|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
diff -uNrp scap-security-guide-0.1.25.orig/RHEL/7/input/profiles/pci-dss.xml scap-security-guide-0.1.25/RHEL/7/input/profiles/pci-dss.xml
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
--- scap-security-guide-0.1.25.orig/RHEL/7/input/profiles/pci-dss.xml 2015-12-08 07:06:53.929233818 -0600
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+++ scap-security-guide-0.1.25/RHEL/7/input/profiles/pci-dss.xml 2015-12-08 07:30:17.747857532 -0600
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
@@ -1,5 +1,5 @@
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<Profile id="pci-dss" xmlns="http://checklists.nist.gov/xccdf/1.1">
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-<title>Draft PCI-DSS v3 Control Baseline for Red Hat Enterprise Linux 7</title>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+<title>Draft PCI-DSS v3 Control Baseline for CentOS Linux 7</title>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<description>This is a *draft* profile for PCI-DSS v3</description>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<refine-value idref="var_password_pam_unix_remember" selector="4" />
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
@@ -54,20 +54,20 @@
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="audit_rules_kernel_module_loading" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="service_chronyd_or_ntpd_enabled" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="rpm_verify_hashes" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="ensure_logrotate_activated" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="package_aide_installed" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="disable_prelink" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="aide_periodic_cron_checking" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="accounts_password_all_shadowed" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="no_empty_passwords" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="display_login_attempts" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
@@ -77,19 +77,19 @@
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="sshd_set_idle_timeout" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="accounts_password_pam_minlen" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="accounts_password_pam_dcredit" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="accounts_password_pam_ucredit" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="accounts_password_pam_lcredit" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="accounts_maximum_age_login_defs" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="ensure_redhat_gpgkey_installed" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="ensure_gpgcheck_globally_activated" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="ensure_gpgcheck_never_disabled" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="security_patches_up_to_date" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="set_password_hashing_algorithm_systemauth" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="set_password_hashing_algorithm_logindefs" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="set_password_hashing_algorithm_libuserconf" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
diff -uNrp scap-security-guide-0.1.25.orig/RHEL/7/input/profiles/pci-dss.xml.rhel7_pcidss_downstream_disabled scap-security-guide-0.1.25/RHEL/7/input/profiles/pci-dss.xml.rhel7_pcidss_downstream_disabled
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
--- scap-security-guide-0.1.25.orig/RHEL/7/input/profiles/pci-dss.xml.rhel7_pcidss_downstream_disabled 2015-08-19 10:54:02.000000000 -0500
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+++ scap-security-guide-0.1.25/RHEL/7/input/profiles/pci-dss.xml.rhel7_pcidss_downstream_disabled 2015-12-08 07:31:08.882743495 -0600
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
@@ -1,5 +1,5 @@
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<Profile id="pci-dss" xmlns="http://checklists.nist.gov/xccdf/1.1">
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-<title>Draft PCI-DSS v3 Control Baseline for Red Hat Enterprise Linux 7</title>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+<title>Draft PCI-DSS v3 Control Baseline for CentOS Linux 7</title>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<description>This is a *draft* profile for PCI-DSS v3</description>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<refine-value idref="var_password_pam_unix_remember" selector="4" />
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
@@ -54,21 +54,21 @@
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="audit_rules_kernel_module_loading" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="audit_rules_immutable" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="service_chronyd_or_ntpd_enabled" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="rpm_verify_permissions" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="rpm_verify_hashes" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="ensure_logrotate_activated" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="package_aide_installed" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="disable_prelink" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="aide_periodic_cron_checking" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="accounts_password_all_shadowed" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="no_empty_passwords" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="display_login_attempts" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
@@ -78,19 +78,19 @@
