|
Packit Service |
39273c |
|
|
Packit Service |
39273c |
|
|
Packit Service |
39273c |
id="xccdf_moc.elpmaxe.www_benchmark_test" resolved="1">
|
|
Packit Service |
39273c |
<status>accepted</status>
|
|
Packit Service |
39273c |
<version>1.0</version>
|
|
Packit Service |
39273c |
<model system="urn:xccdf:scoring:default"/>
|
|
Packit Service |
39273c |
<Profile id="xccdf_moc.elpmaxe.www_profile_1">
|
|
Packit Service |
39273c |
<title>Some arbitrary hardening profile for anaconda testing</title>
|
|
Packit Service |
39273c |
<select idref="xccdf_moc.elpmaxe.www_group_1" selected="true"/>
|
|
Packit Service |
39273c |
<select idref="xccdf_moc.elpmaxe.www_rule_3" selected="true"/>
|
|
Packit Service |
39273c |
<refine-value idref="xccdf_moc.elpmaxe.www_value_1" selector="len14"/>
|
|
Packit Service |
39273c |
</Profile>
|
|
Packit Service |
39273c |
<Rule id="xccdf_moc.elpmaxe.www_rule_1" selected="true">
|
|
Packit Service |
39273c |
<title>Ensure /tmp Located On Separate Partition</title>
|
|
Packit Service |
39273c |
<ident system="http://cce.mitre.org">CCE-14161-4</ident>
|
|
Packit Service |
39273c |
<fix id="partition_for_tmp_fix_anaconda_pre" system="urn:redhat:anaconda:pre">
|
|
Packit Service |
39273c |
|
|
Packit Service |
39273c |
part /tmp
|
|
Packit Service |
39273c |
</fix>
|
|
Packit Service |
39273c |
</Rule>
|
|
Packit Service |
39273c |
<Rule id="xccdf_moc.elpmaxe.www_rule_2" selected="true">
|
|
Packit Service |
39273c |
<title>Add nodev Option to /tmp</title>
|
|
Packit Service |
39273c |
<ident system="http://cce.mitre.org">CCE-14412-1</ident>
|
|
Packit Service |
39273c |
<fix id="mount_option_tmp_fix_anaconda_pre" system="urn:redhat:anaconda:pre">
|
|
Packit Service |
39273c |
part /tmp --mountoptions=nodev
|
|
Packit Service |
39273c |
</fix>
|
|
Packit Service |
39273c |
<fix id="mount_option_tmp_fix" system="urn:xccdf:script:sh">
|
|
Packit Service |
39273c |
|
|
Packit Service |
39273c |
grep -e '^[^#].*/tmp.*nodev' /etc/fstab
|
|
Packit Service |
39273c |
if [ "$?" -ne 0 ]; then
|
|
Packit Service |
39273c |
new_fstab=$(cat /etc/fstab | sed -e 's%^[^#]([^ ]+)\s+/tmp([^ ]+)\s+([^ ]+)\s+(\d)\s+(\d)%\1\t/tmp\2\t\3,nodev\t\4 \5'
|
|
Packit Service |
39273c |
echo $new_fstab > /etc/fstab
|
|
Packit Service |
39273c |
fi
|
|
Packit Service |
39273c |
</fix>
|
|
Packit Service |
39273c |
</Rule>
|
|
Packit Service |
39273c |
<Group id="xccdf_moc.elpmaxe.www_group_1" selected="false">
|
|
Packit Service |
39273c |
<Value id="xccdf_moc.elpmaxe.www_value_1">
|
|
Packit Service |
39273c |
<title>Minimal password length</title>
|
|
Packit Service |
39273c |
<value selector="len8">8</value>
|
|
Packit Service |
39273c |
<value selector="len14">14</value>
|
|
Packit Service |
39273c |
<value selector="len18">18</value>
|
|
Packit Service |
39273c |
</Value>
|
|
Packit Service |
39273c |
<Rule id="xccdf_moc.elpmaxe.www_rule_3">
|
|
Packit Service |
39273c |
<title>Set Password Minimum Length in login.defs</title>
|
|
Packit Service |
39273c |
<fix xmlns:xhtml="http://www.w3.org/1999/xhtml" system="urn:redhat:anaconda:pre">
|
|
Packit Service |
39273c |
|
|
Packit Service |
39273c |
passwd --minlen=<sub idref="xccdf_moc.elpmaxe.www_value_1"/>
|
|
Packit Service |
39273c |
</fix>
|
|
Packit Service |
39273c |
<fix id="password_min_len_fix" system="urn:xccdf:script:python">
|
|
Packit Service |
39273c |
|
|
Packit Service |
39273c |
|
|
Packit Service |
39273c |
PASS_MIN_LEN=<sub idref="xccdf_moc.elpmaxe.www_value_1"/> in /etc/login.defs
|
|
Packit Service |
39273c |
and
|
|
Packit Service |
39273c |
minlen=<sub idref="xccdf_moc.elpmaxe.www_value_1"/> in /etc/security/pwquality.conf
|
|
Packit Service |
39273c |
-->
|
|
Packit Service |
39273c |
</fix>
|
|
Packit Service |
39273c |
</Rule>
|
|
Packit Service |
39273c |
</Group>
|
|
Packit Service |
39273c |
</Benchmark>
|