draft Example of SCAP Security Guidance This example security guidance has been created to demonstrate SCAP functionality on Linux. 0.1 Default install settings This profile is an example policy that simply checks if some of Fedora 14 default install settings have been modified. It is not comprehensive nor checks security hardening. It is just for testing purposes. OSCAP Scan Result localhost.localdomain 127.0.0.1 10.142.14.51 ::1 fe80::20c:29ff:fe84:d2d4 00:00:00:00:00:00 00:0C:29:84:D2:D4 00:00:00:00:00:00 00:0C:29:84:D2:D4 notselected notselected notselected notselected notselected notselected notselected fail notselected CCE-4218-4 # chkconfig yum-updatesd off notselected echo -e "/usr/bin/yum -R 120 -e 0 -d 0 -y update yum\n/usr/bin/yum -R 10 -e 0 -d 0 -y update" > /etc/cron.weekly/yum.cron pass pass notselected pass notselected CCE-4209-3 yum install aide notselected echo -e "/usr/sbin/aide --check" > /etc/cron.daily/aide.cron notselected notselected CCE-4249-9 notselected CCE-3522-0 notselected CCE-4275-4 notselected CCE-4042-8 notselected CCE-4187-1 echo -e "\nblacklist usb_storage" >> /etc/modprobe.d/blacklist.conf notselected CCE-4006-3 rm /lib/modules/2.6.*/kernel/drivers/usb/storage/usb-storage.ko notselected CCE-4173-1 notselected CCE-3944-6 notselected CCE-4072-5 chkconfig autofs off notselected CCE-4231-7 notselected echo "blacklist cramfs" >> /etc/modprobe.d/blacklist.conf notselected echo "blacklist freevxfs" >> /etc/modprobe.d/blacklist.conf notselected echo "blacklist jffs2" >> /etc/modprobe.d/blacklist.conf notselected echo "blacklist hfs" >> /etc/modprobe.d/blacklist.conf notselected echo "blacklist hfsplus" >> /etc/modprobe.d/blacklist.conf notselected echo "blacklist squashfs" >> /etc/modprobe.d/blacklist.conf notselected echo "blacklist udf" >> /etc/modprobe.d/blacklist.conf pass CCE-3918-0 pass CCE-3988-3 pass CCE-3276-3 pass CCE-3883-6 pass CCE-4210-1 pass CCE-4064-2 pass CCE-3958-6 pass CCE-3495-9 pass CCE-4130-1 pass CCE-3967-7 pass CCE-3932-1 pass CCE-3566-7 pass CCE-3399-3 pass CCE-3795-2 fail CCE-4178-0 fail CCE-3324-1 fail CCE-4223-4 fail CCE-3573-3 pass pass CCE-4220-0 notselected CCE-4225-9 pass CCE-4247-3 pass CCE-4168-1 pass CCE-4146-7 notselected CCE-4177-2 notselected CCE-3820-8 notselected CCE-3485-0 notselected CCE-4111-1 pass CCE-4256-4 notselected notselected notselected CCE-4044-4 echo "%wheel ALL=(ALL) ALL" >> /etc/sudoers notselected CCE-3987-5 pass CCE-4238-2 pass pass CCE-4009-7 pass CCE-4154-1 notselected CCE-4180-6 notselected CCE-4092-3 pass CCE-4097-2 notselected notselected notselected CCE-4114-5 notselected CCE-3762-2 notselected CCE-3762-2 notselected CCE-3410-8 notselected notselected CCE-4185-5 # chgrp usergroup /usr/sbin/userhelper notselected CCE-3952-9 # chmod 4710 /usr/sbin/userhelper pass /usr/sbin/authconfig --passalgo=sha512 --update notselected pass CCE-3301-9 pass fail CCE-4090-7 pass CCE-3844-8 pass CCE-4227-5 notselected rm .netrc fail CCE-4144-2 chown root /boot/grub/grub.conf fail CCE-4197-0 chown :root /boot/grub/grub.conf fail CCE-3923-0 chmod 600 /boot/grub/grub.conf notselected CCE-3818-2 notselected CCE-4241-6 notselected CCE-4245-7 notselected CCE-3689-7 notselected CCE-3707-7 notselected CCE-3315-9 notselected notselected notselected notselected CCE-3910-7 yum install vlock notselected CCE-4060-0 notselected CCE-4188-9 pass CCE-3977-6 notselected pass pass CCE-3624-4 notselected notselected CCE-3668-1 notselected CCE-4129-3 notselected notselected CCE-4151-7 notselected CCE-4155-8 notselected CCE-3561-8 notselected CCE-4236-6 notselected CCE-4217-6 notselected CCE-3472-8 notselected CCE-4320-8 notselected CCE-4091-5 notselected CCE-4186-3 notselected CCE-3339-9 