Skip to content

Commit

Permalink
Remove vmmsrg references from rules
Browse files Browse the repository at this point in the history
This SRG was removed in 2015.
  • Loading branch information
Mab879 committed Mar 14, 2023
1 parent d4d6c97 commit 5ae4bfd
Show file tree
Hide file tree
Showing 190 changed files with 17 additions and 207 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -105,7 +105,6 @@ references:
nist: CM-6(a),AU-8(1)(a),AU-8(2),AU-12(1)
nist-csf: PR.PT-1
pcidss: Req-10.4.1,Req-10.4.3
vmmsrg: SRG-OS-000355-VMM-001330

ocil_clause: 'this is not the case'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,6 @@ references:
nist: CM-6(a),AU-8(1)(a),AU-12(1)
nist-csf: PR.PT-1
pcidss: Req-10.4.1
vmmsrg: SRG-OS-000356-VMM-001340

ocil: |-
{{{ ocil_service_enabled(service="chronyd") }}}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,6 @@ references:
cis@sle12: 2.2.15
cis@sle15: 2.2.15
ism: "1311"
vmmsrg: SRG-OS-000480-VMM-002000

ocil_clause: |-
{{{ ocil_clause_service_disabled(service="snmpd") }}}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,6 @@ references:
srg: SRG-OS-000480-GPOS-00229
stigid@ol7: OL07-00-010470
stigid@rhel7: RHEL-07-010470
vmmsrg: SRG-OS-000480-VMM-002000

{{{ complete_ocil_entry_sshd_option(default="yes", option="HostbasedAuthentication", value="no") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,6 @@ references:
srg: SRG-OS-000074-GPOS-00042,SRG-OS-000480-GPOS-00227
stigid@ol7: OL07-00-040390
stigid@rhel7: RHEL-07-040390
vmmsrg: SRG-OS-000033-VMM-000140

ocil_clause: 'it is commented out or is not set correctly to Protocol 2'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,6 @@ references:
stigid@rhel7: RHEL-07-040470
stigid@sle12: SLES-12-030250
stigid@sle15: SLES-15-040280
vmmsrg: SRG-OS-000480-VMM-002000

ocil_clause: 'it is commented out, or is not set to no or delayed'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -62,7 +62,6 @@ references:
stigid@sle12: SLES-12-030150
stigid@sle15: SLES-15-040440
stigid@ubuntu2004: UBTU-20-010047
vmmsrg: SRG-OS-000480-VMM-002000

{{{ complete_ocil_entry_sshd_option(default="yes", option="PermitEmptyPasswords", value="no") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,6 @@ references:
stigid@ol8: OL08-00-010522
stigid@rhel7: RHEL-07-040430
stigid@rhel8: RHEL-08-010522
vmmsrg: SRG-OS-000480-VMM-002000

{{{ complete_ocil_entry_sshd_option(default="yes", option="GSSAPIAuthentication", value="no") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,8 +16,8 @@ description: |-
rationale: |-
Kerberos authentication for SSH is often implemented using GSSAPI. If Kerberos
is enabled through SSH, the SSH daemon provides a means of access to the
system's Kerberos implementation.
Configuring these settings for the SSH daemon provides additional assurance that remote logon via SSH will not use unused methods of authentication, even in the event of misconfiguration elsewhere.
system's Kerberos implementation.
Configuring these settings for the SSH daemon provides additional assurance that remote logon via SSH will not use unused methods of authentication, even in the event of misconfiguration elsewhere.
severity: medium

Expand Down Expand Up @@ -45,7 +45,6 @@ references:
stigid@ol8: OL08-00-010521
stigid@rhel7: RHEL-07-040440
stigid@rhel8: RHEL-08-010521
vmmsrg: SRG-OS-000480-VMM-002000

{{{ complete_ocil_entry_sshd_option(default="yes", option="KerberosAuthentication", value="no") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,6 @@ references:
srg: SRG-OS-000480-GPOS-00227
stigid@ol7: OL07-00-040350
stigid@rhel7: RHEL-07-040350
vmmsrg: SRG-OS-000107-VMM-000530

{{{ complete_ocil_entry_sshd_option(default="yes", option="IgnoreRhosts", value="yes") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,6 @@ references:
stigid@rhel8: RHEL-08-010550
stigid@sle12: SLES-12-030140
stigid@sle15: SLES-15-020040
vmmsrg: SRG-OS-000480-VMM-002000