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="dconf_gnome_screensaver_idle_delay" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="dconf_gnome_screensaver_idle_activation_enabled" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="dconf_gnome_screensaver_lock_enabled" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="sshd_set_idle_timeout" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="accounts_password_pam_minlen" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="accounts_password_pam_dcredit" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="accounts_password_pam_ucredit" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="accounts_password_pam_lcredit" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="accounts_maximum_age_login_defs" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="ensure_redhat_gpgkey_installed" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="ensure_gpgcheck_globally_activated" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="ensure_gpgcheck_never_disabled" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="security_patches_up_to_date" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="set_password_hashing_algorithm_systemauth" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="set_password_hashing_algorithm_logindefs" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="set_password_hashing_algorithm_libuserconf" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
diff -uNrp scap-security-guide-0.1.25.orig/RHEL/7/input/profiles/pci-dss.xml.rhel7_pcidss_drop_rpm_verify_permissions_rule scap-security-guide-0.1.25/RHEL/7/input/profiles/pci-dss.xml.rhel7_pcidss_drop_rpm_verify_permissions_rule
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
--- scap-security-guide-0.1.25.orig/RHEL/7/input/profiles/pci-dss.xml.rhel7_pcidss_drop_rpm_verify_permissions_rule 2015-12-08 07:06:53.928233822 -0600
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+++ scap-security-guide-0.1.25/RHEL/7/input/profiles/pci-dss.xml.rhel7_pcidss_drop_rpm_verify_permissions_rule 2015-12-08 07:31:31.811691561 -0600
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
@@ -1,5 +1,5 @@
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<Profile id="pci-dss" xmlns="http://checklists.nist.gov/xccdf/1.1">
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-<title>Draft PCI-DSS v3 Control Baseline for Red Hat Enterprise Linux 7</title>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+<title>Draft PCI-DSS v3 Control Baseline for CentOS Linux 7</title>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<description>This is a *draft* profile for PCI-DSS v3</description>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<refine-value idref="var_password_pam_unix_remember" selector="4" />
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
@@ -54,21 +54,21 @@
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="audit_rules_kernel_module_loading" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="service_chronyd_or_ntpd_enabled" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="rpm_verify_permissions" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="rpm_verify_hashes" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="ensure_logrotate_activated" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="package_aide_installed" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="disable_prelink" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="aide_periodic_cron_checking" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="accounts_password_all_shadowed" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="no_empty_passwords" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="display_login_attempts" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
@@ -78,19 +78,19 @@
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="sshd_set_idle_timeout" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="accounts_password_pam_minlen" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="accounts_password_pam_dcredit" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="accounts_password_pam_ucredit" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="accounts_password_pam_lcredit" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="accounts_maximum_age_login_defs" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="ensure_redhat_gpgkey_installed" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="ensure_gpgcheck_globally_activated" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="ensure_gpgcheck_never_disabled" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="security_patches_up_to_date" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="set_password_hashing_algorithm_systemauth" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="set_password_hashing_algorithm_logindefs" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="set_password_hashing_algorithm_libuserconf" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
diff -uNrp scap-security-guide-0.1.25.orig/RHEL/7/input/profiles/rht-ccp.xml scap-security-guide-0.1.25/RHEL/7/input/profiles/rht-ccp.xml
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
--- scap-security-guide-0.1.25.orig/RHEL/7/input/profiles/rht-ccp.xml 2015-08-19 10:54:02.000000000 -0500
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+++ scap-security-guide-0.1.25/RHEL/7/input/profiles/rht-ccp.xml 2015-12-08 07:33:09.162465695 -0600
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
@@ -1,6 +1,6 @@
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<Profile id="rht-ccp" xmlns="http://checklists.nist.gov/xccdf/1.1">
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-<title>Red Hat Corporate Profile for Certified Cloud Providers (RH CCP)</title>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-<description>This is a *draft* SCAP profile for Red Hat Certified Cloud Providers</description>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+<title>CentOS Profile for Cloud Providers (CPCP)</title>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+<description>This is a *draft* SCAP profile for CentOS Cloud Providers</description>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<refine-value idref="var_selinux_state" selector="enforcing"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<refine-value idref="var_selinux_policy_name" selector="targeted"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
@@ -98,11 +98,11 @@
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="kernel_module_ipv6_option_disabled" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="service_ip6tables_enabled" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-This requirement does not apply against Red Hat Enterprise Linux 7:
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+This requirement does not apply against CentOS Linux 7:
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
see: https://github.com/OpenSCAP/scap-security-guide/issues/66 for details.