notselected CCE-3644-2 notselected CCE-4133-5 notselected CCE-4265-5 notselected CCE-4080-8 notselected CCE-3840-6 notselected CCE-3628-5 notselected CCE-4276-2 notselected CCE-4170-7 notselected CCE-3562-6 notselected CCE-3381-1 notselected CCE-3377-9 notselected CCE-4296-0 notselected CCE-4269-7 notselected CCE-4291-1 notselected CCE-4313-3 notselected CCE-4198-8 notselected CCE-3842-2 notselected CCE-4159-0 notselected CCE-4221-8 notselected CCE-4058-4 notselected CCE-4128-5 notselected CCE-4287-9 notselected CCE-3895-0 notselected CCE-4137-6 fail CCE-4167-3 chkconfig ip6tables on fail CCE-4189-7 chkconfig iptables on notselected notselected notselected notselected notselected notselected fail CCE-3679-8 chkconfig rsyslog on pass CCE-4366-1 pass CCE-3701-0 fail CCE-4233-3 notselected CCE-4260-6 notselected CCE-3382-9 notselected CCE-4182-2 notselected CCE-4323-2 fail CCE-4292-9 notselected notselected notselected cp /usr/share/doc/audit-version/stig.rules /etc/audit/audit.rules notselected cp /usr/share/doc/audit-version/stig.rules /etc/audit/audit.rules notselected cp /usr/share/doc/audit-version/stig.rules /etc/audit/audit.rules notselected notselected notselected cp /usr/share/doc/audit-version/stig.rules /etc/audit/audit.rules notselected cp /usr/share/doc/audit-version/stig.rules /etc/audit/audit.rules notselected cp /usr/share/doc/audit-version/stig.rules /etc/audit/audit.rules notselected cp /usr/share/doc/audit-version/stig.rules /etc/audit/audit.rules notselected cp /usr/share/doc/audit-version/stig.rules /etc/audit/audit.rules notselected cp /usr/share/doc/audit-version/stig.rules /etc/audit/audit.rules notselected notselected cp /usr/share/doc/audit-version/stig.rules /etc/audit/audit.rules notselected CCE-4234-1 notselected CCE-4252-3 notselected CCE-4023-8 # yum erase inetd notselected CCE-4164-0 # yum erase xinetd notselected CCE-4330-7 # yum erase telnet-server notselected CCE-3390-2 notselected # yum erase telnet notselected # yum erase rsh-server notselected CCE-4308-3 # yum erase rsh-server notselected CCE-3974-3 # chkconfig rcp off notselected CCE-4141-8 # chkconfig rsh off notselected CCE-3537-8 # chkconfig rlogin off notselected notselected # yum erase rsh notselected CCE-4348-9 # yum erase ypserv notselected CCE-3705-1 # chkconfig ypbind off notselected CCE-3916-4 # yum erase tftp-server notselected CCE-4273-9 # chkconfig tftp off notselected CCE-3412-4 # chkconfig firstboot off notselected CCE-4229-1 # chkconfig gpm off notselected CCE-4123-6 # chkconfig irqbalance off notselected CCE-4286-1 # chkconfig isdn off notselected CCE-3425-6 # chkconfig kdump off notselected CCE-4211-9 # chkconfig kudzu off notselected CCE-3854-7 # chkconfig mdmonitor off notselected CCE-4356-2 # chkconfig microcode ctl off notselected CCE-4369-5 # chkconfig network off notselected # rm /etc/sysconfig/network-scripts/ifcfg-interface notselected CCE-4369-5 notselected CCE-4100-4 # chkconfig pcscd off notselected CCE-3455-3 # chkconfig smartd off notselected CCE-4421-4 # chkconfig readahead early off notselected CCE-4302-6 # chkconfig readahead later off notselected CCE-3822-4 # chkconfig messagebus off notselected CCE-4364-6 # chkconfig haldaemon off notselected CCE-4355-4 # chkconfig bluetooth off notselected CCE-4377-8 # chkconfig hidd off notselected notselected CCE-4289-5 # chkconfig apmd off notselected CCE-4298-6 notselected CCE-4051-9 notselected CCE-4324-0 notselected CCE-4406-5 notselected CCE-4428-9 # yum erase anacron pass CCE-3626-9 pass CCE-3851-3 pass CCE-4388-5 pass CCE-3604-6 pass CCE-4379-4 pass CCE-4304-2 pass CCE-4054-3 pass CCE-3481-9 pass CCE-4331-5 pass CCE-4322-4 pass CCE-4212-7 pass CCE-3983-4 pass CCE-4022-0 