{{{ complete_ocil_entry_sshd_option(default="no", option="PermitRootLogin", value="no") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,6 @@ references:
stigid@sle12: SLES-12-030151
stigid@sle15: SLES-15-040440
stigid@ubuntu2004: UBTU-20-010047
vmmsrg: SRG-OS-000480-VMM-002000

{{{ complete_ocil_entry_sshd_option(default="yes", option="PermitUserEnvironment", value="no") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,6 @@ references:
stigid@rhel8: RHEL-08-010500
stigid@sle12: SLES-12-030230
stigid@sle15: SLES-15-040260
vmmsrg: SRG-OS-000480-VMM-002000

{{{ complete_ocil_entry_sshd_option(default="yes", option="StrictModes", value="yes") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,6 @@ references:
stigid@rhel8: RHEL-08-010040
stigid@sle12: SLES-12-030050
stigid@sle15: SLES-15-010040
vmmsrg: SRG-OS-000023-VMM-000060,SRG-OS-000024-VMM-000070

{{{ complete_ocil_entry_sshd_option(default="no", option="Banner", value="/etc/issue") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,6 @@ references:
ospp: FTA_TAB.1
srg: SRG-OS-000023-GPOS-00006,SRG-OS-000228-GPOS-00088
stigid@ubuntu2004: UBTU-20-010038
vmmsrg: SRG-OS-000023-VMM-000060,SRG-OS-000024-VMM-000070

{{{ complete_ocil_entry_sshd_option(default="no", option="Banner", value="/etc/issue.net") }}}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -68,7 +68,6 @@ references:
stigid@sle12: SLES-12-030190
stigid@sle15: SLES-15-010280
stigid@ubuntu2004: UBTU-20-010037
vmmsrg: SRG-OS-000480-VMM-002000

requires:
{{% if product in ['ubuntu2004', 'ubuntu2204'] %}}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,6 @@ references:
stigid@rhel8: RHEL-08-010200
stigid@sle12: SLES-12-030191
stigid@ubuntu2004: UBTU-20-010036
vmmsrg: SRG-OS-000480-VMM-002000

requires:
- sshd_set_idle_timeout
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,6 @@ references:
stigid@rhel7: RHEL-07-040340
stigid@sle12: SLES-12-030191
stigid@sle15: SLES-15-010320
vmmsrg: SRG-OS-000480-VMM-002000

requires:
- sshd_set_idle_timeout
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -73,7 +73,6 @@ references:
srg: SRG-OS-000033-GPOS-00014,SRG-OS-000120-GPOS-00061,SRG-OS-000125-GPOS-00065,SRG-OS-000250-GPOS-00093,SRG-OS-000393-GPOS-00173,SRG-OS-000394-GPOS-00174
stigid@sle12: SLES-12-030170
stigid@sle15: SLES-15-010160
vmmsrg: SRG-OS-000033-VMM-000140,SRG-OS-000120-VMM-000600,SRG-OS-000478-VMM-001980,SRG-OS-000396-VMM-001590

ocil_clause: 'FIPS ciphers are not configured or the enabled ciphers are not FIPS-approved'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,6 @@ references:
srg: SRG-OS-000125-GPOS-00065,SRG-OS-000250-GPOS-00093,SRG-OS-000394-GPOS-00174
stigid@sle12: SLES-12-030180
stigid@sle15: SLES-15-010270
vmmsrg: SRG-OS-000033-VMM-000140,SRG-OS-000120-VMM-000600,SRG-OS-000478-VMM-001980,SRG-OS-000480-VMM-002000,SRG-OS-000396-VMM-001590

ocil_clause: 'MACs option is commented out or not using FIPS-approved hash algorithms'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,6 @@ references:
srg: SRG-OS-000375-GPOS-00160,SRG-OS-000376-GPOS-00161,SRG-OS-000377-GPOS-00162
stigid@ol7: OL07-00-041002
stigid@rhel7: RHEL-07-041002
vmmsrg: SRG-OS-000107-VMM-000530

ocil_clause: 'it does not exist or ''pam'' is not added to the ''services'' option under the ''sssd'' section'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,6 @@ references:
srg: SRG-OS-000375-GPOS-00160,SRG-OS-000105-GPOS-00052,SRG-OS-000106-GPOS-00053,SRG-OS-000107-GPOS-00054,SRG-OS-000108-GPOS-00055
stigid@ol8: OL08-00-020250
stigid@rhel8: RHEL-08-020250
vmmsrg: SRG-OS-000107-VMM-000530

