{
  "platform": {
    "name": "centos",
    "release": "7.6.1810"
  },
  "profiles": [
    {
      "name": "disa_stig-el7",
      "version": "0.2.0",
      "sha256": "d4ecb3e201285a383a4aa6af8d9028e8311cb1975af2b380f098a21c895246ff",
      "title": "DISA RedHat Enterprise Linux 7 STIG - v1r4",
      "maintainer": "SIMP Team",
      "summary": "The `disa_stig-el7` inspec profile helps scan your system aginst the DISA RHEL7 STIG",
      "license": "Apache-2.0",
      "copyright": "SIMP Team",
      "copyright_email": "simp-dev@googlegroups.com",
      "supports": [],
      "attributes": [],
      "groups": [
        {
          "id": "controls/V-71849.rb",
          "controls": [
            "V-71849"
          ]
        },
        {
          "id": "controls/V-71855.rb",
          "controls": [
            "V-71855"
          ]
        },
        {
          "id": "controls/V-71859.rb",
          "controls": [
            "V-71859"
          ]
        },
        {
          "id": "controls/V-71861.rb",
          "controls": [
            "V-71861"
          ]
        },
        {
          "id": "controls/V-71863.rb",
          "controls": [
            "V-71863"
          ]
        },
        {
          "id": "controls/V-71891.rb",
          "controls": [
            "V-71891"
          ]
        },
        {
          "id": "controls/V-71893.rb",
          "controls": [
            "V-71893"
          ]
        },
        {
          "id": "controls/V-71895.rb",
          "controls": [
            "V-71895"
          ]
        },
        {
          "id": "controls/V-71897.rb",
          "controls": [
            "V-71897"
          ]
        },
        {
          "id": "controls/V-71899.rb",
          "controls": [
            "V-71899"
          ]
        },
        {
          "id": "controls/V-71901.rb",
          "controls": [
            "V-71901"
          ]
        },
        {
          "id": "controls/V-71903.rb",
          "controls": [
            "V-71903"
          ]
        },
        {
          "id": "controls/V-71905.rb",
          "controls": [
            "V-71905"
          ]
        },
        {
          "id": "controls/V-71907.rb",
          "controls": [
            "V-71907"
          ]
        },
        {
          "id": "controls/V-71909.rb",
          "controls": [
            "V-71909"
          ]
        },
        {
          "id": "controls/V-71911.rb",
          "controls": [
            "V-71911"
          ]
        },
        {
          "id": "controls/V-71913.rb",
          "controls": [
            "V-71913"
          ]
        },
        {
          "id": "controls/V-71915.rb",
          "controls": [
            "V-71915"
          ]
        },
        {
          "id": "controls/V-71917.rb",
          "controls": [
            "V-71917"
          ]
        },
        {
          "id": "controls/V-71919.rb",
          "controls": [
            "V-71919"
          ]
        },
        {
          "id": "controls/V-71921.rb",
          "controls": [
            "V-71921"
          ]
        },
        {
          "id": "controls/V-71923.rb",
          "controls": [
            "V-71923"
          ]
        },
        {
          "id": "controls/V-71925.rb",
          "controls": [
            "V-71925"
          ]
        },
        {
          "id": "controls/V-71927.rb",
          "controls": [
            "V-71927"
          ]
        },
        {
          "id": "controls/V-71929.rb",
          "controls": [
            "V-71929"
          ]
        },
        {
          "id": "controls/V-71931.rb",
          "controls": [
            "V-71931"
          ]
        },
        {
          "id": "controls/V-71933.rb",
          "controls": [
            "V-71933"
          ]
        },
        {
          "id": "controls/V-71935.rb",
          "controls": [
            "V-71935"
          ]
        },
        {
          "id": "controls/V-71937.rb",
          "controls": [
            "V-71937"
          ]
        },
        {
          "id": "controls/V-71939.rb",
          "controls": [
            "V-71939"
          ]
        },
        {
          "id": "controls/V-71941.rb",
          "controls": [
            "V-71941"
          ]
        },
        {
          "id": "controls/V-71943.rb",
          "controls": [
            "V-71943"
          ]
        },
        {
          "id": "controls/V-71945.rb",
          "controls": [
            "V-71945"
          ]
        },
        {
          "id": "controls/V-71947.rb",
          "controls": [
            "V-71947"
          ]
        },
        {
          "id": "controls/V-71949.rb",
          "controls": [
            "V-71949"
          ]
        },
        {
          "id": "controls/V-71951.rb",
          "controls": [
            "V-71951"
          ]
        },
        {
          "id": "controls/V-71953.rb",
          "controls": [
            "V-71953"
          ]
        },
        {
          "id": "controls/V-71955.rb",
          "controls": [
            "V-71955"
          ]
        },
        {
          "id": "controls/V-71957.rb",
          "controls": [
            "V-71957"
          ]
        },
        {
          "id": "controls/V-71959.rb",
          "controls": [
            "V-71959"
          ]
        },
        {
          "id": "controls/V-71961.rb",
          "controls": [
            "V-71961"
          ]
        },
        {
          "id": "controls/V-71963.rb",
          "controls": [
            "V-71963"
          ]
        },
        {
          "id": "controls/V-71965.rb",
          "controls": [
            "V-71965"
          ]
        },
        {
          "id": "controls/V-71967.rb",
          "controls": [
            "V-71967"
          ]
        },
        {
          "id": "controls/V-71969.rb",
          "controls": [
            "V-71969"
          ]
        },
        {
          "id": "controls/V-71971.rb",
          "controls": [
            "V-71971"
          ]
        },
        {
          "id": "controls/V-71973.rb",
          "controls": [
            "V-71973"
          ]
        },
        {
          "id": "controls/V-71975.rb",
          "controls": [
            "V-71975"
          ]
        },
        {
          "id": "controls/V-71977.rb",
          "controls": [
            "V-71977"
          ]
        },
        {
          "id": "controls/V-71979.rb",
          "controls": [
            "V-71979"
          ]
        },
        {
          "id": "controls/V-71981.rb",
          "controls": [
            "V-71981"
          ]
        },
        {
          "id": "controls/V-71983.rb",
          "controls": [
            "V-71983"
          ]
        },
        {
          "id": "controls/V-71985.rb",
          "controls": [
            "V-71985"
          ]
        },
        {
          "id": "controls/V-71987.rb",
          "controls": [
            "V-71987"
          ]
        },
        {
          "id": "controls/V-71989.rb",
          "controls": [
            "V-71989"
          ]
        },
        {
          "id": "controls/V-71991.rb",
          "controls": [
            "V-71991"
          ]
        },
        {
          "id": "controls/V-71993.rb",
          "controls": [
            "V-71993"
          ]
        },
        {
          "id": "controls/V-71995.rb",
          "controls": [
            "V-71995"
          ]
        },
        {
          "id": "controls/V-71997.rb",
          "controls": [
            "V-71997"
          ]
        },
        {
          "id": "controls/V-71999.rb",
          "controls": [
            "V-71999"
          ]
        },
        {
          "id": "controls/V-72001.rb",
          "controls": [
            "V-72001"
          ]
        },
        {
          "id": "controls/V-72003.rb",
          "controls": [
            "V-72003"
          ]
        },
        {
          "id": "controls/V-72005.rb",
          "controls": [
            "V-72005"
          ]
        },
        {
          "id": "controls/V-72007.rb",
          "controls": [
            "V-72007"
          ]
        },
        {
          "id": "controls/V-72009.rb",
          "controls": [
            "V-72009"
          ]
        },
        {
          "id": "controls/V-72011.rb",
          "controls": [
            "V-72011"
          ]
        },
        {
          "id": "controls/V-72013.rb",
          "controls": [
            "V-72013"
          ]
        },
        {
          "id": "controls/V-72015.rb",
          "controls": [
            "V-72015"
          ]
        },
        {
          "id": "controls/V-72017.rb",
          "controls": [
            "V-72017"
          ]
        },
        {
          "id": "controls/V-72019.rb",
          "controls": [
            "V-72019"
          ]
        },
        {
          "id": "controls/V-72021.rb",
          "controls": [
            "V-72021"
          ]
        },
        {
          "id": "controls/V-72023.rb",
          "controls": [
            "V-72023"
          ]
        },
        {
          "id": "controls/V-72025.rb",
          "controls": [
            "V-72025"
          ]
        },
        {
          "id": "controls/V-72027.rb",
          "controls": [
            "V-72027"
          ]
        },
        {
          "id": "controls/V-72029.rb",
          "controls": [
            "V-72029"
          ]
        },
        {
          "id": "controls/V-72031.rb",
          "controls": [
            "V-72031"
          ]
        },
        {
          "id": "controls/V-72033.rb",
          "controls": [
            "V-72033"
          ]
        },
        {
          "id": "controls/V-72035.rb",
          "controls": [
            "V-72035"
          ]
        },
        {
          "id": "controls/V-72037.rb",
          "controls": [
            "V-72037"
          ]
        },
        {
          "id": "controls/V-72039.rb",
          "controls": [
            "V-72039"
          ]
        },
        {
          "id": "controls/V-72041.rb",
          "controls": [
            "V-72041"
          ]
        },
        {
          "id": "controls/V-72043.rb",
          "controls": [
            "V-72043"
          ]
        },
        {
          "id": "controls/V-72045.rb",
          "controls": [
            "V-72045"
          ]
        },
        {
          "id": "controls/V-72047.rb",
          "controls": [
            "V-72047"
          ]
        },
        {
          "id": "controls/V-72049.rb",
          "controls": [
            "V-72049"
          ]
        },
        {
          "id": "controls/V-72051.rb",
          "controls": [
            "V-72051"
          ]
        },
        {
          "id": "controls/V-72053.rb",
          "controls": [
            "V-72053"
          ]
        },
        {
          "id": "controls/V-72055.rb",
          "controls": [
            "V-72055"
          ]
        },
        {
          "id": "controls/V-72057.rb",
          "controls": [
            "V-72057"
          ]
        },
        {
          "id": "controls/V-72059.rb",
          "controls": [
            "V-72059"
          ]
        },
        {
          "id": "controls/V-72061.rb",
          "controls": [
            "V-72061"
          ]
        },
        {
          "id": "controls/V-72063.rb",
          "controls": [
            "V-72063"
          ]
        },
        {
          "id": "controls/V-72065.rb",
          "controls": [
            "V-72065"
          ]
        },
        {
          "id": "controls/V-72067.rb",
          "controls": [
            "V-72067"
          ]
        },
        {
          "id": "controls/V-72069.rb",
          "controls": [
            "V-72069"
          ]
        },
        {
          "id": "controls/V-72071.rb",
          "controls": [
            "V-72071"
          ]
        },
        {
          "id": "controls/V-72073.rb",
          "controls": [
            "V-72073"
          ]
        },
        {
          "id": "controls/V-72075.rb",
          "controls": [
            "V-72075"
          ]
        },
        {
          "id": "controls/V-72077.rb",
          "controls": [
            "V-72077"
          ]
        },
        {
          "id": "controls/V-72079.rb",
          "controls": [
            "V-72079"
          ]
        },
        {
          "id": "controls/V-72081.rb",
          "controls": [
            "V-72081"
          ]
        },
        {
          "id": "controls/V-72083.rb",
          "controls": [
            "V-72083"
          ]
        },
        {
          "id": "controls/V-72085.rb",
          "controls": [
            "V-72085"
          ]
        },
        {
          "id": "controls/V-72087.rb",
          "controls": [
            "V-72087"
          ]
        },
        {
          "id": "controls/V-72089.rb",
          "controls": [
            "V-72089"
          ]
        },
        {
          "id": "controls/V-72091.rb",
          "controls": [
            "V-72091"
          ]
        },
        {
          "id": "controls/V-72093.rb",
          "controls": [
            "V-72093"
          ]
        },
        {
          "id": "controls/V-72095.rb",
          "controls": [
            "V-72095"
          ]
        },
        {
          "id": "controls/V-72097.rb",
          "controls": [
            "V-72097"
          ]
        },
        {
          "id": "controls/V-72099.rb",
          "controls": [
            "V-72099"
          ]
        },
        {
          "id": "controls/V-72101.rb",
          "controls": [
            "V-72101"
          ]
        },
        {
          "id": "controls/V-72103.rb",
          "controls": [
            "V-72103"
          ]
        },
        {
          "id": "controls/V-72105.rb",
          "controls": [
            "V-72105"
          ]
        },
        {
          "id": "controls/V-72107.rb",
          "controls": [
            "V-72107"
          ]
        },
        {
          "id": "controls/V-72109.rb",
          "controls": [
            "V-72109"
          ]
        },
        {
          "id": "controls/V-72111.rb",
          "controls": [
            "V-72111"
          ]
        },
        {
          "id": "controls/V-72113.rb",
          "controls": [
            "V-72113"
          ]
        },
        {
          "id": "controls/V-72115.rb",
          "controls": [
            "V-72115"
          ]
        },
        {
          "id": "controls/V-72117.rb",
          "controls": [
            "V-72117"
          ]
        },
        {
          "id": "controls/V-72119.rb",
          "controls": [
            "V-72119"
          ]
        },
        {
          "id": "controls/V-72121.rb",
          "controls": [
            "V-72121"
          ]
        },
        {
          "id": "controls/V-72123.rb",
          "controls": [
            "V-72123"
          ]
        },
        {
          "id": "controls/V-72125.rb",
          "controls": [
            "V-72125"
          ]
        },
        {
          "id": "controls/V-72127.rb",
          "controls": [
            "V-72127"
          ]
        },
        {
          "id": "controls/V-72129.rb",
          "controls": [
            "V-72129"
          ]
        },
        {
          "id": "controls/V-72131.rb",
          "controls": [
            "V-72131"
          ]
        },
        {
          "id": "controls/V-72133.rb",
          "controls": [
            "V-72133"
          ]
        },
        {
          "id": "controls/V-72135.rb",
          "controls": [
            "V-72135"
          ]
        },
        {
          "id": "controls/V-72137.rb",
          "controls": [
            "V-72137"
          ]
        },
        {
          "id": "controls/V-72139.rb",
          "controls": [
            "V-72139"
          ]
        },
        {
          "id": "controls/V-72141.rb",
          "controls": [
            "V-72141"
          ]
        },
        {
          "id": "controls/V-72143.rb",
          "controls": [
            "V-72143"
          ]
        },
        {
          "id": "controls/V-72145.rb",
          "controls": [
            "V-72145"
          ]
        },
        {
          "id": "controls/V-72147.rb",
          "controls": [
            "V-72147"
          ]
        },
        {
          "id": "controls/V-72149.rb",
          "controls": [
            "V-72149"
          ]
        },
        {
          "id": "controls/V-72151.rb",
          "controls": [
            "V-72151"
          ]
        },
        {
          "id": "controls/V-72153.rb",
          "controls": [
            "V-72153"
          ]
        },
        {
          "id": "controls/V-72155.rb",
          "controls": [
            "V-72155"
          ]
        },
        {
          "id": "controls/V-72157.rb",
          "controls": [
            "V-72157"
          ]
        },
        {
          "id": "controls/V-72159.rb",
          "controls": [
            "V-72159"
          ]
        },
        {
          "id": "controls/V-72161.rb",
          "controls": [
            "V-72161"
          ]
        },
        {
          "id": "controls/V-72163.rb",
          "controls": [
            "V-72163"
          ]
        },
        {
          "id": "controls/V-72165.rb",
          "controls": [
            "V-72165"
          ]
        },
        {
          "id": "controls/V-72167.rb",
          "controls": [
            "V-72167"
          ]
        },
        {
          "id": "controls/V-72169.rb",
          "controls": [
            "V-72169"
          ]
        },
        {
          "id": "controls/V-72171.rb",
          "controls": [
            "V-72171"
          ]
        },
        {
          "id": "controls/V-72173.rb",
          "controls": [
            "V-72173"
          ]
        },
        {
          "id": "controls/V-72175.rb",
          "controls": [
            "V-72175"
          ]
        },
        {
          "id": "controls/V-72177.rb",
          "controls": [
            "V-72177"
          ]
        },
        {
          "id": "controls/V-72179.rb",
          "controls": [
            "V-72179"
          ]
        },
        {
          "id": "controls/V-72181.rb",
          "controls": [
            "V-72181"
          ]
        },
        {
          "id": "controls/V-72183.rb",
          "controls": [
            "V-72183"
          ]
        },
        {
          "id": "controls/V-72185.rb",
          "controls": [
            "V-72185"
          ]
        },
        {
          "id": "controls/V-72187.rb",
          "controls": [
            "V-72187"
          ]
        },
        {
          "id": "controls/V-72189.rb",
          "controls": [
            "V-72189"
          ]
        },
        {
          "id": "controls/V-72191.rb",
          "controls": [
            "V-72191"
          ]
        },
        {
          "id": "controls/V-72193.rb",
          "controls": [
            "V-72193"
          ]
        },
        {
          "id": "controls/V-72195.rb",
          "controls": [
            "V-72195"
          ]
        },
        {
          "id": "controls/V-72197.rb",
          "controls": [
            "V-72197"
          ]
        },
        {
          "id": "controls/V-72199.rb",
          "controls": [
            "V-72199"
          ]
        },
        {
          "id": "controls/V-72201.rb",
          "controls": [
            "V-72201"
          ]
        },
        {
          "id": "controls/V-72203.rb",
          "controls": [
            "V-72203"
          ]
        },
        {
          "id": "controls/V-72205.rb",
          "controls": [
            "V-72205"
          ]
        },
        {
          "id": "controls/V-72207.rb",
          "controls": [
            "V-72207"
          ]
        },
        {
          "id": "controls/V-72209.rb",
          "controls": [
            "V-72209"
          ]
        },
        {
          "id": "controls/V-72211.rb",
          "controls": [
            "V-72211"
          ]
        },
        {
          "id": "controls/V-72213.rb",
          "controls": [
            "V-72213"
          ]
        },
        {
          "id": "controls/V-72215.rb",
          "controls": [
            "V-72215"
          ]
        },
        {
          "id": "controls/V-72217.rb",
          "controls": [
            "V-72217"
          ]
        },
        {
          "id": "controls/V-72219.rb",
          "controls": [
            "V-72219"
          ]
        },
        {
          "id": "controls/V-72221.rb",
          "controls": [
            "V-72221"
          ]
        },
        {
          "id": "controls/V-72223.rb",
          "controls": [
            "V-72223"
          ]
        },
        {
          "id": "controls/V-72225.rb",
          "controls": [
            "V-72225"
          ]
        },
        {
          "id": "controls/V-72227.rb",
          "controls": [
            "V-72227"
          ]
        },
        {
          "id": "controls/V-72229.rb",
          "controls": [
            "V-72229"
          ]
        },
        {
          "id": "controls/V-72231.rb",
          "controls": [
            "V-72231"
          ]
        },
        {
          "id": "controls/V-72233.rb",
          "controls": [
            "V-72233"
          ]
        },
        {
          "id": "controls/V-72235.rb",
          "controls": [
            "V-72235"
          ]
        },
        {
          "id": "controls/V-72237.rb",
          "controls": [
            "V-72237"
          ]
        },
        {
          "id": "controls/V-72239.rb",
          "controls": [
            "V-72239"
          ]
        },
        {
          "id": "controls/V-72241.rb",
          "controls": [
            "V-72241"
          ]
        },
        {
          "id": "controls/V-72243.rb",
          "controls": [
            "V-72243"
          ]
        },
        {
          "id": "controls/V-72245.rb",
          "controls": [
            "V-72245"
          ]
        },
        {
          "id": "controls/V-72247.rb",
          "controls": [
            "V-72247"
          ]
        },
        {
          "id": "controls/V-72249.rb",
          "controls": [
            "V-72249"
          ]
        },
        {
          "id": "controls/V-72251.rb",
          "controls": [
            "V-72251"
          ]
        },
        {
          "id": "controls/V-72253.rb",
          "controls": [
            "V-72253"
          ]
        },
        {
          "id": "controls/V-72255.rb",
          "controls": [
            "V-72255"
          ]
        },
        {
          "id": "controls/V-72257.rb",
          "controls": [
            "V-72257"
          ]
        },
        {
          "id": "controls/V-72259.rb",
          "controls": [
            "V-72259"
          ]
        },
        {
          "id": "controls/V-72261.rb",
          "controls": [
            "V-72261"
          ]
        },
        {
          "id": "controls/V-72263.rb",
          "controls": [
            "V-72263"
          ]
        },
        {
          "id": "controls/V-72265.rb",
          "controls": [
            "V-72265"
          ]
        },
        {
          "id": "controls/V-72267.rb",
          "controls": [
            "V-72267"
          ]
        },
        {
          "id": "controls/V-72269.rb",
          "controls": [
            "V-72269"
          ]
        },
        {
          "id": "controls/V-72271.rb",
          "controls": [
            "V-72271"
          ]
        },
        {
          "id": "controls/V-72273.rb",
          "controls": [
            "V-72273"
          ]
        },
        {
          "id": "controls/V-72275.rb",
          "controls": [
            "V-72275"
          ]
        },
        {
          "id": "controls/V-72277.rb",
          "controls": [
            "V-72277"
          ]
        },
        {
          "id": "controls/V-72279.rb",
          "controls": [
            "V-72279"
          ]
        },
        {
          "id": "controls/V-72281.rb",
          "controls": [
            "V-72281"
          ]
        },
        {
          "id": "controls/V-72283.rb",
          "controls": [
            "V-72283"
          ]
        },
        {
          "id": "controls/V-72285.rb",
          "controls": [
            "V-72285"
          ]
        },
        {
          "id": "controls/V-72287.rb",
          "controls": [
            "V-72287"
          ]
        },
        {
          "id": "controls/V-72289.rb",
          "controls": [
            "V-72289"
          ]
        },
        {
          "id": "controls/V-72291.rb",
          "controls": [
            "V-72291"
          ]
        },
        {
          "id": "controls/V-72293.rb",
          "controls": [
            "V-72293"
          ]
        },
        {
          "id": "controls/V-72295.rb",
          "controls": [
            "V-72295"
          ]
        },
        {
          "id": "controls/V-72297.rb",
          "controls": [
            "V-72297"
          ]
        },
        {
          "id": "controls/V-72299.rb",
          "controls": [
            "V-72299"
          ]
        },
        {
          "id": "controls/V-72301.rb",
          "controls": [
            "V-72301"
          ]
        },
        {
          "id": "controls/V-72303.rb",
          "controls": [
            "V-72303"
          ]
        },
        {
          "id": "controls/V-72305.rb",
          "controls": [
            "V-72305"
          ]
        },
        {
          "id": "controls/V-72307.rb",
          "controls": [
            "V-72307"
          ]
        },
        {
          "id": "controls/V-72309.rb",
          "controls": [
            "V-72309"
          ]
        },
        {
          "id": "controls/V-72311.rb",
          "controls": [
            "V-72311"
          ]
        },
        {
          "id": "controls/V-72313.rb",
          "controls": [
            "V-72313"
          ]
        },
        {
          "id": "controls/V-72315.rb",
          "controls": [
            "V-72315"
          ]
        },
        {
          "id": "controls/V-72317.rb",
          "controls": [
            "V-72317"
          ]
        },
        {
          "id": "controls/V-72319.rb",
          "controls": [
            "V-72319"
          ]
        },
        {
          "id": "controls/V-72417.rb",
          "controls": [
            "V-72417"
          ]
        },
        {
          "id": "controls/V-72427.rb",
          "controls": [
            "V-72427"
          ]
        },
        {
          "id": "controls/V-72433.rb",
          "controls": [
            "V-72433"
          ]
        },
        {
          "id": "controls/V-72435.rb",
          "controls": [
            "V-72435"
          ]
        },
        {
          "id": "controls/V-73155.rb",
          "controls": [
            "V-73155"
          ]
        },
        {
          "id": "controls/V-73157.rb",
          "controls": [
            "V-73157"
          ]
        },
        {
          "id": "controls/V-73159.rb",
          "controls": [
            "V-73159"
          ]
        },
        {
          "id": "controls/V-73161.rb",
          "controls": [
            "V-73161"
          ]
        },
        {
          "id": "controls/V-73163.rb",
          "controls": [
            "V-73163"
          ]
        },
        {
          "id": "controls/V-73165.rb",
          "controls": [
            "V-73165"
          ]
        },
        {
          "id": "controls/V-73167.rb",
          "controls": [
            "V-73167"
          ]
        },
        {
          "id": "controls/V-73171.rb",
          "controls": [
            "V-73171"
          ]
        },
        {
          "id": "controls/V-73173.rb",
          "controls": [
            "V-73173"
          ]
        },
        {
          "id": "controls/V-73175.rb",
          "controls": [
            "V-73175"
          ]
        },
        {
          "id": "controls/V-73177.rb",
          "controls": [
            "V-73177"
          ]
        },
        {
          "id": "controls/V-77819.rb",
          "controls": [
            "V-77819"
          ]
        },
        {
          "id": "controls/V-77821.rb",
          "controls": [
            "V-77821"
          ]
        },
        {
          "id": "controls/V-77823.rb",
          "controls": [
            "V-77823"
          ]
        },
        {
          "id": "controls/V-77825.rb",
          "controls": [
            "V-77825"
          ]
        },
        {
          "id": "controls/V-78995.rb",
          "controls": [
            "V-78995"
          ]
        },
        {
          "id": "controls/V-78997.rb",
          "controls": [
            "V-78997"
          ]
        },
        {
          "id": "controls/V-78999.rb",
          "controls": [
            "V-78999"
          ]
        },
        {
          "id": "controls/V-79001.rb",
          "controls": [
            "V-79001"
          ]
        }
      ],
      "controls": [
        {
          "id": "V-71849",
          "title": "The file permissions, ownership, and group membership of system files and commands must match the vendor values.",
          "desc": "Discretionary access control is weakened if a user or group has access permissions to system files and directories greater than the default.",
          "descriptions": [
            {
              "label": "default",
              "data": "Discretionary access control is weakened if a user or group has access permissions to system files and directories greater than the default."
            },
            {
              "label": "check",
              "data": "Verify the file permissions, ownership, and group membership of\nsystem files and commands match the vendor values.\n\nCheck the file permissions, ownership, and group membership of system files and\ncommands with the following command:\n\n# rpm -Va | grep '^.M'\n\nIf there is any output from the command indicating that the ownership or group\nof a system file or command, or a system file, has permissions less restrictive\nthan the default, this is a finding."
            },
            {
              "label": "fix",
              "data": "Run the following command to determine which package owns the\nfile:\n\n# rpm -qf <filename>\n\nReset the permissions of files within a package with the following command:\n\n#rpm --setperms <packagename>\n\nReset the user and group ownership of files within a package with the following\ncommand:\n\n#rpm --setugids <packagename>"
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000257-GPOS-00098",
            "satisfies": [
              "SRG-OS-000257-GPOS-00098",
              "SRG-OS-000278-GPOS-00108"
            ],
            "gid": "V-71849",
            "rid": "SV-86473r2_rule",
            "stig_id": "RHEL-07-010010",
            "cci": [
              "CCI-001494",
              "CCI-001496"
            ],
            "documentable": false,
            "nist": [
              "AU-9",
              "AU-9 (3)",
              "Rev_4"
            ],
            "subsystems": [
              "permissions",
              "package",
              "rpm"
            ],
            "fix_id": "F-78201r3_fix"
          },
          "code": "control \"V-71849\" do\n  title \"The file permissions, ownership, and group membership of system files and commands must match the vendor\" \\\n        \" values.\"\n  desc  \"Discretionary access control is weakened if a user or group has access\" \\\n        \" permissions to system files and directories greater than the default.\"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000257-GPOS-00098\"\n  tag \"satisfies\": [\"SRG-OS-000257-GPOS-00098\", \"SRG-OS-000278-GPOS-00108\"]\n  tag \"gid\": \"V-71849\"\n  tag \"rid\": \"SV-86473r2_rule\"\n  tag \"stig_id\": \"RHEL-07-010010\"\n  tag \"cci\": [\"CCI-001494\", \"CCI-001496\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-9\", \"AU-9 (3)\", \"Rev_4\"]\n  tag \"subsystems\": [ \"permissions\", \"package\", \"rpm\" ]\n  desc \"check\", \"Verify the file permissions, ownership, and group membership of\nsystem files and commands match the vendor values.\n\nCheck the file permissions, ownership, and group membership of system files and\ncommands with the following command:\n\n# rpm -Va | grep '^.M'\n\nIf there is any output from the command indicating that the ownership or group\nof a system file or command, or a system file, has permissions less restrictive\nthan the default, this is a finding.\"\n  desc \"fix\", \"Run the following command to determine which package owns the\nfile:\n\n# rpm -qf <filename>\n\nReset the permissions of files within a package with the following command:\n\n#rpm --setperms <packagename>\n\nReset the user and group ownership of files within a package with the following\ncommand:\n\n#rpm --setugids <packagename>\"\n  tag \"fix_id\": \"F-78201r3_fix\"\n\n  if disable_slow_controls\n    describe \"This control consistently takes a long time to run and has been disabled\n    using the disable_slow_controls attribute.\" do\n      skip \"This control consistently takes a long time to run and has been disabled\n            using the disable_slow_controls attribute. You must enable this control for a\n            full accredidation for production.\"\n    end\n  else\n    describe command(\"rpm -Va | grep '^.M' | awk 'NF>1{print $NF}'\").stdout.strip.split(\"\\n\") do\n      it { should all(be_in rpm_verify_perms_except) }\n    end\n  end\nend\n",
          "source_location": {
            "line": 16,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71849.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "[\"/boot/initramfs-3.10.0-957.27.2.el7.x86_64.img\", \"/run/lsm\", \"/run/lsm/ipc\", \"/var/lib/setroubleshoot/email_alert_recipients\", \"/var/run/libvirt/qemu\", \"/boot/initramfs-3.10.0-957.el7.x86_64.img\", \"/var/log/dmesg\", \"/var/log/dmesg.old\", \"/var/lib/PackageKit/transactions.db\", \"/etc/pki/ca-trust/extracted/java/cacerts\", \"/etc/pki/ca-trust/extracted/openssl/ca-bundle.trust.crt\", \"/etc/pki/ca-trust/extracted/pem/email-ca-bundle.pem\", \"/etc/pki/ca-trust/extracted/pem/objsign-ca-bundle.pem\", \"/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem\", \"/var/lock/iscsi\", \"/var/lock/iscsi/lock\"] should all be in",
              "run_time": 0.00056624,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "expected [\"/boot/initramfs-3.10.0-957.27.2.el7.x86_64.img\", \"/run/lsm\", \"/run/lsm/ipc\", \"/var/lib/setroublesho...em\", \"/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem\", \"/var/lock/iscsi\", \"/var/lock/iscsi/lock\"] to all be in\n\n   object at index 0 failed to match:\n      expected `/boot/initramfs-3.10.0-957.27.2.el7.x86_64.img` to be in the list: `[]`\n\n   object at index 1 failed to match:\n      expected `/run/lsm` to be in the list: `[]`\n\n   object at index 2 failed to match:\n      expected `/run/lsm/ipc` to be in the list: `[]`\n\n   object at index 3 failed to match:\n      expected `/var/lib/setroubleshoot/email_alert_recipients` to be in the list: `[]`\n\n   object at index 4 failed to match:\n      expected `/var/run/libvirt/qemu` to be in the list: `[]`\n\n   object at index 5 failed to match:\n      expected `/boot/initramfs-3.10.0-957.el7.x86_64.img` to be in the list: `[]`\n\n   object at index 6 failed to match:\n      expected `/var/log/dmesg` to be in the list: `[]`\n\n   object at index 7 failed to match:\n      expected `/var/log/dmesg.old` to be in the list: `[]`\n\n   object at index 8 failed to match:\n      expected `/var/lib/PackageKit/transactions.db` to be in the list: `[]`\n\n   object at index 9 failed to match:\n      expected `/etc/pki/ca-trust/extracted/java/cacerts` to be in the list: `[]`\n\n   object at index 10 failed to match:\n      expected `/etc/pki/ca-trust/extracted/openssl/ca-bundle.trust.crt` to be in the list: `[]`\n\n   object at index 11 failed to match:\n      expected `/etc/pki/ca-trust/extracted/pem/email-ca-bundle.pem` to be in the list: `[]`\n\n   object at index 12 failed to match:\n      expected `/etc/pki/ca-trust/extracted/pem/objsign-ca-bundle.pem` to be in the list: `[]`\n\n   object at index 13 failed to match:\n      expected `/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem` to be in the list: `[]`\n\n   object at index 14 failed to match:\n      expected `/var/lock/iscsi` to be in the list: `[]`\n\n   object at index 15 failed to match:\n      expected `/var/lock/iscsi/lock` to be in the list: `[]`"
            }
          ]
        },
        {
          "id": "V-71855",
          "title": "The cryptographic hash of system files and commands must match vendor\nvalues.",
          "desc": "Without cryptographic integrity protections, system command and files can\nbe altered by unauthorized users without detection.\n\n    Cryptographic mechanisms used for protecting the integrity of information\ninclude, for example, signed hash functions using asymmetric cryptography\nenabling distribution of the public key to verify the hash information while\nmaintaining the confidentiality of the key used to generate the hash.",
          "descriptions": [
            {
              "label": "default",
              "data": "Without cryptographic integrity protections, system command and files can\nbe altered by unauthorized users without detection.\n\n    Cryptographic mechanisms used for protecting the integrity of information\ninclude, for example, signed hash functions using asymmetric cryptography\nenabling distribution of the public key to verify the hash information while\nmaintaining the confidentiality of the key used to generate the hash."
            },
            {
              "label": "check",
              "data": "Verify the cryptographic hash of system files and commands\nmatch the vendor values.\n\nCheck the cryptographic hash of system files and commands with the following\ncommand:\n\nNote: System configuration files (indicated by a \"c\" in the second column)\nare expected to change over time. Unusual modifications should be investigated\nthrough the system audit log.\n\n# rpm -Va | grep '^..5'\n\nIf there is any output from the command for system binaries, this is a finding."
            },
            {
              "label": "fix",
              "data": "Run the following command to determine which package owns the\nfile:\n\n# rpm -qf <filename>\n\nThe package can be reinstalled from a yum repository using the command:\n\n# sudo yum reinstall <packagename>\n\nAlternatively, the package can be reinstalled from trusted media using the\ncommand:\n\n# sudo rpm -Uvh <packagename>"
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-71855",
            "rid": "SV-86479r2_rule",
            "stig_id": "RHEL-07-010020",
            "cci": [
              "CCI-000663"
            ],
            "documentable": false,
            "nist": [
              "SA-7",
              "Rev_4"
            ],
            "subsystems": [
              "rpm",
              "package"
            ],
            "fix_id": "F-78207r1_fix"
          },
          "code": "control \"V-71855\" do\n  title \"The cryptographic hash of system files and commands must match vendor\nvalues.\"\n  desc  \"\n    Without cryptographic integrity protections, system command and files can\nbe altered by unauthorized users without detection.\n\n    Cryptographic mechanisms used for protecting the integrity of information\ninclude, for example, signed hash functions using asymmetric cryptography\nenabling distribution of the public key to verify the hash information while\nmaintaining the confidentiality of the key used to generate the hash.\n  \"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-71855\"\n  tag \"rid\": \"SV-86479r2_rule\"\n  tag \"stig_id\": \"RHEL-07-010020\"\n  tag \"cci\": [\"CCI-000663\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"SA-7\", \"Rev_4\"]\n  tag \"subsystems\": ['rpm', 'package']\n  desc \"check\", \"Verify the cryptographic hash of system files and commands\nmatch the vendor values.\n\nCheck the cryptographic hash of system files and commands with the following\ncommand:\n\nNote: System configuration files (indicated by a \\\"c\\\" in the second column)\nare expected to change over time. Unusual modifications should be investigated\nthrough the system audit log.\n\n# rpm -Va | grep '^..5'\n\nIf there is any output from the command for system binaries, this is a finding.\"\n  desc \"fix\", \"Run the following command to determine which package owns the\nfile:\n\n# rpm -qf <filename>\n\nThe package can be reinstalled from a yum repository using the command:\n\n# sudo yum reinstall <packagename>\n\nAlternatively, the package can be reinstalled from trusted media using the\ncommand:\n\n# sudo rpm -Uvh <packagename>\"\n  tag \"fix_id\": \"F-78207r1_fix\"\n\n  if disable_slow_controls\n    describe \"This control consistently takes a long to run and has been disabled\n    using the disable_slow_controls attribute.\" do\n      skip \"This control consistently takes a long to run and has been disabled\n      using the disable_slow_controls attribute. You must enable this control for a\n      full accredidation for production.\"\n    end\n  else\n    # grep excludes files that are marked with 'c' attribute (config files)\n    describe command(\"rpm -Va | grep '^..5' | grep -E -v '[a-z]*c[a-z]*\\\\s+\\\\S+$' | awk 'NF>1{print $NF}'\").\n      stdout.strip.split(\"\\n\") do\n        it { should all(be_in rpm_verify_integrity_except) }\n      end\n  end\nend\n",
          "source_location": {
            "line": 15,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71855.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "[] should all be in",
              "run_time": 0.000103517,
              "start_time": "2019-11-04T16:17:07-05:00"
            }
          ]
        },
        {
          "id": "V-71859",
          "title": "The operating system must display the Standard Mandatory DoD Notice\nand Consent Banner before granting local or remote access to the system via a\ngraphical user logon.",
          "desc": "Display of a standardized and approved use notification before granting\naccess to the operating system ensures privacy and security notification\nverbiage used is consistent with applicable federal laws, Executive Orders,\ndirectives, policies, regulations, standards, and guidance.\n\n    System use notifications are required only for access via logon interfaces\nwith human users and are not required when such human interfaces do not exist.\n\n    The banner must be formatted in accordance with applicable DoD policy. Use\nthe following verbiage for operating systems that can accommodate banners of\n1300 characters:\n\n    \"You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only.\n\n    By using this IS (which includes any device attached to this IS), you\nconsent to the following conditions:\n\n    -The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n    -At any time, the USG may inspect and seize data stored on this IS.\n\n    -Communications using, or data stored on, this IS are not private, are\nsubject to routine monitoring, interception, and search, and may be disclosed\nor used for any USG-authorized purpose.\n\n    -This IS includes security measures (e.g., authentication and access\ncontrols) to protect USG interests--not for your personal benefit or privacy.\n\n    -Notwithstanding the above, using this IS does not constitute consent to\nPM, LE or CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details.\"\nUse the following verbiage for operating systems that have severe limitations on\nthe number of characters that can be displayed in the banner:\n\n  \"I've read & consent to terms in IS user agreem't.\"",
          "descriptions": [
            {
              "label": "default",
              "data": "Display of a standardized and approved use notification before granting\naccess to the operating system ensures privacy and security notification\nverbiage used is consistent with applicable federal laws, Executive Orders,\ndirectives, policies, regulations, standards, and guidance.\n\n    System use notifications are required only for access via logon interfaces\nwith human users and are not required when such human interfaces do not exist.\n\n    The banner must be formatted in accordance with applicable DoD policy. Use\nthe following verbiage for operating systems that can accommodate banners of\n1300 characters:\n\n    \"You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only.\n\n    By using this IS (which includes any device attached to this IS), you\nconsent to the following conditions:\n\n    -The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n    -At any time, the USG may inspect and seize data stored on this IS.\n\n    -Communications using, or data stored on, this IS are not private, are\nsubject to routine monitoring, interception, and search, and may be disclosed\nor used for any USG-authorized purpose.\n\n    -This IS includes security measures (e.g., authentication and access\ncontrols) to protect USG interests--not for your personal benefit or privacy.\n\n    -Notwithstanding the above, using this IS does not constitute consent to\nPM, LE or CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details.\"\nUse the following verbiage for operating systems that have severe limitations on\nthe number of characters that can be displayed in the banner:\n\n  \"I've read & consent to terms in IS user agreem't.\""
            },
            {
              "label": "check",
              "data": "Verify the operating system displays the Standard Mandatory DoD\nNotice and Consent Banner before granting access to the operating system via a\ngraphical user logon.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nCheck to see if the operating system displays a banner at the logon screen with\nthe following command:\n\n# grep banner-message-enable /etc/dconf/db/local.d/*\nbanner-message-enable=true\n\nIf \"banner-message-enable\" is set to \"false\" or is missing, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to display the Standard Mandatory\nDoD Notice and Consent Banner before granting access to the system.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nCreate a database to contain the system-wide graphical user logon settings (if\nit does not already exist) with the following command:\n\n# touch /etc/dconf/db/local.d/01-banner-message\n\nAdd the following line to the [org/gnome/login-screen] section of the\n\"/etc/dconf/db/local.d/01-banner-message\":\n\n[org/gnome/login-screen]\nbanner-message-enable=true\n\nUpdate the system databases:\n\n# dconf update\n\nUsers must log out and back in again before the system-wide settings take\neffect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000023-GPOS-00006",
            "satisfies": [
              "SRG-OS-000023-GPOS-00006",
              "SRG-OS-000024-GPOS-00007",
              "SRG-OS-000228-GPOS-00088"
            ],
            "gid": "V-71859",
            "rid": "SV-86483r3_rule",
            "stig_id": "RHEL-07-010030",
            "cci": [
              "CCI-000048"
            ],
            "documentable": false,
            "nist": [
              "AC-8 a",
              "Rev_4"
            ],
            "subsystem": [
              "gdm"
            ],
            "fix_id": "F-78211r4_fix"
          },
          "code": "control \"V-71859\" do\n  title \"The operating system must display the Standard Mandatory DoD Notice\nand Consent Banner before granting local or remote access to the system via a\ngraphical user logon.\"\n  desc  \"\n    Display of a standardized and approved use notification before granting\naccess to the operating system ensures privacy and security notification\nverbiage used is consistent with applicable federal laws, Executive Orders,\ndirectives, policies, regulations, standards, and guidance.\n\n    System use notifications are required only for access via logon interfaces\nwith human users and are not required when such human interfaces do not exist.\n\n    The banner must be formatted in accordance with applicable DoD policy. Use\nthe following verbiage for operating systems that can accommodate banners of\n1300 characters:\n\n    \\\"You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only.\n\n    By using this IS (which includes any device attached to this IS), you\nconsent to the following conditions:\n\n    -The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n    -At any time, the USG may inspect and seize data stored on this IS.\n\n    -Communications using, or data stored on, this IS are not private, are\nsubject to routine monitoring, interception, and search, and may be disclosed\nor used for any USG-authorized purpose.\n\n    -This IS includes security measures (e.g., authentication and access\ncontrols) to protect USG interests--not for your personal benefit or privacy.\n\n    -Notwithstanding the above, using this IS does not constitute consent to\nPM, LE or CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details.\\\"\nUse the following verbiage for operating systems that have severe limitations on\nthe number of characters that can be displayed in the banner:\n\n  \\\"I've read & consent to terms in IS user agreem't.\\\"\"\n\n  if package('gnome-desktop3').installed?\n    impact 0.5\n  else\n    impact 0.0\n  end\n  tag \"gtitle\": \"SRG-OS-000023-GPOS-00006\"\n  tag \"satisfies\": [\"SRG-OS-000023-GPOS-00006\", \"SRG-OS-000024-GPOS-00007\",\n\"SRG-OS-000228-GPOS-00088\"]\n  tag \"gid\": \"V-71859\"\n  tag \"rid\": \"SV-86483r3_rule\"\n  tag \"stig_id\": \"RHEL-07-010030\"\n  tag \"cci\": [\"CCI-000048\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-8 a\", \"Rev_4\"]\n  tag \"subsystem\": [ \"gdm\" ]\n  desc \"check\", \"Verify the operating system displays the Standard Mandatory DoD\nNotice and Consent Banner before granting access to the operating system via a\ngraphical user logon.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nCheck to see if the operating system displays a banner at the logon screen with\nthe following command:\n\n# grep banner-message-enable /etc/dconf/db/local.d/*\nbanner-message-enable=true\n\nIf \\\"banner-message-enable\\\" is set to \\\"false\\\" or is missing, this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to display the Standard Mandatory\nDoD Notice and Consent Banner before granting access to the system.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nCreate a database to contain the system-wide graphical user logon settings (if\nit does not already exist) with the following command:\n\n# touch /etc/dconf/db/local.d/01-banner-message\n\nAdd the following line to the [org/gnome/login-screen] section of the\n\\\"/etc/dconf/db/local.d/01-banner-message\\\":\n\n[org/gnome/login-screen]\nbanner-message-enable=true\n\nUpdate the system databases:\n\n# dconf update\n\nUsers must log out and back in again before the system-wide settings take\neffect.\"\n  tag \"fix_id\": \"F-78211r4_fix\"\n\n  if package('gnome-desktop3').installed?\n    if !dconf_user.empty? and command('whoami').stdout.strip == 'root'\n      describe command(\"sudo -u #{dconf_user} dconf read /org/gnome/login-screen/banner-message-enable\") do\n        its('stdout.strip') { should cmp banner_message_enabled.to_s }\n      end\n    else\n      describe command(\"dconf read /org/gnome/login-screen/banner-message-enable\") do\n        its('stdout.strip') { should cmp banner_message_enabled.to_s }\n      end\n    end\n  else\n    describe \"The GNOME desktop is not installed\" do\n      skip \"The GNOME desktop is not installed, this control is Not Applicable.\"\n    end\n  end\nend\n",
          "source_location": {
            "line": 14,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71859.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Command: `dconf read /org/gnome/login-screen/banner-message-enable` stdout.strip should cmp == \"true\"",
              "run_time": 0.017205426,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "\nexpected: \"true\"\n     got: \"\"\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-71861",
          "title": "The operating system must display the approved Standard Mandatory DoD\nNotice and Consent Banner before granting local or remote access to the system\nvia a graphical user logon.",
          "desc": "Display of a standardized and approved use notification before granting\naccess to the operating system ensures privacy and security notification\nverbiage used is consistent with applicable federal laws, Executive Orders,\ndirectives, policies, regulations, standards, and guidance.\n\n    System use notifications are required only for access via logon interfaces\nwith human users and are not required when such human interfaces do not exist.\n\n    The banner must be formatted in accordance with applicable DoD policy. Use\nthe following verbiage for operating systems that can accommodate banners of\n1300 characters:\n\n    \"You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only.\n\n    By using this IS (which includes any device attached to this IS), you\nconsent to the following conditions:\n\n    -The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n    -At any time, the USG may inspect and seize data stored on this IS.\n\n    -Communications using, or data stored on, this IS are not private, are\nsubject to routine monitoring, interception, and search, and may be disclosed\nor used for any USG-authorized purpose.\n\n    -This IS includes security measures (e.g., authentication and access\ncontrols) to protect USG interests--not for your personal benefit or privacy.\n\n    -Notwithstanding the above, using this IS does not constitute consent to\nPM, LE or CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details.\"\nUse the following verbiage for operating systems that have severe limitations on\nthe number of characters that can be displayed in the banner:\n\n  - `I've read & consent to terms in IS user agreem't.'`",
          "descriptions": [
            {
              "label": "default",
              "data": "Display of a standardized and approved use notification before granting\naccess to the operating system ensures privacy and security notification\nverbiage used is consistent with applicable federal laws, Executive Orders,\ndirectives, policies, regulations, standards, and guidance.\n\n    System use notifications are required only for access via logon interfaces\nwith human users and are not required when such human interfaces do not exist.\n\n    The banner must be formatted in accordance with applicable DoD policy. Use\nthe following verbiage for operating systems that can accommodate banners of\n1300 characters:\n\n    \"You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only.\n\n    By using this IS (which includes any device attached to this IS), you\nconsent to the following conditions:\n\n    -The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n    -At any time, the USG may inspect and seize data stored on this IS.\n\n    -Communications using, or data stored on, this IS are not private, are\nsubject to routine monitoring, interception, and search, and may be disclosed\nor used for any USG-authorized purpose.\n\n    -This IS includes security measures (e.g., authentication and access\ncontrols) to protect USG interests--not for your personal benefit or privacy.\n\n    -Notwithstanding the above, using this IS does not constitute consent to\nPM, LE or CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details.\"\nUse the following verbiage for operating systems that have severe limitations on\nthe number of characters that can be displayed in the banner:\n\n  - `I've read & consent to terms in IS user agreem't.'`"
            },
            {
              "label": "check",
              "data": "Verify the operating system displays the approved Standard\nMandatory DoD Notice and Consent Banner before granting access to the operating\nsystem via a graphical user logon.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nCheck that the operating system displays the exact approved Standard Mandatory\nDoD Notice and Consent Banner text with the command:\n\n# grep banner-message-text /etc/dconf/db/local.d/*\nbanner-message-text=\n'You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only.\n\nBy using this IS (which includes any device attached to this IS), you consent\nto the following conditions:\n\n-The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n-At any time, the USG may inspect and seize data stored on this IS.\n\n-Communications using, or data stored on, this IS are not private, are subject\nto routine monitoring, interception, and search, and may be disclosed or used\nfor any USG-authorized purpose.\n\n-This IS includes security measures (e.g., authentication and access controls)\nto protect USG interests--not for your personal benefit or privacy.\n\n-Notwithstanding the above, using this IS does not constitute consent to PM, LE\nor CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details. '\n\nNote: The \"\n\" characters are for formatting only. They will not be displayed\non the GUI.\n\nIf the banner does not match the approved Standard Mandatory DoD Notice and\nConsent Banner, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to display the approved Standard\nMandatory DoD Notice and Consent Banner before granting access to the system.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nCreate a database to contain the system-wide graphical user logon settings (if\nit does not already exist) with the following command:\n\n# touch /etc/dconf/db/local.d/01-banner-message\n\nAdd the following line to the [org/gnome/login-screen] section of the\n\"/etc/dconf/db/local.d/01-banner-message\":\n\n[org/gnome/login-screen]\n\nbanner-message-enable=true\n\nbanner-message-text='You are accessing a U.S. Government (USG) Information\nSystem (IS) that is provided for USG-authorized use only.\n\nBy using this IS (which includes any device attached to this IS), you consent\nto the following conditions:\n\n-The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n-At any time, the USG may inspect and seize data stored on this IS.\n\n-Communications using, or data stored on, this IS are not private, are subject\nto routine monitoring, interception, and search, and may be disclosed or used\nfor any USG-authorized purpose.\n\n-This IS includes security measures (e.g., authentication and access controls)\nto protect USG interests--not for your personal benefit or privacy.\n\n-Notwithstanding the above, using this IS does not constitute consent to PM, LE\nor CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details. '\n\nNote: The \"\n \" characters are for formatting only. They will not be displayed\non the GUI.\n\nRun the following command to update the database:\n# dconf update"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000023-GPOS-00006",
            "satisfies": [
              "SRG-OS-000023-GPOS-00006",
              "SRG-OS-000024-GPOS-00007",
              "SRG-OS-000228-GPOS-00088"
            ],
            "gid": "V-71861",
            "rid": "SV-86485r3_rule",
            "stig_id": "RHEL-07-010040",
            "cci": [
              "CCI-000048"
            ],
            "documentable": false,
            "nist": [
              "AC-8 a",
              "Rev_4"
            ],
            "subsystems": [
              "gdm"
            ],
            "fix_id": "F-78213r5_fix"
          },
          "code": "control \"V-71861\" do\n  title \"The operating system must display the approved Standard Mandatory DoD\nNotice and Consent Banner before granting local or remote access to the system\nvia a graphical user logon.\"\n  desc  \"\n    Display of a standardized and approved use notification before granting\naccess to the operating system ensures privacy and security notification\nverbiage used is consistent with applicable federal laws, Executive Orders,\ndirectives, policies, regulations, standards, and guidance.\n\n    System use notifications are required only for access via logon interfaces\nwith human users and are not required when such human interfaces do not exist.\n\n    The banner must be formatted in accordance with applicable DoD policy. Use\nthe following verbiage for operating systems that can accommodate banners of\n1300 characters:\n\n    \\\"You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only.\n\n    By using this IS (which includes any device attached to this IS), you\nconsent to the following conditions:\n\n    -The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n    -At any time, the USG may inspect and seize data stored on this IS.\n\n    -Communications using, or data stored on, this IS are not private, are\nsubject to routine monitoring, interception, and search, and may be disclosed\nor used for any USG-authorized purpose.\n\n    -This IS includes security measures (e.g., authentication and access\ncontrols) to protect USG interests--not for your personal benefit or privacy.\n\n    -Notwithstanding the above, using this IS does not constitute consent to\nPM, LE or CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details.\\\"\nUse the following verbiage for operating systems that have severe limitations on\nthe number of characters that can be displayed in the banner:\n\n  - `I've read & consent to terms in IS user agreem't.'`\"\n\n  if package('gnome-desktop3').installed?\n    impact 0.5\n  else\n    impact 0.0\n  end\n  tag \"gtitle\": \"SRG-OS-000023-GPOS-00006\"\n  tag \"satisfies\": [\"SRG-OS-000023-GPOS-00006\", \"SRG-OS-000024-GPOS-00007\",\n\"SRG-OS-000228-GPOS-00088\"]\n  tag \"gid\": \"V-71861\"\n  tag \"rid\": \"SV-86485r3_rule\"\n  tag \"stig_id\": \"RHEL-07-010040\"\n  tag \"cci\": [\"CCI-000048\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-8 a\", \"Rev_4\"]\n  tag \"subsystems\": [ \"gdm\" ]\n  desc \"check\", \"Verify the operating system displays the approved Standard\nMandatory DoD Notice and Consent Banner before granting access to the operating\nsystem via a graphical user logon.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nCheck that the operating system displays the exact approved Standard Mandatory\nDoD Notice and Consent Banner text with the command:\n\n# grep banner-message-text /etc/dconf/db/local.d/*\nbanner-message-text=\n'You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only.\\n\nBy using this IS (which includes any device attached to this IS), you consent\nto the following conditions:\\n\n-The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\\n\n-At any time, the USG may inspect and seize data stored on this IS.\\n\n-Communications using, or data stored on, this IS are not private, are subject\nto routine monitoring, interception, and search, and may be disclosed or used\nfor any USG-authorized purpose.\\n\n-This IS includes security measures (e.g., authentication and access controls)\nto protect USG interests--not for your personal benefit or privacy.\\n\n-Notwithstanding the above, using this IS does not constitute consent to PM, LE\nor CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details. '\n\nNote: The \\\"\\n\\\" characters are for formatting only. They will not be displayed\non the GUI.\n\nIf the banner does not match the approved Standard Mandatory DoD Notice and\nConsent Banner, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to display the approved Standard\nMandatory DoD Notice and Consent Banner before granting access to the system.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nCreate a database to contain the system-wide graphical user logon settings (if\nit does not already exist) with the following command:\n\n# touch /etc/dconf/db/local.d/01-banner-message\n\nAdd the following line to the [org/gnome/login-screen] section of the\n\\\"/etc/dconf/db/local.d/01-banner-message\\\":\n\n[org/gnome/login-screen]\n\nbanner-message-enable=true\n\nbanner-message-text='You are accessing a U.S. Government (USG) Information\nSystem (IS) that is provided for USG-authorized use only.\\n\nBy using this IS (which includes any device attached to this IS), you consent\nto the following conditions:\\n\n-The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\\n\n-At any time, the USG may inspect and seize data stored on this IS.\\n\n-Communications using, or data stored on, this IS are not private, are subject\nto routine monitoring, interception, and search, and may be disclosed or used\nfor any USG-authorized purpose.\\n\n-This IS includes security measures (e.g., authentication and access controls)\nto protect USG interests--not for your personal benefit or privacy.\\n\n-Notwithstanding the above, using this IS does not constitute consent to PM, LE\nor CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details. '\n\nNote: The \\\"\\n \\\" characters are for formatting only. They will not be displayed\non the GUI.\n\nRun the following command to update the database:\n# dconf update\"\n  tag \"fix_id\": \"F-78213r5_fix\"\n  if package('gnome-desktop3').installed?\n    #Get all files that have the banner-message-text specified.\n    banner_files =\n      command(\"grep -l banner-message-text /etc/dconf/db/local.d/*\").stdout.split(\"\\n\")\n\n    #If there are no banner files then this is a finding.\n    banner_missing = banner_files.empty?\n    describe \"If no files specify the banner text then this is a finding\" do\n      subject { banner_missing }\n      it{should be false}\n    end if banner_missing\n\n    #If there are banner files then check them to make sure they have the correct text.\n    banner_files.each do |banner_file|\n      banner_message =\n        parse_config_file(banner_file).params(\"banner-message-text\").gsub(%r{[\\r\\n\\s]}, '')\n      #dconf expects the banner-message-text to be quoted so remove leading and trailing quote.\n      #See https://developer.gnome.org/dconf/unstable/dconf-tool.html which states:\n      #  VALUE arguments must be in GVariant format, so e.g. a string must include\n      #  explicit quotes: \"'foo'\". This format is also used when printing out values.\n      if banner_message.start_with?('\"') || banner_message.start_with?('\\'')\n        banner_message = banner_message[1,banner_message.length]\n      end\n      if banner_message.end_with?('\"') || banner_message.end_with?('\\'')\n        banner_message = banner_message.chop\n      end\n      describe.one do\n        describe banner_message do\n          it{should cmp banner_message_text_gui.gsub(%r{[\\r\\n\\s]}, '')}\n        end\n        describe banner_message do\n          it{should cmp banner_message_text_gui_limited.gsub(%r{[\\r\\n\\s]}, '')}\n        end\n      end\n    end\n  else\n    describe \"The system does not have GNOME installed\" do\n      skip \"The system does not have GNOME installed, this requirement is Not\n        Applicable.\"\n    end\n  end\nend\n",
          "source_location": {
            "line": 29,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71861.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "If no files specify the banner text then this is a finding should equal false",
              "run_time": 0.001565842,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "\nexpected false\n     got true\n"
            }
          ]
        },
        {
          "id": "V-71863",
          "title": "The operating system must display the Standard Mandatory DoD Notice\nand Consent Banner before granting local or remote access to the system via a\ncommand line user logon.",
          "desc": "Display of a standardized and approved use notification before granting\naccess to the operating system ensures privacy and security notification\nverbiage used is consistent with applicable federal laws, Executive Orders,\ndirectives, policies, regulations, standards, and guidance.\n\n    System use notifications are required only for access via logon interfaces\nwith human users and are not required when such human interfaces do not exist.\n\n    The banner must be formatted in accordance with applicable DoD policy. Use\nthe following verbiage for operating systems that can accommodate banners of\n1300 characters:\n\n    \"You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only.\n\n    By using this IS (which includes any device attached to this IS), you\nconsent to the following conditions:\n\n    -The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n    -At any time, the USG may inspect and seize data stored on this IS.\n\n    -Communications using, or data stored on, this IS are not private, are\nsubject to routine monitoring, interception, and search, and may be disclosed\nor used for any USG-authorized purpose.\n\n    -This IS includes security measures (e.g., authentication and access\ncontrols) to protect USG interests--not for your personal benefit or privacy.\n\n    -Notwithstanding the above, using this IS does not constitute consent to\nPM, LE or CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details.\"\nUse the following verbiage for operating systems that have severe limitations on\nthe number of characters that can be displayed in the banner:\n\n  - `I've read & consent to terms in IS user agreem't.'`",
          "descriptions": [
            {
              "label": "default",
              "data": "Display of a standardized and approved use notification before granting\naccess to the operating system ensures privacy and security notification\nverbiage used is consistent with applicable federal laws, Executive Orders,\ndirectives, policies, regulations, standards, and guidance.\n\n    System use notifications are required only for access via logon interfaces\nwith human users and are not required when such human interfaces do not exist.\n\n    The banner must be formatted in accordance with applicable DoD policy. Use\nthe following verbiage for operating systems that can accommodate banners of\n1300 characters:\n\n    \"You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only.\n\n    By using this IS (which includes any device attached to this IS), you\nconsent to the following conditions:\n\n    -The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n    -At any time, the USG may inspect and seize data stored on this IS.\n\n    -Communications using, or data stored on, this IS are not private, are\nsubject to routine monitoring, interception, and search, and may be disclosed\nor used for any USG-authorized purpose.\n\n    -This IS includes security measures (e.g., authentication and access\ncontrols) to protect USG interests--not for your personal benefit or privacy.\n\n    -Notwithstanding the above, using this IS does not constitute consent to\nPM, LE or CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details.\"\nUse the following verbiage for operating systems that have severe limitations on\nthe number of characters that can be displayed in the banner:\n\n  - `I've read & consent to terms in IS user agreem't.'`"
            },
            {
              "label": "check",
              "data": "Verify the operating system displays the Standard Mandatory DoD\nNotice and Consent Banner before granting access to the operating system via a\ncommand line user logon.\n\nCheck to see if the operating system displays a banner at the command line\nlogon screen with the following command:\n\n# more /etc/issue\n\nThe command should return the following text:\n\"You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only.\n\nBy using this IS (which includes any device attached to this IS), you consent\nto the following conditions:\n\n-The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n-At any time, the USG may inspect and seize data stored on this IS.\n\n-Communications using, or data stored on, this IS are not private, are subject\nto routine monitoring, interception, and search, and may be disclosed or used\nfor any USG-authorized purpose.\n\n-This IS includes security measures (e.g., authentication and access controls)\nto protect USG interests--not for your personal benefit or privacy.\n\n-Notwithstanding the above, using this IS does not constitute consent to PM, LE\nor CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details.\"\n\nIf the operating system does not display a graphical logon banner or the banner\ndoes not match the Standard Mandatory DoD Notice and Consent Banner, this is a\nfinding.\n\nIf the text in the \"/etc/issue\" file does not match the Standard Mandatory\nDoD Notice and Consent Banner, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to display the Standard Mandatory\nDoD Notice and Consent Banner before granting access to the system via the\ncommand line by editing the \"/etc/issue\" file.\n\nReplace the default text with the Standard Mandatory DoD Notice and Consent\nBanner. The DoD required text is:\n\n\"You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only.\n\nBy using this IS (which includes any device attached to this IS), you consent\nto the following conditions:\n\n-The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n-At any time, the USG may inspect and seize data stored on this IS.\n\n-Communications using, or data stored on, this IS are not private, are subject\nto routine monitoring, interception, and search, and may be disclosed or used\nfor any USG-authorized purpose.\n\n-This IS includes security measures (e.g., authentication and access controls)\nto protect USG interests -- not for your personal benefit or privacy.\n\n-Notwithstanding the above, using this IS does not constitute consent to PM, LE\nor CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details.\""
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000023-GPOS-00006",
            "satisfies": [
              "SRG-OS-000023-GPOS-00006",
              "SRG-OS-000024-GPOS-00007"
            ],
            "gid": "V-71863",
            "rid": "SV-86487r2_rule",
            "stig_id": "RHEL-07-010050",
            "cci": [
              "CCI-000048"
            ],
            "documentable": false,
            "nist": [
              "AC-8 a",
              "Rev_4"
            ],
            "subsystems": [
              "banner",
              "/etc/issue"
            ],
            "fix_id": "F-78217r1_fix"
          },
          "code": "control \"V-71863\" do\n  title \"The operating system must display the Standard Mandatory DoD Notice\nand Consent Banner before granting local or remote access to the system via a\ncommand line user logon.\"\n  desc  \"\n    Display of a standardized and approved use notification before granting\naccess to the operating system ensures privacy and security notification\nverbiage used is consistent with applicable federal laws, Executive Orders,\ndirectives, policies, regulations, standards, and guidance.\n\n    System use notifications are required only for access via logon interfaces\nwith human users and are not required when such human interfaces do not exist.\n\n    The banner must be formatted in accordance with applicable DoD policy. Use\nthe following verbiage for operating systems that can accommodate banners of\n1300 characters:\n\n    \\\"You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only.\n\n    By using this IS (which includes any device attached to this IS), you\nconsent to the following conditions:\n\n    -The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n    -At any time, the USG may inspect and seize data stored on this IS.\n\n    -Communications using, or data stored on, this IS are not private, are\nsubject to routine monitoring, interception, and search, and may be disclosed\nor used for any USG-authorized purpose.\n\n    -This IS includes security measures (e.g., authentication and access\ncontrols) to protect USG interests--not for your personal benefit or privacy.\n\n    -Notwithstanding the above, using this IS does not constitute consent to\nPM, LE or CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details.\\\"\nUse the following verbiage for operating systems that have severe limitations on\nthe number of characters that can be displayed in the banner:\n\n  - `I've read & consent to terms in IS user agreem't.'`\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000023-GPOS-00006\"\n  tag \"satisfies\": [\"SRG-OS-000023-GPOS-00006\", \"SRG-OS-000024-GPOS-00007\"]\n  tag \"gid\": \"V-71863\"\n  tag \"rid\": \"SV-86487r2_rule\"\n  tag \"stig_id\": \"RHEL-07-010050\"\n  tag \"cci\": [\"CCI-000048\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-8 a\", \"Rev_4\"]\n  tag \"subsystems\": [ \"banner\", \"/etc/issue\" ]\n  desc \"check\", \"Verify the operating system displays the Standard Mandatory DoD\nNotice and Consent Banner before granting access to the operating system via a\ncommand line user logon.\n\nCheck to see if the operating system displays a banner at the command line\nlogon screen with the following command:\n\n# more /etc/issue\n\nThe command should return the following text:\n\\\"You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only.\n\nBy using this IS (which includes any device attached to this IS), you consent\nto the following conditions:\n\n-The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n-At any time, the USG may inspect and seize data stored on this IS.\n\n-Communications using, or data stored on, this IS are not private, are subject\nto routine monitoring, interception, and search, and may be disclosed or used\nfor any USG-authorized purpose.\n\n-This IS includes security measures (e.g., authentication and access controls)\nto protect USG interests--not for your personal benefit or privacy.\n\n-Notwithstanding the above, using this IS does not constitute consent to PM, LE\nor CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details.\\\"\n\nIf the operating system does not display a graphical logon banner or the banner\ndoes not match the Standard Mandatory DoD Notice and Consent Banner, this is a\nfinding.\n\nIf the text in the \\\"/etc/issue\\\" file does not match the Standard Mandatory\nDoD Notice and Consent Banner, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to display the Standard Mandatory\nDoD Notice and Consent Banner before granting access to the system via the\ncommand line by editing the \\\"/etc/issue\\\" file.\n\nReplace the default text with the Standard Mandatory DoD Notice and Consent\nBanner. The DoD required text is:\n\n\\\"You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only.\n\nBy using this IS (which includes any device attached to this IS), you consent\nto the following conditions:\n\n-The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n-At any time, the USG may inspect and seize data stored on this IS.\n\n-Communications using, or data stored on, this IS are not private, are subject\nto routine monitoring, interception, and search, and may be disclosed or used\nfor any USG-authorized purpose.\n\n-This IS includes security measures (e.g., authentication and access controls)\nto protect USG interests -- not for your personal benefit or privacy.\n\n-Notwithstanding the above, using this IS does not constitute consent to PM, LE\nor CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details.\\\"\"\n  tag \"fix_id\": \"F-78217r1_fix\"\n  clean_banner = banner_message_text_cli.gsub(%r{[\\r\\n\\s]}, '')\n  clean_banner_limited = banner_message_text_cli_limited.gsub(%r{[\\r\\n\\s]}, '')\n  banner_file = file(\"/etc/issue\")\n  banner_missing = !banner_file.exist?\n\n  describe \"The banner text is not set because /etc/issue does not exist\" do\n    subject { banner_missing }\n    it { should be false }\n  end if banner_missing\n\n  banner_message = banner_file.content.gsub(%r{[\\r\\n\\s]}, '')\n  describe.one do\n    describe \"The banner text should match the standard banner\" do\n      subject { banner_message }\n      it { should cmp clean_banner }\n    end\n    describe \"The banner text should match the limited banner\" do\n      subject { banner_message }\n      it{should cmp clean_banner_limited }\n    end\n  end if !banner_missing\nend\n",
          "source_location": {
            "line": 32,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71863.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "The banner text should match the standard banner should cmp == \"YouareaccessingaU.S.Government(USG)InformationSystem(IS)thatisprovidedforUSG-authorizeduseonly.ByusingthisIS(whichincludesanydeviceattachedtothisIS),youconsenttothefollowingconditions:-TheUSGroutinelyinterceptsandmonitorscommunicationsonthisISforpurposesincluding,butnotlimitedto,penetrationtesting,COMSECmonitoring,networkoperationsanddefense,personnelmisconduct(PM),lawenforcement(LE),andcounterintelligence(CI)investigations.-Atanytime,theUSGmayinspectandseizedatastoredonthisIS.-Communicationsusing,ordatastoredon,thisISarenotprivate,aresubjecttoroutinemonitoring,interception,andsearch,andmaybedisclosedorusedforanyUSG-authorizedpurpose.-ThisISincludessecuritymeasures(e.g.,authenticationandaccesscontrols)toprotectUSGinterests--notforyourpersonalbenefitorprivacy.-Notwithstandingtheabove,usingthisISdoesnotconstituteconsenttoPM,LEorCIinvestigativesearchingormonitoringofthecontentofprivilegedcommunications,orworkproduct,relatedtopersonalrepresentationorservicesbyattorneys,psychotherapists,orclergy,andtheirassistants.Suchcommunicationsandworkproductareprivateandconfidential.SeeUserAgreementfordetails.\"",
              "run_time": 0.000220362,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "\nexpected: \"YouareaccessingaU.S.Government(USG)InformationSystem(IS)thatisprovidedforUSG-authorizeduseonly.ByusingthisIS(whichincludesanydeviceattachedtothisIS),youconsenttothefollowingconditions:-TheUSGroutinelyinterceptsandmonitorscommunicationsonthisISforpurposesincluding,butnotlimitedto,penetrationtesting,COMSECmonitoring,networkoperationsanddefense,personnelmisconduct(PM),lawenforcement(LE),andcounterintelligence(CI)investigations.-Atanytime,theUSGmayinspectandseizedatastoredonthisIS.-Communicationsusing,ordatastoredon,thisISarenotprivate,aresubjecttoroutinemonitoring,interception,andsearch,andmaybedisclosedorusedforanyUSG-authorizedpurpose.-ThisISincludessecuritymeasures(e.g.,authenticationandaccesscontrols)toprotectUSGinterests--notforyourpersonalbenefitorprivacy.-Notwithstandingtheabove,usingthisISdoesnotconstituteconsenttoPM,LEorCIinvestigativesearchingormonitoringofthecontentofprivilegedcommunications,orworkproduct,relatedtopersonalrepresentationorservicesbyattorneys,psychotherapists,orclergy,andtheirassistants.Suchcommunicationsandworkproductareprivateandconfidential.SeeUserAgreementfordetails.\"\n     got: \"\\\\SKernel\\\\ronan\\\\m\"\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "The banner text should match the limited banner should cmp == \"I'veread&consenttotermsinISuseragreem't.\"",
              "run_time": 0.000139008,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "\nexpected: \"I'veread&consenttotermsinISuseragreem't.\"\n     got: \"\\\\SKernel\\\\ronan\\\\m\"\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            }
          ]
        },
        {
          "id": "V-71891",
          "title": "The operating system must enable a user session lock until that user\nre-establishes access using established identification and authentication\nprocedures.",
          "desc": "A session lock is a temporary action taken when a user stops work and moves\naway from the immediate physical vicinity of the information system but does\nnot want to log out because of the temporary nature of the absence.\n\n    The session lock is implemented at the point where session activity can be\ndetermined.\n\n    Regardless of where the session lock is determined and implemented, once\ninvoked, the session lock must remain in place until the user reauthenticates.\nNo other activity aside from reauthentication must unlock the system.",
          "descriptions": [
            {
              "label": "default",
              "data": "A session lock is a temporary action taken when a user stops work and moves\naway from the immediate physical vicinity of the information system but does\nnot want to log out because of the temporary nature of the absence.\n\n    The session lock is implemented at the point where session activity can be\ndetermined.\n\n    Regardless of where the session lock is determined and implemented, once\ninvoked, the session lock must remain in place until the user reauthenticates.\nNo other activity aside from reauthentication must unlock the system."
            },
            {
              "label": "check",
              "data": "Verify the operating system enables a user's session lock until\nthat user re-establishes access using established identification and\nauthentication procedures. The screen program must be installed to lock\nsessions on the console.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nCheck to see if the screen lock is enabled with the following command:\n\n# grep -i lock-enabled /etc/dconf/db/local.d/00-screensaver\nlock-enabled=true\n\nIf the \"lock-enabled\" setting is missing or is not set to \"true\", this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to enable a user's session lock\nuntil that user re-establishes access using established identification and\nauthentication procedures.\n\nCreate a database to contain the system-wide screensaver settings (if it does\nnot already exist) with the following command:\n\n# touch /etc/dconf/db/local.d/00-screensaver\n\nEdit \"org/gnome/desktop/screensaver\" and add or update the following lines:\n\n# Set this to true to lock the screen when the screensaver activates\nlock-enabled=true\n\nUpdate the system databases:\n\n# dconf update\n\nUsers must log out and back in again before the system-wide settings take\neffect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000028-GPOS-00009",
            "satisfies": [
              "SRG-OS-000028-GPOS-00009",
              "SRG-OS-000030-GPOS-00011"
            ],
            "gid": "V-71891",
            "rid": "SV-86515r4_rule",
            "stig_id": "RHEL-07-010060",
            "cci": [
              "CCI-000056"
            ],
            "documentable": false,
            "nist": [
              "AC-11 b",
              "Rev_4"
            ],
            "subsystems": [
              "session",
              "lock",
              "gnome",
              "screensaver"
            ],
            "fix_id": "F-78243r7_fix"
          },
          "code": "control \"V-71891\" do\n  title \"The operating system must enable a user session lock until that user\nre-establishes access using established identification and authentication\nprocedures.\"\n  desc  \"\n    A session lock is a temporary action taken when a user stops work and moves\naway from the immediate physical vicinity of the information system but does\nnot want to log out because of the temporary nature of the absence.\n\n    The session lock is implemented at the point where session activity can be\ndetermined.\n\n    Regardless of where the session lock is determined and implemented, once\ninvoked, the session lock must remain in place until the user reauthenticates.\nNo other activity aside from reauthentication must unlock the system.\n  \"\n  if package('gnome-desktop3').installed?\n    impact 0.5\n  else\n    impact 0.0\n  end\n  tag \"gtitle\": \"SRG-OS-000028-GPOS-00009\"\n  tag \"satisfies\": [\"SRG-OS-000028-GPOS-00009\", \"SRG-OS-000030-GPOS-00011\"]\n  tag \"gid\": \"V-71891\"\n  tag \"rid\": \"SV-86515r4_rule\"\n  tag \"stig_id\": \"RHEL-07-010060\"\n  tag \"cci\": [\"CCI-000056\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-11 b\", \"Rev_4\"]\n  tag \"subsystems\": [ \"session\", \"lock\", \"gnome\", \"screensaver\" ]\n  desc \"check\", \"Verify the operating system enables a user's session lock until\nthat user re-establishes access using established identification and\nauthentication procedures. The screen program must be installed to lock\nsessions on the console.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nCheck to see if the screen lock is enabled with the following command:\n\n# grep -i lock-enabled /etc/dconf/db/local.d/00-screensaver\nlock-enabled=true\n\nIf the \\\"lock-enabled\\\" setting is missing or is not set to \\\"true\\\", this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to enable a user's session lock\nuntil that user re-establishes access using established identification and\nauthentication procedures.\n\nCreate a database to contain the system-wide screensaver settings (if it does\nnot already exist) with the following command:\n\n# touch /etc/dconf/db/local.d/00-screensaver\n\nEdit \\\"org/gnome/desktop/screensaver\\\" and add or update the following lines:\n\n# Set this to true to lock the screen when the screensaver activates\nlock-enabled=true\n\nUpdate the system databases:\n\n# dconf update\n\nUsers must log out and back in again before the system-wide settings take\neffect.\"\n  tag \"fix_id\": \"F-78243r7_fix\"\n\n  describe command('gsettings get org.gnome.desktop.screensaver lock-enabled') do\n    its('stdout.strip') { should cmp 'true' }\n  end if package('gnome-desktop3').installed?\n\n  describe \"The system does not have GNOME installed\" do\n    skip \"The system does not have GNOME installed, this requirement is Not\n    Applicable.\"\n  end if !package('gnome-desktop3').installed?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71891.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Command: `gsettings get org.gnome.desktop.screensaver lock-enabled` stdout.strip should cmp == \"true\"",
              "run_time": 0.018772374,
              "start_time": "2019-11-04T16:17:07-05:00"
            }
          ]
        },
        {
          "id": "V-71893",
          "title": "The operating system must initiate a screensaver after a 15-minute\nperiod of inactivity for graphical user interfaces.",
          "desc": "A session time-out lock is a temporary action taken when a user stops work\nand moves away from the immediate physical vicinity of the information system\nbut does not log out because of the temporary nature of the absence. Rather\nthan relying on the user to manually lock their operating system session prior\nto vacating the vicinity, operating systems need to be able to identify when a\nuser's session has idled and take action to initiate the session lock.\n\n    The session lock is implemented at the point where session activity can be\ndetermined and/or controlled.",
          "descriptions": [
            {
              "label": "default",
              "data": "A session time-out lock is a temporary action taken when a user stops work\nand moves away from the immediate physical vicinity of the information system\nbut does not log out because of the temporary nature of the absence. Rather\nthan relying on the user to manually lock their operating system session prior\nto vacating the vicinity, operating systems need to be able to identify when a\nuser's session has idled and take action to initiate the session lock.\n\n    The session lock is implemented at the point where session activity can be\ndetermined and/or controlled."
            },
            {
              "label": "check",
              "data": "Verify the operating system initiates a screensaver after a\n15-minute period of inactivity for graphical user interfaces. The screen\nprogram must be installed to lock sessions on the console.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nCheck to see if GNOME is configured to display a screensaver after a 15 minute\ndelay with the following command:\n\n# grep -i idle-delay /etc/dconf/db/local.d/*\nidle-delay=uint32 900\n\nIf the \"idle-delay\" setting is missing or is not set to \"900\" or less, this\nis a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to initiate a screensaver after a\n15-minute period of inactivity for graphical user interfaces.\n\nCreate a database to contain the system-wide screensaver settings (if it does\nnot already exist) with the following command:\n\n# touch /etc/dconf/db/local.d/00-screensaver\n\nEdit /etc/dconf/db/local.d/00-screensaver and add or update the following lines:\n\n[org/gnome/desktop/session]\n# Set the lock time out to 900 seconds before the session is considered idle\nidle-delay=uint32 900\n\nYou must include the \"uint32\" along with the integer key values as shown.\n\nUpdate the system databases:\n\n# dconf update\n\nUsers must log out and back in again before the system-wide settings take\neffect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000029-GPOS-00010",
            "gid": "V-71893",
            "rid": "SV-86517r4_rule",
            "stig_id": "RHEL-07-010070",
            "cci": [
              "CCI-000057"
            ],
            "documentable": false,
            "nist": [
              "AC-11 a",
              "Rev_4"
            ],
            "subsystems": [
              "gnome",
              "screensaver",
              "session",
              "lock"
            ],
            "fix_id": "F-78245r5_fix"
          },
          "code": "control \"V-71893\" do\n  title \"The operating system must initiate a screensaver after a 15-minute\nperiod of inactivity for graphical user interfaces.\"\n  desc  \"\n    A session time-out lock is a temporary action taken when a user stops work\nand moves away from the immediate physical vicinity of the information system\nbut does not log out because of the temporary nature of the absence. Rather\nthan relying on the user to manually lock their operating system session prior\nto vacating the vicinity, operating systems need to be able to identify when a\nuser's session has idled and take action to initiate the session lock.\n\n    The session lock is implemented at the point where session activity can be\ndetermined and/or controlled.\n  \"\n  if package('gnome-desktop3').installed?\n    impact 0.5\n  else\n    impact 0.0\n  end\n  tag \"gtitle\": \"SRG-OS-000029-GPOS-00010\"\n  tag \"gid\": \"V-71893\"\n  tag \"rid\": \"SV-86517r4_rule\"\n  tag \"stig_id\": \"RHEL-07-010070\"\n  tag \"cci\": [\"CCI-000057\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-11 a\", \"Rev_4\"]\n  tag \"subsystems\": [ \"gnome\", \"screensaver\", \"session\", \"lock\" ]\n  desc \"check\", \"Verify the operating system initiates a screensaver after a\n15-minute period of inactivity for graphical user interfaces. The screen\nprogram must be installed to lock sessions on the console.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nCheck to see if GNOME is configured to display a screensaver after a 15 minute\ndelay with the following command:\n\n# grep -i idle-delay /etc/dconf/db/local.d/*\nidle-delay=uint32 900\n\nIf the \\\"idle-delay\\\" setting is missing or is not set to \\\"900\\\" or less, this\nis a finding.\"\n  desc \"fix\", \"Configure the operating system to initiate a screensaver after a\n15-minute period of inactivity for graphical user interfaces.\n\nCreate a database to contain the system-wide screensaver settings (if it does\nnot already exist) with the following command:\n\n# touch /etc/dconf/db/local.d/00-screensaver\n\nEdit /etc/dconf/db/local.d/00-screensaver and add or update the following lines:\n\n[org/gnome/desktop/session]\n# Set the lock time out to 900 seconds before the session is considered idle\nidle-delay=uint32 900\n\nYou must include the \\\"uint32\\\" along with the integer key values as shown.\n\nUpdate the system databases:\n\n# dconf update\n\nUsers must log out and back in again before the system-wide settings take\neffect.\"\n  tag \"fix_id\": \"F-78245r5_fix\"\n\n  describe command(\"gsettings get org.gnome.desktop.session idle-delay | cut -d ' ' -f2\") do\n    its('stdout.strip') { should cmp <= 900 }\n  end if package('gnome-desktop3').installed?\n\n  describe \"The system does not have GNOME installed\" do\n    skip \"The system does not have GNOME installed, this requirement is Not\n    Applicable.\"\n  end if !package('gnome-desktop3').installed?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71893.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Command: `gsettings get org.gnome.desktop.session idle-delay | cut -d ' ' -f2` stdout.strip should cmp <= 900",
              "run_time": 0.019886463,
              "start_time": "2019-11-04T16:17:07-05:00"
            }
          ]
        },
        {
          "id": "V-71895",
          "title": "The operating system must set the idle delay setting for all connection\ntypes.",
          "desc": "A session time-out lock is a temporary action taken when a user stops work and\nmoves away from the immediate physical vicinity of the information system but does\nnot log out because of the temporary nature of the absence. Rather than relying on\nthe user to manually lock their operating system session prior to vacating the\nvicinity, operating systems need to be able to identify when a user's session has\nidled and take action to initiate the session lock.\n\n    The session lock is implemented at the point where session activity can be\ndetermined and/or controlled.",
          "descriptions": [
            {
              "label": "default",
              "data": "A session time-out lock is a temporary action taken when a user stops work and\nmoves away from the immediate physical vicinity of the information system but does\nnot log out because of the temporary nature of the absence. Rather than relying on\nthe user to manually lock their operating system session prior to vacating the\nvicinity, operating systems need to be able to identify when a user's session has\nidled and take action to initiate the session lock.\n\n    The session lock is implemented at the point where session activity can be\ndetermined and/or controlled."
            },
            {
              "label": "check",
              "data": "Verify the operating system prevents a user from overriding session\nlock after a 15-minute period of inactivity for graphical user interfaces. The\nscreen program must be installed to lock sessions on the console.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nDetermine which profile the system database is using with the following command:\n#grep system-db /etc/dconf/profile/user\n\nsystem-db:local\n\nCheck for the lock delay setting with the following command:\n\nNote: The example below is using the database \"local\" for the system, so the path\nis \"/etc/dconf/db/local.d\". This path must be modified if a database other than\n\"local\" is being used.\n\n# grep -i idle-delay /etc/dconf/db/local.d/locks/*\n\n/org/gnome/desktop/screensaver/idle-delay\n\nIf the command does not return a result, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to prevent a user from overriding a\nsession lock after a 15-minute period of inactivity for graphical user interfaces.\n\nCreate a database to contain the system-wide screensaver settings (if it does not\nalready exist) with the following command:\n\nNote: The example below is using the database \"local\" for the system, so if the\nsystem is using another database in /etc/dconf/profile/user, the file should be\ncreated under the appropriate subdirectory.\n\n# touch /etc/dconf/db/local.d/locks/session\n\nAdd the setting to lock the screensaver idle delay:\n\n/org/gnome/desktop/screensaver/idle-delay"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "severity": "medium",
            "gtitle": "SRG-OS-000029-GPOS-00010",
            "gid": "V-71895",
            "rid": "SV-86519r3_rule",
            "stig_id": "RHEL-07-010080",
            "cci": [
              "CCI-000057"
            ],
            "nist": [
              "AC-11 a",
              "Rev_4"
            ],
            "subsystems": [
              "gnome3"
            ]
          },
          "code": "control \"V-71895\" do\n  title \"The operating system must set the idle delay setting for all connection\ntypes.\"\n  desc  \"\n    A session time-out lock is a temporary action taken when a user stops work and\nmoves away from the immediate physical vicinity of the information system but does\nnot log out because of the temporary nature of the absence. Rather than relying on\nthe user to manually lock their operating system session prior to vacating the\nvicinity, operating systems need to be able to identify when a user's session has\nidled and take action to initiate the session lock.\n\n    The session lock is implemented at the point where session activity can be\ndetermined and/or controlled.\n  \"\n  impact 0.5\n  tag \"severity\": \"medium\"\n  tag \"gtitle\": \"SRG-OS-000029-GPOS-00010\"\n  tag \"gid\": \"V-71895\"\n  tag \"rid\": \"SV-86519r3_rule\"\n  tag \"stig_id\": \"RHEL-07-010080\"\n  tag \"cci\": [\"CCI-000057\"]\n  tag \"nist\": [\"AC-11 a\", \"Rev_4\"]\n  tag \"subsystems\": [\"gnome3\"]\n  desc \"check\", \"Verify the operating system prevents a user from overriding session\nlock after a 15-minute period of inactivity for graphical user interfaces. The\nscreen program must be installed to lock sessions on the console.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nDetermine which profile the system database is using with the following command:\n#grep system-db /etc/dconf/profile/user\n\nsystem-db:local\n\nCheck for the lock delay setting with the following command:\n\nNote: The example below is using the database \\\"local\\\" for the system, so the path\nis \\\"/etc/dconf/db/local.d\\\". This path must be modified if a database other than\n\\\"local\\\" is being used.\n\n# grep -i idle-delay /etc/dconf/db/local.d/locks/*\n\n/org/gnome/desktop/screensaver/idle-delay\n\nIf the command does not return a result, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to prevent a user from overriding a\nsession lock after a 15-minute period of inactivity for graphical user interfaces.\n\nCreate a database to contain the system-wide screensaver settings (if it does not\nalready exist) with the following command:\n\nNote: The example below is using the database \\\"local\\\" for the system, so if the\nsystem is using another database in /etc/dconf/profile/user, the file should be\ncreated under the appropriate subdirectory.\n\n# touch /etc/dconf/db/local.d/locks/session\n\nAdd the setting to lock the screensaver idle delay:\n\n/org/gnome/desktop/screensaver/idle-delay\"\n\n  describe command(\"grep -i idle-delay /etc/dconf/db/*/locks/*\") do\n    its('stdout.strip') { should_not cmp \"\" }\n    its('stderr') { should_not match /.*No such file or directory\\n?$/ }\n  end\n  only_if { package('gnome-desktop3').installed? }\nend\n",
          "source_location": {
            "line": 23,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71895.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Command: `grep -i idle-delay /etc/dconf/db/*/locks/*` stdout.strip should not cmp == \"\"",
              "run_time": 0.015451101,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "\nexpected it not to be == \"\"\n     got: \"\"\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "failed",
              "code_desc": "Command: `grep -i idle-delay /etc/dconf/db/*/locks/*` stderr should not match /.*No such file or directory\\n?$/",
              "run_time": 0.000637282,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "expected \"grep: /etc/dconf/db/*/locks/*: No such file or directory\\n\" not to match /.*No such file or directory\\n?$/\nDiff:\n@@ -1,2 +1,2 @@\n-/.*No such file or directory\\n?$/\n+grep: /etc/dconf/db/*/locks/*: No such file or directory\n"
            }
          ]
        },
        {
          "id": "V-71897",
          "title": "The operating system must have the screen package installed.",
          "desc": "A session time-out lock is a temporary action taken when a user stops work\nand moves away from the immediate physical vicinity of the information system\nbut does not log out because of the temporary nature of the absence. Rather\nthan relying on the user to manually lock their operating system session prior\nto vacating the vicinity, operating systems need to be able to identify when a\nuser's session has idled and take action to initiate the session lock.\n\n    The screen package allows for a session lock to be implemented and\nconfigured.",
          "descriptions": [
            {
              "label": "default",
              "data": "A session time-out lock is a temporary action taken when a user stops work\nand moves away from the immediate physical vicinity of the information system\nbut does not log out because of the temporary nature of the absence. Rather\nthan relying on the user to manually lock their operating system session prior\nto vacating the vicinity, operating systems need to be able to identify when a\nuser's session has idled and take action to initiate the session lock.\n\n    The screen package allows for a session lock to be implemented and\nconfigured."
            },
            {
              "label": "check",
              "data": "Verify the operating system has the screen package installed.\n\nCheck to see if the screen package is installed with the following command:\n\n# yum list installed | grep screen\nscreen-4.3.1-3-x86_64.rpm\n\nIf is not installed, this is a finding."