pass CCE-3833-1 pass CCE-4441-2 pass CCE-4380-2 pass CCE-4106-1 pass CCE-4450-3 pass CCE-4203-6 pass CCE-4251-5 pass CCE-4250-7 pass pass pass notselected notselected notselected rm /etc/cron.deny notselected rm /etc/at.deny notselected CCE-4268-9 # chkconfig sshd off notselected CCE-4272-1 # yum erase openssh-server notselected CCE-4295-2 notselected notselected CCE-4325-7 notselected CCE-3845-5 notselected notselected CCE-4475-0 notselected CCE-4370-3 notselected CCE-4387-7 notselected CCE-3660-8 notselected CCE-4431-3 notselected notselected notselected CCE-4462-8 notselected CCE-4422-2 # yum groupremove "X Window System" notselected CCE-4074-1 echo "exec X :0 -nolisten tcp $@" > /etc/X11/xinit/xserverrc notselected CCE-3717-6 notselected CCE-4365-3 # chkconfig avahi-daemon off notselected CCE-4136-8 notselected CCE-4409-9 notselected CCE-4426-3 notselected CCE-4193-9 notselected CCE-4444-6 notselected CCE-4352-1 notselected CCE-4433-9 notselected CCE-4451-1 notselected CCE-4341-4 notselected CCE-4358-8 notselected CCE-4112-9 # chkconfig cups off notselected CCE-3649-1 notselected notselected CCE-4420-6 notselected CCE-4407-3 notselected CCE-4425-5 notselected CCE-4191-3 notselected CCE-4336-4 # chkconfig dhcpd off notselected CCE-4464-4 # yum erase dhcp notselected CCE-4257-2 notselected CCE-4403-2 notselected CCE-4345-5 notselected CCE-3724-2 notselected CCE-4243-2 notselected CCE-4389-3 notselected CCE-3913-1 notselected CCE-4169-9 notselected CCE-4318-2 notselected CCE-4319-0 notselected CCE-3733-3 notselected CCE-4376-0 # chkconfig ntpd on notselected CCE-4134-3 notselected CCE-4385-1 notselected CCE-4032-9 notselected CCE-4424-8 notselected CCE-3487-6 notselected CCE-4293-7 notselected notselected CCE-3501-4 notselected CCE-4396-8 notselected CCE-3535-2 notselected CCE-3568-3 notselected CCE-4533-6 notselected CCE-4559-1 notselected CCE-4015-4 notselected CCE-3667-3 notselected CCE-4310-9 notselected CCE-4438-8 notselected CCE-3579-0 notselected CCE-4473-5 notselected CCE-4491-7 notselected CCE-4368-7 notselected CCE-4024-6 notselected CCE-4526-0 notselected CCE-4544-3 notselected CCE-4465-1 notselected CCE-4350-5 notselected CCE-3578-2 notselected CCE-4219-2 notselected CCE-3985-9 notselected CCE-4258-0 notselected CCE-4487-5 notselected CCE-4399-2 notselected CCE-3919-8 notselected CCE-3919-8 notselected CCE-4549-2 notselected CCE-4554-2 notselected CCE-4443-8 notselected CCE-4461-0 notselected CCE-4338-0 notselected CCE-4514-6 notselected CCE-4474-3 notselected CCE-3756-4 notselected CCE-4509-6 notselected CCE-4386-9 notselected CCE-4029-5 notselected CCE-3581-6 notselected CCE-4574-0 notselected CCE-3847-1 notselected CCE-4239-0 notselected CCE-4384-4 notselected CCE-3887-7 notselected CCE-4530-2 notselected CCE-4547-6 notselected CCE-4552-6 notselected CCE-4371-1 notselected CCE-4410-7 notselected CCE-4551-8 notselected notselected CCE-4556-7 notselected CCE-4556-7 notselected CCE-4556-7 notselected CCE-4076-6 notselected CCE-4454-5 notselected CCE-4459-4 notselected CCE-4503-9 notselected CCE-4353-9 notselected CCE-4419-8 notselected CCE-3692-1 notselected CCE-4476-8 notselected CCE-3585-7 notselected CCE-4344-8 notselected CCE-4494-1 notselected CCE-4181-4 notselected CCE-4577-3 notselected CCE-4511-2 notselected CCE-4529-4 notselected CCE-3610-3 notselected CCE-4466-9 notselected CCE-4607-8 notselected CCE-4255-6 notselected CCE-4127-7 notselected CCE-4519-5 notselected CCE-4413-1 notselected CCE-4373-7 notselected CCE-3765-5 notselected CCE-4404-0 notselected notselected CCE-4148-3 notselected CCE-4254-9 notselected CCE-4416-4 notselected CCE-4484-2 notselected CCE-4502-1 notselected CCE-4550-0 2.303659 620.000000