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="kernel_module_rds_disabled" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-This requirement does not apply against Red Hat Enterprise Linux 7:
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+This requirement does not apply against CentOS Linux 7:
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
see: https://github.com/OpenSCAP/scap-security-guide/issues/67 for details.
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="kernel_module_tipc_disabled" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
diff -uNrp scap-security-guide-0.1.25.orig/RHEL/7/input/profiles/standard.xml scap-security-guide-0.1.25/RHEL/7/input/profiles/standard.xml
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
--- scap-security-guide-0.1.25.orig/RHEL/7/input/profiles/standard.xml 2015-08-19 10:54:02.000000000 -0500
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+++ scap-security-guide-0.1.25/RHEL/7/input/profiles/standard.xml 2015-12-08 07:27:34.453179300 -0600
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
@@ -1,6 +1,6 @@
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<Profile id="standard">
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<title>Standard System Security Profile</title>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-<description>This profile contains rules to ensure standard security base of Red Hat Enterprise Linux 7 system.</description>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+<description>This profile contains rules to ensure standard security base of CentOS Linux 7 system.</description>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<select idref="security_patches_up_to_date" selected="true"/>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
diff -uNrp scap-security-guide-0.1.25.orig/RHEL/7/input/profiles/stig-rhel7-server-upstream.xml scap-security-guide-0.1.25/RHEL/7/input/profiles/stig-rhel7-server-upstream.xml
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
--- scap-security-guide-0.1.25.orig/RHEL/7/input/profiles/stig-rhel7-server-upstream.xml 2015-08-19 10:54:02.000000000 -0500
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+++ scap-security-guide-0.1.25/RHEL/7/input/profiles/stig-rhel7-server-upstream.xml 2015-12-08 07:33:44.930380583 -0600
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
@@ -1,5 +1,5 @@
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<Profile id="stig-rhel7-server-upstream" extends="common">
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-<title override="true">Pre-release Draft STIG for Red Hat Enterprise Linux 7 Server</title>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+<title override="true">Pre-release Draft STIG for CentOS Linux 7 Server</title>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<description override="true">This profile is being developed under the DoD consensus model to become a STIG in coordination with DISA FSO.</description>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
diff -uNrp scap-security-guide-0.1.25.orig/RHEL/7/input/profiles/usgcb-rhel7-server.xml scap-security-guide-0.1.25/RHEL/7/input/profiles/usgcb-rhel7-server.xml
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
--- scap-security-guide-0.1.25.orig/RHEL/7/input/profiles/usgcb-rhel7-server.xml 2015-08-19 10:54:02.000000000 -0500
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+++ scap-security-guide-0.1.25/RHEL/7/input/profiles/usgcb-rhel7-server.xml 2015-12-08 07:34:34.081261816 -0600
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
@@ -1,6 +1,6 @@
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<Profile id="usgcb-rhel7-server">
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<title>United States Government Configuration Baseline (USGCB)</title>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
-<description>This profile is a working draft for a USGCB submission against RHEL7 Server.</description>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
+<description>This profile is a working draft for a USGCB submission against CentOS-7 Server.</description>
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<refine-value idref="var_password_pam_unix_remember" selector="5" />
|
|
![](https://seccdn.libravatar.org/avatar/567cc4a3492d3940b0e3594fbf0d44b33dfe9068aaa9b59f572a4cffd267746c?s=16&d=retro) |
e06992 |
<refine-value idref="var_accounts_maximum_age_login_defs" selector="60" />
|