            },
            {
              "label": "fix",
              "data": "Install the screen package to allow the initiation a session lock\nafter a 15-minute period of inactivity for graphical users interfaces.\n\nInstall the screen program (if it is not on the system) with the following\ncommand:\n\n# yum install screen\n\nThe console can now be locked with the following key combination:\n\nctrl+A x"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000029-GPOS-00010",
            "gid": "V-71897",
            "rid": "SV-86521r1_rule",
            "stig_id": "RHEL-07-010090",
            "cci": [
              "CCI-000057"
            ],
            "documentable": false,
            "nist": [
              "AC-11 a",
              "Rev_4"
            ],
            "subsystems": [
              "screen",
              "lock",
              "session"
            ],
            "fix_id": "F-78249r1_fix"
          },
          "code": "control \"V-71897\" do\n  title \"The operating system must have the screen package installed.\"\n  desc  \"\n    A session time-out lock is a temporary action taken when a user stops work\nand moves away from the immediate physical vicinity of the information system\nbut does not log out because of the temporary nature of the absence. Rather\nthan relying on the user to manually lock their operating system session prior\nto vacating the vicinity, operating systems need to be able to identify when a\nuser's session has idled and take action to initiate the session lock.\n\n    The screen package allows for a session lock to be implemented and\nconfigured.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000029-GPOS-00010\"\n  tag \"gid\": \"V-71897\"\n  tag \"rid\": \"SV-86521r1_rule\"\n  tag \"stig_id\": \"RHEL-07-010090\"\n  tag \"cci\": [\"CCI-000057\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-11 a\", \"Rev_4\"]\n  tag \"subsystems\": [\"screen\", \"lock\", \"session\"]\n  desc \"check\", \"Verify the operating system has the screen package installed.\n\nCheck to see if the screen package is installed with the following command:\n\n# yum list installed | grep screen\nscreen-4.3.1-3-x86_64.rpm\n\nIf is not installed, this is a finding.\"\n  desc \"fix\", \"Install the screen package to allow the initiation a session lock\nafter a 15-minute period of inactivity for graphical users interfaces.\n\nInstall the screen program (if it is not on the system) with the following\ncommand:\n\n# yum install screen\n\nThe console can now be locked with the following key combination:\n\nctrl+A x\"\n  tag \"fix_id\": \"F-78249r1_fix\"\n  describe package('screen') do\n    it { should be_installed }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71897.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "System Package screen should be installed",
              "run_time": 0.039500686,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "expected that `System Package screen` is installed"
            }
          ]
        },
        {
          "id": "V-71899",
          "title": "The operating system must initiate a session lock for the screensaver\nafter a period of inactivity for graphical user interfaces.",
          "desc": "A session time-out lock is a temporary action taken when a user stops work\nand moves away from the immediate physical vicinity of the information system\nbut does not log out because of the temporary nature of the absence. Rather\nthan relying on the user to manually lock their operating system session prior\nto vacating the vicinity, operating systems need to be able to identify when a\nuser's session has idled and take action to initiate the session lock.\n\n    The session lock is implemented at the point where session activity can be\ndetermined and/or controlled.",
          "descriptions": [
            {
              "label": "default",
              "data": "A session time-out lock is a temporary action taken when a user stops work\nand moves away from the immediate physical vicinity of the information system\nbut does not log out because of the temporary nature of the absence. Rather\nthan relying on the user to manually lock their operating system session prior\nto vacating the vicinity, operating systems need to be able to identify when a\nuser's session has idled and take action to initiate the session lock.\n\n    The session lock is implemented at the point where session activity can be\ndetermined and/or controlled."
            },
            {
              "label": "check",
              "data": "Verify the operating system initiates a session lock after a\n15-minute period of inactivity for graphical user interfaces. The screen\nprogram must be installed to lock sessions on the console.\n\nIf it is installed, GNOME must be configured to enforce a session lock after a\n15-minute delay. Check for the session lock settings with the following\ncommands:\n\n# grep -i  idle-activation-enabled /etc/dconf/db/local.d/*\n\nidle-activation-enabled=true\n\nIf \"idle-activation-enabled\" is not set to \"true\", this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to initiate a session lock after a\n15-minute period of inactivity for graphical user interfaces.\n\nCreate a database to contain the system-wide screensaver settings (if it does\nnot already exist) with the following command:\n\n# touch /etc/dconf/db/local.d/00-screensaver\n\nAdd the setting to enable screensaver locking after 15 minutes of inactivity:\n\n[org/gnome/desktop/screensaver]\n\nidle-activation-enabled=true\n\nUpdate the system databases:\n\n# dconf update\n\nUsers must log out and back in again before the system-wide settings take\neffect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000029-GPOS-00010",
            "gid": "V-71899",
            "rid": "SV-86523r3_rule",
            "stig_id": "RHEL-07-010100",
            "cci": [
              "CCI-000057"
            ],
            "documentable": false,
            "nist": [
              "AC-11 a",
              "Rev_4"
            ],
            "subsystems": [
              "gnome3",
              "session",
              "lock"
            ],
            "fix_id": "F-78251r2_fix"
          },
          "code": "control \"V-71899\" do\n  title \"The operating system must initiate a session lock for the screensaver\nafter a period of inactivity for graphical user interfaces.\"\n  desc  \"\n    A session time-out lock is a temporary action taken when a user stops work\nand moves away from the immediate physical vicinity of the information system\nbut does not log out because of the temporary nature of the absence. Rather\nthan relying on the user to manually lock their operating system session prior\nto vacating the vicinity, operating systems need to be able to identify when a\nuser's session has idled and take action to initiate the session lock.\n\n    The session lock is implemented at the point where session activity can be\ndetermined and/or controlled.\n  \"\n  if package('gnome-desktop3').installed?\n    impact 0.5\n  else\n    impact 0.0\n  end\n  tag \"gtitle\": \"SRG-OS-000029-GPOS-00010\"\n  tag \"gid\": \"V-71899\"\n  tag \"rid\": \"SV-86523r3_rule\"\n  tag \"stig_id\": \"RHEL-07-010100\"\n  tag \"cci\": [\"CCI-000057\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-11 a\", \"Rev_4\"]\n  tag \"subsystems\": [\"gnome3\", \"session\", \"lock\"]\n  desc \"check\", \"Verify the operating system initiates a session lock after a\n15-minute period of inactivity for graphical user interfaces. The screen\nprogram must be installed to lock sessions on the console.\n\nIf it is installed, GNOME must be configured to enforce a session lock after a\n15-minute delay. Check for the session lock settings with the following\ncommands:\n\n# grep -i  idle-activation-enabled /etc/dconf/db/local.d/*\n\nidle-activation-enabled=true\n\nIf \\\"idle-activation-enabled\\\" is not set to \\\"true\\\", this is a finding.\"\n  desc \"fix\", \"Configure the operating system to initiate a session lock after a\n15-minute period of inactivity for graphical user interfaces.\n\nCreate a database to contain the system-wide screensaver settings (if it does\nnot already exist) with the following command:\n\n# touch /etc/dconf/db/local.d/00-screensaver\n\nAdd the setting to enable screensaver locking after 15 minutes of inactivity:\n\n[org/gnome/desktop/screensaver]\n\nidle-activation-enabled=true\n\nUpdate the system databases:\n\n# dconf update\n\nUsers must log out and back in again before the system-wide settings take\neffect.\"\n  tag \"fix_id\": \"F-78251r2_fix\"\n\n  describe command('gsettings get org.gnome.desktop.screensaver idle-activation-enabled') do\n    its('stdout.strip') { should cmp 'true' }\n  end if package('gnome-desktop3').installed?\n\n  describe \"The system does not have GNOME installed\" do\n    skip \"The system does not have GNOME installed, this requirement is Not\n    Applicable.\"\n  end if !package('gnome-desktop3').installed?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71899.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Command: `gsettings get org.gnome.desktop.screensaver idle-activation-enabled` stdout.strip should cmp == \"true\"",
              "run_time": 0.016845558,
              "start_time": "2019-11-04T16:17:07-05:00"
            }
          ]
        },
        {
          "id": "V-71901",
          "title": "The operating system must initiate a session lock for graphical user\ninterfaces when the screensaver is activated.",
          "desc": "A session time-out lock is a temporary action taken when a user stops work\nand moves away from the immediate physical vicinity of the information system\nbut does not log out because of the temporary nature of the absence. Rather\nthan relying on the user to manually lock their operating system session prior\nto vacating the vicinity, operating systems need to be able to identify when a\nuser's session has idled and take action to initiate the session lock.\n\n    The session lock is implemented at the point where session activity can be\ndetermined and/or controlled.",
          "descriptions": [
            {
              "label": "default",
              "data": "A session time-out lock is a temporary action taken when a user stops work\nand moves away from the immediate physical vicinity of the information system\nbut does not log out because of the temporary nature of the absence. Rather\nthan relying on the user to manually lock their operating system session prior\nto vacating the vicinity, operating systems need to be able to identify when a\nuser's session has idled and take action to initiate the session lock.\n\n    The session lock is implemented at the point where session activity can be\ndetermined and/or controlled."
            },
            {
              "label": "check",
              "data": "Verify the operating system initiates a session lock a for\ngraphical user interfaces when the screensaver is activated.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable. The screen program must be installed to lock sessions on the\nconsole.\n\nIf GNOME is installed, check to see a session lock occurs when the screensaver\nis activated with the following command:\n\n# grep -i lock-delay /etc/dconf/db/local.d/*\nlock-delay=uint32 5\n\nIf the \"lock-delay\" setting is missing, or is not set to \"5\" or less, this is\na finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to initiate a session lock for\ngraphical user interfaces when a screensaver is activated.\n\nCreate a database to contain the system-wide screensaver settings (if it does\nnot already exist) with the following command:\n\n# touch /etc/dconf/db/local.d/00-screensaver\n\nAdd the setting to enable session locking when a screensaver is activated:\n\n[org/gnome/desktop/screensaver]\nlock-delay=uint32 5\n\nThe \"uint32\" must be included along with the integer key values as shown.\n\nUpdate the system databases:\n\n# dconf update\n\nUsers must log out and back in again before the system-wide settings take\neffect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000029-GPOS-00010",
            "gid": "V-71901",
            "rid": "SV-86525r2_rule",
            "stig_id": "RHEL-07-010110",
            "cci": [
              "CCI-000057"
            ],
            "documentable": false,
            "nist": [
              "AC-11 a",
              "Rev_4"
            ],
            "subsystems": [
              "gnome3",
              "screensaver",
              "lock",
              "session"
            ],
            "fix_id": "F-78253r2_fix"
          },
          "code": "control \"V-71901\" do\n  title \"The operating system must initiate a session lock for graphical user\ninterfaces when the screensaver is activated.\"\n  desc  \"\n    A session time-out lock is a temporary action taken when a user stops work\nand moves away from the immediate physical vicinity of the information system\nbut does not log out because of the temporary nature of the absence. Rather\nthan relying on the user to manually lock their operating system session prior\nto vacating the vicinity, operating systems need to be able to identify when a\nuser's session has idled and take action to initiate the session lock.\n\n    The session lock is implemented at the point where session activity can be\ndetermined and/or controlled.\n  \"\n  if package('gnome-desktop3').installed?\n    impact 0.5\n  else\n    impact 0.0\n  end\n  tag \"gtitle\": \"SRG-OS-000029-GPOS-00010\"\n  tag \"gid\": \"V-71901\"\n  tag \"rid\": \"SV-86525r2_rule\"\n  tag \"stig_id\": \"RHEL-07-010110\"\n  tag \"cci\": [\"CCI-000057\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-11 a\", \"Rev_4\"]\n  tag \"subsystems\": [\"gnome3\", \"screensaver\", \"lock\", \"session\"]\n  desc \"check\", \"Verify the operating system initiates a session lock a for\ngraphical user interfaces when the screensaver is activated.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable. The screen program must be installed to lock sessions on the\nconsole.\n\nIf GNOME is installed, check to see a session lock occurs when the screensaver\nis activated with the following command:\n\n# grep -i lock-delay /etc/dconf/db/local.d/*\nlock-delay=uint32 5\n\nIf the \\\"lock-delay\\\" setting is missing, or is not set to \\\"5\\\" or less, this is\na finding.\"\n  desc \"fix\", \"Configure the operating system to initiate a session lock for\ngraphical user interfaces when a screensaver is activated.\n\nCreate a database to contain the system-wide screensaver settings (if it does\nnot already exist) with the following command:\n\n# touch /etc/dconf/db/local.d/00-screensaver\n\nAdd the setting to enable session locking when a screensaver is activated:\n\n[org/gnome/desktop/screensaver]\nlock-delay=uint32 5\n\nThe \\\"uint32\\\" must be included along with the integer key values as shown.\n\nUpdate the system databases:\n\n# dconf update\n\nUsers must log out and back in again before the system-wide settings take\neffect.\"\n  tag \"fix_id\": \"F-78253r2_fix\"\n\n  describe command(\"gsettings get org.gnome.desktop.screensaver lock-delay | cut -d ' ' -f2\") do\n    its('stdout.strip') { should cmp <= lock_delay }\n  end if package('gnome-desktop3').installed?\n\n  describe \"The system does not have GNOME installed\" do\n    skip \"The system does not have GNOME installed, this requirement is Not\n    Applicable.\"\n  end if !package('gnome-desktop3').installed?\nend\n",
          "source_location": {
            "line": 9,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71901.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Command: `gsettings get org.gnome.desktop.screensaver lock-delay | cut -d ' ' -f2` stdout.strip should cmp <= 5",
              "run_time": 0.021657817,
              "start_time": "2019-11-04T16:17:07-05:00"
            }
          ]
        },
        {
          "id": "V-71903",
          "title": "When passwords are changed or new passwords are established, the new\npassword must contain at least one upper-case character.",
          "desc": "Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised.",
          "descriptions": [
            {
              "label": "default",
              "data": "Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised."
            },
            {
              "label": "check",
              "data": "Note: The value to require a number of upper-case characters to\nbe set is expressed as a negative number in \"/etc/security/pwquality.conf\".\n\nCheck the value for \"ucredit\" in \"/etc/security/pwquality.conf\" with the\nfollowing command:\n\n# grep ucredit /etc/security/pwquality.conf\nucredit = -1\n\nIf the value of \"ucredit\" is not set to a negative value, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to enforce password complexity by\nrequiring that at least one upper-case character be used by setting the\n\"ucredit\" option.\n\nAdd the following line to \"/etc/security/pwquality.conf\" (or modify the line\nto have the required value):\n\nucredit = -1"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000069-GPOS-00037",
            "gid": "V-71903",
            "rid": "SV-86527r2_rule",
            "stig_id": "RHEL-07-010120",
            "cci": [
              "CCI-000192"
            ],
            "documentable": false,
            "nist": [
              "IA-5 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "pam",
              "pwquality",
              "password"
            ],
            "fix_id": "F-78255r1_fix"
          },
          "code": "control \"V-71903\" do\n  title \"When passwords are changed or new passwords are established, the new\npassword must contain at least one upper-case character.\"\n  desc  \"\n    Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000069-GPOS-00037\"\n  tag \"gid\": \"V-71903\"\n  tag \"rid\": \"SV-86527r2_rule\"\n  tag \"stig_id\": \"RHEL-07-010120\"\n  tag \"cci\": [\"CCI-000192\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-5 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['pam', 'pwquality', 'password']\n  desc \"check\", \"Note: The value to require a number of upper-case characters to\nbe set is expressed as a negative number in \\\"/etc/security/pwquality.conf\\\".\n\nCheck the value for \\\"ucredit\\\" in \\\"/etc/security/pwquality.conf\\\" with the\nfollowing command:\n\n# grep ucredit /etc/security/pwquality.conf\nucredit = -1\n\nIf the value of \\\"ucredit\\\" is not set to a negative value, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to enforce password complexity by\nrequiring that at least one upper-case character be used by setting the\n\\\"ucredit\\\" option.\n\nAdd the following line to \\\"/etc/security/pwquality.conf\\\" (or modify the line\nto have the required value):\n\nucredit = -1\"\n  tag \"fix_id\": \"F-78255r1_fix\"\n  describe parse_config_file(\"/etc/security/pwquality.conf\") do\n    its('ucredit.to_i') { should cmp < 0 }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71903.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/security/pwquality.conf ucredit.to_i should cmp < 0",
              "run_time": 0.000228584,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "\nexpected it to be < 0\n     got: 0\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-71905",
          "title": "When passwords are changed or new passwords are established, the new\npassword must contain at least one lower-case character.",
          "desc": "Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised.",
          "descriptions": [
            {
              "label": "default",
              "data": "Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised."
            },
            {
              "label": "check",
              "data": "Note: The value to require a number of lower-case characters to\nbe set is expressed as a negative number in \"/etc/security/pwquality.conf\".\n\nCheck the value for \"lcredit\" in \"/etc/security/pwquality.conf\" with the\nfollowing command:\n\n# grep lcredit /etc/security/pwquality.conf\nlcredit = -1\n\nIf the value of \"lcredit\" is not set to a negative value, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to lock an account for the maximum\nperiod when three unsuccessful logon attempts in 15 minutes are made.\n\nModify the first three lines of the \"auth\" section of the\n\"/etc/pam.d/system-auth-ac\" and \"/etc/pam.d/password-auth-ac\" files to match the\nfollowing lines:\n\nNote: RHEL 7.3 and later allows for a value of \"never\" for \"unlock_time\". This is\nan acceptable value but should be used with caution if availability is a concern.\n\nauth        required       pam_faillock.so preauth silent audit deny=3\neven_deny_root fail_interval=900 unlock_time=604800\nauth        sufficient     pam_unix.so try_first_pass\nauth        [default=die]  pam_faillock.so authfail audit deny=3 even_deny_root\nfail_interval=900 unlock_time=604800\n\nand run the \"authconfig\" command."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000070-GPOS-00038",
            "gid": "V-71905",
            "rid": "SV-86529r4_rule",
            "stig_id": "RHEL-07-010130",
            "cci": [
              "CCI-000193"
            ],
            "documentable": false,
            "nist": [
              "IA-5 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "pam",
              "pwquality",
              "password"
            ]
          },
          "code": "control \"V-71905\" do\n  title \"When passwords are changed or new passwords are established, the new\npassword must contain at least one lower-case character.\"\n  desc  \"\n    Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000070-GPOS-00038\"\n  tag \"gid\": \"V-71905\"\n  tag \"rid\": \"SV-86529r4_rule\"\n  tag \"stig_id\": \"RHEL-07-010130\"\n  tag \"cci\": [\"CCI-000193\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-5 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['pam', 'pwquality', 'password']\n  desc \"check\", \"Note: The value to require a number of lower-case characters to\nbe set is expressed as a negative number in \\\"/etc/security/pwquality.conf\\\".\n\nCheck the value for \\\"lcredit\\\" in \\\"/etc/security/pwquality.conf\\\" with the\nfollowing command:\n\n# grep lcredit /etc/security/pwquality.conf\nlcredit = -1\n\nIf the value of \\\"lcredit\\\" is not set to a negative value, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to lock an account for the maximum\nperiod when three unsuccessful logon attempts in 15 minutes are made.\n\nModify the first three lines of the \\\"auth\\\" section of the\n\\\"/etc/pam.d/system-auth-ac\\\" and \\\"/etc/pam.d/password-auth-ac\\\" files to match the\nfollowing lines:\n\nNote: RHEL 7.3 and later allows for a value of \\\"never\\\" for \\\"unlock_time\\\". This is\nan acceptable value but should be used with caution if availability is a concern.\n\nauth        required       pam_faillock.so preauth silent audit deny=3\neven_deny_root fail_interval=900 unlock_time=604800\nauth        sufficient     pam_unix.so try_first_pass\nauth        [default=die]  pam_faillock.so authfail audit deny=3 even_deny_root\nfail_interval=900 unlock_time=604800\n\nand run the \\\"authconfig\\\" command.\"\n\n  describe parse_config_file(\"/etc/security/pwquality.conf\") do\n    its('lcredit.to_i') { should cmp < 0 }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71905.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/security/pwquality.conf lcredit.to_i should cmp < 0",
              "run_time": 0.000132022,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "\nexpected it to be < 0\n     got: 0\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-71907",
          "title": "When passwords are changed or new passwords are assigned, the new\npassword must contain at least one numeric character.",
          "desc": "Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised.",
          "descriptions": [
            {
              "label": "default",
              "data": "Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised."
            },
            {
              "label": "check",
              "data": "Note: The value to require a number of numeric characters to be\nset is expressed as a negative number in \"/etc/security/pwquality.conf\".\n\nCheck the value for \"dcredit\" in \"/etc/security/pwquality.conf\" with the\nfollowing command:\n\n# grep dcredit /etc/security/pwquality.conf\ndcredit = -1\n\nIf the value of \"dcredit\" is not set to a negative value, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to enforce password complexity by\nrequiring that at least one numeric character be used by setting the\n\"dcredit\" option.\n\nAdd the following line to /etc/security/pwquality.conf (or modify the line to\nhave the required value):\n\ndcredit = -1"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000071-GPOS-00039",
            "gid": "V-71907",
            "rid": "SV-86531r2_rule",
            "stig_id": "RHEL-07-010140",
            "cci": [
              "CCI-000194"
            ],
            "documentable": false,
            "nist": [
              "IA-5 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "pam",
              "pwquality",
              "password"
            ],
            "fix_id": "F-78259r1_fix"
          },
          "code": "control \"V-71907\" do\n  title \"When passwords are changed or new passwords are assigned, the new\npassword must contain at least one numeric character.\"\n  desc  \"\n    Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000071-GPOS-00039\"\n  tag \"gid\": \"V-71907\"\n  tag \"rid\": \"SV-86531r2_rule\"\n  tag \"stig_id\": \"RHEL-07-010140\"\n  tag \"cci\": [\"CCI-000194\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-5 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['pam', 'pwquality', 'password']\n  desc \"check\", \"Note: The value to require a number of numeric characters to be\nset is expressed as a negative number in \\\"/etc/security/pwquality.conf\\\".\n\nCheck the value for \\\"dcredit\\\" in \\\"/etc/security/pwquality.conf\\\" with the\nfollowing command:\n\n# grep dcredit /etc/security/pwquality.conf\ndcredit = -1\n\nIf the value of \\\"dcredit\\\" is not set to a negative value, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to enforce password complexity by\nrequiring that at least one numeric character be used by setting the\n\\\"dcredit\\\" option.\n\nAdd the following line to /etc/security/pwquality.conf (or modify the line to\nhave the required value):\n\ndcredit = -1\"\n  tag \"fix_id\": \"F-78259r1_fix\"\n  describe parse_config_file(\"/etc/security/pwquality.conf\") do\n    its('dcredit.to_i') { should cmp < 0 }\nend\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71907.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/security/pwquality.conf dcredit.to_i should cmp < 0",
              "run_time": 0.000125648,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "\nexpected it to be < 0\n     got: 0\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-71909",
          "title": "When passwords are changed or new passwords are assigned, the new\npassword must contain at least one special character.",
          "desc": "Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised.",
          "descriptions": [
            {
              "label": "default",
              "data": "Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised."
            },
            {
              "label": "check",
              "data": "Verify the operating system enforces password complexity by\nrequiring that at least one special character be used.\n\nNote: The value to require a number of special characters to be set is\nexpressed as a negative number in \"/etc/security/pwquality.conf\".\n\nCheck the value for \"ocredit\" in \"/etc/security/pwquality.conf\" with the\nfollowing command:\n\n# grep ocredit /etc/security/pwquality.conf\nocredit=-1\n\nIf the value of \"ocredit\" is not set to a negative value, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to enforce password complexity by\nrequiring that at least one special character be used by setting the\n\"dcredit\" option.\n\nAdd the following line to \"/etc/security/pwquality.conf\" (or modify the line\nto have the required value):\n\nocredit = -1"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000266-GPOS-00101",
            "gid": "V-71909",
            "rid": "SV-86533r1_rule",
            "stig_id": "RHEL-07-010150",
            "cci": [
              "CCI-001619"
            ],
            "documentable": false,
            "nist": [
              "IA-5 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "pam",
              "pwquality",
              "password"
            ],
            "fix_id": "F-78261r1_fix"
          },
          "code": "control \"V-71909\" do\n  title \"When passwords are changed or new passwords are assigned, the new\npassword must contain at least one special character.\"\n  desc  \"\n    Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000266-GPOS-00101\"\n  tag \"gid\": \"V-71909\"\n  tag \"rid\": \"SV-86533r1_rule\"\n  tag \"stig_id\": \"RHEL-07-010150\"\n  tag \"cci\": [\"CCI-001619\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-5 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['pam', 'pwquality', 'password']\n  desc \"check\", \"Verify the operating system enforces password complexity by\nrequiring that at least one special character be used.\n\nNote: The value to require a number of special characters to be set is\nexpressed as a negative number in \\\"/etc/security/pwquality.conf\\\".\n\nCheck the value for \\\"ocredit\\\" in \\\"/etc/security/pwquality.conf\\\" with the\nfollowing command:\n\n# grep ocredit /etc/security/pwquality.conf\nocredit=-1\n\nIf the value of \\\"ocredit\\\" is not set to a negative value, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to enforce password complexity by\nrequiring that at least one special character be used by setting the\n\\\"dcredit\\\" option.\n\nAdd the following line to \\\"/etc/security/pwquality.conf\\\" (or modify the line\nto have the required value):\n\nocredit = -1\"\n  tag \"fix_id\": \"F-78261r1_fix\"\n  describe parse_config_file(\"/etc/security/pwquality.conf\") do\n    its('ocredit.to_i') { should cmp < 0 }\nend\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71909.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/security/pwquality.conf ocredit.to_i should cmp < 0",
              "run_time": 0.000129722,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "\nexpected it to be < 0\n     got: 0\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-71911",
          "title": "When passwords are changed a minimum of eight of the total number of\ncharacters must be changed.",
          "desc": "Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised.",
          "descriptions": [
            {
              "label": "default",
              "data": "Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised."
            },
            {
              "label": "check",
              "data": "The \"difok\" option sets the number of characters in a\npassword that must not be present in the old password.\n\nCheck for the value of the \"difok\" option in \"/etc/security/pwquality.conf\"\nwith the following command:\n\n# grep difok /etc/security/pwquality.conf\ndifok = 8\n\nIf the value of \"difok\" is set to less than \"8\", this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to require the change of at least\neight of the total number of characters when passwords are changed by setting\nthe \"difok\" option.\n\nAdd the following line to \"/etc/security/pwquality.conf\" (or modify the line\nto have the required value):\n\ndifok = 8"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000072-GPOS-00040",
            "gid": "V-71911",
            "rid": "SV-86535r1_rule",
            "stig_id": "RHEL-07-010160",
            "cci": [
              "CCI-000195"
            ],
            "documentable": false,
            "nist": [
              "IA-5 (1) (b)",
              "Rev_4"
            ],
            "subsystems": [
              "pam",
              "pwquality",
              "password"
            ],
            "fix_id": "F-78263r1_fix"
          },
          "code": "control \"V-71911\" do\n  title \"When passwords are changed a minimum of eight of the total number of\ncharacters must be changed.\"\n  desc  \"\n    Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000072-GPOS-00040\"\n  tag \"gid\": \"V-71911\"\n  tag \"rid\": \"SV-86535r1_rule\"\n  tag \"stig_id\": \"RHEL-07-010160\"\n  tag \"cci\": [\"CCI-000195\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-5 (1) (b)\", \"Rev_4\"]\n  tag \"subsystems\": ['pam', 'pwquality', 'password']\n  desc \"check\", \"The \\\"difok\\\" option sets the number of characters in a\npassword that must not be present in the old password.\n\nCheck for the value of the \\\"difok\\\" option in \\\"/etc/security/pwquality.conf\\\"\nwith the following command:\n\n# grep difok /etc/security/pwquality.conf\ndifok = 8\n\nIf the value of \\\"difok\\\" is set to less than \\\"8\\\", this is a finding.\"\n  desc \"fix\", \"Configure the operating system to require the change of at least\neight of the total number of characters when passwords are changed by setting\nthe \\\"difok\\\" option.\n\nAdd the following line to \\\"/etc/security/pwquality.conf\\\" (or modify the line\nto have the required value):\n\ndifok = 8\"\n  tag \"fix_id\": \"F-78263r1_fix\"\n  describe parse_config_file(\"/etc/security/pwquality.conf\") do\n    its('difok.to_i') { should cmp >= difok }\n  end\nend\n",
          "source_location": {
            "line": 8,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71911.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/security/pwquality.conf difok.to_i should cmp >= 8",
              "run_time": 0.00014405,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "\nexpected it to be >= 8\n     got: 0\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-71913",
          "title": "When passwords are changed a minimum of four character classes must be\nchanged.",
          "desc": "Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised.",
          "descriptions": [
            {
              "label": "default",
              "data": "Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised."
            },
            {
              "label": "check",
              "data": "The \"minclass\" option sets the minimum number of required\nclasses of characters for the new password (digits, upper-case, lower-case,\nothers).\n\nCheck for the value of the \"minclass\" option in\n\"/etc/security/pwquality.conf\" with the following command:\n\n# grep minclass /etc/security/pwquality.conf\nminclass = 4\n\nIf the value of \"minclass\" is set to less than \"4\", this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to require the change of at least\nfour character classes when passwords are changed by setting the \"minclass\"\noption.\n\nAdd the following line to \"/etc/security/pwquality.conf conf\" (or modify the\nline to have the required value):\n\nminclass = 4"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000072-GPOS-00040",
            "gid": "V-71913",
            "rid": "SV-86537r1_rule",
            "stig_id": "RHEL-07-010170",
            "cci": [
              "CCI-000195"
            ],
            "documentable": false,
            "nist": [
              "IA-5 (1) (b)",
              "Rev_4"
            ],
            "subsystems": [
              "pam",
              "pwquality",
              "password"
            ],
            "fix_id": "F-78265r1_fix"
          },
          "code": "control \"V-71913\" do\n  title \"When passwords are changed a minimum of four character classes must be\nchanged.\"\n  desc  \"\n    Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000072-GPOS-00040\"\n  tag \"gid\": \"V-71913\"\n  tag \"rid\": \"SV-86537r1_rule\"\n  tag \"stig_id\": \"RHEL-07-010170\"\n  tag \"cci\": [\"CCI-000195\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-5 (1) (b)\", \"Rev_4\"]\n  tag \"subsystems\": ['pam', 'pwquality', 'password']\n  desc \"check\", \"The \\\"minclass\\\" option sets the minimum number of required\nclasses of characters for the new password (digits, upper-case, lower-case,\nothers).\n\nCheck for the value of the \\\"minclass\\\" option in\n\\\"/etc/security/pwquality.conf\\\" with the following command:\n\n# grep minclass /etc/security/pwquality.conf\nminclass = 4\n\nIf the value of \\\"minclass\\\" is set to less than \\\"4\\\", this is a finding.\"\n  desc \"fix\", \"Configure the operating system to require the change of at least\nfour character classes when passwords are changed by setting the \\\"minclass\\\"\noption.\n\nAdd the following line to \\\"/etc/security/pwquality.conf conf\\\" (or modify the\nline to have the required value):\n\nminclass = 4\"\n  tag \"fix_id\": \"F-78265r1_fix\"\n  describe parse_config_file(\"/etc/security/pwquality.conf\") do\n    its('minclass.to_i') { should cmp >= 4 }\n  end\nend\n",
          "source_location": {
            "line": 6,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71913.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/security/pwquality.conf minclass.to_i should cmp >= 4",
              "run_time": 0.000139995,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "\nexpected it to be >= 4\n     got: 0\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-71915",
          "title": "When passwords are changed the number of repeating consecutive\ncharacters must not be more than three characters.",
          "desc": "Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised.",
          "descriptions": [
            {
              "label": "default",
              "data": "Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised."
            },
            {
              "label": "check",
              "data": "The \"maxrepeat\" option sets the maximum number of allowed\nsame consecutive characters in a new password.\n\nCheck for the value of the \"maxrepeat\" option in\n\"/etc/security/pwquality.conf\" with the following command:\n\n# grep maxrepeat /etc/security/pwquality.conf\nmaxrepeat = 3\n\nIf the value of \"maxrepeat\" is set to more than \"3\", this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to require the change of the\nnumber of repeating consecutive characters when passwords are changed by\nsetting the \"maxrepeat\" option.\n\nAdd the following line to \"/etc/security/pwquality.conf conf\" (or modify the\nline to have the required value):\n\nmaxrepeat = 3"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000072-GPOS-00040",
            "gid": "V-71915",
            "rid": "SV-86539r2_rule",
            "stig_id": "RHEL-07-010180",
            "cci": [
              "CCI-000195"
            ],
            "documentable": false,
            "nist": [
              "IA-5 (1) (b)",
              "Rev_4"
            ],
            "subsystems": [
              "pam",
              "pwquality",
              "password"
            ],
            "fix_id": "F-78267r2_fix"
          },
          "code": "control \"V-71915\" do\n  title \"When passwords are changed the number of repeating consecutive\ncharacters must not be more than three characters.\"\n  desc  \"\n    Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000072-GPOS-00040\"\n  tag \"gid\": \"V-71915\"\n  tag \"rid\": \"SV-86539r2_rule\"\n  tag \"stig_id\": \"RHEL-07-010180\"\n  tag \"cci\": [\"CCI-000195\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-5 (1) (b)\", \"Rev_4\"]\n  tag \"subsystems\": ['pam', 'pwquality', 'password']\n  desc \"check\", \"The \\\"maxrepeat\\\" option sets the maximum number of allowed\nsame consecutive characters in a new password.\n\nCheck for the value of the \\\"maxrepeat\\\" option in\n\\\"/etc/security/pwquality.conf\\\" with the following command:\n\n# grep maxrepeat /etc/security/pwquality.conf\nmaxrepeat = 3\n\nIf the value of \\\"maxrepeat\\\" is set to more than \\\"3\\\", this is a finding.\"\n  desc \"fix\", \"Configure the operating system to require the change of the\nnumber of repeating consecutive characters when passwords are changed by\nsetting the \\\"maxrepeat\\\" option.\n\nAdd the following line to \\\"/etc/security/pwquality.conf conf\\\" (or modify the\nline to have the required value):\n\nmaxrepeat = 3\"\n  tag \"fix_id\": \"F-78267r2_fix\"\n  describe parse_config_file(\"/etc/security/pwquality.conf\") do\n    its('maxrepeat.to_i') { should cmp <= 3 }\n  end\nend\n",
          "source_location": {
            "line": 6,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71915.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Parse Config File /etc/security/pwquality.conf maxrepeat.to_i should cmp <= 3",
              "run_time": 0.000117557,
              "start_time": "2019-11-04T16:17:07-05:00"
            }
          ]
        },
        {
          "id": "V-71917",
          "title": "When passwords are changed the number of repeating characters of the\nsame character class must not be more than four characters.",
          "desc": "Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised.",
          "descriptions": [
            {
              "label": "default",
              "data": "Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised."
            },
            {
              "label": "check",
              "data": "The \"maxclassrepeat\" option sets the maximum number of\nallowed same consecutive characters in the same class in the new password.\n\nCheck for the value of the \"maxclassrepeat\" option in\n\"/etc/security/pwquality.conf\" with the following command:\n\n# grep maxclassrepeat /etc/security/pwquality.conf\nmaxclassrepeat = 4\n\nIf the value of \"maxclassrepeat\" is set to more than \"4\", this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to require the change of the\nnumber of repeating characters of the same character class when passwords are\nchanged by setting the \"maxclassrepeat\" option.\n\nAdd the following line to \"/etc/security/pwquality.conf\" conf (or modify the\nline to have the required value):\n\nmaxclassrepeat = 4"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000072-GPOS-00040",
            "gid": "V-71917",
            "rid": "SV-86541r1_rule",
            "stig_id": "RHEL-07-010190",
            "cci": [
              "CCI-000195"
            ],
            "documentable": false,
            "nist": [
              "IA-5 (1) (b)",
              "Rev_4"
            ],
            "subsystems": [
              "pam",
              "pwquality",
              "password"
            ],
            "fix_id": "F-78269r1_fix"
          },
          "code": "control \"V-71917\" do\n  title \"When passwords are changed the number of repeating characters of the\nsame character class must not be more than four characters.\"\n  desc  \"\n    Use of a complex password helps to increase the time and resources required\nto compromise the password. Password complexity, or strength, is a measure of\nthe effectiveness of a password in resisting attempts at guessing and\nbrute-force attacks.\n\n    Password complexity is one factor of several that determines how long it\ntakes to crack a password. The more complex the password, the greater the\nnumber of possible combinations that need to be tested before the password is\ncompromised.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000072-GPOS-00040\"\n  tag \"gid\": \"V-71917\"\n  tag \"rid\": \"SV-86541r1_rule\"\n  tag \"stig_id\": \"RHEL-07-010190\"\n  tag \"cci\": [\"CCI-000195\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-5 (1) (b)\", \"Rev_4\"]\n  tag \"subsystems\": ['pam', 'pwquality', 'password']\n  desc \"check\", \"The \\\"maxclassrepeat\\\" option sets the maximum number of\nallowed same consecutive characters in the same class in the new password.\n\nCheck for the value of the \\\"maxclassrepeat\\\" option in\n\\\"/etc/security/pwquality.conf\\\" with the following command:\n\n# grep maxclassrepeat /etc/security/pwquality.conf\nmaxclassrepeat = 4\n\nIf the value of \\\"maxclassrepeat\\\" is set to more than \\\"4\\\", this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to require the change of the\nnumber of repeating characters of the same character class when passwords are\nchanged by setting the \\\"maxclassrepeat\\\" option.\n\nAdd the following line to \\\"/etc/security/pwquality.conf\\\" conf (or modify the\nline to have the required value):\n\nmaxclassrepeat = 4\"\n  tag \"fix_id\": \"F-78269r1_fix\"\n  describe parse_config_file(\"/etc/security/pwquality.conf\") do\n    its('maxclassrepeat.to_i') { should cmp <= 4 }\n  end\nend\n",
          "source_location": {
            "line": 6,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71917.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Parse Config File /etc/security/pwquality.conf maxclassrepeat.to_i should cmp <= 4",
              "run_time": 0.000118975,
              "start_time": "2019-11-04T16:17:07-05:00"
            }
          ]
        },
        {
          "id": "V-71919",
          "title": "The PAM system service must be configured to store only encrypted\nrepresentations of passwords.",
          "desc": "Passwords need to be protected at all times, and encryption is the\nstandard method for protecting passwords. If passwords are not encrypted, they\ncan be plainly read (i.e., clear text) and easily compromised. Passwords\nencrypted with a weak algorithm are no more protected than if they are kept in\nplain text.",
          "descriptions": [
            {
              "label": "default",
              "data": "Passwords need to be protected at all times, and encryption is the\nstandard method for protecting passwords. If passwords are not encrypted, they\ncan be plainly read (i.e., clear text) and easily compromised. Passwords\nencrypted with a weak algorithm are no more protected than if they are kept in\nplain text."
            },
            {
              "label": "check",
              "data": "Verify the PAM system service is configured to store only\nencrypted representations of passwords. The strength of encryption that must be\nused to hash passwords for all accounts is SHA512.\n\nCheck that the system is configured to create SHA512 hashed passwords with the\nfollowing command:\n\n# grep password /etc/pam.d/system-auth-ac\npassword sufficient pam_unix.so sha512\n\nIf the \"/etc/pam.d/system-auth-ac\" configuration files allow for password\nhashes other than SHA512 to be used, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to store only SHA512 encrypted\nrepresentations of passwords.\n\nAdd the following line in \"/etc/pam.d/system-auth-ac\":\n\npassword sufficient pam_unix.so sha512"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000073-GPOS-00041",
            "gid": "V-71919",
            "rid": "SV-86543r2_rule",
            "stig_id": "RHEL-07-010200",
            "cci": [
              "CCI-000196"
            ],
            "documentable": false,
            "nist": [
              "IA-5 (1) (c)",
              "Rev_4"
            ],
            "subsystems": [
              "pam",
              "password"
            ],
            "fix_id": "F-78271r2_fix"
          },
          "code": "control \"V-71919\" do\n  title \"The PAM system service must be configured to store only encrypted\nrepresentations of passwords.\"\n  desc  \"Passwords need to be protected at all times, and encryption is the\nstandard method for protecting passwords. If passwords are not encrypted, they\ncan be plainly read (i.e., clear text) and easily compromised. Passwords\nencrypted with a weak algorithm are no more protected than if they are kept in\nplain text.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000073-GPOS-00041\"\n  tag \"gid\": \"V-71919\"\n  tag \"rid\": \"SV-86543r2_rule\"\n  tag \"stig_id\": \"RHEL-07-010200\"\n  tag \"cci\": [\"CCI-000196\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-5 (1) (c)\", \"Rev_4\"]\n  tag \"subsystems\": ['pam', 'password']\n  desc \"check\", \"Verify the PAM system service is configured to store only\nencrypted representations of passwords. The strength of encryption that must be\nused to hash passwords for all accounts is SHA512.\n\nCheck that the system is configured to create SHA512 hashed passwords with the\nfollowing command:\n\n# grep password /etc/pam.d/system-auth-ac\npassword sufficient pam_unix.so sha512\n\nIf the \\\"/etc/pam.d/system-auth-ac\\\" configuration files allow for password\nhashes other than SHA512 to be used, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to store only SHA512 encrypted\nrepresentations of passwords.\n\nAdd the following line in \\\"/etc/pam.d/system-auth-ac\\\":\n\npassword sufficient pam_unix.so sha512\"\n  tag \"fix_id\": \"F-78271r2_fix\"\n\n  describe pam(\"/etc/pam.d/system-auth\") do\n    its('lines') { should match_pam_rule('password sufficient pam_unix.so sha512') }\n    its('lines') { should match_pam_rule('password .* pam_unix.so').all_without_args('^(md5|bigcrypt|sha256|blowfish)$') }\n  end\nend\n",
          "source_location": {
            "line": 6,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71919.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "PAM Config[/etc/pam.d/system-auth] lines should include password sufficient pam_unix.so sha512",
              "run_time": 0.000320866,
              "start_time": "2019-11-04T16:17:07-05:00"
            },
            {
              "status": "passed",
              "code_desc": "PAM Config[/etc/pam.d/system-auth] lines should include password .* pam_unix.so, all without args ^(md5|bigcrypt|sha256|blowfish)$",
              "run_time": 0.000296655,
              "start_time": "2019-11-04T16:17:07-05:00"
            }
          ]
        },
        {
          "id": "V-71921",
          "title": "The shadow file must be configured to store only encrypted\nrepresentations of passwords.",
          "desc": "Passwords need to be protected at all times, and encryption is the\nstandard method for protecting passwords. If passwords are not encrypted, they\ncan be plainly read (i.e., clear text) and easily compromised. Passwords\nencrypted with a weak algorithm are no more protected than if they are kept in\nplain text.",
          "descriptions": [
            {
              "label": "default",
              "data": "Passwords need to be protected at all times, and encryption is the\nstandard method for protecting passwords. If passwords are not encrypted, they\ncan be plainly read (i.e., clear text) and easily compromised. Passwords\nencrypted with a weak algorithm are no more protected than if they are kept in\nplain text."
            },
            {
              "label": "check",
              "data": "Verify the system's shadow file is configured to store only\nencrypted representations of passwords. The strength of encryption that must be\nused to hash passwords for all accounts is SHA512.\n\nCheck that the system is configured to create SHA512 hashed passwords with the\nfollowing command:\n\n# grep -i encrypt /etc/login.defs\nENCRYPT_METHOD SHA512\n\nIf the \"/etc/login.defs\" configuration file does not exist or allows for\npassword hashes other than SHA512 to be used, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to store only SHA512 encrypted\nrepresentations of passwords.\n\nAdd or update the following line in \"/etc/login.defs\":\n\nENCRYPT_METHOD SHA512"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000073-GPOS-00041",
            "gid": "V-71921",
            "rid": "SV-86545r1_rule",
            "stig_id": "RHEL-07-010210",
            "cci": [
              "CCI-000196"
            ],
            "documentable": false,
            "nist": [
              "IA-5 (1) (c)",
              "Rev_4"
            ],
            "subsystems": [
              "login_defs",
              "password"
            ],
            "fix_id": "F-78273r1_fix"
          },
          "code": "control \"V-71921\" do\n  title \"The shadow file must be configured to store only encrypted\nrepresentations of passwords.\"\n  desc  \"Passwords need to be protected at all times, and encryption is the\nstandard method for protecting passwords. If passwords are not encrypted, they\ncan be plainly read (i.e., clear text) and easily compromised. Passwords\nencrypted with a weak algorithm are no more protected than if they are kept in\nplain text.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000073-GPOS-00041\"\n  tag \"gid\": \"V-71921\"\n  tag \"rid\": \"SV-86545r1_rule\"\n  tag \"stig_id\": \"RHEL-07-010210\"\n  tag \"cci\": [\"CCI-000196\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-5 (1) (c)\", \"Rev_4\"]\n  tag \"subsystems\": ['login_defs', 'password']\n  desc \"check\", \"Verify the system's shadow file is configured to store only\nencrypted representations of passwords. The strength of encryption that must be\nused to hash passwords for all accounts is SHA512.\n\nCheck that the system is configured to create SHA512 hashed passwords with the\nfollowing command:\n\n# grep -i encrypt /etc/login.defs\nENCRYPT_METHOD SHA512\n\nIf the \\\"/etc/login.defs\\\" configuration file does not exist or allows for\npassword hashes other than SHA512 to be used, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to store only SHA512 encrypted\nrepresentations of passwords.\n\nAdd or update the following line in \\\"/etc/login.defs\\\":\n\nENCRYPT_METHOD SHA512\"\n  tag \"fix_id\": \"F-78273r1_fix\"\n  describe login_defs do\n    its('ENCRYPT_METHOD') { should cmp \"SHA512\" }\n  end\nend\n",
          "source_location": {
            "line": 6,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71921.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "login.defs ENCRYPT_METHOD should cmp == \"SHA512\"",
              "run_time": 0.00033233,
              "start_time": "2019-11-04T16:17:07-05:00"
            }
          ]
        },
        {
          "id": "V-71923",
          "title": "User and group account administration utilities must be configured to\nstore only encrypted representations of passwords.",
          "desc": "Passwords need to be protected at all times, and encryption is the\nstandard method for protecting passwords. If passwords are not encrypted, they\ncan be plainly read (i.e., clear text) and easily compromised. Passwords\nencrypted with a weak algorithm are no more protected than if they are kept in\nplain text.",
          "descriptions": [
            {
              "label": "default",
              "data": "Passwords need to be protected at all times, and encryption is the\nstandard method for protecting passwords. If passwords are not encrypted, they\ncan be plainly read (i.e., clear text) and easily compromised. Passwords\nencrypted with a weak algorithm are no more protected than if they are kept in\nplain text."
            },
            {
              "label": "check",
              "data": "Verify the user and group account administration utilities are\nconfigured to store only encrypted representations of passwords. The strength\nof encryption that must be used to hash passwords for all accounts is\n\"SHA512\".\n\nCheck that the system is configured to create \"SHA512\" hashed passwords with\nthe following command:\n\n# cat /etc/libuser.conf | grep -i sha512\n\ncrypt_style = sha512\n\nIf the \"crypt_style\" variable is not set to \"sha512\", is not in the\ndefaults section, or does not exist, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to store only SHA512 encrypted\nrepresentations of passwords.\n\nAdd or update the following line in \"/etc/libuser.conf\" in the [defaults]\nsection:\n\ncrypt_style = sha512"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000073-GPOS-00041",
            "gid": "V-71923",
            "rid": "SV-86547r2_rule",
            "stig_id": "RHEL-07-010220",
            "cci": [
              "CCI-000196"
            ],
            "documentable": false,
            "nist": [
              "IA-5 (1) (c)",
              "Rev_4"
            ],
            "subsystems": [
              "libuser_conf",
              "password"
            ],
            "fix_id": "F-78275r1_fix"
          },
          "code": "control \"V-71923\" do\n  title \"User and group account administration utilities must be configured to\nstore only encrypted representations of passwords.\"\n  desc  \"Passwords need to be protected at all times, and encryption is the\nstandard method for protecting passwords. If passwords are not encrypted, they\ncan be plainly read (i.e., clear text) and easily compromised. Passwords\nencrypted with a weak algorithm are no more protected than if they are kept in\nplain text.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000073-GPOS-00041\"\n  tag \"gid\": \"V-71923\"\n  tag \"rid\": \"SV-86547r2_rule\"\n  tag \"stig_id\": \"RHEL-07-010220\"\n  tag \"cci\": [\"CCI-000196\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-5 (1) (c)\", \"Rev_4\"]\n  tag \"subsystems\": ['libuser_conf', 'password']\n  desc \"check\", \"Verify the user and group account administration utilities are\nconfigured to store only encrypted representations of passwords. The strength\nof encryption that must be used to hash passwords for all accounts is\n\\\"SHA512\\\".\n\nCheck that the system is configured to create \\\"SHA512\\\" hashed passwords with\nthe following command:\n\n# cat /etc/libuser.conf | grep -i sha512\n\ncrypt_style = sha512\n\nIf the \\\"crypt_style\\\" variable is not set to \\\"sha512\\\", is not in the\ndefaults section, or does not exist, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to store only SHA512 encrypted\nrepresentations of passwords.\n\nAdd or update the following line in \\\"/etc/libuser.conf\\\" in the [defaults]\nsection:\n\ncrypt_style = sha512\"\n  tag \"fix_id\": \"F-78275r1_fix\"\n  describe command(\"cat /etc/libuser.conf | grep -i sha512\") do\n    its('stdout.strip') { should match %r(^crypt_style = sha512$) }\n  end\nend\n",
          "source_location": {
            "line": 6,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71923.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Command: `cat /etc/libuser.conf | grep -i sha512` stdout.strip should match /^crypt_style = sha512$/",
              "run_time": 0.015757939,
              "start_time": "2019-11-04T16:17:07-05:00"
            }
          ]
        },
        {
          "id": "V-71925",
          "title": "Passwords for new users must be restricted to a 24 hours/1 day minimum\nlifetime.",
          "desc": "Enforcing a minimum password lifetime helps to prevent repeated\npassword changes to defeat the password reuse or history enforcement\nrequirement. If users are allowed to immediately and continually change their\npassword, the password could be repeatedly changed in a short period of time to\ndefeat the organization's policy regarding password reuse.",
          "descriptions": [
            {
              "label": "default",
              "data": "Enforcing a minimum password lifetime helps to prevent repeated\npassword changes to defeat the password reuse or history enforcement\nrequirement. If users are allowed to immediately and continually change their\npassword, the password could be repeatedly changed in a short period of time to\ndefeat the organization's policy regarding password reuse."
            },
            {
              "label": "check",
              "data": "Verify the operating system enforces 24 hours/1 day as the\nminimum password lifetime for new user accounts.\n\nCheck for the value of \"PASS_MIN_DAYS\" in \"/etc/login.defs\" with the\nfollowing command:\n\n# grep -i pass_min_days /etc/login.defs\nPASS_MIN_DAYS     1\n\nIf the \"PASS_MIN_DAYS\" parameter value is not \"1\" or greater, or is\ncommented out, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to enforce 24 hours/1 day as the\nminimum password lifetime.\n\nAdd the following line in \"/etc/login.defs\" (or modify the line to have the\nrequired value):\n\nPASS_MIN_DAYS     1"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000075-GPOS-00043",
            "gid": "V-71925",
            "rid": "SV-86549r1_rule",
            "stig_id": "RHEL-07-010230",
            "cci": [
              "CCI-000198"
            ],
            "documentable": false,
            "nist": [
              "IA-5 (1) (d)",
              "Rev_4"
            ],
            "subsystems": [
              "login_defs",
              "password"
            ],
            "fix_id": "F-78277r1_fix"
          },
          "code": "control \"V-71925\" do\n  title \"Passwords for new users must be restricted to a 24 hours/1 day minimum\nlifetime.\"\n  desc  \"Enforcing a minimum password lifetime helps to prevent repeated\npassword changes to defeat the password reuse or history enforcement\nrequirement. If users are allowed to immediately and continually change their\npassword, the password could be repeatedly changed in a short period of time to\ndefeat the organization's policy regarding password reuse.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000075-GPOS-00043\"\n  tag \"gid\": \"V-71925\"\n  tag \"rid\": \"SV-86549r1_rule\"\n  tag \"stig_id\": \"RHEL-07-010230\"\n  tag \"cci\": [\"CCI-000198\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-5 (1) (d)\", \"Rev_4\"]\n  tag \"subsystems\": ['login_defs', 'password']\n  desc \"check\", \"Verify the operating system enforces 24 hours/1 day as the\nminimum password lifetime for new user accounts.\n\nCheck for the value of \\\"PASS_MIN_DAYS\\\" in \\\"/etc/login.defs\\\" with the\nfollowing command:\n\n# grep -i pass_min_days /etc/login.defs\nPASS_MIN_DAYS     1\n\nIf the \\\"PASS_MIN_DAYS\\\" parameter value is not \\\"1\\\" or greater, or is\ncommented out, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to enforce 24 hours/1 day as the\nminimum password lifetime.\n\nAdd the following line in \\\"/etc/login.defs\\\" (or modify the line to have the\nrequired value):\n\nPASS_MIN_DAYS     1\"\n  tag \"fix_id\": \"F-78277r1_fix\"\n  describe login_defs do\n    its('PASS_MIN_DAYS.to_i') { should cmp >= 1 }\n  end\nend\n",
          "source_location": {
            "line": 6,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71925.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "login.defs PASS_MIN_DAYS.to_i should cmp >= 1",
              "run_time": 0.000533083,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "\nexpected it to be >= 1\n     got: 0\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-71927",
          "title": "Passwords must be restricted to a 24 hours/1 day minimum lifetime.",
          "desc": "Enforcing a minimum password lifetime helps to prevent repeated\npassword changes to defeat the password reuse or history enforcement\nrequirement. If users are allowed to immediately and continually change their\npassword, the password could be repeatedly changed in a short period of time to\ndefeat the organization's policy regarding password reuse.",
          "descriptions": [
            {
              "label": "default",
              "data": "Enforcing a minimum password lifetime helps to prevent repeated\npassword changes to defeat the password reuse or history enforcement\nrequirement. If users are allowed to immediately and continually change their\npassword, the password could be repeatedly changed in a short period of time to\ndefeat the organization's policy regarding password reuse."
            },
            {
              "label": "check",
              "data": "Check whether the minimum time period between password changes\nfor each user account is one day or greater.\n\n# awk -F: '$4 < 1 {print $1}' /etc/shadow\n\nIf any results are returned that are not associated with a system account, this\nis a finding."
            },
            {
              "label": "fix",
              "data": "Configure non-compliant accounts to enforce a 24 hours/1 day\nminimum password lifetime:\n\n# chage -m 1 [user]"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000075-GPOS-00043",
            "gid": "V-71927",
            "rid": "SV-86551r1_rule",
            "stig_id": "RHEL-07-010240",
            "cci": [
              "CCI-000198"
            ],
            "documentable": false,
            "nist": [
              "IA-5 (1) (d)",
              "Rev_4"
            ],
            "subsystems": [
              "password",
              "/etc/shadow"
            ],
            "fix_id": "F-78279r1_fix"
          },
          "code": "control \"V-71927\" do\n  title \"Passwords must be restricted to a 24 hours/1 day minimum lifetime.\"\n  desc  \"Enforcing a minimum password lifetime helps to prevent repeated\npassword changes to defeat the password reuse or history enforcement\nrequirement. If users are allowed to immediately and continually change their\npassword, the password could be repeatedly changed in a short period of time to\ndefeat the organization's policy regarding password reuse.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000075-GPOS-00043\"\n  tag \"gid\": \"V-71927\"\n  tag \"rid\": \"SV-86551r1_rule\"\n  tag \"stig_id\": \"RHEL-07-010240\"\n  tag \"cci\": [\"CCI-000198\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-5 (1) (d)\", \"Rev_4\"]\n  tag \"subsystems\": ['password', '/etc/shadow']\n  desc \"check\", \"Check whether the minimum time period between password changes\nfor each user account is one day or greater.\n\n# awk -F: '$4 < 1 {print $1}' /etc/shadow\n\nIf any results are returned that are not associated with a system account, this\nis a finding.\"\n  desc \"fix\", \"Configure non-compliant accounts to enforce a 24 hours/1 day\nminimum password lifetime:\n\n# chage -m 1 [user]\"\n  tag \"fix_id\": \"F-78279r1_fix\"\n  shadow.users.each do |user|\n    # filtering on non-system accounts (uid >= 1000)\n    next unless user(user).uid >= 1000\n    describe shadow.users(user) do\n      its('min_days.first.to_i') { should cmp >= 1 }\n    end\n  end\nend\n",
          "source_location": {
            "line": 6,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71927.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "/etc/shadow with user == \"dhaynes\" min_days.first.to_i should cmp >= 1",
              "run_time": 0.000147238,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "\nexpected it to be >= 1\n     got: 0\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "failed",
              "code_desc": "/etc/shadow with user == \"nfsnobody\" min_days.first.to_i should cmp >= 1",
              "run_time": 0.000196372,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "\nexpected it to be >= 1\n     got: 0\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-71929",
          "title": "Passwords for new users must be restricted to a 60-day maximum\nlifetime.",
          "desc": "Any password, no matter how complex, can eventually be cracked.\nTherefore, passwords need to be changed periodically. If the operating system\ndoes not limit the lifetime of passwords and force users to change their\npasswords, there is the risk that the operating system passwords could be\ncompromised.",
          "descriptions": [
            {
              "label": "default",
              "data": "Any password, no matter how complex, can eventually be cracked.\nTherefore, passwords need to be changed periodically. If the operating system\ndoes not limit the lifetime of passwords and force users to change their\npasswords, there is the risk that the operating system passwords could be\ncompromised."
            },
            {
              "label": "check",
              "data": "Verify the operating system enforces a 60-day maximum password\nlifetime restriction for new user accounts.\n\nCheck for the value of \"PASS_MAX_DAYS\" in \"/etc/login.defs\" with the\nfollowing command:\n\n# grep -i pass_max_days /etc/login.defs\nPASS_MAX_DAYS     60\n\nIf the \"PASS_MAX_DAYS\" parameter value is not 60 or less, or is commented\nout, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to enforce a 60-day maximum\npassword lifetime restriction.\n\nAdd the following line in \"/etc/login.defs\" (or modify the line to have the\nrequired value):\n\nPASS_MAX_DAYS     60"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000076-GPOS-00044",
            "gid": "V-71929",
            "rid": "SV-86553r1_rule",
            "stig_id": "RHEL-07-010250",
            "cci": [
              "CCI-000199"
            ],
            "documentable": false,
            "nist": [
              "IA-5 (1) (d)",
              "Rev_4"
            ],
            "subsystems": [
              "login_defs",
              "password"
            ],
            "fix_id": "F-78281r1_fix"
          },
          "code": "control \"V-71929\" do\n  title \"Passwords for new users must be restricted to a 60-day maximum\nlifetime.\"\n  desc  \"Any password, no matter how complex, can eventually be cracked.\nTherefore, passwords need to be changed periodically. If the operating system\ndoes not limit the lifetime of passwords and force users to change their\npasswords, there is the risk that the operating system passwords could be\ncompromised.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000076-GPOS-00044\"\n  tag \"gid\": \"V-71929\"\n  tag \"rid\": \"SV-86553r1_rule\"\n  tag \"stig_id\": \"RHEL-07-010250\"\n  tag \"cci\": [\"CCI-000199\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-5 (1) (d)\", \"Rev_4\"]\n  tag \"subsystems\": ['login_defs', 'password']\n  desc \"check\", \"Verify the operating system enforces a 60-day maximum password\nlifetime restriction for new user accounts.\n\nCheck for the value of \\\"PASS_MAX_DAYS\\\" in \\\"/etc/login.defs\\\" with the\nfollowing command:\n\n# grep -i pass_max_days /etc/login.defs\nPASS_MAX_DAYS     60\n\nIf the \\\"PASS_MAX_DAYS\\\" parameter value is not 60 or less, or is commented\nout, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to enforce a 60-day maximum\npassword lifetime restriction.\n\nAdd the following line in \\\"/etc/login.defs\\\" (or modify the line to have the\nrequired value):\n\nPASS_MAX_DAYS     60\"\n  tag \"fix_id\": \"F-78281r1_fix\"\n  describe login_defs do\n    its('PASS_MAX_DAYS.to_i') { should cmp <= 60 }\n  end\nend\n",
          "source_location": {
            "line": 6,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71929.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "login.defs PASS_MAX_DAYS.to_i should cmp <= 60",
              "run_time": 0.000306667,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "\nexpected it to be <= 60\n     got: 99999\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-71931",
          "title": "Existing passwords must be restricted to a 60-day maximum lifetime.",
          "desc": "Any password, no matter how complex, can eventually be cracked.\nTherefore, passwords need to be changed periodically. If the operating system\ndoes not limit the lifetime of passwords and force users to change their\npasswords, there is the risk that the operating system passwords could be\ncompromised.",
          "descriptions": [
            {
              "label": "default",
              "data": "Any password, no matter how complex, can eventually be cracked.\nTherefore, passwords need to be changed periodically. If the operating system\ndoes not limit the lifetime of passwords and force users to change their\npasswords, there is the risk that the operating system passwords could be\ncompromised."
            },
            {
              "label": "check",
              "data": "Check whether the maximum time period for existing passwords is\nrestricted to 60 days.\n\n# awk -F: '$5 > 60 {print $1}' /etc/shadow\n\nIf any results are returned that are not associated with a system account, this\nis a finding."
            },
            {
              "label": "fix",
              "data": "Configure non-compliant accounts to enforce a 60-day maximum\npassword lifetime restriction.\n\n# chage -M 60 [user]"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000076-GPOS-00044",
            "gid": "V-71931",
            "rid": "SV-86555r1_rule",
            "stig_id": "RHEL-07-010260",
            "cci": [
              "CCI-000199"
            ],
            "documentable": false,
            "nist": [
              "IA-5 (1) (d)",
              "Rev_4"
            ],
            "subsystems": [
              "password",
              "/etc/shadow"
            ],
            "fix_id": "F-78283r1_fix"
          },
          "code": "control \"V-71931\" do\n  title \"Existing passwords must be restricted to a 60-day maximum lifetime.\"\n  desc  \"Any password, no matter how complex, can eventually be cracked.\nTherefore, passwords need to be changed periodically. If the operating system\ndoes not limit the lifetime of passwords and force users to change their\npasswords, there is the risk that the operating system passwords could be\ncompromised.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000076-GPOS-00044\"\n  tag \"gid\": \"V-71931\"\n  tag \"rid\": \"SV-86555r1_rule\"\n  tag \"stig_id\": \"RHEL-07-010260\"\n  tag \"cci\": [\"CCI-000199\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-5 (1) (d)\", \"Rev_4\"]\n  tag \"subsystems\": ['password', '/etc/shadow']\n  desc \"check\", \"Check whether the maximum time period for existing passwords is\nrestricted to 60 days.\n\n# awk -F: '$5 > 60 {print $1}' /etc/shadow\n\nIf any results are returned that are not associated with a system account, this\nis a finding.\"\n  desc \"fix\", \"Configure non-compliant accounts to enforce a 60-day maximum\npassword lifetime restriction.\n\n# chage -M 60 [user]\"\n  tag \"fix_id\": \"F-78283r1_fix\"\n  shadow.users.each do |user|\n    # filtering on non-system accounts (uid >= 1000)\n    next unless user(user).uid >= 1000\n    describe shadow.users(user) do\n      its('max_days.first.to_i') { should cmp <= 60 }\n    end\n  end\nend\n",
          "source_location": {
            "line": 6,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71931.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "/etc/shadow with user == \"dhaynes\" max_days.first.to_i should cmp <= 60",
              "run_time": 0.000143191,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "\nexpected it to be <= 60\n     got: 99999\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "/etc/shadow with user == \"nfsnobody\" max_days.first.to_i should cmp <= 60",
              "run_time": 0.000118522,
              "start_time": "2019-11-04T16:17:07-05:00"
            }
          ]
        },
        {
          "id": "V-71933",
          "title": "Passwords must be prohibited from reuse for a minimum of five\ngenerations.",
          "desc": "Password complexity, or strength, is a measure of the effectiveness of\na password in resisting attempts at guessing and brute-force attacks. If the\ninformation system or application allows the user to consecutively reuse their\npassword when that password has exceeded its defined lifetime, the end result\nis a password that is not changed per policy requirements.",
          "descriptions": [
            {
              "label": "default",
              "data": "Password complexity, or strength, is a measure of the effectiveness of\na password in resisting attempts at guessing and brute-force attacks. If the\ninformation system or application allows the user to consecutively reuse their\npassword when that password has exceeded its defined lifetime, the end result\nis a password that is not changed per policy requirements."
            },
            {
              "label": "check",
              "data": "Verify the operating system prohibits password reuse for a\nminimum of five generations.\n\nCheck for the value of the \"remember\" argument in\n\"/etc/pam.d/system-auth-ac\" with the following command:\n\n# grep -i remember /etc/pam.d/system-auth-ac\npassword sufficient pam_unix.so use_authtok sha512 shadow remember=5\n\nIf the line containing the \"pam_unix.so\" line does not have the \"remember\"\nmodule argument set, or the value of the \"remember\" module argument is set to\nless than \"5\", this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to prohibit password reuse for a\nminimum of five generations.\n\nAdd the following line in \"/etc/pam.d/system-auth-ac\" (or modify the line to\nhave the required value):\n\npassword sufficient pam_unix.so use_authtok sha512 shadow remember=5"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000077-GPOS-00045",
            "gid": "V-71933",
            "rid": "SV-86557r2_rule",
            "stig_id": "RHEL-07-010270",
            "cci": [
              "CCI-000200"
            ],
            "documentable": false,
            "nist": [
              "IA-5 (1) (e)",
              "Rev_4"
            ],
            "subsystems": [
              "pam",
              "password"
            ],
            "fix_id": "F-78285r2_fix"
          },
          "code": "control \"V-71933\" do\n  title \"Passwords must be prohibited from reuse for a minimum of five\ngenerations.\"\n  desc  \"Password complexity, or strength, is a measure of the effectiveness of\na password in resisting attempts at guessing and brute-force attacks. If the\ninformation system or application allows the user to consecutively reuse their\npassword when that password has exceeded its defined lifetime, the end result\nis a password that is not changed per policy requirements.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000077-GPOS-00045\"\n  tag \"gid\": \"V-71933\"\n  tag \"rid\": \"SV-86557r2_rule\"\n  tag \"stig_id\": \"RHEL-07-010270\"\n  tag \"cci\": [\"CCI-000200\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-5 (1) (e)\", \"Rev_4\"]\n  tag \"subsystems\": ['pam', 'password']\n  desc \"check\", \"Verify the operating system prohibits password reuse for a\nminimum of five generations.\n\nCheck for the value of the \\\"remember\\\" argument in\n\\\"/etc/pam.d/system-auth-ac\\\" with the following command:\n\n# grep -i remember /etc/pam.d/system-auth-ac\npassword sufficient pam_unix.so use_authtok sha512 shadow remember=5\n\nIf the line containing the \\\"pam_unix.so\\\" line does not have the \\\"remember\\\"\nmodule argument set, or the value of the \\\"remember\\\" module argument is set to\nless than \\\"5\\\", this is a finding.\"\n  desc \"fix\", \"Configure the operating system to prohibit password reuse for a\nminimum of five generations.\n\nAdd the following line in \\\"/etc/pam.d/system-auth-ac\\\" (or modify the line to\nhave the required value):\n\npassword sufficient pam_unix.so use_authtok sha512 shadow remember=5\"\n  tag \"fix_id\": \"F-78285r2_fix\"\n\n  describe pam(\"/etc/pam.d/system-auth\") do\n    its('lines') { should match_pam_rule('password (required|requisite|sufficient) pam_(unix|pwhistory).so').any_with_integer_arg('remember', '>=', min_reuse_generations) }\n  end\nend\n",
          "source_location": {
            "line": 12,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71933.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "PAM Config[/etc/pam.d/system-auth] lines should include password (required|requisite|sufficient) pam_(unix|pwhistory).so, any with arg remember >= 5",
              "run_time": 0.000414109,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "expected \"password sufficient pam_unix.so sha512 shadow nullok try_first_pass use_authtok\" to include password (required|requisite|sufficient) pam_(unix|pwhistory).so, any with arg remember >= 5"
            }
          ]
        },
        {
          "id": "V-71935",
          "title": "Passwords must be a minimum of 15 characters in length.",
          "desc": "The shorter the password, the lower the number of possible combinations\nthat need to be tested before the password is compromised.\n\n    Password complexity, or strength, is a measure of the effectiveness of a\npassword in resisting attempts at guessing and brute-force attacks. Password\nlength is one factor of several that helps to determine strength and how long\nit takes to crack a password. Use of more characters in a password helps to\nexponentially increase the time and/or resources required to compromise the\npassword.",
          "descriptions": [
            {
              "label": "default",
              "data": "The shorter the password, the lower the number of possible combinations\nthat need to be tested before the password is compromised.\n\n    Password complexity, or strength, is a measure of the effectiveness of a\npassword in resisting attempts at guessing and brute-force attacks. Password\nlength is one factor of several that helps to determine strength and how long\nit takes to crack a password. Use of more characters in a password helps to\nexponentially increase the time and/or resources required to compromise the\npassword."
            },
            {
              "label": "check",
              "data": "Verify the operating system enforces a minimum 15-character\npassword length. The \"minlen\" option sets the minimum number of characters in\na new password.\n\nCheck for the value of the \"minlen\" option in\n\"/etc/security/pwquality.conf\" with the following command:\n\n# grep minlen /etc/security/pwquality.conf\nminlen = 15\n\nIf the command does not return a \"minlen\" value of 15 or greater, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure operating system to enforce a minimum 15-character\npassword length.\n\nAdd the following line to \"/etc/security/pwquality.conf\" (or modify the line\nto have the required value):\n\nminlen = 15"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000078-GPOS-00046",
            "gid": "V-71935",
            "rid": "SV-86559r1_rule",
            "stig_id": "RHEL-07-010280",
            "cci": [
              "CCI-000205"
            ],
            "documentable": false,
            "nist": [
              "IA-5 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "pam",
              "pwquality",
              "password"
            ],
            "fix_id": "F-78287r1_fix"
          },
          "code": "control \"V-71935\" do\n  title \"Passwords must be a minimum of 15 characters in length.\"\n  desc  \"\n    The shorter the password, the lower the number of possible combinations\nthat need to be tested before the password is compromised.\n\n    Password complexity, or strength, is a measure of the effectiveness of a\npassword in resisting attempts at guessing and brute-force attacks. Password\nlength is one factor of several that helps to determine strength and how long\nit takes to crack a password. Use of more characters in a password helps to\nexponentially increase the time and/or resources required to compromise the\npassword.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000078-GPOS-00046\"\n  tag \"gid\": \"V-71935\"\n  tag \"rid\": \"SV-86559r1_rule\"\n  tag \"stig_id\": \"RHEL-07-010280\"\n  tag \"cci\": [\"CCI-000205\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-5 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['pam', 'pwquality', 'password']\n  desc \"check\", \"Verify the operating system enforces a minimum 15-character\npassword length. The \\\"minlen\\\" option sets the minimum number of characters in\na new password.\n\nCheck for the value of the \\\"minlen\\\" option in\n\\\"/etc/security/pwquality.conf\\\" with the following command:\n\n# grep minlen /etc/security/pwquality.conf\nminlen = 15\n\nIf the command does not return a \\\"minlen\\\" value of 15 or greater, this is a\nfinding.\"\n  desc \"fix\", \"Configure operating system to enforce a minimum 15-character\npassword length.\n\nAdd the following line to \\\"/etc/security/pwquality.conf\\\" (or modify the line\nto have the required value):\n\nminlen = 15\"\n  tag \"fix_id\": \"F-78287r1_fix\"\n  describe parse_config_file(\"/etc/security/pwquality.conf\") do\n    its('minlen.to_i') { should cmp >= min_len }\n  end\nend\n",
          "source_location": {
            "line": 10,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71935.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/security/pwquality.conf minlen.to_i should cmp >= 15",
              "run_time": 0.000149026,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "\nexpected it to be >= 15\n     got: 0\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-71937",
          "title": "The system must not have accounts configured with blank or null\npasswords.",
          "desc": "If an account has an empty password, anyone could log on and run\ncommands with the privileges of that account. Accounts with empty passwords\nshould never be used in operational environments.",
          "descriptions": [
            {
              "label": "default",
              "data": "If an account has an empty password, anyone could log on and run\ncommands with the privileges of that account. Accounts with empty passwords\nshould never be used in operational environments."
            },
            {
              "label": "check",
              "data": "To verify that null passwords cannot be used, run the following\ncommand:\n\n# grep nullok /etc/pam.d/system-auth-ac\n\nIf this produces any output, it may be possible to log on with accounts with\nempty passwords.\n\nIf null passwords can be used, this is a finding."
            },
            {
              "label": "fix",
              "data": "If an account is configured for password authentication but does\nnot have an assigned password, it may be possible to log on to the account\nwithout authenticating.\n\nRemove any instances of the \"nullok\" option in \"/etc/pam.d/system-auth-ac\"\nto prevent logons with empty passwords.\n\nNote: Any updates made to \"/etc/pam.d/system-auth-ac\" may be overwritten by\nthe \"authconfig\" program. The \"authconfig\" program should not be used."
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-71937",
            "rid": "SV-86561r2_rule",
            "stig_id": "RHEL-07-010290",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "pam",
              "password"
            ],
            "fix_id": "F-78289r2_fix"
          },
          "code": "control \"V-71937\" do\n  title \"The system must not have accounts configured with blank or null\npasswords.\"\n  desc  \"If an account has an empty password, anyone could log on and run\ncommands with the privileges of that account. Accounts with empty passwords\nshould never be used in operational environments.\"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-71937\"\n  tag \"rid\": \"SV-86561r2_rule\"\n  tag \"stig_id\": \"RHEL-07-010290\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['pam', 'password']\n  desc \"check\", \"To verify that null passwords cannot be used, run the following\ncommand:\n\n# grep nullok /etc/pam.d/system-auth-ac\n\nIf this produces any output, it may be possible to log on with accounts with\nempty passwords.\n\nIf null passwords can be used, this is a finding.\"\n  desc \"fix\", \"If an account is configured for password authentication but does\nnot have an assigned password, it may be possible to log on to the account\nwithout authenticating.\n\nRemove any instances of the \\\"nullok\\\" option in \\\"/etc/pam.d/system-auth-ac\\\"\nto prevent logons with empty passwords.\n\nNote: Any updates made to \\\"/etc/pam.d/system-auth-ac\\\" may be overwritten by\nthe \\\"authconfig\\\" program. The \\\"authconfig\\\" program should not be used.\"\n  tag \"fix_id\": \"F-78289r2_fix\"\n\n  describe pam('/etc/pam.d') do\n    its('lines') { should match_pam_rule('.* .* pam_unix.so').all_without_args('nullok') }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71937.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "PAM Config[/etc/pam.d] lines should include .* .* pam_unix.so, all without args nullok",
              "run_time": 0.006853754,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "expected \"auth sufficient pam_unix.so nullok try_first_pass\\naccount required pam_unix.so\\npassword sufficient...ufficient pam_unix.so sha512 shadow nullok try_first_pass use_authtok\\nsession required pam_unix.so\" to include .* .* pam_unix.so, all without args nullok\nDiff:\n@@ -1,2 +1,13 @@\n-.* .* pam_unix.so\n+auth sufficient pam_unix.so nullok try_first_pass\n+account required pam_unix.so\n+password sufficient pam_unix.so sha512 shadow nullok try_first_pass use_authtok\n+session required pam_unix.so\n+auth sufficient pam_unix.so nullok try_first_pass\n+account required pam_unix.so\n+password sufficient pam_unix.so sha512 shadow nullok try_first_pass use_authtok\n+session required pam_unix.so\n+auth sufficient pam_unix.so nullok try_first_pass\n+account required pam_unix.so\n+password sufficient pam_unix.so sha512 shadow nullok try_first_pass use_authtok\n+session required pam_unix.so\n"
            }
          ]
        },
        {
          "id": "V-71939",
          "title": "The SSH daemon must not allow authentication using an empty password.",
          "desc": "Configuring this setting for the SSH daemon provides additional\nassurance that remote logon via SSH will require a password, even in the event\nof misconfiguration elsewhere.",
          "descriptions": [
            {
              "label": "default",
              "data": "Configuring this setting for the SSH daemon provides additional\nassurance that remote logon via SSH will require a password, even in the event\nof misconfiguration elsewhere."
            },
            {
              "label": "check",
              "data": "To determine how the SSH daemon's \"PermitEmptyPasswords\"\noption is set, run the following command:\n\n# grep -i PermitEmptyPasswords /etc/ssh/sshd_config\nPermitEmptyPasswords no\n\nIf no line, a commented line, or a line indicating the value \"no\" is\nreturned, the required value is set.\n\nIf the required value is not set, this is a finding."
            },
            {
              "label": "fix",
              "data": "To explicitly disallow remote logon from accounts with empty\npasswords, add or correct the following line in \"/etc/ssh/sshd_config\":\n\nPermitEmptyPasswords no\n\nThe SSH service must be restarted for changes to take effect.  Any accounts\nwith empty passwords should be disabled immediately, and PAM configuration\nshould prevent users from being able to assign themselves empty passwords."
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000106-GPOS-00053",
            "gid": "V-71939",
            "rid": "SV-86563r2_rule",
            "stig_id": "RHEL-07-010300",
            "cci": [
              "CCI-000766"
            ],
            "documentable": false,
            "nist": [
              "IA-2 (2)",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78291r2_fix"
          },
          "code": "control \"V-71939\" do\n  title \"The SSH daemon must not allow authentication using an empty password.\"\n  desc  \"Configuring this setting for the SSH daemon provides additional\nassurance that remote logon via SSH will require a password, even in the event\nof misconfiguration elsewhere.\"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000106-GPOS-00053\"\n  tag \"gid\": \"V-71939\"\n  tag \"rid\": \"SV-86563r2_rule\"\n  tag \"stig_id\": \"RHEL-07-010300\"\n  tag \"cci\": [\"CCI-000766\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-2 (2)\", \"Rev_4\"]\n  tag \"subsystems\": [\"ssh\"]\n  desc \"check\", \"To determine how the SSH daemon's \\\"PermitEmptyPasswords\\\"\noption is set, run the following command:\n\n# grep -i PermitEmptyPasswords /etc/ssh/sshd_config\nPermitEmptyPasswords no\n\nIf no line, a commented line, or a line indicating the value \\\"no\\\" is\nreturned, the required value is set.\n\nIf the required value is not set, this is a finding.\"\n  desc \"fix\", \"To explicitly disallow remote logon from accounts with empty\npasswords, add or correct the following line in \\\"/etc/ssh/sshd_config\\\":\n\nPermitEmptyPasswords no\n\nThe SSH service must be restarted for changes to take effect.  Any accounts\nwith empty passwords should be disabled immediately, and PAM configuration\nshould prevent users from being able to assign themselves empty passwords.\"\n  tag \"fix_id\": \"F-78291r2_fix\"\n\n  describe sshd_config do\n    its('PermitEmptyPasswords') { should eq 'no' }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71939.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "SSHD Configuration PermitEmptyPasswords should eq \"no\"",
              "run_time": 0.000507482,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "\nexpected: \"no\"\n     got: nil\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-71941",
          "title": "The operating system must disable account identifiers (individuals,\ngroups, roles, and devices) if the password expires.",
          "desc": "Inactive identifiers pose a risk to systems and applications because\nattackers may exploit an inactive identifier and potentially obtain undetected\naccess to the system. Owners of inactive accounts will not notice if\nunauthorized access to their user account has been obtained.\n\n    Operating systems need to track periods of inactivity and disable\napplication identifiers after zero days of inactivity.",
          "descriptions": [
            {
              "label": "default",
              "data": "Inactive identifiers pose a risk to systems and applications because\nattackers may exploit an inactive identifier and potentially obtain undetected\naccess to the system. Owners of inactive accounts will not notice if\nunauthorized access to their user account has been obtained.\n\n    Operating systems need to track periods of inactivity and disable\napplication identifiers after zero days of inactivity."
            },
            {
              "label": "check",
              "data": "Verify the operating system disables account identifiers\n(individuals, groups, roles, and devices) after the password expires with the\nfollowing command:\n\n# grep -i inactive /etc/default/useradd\nINACTIVE=0\n\nIf the value is not set to \"0\", is commented out, or is not defined, this is\na finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to disable account identifiers\n(individuals, groups, roles, and devices) after the password expires.\n\nAdd the following line to \"/etc/default/useradd\" (or modify the line to have\nthe required value):\n\nINACTIVE=0"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000118-GPOS-00060",
            "gid": "V-71941",
            "rid": "SV-86565r1_rule",
            "stig_id": "RHEL-07-010310",
            "cci": [
              "CCI-000795"
            ],
            "documentable": false,
            "nist": [
              "IA-4 e",
              "Rev_4"
            ],
            "subsystems": [
              "user"
            ],
            "fix_id": "F-78293r1_fix"
          },
          "code": "control \"V-71941\" do\n  title \"The operating system must disable account identifiers (individuals,\ngroups, roles, and devices) if the password expires.\"\n  desc  \"\n    Inactive identifiers pose a risk to systems and applications because\nattackers may exploit an inactive identifier and potentially obtain undetected\naccess to the system. Owners of inactive accounts will not notice if\nunauthorized access to their user account has been obtained.\n\n    Operating systems need to track periods of inactivity and disable\napplication identifiers after zero days of inactivity.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000118-GPOS-00060\"\n  tag \"gid\": \"V-71941\"\n  tag \"rid\": \"SV-86565r1_rule\"\n  tag \"stig_id\": \"RHEL-07-010310\"\n  tag \"cci\": [\"CCI-000795\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-4 e\", \"Rev_4\"]\n  tag \"subsystems\": ['user']\n  desc \"check\", \"Verify the operating system disables account identifiers\n(individuals, groups, roles, and devices) after the password expires with the\nfollowing command:\n\n# grep -i inactive /etc/default/useradd\nINACTIVE=0\n\nIf the value is not set to \\\"0\\\", is commented out, or is not defined, this is\na finding.\"\n  desc \"fix\", \"Configure the operating system to disable account identifiers\n(individuals, groups, roles, and devices) after the password expires.\n\nAdd the following line to \\\"/etc/default/useradd\\\" (or modify the line to have\nthe required value):\n\nINACTIVE=0\"\n  tag \"fix_id\": \"F-78293r1_fix\"\n  describe parse_config_file(\"/etc/default/useradd\") do\n    its('INACTIVE') { should cmp >= 0 }\n    its('INACTIVE') { should cmp <= days_of_inactivity }\n  end\nend\n",
          "source_location": {
            "line": 7,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71941.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/default/useradd INACTIVE should cmp >= 0",
              "run_time": 0.000150632,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "\nexpected it to be >= 0\n     got: \"-1\"\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Parse Config File /etc/default/useradd INACTIVE should cmp <= 0",
              "run_time": 0.000116559,
              "start_time": "2019-11-04T16:17:07-05:00"
            }
          ]
        },
        {
          "id": "V-71943",
          "title": "Accounts subject to three unsuccessful logon attempts within 15\nminutes must be locked for the maximum configurable period.",
          "desc": "By limiting the number of failed logon attempts, the risk of\nunauthorized system access via user password guessing, otherwise known as\nbrute-forcing, is reduced. Limits are imposed by locking the account.",
          "descriptions": [
            {
              "label": "default",
              "data": "By limiting the number of failed logon attempts, the risk of\nunauthorized system access via user password guessing, otherwise known as\nbrute-forcing, is reduced. Limits are imposed by locking the account."