ocil_clause: 'smart cards are not enabled in SSSD'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,6 @@ references:
srg: SRG-OS-000383-GPOS-00166
stigid@sle12: SLES-12-010670
stigid@sle15: SLES-15-010490
vmmsrg: SRG-OS-000383-VMM-001570

ocil_clause: 'it does not exist or is not configured properly'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -51,7 +51,6 @@ references:
stigid@sle12: SLES-12-010680
stigid@sle15: SLES-15-010500
stigid@ubuntu2004: UBTU-20-010441
vmmsrg: SRG-OS-000383-VMM-001570

ocil_clause: 'it does not exist or is not configured properly'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -122,7 +122,6 @@ references:
stigid@rhel8: RHEL-08-010060
stigid@sle12: SLES-12-010030
stigid@sle15: SLES-15-010020
vmmsrg: SRG-OS-000023-VMM-000060,SRG-OS-000024-VMM-000070

platform: machine

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -65,7 +65,6 @@ references:
stigid@ol8: OL08-00-020220
stigid@rhel7: RHEL-07-010270
stigid@rhel8: RHEL-08-020220
vmmsrg: SRG-OS-000077-VMM-000440

ocil_clause: |-
the pam_pwhistory.so module is not used, the "remember" module option is not set in
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -65,7 +65,6 @@ references:
stigid@ol8: OL08-00-020221
stigid@rhel7: RHEL-07-010270
stigid@rhel8: RHEL-08-020221
vmmsrg: SRG-OS-000077-VMM-000440

ocil_clause: |-
the pam_pwhistory.so module is not used, the "remember" module option is not set in
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,6 @@ references:
srg: SRG-OS-000077-GPOS-00045
stigid@sle15: SLES-15-020250
stigid@ubuntu2004: UBTU-20-010070
vmmsrg: SRG-OS-000077-VMM-000440

ocil_clause: 'the value of remember is not equal to or greater than the expected value'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,6 @@ references:
stigid@ol8: OL08-00-020010
stigid@rhel7: RHEL-07-010320
stigid@rhel8: RHEL-08-020011
vmmsrg: SRG-OS-000021-VMM-000050

platform: package[pam]

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,6 @@ references:
stigid@ol8: OL08-00-020012
stigid@rhel7: RHEL-07-010320
stigid@rhel8: RHEL-08-020012
vmmsrg: SRG-OS-000021-VMM-000050

platform: package[pam]

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,6 @@ references:
stigid@ol8: OL08-00-020014
stigid@rhel7: RHEL-07-010320
stigid@rhel8: RHEL-08-020016
vmmsrg: SRG-OS-000329-VMM-001180

platform: package[pam]

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -55,7 +55,6 @@ references:
stigid@rhel7: RHEL-07-010140
stigid@rhel8: RHEL-08-020130
stigid@ubuntu2004: UBTU-20-010052
vmmsrg: SRG-OS-000071-VMM-000380

ocil_clause: 'the value of "dcredit" is a positive number or is commented out'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,6 @@ references:
stigid@rhel7: RHEL-07-010160
stigid@rhel8: RHEL-08-020170
stigid@ubuntu2004: UBTU-20-010053
vmmsrg: SRG-OS-000072-VMM-000390

ocil_clause: 'the value of "difok" is set to less than "{{{ xccdf_value("var_password_pam_difok") }}}", or is commented out'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -55,7 +55,6 @@ references:
stigid@rhel7: RHEL-07-010130
stigid@rhel8: RHEL-08-020120
stigid@ubuntu2004: UBTU-20-010051
vmmsrg: SRG-OS-000070-VMM-000370

ocil_clause: 'the value of "lcredit" is a positive number or is commented out'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -58,7 +58,6 @@ references:
stigid@rhel7: RHEL-07-010280
stigid@rhel8: RHEL-08-020230
stigid@ubuntu2004: UBTU-20-010054
vmmsrg: SRG-OS-000072-VMM-000390,SRG-OS-000078-VMM-000450

ocil_clause: 'the command does not return a "minlen" value of "{{{ xccdf_value("var_password_pam_minlen") }}}" or greater, does not return a line, or the line is commented out'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,6 @@ references:
stigid@rhel7: RHEL-07-010150
stigid@rhel8: RHEL-08-020280
stigid@ubuntu2004: UBTU-20-010055
vmmsrg: SRG-OS-000266-VMM-000940

ocil_clause: 'value of "ocredit" is a positive number or is commented out'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,6 @@ references:
stigid@rhel7: RHEL-07-010120
stigid@rhel8: RHEL-08-020110
stigid@ubuntu2004: UBTU-20-010050
vmmsrg: SRG-OS-000069-VMM-000360

