable Datagram Sockets (RDS) protocol is a transport layer protocol designed to provide low-latency, high-bandwidth communications between cluster...
Ensure RDS is disabled – modprobe Details The Reliable Datagram Sockets (RDS) protocol is a transport layer protocol designed to provide low-latency, high-bandwidth communications between cluster...
Ensure SCTP is disabled – lsmod Details The Stream Control Transmission Protocol (SCTP) is a transport layer protocol used to support message oriented communication, with several...
Ensure SCTP is disabled – modprobe Details The Stream Control Transmission Protocol (SCTP) is a transport layer protocol used to support message oriented communication, with several...
Ensure SELinux is installed Details SELinux provides Mandatory Access Control. Rationale: Without a Mandatory Access Control system installed only the default Discretionary Access Control...
Ensure SELinux is not disabled in bootloader configuration – enforcing = 0 Details Configure SELINUX to be enabled at boot time and verify that it has not been overwritten by the grub...
Ensure SELinux is not disabled in bootloader configuration – selinux = 0 Details Configure SELINUX to be enabled at boot time and verify that it has not been overwritten by the grub...
Ensure SELinux policy is configured Details Configure SELinux to meet or exceed the default targeted policy, which constrains daemons and system software only. Rationale: Security...
Ensure separate partition exists for /home Details The /home directory is used to support disk storage needs of local users. Rationale: If the system is intended...