            },
            {
              "label": "check",
              "data": "Verify the operating system automatically locks an account for the\nmaximum period for which the system can be configured.\n\nCheck that the system locks an account for the maximum period after three\nunsuccessful logon attempts within a period of 15 minutes with the following\ncommand:\n\n# grep pam_faillock.so /etc/pam.d/password-auth-ac\nauth        required       pam_faillock.so preauth silent audit deny=3 even_deny_root unlock_time=604800\nauth        [default=die]  pam_faillock.so authfail audit deny=3 even_deny_root unlock_time=604800\naccount required pam_faillock.so\n\nIf the \"unlock_time\" setting is greater than \"604800\" on both lines with\nthe \"pam_faillock.so\" module name or is missing from a line, this is a\nfinding.\n\n# grep pam_faillock.so /etc/pam.d/system-auth-ac\nauth required pam_faillock.so preauth silent audit deny=3 even_deny_root unlock_time=604800\nauth [default=die] pam_faillock.so authfail audit deny=3 even_deny_root unlock_time=604800\naccount required pam_faillock.so\n\nIf the \"unlock_time\" setting is greater than \"604800\" on both lines with\nthe \"pam_faillock.so\" module name or is missing from a line, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to lock an account for the maximum\nperiod when three unsuccessful logon attempts in 15 minutes are made.\n\nModify the first three lines of the auth section of the\n\"/etc/pam.d/system-auth-ac\" and \"/etc/pam.d/password-auth-ac\" files to\nmatch the following lines:\n\nauth        required       pam_faillock.so preauth silent audit deny=3 even_deny_root fail_interval=900 unlock_time=604800\nauth        sufficient     pam_unix.so try_first_pass\nauth        [default=die]  pam_faillock.so authfail audit deny=3 even_deny_root fail_interval=900 unlock_time=604800\naccount required pam_faillock.so"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000329-GPOS-00128",
            "satisfies": [
              "SRG-OS-000329-GPOS-00128",
              "SRG-OS-000021-GPOS-00005"
            ],
            "gid": "V-71943",
            "rid": "SV-86567r3_rule",
            "stig_id": "RHEL-07-010320",
            "cci": [
              "CCI-002238"
            ],
            "documentable": false,
            "nist": [
              "AC-7 b",
              "Rev_4"
            ],
            "subsystems": [
              "pam",
              "faillock"
            ],
            "fix_id": "F-78295r4_fix"
          },
          "code": "control \"V-71943\" do\n  title \"Accounts subject to three unsuccessful logon attempts within 15\nminutes must be locked for the maximum configurable period.\"\n  desc  \"By limiting the number of failed logon attempts, the risk of\nunauthorized system access via user password guessing, otherwise known as\nbrute-forcing, is reduced. Limits are imposed by locking the account.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000329-GPOS-00128\"\n  tag \"satisfies\": [\"SRG-OS-000329-GPOS-00128\", \"SRG-OS-000021-GPOS-00005\"]\n  tag \"gid\": \"V-71943\"\n  tag \"rid\": \"SV-86567r3_rule\"\n  tag \"stig_id\": \"RHEL-07-010320\"\n  tag \"cci\": [\"CCI-002238\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-7 b\", \"Rev_4\"]\n  tag \"subsystems\": ['pam', 'faillock']\n  desc \"check\", \"Verify the operating system automatically locks an account for the\nmaximum period for which the system can be configured.\n\nCheck that the system locks an account for the maximum period after three\nunsuccessful logon attempts within a period of 15 minutes with the following\ncommand:\n\n# grep pam_faillock.so /etc/pam.d/password-auth-ac\nauth        required       pam_faillock.so preauth silent audit deny=3 even_deny_root unlock_time=604800\nauth        [default=die]  pam_faillock.so authfail audit deny=3 even_deny_root unlock_time=604800\naccount required pam_faillock.so\n\nIf the \\\"unlock_time\\\" setting is greater than \\\"604800\\\" on both lines with\nthe \\\"pam_faillock.so\\\" module name or is missing from a line, this is a\nfinding.\n\n# grep pam_faillock.so /etc/pam.d/system-auth-ac\nauth required pam_faillock.so preauth silent audit deny=3 even_deny_root unlock_time=604800\nauth [default=die] pam_faillock.so authfail audit deny=3 even_deny_root unlock_time=604800\naccount required pam_faillock.so\n\nIf the \\\"unlock_time\\\" setting is greater than \\\"604800\\\" on both lines with\nthe \\\"pam_faillock.so\\\" module name or is missing from a line, this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to lock an account for the maximum\nperiod when three unsuccessful logon attempts in 15 minutes are made.\n\nModify the first three lines of the auth section of the\n\\\"/etc/pam.d/system-auth-ac\\\" and \\\"/etc/pam.d/password-auth-ac\\\" files to\nmatch the following lines:\n\nauth        required       pam_faillock.so preauth silent audit deny=3 even_deny_root fail_interval=900 unlock_time=604800\nauth        sufficient     pam_unix.so try_first_pass\nauth        [default=die]  pam_faillock.so authfail audit deny=3 even_deny_root fail_interval=900 unlock_time=604800\naccount required pam_faillock.so\"\n  tag \"fix_id\": \"F-78295r4_fix\"\n\n  required_rules = [\n    'auth required pam_faillock.so unlock_time=.*',\n    'auth sufficient pam_unix.so try_first_pass',\n    'auth [default=die] pam_faillock.so unlock_time=.*'\n  ]\n  alternate_rules = [\n    'auth required pam_faillock.so unlock_time=.*',\n    'auth sufficient pam_sss.so forward_pass',\n    'auth sufficient pam_unix.so try_first_pass',\n    'auth [default=die] pam_faillock.so unlock_time=.*'\n  ]\n\n  describe pam('/etc/pam.d/password-auth') do\n    its('lines') {\n      should match_pam_rules(required_rules).exactly.or \\\n             match_pam_rules(alternate_rules).exactly\n    }\n    its('lines') { should match_pam_rule('auth [default=die]|required pam_faillock.so').all_with_integer_arg('deny', '<=', unsuccessful_attempts) }\n    its('lines') { should match_pam_rule('auth [default=die]|required pam_faillock.so').all_with_integer_arg('fail_interval', '<=', fail_interval) }\n    its('lines') {\n      should match_pam_rule('auth [default=die]|required pam_faillock.so').all_with_args('unlock_time=(0|never)').or \\\n            (match_pam_rule('auth [default=die]|required pam_faillock.so').all_with_integer_arg('unlock_time', '<=', 604800).and \\\n             match_pam_rule('auth [default=die]|required pam_faillock.so').all_with_integer_arg('unlock_time', '>=', lockout_time))\n    }\n  end\n\n  describe pam('/etc/pam.d/system-auth') do\n    its('lines') {\n      should match_pam_rules(required_rules).exactly.or \\\n             match_pam_rules(alternate_rules).exactly\n    }\n    its('lines') { should match_pam_rule('auth [default=die]|required pam_faillock.so').all_with_integer_arg('deny', '<=', unsuccessful_attempts) }\n    its('lines') { should match_pam_rule('auth [default=die]|required pam_faillock.so').all_with_integer_arg('fail_interval', '<=', fail_interval) }\n    its('lines') {\n      should match_pam_rule('auth [default=die]|required pam_faillock.so').all_with_args('unlock_time=(0|never)').or \\\n            (match_pam_rule('auth [default=die]|required pam_faillock.so').all_with_integer_arg('unlock_time', '<=', 604800).and \\\n             match_pam_rule('auth [default=die]|required pam_faillock.so').all_with_integer_arg('unlock_time', '>=', lockout_time))\n    }\n  end\nend\n",
          "source_location": {
            "line": 15,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71943.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "PAM Config[/etc/pam.d/password-auth] lines should include [\"auth required pam_faillock.so unlock_time=.*\", \"auth sufficient pam_unix.so try_first_pass\", \"auth [default=die] pam_faillock.so unlock_time=.*\"] exactly or include [\"auth required pam_faillock.so unlock_time=.*\", \"auth sufficient pam_sss.so forward_pass\", \"auth sufficient pam_unix.so try_first_pass\", \"auth [default=die] pam_faillock.so unlock_time=.*\"] exactly",
              "run_time": 0.271544281,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "   expected \"account required pam_unix.so\\naccount sufficient pam_localuser.so\\naccount sufficient pam_succeed_if...ss=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid\\nsession required pam_unix.so\" to include [\"auth required pam_faillock.so unlock_time=.*\", \"auth sufficient pam_unix.so try_first_pass\", \"auth [default=die] pam_faillock.so unlock_time=.*\"] exactly\n\n...or:\n\n   expected \"account required pam_unix.so\\naccount sufficient pam_localuser.so\\naccount sufficient pam_succeed_if...ss=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid\\nsession required pam_unix.so\" to include [\"auth required pam_faillock.so unlock_time=.*\", \"auth sufficient pam_sss.so forward_pass\", \"auth sufficient pam_unix.so try_first_pass\", \"auth [default=die] pam_faillock.so unlock_time=.*\"] exactly\nDiff for (include [\"auth required pam_faillock.so unlock_time=.*\", \"auth...):\n@@ -1,4 +1,18 @@\n-[\"auth required pam_faillock.so unlock_time=.*\",\n- \"auth sufficient pam_unix.so try_first_pass\",\n- \"auth [default=die] pam_faillock.so unlock_time=.*\"]\n+[#<#<Class:0x0000000005879628>::Pam::Rule:0x00000000057245c0 @to_s=\"auth required pam_env.so\", @service=\"password-auth\", @silent=false, @type=\"auth\", @control=\"required\", @module_path=\"pam_env.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x00000000057240e8 @to_s=\"auth required pam_faildelay.so delay=2000000\", @service=\"password-auth\", @silent=false, @type=\"auth\", @control=\"required\", @module_path=\"pam_faildelay.so\", @module_arguments=[\"delay=2000000\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572bbe0 @to_s=\"auth sufficient pam_unix.so nullok try_first_pass\", @service=\"password-auth\", @silent=false, @type=\"auth\", @control=\"sufficient\", @module_path=\"pam_unix.so\", @module_arguments=[\"nullok\", \"try_first_pass\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572b690 @to_s=\"auth requisite pam_succeed_if.so uid >= 1000 quiet_success\", @service=\"password-auth\", @silent=false, @type=\"auth\", @control=\"requisite\", @module_path=\"pam_succeed_if.so\", @module_arguments=[\"uid\", \">=\", \"1000\", \"quiet_success\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572b118 @to_s=\"auth required pam_deny.so\", @service=\"password-auth\", @silent=false, @type=\"auth\", @control=\"required\", @module_path=\"pam_deny.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572ad08 @to_s=\"account required pam_unix.so\", @service=\"password-auth\", @silent=false, @type=\"account\", @control=\"required\", @module_path=\"pam_unix.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572a8d0 @to_s=\"account sufficient pam_localuser.so\", @service=\"password-auth\", @silent=false, @type=\"account\", @control=\"sufficient\", @module_path=\"pam_localuser.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572a4c0 @to_s=\"account sufficient pam_succeed_if.so uid < 1000 quiet\", @service=\"password-auth\", @silent=false, @type=\"account\", @control=\"sufficient\", @module_path=\"pam_succeed_if.so\", @module_arguments=[\"uid\", \"<\", \"1000\", \"quiet\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x0000000005729f20 @to_s=\"account required pam_permit.so\", @service=\"password-auth\", @silent=false, @type=\"account\", @control=\"required\", @module_path=\"pam_permit.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x0000000005729b10 @to_s=\"password requisite pam_pwquality.so try_first_pass local_users_only retry=3 authtok_type=\", @service=\"password-auth\", @silent=false, @type=\"password\", @control=\"requisite\", @module_path=\"pam_pwquality.so\", @module_arguments=[\"try_first_pass\", \"local_users_only\", \"retry=3\", \"authtok_type=\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x0000000005729548 @to_s=\"password sufficient pam_unix.so sha512 shadow nullok try_first_pass use_authtok\", @service=\"password-auth\", @silent=false, @type=\"password\", @control=\"sufficient\", @module_path=\"pam_unix.so\", @module_arguments=[\"sha512\", \"shadow\", \"nullok\", \"try_first_pass\", \"use_authtok\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x0000000005728fd0 @to_s=\"password required pam_deny.so\", @service=\"password-auth\", @silent=false, @type=\"password\", @control=\"required\", @module_path=\"pam_deny.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x0000000005728c10 @to_s=\"session optional pam_keyinit.so revoke\", @service=\"password-auth\", @silent=false, @type=\"session\", @control=\"optional\", @module_path=\"pam_keyinit.so\", @module_arguments=[\"revoke\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x00000000057286c0 @to_s=\"session required pam_limits.so\", @service=\"password-auth\", @silent=false, @type=\"session\", @control=\"required\", @module_path=\"pam_limits.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x00000000057282b0 @to_s=\"-session optional pam_systemd.so\", @service=\"password-auth\", @silent=true, @type=\"session\", @control=\"optional\", @module_path=\"pam_systemd.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572fe48 @to_s=\"session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid\", @service=\"password-auth\", @silent=false, @type=\"session\", @control=\"[success=1 default=ignore]\", @module_path=\"pam_succeed_if.so\", @module_arguments=[\"service\", \"in\", \"crond\", \"quiet\", \"use_uid\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572f8d0 @to_s=\"session required pam_unix.so\", @service=\"password-auth\", @silent=false, @type=\"session\", @control=\"required\", @module_path=\"pam_unix.so\", @module_arguments=[]>]\n\nDiff for (include [\"auth required pam_faillock.so unlock_time=.*\", \"auth...):\n@@ -1,5 +1,18 @@\n-[\"auth required pam_faillock.so unlock_time=.*\",\n- \"auth sufficient pam_sss.so forward_pass\",\n- \"auth sufficient pam_unix.so try_first_pass\",\n- \"auth [default=die] pam_faillock.so unlock_time=.*\"]\n+[#<#<Class:0x0000000005879628>::Pam::Rule:0x00000000057245c0 @to_s=\"auth required pam_env.so\", @service=\"password-auth\", @silent=false, @type=\"auth\", @control=\"required\", @module_path=\"pam_env.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x00000000057240e8 @to_s=\"auth required pam_faildelay.so delay=2000000\", @service=\"password-auth\", @silent=false, @type=\"auth\", @control=\"required\", @module_path=\"pam_faildelay.so\", @module_arguments=[\"delay=2000000\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572bbe0 @to_s=\"auth sufficient pam_unix.so nullok try_first_pass\", @service=\"password-auth\", @silent=false, @type=\"auth\", @control=\"sufficient\", @module_path=\"pam_unix.so\", @module_arguments=[\"nullok\", \"try_first_pass\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572b690 @to_s=\"auth requisite pam_succeed_if.so uid >= 1000 quiet_success\", @service=\"password-auth\", @silent=false, @type=\"auth\", @control=\"requisite\", @module_path=\"pam_succeed_if.so\", @module_arguments=[\"uid\", \">=\", \"1000\", \"quiet_success\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572b118 @to_s=\"auth required pam_deny.so\", @service=\"password-auth\", @silent=false, @type=\"auth\", @control=\"required\", @module_path=\"pam_deny.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572ad08 @to_s=\"account required pam_unix.so\", @service=\"password-auth\", @silent=false, @type=\"account\", @control=\"required\", @module_path=\"pam_unix.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572a8d0 @to_s=\"account sufficient pam_localuser.so\", @service=\"password-auth\", @silent=false, @type=\"account\", @control=\"sufficient\", @module_path=\"pam_localuser.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572a4c0 @to_s=\"account sufficient pam_succeed_if.so uid < 1000 quiet\", @service=\"password-auth\", @silent=false, @type=\"account\", @control=\"sufficient\", @module_path=\"pam_succeed_if.so\", @module_arguments=[\"uid\", \"<\", \"1000\", \"quiet\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x0000000005729f20 @to_s=\"account required pam_permit.so\", @service=\"password-auth\", @silent=false, @type=\"account\", @control=\"required\", @module_path=\"pam_permit.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x0000000005729b10 @to_s=\"password requisite pam_pwquality.so try_first_pass local_users_only retry=3 authtok_type=\", @service=\"password-auth\", @silent=false, @type=\"password\", @control=\"requisite\", @module_path=\"pam_pwquality.so\", @module_arguments=[\"try_first_pass\", \"local_users_only\", \"retry=3\", \"authtok_type=\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x0000000005729548 @to_s=\"password sufficient pam_unix.so sha512 shadow nullok try_first_pass use_authtok\", @service=\"password-auth\", @silent=false, @type=\"password\", @control=\"sufficient\", @module_path=\"pam_unix.so\", @module_arguments=[\"sha512\", \"shadow\", \"nullok\", \"try_first_pass\", \"use_authtok\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x0000000005728fd0 @to_s=\"password required pam_deny.so\", @service=\"password-auth\", @silent=false, @type=\"password\", @control=\"required\", @module_path=\"pam_deny.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x0000000005728c10 @to_s=\"session optional pam_keyinit.so revoke\", @service=\"password-auth\", @silent=false, @type=\"session\", @control=\"optional\", @module_path=\"pam_keyinit.so\", @module_arguments=[\"revoke\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x00000000057286c0 @to_s=\"session required pam_limits.so\", @service=\"password-auth\", @silent=false, @type=\"session\", @control=\"required\", @module_path=\"pam_limits.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x00000000057282b0 @to_s=\"-session optional pam_systemd.so\", @service=\"password-auth\", @silent=true, @type=\"session\", @control=\"optional\", @module_path=\"pam_systemd.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572fe48 @to_s=\"session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid\", @service=\"password-auth\", @silent=false, @type=\"session\", @control=\"[success=1 default=ignore]\", @module_path=\"pam_succeed_if.so\", @module_arguments=[\"service\", \"in\", \"crond\", \"quiet\", \"use_uid\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572f8d0 @to_s=\"session required pam_unix.so\", @service=\"password-auth\", @silent=false, @type=\"session\", @control=\"required\", @module_path=\"pam_unix.so\", @module_arguments=[]>]\n"
            },
            {
              "status": "passed",
              "code_desc": "PAM Config[/etc/pam.d/password-auth] lines should include auth [default=die]|required pam_faillock.so, all with arg deny <= 3",
              "run_time": 0.000392554,
              "start_time": "2019-11-04T16:17:07-05:00"
            },
            {
              "status": "passed",
              "code_desc": "PAM Config[/etc/pam.d/password-auth] lines should include auth [default=die]|required pam_faillock.so, all with arg fail_interval <= 900",
              "run_time": 0.000300926,
              "start_time": "2019-11-04T16:17:07-05:00"
            },
            {
              "status": "passed",
              "code_desc": "PAM Config[/etc/pam.d/password-auth] lines should include auth [default=die]|required pam_faillock.so, all with args unlock_time=(0|never) or include auth [default=die]|required pam_faillock.so, all with arg unlock_time <= 604800 and include auth [default=die]|required pam_faillock.so, all with arg unlock_time >= 604800",
              "run_time": 0.000352844,
              "start_time": "2019-11-04T16:17:07-05:00"
            },
            {
              "status": "failed",
              "code_desc": "PAM Config[/etc/pam.d/system-auth] lines should include [\"auth required pam_faillock.so unlock_time=.*\", \"auth sufficient pam_unix.so try_first_pass\", \"auth [default=die] pam_faillock.so unlock_time=.*\"] exactly or include [\"auth required pam_faillock.so unlock_time=.*\", \"auth sufficient pam_sss.so forward_pass\", \"auth sufficient pam_unix.so try_first_pass\", \"auth [default=die] pam_faillock.so unlock_time=.*\"] exactly",
              "run_time": 0.264804286,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "   expected \"account required pam_unix.so\\naccount sufficient pam_localuser.so\\naccount sufficient pam_succeed_if...ss=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid\\nsession required pam_unix.so\" to include [\"auth required pam_faillock.so unlock_time=.*\", \"auth sufficient pam_unix.so try_first_pass\", \"auth [default=die] pam_faillock.so unlock_time=.*\"] exactly\n\n...or:\n\n   expected \"account required pam_unix.so\\naccount sufficient pam_localuser.so\\naccount sufficient pam_succeed_if...ss=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid\\nsession required pam_unix.so\" to include [\"auth required pam_faillock.so unlock_time=.*\", \"auth sufficient pam_sss.so forward_pass\", \"auth sufficient pam_unix.so try_first_pass\", \"auth [default=die] pam_faillock.so unlock_time=.*\"] exactly\nDiff for (include [\"auth required pam_faillock.so unlock_time=.*\", \"auth...):\n@@ -1,4 +1,18 @@\n-[\"auth required pam_faillock.so unlock_time=.*\",\n- \"auth sufficient pam_unix.so try_first_pass\",\n- \"auth [default=die] pam_faillock.so unlock_time=.*\"]\n+[#<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572df80 @to_s=\"auth required pam_env.so\", @service=\"system-auth\", @silent=false, @type=\"auth\", @control=\"required\", @module_path=\"pam_env.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572dad0 @to_s=\"auth required pam_faildelay.so delay=2000000\", @service=\"system-auth\", @silent=false, @type=\"auth\", @control=\"required\", @module_path=\"pam_faildelay.so\", @module_arguments=[\"delay=2000000\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572d620 @to_s=\"auth sufficient pam_unix.so nullok try_first_pass\", @service=\"system-auth\", @silent=false, @type=\"auth\", @control=\"sufficient\", @module_path=\"pam_unix.so\", @module_arguments=[\"nullok\", \"try_first_pass\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572d0f8 @to_s=\"auth requisite pam_succeed_if.so uid >= 1000 quiet_success\", @service=\"system-auth\", @silent=false, @type=\"auth\", @control=\"requisite\", @module_path=\"pam_succeed_if.so\", @module_arguments=[\"uid\", \">=\", \"1000\", \"quiet_success\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572cb58 @to_s=\"auth required pam_deny.so\", @service=\"system-auth\", @silent=false, @type=\"auth\", @control=\"required\", @module_path=\"pam_deny.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572c748 @to_s=\"account required pam_unix.so\", @service=\"system-auth\", @silent=false, @type=\"account\", @control=\"required\", @module_path=\"pam_unix.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572c310 @to_s=\"account sufficient pam_localuser.so\", @service=\"system-auth\", @silent=false, @type=\"account\", @control=\"sufficient\", @module_path=\"pam_localuser.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x0000000005733ea8 @to_s=\"account sufficient pam_succeed_if.so uid < 1000 quiet\", @service=\"system-auth\", @silent=false, @type=\"account\", @control=\"sufficient\", @module_path=\"pam_succeed_if.so\", @module_arguments=[\"uid\", \"<\", \"1000\", \"quiet\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x0000000005733930 @to_s=\"account required pam_permit.so\", @service=\"system-auth\", @silent=false, @type=\"account\", @control=\"required\", @module_path=\"pam_permit.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x00000000057334f8 @to_s=\"password requisite pam_pwquality.so try_first_pass local_users_only retry=3 authtok_type=\", @service=\"system-auth\", @silent=false, @type=\"password\", @control=\"requisite\", @module_path=\"pam_pwquality.so\", @module_arguments=[\"try_first_pass\", \"local_users_only\", \"retry=3\", \"authtok_type=\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x0000000005732f30 @to_s=\"password sufficient pam_unix.so sha512 shadow nullok try_first_pass use_authtok\", @service=\"system-auth\", @silent=false, @type=\"password\", @control=\"sufficient\", @module_path=\"pam_unix.so\", @module_arguments=[\"sha512\", \"shadow\", \"nullok\", \"try_first_pass\", \"use_authtok\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x00000000057329b8 @to_s=\"password required pam_deny.so\", @service=\"system-auth\", @silent=false, @type=\"password\", @control=\"required\", @module_path=\"pam_deny.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x00000000057325f8 @to_s=\"session optional pam_keyinit.so revoke\", @service=\"system-auth\", @silent=false, @type=\"session\", @control=\"optional\", @module_path=\"pam_keyinit.so\", @module_arguments=[\"revoke\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x00000000057320a8 @to_s=\"session required pam_limits.so\", @service=\"system-auth\", @silent=false, @type=\"session\", @control=\"required\", @module_path=\"pam_limits.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x0000000005731c98 @to_s=\"-session optional pam_systemd.so\", @service=\"system-auth\", @silent=true, @type=\"session\", @control=\"optional\", @module_path=\"pam_systemd.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x0000000005731860 @to_s=\"session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid\", @service=\"system-auth\", @silent=false, @type=\"session\", @control=\"[success=1 default=ignore]\", @module_path=\"pam_succeed_if.so\", @module_arguments=[\"service\", \"in\", \"crond\", \"quiet\", \"use_uid\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x00000000057312e8 @to_s=\"session required pam_unix.so\", @service=\"system-auth\", @silent=false, @type=\"session\", @control=\"required\", @module_path=\"pam_unix.so\", @module_arguments=[]>]\n\nDiff for (include [\"auth required pam_faillock.so unlock_time=.*\", \"auth...):\n@@ -1,5 +1,18 @@\n-[\"auth required pam_faillock.so unlock_time=.*\",\n- \"auth sufficient pam_sss.so forward_pass\",\n- \"auth sufficient pam_unix.so try_first_pass\",\n- \"auth [default=die] pam_faillock.so unlock_time=.*\"]\n+[#<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572df80 @to_s=\"auth required pam_env.so\", @service=\"system-auth\", @silent=false, @type=\"auth\", @control=\"required\", @module_path=\"pam_env.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572dad0 @to_s=\"auth required pam_faildelay.so delay=2000000\", @service=\"system-auth\", @silent=false, @type=\"auth\", @control=\"required\", @module_path=\"pam_faildelay.so\", @module_arguments=[\"delay=2000000\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572d620 @to_s=\"auth sufficient pam_unix.so nullok try_first_pass\", @service=\"system-auth\", @silent=false, @type=\"auth\", @control=\"sufficient\", @module_path=\"pam_unix.so\", @module_arguments=[\"nullok\", \"try_first_pass\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572d0f8 @to_s=\"auth requisite pam_succeed_if.so uid >= 1000 quiet_success\", @service=\"system-auth\", @silent=false, @type=\"auth\", @control=\"requisite\", @module_path=\"pam_succeed_if.so\", @module_arguments=[\"uid\", \">=\", \"1000\", \"quiet_success\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572cb58 @to_s=\"auth required pam_deny.so\", @service=\"system-auth\", @silent=false, @type=\"auth\", @control=\"required\", @module_path=\"pam_deny.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572c748 @to_s=\"account required pam_unix.so\", @service=\"system-auth\", @silent=false, @type=\"account\", @control=\"required\", @module_path=\"pam_unix.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x000000000572c310 @to_s=\"account sufficient pam_localuser.so\", @service=\"system-auth\", @silent=false, @type=\"account\", @control=\"sufficient\", @module_path=\"pam_localuser.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x0000000005733ea8 @to_s=\"account sufficient pam_succeed_if.so uid < 1000 quiet\", @service=\"system-auth\", @silent=false, @type=\"account\", @control=\"sufficient\", @module_path=\"pam_succeed_if.so\", @module_arguments=[\"uid\", \"<\", \"1000\", \"quiet\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x0000000005733930 @to_s=\"account required pam_permit.so\", @service=\"system-auth\", @silent=false, @type=\"account\", @control=\"required\", @module_path=\"pam_permit.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x00000000057334f8 @to_s=\"password requisite pam_pwquality.so try_first_pass local_users_only retry=3 authtok_type=\", @service=\"system-auth\", @silent=false, @type=\"password\", @control=\"requisite\", @module_path=\"pam_pwquality.so\", @module_arguments=[\"try_first_pass\", \"local_users_only\", \"retry=3\", \"authtok_type=\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x0000000005732f30 @to_s=\"password sufficient pam_unix.so sha512 shadow nullok try_first_pass use_authtok\", @service=\"system-auth\", @silent=false, @type=\"password\", @control=\"sufficient\", @module_path=\"pam_unix.so\", @module_arguments=[\"sha512\", \"shadow\", \"nullok\", \"try_first_pass\", \"use_authtok\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x00000000057329b8 @to_s=\"password required pam_deny.so\", @service=\"system-auth\", @silent=false, @type=\"password\", @control=\"required\", @module_path=\"pam_deny.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x00000000057325f8 @to_s=\"session optional pam_keyinit.so revoke\", @service=\"system-auth\", @silent=false, @type=\"session\", @control=\"optional\", @module_path=\"pam_keyinit.so\", @module_arguments=[\"revoke\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x00000000057320a8 @to_s=\"session required pam_limits.so\", @service=\"system-auth\", @silent=false, @type=\"session\", @control=\"required\", @module_path=\"pam_limits.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x0000000005731c98 @to_s=\"-session optional pam_systemd.so\", @service=\"system-auth\", @silent=true, @type=\"session\", @control=\"optional\", @module_path=\"pam_systemd.so\", @module_arguments=[]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x0000000005731860 @to_s=\"session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid\", @service=\"system-auth\", @silent=false, @type=\"session\", @control=\"[success=1 default=ignore]\", @module_path=\"pam_succeed_if.so\", @module_arguments=[\"service\", \"in\", \"crond\", \"quiet\", \"use_uid\"]>,\n+ #<#<Class:0x0000000005879628>::Pam::Rule:0x00000000057312e8 @to_s=\"session required pam_unix.so\", @service=\"system-auth\", @silent=false, @type=\"session\", @control=\"required\", @module_path=\"pam_unix.so\", @module_arguments=[]>]\n"
            },
            {
              "status": "passed",
              "code_desc": "PAM Config[/etc/pam.d/system-auth] lines should include auth [default=die]|required pam_faillock.so, all with arg deny <= 3",
              "run_time": 0.00036778,
              "start_time": "2019-11-04T16:17:07-05:00"
            },
            {
              "status": "passed",
              "code_desc": "PAM Config[/etc/pam.d/system-auth] lines should include auth [default=die]|required pam_faillock.so, all with arg fail_interval <= 900",
              "run_time": 0.000251298,
              "start_time": "2019-11-04T16:17:07-05:00"
            },
            {
              "status": "passed",
              "code_desc": "PAM Config[/etc/pam.d/system-auth] lines should include auth [default=die]|required pam_faillock.so, all with args unlock_time=(0|never) or include auth [default=die]|required pam_faillock.so, all with arg unlock_time <= 604800 and include auth [default=die]|required pam_faillock.so, all with arg unlock_time >= 604800",
              "run_time": 0.000298751,
              "start_time": "2019-11-04T16:17:07-05:00"
            }
          ]
        },
        {
          "id": "V-71945",
          "title": "If three unsuccessful root logon attempts within 15 minutes occur the\nassociated account must be locked.",
          "desc": "By limiting the number of failed logon attempts, the risk of\nunauthorized system access via user password guessing, otherwise known as\nbrute-forcing, is reduced. Limits are imposed by locking the account.",
          "descriptions": [
            {
              "label": "default",
              "data": "By limiting the number of failed logon attempts, the risk of\nunauthorized system access via user password guessing, otherwise known as\nbrute-forcing, is reduced. Limits are imposed by locking the account."
            },
            {
              "label": "check",
              "data": "Verify the operating system automatically locks the root\naccount until it is released by an administrator when three unsuccessful logon\nattempts in 15 minutes are made.\n\n# grep pam_faillock.so /etc/pam.d/password-auth-ac\nauth required pam_faillock.so preauth silent audit deny=3 even_deny_root unlock_time=604800 fail_interval=900\nauth [default=die] pam_faillock.so authfail audit deny=3 even_deny_root unlock_time=604800 fail_interval=900\naccount required pam_faillock.so\n\nIf the \"even_deny_root\" setting is not defined on both lines with the\n\"pam_faillock.so\" module name, this is a finding.\n\n# grep pam_faillock.so /etc/pam.d/system-auth-ac\nauth required pam_faillock.so preauth silent audit deny=3 even_deny_root unlock_time=604800 fail_interval=900\nauth [default=die] pam_faillock.so authfail audit deny=3 even_deny_root unlock_time=604800 fail_interval=900\naccount required pam_faillock.so\n\nIf the \"even_deny_root\" setting is not defined on both lines with the\n\"pam_faillock.so\" module name, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to automatically lock the root\naccount until the locked account is released by an administrator when three\nunsuccessful logon attempts in 15 minutes are made.\n\nModify the first three lines of the auth section of the\n\"/etc/pam.d/system-auth-ac\" and \"/etc/pam.d/password-auth-ac\" files to\nmatch the following lines:\n\nauth        required       pam_faillock.so preauth silent audit deny=3 even_deny_root fail_interval=900 unlock_time=604800\nauth        sufficient     pam_unix.so try_first_pass\nauth        [default=die]  pam_faillock.so authfail audit deny=3 even_deny_root fail_interval=900 unlock_time=604800\naccount required pam_faillock.so\n\nNote: Any updates made to \"/etc/pam.d/system-auth-ac\" and\n\"/etc/pam.d/password-auth-ac\" may be overwritten by the \"authconfig\"\nprogram. The \"authconfig\" program should not be used."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000329-GPOS-00128",
            "satisfies": [
              "SRG-OS-000329-GPOS-00128",
              "SRG-OS-000021-GPOS-00005"
            ],
            "gid": "V-71945",
            "rid": "SV-86569r2_rule",
            "stig_id": "RHEL-07-010330",
            "cci": [
              "CCI-002238"
            ],
            "documentable": false,
            "nist": [
              "AC-7 b",
              "Rev_4"
            ],
            "subsystems": [
              "pam"
            ],
            "fix_id": "F-78297r2_fix"
          },
          "code": "control \"V-71945\" do\n  title \"If three unsuccessful root logon attempts within 15 minutes occur the\nassociated account must be locked.\"\n  desc  \"By limiting the number of failed logon attempts, the risk of\nunauthorized system access via user password guessing, otherwise known as\nbrute-forcing, is reduced. Limits are imposed by locking the account.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000329-GPOS-00128\"\n  tag \"satisfies\": [\"SRG-OS-000329-GPOS-00128\", \"SRG-OS-000021-GPOS-00005\"]\n  tag \"gid\": \"V-71945\"\n  tag \"rid\": \"SV-86569r2_rule\"\n  tag \"stig_id\": \"RHEL-07-010330\"\n  tag \"cci\": [\"CCI-002238\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-7 b\", \"Rev_4\"]\n  tag \"subsystems\": ['pam']\n  desc \"check\", \"Verify the operating system automatically locks the root\naccount until it is released by an administrator when three unsuccessful logon\nattempts in 15 minutes are made.\n\n# grep pam_faillock.so /etc/pam.d/password-auth-ac\nauth required pam_faillock.so preauth silent audit deny=3 even_deny_root unlock_time=604800 fail_interval=900\nauth [default=die] pam_faillock.so authfail audit deny=3 even_deny_root unlock_time=604800 fail_interval=900\naccount required pam_faillock.so\n\nIf the \\\"even_deny_root\\\" setting is not defined on both lines with the\n\\\"pam_faillock.so\\\" module name, this is a finding.\n\n# grep pam_faillock.so /etc/pam.d/system-auth-ac\nauth required pam_faillock.so preauth silent audit deny=3 even_deny_root unlock_time=604800 fail_interval=900\nauth [default=die] pam_faillock.so authfail audit deny=3 even_deny_root unlock_time=604800 fail_interval=900\naccount required pam_faillock.so\n\nIf the \\\"even_deny_root\\\" setting is not defined on both lines with the\n\\\"pam_faillock.so\\\" module name, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to automatically lock the root\naccount until the locked account is released by an administrator when three\nunsuccessful logon attempts in 15 minutes are made.\n\nModify the first three lines of the auth section of the\n\\\"/etc/pam.d/system-auth-ac\\\" and \\\"/etc/pam.d/password-auth-ac\\\" files to\nmatch the following lines:\n\nauth        required       pam_faillock.so preauth silent audit deny=3 even_deny_root fail_interval=900 unlock_time=604800\nauth        sufficient     pam_unix.so try_first_pass\nauth        [default=die]  pam_faillock.so authfail audit deny=3 even_deny_root fail_interval=900 unlock_time=604800\naccount required pam_faillock.so\n\nNote: Any updates made to \\\"/etc/pam.d/system-auth-ac\\\" and\n\\\"/etc/pam.d/password-auth-ac\\\" may be overwritten by the \\\"authconfig\\\"\nprogram. The \\\"authconfig\\\" program should not be used.\"\n  tag \"fix_id\": \"F-78297r2_fix\"\n\n  required_lines = [\n    'auth required pam_faillock.so even_deny_root',\n    'auth sufficient pam_unix.so try_first_pass',\n    'auth [default=die] pam_faillock.so even_deny_root'\n  ]\n\n  describe pam('/etc/pam.d/password-auth') do\n    its('lines') { should match_pam_rules(required_lines) }\n    its('lines') { should match_pam_rule('auth .* pam_faillock.so (preauth|authfail)').all_with_args('even_deny_root') }\n  end\n\n  describe pam('/etc/pam.d/system-auth') do\n    its('lines') { should match_pam_rules(required_lines) }\n    its('lines') { should match_pam_rule('auth .* pam_faillock.so (preauth|authfail)').all_with_args('even_deny_root') }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71945.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "PAM Config[/etc/pam.d/password-auth] lines should include [\"auth required pam_faillock.so even_deny_root\", \"auth sufficient pam_unix.so try_first_pass\", \"auth [default=die] pam_faillock.so even_deny_root\"]",
              "run_time": 0.000855356,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "expected \"account required pam_unix.so\\naccount sufficient pam_localuser.so\\naccount sufficient pam_succeed_if...ss=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid\\nsession required pam_unix.so\" to include [\"auth required pam_faillock.so even_deny_root\", \"auth sufficient pam_unix.so try_first_pass\", \"auth [default=die] pam_faillock.so even_deny_root\"]\nDiff:\n@@ -1,4 +1,18 @@\n-auth required pam_faillock.so even_deny_root\n-auth sufficient pam_unix.so try_first_pass\n-auth [default=die] pam_faillock.so even_deny_root\n+account required pam_unix.so\n+account sufficient pam_localuser.so\n+account sufficient pam_succeed_if.so uid < 1000 quiet\n+account required pam_permit.so\n+auth required pam_env.so\n+auth required pam_faildelay.so delay=2000000\n+auth sufficient pam_unix.so nullok try_first_pass\n+auth requisite pam_succeed_if.so uid >= 1000 quiet_success\n+auth required pam_deny.so\n+password requisite pam_pwquality.so try_first_pass local_users_only retry=3 authtok_type=\n+password sufficient pam_unix.so sha512 shadow nullok try_first_pass use_authtok\n+password required pam_deny.so\n+session optional pam_keyinit.so revoke\n+session required pam_limits.so\n+-session optional pam_systemd.so\n+session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid\n+session required pam_unix.so\n"
            },
            {
              "status": "passed",
              "code_desc": "PAM Config[/etc/pam.d/password-auth] lines should include auth .* pam_faillock.so (preauth|authfail), all with args even_deny_root",
              "run_time": 0.000329063,
              "start_time": "2019-11-04T16:17:07-05:00"
            },
            {
              "status": "failed",
              "code_desc": "PAM Config[/etc/pam.d/system-auth] lines should include [\"auth required pam_faillock.so even_deny_root\", \"auth sufficient pam_unix.so try_first_pass\", \"auth [default=die] pam_faillock.so even_deny_root\"]",
              "run_time": 0.000787282,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "expected \"account required pam_unix.so\\naccount sufficient pam_localuser.so\\naccount sufficient pam_succeed_if...ss=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid\\nsession required pam_unix.so\" to include [\"auth required pam_faillock.so even_deny_root\", \"auth sufficient pam_unix.so try_first_pass\", \"auth [default=die] pam_faillock.so even_deny_root\"]\nDiff:\n@@ -1,4 +1,18 @@\n-auth required pam_faillock.so even_deny_root\n-auth sufficient pam_unix.so try_first_pass\n-auth [default=die] pam_faillock.so even_deny_root\n+account required pam_unix.so\n+account sufficient pam_localuser.so\n+account sufficient pam_succeed_if.so uid < 1000 quiet\n+account required pam_permit.so\n+auth required pam_env.so\n+auth required pam_faildelay.so delay=2000000\n+auth sufficient pam_unix.so nullok try_first_pass\n+auth requisite pam_succeed_if.so uid >= 1000 quiet_success\n+auth required pam_deny.so\n+password requisite pam_pwquality.so try_first_pass local_users_only retry=3 authtok_type=\n+password sufficient pam_unix.so sha512 shadow nullok try_first_pass use_authtok\n+password required pam_deny.so\n+session optional pam_keyinit.so revoke\n+session required pam_limits.so\n+-session optional pam_systemd.so\n+session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid\n+session required pam_unix.so\n"
            },
            {
              "status": "passed",
              "code_desc": "PAM Config[/etc/pam.d/system-auth] lines should include auth .* pam_faillock.so (preauth|authfail), all with args even_deny_root",
              "run_time": 0.000327565,
              "start_time": "2019-11-04T16:17:07-05:00"
            }
          ]
        },
        {
          "id": "V-71947",
          "title": "Users must provide a password for privilege escalation.",
          "desc": "Without re-authentication, users may access resources or perform tasks for\nwhich they do not have authorization.\n\n    When operating systems provide the capability to escalate a functional\ncapability, it is critical the user re-authenticate.",
          "descriptions": [
            {
              "label": "default",
              "data": "Without re-authentication, users may access resources or perform tasks for\nwhich they do not have authorization.\n\n    When operating systems provide the capability to escalate a functional\ncapability, it is critical the user re-authenticate."
            },
            {
              "label": "check",
              "data": "If passwords are not being used for authentication, this is Not\nApplicable.\n\nVerify the operating system requires users to supply a password for privilege\nescalation.\n\nCheck the configuration of the \"/etc/sudoers\" and \"/etc/sudoers.d/*\" files\nwith the following command:\n\n# grep -i nopasswd /etc/sudoers /etc/sudoers.d/*\n\nIf any uncommented line is found with a \"NOPASSWD\" tag, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to require users to supply a\npassword for privilege escalation.\n\nCheck the configuration of the \"/etc/sudoers\" and \"/etc/sudoers.d/*\" files\nwith the following command:\n\n# grep -i nopasswd /etc/sudoers /etc/sudoers.d/*\n\nRemove any occurrences of \"NOPASSWD\" tags in the file."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000373-GPOS-00156",
            "satisfies": [
              "SRG-OS-000373-GPOS-00156",
              "SRG-OS-000373-GPOS-00157",
              "SRG-OS-000373-GPOS-00158"
            ],
            "gid": "V-71947",
            "rid": "SV-86571r2_rule",
            "stig_id": "RHEL-07-010340",
            "cci": [
              "CCI-002038"
            ],
            "documentable": false,
            "nist": [
              "IA-11",
              "Rev_4"
            ],
            "subsystems": [
              "sudo"
            ],
            "fix_id": "F-78299r1_fix"
          },
          "code": "control \"V-71947\" do\n  title \"Users must provide a password for privilege escalation.\"\n  desc  \"\n    Without re-authentication, users may access resources or perform tasks for\nwhich they do not have authorization.\n\n    When operating systems provide the capability to escalate a functional\ncapability, it is critical the user re-authenticate.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000373-GPOS-00156\"\n  tag \"satisfies\": [\"SRG-OS-000373-GPOS-00156\", \"SRG-OS-000373-GPOS-00157\", \"SRG-OS-000373-GPOS-00158\"]\n  tag \"gid\": \"V-71947\"\n  tag \"rid\": \"SV-86571r2_rule\"\n  tag \"stig_id\": \"RHEL-07-010340\"\n  tag \"cci\": [\"CCI-002038\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-11\", \"Rev_4\"]\n  tag \"subsystems\": ['sudo']\n  desc \"check\", \"If passwords are not being used for authentication, this is Not\nApplicable.\n\nVerify the operating system requires users to supply a password for privilege\nescalation.\n\nCheck the configuration of the \\\"/etc/sudoers\\\" and \\\"/etc/sudoers.d/*\\\" files\nwith the following command:\n\n# grep -i nopasswd /etc/sudoers /etc/sudoers.d/*\n\nIf any uncommented line is found with a \\\"NOPASSWD\\\" tag, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to require users to supply a\npassword for privilege escalation.\n\nCheck the configuration of the \\\"/etc/sudoers\\\" and \\\"/etc/sudoers.d/*\\\" files\nwith the following command:\n\n# grep -i nopasswd /etc/sudoers /etc/sudoers.d/*\n\nRemove any occurrences of \\\"NOPASSWD\\\" tags in the file.\"\n  tag \"fix_id\": \"F-78299r1_fix\"\n\n  processed = []\n  to_process = ['/etc/sudoers', '/etc/sudoers.d']\n\n  while !to_process.empty?\n    in_process = to_process.pop\n    next if processed.include? in_process\n    processed.push in_process\n\n    if file(in_process).directory?\n      to_process.concat(\n        command(\"find #{in_process} -maxdepth 1 -mindepth 1\").\n          stdout.strip.split(\"\\n\").\n          select { |f| file(f).file? }\n      )\n    elsif file(in_process).file?\n      to_process.concat(\n        command(\"grep -E '#include\\\\s+' #{in_process} | sed 's/.*#include[[:space:]]*//g'\").\n          stdout.strip.split(\"\\n\").\n          map { |f| f.start_with?('/') ? f : File.join(File.dirname(in_process), f) }.\n          select { |f| file(f).exist? }\n      )\n      to_process.concat(\n        command(\"grep -E '#includedir\\\\s+' #{in_process} | sed 's/.*#includedir[[:space:]]*//g'\").\n          stdout.strip.split(\"\\n\").\n          map { |f| f.start_with?('/') ? f : File.join(File.dirname(in_process), f) }.\n          select { |f| file(f).exist? }\n      )\n    end\n  end\n\n  sudoers = processed.select { |f| file(f).file? }\n\n  sudoers.each do |sudoer|\n    describe command(\"grep -i nopasswd #{sudoer}\") do\n      its('stdout') { should_not match %r{^[^#]*NOPASSWD} }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71947.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Command: `grep -i nopasswd /etc/sudoers` stdout should not match /^[^#]*NOPASSWD/",
              "run_time": 0.013861138,
              "start_time": "2019-11-04T16:17:07-05:00"
            }
          ]
        },
        {
          "id": "V-71949",
          "title": "Users must re-authenticate for privilege escalation.",
          "desc": "Without re-authentication, users may access resources or perform tasks for\nwhich they do not have authorization.\n\n    When operating systems provide the capability to escalate a functional\ncapability, it is critical the user reauthenticate.",
          "descriptions": [
            {
              "label": "default",
              "data": "Without re-authentication, users may access resources or perform tasks for\nwhich they do not have authorization.\n\n    When operating systems provide the capability to escalate a functional\ncapability, it is critical the user reauthenticate."
            },
            {
              "label": "check",
              "data": "Verify the operating system requires users to reauthenticate\nfor privilege escalation.\n\nCheck the configuration of the \"/etc/sudoers\" and \"/etc/sudoers.d/*\" files\nwith the following command:\n\n# grep -i authenticate /etc/sudoers /etc/sudoers.d/*\n\nIf any line is found with a \"!authenticate\" tag, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to require users to reauthenticate\nfor privilege escalation.\n\nCheck the configuration of the \"/etc/sudoers\" and \"/etc/sudoers.d/*\" files\nwith the following command:\n\nRemove any occurrences of \"!authenticate\" tags in the file."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000373-GPOS-00156",
            "satisfies": [
              "SRG-OS-000373-GPOS-00156",
              "SRG-OS-000373-GPOS-00157",
              "SRG-OS-000373-GPOS-00158"
            ],
            "gid": "V-71949",
            "rid": "SV-86573r2_rule",
            "stig_id": "RHEL-07-010350",
            "cci": [
              "CCI-002038"
            ],
            "documentable": false,
            "nist": [
              "IA-11",
              "Rev_4"
            ],
            "subsystems": [
              "sudo"
            ],
            "fix_id": "F-78301r2_fix"
          },
          "code": "control \"V-71949\" do\n  title \"Users must re-authenticate for privilege escalation.\"\n  desc  \"\n    Without re-authentication, users may access resources or perform tasks for\nwhich they do not have authorization.\n\n    When operating systems provide the capability to escalate a functional\ncapability, it is critical the user reauthenticate.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000373-GPOS-00156\"\n  tag \"satisfies\": [\"SRG-OS-000373-GPOS-00156\", \"SRG-OS-000373-GPOS-00157\", \"SRG-OS-000373-GPOS-00158\"]\n  tag \"gid\": \"V-71949\"\n  tag \"rid\": \"SV-86573r2_rule\"\n  tag \"stig_id\": \"RHEL-07-010350\"\n  tag \"cci\": [\"CCI-002038\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-11\", \"Rev_4\"]\n  tag \"subsystems\": ['sudo']\n  desc \"check\", \"Verify the operating system requires users to reauthenticate\nfor privilege escalation.\n\nCheck the configuration of the \\\"/etc/sudoers\\\" and \\\"/etc/sudoers.d/*\\\" files\nwith the following command:\n\n# grep -i authenticate /etc/sudoers /etc/sudoers.d/*\n\nIf any line is found with a \\\"!authenticate\\\" tag, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to require users to reauthenticate\nfor privilege escalation.\n\nCheck the configuration of the \\\"/etc/sudoers\\\" and \\\"/etc/sudoers.d/*\\\" files\nwith the following command:\n\nRemove any occurrences of \\\"!authenticate\\\" tags in the file.\"\n  tag \"fix_id\": \"F-78301r2_fix\"\n  describe command(\"grep -ir authenticate /etc/sudoers /etc/sudoers.d/*\") do\n    its('stdout') { should_not match %r{!authenticate} }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71949.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Command: `grep -ir authenticate /etc/sudoers /etc/sudoers.d/*` stdout should not match /!authenticate/",
              "run_time": 0.014122884,
              "start_time": "2019-11-04T16:17:07-05:00"
            }
          ]
        },
        {
          "id": "V-71951",
          "title": "The delay between logon prompts following a failed console logon\nattempt must be at least four seconds.",
          "desc": "Configuring the operating system to implement organization-wide security\nimplementation guides and security checklists verifies compliance with federal\nstandards and establishes a common security baseline across DoD that reflects\nthe most restrictive security posture consistent with operational requirements.\n\n    Configuration settings are the set of parameters that can be changed in\nhardware, software, or firmware components of the system that affect the\nsecurity posture and/or functionality of the system. Security-related\nparameters are those parameters impacting the security state of the system,\nincluding the parameters required to satisfy other security control\nrequirements. Security-related parameters include, for example, registry\nsettings; account, file, and directory permission settings; and settings for\nfunctions, ports, protocols, services, and remote connections.",
          "descriptions": [
            {
              "label": "default",
              "data": "Configuring the operating system to implement organization-wide security\nimplementation guides and security checklists verifies compliance with federal\nstandards and establishes a common security baseline across DoD that reflects\nthe most restrictive security posture consistent with operational requirements.\n\n    Configuration settings are the set of parameters that can be changed in\nhardware, software, or firmware components of the system that affect the\nsecurity posture and/or functionality of the system. Security-related\nparameters are those parameters impacting the security state of the system,\nincluding the parameters required to satisfy other security control\nrequirements. Security-related parameters include, for example, registry\nsettings; account, file, and directory permission settings; and settings for\nfunctions, ports, protocols, services, and remote connections."
            },
            {
              "label": "check",
              "data": "Verify the operating system enforces a delay of at least four\nseconds between console logon prompts following a failed logon attempt.\n\nCheck the value of the \"fail_delay\" parameter in the \"/etc/login.defs\" file\nwith the following command:\n\n# grep -i fail_delay /etc/login.defs\nFAIL_DELAY 4\n\nIf the value of \"FAIL_DELAY\" is not set to \"4\" or greater, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to enforce a delay of at least\nfour seconds between logon prompts following a failed console logon attempt.\n\nModify the \"/etc/login.defs\" file to set the \"FAIL_DELAY\" parameter to\n\"4\" or greater:\n\nFAIL_DELAY 4"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00226",
            "gid": "V-71951",
            "rid": "SV-86575r1_rule",
            "stig_id": "RHEL-07-010430",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "login_defs"
            ],
            "fix_id": "F-78303r1_fix"
          },
          "code": "control \"V-71951\" do\n  title \"The delay between logon prompts following a failed console logon\nattempt must be at least four seconds.\"\n  desc  \"\n    Configuring the operating system to implement organization-wide security\nimplementation guides and security checklists verifies compliance with federal\nstandards and establishes a common security baseline across DoD that reflects\nthe most restrictive security posture consistent with operational requirements.\n\n    Configuration settings are the set of parameters that can be changed in\nhardware, software, or firmware components of the system that affect the\nsecurity posture and/or functionality of the system. Security-related\nparameters are those parameters impacting the security state of the system,\nincluding the parameters required to satisfy other security control\nrequirements. Security-related parameters include, for example, registry\nsettings; account, file, and directory permission settings; and settings for\nfunctions, ports, protocols, services, and remote connections.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00226\"\n  tag \"gid\": \"V-71951\"\n  tag \"rid\": \"SV-86575r1_rule\"\n  tag \"stig_id\": \"RHEL-07-010430\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['login_defs']\n  desc \"check\", \"Verify the operating system enforces a delay of at least four\nseconds between console logon prompts following a failed logon attempt.\n\nCheck the value of the \\\"fail_delay\\\" parameter in the \\\"/etc/login.defs\\\" file\nwith the following command:\n\n# grep -i fail_delay /etc/login.defs\nFAIL_DELAY 4\n\nIf the value of \\\"FAIL_DELAY\\\" is not set to \\\"4\\\" or greater, this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to enforce a delay of at least\nfour seconds between logon prompts following a failed console logon attempt.\n\nModify the \\\"/etc/login.defs\\\" file to set the \\\"FAIL_DELAY\\\" parameter to\n\\\"4\\\" or greater:\n\nFAIL_DELAY 4\"\n  tag \"fix_id\": \"F-78303r1_fix\"\n  describe login_defs do\n    its('FAIL_DELAY.to_i') { should cmp >= 4 }\n  end\nend\n",
          "source_location": {
            "line": 6,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71951.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "login.defs FAIL_DELAY.to_i should cmp >= 4",
              "run_time": 0.000567544,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "\nexpected it to be >= 4\n     got: 0\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-71953",
          "title": "The operating system must not allow an unattended or automatic logon\nto the system via a graphical user interface.",
          "desc": "Failure to restrict system access to authenticated users negatively\nimpacts operating system security.",
          "descriptions": [
            {
              "label": "default",
              "data": "Failure to restrict system access to authenticated users negatively\nimpacts operating system security."
            },
            {
              "label": "check",
              "data": "Verify the operating system does not allow an unattended or\nautomatic logon to the system via a graphical user interface.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nCheck for the value of the \"AutomaticLoginEnable\" in the\n\"/etc/gdm/custom.conf\" file with the following command:\n\n# grep -i automaticloginenable /etc/gdm/custom.conf\nAutomaticLoginEnable=false\n\nIf the value of \"AutomaticLoginEnable\" is not set to \"false\", this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to not allow an unattended or\nautomatic logon to the system via a graphical user interface.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nAdd or edit the line for the \"AutomaticLoginEnable\" parameter in the [daemon]\nsection of the \"/etc/gdm/custom.conf\" file to \"false\":\n\n[daemon]\nAutomaticLoginEnable=false"
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00229",
            "gid": "V-71953",
            "rid": "SV-86577r1_rule",
            "stig_id": "RHEL-07-010440",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "gdm"
            ],
            "fix_id": "F-78305r1_fix"
          },
          "code": "control \"V-71953\" do\n  title \"The operating system must not allow an unattended or automatic logon\nto the system via a graphical user interface.\"\n  desc  \"Failure to restrict system access to authenticated users negatively\nimpacts operating system security.\"\nif package('gdm').installed?\n  impact 0.7\nelse\n  impact 0.0\nend\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00229\"\n  tag \"gid\": \"V-71953\"\n  tag \"rid\": \"SV-86577r1_rule\"\n  tag \"stig_id\": \"RHEL-07-010440\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": [\"gdm\"]\n  desc \"check\", \"Verify the operating system does not allow an unattended or\nautomatic logon to the system via a graphical user interface.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nCheck for the value of the \\\"AutomaticLoginEnable\\\" in the\n\\\"/etc/gdm/custom.conf\\\" file with the following command:\n\n# grep -i automaticloginenable /etc/gdm/custom.conf\nAutomaticLoginEnable=false\n\nIf the value of \\\"AutomaticLoginEnable\\\" is not set to \\\"false\\\", this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to not allow an unattended or\nautomatic logon to the system via a graphical user interface.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nAdd or edit the line for the \\\"AutomaticLoginEnable\\\" parameter in the [daemon]\nsection of the \\\"/etc/gdm/custom.conf\\\" file to \\\"false\\\":\n\n[daemon]\nAutomaticLoginEnable=false\"\n  tag \"fix_id\": \"F-78305r1_fix\"\n\n  custom_conf = '/etc/gdm/custom.conf'\n\n  if package('gdm').installed?\n    if ((f = file(custom_conf)).exist?)\n      describe ini(custom_conf) do\n        its('daemon.AutomaticLoginEnable') { cmp false }\n      end\n    else\n      describe f do\n        it { should exist }\n      end\n    end\n  else\n    describe \"The system does not have GDM installed\" do\n      skip \"The system does not have GDM installed, this requirement is Not Applicable.\"\n    end \n  end\nend\n",
          "source_location": {
            "line": 6,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71953.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "INI /etc/gdm/custom.conf daemon.AutomaticLoginEnable ",
              "run_time": 9.365e-05,
              "start_time": "2019-11-04T16:17:07-05:00"
            }
          ]
        },
        {
          "id": "V-71955",
          "title": "The operating system must not allow an unrestricted logon to the\nsystem.",
          "desc": "Failure to restrict system access to authenticated users negatively\nimpacts operating system security.",
          "descriptions": [
            {
              "label": "default",
              "data": "Failure to restrict system access to authenticated users negatively\nimpacts operating system security."
            },
            {
              "label": "check",
              "data": "Verify the operating system does not allow an unrestricted\nlogon to the system via a graphical user interface.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nCheck for the value of the \"TimedLoginEnable\" parameter in\n\"/etc/gdm/custom.conf\" file with the following command:\n\n# grep -i timedloginenable /etc/gdm/custom.conf\nTimedLoginEnable=false\n\nIf the value of \"TimedLoginEnable\" is not set to \"false\", this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to not allow an unrestricted\naccount to log on to the system via a graphical user interface.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nAdd or edit the line for the \"TimedLoginEnable\" parameter in the [daemon]\nsection of the \"/etc/gdm/custom.conf\" file to \"false\":\n\n[daemon]\nTimedLoginEnable=false"
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00229",
            "gid": "V-71955",
            "rid": "SV-86579r2_rule",
            "stig_id": "RHEL-07-010450",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "gdm"
            ],
            "fix_id": "F-78307r2_fix"
          },
          "code": "control \"V-71955\" do\n  title \"The operating system must not allow an unrestricted logon to the\nsystem.\"\n  desc  \"Failure to restrict system access to authenticated users negatively\nimpacts operating system security.\"\nif package('gdm').installed?\n  impact 0.7\nelse\n  impact 0.0\nend\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00229\"\n  tag \"gid\": \"V-71955\"\n  tag \"rid\": \"SV-86579r2_rule\"\n  tag \"stig_id\": \"RHEL-07-010450\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": [\"gdm\"]\n  desc \"check\", \"Verify the operating system does not allow an unrestricted\nlogon to the system via a graphical user interface.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nCheck for the value of the \\\"TimedLoginEnable\\\" parameter in\n\\\"/etc/gdm/custom.conf\\\" file with the following command:\n\n# grep -i timedloginenable /etc/gdm/custom.conf\nTimedLoginEnable=false\n\nIf the value of \\\"TimedLoginEnable\\\" is not set to \\\"false\\\", this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to not allow an unrestricted\naccount to log on to the system via a graphical user interface.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nAdd or edit the line for the \\\"TimedLoginEnable\\\" parameter in the [daemon]\nsection of the \\\"/etc/gdm/custom.conf\\\" file to \\\"false\\\":\n\n[daemon]\nTimedLoginEnable=false\"\n  tag \"fix_id\": \"F-78307r2_fix\"\n\n  custom_conf = '/etc/gdm/custom.conf'\n\n  if package('gdm').installed?\n    if ((f = file(custom_conf)).exist?)\n      describe ini(custom_conf) do\n        its('daemon.TimedLoginEnable') { cmp false }\n      end\n    else\n      describe f do\n        it { should exist }\n      end\n    end\n  else\n    describe \"The system does not have GDM installed\" do\n      skip \"The system does not have GDM installed, this requirement is Not Applicable.\"\n    end\n  end\nend\n",
          "source_location": {
            "line": 6,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71955.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "INI /etc/gdm/custom.conf daemon.TimedLoginEnable ",
              "run_time": 9.0531e-05,
              "start_time": "2019-11-04T16:17:07-05:00"
            }
          ]
        },
        {
          "id": "V-71957",
          "title": "The operating system must not allow users to override SSH environment\nvariables.",
          "desc": "Failure to restrict system access to authenticated users negatively\nimpacts operating system security.",
          "descriptions": [
            {
              "label": "default",
              "data": "Failure to restrict system access to authenticated users negatively\nimpacts operating system security."
            },
            {
              "label": "check",
              "data": "Verify the operating system does not allow users to override\nenvironment variables to the SSH daemon.\n\nCheck for the value of the \"PermitUserEnvironment\" keyword with the following\ncommand:\n\n# grep -i permituserenvironment /etc/ssh/sshd_config\nPermitUserEnvironment no\n\nIf the \"PermitUserEnvironment\" keyword is not set to \"no\", is missing, or\nis commented out, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to not allow users to override\nenvironment variables to the SSH daemon.\n\nEdit the \"/etc/ssh/sshd_config\" file to uncomment or add the line for\n\"PermitUserEnvironment\" keyword and set the value to \"no\":\n\nPermitUserEnvironment no\n\nThe SSH service must be restarted for changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00229",
            "gid": "V-71957",
            "rid": "SV-86581r2_rule",
            "stig_id": "RHEL-07-010460",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78309r2_fix"
          },
          "code": "control \"V-71957\" do\n  title \"The operating system must not allow users to override SSH environment\nvariables.\"\n  desc  \"Failure to restrict system access to authenticated users negatively\nimpacts operating system security.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00229\"\n  tag \"gid\": \"V-71957\"\n  tag \"rid\": \"SV-86581r2_rule\"\n  tag \"stig_id\": \"RHEL-07-010460\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": [\"ssh\"]\n  desc \"check\", \"Verify the operating system does not allow users to override\nenvironment variables to the SSH daemon.\n\nCheck for the value of the \\\"PermitUserEnvironment\\\" keyword with the following\ncommand:\n\n# grep -i permituserenvironment /etc/ssh/sshd_config\nPermitUserEnvironment no\n\nIf the \\\"PermitUserEnvironment\\\" keyword is not set to \\\"no\\\", is missing, or\nis commented out, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to not allow users to override\nenvironment variables to the SSH daemon.\n\nEdit the \\\"/etc/ssh/sshd_config\\\" file to uncomment or add the line for\n\\\"PermitUserEnvironment\\\" keyword and set the value to \\\"no\\\":\n\nPermitUserEnvironment no\n\nThe SSH service must be restarted for changes to take effect.\"\n  tag \"fix_id\": \"F-78309r2_fix\"\n  # the `i` will ignore case\n  describe sshd_config do\n    its('PermitUserEnvironment') { should eq 'no' }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71957.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "SSHD Configuration PermitUserEnvironment should eq \"no\"",
              "run_time": 0.000522463,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "\nexpected: \"no\"\n     got: nil\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-71959",
          "title": "The operating system must not allow a non-certificate trusted host SSH\nlogon to the system.",
          "desc": "Failure to restrict system access to authenticated users negatively\nimpacts operating system security.",
          "descriptions": [
            {
              "label": "default",
              "data": "Failure to restrict system access to authenticated users negatively\nimpacts operating system security."
            },
            {
              "label": "check",
              "data": "Verify the operating system does not allow a non-certificate\ntrusted host SSH logon to the system.\n\nCheck for the value of the \"HostbasedAuthentication\" keyword with the\nfollowing command:\n\n# grep -i hostbasedauthentication /etc/ssh/sshd_config\nHostbasedAuthentication no\n\nIf the \"HostbasedAuthentication\" keyword is not set to \"no\", is missing, or\nis commented out, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to not allow a non-certificate\ntrusted host SSH logon to the system.\n\nEdit the \"/etc/ssh/sshd_config\" file to uncomment or add the line for\n\"HostbasedAuthentication\" keyword and set the value to \"no\":\n\nHostbasedAuthentication no\n\nThe SSH service must be restarted for changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00229",
            "gid": "V-71959",
            "rid": "SV-86583r2_rule",
            "stig_id": "RHEL-07-010470",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78311r3_fix"
          },
          "code": "control \"V-71959\" do\n  title \"The operating system must not allow a non-certificate trusted host SSH\nlogon to the system.\"\n  desc  \"Failure to restrict system access to authenticated users negatively\nimpacts operating system security.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00229\"\n  tag \"gid\": \"V-71959\"\n  tag \"rid\": \"SV-86583r2_rule\"\n  tag \"stig_id\": \"RHEL-07-010470\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": [\"ssh\"]\n  desc \"check\", \"Verify the operating system does not allow a non-certificate\ntrusted host SSH logon to the system.\n\nCheck for the value of the \\\"HostbasedAuthentication\\\" keyword with the\nfollowing command:\n\n# grep -i hostbasedauthentication /etc/ssh/sshd_config\nHostbasedAuthentication no\n\nIf the \\\"HostbasedAuthentication\\\" keyword is not set to \\\"no\\\", is missing, or\nis commented out, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to not allow a non-certificate\ntrusted host SSH logon to the system.\n\nEdit the \\\"/etc/ssh/sshd_config\\\" file to uncomment or add the line for\n\\\"HostbasedAuthentication\\\" keyword and set the value to \\\"no\\\":\n\nHostbasedAuthentication no\n\nThe SSH service must be restarted for changes to take effect.\"\n  tag \"fix_id\": \"F-78311r3_fix\"\n  describe sshd_config do\n    its('HostbasedAuthentication') { should eq 'no' }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71959.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "SSHD Configuration HostbasedAuthentication should eq \"no\"",
              "run_time": 0.000531938,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "\nexpected: \"no\"\n     got: nil\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-71961",
          "title": "Systems with a Basic Input/Output System (BIOS) must require\nauthentication upon booting into single-user and maintenance modes.",
          "desc": "If the system does not require valid root authentication before it\nboots into single-user or maintenance mode, anyone who invokes single-user or\nmaintenance mode is granted privileged access to all files on the system. GRUB\n2 is the default boot loader for RHEL 7 and is designed to require a password\nto boot into single-user mode or make modifications to the boot menu.",
          "descriptions": [
            {
              "label": "default",
              "data": "If the system does not require valid root authentication before it\nboots into single-user or maintenance mode, anyone who invokes single-user or\nmaintenance mode is granted privileged access to all files on the system. GRUB\n2 is the default boot loader for RHEL 7 and is designed to require a password\nto boot into single-user mode or make modifications to the boot menu."
            },
            {
              "label": "check",
              "data": "For systems that use UEFI, this is Not Applicable.\n\nCheck to see if an encrypted root password is set. On systems that use a BIOS,\nuse the following command:\n\n# grep -i ^password_pbkdf2 /boot/grub2/grub.cfg\n\npassword_pbkdf2 [superusers-account] [password-hash]\n\nIf the root password entry does not begin with \"password_pbkdf2\", this is a\nfinding.\n\nIf the \"superusers-account\" is not set to \"root\", this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the system to encrypt the boot password for root.\n\nGenerate an encrypted grub2 password for root with the following command:\n\nNote: The hash generated is an example.\n\n# grub2-mkpasswd-pbkdf2\n\nEnter Password:\nReenter Password:\nPBKDF2 hash of your password is\ngrub.pbkdf2.sha512.10000.F3A7CFAA5A51EED123BE8238C23B25B2A6909AFC9812F0D45\n\nEdit \"/etc/grub.d/40_custom\" and add the following lines below the comments:\n\n# vi /etc/grub.d/40_custom\n\nset superusers=\"root\"\n\npassword_pbkdf2 root {hash from grub2-mkpasswd-pbkdf2 command}\n\nGenerate a new \"grub.conf\" file with the new password with the following\ncommands:\n\n# grub2-mkconfig --output=/tmp/grub2.cfg\n# mv /tmp/grub2.cfg /boot/grub2/grub.cfg"
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000080-GPOS-00048",
            "gid": "V-71961",
            "rid": "SV-86585r4_rule",
            "stig_id": "RHEL-07-010480",
            "cci": [
              "CCI-000213"
            ],
            "documentable": false,
            "nist": [
              "AC-3",
              "Rev_4"
            ],
            "subsystems": [
              "grub"
            ],
            "fix_id": "F-78313r2_fix"
          },
          "code": "control \"V-71961\" do\n  title \"Systems with a Basic Input/Output System (BIOS) must require\nauthentication upon booting into single-user and maintenance modes.\"\n  desc  \"If the system does not require valid root authentication before it\nboots into single-user or maintenance mode, anyone who invokes single-user or\nmaintenance mode is granted privileged access to all files on the system. GRUB\n2 is the default boot loader for RHEL 7 and is designed to require a password\nto boot into single-user mode or make modifications to the boot menu.\"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000080-GPOS-00048\"\n  tag \"gid\": \"V-71961\"\n  tag \"rid\": \"SV-86585r4_rule\"\n  tag \"stig_id\": \"RHEL-07-010480\"\n  tag \"cci\": [\"CCI-000213\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-3\", \"Rev_4\"]\n  tag \"subsystems\": ['grub']\n  desc \"check\", \"For systems that use UEFI, this is Not Applicable.\n\nCheck to see if an encrypted root password is set. On systems that use a BIOS,\nuse the following command:\n\n# grep -i ^password_pbkdf2 /boot/grub2/grub.cfg\n\npassword_pbkdf2 [superusers-account] [password-hash]\n\nIf the root password entry does not begin with \\\"password_pbkdf2\\\", this is a\nfinding.\n\nIf the \\\"superusers-account\\\" is not set to \\\"root\\\", this is a finding.\"\n  desc \"fix\", \"Configure the system to encrypt the boot password for root.\n\nGenerate an encrypted grub2 password for root with the following command:\n\nNote: The hash generated is an example.\n\n# grub2-mkpasswd-pbkdf2\n\nEnter Password:\nReenter Password:\nPBKDF2 hash of your password is\ngrub.pbkdf2.sha512.10000.F3A7CFAA5A51EED123BE8238C23B25B2A6909AFC9812F0D45\n\nEdit \\\"/etc/grub.d/40_custom\\\" and add the following lines below the comments:\n\n# vi /etc/grub.d/40_custom\n\nset superusers=\\\"root\\\"\n\npassword_pbkdf2 root {hash from grub2-mkpasswd-pbkdf2 command}\n\nGenerate a new \\\"grub.conf\\\" file with the new password with the following\ncommands:\n\n# grub2-mkconfig --output=/tmp/grub2.cfg\n# mv /tmp/grub2.cfg /boot/grub2/grub.cfg\n\"\n  tag \"fix_id\": \"F-78313r2_fix\"\n  describe file(grub_main_cfg) do\n    its('content') { should match %r{^\\s*password_pbkdf2\\s+root } }\n  end\n\n  grub_user_boot_files.each do |user_cfg_file|\n    next if !file(user_cfg_file).exist?\n    describe.one do\n      grub_superusers.each do |user|\n        describe file(user_cfg_file) do\n          its('content') { should match %r{^\\s*password_pbkdf2\\s+#{user} } }\n        end\n      end\n    end\n  end\nend\n",
          "source_location": {
            "line": 20,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71961.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "File /boot/grub2/grub.cfg content should match /^\\s*password_pbkdf2\\s+root /",
              "run_time": 0.000430113,
              "start_time": "2019-11-04T16:17:07-05:00"
            }
          ]
        },
        {
          "id": "V-71963",
          "title": "Systems using Unified Extensible Firmware Interface (UEFI) must\nrequire authentication upon booting into single-user and maintenance modes.",
          "desc": "If the system does not require valid root authentication before it\nboots into single-user or maintenance mode, anyone who invokes single-user or\nmaintenance mode is granted privileged access to all files on the system. GRUB\n2 is the default boot loader for RHEL 7 and is designed to require a password\nto boot into single-user mode or make modifications to the boot menu.",
          "descriptions": [
            {
              "label": "default",
              "data": "If the system does not require valid root authentication before it\nboots into single-user or maintenance mode, anyone who invokes single-user or\nmaintenance mode is granted privileged access to all files on the system. GRUB\n2 is the default boot loader for RHEL 7 and is designed to require a password\nto boot into single-user mode or make modifications to the boot menu."
            },
            {
              "label": "check",
              "data": "For systems that use BIOS, this is Not Applicable.\n\nCheck to see if an encrypted root password is set. On systems that use UEFI,\nuse the following command:\n\n# grep -i password /boot/efi/EFI/redhat/grub.cfg\n\npassword_pbkdf2 [superusers-account] [password-hash]\n\nIf the root password entry does not begin with \"password_pbkdf2\", this is a\nfinding.\n\nIf the \"superusers-account\" is not set to \"root\", this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the system to encrypt the boot password for root.\n\nGenerate an encrypted grub2 password for root with the following command:\n\nNote: The hash generated is an example.\n\n# grub2-mkpasswd-pbkdf2\n\nEnter Password:\nReenter Password:\nPBKDF2 hash of your password is\ngrub.pbkdf2.sha512.10000.F3A7CFAA5A51EED123BE8238C23B25B2A6909AFC9812F0D45\n\nEdit \"/etc/grub.d/40_custom\" and add the following lines below the comments:\n\n# vi /etc/grub.d/40_custom\n\nset superusers=\"root\"\n\npassword_pbkdf2 root {hash from grub2-mkpasswd-pbkdf2 command}\n\nGenerate a new \"grub.conf\" file with the new password with the following\ncommands:\n\n# grub2-mkconfig --output=/tmp/grub2.cfg\n# mv /tmp/grub2.cfg /boot/efi/EFI/redhat/grub.cfg"
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000080-GPOS-00048",
            "gid": "V-71963",
            "rid": "SV-86587r3_rule",
            "stig_id": "RHEL-07-010490",
            "cci": [
              "CCI-000213"
            ],
            "documentable": false,
            "nist": [
              "AC-3",
              "Rev_4"
            ],
            "subsystems": [
              "grub"
            ],
            "fix_id": "F-78315r2_fix"
          },
          "code": "control \"V-71963\" do\n  title \"Systems using Unified Extensible Firmware Interface (UEFI) must\nrequire authentication upon booting into single-user and maintenance modes.\"\n  desc  \"If the system does not require valid root authentication before it\nboots into single-user or maintenance mode, anyone who invokes single-user or\nmaintenance mode is granted privileged access to all files on the system. GRUB\n2 is the default boot loader for RHEL 7 and is designed to require a password\nto boot into single-user mode or make modifications to the boot menu.\"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000080-GPOS-00048\"\n  tag \"gid\": \"V-71963\"\n  tag \"rid\": \"SV-86587r3_rule\"\n  tag \"stig_id\": \"RHEL-07-010490\"\n  tag \"cci\": [\"CCI-000213\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-3\", \"Rev_4\"]\n  tag \"subsystems\": ['grub']\n  desc \"check\", \"For systems that use BIOS, this is Not Applicable.\n\nCheck to see if an encrypted root password is set. On systems that use UEFI,\nuse the following command:\n\n# grep -i password /boot/efi/EFI/redhat/grub.cfg\n\npassword_pbkdf2 [superusers-account] [password-hash]\n\nIf the root password entry does not begin with \\\"password_pbkdf2\\\", this is a\nfinding.\n\nIf the \\\"superusers-account\\\" is not set to \\\"root\\\", this is a finding.\"\n  desc \"fix\", \"Configure the system to encrypt the boot password for root.\n\nGenerate an encrypted grub2 password for root with the following command:\n\nNote: The hash generated is an example.\n\n# grub2-mkpasswd-pbkdf2\n\nEnter Password:\nReenter Password:\nPBKDF2 hash of your password is\ngrub.pbkdf2.sha512.10000.F3A7CFAA5A51EED123BE8238C23B25B2A6909AFC9812F0D45\n\nEdit \\\"/etc/grub.d/40_custom\\\" and add the following lines below the comments:\n\n# vi /etc/grub.d/40_custom\n\nset superusers=\\\"root\\\"\n\npassword_pbkdf2 root {hash from grub2-mkpasswd-pbkdf2 command}\n\nGenerate a new \\\"grub.conf\\\" file with the new password with the following\ncommands:\n\n# grub2-mkconfig --output=/tmp/grub2.cfg\n# mv /tmp/grub2.cfg /boot/efi/EFI/redhat/grub.cfg\n\"\n  tag \"fix_id\": \"F-78315r2_fix\"\n  describe file(efi_main_cfg) do\n    its('content') { should match %r{^\\s*password_pbkdf2\\s+root } }\n  end\n\n  efi_user_boot_files.each do |user_cfg_file|\n    next if !file(user_cfg_file).exist?\n    describe.one do\n      efi_superusers.each do |user|\n        describe file(user_cfg_file) do\n          its('content') { should match %r{^\\s*password_pbkdf2\\s+#{user} } }\n        end\n      end\n    end\n  end\nend\n",
          "source_location": {
            "line": 20,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71963.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "File /boot/efi/EFI/redhat/grub.cfg content should match /^\\s*password_pbkdf2\\s+root /",
              "run_time": 0.000160855,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "expected nil to match /^\\s*password_pbkdf2\\s+root /"
            }
          ]
        },
        {
          "id": "V-71965",
          "title": "The operating system must uniquely identify and must authenticate\norganizational users (or processes acting on behalf of organizational users)\nusing multifactor authentication.",
          "desc": "To assure accountability and prevent unauthenticated access, organizational\nusers must be identified and authenticated to prevent potential misuse and\ncompromise of the system.\n\n    Organizational users include organizational employees or individuals the\norganization deems to have equivalent status of employees (e.g., contractors).\nOrganizational users (and processes acting on behalf of users) must be uniquely\nidentified and authenticated to all accesses, except for the following:\n\n    1) Accesses explicitly identified and documented by the organization.\nOrganizations document specific user actions that can be performed on the\ninformation system without identification or authentication;\n\n    and\n\n    2) Accesses that occur through authorized use of group authenticators\nwithout individual authentication. Organizations may require unique\nidentification of individuals in group accounts (e.g., shared privilege\naccounts) or for detailed accountability of individual activity.",
          "descriptions": [
            {
              "label": "default",
              "data": "To assure accountability and prevent unauthenticated access, organizational\nusers must be identified and authenticated to prevent potential misuse and\ncompromise of the system.\n\n    Organizational users include organizational employees or individuals the\norganization deems to have equivalent status of employees (e.g., contractors).\nOrganizational users (and processes acting on behalf of users) must be uniquely\nidentified and authenticated to all accesses, except for the following:\n\n    1) Accesses explicitly identified and documented by the organization.\nOrganizations document specific user actions that can be performed on the\ninformation system without identification or authentication;\n\n    and\n\n    2) Accesses that occur through authorized use of group authenticators\nwithout individual authentication. Organizations may require unique\nidentification of individuals in group accounts (e.g., shared privilege\naccounts) or for detailed accountability of individual activity."
            },
            {
              "label": "check",
              "data": "Verify the operating system requires multifactor authentication\nto uniquely identify organizational users using multifactor authentication.\n\nCheck to see if smartcard authentication is enforced on the system:\n\n# authconfig --test | grep -i smartcard\n\nThe entry for use only smartcard for logon may be enabled, and the smartcard\nmodule and smartcard removal actions must not be blank.\n\nIf smartcard authentication is disabled or the smartcard and smartcard removal\nactions are blank, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to require individuals to be\nauthenticated with a multifactor authenticator.\n\nEnable smartcard logons with the following commands:\n\n# authconfig --enablesmartcard --smartcardaction=1 --update\n# authconfig --enablerequiresmartcard -update\n\nModify the \"/etc/pam_pkcs11/pkcs11_eventmgr.conf\" file to uncomment the\nfollowing line:\n\n#/usr/X11R6/bin/xscreensaver-command -lock\n\nModify the \"/etc/pam_pkcs11/pam_pkcs11.conf\" file to use the cackey module if\nrequired."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000104-GPOS-00051",
            "satisfies": [
              "SRG-OS-000104-GPOS-00051",
              "SRG-OS-000106-GPOS-00053",
              "SRG-OS-000107-GPOS-00054",
              "SRG-OS-000109-GPOS-00056",
              "SRG-OS-000108-GPOS-00055",
              "SRG-OS-000108-GPOS-00057",
              "SRG-OS-000108-GPOS-00058"
            ],
            "gid": "V-71965",
            "rid": "SV-86589r1_rule",
            "stig_id": "RHEL-07-010500",
            "cci": [
              "CCI-000766"
            ],
            "documentable": false,
            "nist": [
              "IA-2 (2)",
              "Rev_4"
            ],
            "subsystems": [
              "pam",
              "smartcard"
            ],
            "fix_id": "F-78317r1_fix"
          },
          "code": "control \"V-71965\" do\n  title \"The operating system must uniquely identify and must authenticate\norganizational users (or processes acting on behalf of organizational users)\nusing multifactor authentication.\"\n  desc  \"\n    To assure accountability and prevent unauthenticated access, organizational\nusers must be identified and authenticated to prevent potential misuse and\ncompromise of the system.\n\n    Organizational users include organizational employees or individuals the\norganization deems to have equivalent status of employees (e.g., contractors).\nOrganizational users (and processes acting on behalf of users) must be uniquely\nidentified and authenticated to all accesses, except for the following:\n\n    1) Accesses explicitly identified and documented by the organization.\nOrganizations document specific user actions that can be performed on the\ninformation system without identification or authentication;\n\n    and\n\n    2) Accesses that occur through authorized use of group authenticators\nwithout individual authentication. Organizations may require unique\nidentification of individuals in group accounts (e.g., shared privilege\naccounts) or for detailed accountability of individual activity.\n  \"\n  if smart_card_status.eql?('enabled')\n  impact 0.5\n  else\n    impact 0.0\n  end\n  tag \"gtitle\": \"SRG-OS-000104-GPOS-00051\"\n  tag \"satisfies\": [\"SRG-OS-000104-GPOS-00051\", \"SRG-OS-000106-GPOS-00053\",\n\"SRG-OS-000107-GPOS-00054\", \"SRG-OS-000109-GPOS-00056\",\n\"SRG-OS-000108-GPOS-00055\", \"SRG-OS-000108-GPOS-00057\",\n\"SRG-OS-000108-GPOS-00058\"]\n  tag \"gid\": \"V-71965\"\n  tag \"rid\": \"SV-86589r1_rule\"\n  tag \"stig_id\": \"RHEL-07-010500\"\n  tag \"cci\": [\"CCI-000766\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-2 (2)\", \"Rev_4\"]\n  tag \"subsystems\": ['pam', 'smartcard']\n  desc \"check\", \"Verify the operating system requires multifactor authentication\nto uniquely identify organizational users using multifactor authentication.\n\nCheck to see if smartcard authentication is enforced on the system:\n\n# authconfig --test | grep -i smartcard\n\nThe entry for use only smartcard for logon may be enabled, and the smartcard\nmodule and smartcard removal actions must not be blank.\n\nIf smartcard authentication is disabled or the smartcard and smartcard removal\nactions are blank, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to require individuals to be\nauthenticated with a multifactor authenticator.\n\nEnable smartcard logons with the following commands:\n\n# authconfig --enablesmartcard --smartcardaction=1 --update\n# authconfig --enablerequiresmartcard -update\n\nModify the \\\"/etc/pam_pkcs11/pkcs11_eventmgr.conf\\\" file to uncomment the\nfollowing line:\n\n#/usr/X11R6/bin/xscreensaver-command -lock\n\nModify the \\\"/etc/pam_pkcs11/pam_pkcs11.conf\\\" file to use the cackey module if\nrequired.\"\n  tag \"fix_id\": \"F-78317r1_fix\"\n  describe command(\"authconfig --test | grep -i smartcard\") do\n    its('stdout') { should match %r{use\\sonly\\ssmartcard\\sfor\\slogin\\sis\\s#{smart_card_status}} }\n    its('stdout') { should match %r{smartcard\\smodule\\s=\\s\".+\"} }\n    its('stdout') { should match %r{smartcard\\sremoval\\saction\\s=\\s\".+\"} }\n  end if smart_card_status.eql?('enabled')\n\n  describe \"The system is not smartcard enabled\" do\n    skip \"The system is not using Smartcards / PIVs to fulfil the MFA requirement, this control is Not Applicable.\"\n  end if !smart_card_status.eql?('enabled')\nend\n",
          "source_location": {
            "line": 17,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71965.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Command: `authconfig --test | grep -i smartcard` stdout should match /use\\sonly\\ssmartcard\\sfor\\slogin\\sis\\senabled/",
              "run_time": 0.099987618,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "expected \"SSSD smartcard support is disabled\\n use only smartcard for login is disabled\\n smartcard module = \\\"\\\"\\n smartcard removal action = \\\"\\\"\\n\" to match /use\\sonly\\ssmartcard\\sfor\\slogin\\sis\\senabled/\nDiff:\n@@ -1,2 +1,5 @@\n-/use\\sonly\\ssmartcard\\sfor\\slogin\\sis\\senabled/\n+SSSD smartcard support is disabled\n+ use only smartcard for login is disabled\n+ smartcard module = \"\"\n+ smartcard removal action = \"\"\n"
            },
            {
              "status": "failed",
              "code_desc": "Command: `authconfig --test | grep -i smartcard` stdout should match /smartcard\\smodule\\s=\\s\".+\"/",
              "run_time": 0.000246755,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "expected \"SSSD smartcard support is disabled\\n use only smartcard for login is disabled\\n smartcard module = \\\"\\\"\\n smartcard removal action = \\\"\\\"\\n\" to match /smartcard\\smodule\\s=\\s\".+\"/\nDiff:\n@@ -1,2 +1,5 @@\n-/smartcard\\smodule\\s=\\s\".+\"/\n+SSSD smartcard support is disabled\n+ use only smartcard for login is disabled\n+ smartcard module = \"\"\n+ smartcard removal action = \"\"\n"
            },
            {
              "status": "failed",
              "code_desc": "Command: `authconfig --test | grep -i smartcard` stdout should match /smartcard\\sremoval\\saction\\s=\\s\".+\"/",
              "run_time": 0.000211145,
              "start_time": "2019-11-04T16:17:07-05:00",
              "message": "expected \"SSSD smartcard support is disabled\\n use only smartcard for login is disabled\\n smartcard module = \\\"\\\"\\n smartcard removal action = \\\"\\\"\\n\" to match /smartcard\\sremoval\\saction\\s=\\s\".+\"/\nDiff:\n@@ -1,2 +1,5 @@\n-/smartcard\\sremoval\\saction\\s=\\s\".+\"/\n+SSSD smartcard support is disabled\n+ use only smartcard for login is disabled\n+ smartcard module = \"\"\n+ smartcard removal action = \"\"\n"
            }
          ]
        },
        {
          "id": "V-71967",
          "title": "The rsh-server package must not be installed.",
          "desc": "It is detrimental for operating systems to provide, or install by default,\nfunctionality exceeding requirements or mission objectives. These unnecessary\ncapabilities or services are often overlooked and therefore may remain\nunsecured. They increase the risk to the platform by providing additional\nattack vectors.\n\n    Operating systems are capable of providing a wide variety of functions and\nservices. Some of the functions and services, provided by default, may not be\nnecessary to support essential organizational operations (e.g., key missions,\nfunctions).\n\n    The rsh-server service provides an unencrypted remote access service that\ndoes not provide for the confidentiality and integrity of user passwords or the\nremote session and has very weak authentication.\n\n    If a privileged user were to log on using this service, the privileged user\npassword could be compromised.",
          "descriptions": [
            {
              "label": "default",
              "data": "It is detrimental for operating systems to provide, or install by default,\nfunctionality exceeding requirements or mission objectives. These unnecessary\ncapabilities or services are often overlooked and therefore may remain\nunsecured. They increase the risk to the platform by providing additional\nattack vectors.\n\n    Operating systems are capable of providing a wide variety of functions and\nservices. Some of the functions and services, provided by default, may not be\nnecessary to support essential organizational operations (e.g., key missions,\nfunctions).\n\n    The rsh-server service provides an unencrypted remote access service that\ndoes not provide for the confidentiality and integrity of user passwords or the\nremote session and has very weak authentication.\n\n    If a privileged user were to log on using this service, the privileged user\npassword could be compromised."
            },
            {
              "label": "check",
              "data": "Check to see if the rsh-server package is installed with the\nfollowing command:\n\n# yum list installed rsh-server\n\nIf the rsh-server package is installed, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to disable non-essential\ncapabilities by removing the rsh-server package from the system with the\nfollowing command:\n\n# yum remove rsh-server"
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000095-GPOS-00049",
            "gid": "V-71967",
            "rid": "SV-86591r1_rule",
            "stig_id": "RHEL-07-020000",
            "cci": [
              "CCI-000381"
            ],
            "documentable": false,
            "nist": [
              "CM-7 a",
              "Rev_4"
            ],
            "subsystems": [
              "packages"
            ],
            "fix_id": "F-78319r1_fix"
          },
          "code": "control \"V-71967\" do\n  title \"The rsh-server package must not be installed.\"\n  desc  \"\n    It is detrimental for operating systems to provide, or install by default,\nfunctionality exceeding requirements or mission objectives. These unnecessary\ncapabilities or services are often overlooked and therefore may remain\nunsecured. They increase the risk to the platform by providing additional\nattack vectors.\n\n    Operating systems are capable of providing a wide variety of functions and\nservices. Some of the functions and services, provided by default, may not be\nnecessary to support essential organizational operations (e.g., key missions,\nfunctions).\n\n    The rsh-server service provides an unencrypted remote access service that\ndoes not provide for the confidentiality and integrity of user passwords or the\nremote session and has very weak authentication.\n\n    If a privileged user were to log on using this service, the privileged user\npassword could be compromised.\n  \"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000095-GPOS-00049\"\n  tag \"gid\": \"V-71967\"\n  tag \"rid\": \"SV-86591r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020000\"\n  tag \"cci\": [\"CCI-000381\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-7 a\", \"Rev_4\"]\n  tag \"subsystems\": ['packages']\n  desc \"check\", \"Check to see if the rsh-server package is installed with the\nfollowing command:\n\n# yum list installed rsh-server\n\nIf the rsh-server package is installed, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to disable non-essential\ncapabilities by removing the rsh-server package from the system with the\nfollowing command:\n\n# yum remove rsh-server\"\n  tag \"fix_id\": \"F-78319r1_fix\"\n  describe package(\"rsh-server\") do\n    it { should_not be_installed }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71967.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "System Package rsh-server should not be installed",
              "run_time": 0.036129475,
              "start_time": "2019-11-04T16:17:07-05:00"
            }
          ]
        },
        {
          "id": "V-71969",
          "title": "The ypserv package must not be installed.",
          "desc": "Removing the \"ypserv\" package decreases the risk of the accidental\n(or intentional) activation of NIS or NIS+ services.",
          "descriptions": [
            {
              "label": "default",
              "data": "Removing the \"ypserv\" package decreases the risk of the accidental\n(or intentional) activation of NIS or NIS+ services."
            },
            {
              "label": "check",
              "data": "The NIS service provides an unencrypted authentication service\nthat does not provide for the confidentiality and integrity of user passwords\nor the remote session.\n\nCheck to see if the \"ypserve\" package is installed with the following command:\n\n# yum list installed ypserv\n\nIf the \"ypserv\" package is installed, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to disable non-essential\ncapabilities by removing the \"ypserv\" package from the system with the\nfollowing command:\n\n# yum remove ypserv"
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000095-GPOS-00049",
            "gid": "V-71969",
            "rid": "SV-86593r1_rule",
            "stig_id": "RHEL-07-020010",
            "cci": [
              "CCI-000381"
            ],
            "documentable": false,
            "nist": [
              "CM-7 a",
              "Rev_4"
            ],
            "subsystems": [
              "packages"
            ],
            "fix_id": "F-78321r1_fix"
          },
          "code": "control \"V-71969\" do\n  title \"The ypserv package must not be installed.\"\n  desc  \"Removing the \\\"ypserv\\\" package decreases the risk of the accidental\n(or intentional) activation of NIS or NIS+ services.\"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000095-GPOS-00049\"\n  tag \"gid\": \"V-71969\"\n  tag \"rid\": \"SV-86593r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020010\"\n  tag \"cci\": [\"CCI-000381\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-7 a\", \"Rev_4\"]\n  tag \"subsystems\": ['packages']\n  desc \"check\", \"The NIS service provides an unencrypted authentication service\nthat does not provide for the confidentiality and integrity of user passwords\nor the remote session.\n\nCheck to see if the \\\"ypserve\\\" package is installed with the following command:\n\n# yum list installed ypserv\n\nIf the \\\"ypserv\\\" package is installed, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to disable non-essential\ncapabilities by removing the \\\"ypserv\\\" package from the system with the\nfollowing command:\n\n# yum remove ypserv\"\n  tag \"fix_id\": \"F-78321r1_fix\"\n  describe package(\"ypserv\") do\n    it { should_not be_installed }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71969.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "System Package ypserv should not be installed",
              "run_time": 0.036916941,
              "start_time": "2019-11-04T16:17:08-05:00"
            }
          ]
        },
        {
          "id": "V-71971",
          "title": "The operating system must prevent non-privileged users from executing\nprivileged functions to include disabling, circumventing, or altering\nimplemented security safeguards/countermeasures.",
          "desc": "Preventing non-privileged users from executing privileged functions\nmitigates the risk that unauthorized individuals or processes may gain\nunnecessary access to information or privileges.\n\n    Privileged functions include, for example, establishing accounts,\nperforming system integrity checks, or administering cryptographic key\nmanagement activities. Non-privileged users are individuals who do not possess\nappropriate authorizations. Circumventing intrusion detection and prevention\nmechanisms or malicious code protection mechanisms are examples of privileged\nfunctions that require protection from non-privileged users.",
          "descriptions": [
            {
              "label": "default",
              "data": "Preventing non-privileged users from executing privileged functions\nmitigates the risk that unauthorized individuals or processes may gain\nunnecessary access to information or privileges.\n\n    Privileged functions include, for example, establishing accounts,\nperforming system integrity checks, or administering cryptographic key\nmanagement activities. Non-privileged users are individuals who do not possess\nappropriate authorizations. Circumventing intrusion detection and prevention\nmechanisms or malicious code protection mechanisms are examples of privileged\nfunctions that require protection from non-privileged users."