ocil_clause: 'the value of "ucredit" is a positive number or is commented out'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,6 @@ references:
nist: IA-7,IA-7.1
pcidss: Req-8.2.1
srg: SRG-OS-000120-GPOS-00061
vmmsrg: SRG-OS-000480-VMM-002000

ocil_clause: 'it does not'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,6 @@ references:
srg: SRG-OS-000073-GPOS-00041
stigid@ol7: OL07-00-010220
stigid@rhel7: RHEL-07-010220
vmmsrg: SRG-OS-000480-VMM-002000

ocil_clause: crypt_style is not set to sha512

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -62,7 +62,6 @@ references:
stigid@ol8: OL08-00-010160
stigid@rhel7: RHEL-07-010200
stigid@rhel8: RHEL-08-010160
vmmsrg: SRG-OS-000480-VMM-002000

ocil_clause: 'it does not'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -76,7 +76,6 @@ references:
stigid@rhel8: RHEL-08-010159
stigid@sle12: SLES-12-010230
stigid@sle15: SLES-15-020170
vmmsrg: SRG-OS-000480-VMM-002000

ocil_clause: '"sha512" is missing, or is commented out'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,6 @@ references:
nist-csf: DE.CM-1,DE.CM-3,PR.AC-1,PR.AC-4,PR.AC-6,PR.AC-7,PR.IP-2
ospp: FMT_SMF_EXT.1.1
pcidss: Req-8.1.8
vmmsrg: SRG-OS-000480-VMM-002000

ocil_clause: "the option is not configured"

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,6 @@ references:
srg: SRG-OS-000028-GPOS-00009,SRG-OS-000030-GPOS-00011
stigid@ol8: OL08-00-020040
stigid@rhel8: RHEL-08-020040
vmmsrg: SRG-OS-000028-VMM-000090,SRG-OS-000030-VMM-000110

ocil_clause: 'the "lock-command" is not set in the global settings to call "vlock"'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,6 @@ references:
srg: SRG-OS-000029-GPOS-00010
stigid@ol7: OL07-00-010090
stigid@rhel7: RHEL-07-010090
vmmsrg: SRG-OS-000030-VMM-000110

ocil_clause: 'the package is not installed'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,6 @@ references:
srg: SRG-OS-000030-GPOS-00011,SRG-OS-000028-GPOS-00009
stigid@ol8: OL08-00-020039
stigid@rhel8: RHEL-08-020039
vmmsrg: SRG-OS-000030-VMM-000110

ocil_clause: 'the package is not installed'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,6 @@ references:
nist-csf: PR.AC-1,PR.AC-6,PR.AC-7
pcidss: Req-8.3
srg: SRG-OS-000104-GPOS-00051,SRG-OS-000106-GPOS-00053,SRG-OS-000107-GPOS-00054,SRG-OS-000109-GPOS-00056,SRG-OS-000108-GPOS-00055,SRG-OS-000108-GPOS-00057,SRG-OS-000108-GPOS-00058
vmmsrg: SRG-OS-000376-VMM-001520

ocil_clause: '"{{{ xccdf_value("var_smartcard_drivers") }}}" is not listed as a card driver, or there is no line returned for "card_drivers"'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,6 @@ references:
nist-csf: PR.AC-1,PR.AC-6,PR.AC-7
pcidss: Req-8.3
srg: SRG-OS-000104-GPOS-00051,SRG-OS-000106-GPOS-00053,SRG-OS-000107-GPOS-00054,SRG-OS-000109-GPOS-00056,SRG-OS-000108-GPOS-00055,SRG-OS-000108-GPOS-00057,SRG-OS-000108-GPOS-00058
vmmsrg: SRG-OS-000376-VMM-001520,SRG-OS-000403-VMM-001640

ocil_clause: 'opensc is not in use by the nss database'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,6 @@ references:
nist-csf: PR.AC-1,PR.AC-6,PR.AC-7
pcidss: Req-8.3
srg: SRG-OS-000104-GPOS-00051,SRG-OS-000106-GPOS-00053,SRG-OS-000107-GPOS-00054,SRG-OS-000109-GPOS-00056,SRG-OS-000108-GPOS-00055,SRG-OS-000108-GPOS-00057,SRG-OS-000108-GPOS-00058
vmmsrg: SRG-OS-000376-VMM-001520

ocil_clause: 'the smart card driver is not configured correctly'

Expand Down
Loading

0 comments on commit 5ae4bfd

Please sign in to comment.