            },
            {
              "label": "check",
              "data": "Verify the operating system prevents non-privileged users from\nexecuting privileged functions to include disabling, circumventing, or altering\nimplemented security safeguards/countermeasures.\n\nGet a list of authorized users (other than System Administrator and guest\naccounts) for the system.\n\nCheck the list against the system by using the following command:\n\n# semanage login -l | more\nLogin Name  SELinux User   MLS/MCS Range  Service\n__default__  user_u    s0-s0:c0.c1023   *\nroot   unconfined_u   s0-s0:c0.c1023   *\nsystem_u  system_u   s0-s0:c0.c1023   *\njoe  staff_u   s0-s0:c0.c1023   *\n\nAll administrators must be mapped to the \"sysadm_u\" or \"staff_u\" users with\nthe appropriate domains (sysadm_t and staff_t).\n\nAll authorized non-administrative users must be mapped to the \"user_u\" role\nor the appropriate domain (user_t).\n\nIf they are not mapped in this way, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to prevent non-privileged users\nfrom executing privileged functions to include disabling, circumventing, or\naltering implemented security safeguards/countermeasures.\n\nUse the following command to map a new user to the \"sysdam_u\" role:\n\n#semanage login -a -s sysadm_u <username>\n\nUse the following command to map an existing user to the \"sysdam_u\" role:\n\n#semanage login -m -s sysadm_u <username>\n\nUse the following command to map a new user to the \"staff_u\" role:\n\n#semanage login -a -s staff_u <username>\n\nUse the following command to map an existing user to the \"staff_u\" role:\n\n#semanage login -m -s staff_u <username>\n\nUse the following command to map a new user to the \"user_u\" role:\n\n# semanage login -a -s user_u <username>\n\nUse the following command to map an existing user to the \"user_u\" role:\n\n# semanage login -m -s user_u <username>"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000324-GPOS-00125",
            "gid": "V-71971",
            "rid": "SV-86595r1_rule",
            "stig_id": "RHEL-07-020020",
            "cci": [
              "CCI-002165",
              "CCI-002235"
            ],
            "documentable": false,
            "nist": [
              "AC-3 (4)",
              "AC-6 (10)",
              "Rev_4"
            ],
            "subsystems": [
              "selinux"
            ],
            "fix_id": "F-78323r1_fix"
          },
          "code": "control \"V-71971\" do\n  title \"The operating system must prevent non-privileged users from executing\nprivileged functions to include disabling, circumventing, or altering\nimplemented security safeguards/countermeasures.\"\n  desc  \"\n    Preventing non-privileged users from executing privileged functions\nmitigates the risk that unauthorized individuals or processes may gain\nunnecessary access to information or privileges.\n\n    Privileged functions include, for example, establishing accounts,\nperforming system integrity checks, or administering cryptographic key\nmanagement activities. Non-privileged users are individuals who do not possess\nappropriate authorizations. Circumventing intrusion detection and prevention\nmechanisms or malicious code protection mechanisms are examples of privileged\nfunctions that require protection from non-privileged users.\n  \"\n  impact 0.5\n\n  tag \"gtitle\": \"SRG-OS-000324-GPOS-00125\"\n  tag \"gid\": \"V-71971\"\n  tag \"rid\": \"SV-86595r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020020\"\n  tag \"cci\": [\"CCI-002165\", \"CCI-002235\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-3 (4)\", \"AC-6 (10)\", \"Rev_4\"]\n  tag \"subsystems\": [\"selinux\"]\n  desc \"check\", \"Verify the operating system prevents non-privileged users from\nexecuting privileged functions to include disabling, circumventing, or altering\nimplemented security safeguards/countermeasures.\n\nGet a list of authorized users (other than System Administrator and guest\naccounts) for the system.\n\nCheck the list against the system by using the following command:\n\n# semanage login -l | more\nLogin Name  SELinux User   MLS/MCS Range  Service\n__default__  user_u    s0-s0:c0.c1023   *\nroot   unconfined_u   s0-s0:c0.c1023   *\nsystem_u  system_u   s0-s0:c0.c1023   *\njoe  staff_u   s0-s0:c0.c1023   *\n\nAll administrators must be mapped to the \\\"sysadm_u\\\" or \\\"staff_u\\\" users with\nthe appropriate domains (sysadm_t and staff_t).\n\nAll authorized non-administrative users must be mapped to the \\\"user_u\\\" role\nor the appropriate domain (user_t).\n\nIf they are not mapped in this way, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to prevent non-privileged users\nfrom executing privileged functions to include disabling, circumventing, or\naltering implemented security safeguards/countermeasures.\n\nUse the following command to map a new user to the \\\"sysdam_u\\\" role:\n\n#semanage login -a -s sysadm_u <username>\n\nUse the following command to map an existing user to the \\\"sysdam_u\\\" role:\n\n#semanage login -m -s sysadm_u <username>\n\nUse the following command to map a new user to the \\\"staff_u\\\" role:\n\n#semanage login -a -s staff_u <username>\n\nUse the following command to map an existing user to the \\\"staff_u\\\" role:\n\n#semanage login -m -s staff_u <username>\n\nUse the following command to map a new user to the \\\"user_u\\\" role:\n\n# semanage login -a -s user_u <username>\n\nUse the following command to map an existing user to the \\\"user_u\\\" role:\n\n# semanage login -m -s user_u <username>\"\n  tag \"fix_id\": \"F-78323r1_fix\"\n\n  describe command('selinuxenabled') do\n    its('exist?') { should be true }\n    its('exit_status') { should eq 0 }\n  end\n\n  describe command('semanage') do\n    its('exist?') { should be true }\n  end\n\n  semanage_results = command('semanage login -l -n')\n\n  describe semanage_results do\n    its('stdout.lines') { should_not be_empty }\n  end\n\n  semanage_results.stdout.lines.each do |result|\n    login, seuser = result.split(/\\s+/)\n\n    # Skip Blank Lines\n    next unless login\n\n    # Next if for some reason we still have header row\n    next if ( login == 'Login')\n\n    # Next if root\n    next if ( login == 'root')\n\n    describe \"SELinux login #{login}\" do\n      # This is required by the STIG\n      if login == '__default__'\n        let(:valid_users){[ 'user_u' ]}\n      elsif admin_logins.include?(login)\n        let(:valid_users){[\n          'sysadm_u',\n          'staff_u'\n        ]}\n      else\n        let(:valid_users){[\n          'user_u',\n          'guest_u',\n          'xguest_u'\n        ]}\n      end\n\n      it { expect(seuser).to be_in(valid_users) }\n    end\n  end\nend\n",
          "source_location": {
            "line": 12,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71971.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Command: `selinuxenabled` exist? should equal true",
              "run_time": 0.015290676,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "Command: `selinuxenabled` exit_status should eq 0",
              "run_time": 0.014144529,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "Command: `semanage` exist? should equal true",
              "run_time": 0.015101168,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "Command: `semanage login -l -n` stdout.lines should not be empty",
              "run_time": 0.000204601,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "failed",
              "code_desc": "SELinux login __default__ should be in \"user_u\"",
              "run_time": 0.000197288,
              "start_time": "2019-11-04T16:17:08-05:00",
              "message": "expected `unconfined_u` to be in the list: `[\"user_u\"]`"
            },
            {
              "status": "failed",
              "code_desc": "SELinux login system_u should be in \"user_u\", \"guest_u\", and \"xguest_u\"",
              "run_time": 0.000142643,
              "start_time": "2019-11-04T16:17:08-05:00",
              "message": "expected `system_u` to be in the list: `[\"user_u\", \"guest_u\", \"xguest_u\"]`"
            }
          ]
        },
        {
          "id": "V-71973",
          "title": "A file integrity tool must verify the baseline operating system\nconfiguration at least weekly.",
          "desc": "Unauthorized changes to the baseline configuration could make the system\nvulnerable to various attacks or allow unauthorized access to the operating\nsystem. Changes to operating system configurations can have unintended side\neffects, some of which may be relevant to security.\n\n    Detecting such changes and providing an automated response can help avoid\nunintended, negative consequences that could ultimately affect the security\nstate of the operating system. The operating system's Information Management\nOfficer (IMO)/Information System Security Officer (ISSO) and System\nAdministrators (SAs) must be notified via email and/or monitoring system trap\nwhen there is an unauthorized modification of a configuration item.",
          "descriptions": [
            {
              "label": "default",
              "data": "Unauthorized changes to the baseline configuration could make the system\nvulnerable to various attacks or allow unauthorized access to the operating\nsystem. Changes to operating system configurations can have unintended side\neffects, some of which may be relevant to security.\n\n    Detecting such changes and providing an automated response can help avoid\nunintended, negative consequences that could ultimately affect the security\nstate of the operating system. The operating system's Information Management\nOfficer (IMO)/Information System Security Officer (ISSO) and System\nAdministrators (SAs) must be notified via email and/or monitoring system trap\nwhen there is an unauthorized modification of a configuration item."
            },
            {
              "label": "check",
              "data": "Verify the operating system routinely checks the baseline\nconfiguration for unauthorized changes.\n\nNote: A file integrity tool other than Advanced Intrusion Detection Environment\n(AIDE) may be used, but the tool must be executed at least once per week.\n\nCheck to see if AIDE is installed on the system with the following command:\n\n# yum list installed aide\n\nIf AIDE is not installed, ask the SA how file integrity checks are performed on\nthe system.\n\nCheck for the presence of a cron job running daily or weekly on the system that\nexecutes AIDE daily to scan for changes to the system baseline. The command\nused in the example will use a daily occurrence.\n\nCheck the \"/etc/cron.daily\" subdirectory for a \"crontab\" file controlling\nthe execution of the file integrity application. For example, if AIDE is\ninstalled on the system, use the following command:\n\n# ls -al /etc/cron.* | grep aide\n-rwxr-xr-x  1 root root        29 Nov  22  2015 aide\n\nIf the file integrity application does not exist, or a \"crontab\" file does\nnot exist in the \"/etc/cron.daily\" or \"/etc/cron.weekly\" subdirectories,\nthis is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the file integrity tool to automatically run on the\nsystem at least weekly. The following example output is generic. It will set\ncron to run AIDE daily, but other file integrity tools may be used:\n\n# cat /etc/cron.daily/aide\n0 0 * * * /usr/sbin/aide --check | /bin/mail -s \"aide integrity check run for <system name>\" root@sysname.mil"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000363-GPOS-00150",
            "gid": "V-71973",
            "rid": "SV-86597r1_rule",
            "stig_id": "RHEL-07-020030",
            "cci": [
              "CCI-001744"
            ],
            "documentable": false,
            "nist": [
              "CM-3 (5)",
              "Rev_4"
            ],
            "subsystems": [
              "aide"
            ],
            "fix_id": "F-78325r1_fix"
          },
          "code": "control \"V-71973\" do\n  title \"A file integrity tool must verify the baseline operating system\nconfiguration at least weekly.\"\n  desc  \"\n    Unauthorized changes to the baseline configuration could make the system\nvulnerable to various attacks or allow unauthorized access to the operating\nsystem. Changes to operating system configurations can have unintended side\neffects, some of which may be relevant to security.\n\n    Detecting such changes and providing an automated response can help avoid\nunintended, negative consequences that could ultimately affect the security\nstate of the operating system. The operating system's Information Management\nOfficer (IMO)/Information System Security Officer (ISSO) and System\nAdministrators (SAs) must be notified via email and/or monitoring system trap\nwhen there is an unauthorized modification of a configuration item.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000363-GPOS-00150\"\n  tag \"gid\": \"V-71973\"\n  tag \"rid\": \"SV-86597r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020030\"\n  tag \"cci\": [\"CCI-001744\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-3 (5)\", \"Rev_4\"]\n  tag \"subsystems\": ['aide']\n  desc \"check\", \"Verify the operating system routinely checks the baseline\nconfiguration for unauthorized changes.\n\nNote: A file integrity tool other than Advanced Intrusion Detection Environment\n(AIDE) may be used, but the tool must be executed at least once per week.\n\nCheck to see if AIDE is installed on the system with the following command:\n\n# yum list installed aide\n\nIf AIDE is not installed, ask the SA how file integrity checks are performed on\nthe system.\n\nCheck for the presence of a cron job running daily or weekly on the system that\nexecutes AIDE daily to scan for changes to the system baseline. The command\nused in the example will use a daily occurrence.\n\nCheck the \\\"/etc/cron.daily\\\" subdirectory for a \\\"crontab\\\" file controlling\nthe execution of the file integrity application. For example, if AIDE is\ninstalled on the system, use the following command:\n\n# ls -al /etc/cron.* | grep aide\n-rwxr-xr-x  1 root root        29 Nov  22  2015 aide\n\nIf the file integrity application does not exist, or a \\\"crontab\\\" file does\nnot exist in the \\\"/etc/cron.daily\\\" or \\\"/etc/cron.weekly\\\" subdirectories,\nthis is a finding.\"\n  desc \"fix\", \"Configure the file integrity tool to automatically run on the\nsystem at least weekly. The following example output is generic. It will set\ncron to run AIDE daily, but other file integrity tools may be used:\n\n# cat /etc/cron.daily/aide\n0 0 * * * /usr/sbin/aide --check | /bin/mail -s \\\"aide integrity check run for <system name>\\\" root@sysname.mil\"\n  tag \"fix_id\": \"F-78325r1_fix\"\n\n  describe package(file_integrity_tool) do\n    it { should be_installed }\n  end\n\n  if file_integrity_interval == 'monthly'\n    describe.one do\n      describe file(\"/etc/cron.daily/#{file_integrity_tool}\") do\n        it { should exist }\n      end\n      describe file(\"/etc/cron.weekly/#{file_integrity_tool}\") do\n        it { should exist }\n      end\n      describe file(\"/etc/cron.monthly/#{file_integrity_tool}\") do\n        it { should exist }\n      end\n      if file(\"/etc/cron.d/#{file_integrity_tool}\").exist?\n        describe crontab(path: \"/etc/cron.d/#{file_integrity_tool}\") do\n          its('months') { should cmp '*' }\n          its('weekdays') { should cmp '*' }\n        end\n        describe crontab(path: \"/etc/cron.d/#{file_integrity_tool}\") do\n          its('days') { should cmp '*' }\n          its('months') { should cmp '*' }\n        end\n      end\n      describe crontab('root').where { command =~ %r{#{file_integrity_tool}} } do\n        its('months') { should cmp '*' }\n        its('weekdays') { should cmp '*' }\n      end\n      describe crontab('root').where { command =~ %r{#{file_integrity_tool}} } do\n        its('days') { should cmp '*' }\n        its('months') { should cmp '*' }\n      end\n    end\n  elsif file_integrity_interval == 'weekly'\n    describe.one do\n      describe file(\"/etc/cron.daily/#{file_integrity_tool}\") do\n        it { should exist }\n      end\n      describe file(\"/etc/cron.weekly/#{file_integrity_tool}\") do\n        it { should exist }\n      end\n      if file(\"/etc/cron.d/#{file_integrity_tool}\").exist?\n        describe crontab(path: \"/etc/cron.d/#{file_integrity_tool}\") do\n          its('days') { should cmp '*' }\n          its('months') { should cmp '*' }\n        end\n      end\n      describe crontab('root').where { command =~ %r{#{file_integrity_tool}} } do\n        its('days') { should cmp '*' }\n        its('months') { should cmp '*' }\n      end\n    end\n  elsif file_integrity_interval == 'daily'\n    describe.one do\n      describe file(\"/etc/cron.daily/#{file_integrity_tool}\") do\n        it { should exist }\n      end\n      if file(\"/etc/cron.d/#{file_integrity_tool}\").exist?\n        describe crontab(path: \"/etc/cron.d/#{file_integrity_tool}\") do\n          its('days') { should cmp '*' }\n          its('months') { should cmp '*' }\n          its('weekdays') { should cmp '*' }\n        end\n      end\n      describe crontab('root').where { command =~ %r{#{file_integrity_tool}} } do\n        its('days') { should cmp '*' }\n        its('months') { should cmp '*' }\n        its('weekdays') { should cmp '*' }\n      end\n    end\n  end\nend\n",
          "source_location": {
            "line": 9,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71973.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "System Package aide should be installed",
              "run_time": 0.03692639,
              "start_time": "2019-11-04T16:17:08-05:00",
              "message": "expected that `System Package aide` is installed"
            },
            {
              "status": "failed",
              "code_desc": "File /etc/cron.daily/aide should exist",
              "run_time": 0.000305108,
              "start_time": "2019-11-04T16:17:08-05:00",
              "message": "expected File /etc/cron.daily/aide to exist",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "File /etc/cron.weekly/aide should exist",
              "run_time": 0.000133578,
              "start_time": "2019-11-04T16:17:08-05:00",
              "message": "expected File /etc/cron.weekly/aide to exist",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "crontab for user root with command =~ /aide/ days should cmp == \"*\"",
              "run_time": 0.000209582,
              "start_time": "2019-11-04T16:17:08-05:00",
              "message": "\nexpected: \"*\"\n     got: []\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "crontab for user root with command =~ /aide/ months should cmp == \"*\"",
              "run_time": 0.00014389,
              "start_time": "2019-11-04T16:17:08-05:00",
              "message": "\nexpected: \"*\"\n     got: []\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            }
          ]
        },
        {
          "id": "V-71975",
          "title": "Designated personnel must be notified if baseline configurations are\nchanged in an unauthorized manner.",
          "desc": "Unauthorized changes to the baseline configuration could make the system\nvulnerable to various attacks or allow unauthorized access to the operating\nsystem. Changes to operating system configurations can have unintended side\neffects, some of which may be relevant to security.\n\n    Detecting such changes and providing an automated response can help avoid\nunintended, negative consequences that could ultimately affect the security\nstate of the operating system. The operating system's Information Management\nOfficer (IMO)/Information System Security Officer (ISSO) and System\nAdministrators (SAs) must be notified via email and/or monitoring system trap\nwhen there is an unauthorized modification of a configuration item.",
          "descriptions": [
            {
              "label": "default",
              "data": "Unauthorized changes to the baseline configuration could make the system\nvulnerable to various attacks or allow unauthorized access to the operating\nsystem. Changes to operating system configurations can have unintended side\neffects, some of which may be relevant to security.\n\n    Detecting such changes and providing an automated response can help avoid\nunintended, negative consequences that could ultimately affect the security\nstate of the operating system. The operating system's Information Management\nOfficer (IMO)/Information System Security Officer (ISSO) and System\nAdministrators (SAs) must be notified via email and/or monitoring system trap\nwhen there is an unauthorized modification of a configuration item."
            },
            {
              "label": "check",
              "data": "Verify the operating system notifies designated personnel if\nbaseline configurations are changed in an unauthorized manner.\n\nNote: A file integrity tool other than Advanced Intrusion Detection Environment\n(AIDE) may be used, but the tool must be executed and notify specified\nindividuals via email or an alert.\n\nCheck to see if AIDE is installed on the system with the following command:\n\n# yum list installed aide\n\nIf AIDE is not installed, ask the SA how file integrity checks are performed on\nthe system.\n\nCheck for the presence of a cron job running routinely on the system that\nexecutes AIDE to scan for changes to the system baseline. The commands used in\nthe example will use a daily occurrence.\n\nCheck the \"/etc/cron.daily\" subdirectory for a \"crontab\" file controlling\nthe execution of the file integrity application. For example, if AIDE is\ninstalled on the system, use the following commands:\n\n# ls -al /etc/cron.daily | grep aide\n-rwxr-xr-x  1 root root        32 Jul  1  2011 aide\n\nAIDE does not have a configuration that will send a notification, so the cron\njob uses the mail application on the system to email the results of the file\nintegrity run as in the following example:\n\n# more /etc/cron.daily/aide\n0 0 * * * /usr/sbin/aide --check | /bin/mail -s \"$HOSTNAME - Daily aide integrity check run\" root@sysname.mil\n\nIf the file integrity application does not notify designated personnel of\nchanges, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to notify designated personnel if\nbaseline configurations are changed in an unauthorized manner. The AIDE tool\ncan be configured to email designated personnel through the use of the cron\nsystem.\n\nThe following example output is generic. It will set cron to run AIDE daily and\nto send email at the completion of the analysis.\n\n# more /etc/cron.daily/aide\n0 0 * * * /usr/sbin/aide --check | /bin/mail -s \"$HOSTNAME - Daily aide integrity check run\" root@sysname.mil"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000363-GPOS-00150",
            "gid": "V-71975",
            "rid": "SV-86599r1_rule",
            "stig_id": "RHEL-07-020040",
            "cci": [
              "CCI-001744"
            ],
            "documentable": false,
            "nist": [
              "CM-3 (5)",
              "Rev_4"
            ],
            "subsystems": [
              "aide"
            ],
            "fix_id": "F-78327r1_fix"
          },
          "code": "control \"V-71975\" do\n  title \"Designated personnel must be notified if baseline configurations are\nchanged in an unauthorized manner.\"\n  desc  \"\n    Unauthorized changes to the baseline configuration could make the system\nvulnerable to various attacks or allow unauthorized access to the operating\nsystem. Changes to operating system configurations can have unintended side\neffects, some of which may be relevant to security.\n\n    Detecting such changes and providing an automated response can help avoid\nunintended, negative consequences that could ultimately affect the security\nstate of the operating system. The operating system's Information Management\nOfficer (IMO)/Information System Security Officer (ISSO) and System\nAdministrators (SAs) must be notified via email and/or monitoring system trap\nwhen there is an unauthorized modification of a configuration item.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000363-GPOS-00150\"\n  tag \"gid\": \"V-71975\"\n  tag \"rid\": \"SV-86599r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020040\"\n  tag \"cci\": [\"CCI-001744\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-3 (5)\", \"Rev_4\"]\n  tag \"subsystems\": ['aide']\n  desc \"check\", \"Verify the operating system notifies designated personnel if\nbaseline configurations are changed in an unauthorized manner.\n\nNote: A file integrity tool other than Advanced Intrusion Detection Environment\n(AIDE) may be used, but the tool must be executed and notify specified\nindividuals via email or an alert.\n\nCheck to see if AIDE is installed on the system with the following command:\n\n# yum list installed aide\n\nIf AIDE is not installed, ask the SA how file integrity checks are performed on\nthe system.\n\nCheck for the presence of a cron job running routinely on the system that\nexecutes AIDE to scan for changes to the system baseline. The commands used in\nthe example will use a daily occurrence.\n\nCheck the \\\"/etc/cron.daily\\\" subdirectory for a \\\"crontab\\\" file controlling\nthe execution of the file integrity application. For example, if AIDE is\ninstalled on the system, use the following commands:\n\n# ls -al /etc/cron.daily | grep aide\n-rwxr-xr-x  1 root root        32 Jul  1  2011 aide\n\nAIDE does not have a configuration that will send a notification, so the cron\njob uses the mail application on the system to email the results of the file\nintegrity run as in the following example:\n\n# more /etc/cron.daily/aide\n0 0 * * * /usr/sbin/aide --check | /bin/mail -s \\\"$HOSTNAME - Daily aide integrity check run\\\" root@sysname.mil\n\nIf the file integrity application does not notify designated personnel of\nchanges, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to notify designated personnel if\nbaseline configurations are changed in an unauthorized manner. The AIDE tool\ncan be configured to email designated personnel through the use of the cron\nsystem.\n\nThe following example output is generic. It will set cron to run AIDE daily and\nto send email at the completion of the analysis.\n\n# more /etc/cron.daily/aide\n0 0 * * * /usr/sbin/aide --check | /bin/mail -s \\\"$HOSTNAME - Daily aide integrity check run\\\" root@sysname.mil\"\n  tag \"fix_id\": \"F-78327r1_fix\"\n  describe package(file_integrity_tool) do\n    it { should be_installed }\n  end\n  describe.one do\n    describe file(\"/etc/cron.daily/#{file_integrity_tool}\") do\n      its('content') { should match %r{/bin/mail} }\n    end\n    describe file(\"/etc/cron.weekly/#{file_integrity_tool}\") do\n      its('content') { should match %r{/bin/mail} }\n    end\n    describe crontab('root').where { command =~ %r{#{file_integrity_tool}} } do\n      its('commands.flatten') { should include(match %r{/bin/mail}) }\n    end\n    if file(\"/etc/cron.d/#{file_integrity_tool}\").exist?\n      describe crontab(path: \"/etc/cron.d/#{file_integrity_tool}\") do\n        its('commands') { should include(match %r{/bin/mail}) }\n      end\n    end\n  end\nend\n",
          "source_location": {
            "line": 10,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71975.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "System Package aide should be installed",
              "run_time": 0.000178493,
              "start_time": "2019-11-04T16:17:08-05:00",
              "message": "expected that `System Package aide` is installed"
            },
            {
              "status": "failed",
              "code_desc": "File /etc/cron.daily/aide content should match /\\/bin\\/mail/",
              "run_time": 0.000170624,
              "start_time": "2019-11-04T16:17:08-05:00",
              "message": "expected nil to match /\\/bin\\/mail/",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "File /etc/cron.weekly/aide content should match /\\/bin\\/mail/",
              "run_time": 0.000133724,
              "start_time": "2019-11-04T16:17:08-05:00",
              "message": "expected nil to match /\\/bin\\/mail/",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "crontab for user root with command =~ /aide/ commands.flatten should include (match /\\/bin\\/mail/)",
              "run_time": 0.000373009,
              "start_time": "2019-11-04T16:17:08-05:00",
              "message": "expected [] to include (match /\\/bin\\/mail/)\nDiff:\n@@ -1,2 +1,2 @@\n-[(match /\\/bin\\/mail/)]\n+[]\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            }
          ]
        },
        {
          "id": "V-71977",
          "title": "The operating system must prevent the installation of software,\npatches, service packs, device drivers, or operating system components from a\nrepository without verification they have been digitally signed using a\ncertificate that is issued by a Certificate Authority (CA) that is recognized\nand approved by the organization.",
          "desc": "Changes to any software components can have significant effects on the\noverall security of the operating system. This requirement ensures the software\nhas not been tampered with and that it has been provided by a trusted vendor.\n\n    Accordingly, patches, service packs, device drivers, or operating system\ncomponents must be signed with a certificate recognized and approved by the\norganization.\n\n    Verifying the authenticity of the software prior to installation validates\nthe integrity of the patch or upgrade received from a vendor. This verifies the\nsoftware has not been tampered with and that it has been provided by a trusted\nvendor. Self-signed certificates are disallowed by this requirement. The\noperating system should not have to verify the software again. This requirement\ndoes not mandate DoD certificates for this purpose; however, the certificate\nused to verify the software must be from an approved CA.",
          "descriptions": [
            {
              "label": "default",
              "data": "Changes to any software components can have significant effects on the\noverall security of the operating system. This requirement ensures the software\nhas not been tampered with and that it has been provided by a trusted vendor.\n\n    Accordingly, patches, service packs, device drivers, or operating system\ncomponents must be signed with a certificate recognized and approved by the\norganization.\n\n    Verifying the authenticity of the software prior to installation validates\nthe integrity of the patch or upgrade received from a vendor. This verifies the\nsoftware has not been tampered with and that it has been provided by a trusted\nvendor. Self-signed certificates are disallowed by this requirement. The\noperating system should not have to verify the software again. This requirement\ndoes not mandate DoD certificates for this purpose; however, the certificate\nused to verify the software must be from an approved CA."
            },
            {
              "label": "check",
              "data": "Verify the operating system prevents the installation of\npatches, service packs, device drivers, or operating system components from a\nrepository without verification that they have been digitally signed using a\ncertificate that is recognized and approved by the organization.\n\nCheck that yum verifies the signature of packages from a repository prior to\ninstall with the following command:\n\n# grep gpgcheck /etc/yum.conf\ngpgcheck=1\n\nIf \"gpgcheck\" is not set to \"1\", or if options are missing or commented\nout, ask the System Administrator how the certificates for patches and other\noperating system components are verified.\n\nIf there is no process to validate certificates that is approved by the\norganization, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to verify the signature of\npackages from a repository prior to install by setting the following option in\nthe \"/etc/yum.conf\" file:\n\ngpgcheck=1"
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000366-GPOS-00153",
            "gid": "V-71977",
            "rid": "SV-86601r1_rule",
            "stig_id": "RHEL-07-020050",
            "cci": [
              "CCI-001749"
            ],
            "documentable": false,
            "nist": [
              "CM-5 (3)",
              "Rev_4"
            ],
            "subsystems": [
              "yum"
            ],
            "fix_id": "F-78329r1_fix"
          },
          "code": "control \"V-71977\" do\n  title \"The operating system must prevent the installation of software,\npatches, service packs, device drivers, or operating system components from a\nrepository without verification they have been digitally signed using a\ncertificate that is issued by a Certificate Authority (CA) that is recognized\nand approved by the organization.\"\n  desc  \"\n    Changes to any software components can have significant effects on the\noverall security of the operating system. This requirement ensures the software\nhas not been tampered with and that it has been provided by a trusted vendor.\n\n    Accordingly, patches, service packs, device drivers, or operating system\ncomponents must be signed with a certificate recognized and approved by the\norganization.\n\n    Verifying the authenticity of the software prior to installation validates\nthe integrity of the patch or upgrade received from a vendor. This verifies the\nsoftware has not been tampered with and that it has been provided by a trusted\nvendor. Self-signed certificates are disallowed by this requirement. The\noperating system should not have to verify the software again. This requirement\ndoes not mandate DoD certificates for this purpose; however, the certificate\nused to verify the software must be from an approved CA.\n  \"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000366-GPOS-00153\"\n  tag \"gid\": \"V-71977\"\n  tag \"rid\": \"SV-86601r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020050\"\n  tag \"cci\": [\"CCI-001749\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-5 (3)\", \"Rev_4\"]\n  tag \"subsystems\": ['yum']\n  desc \"check\", \"Verify the operating system prevents the installation of\npatches, service packs, device drivers, or operating system components from a\nrepository without verification that they have been digitally signed using a\ncertificate that is recognized and approved by the organization.\n\nCheck that yum verifies the signature of packages from a repository prior to\ninstall with the following command:\n\n# grep gpgcheck /etc/yum.conf\ngpgcheck=1\n\nIf \\\"gpgcheck\\\" is not set to \\\"1\\\", or if options are missing or commented\nout, ask the System Administrator how the certificates for patches and other\noperating system components are verified.\n\nIf there is no process to validate certificates that is approved by the\norganization, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to verify the signature of\npackages from a repository prior to install by setting the following option in\nthe \\\"/etc/yum.conf\\\" file:\n\ngpgcheck=1\"\n  tag \"fix_id\": \"F-78329r1_fix\"\n\n  yum_conf = '/etc/yum.conf'\n \n  if ((f = file(yum_conf)).exist?) \n    describe ini(yum_conf) do\n      its('main.gpgcheck') { should cmp 1 }\n    end \n  else\n    describe f do\n      it { should exist }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71977.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "INI /etc/yum.conf main.gpgcheck should cmp == 1",
              "run_time": 0.000201587,
              "start_time": "2019-11-04T16:17:08-05:00"
            }
          ]
        },
        {
          "id": "V-71979",
          "title": "The operating system must prevent the installation of software,\npatches, service packs, device drivers, or operating system components of local\npackages without verification they have been digitally signed using a\ncertificate that is issued by a Certificate Authority (CA) that is recognized\nand approved by the organization.",
          "desc": "Changes to any software components can have significant effects on the\noverall security of the operating system. This requirement ensures the software\nhas not been tampered with and that it has been provided by a trusted vendor.\n\n    Accordingly, patches, service packs, device drivers, or operating system\ncomponents must be signed with a certificate recognized and approved by the\norganization.\n\n    Verifying the authenticity of the software prior to installation validates\nthe integrity of the patch or upgrade received from a vendor. This verifies the\nsoftware has not been tampered with and that it has been provided by a trusted\nvendor. Self-signed certificates are disallowed by this requirement. The\noperating system should not have to verify the software again. This requirement\ndoes not mandate DoD certificates for this purpose; however, the certificate\nused to verify the software must be from an approved CA.",
          "descriptions": [
            {
              "label": "default",
              "data": "Changes to any software components can have significant effects on the\noverall security of the operating system. This requirement ensures the software\nhas not been tampered with and that it has been provided by a trusted vendor.\n\n    Accordingly, patches, service packs, device drivers, or operating system\ncomponents must be signed with a certificate recognized and approved by the\norganization.\n\n    Verifying the authenticity of the software prior to installation validates\nthe integrity of the patch or upgrade received from a vendor. This verifies the\nsoftware has not been tampered with and that it has been provided by a trusted\nvendor. Self-signed certificates are disallowed by this requirement. The\noperating system should not have to verify the software again. This requirement\ndoes not mandate DoD certificates for this purpose; however, the certificate\nused to verify the software must be from an approved CA."
            },
            {
              "label": "check",
              "data": "Verify the operating system prevents the installation of\npatches, service packs, device drivers, or operating system components of local\npackages without verification that they have been digitally signed using a\ncertificate that is recognized and approved by the organization.\n\nCheck that yum verifies the signature of local packages prior to install with\nthe following command:\n\n# grep localpkg_gpgcheck /etc/yum.conf\nlocalpkg_gpgcheck=1\n\nIf \"localpkg_gpgcheck\" is not set to \"1\", or if options are missing or\ncommented out, ask the System Administrator how the signatures of local\npackages and other operating system components are verified.\n\nIf there is no process to validate the signatures of local packages that is\napproved by the organization, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to verify the signature of local\npackages prior to install by setting the following option in the\n\"/etc/yum.conf\" file:\n\nlocalpkg_gpgcheck=1"
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000366-GPOS-00153",
            "gid": "V-71979",
            "rid": "SV-86603r1_rule",
            "stig_id": "RHEL-07-020060",
            "cci": [
              "CCI-001749"
            ],
            "documentable": false,
            "nist": [
              "CM-5 (3)",
              "Rev_4"
            ],
            "subsystems": [
              "yum"
            ],
            "fix_id": "F-78331r1_fix"
          },
          "code": "control \"V-71979\" do\n  title \"The operating system must prevent the installation of software,\npatches, service packs, device drivers, or operating system components of local\npackages without verification they have been digitally signed using a\ncertificate that is issued by a Certificate Authority (CA) that is recognized\nand approved by the organization.\"\n  desc  \"\n    Changes to any software components can have significant effects on the\noverall security of the operating system. This requirement ensures the software\nhas not been tampered with and that it has been provided by a trusted vendor.\n\n    Accordingly, patches, service packs, device drivers, or operating system\ncomponents must be signed with a certificate recognized and approved by the\norganization.\n\n    Verifying the authenticity of the software prior to installation validates\nthe integrity of the patch or upgrade received from a vendor. This verifies the\nsoftware has not been tampered with and that it has been provided by a trusted\nvendor. Self-signed certificates are disallowed by this requirement. The\noperating system should not have to verify the software again. This requirement\ndoes not mandate DoD certificates for this purpose; however, the certificate\nused to verify the software must be from an approved CA.\n  \"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000366-GPOS-00153\"\n  tag \"gid\": \"V-71979\"\n  tag \"rid\": \"SV-86603r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020060\"\n  tag \"cci\": [\"CCI-001749\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-5 (3)\", \"Rev_4\"]\n  tag \"subsystems\": ['yum']\n  desc \"check\", \"Verify the operating system prevents the installation of\npatches, service packs, device drivers, or operating system components of local\npackages without verification that they have been digitally signed using a\ncertificate that is recognized and approved by the organization.\n\nCheck that yum verifies the signature of local packages prior to install with\nthe following command:\n\n# grep localpkg_gpgcheck /etc/yum.conf\nlocalpkg_gpgcheck=1\n\nIf \\\"localpkg_gpgcheck\\\" is not set to \\\"1\\\", or if options are missing or\ncommented out, ask the System Administrator how the signatures of local\npackages and other operating system components are verified.\n\nIf there is no process to validate the signatures of local packages that is\napproved by the organization, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to verify the signature of local\npackages prior to install by setting the following option in the\n\\\"/etc/yum.conf\\\" file:\n\nlocalpkg_gpgcheck=1\"\n  tag \"fix_id\": \"F-78331r1_fix\"\n\n  yum_conf = '/etc/yum.conf'\n\n  if ((f = file(yum_conf)).exist?)\n     describe ini(yum_conf) do\n       its('main.localpkg_gpgcheck') { cmp 1 }\n     end\n   else\n     describe f do\n       it { should exist }\n     end\n   end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71979.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "INI /etc/yum.conf main.localpkg_gpgcheck ",
              "run_time": 0.000102633,
              "start_time": "2019-11-04T16:17:08-05:00"
            }
          ]
        },
        {
          "id": "V-71981",
          "title": "The operating system must prevent the installation of software,\npatches, service packs, device drivers, or operating system components of\npackages without verification of the repository metadata.",
          "desc": "Changes to any software components can have significant effects on the\noverall security of the operating system. This requirement ensures the software\nhas not been tampered with and that it has been provided by a trusted vendor.\n\n    Accordingly, patches, service packs, device drivers, or operating system\ncomponents must be signed with a certificate recognized and approved by the\norganization.\n\n    Verifying the authenticity of the software prior to installation validates\nthe integrity of the patch or upgrade received from a vendor. This ensures the\nsoftware has not been tampered with and that it has been provided by a trusted\nvendor. Self-signed certificates are disallowed by this requirement. The\noperating system should not have to verify the software again. This requirement\ndoes not mandate DoD certificates for this purpose; however, the certificate\nused to verify the software must be from an approved Certificate Authority.",
          "descriptions": [
            {
              "label": "default",
              "data": "Changes to any software components can have significant effects on the\noverall security of the operating system. This requirement ensures the software\nhas not been tampered with and that it has been provided by a trusted vendor.\n\n    Accordingly, patches, service packs, device drivers, or operating system\ncomponents must be signed with a certificate recognized and approved by the\norganization.\n\n    Verifying the authenticity of the software prior to installation validates\nthe integrity of the patch or upgrade received from a vendor. This ensures the\nsoftware has not been tampered with and that it has been provided by a trusted\nvendor. Self-signed certificates are disallowed by this requirement. The\noperating system should not have to verify the software again. This requirement\ndoes not mandate DoD certificates for this purpose; however, the certificate\nused to verify the software must be from an approved Certificate Authority."
            },
            {
              "label": "check",
              "data": "Verify the operating system prevents the installation of\npatches, service packs, device drivers, or operating system components of local\npackages without verification of the repository metadata.\n\nCheck that yum verifies the package metadata prior to install with the\nfollowing command:\n\n# grep repo_gpgcheck /etc/yum.conf\nrepo_gpgcheck=1\n\nIf \"repo_gpgcheck\" is not set to \"1\", or if options are missing or\ncommented out, ask the System Administrator how the metadata of local packages\nand other operating system components are verified.\n\nIf there is no process to validate the metadata of packages that is approved by\nthe organization, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to verify the repository metadata\nby setting the following options in the \"/etc/yum.conf\" file:\n\nrepo_gpgcheck=1"
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000366-GPOS-00153",
            "gid": "V-71981",
            "rid": "SV-86605r1_rule",
            "stig_id": "RHEL-07-020070",
            "cci": [
              "CCI-001749"
            ],
            "documentable": false,
            "nist": [
              "CM-5 (3)",
              "Rev_4"
            ],
            "subsystems": [
              "yum"
            ],
            "fix_id": "F-78333r1_fix"
          },
          "code": "control \"V-71981\" do\n  title \"The operating system must prevent the installation of software,\npatches, service packs, device drivers, or operating system components of\npackages without verification of the repository metadata.\"\n  desc  \"\n    Changes to any software components can have significant effects on the\noverall security of the operating system. This requirement ensures the software\nhas not been tampered with and that it has been provided by a trusted vendor.\n\n    Accordingly, patches, service packs, device drivers, or operating system\ncomponents must be signed with a certificate recognized and approved by the\norganization.\n\n    Verifying the authenticity of the software prior to installation validates\nthe integrity of the patch or upgrade received from a vendor. This ensures the\nsoftware has not been tampered with and that it has been provided by a trusted\nvendor. Self-signed certificates are disallowed by this requirement. The\noperating system should not have to verify the software again. This requirement\ndoes not mandate DoD certificates for this purpose; however, the certificate\nused to verify the software must be from an approved Certificate Authority.\n  \"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000366-GPOS-00153\"\n  tag \"gid\": \"V-71981\"\n  tag \"rid\": \"SV-86605r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020070\"\n  tag \"cci\": [\"CCI-001749\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-5 (3)\", \"Rev_4\"]\n  tag \"subsystems\": ['yum']\n  desc \"check\", \"Verify the operating system prevents the installation of\npatches, service packs, device drivers, or operating system components of local\npackages without verification of the repository metadata.\n\nCheck that yum verifies the package metadata prior to install with the\nfollowing command:\n\n# grep repo_gpgcheck /etc/yum.conf\nrepo_gpgcheck=1\n\nIf \\\"repo_gpgcheck\\\" is not set to \\\"1\\\", or if options are missing or\ncommented out, ask the System Administrator how the metadata of local packages\nand other operating system components are verified.\n\nIf there is no process to validate the metadata of packages that is approved by\nthe organization, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to verify the repository metadata\nby setting the following options in the \\\"/etc/yum.conf\\\" file:\n\nrepo_gpgcheck=1\"\n  tag \"fix_id\": \"F-78333r1_fix\"\n\n  yum_conf = '/etc/yum.conf'\n\n  if ((f = file(yum_conf)).exist?)\n    describe ini(yum_conf) do\n      its('main.repo_gpgcheck') { cmp 1 }\n    end\n  else\n    describe f do\n      it { should exist }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71981.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "INI /etc/yum.conf main.repo_gpgcheck ",
              "run_time": 0.000150467,
              "start_time": "2019-11-04T16:17:08-05:00"
            }
          ]
        },
        {
          "id": "V-71983",
          "title": "USB mass storage must be disabled.",
          "desc": "USB mass storage permits easy introduction of unknown devices, thereby\nfacilitating malicious activity.",
          "descriptions": [
            {
              "label": "default",
              "data": "USB mass storage permits easy introduction of unknown devices, thereby\nfacilitating malicious activity."
            },
            {
              "label": "check",
              "data": "If there is an HBSS with a Device Control Module and a Data\nLoss Prevention mechanism, this requirement is not applicable.\n\nVerify the operating system disables the ability to use USB mass storage\ndevices.\n\nCheck to see if USB mass storage is disabled with the following command:\n\n# grep usb-storage /etc/modprobe.d/blacklist.conf\nblacklist usb-storage\n\nIf the command does not return any output or the output is not \"blacklist\nusb-storage\", and use of USB storage devices is not documented with the\nInformation System Security Officer (ISSO) as an operational requirement, this\nis a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to disable the ability to use USB\nmass storage devices.\n\n# vi /etc/modprobe.d/blacklist.conf\n\nAdd or update the line:\n\nblacklist usb-storage"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000114-GPOS-00059",
            "satisfies": [
              "SRG-OS-000114-GPOS-00059",
              "SRG-OS-000378-GPOS-00163",
              "SRG-OS-000480-GPOS-00227"
            ],
            "gid": "V-71983",
            "rid": "SV-86607r2_rule",
            "stig_id": "RHEL-07-020100",
            "cci": [
              "CCI-000366",
              "CCI-000778",
              "CCI-001958"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "IA-3",
              "IA-3",
              "Rev_4"
            ],
            "subsystems": [
              "usb",
              "kernel_module"
            ],
            "fix_id": "F-78335r2_fix"
          },
          "code": "control \"V-71983\" do\n  title \"USB mass storage must be disabled.\"\n  desc  \"USB mass storage permits easy introduction of unknown devices, thereby\nfacilitating malicious activity.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000114-GPOS-00059\"\n  tag \"satisfies\": [\"SRG-OS-000114-GPOS-00059\", \"SRG-OS-000378-GPOS-00163\",\n\"SRG-OS-000480-GPOS-00227\"]\n  tag \"gid\": \"V-71983\"\n  tag \"rid\": \"SV-86607r2_rule\"\n  tag \"stig_id\": \"RHEL-07-020100\"\n  tag \"cci\": [\"CCI-000366\", \"CCI-000778\", \"CCI-001958\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"IA-3\", \"IA-3\", \"Rev_4\"]\n  tag \"subsystems\": ['usb', 'kernel_module']\n  desc \"check\", \"If there is an HBSS with a Device Control Module and a Data\nLoss Prevention mechanism, this requirement is not applicable.\n\nVerify the operating system disables the ability to use USB mass storage\ndevices.\n\nCheck to see if USB mass storage is disabled with the following command:\n\n# grep usb-storage /etc/modprobe.d/blacklist.conf\nblacklist usb-storage\n\nIf the command does not return any output or the output is not \\\"blacklist\nusb-storage\\\", and use of USB storage devices is not documented with the\nInformation System Security Officer (ISSO) as an operational requirement, this\nis a finding.\"\n  desc \"fix\", \"Configure the operating system to disable the ability to use USB\nmass storage devices.\n\n# vi /etc/modprobe.d/blacklist.conf\n\nAdd or update the line:\n\nblacklist usb-storage\"\n  tag \"fix_id\": \"F-78335r2_fix\"\n\n  # TODO ALWAYS check your resources\n  describe kernel_module('usb_storage') do\n    it { should_not be_loaded }\n    it { should be_blacklisted }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71983.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Kernel Module usb_storage should not be loaded",
              "run_time": 0.016572911,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Kernel Module usb_storage should be blacklisted",
              "run_time": 0.087747255,
              "start_time": "2019-11-04T16:17:08-05:00",
              "message": "expected `Kernel Module usb_storage.blacklisted?` to return true, got false"
            }
          ]
        },
        {
          "id": "V-71985",
          "title": "File system automounter must be disabled unless required.",
          "desc": "Automatically mounting file systems permits easy introduction of\nunknown devices, thereby facilitating malicious activity.",
          "descriptions": [
            {
              "label": "default",
              "data": "Automatically mounting file systems permits easy introduction of\nunknown devices, thereby facilitating malicious activity."
            },
            {
              "label": "check",
              "data": "Verify the operating system disables the ability to automount\ndevices.\n\nCheck to see if automounter service is active with the following command:\n\n# systemctl status autofs\nautofs.service - Automounts filesystems on demand\n   Loaded: loaded (/usr/lib/systemd/system/autofs.service; disabled)\n   Active: inactive (dead)\n\nIf the \"autofs\" status is set to \"active\" and is not documented with the\nInformation System Security Officer (ISSO) as an operational requirement, this\nis a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to disable the ability to\nautomount devices.\n\nTurn off the automount service with the following command:\n\n# systemctl disable autofs\n\nIf \"autofs\" is required for Network File System (NFS), it must be documented\nwith the ISSO."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000114-GPOS-00059",
            "satisfies": [
              "SRG-OS-000114-GPOS-00059",
              "SRG-OS-000378-GPOS-00163",
              "SRG-OS-000480-GPOS-00227"
            ],
            "gid": "V-71985",
            "rid": "SV-86609r1_rule",
            "stig_id": "RHEL-07-020110",
            "cci": [
              "CCI-000366",
              "CCI-000778",
              "CCI-001958"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "IA-3",
              "IA-3",
              "Rev_4"
            ],
            "subsystems": [
              "file_system",
              "nfs",
              "autofs"
            ],
            "fix_id": "F-78337r1_fix"
          },
          "code": "control \"V-71985\" do\n  title \"File system automounter must be disabled unless required.\"\n  desc  \"Automatically mounting file systems permits easy introduction of\nunknown devices, thereby facilitating malicious activity.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000114-GPOS-00059\"\n  tag \"satisfies\": [\"SRG-OS-000114-GPOS-00059\", \"SRG-OS-000378-GPOS-00163\",\n\"SRG-OS-000480-GPOS-00227\"]\n  tag \"gid\": \"V-71985\"\n  tag \"rid\": \"SV-86609r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020110\"\n  tag \"cci\": [\"CCI-000366\", \"CCI-000778\", \"CCI-001958\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"IA-3\", \"IA-3\", \"Rev_4\"]\n  tag \"subsystems\": ['file_system', 'nfs', 'autofs']\n  desc \"check\", \"Verify the operating system disables the ability to automount\ndevices.\n\nCheck to see if automounter service is active with the following command:\n\n# systemctl status autofs\nautofs.service - Automounts filesystems on demand\n   Loaded: loaded (/usr/lib/systemd/system/autofs.service; disabled)\n   Active: inactive (dead)\n\nIf the \\\"autofs\\\" status is set to \\\"active\\\" and is not documented with the\nInformation System Security Officer (ISSO) as an operational requirement, this\nis a finding.\"\n  desc \"fix\", \"Configure the operating system to disable the ability to\nautomount devices.\n\nTurn off the automount service with the following command:\n\n# systemctl disable autofs\n\nIf \\\"autofs\\\" is required for Network File System (NFS), it must be documented\nwith the ISSO.\"\n  tag \"fix_id\": \"F-78337r1_fix\"\n\n  describe systemd_service('autofs.service') do\n    it { should_not be_running }\n    it { should_not be_enabled }\n    it { should_not be_installed }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71985.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Service autofs.service should not be running",
              "run_time": 0.04956875,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "Service autofs.service should not be enabled",
              "run_time": 0.000179754,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Service autofs.service should not be installed",
              "run_time": 0.000185432,
              "start_time": "2019-11-04T16:17:08-05:00",
              "message": "expected Service autofs.service not to be installed"
            }
          ]
        },
        {
          "id": "V-71987",
          "title": "The operating system must remove all software components after updated\nversions have been installed.",
          "desc": "Previous versions of software components that are not removed from the\ninformation system after updates have been installed may be exploited by\nadversaries. Some information technology products may remove older versions of\nsoftware automatically from the information system.",
          "descriptions": [
            {
              "label": "default",
              "data": "Previous versions of software components that are not removed from the\ninformation system after updates have been installed may be exploited by\nadversaries. Some information technology products may remove older versions of\nsoftware automatically from the information system."
            },
            {
              "label": "check",
              "data": "Verify the operating system removes all software components\nafter updated versions have been installed.\n\nCheck if yum is configured to remove unneeded packages with the following\ncommand:\n\n# grep -i clean_requirements_on_remove /etc/yum.conf\nclean_requirements_on_remove=1\n\nIf \"clean_requirements_on_remove\" is not set to \"1\", \"True\", or \"yes\",\nor is not set in \"/etc/yum.conf\", this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to remove all software components\nafter updated versions have been installed.\n\nSet the \"clean_requirements_on_remove\" option to \"1\" in the\n\"/etc/yum.conf\" file:\n\nclean_requirements_on_remove=1"
            }
          ],
          "impact": 0.3,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000437-GPOS-00194",
            "gid": "V-71987",
            "rid": "SV-86611r1_rule",
            "stig_id": "RHEL-07-020200",
            "cci": [
              "CCI-002617"
            ],
            "documentable": false,
            "nist": [
              "SI-2 (6)",
              "Rev_4"
            ],
            "subsystems": [
              "yum"
            ],
            "fix_id": "F-78339r1_fix"
          },
          "code": "control \"V-71987\" do\n  title \"The operating system must remove all software components after updated\nversions have been installed.\"\n  desc  \"Previous versions of software components that are not removed from the\ninformation system after updates have been installed may be exploited by\nadversaries. Some information technology products may remove older versions of\nsoftware automatically from the information system.\"\n  impact 0.3\n  tag \"gtitle\": \"SRG-OS-000437-GPOS-00194\"\n  tag \"gid\": \"V-71987\"\n  tag \"rid\": \"SV-86611r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020200\"\n  tag \"cci\": [\"CCI-002617\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"SI-2 (6)\", \"Rev_4\"]\n  tag \"subsystems\": ['yum']\n  desc \"check\", \"Verify the operating system removes all software components\nafter updated versions have been installed.\n\nCheck if yum is configured to remove unneeded packages with the following\ncommand:\n\n# grep -i clean_requirements_on_remove /etc/yum.conf\nclean_requirements_on_remove=1\n\nIf \\\"clean_requirements_on_remove\\\" is not set to \\\"1\\\", \\\"True\\\", or \\\"yes\\\",\nor is not set in \\\"/etc/yum.conf\\\", this is a finding.\"\n  desc \"fix\", \"Configure the operating system to remove all software components\nafter updated versions have been installed.\n\nSet the \\\"clean_requirements_on_remove\\\" option to \\\"1\\\" in the\n\\\"/etc/yum.conf\\\" file:\n\nclean_requirements_on_remove=1\"\n  tag \"fix_id\": \"F-78339r1_fix\"\n\n  describe parse_config_file(\"/etc/yum.conf\") do\n    its('main.clean_requirements_on_remove') { should match %r{1|True|yes}i }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71987.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/yum.conf main.clean_requirements_on_remove should match /1|True|yes/i",
              "run_time": 0.000229599,
              "start_time": "2019-11-04T16:17:08-05:00",
              "message": "expected nil to match /1|True|yes/i"
            }
          ]
        },
        {
          "id": "V-71989",
          "title": "The operating system must enable SELinux.",
          "desc": "Without verification of the security functions, security functions may not\noperate correctly and the failure may go unnoticed. Security function is\ndefined as the hardware, software, and/or firmware of the information system\nresponsible for enforcing the system security policy and supporting the\nisolation of code and data on which the protection is based. Security\nfunctionality includes, but is not limited to, establishing system accounts,\nconfiguring access authorizations (i.e., permissions, privileges), setting\nevents to be audited, and setting intrusion detection parameters.\n\n    This requirement applies to operating systems performing security function\nverification/testing and/or systems and environments that require this\nfunctionality.",
          "descriptions": [
            {
              "label": "default",
              "data": "Without verification of the security functions, security functions may not\noperate correctly and the failure may go unnoticed. Security function is\ndefined as the hardware, software, and/or firmware of the information system\nresponsible for enforcing the system security policy and supporting the\nisolation of code and data on which the protection is based. Security\nfunctionality includes, but is not limited to, establishing system accounts,\nconfiguring access authorizations (i.e., permissions, privileges), setting\nevents to be audited, and setting intrusion detection parameters.\n\n    This requirement applies to operating systems performing security function\nverification/testing and/or systems and environments that require this\nfunctionality."
            },
            {
              "label": "check",
              "data": "Verify the operating system verifies correct operation of all\nsecurity functions.\n\nCheck if \"SELinux\" is active and in \"Enforcing\" mode with the following\ncommand:\n\n# getenforce\nEnforcing\n\nIf \"SELinux\" is not active and not in \"Enforcing\" mode, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to verify correct operation of all\nsecurity functions.\n\nSet the \"SELinux\" status and the \"Enforcing\" mode by modifying the\n\"/etc/selinux/config\" file to have the following line:\n\nSELINUX=enforcing\n\nA reboot is required for the changes to take effect."
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000445-GPOS-00199",
            "gid": "V-71989",
            "rid": "SV-86613r2_rule",
            "stig_id": "RHEL-07-020210",
            "cci": [
              "CCI-002165",
              "CCI-002696"
            ],
            "documentable": false,
            "nist": [
              "AC-3 (4)",
              "SI-6 a",
              "Rev_4"
            ],
            "subsystems": [
              "selinux"
            ],
            "fix_id": "F-78341r2_fix"
          },
          "code": "control \"V-71989\" do\n  title \"The operating system must enable SELinux.\"\n  desc  \"\n    Without verification of the security functions, security functions may not\noperate correctly and the failure may go unnoticed. Security function is\ndefined as the hardware, software, and/or firmware of the information system\nresponsible for enforcing the system security policy and supporting the\nisolation of code and data on which the protection is based. Security\nfunctionality includes, but is not limited to, establishing system accounts,\nconfiguring access authorizations (i.e., permissions, privileges), setting\nevents to be audited, and setting intrusion detection parameters.\n\n    This requirement applies to operating systems performing security function\nverification/testing and/or systems and environments that require this\nfunctionality.\n  \"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000445-GPOS-00199\"\n  tag \"gid\": \"V-71989\"\n  tag \"rid\": \"SV-86613r2_rule\"\n  tag \"stig_id\": \"RHEL-07-020210\"\n  tag \"cci\": [\"CCI-002165\", \"CCI-002696\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-3 (4)\", \"SI-6 a\", \"Rev_4\"]\n  tag \"subsystems\": ['selinux']\n  desc \"check\", \"Verify the operating system verifies correct operation of all\nsecurity functions.\n\nCheck if \\\"SELinux\\\" is active and in \\\"Enforcing\\\" mode with the following\ncommand:\n\n# getenforce\nEnforcing\n\nIf \\\"SELinux\\\" is not active and not in \\\"Enforcing\\\" mode, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to verify correct operation of all\nsecurity functions.\n\nSet the \\\"SELinux\\\" status and the \\\"Enforcing\\\" mode by modifying the\n\\\"/etc/selinux/config\\\" file to have the following line:\n\nSELINUX=enforcing\n\nA reboot is required for the changes to take effect.\"\n  tag \"fix_id\": \"F-78341r2_fix\"\n\n  # TODO SELinux resource?? (https://github.com/chef/inspec/issues/534)\n  describe command('getenforce') do\n    its('stdout.strip') { should eq 'Enforcing' }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71989.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Command: `getenforce` stdout.strip should eq \"Enforcing\"",
              "run_time": 0.013583777,
              "start_time": "2019-11-04T16:17:08-05:00"
            }
          ]
        },
        {
          "id": "V-71991",
          "title": "The operating system must enable the SELinux targeted policy.",
          "desc": "Without verification of the security functions, security functions may not\noperate correctly and the failure may go unnoticed. Security function is\ndefined as the hardware, software, and/or firmware of the information system\nresponsible for enforcing the system security policy and supporting the\nisolation of code and data on which the protection is based. Security\nfunctionality includes, but is not limited to, establishing system accounts,\nconfiguring access authorizations (i.e., permissions, privileges), setting\nevents to be audited, and setting intrusion detection parameters.\n\n    This requirement applies to operating systems performing security function\nverification/testing and/or systems and environments that require this\nfunctionality.",
          "descriptions": [
            {
              "label": "default",
              "data": "Without verification of the security functions, security functions may not\noperate correctly and the failure may go unnoticed. Security function is\ndefined as the hardware, software, and/or firmware of the information system\nresponsible for enforcing the system security policy and supporting the\nisolation of code and data on which the protection is based. Security\nfunctionality includes, but is not limited to, establishing system accounts,\nconfiguring access authorizations (i.e., permissions, privileges), setting\nevents to be audited, and setting intrusion detection parameters.\n\n    This requirement applies to operating systems performing security function\nverification/testing and/or systems and environments that require this\nfunctionality."
            },
            {
              "label": "check",
              "data": "Verify the operating system verifies correct operation of all\nsecurity functions.\n\nCheck if \"SELinux\" is active and is enforcing the targeted policy with the\nfollowing command:\n\n# sestatus\n\nSELinux status:                 enabled\n\nSELinuxfs mount:                /selinux\n\nSELinux root directory:         /etc/selinux\n\nLoaded policy name:             targeted\n\nCurrent mode:                   enforcing\n\nMode from config file:          enforcing\n\nPolicy MLS status:              enabled\n\nPolicy deny_unknown status:     allowed\n\nMax kernel policy version:      28\n\n\nIf the \"Policy from config file\" is not set to \"targeted\", or the \"Loaded\npolicy name\" is not set to \"targeted\", this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to verify correct operation of all\nsecurity functions.\n\nSet the \"SELinuxtype\" to the \"targeted\" policy by modifying the\n\"/etc/selinux/config\" file to have the following line:\n\nSELINUXTYPE=targeted\n\nA reboot is required for the changes to take effect."
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000445-GPOS-00199",
            "gid": "V-71991",
            "rid": "SV-86615r3_rule",
            "stig_id": "RHEL-07-020220",
            "cci": [
              "CCI-002165",
              "CCI-002696"
            ],
            "documentable": false,
            "nist": [
              "AC-3 (4)",
              "SI-6 a",
              "Rev_4"
            ],
            "subsystems": [
              "selinux"
            ],
            "fix_id": "F-78343r2_fix"
          },
          "code": "control \"V-71991\" do\n  title \"The operating system must enable the SELinux targeted policy.\"\n  desc  \"\n    Without verification of the security functions, security functions may not\noperate correctly and the failure may go unnoticed. Security function is\ndefined as the hardware, software, and/or firmware of the information system\nresponsible for enforcing the system security policy and supporting the\nisolation of code and data on which the protection is based. Security\nfunctionality includes, but is not limited to, establishing system accounts,\nconfiguring access authorizations (i.e., permissions, privileges), setting\nevents to be audited, and setting intrusion detection parameters.\n\n    This requirement applies to operating systems performing security function\nverification/testing and/or systems and environments that require this\nfunctionality.\n  \"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000445-GPOS-00199\"\n  tag \"gid\": \"V-71991\"\n  tag \"rid\": \"SV-86615r3_rule\"\n  tag \"stig_id\": \"RHEL-07-020220\"\n  tag \"cci\": [\"CCI-002165\", \"CCI-002696\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-3 (4)\", \"SI-6 a\", \"Rev_4\"]\n  tag \"subsystems\": ['selinux']\n  desc \"check\", \"Verify the operating system verifies correct operation of all\nsecurity functions.\n\nCheck if \\\"SELinux\\\" is active and is enforcing the targeted policy with the\nfollowing command:\n\n# sestatus\n\nSELinux status:                 enabled\n\nSELinuxfs mount:                /selinux\n\nSELinux root directory:         /etc/selinux\n\nLoaded policy name:             targeted\n\nCurrent mode:                   enforcing\n\nMode from config file:          enforcing\n\nPolicy MLS status:              enabled\n\nPolicy deny_unknown status:     allowed\n\nMax kernel policy version:      28\n\n\nIf the \\\"Policy from config file\\\" is not set to \\\"targeted\\\", or the \\\"Loaded\npolicy name\\\" is not set to \\\"targeted\\\", this is a finding.\n\"\n  desc \"fix\", \"Configure the operating system to verify correct operation of all\nsecurity functions.\n\nSet the \\\"SELinuxtype\\\" to the \\\"targeted\\\" policy by modifying the\n\\\"/etc/selinux/config\\\" file to have the following line:\n\nSELINUXTYPE=targeted\n\nA reboot is required for the changes to take effect.\"\n  tag \"fix_id\": \"F-78343r2_fix\"\n\n  #@todo - SELinux resource?? (https://github.com/chef/inspec/issues/534)\n  describe.one do\n    describe command('sestatus') do\n      its('stdout') { should match %r{^Policy\\sfrom\\sconfigs\\sfile:\\s+targeted\\n?$} }\n    end\n    describe command('sestatus') do\n      its('stdout') { should match %r{^Loaded\\spolicy\\sname:\\s+targeted\\n?$} }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71991.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Command: `sestatus` stdout should match /^Loaded\\spolicy\\sname:\\s+targeted\\n?$/",
              "run_time": 0.000282917,
              "start_time": "2019-11-04T16:17:08-05:00"
            }
          ]
        },
        {
          "id": "V-71993",
          "title": "The x86 Ctrl-Alt-Delete key sequence must be disabled.",
          "desc": "A locally logged-on user who presses Ctrl-Alt-Delete, when at the\nconsole, can reboot the system. If accidentally pressed, as could happen in the\ncase of a mixed OS environment, this can create the risk of short-term loss of\navailability of systems due to unintentional reboot. In the GNOME graphical\nenvironment, risk of unintentional reboot from the Ctrl-Alt-Delete sequence is\nreduced because the user will be prompted before any action is taken.",
          "descriptions": [
            {
              "label": "default",
              "data": "A locally logged-on user who presses Ctrl-Alt-Delete, when at the\nconsole, can reboot the system. If accidentally pressed, as could happen in the\ncase of a mixed OS environment, this can create the risk of short-term loss of\navailability of systems due to unintentional reboot. In the GNOME graphical\nenvironment, risk of unintentional reboot from the Ctrl-Alt-Delete sequence is\nreduced because the user will be prompted before any action is taken."
            },
            {
              "label": "check",
              "data": "Verify the operating system is not configured to reboot the\nsystem when Ctrl-Alt-Delete is pressed.\n\nCheck that the ctrl-alt-del.service is not active with the following command:\n\n# systemctl status ctrl-alt-del.service\nreboot.target - Reboot\n   Loaded: loaded (/usr/lib/systemd/system/reboot.target; disabled)\n   Active: inactive (dead)\n     Docs: man:systemd.special(7)\n\nIf the ctrl-alt-del.service is active, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the system to disable the Ctrl-Alt_Delete sequence for\nthe command line with the following command:\n\n# systemctl mask ctrl-alt-del.target\n\nIf GNOME is active on the system, create a database to contain the system-wide\nsetting (if it does not already exist) with the following command:\n\n# cat /etc/dconf/db/local.d/00-disable-CAD\n\nAdd the setting to disable the Ctrl-Alt_Delete sequence for GNOME:\n\n[org/gnome/settings-daemon/plugins/media-keys]\nlogout=’’"
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-71993",
            "rid": "SV-86617r1_rule",
            "stig_id": "RHEL-07-020230",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "gnome",
              "general"
            ],
            "fix_id": "F-78345r2_fix"
          },
          "code": "control \"V-71993\" do\n  title \"The x86 Ctrl-Alt-Delete key sequence must be disabled.\"\n  desc  \"A locally logged-on user who presses Ctrl-Alt-Delete, when at the\nconsole, can reboot the system. If accidentally pressed, as could happen in the\ncase of a mixed OS environment, this can create the risk of short-term loss of\navailability of systems due to unintentional reboot. In the GNOME graphical\nenvironment, risk of unintentional reboot from the Ctrl-Alt-Delete sequence is\nreduced because the user will be prompted before any action is taken.\"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-71993\"\n  tag \"rid\": \"SV-86617r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020230\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": [\"gnome\", \"general\"]\n  desc \"check\", \"Verify the operating system is not configured to reboot the\nsystem when Ctrl-Alt-Delete is pressed.\n\nCheck that the ctrl-alt-del.service is not active with the following command:\n\n# systemctl status ctrl-alt-del.service\nreboot.target - Reboot\n   Loaded: loaded (/usr/lib/systemd/system/reboot.target; disabled)\n   Active: inactive (dead)\n     Docs: man:systemd.special(7)\n\nIf the ctrl-alt-del.service is active, this is a finding.\"\n  desc \"fix\", \"Configure the system to disable the Ctrl-Alt_Delete sequence for\nthe command line with the following command:\n\n# systemctl mask ctrl-alt-del.target\n\nIf GNOME is active on the system, create a database to contain the system-wide\nsetting (if it does not already exist) with the following command:\n\n# cat /etc/dconf/db/local.d/00-disable-CAD\n\nAdd the setting to disable the Ctrl-Alt_Delete sequence for GNOME:\n\n[org/gnome/settings-daemon/plugins/media-keys]\nlogout=’’\"\n  tag \"fix_id\": \"F-78345r2_fix\"\n\n  describe systemd_service('ctrl-alt-del.target') do\n    it { should_not be_running }\n    it { should_not be_enabled }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71993.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Service ctrl-alt-del.target should not be running",
              "run_time": 0.049882772,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "Service ctrl-alt-del.target should not be enabled",
              "run_time": 0.000170249,
              "start_time": "2019-11-04T16:17:08-05:00"
            }
          ]
        },
        {
          "id": "V-71995",
          "title": "The operating system must define default permissions for all\nauthenticated users in such a way that the user can only read and modify their\nown files.",
          "desc": "Setting the most restrictive default permissions ensures that when new\naccounts are created, they do not have unnecessary access.",
          "descriptions": [
            {
              "label": "default",
              "data": "Setting the most restrictive default permissions ensures that when new\naccounts are created, they do not have unnecessary access."
            },
            {
              "label": "check",
              "data": "Verify the operating system defines default permissions for all\nauthenticated users in such a way that the user can only read and modify their\nown files.\n\nCheck for the value of the \"UMASK\" parameter in \"/etc/login.defs\" file with\nthe following command:\n\nNote: If the value of the \"UMASK\" parameter is set to \"000\" in\n\"/etc/login.defs\" file, the Severity is raised to a CAT I.\n\n# grep -i umask /etc/login.defs\nUMASK  077\n\nIf the value for the \"UMASK\" parameter is not \"077\", or the \"UMASK\"\nparameter is missing or is commented out, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to define default permissions for\nall authenticated users in such a way that the user can only read and modify\ntheir own files.\n\nAdd or edit the line for the \"UMASK\" parameter in \"/etc/login.defs\" file to\n\"077\":\n\nUMASK  077"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00228",
            "gid": "V-71995",
            "rid": "SV-86619r1_rule",
            "stig_id": "RHEL-07-020240",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "login_defs"
            ],
            "fix_id": "F-78347r1_fix"
          },
          "code": "control \"V-71995\" do\n  title \"The operating system must define default permissions for all\nauthenticated users in such a way that the user can only read and modify their\nown files.\"\n  desc  \"Setting the most restrictive default permissions ensures that when new\naccounts are created, they do not have unnecessary access.\"\nif login_defs.read_params[\"UMASK\"].eql?('000')\n  impact 0.7\nelse\n  impact 0.5\nend\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00228\"\n  tag \"gid\": \"V-71995\"\n  tag \"rid\": \"SV-86619r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020240\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['login_defs']\n  desc \"check\", \"Verify the operating system defines default permissions for all\nauthenticated users in such a way that the user can only read and modify their\nown files.\n\nCheck for the value of the \\\"UMASK\\\" parameter in \\\"/etc/login.defs\\\" file with\nthe following command:\n\nNote: If the value of the \\\"UMASK\\\" parameter is set to \\\"000\\\" in\n\\\"/etc/login.defs\\\" file, the Severity is raised to a CAT I.\n\n# grep -i umask /etc/login.defs\nUMASK  077\n\nIf the value for the \\\"UMASK\\\" parameter is not \\\"077\\\", or the \\\"UMASK\\\"\nparameter is missing or is commented out, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to define default permissions for\nall authenticated users in such a way that the user can only read and modify\ntheir own files.\n\nAdd or edit the line for the \\\"UMASK\\\" parameter in \\\"/etc/login.defs\\\" file to\n\\\"077\\\":\n\nUMASK  077\"\n  tag \"fix_id\": \"F-78347r1_fix\"\n\n  describe login_defs do\n    its('UMASK') { should eq '077' }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71995.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "login.defs UMASK should eq \"077\"",
              "run_time": 0.000344919,
              "start_time": "2019-11-04T16:17:08-05:00"
            }
          ]
        },
        {
          "id": "V-71997",
          "title": "The operating system must be a vendor supported release.",
          "desc": "An operating system release is considered \"supported\" if the vendor \n  continues to provide security patches for the product. With an unsupported\n  release, it will not be possible to resolve security issues discovered in the\n  system software.",
          "descriptions": [
            {
              "label": "default",
              "data": "An operating system release is considered \"supported\" if the vendor \n  continues to provide security patches for the product. With an unsupported\n  release, it will not be possible to resolve security issues discovered in the\n  system software."
            },
            {
              "label": "check",
              "data": "Verify the version of the operating system is vendor supported.\n   \n  Check the version of the operating system with the following command:\n  \n  # cat /etc/redhat-release\n  \n  Red Hat Enterprise Linux Server release 7.2 (Maipo)\n  \n  Current End of Life for RHEL 7.2 is Q4 2020.\n  \n  Current End of Life for RHEL 7.3 is 30 June 2024.\n  \n  If the release is not supported by the vendor, this is a finding."
            },
            {
              "label": "fix",
              "data": "Upgrade to a supported version of the operating system."
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-71997",
            "rid": "SV-86621r2_rule",
            "stig_id": "RHEL-07-020250",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "fix_id": "F-78349r1_fix",
            "subsystems": [
              "redhat_release"
            ]
          },
          "code": "control \"V-71997\" do\n  title \"The operating system must be a vendor supported release.\"\n  desc  \"An operating system release is considered \\\"supported\\\" if the vendor \n  continues to provide security patches for the product. With an unsupported\n  release, it will not be possible to resolve security issues discovered in the\n  system software.\"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-71997\"\n  tag \"rid\": \"SV-86621r2_rule\"\n  tag \"stig_id\": \"RHEL-07-020250\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"fix_id\": \"F-78349r1_fix\"\n  tag \"subsystems\": ['redhat_release']\n  desc \"check\", \"Verify the version of the operating system is vendor supported.\n   \n  Check the version of the operating system with the following command:\n  \n  # cat /etc/redhat-release\n  \n  Red Hat Enterprise Linux Server release 7.2 (Maipo)\n  \n  Current End of Life for RHEL 7.2 is Q4 2020.\n  \n  Current End of Life for RHEL 7.3 is 30 June 2024.\n  \n  If the release is not supported by the vendor, this is a finding.\"\n  \n  desc \"fix\", \"Upgrade to a supported version of the operating system.\"\n\n  # TODO use an array attribute of supported DISTROS and use the be_in matcher?\n  describe file('/etc/redhat-release') do\n    its('content') { should match %r{Release (6.7*|7.[2-9].*)}i }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71997.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "File /etc/redhat-release content should match /Release (6.7*|7.[2-9].*)/i",
              "run_time": 0.001268626,
              "start_time": "2019-11-04T16:17:08-05:00"
            }
          ]
        },
        {
          "id": "V-71999",
          "title": "Vendor packaged system security patches and updates must be installed\nand up to date.",
          "desc": "Timely patching is critical for maintaining the operational\navailability, confidentiality, and integrity of information technology (IT)\nsystems. However, failure to keep operating system and application software\npatched is a common mistake made by IT professionals. New patches are released\ndaily, and it is often difficult for even experienced System Administrators to\nkeep abreast of all the new patches. When new weaknesses in an operating system\nexist, patches are usually made available by the vendor to resolve the\nproblems. If the most recent security patches and updates are not installed,\nunauthorized users may take advantage of weaknesses in the unpatched software.\nThe lack of prompt attention to patching could result in a system compromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "Timely patching is critical for maintaining the operational\navailability, confidentiality, and integrity of information technology (IT)\nsystems. However, failure to keep operating system and application software\npatched is a common mistake made by IT professionals. New patches are released\ndaily, and it is often difficult for even experienced System Administrators to\nkeep abreast of all the new patches. When new weaknesses in an operating system\nexist, patches are usually made available by the vendor to resolve the\nproblems. If the most recent security patches and updates are not installed,\nunauthorized users may take advantage of weaknesses in the unpatched software.\nThe lack of prompt attention to patching could result in a system compromise."
            },
            {
              "label": "check",
              "data": "Verify the operating system security patches and updates are\ninstalled and up to date. Updates are required to be applied with a frequency\ndetermined by the site or Program Management Office (PMO).\n\nObtain the list of available package security updates from Red Hat. The URL for\nupdates is https://rhn.redhat.com/errata/. It is important to note that updates\nprovided by Red Hat may not be present on the system if the underlying packages\nare not installed.\n\nCheck that the available package security updates have been installed on the\nsystem with the following command:\n\n# yum history list | more\nLoaded plugins: langpacks, product-id, subscription-manager\nID     | Command line             | Date and time    | Action(s)      | Altered\n-------------------------------------------------------------------------------\n    70 | install aide             | 2016-05-05 10:58 | Install       |     1\n    69 | update -y                | 2016-05-04 14:34 | Update     |   18 EE\n    68 | install vlc                | 2016-04-21 17:12 | Install        |   21\n\n    67 | update -y                | 2016-04-21 17:04 | Update     |     7 EE\n    66 | update -y                | 2016-04-15 16:47 | E, I, U         |   84 EE\n\nIf package updates have not been performed on the system within the timeframe\nthat the site/program documentation requires, this is a finding.\n\nTypical update frequency may be overridden by Information Assurance\nVulnerability Alert (IAVA) notifications from CYBERCOM.\n\nIf the operating system is in non-compliance with the Information Assurance\nVulnerability Management (IAVM) process, this is a finding."
            },
            {
              "label": "fix",
              "data": "Install the operating system patches or updated packages\navailable from Red Hat within 30 days or sooner as local policy dictates."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-71999",
            "rid": "SV-86623r3_rule",
            "stig_id": "RHEL-07-020260",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "fix_id": "F-78351r1_fix",
            "subsystems": [
              "packages"
            ],
            "nist": [
              "CM-6 b",
              "Rev_4"
            ]
          },
          "code": "control \"V-71999\" do\n  title \"Vendor packaged system security patches and updates must be installed\nand up to date.\"\n  desc  \"Timely patching is critical for maintaining the operational\navailability, confidentiality, and integrity of information technology (IT)\nsystems. However, failure to keep operating system and application software\npatched is a common mistake made by IT professionals. New patches are released\ndaily, and it is often difficult for even experienced System Administrators to\nkeep abreast of all the new patches. When new weaknesses in an operating system\nexist, patches are usually made available by the vendor to resolve the\nproblems. If the most recent security patches and updates are not installed,\nunauthorized users may take advantage of weaknesses in the unpatched software.\nThe lack of prompt attention to patching could result in a system compromise.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-71999\"\n  tag \"rid\": \"SV-86623r3_rule\"\n  tag \"stig_id\": \"RHEL-07-020260\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"fix_id\": \"F-78351r1_fix\"\n  tag \"subsystems\": ['packages']\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  desc \"check\", \"Verify the operating system security patches and updates are\ninstalled and up to date. Updates are required to be applied with a frequency\ndetermined by the site or Program Management Office (PMO).\n\nObtain the list of available package security updates from Red Hat. The URL for\nupdates is https://rhn.redhat.com/errata/. It is important to note that updates\nprovided by Red Hat may not be present on the system if the underlying packages\nare not installed.\n\nCheck that the available package security updates have been installed on the\nsystem with the following command:\n\n# yum history list | more\nLoaded plugins: langpacks, product-id, subscription-manager\nID     | Command line             | Date and time    | Action(s)      | Altered\n-------------------------------------------------------------------------------\n    70 | install aide             | 2016-05-05 10:58 | Install       |     1\n    69 | update -y                | 2016-05-04 14:34 | Update     |   18 EE\n    68 | install vlc                | 2016-04-21 17:12 | Install        |   21\n\n    67 | update -y                | 2016-04-21 17:04 | Update     |     7 EE\n    66 | update -y                | 2016-04-15 16:47 | E, I, U         |   84 EE\n\nIf package updates have not been performed on the system within the timeframe\nthat the site/program documentation requires, this is a finding.\n\nTypical update frequency may be overridden by Information Assurance\nVulnerability Alert (IAVA) notifications from CYBERCOM.\n\nIf the operating system is in non-compliance with the Information Assurance\nVulnerability Management (IAVM) process, this is a finding.\"\n  desc \"fix\", \"Install the operating system patches or updated packages\navailable from Red Hat within 30 days or sooner as local policy dictates.\"\n\n  describe.one do\n    describe 'List of out-of-date packages' do\n      subject { linux_update.updates }\n      it { should be_empty }\n    end\n\n    linux_update.updates.each do |update|\n      describe package(update['name']) do\n        its('version') { should eq update['version'] }\n      end\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-71999.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "List of out-of-date packages ",
              "run_time": 0.000205501,
              "start_time": "2019-11-04T16:17:08-05:00",
              "message": "undefined local variable or method `linux_update' for #<RSpec::ExampleGroups::ListOfOutOfDatePackages:0x0000000005d783e0>\n\nundefined local variable or method `linux_update' for #<RSpec::ExampleGroups::ListOfOutOfDatePackages:0x0000000007de7900>",
              "exception": "RSpec::Core::MultipleExceptionError"
            }
          ]
        },
        {
          "id": "V-72001",
          "title": "The system must not have unnecessary accounts.",
          "desc": "Accounts providing no operational purpose provide additional\nopportunities for system compromise. Unnecessary accounts include user accounts\nfor individuals not requiring access to the system and application accounts for\napplications not installed on the system.",
          "descriptions": [
            {
              "label": "default",
              "data": "Accounts providing no operational purpose provide additional\nopportunities for system compromise. Unnecessary accounts include user accounts\nfor individuals not requiring access to the system and application accounts for\napplications not installed on the system."
            },
            {
              "label": "check",
              "data": "Verify all accounts on the system are assigned to an active\nsystem, application, or user account.\n\nObtain the list of authorized system accounts from the Information System\nSecurity Officer (ISSO).\n\nCheck the system accounts on the system with the following command:\n\n# more /etc/passwd\nroot:x:0:0:root:/root:/bin/bash\nbin:x:1:1:bin:/bin:/sbin/nologin\ndaemon:x:2:2:daemon:/sbin:/sbin/nologin\nsync:x:5:0:sync:/sbin:/bin/sync\nshutdown:x:6:0:shutdown:/sbin:/sbin/shutdown\nhalt:x:7:0:halt:/sbin:/sbin/halt\ngames:x:12:100:games:/usr/games:/sbin/nologin\ngopher:x:13:30:gopher:/var/gopher:/sbin/nologin\n\nAccounts such as \"games\" and \"gopher\" are not authorized accounts as they\ndo not support authorized system functions.\n\nIf the accounts on the system do not match the provided documentation, or\naccounts that do not support an authorized system function are present, this is\na finding."
            },
            {
              "label": "fix",
              "data": "Configure the system so all accounts on the system are assigned\nto an active system, application, or user account.\n\nRemove accounts that do not support approved system activities or that allow\nfor a normal user to perform administrative-level actions.\n\nDocument all authorized accounts on the system."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72001",
            "rid": "SV-86625r1_rule",
            "stig_id": "RHEL-07-020270",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "accounts"
            ],
            "fix_id": "F-78353r1_fix"
          },
          "code": "control \"V-72001\" do\n  title \"The system must not have unnecessary accounts.\"\n  desc  \"Accounts providing no operational purpose provide additional\nopportunities for system compromise. Unnecessary accounts include user accounts\nfor individuals not requiring access to the system and application accounts for\napplications not installed on the system.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72001\"\n  tag \"rid\": \"SV-86625r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020270\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['accounts']\n  desc \"check\", \"Verify all accounts on the system are assigned to an active\nsystem, application, or user account.\n\nObtain the list of authorized system accounts from the Information System\nSecurity Officer (ISSO).\n\nCheck the system accounts on the system with the following command:\n\n# more /etc/passwd\nroot:x:0:0:root:/root:/bin/bash\nbin:x:1:1:bin:/bin:/sbin/nologin\ndaemon:x:2:2:daemon:/sbin:/sbin/nologin\nsync:x:5:0:sync:/sbin:/bin/sync\nshutdown:x:6:0:shutdown:/sbin:/sbin/shutdown\nhalt:x:7:0:halt:/sbin:/sbin/halt\ngames:x:12:100:games:/usr/games:/sbin/nologin\ngopher:x:13:30:gopher:/var/gopher:/sbin/nologin\n\nAccounts such as \\\"games\\\" and \\\"gopher\\\" are not authorized accounts as they\ndo not support authorized system functions.\n\nIf the accounts on the system do not match the provided documentation, or\naccounts that do not support an authorized system function are present, this is\na finding.\"\n  desc \"fix\", \"Configure the system so all accounts on the system are assigned\nto an active system, application, or user account.\n\nRemove accounts that do not support approved system activities or that allow\nfor a normal user to perform administrative-level actions.\n\nDocument all authorized accounts on the system.\"\n  tag \"fix_id\": \"F-78353r1_fix\"\n\n  allowed_accounts = (known_system_accounts + user_accounts).uniq\n\n  describe passwd do\n    its('users') { should be_in allowed_accounts }\n  end\n\n  describe passwd do\n    its('users') { should_not be_in disallowed_accounts }\n  end\nend\n",
          "source_location": {
            "line": 53,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72001.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "/etc/passwd users should be in \"root\", \"bin\", \"daemon\", \"adm\", \"lp\", \"sync\", \"shutdown\", \"halt\", \"mail\", \"operator\", \"nobody\", \"systemd-bus-proxy\", \"systemd-network\", \"dbus\", \"polkitd\", \"tss\", \"postfix\", \"chrony\", \"sshd\", \"sssd\", \"rpc\", \"ntp\", \"vboxadd\", \"nfsnobody\", \"vagrant\", and \"rpcuser\"",
              "run_time": 0.000374231,
              "start_time": "2019-11-04T16:17:08-05:00",
              "message": "expected `[\"root\", \"bin\", \"daemon\", \"adm\", \"lp\", \"sync\", \"shutdown\", \"halt\", \"mail\", \"operator\", \"games\", \"ftp\", \"nobody\", \"systemd-network\", \"dbus\", \"polkitd\", \"sshd\", \"postfix\", \"chrony\", \"dhaynes\", \"rpc\", \"gluster\", \"libstoragemgmt\", \"qemu\", \"unbound\", \"rtkit\", \"ntp\", \"saslauth\", \"tss\", \"usbmuxd\", \"colord\", \"radvd\", \"geoclue\", \"abrt\", \"rpcuser\", \"nfsnobody\", \"pulse\", \"saned\", \"sssd\", \"setroubleshoot\", \"gdm\", \"gnome-initial-setup\", \"tcpdump\", \"avahi\"]` to be in the list: `[\"root\", \"bin\", \"daemon\", \"adm\", \"lp\", \"sync\", \"shutdown\", \"halt\", \"mail\", \"operator\", \"nobody\", \"systemd-bus-proxy\", \"systemd-network\", \"dbus\", \"polkitd\", \"tss\", \"postfix\", \"chrony\", \"sshd\", \"sssd\", \"rpc\", \"ntp\", \"vboxadd\", \"nfsnobody\", \"vagrant\", \"rpcuser\"]` \nDiff:\n [\"games\", \"ftp\", \"dhaynes\", \"gluster\", \"libstoragemgmt\", \"qemu\", \"unbound\", \"rtkit\", \"saslauth\", \"usbmuxd\", \"colord\", \"radvd\", \"geoclue\", \"abrt\", \"pulse\", \"saned\", \"setroubleshoot\", \"gdm\", \"gnome-initial-setup\", \"tcpdump\", \"avahi\"]"
            },
            {
              "status": "failed",
              "code_desc": "/etc/passwd users should not be in \"games\", \"gopher\", and \"ftp\"",
              "run_time": 0.000180236,
              "start_time": "2019-11-04T16:17:08-05:00",
              "message": "expected `[\"root\", \"bin\", \"daemon\", \"adm\", \"lp\", \"sync\", \"shutdown\", \"halt\", \"mail\", \"operator\", \"games\", \"ftp\", \"nobody\", \"systemd-network\", \"dbus\", \"polkitd\", \"sshd\", \"postfix\", \"chrony\", \"dhaynes\", \"rpc\", \"gluster\", \"libstoragemgmt\", \"qemu\", \"unbound\", \"rtkit\", \"ntp\", \"saslauth\", \"tss\", \"usbmuxd\", \"colord\", \"radvd\", \"geoclue\", \"abrt\", \"rpcuser\", \"nfsnobody\", \"pulse\", \"saned\", \"sssd\", \"setroubleshoot\", \"gdm\", \"gnome-initial-setup\", \"tcpdump\", \"avahi\"]` not to be in the list: `[\"games\", \"gopher\", \"ftp\"]` \nComm:\n [\"games\", \"ftp\"]"
            }
          ]
        },
        {
          "id": "V-72003",
          "title": "All Group Identifiers (GIDs) referenced in the /etc/passwd file must\nbe defined in the /etc/group file.",
          "desc": "If a user is assigned the GID of a group not existing on the system,\nand a group with the GID is subsequently created, the user may have unintended\nrights to any files associated with the group.",
          "descriptions": [
            {
              "label": "default",
              "data": "If a user is assigned the GID of a group not existing on the system,\nand a group with the GID is subsequently created, the user may have unintended\nrights to any files associated with the group."
            },
            {
              "label": "check",
              "data": "Verify all GIDs referenced in the \"/etc/passwd\" file are\ndefined in the \"/etc/group\" file.\n\nCheck that all referenced GIDs exist with the following command:\n\n# pwck -r\n\nIf GIDs referenced in \"/etc/passwd\" file are returned as not defined in\n\"/etc/group\" file, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the system to define all GIDs found in the\n\"/etc/passwd\" file by modifying the \"/etc/group\" file to add any\nnon-existent group referenced in the \"/etc/passwd\" file, or change the GIDs\nreferenced in the \"/etc/passwd\" file to a group that exists in\n\"/etc/group\"."
            }
          ],
          "impact": 0.3,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000104-GPOS-00051",
            "gid": "V-72003",
            "rid": "SV-86627r1_rule",
            "stig_id": "RHEL-07-020300",
            "cci": [
              "CCI-000764"
            ],
            "documentable": false,
            "nist": [
              "IA-2",
              "Rev_4"
            ],
            "subsystems": [
              "accounts"
            ],
            "fix_id": "F-78355r1_fix"
          },
          "code": "control \"V-72003\" do\n  title \"All Group Identifiers (GIDs) referenced in the /etc/passwd file must\nbe defined in the /etc/group file.\"\n  desc  \"If a user is assigned the GID of a group not existing on the system,\nand a group with the GID is subsequently created, the user may have unintended\nrights to any files associated with the group.\"\n  impact 0.3\n  tag \"gtitle\": \"SRG-OS-000104-GPOS-00051\"\n  tag \"gid\": \"V-72003\"\n  tag \"rid\": \"SV-86627r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020300\"\n  tag \"cci\": [\"CCI-000764\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-2\", \"Rev_4\"]\n  tag \"subsystems\": ['accounts']\n  desc \"check\", \"Verify all GIDs referenced in the \\\"/etc/passwd\\\" file are\ndefined in the \\\"/etc/group\\\" file.\n\nCheck that all referenced GIDs exist with the following command:\n\n# pwck -r\n\nIf GIDs referenced in \\\"/etc/passwd\\\" file are returned as not defined in\n\\\"/etc/group\\\" file, this is a finding.\"\n  desc \"fix\", \"Configure the system to define all GIDs found in the\n\\\"/etc/passwd\\\" file by modifying the \\\"/etc/group\\\" file to add any\nnon-existent group referenced in the \\\"/etc/passwd\\\" file, or change the GIDs\nreferenced in the \\\"/etc/passwd\\\" file to a group that exists in\n\\\"/etc/group\\\".\"\n  tag \"fix_id\": \"F-78355r1_fix\"\n  passwd.gids.each do |gid|\n    describe etc_group do\n      its('gids') { should include gid.to_i }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72003.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 0",
              "run_time": 0.000134011,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 1",
              "run_time": 0.000100301,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 2",
              "run_time": 9.4475e-05,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 4",
              "run_time": 9.3142e-05,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 7",
              "run_time": 0.000100454,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 0",
              "run_time": 9.3722e-05,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 0",
              "run_time": 0.000107971,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 0",
              "run_time": 9.1072e-05,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 12",
              "run_time": 0.00010428,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 0",
              "run_time": 0.000103425,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 100",
              "run_time": 0.000121191,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 50",
              "run_time": 9.721e-05,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 99",
              "run_time": 0.000105681,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 192",
              "run_time": 9.424e-05,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 81",
              "run_time": 0.000105738,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 998",
              "run_time": 9.6918e-05,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 74",
              "run_time": 0.000106996,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 89",
              "run_time": 0.000160704,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 996",
              "run_time": 0.000112448,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 1000",
              "run_time": 9.4875e-05,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 32",
              "run_time": 0.000104037,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 993",
              "run_time": 0.000109797,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 992",
              "run_time": 0.000108697,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 107",
              "run_time": 9.6119e-05,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 991",
              "run_time": 0.000102969,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 172",
              "run_time": 9.8895e-05,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 38",
              "run_time": 0.000111036,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 76",
              "run_time": 0.000101901,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 59",
              "run_time": 0.000111692,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 113",
              "run_time": 9.8056e-05,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 989",
              "run_time": 0.000130096,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 75",
              "run_time": 0.000101684,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 988",
              "run_time": 0.000100502,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 173",
              "run_time": 0.000106541,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 29",
              "run_time": 0.000100875,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 65534",
              "run_time": 0.000101852,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 171",
              "run_time": 0.000213742,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 985",
              "run_time": 0.000110129,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 984",
              "run_time": 0.00010439,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 983",
              "run_time": 0.000150799,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 42",
              "run_time": 0.00010437,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 982",
              "run_time": 0.000158241,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 72",
              "run_time": 0.00011031,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/group gids should include 70",
              "run_time": 0.000173572,
              "start_time": "2019-11-04T16:17:08-05:00"
            }
          ]
        },
        {
          "id": "V-72005",
          "title": "The root account must be the only account having unrestricted access\nto the system.",
          "desc": "If an account other than root also has a User Identifier (UID) of\n\"0\", it has root authority, giving that account unrestricted access to the\nentire operating system. Multiple accounts with a UID of \"0\" afford an\nopportunity for potential intruders to guess a password for a privileged\naccount.",
          "descriptions": [
            {
              "label": "default",
              "data": "If an account other than root also has a User Identifier (UID) of\n\"0\", it has root authority, giving that account unrestricted access to the\nentire operating system. Multiple accounts with a UID of \"0\" afford an\nopportunity for potential intruders to guess a password for a privileged\naccount."
            },
            {
              "label": "check",
              "data": "Check the system for duplicate UID \"0\" assignments with the\nfollowing command:\n\n# awk -F: '$3 == 0 {print $1}' /etc/passwd\n\nIf any accounts other than root have a UID of \"0\", this is a finding."
            },
            {
              "label": "fix",
              "data": "Change the UID of any account on the system, other than root,\nthat has a UID of \"0\".\n\nIf the account is associated with system commands or applications, the UID\nshould be changed to one greater than \"0\" but less than \"1000\". Otherwise,\nassign a UID of greater than \"1000\" that has not already been assigned."
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72005",
            "rid": "SV-86629r1_rule",
            "stig_id": "RHEL-07-020310",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "accounts"
            ],
            "fix_id": "F-78357r1_fix"
          },
          "code": "control \"V-72005\" do\n  title \"The root account must be the only account having unrestricted access\nto the system.\"\n  desc  \"If an account other than root also has a User Identifier (UID) of\n\\\"0\\\", it has root authority, giving that account unrestricted access to the\nentire operating system. Multiple accounts with a UID of \\\"0\\\" afford an\nopportunity for potential intruders to guess a password for a privileged\naccount.\"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72005\"\n  tag \"rid\": \"SV-86629r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020310\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['accounts']\n  desc \"check\", \"Check the system for duplicate UID \\\"0\\\" assignments with the\nfollowing command:\n\n# awk -F: '$3 == 0 {print $1}' /etc/passwd\n\nIf any accounts other than root have a UID of \\\"0\\\", this is a finding.\"\n  desc \"fix\", \"Change the UID of any account on the system, other than root,\nthat has a UID of \\\"0\\\".\n\nIf the account is associated with system commands or applications, the UID\nshould be changed to one greater than \\\"0\\\" but less than \\\"1000\\\". Otherwise,\nassign a UID of greater than \\\"1000\\\" that has not already been assigned.\"\n  tag \"fix_id\": \"F-78357r1_fix\"\n\n  describe passwd.uids(0) do\n    its('users') { should cmp 'root' }\n    its('entries.length') { should eq 1 }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72005.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "/etc/passwd with uid == 0 users should cmp == \"root\"",
              "run_time": 0.000188622,
              "start_time": "2019-11-04T16:17:08-05:00"
            },
            {
              "status": "passed",
              "code_desc": "/etc/passwd with uid == 0 entries.length should eq 1",
              "run_time": 0.000188011,
              "start_time": "2019-11-04T16:17:08-05:00"
            }
          ]
        },
        {
          "id": "V-72007",
          "title": "All files and directories must have a valid owner.",
          "desc": "Unowned files and directories may be unintentionally inherited if a\nuser is assigned the same User Identifier \"UID\" as the UID of the un-owned\nfiles.",
          "descriptions": [
            {
              "label": "default",
              "data": "Unowned files and directories may be unintentionally inherited if a\nuser is assigned the same User Identifier \"UID\" as the UID of the un-owned\nfiles."
            },
            {
              "label": "check",
              "data": "Verify all files and directories on the system have a valid\nowner.\n\nCheck the owner of all files and directories with the following command:\n\nNote: The value after -fstype must be replaced with the filesystem type. XFS is\nused as an example.\n\n# find / -fstype xfs -nouser\n\nIf any files on the system do not have an assigned owner, this is a finding."
            },
            {
              "label": "fix",
              "data": "Either remove all files and directories from the system that do\nnot have a valid user, or assign a valid user to all unowned files and\ndirectories on the system with the \"chown\" command:\n\n# chown <user> <file>"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72007",
            "rid": "SV-86631r2_rule",
            "stig_id": "RHEL-07-020320",
            "cci": [
              "CCI-002165"
            ],
            "documentable": false,
            "nist": [
              "AC-3 (4)",
              "Rev_4"
            ],
            "subsystems": [
              "file_system",
              "users",
              "files"
            ],
            "fix_id": "F-78359r1_fix"
          },
          "code": "control \"V-72007\" do\n  title \"All files and directories must have a valid owner.\"\n  desc  \"Unowned files and directories may be unintentionally inherited if a\nuser is assigned the same User Identifier \\\"UID\\\" as the UID of the un-owned\nfiles.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72007\"\n  tag \"rid\": \"SV-86631r2_rule\"\n  tag \"stig_id\": \"RHEL-07-020320\"\n  tag \"cci\": [\"CCI-002165\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-3 (4)\", \"Rev_4\"]\n  tag \"subsystems\": ['file_system', 'users' ,'files']\n  desc \"check\", \"Verify all files and directories on the system have a valid\nowner.\n\nCheck the owner of all files and directories with the following command:\n\nNote: The value after -fstype must be replaced with the filesystem type. XFS is\nused as an example.\n\n# find / -fstype xfs -nouser\n\nIf any files on the system do not have an assigned owner, this is a finding.\"\n  desc \"fix\", \"Either remove all files and directories from the system that do\nnot have a valid user, or assign a valid user to all unowned files and\ndirectories on the system with the \\\"chown\\\" command:\n\n# chown <user> <file>\"\n  tag \"fix_id\": \"F-78359r1_fix\"\n\n  command('grep -v \"nodev\" /proc/filesystems | awk \\'NF{ print $NF }\\'').\n    stdout.strip.split(\"\\n\").each do |fs|\n      describe command(\"find / -xautofs -fstype #{fs} -nouser\") do\n        its('stdout.strip') { should be_empty }\n      end\n    end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72007.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Command: `find / -xautofs -fstype xfs -nouser` stdout.strip should be empty",
              "run_time": 2.786709167,
              "start_time": "2019-11-04T16:17:08-05:00"
            }
          ]
        },
        {
          "id": "V-72009",
          "title": "All files and directories must have a valid group owner.",
          "desc": "Files without a valid group owner may be unintentionally inherited if\na group is assigned the same Group Identifier (GID) as the GID of the files\nwithout a valid group owner.",
          "descriptions": [
            {
              "label": "default",
              "data": "Files without a valid group owner may be unintentionally inherited if\na group is assigned the same Group Identifier (GID) as the GID of the files\nwithout a valid group owner."
            },
            {
              "label": "check",
              "data": "Verify all files and directories on the system have a valid\ngroup.\n\nCheck the owner of all files and directories with the following command:\n\nNote: The value after -fstype must be replaced with the filesystem type. XFS is\nused as an example.\n\n# find / -fstype xfs -nogroup\n\nIf any files on the system do not have an assigned group, this is a finding."
            },
            {
              "label": "fix",
              "data": "Either remove all files and directories from the system that do\nnot have a valid group, or assign a valid group to all files and directories on\nthe system with the \"chgrp\" command:\n\n# chgrp <group> <file>"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72009",
            "rid": "SV-86633r2_rule",
            "stig_id": "RHEL-07-020330",
            "cci": [
              "CCI-002165"
            ],
            "documentable": false,
            "nist": [
              "AC-3 (4)",
              "Rev_4"
            ],
            "subsystems": [
              "file_system",
              "groups",
              "files"
            ],
            "fix_id": "F-78361r1_fix"
          },
          "code": "control \"V-72009\" do\n  title \"All files and directories must have a valid group owner.\"\n  desc  \"Files without a valid group owner may be unintentionally inherited if\na group is assigned the same Group Identifier (GID) as the GID of the files\nwithout a valid group owner.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72009\"\n  tag \"rid\": \"SV-86633r2_rule\"\n  tag \"stig_id\": \"RHEL-07-020330\"\n  tag \"cci\": [\"CCI-002165\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-3 (4)\", \"Rev_4\"]\n  tag \"subsystems\": ['file_system', 'groups' ,'files']\n  desc \"check\", \"Verify all files and directories on the system have a valid\ngroup.\n\nCheck the owner of all files and directories with the following command:\n\nNote: The value after -fstype must be replaced with the filesystem type. XFS is\nused as an example.\n\n# find / -fstype xfs -nogroup\n\nIf any files on the system do not have an assigned group, this is a finding.\"\n  desc \"fix\", \"Either remove all files and directories from the system that do\nnot have a valid group, or assign a valid group to all files and directories on\nthe system with the \\\"chgrp\\\" command:\n\n# chgrp <group> <file>\"\n  tag \"fix_id\": \"F-78361r1_fix\"\n\n  command('grep -v \"nodev\" /proc/filesystems | awk \\'NF{ print $NF }\\'').\n    stdout.strip.split(\"\\n\").each do |fs|\n      describe command(\"find / -xautofs -fstype #{fs} -nogroup\") do\n        its('stdout.strip') { should be_empty }\n      end\n    end\nend\n",
          "source_location": {
            "line": 6,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72009.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Command: `find / -xautofs -fstype xfs -nogroup` stdout.strip should be empty",
              "run_time": 2.660497032,
              "start_time": "2019-11-04T16:17:11-05:00"
            }
          ]
        },
        {
          "id": "V-72011",
          "title": "All local interactive users must have a home directory assigned in the\n/etc/passwd file.",
          "desc": "If local interactive users are not assigned a valid home directory,\nthere is no place for the storage and control of files they should own.",
          "descriptions": [
            {
              "label": "default",
              "data": "If local interactive users are not assigned a valid home directory,\nthere is no place for the storage and control of files they should own."
            },
            {
              "label": "check",
              "data": "Verify local interactive users on the system have a home\ndirectory assigned.\n\nCheck for missing local interactive user home directories with the following\ncommand:\n\n# pwck -r\nuser 'lp': directory '/var/spool/lpd' does not exist\nuser 'news': directory '/var/spool/news' does not exist\nuser 'uucp': directory '/var/spool/uucp' does not exist\nuser 'smithj': directory '/home/smithj' does not exist\n\nAsk the System Administrator (SA) if any users found without home directories\nare local interactive users. If the SA is unable to provide a response, check\nfor users with a User Identifier (UID) of 1000 or greater with the following\ncommand:\n\n# cut -d: -f 1,3 /etc/passwd | egrep \":[1-4][0-9]{2}$|:[0-9]{1,2}$\"\n\nIf any interactive users do not have a home directory assigned, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Assign home directories to all local interactive users that\ncurrently do not have a home directory assigned."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72011",
            "rid": "SV-86635r1_rule",
            "stig_id": "RHEL-07-020600",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "home_dirs"
            ],
            "fix_id": "F-78363r1_fix"
          },
          "code": "control \"V-72011\" do\n  title \"All local interactive users must have a home directory assigned in the\n/etc/passwd file.\"\n  desc  \"If local interactive users are not assigned a valid home directory,\nthere is no place for the storage and control of files they should own.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72011\"\n  tag \"rid\": \"SV-86635r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020600\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['home_dirs']\n  desc \"check\", \"Verify local interactive users on the system have a home\ndirectory assigned.\n\nCheck for missing local interactive user home directories with the following\ncommand:\n\n# pwck -r\nuser 'lp': directory '/var/spool/lpd' does not exist\nuser 'news': directory '/var/spool/news' does not exist\nuser 'uucp': directory '/var/spool/uucp' does not exist\nuser 'smithj': directory '/home/smithj' does not exist\n\nAsk the System Administrator (SA) if any users found without home directories\nare local interactive users. If the SA is unable to provide a response, check\nfor users with a User Identifier (UID) of 1000 or greater with the following\ncommand:\n\n# cut -d: -f 1,3 /etc/passwd | egrep \\\":[1-4][0-9]{2}$|:[0-9]{1,2}$\\\"\n\nIf any interactive users do not have a home directory assigned, this is a\nfinding.\"\n  desc \"fix\", \"Assign home directories to all local interactive users that\ncurrently do not have a home directory assigned.\"\n  tag \"fix_id\": \"F-78363r1_fix\"\n\n  ignore_shells = non_interactive_shells.join('|')\n\n  uid_min = login_defs.read_params['UID_MIN'].to_i\n  uid_min = 1000 if uid_min.nil?\n\n  users.where{ !shell.match(ignore_shells) && (uid >= uid_min || uid == 0)}.entries.each do |user_info|\n    next if exempt_home_users.include?(\"#{user_info.username}\")\n    describe directory(user_info.home) do\n      it { should exist }\n    end\n  end\nend\n",
          "source_location": {
            "line": 19,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72011.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Directory /root should exist",
              "run_time": 0.000294144,
              "start_time": "2019-11-04T16:17:13-05:00"
            },
            {
              "status": "passed",
              "code_desc": "Directory /home/dhaynes should exist",
              "run_time": 7.849e-05,
              "start_time": "2019-11-04T16:17:13-05:00"
            }
          ]
        },
        {
          "id": "V-72013",
          "title": "All local interactive user accounts, upon creation, must be assigned a\nhome directory.",
          "desc": "If local interactive users are not assigned a valid home directory,\nthere is no place for the storage and control of files they should own.",
          "descriptions": [
            {
              "label": "default",
              "data": "If local interactive users are not assigned a valid home directory,\nthere is no place for the storage and control of files they should own."
            },
            {
              "label": "check",
              "data": "Verify all local interactive users on the system are assigned a\nhome directory upon creation.\n\nCheck to see if the system is configured to create home directories for local\ninteractive users with the following command:\n\n# grep -i create_home /etc/login.defs\nCREATE_HOME yes\n\nIf the value for \"CREATE_HOME\" parameter is not set to \"yes\", the line is\nmissing, or the line is commented out, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to assign home directories to all\nnew local interactive users by setting the \"CREATE_HOME\" parameter in\n\"/etc/login.defs\" to \"yes\" as follows.\n\nCREATE_HOME yes"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72013",
            "rid": "SV-86637r1_rule",
            "stig_id": "RHEL-07-020610",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "login_defs"
            ],
            "fix_id": "F-78365r1_fix"
          },
          "code": "control \"V-72013\" do\n  title \"All local interactive user accounts, upon creation, must be assigned a\nhome directory.\"\n  desc  \"If local interactive users are not assigned a valid home directory,\nthere is no place for the storage and control of files they should own.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72013\"\n  tag \"rid\": \"SV-86637r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020610\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['login_defs']\n  desc \"check\", \"Verify all local interactive users on the system are assigned a\nhome directory upon creation.\n\nCheck to see if the system is configured to create home directories for local\ninteractive users with the following command:\n\n# grep -i create_home /etc/login.defs\nCREATE_HOME yes\n\nIf the value for \\\"CREATE_HOME\\\" parameter is not set to \\\"yes\\\", the line is\nmissing, or the line is commented out, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to assign home directories to all\nnew local interactive users by setting the \\\"CREATE_HOME\\\" parameter in\n\\\"/etc/login.defs\\\" to \\\"yes\\\" as follows.\n\nCREATE_HOME yes\"\n  tag \"fix_id\": \"F-78365r1_fix\"\n\n  describe login_defs do\n    its('CREATE_HOME') { should eq 'yes' }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72013.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "login.defs CREATE_HOME should eq \"yes\"",
              "run_time": 0.000330283,
              "start_time": "2019-11-04T16:17:13-05:00"
            }
          ]
        },
        {
          "id": "V-72015",
          "title": "All local interactive user home directories defined in the /etc/passwd\nfile must exist.",
          "desc": "If a local interactive user has a home directory defined that does not\nexist, the user may be given access to the / directory as the current working\ndirectory upon logon. This could create a Denial of Service because the user\nwould not be able to access their logon configuration files, and it may give\nthem visibility to system files they normally would not be able to access.",
          "descriptions": [
            {
              "label": "default",
              "data": "If a local interactive user has a home directory defined that does not\nexist, the user may be given access to the / directory as the current working\ndirectory upon logon. This could create a Denial of Service because the user\nwould not be able to access their logon configuration files, and it may give\nthem visibility to system files they normally would not be able to access."
            },
            {
              "label": "check",
              "data": "Verify the assigned home directory of all local interactive\nusers on the system exists.\n\nCheck the home directory assignment for all local interactive non-privileged\nusers on the system with the following command:\n\n# cut -d: -f 1,3 /etc/passwd | egrep \":[1-9][0-9]{2}$|:[0-9]{1,2}$\"\nsmithj /home/smithj\n\nNote: This may miss interactive users that have been assigned a privileged UID.\nEvidence of interactive use may be obtained from a number of log files\ncontaining system logon information.\n\nCheck that all referenced home directories exist with the following command:\n\n# pwck -r\nuser 'smithj': directory '/home/smithj' does not exist\n\nIf any home directories referenced in \"/etc/passwd\" are returned as not\ndefined, this is a finding."
            },
            {
              "label": "fix",
              "data": "Create home directories to all local interactive users that\ncurrently do not have a home directory assigned. Use the following commands to\ncreate the user home directory assigned in \"/etc/ passwd\":\n\nNote: The example will be for the user smithj, who has a home directory of\n\"/home/smithj\", a UID of \"smithj\", and a Group Identifier (GID) of \"users\nassigned\" in \"/etc/passwd\".\n\n# mkdir /home/smithj\n# chown smithj /home/smithj\n# chgrp users /home/smithj\n# chmod 0750 /home/smithj"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72015",
            "rid": "SV-86639r1_rule",
            "stig_id": "RHEL-07-020620",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "accounts"
            ],
            "fix_id": "F-78367r1_fix"
          },
          "code": "control \"V-72015\" do\n  title \"All local interactive user home directories defined in the /etc/passwd\nfile must exist.\"\n  desc  \"If a local interactive user has a home directory defined that does not\nexist, the user may be given access to the / directory as the current working\ndirectory upon logon. This could create a Denial of Service because the user\nwould not be able to access their logon configuration files, and it may give\nthem visibility to system files they normally would not be able to access.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72015\"\n  tag \"rid\": \"SV-86639r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020620\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['accounts']\n  desc \"check\", \"Verify the assigned home directory of all local interactive\nusers on the system exists.\n\nCheck the home directory assignment for all local interactive non-privileged\nusers on the system with the following command:\n\n# cut -d: -f 1,3 /etc/passwd | egrep \\\":[1-9][0-9]{2}$|:[0-9]{1,2}$\\\"\nsmithj /home/smithj\n\nNote: This may miss interactive users that have been assigned a privileged UID.\nEvidence of interactive use may be obtained from a number of log files\ncontaining system logon information.\n\nCheck that all referenced home directories exist with the following command:\n\n# pwck -r\nuser 'smithj': directory '/home/smithj' does not exist\n\nIf any home directories referenced in \\\"/etc/passwd\\\" are returned as not\ndefined, this is a finding.\"\n  desc \"fix\", \"Create home directories to all local interactive users that\ncurrently do not have a home directory assigned. Use the following commands to\ncreate the user home directory assigned in \\\"/etc/ passwd\\\":\n\nNote: The example will be for the user smithj, who has a home directory of\n\\\"/home/smithj\\\", a UID of \\\"smithj\\\", and a Group Identifier (GID) of \\\"users\nassigned\\\" in \\\"/etc/passwd\\\".\n\n# mkdir /home/smithj\n# chown smithj /home/smithj\n# chgrp users /home/smithj\n# chmod 0750 /home/smithj\"\n  tag \"fix_id\": \"F-78367r1_fix\"\n\n  ignore_shells = non_interactive_shells.join('|')\n\n  uid_min = login_defs.read_params['UID_MIN'].to_i\n  uid_min = 1000 if uid_min.nil?\n\n  users.where{ !shell.match(ignore_shells) && (uid >= uid_min || uid == 0)}.entries.each do |user_info|\n    next if exempt_home_users.include?(\"#{user_info.username}\")\n    describe directory(user_info.home) do\n      it { should exist }\n    end\n  end\nend\n",
          "source_location": {
            "line": 18,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72015.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Directory /root should exist",
              "run_time": 7.5849e-05,
              "start_time": "2019-11-04T16:17:13-05:00"
            },
            {
              "status": "passed",
              "code_desc": "Directory /home/dhaynes should exist",
              "run_time": 6.7686e-05,
              "start_time": "2019-11-04T16:17:13-05:00"
            }
          ]
        },
        {
          "id": "V-72017",
          "title": "All local interactive user home directories must have mode 0750 or\nless permissive.",
          "desc": "Excessive permissions on local interactive user home directories may\nallow unauthorized access to user files by other users.",
          "descriptions": [
            {
              "label": "default",
              "data": "Excessive permissions on local interactive user home directories may\nallow unauthorized access to user files by other users."
            },
            {
              "label": "check",
              "data": "Verify the assigned home directory of all local interactive\nusers has a mode of \"0750\" or less permissive.\n\nCheck the home directory assignment for all non-privileged users on the system\nwith the following command:\n\nNote: This may miss interactive users that have been assigned a privileged User\nIdentifier (UID). Evidence of interactive use may be obtained from a number of\nlog files containing system logon information.\n\n# ls -ld $(egrep ':[0-9]{4}' /etc/passwd | cut -d: -f6)\n-rwxr-x--- 1 smithj users  18 Mar  5 17:06 /home/smithj\n\nIf home directories referenced in \"/etc/passwd\" do not have a mode of\n\"0750\" or less permissive, this is a finding."
            },
            {
              "label": "fix",
              "data": "Change the mode of interactive user’s home directories to\n\"0750\". To change the mode of a local interactive user’s home directory, use\nthe following command:\n\nNote: The example will be for the user \"smithj\".\n\n# chmod 0750 /home/smithj"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72017",
            "rid": "SV-86641r2_rule",
            "stig_id": "RHEL-07-020630",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "home_dirs"
            ],
            "fix_id": "F-78369r1_fix"
          },
          "code": "control \"V-72017\" do\n  title \"All local interactive user home directories must have mode 0750 or\nless permissive.\"\n  desc  \"Excessive permissions on local interactive user home directories may\nallow unauthorized access to user files by other users.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72017\"\n  tag \"rid\": \"SV-86641r2_rule\"\n  tag \"stig_id\": \"RHEL-07-020630\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['home_dirs']\n  desc \"check\", \"Verify the assigned home directory of all local interactive\nusers has a mode of \\\"0750\\\" or less permissive.\n\nCheck the home directory assignment for all non-privileged users on the system\nwith the following command:\n\nNote: This may miss interactive users that have been assigned a privileged User\nIdentifier (UID). Evidence of interactive use may be obtained from a number of\nlog files containing system logon information.\n\n# ls -ld $(egrep ':[0-9]{4}' /etc/passwd | cut -d: -f6)\n-rwxr-x--- 1 smithj users  18 Mar  5 17:06 /home/smithj\n\nIf home directories referenced in \\\"/etc/passwd\\\" do not have a mode of\n\\\"0750\\\" or less permissive, this is a finding.\"\n  desc \"fix\", \"Change the mode of interactive user’s home directories to\n\\\"0750\\\". To change the mode of a local interactive user’s home directory, use\nthe following command:\n\nNote: The example will be for the user \\\"smithj\\\".\n\n# chmod 0750 /home/smithj\"\n  tag \"fix_id\": \"F-78369r1_fix\"\n\n  ignore_shells = non_interactive_shells.join('|')\n\n  uid_min = login_defs.read_params['UID_MIN'].to_i\n  uid_min = 1000 if uid_min.nil?\n\n  findings = Set[]\n  users.where{ !shell.match(ignore_shells) && (uid >= uid_min || uid == 0)}.entries.each do |user_info|\n    next if exempt_home_users.include?(\"#{user_info.username}\")\n    findings = findings + command(\"find #{user_info.home} -maxdepth 0 -perm /027\").stdout.split(\"\\n\")\n  end\n  describe \"Home directories with excessive permissions\" do\n    subject { findings.to_a }\n    it { should be_empty }\n  end\nend\n",
          "source_location": {
            "line": 16,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72017.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Home directories with excessive permissions should be empty",
              "run_time": 0.000107291,
              "start_time": "2019-11-04T16:17:13-05:00"
            }
          ]
        },
        {
          "id": "V-72019",
          "title": "All local interactive user home directories must be owned by their\nrespective users.",
          "desc": "If a local interactive user does not own their home directory,\nunauthorized users could access or modify the user's files, and the users may\nnot be able to access their own files.",
          "descriptions": [
            {
              "label": "default",
              "data": "If a local interactive user does not own their home directory,\nunauthorized users could access or modify the user's files, and the users may\nnot be able to access their own files."
            },
            {
              "label": "check",
              "data": "Verify the assigned home directory of all local interactive\nusers on the system exists.\n\nCheck the home directory assignment for all local interactive users on the\nsystem with the following command:\n\n# ls -ld $(egrep ':[0-9]{4}' /etc/passwd | cut -d: -f6)\n\n-rwxr-x--- 1 smithj users 18 Mar 5 17:06 /home/smithj\n\nIf any home directories referenced in \"/etc/passwd\" are not owned by the\ninteractive user, this is a finding."
            },
            {
              "label": "fix",
              "data": "Change the owner of a local interactive user’s home directories\nto that owner. To change the owner of a local interactive user’s home\ndirectory, use the following command:\n\nNote: The example will be for the user smithj, who has a home directory of\n\"/home/smithj\".\n\n# chown smithj /home/smithj"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72019",
            "rid": "SV-86643r4_rule",
            "stig_id": "RHEL-07-020640",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "home_dirs"
            ],
            "fix_id": "F-78371r1_fix"
          },
          "code": "control \"V-72019\" do\n  title \"All local interactive user home directories must be owned by their\nrespective users.\"\n  desc  \"If a local interactive user does not own their home directory,\nunauthorized users could access or modify the user's files, and the users may\nnot be able to access their own files.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72019\"\n  tag \"rid\": \"SV-86643r4_rule\"\n  tag \"stig_id\": \"RHEL-07-020640\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['home_dirs']\n  desc \"check\", \"Verify the assigned home directory of all local interactive\nusers on the system exists.\n\nCheck the home directory assignment for all local interactive users on the\nsystem with the following command:\n\n# ls -ld $(egrep ':[0-9]{4}' /etc/passwd | cut -d: -f6)\n\n-rwxr-x--- 1 smithj users 18 Mar 5 17:06 /home/smithj\n\nIf any home directories referenced in \\\"/etc/passwd\\\" are not owned by the\ninteractive user, this is a finding.\"\n  desc \"fix\", \"Change the owner of a local interactive user’s home directories\nto that owner. To change the owner of a local interactive user’s home\ndirectory, use the following command:\n\nNote: The example will be for the user smithj, who has a home directory of\n\\\"/home/smithj\\\".\n\n# chown smithj /home/smithj\"\n  tag \"fix_id\": \"F-78371r1_fix\"\n\n  ignore_shells = non_interactive_shells.join('|')\n\n  uid_min = login_defs.read_params['UID_MIN'].to_i\n  uid_min = 1000 if uid_min.nil?\n\n  findings = Set[]\n  users.where{ !shell.match(ignore_shells) && (uid >= uid_min || uid == 0)}.entries.each do |user_info|\n    next if exempt_home_users.include?(\"#{user_info.username}\")\n    describe directory(user_info.home) do\n      it { should exist }\n      its('owner') { should eq user_info.username }\n    end\n  end\nend\n",
          "source_location": {
            "line": 16,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72019.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Directory /root should exist",
              "run_time": 7.0783e-05,
              "start_time": "2019-11-04T16:17:13-05:00"
            },
            {
              "status": "passed",
              "code_desc": "Directory /root owner should eq \"root\"",
              "run_time": 0.017737027,
              "start_time": "2019-11-04T16:17:13-05:00"
            },
            {
              "status": "passed",
              "code_desc": "Directory /home/dhaynes should exist",
              "run_time": 0.004016682,
              "start_time": "2019-11-04T16:17:13-05:00"
            },
            {
              "status": "passed",
              "code_desc": "Directory /home/dhaynes owner should eq \"dhaynes\"",
              "run_time": 0.100868578,
              "start_time": "2019-11-04T16:17:13-05:00"
            }
          ]
        },
        {
          "id": "V-72021",
          "title": "All local interactive user home directories must be group-owned by the\nhome directory owners primary group.",
          "desc": "If the Group Identifier (GID) of a local interactive user’s home\ndirectory is not the same as the primary GID of the user, this would allow\nunauthorized access to the user’s files, and users that share the same group\nmay not be able to access files that they legitimately should.",
          "descriptions": [
            {
              "label": "default",
              "data": "If the Group Identifier (GID) of a local interactive user’s home\ndirectory is not the same as the primary GID of the user, this would allow\nunauthorized access to the user’s files, and users that share the same group\nmay not be able to access files that they legitimately should."
            },
            {
              "label": "check",
              "data": "Verify the assigned home directory of all local interactive\nusers is group-owned by that user’s primary GID.\n\nCheck the home directory assignment for all local interactive users on the\nsystem with the following command:\n\n# ls -ld $(egrep ':[0-9]{4}' /etc/passwd | cut -d: -f6)\n\n-rwxr-x--- 1 smithj users 18 Mar 5 17:06 /home/smithj\n\nCheck the user's primary group with the following command:\n\n# grep users /etc/group\n\nusers:x:250:smithj,jonesj,jacksons\n\nIf the user home directory referenced in \"/etc/passwd\" is not group-owned by\nthat user’s primary GID, this is a finding."
            },
            {
              "label": "fix",
              "data": "Change the group owner of a local interactive user’s home\ndirectory to the group found in \"/etc/passwd\". To change the group owner of a\nlocal interactive user’s home directory, use the following command:\n\nNote: The example will be for the user \"smithj\", who has a home directory of\n\"/home/smithj\", and has a primary group of users.\n\n# chgrp users /home/smithj"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72021",
            "rid": "SV-86645r4_rule",
            "stig_id": "RHEL-07-020650",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "home_dirs"
            ],
            "fix_id": "F-78373r1_fix"
          },
          "code": "control \"V-72021\" do\n  title \"All local interactive user home directories must be group-owned by the\nhome directory owners primary group.\"\n  desc  \"If the Group Identifier (GID) of a local interactive user’s home\ndirectory is not the same as the primary GID of the user, this would allow\nunauthorized access to the user’s files, and users that share the same group\nmay not be able to access files that they legitimately should.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72021\"\n  tag \"rid\": \"SV-86645r4_rule\"\n  tag \"stig_id\": \"RHEL-07-020650\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['home_dirs']\n  desc \"check\", \"Verify the assigned home directory of all local interactive\nusers is group-owned by that user’s primary GID.\n\nCheck the home directory assignment for all local interactive users on the\nsystem with the following command:\n\n# ls -ld $(egrep ':[0-9]{4}' /etc/passwd | cut -d: -f6)\n\n-rwxr-x--- 1 smithj users 18 Mar 5 17:06 /home/smithj\n\nCheck the user's primary group with the following command:\n\n# grep users /etc/group\n\nusers:x:250:smithj,jonesj,jacksons\n\nIf the user home directory referenced in \\\"/etc/passwd\\\" is not group-owned by\nthat user’s primary GID, this is a finding.\n\"\n  desc \"fix\", \"Change the group owner of a local interactive user’s home\ndirectory to the group found in \\\"/etc/passwd\\\". To change the group owner of a\nlocal interactive user’s home directory, use the following command:\n\nNote: The example will be for the user \\\"smithj\\\", who has a home directory of\n\\\"/home/smithj\\\", and has a primary group of users.\n\n# chgrp users /home/smithj\"\n  tag \"fix_id\": \"F-78373r1_fix\"\n\n  ignore_shells = non_interactive_shells.join('|')\n\n  uid_min = login_defs.read_params['UID_MIN'].to_i\n  uid_min = 1000 if uid_min.nil?\n\n  findings = Set[]\n  users.where{ !shell.match(ignore_shells) && (uid >= uid_min || uid == 0)}.entries.each do |user_info|\n    next if exempt_home_users.include?(\"#{user_info.username}\")\n    findings = findings + command(\"find #{user_info.home} -maxdepth 0 -not -gid #{user_info.gid}\").stdout.split(\"\\n\")\n  end\n  describe \"Home directories that are not group-owned by the user's primary GID\" do\n    subject { findings.to_a }\n    it { should be_empty }\n  end\nend\n",
          "source_location": {
            "line": 16,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72021.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Home directories that are not group-owned by the user's primary GID should be empty",
              "run_time": 0.000382312,
              "start_time": "2019-11-04T16:17:13-05:00"
            }
          ]
        },
        {
          "id": "V-72023",
          "title": "All files and directories contained in local interactive user home\ndirectories must be owned by the owner of the home directory.",
          "desc": "If local interactive users do not own the files in their directories,\nunauthorized users may be able to access them. Additionally, if files are not\nowned by the user, this could be an indication of system compromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "If local interactive users do not own the files in their directories,\nunauthorized users may be able to access them. Additionally, if files are not\nowned by the user, this could be an indication of system compromise."
            },
            {
              "label": "check",
              "data": "Verify all files and directories in a local interactive user’s\nhome directory are owned by the user.\n\nCheck the owner of all files and directories in a local interactive user’s home\ndirectory with the following command:\n\nNote: The example will be for the user \"smithj\", who has a home directory of\n\"/home/smithj\".\n\n# ls -lLR /home/smithj\n-rw-r--r-- 1 smithj smithj  18 Mar  5 17:06 file1\n-rw-r--r-- 1 smithj smithj 193 Mar  5 17:06 file2\n-rw-r--r-- 1 smithj smithj 231 Mar  5 17:06 file3\n\nIf any files are found with an owner different than the home directory user,\nthis is a finding."
            },
            {
              "label": "fix",
              "data": "Change the owner of a local interactive user’s files and\ndirectories to that owner. To change the owner of a local interactive user’s\nfiles and directories, use the following command:\n\nNote: The example will be for the user smithj, who has a home directory of\n\"/home/smithj\".\n\n# chown smithj /home/smithj/<file or directory>"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72023",
            "rid": "SV-86647r1_rule",
            "stig_id": "RHEL-07-020660",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "home_dirs"
            ],
            "fix_id": "F-78375r1_fix"
          },
          "code": "control \"V-72023\" do\n  title \"All files and directories contained in local interactive user home\ndirectories must be owned by the owner of the home directory.\"\n  desc  \"If local interactive users do not own the files in their directories,\nunauthorized users may be able to access them. Additionally, if files are not\nowned by the user, this could be an indication of system compromise.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72023\"\n  tag \"rid\": \"SV-86647r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020660\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['home_dirs']\n  desc \"check\", \"Verify all files and directories in a local interactive user’s\nhome directory are owned by the user.\n\nCheck the owner of all files and directories in a local interactive user’s home\ndirectory with the following command:\n\nNote: The example will be for the user \\\"smithj\\\", who has a home directory of\n\\\"/home/smithj\\\".\n\n# ls -lLR /home/smithj\n-rw-r--r-- 1 smithj smithj  18 Mar  5 17:06 file1\n-rw-r--r-- 1 smithj smithj 193 Mar  5 17:06 file2\n-rw-r--r-- 1 smithj smithj 231 Mar  5 17:06 file3\n\nIf any files are found with an owner different than the home directory user,\nthis is a finding.\"\n  desc \"fix\", \"Change the owner of a local interactive user’s files and\ndirectories to that owner. To change the owner of a local interactive user’s\nfiles and directories, use the following command:\n\nNote: The example will be for the user smithj, who has a home directory of\n\\\"/home/smithj\\\".\n\n# chown smithj /home/smithj/<file or directory>\"\n  tag \"fix_id\": \"F-78375r1_fix\"\n\n  ignore_shells = non_interactive_shells.join('|')\n\n  uid_min = login_defs.read_params['UID_MIN'].to_i\n  uid_min = 1000 if uid_min.nil?\n\n  findings = Set[]\n  users.where{ !shell.match(ignore_shells) && (uid >= uid_min || uid == 0)}.entries.each do |user_info|\n    next if exempt_home_users.include?(\"#{user_info.username}\")\n    findings = findings + command(\"find #{user_info.home} -xdev -xautofs -not -user #{user_info.username}\").stdout.split(\"\\n\")\n  end\n  describe \"Files and directories that are not owned by the user\" do\n    subject { findings.to_a }\n    it { should be_empty }\n  end\nend\n",
          "source_location": {
            "line": 16,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72023.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Files and directories that are not owned by the user should be empty",
              "run_time": 0.000521746,
              "start_time": "2019-11-04T16:17:13-05:00",
              "message": "expected `[\"/home/dhaynes/Music/1.0.0/cms-ars-3.1-moderate-red-hat-enterprise-linux-7-stig-overlay/inspec.lock\"...nes/rhel7-4.18-update.json\", \"/home/dhaynes/eugene/inspec-profile-disa_stig-el7-master/inspec.lock\"].empty?` to return true, got false"
            }
          ]
        },
        {
          "id": "V-72025",
          "title": "All files and directories contained in local interactive user home\ndirectories must be group-owned by a group of which the home directory owner is\na member.",
          "desc": "If a local interactive user’s files are group-owned by a group of\nwhich the user is not a member, unintended users may be able to access them.",
          "descriptions": [
            {
              "label": "default",
              "data": "If a local interactive user’s files are group-owned by a group of\nwhich the user is not a member, unintended users may be able to access them."
            },
            {
              "label": "check",
              "data": "Verify all files and directories in a local interactive user\nhome directory are group-owned by a group the user is a member of.\n\nCheck the group owner of all files and directories in a local interactive\nuser’s home directory with the following command:\n\nNote: The example will be for the user \"smithj\", who has a home directory of\n\"/home/smithj\".\n\n# ls -lLR /<home directory>/<users home directory>/\n-rw-r--r-- 1 smithj smithj  18 Mar  5 17:06 file1\n-rw-r--r-- 1 smithj smithj 193 Mar  5 17:06 file2\n-rw-r--r-- 1 smithj sa        231 Mar  5 17:06 file3\n\nIf any files are found with an owner different than the group home directory\nuser, check to see if the user is a member of that group with the following\ncommand:\n\n# grep smithj /etc/group\nsa:x:100:juan,shelley,bob,smithj\nsmithj:x:521:smithj\n\nIf the user is not a member of a group that group owns file(s) in a local\ninteractive user’s home directory, this is a finding."
            },
            {
              "label": "fix",
              "data": "Change the group of a local interactive user’s files and\ndirectories to a group that the interactive user is a member of. To change the\ngroup owner of a local interactive user’s files and directories, use the\nfollowing command:\n\nNote: The example will be for the user smithj, who has a home directory of\n\"/home/smithj\" and is a member of the users group.\n\n# chgrp users /home/smithj/<file>"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72025",
            "rid": "SV-86649r1_rule",
            "stig_id": "RHEL-07-020670",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "home_dirs"
            ],
            "fix_id": "F-78377r1_fix"
          },
          "code": "control \"V-72025\" do\n  title \"All files and directories contained in local interactive user home\ndirectories must be group-owned by a group of which the home directory owner is\na member.\"\n  desc  \"If a local interactive user’s files are group-owned by a group of\nwhich the user is not a member, unintended users may be able to access them.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72025\"\n  tag \"rid\": \"SV-86649r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020670\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['home_dirs']\n  desc \"check\", \"Verify all files and directories in a local interactive user\nhome directory are group-owned by a group the user is a member of.\n\nCheck the group owner of all files and directories in a local interactive\nuser’s home directory with the following command:\n\nNote: The example will be for the user \\\"smithj\\\", who has a home directory of\n\\\"/home/smithj\\\".\n\n# ls -lLR /<home directory>/<users home directory>/\n-rw-r--r-- 1 smithj smithj  18 Mar  5 17:06 file1\n-rw-r--r-- 1 smithj smithj 193 Mar  5 17:06 file2\n-rw-r--r-- 1 smithj sa        231 Mar  5 17:06 file3\n\nIf any files are found with an owner different than the group home directory\nuser, check to see if the user is a member of that group with the following\ncommand:\n\n# grep smithj /etc/group\nsa:x:100:juan,shelley,bob,smithj\nsmithj:x:521:smithj\n\nIf the user is not a member of a group that group owns file(s) in a local\ninteractive user’s home directory, this is a finding.\"\n  desc \"fix\", \"Change the group of a local interactive user’s files and\ndirectories to a group that the interactive user is a member of. To change the\ngroup owner of a local interactive user’s files and directories, use the\nfollowing command:\n\nNote: The example will be for the user smithj, who has a home directory of\n\\\"/home/smithj\\\" and is a member of the users group.\n\n# chgrp users /home/smithj/<file>\"\n  tag \"fix_id\": \"F-78377r1_fix\"\n\n  ignore_shells = non_interactive_shells.join('|')\n\n  uid_min = login_defs.read_params['UID_MIN'].to_i\n  uid_min = 1000 if uid_min.nil?\n\n  findings = Set[]\n  users.where{ !shell.match(ignore_shells) && (uid >= uid_min || uid == 0)}.entries.each do |user_info|\n    next if exempt_home_users.include?(\"#{user_info.username}\")\n    find_args = \"\"\n    user_info.groups.each { |curr_group|\n      # some key files and secure dirs (like .ssh) are group owned 'root'\n      find_args = find_args + \"-not -group #{curr_group} -o root\"\n    }\n    findings = findings + command(\"find #{user_info.home} -xdev -xautofs #{find_args}\").stdout.split(\"\\n\")\n  end\n  describe \"Home directory files with incorrect group ownership or not 'root' owned\" do\n    subject { findings.to_a }\n    it { should be_empty }\n  end\nend\n",
          "source_location": {
            "line": 16,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72025.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Home directory files with incorrect group ownership or not 'root' owned should be empty",
              "run_time": 0.000131479,
              "start_time": "2019-11-04T16:17:13-05:00"
            }
          ]
        },
        {
          "id": "V-72027",
          "title": "All files and directories contained in local interactive user home\ndirectories must have mode 0750 or less permissive.",
          "desc": "If a local interactive user files have excessive permissions,\nunintended users may be able to access or modify them.",
          "descriptions": [
            {
              "label": "default",
              "data": "If a local interactive user files have excessive permissions,\nunintended users may be able to access or modify them."
            },
            {
              "label": "check",
              "data": "Verify all files and directories contained in a local\ninteractive user home directory, excluding local initialization files, have a\nmode of \"0750\".\n\nCheck the mode of all non-initialization files in a local interactive user home\ndirectory with the following command:\n\nFiles that begin with a \".\" are excluded from this requirement.\n\nNote: The example will be for the user \"smithj\", who has a home directory of\n\"/home/smithj\".\n\n# ls -lLR /home/smithj\n-rwxr-x--- 1 smithj smithj  18 Mar  5 17:06 file1\n-rwxr----- 1 smithj smithj 193 Mar  5 17:06 file2\n-rw-r-x--- 1 smithj smithj 231 Mar  5 17:06 file3\n\nIf any files are found with a mode more permissive than \"0750\", this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Set the mode on files and directories in the local interactive\nuser home directory with the following command:\n\nNote: The example will be for the user smithj, who has a home directory of\n\"/home/smithj\" and is a member of the users group.\n\n# chmod 0750 /home/smithj/<file>"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72027",
            "rid": "SV-86651r1_rule",
            "stig_id": "RHEL-07-020680",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "home_dirs"
            ],
            "fix_id": "F-78379r1_fix"
          },
          "code": "control \"V-72027\" do\n  title \"All files and directories contained in local interactive user home\ndirectories must have mode 0750 or less permissive.\"\n  desc  \"If a local interactive user files have excessive permissions,\nunintended users may be able to access or modify them.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72027\"\n  tag \"rid\": \"SV-86651r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020680\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['home_dirs']\n  desc \"check\", \"Verify all files and directories contained in a local\ninteractive user home directory, excluding local initialization files, have a\nmode of \\\"0750\\\".\n\nCheck the mode of all non-initialization files in a local interactive user home\ndirectory with the following command:\n\nFiles that begin with a \\\".\\\" are excluded from this requirement.\n\nNote: The example will be for the user \\\"smithj\\\", who has a home directory of\n\\\"/home/smithj\\\".\n\n# ls -lLR /home/smithj\n-rwxr-x--- 1 smithj smithj  18 Mar  5 17:06 file1\n-rwxr----- 1 smithj smithj 193 Mar  5 17:06 file2\n-rw-r-x--- 1 smithj smithj 231 Mar  5 17:06 file3\n\nIf any files are found with a mode more permissive than \\\"0750\\\", this is a\nfinding.\"\n  desc \"fix\", \"Set the mode on files and directories in the local interactive\nuser home directory with the following command:\n\nNote: The example will be for the user smithj, who has a home directory of\n\\\"/home/smithj\\\" and is a member of the users group.\n\n# chmod 0750 /home/smithj/<file>\"\n  tag \"fix_id\": \"F-78379r1_fix\"\n\n  ignore_shells = non_interactive_shells.join('|')\n\n  findings = Set[]\n\n allowed_users = %w(user1 user2 user3)\n\nusers.where { uid > 1000 && uid < 65534 }.usernames.sort.each do |u|\n  describe user(u) do\n    if allowed_users.include?(u)\n      it { should exist }\n    else\n      it { should_not exist }\n    end\n  end\nend\n\n  #describe users.where{ }.entries.each do |user_info| \n  #users.where{ !shell.match(ignore_shells) && (uid >= 1000 || uid == 0)}.entries.each do |user_info|\n  #  next if exempt_home_users.include?(\"#{user_info.username}\")\n  #  findings = findings + command(\"find #{user_info.home} -xdev ! -name '.*' -perm /027 ! -type l\").stdout.split(\"\\n\")\n  #end\n  describe \"Home directories with excessive permissions\" do\n    subject { findings.to_a }\n    it { should be_empty }\n  end\nend\n",
          "source_location": {
            "line": 16,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72027.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Home directories with excessive permissions should be empty",
              "run_time": 0.000140518,
              "start_time": "2019-11-04T16:17:13-05:00"
            }
          ]
        },
        {
          "id": "V-72029",
          "title": "All local initialization files for interactive users must be owned by\nthe home directory user or root.",
          "desc": "Local initialization files are used to configure the user's shell\nenvironment upon logon. Malicious modification of these files could compromise\naccounts upon logon.",
          "descriptions": [
            {
              "label": "default",
              "data": "Local initialization files are used to configure the user's shell\nenvironment upon logon. Malicious modification of these files could compromise\naccounts upon logon."
            },
            {
              "label": "check",
              "data": "Verify all local initialization files for interactive users are\nowned by the home directory user or root.\n\nCheck the owner on all local initialization files with the following command:\n\nNote: The example will be for the \"smithj\" user, who has a home directory of\n\"/home/smithj\".\n\n# ls -al /home/smithj/.* | more\n-rwxr-xr-x  1 smithj users        896 Mar 10  2011 .bash_profile\n-rwxr-xr-x  1 smithj users        497 Jan  6  2007 .login\n-rwxr-xr-x  1 smithj users        886 Jan  6  2007 .profile\n\nIf any file that sets a local interactive user’s environment variables to\noverride the system is not owned by the home directory owner or root, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Set the owner of the local initialization files for interactive\nusers to either the directory owner or root with the following command:\n\nNote: The example will be for the smithj user, who has a home directory of\n\"/home/smithj\".\n\n# chown smithj /home/smithj/.*"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72029",
            "rid": "SV-86653r1_rule",
            "stig_id": "RHEL-07-020690",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "init_files"
            ],
            "fix_id": "F-78381r1_fix"
          },
          "code": "control \"V-72029\" do\n  title \"All local initialization files for interactive users must be owned by\nthe home directory user or root.\"\n  desc  \"Local initialization files are used to configure the user's shell\nenvironment upon logon. Malicious modification of these files could compromise\naccounts upon logon.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72029\"\n  tag \"rid\": \"SV-86653r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020690\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['init_files']\n  desc \"check\", \"Verify all local initialization files for interactive users are\nowned by the home directory user or root.\n\nCheck the owner on all local initialization files with the following command:\n\nNote: The example will be for the \\\"smithj\\\" user, who has a home directory of\n\\\"/home/smithj\\\".\n\n# ls -al /home/smithj/.* | more\n-rwxr-xr-x  1 smithj users        896 Mar 10  2011 .bash_profile\n-rwxr-xr-x  1 smithj users        497 Jan  6  2007 .login\n-rwxr-xr-x  1 smithj users        886 Jan  6  2007 .profile\n\nIf any file that sets a local interactive user’s environment variables to\noverride the system is not owned by the home directory owner or root, this is a\nfinding.\"\n  desc \"fix\", \"Set the owner of the local initialization files for interactive\nusers to either the directory owner or root with the following command:\n\nNote: The example will be for the smithj user, who has a home directory of\n\\\"/home/smithj\\\".\n\n# chown smithj /home/smithj/.*\"\n  tag \"fix_id\": \"F-78381r1_fix\"\n\n  ignore_shells = non_interactive_shells.join('|')\n\n  findings = Set[]\n  users.where{ !shell.match(ignore_shells) && (uid >= 1000 || uid == 0)}.entries.each do |user_info|\n    next if exempt_home_users.include?(\"#{user_info.username}\")\n    findings = findings + command(\"find #{user_info.home} -name '.*' -not -user #{user_info.username} -a -not -user root\").stdout.split(\"\\n\")\n  end\n  describe \"Files and Directories not owned by the user or root of the parent home directory\" do\n    subject { findings.to_a }\n    it { should be_empty }\n  end\nend\n",
          "source_location": {
            "line": 16,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72029.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Files and Directories not owned by the user or root of the parent home directory should be empty",
              "run_time": 0.000120488,
              "start_time": "2019-11-04T16:17:13-05:00"
            }
          ]
        },
        {
          "id": "V-72031",
          "title": "Local initialization files for local interactive users must be\ngroup-owned by the users primary group or root.",
          "desc": "Local initialization files for interactive users are used to configure\nthe user's shell environment upon logon. Malicious modification of these files\ncould compromise accounts upon logon.",
          "descriptions": [
            {
              "label": "default",
              "data": "Local initialization files for interactive users are used to configure\nthe user's shell environment upon logon. Malicious modification of these files\ncould compromise accounts upon logon."
            },
            {
              "label": "check",
              "data": "Verify the local initialization files of all local interactive\nusers are group-owned by that user’s primary Group Identifier (GID).\n\nCheck the home directory assignment for all non-privileged users on the system\nwith the following command:\n\nNote: The example will be for the smithj user, who has a home directory of\n\"/home/smithj\" and a primary group of \"users\".\n\n# cut -d: -f 1,4,6 /etc/passwd | egrep \":[1-4][0-9]{3}\"\nsmithj:1000:/home/smithj\n\n# grep 1000 /etc/group\nusers:x:1000:smithj,jonesj,jacksons\n\nNote: This may miss interactive users that have been assigned a privileged User\nIdentifier (UID). Evidence of interactive use may be obtained from a number of\nlog files containing system logon information.\n\nCheck the group owner of all local interactive users’ initialization files with\nthe following command:\n\n# ls -al /home/smithj/.*\n-rwxr-xr-x  1 smithj users        896 Mar 10  2011 .profile\n-rwxr-xr-x  1 smithj users        497 Jan  6  2007 .login\n-rwxr-xr-x  1 smithj users        886 Jan  6  2007 .something\n\nIf all local interactive users’ initialization files are not group-owned by\nthat user’s primary GID, this is a finding."
            },
            {
              "label": "fix",
              "data": "Change the group owner of a local interactive user’s files to the\ngroup found in \"/etc/passwd\" for the user. To change the group owner of a\nlocal interactive user home directory, use the following command:\n\nNote: The example will be for the user smithj, who has a home directory of\n\"/home/smithj\", and has a primary group of users.\n\n# chgrp users /home/smithj/<file>"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72031",
            "rid": "SV-86655r2_rule",
            "stig_id": "RHEL-07-020700",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "init_files"
            ],
            "fix_id": "F-78383r1_fix"
          },
          "code": "control \"V-72031\" do\n  title \"Local initialization files for local interactive users must be\ngroup-owned by the users primary group or root.\"\n  desc  \"Local initialization files for interactive users are used to configure\nthe user's shell environment upon logon. Malicious modification of these files\ncould compromise accounts upon logon.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72031\"\n  tag \"rid\": \"SV-86655r2_rule\"\n  tag \"stig_id\": \"RHEL-07-020700\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['init_files']\n  desc \"check\", \"Verify the local initialization files of all local interactive\nusers are group-owned by that user’s primary Group Identifier (GID).\n\nCheck the home directory assignment for all non-privileged users on the system\nwith the following command:\n\nNote: The example will be for the smithj user, who has a home directory of\n\\\"/home/smithj\\\" and a primary group of \\\"users\\\".\n\n# cut -d: -f 1,4,6 /etc/passwd | egrep \\\":[1-4][0-9]{3}\\\"\nsmithj:1000:/home/smithj\n\n# grep 1000 /etc/group\nusers:x:1000:smithj,jonesj,jacksons\n\nNote: This may miss interactive users that have been assigned a privileged User\nIdentifier (UID). Evidence of interactive use may be obtained from a number of\nlog files containing system logon information.\n\nCheck the group owner of all local interactive users’ initialization files with\nthe following command:\n\n# ls -al /home/smithj/.*\n-rwxr-xr-x  1 smithj users        896 Mar 10  2011 .profile\n-rwxr-xr-x  1 smithj users        497 Jan  6  2007 .login\n-rwxr-xr-x  1 smithj users        886 Jan  6  2007 .something\n\nIf all local interactive users’ initialization files are not group-owned by\nthat user’s primary GID, this is a finding.\"\n  desc \"fix\", \"Change the group owner of a local interactive user’s files to the\ngroup found in \\\"/etc/passwd\\\" for the user. To change the group owner of a\nlocal interactive user home directory, use the following command:\n\nNote: The example will be for the user smithj, who has a home directory of\n\\\"/home/smithj\\\", and has a primary group of users.\n\n# chgrp users /home/smithj/<file>\"\n  tag \"fix_id\": \"F-78383r1_fix\"\n\n  ignore_shells = non_interactive_shells.join('|')\n\n  findings = Set[]\n  users.where{ !shell.match(ignore_shells) && (uid >= 1000 || uid == 0)}.entries.each do |user_info|\n    findings = findings + command(\"find #{user_info.home} -name '.*' -not -gid #{user_info.gid} -not -group root\").stdout.split(\"\\n\")\n  end\n  describe findings do\n    its('length') { should == 0 }\n  end\nend\n",
          "source_location": {
            "line": 16,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72031.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "#<Set: {}> length should == 0",
              "run_time": 0.01141217,
              "start_time": "2019-11-04T16:17:13-05:00"
            }
          ]
        },
        {
          "id": "V-72033",
          "title": "All local initialization files must have mode 0740 or less permissive.",
          "desc": "Local initialization files are used to configure the user's shell\nenvironment upon logon. Malicious modification of these files could compromise\naccounts upon logon.",
          "descriptions": [
            {
              "label": "default",
              "data": "Local initialization files are used to configure the user's shell\nenvironment upon logon. Malicious modification of these files could compromise\naccounts upon logon."
            },
            {
              "label": "check",
              "data": "Verify that all local initialization files have a mode of\n\"0740\" or less permissive.\n\nCheck the mode on all local initialization files with the following command:\n\nNote: The example will be for the smithj user, who has a home directory of\n\"/home/smithj\".\n\n# ls -al /home/smithj/.* | more\n-rwxr-xr-x  1 smithj users        896 Mar 10  2011 .profile\n-rwxr-xr-x  1 smithj users        497 Jan  6  2007 .login\n-rwxr-xr-x  1 smithj users        886 Jan  6  2007 .something\n\nIf any local initialization files have a mode more permissive than \"0740\",\nthis is a finding."
            },
            {
              "label": "fix",
              "data": "Set the mode of the local initialization files to \"0740\" with\nthe following command:\n\nNote: The example will be for the smithj user, who has a home directory of\n\"/home/smithj\".\n\n# chmod 0740 /home/smithj/.<INIT_FILE>"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72033",
            "rid": "SV-86657r1_rule",
            "stig_id": "RHEL-07-020710",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "init_files"
            ],
            "fix_id": "F-78385r1_fix"
          },
          "code": "control \"V-72033\" do\n  title \"All local initialization files must have mode 0740 or less permissive.\"\n  desc  \"Local initialization files are used to configure the user's shell\nenvironment upon logon. Malicious modification of these files could compromise\naccounts upon logon.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72033\"\n  tag \"rid\": \"SV-86657r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020710\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['init_files']\n  desc \"check\", \"Verify that all local initialization files have a mode of\n\\\"0740\\\" or less permissive.\n\nCheck the mode on all local initialization files with the following command:\n\nNote: The example will be for the smithj user, who has a home directory of\n\\\"/home/smithj\\\".\n\n# ls -al /home/smithj/.* | more\n-rwxr-xr-x  1 smithj users        896 Mar 10  2011 .profile\n-rwxr-xr-x  1 smithj users        497 Jan  6  2007 .login\n-rwxr-xr-x  1 smithj users        886 Jan  6  2007 .something\n\nIf any local initialization files have a mode more permissive than \\\"0740\\\",\nthis is a finding.\"\n  desc \"fix\", \"Set the mode of the local initialization files to \\\"0740\\\" with\nthe following command:\n\nNote: The example will be for the smithj user, who has a home directory of\n\\\"/home/smithj\\\".\n\n# chmod 0740 /home/smithj/.<INIT_FILE>\"\n  tag \"fix_id\": \"F-78385r1_fix\"\n\n  ignore_shells = non_interactive_shells.join('|')\n\n  findings = Set[]\n  users.where{ !shell.match(ignore_shells) && (uid >= 1000 || uid == 0)}.entries.each do |user_info|\n    findings = findings + command(\"find #{user_info.home} -xdev -maxdepth 1 -name '.*' -type f -perm /037\").stdout.split(\"\\n\")\n  end\n  describe findings do\n    it { should be_empty }\n  end\nend\n",
          "source_location": {
            "line": 16,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72033.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "#<Set: {\"/root/.bash_logout\", \"/root/.bash_profile\", \"/root/.bashrc\", \"/root/.cshrc\", \"/root/.tcshrc\", \"/home/dhaynes/.bash_logout\", \"/home/dhaynes/.bash_profile\", \"/home/dhaynes/.bashrc\"}> should be empty",
              "run_time": 0.000812351,
              "start_time": "2019-11-04T16:17:13-05:00",
              "message": "expected `#<Set: {\"/root/.bash_logout\", \"/root/.bash_profile\", \"/root/.bashrc\", \"/root/.cshrc\", \"/root/.tcshrc\", \"/home/dhaynes/.bash_logout\", \"/home/dhaynes/.bash_profile\", \"/home/dhaynes/.bashrc\"}>.empty?` to return true, got false"
            }
          ]
        },
        {
          "id": "V-72035",
          "title": "All local interactive user initialization files executable search\npaths must contain only paths that resolve to the users home directory.",
          "desc": "The executable search path (typically the PATH environment variable)\ncontains a list of directories for the shell to search to find executables. If\nthis path includes the current working directory (other than the user’s home\ndirectory), executables in these directories may be executed instead of system\ncommands. This variable is formatted as a colon-separated list of directories.\nIf there is an empty entry, such as a leading or trailing colon or two\nconsecutive colons, this is interpreted as the current working directory. If\ndeviations from the default system search path for the local interactive user\nare required, they must be documented with the Information System Security\nOfficer (ISSO).",
          "descriptions": [
            {
              "label": "default",
              "data": "The executable search path (typically the PATH environment variable)\ncontains a list of directories for the shell to search to find executables. If\nthis path includes the current working directory (other than the user’s home\ndirectory), executables in these directories may be executed instead of system\ncommands. This variable is formatted as a colon-separated list of directories.\nIf there is an empty entry, such as a leading or trailing colon or two\nconsecutive colons, this is interpreted as the current working directory. If\ndeviations from the default system search path for the local interactive user\nare required, they must be documented with the Information System Security\nOfficer (ISSO)."
            },
            {
              "label": "check",
              "data": "Verify that all local interactive user initialization files'\nexecutable search path statements do not contain statements that will reference\na working directory other than the users’ home directory.\n\nCheck the executable search path statement for all local interactive user\ninitialization files in the users' home directory with the following commands:\n\nNote: The example will be for the smithj user, which has a home directory of\n\"/home/smithj\".\n\n# grep -i path /home/smithj/.*\n/home/smithj/.bash_profile:PATH=$PATH:$HOME/.local/bin:$HOME/bin\n/home/smithj/.bash_profile:export PATH\n\nIf any local interactive user initialization files have executable search path\nstatements that include directories outside of their home directory, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Edit the local interactive user initialization files to change\nany PATH variable statements that reference directories other than their home\ndirectory.\n\nIf a local interactive user requires path variables to reference a directory\nowned by the application, it must be documented with the ISSO."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72035",
            "rid": "SV-86659r3_rule",
            "stig_id": "RHEL-07-020720",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "init_files"
            ],
            "fix_id": "F-78387r3_fix"
          },
          "code": "control \"V-72035\" do\n  title \"All local interactive user initialization files executable search\npaths must contain only paths that resolve to the users home directory.\"\n  desc  \"The executable search path (typically the PATH environment variable)\ncontains a list of directories for the shell to search to find executables. If\nthis path includes the current working directory (other than the user’s home\ndirectory), executables in these directories may be executed instead of system\ncommands. This variable is formatted as a colon-separated list of directories.\nIf there is an empty entry, such as a leading or trailing colon or two\nconsecutive colons, this is interpreted as the current working directory. If\ndeviations from the default system search path for the local interactive user\nare required, they must be documented with the Information System Security\nOfficer (ISSO).\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72035\"\n  tag \"rid\": \"SV-86659r3_rule\"\n  tag \"stig_id\": \"RHEL-07-020720\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['init_files']\n  desc \"check\", \"Verify that all local interactive user initialization files'\nexecutable search path statements do not contain statements that will reference\na working directory other than the users’ home directory.\n\nCheck the executable search path statement for all local interactive user\ninitialization files in the users' home directory with the following commands:\n\nNote: The example will be for the smithj user, which has a home directory of\n\\\"/home/smithj\\\".\n\n# grep -i path /home/smithj/.*\n/home/smithj/.bash_profile:PATH=$PATH:$HOME/.local/bin:$HOME/bin\n/home/smithj/.bash_profile:export PATH\n\nIf any local interactive user initialization files have executable search path\nstatements that include directories outside of their home directory, this is a\nfinding.\"\n  desc \"fix\", \"Edit the local interactive user initialization files to change\nany PATH variable statements that reference directories other than their home\ndirectory.\n\nIf a local interactive user requires path variables to reference a directory\nowned by the application, it must be documented with the ISSO. \"\n  tag \"fix_id\": \"F-78387r3_fix\"\n  ignore_shells = non_interactive_shells.join('|')\n\n  findings = Set[]\n  users.where{ !shell.match(ignore_shells) && (uid >= 1000 || uid == 0)}.entries.each do |user_info|\n    next if exempt_home_users.include?(\"#{user_info.username}\")\n    grep_results =  command(\"grep -i path --exclude=\\\".bash_history\\\" #{user_info.home}/.*\").stdout.split(\"\\\\n\")\n    grep_results.each do |result|\n      result.slice! \"PATH=\"\n      # Case when last value in exec search path is :\n      if result[-1] == \":\" then\n        result = result + \" \"\n      end\n      result.slice! \"$PATH:\"\n      result.gsub! '$HOME', \"#{user_info.home}\"\n      result.gsub! '~', \"#{user_info.home}\"\n      line_arr = result.split(\":\")\n      line_arr.delete_at(0)\n      line_arr.each do |line|\n        # Don't run test on line that exports PATH and is not commented out\n        if !line.start_with?('export') && !line.start_with?('#') then\n          # Case when :: found in exec search path or : found at beginning\n          if line.strip.empty? then\n            curr_work_dir = command(\"pwd\").stdout.gsub(\"\\n\", \"\")\n            if curr_work_dir.start_with?(\"#{user_info.home}\") then\n              line = curr_work_dir\n            end\n          end\n          # This will fail if non-home directory found in path\n          if !line.start_with?(user_info.home)\n            findings.add(line)\n          end\n        end\n      end\n    end\n  end\n  describe.one do\n    describe etc_fstab do\n      its('home_mount_options') { should include 'nosuid' }\n    end\n    describe \"Initialization files that include executable search paths that include directories outside their home directories\" do\n      subject { findings.to_a }\n      it { should be_empty }\n    end\n  end\nend\n",
          "source_location": {
            "line": 16,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72035.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Initialization files that include executable search paths that include directories outside their home directories should be empty",
              "run_time": 0.000177857,
              "start_time": "2019-11-04T16:17:13-05:00"
            }
          ]
        },
        {
          "id": "V-72037",
          "title": "The Red Hat Enterprise Linux operating system must be configured so\n that local initialization files do not execute world-writable programs.",
          "desc": "If user start-up files execute world-writable programs, especially in\nunprotected directories, they could be maliciously modified to destroy user\nfiles or otherwise compromise the system at the user level. If the system is\ncompromised at the user level, it is easier to elevate privileges to eventually\ncompromise the system at the root and network level.",
          "descriptions": [
            {
              "label": "default",
              "data": "If user start-up files execute world-writable programs, especially in\nunprotected directories, they could be maliciously modified to destroy user\nfiles or otherwise compromise the system at the user level. If the system is\ncompromised at the user level, it is easier to elevate privileges to eventually\ncompromise the system at the root and network level."
            },
            {
              "label": "check",
              "data": "Verify that local initialization files do not execute\nworld-writable programs.\n\nCheck the system for world-writable files with the following command:\n\n# find / -xdev -perm -002 -type f -exec ls -ld {} \\; | more\n\nFor all files listed, check for their presence in the local initialization\nfiles with the following commands:\n\nNote: The example will be for a system that is configured to create users' home\ndirectories in the \"/home\" directory.\n\n# grep <file> /home/*/.*\n\nIf any local initialization files are found to reference world-writable files,\nthis is a finding."
            },
            {
              "label": "fix",
              "data": "Set the mode on files being executed by the local initialization\nfiles with the following command:\n\n# chmod 0755  <file>"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72037",
            "rid": "SV-86661r1_rule",
            "stig_id": "RHEL-07-020730",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "init_files"
            ],
            "fix_id": "F-78389r1_fix"
          },
          "code": "control \"V-72037\" do\n    title \"The Red Hat Enterprise Linux operating system must be configured so\n that local initialization files do not execute world-writable programs.\"\n  if disable_slow_controls\n    desc \"This control consistently takes a long to run and has been disabled\n          using the disable_slow_controls attribute.\"\n  else\n  desc  \"If user start-up files execute world-writable programs, especially in\nunprotected directories, they could be maliciously modified to destroy user\nfiles or otherwise compromise the system at the user level. If the system is\ncompromised at the user level, it is easier to elevate privileges to eventually\ncompromise the system at the root and network level.\"\n  end\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72037\"\n  tag \"rid\": \"SV-86661r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020730\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['init_files']\n  desc \"check\", \"Verify that local initialization files do not execute\nworld-writable programs.\n\nCheck the system for world-writable files with the following command:\n\n# find / -xdev -perm -002 -type f -exec ls -ld {} \\\\; | more\n\nFor all files listed, check for their presence in the local initialization\nfiles with the following commands:\n\nNote: The example will be for a system that is configured to create users' home\ndirectories in the \\\"/home\\\" directory.\n\n# grep <file> /home/*/.*\n\nIf any local initialization files are found to reference world-writable files,\nthis is a finding.\"\n  desc \"fix\", \"Set the mode on files being executed by the local initialization\nfiles with the following command:\n\n# chmod 0755  <file>\"\n  tag \"fix_id\": \"F-78389r1_fix\"\n\n  if disable_slow_controls\n    describe \"This control consistently takes a long to run and has been disabled\n  using the disable_slow_controls attribute.\" do\n      skip \"This control consistently takes a long to run and has been disabled\n  using the disable_slow_controls attribute. You must enable this control for a\n  full accredidation for production.\"\n  end\n  else\n    ignore_shells = non_interactive_shells.join('|')\n\n    #Get home directory for users with UID >= 1000 or UID == 0 and support interactive logins.\n    dotfiles = Set[]\n    u = users.where{ !shell.match(ignore_shells) && (uid >= 1000 || uid == 0)}.entries\n    #For each user, build and execute a find command that identifies initialization files\n    #in a user's home directory.\n    u.each do |user|\n      dotfiles = dotfiles + command(\"find #{user.home} -xdev -maxdepth 2 ( -name '.*' ! -name '.bash_history' ) -type f\").stdout.split(\"\\n\")\n    end\n    ww_files = Set[]\n    ww_files = command('find / -xdev -perm -002 -type f -exec ls {} \\;').stdout.lines\n\n    #To reduce the number of commands ran, we use a pattern file in the grep command below\n    #So we don't have too long of a grep command, we chunk the list of ww_files\n    #into strings not longer than PATTERN_FILE_MAX_LENGTH\n    #Based on MAX_ARG_STRLEN, /usr/include/linux/binfmts.h\n    #We cut off 100 to leave room for the rest of the arguments\n    PATTERN_FILE_MAX_LENGTH=command(\"getconf PAGE_SIZE\").stdout.to_i * 32 - 100\n    ww_chunked=[\"\"]\n    ww_files.each do |item|\n      item = item.strip\n      if item.length + \"\\n\".length > PATTERN_FILE_MAX_LENGTH\n        raise \"Single pattern is longer than PATTERN_FILE_MAX_LENGTH\"\n      end\n      if ww_chunked[-1].length + \"\\n\".length + item.length > PATTERN_FILE_MAX_LENGTH\n        ww_chunked.append(\"\")\n      end\n      ww_chunked[-1] += \"\\n\" + item  # This will leave an extra newline at the beginning of chunks\n    end\n    ww_chunked = ww_chunked.map(&:strip)  # This gets rid of the beginning newlines\n    if ww_chunked[0] == \"\"\n      ww_chunked = []  # If we didn't have any ww_files, this will prevent an empty grep pattern\n    end\n\n    #Check each dotfile for existence of each world-writeable file\n    findings = Set[]\n    dotfiles.each do |dotfile|\n      dotfile = dotfile.strip\n      ww_chunked.each do |ww_pattern_file|\n        count = command(\"grep -c -f <(echo \\\"#{ww_pattern_file}\\\") \\\"#{dotfile}\\\"\").stdout.strip.to_i\n        findings << dotfile if count > 0\n      end\n    end\n    describe \"Local initialization files that are found to reference world-writable files\" do\n      subject { findings.to_a }\n      it { should be_empty }\n    end\n  end\nend\n",
          "source_location": {
            "line": 22,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72037.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Local initialization files that are found to reference world-writable files should be empty",
              "run_time": 0.000169838,
              "start_time": "2019-11-04T16:17:13-05:00"
            }
          ]
        },
        {
          "id": "V-72039",
          "title": "All system device files must be correctly labeled to prevent\nunauthorized modification.",
          "desc": "If an unauthorized or modified device is allowed to exist on the\nsystem, there is the possibility the system may perform unintended or\nunauthorized operations.",
          "descriptions": [
            {
              "label": "default",
              "data": "If an unauthorized or modified device is allowed to exist on the\nsystem, there is the possibility the system may perform unintended or\nunauthorized operations."
            },
            {
              "label": "check",
              "data": "Verify that all system device files are correctly labeled to\nprevent unauthorized modification.\n\nList all device files on the system that are incorrectly labeled with the\nfollowing commands:\n\nNote: Device files are normally found under \"/dev\", but applications may\nplace device files in other directories and may necessitate a search of the\nentire system.\n\n#find /dev -context *:device_t:* \\( -type c -o -type b \\) -printf \"%p %Z\n\"\n\n#find /dev -context *:unlabeled_t:* \\( -type c -o -type b \\) -printf \"%p %Z\n\n\"\n\nNote: There are device files, such as \"/dev/vmci\", that are used when the\noperating system is a host virtual machine. They will not be owned by a user on\nthe system and require the \"device_t\" label to operate. These device files\nare not a finding.\n\nIf there is output from either of these commands, other than already noted,\nthis is a finding."
            },
            {
              "label": "fix",
              "data": "Run the following command to determine which package owns the\ndevice file:\n\n# rpm -qf <filename>\n\nThe package can be reinstalled from a yum repository using the command:\n\n# sudo yum reinstall <packagename>\n\nAlternatively, the package can be reinstalled from trusted media using the\ncommand:\n\n# sudo rpm -Uvh <packagename>"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72039",
            "rid": "SV-86663r1_rule",
            "stig_id": "RHEL-07-020900",
            "cci": [
              "CCI-000318",
              "CCI-000368",
              "CCI-001812",
              "CCI-001813",
              "CCI-001814"
            ],
            "documentable": false,
            "subsystems": [
              "system_device",
              "device_files"
            ],
            "nist": [
              "CM-3 f",
              "CM-6 c",
              "CM-11 (2)",
              "CM-5 (1)",
              "CM-5 (1)",
              "Rev_4"
            ],
            "fix_id": "F-78391r1_fix",
            "dangerous": {
              "reason": "Uses global find command"
            }
          },
          "code": "control \"V-72039\" do\n  title \"All system device files must be correctly labeled to prevent\nunauthorized modification.\"\n  desc  \"If an unauthorized or modified device is allowed to exist on the\nsystem, there is the possibility the system may perform unintended or\nunauthorized operations.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72039\"\n  tag \"rid\": \"SV-86663r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020900\"\n  tag \"cci\": [\"CCI-000318\", \"CCI-000368\", \"CCI-001812\", \"CCI-001813\",\n\"CCI-001814\"]\n  tag \"documentable\": false\n    tag \"subsystems\": ['system_device', 'device_files']\n  tag \"nist\": [\"CM-3 f\", \"CM-6 c\", \"CM-11 (2)\", \"CM-5 (1)\", \"CM-5 (1)\", \"Rev_4\"]\n  desc \"check\", \"Verify that all system device files are correctly labeled to\nprevent unauthorized modification.\n\nList all device files on the system that are incorrectly labeled with the\nfollowing commands:\n\nNote: Device files are normally found under \\\"/dev\\\", but applications may\nplace device files in other directories and may necessitate a search of the\nentire system.\n\n#find /dev -context *:device_t:* \\\\( -type c -o -type b \\\\) -printf \\\"%p %Z\\n\\\"\n\n#find /dev -context *:unlabeled_t:* \\\\( -type c -o -type b \\\\) -printf \\\"%p %Z\\n\n\\\"\n\nNote: There are device files, such as \\\"/dev/vmci\\\", that are used when the\noperating system is a host virtual machine. They will not be owned by a user on\nthe system and require the \\\"device_t\\\" label to operate. These device files\nare not a finding.\n\nIf there is output from either of these commands, other than already noted,\nthis is a finding.\"\n  desc \"fix\", \"Run the following command to determine which package owns the\ndevice file:\n\n# rpm -qf <filename>\n\nThe package can be reinstalled from a yum repository using the command:\n\n# sudo yum reinstall <packagename>\n\nAlternatively, the package can be reinstalled from trusted media using the\ncommand:\n\n# sudo rpm -Uvh <packagename>\"\n\n  tag \"fix_id\": \"F-78391r1_fix\"\n  \n  tag \"dangerous\": { :reason => \"Uses global find command\" }\n\n  findings = Set[]\n  findings = findings + command('find / -context *:device_t:* \\( -type c -o -type b \\) -printf \"%p %Z\\n\"').stdout.split(\"\\n\")\n  findings = findings + command('find / -context *:unlabeled_t:* \\( -type c -o -type b \\) -printf \"%p %Z\\n\"').stdout.split(\"\\n\")\n  findings = findings + command('find / -context *:vmci_device_t:* \\( -type c -o -type b \\) -printf \"%p %Z\\n\"').stdout.split(\"\\n\")\n\n  describe findings do\n    if virtual_machine\n      its ('length') { should cmp 1 }\n      its ('first') { should include '/dev/vmci' }\n    else\n      its ('length') { should cmp 0 }\n    end\n  end\nend\n",
          "source_location": {
            "line": 9,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72039.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "#<Set: {}> length should cmp == 0",
              "run_time": 0.000367933,
              "start_time": "2019-11-04T16:17:13-05:00"
            }
          ]
        },
        {
          "id": "V-72041",
          "title": "File systems that contain user home directories must be mounted to\nprevent files with the setuid and setgid bit set from being executed.",
          "desc": "The \"nosuid\" mount option causes the system to not execute setuid\nand setgid files with owner privileges. This option must be used for mounting\nany file system not containing approved setuid and setguid files. Executing\nfiles from untrusted file systems increases the opportunity for unprivileged\nusers to attain unauthorized administrative access.",
          "descriptions": [
            {
              "label": "default",
              "data": "The \"nosuid\" mount option causes the system to not execute setuid\nand setgid files with owner privileges. This option must be used for mounting\nany file system not containing approved setuid and setguid files. Executing\nfiles from untrusted file systems increases the opportunity for unprivileged\nusers to attain unauthorized administrative access."
            },
            {
              "label": "check",
              "data": "Verify file systems that contain user home directories are\nmounted with the \"nosuid\" option.\n\nFind the file system(s) that contain the user home directories with the\nfollowing command:\n\nNote: If a separate file system has not been created for the user home\ndirectories (user home directories are mounted under \"/\"), this is not a\nfinding as the \"nosuid\" option cannot be used on the \"/\" system.\n\n# cut -d: -f 1,3,6 /etc/passwd | egrep \":[1-4][0-9]{3}\"\nsmithj:1001:/home/smithj\nthomasr:1002:/home/thomasr\n\nCheck the file systems that are mounted at boot time with the following command:\n\n# more /etc/fstab\n\nUUID=a411dc99-f2a1-4c87-9e05-184977be8539 /home   ext4\nrw,relatime,discard,data=ordered,nosuid 0 2\n\nIf a file system found in \"/etc/fstab\" refers to the user home directory file\nsystem and it does not have the \"nosuid\" option set, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the \"/etc/fstab\" to use the \"nosuid\" option on file\nsystems that contain user home directories."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72041",
            "rid": "SV-86665r3_rule",
            "stig_id": "RHEL-07-021000",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "home_dirs",
              "file_system"
            ],
            "fix_id": "F-78393r2_fix"
          },
          "code": "control \"V-72041\" do\n  title \"File systems that contain user home directories must be mounted to\nprevent files with the setuid and setgid bit set from being executed.\"\n  desc  \"The \\\"nosuid\\\" mount option causes the system to not execute setuid\nand setgid files with owner privileges. This option must be used for mounting\nany file system not containing approved setuid and setguid files. Executing\nfiles from untrusted file systems increases the opportunity for unprivileged\nusers to attain unauthorized administrative access.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72041\"\n  tag \"rid\": \"SV-86665r3_rule\"\n  tag \"stig_id\": \"RHEL-07-021000\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['home_dirs', 'file_system']\n  desc \"check\", \"Verify file systems that contain user home directories are\nmounted with the \\\"nosuid\\\" option.\n\nFind the file system(s) that contain the user home directories with the\nfollowing command:\n\nNote: If a separate file system has not been created for the user home\ndirectories (user home directories are mounted under \\\"/\\\"), this is not a\nfinding as the \\\"nosuid\\\" option cannot be used on the \\\"/\\\" system.\n\n# cut -d: -f 1,3,6 /etc/passwd | egrep \\\":[1-4][0-9]{3}\\\"\nsmithj:1001:/home/smithj\nthomasr:1002:/home/thomasr\n\nCheck the file systems that are mounted at boot time with the following command:\n\n# more /etc/fstab\n\nUUID=a411dc99-f2a1-4c87-9e05-184977be8539 /home   ext4\nrw,relatime,discard,data=ordered,nosuid 0 2\n\nIf a file system found in \\\"/etc/fstab\\\" refers to the user home directory file\nsystem and it does not have the \\\"nosuid\\\" option set, this is a finding.\"\n  desc \"fix\", \"Configure the \\\"/etc/fstab\\\" to use the \\\"nosuid\\\" option on file\nsystems that contain user home directories.\"\n  tag \"fix_id\": \"F-78393r2_fix\"\n\n  # Assumption - users' home directories created in \"home\"\n  describe mount('/home') do\n    its('options') { should include 'nosuid' }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72041.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Mount /home options should include \"nosuid\"",
              "run_time": 0.028659638,
              "start_time": "2019-11-04T16:17:13-05:00",
              "message": "expected nil to include \"nosuid\", but it does not respond to `include?`"
            }
          ]
        },
        {
          "id": "V-72043",
          "title": "File systems that are used with removable media must be mounted to\nprevent files with the setuid and setgid bit set from being executed.",
          "desc": "The \"nosuid\" mount option causes the system to not execute\n\"setuid\" and \"setgid\" files with owner privileges. This option must be used\nfor mounting any file system not containing approved \"setuid\" and \"setguid\"\nfiles. Executing files from untrusted file systems increases the opportunity\nfor unprivileged users to attain unauthorized administrative access.",
          "descriptions": [
            {
              "label": "default",
              "data": "The \"nosuid\" mount option causes the system to not execute\n\"setuid\" and \"setgid\" files with owner privileges. This option must be used\nfor mounting any file system not containing approved \"setuid\" and \"setguid\"\nfiles. Executing files from untrusted file systems increases the opportunity\nfor unprivileged users to attain unauthorized administrative access."
            },
            {
              "label": "check",
              "data": "Verify file systems that are used for removable media are\nmounted with the \"nouid\" option.\n\nCheck the file systems that are mounted at boot time with the following command:\n\n# more /etc/fstab\n\nUUID=2bc871e4-e2a3-4f29-9ece-3be60c835222     /mnt/usbflash      vfat\nnoauto,owner,ro,nosuid                        0 0\n\nIf a file system found in \"/etc/fstab\" refers to removable media and it does\nnot have the \"nosuid\" option set, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the \"/etc/fstab\" to use the \"nosuid\" option on file\nsystems that are associated with removable media."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72043",
            "rid": "SV-86667r1_rule",
            "stig_id": "RHEL-07-021010",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "file_system",
              "removable_media"
            ],
            "fix_id": "F-78395r1_fix"
          },
          "code": "control \"V-72043\" do\n  title \"File systems that are used with removable media must be mounted to\nprevent files with the setuid and setgid bit set from being executed.\"\n  desc  \"The \\\"nosuid\\\" mount option causes the system to not execute\n\\\"setuid\\\" and \\\"setgid\\\" files with owner privileges. This option must be used\nfor mounting any file system not containing approved \\\"setuid\\\" and \\\"setguid\\\"\nfiles. Executing files from untrusted file systems increases the opportunity\nfor unprivileged users to attain unauthorized administrative access.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72043\"\n  tag \"rid\": \"SV-86667r1_rule\"\n  tag \"stig_id\": \"RHEL-07-021010\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['file_system', 'removable_media']\n  desc \"check\", \"Verify file systems that are used for removable media are\nmounted with the \\\"nouid\\\" option.\n\nCheck the file systems that are mounted at boot time with the following command:\n\n# more /etc/fstab\n\nUUID=2bc871e4-e2a3-4f29-9ece-3be60c835222     /mnt/usbflash      vfat\nnoauto,owner,ro,nosuid                        0 0\n\nIf a file system found in \\\"/etc/fstab\\\" refers to removable media and it does\nnot have the \\\"nosuid\\\" option set, this is a finding.\"\n  desc \"fix\", \"Configure the \\\"/etc/fstab\\\" to use the \\\"nosuid\\\" option on file\nsystems that are associated with removable media.\"\n  tag \"fix_id\": \"F-78395r1_fix\"\n\n  file_systems = etc_fstab.params\n  if !file_systems.nil? and !file_systems.empty?\n    file_systems.each do |file_sys_line|\n      if !\"#{non_removable_media_fs}\".include?(file_sys_line['file_system_type']) then\n        describe file_sys_line['mount_options'] do\n          it { should include 'nosuid' }\n        end\n      else\n        describe \"File system \\\"#{file_sys_line['file_system_type']}\\\" does not correspond to removable media.\" do\n          subject { \"#{non_removable_media_fs}\".include?(file_sys_line['file_system_type']) }\n          it { should eq true }\n        end\n      end\n    end\n  else\n    describe \"No file systems were found.\" do\n      subject { file_systems.nil? }\n      it { should eq true }\n    end\n  end\nend\n",
          "source_location": {
            "line": 10,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72043.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "File system \"xfs\" does not correspond to removable media. should eq true",
              "run_time": 0.000293025,
              "start_time": "2019-11-04T16:17:13-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File system \"xfs\" does not correspond to removable media. should eq true",
              "run_time": 0.000168776,
              "start_time": "2019-11-04T16:17:13-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File system \"swap\" does not correspond to removable media. should eq true",
              "run_time": 0.000149351,
              "start_time": "2019-11-04T16:17:13-05:00"
            }
          ]
        },
        {
          "id": "V-72045",
          "title": "File systems that are being imported via Network File System (NFS)\nmust be mounted to prevent files with the setuid and setgid bit set from being\nexecuted.",
          "desc": "The \"nosuid\" mount option causes the system to not execute\n\"setuid\" and \"setgid\" files with owner privileges. This option must be used\nfor mounting any file system not containing approved \"setuid\" and \"setguid\"\nfiles. Executing files from untrusted file systems increases the opportunity\nfor unprivileged users to attain unauthorized administrative access.",
          "descriptions": [
            {
              "label": "default",
              "data": "The \"nosuid\" mount option causes the system to not execute\n\"setuid\" and \"setgid\" files with owner privileges. This option must be used\nfor mounting any file system not containing approved \"setuid\" and \"setguid\"\nfiles. Executing files from untrusted file systems increases the opportunity\nfor unprivileged users to attain unauthorized administrative access."
            },
            {
              "label": "check",
              "data": "Verify file systems that are being NFS exported are mounted\nwith the \"nosuid\" option.\n\nFind the file system(s) that contain the directories being exported with the\nfollowing command:\n\n# more /etc/fstab | grep nfs\n\nUUID=e06097bb-cfcd-437b-9e4d-a691f5662a7d    /store           nfs\nrw,nosuid                                                    0 0\n\nIf a file system found in \"/etc/fstab\" refers to NFS and it does not have the\n\"nosuid\" option set, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the \"/etc/fstab\" to use the \"nosuid\" option on file\nsystems that are being exported via NFS."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72045",
            "rid": "SV-86669r1_rule",
            "stig_id": "RHEL-07-021020",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystem": [
              "nfs",
              "file_system"
            ],
            "fix_id": "F-78397r1_fix"
          },
          "code": "control \"V-72045\" do\n  title \"File systems that are being imported via Network File System (NFS)\nmust be mounted to prevent files with the setuid and setgid bit set from being\nexecuted.\"\n  desc  \"The \\\"nosuid\\\" mount option causes the system to not execute\n\\\"setuid\\\" and \\\"setgid\\\" files with owner privileges. This option must be used\nfor mounting any file system not containing approved \\\"setuid\\\" and \\\"setguid\\\"\nfiles. Executing files from untrusted file systems increases the opportunity\nfor unprivileged users to attain unauthorized administrative access.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72045\"\n  tag \"rid\": \"SV-86669r1_rule\"\n  tag \"stig_id\": \"RHEL-07-021020\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystem\": ['nfs', 'file_system']\n  desc \"check\", \"Verify file systems that are being NFS exported are mounted\nwith the \\\"nosuid\\\" option.\n\nFind the file system(s) that contain the directories being exported with the\nfollowing command:\n\n# more /etc/fstab | grep nfs\n\nUUID=e06097bb-cfcd-437b-9e4d-a691f5662a7d    /store           nfs\nrw,nosuid                                                    0 0\n\nIf a file system found in \\\"/etc/fstab\\\" refers to NFS and it does not have the\n\\\"nosuid\\\" option set, this is a finding.\"\n  desc \"fix\", \"Configure the \\\"/etc/fstab\\\" to use the \\\"nosuid\\\" option on file\nsystems that are being exported via NFS.\"\n  tag \"fix_id\": \"F-78397r1_fix\"\n\n  nfs_systems = etc_fstab.nfs_file_systems.entries\n  if !nfs_systems.nil? and !nfs_systems.empty?\n    nfs_systems.each do |partition|\n      describe partition do\n        its('mount_options') { should include 'nosuid' }\n      end\n    end\n  else\n    describe \"No NFS file systems were found.\" do\n      subject { nfs_systems.nil? or nfs_systems.empty? }\n      it { should eq true }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72045.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "No NFS file systems were found. should eq true",
              "run_time": 0.000140695,
              "start_time": "2019-11-04T16:17:13-05:00"
            }
          ]
        },
        {
          "id": "V-72047",
          "title": "All world-writable directories must be group-owned by root, sys, bin,\nor an application group.",
          "desc": "If a world-writable directory has the sticky bit set and is not group-owned\nby a privileged Group Identifier (GID), unauthorized users may be able to\nmodify files created by others.\n\n    The only authorized public directories are those temporary directories\nsupplied with the system or those designed to be temporary file repositories.\nThe setting is normally reserved for directories used by the system and by\nusers for temporary file storage, (e.g., /tmp), and for directories requiring\nglobal read/write access.",
          "descriptions": [
            {
              "label": "default",
              "data": "If a world-writable directory has the sticky bit set and is not group-owned\nby a privileged Group Identifier (GID), unauthorized users may be able to\nmodify files created by others.\n\n    The only authorized public directories are those temporary directories\nsupplied with the system or those designed to be temporary file repositories.\nThe setting is normally reserved for directories used by the system and by\nusers for temporary file storage, (e.g., /tmp), and for directories requiring\nglobal read/write access."
            },
            {
              "label": "check",
              "data": "Verify all world-writable directories are group-owned by root,\nsys, bin, or an application group.\n\nCheck the system for world-writable directories with the following command:\n\nNote: The value after -fstype must be replaced with the filesystem type. XFS is\nused as an example.\n\n# find / -xdev -perm -002 -type d -fstype xfs -exec ls -lLd {} \\;\ndrwxrwxrwt 2 root root 40 Aug 26 13:07 /dev/mqueue\ndrwxrwxrwt 2 root root 220 Aug 26 13:23 /dev/shm\ndrwxrwxrwt 14 root root 4096 Aug 26 13:29 /tmp\n\nIf any world-writable directories are not owned by root, sys, bin, or an\napplication group associated with the directory, this is a finding."
            },
            {
              "label": "fix",
              "data": "Change the group of the world-writable directories to root with\nthe following command:\n\n# chgrp root <directory>"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72047",
            "rid": "SV-86671r3_rule",
            "stig_id": "RHEL-07-021030",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "subsystems": [
              "world_writable",
              "ww_dirs"
            ],
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "fix_id": "F-78399r1_fix"
          },
          "code": "control \"V-72047\" do\n  title \"All world-writable directories must be group-owned by root, sys, bin,\nor an application group.\"\n  desc  \"\n    If a world-writable directory has the sticky bit set and is not group-owned\nby a privileged Group Identifier (GID), unauthorized users may be able to\nmodify files created by others.\n\n    The only authorized public directories are those temporary directories\nsupplied with the system or those designed to be temporary file repositories.\nThe setting is normally reserved for directories used by the system and by\nusers for temporary file storage, (e.g., /tmp), and for directories requiring\nglobal read/write access.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72047\"\n  tag \"rid\": \"SV-86671r3_rule\"\n  tag \"stig_id\": \"RHEL-07-021030\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"subsystems\": ['world_writable', 'ww_dirs']\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  desc \"check\", \"Verify all world-writable directories are group-owned by root,\nsys, bin, or an application group.\n\nCheck the system for world-writable directories with the following command:\n\nNote: The value after -fstype must be replaced with the filesystem type. XFS is\nused as an example.\n\n# find / -xdev -perm -002 -type d -fstype xfs -exec ls -lLd {} \\\\;\ndrwxrwxrwt 2 root root 40 Aug 26 13:07 /dev/mqueue\ndrwxrwxrwt 2 root root 220 Aug 26 13:23 /dev/shm\ndrwxrwxrwt 14 root root 4096 Aug 26 13:29 /tmp\n\nIf any world-writable directories are not owned by root, sys, bin, or an\napplication group associated with the directory, this is a finding.\"\n  desc \"fix\", \"Change the group of the world-writable directories to root with\nthe following command:\n\n# chgrp root <directory>\"\n  tag \"fix_id\": \"F-78399r1_fix\"\n\n  # TODO - add option for app group associated with dir?\n  # TODO - add an attribute for 'APPLICATION_GROUP'\n\n  ww_dirs = Set[]\n  partitions = etc_fstab.params.map{|partition| partition['file_system_type']}.uniq\n  partitions.each do |part|\n    cmd = \"find / -perm -002 -xdev -type d -fstype #{part} -exec ls -lLd {} \\\\;\"\n    ww_dirs = ww_dirs + command(cmd).stdout.split(\"\\n\")\n  end\n\n  ww_dirs.to_a.each do |curr_dir|\n    dir_arr = curr_dir.split(' ')\n    describe file(dir_arr.last) do\n      its('group') { should be_in [\"root\",\"sys\",\"bin\"] + application_groups }\n    end\n  end\nend\n",
          "source_location": {
            "line": 10,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72047.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "File /var/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.041610981,
              "start_time": "2019-11-04T16:17:13-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-750b76c827f94bef8d79f747d739d544-bolt.service-1kbZYj/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.027747754,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-61566708ab5741e5af7bead319dfb433-rtkit-daemon.service-VzdzUV/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.021891302,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-61566708ab5741e5af7bead319dfb433-bolt.service-7nOKsO/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.019838114,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-0156528e39234864820ad26792e84d13-fwupd.service-SyiaNF/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.028537893,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-750b76c827f94bef8d79f747d739d544-chronyd.service-vJlm5e/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.016602891,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-61566708ab5741e5af7bead319dfb433-chronyd.service-Fb8yJ7/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.016503258,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-3a33452171e14f05ab34793501ae2b3d-rtkit-daemon.service-zRfjSJ/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.028701189,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-750b76c827f94bef8d79f747d739d544-colord.service-FwYswx/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.016843281,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-61566708ab5741e5af7bead319dfb433-cups.service-VApgzm/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.020537411,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-93e0dc1316ed4bbfaa8980e7400f42a9-rtkit-daemon.service-06rcHT/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.090121252,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-93e0dc1316ed4bbfaa8980e7400f42a9-systemd-machined.service-gi9Xg6/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.01956989,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-93e0dc1316ed4bbfaa8980e7400f42a9-chronyd.service-gHHydj/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.019114199,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-3a33452171e14f05ab34793501ae2b3d-chronyd.service-DN3Nu0/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.017906232,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-93e0dc1316ed4bbfaa8980e7400f42a9-cups.service-IVFwim/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.017734249,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-61566708ab5741e5af7bead319dfb433-colord.service-Pr0QmT/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.017453569,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-93e0dc1316ed4bbfaa8980e7400f42a9-bolt.service-kiMMwy/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.018875277,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-86b77322fe26486ea33fd008bbc3acd7-cups.service-b4XoGH/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.022674253,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-93e0dc1316ed4bbfaa8980e7400f42a9-colord.service-8tYQD4/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.021869873,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-93e0dc1316ed4bbfaa8980e7400f42a9-fwupd.service-SedHyC/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.01782812,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-4f6a851e71de47f8987277dbeba1a138-rtkit-daemon.service-eX7uMO/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.018383414,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-4f6a851e71de47f8987277dbeba1a138-chronyd.service-0Dp77Z/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.016608177,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-86b77322fe26486ea33fd008bbc3acd7-rtkit-daemon.service-dFEJah/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.01795467,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-4f6a851e71de47f8987277dbeba1a138-cups.service-U2ZIIT/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.017240552,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-4f6a851e71de47f8987277dbeba1a138-bolt.service-eovIN9/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.017294293,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-86b77322fe26486ea33fd008bbc3acd7-bolt.service-H1CZ5S/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.017783133,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-4f6a851e71de47f8987277dbeba1a138-colord.service-em8mO4/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.018008028,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-4f6a851e71de47f8987277dbeba1a138-fwupd.service-mqrf3S/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.017474692,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-0156528e39234864820ad26792e84d13-rtkit-daemon.service-uoF7zK/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.017665313,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-86b77322fe26486ea33fd008bbc3acd7-chronyd.service-tf11qM/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.017990298,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-0156528e39234864820ad26792e84d13-chronyd.service-stdof6/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.018008414,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-0156528e39234864820ad26792e84d13-cups.service-WgwJ1P/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.017572354,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-0156528e39234864820ad26792e84d13-bolt.service-wNJ7X8/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.016565633,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-0156528e39234864820ad26792e84d13-colord.service-8G5ha7/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.017256279,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-3a33452171e14f05ab34793501ae2b3d-colord.service-1RJ6Nt/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.018563624,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-750b76c827f94bef8d79f747d739d544-rtkit-daemon.service-bRIR1t/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.071796324,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-750b76c827f94bef8d79f747d739d544-cups.service-ZyRwYl/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.021376016,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-750b76c827f94bef8d79f747d739d544-fwupd.service-JJqllA/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.020201189,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-61566708ab5741e5af7bead319dfb433-fwupd.service-Cm9F93/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.018031207,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-3a33452171e14f05ab34793501ae2b3d-cups.service-9VsuNX/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.016649698,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-3a33452171e14f05ab34793501ae2b3d-bolt.service-lcaS49/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.018102703,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /var/tmp/systemd-private-86b77322fe26486ea33fd008bbc3acd7-colord.service-7lgCgd/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.01772369,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.017454352,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /tmp/.ICE-unix group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.016651939,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /tmp/.font-unix group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.019050658,
              "start_time": "2019-11-04T16:17:14-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /tmp/.XIM-unix group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.018901879,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /tmp/.Test-unix group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.019197275,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /tmp/.X11-unix group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.017505996,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /tmp/systemd-private-86b77322fe26486ea33fd008bbc3acd7-rtkit-daemon.service-wH5q7E/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.017329929,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /tmp/systemd-private-86b77322fe26486ea33fd008bbc3acd7-chronyd.service-EAhqf9/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.01751105,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /tmp/systemd-private-86b77322fe26486ea33fd008bbc3acd7-cups.service-wwWgiV/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.019728487,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /tmp/systemd-private-86b77322fe26486ea33fd008bbc3acd7-bolt.service-ux6uZP/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.01981311,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /tmp/systemd-private-86b77322fe26486ea33fd008bbc3acd7-colord.service-S78SU7/tmp group should be in \"root\", \"sys\", and \"bin\"",
              "run_time": 0.020510649,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72049",
          "title": "The umask must be set to 077 for all local interactive user accounts.",
          "desc": "The umask controls the default access mode assigned to newly created\nfiles. A umask of 077 limits new files to mode 700 or less permissive. Although\numask can be represented as a four-digit number, the first digit representing\nspecial access modes is typically ignored or required to be \"0\". This\nrequirement applies to the globally configured system defaults and the local\ninteractive user defaults for each account on the system.",
          "descriptions": [
            {
              "label": "default",
              "data": "The umask controls the default access mode assigned to newly created\nfiles. A umask of 077 limits new files to mode 700 or less permissive. Although\numask can be represented as a four-digit number, the first digit representing\nspecial access modes is typically ignored or required to be \"0\". This\nrequirement applies to the globally configured system defaults and the local\ninteractive user defaults for each account on the system."
            },
            {
              "label": "check",
              "data": "Verify that the default umask for all local interactive users\nis \"077\".\n\nIdentify the locations of all local interactive user home directories by\nlooking at the \"/etc/passwd\" file.\n\nCheck all local interactive user initialization files for interactive users\nwith the following command:\n\nNote: The example is for a system that is configured to create users home\ndirectories in the \"/home\" directory.\n\n# grep -i umask /home/*/.*\n\nIf any local interactive user initialization files are found to have a umask\nstatement that has a value less restrictive than \"077\", this is a finding."
            },
            {
              "label": "fix",
              "data": "Remove the umask statement from all local interactive users’\ninitialization files.\n\nIf the account is for an application, the requirement for a umask less\nrestrictive than \"077\" can be documented with the Information System Security\nOfficer, but the user agreement for access to the account must specify that the\nlocal interactive user must log on to their account first and then switch the\nuser to the application account with the correct option to gain the account’s\nenvironment variables."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72049",
            "rid": "SV-86673r1_rule",
            "stig_id": "RHEL-07-021040",
            "cci": [
              "CCI-000318",
              "CCI-000368",
              "CCI-001812",
              "CCI-001813",
              "CCI-001814"
            ],
            "documentable": false,
            "nist": [
              "CM-3 f",
              "CM-6 c",
              "CM-11 (2)",
              "CM-5 (1)",
              "CM-5 (1)",
              "Rev_4"
            ],
            "subsystems": [
              "init_files",
              "home_dirs"
            ],
            "fix_id": "F-78401r1_fix"
          },
          "code": "control \"V-72049\" do\n  title \"The umask must be set to 077 for all local interactive user accounts.\"\n  desc  \"The umask controls the default access mode assigned to newly created\nfiles. A umask of 077 limits new files to mode 700 or less permissive. Although\numask can be represented as a four-digit number, the first digit representing\nspecial access modes is typically ignored or required to be \\\"0\\\". This\nrequirement applies to the globally configured system defaults and the local\ninteractive user defaults for each account on the system.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72049\"\n  tag \"rid\": \"SV-86673r1_rule\"\n  tag \"stig_id\": \"RHEL-07-021040\"\n  tag \"cci\": [\"CCI-000318\", \"CCI-000368\", \"CCI-001812\", \"CCI-001813\",\n\"CCI-001814\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-3 f\", \"CM-6 c\", \"CM-11 (2)\", \"CM-5 (1)\", \"CM-5 (1)\", \"Rev_4\"]\n  tag \"subsystems\": ['init_files', 'home_dirs']\n  desc \"check\", \"Verify that the default umask for all local interactive users\nis \\\"077\\\".\n\nIdentify the locations of all local interactive user home directories by\nlooking at the \\\"/etc/passwd\\\" file.\n\nCheck all local interactive user initialization files for interactive users\nwith the following command:\n\nNote: The example is for a system that is configured to create users home\ndirectories in the \\\"/home\\\" directory.\n\n# grep -i umask /home/*/.*\n\nIf any local interactive user initialization files are found to have a umask\nstatement that has a value less restrictive than \\\"077\\\", this is a finding.\"\n  desc \"fix\", \"Remove the umask statement from all local interactive users’\ninitialization files.\n\nIf the account is for an application, the requirement for a umask less\nrestrictive than \\\"077\\\" can be documented with the Information System Security\nOfficer, but the user agreement for access to the account must specify that the\nlocal interactive user must log on to their account first and then switch the\nuser to the application account with the correct option to gain the account’s\nenvironment variables.\"\n  tag \"fix_id\": \"F-78401r1_fix\"\n\n  # @todo - test for values more restrictive than 077\n  file_lines = command('grep -i -s umask /home/*/.*').stdout.split(\"\\n\")\n  if !file_lines.nil? and !file_lines.empty?\n    file_lines.each do |curr_line|\n      file_name = curr_line.split(':').first\n      describe command(\"grep -i umask #{file_name}\") do\n        its('stdout.strip') { should match %r{^umask\\s+.*077} }\n      end\n    end\n  else\n    describe \"No interactive files with a less restrictive umask were found.\" do\n      subject { file_lines.nil? or file_lines.empty? }\n      it { should eq true }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72049.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "No interactive files with a less restrictive umask were found. should eq true",
              "run_time": 0.000206121,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72051",
          "title": "Cron logging must be implemented.",
          "desc": "Cron logging can be used to trace the successful or unsuccessful\nexecution of cron jobs. It can also be used to spot intrusions into the use of\nthe cron facility by unauthorized and malicious users.",
          "descriptions": [
            {
              "label": "default",
              "data": "Cron logging can be used to trace the successful or unsuccessful\nexecution of cron jobs. It can also be used to spot intrusions into the use of\nthe cron facility by unauthorized and malicious users."
            },
            {
              "label": "check",
              "data": "Verify that \"rsyslog\" is configured to log cron events.\n\nCheck the configuration of \"/etc/rsyslog.conf\" for the cron facility with the\nfollowing command:\n\nNote: If another logging package is used, substitute the utility configuration\nfile for \"/etc/rsyslog.conf\".\n\n# grep cron /etc/rsyslog.conf\ncron.* /var/log/cron.log\n\nIf the command does not return a response, check for cron logging all\nfacilities by inspecting the \"/etc/rsyslog.conf\" file:\n\n# more /etc/rsyslog.conf\n\nLook for the following entry:\n\n*.* /var/log/messages\n\nIf \"rsyslog\" is not logging messages for the cron facility or all facilities,\nthis is a finding.\n\nIf the entry is in the \"/etc/rsyslog.conf\" file but is after the entry\n\"*.*\", this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure \"rsyslog\" to log all cron messages by adding or\nupdating the following line to \"/etc/rsyslog.conf\":\n\ncron.* /var/log/cron.log\n\nNote: The line must be added before the following entry if it exists in\n\"/etc/rsyslog.conf\":\n\n*.* ~ # discards everything"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72051",
            "rid": "SV-86675r1_rule",
            "stig_id": "RHEL-07-021100",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "cron",
              "rsyslog"
            ],
            "fix_id": "F-78403r1_fix"
          },
          "code": "control \"V-72051\" do\n  title \"Cron logging must be implemented.\"\n  desc  \"Cron logging can be used to trace the successful or unsuccessful\nexecution of cron jobs. It can also be used to spot intrusions into the use of\nthe cron facility by unauthorized and malicious users.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72051\"\n  tag \"rid\": \"SV-86675r1_rule\"\n  tag \"stig_id\": \"RHEL-07-021100\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['cron', 'rsyslog']\n  desc \"check\", \"Verify that \\\"rsyslog\\\" is configured to log cron events.\n\nCheck the configuration of \\\"/etc/rsyslog.conf\\\" for the cron facility with the\nfollowing command:\n\nNote: If another logging package is used, substitute the utility configuration\nfile for \\\"/etc/rsyslog.conf\\\".\n\n# grep cron /etc/rsyslog.conf\ncron.* /var/log/cron.log\n\nIf the command does not return a response, check for cron logging all\nfacilities by inspecting the \\\"/etc/rsyslog.conf\\\" file:\n\n# more /etc/rsyslog.conf\n\nLook for the following entry:\n\n*.* /var/log/messages\n\nIf \\\"rsyslog\\\" is not logging messages for the cron facility or all facilities,\nthis is a finding.\n\nIf the entry is in the \\\"/etc/rsyslog.conf\\\" file but is after the entry\n\\\"*.*\\\", this is a finding.\"\n  desc \"fix\", \"Configure \\\"rsyslog\\\" to log all cron messages by adding or\nupdating the following line to \\\"/etc/rsyslog.conf\\\":\n\ncron.* /var/log/cron.log\n\nNote: The line must be added before the following entry if it exists in\n\\\"/etc/rsyslog.conf\\\":\n\n*.* ~ # discards everything\"\n  tag \"fix_id\": \"F-78403r1_fix\"\n\n  describe.one do\n    describe command(\"grep cron #{log_pkg_path}\") do\n      its('stdout.strip') { should match %r{^cron} }\n    end\n    describe file(\"#{log_pkg_path}\") do\n      its('content') { should match %r{^\\*\\.\\* \\/var\\/log\\/messages\\n?$} }\n      its('content') { should_not match %r{^*.*\\s+~$.*^*\\.\\* \\/var\\/log\\/messages\\n?$}m }\n    end\n  end\nend\n",
          "source_location": {
            "line": 10,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72051.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Command: `grep cron /etc/rsyslog.conf` stdout.strip should match /^cron/",
              "run_time": 0.000295983,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72053",
          "title": "If the cron.allow file exists it must be owned by root.",
          "desc": "If the owner of the \"cron.allow\" file is not set to root, the\npossibility exists for an unauthorized user to view or to edit sensitive\ninformation.",
          "descriptions": [
            {
              "label": "default",
              "data": "If the owner of the \"cron.allow\" file is not set to root, the\npossibility exists for an unauthorized user to view or to edit sensitive\ninformation."
            },
            {
              "label": "check",
              "data": "Verify that the \"cron.allow\" file is owned by root.\n\nCheck the owner of the \"cron.allow\" file with the following command:\n\n# ls -al /etc/cron.allow\n-rw------- 1 root root 6 Mar  5  2011 /etc/cron.allow\n\nIf the \"cron.allow\" file exists and has an owner other than root, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Set the owner on the \"/etc/cron.allow\" file to root with the\nfollowing command:\n\n# chown root /etc/cron.allow"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72053",
            "rid": "SV-86677r2_rule",
            "stig_id": "RHEL-07-021110",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "cron"
            ],
            "fix_id": "F-78405r1_fix"
          },
          "code": "control \"V-72053\" do\n  title \"If the cron.allow file exists it must be owned by root.\"\n  desc  \"If the owner of the \\\"cron.allow\\\" file is not set to root, the\npossibility exists for an unauthorized user to view or to edit sensitive\ninformation.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72053\"\n  tag \"rid\": \"SV-86677r2_rule\"\n  tag \"stig_id\": \"RHEL-07-021110\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['cron']\n  desc \"check\", \"Verify that the \\\"cron.allow\\\" file is owned by root.\n\nCheck the owner of the \\\"cron.allow\\\" file with the following command:\n\n# ls -al /etc/cron.allow\n-rw------- 1 root root 6 Mar  5  2011 /etc/cron.allow\n\nIf the \\\"cron.allow\\\" file exists and has an owner other than root, this is a\nfinding.\"\n  desc \"fix\", \"Set the owner on the \\\"/etc/cron.allow\\\" file to root with the\nfollowing command:\n\n# chown root /etc/cron.allow\"\n  tag \"fix_id\": \"F-78405r1_fix\"\n\n  describe.one do\n    # case where file doesn't exist\n    describe file('/etc/cron.allow') do\n      it { should_not exist }\n    end\n    # case where file exists\n    describe file('/etc/cron.allow') do\n      it { should be_owned_by 'root' }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72053.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "File /etc/cron.allow should not exist",
              "run_time": 0.000178297,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72055",
          "title": "If the cron.allow file exists it must be group-owned by root.",
          "desc": "If the group owner of the \"cron.allow\" file is not set to root,\nsensitive information could be viewed or edited by unauthorized users.",
          "descriptions": [
            {
              "label": "default",
              "data": "If the group owner of the \"cron.allow\" file is not set to root,\nsensitive information could be viewed or edited by unauthorized users."
            },
            {
              "label": "check",
              "data": "Verify that the \"cron.allow\" file is group-owned by root.\n\nCheck the group owner of the \"cron.allow\" file with the following command:\n\n# ls -al /etc/cron.allow\n-rw------- 1 root root 6 Mar  5  2011 /etc/cron.allow\n\nIf the \"cron.allow\" file exists and has a group owner other than root, this\nis a finding."
            },
            {
              "label": "fix",
              "data": "Set the group owner on the \"/etc/cron.allow\" file to root with\nthe following command:\n\n# chgrp root /etc/cron.allow"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72055",
            "rid": "SV-86679r1_rule",
            "stig_id": "RHEL-07-021120",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "cron"
            ],
            "fix_id": "F-78407r1_fix"
          },
          "code": "control \"V-72055\" do\n  title \"If the cron.allow file exists it must be group-owned by root.\"\n  desc  \"If the group owner of the \\\"cron.allow\\\" file is not set to root,\nsensitive information could be viewed or edited by unauthorized users.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72055\"\n  tag \"rid\": \"SV-86679r1_rule\"\n  tag \"stig_id\": \"RHEL-07-021120\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['cron']\n  desc \"check\", \"Verify that the \\\"cron.allow\\\" file is group-owned by root.\n\nCheck the group owner of the \\\"cron.allow\\\" file with the following command:\n\n# ls -al /etc/cron.allow\n-rw------- 1 root root 6 Mar  5  2011 /etc/cron.allow\n\nIf the \\\"cron.allow\\\" file exists and has a group owner other than root, this\nis a finding.\"\n  desc \"fix\", \"Set the group owner on the \\\"/etc/cron.allow\\\" file to root with\nthe following command:\n\n# chgrp root /etc/cron.allow\"\n  tag \"fix_id\": \"F-78407r1_fix\"\n\n  describe.one do\n    # case where file doesn't exist\n    describe file('/etc/cron.allow') do\n      it { should_not exist }\n    end\n    # case where file exists\n    describe file('/etc/cron.allow') do\n      its('group') { should eq 'root' }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72055.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "File /etc/cron.allow should not exist",
              "run_time": 0.000432889,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72057",
          "title": "Kernel core dumps must be disabled unless needed.",
          "desc": "Kernel core dumps may contain the full contents of system memory at\nthe time of the crash. Kernel core dumps may consume a considerable amount of\ndisk space and may result in denial of service by exhausting the available\nspace on the target file system partition.",
          "descriptions": [
            {
              "label": "default",
              "data": "Kernel core dumps may contain the full contents of system memory at\nthe time of the crash. Kernel core dumps may consume a considerable amount of\ndisk space and may result in denial of service by exhausting the available\nspace on the target file system partition."
            },
            {
              "label": "check",
              "data": "Verify that kernel core dumps are disabled unless needed.\n\nCheck the status of the \"kdump\" service with the following command:\n\n# systemctl status kdump.service\nkdump.service - Crash recovery kernel arming\n   Loaded: loaded (/usr/lib/systemd/system/kdump.service; enabled)\n   Active: active (exited) since Wed 2015-08-26 13:08:09 EDT; 43min ago\n Main PID: 1130 (code=exited, status=0/SUCCESS)\nkernel arming.\n\nIf the \"kdump\" service is active, ask the System Administrator if the use of\nthe service is required and documented with the Information System Security\nOfficer (ISSO).\n\nIf the service is active and is not documented, this is a finding."
            },
            {
              "label": "fix",
              "data": "If kernel core dumps are not required, disable the \"kdump\"\nservice with the following command:\n\n# systemctl disable kdump.service\n\nIf kernel core dumps are required, document the need with the ISSO."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72057",
            "rid": "SV-86681r1_rule",
            "stig_id": "RHEL-07-021300",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "kdump",
              "kernel"
            ],
            "fix_id": "F-78409r1_fix"
          },
          "code": "control \"V-72057\" do\n  title \"Kernel core dumps must be disabled unless needed.\"\n  desc  \"Kernel core dumps may contain the full contents of system memory at\nthe time of the crash. Kernel core dumps may consume a considerable amount of\ndisk space and may result in denial of service by exhausting the available\nspace on the target file system partition.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72057\"\n  tag \"rid\": \"SV-86681r1_rule\"\n  tag \"stig_id\": \"RHEL-07-021300\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['kdump', 'kernel']\n  desc \"check\", \"Verify that kernel core dumps are disabled unless needed.\n\nCheck the status of the \\\"kdump\\\" service with the following command:\n\n# systemctl status kdump.service\nkdump.service - Crash recovery kernel arming\n   Loaded: loaded (/usr/lib/systemd/system/kdump.service; enabled)\n   Active: active (exited) since Wed 2015-08-26 13:08:09 EDT; 43min ago\n Main PID: 1130 (code=exited, status=0/SUCCESS)\nkernel arming.\n\nIf the \\\"kdump\\\" service is active, ask the System Administrator if the use of\nthe service is required and documented with the Information System Security\nOfficer (ISSO).\n\nIf the service is active and is not documented, this is a finding.\"\n  desc \"fix\", \"If kernel core dumps are not required, disable the \\\"kdump\\\"\nservice with the following command:\n\n# systemctl disable kdump.service\n\nIf kernel core dumps are required, document the need with the ISSO.\"\n  tag \"fix_id\": \"F-78409r1_fix\"\n\n  describe systemd_service('kdump.service') do\n    it { should_not be_running }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72057.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Service kdump.service should not be running",
              "run_time": 0.075257356,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected Service kdump.service not to be running"
            }
          ]
        },
        {
          "id": "V-72059",
          "title": "A separate file system must be used for user home directories (such as\n/home or an equivalent).",
          "desc": "The use of separate file systems for different paths can protect the\nsystem from failures resulting from a file system becoming full or failing.",
          "descriptions": [
            {
              "label": "default",
              "data": "The use of separate file systems for different paths can protect the\nsystem from failures resulting from a file system becoming full or failing."
            },
            {
              "label": "check",
              "data": "Verify that a separate file system/partition has been created\nfor non-privileged local interactive user home directories.\n\nCheck the home directory assignment for all non-privileged users (those with a\nUID greater than 1000) on the system with the following command:\n\n#cut -d: -f 1,3,6,7 /etc/passwd | egrep \":[1-4][0-9]{3}\" | tr \":\" \"\\t\"\n\nadamsj /home/adamsj /bin/bash\njacksonm /home/jacksonm /bin/bash\nsmithj /home/smithj /bin/bash\n\nThe output of the command will give the directory/partition that contains the\nhome directories for the non-privileged users on the system (in this example,\n/home) and users’ shell. All accounts with a valid shell (such as /bin/bash)\nare considered interactive users.\n\nCheck that a file system/partition has been created for the non-privileged\ninteractive users with the following command:\n\nNote: The partition of /home is used in the example.\n\n# grep /home /etc/fstab\nUUID=333ada18    /home                   ext4    noatime,nobarrier,nodev  1 2\n\nIf a separate entry for the file system/partition that contains the\nnon-privileged interactive users' home directories does not exist, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Migrate the \"/home\" directory onto a separate file\nsystem/partition."
            }
          ],
          "impact": 0.3,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72059",
            "rid": "SV-86683r1_rule",
            "stig_id": "RHEL-07-021310",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "home_dirs",
              "file_system"
            ],
            "fix_id": "F-78411r1_fix"
          },
          "code": "control \"V-72059\" do\n  title \"A separate file system must be used for user home directories (such as\n/home or an equivalent).\"\n  desc  \"The use of separate file systems for different paths can protect the\nsystem from failures resulting from a file system becoming full or failing.\"\n  impact 0.3\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72059\"\n  tag \"rid\": \"SV-86683r1_rule\"\n  tag \"stig_id\": \"RHEL-07-021310\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['home_dirs', 'file_system']\n  desc \"check\", \"Verify that a separate file system/partition has been created\nfor non-privileged local interactive user home directories.\n\nCheck the home directory assignment for all non-privileged users (those with a\nUID greater than 1000) on the system with the following command:\n\n#cut -d: -f 1,3,6,7 /etc/passwd | egrep \\\":[1-4][0-9]{3}\\\" | tr \\\":\\\" \\\"\\\\t\\\"\n\nadamsj /home/adamsj /bin/bash\njacksonm /home/jacksonm /bin/bash\nsmithj /home/smithj /bin/bash\n\nThe output of the command will give the directory/partition that contains the\nhome directories for the non-privileged users on the system (in this example,\n/home) and users’ shell. All accounts with a valid shell (such as /bin/bash)\nare considered interactive users.\n\nCheck that a file system/partition has been created for the non-privileged\ninteractive users with the following command:\n\nNote: The partition of /home is used in the example.\n\n# grep /home /etc/fstab\nUUID=333ada18    /home                   ext4    noatime,nobarrier,nodev  1 2\n\nIf a separate entry for the file system/partition that contains the\nnon-privileged interactive users' home directories does not exist, this is a\nfinding.\"\n  desc \"fix\", \"Migrate the \\\"/home\\\" directory onto a separate file\nsystem/partition.\"\n  tag \"fix_id\": \"F-78411r1_fix\"\n\n  ignore_shells = non_interactive_shells.join('|')\n\n  uid_min = login_defs.read_params['UID_MIN'].to_i\n  uid_min = 1000 if uid_min.nil?\n\n  # excluding root because its home directory is usually \"/root\" (mountpoint \"/\")\n  users.where{ !shell.match(ignore_shells) && (uid >= uid_min)}.entries.each do |user_info|\n    next if exempt_home_users.include?(\"#{user_info.username}\")\n\n    home_mount = command(%(df #{user_info.home} --output=target | tail -1)).stdout.strip\n    describe user_info.username do\n      context 'with mountpoint' do\n        context home_mount do\n          it { should_not be_empty }\n          it { should_not match(%r(^/$)) }\n        end\n      end\n    end\n  end\nend\n",
          "source_location": {
            "line": 16,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72059.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "dhaynes with mountpoint / should not be empty",
              "run_time": 0.000207732,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "dhaynes with mountpoint / should not match /^\\/$/",
              "run_time": 0.000472772,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected \"/\" not to match /^\\/$/\nDiff:\n@@ -1,2 +1,2 @@\n-/^\\/$/\n+\"/\"\n"
            }
          ]
        },
        {
          "id": "V-72061",
          "title": "The system must use a separate file system for /var.",
          "desc": "The use of separate file systems for different paths can protect the\n  system from failures resulting from a file system becoming full or failing.",
          "descriptions": [
            {
              "label": "default",
              "data": "The use of separate file systems for different paths can protect the\n  system from failures resulting from a file system becoming full or failing."
            },
            {
              "label": "check",
              "data": "Verify that a separate file system/partition has been created\n  for \"/var\".\n\n  Check that a file system/partition has been created for \"/var\" with the\n  following command:\n\n  # grep /var /etc/fstab\n  \n  UUID=c274f65f /var ext4 noatime,nobarrier 1 2\n\n  If a separate entry for \"/var\" is not in use, this is a finding."
            },
            {
              "label": "fix",
              "data": "Migrate the \"/var\" path onto a separate file system."
            }
          ],
          "impact": 0.3,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72061",
            "rid": "SV-86685r1_rule",
            "stig_id": "RHEL-07-021320",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "fix_id": "F-78413r1_fix",
            "subsystems": [
              "/var",
              "file_system"
            ],
            "nist": [
              "CM-6 b",
              "Rev_4"
            ]
          },
          "code": "control \"V-72061\" do\n  title \"The system must use a separate file system for /var.\"\n  desc  \"The use of separate file systems for different paths can protect the\n  system from failures resulting from a file system becoming full or failing.\"\n  impact 0.3\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72061\"\n  tag \"rid\": \"SV-86685r1_rule\"\n  tag \"stig_id\": \"RHEL-07-021320\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"fix_id\": \"F-78413r1_fix\"\n  tag \"subsystems\": ['/var', 'file_system']\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  desc \"check\", \"Verify that a separate file system/partition has been created\n  for \\\"/var\\\".\n\n  Check that a file system/partition has been created for \\\"/var\\\" with the\n  following command:\n\n  # grep /var /etc/fstab\n  \n  UUID=c274f65f /var ext4 noatime,nobarrier 1 2\n\n  If a separate entry for \\\"/var\\\" is not in use, this is a finding.\"\n  \n  desc \"fix\", \"Migrate the \\\"/var\\\" path onto a separate file system.\"\n\n  describe mount('/var') do\n    it { should be_mounted }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72061.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Mount /var should be mounted",
              "run_time": 0.026203976,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nMount /var is not mounted\n"
            }
          ]
        },
        {
          "id": "V-72063",
          "title": "The system must use a separate file system for the system audit data\npath.",
          "desc": "The use of separate file systems for different paths can protect the\nsystem from failures resulting from a file system becoming full or failing.",
          "descriptions": [
            {
              "label": "default",
              "data": "The use of separate file systems for different paths can protect the\nsystem from failures resulting from a file system becoming full or failing."
            },
            {
              "label": "check",
              "data": "Determine if the \"/var/log/audit\" path is a separate file\n  system.\n\n  # grep /var/log/audit /etc/fstab\n\n  If no result is returned, \"/var/log/audit\" is not on a separate file system,\n  and this is a finding."
            },
            {
              "label": "fix",
              "data": "Migrate the system audit data path onto a separate file system."
            }
          ],
          "impact": 0.3,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72063",
            "rid": "SV-86687r5_rule",
            "stig_id": "RHEL-07-021330",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "file_system"
            ],
            "fix_id": "F-78415r1_fix"
          },
          "code": "control \"V-72063\" do\n  title \"The system must use a separate file system for the system audit data\npath.\"\n  desc  \"The use of separate file systems for different paths can protect the\nsystem from failures resulting from a file system becoming full or failing.\"\n  impact 0.3\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72063\"\n  tag \"rid\": \"SV-86687r5_rule\"\n  tag \"stig_id\": \"RHEL-07-021330\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['file_system']\n  tag \"fix_id\": \"F-78415r1_fix\"\n  desc \"check\", \"Determine if the \\\"/var/log/audit\\\" path is a separate file\n  system.\n\n  # grep /var/log/audit /etc/fstab\n\n  If no result is returned, \\\"/var/log/audit\\\" is not on a separate file system,\n  and this is a finding.\"\n  desc \"fix\", \"Migrate the system audit data path onto a separate file system.\"\n\n  describe mount('/var/log/audit') do\n    it {should be_mounted}\n  end\n\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72063.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Mount /var/log/audit should be mounted",
              "run_time": 0.019823163,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nMount /var/log/audit is not mounted\n"
            }
          ]
        },
        {
          "id": "V-72065",
          "title": "The system must use a separate file system for /tmp (or equivalent).",
          "desc": "The use of separate file systems for different paths can protect the\nsystem from failures resulting from a file system becoming full or failing.",
          "descriptions": [
            {
              "label": "default",
              "data": "The use of separate file systems for different paths can protect the\nsystem from failures resulting from a file system becoming full or failing."
            },
            {
              "label": "check",
              "data": "Verify that a separate file system/partition has been created\n  for \"/tmp\".\n\n  Check that a file system/partition has been created for \"/tmp\" with the\n  following command:\n\n  # systemctl is-enabled tmp.mount\n  enabled\n\n  If the \"tmp.mount\" service is not enabled, this is a finding."
            },
            {
              "label": "fix",
              "data": "Start the \"tmp.mount\" service with the following command:\n  \n  # systemctl enable tmp.mount"
            }
          ],
          "impact": 0.3,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72065",
            "rid": "SV-86689r1_rule",
            "stig_id": "RHEL-07-021340",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "file_system",
              "tmp"
            ],
            "fix_id": "F-78417r1_fix"
          },
          "code": "control \"V-72065\" do\n  title \"The system must use a separate file system for /tmp (or equivalent).\"\n  desc  \"The use of separate file systems for different paths can protect the\nsystem from failures resulting from a file system becoming full or failing.\"\n  impact 0.3\n  \n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72065\"\n  tag \"rid\": \"SV-86689r1_rule\"\n  tag \"stig_id\": \"RHEL-07-021340\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['file_system', 'tmp']\n  tag \"fix_id\": \"F-78417r1_fix\"\n  \n  desc \"check\", \"Verify that a separate file system/partition has been created\n  for \\\"/tmp\\\".\n\n  Check that a file system/partition has been created for \\\"/tmp\\\" with the\n  following command:\n\n  # systemctl is-enabled tmp.mount\n  enabled\n\n  If the \\\"tmp.mount\\\" service is not enabled, this is a finding.\"\n\n  desc \"fix\", \"Start the \\\"tmp.mount\\\" service with the following command:\n  \n  # systemctl enable tmp.mount\"\n\n  describe systemd_service('tmp.mount') do\n    it { should be_enabled }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72065.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Service tmp.mount should be enabled",
              "run_time": 0.061610871,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected that `Service tmp.mount` is enabled"
            }
          ]
        },
        {
          "id": "V-72067",
          "title": "The operating system must implement NIST FIPS-validated cryptography\nfor the following: to provision digital signatures, to generate cryptographic\nhashes, and to protect data requiring data-at-rest protections in accordance\nwith applicable federal laws, Executive Orders, directives, policies,\nregulations, and standards.",
          "desc": "Use of weak or untested encryption algorithms undermines the purposes\nof using encryption to protect data. The operating system must implement\ncryptographic modules adhering to the higher standards approved by the federal\ngovernment since this provides assurance they have been tested and validated.",
          "descriptions": [
            {
              "label": "default",
              "data": "Use of weak or untested encryption algorithms undermines the purposes\nof using encryption to protect data. The operating system must implement\ncryptographic modules adhering to the higher standards approved by the federal\ngovernment since this provides assurance they have been tested and validated."
            },
            {
              "label": "check",
              "data": "Verify the operating system implements DoD-approved encryption\nto protect the confidentiality of remote access sessions.\n\nCheck to see if the \"dracut-fips\" package is installed with the following\ncommand:\n\n# yum list installed | grep dracut-fips\n\ndracut-fips-033-360.el7_2.x86_64.rpm\n\nIf a \"dracut-fips\" package is installed, check to see if the kernel command\nline is configured to use FIPS mode with the following command:\n\nNote: GRUB 2 reads its configuration from the \"/boot/grub2/grub.cfg\" file on\ntraditional BIOS-based machines and from the \"/boot/efi/EFI/redhat/grub.cfg\"\nfile on UEFI machines.\n\n# grep fips /boot/grub2/grub.cfg\n/vmlinuz-3.8.0-0.40.el7.x86_64 root=/dev/mapper/rhel-root ro rd.md=0 rd.dm=0\nrd.lvm.lv=rhel/swap crashkernel=auto rd.luks=0 vconsole.keymap=us\nrd.lvm.lv=rhel/root rhgb fips=1 quiet\n\nIf the kernel command line is configured to use FIPS mode, check to see if the\nsystem is in FIPS mode with the following command:\n\n# cat /proc/sys/crypto/fips_enabled\n1\n\nIf a \"dracut-fips\" package is not installed, the kernel command line does not\nhave a fips entry, or the system has a value of \"0\" for \"fips_enabled\" in\n\"/proc/sys/crypto\", this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to implement DoD-approved\nencryption by installing the dracut-fips package.\n\nTo enable strict FIPS compliance, the fips=1 kernel option needs to be added to\nthe kernel command line during system installation so key generation is done\nwith FIPS-approved algorithms and continuous monitoring tests in place.\n\nConfigure the operating system to implement DoD-approved encryption by\nfollowing the steps below:\n\nThe fips=1 kernel option needs to be added to the kernel command line during\nsystem installation so that key generation is done with FIPS-approved\nalgorithms and continuous monitoring tests in place. Users should also ensure\nthat the system has plenty of entropy during the installation process by moving\nthe mouse around, or if no mouse is available, ensuring that many keystrokes\nare typed. The recommended amount of keystrokes is 256 and more. Less than 256\nkeystrokes may generate a non-unique key.\n\nInstall the dracut-fips package with the following command:\n\n# yum install dracut-fips\n\nRecreate the \"initramfs\" file with the following command:\n\nNote: This command will overwrite the existing \"initramfs\" file.\n\n# dracut -f\n\nModify the kernel command line of the current kernel in the \"grub.cfg\" file\nby adding the following option to the GRUB_CMDLINE_LINUX key in the\n\"/etc/default/grub\" file and then rebuild the \"grub.cfg\" file:\n\nfips=1\n\nChanges to \"/etc/default/grub\" require rebuilding the \"grub.cfg\" file as\nfollows:\n\nOn BIOS-based machines, use the following command:\n\n# grub2-mkconfig -o /boot/grub2/grub.cfg\n\nOn UEFI-based machines, use the following command:\n\n# grub2-mkconfig -o /boot/efi/EFI/redhat/grub.cfg\n\nIf /boot or /boot/efi reside on separate partitions, the kernel parameter\nboot=<partition of /boot or /boot/efi> must be added to the kernel command\nline. You can identify a partition by running the df /boot or df /boot/efi\ncommand:\n\n# df /boot\nFilesystem 1K-blocks Used Available Use% Mounted on\n/dev/sda1 495844 53780 416464 12% /boot\n\nTo ensure the boot= configuration option will work even if device naming\nchanges between boots, identify the universally unique identifier (UUID) of the\npartition with the following command:\n\n# blkid /dev/sda1\n/dev/sda1: UUID=\"05c000f1-a213-759e-c7a2-f11b7424c797\" TYPE=\"ext4\"\n\nFor the example above, append the following string to the kernel command line:\n\nboot=UUID=05c000f1-a213-759e-c7a2-f11b7424c797\n\nReboot the system for the changes to take effect."
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000033-GPOS-00014",
            "satisfies": [
              "SRG-OS-000033-GPOS-00014",
              "SRG-OS-000185-GPOS-00079",
              "SRG-OS-000396-GPOS-00176",
              "SRG-OS-000405-GPOS-00184",
              "SRG-OS-000478-GPOS-00223"
            ],
            "gid": "V-72067",
            "rid": "SV-86691r3_rule",
            "stig_id": "RHEL-07-021350",
            "cci": [
              "CCI-000068",
              "CCI-001199",
              "CCI-002450",
              "CCI-002476"
            ],
            "documentable": false,
            "nist": [
              "AC-17 (2)",
              "SC-28",
              "SC-13",
              "SC-28 (1)",
              "Rev_4"
            ],
            "subsystems": [
              "fips"
            ],
            "fix_id": "F-78419r2_fix"
          },
          "code": "control \"V-72067\" do\n  title \"The operating system must implement NIST FIPS-validated cryptography\nfor the following: to provision digital signatures, to generate cryptographic\nhashes, and to protect data requiring data-at-rest protections in accordance\nwith applicable federal laws, Executive Orders, directives, policies,\nregulations, and standards.\"\n  desc  \"Use of weak or untested encryption algorithms undermines the purposes\nof using encryption to protect data. The operating system must implement\ncryptographic modules adhering to the higher standards approved by the federal\ngovernment since this provides assurance they have been tested and validated.\"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000033-GPOS-00014\"\n  tag \"satisfies\": [\"SRG-OS-000033-GPOS-00014\", \"SRG-OS-000185-GPOS-00079\",\n\"SRG-OS-000396-GPOS-00176\", \"SRG-OS-000405-GPOS-00184\",\n\"SRG-OS-000478-GPOS-00223\"]\n  tag \"gid\": \"V-72067\"\n  tag \"rid\": \"SV-86691r3_rule\"\n  tag \"stig_id\": \"RHEL-07-021350\"\n  tag \"cci\": [\"CCI-000068\", \"CCI-001199\", \"CCI-002450\", \"CCI-002476\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-17 (2)\", \"SC-28\", \"SC-13\", \"SC-28 (1)\", \"Rev_4\"]\n  tag \"subsystems\": ['fips']\n  desc \"check\", \"Verify the operating system implements DoD-approved encryption\nto protect the confidentiality of remote access sessions.\n\nCheck to see if the \\\"dracut-fips\\\" package is installed with the following\ncommand:\n\n# yum list installed | grep dracut-fips\n\ndracut-fips-033-360.el7_2.x86_64.rpm\n\nIf a \\\"dracut-fips\\\" package is installed, check to see if the kernel command\nline is configured to use FIPS mode with the following command:\n\nNote: GRUB 2 reads its configuration from the \\\"/boot/grub2/grub.cfg\\\" file on\ntraditional BIOS-based machines and from the \\\"/boot/efi/EFI/redhat/grub.cfg\\\"\nfile on UEFI machines.\n\n# grep fips /boot/grub2/grub.cfg\n/vmlinuz-3.8.0-0.40.el7.x86_64 root=/dev/mapper/rhel-root ro rd.md=0 rd.dm=0\nrd.lvm.lv=rhel/swap crashkernel=auto rd.luks=0 vconsole.keymap=us\nrd.lvm.lv=rhel/root rhgb fips=1 quiet\n\nIf the kernel command line is configured to use FIPS mode, check to see if the\nsystem is in FIPS mode with the following command:\n\n# cat /proc/sys/crypto/fips_enabled\n1\n\nIf a \\\"dracut-fips\\\" package is not installed, the kernel command line does not\nhave a fips entry, or the system has a value of \\\"0\\\" for \\\"fips_enabled\\\" in\n\\\"/proc/sys/crypto\\\", this is a finding.\"\n  desc \"fix\", \"Configure the operating system to implement DoD-approved\nencryption by installing the dracut-fips package.\n\nTo enable strict FIPS compliance, the fips=1 kernel option needs to be added to\nthe kernel command line during system installation so key generation is done\nwith FIPS-approved algorithms and continuous monitoring tests in place.\n\nConfigure the operating system to implement DoD-approved encryption by\nfollowing the steps below:\n\nThe fips=1 kernel option needs to be added to the kernel command line during\nsystem installation so that key generation is done with FIPS-approved\nalgorithms and continuous monitoring tests in place. Users should also ensure\nthat the system has plenty of entropy during the installation process by moving\nthe mouse around, or if no mouse is available, ensuring that many keystrokes\nare typed. The recommended amount of keystrokes is 256 and more. Less than 256\nkeystrokes may generate a non-unique key.\n\nInstall the dracut-fips package with the following command:\n\n# yum install dracut-fips\n\nRecreate the \\\"initramfs\\\" file with the following command:\n\nNote: This command will overwrite the existing \\\"initramfs\\\" file.\n\n# dracut -f\n\nModify the kernel command line of the current kernel in the \\\"grub.cfg\\\" file\nby adding the following option to the GRUB_CMDLINE_LINUX key in the\n\\\"/etc/default/grub\\\" file and then rebuild the \\\"grub.cfg\\\" file:\n\nfips=1\n\nChanges to \\\"/etc/default/grub\\\" require rebuilding the \\\"grub.cfg\\\" file as\nfollows:\n\nOn BIOS-based machines, use the following command:\n\n# grub2-mkconfig -o /boot/grub2/grub.cfg\n\nOn UEFI-based machines, use the following command:\n\n# grub2-mkconfig -o /boot/efi/EFI/redhat/grub.cfg\n\nIf /boot or /boot/efi reside on separate partitions, the kernel parameter\nboot=<partition of /boot or /boot/efi> must be added to the kernel command\nline. You can identify a partition by running the df /boot or df /boot/efi\ncommand:\n\n# df /boot\nFilesystem 1K-blocks Used Available Use% Mounted on\n/dev/sda1 495844 53780 416464 12% /boot\n\nTo ensure the boot= configuration option will work even if device naming\nchanges between boots, identify the universally unique identifier (UUID) of the\npartition with the following command:\n\n# blkid /dev/sda1\n/dev/sda1: UUID=\\\"05c000f1-a213-759e-c7a2-f11b7424c797\\\" TYPE=\\\"ext4\\\"\n\nFor the example above, append the following string to the kernel command line:\n\nboot=UUID=05c000f1-a213-759e-c7a2-f11b7424c797\n\nReboot the system for the changes to take effect.\n\"\n  tag \"fix_id\": \"F-78419r2_fix\"\n\n  describe package('dracut-fips') do\n    it { should be_installed }\n  end\n\n  all_args = command('grubby --info=ALL | grep \"^args=\" | sed \"s/^args=//g\"').\n    stdout.strip.split(\"\\n\").\n    map { |s| s.sub(%r{^\"(.*)\"$}, '\\1') } # strip outer quotes if they exist\n\n  all_args.each { |args|\n    describe args do\n      it { should match %r{\\bfips=1\\b} }\n    end\n  }\n\n  describe file('/proc/sys/crypto/fips_enabled') do\n    its('content.strip') { should cmp 1 }\n  end\nend\n",
          "source_location": {
            "line": 4,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72067.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "System Package dracut-fips should be installed",
              "run_time": 0.054605779,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected that `System Package dracut-fips` is installed"
            },
            {
              "status": "failed",
              "code_desc": "ro crashkernel=auto rd.lvm.lv=centos/root rd.lvm.lv=centos/swap rhgb quiet LANG=en_US.UTF-8 should match /\\bfips=1\\b/",
              "run_time": 0.000537016,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected \"ro crashkernel=auto rd.lvm.lv=centos/root rd.lvm.lv=centos/swap rhgb quiet LANG=en_US.UTF-8\" to match /\\bfips=1\\b/\nDiff:\n@@ -1,2 +1,2 @@\n-/\\bfips=1\\b/\n+\"ro crashkernel=auto rd.lvm.lv=centos/root rd.lvm.lv=centos/swap rhgb quiet LANG=en_US.UTF-8\"\n"
            },
            {
              "status": "failed",
              "code_desc": "ro crashkernel=auto rd.lvm.lv=centos/root rd.lvm.lv=centos/swap rhgb quiet LANG=en_US.UTF-8 should match /\\bfips=1\\b/",
              "run_time": 0.000694799,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected \"ro crashkernel=auto rd.lvm.lv=centos/root rd.lvm.lv=centos/swap rhgb quiet LANG=en_US.UTF-8\" to match /\\bfips=1\\b/\nDiff:\n@@ -1,2 +1,2 @@\n-/\\bfips=1\\b/\n+\"ro crashkernel=auto rd.lvm.lv=centos/root rd.lvm.lv=centos/swap rhgb quiet LANG=en_US.UTF-8\"\n"
            },
            {
              "status": "failed",
              "code_desc": "ro crashkernel=auto rd.lvm.lv=centos/root rd.lvm.lv=centos/swap rhgb quiet should match /\\bfips=1\\b/",
              "run_time": 0.000259195,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected \"ro crashkernel=auto rd.lvm.lv=centos/root rd.lvm.lv=centos/swap rhgb quiet\" to match /\\bfips=1\\b/\nDiff:\n@@ -1,2 +1,2 @@\n-/\\bfips=1\\b/\n+\"ro crashkernel=auto rd.lvm.lv=centos/root rd.lvm.lv=centos/swap rhgb quiet\"\n"
            },
            {
              "status": "failed",
              "code_desc": "File /proc/sys/crypto/fips_enabled content.strip should cmp == 1",
              "run_time": 0.000363049,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: 1\n     got: \"0\"\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-72069",
          "title": "The file integrity tool must be configured to verify Access Control\nLists (ACLs).",
          "desc": "ACLs can provide permissions beyond those permitted through the file\nmode and must be verified by file integrity tools.",
          "descriptions": [
            {
              "label": "default",
              "data": "ACLs can provide permissions beyond those permitted through the file\nmode and must be verified by file integrity tools."
            },
            {
              "label": "check",
              "data": "Verify the file integrity tool is configured to verify ACLs.\n\nCheck to see if Advanced Intrusion Detection Environment (AIDE) is installed on\nthe system with the following command:\n\n# yum list installed aide\n\nIf AIDE is not installed, ask the System Administrator how file integrity\nchecks are performed on the system.\n\nIf there is no application installed to perform file integrity checks, this is\na finding.\n\nNote: AIDE is highly configurable at install time. These commands assume the\n\"aide.conf\" file is under the \"/etc\" directory.\n\nUse the following command to determine if the file is in another location:\n\n# find / -name aide.conf\n\nCheck the \"aide.conf\" file to determine if the \"acl\" rule has been added to\nthe rule list being applied to the files and directories selection lists.\n\nAn example rule that includes the \"acl\" rule is below:\n\nAll= p+i+n+u+g+s+m+S+sha512+acl+xattrs+selinux\n/bin All            # apply the custom rule to the files in bin\n/sbin All          # apply the same custom rule to the files in sbin\n\nIf the \"acl\" rule is not being used on all selection lines in the\n\"/etc/aide.conf\" file, or ACLs are not being checked by another file\nintegrity tool, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the file integrity tool to check file and directory\nACLs.\n\nIf AIDE is installed, ensure the \"acl\" rule is present on all file and\ndirectory selection lists."
            }
          ],
          "impact": 0.3,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72069",
            "rid": "SV-86693r2_rule",
            "stig_id": "RHEL-07-021600",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "aide"
            ],
            "fix_id": "F-78421r1_fix"
          },
          "code": "control \"V-72069\" do\n  title \"The file integrity tool must be configured to verify Access Control\nLists (ACLs).\"\n  desc  \"ACLs can provide permissions beyond those permitted through the file\nmode and must be verified by file integrity tools.\"\n  impact 0.3\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72069\"\n  tag \"rid\": \"SV-86693r2_rule\"\n  tag \"stig_id\": \"RHEL-07-021600\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['aide']\n  desc \"check\", \"Verify the file integrity tool is configured to verify ACLs.\n\nCheck to see if Advanced Intrusion Detection Environment (AIDE) is installed on\nthe system with the following command:\n\n# yum list installed aide\n\nIf AIDE is not installed, ask the System Administrator how file integrity\nchecks are performed on the system.\n\nIf there is no application installed to perform file integrity checks, this is\na finding.\n\nNote: AIDE is highly configurable at install time. These commands assume the\n\\\"aide.conf\\\" file is under the \\\"/etc\\\" directory.\n\nUse the following command to determine if the file is in another location:\n\n# find / -name aide.conf\n\nCheck the \\\"aide.conf\\\" file to determine if the \\\"acl\\\" rule has been added to\nthe rule list being applied to the files and directories selection lists.\n\nAn example rule that includes the \\\"acl\\\" rule is below:\n\nAll= p+i+n+u+g+s+m+S+sha512+acl+xattrs+selinux\n/bin All            # apply the custom rule to the files in bin\n/sbin All          # apply the same custom rule to the files in sbin\n\nIf the \\\"acl\\\" rule is not being used on all selection lines in the\n\\\"/etc/aide.conf\\\" file, or ACLs are not being checked by another file\nintegrity tool, this is a finding.\"\n  desc \"fix\", \"Configure the file integrity tool to check file and directory\nACLs.\n\nIf AIDE is installed, ensure the \\\"acl\\\" rule is present on all file and\ndirectory selection lists.\"\n  tag \"fix_id\": \"F-78421r1_fix\"\n\n  describe package(\"aide\") do\n    it { should be_installed }\n  end\n\n  findings = []\n  aide_conf.where { !selection_line.start_with? '!' }.entries.each do |selection|\n    unless selection.rules.include? 'acl'\n      findings.append(selection.selection_line)\n    end\n  end\n\n  describe \"List of monitored files/directories without 'acl' rule\" do\n    subject { findings }\n    it { should be_empty }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72069.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "System Package aide should be installed",
              "run_time": 0.000205616,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected that `System Package aide` is installed"
            },
            {
              "status": "passed",
              "code_desc": "List of monitored files/directories without 'acl' rule should be empty",
              "run_time": 0.000134235,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72071",
          "title": "The file integrity tool must be configured to verify extended\nattributes.",
          "desc": "Extended attributes in file systems are used to contain arbitrary data\nand file metadata with security implications.",
          "descriptions": [
            {
              "label": "default",
              "data": "Extended attributes in file systems are used to contain arbitrary data\nand file metadata with security implications."
            },
            {
              "label": "check",
              "data": "Verify the file integrity tool is configured to verify extended\nattributes.\n\nCheck to see if Advanced Intrusion Detection Environment (AIDE) is installed on\nthe system with the following command:\n\n# yum list installed aide\n\nIf AIDE is not installed, ask the System Administrator how file integrity\nchecks are performed on the system.\n\nIf there is no application installed to perform file integrity checks, this is\na finding.\n\nNote: AIDE is highly configurable at install time. These commands assume the\n\"aide.conf\" file is under the \"/etc\" directory.\n\nUse the following command to determine if the file is in another location:\n\n# find / -name aide.conf\n\nCheck the \"aide.conf\" file to determine if the \"xattrs\" rule has been added\nto the rule list being applied to the files and directories selection lists.\n\nAn example rule that includes the \"xattrs\" rule follows:\n\nAll= p+i+n+u+g+s+m+S+sha512+acl+xattrs+selinux\n/bin All            # apply the custom rule to the files in bin\n/sbin All          # apply the same custom rule to the files in sbin\n\nIf the \"xattrs\" rule is not being used on all selection lines in the\n\"/etc/aide.conf\" file, or extended attributes are not being checked by\nanother file integrity tool, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the file integrity tool to check file and directory\nextended attributes.\n\nIf AIDE is installed, ensure the \"xattrs\" rule is present on all file and\ndirectory selection lists."
            }
          ],
          "impact": 0.3,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72071",
            "rid": "SV-86695r2_rule",
            "stig_id": "RHEL-07-021610",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "aide"
            ],
            "fix_id": "F-78423r1_fix"
          },
          "code": "control \"V-72071\" do\n  title \"The file integrity tool must be configured to verify extended\nattributes.\"\n  desc  \"Extended attributes in file systems are used to contain arbitrary data\nand file metadata with security implications.\"\n  impact 0.3\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72071\"\n  tag \"rid\": \"SV-86695r2_rule\"\n  tag \"stig_id\": \"RHEL-07-021610\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['aide']\n  desc \"check\", \"Verify the file integrity tool is configured to verify extended\nattributes.\n\nCheck to see if Advanced Intrusion Detection Environment (AIDE) is installed on\nthe system with the following command:\n\n# yum list installed aide\n\nIf AIDE is not installed, ask the System Administrator how file integrity\nchecks are performed on the system.\n\nIf there is no application installed to perform file integrity checks, this is\na finding.\n\nNote: AIDE is highly configurable at install time. These commands assume the\n\\\"aide.conf\\\" file is under the \\\"/etc\\\" directory.\n\nUse the following command to determine if the file is in another location:\n\n# find / -name aide.conf\n\nCheck the \\\"aide.conf\\\" file to determine if the \\\"xattrs\\\" rule has been added\nto the rule list being applied to the files and directories selection lists.\n\nAn example rule that includes the \\\"xattrs\\\" rule follows:\n\nAll= p+i+n+u+g+s+m+S+sha512+acl+xattrs+selinux\n/bin All            # apply the custom rule to the files in bin\n/sbin All          # apply the same custom rule to the files in sbin\n\nIf the \\\"xattrs\\\" rule is not being used on all selection lines in the\n\\\"/etc/aide.conf\\\" file, or extended attributes are not being checked by\nanother file integrity tool, this is a finding.\"\n  desc \"fix\", \"Configure the file integrity tool to check file and directory\nextended attributes.\n\nIf AIDE is installed, ensure the \\\"xattrs\\\" rule is present on all file and\ndirectory selection lists.\"\n  tag \"fix_id\": \"F-78423r1_fix\"\n\n  describe package(\"aide\") do\n    it { should be_installed }\n  end\n\n  findings = []\n  aide_conf.where { !selection_line.start_with? '!' }.entries.each do |selection|\n    unless selection.rules.include? 'xattrs'\n      findings.append(selection.selection_line)\n    end\n  end\n\n  describe \"List of monitored files/directories without 'xattrs' rule\" do\n    subject { findings }\n    it { should be_empty }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72071.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "System Package aide should be installed",
              "run_time": 0.000170935,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected that `System Package aide` is installed"
            },
            {
              "status": "passed",
              "code_desc": "List of monitored files/directories without 'xattrs' rule should be empty",
              "run_time": 0.000106487,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72073",
          "title": "The file integrity tool must use FIPS 140-2 approved cryptographic\nhashes for validating file contents and directories.",
          "desc": "File integrity tools use cryptographic hashes for verifying file\ncontents and directories have not been altered. These hashes must be FIPS 140-2\napproved cryptographic hashes.",
          "descriptions": [
            {
              "label": "default",
              "data": "File integrity tools use cryptographic hashes for verifying file\ncontents and directories have not been altered. These hashes must be FIPS 140-2\napproved cryptographic hashes."
            },
            {
              "label": "check",
              "data": "Verify the file integrity tool is configured to use FIPS 140-2\napproved cryptographic hashes for validating file contents and directories.\n\nNote: If RHEL-07-021350 is a finding, this is automatically a finding as the\nsystem cannot implement FIPS 140-2 approved cryptographic algorithms and hashes.\n\nCheck to see if Advanced Intrusion Detection Environment (AIDE) is installed on\nthe system with the following command:\n\n# yum list installed aide\n\nIf AIDE is not installed, ask the System Administrator how file integrity\nchecks are performed on the system.\n\nIf there is no application installed to perform file integrity checks, this is\na finding.\n\nNote: AIDE is highly configurable at install time. These commands assume the\n\"aide.conf\" file is under the \"/etc\" directory.\n\nUse the following command to determine if the file is in another location:\n\n# find / -name aide.conf\n\nCheck the \"aide.conf\" file to determine if the \"sha512\" rule has been added\nto the rule list being applied to the files and directories selection lists.\n\nAn example rule that includes the \"sha512\" rule follows:\n\nAll=p+i+n+u+g+s+m+S+sha512+acl+xattrs+selinux\n/bin All            # apply the custom rule to the files in bin\n/sbin All          # apply the same custom rule to the files in sbin\n\nIf the \"sha512\" rule is not being used on all selection lines in the\n\"/etc/aide.conf\" file, or another file integrity tool is not using FIPS 140-2\napproved cryptographic hashes for validating file contents and directories,\nthis is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the file integrity tool to use FIPS 140-2 cryptographic\nhashes for validating file and directory contents.\n\nIf AIDE is installed, ensure the \"sha512\" rule is present on all file and\ndirectory selection lists."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72073",
            "rid": "SV-86697r2_rule",
            "stig_id": "RHEL-07-021620",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "aide"
            ],
            "fix_id": "F-78425r1_fix"
          },
          "code": "control \"V-72073\" do\n  title \"The file integrity tool must use FIPS 140-2 approved cryptographic\nhashes for validating file contents and directories.\"\n  desc  \"File integrity tools use cryptographic hashes for verifying file\ncontents and directories have not been altered. These hashes must be FIPS 140-2\napproved cryptographic hashes.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72073\"\n  tag \"rid\": \"SV-86697r2_rule\"\n  tag \"stig_id\": \"RHEL-07-021620\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['aide']\n  desc \"check\", \"Verify the file integrity tool is configured to use FIPS 140-2\napproved cryptographic hashes for validating file contents and directories.\n\nNote: If RHEL-07-021350 is a finding, this is automatically a finding as the\nsystem cannot implement FIPS 140-2 approved cryptographic algorithms and hashes.\n\nCheck to see if Advanced Intrusion Detection Environment (AIDE) is installed on\nthe system with the following command:\n\n# yum list installed aide\n\nIf AIDE is not installed, ask the System Administrator how file integrity\nchecks are performed on the system.\n\nIf there is no application installed to perform file integrity checks, this is\na finding.\n\nNote: AIDE is highly configurable at install time. These commands assume the\n\\\"aide.conf\\\" file is under the \\\"/etc\\\" directory.\n\nUse the following command to determine if the file is in another location:\n\n# find / -name aide.conf\n\nCheck the \\\"aide.conf\\\" file to determine if the \\\"sha512\\\" rule has been added\nto the rule list being applied to the files and directories selection lists.\n\nAn example rule that includes the \\\"sha512\\\" rule follows:\n\nAll=p+i+n+u+g+s+m+S+sha512+acl+xattrs+selinux\n/bin All            # apply the custom rule to the files in bin\n/sbin All          # apply the same custom rule to the files in sbin\n\nIf the \\\"sha512\\\" rule is not being used on all selection lines in the\n\\\"/etc/aide.conf\\\" file, or another file integrity tool is not using FIPS 140-2\napproved cryptographic hashes for validating file contents and directories,\nthis is a finding.\"\n  desc \"fix\", \"Configure the file integrity tool to use FIPS 140-2 cryptographic\nhashes for validating file and directory contents.\n\nIf AIDE is installed, ensure the \\\"sha512\\\" rule is present on all file and\ndirectory selection lists.\"\n  tag \"fix_id\": \"F-78425r1_fix\"\n\n  # Redundant with V-72063\n  describe package(\"aide\") do\n    it { should be_installed }\n  end\n\n  findings = []\n  aide_conf.where { !selection_line.start_with? '!' }.entries.each do |selection|\n    unless selection.rules.include? 'sha512'\n      findings.append(selection.selection_line)\n    end\n  end\n\n  describe \"List of monitored files/directories without 'sha512' rule\" do\n    subject { findings }\n    it { should be_empty }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72073.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "System Package aide should be installed",
              "run_time": 0.000159388,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected that `System Package aide` is installed"
            },
            {
              "status": "passed",
              "code_desc": "List of monitored files/directories without 'sha512' rule should be empty",
              "run_time": 0.000112072,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72075",
          "title": "The system must not allow removable media to be used as the boot\nloader unless approved.",
          "desc": "Malicious users with removable boot media can gain access to a system\nconfigured to use removable media as the boot loader. If removable media is\ndesigned to be used as the boot loader, the requirement must be documented with\nthe Information System Security Officer (ISSO).",
          "descriptions": [
            {
              "label": "default",
              "data": "Malicious users with removable boot media can gain access to a system\nconfigured to use removable media as the boot loader. If removable media is\ndesigned to be used as the boot loader, the requirement must be documented with\nthe Information System Security Officer (ISSO)."
            },
            {
              "label": "check",
              "data": "Verify the system is not configured to use a boot loader on\nremovable media.\n\nNote: GRUB 2 reads its configuration from the \"/boot/grub2/grub.cfg\" file on\ntraditional BIOS-based machines and from the \"/boot/efi/EFI/redhat/grub.cfg\"\nfile on UEFI machines.\n\nCheck for the existence of alternate boot loader configuration files with the\nfollowing command:\n\n# find / -name grub.cfg\n/boot/grub2/grub.cfg\n\nIf a \"grub.cfg\" is found in any subdirectories other than \"/boot/grub2\" and\n\"/boot/efi/EFI/redhat\", ask the System Administrator if there is\ndocumentation signed by the ISSO to approve the use of removable media as a\nboot loader.\n\nCheck that the grub configuration file has the set root command in each menu\nentry with the following commands:\n\n# grep -c menuentry /boot/grub2/grub.cfg\n1\n# grep ‘set root’ /boot/grub2/grub.cfg\nset root=(hd0,1)\n\nIf the system is using an alternate boot loader on removable media, and\ndocumentation does not exist approving the alternate configuration, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Remove alternate methods of booting the system from removable\nmedia or document the configuration to boot from removable media with the ISSO."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000364-GPOS-00151",
            "gid": "V-72075",
            "rid": "SV-86699r1_rule",
            "stig_id": "RHEL-07-021700",
            "cci": [
              "CCI-000318",
              "CCI-000368",
              "CCI-001812",
              "CCI-001813",
              "CCI-001814"
            ],
            "documentable": false,
            "nist": [
              "CM-3 f",
              "CM-6 c",
              "CM-11 (2)",
              "CM-5 (1)",
              "CM-5 (1)",
              "Rev_4"
            ],
            "subsystems": [
              "grub"
            ],
            "fix_id": "F-78427r1_fix"
          },
          "code": "control \"V-72075\" do\n  title \"The system must not allow removable media to be used as the boot\nloader unless approved.\"\n  desc  \"Malicious users with removable boot media can gain access to a system\nconfigured to use removable media as the boot loader. If removable media is\ndesigned to be used as the boot loader, the requirement must be documented with\nthe Information System Security Officer (ISSO).\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000364-GPOS-00151\"\n  tag \"gid\": \"V-72075\"\n  tag \"rid\": \"SV-86699r1_rule\"\n  tag \"stig_id\": \"RHEL-07-021700\"\n  tag \"cci\": [\"CCI-000318\", \"CCI-000368\", \"CCI-001812\", \"CCI-001813\",\n\"CCI-001814\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-3 f\", \"CM-6 c\", \"CM-11 (2)\", \"CM-5 (1)\", \"CM-5 (1)\", \"Rev_4\"]\n  tag \"subsystems\": ['grub']\n  desc \"check\", \"Verify the system is not configured to use a boot loader on\nremovable media.\n\nNote: GRUB 2 reads its configuration from the \\\"/boot/grub2/grub.cfg\\\" file on\ntraditional BIOS-based machines and from the \\\"/boot/efi/EFI/redhat/grub.cfg\\\"\nfile on UEFI machines.\n\nCheck for the existence of alternate boot loader configuration files with the\nfollowing command:\n\n# find / -name grub.cfg\n/boot/grub2/grub.cfg\n\nIf a \\\"grub.cfg\\\" is found in any subdirectories other than \\\"/boot/grub2\\\" and\n\\\"/boot/efi/EFI/redhat\\\", ask the System Administrator if there is\ndocumentation signed by the ISSO to approve the use of removable media as a\nboot loader.\n\nCheck that the grub configuration file has the set root command in each menu\nentry with the following commands:\n\n# grep -c menuentry /boot/grub2/grub.cfg\n1\n# grep ‘set root’ /boot/grub2/grub.cfg\nset root=(hd0,1)\n\nIf the system is using an alternate boot loader on removable media, and\ndocumentation does not exist approving the alternate configuration, this is a\nfinding.\"\n  desc \"fix\", \"Remove alternate methods of booting the system from removable\nmedia or document the configuration to boot from removable media with the ISSO.\"\n  tag \"fix_id\": \"F-78427r1_fix\"\n\n  roots = command('grubby --info=ALL | grep \"^root=\" | sed \"s/^root=//g\"').\n    stdout.strip.split(\"\\n\")\n\n  blocks = roots.map { |root|\n    root_file = file(root)\n    root_file.symlink? ? root_file.link_path : root_file.path\n  }\n\n  blocks.each { |block|\n    block_file = file(block)\n    describe block_file do\n      it { should exist }\n      its('path') { should match %r{^/dev/} }\n    end\n\n    if block_file.exist? and block_file.path.match? %r{^/dev/}\n      removable = ['/sys/block', block.sub(%r{^/dev/}, ''), 'removable'].join('/')\n      describe file(removable) do\n        it { should exist }\n        its('content.strip') { should eq '0' }\n      end\n    end\n  }\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72075.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "File /dev/dm-0 should exist",
              "run_time": 0.000158981,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /dev/dm-0 path should match /^\\/dev\\//",
              "run_time": 0.00011422,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /sys/block/dm-0/removable should exist",
              "run_time": 0.000112208,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /sys/block/dm-0/removable content.strip should eq \"0\"",
              "run_time": 0.000165919,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /dev/dm-0 should exist",
              "run_time": 8.6062e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /dev/dm-0 path should match /^\\/dev\\//",
              "run_time": 0.000104561,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /sys/block/dm-0/removable should exist",
              "run_time": 9.5564e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /sys/block/dm-0/removable content.strip should eq \"0\"",
              "run_time": 9.8015e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /dev/dm-0 should exist",
              "run_time": 8.2765e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /dev/dm-0 path should match /^\\/dev\\//",
              "run_time": 9.6169e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /sys/block/dm-0/removable should exist",
              "run_time": 9.3668e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /sys/block/dm-0/removable content.strip should eq \"0\"",
              "run_time": 9.5448e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72077",
          "title": "The telnet-server package must not be installed.",
          "desc": "It is detrimental for operating systems to provide, or install by default,\nfunctionality exceeding requirements or mission objectives. These unnecessary\ncapabilities or services are often overlooked and therefore may remain\nunsecured. They increase the risk to the platform by providing additional\nattack vectors.\n\n    Operating systems are capable of providing a wide variety of functions and\nservices. Some of the functions and services, provided by default, may not be\nnecessary to support essential organizational operations (e.g., key missions,\nfunctions).\n\n    Examples of non-essential capabilities include, but are not limited to,\ngames, software packages, tools, and demonstration software not related to\nrequirements or providing a wide array of functionality not required for every\nmission, but which cannot be disabled.",
          "descriptions": [
            {
              "label": "default",
              "data": "It is detrimental for operating systems to provide, or install by default,\nfunctionality exceeding requirements or mission objectives. These unnecessary\ncapabilities or services are often overlooked and therefore may remain\nunsecured. They increase the risk to the platform by providing additional\nattack vectors.\n\n    Operating systems are capable of providing a wide variety of functions and\nservices. Some of the functions and services, provided by default, may not be\nnecessary to support essential organizational operations (e.g., key missions,\nfunctions).\n\n    Examples of non-essential capabilities include, but are not limited to,\ngames, software packages, tools, and demonstration software not related to\nrequirements or providing a wide array of functionality not required for every\nmission, but which cannot be disabled."
            },
            {
              "label": "check",
              "data": "Verify the operating system is configured to disable\nnon-essential capabilities. The most secure way of ensuring a non-essential\ncapability is disabled is to not have the capability installed.\n\nThe telnet service provides an unencrypted remote access service that does not\nprovide for the confidentiality and integrity of user passwords or the remote\nsession.\n\nIf a privileged user were to log on using this service, the privileged user\npassword could be compromised.\n\nCheck to see if the telnet-server package is installed with the following\ncommand:\n\n# yum list installed | grep telnet-server\n\nIf the telnet-server package is installed, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to disable non-essential\ncapabilities by removing the telnet-server package from the system with the\nfollowing command:\n\n# yum remove telnet-server"
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000095-GPOS-00049",
            "gid": "V-72077",
            "rid": "SV-86701r1_rule",
            "stig_id": "RHEL-07-021710",
            "cci": [
              "CCI-000381"
            ],
            "documentable": false,
            "nist": [
              "CM-7 a",
              "Rev_4"
            ],
            "subsystems": [
              "packages"
            ],
            "fix_id": "F-78429r1_fix"
          },
          "code": "control \"V-72077\" do\n  title \"The telnet-server package must not be installed.\"\n  desc  \"\n    It is detrimental for operating systems to provide, or install by default,\nfunctionality exceeding requirements or mission objectives. These unnecessary\ncapabilities or services are often overlooked and therefore may remain\nunsecured. They increase the risk to the platform by providing additional\nattack vectors.\n\n    Operating systems are capable of providing a wide variety of functions and\nservices. Some of the functions and services, provided by default, may not be\nnecessary to support essential organizational operations (e.g., key missions,\nfunctions).\n\n    Examples of non-essential capabilities include, but are not limited to,\ngames, software packages, tools, and demonstration software not related to\nrequirements or providing a wide array of functionality not required for every\nmission, but which cannot be disabled.\n  \"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000095-GPOS-00049\"\n  tag \"gid\": \"V-72077\"\n  tag \"rid\": \"SV-86701r1_rule\"\n  tag \"stig_id\": \"RHEL-07-021710\"\n  tag \"cci\": [\"CCI-000381\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-7 a\", \"Rev_4\"]\n  tag \"subsystems\": ['packages']\n  desc \"check\", \"Verify the operating system is configured to disable\nnon-essential capabilities. The most secure way of ensuring a non-essential\ncapability is disabled is to not have the capability installed.\n\nThe telnet service provides an unencrypted remote access service that does not\nprovide for the confidentiality and integrity of user passwords or the remote\nsession.\n\nIf a privileged user were to log on using this service, the privileged user\npassword could be compromised.\n\nCheck to see if the telnet-server package is installed with the following\ncommand:\n\n# yum list installed | grep telnet-server\n\nIf the telnet-server package is installed, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to disable non-essential\ncapabilities by removing the telnet-server package from the system with the\nfollowing command:\n\n# yum remove telnet-server\"\n  tag \"fix_id\": \"F-78429r1_fix\"\n\n  describe package('telnet-server') do\n    it { should_not be_installed }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72077.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "System Package telnet-server should not be installed",
              "run_time": 0.059480609,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72079",
          "title": "Auditing must be configured to produce records containing information\nto establish what type of events occurred, where the events occurred, the\nsource of the events, and the outcome of the events.\n\nThese audit records must also identify individual identities of group account\nusers.",
          "desc": "Without establishing what type of events occurred, it would be difficult to\nestablish, correlate, and investigate the events leading up to an outage or\nattack.\n\n    Audit record content that may be necessary to satisfy this requirement\nincludes, for example, time stamps, source and destination addresses,\nuser/process identifiers, event descriptions, success/fail indications,\nfilenames involved, and access control or flow control rules invoked.\n\n    Associating event types with detected events in the operating system audit\nlogs provides a means of investigating an attack; recognizing resource\nutilization or capacity thresholds; or identifying an improperly configured\noperating system.",
          "descriptions": [
            {
              "label": "default",
              "data": "Without establishing what type of events occurred, it would be difficult to\nestablish, correlate, and investigate the events leading up to an outage or\nattack.\n\n    Audit record content that may be necessary to satisfy this requirement\nincludes, for example, time stamps, source and destination addresses,\nuser/process identifiers, event descriptions, success/fail indications,\nfilenames involved, and access control or flow control rules invoked.\n\n    Associating event types with detected events in the operating system audit\nlogs provides a means of investigating an attack; recognizing resource\nutilization or capacity thresholds; or identifying an improperly configured\noperating system."
            },
            {
              "label": "check",
              "data": "Verify the operating system produces audit records containing\ninformation to establish when (date and time) the events occurred.\n\nCheck to see if auditing is active by issuing the following command:\n\n# systemctl is-active auditd.service\nActive: active (running) since Tue 2015-01-27 19:41:23 EST; 22h ago\n\nIf the \"auditd\" status is not active, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to produce audit records\ncontaining information to establish when (date and time) the events occurred.\n\nEnable the auditd service with the following command:\n\n# systemctl start auditd.service"
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000038-GPOS-00016",
            "satisfies": [
              "SRG-OS-000038-GPOS-00016",
              "SRG-OS-000039-GPOS-00017",
              "SRG-OS-000042-GPOS-00021",
              "SRG-OS-000254-GPOS-00095",
              "SRG-OS-000255-GPOS-00096"
            ],
            "gid": "V-72079",
            "rid": "SV-86703r2_rule",
            "stig_id": "RHEL-07-030000",
            "cci": [
              "CCI-000126",
              "CCI-000131"
            ],
            "documentable": false,
            "nist": [
              "AU-2 d",
              "AU-3",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd"
            ],
            "fix_id": "F-78431r2_fix"
          },
          "code": "control \"V-72079\" do\n  title \"Auditing must be configured to produce records containing information\nto establish what type of events occurred, where the events occurred, the\nsource of the events, and the outcome of the events.\n\nThese audit records must also identify individual identities of group account\nusers.\"\n  desc  \"\n    Without establishing what type of events occurred, it would be difficult to\nestablish, correlate, and investigate the events leading up to an outage or\nattack.\n\n    Audit record content that may be necessary to satisfy this requirement\nincludes, for example, time stamps, source and destination addresses,\nuser/process identifiers, event descriptions, success/fail indications,\nfilenames involved, and access control or flow control rules invoked.\n\n    Associating event types with detected events in the operating system audit\nlogs provides a means of investigating an attack; recognizing resource\nutilization or capacity thresholds; or identifying an improperly configured\noperating system.\n  \"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000038-GPOS-00016\"\n  tag \"satisfies\": [\"SRG-OS-000038-GPOS-00016\", \"SRG-OS-000039-GPOS-00017\",\n\"SRG-OS-000042-GPOS-00021\", \"SRG-OS-000254-GPOS-00095\",\n\"SRG-OS-000255-GPOS-00096\"]\n  tag \"gid\": \"V-72079\"\n  tag \"rid\": \"SV-86703r2_rule\"\n  tag \"stig_id\": \"RHEL-07-030000\"\n  tag \"cci\": [\"CCI-000126\", \"CCI-000131\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-2 d\", \"AU-3\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd']\n  desc \"check\", \"Verify the operating system produces audit records containing\ninformation to establish when (date and time) the events occurred.\n\nCheck to see if auditing is active by issuing the following command:\n\n# systemctl is-active auditd.service\nActive: active (running) since Tue 2015-01-27 19:41:23 EST; 22h ago\n\nIf the \\\"auditd\\\" status is not active, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to produce audit records\ncontaining information to establish when (date and time) the events occurred.\n\nEnable the auditd service with the following command:\n\n# systemctl start auditd.service\"\n  tag \"fix_id\": \"F-78431r2_fix\"\n\n  describe service('auditd') do\n    it { should be_running }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72079.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Service auditd should be running",
              "run_time": 0.064141543,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72081",
          "title": "The operating system must shut down upon audit processing failure,\nunless availability is an overriding concern. If availability is a concern, the\nsystem must alert the designated staff (System Administrator [SA] and\nInformation System Security Officer [ISSO] at a minimum) in the event of an\naudit processing failure.",
          "desc": "It is critical for the appropriate personnel to be aware if a system is at\nrisk of failing to process audit logs as required. Without this notification,\nthe security personnel may be unaware of an impending failure of the audit\ncapability, and system operation may be adversely affected.\n\n    Audit processing failures include software/hardware errors, failures in the\naudit capturing mechanisms, and audit storage capacity being reached or\nexceeded.\n\n    This requirement applies to each audit data storage repository (i.e.,\ndistinct information system component where audit records are stored), the\ncentralized audit storage capacity of organizations (i.e., all audit data\nstorage repositories combined), or both.",
          "descriptions": [
            {
              "label": "default",
              "data": "It is critical for the appropriate personnel to be aware if a system is at\nrisk of failing to process audit logs as required. Without this notification,\nthe security personnel may be unaware of an impending failure of the audit\ncapability, and system operation may be adversely affected.\n\n    Audit processing failures include software/hardware errors, failures in the\naudit capturing mechanisms, and audit storage capacity being reached or\nexceeded.\n\n    This requirement applies to each audit data storage repository (i.e.,\ndistinct information system component where audit records are stored), the\ncentralized audit storage capacity of organizations (i.e., all audit data\nstorage repositories combined), or both."
            },
            {
              "label": "check",
              "data": "Confirm the audit configuration regarding how auditing processing\nfailures are handled.\n\nCheck to see what level \"auditctl\" is set to with following command:\n\n# auditctl -s | grep -i \"fail\"\n\nfailure 2\n\nIf the value of \"failure\" is set to \"2\", the system is configured to panic\n(shut down) in the event of an auditing failure.\n\nIf the value of \"failure\" is set to \"1\", the system is configured to only\nsend information to the kernel log regarding the failure.\n\nIf the \"failure\" setting is not set, this is a CAT I finding.\n\nIf the \"failure\" setting is set to any value other than \"1\" or \"2\", this\nis a CAT II finding.\n\nIf the \"failure\" setting is set to \"1\" but the availability concern is not\ndocumented or there is no monitoring of the kernel log, this is a CAT III\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to shut down in the event of an\naudit processing failure.\n\nAdd or correct the option to shut down the operating system with the following\ncommand:\n\n# auditctl -f 2\n\nEdit the \"/etc/audit/rules.d/audit.rules\" file and add the following line:\n\n-f 2\n\nIf availability has been determined to be more important, and this decision is\ndocumented with the ISSO, configure the operating system to notify system\nadministration staff and ISSO staff in the event of an audit processing failure\nwith the following command:\n\n# auditctl -f 1\n\nEdit the \"/etc/audit/rules.d/audit.rules\" file and add the following line:\n\n-f 1\n\nKernel log monitoring must also be configured to properly alert designated\nstaff.\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000046-GPOS-00022",
            "satisfies": [
              "SRG-OS-000046-GPOS-00022",
              "SRG-OS-000047-GPOS-00023"
            ],
            "gid": "V-72081",
            "rid": "SV-86705r3_rule",
            "stig_id": "RHEL-07-030010",
            "cci": [
              "CCI-000139"
            ],
            "documentable": false,
            "nist": [
              "AU-5 a",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd"
            ],
            "fix_id": "F-78433r2_fix"
          },
          "code": "control \"V-72081\" do\n  title \"The operating system must shut down upon audit processing failure,\nunless availability is an overriding concern. If availability is a concern, the\nsystem must alert the designated staff (System Administrator [SA] and\nInformation System Security Officer [ISSO] at a minimum) in the event of an\naudit processing failure.\"\n  desc  \"\n    It is critical for the appropriate personnel to be aware if a system is at\nrisk of failing to process audit logs as required. Without this notification,\nthe security personnel may be unaware of an impending failure of the audit\ncapability, and system operation may be adversely affected.\n\n    Audit processing failures include software/hardware errors, failures in the\naudit capturing mechanisms, and audit storage capacity being reached or\nexceeded.\n\n    This requirement applies to each audit data storage repository (i.e.,\ndistinct information system component where audit records are stored), the\ncentralized audit storage capacity of organizations (i.e., all audit data\nstorage repositories combined), or both.\n  \"\n  if auditd.status['failure'].nil?\n    impact 0.7\n  elsif auditd.status['failure'].match?(%r{^1$}) && !monitor_kernel_log\n    impact 0.3\n  else\n    impact 0.5\n  end\n\n  tag \"gtitle\": \"SRG-OS-000046-GPOS-00022\"\n  tag \"satisfies\": [\"SRG-OS-000046-GPOS-00022\", \"SRG-OS-000047-GPOS-00023\"]\n  tag \"gid\": \"V-72081\"\n  tag \"rid\": \"SV-86705r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030010\"\n  tag \"cci\": [\"CCI-000139\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-5 a\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd']\n  desc \"check\", \"Confirm the audit configuration regarding how auditing processing\nfailures are handled.\n\nCheck to see what level \\\"auditctl\\\" is set to with following command:\n\n# auditctl -s | grep -i \\\"fail\\\"\n\nfailure 2\n\nIf the value of \\\"failure\\\" is set to \\\"2\\\", the system is configured to panic\n(shut down) in the event of an auditing failure.\n\nIf the value of \\\"failure\\\" is set to \\\"1\\\", the system is configured to only\nsend information to the kernel log regarding the failure.\n\nIf the \\\"failure\\\" setting is not set, this is a CAT I finding.\n\nIf the \\\"failure\\\" setting is set to any value other than \\\"1\\\" or \\\"2\\\", this\nis a CAT II finding.\n\nIf the \\\"failure\\\" setting is set to \\\"1\\\" but the availability concern is not\ndocumented or there is no monitoring of the kernel log, this is a CAT III\nfinding.\n\"\n  desc \"fix\", \"Configure the operating system to shut down in the event of an\naudit processing failure.\n\nAdd or correct the option to shut down the operating system with the following\ncommand:\n\n# auditctl -f 2\n\nEdit the \\\"/etc/audit/rules.d/audit.rules\\\" file and add the following line:\n\n-f 2\n\nIf availability has been determined to be more important, and this decision is\ndocumented with the ISSO, configure the operating system to notify system\nadministration staff and ISSO staff in the event of an audit processing failure\nwith the following command:\n\n# auditctl -f 1\n\nEdit the \\\"/etc/audit/rules.d/audit.rules\\\" file and add the following line:\n\n-f 1\n\nKernel log monitoring must also be configured to properly alert designated\nstaff.\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78433r2_fix\"\n\n  if !monitor_kernel_log\n    describe auditd.status['failure'] do\n      it { should match %r{^2$} }\n    end\n  else\n    describe auditd.status['failure'] do\n      it { should match %r{^(1|2)$} }\n    end\n  end\nend\n",
          "source_location": {
            "line": 11,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72081.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "1 should match /^(1|2)$/",
              "run_time": 0.000146607,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72083",
          "title": "The operating system must off-load audit records onto a different\nsystem or media from the system being audited.",
          "desc": "Information stored in one location is vulnerable to accidental or\nincidental deletion or alteration.\n\n    Off-loading is a common process in information systems with limited audit\nstorage capacity.",
          "descriptions": [
            {
              "label": "default",
              "data": "Information stored in one location is vulnerable to accidental or\nincidental deletion or alteration.\n\n    Off-loading is a common process in information systems with limited audit\nstorage capacity."
            },
            {
              "label": "check",
              "data": "Verify the operating system off-loads audit records onto a different\nsystem or media from the system being audited.\n\nTo determine the remote server that the records are being sent to, use the\nfollowing command:\n\n# grep -i remote_server /etc/audisp/audisp-remote.conf\nremote_server = 10.0.21.1\n\nIf a remote server is not configured, or the line is commented out, ask the\nSystem Administrator to indicate how the audit logs are off-loaded to a\ndifferent system or media.\n\nIf there is no evidence that the audit logs are being off-loaded to another\nsystem or media, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to off-load audit records onto a\ndifferent system or media from the system being audited.\n\nSet the remote server option in \"/etc/audisp/audisp-remote.conf\" with the IP\naddress of the log aggregation server."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000342-GPOS-00133",
            "satisfies": [
              "SRG-OS-000342-GPOS-00133",
              "SRG-OS-000479-GPOS-00224"
            ],
            "gid": "V-72083",
            "rid": "SV-86707r1_rule",
            "stig_id": "RHEL-07-030300",
            "cci": [
              "CCI-001851"
            ],
            "documentable": false,
            "nist": [
              "AU-4 (1)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audisp"
            ],
            "fix_id": "F-78435r1_fix"
          },
          "code": "control \"V-72083\" do\n  title \"The operating system must off-load audit records onto a different\nsystem or media from the system being audited.\"\n  desc  \"\n    Information stored in one location is vulnerable to accidental or\nincidental deletion or alteration.\n\n    Off-loading is a common process in information systems with limited audit\nstorage capacity.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000342-GPOS-00133\"\n  tag \"satisfies\": [\"SRG-OS-000342-GPOS-00133\", \"SRG-OS-000479-GPOS-00224\"]\n  tag \"gid\": \"V-72083\"\n  tag \"rid\": \"SV-86707r1_rule\"\n  tag \"stig_id\": \"RHEL-07-030300\"\n  tag \"cci\": [\"CCI-001851\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-4 (1)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audisp']\n  desc \"check\", \"Verify the operating system off-loads audit records onto a different\nsystem or media from the system being audited.\n\nTo determine the remote server that the records are being sent to, use the\nfollowing command:\n\n# grep -i remote_server /etc/audisp/audisp-remote.conf\nremote_server = 10.0.21.1\n\nIf a remote server is not configured, or the line is commented out, ask the\nSystem Administrator to indicate how the audit logs are off-loaded to a\ndifferent system or media.\n\nIf there is no evidence that the audit logs are being off-loaded to another\nsystem or media, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to off-load audit records onto a\ndifferent system or media from the system being audited.\n\nSet the remote server option in \\\"/etc/audisp/audisp-remote.conf\\\" with the IP\naddress of the log aggregation server.\"\n  tag \"fix_id\": \"F-78435r1_fix\"\n\n  if file('/etc/audisp/audisp-remote.conf').exist?\n    describe parse_config_file('/etc/audisp/audisp-remote.conf') do\n      its('remote_server') { should match %r{^\\S+$} }\n      its('remote_server') { should_not match %r{localhost|127.0.0.1} }\n    end\n  else\n    describe \"File '/etc/audisp/audisp-remote.conf' cannot be found. This test cannot be checked in a automated fashion and you must check it manually\" do\n      skip \"File '/etc/audisp/audisp-remote.conf' cannot be found. This check must be performed manually\"\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72083.rb"
          },
          "results": [
            {
              "status": "skipped",
              "code_desc": "File '/etc/audisp/audisp-remote.conf' cannot be found. This test cannot be checked in a automated fashion and you must check it manually",
              "run_time": 2.096e-05,
              "start_time": "2019-11-04T16:17:15-05:00",
              "resource": "",
              "skip_message": "File '/etc/audisp/audisp-remote.conf' cannot be found. This check must be performed manually"
            }
          ]
        },
        {
          "id": "V-72085",
          "title": "The operating system must encrypt the transfer of audit records\noff-loaded onto a different system or media from the system being audited.",
          "desc": "Information stored in one location is vulnerable to accidental or\nincidental deletion or alteration.\n\n    Off-loading is a common process in information systems with limited audit\nstorage capacity.",
          "descriptions": [
            {
              "label": "default",
              "data": "Information stored in one location is vulnerable to accidental or\nincidental deletion or alteration.\n\n    Off-loading is a common process in information systems with limited audit\nstorage capacity."
            },
            {
              "label": "check",
              "data": "Verify the operating system encrypts audit records off-loaded\nonto a different system or media from the system being audited.\n\nTo determine if the transfer is encrypted, use the following command:\n\n# grep -i enable_krb5 /etc/audisp/audisp-remote.conf\nenable_krb5 = yes\n\nIf the value of the \"enable_krb5\" option is not set to \"yes\" or the line is\ncommented out, ask the System Administrator to indicate how the audit logs are\noff-loaded to a different system or media.\n\nIf there is no evidence that the transfer of the audit logs being off-loaded to\nanother system or media is encrypted, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to encrypt the transfer of\noff-loaded audit records onto a different system or media from the system being\naudited.\n\nUncomment the \"enable_krb5\" option in \"/etc/audisp/audisp-remote.conf\" and\nset it with the following line:\n\nenable_krb5 = yes"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000342-GPOS-00133",
            "satisfies": [
              "SRG-OS-000342-GPOS-00133",
              "SRG-OS-000479-GPOS-00224"
            ],
            "gid": "V-72085",
            "rid": "SV-86709r1_rule",
            "stig_id": "RHEL-07-030310",
            "cci": [
              "CCI-001851"
            ],
            "documentable": false,
            "nist": [
              "AU-4 (1)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audisp"
            ],
            "fix_id": "F-78437r1_fix"
          },
          "code": "control \"V-72085\" do\n  title \"The operating system must encrypt the transfer of audit records\noff-loaded onto a different system or media from the system being audited.\"\n  desc  \"\n    Information stored in one location is vulnerable to accidental or\nincidental deletion or alteration.\n\n    Off-loading is a common process in information systems with limited audit\nstorage capacity.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000342-GPOS-00133\"\n  tag \"satisfies\": [\"SRG-OS-000342-GPOS-00133\", \"SRG-OS-000479-GPOS-00224\"]\n  tag \"gid\": \"V-72085\"\n  tag \"rid\": \"SV-86709r1_rule\"\n  tag \"stig_id\": \"RHEL-07-030310\"\n  tag \"cci\": [\"CCI-001851\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-4 (1)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audisp']\n  desc \"check\", \"Verify the operating system encrypts audit records off-loaded\nonto a different system or media from the system being audited.\n\nTo determine if the transfer is encrypted, use the following command:\n\n# grep -i enable_krb5 /etc/audisp/audisp-remote.conf\nenable_krb5 = yes\n\nIf the value of the \\\"enable_krb5\\\" option is not set to \\\"yes\\\" or the line is\ncommented out, ask the System Administrator to indicate how the audit logs are\noff-loaded to a different system or media.\n\nIf there is no evidence that the transfer of the audit logs being off-loaded to\nanother system or media is encrypted, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to encrypt the transfer of\noff-loaded audit records onto a different system or media from the system being\naudited.\n\nUncomment the \\\"enable_krb5\\\" option in \\\"/etc/audisp/audisp-remote.conf\\\" and\nset it with the following line:\n\nenable_krb5 = yes\"\n  tag \"fix_id\": \"F-78437r1_fix\"\n\n  describe parse_config_file('/etc/audisp/audisp-remote.conf') do\n    its('enable_krb5.strip') { should cmp 'yes' }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72085.rb"
          },
          "results": [
            {
              "status": "skipped",
              "code_desc": "Parse Config File /etc/audisp/audisp-remote.conf",
              "run_time": 8.689e-06,
              "start_time": "2019-11-04T16:17:15-05:00",
              "resource": "Parse Config File /etc/audisp/audisp-remote.conf",
              "skip_message": "Can't find file: /etc/audisp/audisp-remote.conf"
            }
          ]
        },
        {
          "id": "V-72087",
          "title": "The audit system must take appropriate action when the audit storage\nvolume is full.",
          "desc": "Taking appropriate action in case of a filled audit storage volume\nwill minimize the possibility of losing audit records.",
          "descriptions": [
            {
              "label": "default",
              "data": "Taking appropriate action in case of a filled audit storage volume\nwill minimize the possibility of losing audit records."
            },
            {
              "label": "check",
              "data": "Verify the action the operating system takes if the disk the audit\nrecords are written to becomes full.\n\nTo determine the action that takes place if the disk is full on the remote\nserver, use the following command:\n\n# grep -i disk_full_action /etc/audisp/audisp-remote.conf\ndisk_full_action = single\n\nTo determine the action that takes place if the network connection fails, use\nthe following command:\n\n# grep -i network_failure_action /etc/audisp/audisp-remote.conf\nnetwork_failure_action = stop\n\nIf the value of the \"network_failure_action\" option is not \"syslog\",\n\"single\", or \"halt\", or the line is commented out, this is a finding.\n\nIf the value of the \"disk_full_action\" option is not \"syslog\", \"single\",\nor \"halt\", or the line is commented out, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the action the operating system takes if the disk the\naudit records are written to becomes full.\n\nUncomment or edit the \"disk_full_action\" option in\n\"/etc/audisp/audisp-remote.conf\" and set it to \"syslog\", \"single\", or\n\"halt\", such as the following line:\n\ndisk_full_action = single\n\nUncomment the \"network_failure_action\" option in\n\"/etc/audisp/audisp-remote.conf\" and set it to \"syslog\", \"single\", or\n\"halt\"."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000342-GPOS-00133",
            "gid": "V-72087",
            "rid": "SV-86711r2_rule",
            "stig_id": "RHEL-07-030320",
            "cci": [
              "CCI-001851"
            ],
            "documentable": false,
            "nist": [
              "AU-4 (1)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd"
            ],
            "fix_id": "F-78439r3_fix"
          },
          "code": "control \"V-72087\" do\n  title \"The audit system must take appropriate action when the audit storage\nvolume is full.\"\n  desc  \"Taking appropriate action in case of a filled audit storage volume\nwill minimize the possibility of losing audit records.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000342-GPOS-00133\"\n  tag \"gid\": \"V-72087\"\n  tag \"rid\": \"SV-86711r2_rule\"\n  tag \"stig_id\": \"RHEL-07-030320\"\n  tag \"cci\": [\"CCI-001851\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-4 (1)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd']\n  desc \"check\", \"Verify the action the operating system takes if the disk the audit\nrecords are written to becomes full.\n\nTo determine the action that takes place if the disk is full on the remote\nserver, use the following command:\n\n# grep -i disk_full_action /etc/audisp/audisp-remote.conf\ndisk_full_action = single\n\nTo determine the action that takes place if the network connection fails, use\nthe following command:\n\n# grep -i network_failure_action /etc/audisp/audisp-remote.conf\nnetwork_failure_action = stop\n\nIf the value of the \\\"network_failure_action\\\" option is not \\\"syslog\\\",\n\\\"single\\\", or \\\"halt\\\", or the line is commented out, this is a finding.\n\nIf the value of the \\\"disk_full_action\\\" option is not \\\"syslog\\\", \\\"single\\\",\nor \\\"halt\\\", or the line is commented out, this is a finding.\"\n  desc \"fix\", \"Configure the action the operating system takes if the disk the\naudit records are written to becomes full.\n\nUncomment or edit the \\\"disk_full_action\\\" option in\n\\\"/etc/audisp/audisp-remote.conf\\\" and set it to \\\"syslog\\\", \\\"single\\\", or\n\\\"halt\\\", such as the following line:\n\ndisk_full_action = single\n\nUncomment the \\\"network_failure_action\\\" option in\n\\\"/etc/audisp/audisp-remote.conf\\\" and set it to \\\"syslog\\\", \\\"single\\\", or\n\\\"halt\\\".\"\n  tag \"fix_id\": \"F-78439r3_fix\"\n\n  describe parse_config_file('/etc/audisp/audisp-remote.conf') do\n    its('disk_full_action.strip') { should match %r{^(syslog|single|halt)$} }\n  end\n\n# Test matches ./inspec-profiles/controls/V-73163.rb\n  describe parse_config_file('/etc/audisp/audisp-remote.conf') do\n    its('network_failure_action.strip') { should match %r{^(syslog|single|halt)$} }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72087.rb"
          },
          "results": [
            {
              "status": "skipped",
              "code_desc": "Parse Config File /etc/audisp/audisp-remote.conf",
              "run_time": 7.581e-06,
              "start_time": "2019-11-04T16:17:15-05:00",
              "resource": "Parse Config File /etc/audisp/audisp-remote.conf",
              "skip_message": "Can't find file: /etc/audisp/audisp-remote.conf"
            },
            {
              "status": "skipped",
              "code_desc": "Parse Config File /etc/audisp/audisp-remote.conf",
              "run_time": 7.394e-06,
              "start_time": "2019-11-04T16:17:15-05:00",
              "resource": "Parse Config File /etc/audisp/audisp-remote.conf",
              "skip_message": "Can't find file: /etc/audisp/audisp-remote.conf"
            }
          ]
        },
        {
          "id": "V-72089",
          "title": "The operating system must immediately notify the System Administrator\n(SA) and Information System Security Officer ISSO (at a minimum) when allocated\naudit record storage volume reaches 75% of the repository maximum audit record\nstorage capacity.",
          "desc": "If security personnel are not notified immediately when storage volume\nreaches 75 percent utilization, they are unable to plan for audit record\nstorage capacity expansion.",
          "descriptions": [
            {
              "label": "default",
              "data": "If security personnel are not notified immediately when storage volume\nreaches 75 percent utilization, they are unable to plan for audit record\nstorage capacity expansion."
            },
            {
              "label": "check",
              "data": "Verify the operating system immediately notifies the SA and\nISSO (at a minimum) when allocated audit record storage volume reaches 75\npercent of the repository maximum audit record storage capacity.\n\nCheck the system configuration to determine the partition the audit records are\nbeing written to with the following command:\n\n# grep log_file /etc/audit/auditd.conf\nlog_file = /var/log/audit/audit.log\n\nCheck the size of the partition that audit records are written to (with the\nexample being \"/var/log/audit/\"):\n\n# df -h /var/log/audit/\n0.9G /var/log/audit\n\nIf the audit records are not being written to a partition specifically created\nfor audit records (in this example \"/var/log/audit\" is a separate partition),\ndetermine the amount of space other files in the partition are currently\noccupying with the following command:\n\n# du -sh <partition>\n1.8G /var\n\nDetermine what the threshold is for the system to take action when 75 percent\nof the repository maximum audit record storage capacity is reached:\n\n# grep -i space_left /etc/audit/auditd.conf\nspace_left = 225\n\nIf the value of the \"space_left\" keyword is not set to 25 percent of the\ntotal partition size, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to immediately notify the SA and\nISSO (at a minimum) when allocated audit record storage volume reaches 75\npercent of the repository maximum audit record storage capacity.\n\nCheck the system configuration to determine the partition the audit records are\nbeing written to:\n\n# grep log_file /etc/audit/auditd.conf\n\nDetermine the size of the partition that audit records are written to (with the\nexample being \"/var/log/audit/\"):\n\n# df -h /var/log/audit/\n\nSet the value of the \"space_left\" keyword in \"/etc/audit/auditd.conf\" to 75\npercent of the partition size."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000343-GPOS-00134",
            "gid": "V-72089",
            "rid": "SV-86713r1_rule",
            "stig_id": "RHEL-07-030330",
            "cci": [
              "CCI-001855"
            ],
            "documentable": false,
            "nist": [
              "AU-5 (1)",
              "Rev_4"
            ],
            "subsystems": [
              "auditd"
            ],
            "fix_id": "F-78441r1_fix"
          },
          "code": "control \"V-72089\" do\n  title \"The operating system must immediately notify the System Administrator\n(SA) and Information System Security Officer ISSO (at a minimum) when allocated\naudit record storage volume reaches 75% of the repository maximum audit record\nstorage capacity.\"\n  desc  \"If security personnel are not notified immediately when storage volume\nreaches 75 percent utilization, they are unable to plan for audit record\nstorage capacity expansion.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000343-GPOS-00134\"\n  tag \"gid\": \"V-72089\"\n  tag \"rid\": \"SV-86713r1_rule\"\n  tag \"stig_id\": \"RHEL-07-030330\"\n  tag \"cci\": [\"CCI-001855\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-5 (1)\", \"Rev_4\"]\n  tag \"subsystems\": ['auditd']\n  desc \"check\", \"Verify the operating system immediately notifies the SA and\nISSO (at a minimum) when allocated audit record storage volume reaches 75\npercent of the repository maximum audit record storage capacity.\n\nCheck the system configuration to determine the partition the audit records are\nbeing written to with the following command:\n\n# grep log_file /etc/audit/auditd.conf\nlog_file = /var/log/audit/audit.log\n\nCheck the size of the partition that audit records are written to (with the\nexample being \\\"/var/log/audit/\\\"):\n\n# df -h /var/log/audit/\n0.9G /var/log/audit\n\nIf the audit records are not being written to a partition specifically created\nfor audit records (in this example \\\"/var/log/audit\\\" is a separate partition),\ndetermine the amount of space other files in the partition are currently\noccupying with the following command:\n\n# du -sh <partition>\n1.8G /var\n\nDetermine what the threshold is for the system to take action when 75 percent\nof the repository maximum audit record storage capacity is reached:\n\n# grep -i space_left /etc/audit/auditd.conf\nspace_left = 225\n\nIf the value of the \\\"space_left\\\" keyword is not set to 25 percent of the\ntotal partition size, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to immediately notify the SA and\nISSO (at a minimum) when allocated audit record storage volume reaches 75\npercent of the repository maximum audit record storage capacity.\n\nCheck the system configuration to determine the partition the audit records are\nbeing written to:\n\n# grep log_file /etc/audit/auditd.conf\n\nDetermine the size of the partition that audit records are written to (with the\nexample being \\\"/var/log/audit/\\\"):\n\n# df -h /var/log/audit/\n\nSet the value of the \\\"space_left\\\" keyword in \\\"/etc/audit/auditd.conf\\\" to 75\npercent of the partition size.\"\n  tag \"fix_id\": \"F-78441r1_fix\"\n \n  if((f = file(audit_log_dir= File.dirname(auditd_conf.log_file))).directory?)\n    partition_info = command(\"df -h #{@audit_log_dir}\").stdout.split(\"\\n\")                                                                              \n    partition_sz_arr = partition_info.last.gsub(/\\s+/m, ' ').strip.split(\" \")                                                                           \n    \n    # Get partition size in GB                                                                                                                           \n    partition_sz = partition_sz_arr[1].gsub(/G/, '')                                                                                                   \n    \n    # Convert to MB and get 25%                                                                                                                          \n    exp_space_left = partition_sz.to_i * 1024 / 4 \n\n    describe auditd_conf do\n      its('space_left.to_i') { should be >= exp_space_left } \n    end\n  else\n    describe f.directory? do\n     it { should be true }\n    end    \n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72089.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Audit Daemon Config space_left.to_i should be >= 97024",
              "run_time": 0.001091468,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected: >= 97024\n     got:    75"
            }
          ]
        },
        {
          "id": "V-72091",
          "title": "The operating system must immediately notify the System Administrator\n(SA) and Information System Security Officer (ISSO) (at a minimum) via email\nwhen the threshold for the repository maximum audit record storage capacity is\nreached.",
          "desc": "If security personnel are not notified immediately when the threshold\nfor the repository maximum audit record storage capacity is reached, they are\nunable to expand the audit record storage capacity before records are lost.",
          "descriptions": [
            {
              "label": "default",
              "data": "If security personnel are not notified immediately when the threshold\nfor the repository maximum audit record storage capacity is reached, they are\nunable to expand the audit record storage capacity before records are lost."
            },
            {
              "label": "check",
              "data": "Verify the operating system immediately notifies the SA and\nISSO (at a minimum) via email when the allocated audit record storage volume\nreaches 75 percent of the repository maximum audit record storage capacity.\n\nCheck what action the operating system takes when the threshold for the\nrepository maximum audit record storage capacity is reached with the following\ncommand:\n\n# grep -i space_left_action  /etc/audit/auditd.conf\nspace_left_action = email\n\nIf the value of the \"space_left_action\" keyword is not set to \"email\", this\nis a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to immediately notify the SA and\nISSO (at a minimum) when the threshold for the repository maximum audit record\nstorage capacity is reached.\n\nUncomment or edit the \"space_left_action\" keyword in\n\"/etc/audit/auditd.conf\" and set it to \"email\".\n\nspace_left_action = email"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000343-GPOS-00134",
            "gid": "V-72091",
            "rid": "SV-86715r1_rule",
            "stig_id": "RHEL-07-030340",
            "cci": [
              "CCI-001855"
            ],
            "documentable": false,
            "nist": [
              "AU-5 (1)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd"
            ],
            "fix_id": "F-78443r1_fix"
          },
          "code": "control \"V-72091\" do\n  title \"The operating system must immediately notify the System Administrator\n(SA) and Information System Security Officer (ISSO) (at a minimum) via email\nwhen the threshold for the repository maximum audit record storage capacity is\nreached.\"\n  desc  \"If security personnel are not notified immediately when the threshold\nfor the repository maximum audit record storage capacity is reached, they are\nunable to expand the audit record storage capacity before records are lost.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000343-GPOS-00134\"\n  tag \"gid\": \"V-72091\"\n  tag \"rid\": \"SV-86715r1_rule\"\n  tag \"stig_id\": \"RHEL-07-030340\"\n  tag \"cci\": [\"CCI-001855\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-5 (1)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd']\n  desc \"check\", \"Verify the operating system immediately notifies the SA and\nISSO (at a minimum) via email when the allocated audit record storage volume\nreaches 75 percent of the repository maximum audit record storage capacity.\n\nCheck what action the operating system takes when the threshold for the\nrepository maximum audit record storage capacity is reached with the following\ncommand:\n\n# grep -i space_left_action  /etc/audit/auditd.conf\nspace_left_action = email\n\nIf the value of the \\\"space_left_action\\\" keyword is not set to \\\"email\\\", this\nis a finding.\"\n  desc \"fix\", \"Configure the operating system to immediately notify the SA and\nISSO (at a minimum) when the threshold for the repository maximum audit record\nstorage capacity is reached.\n\nUncomment or edit the \\\"space_left_action\\\" keyword in\n\\\"/etc/audit/auditd.conf\\\" and set it to \\\"email\\\".\n\nspace_left_action = email\"\n  tag \"fix_id\": \"F-78443r1_fix\"\n\n  describe auditd_conf do\n    its('space_left_action.downcase') { should cmp 'email' }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72091.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Audit Daemon Config space_left_action.downcase should cmp == \"email\"",
              "run_time": 0.000549379,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: \"email\"\n     got: \"syslog\"\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-72093",
          "title": "The operating system must immediately notify the System Administrator\n(SA) and Information System Security Officer (ISSO) (at a minimum) when the\nthreshold for the repository maximum audit record storage capacity is reached.",
          "desc": "If security personnel are not notified immediately when the threshold\nfor the repository maximum audit record storage capacity is reached, they are\nunable to expand the audit record storage capacity before records are lost.",
          "descriptions": [
            {
              "label": "default",
              "data": "If security personnel are not notified immediately when the threshold\nfor the repository maximum audit record storage capacity is reached, they are\nunable to expand the audit record storage capacity before records are lost."
            },
            {
              "label": "check",
              "data": "Verify the operating system immediately notifies the SA and\nISSO (at a minimum) via email when the threshold for the repository maximum\naudit record storage capacity is reached.\n\nCheck what account the operating system emails when the threshold for the\nrepository maximum audit record storage capacity is reached with the following\ncommand:\n\n# grep -i action_mail_acct  /etc/audit/auditd.conf\naction_mail_acct = root\n\nIf the value of the \"action_mail_acct\" keyword is not set to \"root\" and\nother accounts for security personnel, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to immediately notify the SA and\nISSO (at a minimum) when the threshold for the repository maximum audit record\nstorage capacity is reached.\n\nUncomment or edit the \"action_mail_acct\" keyword in\n\"/etc/audit/auditd.conf\" and set it to root and any other accounts associated\nwith security personnel.\n\naction_mail_acct = root"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000343-GPOS-00134",
            "gid": "V-72093",
            "rid": "SV-86717r2_rule",
            "stig_id": "RHEL-07-030350",
            "cci": [
              "CCI-001855"
            ],
            "documentable": false,
            "nist": [
              "AU-5 (1)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd"
            ],
            "fix_id": "F-78445r3_fix"
          },
          "code": "control \"V-72093\" do\n  title \"The operating system must immediately notify the System Administrator\n(SA) and Information System Security Officer (ISSO) (at a minimum) when the\nthreshold for the repository maximum audit record storage capacity is reached.\"\n  desc  \"If security personnel are not notified immediately when the threshold\nfor the repository maximum audit record storage capacity is reached, they are\nunable to expand the audit record storage capacity before records are lost.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000343-GPOS-00134\"\n  tag \"gid\": \"V-72093\"\n  tag \"rid\": \"SV-86717r2_rule\"\n  tag \"stig_id\": \"RHEL-07-030350\"\n  tag \"cci\": [\"CCI-001855\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-5 (1)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd']\n  desc \"check\", \"Verify the operating system immediately notifies the SA and\nISSO (at a minimum) via email when the threshold for the repository maximum\naudit record storage capacity is reached.\n\nCheck what account the operating system emails when the threshold for the\nrepository maximum audit record storage capacity is reached with the following\ncommand:\n\n# grep -i action_mail_acct  /etc/audit/auditd.conf\naction_mail_acct = root\n\nIf the value of the \\\"action_mail_acct\\\" keyword is not set to \\\"root\\\" and\nother accounts for security personnel, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to immediately notify the SA and\nISSO (at a minimum) when the threshold for the repository maximum audit record\nstorage capacity is reached.\n\nUncomment or edit the \\\"action_mail_acct\\\" keyword in\n\\\"/etc/audit/auditd.conf\\\" and set it to root and any other accounts associated\nwith security personnel.\n\naction_mail_acct = root\"\n  tag \"fix_id\": \"F-78445r3_fix\"\n\n  describe auditd_conf  do\n    its('action_mail_acct') { should cmp 'root' }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72093.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Audit Daemon Config action_mail_acct should cmp == \"root\"",
              "run_time": 0.000639299,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72095",
          "title": "All privileged function executions must be audited.",
          "desc": "Misuse of privileged functions, either intentionally or\nunintentionally by authorized users, or by unauthorized external entities that\nhave compromised information system accounts, is a serious and ongoing concern\nand can have significant adverse impacts on organizations. Auditing the use of\nprivileged functions is one way to detect such misuse and identify the risk\nfrom insider threats and the advanced persistent threat.",
          "descriptions": [
            {
              "label": "default",
              "data": "Misuse of privileged functions, either intentionally or\nunintentionally by authorized users, or by unauthorized external entities that\nhave compromised information system accounts, is a serious and ongoing concern\nand can have significant adverse impacts on organizations. Auditing the use of\nprivileged functions is one way to detect such misuse and identify the risk\nfrom insider threats and the advanced persistent threat."
            },
            {
              "label": "check",
              "data": "Verify the operating system audits the execution of privileged\nfunctions.\n\nTo find relevant setuid and setgid programs, use the following command once for\neach local partition [PART]:\n\n# find [PART] -xdev -type f \\( -perm -4000 -o -perm -2000 \\) 2>/dev/null\n\nRun the following command to verify entries in the audit rules for all programs\nfound with the previous command:\n\n# grep -i \"<suid_prog_with_full_path>\" /etc/audit/audit.rules\n-a always,exit -F path=\"<suid_prog_with_full_path>\" -F perm=x -F auid>=1000 -F auid!=4294967295 -k setuid/setgid\n\nAll \"setuid\" and \"setgid\" files on the system must have a corresponding\naudit rule, or must have an audit rule for the (sub) directory that contains\nthe \"setuid\"/\"setgid\" file.\n\nIf all \"setuid\"/\"setgid\" files on the system do not have audit rule\ncoverage, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to audit the execution of\nprivileged functions.\n\nTo find the relevant \"setuid\"/\"setgid\" programs, run the following command\nfor each local partition [PART]:\n\n# find [PART] -xdev -type f \\( -perm -4000 -o -perm -2000 \\) 2>/dev/null\n\nFor each \"setuid\"/\"setgid\" program on the system, which is not covered by\nan audit rule for a (sub) directory (such as \"/usr/sbin\"), add a line of the\nfollowing form to \"/etc/audit/rules.d/audit.rules\", where\n<suid_prog_with_full_path> is the full path to each \"setuid\"/\"setgid\"\nprogram in the list:\n\n-a always,exit -F path=<suid_prog_with_full_path> -F perm=x -F auid>=1000 -F auid!=4294967295 -k setuid/setgid"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000327-GPOS-00127",
            "gid": "V-72095",
            "rid": "SV-86719r5_rule",
            "stig_id": "RHEL-07-030360",
            "cci": [
              "CCI-002234"
            ],
            "documentable": false,
            "nist": [
              "AC-6 (9)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "filesystem_heavy": true,
            "fix_id": "F-78447r7_fix"
          },
          "code": "control \"V-72095\" do\n  title \"All privileged function executions must be audited.\"\n  desc  \"Misuse of privileged functions, either intentionally or\nunintentionally by authorized users, or by unauthorized external entities that\nhave compromised information system accounts, is a serious and ongoing concern\nand can have significant adverse impacts on organizations. Auditing the use of\nprivileged functions is one way to detect such misuse and identify the risk\nfrom insider threats and the advanced persistent threat.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000327-GPOS-00127\"\n  tag \"gid\": \"V-72095\"\n  tag \"rid\": \"SV-86719r5_rule\"\n  tag \"stig_id\": \"RHEL-07-030360\"\n  tag \"cci\": [\"CCI-002234\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-6 (9)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  tag \"filesystem_heavy\": true\n  desc \"check\", \"Verify the operating system audits the execution of privileged\nfunctions.\n\nTo find relevant setuid and setgid programs, use the following command once for\neach local partition [PART]:\n\n# find [PART] -xdev -type f \\\\( -perm -4000 -o -perm -2000 \\\\) 2>/dev/null\n\nRun the following command to verify entries in the audit rules for all programs\nfound with the previous command:\n\n# grep -i \\\"<suid_prog_with_full_path>\\\" /etc/audit/audit.rules\n-a always,exit -F path=\\\"<suid_prog_with_full_path>\\\" -F perm=x -F auid>=1000 -F auid!=4294967295 -k setuid/setgid\n\nAll \\\"setuid\\\" and \\\"setgid\\\" files on the system must have a corresponding\naudit rule, or must have an audit rule for the (sub) directory that contains\nthe \\\"setuid\\\"/\\\"setgid\\\" file.\n\nIf all \\\"setuid\\\"/\\\"setgid\\\" files on the system do not have audit rule\ncoverage, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to audit the execution of\nprivileged functions.\n\nTo find the relevant \\\"setuid\\\"/\\\"setgid\\\" programs, run the following command\nfor each local partition [PART]:\n\n# find [PART] -xdev -type f \\\\( -perm -4000 -o -perm -2000 \\\\) 2>/dev/null\n\nFor each \\\"setuid\\\"/\\\"setgid\\\" program on the system, which is not covered by\nan audit rule for a (sub) directory (such as \\\"/usr/sbin\\\"), add a line of the\nfollowing form to \\\"/etc/audit/rules.d/audit.rules\\\", where\n<suid_prog_with_full_path> is the full path to each \\\"setuid\\\"/\\\"setgid\\\"\nprogram in the list:\n\n-a always,exit -F path=<suid_prog_with_full_path> -F perm=x -F auid>=1000 -F auid!=4294967295 -k setuid/setgid\"\n  tag \"fix_id\": \"F-78447r7_fix\"\n\n  # Tried to make this as safe as possible\n  target_files = command(%(find / -xautofs -noleaf -wholename '/proc' -prune -o -wholename '/sys' -prune -o -wholename '/dev' -prune -o -type f \\\\( -perm -4000 -o -perm -2000 \\\\) -print 2>/dev/null)).stdout.strip.lines\n\n  target_files.each do |target_file|\n    # target_file still contains \\n, need to chomp it\n    describe auditd.file(target_file.chomp) do\n      its('permissions') { should_not cmp [] }\n      its('action') { should_not include 'never' }\n    end\n    # Resource creates data structure including all usages of file\n    @perms = auditd.file(target_file).permissions\n\n    @perms.each do |perm|\n      describe perm do\n        it { should include 'x' }\n      end\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72095.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/wall\" permissions should not cmp == []",
              "run_time": 0.000288747,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/wall\" action should not include \"never\"",
              "run_time": 0.000238394,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/chfn\" permissions should not cmp == []",
              "run_time": 0.000227102,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/chfn\" action should not include \"never\"",
              "run_time": 0.000161866,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/mount\" permissions should not cmp == []",
              "run_time": 0.000212469,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/mount\" action should not include \"never\"",
              "run_time": 0.000132821,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/chage\" permissions should not cmp == []",
              "run_time": 0.000275204,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/chage\" action should not include \"never\"",
              "run_time": 0.000145568,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/gpasswd\" permissions should not cmp == []",
              "run_time": 0.000208258,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/gpasswd\" action should not include \"never\"",
              "run_time": 0.000115389,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/newgrp\" permissions should not cmp == []",
              "run_time": 0.000275534,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/newgrp\" action should not include \"never\"",
              "run_time": 0.000111674,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/su\" permissions should not cmp == []",
              "run_time": 0.000193124,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/su\" action should not include \"never\"",
              "run_time": 0.000107018,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/umount\" permissions should not cmp == []",
              "run_time": 0.000381645,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/umount\" action should not include \"never\"",
              "run_time": 0.000366845,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/chsh\" permissions should not cmp == []",
              "run_time": 0.000212247,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/chsh\" action should not include \"never\"",
              "run_time": 0.000268575,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/write\" permissions should not cmp == []",
              "run_time": 0.000609888,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/write\" action should not include \"never\"",
              "run_time": 0.000124239,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/sudo\" permissions should not cmp == []",
              "run_time": 0.000234295,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/sudo\" action should not include \"never\"",
              "run_time": 0.000113916,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/pkexec\" permissions should not cmp == []",
              "run_time": 0.000177291,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/pkexec\" action should not include \"never\"",
              "run_time": 9.955e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/ssh-agent\" permissions should not cmp == []",
              "run_time": 0.000173299,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/ssh-agent\" action should not include \"never\"",
              "run_time": 0.00010597,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/crontab\" permissions should not cmp == []",
              "run_time": 0.000178125,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/crontab\" action should not include \"never\"",
              "run_time": 0.00010149,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/passwd\" permissions should not cmp == []",
              "run_time": 0.000187015,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/passwd\" action should not include \"never\"",
              "run_time": 0.000101256,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/ksu\" permissions should not cmp == []",
              "run_time": 0.000169645,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/ksu\" action should not include \"never\"",
              "run_time": 0.000175884,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/fusermount\" permissions should not cmp == []",
              "run_time": 0.000193715,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/fusermount\" action should not include \"never\"",
              "run_time": 0.000111223,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/cgclassify\" permissions should not cmp == []",
              "run_time": 0.000181233,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/cgclassify\" action should not include \"never\"",
              "run_time": 0.000102503,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/cgexec\" permissions should not cmp == []",
              "run_time": 0.000167787,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/cgexec\" action should not include \"never\"",
              "run_time": 0.000100339,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/Xorg\" permissions should not cmp == []",
              "run_time": 0.000180388,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/Xorg\" action should not include \"never\"",
              "run_time": 0.000110823,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/at\" permissions should not cmp == []",
              "run_time": 0.000183931,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/at\" action should not include \"never\"",
              "run_time": 0.000106249,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/staprun\" permissions should not cmp == []",
              "run_time": 0.000184483,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/staprun\" action should not include \"never\"",
              "run_time": 9.9963e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/locate\" permissions should not cmp == []",
              "run_time": 0.000182432,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/locate\" action should not include \"never\"",
              "run_time": 0.000108863,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/pam_timestamp_check\" permissions should not cmp == []",
              "run_time": 0.000204178,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/pam_timestamp_check\" action should not include \"never\"",
              "run_time": 0.000104034,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/unix_chkpwd\" permissions should not cmp == []",
              "run_time": 0.00027058,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/unix_chkpwd\" action should not include \"never\"",
              "run_time": 0.000113843,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/netreport\" permissions should not cmp == []",
              "run_time": 0.00036144,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/netreport\" action should not include \"never\"",
              "run_time": 0.000264494,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/usernetctl\" permissions should not cmp == []",
              "run_time": 0.000190563,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/usernetctl\" action should not include \"never\"",
              "run_time": 0.000115177,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/postdrop\" permissions should not cmp == []",
              "run_time": 0.000202157,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/postdrop\" action should not include \"never\"",
              "run_time": 0.000117665,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/postqueue\" permissions should not cmp == []",
              "run_time": 0.000173646,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/postqueue\" action should not include \"never\"",
              "run_time": 0.000180261,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/userhelper\" permissions should not cmp == []",
              "run_time": 0.000372478,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/userhelper\" action should not include \"never\"",
              "run_time": 0.000123856,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/lockdev\" permissions should not cmp == []",
              "run_time": 0.000233216,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/lockdev\" action should not include \"never\"",
              "run_time": 0.000114273,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/mount.nfs\" permissions should not cmp == []",
              "run_time": 0.000183836,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/mount.nfs\" action should not include \"never\"",
              "run_time": 9.8481e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/lib/polkit-1/polkit-agent-helper-1\" permissions should not cmp == []",
              "run_time": 0.00017457,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/lib/polkit-1/polkit-agent-helper-1\" action should not include \"never\"",
              "run_time": 9.532e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/lib64/vte-2.91/gnome-pty-helper\" permissions should not cmp == []",
              "run_time": 0.000159615,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/lib64/vte-2.91/gnome-pty-helper\" action should not include \"never\"",
              "run_time": 0.000114951,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/sssd/krb5_child\" permissions should not cmp == []",
              "run_time": 0.000166437,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/sssd/krb5_child\" action should not include \"never\"",
              "run_time": 9.6007e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/sssd/ldap_child\" permissions should not cmp == []",
              "run_time": 0.000153603,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/sssd/ldap_child\" action should not include \"never\"",
              "run_time": 9.2499e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/sssd/selinux_child\" permissions should not cmp == []",
              "run_time": 0.000153233,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/sssd/selinux_child\" action should not include \"never\"",
              "run_time": 8.8777e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/sssd/proxy_child\" permissions should not cmp == []",
              "run_time": 0.000152572,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/sssd/proxy_child\" action should not include \"never\"",
              "run_time": 9.7221e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/utempter/utempter\" permissions should not cmp == []",
              "run_time": 0.00014963,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/utempter/utempter\" action should not include \"never\"",
              "run_time": 9.4435e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/dbus-1/dbus-daemon-launch-helper\" permissions should not cmp == []",
              "run_time": 0.000187078,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/dbus-1/dbus-daemon-launch-helper\" action should not include \"never\"",
              "run_time": 0.000387391,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/openssh/ssh-keysign\" permissions should not cmp == []",
              "run_time": 0.000454931,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/openssh/ssh-keysign\" action should not include \"never\"",
              "run_time": 0.000171032,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/flatpak-bwrap\" permissions should not cmp == []",
              "run_time": 0.000321482,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/flatpak-bwrap\" action should not include \"never\"",
              "run_time": 0.000102499,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/qemu-bridge-helper\" permissions should not cmp == []",
              "run_time": 0.000211913,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/qemu-bridge-helper\" action should not include \"never\"",
              "run_time": 0.000100378,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/abrt-action-install-debuginfo-to-abrt-cache\" permissions should not cmp == []",
              "run_time": 0.000165312,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/abrt-action-install-debuginfo-to-abrt-cache\" action should not include \"never\"",
              "run_time": 0.000181772,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/spice-gtk-x86_64/spice-client-glib-usb-acl-helper\" permissions should not cmp == []",
              "run_time": 0.000171546,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/spice-gtk-x86_64/spice-client-glib-usb-acl-helper\" action should not include \"never\"",
              "run_time": 9.2061e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72097",
          "title": "All uses of the chown command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"chown\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw chown /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S chown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S chown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \"chown\" command, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Add or update the following rule in\n\"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S chown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S chown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000064-GPOS-00033",
            "satisfies": [
              "SRG-OS-000064-GPOS-00033",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000458-GPOS-00203",
              "SRG-OS-000474-GPOS-00219"
            ],
            "gid": "V-72097",
            "rid": "SV-86721r3_rule",
            "stig_id": "RHEL-07-030370",
            "cci": [
              "CCI-000126",
              "CCI-000172"
            ],
            "documentable": false,
            "nist": [
              "AU-2 d",
              "AU-12 c",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78449r6_fix"
          },
          "code": "control \"V-72097\" do\n  title \"All uses of the chown command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000064-GPOS-00033\"\n  tag \"satisfies\": [\"SRG-OS-000064-GPOS-00033\", \"SRG-OS-000392-GPOS-00172\",\n\"SRG-OS-000458-GPOS-00203\", \"SRG-OS-000474-GPOS-00219\"]\n  tag \"gid\": \"V-72097\"\n  tag \"rid\": \"SV-86721r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030370\"\n  tag \"cci\": [\"CCI-000126\", \"CCI-000172\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-2 d\", \"AU-12 c\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"chown\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw chown /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S chown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S chown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \\\"chown\\\" command, this is a\nfinding.\n\"\n  desc \"fix\", \"Add or update the following rule in\n\\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S chown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S chown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect.\n\"\n  tag \"fix_id\": \"F-78449r6_fix\"\n\n  describe auditd.syscall(\"chown\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"chown\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72097.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"chown\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000153029,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"chown\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.00015335,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"chown\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000139357,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"chown\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000136363,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72099",
          "title": "All uses of the fchown command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"fchown\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw fchown /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S fchown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S fchown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \"fchown\" command, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Add or update the following rule in\n\"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S fchown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S fchown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000064-GPOS-00033",
            "satisfies": [
              "SRG-OS-000064-GPOS-00033",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000458-GPOS-00203",
              "SRG-OS-000474-GPOS-00219"
            ],
            "gid": "V-72099",
            "rid": "SV-86723r3_rule",
            "stig_id": "RHEL-07-030380",
            "cci": [
              "CCI-000126",
              "CCI-000172"
            ],
            "documentable": false,
            "nist": [
              "AU-2 d",
              "AU-12 c",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78451r6_fix"
          },
          "code": "control \"V-72099\" do\n  title \"All uses of the fchown command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000064-GPOS-00033\"\n  tag \"satisfies\": [\"SRG-OS-000064-GPOS-00033\", \"SRG-OS-000392-GPOS-00172\",\n\"SRG-OS-000458-GPOS-00203\", \"SRG-OS-000474-GPOS-00219\"]\n  tag \"gid\": \"V-72099\"\n  tag \"rid\": \"SV-86723r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030380\"\n  tag \"cci\": [\"CCI-000126\", \"CCI-000172\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-2 d\", \"AU-12 c\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"fchown\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw fchown /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S fchown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S fchown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \\\"fchown\\\" command, this is a\nfinding.\n\"\n  desc \"fix\", \"Add or update the following rule in\n\\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S fchown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S fchown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect.\n\"\n  tag \"fix_id\": \"F-78451r6_fix\"\n\n  describe auditd.syscall(\"fchown\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"fchown\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72099.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fchown\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000132994,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fchown\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000206346,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fchown\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000220617,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fchown\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000125598,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72101",
          "title": "All uses of the lchown command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"lchown\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw lchown /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S lchown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S lchown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \"lchown\" command, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Add or update the following rule in\n\"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S lchown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S lchown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000064-GPOS-00033",
            "satisfies": [
              "SRG-OS-000064-GPOS-00033",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000458-GPOS-00203",
              "SRG-OS-000474-GPOS-00219"
            ],
            "gid": "V-72101",
            "rid": "SV-86725r3_rule",
            "stig_id": "RHEL-07-030390",
            "cci": [
              "CCI-000126",
              "CCI-000172"
            ],
            "documentable": false,
            "nist": [
              "AU-2 d",
              "AU-12 c",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78453r6_fix"
          },
          "code": "control \"V-72101\" do\n  title \"All uses of the lchown command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000064-GPOS-00033\"\n  tag \"satisfies\": [\"SRG-OS-000064-GPOS-00033\", \"SRG-OS-000392-GPOS-00172\",\n\"SRG-OS-000458-GPOS-00203\", \"SRG-OS-000474-GPOS-00219\"]\n  tag \"gid\": \"V-72101\"\n  tag \"rid\": \"SV-86725r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030390\"\n  tag \"cci\": [\"CCI-000126\", \"CCI-000172\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-2 d\", \"AU-12 c\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"lchown\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw lchown /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S lchown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S lchown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \\\"lchown\\\" command, this is a\nfinding.\"\n  desc \"fix\", \"Add or update the following rule in\n\\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S lchown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S lchown -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect. \"\n  tag \"fix_id\": \"F-78453r6_fix\"\n\n  describe auditd.syscall(\"lchown\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"lchown\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72101.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"lchown\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000153787,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"lchown\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000168274,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"lchown\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.0001465,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"lchown\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.00035141,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72103",
          "title": "All uses of the fchownat command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"fchownat\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw fchownat /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S fchownat -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S fchownat -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \"fchownat\" command, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Add or update the following rule in\n\"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S fchownat -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S fchownat -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000064-GPOS-00033",
            "satisfies": [
              "SRG-OS-000064-GPOS-00033",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000458-GPOS-00203",
              "SRG-OS-000474-GPOS-00219"
            ],
            "gid": "V-72103",
            "rid": "SV-86727r3_rule",
            "stig_id": "RHEL-07-030400",
            "cci": [
              "CCI-000126",
              "CCI-000172"
            ],
            "documentable": false,
            "nist": [
              "AU-2 d",
              "AU-12 c",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78455r5_fix"
          },
          "code": "control \"V-72103\" do\n  title \"All uses of the fchownat command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000064-GPOS-00033\"\n  tag \"satisfies\": [\"SRG-OS-000064-GPOS-00033\", \"SRG-OS-000392-GPOS-00172\",\n\"SRG-OS-000458-GPOS-00203\", \"SRG-OS-000474-GPOS-00219\"]\n  tag \"gid\": \"V-72103\"\n  tag \"rid\": \"SV-86727r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030400\"\n  tag \"cci\": [\"CCI-000126\", \"CCI-000172\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-2 d\", \"AU-12 c\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"fchownat\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw fchownat /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S fchownat -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S fchownat -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \\\"fchownat\\\" command, this is a\nfinding.\n\"\n  desc \"fix\", \"Add or update the following rule in\n\\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S fchownat -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S fchownat -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect.\n\"\n  tag \"fix_id\": \"F-78455r5_fix\"\n\n  describe auditd.syscall(\"fchownat\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"fchownat\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72103.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fchownat\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000394214,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fchownat\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000382104,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fchownat\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000224641,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fchownat\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000364745,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72105",
          "title": "All uses of the chmod command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"chmod\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommand:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw chmod /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S chmod -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S chmod -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \"chmod\" command, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"chmod\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S chmod -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S chmod -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000458-GPOS-00203",
            "satisfies": [
              "SRG-OS-000458-GPOS-00203",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000064-GPOS-00033"
            ],
            "gid": "V-72105",
            "rid": "SV-86729r3_rule",
            "stig_id": "RHEL-07-030410",
            "cci": [
              "CCI-000172"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78457r5_fix"
          },
          "code": "control \"V-72105\" do\n  title \"All uses of the chmod command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000458-GPOS-00203\"\n  tag \"satisfies\": [\"SRG-OS-000458-GPOS-00203\", \"SRG-OS-000392-GPOS-00172\",\n\"SRG-OS-000064-GPOS-00033\"]\n  tag \"gid\": \"V-72105\"\n  tag \"rid\": \"SV-86729r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030410\"\n  tag \"cci\": [\"CCI-000172\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"chmod\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw chmod /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S chmod -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S chmod -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \\\"chmod\\\" command, this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"chmod\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S chmod -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S chmod -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78457r5_fix\"\n\n  describe auditd.syscall(\"chmod\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"chmod\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72105.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"chmod\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000409961,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"chmod\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000290921,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"chmod\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000349197,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"chmod\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000178419,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72107",
          "title": "All uses of the fchmod command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"fchmod\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommand:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw fchmod /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S fchmod -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S fchmod -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \"fchmod\" command, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"fchmod\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S fchmod -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S fchmod -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000458-GPOS-00203",
            "satisfies": [
              "SRG-OS-000458-GPOS-00203",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000064-GPOS-00033"
            ],
            "gid": "V-72107",
            "rid": "SV-86731r3_rule",
            "stig_id": "RHEL-07-030420",
            "cci": [
              "CCI-000172"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78459r6_fix"
          },
          "code": "control \"V-72107\" do\n  title \"All uses of the fchmod command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000458-GPOS-00203\"\n  tag \"satisfies\": [\"SRG-OS-000458-GPOS-00203\", \"SRG-OS-000392-GPOS-00172\",\n\"SRG-OS-000064-GPOS-00033\"]\n  tag \"gid\": \"V-72107\"\n  tag \"rid\": \"SV-86731r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030420\"\n  tag \"cci\": [\"CCI-000172\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"fchmod\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw fchmod /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S fchmod -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S fchmod -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \\\"fchmod\\\" command, this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"fchmod\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S fchmod -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S fchmod -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78459r6_fix\"\n\n  describe auditd.syscall(\"fchmod\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"fchmod\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72107.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fchmod\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000255127,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fchmod\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000176406,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fchmod\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000129026,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fchmod\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000123718,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72109",
          "title": "All uses of the fchmodat command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"fchmodat\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommand:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw fchmodat /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S fchmodat -F auid>=1000 -F auid!=4294967295 -k perm_mod\n-a always,exit -F arch=b64 -S fchmodat -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \"fchmodat\" command, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"fchmodat\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S fchmodat -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S fchmodat -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000458-GPOS-00203",
            "satisfies": [
              "SRG-OS-000458-GPOS-00203",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000064-GPOS-00033"
            ],
            "gid": "V-72109",
            "rid": "SV-86733r3_rule",
            "stig_id": "RHEL-07-030430",
            "cci": [
              "CCI-000172"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78461r6_fix"
          },
          "code": "control \"V-72109\" do\n  title \"All uses of the fchmodat command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000458-GPOS-00203\"\n  tag \"satisfies\": [\"SRG-OS-000458-GPOS-00203\", \"SRG-OS-000392-GPOS-00172\",\n\"SRG-OS-000064-GPOS-00033\"]\n  tag \"gid\": \"V-72109\"\n  tag \"rid\": \"SV-86733r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030430\"\n  tag \"cci\": [\"CCI-000172\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"fchmodat\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw fchmodat /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S fchmodat -F auid>=1000 -F auid!=4294967295 -k perm_mod\n-a always,exit -F arch=b64 -S fchmodat -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \\\"fchmodat\\\" command, this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"fchmodat\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S fchmodat -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S fchmodat -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78461r6_fix\"\n\n  describe auditd.syscall(\"fchmodat\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"fchmodat\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72109.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fchmodat\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.00012539,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fchmodat\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000121008,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fchmodat\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000121706,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fchmodat\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000116282,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72111",
          "title": "All uses of the setxattr command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"setxattr\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw setxattr /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S setxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S setxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \"setxattr\" command, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"setxattr\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S setxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S setxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000458-GPOS-00203",
            "satisfies": [
              "SRG-OS-000458-GPOS-00203",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000064-GPOS-00033"
            ],
            "gid": "V-72111",
            "rid": "SV-86735r3_rule",
            "stig_id": "RHEL-07-030440",
            "cci": [
              "CCI-000172"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78463r6_fix"
          },
          "code": "control \"V-72111\" do\n  title \"All uses of the setxattr command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000458-GPOS-00203\"\n  tag \"satisfies\": [\"SRG-OS-000458-GPOS-00203\", \"SRG-OS-000392-GPOS-00172\",\n\"SRG-OS-000064-GPOS-00033\"]\n  tag \"gid\": \"V-72111\"\n  tag \"rid\": \"SV-86735r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030440\"\n  tag \"cci\": [\"CCI-000172\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"setxattr\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw setxattr /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S setxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S setxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \\\"setxattr\\\" command, this is a\nfinding.\n\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"setxattr\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S setxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S setxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78463r6_fix\"\n\n  describe auditd.syscall(\"setxattr\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"setxattr\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72111.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"setxattr\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000120277,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"setxattr\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000113163,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"setxattr\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.00011908,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"setxattr\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.00011144,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72113",
          "title": "All uses of the fsetxattr command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"fsetxattr\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw fsetxattr /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S fsetxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S fsetxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \"fsetxattr\" command, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"fsetxattr\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S fsetxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S fsetxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000458-GPOS-00203",
            "satisfies": [
              "SRG-OS-000458-GPOS-00203",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000064-GPOS-00033"
            ],
            "gid": "V-72113",
            "rid": "SV-86737r3_rule",
            "stig_id": "RHEL-07-030450",
            "cci": [
              "CCI-000172"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78465r5_fix"
          },
          "code": "control \"V-72113\" do\n  title \"All uses of the fsetxattr command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000458-GPOS-00203\"\n  tag \"satisfies\": [\"SRG-OS-000458-GPOS-00203\", \"SRG-OS-000392-GPOS-00172\",\n\"SRG-OS-000064-GPOS-00033\"]\n  tag \"gid\": \"V-72113\"\n  tag \"rid\": \"SV-86737r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030450\"\n  tag \"cci\": [\"CCI-000172\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"fsetxattr\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw fsetxattr /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S fsetxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S fsetxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \\\"fsetxattr\\\" command, this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"fsetxattr\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S fsetxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S fsetxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78465r5_fix\"\n\n  describe auditd.syscall(\"fsetxattr\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"fsetxattr\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72113.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fsetxattr\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.00011556,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fsetxattr\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.00011752,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fsetxattr\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000134184,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fsetxattr\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000115235,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72115",
          "title": "All uses of the lsetxattr command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"lsetxattr\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw lsetxattr /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S lsetxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S lsetxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \"lsetxattr\" command, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"lsetxattr\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S lsetxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S lsetxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000458-GPOS-00203",
            "satisfies": [
              "SRG-OS-000458-GPOS-00203",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000064-GPOS-00033"
            ],
            "gid": "V-72115",
            "rid": "SV-86739r3_rule",
            "stig_id": "RHEL-07-030460",
            "cci": [
              "CCI-000172"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78467r8_fix"
          },
          "code": "control \"V-72115\" do\n  title \"All uses of the lsetxattr command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000458-GPOS-00203\"\n  tag \"satisfies\": [\"SRG-OS-000458-GPOS-00203\", \"SRG-OS-000392-GPOS-00172\",\n\"SRG-OS-000064-GPOS-00033\"]\n  tag \"gid\": \"V-72115\"\n  tag \"rid\": \"SV-86739r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030460\"\n  tag \"cci\": [\"CCI-000172\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"lsetxattr\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw lsetxattr /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S lsetxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S lsetxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \\\"lsetxattr\\\" command, this is a\nfinding.\n\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"lsetxattr\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S lsetxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S lsetxattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78467r8_fix\"\n\n  describe auditd.syscall(\"lsetxattr\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"lsetxattr\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72115.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"lsetxattr\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000123892,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"lsetxattr\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000115345,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"lsetxattr\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000121774,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"lsetxattr\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000117802,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72117",
          "title": "All uses of the removexattr command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"removexattr\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw removexattr /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S removexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S removexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \"removexattr\" command, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"removexattr\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S removexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S removexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000458-GPOS-00203",
            "satisfies": [
              "SRG-OS-000458-GPOS-00203",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000064-GPOS-00033"
            ],
            "gid": "V-72117",
            "rid": "SV-86741r3_rule",
            "stig_id": "RHEL-07-030470",
            "cci": [
              "CCI-000172"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78469r5_fix"
          },
          "code": "control \"V-72117\" do\n  title \"All uses of the removexattr command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000458-GPOS-00203\"\n  tag \"satisfies\": [\"SRG-OS-000458-GPOS-00203\", \"SRG-OS-000392-GPOS-00172\",\n\"SRG-OS-000064-GPOS-00033\"]\n  tag \"gid\": \"V-72117\"\n  tag \"rid\": \"SV-86741r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030470\"\n  tag \"cci\": [\"CCI-000172\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"removexattr\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw removexattr /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S removexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S removexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \\\"removexattr\\\" command, this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"removexattr\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S removexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S removexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78469r5_fix\"\n\n  describe auditd.syscall(\"removexattr\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"removexattr\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72117.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"removexattr\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000127738,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"removexattr\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000118481,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"removexattr\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000125244,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"removexattr\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000115765,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72119",
          "title": "All uses of the fremovexattr command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"fremovexattr\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw fremovexattr /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S fremovexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S fremovexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \"fremovexattr\" command, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"fremovexattr\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S fremovexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S fremovexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000458-GPOS-00203",
            "satisfies": [
              "SRG-OS-000458-GPOS-00203",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000064-GPOS-00033"
            ],
            "gid": "V-72119",
            "rid": "SV-86743r3_rule",
            "stig_id": "RHEL-07-030480",
            "cci": [
              "CCI-000172"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78471r4_fix"
          },
          "code": "control \"V-72119\" do\n  title \"All uses of the fremovexattr command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000458-GPOS-00203\"\n  tag \"satisfies\": [\"SRG-OS-000458-GPOS-00203\", \"SRG-OS-000392-GPOS-00172\",\n\"SRG-OS-000064-GPOS-00033\"]\n  tag \"gid\": \"V-72119\"\n  tag \"rid\": \"SV-86743r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030480\"\n  tag \"cci\": [\"CCI-000172\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"fremovexattr\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw fremovexattr /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S fremovexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S fremovexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \\\"fremovexattr\\\" command, this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"fremovexattr\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S fremovexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S fremovexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect.\n\"\n  tag \"fix_id\": \"F-78471r4_fix\"\n\n  describe auditd.syscall(\"fremovexattr\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"fremovexattr\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72119.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fremovexattr\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000125596,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fremovexattr\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000121024,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fremovexattr\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000120713,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"fremovexattr\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000114546,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72121",
          "title": "All uses of the lremovexattr command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"lremovexattr\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw lremovexattr /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S lremovexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S lremovexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \"lremovexattr\" command, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"lremovexattr\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S lremovexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S lremovexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000458-GPOS-00203",
            "satisfies": [
              "SRG-OS-000458-GPOS-00203",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000064-GPOS-00033"
            ],
            "gid": "V-72121",
            "rid": "SV-86745r3_rule",
            "stig_id": "RHEL-07-030490",
            "cci": [
              "CCI-000172"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78473r5_fix"
          },
          "code": "control \"V-72121\" do\n  title \"All uses of the lremovexattr command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000458-GPOS-00203\"\n  tag \"satisfies\": [\"SRG-OS-000458-GPOS-00203\", \"SRG-OS-000392-GPOS-00172\",\n\"SRG-OS-000064-GPOS-00033\"]\n  tag \"gid\": \"V-72121\"\n  tag \"rid\": \"SV-86745r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030490\"\n  tag \"cci\": [\"CCI-000172\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"lremovexattr\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw lremovexattr /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S lremovexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S lremovexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nIf there are no audit rules defined for the \\\"lremovexattr\\\" command, this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"lremovexattr\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S lremovexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\n-a always,exit -F arch=b64 -S lremovexattr -F auid>=1000 -F auid!=4294967295 -k perm_mod\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78473r5_fix\"\n\n  describe auditd.syscall(\"lremovexattr\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"lremovexattr\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72121.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"lremovexattr\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000123245,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"lremovexattr\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000116088,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"lremovexattr\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000125485,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"lremovexattr\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000300298,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72123",
          "title": "All uses of the creat command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"creat\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw creat /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S creat F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nIf there are no audit rules defined for the \"creat\" command, this is a finding.\n\nIf the output does not produce a rule containing \"-F exit=-EPERM\", this is a\nfinding.\n\nIf the output does not produce a rule containing \"-F exit=-EACCES\", this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"creat\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules:\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000064-GPOS-00033",
            "satisfies": [
              "SRG-OS-000064-GPOS-00033",
              "SRG-OS-000458-GPOS-00203",
              "SRG-OS-000461-GPOS-00205",
              "SRG-OS-000392-GPOS-00172"
            ],
            "gid": "V-72123",
            "rid": "SV-86747r3_rule",
            "stig_id": "RHEL-07-030500",
            "cci": [
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78475r5_fix"
          },
          "code": "control \"V-72123\" do\n  title \"All uses of the creat command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000064-GPOS-00033\"\n  tag \"satisfies\": [\"SRG-OS-000064-GPOS-00033\", \"SRG-OS-000458-GPOS-00203\",\n\"SRG-OS-000461-GPOS-00205\", \"SRG-OS-000392-GPOS-00172\"]\n  tag \"gid\": \"V-72123\"\n  tag \"rid\": \"SV-86747r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030500\"\n  tag \"cci\": [\"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"creat\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw creat /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S creat F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nIf there are no audit rules defined for the \\\"creat\\\" command, this is a finding.\n\nIf the output does not produce a rule containing \\\"-F exit=-EPERM\\\", this is a\nfinding.\n\nIf the output does not produce a rule containing \\\"-F exit=-EACCES\\\", this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"creat\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules:\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nThe audit daemon must be restarted for the changes to take effect.\n\"\n  tag \"fix_id\": \"F-78475r5_fix\"\n\n  describe auditd.syscall(\"creat\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n    its('exit.uniq') { should include '-EPERM' }\n  end\n  describe auditd.syscall(\"creat\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n    its('exit.uniq') { should include '-EACCES' }\n  end\n\n  if os.arch == 'x86_64'\n     describe auditd.syscall(\"creat\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n      its('exit.uniq') { should include '-EPERM' }\n    end\n    describe auditd.syscall(\"creat\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n      its('exit.uniq') { should include '-EACCES' }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72123.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"creat\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000153905,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"creat\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.00031542,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"creat\" arch == \"b32\" exit.uniq should include \"-EPERM\"",
              "run_time": 0.000183669,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EPERM\""
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"creat\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000147565,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"creat\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000130718,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"creat\" arch == \"b32\" exit.uniq should include \"-EACCES\"",
              "run_time": 0.000147159,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EACCES\""
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"creat\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000285814,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"creat\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000249531,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"creat\" arch == \"b64\" exit.uniq should include \"-EPERM\"",
              "run_time": 0.000159214,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EPERM\""
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"creat\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000138204,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"creat\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.00015652,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"creat\" arch == \"b64\" exit.uniq should include \"-EACCES\"",
              "run_time": 0.000252196,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EACCES\""
            }
          ]
        },
        {
          "id": "V-72125",
          "title": "All uses of the open command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"open\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw open /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S open -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S open -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S open -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S open -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nIf there are no audit rules defined for the \"open\" command, this is a finding.\n\nIf the output does not produce a rule containing \"-F exit=-EPERM\", this is a\nfinding.\n\nIf the output does not produce a rule containing \"-F exit=-EACCES\", this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"open\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S open -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S open -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S open -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S open -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000064-GPOS-00033",
            "satisfies": [
              "SRG-OS-000064-GPOS-00033",
              "SRG-OS-000458-GPOS-00203",
              "SRG-OS-000461-GPOS-00205",
              "SRG-OS-000392-GPOS-00172"
            ],
            "gid": "V-72125",
            "rid": "SV-86749r3_rule",
            "stig_id": "RHEL-07-030510",
            "cci": [
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78477r5_fix"
          },
          "code": "control \"V-72125\" do\n  title \"All uses of the open command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000064-GPOS-00033\"\n  tag \"satisfies\": [\"SRG-OS-000064-GPOS-00033\", \"SRG-OS-000458-GPOS-00203\",\n\"SRG-OS-000461-GPOS-00205\", \"SRG-OS-000392-GPOS-00172\"]\n  tag \"gid\": \"V-72125\"\n  tag \"rid\": \"SV-86749r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030510\"\n  tag \"cci\": [\"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"open\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw open /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S open -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S open -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S open -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S open -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nIf there are no audit rules defined for the \\\"open\\\" command, this is a finding.\n\nIf the output does not produce a rule containing \\\"-F exit=-EPERM\\\", this is a\nfinding.\n\nIf the output does not produce a rule containing \\\"-F exit=-EACCES\\\", this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"open\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S open -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S open -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S open -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S open -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nThe audit daemon must be restarted for the changes to take effect.\n\"\n  tag \"fix_id\": \"F-78477r5_fix\"\n\n  describe auditd.syscall(\"open\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n    its('exit.uniq') { should include '-EPERM' }\n  end\n  describe auditd.syscall(\"open\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n    its('exit.uniq') { should include '-EACCES' }\n  end\n\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"open\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n      its('exit.uniq') { should include '-EPERM' }\n    end\n    describe auditd.syscall(\"open\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n      its('exit.uniq') { should include '-EACCES' }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72125.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000132964,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000143545,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open\" arch == \"b32\" exit.uniq should include \"-EPERM\"",
              "run_time": 0.000178327,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EPERM\""
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000151527,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000186196,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open\" arch == \"b32\" exit.uniq should include \"-EACCES\"",
              "run_time": 0.000270842,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EACCES\""
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000255694,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000296997,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open\" arch == \"b64\" exit.uniq should include \"-EPERM\"",
              "run_time": 0.000173214,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EPERM\""
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000144617,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000345076,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open\" arch == \"b64\" exit.uniq should include \"-EACCES\"",
              "run_time": 0.000163199,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EACCES\""
            }
          ]
        },
        {
          "id": "V-72127",
          "title": "All uses of the openat command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"openat\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw openat /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S openat -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S openat -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S openat -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S openat -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nIf there are no audit rules defined for the \"openat\" command, this is a finding.\n\nIf the output does not produce a rule containing \"-F exit=-EPERM\", this is a\nfinding.\n\nIf the output does not produce a rule containing \"-F exit=-EACCES\", this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"openat\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S openat -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S openat -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S openat -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S openat -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000064-GPOS-00033",
            "satisfies": [
              "SRG-OS-000064-GPOS-00033",
              "SRG-OS-000458-GPOS-00203",
              "SRG-OS-000461-GPOS-00205",
              "SRG-OS-000392-GPOS-00172"
            ],
            "gid": "V-72127",
            "rid": "SV-86751r3_rule",
            "stig_id": "RHEL-07-030520",
            "cci": [
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78479r5_fix"
          },
          "code": "control \"V-72127\" do\n  title \"All uses of the openat command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000064-GPOS-00033\"\n  tag \"satisfies\": [\"SRG-OS-000064-GPOS-00033\", \"SRG-OS-000458-GPOS-00203\",\n\"SRG-OS-000461-GPOS-00205\", \"SRG-OS-000392-GPOS-00172\"]\n  tag \"gid\": \"V-72127\"\n  tag \"rid\": \"SV-86751r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030520\"\n  tag \"cci\": [\"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"openat\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw openat /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S openat -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S openat -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S openat -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S openat -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nIf there are no audit rules defined for the \\\"openat\\\" command, this is a finding.\n\nIf the output does not produce a rule containing \\\"-F exit=-EPERM\\\", this is a\nfinding.\n\nIf the output does not produce a rule containing \\\"-F exit=-EACCES\\\", this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"openat\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S openat -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S openat -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S openat -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S openat -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78479r5_fix\"\n\n  describe auditd.syscall(\"openat\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n    its('exit.uniq') { should include '-EPERM' }\n  end\n  describe auditd.syscall(\"openat\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n    its('exit.uniq') { should include '-EACCES' }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"openat\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n      its('exit.uniq') { should include '-EPERM' }\n    end\n    describe auditd.syscall(\"openat\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n      its('exit.uniq') { should include '-EACCES' }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72127.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"openat\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000270467,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"openat\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000141837,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"openat\" arch == \"b32\" exit.uniq should include \"-EPERM\"",
              "run_time": 0.000200123,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EPERM\""
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"openat\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000595286,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"openat\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000219089,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"openat\" arch == \"b32\" exit.uniq should include \"-EACCES\"",
              "run_time": 0.000161718,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EACCES\""
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"openat\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000218707,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"openat\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000354541,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"openat\" arch == \"b64\" exit.uniq should include \"-EPERM\"",
              "run_time": 0.000419184,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EPERM\""
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"openat\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000276901,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"openat\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000153376,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"openat\" arch == \"b64\" exit.uniq should include \"-EACCES\"",
              "run_time": 0.000154597,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EACCES\""
            }
          ]
        },
        {
          "id": "V-72129",
          "title": "All uses of the open_by_handle_at command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"open_by_handle_at\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw open_by_handle_at /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S open_by_handle_at -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S open_by_handle_at -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S open_by_handle_at -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S open_by_handle_at -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nIf there are no audit rules defined for the \"open_by_handle_at\" command, this\nis a finding.\n\nIf the output does not produce a rule containing \"-F exit=-EPERM\", this is a\nfinding.\n\nIf the output does not produce a rule containing \"-F exit=-EACCES\", this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"open_by_handle_at\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S open_by_handle_at -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S open_by_handle_at -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S open_by_handle_at -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S open_by_handle_at -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000064-GPOS-00033",
            "satisfies": [
              "SRG-OS-000064-GPOS-00033",
              "SRG-OS-000458-GPOS-00203",
              "SRG-OS-000461-GPOS-00205",
              "SRG-OS-000392-GPOS-00172"
            ],
            "gid": "V-72129",
            "rid": "SV-86753r3_rule",
            "stig_id": "RHEL-07-030530",
            "cci": [
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78481r5_fix"
          },
          "code": "control \"V-72129\" do\n  title \"All uses of the open_by_handle_at command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000064-GPOS-00033\"\n  tag \"satisfies\": [\"SRG-OS-000064-GPOS-00033\", \"SRG-OS-000458-GPOS-00203\",\n\"SRG-OS-000461-GPOS-00205\", \"SRG-OS-000392-GPOS-00172\"]\n  tag \"gid\": \"V-72129\"\n  tag \"rid\": \"SV-86753r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030530\"\n  tag \"cci\": [\"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"open_by_handle_at\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw open_by_handle_at /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S open_by_handle_at -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S open_by_handle_at -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S open_by_handle_at -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S open_by_handle_at -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nIf there are no audit rules defined for the \\\"open_by_handle_at\\\" command, this\nis a finding.\n\nIf the output does not produce a rule containing \\\"-F exit=-EPERM\\\", this is a\nfinding.\n\nIf the output does not produce a rule containing \\\"-F exit=-EACCES\\\", this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"open_by_handle_at\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S open_by_handle_at -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S open_by_handle_at -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S open_by_handle_at -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S open_by_handle_at -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nThe audit daemon must be restarted for the changes to take effect.\n\"\n  tag \"fix_id\": \"F-78481r5_fix\"\n\n  describe auditd.syscall(\"open_by_handle_at\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n    its('exit.uniq') { should include '-EPERM' }\n  end\n  describe auditd.syscall(\"open_by_handle_at\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n    its('exit.uniq') { should include '-EACCES' }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"open_by_handle_at\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n      its('exit.uniq') { should include '-EPERM' }\n    end\n    describe auditd.syscall(\"open_by_handle_at\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n      its('exit.uniq') { should include '-EACCES' }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72129.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open_by_handle_at\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000224502,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open_by_handle_at\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000150257,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open_by_handle_at\" arch == \"b32\" exit.uniq should include \"-EPERM\"",
              "run_time": 0.000157509,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EPERM\""
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open_by_handle_at\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000142789,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open_by_handle_at\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000127199,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open_by_handle_at\" arch == \"b32\" exit.uniq should include \"-EACCES\"",
              "run_time": 0.000135018,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EACCES\""
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open_by_handle_at\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000129523,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open_by_handle_at\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000123025,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open_by_handle_at\" arch == \"b64\" exit.uniq should include \"-EPERM\"",
              "run_time": 0.000134415,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EPERM\""
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open_by_handle_at\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000197726,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open_by_handle_at\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000121572,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"open_by_handle_at\" arch == \"b64\" exit.uniq should include \"-EACCES\"",
              "run_time": 0.000130802,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EACCES\""
            }
          ]
        },
        {
          "id": "V-72131",
          "title": "All uses of the truncate command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"truncate\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw truncate /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S truncate -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S truncate -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S truncate -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S truncate -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nIf there are no audit rules defined for the \"truncate\" command, this is a\nfinding.\n\nIf the output does not produce a rule containing \"-F exit=-EPERM\", this is a\nfinding.\n\nIf the output does not produce a rule containing \"-F exit=-EACCES\", this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"truncate\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S truncate -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S truncate -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S truncate -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S truncate -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000064-GPOS-00033",
            "satisfies": [
              "SRG-OS-000064-GPOS-00033",
              "SRG-OS-000458-GPOS-00203",
              "SRG-OS-000461-GPOS-00205",
              "SRG-OS-000392-GPOS-00172"
            ],
            "gid": "V-72131",
            "rid": "SV-86755r3_rule",
            "stig_id": "RHEL-07-030540",
            "cci": [
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78483r5_fix"
          },
          "code": "control \"V-72131\" do\n  title \"All uses of the truncate command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000064-GPOS-00033\"\n  tag \"satisfies\": [\"SRG-OS-000064-GPOS-00033\", \"SRG-OS-000458-GPOS-00203\",\n\"SRG-OS-000461-GPOS-00205\", \"SRG-OS-000392-GPOS-00172\"]\n  tag \"gid\": \"V-72131\"\n  tag \"rid\": \"SV-86755r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030540\"\n  tag \"cci\": [\"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"truncate\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw truncate /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S truncate -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S truncate -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S truncate -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S truncate -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nIf there are no audit rules defined for the \\\"truncate\\\" command, this is a\nfinding.\n\nIf the output does not produce a rule containing \\\"-F exit=-EPERM\\\", this is a\nfinding.\n\nIf the output does not produce a rule containing \\\"-F exit=-EACCES\\\", this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"truncate\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S truncate -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S truncate -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S truncate -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S truncate -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78483r5_fix\"\n\n  describe auditd.syscall(\"truncate\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n    its('exit.uniq') { should include '-EPERM' }\n  end\n  describe auditd.syscall(\"truncate\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n    its('exit.uniq') { should include '-EACCES' }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"truncate\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n      its('exit.uniq') { should include '-EPERM' }\n    end\n    describe auditd.syscall(\"truncate\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n      its('exit.uniq') { should include '-EACCES' }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72131.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"truncate\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.0006761,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"truncate\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000144397,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"truncate\" arch == \"b32\" exit.uniq should include \"-EPERM\"",
              "run_time": 0.000145146,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EPERM\""
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"truncate\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000133181,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"truncate\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000123894,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"truncate\" arch == \"b32\" exit.uniq should include \"-EACCES\"",
              "run_time": 0.000265493,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EACCES\""
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"truncate\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000410955,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"truncate\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000252826,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"truncate\" arch == \"b64\" exit.uniq should include \"-EPERM\"",
              "run_time": 0.000148796,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EPERM\""
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"truncate\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000218036,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"truncate\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000339157,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"truncate\" arch == \"b64\" exit.uniq should include \"-EACCES\"",
              "run_time": 0.000197916,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EACCES\""
            }
          ]
        },
        {
          "id": "V-72133",
          "title": "All uses of the ftruncate command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"ftruncate\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw ftruncate /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S ftruncate -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S ftruncate -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S ftruncate -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S ftruncate -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nIf there are no audit rules defined for the \"ftruncate\" command, this is a\nfinding.\n\nIf the output does not produce a rule containing \"-F exit=-EPERM\", this is a\nfinding.\n\nIf the output does not produce a rule containing \"-F exit=-EACCES\", this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"ftruncate\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S ftruncate -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S ftruncate -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S ftruncate -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S ftruncate -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000064-GPOS-00033",
            "satisfies": [
              "SRG-OS-000064-GPOS-00033",
              "SRG-OS-000458-GPOS-00203",
              "SRG-OS-000461-GPOS-00205",
              "SRG-OS-000392-GPOS-00172"
            ],
            "gid": "V-72133",
            "rid": "SV-86757r3_rule",
            "stig_id": "RHEL-07-030550",
            "cci": [
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78485r6_fix"
          },
          "code": "control \"V-72133\" do\n  title \"All uses of the ftruncate command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000064-GPOS-00033\"\n  tag \"satisfies\": [\"SRG-OS-000064-GPOS-00033\", \"SRG-OS-000458-GPOS-00203\",\n\"SRG-OS-000461-GPOS-00205\", \"SRG-OS-000392-GPOS-00172\"]\n  tag \"gid\": \"V-72133\"\n  tag \"rid\": \"SV-86757r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030550\"\n  tag \"cci\": [\"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"ftruncate\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw ftruncate /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S ftruncate -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S ftruncate -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S ftruncate -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S ftruncate -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nIf there are no audit rules defined for the \\\"ftruncate\\\" command, this is a\nfinding.\n\nIf the output does not produce a rule containing \\\"-F exit=-EPERM\\\", this is a\nfinding.\n\nIf the output does not produce a rule containing \\\"-F exit=-EACCES\\\", this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"ftruncate\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S ftruncate -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b32 -S ftruncate -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S ftruncate -F exit=-EPERM -F auid>=1000 -F auid!=4294967295 -k access\n\n-a always,exit -F arch=b64 -S ftruncate -F exit=-EACCES -F auid>=1000 -F auid!=4294967295 -k access\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78485r6_fix\"\n\n  describe auditd.syscall(\"ftruncate\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n    its('exit.uniq') { should include '-EPERM' }\n  end\n  describe auditd.syscall(\"ftruncate\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n    its('exit.uniq') { should include '-EACCES' }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"ftruncate\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n      its('exit.uniq') { should include '-EPERM' }\n    end\n    describe auditd.syscall(\"ftruncate\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n      its('exit.uniq') { should include '-EACCES' }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72133.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"ftruncate\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000323794,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"ftruncate\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000190873,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"ftruncate\" arch == \"b32\" exit.uniq should include \"-EPERM\"",
              "run_time": 0.00055378,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EPERM\""
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"ftruncate\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000243921,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"ftruncate\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000157588,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"ftruncate\" arch == \"b32\" exit.uniq should include \"-EACCES\"",
              "run_time": 0.000478438,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EACCES\""
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"ftruncate\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000179315,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"ftruncate\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000194551,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"ftruncate\" arch == \"b64\" exit.uniq should include \"-EPERM\"",
              "run_time": 0.000153798,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EPERM\""
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"ftruncate\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000128375,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"ftruncate\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000123774,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"ftruncate\" arch == \"b64\" exit.uniq should include \"-EACCES\"",
              "run_time": 0.000138116,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [] to include \"-EACCES\""
            }
          ]
        },
        {
          "id": "V-72135",
          "title": "All uses of the semanage command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"semanage\" command occur.\n\nCheck the file system rule in \"/etc/audit/audit.rules\" with the following\ncommand:\n\n# grep -i /usr/sbin/semanage /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/sbin/semanage -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"semanage\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-a always,exit -F path=/usr/sbin/semanage -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000392-GPOS-00172",
            "satisfies": [
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000463-GPOS-00207",
              "SRG-OS-000465-GPOS-00209"
            ],
            "gid": "V-72135",
            "rid": "SV-86759r3_rule",
            "stig_id": "RHEL-07-030560",
            "cci": [
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78487r4_fix"
          },
          "code": "control \"V-72135\" do\n  title \"All uses of the semanage command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  tag \"gtitle\": \"SRG-OS-000392-GPOS-00172\"\n  tag \"satisfies\": [\"SRG-OS-000392-GPOS-00172\", \"SRG-OS-000463-GPOS-00207\",\n\"SRG-OS-000465-GPOS-00209\"]\n  tag \"gid\": \"V-72135\"\n  tag \"rid\": \"SV-86759r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030560\"\n  tag \"cci\": [\"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"semanage\\\" command occur.\n\nCheck the file system rule in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\n# grep -i /usr/sbin/semanage /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/sbin/semanage -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"semanage\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-a always,exit -F path=/usr/sbin/semanage -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78487r4_fix\"\n\n  audit_file = '/usr/sbin/semanage'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72135.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/semanage\" permissions should not cmp == []",
              "run_time": 0.000180678,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/semanage\" action should not include \"never\"",
              "run_time": 0.000537765,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72137",
          "title": "All uses of the setsebool command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"setsebool\" command occur.\n\nCheck the file system rule in \"/etc/audit/audit.rules\" with the following\ncommand:\n\n# grep -i /usr/sbin/setsebool /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/sbin/setsebool -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"setsebool\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-a always,exit -F path=/usr/sbin/setsebool -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000392-GPOS-00172",
            "satisfies": [
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000463-GPOS-00207",
              "SRG-OS-000465-GPOS-00209"
            ],
            "gid": "V-72137",
            "rid": "SV-86761r3_rule",
            "stig_id": "RHEL-07-030570",
            "cci": [
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78489r5_fix"
          },
          "code": "control \"V-72137\" do\n  title \"All uses of the setsebool command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  tag \"gtitle\": \"SRG-OS-000392-GPOS-00172\"\n  tag \"satisfies\": [\"SRG-OS-000392-GPOS-00172\", \"SRG-OS-000463-GPOS-00207\",\n\"SRG-OS-000465-GPOS-00209\"]\n  tag \"gid\": \"V-72137\"\n  tag \"rid\": \"SV-86761r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030570\"\n  tag \"cci\": [\"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"setsebool\\\" command occur.\n\nCheck the file system rule in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\n# grep -i /usr/sbin/setsebool /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/sbin/setsebool -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"setsebool\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-a always,exit -F path=/usr/sbin/setsebool -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78489r5_fix\"\n\n  audit_file = '/usr/sbin/setsebool'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72137.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/setsebool\" permissions should not cmp == []",
              "run_time": 0.000247357,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/setsebool\" action should not include \"never\"",
              "run_time": 0.000103508,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72139",
          "title": "All uses of the chcon command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"chcon\" command occur.\n\nCheck the file system rule in \"/etc/audit/audit.rules\" with the following\ncommand:\n\n# grep -i /usr/bin/chcon /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/bin/chcon -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"chcon\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-a always,exit -F path=/usr/bin/chcon -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000392-GPOS-00172",
            "satisfies": [
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000463-GPOS-00207",
              "SRG-OS-000465-GPOS-00209"
            ],
            "gid": "V-72139",
            "rid": "SV-86763r3_rule",
            "stig_id": "RHEL-07-030580",
            "cci": [
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78491r5_fix"
          },
          "code": "control \"V-72139\" do\n  title \"All uses of the chcon command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  tag \"gtitle\": \"SRG-OS-000392-GPOS-00172\"\n  tag \"satisfies\": [\"SRG-OS-000392-GPOS-00172\", \"SRG-OS-000463-GPOS-00207\",\n\"SRG-OS-000465-GPOS-00209\"]\n  tag \"gid\": \"V-72139\"\n  tag \"rid\": \"SV-86763r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030580\"\n  tag \"cci\": [\"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"chcon\\\" command occur.\n\nCheck the file system rule in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\n# grep -i /usr/bin/chcon /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/bin/chcon -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"chcon\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-a always,exit -F path=/usr/bin/chcon -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78491r5_fix\"\n\n  audit_file = '/usr/bin/chcon'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72139.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/chcon\" permissions should not cmp == []",
              "run_time": 0.000289586,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/chcon\" action should not include \"never\"",
              "run_time": 0.000101216,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72141",
          "title": "All uses of the setfiles command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"setfiles\" command occur.\n\nCheck the file system rule in \"/etc/audit/audit.rules\" with the following\ncommand:\n\n# grep -i /usr/sbin/setfiles /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/sbin/setfiles -F perm=x -F auid>=1000 -F auid!=4294967295 -k -F privileged-priv_change\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"setfiles\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-a always,exit -F path=/usr/sbin/setfiles -F perm=x -F auid>=1000 -F auid!=4294967295 -k -F privileged-priv_change\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000392-GPOS-00172",
            "satisfies": [
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000463-GPOS-00207",
              "SRG-OS-000465-GPOS-00209"
            ],
            "gid": "V-72141",
            "rid": "SV-86765r4_rule",
            "stig_id": "RHEL-07-030590",
            "cci": [
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78493r6_fix"
          },
          "code": "control \"V-72141\" do\n  title \"All uses of the setfiles command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  tag \"gtitle\": \"SRG-OS-000392-GPOS-00172\"\n  tag \"satisfies\": [\"SRG-OS-000392-GPOS-00172\", \"SRG-OS-000463-GPOS-00207\",\n\"SRG-OS-000465-GPOS-00209\"]\n  tag \"gid\": \"V-72141\"\n  tag \"rid\": \"SV-86765r4_rule\"\n  tag \"stig_id\": \"RHEL-07-030590\"\n  tag \"cci\": [\"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"setfiles\\\" command occur.\n\nCheck the file system rule in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\n# grep -i /usr/sbin/setfiles /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/sbin/setfiles -F perm=x -F auid>=1000 -F auid!=4294967295 -k -F privileged-priv_change\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"setfiles\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-a always,exit -F path=/usr/sbin/setfiles -F perm=x -F auid>=1000 -F auid!=4294967295 -k -F privileged-priv_change\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78493r6_fix\"\n\n  audit_file = '/usr/sbin/setfiles'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72141.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/setfiles\" permissions should not cmp == []",
              "run_time": 0.000344522,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/setfiles\" action should not include \"never\"",
              "run_time": 0.000175095,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72143",
          "title": "The operating system must generate audit records for all\nsuccessful/unsuccessful account access count events.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful account access count events occur.\n\nCheck the file system rule in \"/etc/audit/audit.rules\" with the following\ncommands:\n\n# grep -i /var/log/tallylog /etc/audit/audit.rules\n\n-w /var/log/tallylog -p wa -k logins\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful account access count events occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-w /var/log/tallylog -p wa -k logins\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000392-GPOS-00172",
            "satisfies": [
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000470-GPOS-00214",
              "SRG-OS-000473-GPOS-00218"
            ],
            "gid": "V-72143",
            "rid": "SV-86767r2_rule",
            "stig_id": "RHEL-07-030600",
            "cci": [
              "CCI-000126",
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-2 d",
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78495r4_fix"
          },
          "code": "control \"V-72143\" do\n  title \"The operating system must generate audit records for all\nsuccessful/unsuccessful account access count events.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  tag \"gtitle\": \"SRG-OS-000392-GPOS-00172\"\n  tag \"satisfies\": [\"SRG-OS-000392-GPOS-00172\", \"SRG-OS-000470-GPOS-00214\",\n\"SRG-OS-000473-GPOS-00218\"]\n  tag \"gid\": \"V-72143\"\n  tag \"rid\": \"SV-86767r2_rule\"\n  tag \"stig_id\": \"RHEL-07-030600\"\n  tag \"cci\": [\"CCI-000126\", \"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-2 d\", \"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful account access count events occur.\n\nCheck the file system rule in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\n# grep -i /var/log/tallylog /etc/audit/audit.rules\n\n-w /var/log/tallylog -p wa -k logins\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful account access count events occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-w /var/log/tallylog -p wa -k logins\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78495r4_fix\"\n\n  audit_file = '/var/log/tallylog'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'w' }\n      it { should include 'a' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72143.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/var/log/tallylog\" permissions should not cmp == []",
              "run_time": 0.000295948,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/var/log/tallylog\" action should not include \"never\"",
              "run_time": 0.00024707,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72145",
          "title": "The operating system must generate audit records for all unsuccessful\naccount access events.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nunsuccessful account access events occur.\n\nCheck the file system rule in \"/etc/audit/audit.rules\" with the following\ncommands:\n\n# grep -i /var/run/faillock /etc/audit/audit.rules\n\n-w /var/run/faillock -p wa -k logins\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nunsuccessful account access events occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-w /var/run/faillock -p wa -k logins\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000392-GPOS-00172",
            "satisfies": [
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000470-GPOS-00214",
              "SRG-OS-000473-GPOS-00218"
            ],
            "gid": "V-72145",
            "rid": "SV-86769r3_rule",
            "stig_id": "RHEL-07-030610",
            "cci": [
              "CCI-000126",
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-2 d",
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78497r4_fix"
          },
          "code": "control \"V-72145\" do\n  title \"The operating system must generate audit records for all unsuccessful\naccount access events.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  tag \"gtitle\": \"SRG-OS-000392-GPOS-00172\"\n  tag \"satisfies\": [\"SRG-OS-000392-GPOS-00172\", \"SRG-OS-000470-GPOS-00214\",\n\"SRG-OS-000473-GPOS-00218\"]\n  tag \"gid\": \"V-72145\"\n  tag \"rid\": \"SV-86769r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030610\"\n  tag \"cci\": [\"CCI-000126\", \"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-2 d\", \"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nunsuccessful account access events occur.\n\nCheck the file system rule in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\n# grep -i /var/run/faillock /etc/audit/audit.rules\n\n-w /var/run/faillock -p wa -k logins\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nunsuccessful account access events occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-w /var/run/faillock -p wa -k logins\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78497r4_fix\"\n\n  audit_file = '/var/run/faillock'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'w' }\n      it { should include 'a' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72145.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/var/run/faillock\" permissions should not cmp == []",
              "run_time": 0.000342265,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/var/run/faillock\" action should not include \"never\"",
              "run_time": 0.000158078,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72147",
          "title": "The operating system must generate audit records for all successful\naccount access events.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when successful\naccount access events occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommands:\n\n# grep -i /var/log/lastlog /etc/audit/audit.rules\n\n-w /var/log/lastlog -p wa -k logins\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful account access events occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-w /var/log/lastlog -p wa -k logins\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000392-GPOS-00172",
            "satisfies": [
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000470-GPOS-00214",
              "SRG-OS-000473-GPOS-00218"
            ],
            "gid": "V-72147",
            "rid": "SV-86771r2_rule",
            "stig_id": "RHEL-07-030620",
            "cci": [
              "CCI-000126",
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-2 d",
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78499r3_fix"
          },
          "code": "control \"V-72147\" do\n  title \"The operating system must generate audit records for all successful\naccount access events.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  tag \"gtitle\": \"SRG-OS-000392-GPOS-00172\"\n  tag \"satisfies\": [\"SRG-OS-000392-GPOS-00172\", \"SRG-OS-000470-GPOS-00214\",\n\"SRG-OS-000473-GPOS-00218\"]\n  tag \"gid\": \"V-72147\"\n  tag \"rid\": \"SV-86771r2_rule\"\n  tag \"stig_id\": \"RHEL-07-030620\"\n  tag \"cci\": [\"CCI-000126\", \"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-2 d\", \"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when successful\naccount access events occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\n# grep -i /var/log/lastlog /etc/audit/audit.rules\n\n-w /var/log/lastlog -p wa -k logins\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful account access events occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-w /var/log/lastlog -p wa -k logins\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78499r3_fix\"\n\n  audit_file = '/var/log/lastlog'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'w' }\n      it { should include 'a' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72147.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/var/log/lastlog\" permissions should not cmp == []",
              "run_time": 0.000277276,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/var/log/lastlog\" action should not include \"never\"",
              "run_time": 0.000161325,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72149",
          "title": "All uses of the passwd command must be audited.",
          "desc": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged password commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged password commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"passwd\" command occur.\n\nCheck the file system rule in \"/etc/audit/audit.rules\" with the following\ncommand:\n\n# grep -i /usr/bin/passwd /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/bin/passwd -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-passwd\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"passwd\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-a always,exit -F path=/usr/bin/passwd -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-passwd\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000042-GPOS-00020",
            "satisfies": [
              "SRG-OS-000042-GPOS-00020",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000471-GPOS-00215"
            ],
            "gid": "V-72149",
            "rid": "SV-86773r3_rule",
            "stig_id": "RHEL-07-030630",
            "cci": [
              "CCI-000135",
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-3 (1)",
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78501r5_fix"
          },
          "code": "control \"V-72149\" do\n  title \"All uses of the passwd command must be audited.\"\n  desc  \"\n    Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged password commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.\n  \"\n  tag \"gtitle\": \"SRG-OS-000042-GPOS-00020\"\n  tag \"satisfies\": [\"SRG-OS-000042-GPOS-00020\", \"SRG-OS-000392-GPOS-00172\",\n\"SRG-OS-000471-GPOS-00215\"]\n  tag \"gid\": \"V-72149\"\n  tag \"rid\": \"SV-86773r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030630\"\n  tag \"cci\": [\"CCI-000135\", \"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-3 (1)\", \"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"passwd\\\" command occur.\n\nCheck the file system rule in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\n# grep -i /usr/bin/passwd /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/bin/passwd -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-passwd\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"passwd\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-a always,exit -F path=/usr/bin/passwd -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-passwd\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78501r5_fix\"\n\n  audit_file = '/usr/bin/passwd'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72149.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/passwd\" permissions should not cmp == []",
              "run_time": 0.000374896,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/passwd\" action should not include \"never\"",
              "run_time": 0.000113496,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72151",
          "title": "All uses of the unix_chkpwd command must be audited.",
          "desc": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged password commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged password commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"unix_chkpwd\" command occur.\n\nCheck the file system rule in \"/etc/audit/audit.rules\" with the following\ncommand:\n\n# grep -i /sbin/unix_chkpwd /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/sbin/unix_chkpwd -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-passwd\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"unix_chkpwd\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-a always,exit -F path=/usr/sbin/unix_chkpwd -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-passwd\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000042-GPOS-00020",
            "satisfies": [
              "SRG-OS-000042-GPOS-00020",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000471-GPOS-00215"
            ],
            "gid": "V-72151",
            "rid": "SV-86775r4_rule",
            "stig_id": "RHEL-07-030640",
            "cci": [
              "CCI-000135",
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-3 (1)",
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78503r7_fix"
          },
          "code": "control \"V-72151\" do\n  title \"All uses of the unix_chkpwd command must be audited.\"\n  desc  \"\n    Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged password commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.\n  \"\n  tag \"gtitle\": \"SRG-OS-000042-GPOS-00020\"\n  tag \"satisfies\": [\"SRG-OS-000042-GPOS-00020\", \"SRG-OS-000392-GPOS-00172\",\n\"SRG-OS-000471-GPOS-00215\"]\n  tag \"gid\": \"V-72151\"\n  tag \"rid\": \"SV-86775r4_rule\"\n  tag \"stig_id\": \"RHEL-07-030640\"\n  tag \"cci\": [\"CCI-000135\", \"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-3 (1)\", \"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"unix_chkpwd\\\" command occur.\n\nCheck the file system rule in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\n# grep -i /sbin/unix_chkpwd /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/sbin/unix_chkpwd -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-passwd\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"unix_chkpwd\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-a always,exit -F path=/usr/sbin/unix_chkpwd -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-passwd\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78503r7_fix\"\n\n  audit_file = '/usr/sbin/unix_chkpwd'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72151.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/unix_chkpwd\" permissions should not cmp == []",
              "run_time": 0.000160119,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/unix_chkpwd\" action should not include \"never\"",
              "run_time": 9.8968e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72153",
          "title": "All uses of the gpasswd command must be audited.",
          "desc": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged password commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged password commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"gpasswd\" command occur.\n\nCheck the file system rule in \"/etc/audit/audit.rules\" with the following\ncommand:\n\n# grep -i /usr/bin/gpasswd /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/bin/gpasswd -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-passwd\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"gpasswd\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-a always,exit -F path=/usr/bin/gpasswd -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-passwd\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000042-GPOS-00020",
            "satisfies": [
              "SRG-OS-000042-GPOS-00020",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000471-GPOS-00215"
            ],
            "gid": "V-72153",
            "rid": "SV-86777r3_rule",
            "stig_id": "RHEL-07-030650",
            "cci": [
              "CCI-000135",
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-3 (1)",
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78505r4_fix"
          },
          "code": "control \"V-72153\" do\n  title \"All uses of the gpasswd command must be audited.\"\n  desc  \"\n    Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged password commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.\n  \"\n  tag \"gtitle\": \"SRG-OS-000042-GPOS-00020\"\n  tag \"satisfies\": [\"SRG-OS-000042-GPOS-00020\", \"SRG-OS-000392-GPOS-00172\",\n\"SRG-OS-000471-GPOS-00215\"]\n  tag \"gid\": \"V-72153\"\n  tag \"rid\": \"SV-86777r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030650\"\n  tag \"cci\": [\"CCI-000135\", \"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-3 (1)\", \"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"gpasswd\\\" command occur.\n\nCheck the file system rule in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\n# grep -i /usr/bin/gpasswd /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/bin/gpasswd -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-passwd\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"gpasswd\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-a always,exit -F path=/usr/bin/gpasswd -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-passwd\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78505r4_fix\"\n\n  audit_file = '/usr/bin/gpasswd'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72153.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/gpasswd\" permissions should not cmp == []",
              "run_time": 0.000169357,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/gpasswd\" action should not include \"never\"",
              "run_time": 0.00010863,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72155",
          "title": "All uses of the chage command must be audited.",
          "desc": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged password commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged password commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"chage\" command occur.\n\nCheck the file system rule in \"/etc/audit/audit.rules\" with the following\ncommand:\n\n# grep -i /usr/bin/chage /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/bin/chage -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-passwd\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"chage\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-a always,exit -F path=/usr/bin/chage -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-passwd\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000042-GPOS-00020",
            "satisfies": [
              "SRG-OS-000042-GPOS-00020",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000471-GPOS-00215"
            ],
            "gid": "V-72155",
            "rid": "SV-86779r3_rule",
            "stig_id": "RHEL-07-030660",
            "cci": [
              "CCI-000135",
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-3 (1)",
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78507r4_fix"
          },
          "code": "control \"V-72155\" do\n  title \"All uses of the chage command must be audited.\"\n  desc  \"\n    Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged password commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.\n  \"\n  tag \"gtitle\": \"SRG-OS-000042-GPOS-00020\"\n  tag \"satisfies\": [\"SRG-OS-000042-GPOS-00020\", \"SRG-OS-000392-GPOS-00172\",\n\"SRG-OS-000471-GPOS-00215\"]\n  tag \"gid\": \"V-72155\"\n  tag \"rid\": \"SV-86779r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030660\"\n  tag \"cci\": [\"CCI-000135\", \"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-3 (1)\", \"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"chage\\\" command occur.\n\nCheck the file system rule in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\n# grep -i /usr/bin/chage /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/bin/chage -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-passwd\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"chage\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-a always,exit -F path=/usr/bin/chage -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-passwd\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78507r4_fix\"\n\n  audit_file = '/usr/bin/chage'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72155.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/chage\" permissions should not cmp == []",
              "run_time": 0.000151459,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/chage\" action should not include \"never\"",
              "run_time": 0.000722385,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72157",
          "title": "All uses of the userhelper command must be audited.",
          "desc": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged password commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged password commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"userhelper\" command occur.\n\nCheck the file system rule in \"/etc/audit/audit.rules\" with the following\ncommand:\n\n# grep -i /usr/sbin/userhelper /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/sbin/userhelper -F perm=x -F auid>=1000 -F\nauid!=4294967295 -k privileged-passwd\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"userhelper\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-a always,exit -F path=/usr/sbin/userhelper -F perm=x -F auid>=1000 -F\nauid!=4294967295 -k privileged-passwd\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000042-GPOS-00020",
            "satisfies": [
              "SRG-OS-000042-GPOS-00020",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000471-GPOS-00215"
            ],
            "gid": "V-72157",
            "rid": "SV-86781r3_rule",
            "stig_id": "RHEL-07-030670",
            "cci": [
              "CCI-000135",
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-3 (1)",
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78509r4_fix"
          },
          "code": "control \"V-72157\" do\n  title \"All uses of the userhelper command must be audited.\"\n  desc  \"\n    Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged password commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.\n  \"\n  tag \"gtitle\": \"SRG-OS-000042-GPOS-00020\"\n  tag \"satisfies\": [\"SRG-OS-000042-GPOS-00020\", \"SRG-OS-000392-GPOS-00172\",\n\"SRG-OS-000471-GPOS-00215\"]\n  tag \"gid\": \"V-72157\"\n  tag \"rid\": \"SV-86781r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030670\"\n  tag \"cci\": [\"CCI-000135\", \"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-3 (1)\", \"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"userhelper\\\" command occur.\n\nCheck the file system rule in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\n# grep -i /usr/sbin/userhelper /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/sbin/userhelper -F perm=x -F auid>=1000 -F\nauid!=4294967295 -k privileged-passwd\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"userhelper\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-a always,exit -F path=/usr/sbin/userhelper -F perm=x -F auid>=1000 -F\nauid!=4294967295 -k privileged-passwd\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78509r4_fix\"\n\n  audit_file = '/usr/sbin/userhelper'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72157.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/userhelper\" permissions should not cmp == []",
              "run_time": 0.000227216,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/userhelper\" action should not include \"never\"",
              "run_time": 0.000172847,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72159",
          "title": "All uses of the su command must be audited.",
          "desc": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged access commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged access commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"su\" command occur.\n\nCheck for the following system call being audited by performing the following\ncommand to check the file system rules in \"/etc/audit/audit.rules\":\n\n# grep -i /usr/bin/su /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/bin/su -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"su\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-a always,exit -F path=/usr/bin/su -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000037-GPOS-00015",
            "satisfies": [
              "SRG-OS-000037-GPOS-00015",
              "SRG-OS-000042-GPOS-00020",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000462-GPOS-00206",
              "SRG-OS-000471-GPOS-00215"
            ],
            "gid": "V-72159",
            "rid": "SV-86783r4_rule",
            "stig_id": "RHEL-07-030680",
            "cci": [
              "CCI-000130",
              "CCI-000135",
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-3",
              "AU-3 (1)",
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78511r5_fix"
          },
          "code": "control \"V-72159\" do\n  title \"All uses of the su command must be audited.\"\n  desc  \"\n    Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged access commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.\n  \"\n  tag \"gtitle\": \"SRG-OS-000037-GPOS-00015\"\n  tag \"satisfies\": [\"SRG-OS-000037-GPOS-00015\", \"SRG-OS-000042-GPOS-00020\",\n\"SRG-OS-000392-GPOS-00172\", \"SRG-OS-000462-GPOS-00206\",\n\"SRG-OS-000471-GPOS-00215\"]\n  tag \"gid\": \"V-72159\"\n  tag \"rid\": \"SV-86783r4_rule\"\n  tag \"stig_id\": \"RHEL-07-030680\"\n  tag \"cci\": [\"CCI-000130\", \"CCI-000135\", \"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-3\", \"AU-3 (1)\", \"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"su\\\" command occur.\n\nCheck for the following system call being audited by performing the following\ncommand to check the file system rules in \\\"/etc/audit/audit.rules\\\":\n\n# grep -i /usr/bin/su /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/bin/su -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"su\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-a always,exit -F path=/usr/bin/su -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78511r5_fix\"\n\n  audit_file = '/usr/bin/su'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72159.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/su\" permissions should not cmp == []",
              "run_time": 0.000173794,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/su\" action should not include \"never\"",
              "run_time": 0.000102348,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72161",
          "title": "All uses of the sudo command must be audited.",
          "desc": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged access commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged access commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"sudo\" command occur.\n\nCheck for the following system calls being audited by performing the following\ncommand to check the file system rules in \"/etc/audit/audit.rules\":\n\n# grep -i /usr/bin/sudo /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/bin/sudo -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"sudo\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-a always,exit -F path=/usr/bin/sudo -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000037-GPOS-00015",
            "satisfies": [
              "SRG-OS-000037-GPOS-00015",
              "SRG-OS-000042-GPOS-00020",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000462-GPOS-00206",
              "SRG-OS-000471-GPOS-00215"
            ],
            "gid": "V-72161",
            "rid": "SV-86785r3_rule",
            "stig_id": "RHEL-07-030690",
            "cci": [
              "CCI-000130",
              "CCI-000135",
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-3",
              "AU-3 (1)",
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78513r4_fix"
          },
          "code": "control \"V-72161\" do\n  title \"All uses of the sudo command must be audited.\"\n  desc  \"\n    Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged access commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.\n  \"\n  tag \"gtitle\": \"SRG-OS-000037-GPOS-00015\"\n  tag \"satisfies\": [\"SRG-OS-000037-GPOS-00015\", \"SRG-OS-000042-GPOS-00020\",\n\"SRG-OS-000392-GPOS-00172\", \"SRG-OS-000462-GPOS-00206\",\n\"SRG-OS-000471-GPOS-00215\"]\n  tag \"gid\": \"V-72161\"\n  tag \"rid\": \"SV-86785r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030690\"\n  tag \"cci\": [\"CCI-000130\", \"CCI-000135\", \"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-3\", \"AU-3 (1)\", \"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"sudo\\\" command occur.\n\nCheck for the following system calls being audited by performing the following\ncommand to check the file system rules in \\\"/etc/audit/audit.rules\\\":\n\n# grep -i /usr/bin/sudo /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/bin/sudo -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"sudo\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-a always,exit -F path=/usr/bin/sudo -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78513r4_fix\"\n\n  audit_file = '/usr/bin/sudo'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72161.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/sudo\" permissions should not cmp == []",
              "run_time": 0.000150491,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/sudo\" action should not include \"never\"",
              "run_time": 0.000177797,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72163",
          "title": "All uses of the sudoers command must be audited.",
          "desc": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged access commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged access commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"sudoer\" command occur.\n\nCheck for modification of the following files being audited by performing the\nfollowing commands to check the file system rules in\n\"/etc/audit/audit.rules\":\n\n# grep -i \"/etc/sudoers\" /etc/audit/audit.rules\n\n-w /etc/sudoers -p wa -k privileged-actions\n\n# grep -i \"/etc/sudoers.d/\" /etc/audit/audit.rules\n\n-w /etc/sudoers.d/ -p wa -k privileged-actions\n\nIf the commands do not return output that does not match the examples, this is\na finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"sudoer\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-w /etc/sudoers -p wa -k privileged-actions\n\n-w /etc/sudoers.d/ -p wa -k privileged-actions\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000037-GPOS-00015",
            "satisfies": [
              "SRG-OS-000037-GPOS-00015",
              "SRG-OS-000042-GPOS-00020",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000462-GPOS-00206",
              "SRG-OS-000471-GPOS-00215"
            ],
            "gid": "V-72163",
            "rid": "SV-86787r4_rule",
            "stig_id": "RHEL-07-030700",
            "cci": [
              "CCI-000130",
              "CCI-000135",
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-3",
              "AU-3 (1)",
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78517r5_fix"
          },
          "code": "control \"V-72163\" do\n  title \"All uses of the sudoers command must be audited.\"\n  desc  \"\n    Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged access commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.\n  \"\n  tag \"gtitle\": \"SRG-OS-000037-GPOS-00015\"\n  tag \"satisfies\": [\"SRG-OS-000037-GPOS-00015\", \"SRG-OS-000042-GPOS-00020\",\n\"SRG-OS-000392-GPOS-00172\", \"SRG-OS-000462-GPOS-00206\",\n\"SRG-OS-000471-GPOS-00215\"]\n  tag \"gid\": \"V-72163\"\n  tag \"rid\": \"SV-86787r4_rule\"\n  tag \"stig_id\": \"RHEL-07-030700\"\n  tag \"cci\": [\"CCI-000130\", \"CCI-000135\", \"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-3\", \"AU-3 (1)\", \"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"sudoer\\\" command occur.\n\nCheck for modification of the following files being audited by performing the\nfollowing commands to check the file system rules in\n\\\"/etc/audit/audit.rules\\\":\n\n# grep -i \\\"/etc/sudoers\\\" /etc/audit/audit.rules\n\n-w /etc/sudoers -p wa -k privileged-actions\n\n# grep -i \\\"/etc/sudoers.d/\\\" /etc/audit/audit.rules\n\n-w /etc/sudoers.d/ -p wa -k privileged-actions\n\nIf the commands do not return output that does not match the examples, this is\na finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"sudoer\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-w /etc/sudoers -p wa -k privileged-actions\n\n-w /etc/sudoers.d/ -p wa -k privileged-actions\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78517r5_fix\"\n\n  audit_files = ['/etc/sudoers', '/etc/sudoers.d']\n\n  if audit_files.any? { |audit_file| file(audit_file).exist? }\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  audit_files.each do |audit_file|\n    describe auditd.file(audit_file) do\n      its('permissions') { should_not cmp [] }\n      its('action') { should_not include 'never' }\n    end if file(audit_file).exist?\n\n    # Resource creates data structure including all usages of file\n    perms = auditd.file(audit_file).permissions\n\n    perms.each do |perm|\n      describe perm do\n        it { should include 'w' }\n        it { should include 'a' }\n      end\n    end if file(audit_file).exist?\n  end\n\n  describe \"The #{audit_files} files do not exist\" do\n    skip \"The #{audit_files} files do not exist, this requirement is Not Applicable.\"\n  end if !audit_files.any? { |audit_file| file(audit_file).exist? }\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72163.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/etc/sudoers\" permissions should not cmp == []",
              "run_time": 0.000238493,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/etc/sudoers\" action should not include \"never\"",
              "run_time": 0.000108462,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/etc/sudoers.d\" permissions should not cmp == []",
              "run_time": 0.000345887,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/etc/sudoers.d\" action should not include \"never\"",
              "run_time": 0.000172184,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72165",
          "title": "All uses of the newgrp command must be audited.",
          "desc": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged access commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged access commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"newgrp\" command occur.\n\nCheck for the following system call being audited by performing the following\ncommand to check the file system rules in \"/etc/audit/audit.rules\":\n\n# grep -i /usr/bin/newgrp /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/bin/newgrp -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"newgrp\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-a always,exit -F path=/usr/bin/newgrp -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000037-GPOS-00015",
            "satisfies": [
              "SRG-OS-000037-GPOS-00015",
              "SRG-OS-000042-GPOS-00020",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000462-GPOS-00206",
              "SRG-OS-000471-GPOS-00215"
            ],
            "gid": "V-72165",
            "rid": "SV-86789r3_rule",
            "stig_id": "RHEL-07-030710",
            "cci": [
              "CCI-000130",
              "CCI-000135",
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-3",
              "AU-3 (1)",
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78519r4_fix"
          },
          "code": "control \"V-72165\" do\n  title \"All uses of the newgrp command must be audited.\"\n  desc  \"\n    Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged access commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.\n  \"\n  tag \"gtitle\": \"SRG-OS-000037-GPOS-00015\"\n  tag \"satisfies\": [\"SRG-OS-000037-GPOS-00015\", \"SRG-OS-000042-GPOS-00020\",\n\"SRG-OS-000392-GPOS-00172\", \"SRG-OS-000462-GPOS-00206\",\n\"SRG-OS-000471-GPOS-00215\"]\n  tag \"gid\": \"V-72165\"\n  tag \"rid\": \"SV-86789r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030710\"\n  tag \"cci\": [\"CCI-000130\", \"CCI-000135\", \"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-3\", \"AU-3 (1)\", \"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"newgrp\\\" command occur.\n\nCheck for the following system call being audited by performing the following\ncommand to check the file system rules in \\\"/etc/audit/audit.rules\\\":\n\n# grep -i /usr/bin/newgrp /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/bin/newgrp -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"newgrp\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-a always,exit -F path=/usr/bin/newgrp -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78519r4_fix\"\n\n  audit_file = '/usr/bin/newgrp'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72165.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/newgrp\" permissions should not cmp == []",
              "run_time": 0.000494792,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/newgrp\" action should not include \"never\"",
              "run_time": 0.000121314,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72167",
          "title": "All uses of the chsh command must be audited.",
          "desc": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged access commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged access commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"chsh\" command occur.\n\nCheck for the following system call being audited by performing the following\ncommand to check the file system rules in \"/etc/audit/audit.rules\":\n\n# grep -i /usr/bin/chsh /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/bin/chsh -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"chsh\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-a always,exit -F path=/usr/bin/chsh -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000037-GPOS-00015",
            "satisfies": [
              "SRG-OS-000037-GPOS-00015",
              "SRG-OS-000042-GPOS-00020",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000462-GPOS-00206",
              "SRG-OS-000471-GPOS-00215"
            ],
            "gid": "V-72167",
            "rid": "SV-86791r3_rule",
            "stig_id": "RHEL-07-030720",
            "cci": [
              "CCI-000130",
              "CCI-000135",
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-3",
              "AU-3 (1)",
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78521r4_fix"
          },
          "code": "control \"V-72167\" do\n  title \"All uses of the chsh command must be audited.\"\n  desc  \"\n    Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged access commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.\n  \"\n  tag \"gtitle\": \"SRG-OS-000037-GPOS-00015\"\n  tag \"satisfies\": [\"SRG-OS-000037-GPOS-00015\", \"SRG-OS-000042-GPOS-00020\",\n\"SRG-OS-000392-GPOS-00172\", \"SRG-OS-000462-GPOS-00206\",\n\"SRG-OS-000471-GPOS-00215\"]\n  tag \"gid\": \"V-72167\"\n  tag \"rid\": \"SV-86791r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030720\"\n  tag \"cci\": [\"CCI-000130\", \"CCI-000135\", \"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-3\", \"AU-3 (1)\", \"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"chsh\\\" command occur.\n\nCheck for the following system call being audited by performing the following\ncommand to check the file system rules in \\\"/etc/audit/audit.rules\\\":\n\n# grep -i /usr/bin/chsh /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/bin/chsh -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"chsh\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-a always,exit -F path=/usr/bin/chsh -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78521r4_fix\"\n\n  audit_file = '/usr/bin/chsh'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72167.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/chsh\" permissions should not cmp == []",
              "run_time": 0.000186528,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/chsh\" action should not include \"never\"",
              "run_time": 0.000108902,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72169",
          "title": "All uses of the sudoedit command must be audited.",
          "desc": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged access commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged access commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"sudoedit\" command occur.\n\nCheck for the following system calls being audited by performing the following\ncommand to check the file system rules in \"/etc/audit/audit.rules\":\n\n# grep -i \"/usr/bin/sudoedit\" /etc/audit/audit.rules\n\n-a always,exit -F path=/bin/sudoedit -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"sudoedit\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-a always,exit -F path=/bin/sudoedit -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000037-GPOS-00015",
            "satisfies": [
              "SRG-OS-000037-GPOS-00015",
              "SRG-OS-000042-GPOS-00020",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000462-GPOS-00206",
              "SRG-OS-000471-GPOS-00215"
            ],
            "gid": "V-72169",
            "rid": "SV-86793r4_rule",
            "stig_id": "RHEL-07-030730",
            "cci": [
              "CCI-000130",
              "CCI-000135",
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-3",
              "AU-3 (1)",
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78523r4_fix"
          },
          "code": "control \"V-72169\" do\n  title \"All uses of the sudoedit command must be audited.\"\n  desc  \"\n    Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged access commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.\n  \"\n  tag \"gtitle\": \"SRG-OS-000037-GPOS-00015\"\n  tag \"satisfies\": [\"SRG-OS-000037-GPOS-00015\", \"SRG-OS-000042-GPOS-00020\",\n\"SRG-OS-000392-GPOS-00172\", \"SRG-OS-000462-GPOS-00206\",\n\"SRG-OS-000471-GPOS-00215\"]\n  tag \"gid\": \"V-72169\"\n  tag \"rid\": \"SV-86793r4_rule\"\n  tag \"stig_id\": \"RHEL-07-030730\"\n  tag \"cci\": [\"CCI-000130\", \"CCI-000135\", \"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-3\", \"AU-3 (1)\", \"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"sudoedit\\\" command occur.\n\nCheck for the following system calls being audited by performing the following\ncommand to check the file system rules in \\\"/etc/audit/audit.rules\\\":\n\n# grep -i \\\"/usr/bin/sudoedit\\\" /etc/audit/audit.rules\n\n-a always,exit -F path=/bin/sudoedit -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"sudoedit\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-a always,exit -F path=/bin/sudoedit -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-priv_change\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78523r4_fix\"\n\n  audit_file = '/bin/sudoedit'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72169.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/bin/sudoedit\" permissions should not cmp == []",
              "run_time": 0.000163853,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/bin/sudoedit\" action should not include \"never\"",
              "run_time": 0.000106283,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72171",
          "title": "All uses of the mount command must be audited.",
          "desc": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged mount commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged mount commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"mount\" command occur.\n\nCheck for the following system calls being audited by performing the following\nseries of commands to check the file system rules in\n\"/etc/audit/audit.rules\":\n\n# grep -iw \"mount\" /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\n-a always,exit -F arch=b32 -F path=/bin/mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\n-a always,exit -F arch=b32 -F path=/usr/bin/mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\n-a always,exit -F arch=b64 -S mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\n-a always,exit -F arch=b64 -F path=/bin/mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\n-a always,exit -F arch=b64 -F path=/usr/bin/mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\nIf all uses of the mount command are not being audited, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"mount\" command occur.\n\nAdd or update the following rules in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\n-a always,exit -F arch=b32 -F path=/bin/mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\n-a always,exit -F arch=b32 -F path=/usr/bin/mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\n-a always,exit -F arch=b64 -S mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\n-a always,exit -F arch=b64 -F path=/bin/mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\n-a always,exit -F arch=b64 -F path=/usr/bin/mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000042-GPOS-00020",
            "satisfies": [
              "SRG-OS-000042-GPOS-00020",
              "SRG-OS-000392-GPOS-00172"
            ],
            "gid": "V-72171",
            "rid": "SV-86795r5_rule",
            "stig_id": "RHEL-07-030740",
            "cci": [
              "CCI-000135",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-3 (1)",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78525r6_fix"
          },
          "code": "control \"V-72171\" do\n  title \"All uses of the mount command must be audited.\"\n  desc  \"\n    Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged mount commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000042-GPOS-00020\"\n  tag \"satisfies\": [\"SRG-OS-000042-GPOS-00020\", \"SRG-OS-000392-GPOS-00172\"]\n  tag \"gid\": \"V-72171\"\n  tag \"rid\": \"SV-86795r5_rule\"\n  tag \"stig_id\": \"RHEL-07-030740\"\n  tag \"cci\": [\"CCI-000135\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-3 (1)\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"mount\\\" command occur.\n\nCheck for the following system calls being audited by performing the following\nseries of commands to check the file system rules in\n\\\"/etc/audit/audit.rules\\\":\n\n# grep -iw \\\"mount\\\" /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\n-a always,exit -F arch=b32 -F path=/bin/mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\n-a always,exit -F arch=b32 -F path=/usr/bin/mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\n-a always,exit -F arch=b64 -S mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\n-a always,exit -F arch=b64 -F path=/bin/mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\n-a always,exit -F arch=b64 -F path=/usr/bin/mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\nIf all uses of the mount command are not being audited, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"mount\\\" command occur.\n\nAdd or update the following rules in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\n-a always,exit -F arch=b32 -F path=/bin/mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\n-a always,exit -F arch=b32 -F path=/usr/bin/mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\n-a always,exit -F arch=b64 -S mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\n-a always,exit -F arch=b64 -F path=/bin/mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\n-a always,exit -F arch=b64 -F path=/usr/bin/mount -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78525r6_fix\"\n\n  describe auditd.syscall(\"mount\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  describe auditd.path(\"/bin/mount\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  describe auditd.path(\"/usr/bin/mount\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"mount\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n    describe auditd.path(\"/bin/mount\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n    describe auditd.path(\"/usr/bin/mount\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72171.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"mount\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000149083,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"mount\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000126192,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with path == \"/bin/mount\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000127435,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with path == \"/bin/mount\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000122448,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with path == \"/usr/bin/mount\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000129105,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with path == \"/usr/bin/mount\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000122726,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"mount\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000123586,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"mount\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000120574,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with path == \"/bin/mount\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000123639,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with path == \"/bin/mount\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000118525,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with path == \"/usr/bin/mount\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000118,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with path == \"/usr/bin/mount\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000119705,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72173",
          "title": "All uses of the umount command must be audited.",
          "desc": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged mount commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged mount commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"umount\" command occur.\n\nCheck for the following system calls being audited by performing the following\nseries of commands to check the file system rules in\n\"/etc/audit/audit.rules\":\n\n# grep -i \"/bin/umount\" /etc/audit/audit.rules\n\n-a always,exit -F path=/bin/umount -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"umount\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-a always,exit -F path=/bin/umount -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000042-GPOS-00020",
            "satisfies": [
              "SRG-OS-000042-GPOS-00020",
              "SRG-OS-000392-GPOS-00172"
            ],
            "gid": "V-72173",
            "rid": "SV-86797r4_rule",
            "stig_id": "RHEL-07-030750",
            "cci": [
              "CCI-000135",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-3 (1)",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78527r4_fix"
          },
          "code": "control \"V-72173\" do\n  title \"All uses of the umount command must be audited.\"\n  desc  \"\n    Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged mount commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.\n  \"\n  tag \"gtitle\": \"SRG-OS-000042-GPOS-00020\"\n  tag \"satisfies\": [\"SRG-OS-000042-GPOS-00020\", \"SRG-OS-000392-GPOS-00172\"]\n  tag \"gid\": \"V-72173\"\n  tag \"rid\": \"SV-86797r4_rule\"\n  tag \"stig_id\": \"RHEL-07-030750\"\n  tag \"cci\": [\"CCI-000135\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-3 (1)\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"umount\\\" command occur.\n\nCheck for the following system calls being audited by performing the following\nseries of commands to check the file system rules in\n\\\"/etc/audit/audit.rules\\\":\n\n# grep -i \\\"/bin/umount\\\" /etc/audit/audit.rules\n\n-a always,exit -F path=/bin/umount -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"umount\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-a always,exit -F path=/bin/umount -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-mount\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78527r4_fix\"\n\n  audit_file = '/bin/umount'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72173.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/bin/umount\" permissions should not cmp == []",
              "run_time": 0.000162932,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/bin/umount\" action should not include \"never\"",
              "run_time": 9.887e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72175",
          "title": "All uses of the postdrop command must be audited.",
          "desc": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged postfix commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged postfix commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"postdrop\" command occur.\n\nCheck for the following system call being audited by performing the following\ncommand to check the file system rules in \"/etc/audit/audit.rules\":\n\n# grep -i /usr/sbin/postdrop /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/sbin/postdrop -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-postfix\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"postdrop\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-a always,exit -F path=/usr/sbin/postdrop -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-postfix\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000042-GPOS-00020",
            "satisfies": [
              "SRG-OS-000042-GPOS-00020",
              "SRG-OS-000392-GPOS-00172"
            ],
            "gid": "V-72175",
            "rid": "SV-86799r3_rule",
            "stig_id": "RHEL-07-030760",
            "cci": [
              "CCI-000135",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-3 (1)",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78529r4_fix"
          },
          "code": "control \"V-72175\" do\n  title \"All uses of the postdrop command must be audited.\"\n  desc  \"\n    Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged postfix commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.\n  \"\n  tag \"gtitle\": \"SRG-OS-000042-GPOS-00020\"\n  tag \"satisfies\": [\"SRG-OS-000042-GPOS-00020\", \"SRG-OS-000392-GPOS-00172\"]\n  tag \"gid\": \"V-72175\"\n  tag \"rid\": \"SV-86799r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030760\"\n  tag \"cci\": [\"CCI-000135\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-3 (1)\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"postdrop\\\" command occur.\n\nCheck for the following system call being audited by performing the following\ncommand to check the file system rules in \\\"/etc/audit/audit.rules\\\":\n\n# grep -i /usr/sbin/postdrop /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/sbin/postdrop -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-postfix\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"postdrop\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-a always,exit -F path=/usr/sbin/postdrop -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-postfix\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78529r4_fix\"\n\n  audit_file = '/usr/sbin/postdrop'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72175.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/postdrop\" permissions should not cmp == []",
              "run_time": 0.000334773,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/postdrop\" action should not include \"never\"",
              "run_time": 0.000187808,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72177",
          "title": "All uses of the postqueue command must be audited.",
          "desc": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged postfix commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged postfix commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"postqueue\" command occur.\n\nCheck for the following system call being audited by performing the following\ncommand to check the file system rules in \"/etc/audit/audit.rules\":\n\n# grep -i /usr/sbin/postqueue /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/sbin/postqueue -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-postfix\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"postqueue\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-a always,exit -F path=/usr/sbin/postqueue -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-postfix\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000042-GPOS-00020",
            "satisfies": [
              "SRG-OS-000042-GPOS-00020",
              "SRG-OS-000392-GPOS-00172"
            ],
            "gid": "V-72177",
            "rid": "SV-86801r2_rule",
            "stig_id": "RHEL-07-030770",
            "cci": [
              "CCI-000135",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-3 (1)",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78531r4_fix"
          },
          "code": "control \"V-72177\" do\n  title \"All uses of the postqueue command must be audited.\"\n  desc  \"\n    Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged postfix commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.\n  \"\n  tag \"gtitle\": \"SRG-OS-000042-GPOS-00020\"\n  tag \"satisfies\": [\"SRG-OS-000042-GPOS-00020\", \"SRG-OS-000392-GPOS-00172\"]\n  tag \"gid\": \"V-72177\"\n  tag \"rid\": \"SV-86801r2_rule\"\n  tag \"stig_id\": \"RHEL-07-030770\"\n  tag \"cci\": [\"CCI-000135\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-3 (1)\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"postqueue\\\" command occur.\n\nCheck for the following system call being audited by performing the following\ncommand to check the file system rules in \\\"/etc/audit/audit.rules\\\":\n\n# grep -i /usr/sbin/postqueue /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/sbin/postqueue -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-postfix\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"postqueue\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-a always,exit -F path=/usr/sbin/postqueue -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-postfix\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78531r4_fix\"\n\n  audit_file = '/usr/sbin/postqueue'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72177.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/postqueue\" permissions should not cmp == []",
              "run_time": 0.00018294,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/sbin/postqueue\" action should not include \"never\"",
              "run_time": 0.000113145,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72179",
          "title": "All uses of the ssh-keysign command must be audited.",
          "desc": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged ssh commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged ssh commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"ssh-keysign\" command occur.\n\nCheck for the following system call being audited by performing the following\ncommand to check the file system rules in \"/etc/audit/audit.rules\":\n\n# grep -i /usr/libexec/openssh/ssh-keysign /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/libexec/openssh/ssh-keysign -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-ssh\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"ssh-keysign\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-a always,exit -F path=/usr/libexec/openssh/ssh-keysign -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-ssh\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000042-GPOS-00020",
            "satisfies": [
              "SRG-OS-000042-GPOS-00020",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000471-GPOS-00215"
            ],
            "gid": "V-72179",
            "rid": "SV-86803r2_rule",
            "stig_id": "RHEL-07-030780",
            "cci": [
              "CCI-000135",
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-3 (1)",
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78533r3_fix"
          },
          "code": "control \"V-72179\" do\n  title \"All uses of the ssh-keysign command must be audited.\"\n  desc  \"\n    Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged ssh commands. The organization must maintain audit trails in\nsufficient detail to reconstruct events to determine the cause and impact of\ncompromise.\n  \"\n  tag \"gtitle\": \"SRG-OS-000042-GPOS-00020\"\n  tag \"satisfies\": [\"SRG-OS-000042-GPOS-00020\", \"SRG-OS-000392-GPOS-00172\",\n\"SRG-OS-000471-GPOS-00215\"]\n  tag \"gid\": \"V-72179\"\n  tag \"rid\": \"SV-86803r2_rule\"\n  tag \"stig_id\": \"RHEL-07-030780\"\n  tag \"cci\": [\"CCI-000135\", \"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-3 (1)\", \"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"ssh-keysign\\\" command occur.\n\nCheck for the following system call being audited by performing the following\ncommand to check the file system rules in \\\"/etc/audit/audit.rules\\\":\n\n# grep -i /usr/libexec/openssh/ssh-keysign /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/libexec/openssh/ssh-keysign -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-ssh\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"ssh-keysign\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-a always,exit -F path=/usr/libexec/openssh/ssh-keysign -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-ssh\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78533r3_fix\"\n\n  audit_file = '/usr/libexec/openssh/ssh-keysign'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72179.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/openssh/ssh-keysign\" permissions should not cmp == []",
              "run_time": 0.0001866,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/libexec/openssh/ssh-keysign\" action should not include \"never\"",
              "run_time": 0.000145863,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72181",
          "title": "All uses of the pt_chown command must be audited.",
          "desc": "Reconstruction of harmful events or forensic analysis is not possible if audit\nrecords do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of privileged\ncommands. The organization must maintain audit trails in sufficient detail to\nreconstruct events to determine the cause and impact of compromise.\n\n    Satisfies: SRG-OS-000042-GPOS-00020, SRG-OS-000392-GPOS-00172,\nSRG-OS-000471-GPOS-0021.",
          "descriptions": [
            {
              "label": "default",
              "data": "Reconstruction of harmful events or forensic analysis is not possible if audit\nrecords do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of privileged\ncommands. The organization must maintain audit trails in sufficient detail to\nreconstruct events to determine the cause and impact of compromise.\n\n    Satisfies: SRG-OS-000042-GPOS-00020, SRG-OS-000392-GPOS-00172,\nSRG-OS-000471-GPOS-0021."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"pt_chown\" command occur.\n\nCheck for the following system call being audited by performing the following\ncommand to check the file system rules in \"/etc/audit/audit.rules\":\n\n# grep -i /usr/libexec/pt_chown /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/libexec/pt_chown -F perm=x -F auid>=1000 -F\nauid!=4294967295 -k privileged_terminal\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"pt_chown\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-a always,exit -F path=/usr/libexec/pt_chown -F perm=x -F auid>=1000 -F\nauid!=4294967295 -k privileged_terminal\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0,
          "refs": [],
          "tags": {
            "severity": "medium",
            "gtitle": "SRG-OS-000042-GPOS-00020",
            "gid": "V-72181",
            "rid": "SV-86805r2_rule",
            "stig_id": "RHEL-07-030790",
            "cci": [
              "CCI-002884"
            ],
            "nist": [
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ]
          },
          "code": "control \"V-72181\" do\n  title \"All uses of the pt_chown command must be audited.\"\n  desc  \"\n    Reconstruction of harmful events or forensic analysis is not possible if audit\nrecords do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of privileged\ncommands. The organization must maintain audit trails in sufficient detail to\nreconstruct events to determine the cause and impact of compromise.\n\n    Satisfies: SRG-OS-000042-GPOS-00020, SRG-OS-000392-GPOS-00172,\nSRG-OS-000471-GPOS-0021.\n  \"\n  tag \"severity\": \"medium\"\n  tag \"gtitle\": \"SRG-OS-000042-GPOS-00020\"\n  tag \"gid\": \"V-72181\"\n  tag \"rid\": \"SV-86805r2_rule\"\n  tag \"stig_id\": \"RHEL-07-030790\"\n  tag \"cci\": \"CCI-000135\"\n  tag \"nist\": [\"AU-3 (1)\", \"Rev_4\"]\n  tag \"cci\": \"CCI-000172\"\n  tag \"nist\": [\"AU-12 c\", \"Rev_4\"]\n  tag \"cci\": \"CCI-002884\"\n  tag \"nist\": [\"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"pt_chown\\\" command occur.\n\nCheck for the following system call being audited by performing the following\ncommand to check the file system rules in \\\"/etc/audit/audit.rules\\\":\n\n# grep -i /usr/libexec/pt_chown /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/libexec/pt_chown -F perm=x -F auid>=1000 -F\nauid!=4294967295 -k privileged_terminal\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"pt_chown\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-a always,exit -F path=/usr/libexec/pt_chown -F perm=x -F auid>=1000 -F\nauid!=4294967295 -k privileged_terminal\n\nThe audit daemon must be restarted for the changes to take effect.\"\n\n  audit_file = '/usr/libexec/pt_chown'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72181.rb"
          },
          "results": [
            {
              "status": "skipped",
              "code_desc": "The /usr/libexec/pt_chown file does not exist",
              "run_time": 6.094e-06,
              "start_time": "2019-11-04T16:17:15-05:00",
              "resource": "",
              "skip_message": "The /usr/libexec/pt_chown file does not exist, this requirement is Not Applicable."
            }
          ]
        },
        {
          "id": "V-72183",
          "title": "All uses of the crontab command must be audited.",
          "desc": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged commands. The organization must maintain audit trails in sufficient\ndetail to reconstruct events to determine the cause and impact of compromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged commands. The organization must maintain audit trails in sufficient\ndetail to reconstruct events to determine the cause and impact of compromise."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"crontab\" command occur.\n\nCheck for the following system call being audited by performing the following\ncommand to check the file system rules in \"/etc/audit/audit.rules\":\n\n# grep -i /usr/bin/crontab /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/bin/crontab -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-cron\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"crontab\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-a always,exit -F path=/usr/bin/crontab -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-cron\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000042-GPOS-00020",
            "satisfies": [
              "SRG-OS-000042-GPOS-00020",
              "SRG-OS-000392-GPOS-00172",
              "SRG-OS-000471-GPOS-00215"
            ],
            "gid": "V-72183",
            "rid": "SV-86807r2_rule",
            "stig_id": "RHEL-07-030800",
            "cci": [
              "CCI-000135",
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-3 (1)",
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78537r3_fix"
          },
          "code": "control \"V-72183\" do\n  title \"All uses of the crontab command must be audited.\"\n  desc  \"\n    Reconstruction of harmful events or forensic analysis is not possible if\naudit records do not contain enough information.\n\n    At a minimum, the organization must audit the full-text recording of\nprivileged commands. The organization must maintain audit trails in sufficient\ndetail to reconstruct events to determine the cause and impact of compromise.\n  \"\n  tag \"gtitle\": \"SRG-OS-000042-GPOS-00020\"\n  tag \"satisfies\": [\"SRG-OS-000042-GPOS-00020\", \"SRG-OS-000392-GPOS-00172\",\n\"SRG-OS-000471-GPOS-00215\"]\n  tag \"gid\": \"V-72183\"\n  tag \"rid\": \"SV-86807r2_rule\"\n  tag \"stig_id\": \"RHEL-07-030800\"\n  tag \"cci\": [\"CCI-000135\", \"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-3 (1)\", \"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"crontab\\\" command occur.\n\nCheck for the following system call being audited by performing the following\ncommand to check the file system rules in \\\"/etc/audit/audit.rules\\\":\n\n# grep -i /usr/bin/crontab /etc/audit/audit.rules\n\n-a always,exit -F path=/usr/bin/crontab -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-cron\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"crontab\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-a always,exit -F path=/usr/bin/crontab -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-cron\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78537r3_fix\"\n\n  audit_file = '/usr/bin/crontab'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72183.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/crontab\" permissions should not cmp == []",
              "run_time": 0.00021732,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/usr/bin/crontab\" action should not include \"never\"",
              "run_time": 0.000121445,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72185",
          "title": "All uses of the pam_timestamp_check command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"pam_timestamp_check\" command\noccur.\n\nCheck the auditing rules in \"/etc/audit/audit.rules\" with the following\ncommand:\n\n# grep -i \"/sbin/pam_timestamp_check\" /etc/audit/audit.rules\n\n-a always,exit -F path=/sbin/pam_timestamp_check -F perm=x -F auid>=1000 -F auid!=4294967295  -k privileged-pam\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"pam_timestamp_check\" command\noccur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-a always,exit -F path=/sbin/pam_timestamp_check -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-pam\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000471-GPOS-00215",
            "gid": "V-72185",
            "rid": "SV-86809r3_rule",
            "stig_id": "RHEL-07-030810",
            "cci": [
              "CCI-000172"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78539r3_fix"
          },
          "code": "control \"V-72185\" do\n  title \"All uses of the pam_timestamp_check command must be audited.\"\n  desc  \"Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\"\n  tag \"gtitle\": \"SRG-OS-000471-GPOS-00215\"\n  tag \"gid\": \"V-72185\"\n  tag \"rid\": \"SV-86809r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030810\"\n  tag \"cci\": [\"CCI-000172\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"pam_timestamp_check\\\" command\noccur.\n\nCheck the auditing rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\n# grep -i \\\"/sbin/pam_timestamp_check\\\" /etc/audit/audit.rules\n\n-a always,exit -F path=/sbin/pam_timestamp_check -F perm=x -F auid>=1000 -F auid!=4294967295  -k privileged-pam\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"pam_timestamp_check\\\" command\noccur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-a always,exit -F path=/sbin/pam_timestamp_check -F perm=x -F auid>=1000 -F auid!=4294967295 -k privileged-pam\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78539r3_fix\"\n\n  audit_file = '/sbin/pam_timestamp_check'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72185.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/sbin/pam_timestamp_check\" permissions should not cmp == []",
              "run_time": 0.000222147,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/sbin/pam_timestamp_check\" action should not include \"never\"",
              "run_time": 0.000107188,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72187",
          "title": "All uses of the init_module command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"init_module\" command occur.\n\nCheck the auditing rules in \"/etc/audit/audit.rules\" with the following\ncommand:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the line appropriate for the system architecture\nmust be present.\n\n# grep -iw init_module /etc/audit/audit.rules\n\nIf the command does not return the following output (appropriate to the\narchitecture), this is a finding.\n\n-a always,exit -F arch=b32 -S init_module -k module-change\n\n-a always,exit -F arch=b64 -S init_module -k module-change\n\nIf there are no audit rules defined for \"init_module\", this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"init_module\" command occur.\n\nAdd or update the following rules in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S init_module -k module-change\n\n-a always,exit -F arch=b64 -S init_module -k module-change\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000471-GPOS-00216",
            "satisfies": [
              "SRG-OS-000471-GPOS-00216",
              "SRG-OS-000477-GPOS-00222"
            ],
            "gid": "V-72187",
            "rid": "SV-86811r3_rule",
            "stig_id": "RHEL-07-030820",
            "cci": [
              "CCI-000172"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78541r5_fix"
          },
          "code": "control \"V-72187\" do\n  title \"All uses of the init_module command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000471-GPOS-00216\"\n  tag \"satisfies\": [\"SRG-OS-000471-GPOS-00216\", \"SRG-OS-000477-GPOS-00222\"]\n  tag \"gid\": \"V-72187\"\n  tag \"rid\": \"SV-86811r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030820\"\n  tag \"cci\": [\"CCI-000172\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"init_module\\\" command occur.\n\nCheck the auditing rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the line appropriate for the system architecture\nmust be present.\n\n# grep -iw init_module /etc/audit/audit.rules\n\nIf the command does not return the following output (appropriate to the\narchitecture), this is a finding.\n\n-a always,exit -F arch=b32 -S init_module -k module-change\n\n-a always,exit -F arch=b64 -S init_module -k module-change\n\nIf there are no audit rules defined for \\\"init_module\\\", this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"init_module\\\" command occur.\n\nAdd or update the following rules in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S init_module -k module-change\n\n-a always,exit -F arch=b64 -S init_module -k module-change\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78541r5_fix\"\n\n  describe auditd.syscall(\"init_module\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"init_module\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72187.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"init_module\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000153957,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"init_module\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000128302,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"init_module\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.00012322,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"init_module\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000119005,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72189",
          "title": "All uses of the delete_module command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"delete_module\" command occur.\n\nCheck the auditing rules in \"/etc/audit/audit.rules\" with the following\ncommand:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the line appropriate for the system architecture\nmust be present.\n\n# grep -iw delete_module /etc/audit/audit.rules\n\nIf the command does not return the following output (appropriate to the\narchitecture), this is a finding.\n\n-a always,exit -F arch=b32 -S delete_module -k module-change\n\n-a always,exit -F arch=b64 -S delete_module -k module-change\n\nIf there are no audit rules defined for \"delete_module\", this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"delete_module\" command occur.\n\nAdd or update the following rules in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S delete_module -k module-change\n\n-a always,exit -F arch=b64 -S delete_module -k module-change\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000471-GPOS-00216",
            "satisfies": [
              "SRG-OS-000471-GPOS-00216",
              "SRG-OS-000477-GPOS-00222"
            ],
            "gid": "V-72189",
            "rid": "SV-86813r3_rule",
            "stig_id": "RHEL-07-030830",
            "cci": [
              "CCI-000172"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78543r5_fix"
          },
          "code": "control \"V-72189\" do\n  title \"All uses of the delete_module command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000471-GPOS-00216\"\n  tag \"satisfies\": [\"SRG-OS-000471-GPOS-00216\", \"SRG-OS-000477-GPOS-00222\"]\n  tag \"gid\": \"V-72189\"\n  tag \"rid\": \"SV-86813r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030830\"\n  tag \"cci\": [\"CCI-000172\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"delete_module\\\" command occur.\n\nCheck the auditing rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the line appropriate for the system architecture\nmust be present.\n\n# grep -iw delete_module /etc/audit/audit.rules\n\nIf the command does not return the following output (appropriate to the\narchitecture), this is a finding.\n\n-a always,exit -F arch=b32 -S delete_module -k module-change\n\n-a always,exit -F arch=b64 -S delete_module -k module-change\n\nIf there are no audit rules defined for \\\"delete_module\\\", this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"delete_module\\\" command occur.\n\nAdd or update the following rules in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S delete_module -k module-change\n\n-a always,exit -F arch=b64 -S delete_module -k module-change\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78543r5_fix\"\n\n  describe auditd.syscall(\"delete_module\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"delete_module\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72189.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"delete_module\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.00012188,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"delete_module\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000115731,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"delete_module\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000118833,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"delete_module\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000119242,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72191",
          "title": "All uses of the insmod command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"insmod\" command occur.\n\nCheck the auditing rules in \"/etc/audit/audit.rules\" with the following\ncommand:\n\n# grep -i insmod /etc/audit/audit.rules\n\nIf the command does not return the following output this is a finding.\n\n-w /sbin/insmod -p x -F auid!=4294967295 -k module-change\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"insmod\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-w /sbin/insmod -p x -F auid!=4294967295 -k module-change\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000471-GPOS-00216",
            "satisfies": [
              "SRG-OS-000471-GPOS-00216",
              "SRG-OS-000477-GPOS-00222"
            ],
            "gid": "V-72191",
            "rid": "SV-86815r3_rule",
            "stig_id": "RHEL-07-030840",
            "cci": [
              "CCI-000172"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78545r7_fix"
          },
          "code": "control \"V-72191\" do\n  title \"All uses of the insmod command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  tag \"gtitle\": \"SRG-OS-000471-GPOS-00216\"\n  tag \"satisfies\": [\"SRG-OS-000471-GPOS-00216\", \"SRG-OS-000477-GPOS-00222\"]\n  tag \"gid\": \"V-72191\"\n  tag \"rid\": \"SV-86815r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030840\"\n  tag \"cci\": [\"CCI-000172\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"insmod\\\" command occur.\n\nCheck the auditing rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\n# grep -i insmod /etc/audit/audit.rules\n\nIf the command does not return the following output this is a finding.\n\n-w /sbin/insmod -p x -F auid!=4294967295 -k module-change\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"insmod\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-w /sbin/insmod -p x -F auid!=4294967295 -k module-change\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78545r7_fix\"\n\n  audit_file = '/sbin/insmod'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72191.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/sbin/insmod\" permissions should not cmp == []",
              "run_time": 0.00017706,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/sbin/insmod\" action should not include \"never\"",
              "run_time": 0.00010726,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72193",
          "title": "All uses of the rmmod command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"rmmod\" command occur.\n\nCheck the auditing rules in \"/etc/audit/audit.rules\" with the following\ncommand:\n\n# grep -i rmmod /etc/audit/audit.rules\n\nIf the command does not return the following output, this is a finding.\n\n-w /sbin/rmmod -p x -F auid!=4294967295 -k module-change\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"rmmod\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-w /sbin/rmmod-p x -F auid!=4294967295 -k module-change\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000471-GPOS-00216",
            "satisfies": [
              "SRG-OS-000471-GPOS-00216",
              "SRG-OS-000477-GPOS-00222"
            ],
            "gid": "V-72193",
            "rid": "SV-86817r3_rule",
            "stig_id": "RHEL-07-030850",
            "cci": [
              "CCI-000172"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78547r5_fix"
          },
          "code": "control \"V-72193\" do\n  title \"All uses of the rmmod command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  tag \"gtitle\": \"SRG-OS-000471-GPOS-00216\"\n  tag \"satisfies\": [\"SRG-OS-000471-GPOS-00216\", \"SRG-OS-000477-GPOS-00222\"]\n  tag \"gid\": \"V-72193\"\n  tag \"rid\": \"SV-86817r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030850\"\n  tag \"cci\": [\"CCI-000172\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"rmmod\\\" command occur.\n\nCheck the auditing rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\n# grep -i rmmod /etc/audit/audit.rules\n\nIf the command does not return the following output, this is a finding.\n\n-w /sbin/rmmod -p x -F auid!=4294967295 -k module-change\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"rmmod\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-w /sbin/rmmod-p x -F auid!=4294967295 -k module-change\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78547r5_fix\"\n\n  audit_file = '/sbin/rmmod'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72193.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/sbin/rmmod\" permissions should not cmp == []",
              "run_time": 0.000692528,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/sbin/rmmod\" action should not include \"never\"",
              "run_time": 0.000187537,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72195",
          "title": "All uses of the modprobe command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"modprobe\" command occur.\n\nCheck the auditing rules in \"/etc/audit/audit.rules\" with the following\ncommand:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the line appropriate for the system architecture\nmust be present.\n\n# grep -i modprobe /etc/audit/audit.rules\n\nIf the command does not return the following output, this is a finding.\n\n-w /sbin/modprobe -p x -F auid!=4294967295 -k module-change\n\nIf the command does not return any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"modprobe\" command occur.\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-w /sbin/modprobe -p x -F auid!=4294967295 -k module-change\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000471-GPOS-00216",
            "satisfies": [
              "SRG-OS-000471-GPOS-00216",
              "SRG-OS-000477-GPOS-00222"
            ],
            "gid": "V-72195",
            "rid": "SV-86819r3_rule",
            "stig_id": "RHEL-07-030860",
            "cci": [
              "CCI-000172"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78549r5_fix"
          },
          "code": "control \"V-72195\" do\n  title \"All uses of the modprobe command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  tag \"gtitle\": \"SRG-OS-000471-GPOS-00216\"\n  tag \"satisfies\": [\"SRG-OS-000471-GPOS-00216\", \"SRG-OS-000477-GPOS-00222\"]\n  tag \"gid\": \"V-72195\"\n  tag \"rid\": \"SV-86819r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030860\"\n  tag \"cci\": [\"CCI-000172\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"modprobe\\\" command occur.\n\nCheck the auditing rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the line appropriate for the system architecture\nmust be present.\n\n# grep -i modprobe /etc/audit/audit.rules\n\nIf the command does not return the following output, this is a finding.\n\n-w /sbin/modprobe -p x -F auid!=4294967295 -k module-change\n\nIf the command does not return any output, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"modprobe\\\" command occur.\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-w /sbin/modprobe -p x -F auid!=4294967295 -k module-change\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78549r5_fix\"\n\n  audit_file = '/sbin/modprobe'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'x' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72195.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/sbin/modprobe\" permissions should not cmp == []",
              "run_time": 0.000335654,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/sbin/modprobe\" action should not include \"never\"",
              "run_time": 0.000100772,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72197",
          "title": "The operating system must generate audit records for all account\ncreations, modifications, disabling, and termination events that affect\n/etc/passwd.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system must generate audit records for all\naccount creations, modifications, disabling, and termination events that affect\n\"/etc/passwd\".\n\nCheck the auditing rules in \"/etc/audit/audit.rules\" with the following\ncommand:\n\n# grep /etc/passwd /etc/audit/audit.rules\n\n-w /etc/passwd -p wa -k identity\n\nIf the command does not return a line, or the line is commented out, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records for all\naccount creations, modifications, disabling, and termination events that affect\n\"/etc/passwd\".\n\nAdd or update the following rule \"/etc/audit/rules.d/audit.rules\":\n\n-w /etc/passwd -p wa -k identity\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000004-GPOS-00004",
            "satisfies": [
              "SRG-OS-000004-GPOS-00004",
              "SRG-OS-000239-GPOS-00089",
              "SRG-OS-000240-GPOS-00090",
              "SRG-OS-000241-GPOS-00091",
              "SRG-OS-000303-GPOS-00120",
              "SRG-OS-000476-GPOS-00221"
            ],
            "gid": "V-72197",
            "rid": "SV-86821r4_rule",
            "stig_id": "RHEL-07-030870",
            "cci": [
              "CCI-000018",
              "CCI-000172",
              "CCI-001403",
              "CCI-002130"
            ],
            "documentable": false,
            "nist": [
              "AC-2 (4)",
              "AU-12 c",
              "AC-2 (4)",
              "AC-2 (4)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78551r4_fix"
          },
          "code": "control \"V-72197\" do\n  title \"The operating system must generate audit records for all account\ncreations, modifications, disabling, and termination events that affect\n/etc/passwd.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  tag \"gtitle\": \"SRG-OS-000004-GPOS-00004\"\n  tag \"satisfies\": [\"SRG-OS-000004-GPOS-00004\", \"SRG-OS-000239-GPOS-00089\",\n\"SRG-OS-000240-GPOS-00090\", \"SRG-OS-000241-GPOS-00091\",\n\"SRG-OS-000303-GPOS-00120\", \"SRG-OS-000476-GPOS-00221\"]\n  tag \"gid\": \"V-72197\"\n  tag \"rid\": \"SV-86821r4_rule\"\n  tag \"stig_id\": \"RHEL-07-030870\"\n  tag \"cci\": [\"CCI-000018\", \"CCI-000172\", \"CCI-001403\", \"CCI-002130\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-2 (4)\", \"AU-12 c\", \"AC-2 (4)\", \"AC-2 (4)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system must generate audit records for all\naccount creations, modifications, disabling, and termination events that affect\n\\\"/etc/passwd\\\".\n\nCheck the auditing rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\n# grep /etc/passwd /etc/audit/audit.rules\n\n-w /etc/passwd -p wa -k identity\n\nIf the command does not return a line, or the line is commented out, this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records for all\naccount creations, modifications, disabling, and termination events that affect\n\\\"/etc/passwd\\\".\n\nAdd or update the following rule \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-w /etc/passwd -p wa -k identity\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78551r4_fix\"\n\n  audit_file = '/etc/passwd'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'w' }\n      it { should include 'a' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72197.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/etc/passwd\" permissions should not cmp == []",
              "run_time": 0.000307059,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/etc/passwd\" action should not include \"never\"",
              "run_time": 0.000108528,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72199",
          "title": "All uses of the rename command must be audited.",
          "desc": "If the system is not configured to audit certain activities and write\nthem to an audit log, it is more difficult to detect and track system\ncompromises and damages incurred during a system compromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "If the system is not configured to audit certain activities and write\nthem to an audit log, it is more difficult to detect and track system\ncompromises and damages incurred during a system compromise."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"rename\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw rename /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S rename -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\n-a always,exit -F arch=b64 -S rename -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\nIf there are no audit rules defined for the \"rename\" command, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"rename\" command occur.\n\nAdd the following rules in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S rename -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\n-a always,exit -F arch=b64 -S rename -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000466-GPOS-00210",
            "satisfies": [
              "SRG-OS-000466-GPOS-00210",
              "SRG-OS-000467-GPOS-00210",
              "SRG-OS-000468-GPOS-00212",
              "SRG-OS-000392-GPOS-00172"
            ],
            "gid": "V-72199",
            "rid": "SV-86823r3_rule",
            "stig_id": "RHEL-07-030880",
            "cci": [
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78553r5_fix"
          },
          "code": "control \"V-72199\" do\n  title \"All uses of the rename command must be audited.\"\n  desc  \"If the system is not configured to audit certain activities and write\nthem to an audit log, it is more difficult to detect and track system\ncompromises and damages incurred during a system compromise.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000466-GPOS-00210\"\n  tag \"satisfies\": [\"SRG-OS-000466-GPOS-00210\", \"SRG-OS-000467-GPOS-00210\",\n\"SRG-OS-000468-GPOS-00212\", \"SRG-OS-000392-GPOS-00172\"]\n  tag \"gid\": \"V-72199\"\n  tag \"rid\": \"SV-86823r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030880\"\n  tag \"cci\": [\"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"rename\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw rename /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S rename -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\n-a always,exit -F arch=b64 -S rename -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\nIf there are no audit rules defined for the \\\"rename\\\" command, this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"rename\\\" command occur.\n\nAdd the following rules in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S rename -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\n-a always,exit -F arch=b64 -S rename -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78553r5_fix\"\n\n  describe auditd.syscall(\"rename\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"rename\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72199.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"rename\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000236185,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"rename\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000133281,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"rename\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000183505,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"rename\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000123539,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72201",
          "title": "All uses of the renameat command must be audited.",
          "desc": "If the system is not configured to audit certain activities and write\nthem to an audit log, it is more difficult to detect and track system\ncompromises and damages incurred during a system compromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "If the system is not configured to audit certain activities and write\nthem to an audit log, it is more difficult to detect and track system\ncompromises and damages incurred during a system compromise."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"renameat\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw renameat /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S renameat -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\n-a always,exit -F arch=b64 -S renameat -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\nIf there are no audit rules defined for the \"renameat\" command, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"renameat\" command occur.\n\nAdd the following rules in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S renameat -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\n-a always,exit -F arch=b64 -S renameat -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000466-GPOS-00210",
            "satisfies": [
              "SRG-OS-000466-GPOS-00210",
              "SRG-OS-000467-GPOS-00210",
              "SRG-OS-000468-GPOS-00212",
              "SRG-OS-000392-GPOS-00172"
            ],
            "gid": "V-72201",
            "rid": "SV-86825r3_rule",
            "stig_id": "RHEL-07-030890",
            "cci": [
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78555r6_fix"
          },
          "code": "control \"V-72201\" do\n  title \"All uses of the renameat command must be audited.\"\n  desc  \"If the system is not configured to audit certain activities and write\nthem to an audit log, it is more difficult to detect and track system\ncompromises and damages incurred during a system compromise.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000466-GPOS-00210\"\n  tag \"satisfies\": [\"SRG-OS-000466-GPOS-00210\", \"SRG-OS-000467-GPOS-00210\",\n\"SRG-OS-000468-GPOS-00212\", \"SRG-OS-000392-GPOS-00172\"]\n  tag \"gid\": \"V-72201\"\n  tag \"rid\": \"SV-86825r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030890\"\n  tag \"cci\": [\"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"renameat\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw renameat /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S renameat -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\n-a always,exit -F arch=b64 -S renameat -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\nIf there are no audit rules defined for the \\\"renameat\\\" command, this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"renameat\\\" command occur.\n\nAdd the following rules in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S renameat -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\n-a always,exit -F arch=b64 -S renameat -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78555r6_fix\"\n\n  describe auditd.syscall(\"renameat\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"renameat\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72201.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"renameat\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000122693,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"renameat\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000117503,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"renameat\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000194741,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"renameat\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000335986,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72203",
          "title": "All uses of the rmdir command must be audited.",
          "desc": "If the system is not configured to audit certain activities and write\nthem to an audit log, it is more difficult to detect and track system\ncompromises and damages incurred during a system compromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "If the system is not configured to audit certain activities and write\nthem to an audit log, it is more difficult to detect and track system\ncompromises and damages incurred during a system compromise."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"rmdir\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw rmdir /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S rmdir -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\n-a always,exit -F arch=b64 -S rmdir -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\nIf there are no audit rules defined for the \"rmdir\" command, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"rmdir\" command occur.\n\nAdd the following rules in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S rmdir -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\n-a always,exit -F arch=b64 -S rmdir -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000466-GPOS-00210",
            "satisfies": [
              "SRG-OS-000466-GPOS-00210",
              "SRG-OS-000467-GPOS-00210",
              "SRG-OS-000468-GPOS-00212",
              "SRG-OS-000392-GPOS-00172"
            ],
            "gid": "V-72203",
            "rid": "SV-86827r3_rule",
            "stig_id": "RHEL-07-030900",
            "cci": [
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78557r6_fix"
          },
          "code": "control \"V-72203\" do\n  title \"All uses of the rmdir command must be audited.\"\n  desc  \"If the system is not configured to audit certain activities and write\nthem to an audit log, it is more difficult to detect and track system\ncompromises and damages incurred during a system compromise.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000466-GPOS-00210\"\n  tag \"satisfies\": [\"SRG-OS-000466-GPOS-00210\", \"SRG-OS-000467-GPOS-00210\",\n\"SRG-OS-000468-GPOS-00212\", \"SRG-OS-000392-GPOS-00172\"]\n  tag \"gid\": \"V-72203\"\n  tag \"rid\": \"SV-86827r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030900\"\n  tag \"cci\": [\"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"rmdir\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw rmdir /etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S rmdir -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\n-a always,exit -F arch=b64 -S rmdir -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\nIf there are no audit rules defined for the \\\"rmdir\\\" command, this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"rmdir\\\" command occur.\n\nAdd the following rules in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S rmdir -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\n-a always,exit -F arch=b64 -S rmdir -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78557r6_fix\"\n\n  describe auditd.syscall(\"rmdir\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"rmdir\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72203.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"rmdir\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000287479,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"rmdir\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000130879,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"rmdir\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000430003,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"rmdir\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000224957,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72205",
          "title": "All uses of the unlink command must be audited.",
          "desc": "If the system is not configured to audit certain activities and write\nthem to an audit log, it is more difficult to detect and track system\ncompromises and damages incurred during a system compromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "If the system is not configured to audit certain activities and write\nthem to an audit log, it is more difficult to detect and track system\ncompromises and damages incurred during a system compromise."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"unlink\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw unlink/etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S unlink -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\n-a always,exit -F arch=b64 -S unlink -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\nIf there are no audit rules defined for the \"unlink\" command, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"unlink\" command occur.\n\nAdd the following rules in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S unlink -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\n-a always,exit -F arch=b64 -S unlink -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000466-GPOS-00210",
            "satisfies": [
              "SRG-OS-000466-GPOS-00210",
              "SRG-OS-000467-GPOS-00210",
              "SRG-OS-000468-GPOS-00212",
              "SRG-OS-000392-GPOS-00172"
            ],
            "gid": "V-72205",
            "rid": "SV-86829r3_rule",
            "stig_id": "RHEL-07-030910",
            "cci": [
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78559r5_fix"
          },
          "code": "control \"V-72205\" do\n  title \"All uses of the unlink command must be audited.\"\n  desc  \"If the system is not configured to audit certain activities and write\nthem to an audit log, it is more difficult to detect and track system\ncompromises and damages incurred during a system compromise.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000466-GPOS-00210\"\n  tag \"satisfies\": [\"SRG-OS-000466-GPOS-00210\", \"SRG-OS-000467-GPOS-00210\",\n\"SRG-OS-000468-GPOS-00212\", \"SRG-OS-000392-GPOS-00172\"]\n  tag \"gid\": \"V-72205\"\n  tag \"rid\": \"SV-86829r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030910\"\n  tag \"cci\": [\"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"unlink\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw unlink/etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S unlink -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\n-a always,exit -F arch=b64 -S unlink -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\nIf there are no audit rules defined for the \\\"unlink\\\" command, this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"unlink\\\" command occur.\n\nAdd the following rules in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S unlink -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\n-a always,exit -F arch=b64 -S unlink -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78559r5_fix\"\n\n  describe auditd.syscall(\"unlink\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"unlink\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72205.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"unlink\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000148387,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"unlink\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000123711,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"unlink\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000415641,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"unlink\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000314904,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72207",
          "title": "All uses of the unlinkat command must be audited.",
          "desc": "If the system is not configured to audit certain activities and write\nthem to an audit log, it is more difficult to detect and track system\ncompromises and damages incurred during a system compromise.",
          "descriptions": [
            {
              "label": "default",
              "data": "If the system is not configured to audit certain activities and write\nthem to an audit log, it is more difficult to detect and track system\ncompromises and damages incurred during a system compromise."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"unlinkat\" command occur.\n\nCheck the file system rules in \"/etc/audit/audit.rules\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw unlinkat/etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S unlinkat -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\n-a always,exit -F arch=b64 -S unlinkat -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\nIf there are no audit rules defined for the \"unlinkat\" command, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"unlinkat\" command occur.\n\nAdd the following rules in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S unlinkat -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\n-a always,exit -F arch=b64 -S unlinkat -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000466-GPOS-00210",
            "satisfies": [
              "SRG-OS-000466-GPOS-00210",
              "SRG-OS-000467-GPOS-00210",
              "SRG-OS-000468-GPOS-00212",
              "SRG-OS-000392-GPOS-00172"
            ],
            "gid": "V-72207",
            "rid": "SV-86831r3_rule",
            "stig_id": "RHEL-07-030920",
            "cci": [
              "CCI-000172",
              "CCI-002884"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "MA-4 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-78561r5_fix"
          },
          "code": "control \"V-72207\" do\n  title \"All uses of the unlinkat command must be audited.\"\n  desc  \"If the system is not configured to audit certain activities and write\nthem to an audit log, it is more difficult to detect and track system\ncompromises and damages incurred during a system compromise.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000466-GPOS-00210\"\n  tag \"satisfies\": [\"SRG-OS-000466-GPOS-00210\", \"SRG-OS-000467-GPOS-00210\",\n\"SRG-OS-000468-GPOS-00212\", \"SRG-OS-000392-GPOS-00172\"]\n  tag \"gid\": \"V-72207\"\n  tag \"rid\": \"SV-86831r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030920\"\n  tag \"cci\": [\"CCI-000172\", \"CCI-002884\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"MA-4 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"unlinkat\\\" command occur.\n\nCheck the file system rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommands:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the lines appropriate for the system architecture\nmust be present.\n\n# grep -iw unlinkat/etc/audit/audit.rules\n\n-a always,exit -F arch=b32 -S unlinkat -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\n-a always,exit -F arch=b64 -S unlinkat -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\nIf there are no audit rules defined for the \\\"unlinkat\\\" command, this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"unlinkat\\\" command occur.\n\nAdd the following rules in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S unlinkat -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\n-a always,exit -F arch=b64 -S unlinkat -F perm=x -F auid>=1000 -F auid!=4294967295 -k delete\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-78561r5_fix\"\n\n  describe auditd.syscall(\"unlinkat\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"unlinkat\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72207.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"unlinkat\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000192197,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"unlinkat\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000182271,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"unlinkat\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000188501,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"unlinkat\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000397279,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72209",
          "title": "The system must send rsyslog output to a log aggregation server.",
          "desc": "Sending rsyslog output to another system ensures that the logs cannot\nbe removed or modified in the event that the system is compromised or has a\nhardware failure.",
          "descriptions": [
            {
              "label": "default",
              "data": "Sending rsyslog output to another system ensures that the logs cannot\nbe removed or modified in the event that the system is compromised or has a\nhardware failure."
            },
            {
              "label": "check",
              "data": "Verify \"rsyslog\" is configured to send all messages to a log\naggregation server.\n\nCheck the configuration of \"rsyslog\" with the following command:\n\nNote: If another logging package is used, substitute the utility configuration\nfile for \"/etc/rsyslog.conf\".\n\n# grep @ /etc/rsyslog.conf\n*.* @@logagg.site.mil\n\nIf there are no lines in the \"/etc/rsyslog.conf\" file that contain the \"@\"\nor \"@@\" symbol(s), and the lines with the correct symbol(s) to send output to\nanother system do not cover all \"rsyslog\" output, ask the System\nAdministrator to indicate how the audit logs are off-loaded to a different\nsystem or media.\n\nIf there is no evidence that the audit logs are being sent to another system,\nthis is a finding."
            },
            {
              "label": "fix",
              "data": "Modify the \"/etc/rsyslog.conf\" file to contain a configuration\nline to send all \"rsyslog\" output to a log aggregation system:\n\n*.* @@<log aggregation system name>"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72209",
            "rid": "SV-86833r1_rule",
            "stig_id": "RHEL-07-031000",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "rsyslog"
            ],
            "fix_id": "F-78563r1_fix"
          },
          "code": "control \"V-72209\" do\n  title \"The system must send rsyslog output to a log aggregation server.\"\n  desc  \"Sending rsyslog output to another system ensures that the logs cannot\nbe removed or modified in the event that the system is compromised or has a\nhardware failure.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72209\"\n  tag \"rid\": \"SV-86833r1_rule\"\n  tag \"stig_id\": \"RHEL-07-031000\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'rsyslog']\n  desc \"check\", \"Verify \\\"rsyslog\\\" is configured to send all messages to a log\naggregation server.\n\nCheck the configuration of \\\"rsyslog\\\" with the following command:\n\nNote: If another logging package is used, substitute the utility configuration\nfile for \\\"/etc/rsyslog.conf\\\".\n\n# grep @ /etc/rsyslog.conf\n*.* @@logagg.site.mil\n\nIf there are no lines in the \\\"/etc/rsyslog.conf\\\" file that contain the \\\"@\\\"\nor \\\"@@\\\" symbol(s), and the lines with the correct symbol(s) to send output to\nanother system do not cover all \\\"rsyslog\\\" output, ask the System\nAdministrator to indicate how the audit logs are off-loaded to a different\nsystem or media.\n\nIf there is no evidence that the audit logs are being sent to another system,\nthis is a finding.\"\n  desc \"fix\", \"Modify the \\\"/etc/rsyslog.conf\\\" file to contain a configuration\nline to send all \\\"rsyslog\\\" output to a log aggregation system:\n\n*.* @@<log aggregation system name>\"\n  tag \"fix_id\": \"F-78563r1_fix\"\n\n  describe command(\"grep @ #{log_pkg_path} | grep -v \\\"^#\\\"\") do\n    its('stdout.strip') { should_not be_empty }\n  end\nend\n",
          "source_location": {
            "line": 10,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72209.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Command: `grep @ /etc/rsyslog.conf | grep -v \"^#\"` stdout.strip should not be empty",
              "run_time": 0.019694433,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected `\"\".empty?` to return false, got true"
            }
          ]
        },
        {
          "id": "V-72211",
          "title": "The rsyslog daemon must not accept log messages from other servers\nunless the server is being used for log aggregation.",
          "desc": "Unintentionally running a rsyslog server accepting remote messages puts the\nsystem at increased risk. Malicious rsyslog messages sent to the server could\nexploit vulnerabilities in the server software itself, could introduce\nmisleading information in to the system's logs, or could fill the system's\nstorage leading to a Denial of Service.\n    If the system is intended to be a log aggregation server its use must be\ndocumented with the ISSO.",
          "descriptions": [
            {
              "label": "default",
              "data": "Unintentionally running a rsyslog server accepting remote messages puts the\nsystem at increased risk. Malicious rsyslog messages sent to the server could\nexploit vulnerabilities in the server software itself, could introduce\nmisleading information in to the system's logs, or could fill the system's\nstorage leading to a Denial of Service.\n    If the system is intended to be a log aggregation server its use must be\ndocumented with the ISSO."
            },
            {
              "label": "check",
              "data": "Verify that the system is not accepting \"rsyslog\" messages\nfrom other systems unless it is documented as a log aggregation server.\n\nCheck the configuration of \"rsyslog\" with the following command:\n\n# grep imtcp /etc/rsyslog.conf\nModLoad imtcp\n\nIf the \"imtcp\" module is being loaded in the \"/etc/rsyslog.conf\" file, ask\nto see the documentation for the system being used for log aggregation.\n\nIf the documentation does not exist, or does not specify the server as a log\naggregation system, this is a finding."
            },
            {
              "label": "fix",
              "data": "Modify the \"/etc/rsyslog.conf\" file to remove the \"ModLoad\nimtcp\" configuration line, or document the system as being used for log\naggregation."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72211",
            "rid": "SV-86835r1_rule",
            "stig_id": "RHEL-07-031010",
            "cci": [
              "CCI-000318",
              "CCI-000368",
              "CCI-001812",
              "CCI-001813",
              "CCI-001814"
            ],
            "documentable": false,
            "nist": [
              "CM-3 f",
              "CM-6 c",
              "CM-11 (2)",
              "CM-5 (1)",
              "CM-5 (1)",
              "Rev_4"
            ],
            "subsystems": [
              "rsyslog"
            ],
            "fix_id": "F-78565r1_fix"
          },
          "code": "control \"V-72211\" do\n  title \"The rsyslog daemon must not accept log messages from other servers\nunless the server is being used for log aggregation.\"\n  desc  \"\n    Unintentionally running a rsyslog server accepting remote messages puts the\nsystem at increased risk. Malicious rsyslog messages sent to the server could\nexploit vulnerabilities in the server software itself, could introduce\nmisleading information in to the system's logs, or could fill the system's\nstorage leading to a Denial of Service.\n    If the system is intended to be a log aggregation server its use must be\ndocumented with the ISSO.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72211\"\n  tag \"rid\": \"SV-86835r1_rule\"\n  tag \"stig_id\": \"RHEL-07-031010\"\n  tag \"cci\": [\"CCI-000318\", \"CCI-000368\", \"CCI-001812\", \"CCI-001813\",\n\"CCI-001814\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-3 f\", \"CM-6 c\", \"CM-11 (2)\", \"CM-5 (1)\", \"CM-5 (1)\", \"Rev_4\"]\n  tag \"subsystems\": ['rsyslog']\n  desc \"check\", \"Verify that the system is not accepting \\\"rsyslog\\\" messages\nfrom other systems unless it is documented as a log aggregation server.\n\nCheck the configuration of \\\"rsyslog\\\" with the following command:\n\n# grep imtcp /etc/rsyslog.conf\nModLoad imtcp\n\nIf the \\\"imtcp\\\" module is being loaded in the \\\"/etc/rsyslog.conf\\\" file, ask\nto see the documentation for the system being used for log aggregation.\n\nIf the documentation does not exist, or does not specify the server as a log\naggregation system, this is a finding.\"\n  desc \"fix\", \"Modify the \\\"/etc/rsyslog.conf\\\" file to remove the \\\"ModLoad\nimtcp\\\" configuration line, or document the system as being used for log\naggregation.\"\n  tag \"fix_id\": \"F-78565r1_fix\"\n\n  if log_aggregation_server\n    describe file('/etc/rsyslog.conf') do\n      its('content') { should match %r{^\\$ModLoad\\s+imtcp.*\\n?$} }\n    end\n  else\n    describe.one do\n      describe file('/etc/rsyslog.conf') do\n        its('content') { should match %r{\\$ModLoad\\s+imtcp.*\\n?$} }\n      end\n      describe file('/etc/rsyslog.conf') do\n        its('content') { should_not match %r{^\\$ModLoad\\s+imtcp.*\\n?$} }\n      end\n    end\n  end\nend\n",
          "source_location": {
            "line": 13,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72211.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "File /etc/rsyslog.conf content should match /\\$ModLoad\\s+imtcp.*\\n?$/",
              "run_time": 0.00022924,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /etc/rsyslog.conf content should not match /^\\$ModLoad\\s+imtcp.*\\n?$/",
              "run_time": 0.000122759,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72213",
          "title": "The system must use a virus scan program.",
          "desc": "Virus scanning software can be used to protect a system from penetration\nfrom computer viruses and to limit their spread through intermediate systems.\n\n    The virus scanning software should be configured to perform scans\ndynamically on accessed files. If this capability is not available, the system\nmust be configured to scan, at a minimum, all altered files on the system on a\ndaily basis.\n\n    If the system processes inbound SMTP mail, the virus scanner must be\nconfigured to scan all received mail.",
          "descriptions": [
            {
              "label": "default",
              "data": "Virus scanning software can be used to protect a system from penetration\nfrom computer viruses and to limit their spread through intermediate systems.\n\n    The virus scanning software should be configured to perform scans\ndynamically on accessed files. If this capability is not available, the system\nmust be configured to scan, at a minimum, all altered files on the system on a\ndaily basis.\n\n    If the system processes inbound SMTP mail, the virus scanner must be\nconfigured to scan all received mail."
            },
            {
              "label": "check",
              "data": "Verify the system is using a virus scan program.\n\nCheck for the presence of \"McAfee VirusScan Enterprise for Linux\" with the\nfollowing command:\n\n# systemctl status nails\nnails - service for McAfee VirusScan Enterprise for Linux\n>  Loaded: loaded\n/opt/NAI/package/McAfeeVSEForLinux/McAfeeVSEForLinux-2.0.2.<build_number>;\nenabled)\n>  Active: active (running) since Mon 2015-09-27 04:11:22 UTC;21 min ago\n\nIf the \"nails\" service is not active, check for the presence of \"clamav\" on\nthe system with the following command:\n\n# systemctl status clamav-daemon.socket\n systemctl status clamav-daemon.socket\n  clamav-daemon.socket - Socket for Clam AntiVirus userspace daemon\n     Loaded: loaded (/lib/systemd/system/clamav-daemon.socket; enabled)\n     Active: active (running) since Mon 2015-01-12 09:32:59 UTC; 7min ago\n\nIf neither of these applications are loaded and active, ask the System\nAdministrator if there is an antivirus package installed and active on the\nsystem.\n\nIf no antivirus scan program is active on the system, this is a finding."
            },
            {
              "label": "fix",
              "data": "Install an antivirus solution on the system."
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72213",
            "rid": "SV-86837r2_rule",
            "stig_id": "RHEL-07-032000",
            "cci": [
              "CCI-001668"
            ],
            "documentable": false,
            "nist": [
              "SI-3 a",
              "Rev_4"
            ],
            "subsystems": [
              "clamav",
              "nails",
              "virus_scan"
            ],
            "fix_id": "F-78567r2_fix"
          },
          "code": "control \"V-72213\" do\n  title \"The system must use a virus scan program.\"\n  desc  \"\n    Virus scanning software can be used to protect a system from penetration\nfrom computer viruses and to limit their spread through intermediate systems.\n\n    The virus scanning software should be configured to perform scans\ndynamically on accessed files. If this capability is not available, the system\nmust be configured to scan, at a minimum, all altered files on the system on a\ndaily basis.\n\n    If the system processes inbound SMTP mail, the virus scanner must be\nconfigured to scan all received mail.\n  \"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72213\"\n  tag \"rid\": \"SV-86837r2_rule\"\n  tag \"stig_id\": \"RHEL-07-032000\"\n  tag \"cci\": [\"CCI-001668\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"SI-3 a\", \"Rev_4\"]\n  tag \"subsystems\": ['clamav', 'nails', 'virus_scan']\n  desc \"check\", \"Verify the system is using a virus scan program.\n\nCheck for the presence of \\\"McAfee VirusScan Enterprise for Linux\\\" with the\nfollowing command:\n\n# systemctl status nails\nnails - service for McAfee VirusScan Enterprise for Linux\n>  Loaded: loaded\n/opt/NAI/package/McAfeeVSEForLinux/McAfeeVSEForLinux-2.0.2.<build_number>;\nenabled)\n>  Active: active (running) since Mon 2015-09-27 04:11:22 UTC;21 min ago\n\nIf the \\\"nails\\\" service is not active, check for the presence of \\\"clamav\\\" on\nthe system with the following command:\n\n# systemctl status clamav-daemon.socket\n systemctl status clamav-daemon.socket\n  clamav-daemon.socket - Socket for Clam AntiVirus userspace daemon\n     Loaded: loaded (/lib/systemd/system/clamav-daemon.socket; enabled)\n     Active: active (running) since Mon 2015-01-12 09:32:59 UTC; 7min ago\n\nIf neither of these applications are loaded and active, ask the System\nAdministrator if there is an antivirus package installed and active on the\nsystem.\n\nIf no antivirus scan program is active on the system, this is a finding.\"\n  desc \"fix\", \"Install an antivirus solution on the system.\"\n  tag \"fix_id\": \"F-78567r2_fix\"\n\n  describe.one do\n\t  describe service('nails') do\n\t    it { should be_running }\n    end\n    describe service('clamav-daemon.socket') do\n\t    it { should be_running }\n\t  end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72213.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Service nails should be running",
              "run_time": 0.000409014,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected that `Service nails` is running",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Service clamav-daemon.socket should be running",
              "run_time": 0.000215258,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected that `Service clamav-daemon.socket` is running",
              "exception": "RSpec::Core::MultipleExceptionError"
            }
          ]
        },
        {
          "id": "V-72215",
          "title": "The system must update the virus scan program every seven days or more\nfrequently.",
          "desc": "Virus scanning software can be used to protect a system from penetration\nfrom computer viruses and to limit their spread through intermediate systems.\n\n    The virus scanning software should be configured to check for software and\nvirus definition updates with a frequency no longer than seven days. If a\nmanual process is required to update the virus scan software or definitions, it\nmust be documented with the Information System Security Officer (ISSO).",
          "descriptions": [
            {
              "label": "default",
              "data": "Virus scanning software can be used to protect a system from penetration\nfrom computer viruses and to limit their spread through intermediate systems.\n\n    The virus scanning software should be configured to check for software and\nvirus definition updates with a frequency no longer than seven days. If a\nmanual process is required to update the virus scan software or definitions, it\nmust be documented with the Information System Security Officer (ISSO)."
            },
            {
              "label": "check",
              "data": "Verify the system is using a virus scan program and the virus\ndefinition file is less than seven days old.\n\nCheck for the presence of \"McAfee VirusScan Enterprise for Linux\" with the\nfollowing command:\n\n# systemctl status nails\nnails - service for McAfee VirusScan Enterprise for Linux\n>  Loaded: loaded\n/opt/NAI/package/McAfeeVSEForLinux/McAfeeVSEForLinux-2.0.2.<build_number>;\nenabled)\n>  Active: active (running) since Mon 2015-09-27 04:11:22 UTC;21 min ago\n\nIf the \"nails\" service is not active, check for the presence of \"clamav\" on\nthe system with the following command:\n\n# systemctl status clamav-daemon.socket\nsystemctl status clamav-daemon.socket\n  clamav-daemon.socket - Socket for Clam AntiVirus userspace daemon\n     Loaded: loaded (/lib/systemd/system/clamav-daemon.socket; enabled)\n     Active: active (running) since Mon 2015-01-12 09:32:59 UTC; 7min ago\n\nIf \"McAfee VirusScan Enterprise for Linux\" is active on the system, check the\ndates of the virus definition files with the following command:\n\n# ls -al /opt/NAI/LinuxShield/engine/dat/*.dat\n<need output>\n\nIf the virus definition files have dates older than seven days from the current\ndate, this is a finding.\n\nIf \"clamav\" is active on the system, check the dates of the virus database\nwith the following commands:\n\n# grep -I databasedirectory /etc/clamav.conf\nDatabaseDirectory /var/lib/clamav\n\n# ls -al /var/lib/clamav/*.cvd\n-rwxr-xr-x  1 root root      149156 Mar  5  2011 daily.cvd\n\nIf the database file has a date older than seven days from the current date,\nthis is a finding."
            },
            {
              "label": "fix",
              "data": "Update the virus scan software and virus definition files."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72215",
            "rid": "SV-86839r2_rule",
            "stig_id": "RHEL-07-032010",
            "cci": [
              "CCI-001668"
            ],
            "documentable": false,
            "nist": [
              "SI-3 a",
              "Rev_4"
            ],
            "subsystems": [
              "clamav",
              "nails",
              "virus_scan"
            ],
            "fix_id": "F-78569r2_fix"
          },
          "code": "control \"V-72215\" do\n  title \"The system must update the virus scan program every seven days or more\nfrequently.\"\n  desc  \"\n    Virus scanning software can be used to protect a system from penetration\nfrom computer viruses and to limit their spread through intermediate systems.\n\n    The virus scanning software should be configured to check for software and\nvirus definition updates with a frequency no longer than seven days. If a\nmanual process is required to update the virus scan software or definitions, it\nmust be documented with the Information System Security Officer (ISSO).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72215\"\n  tag \"rid\": \"SV-86839r2_rule\"\n  tag \"stig_id\": \"RHEL-07-032010\"\n  tag \"cci\": [\"CCI-001668\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"SI-3 a\", \"Rev_4\"]\n  tag \"subsystems\": ['clamav', 'nails', 'virus_scan']\n  desc \"check\", \"Verify the system is using a virus scan program and the virus\ndefinition file is less than seven days old.\n\nCheck for the presence of \\\"McAfee VirusScan Enterprise for Linux\\\" with the\nfollowing command:\n\n# systemctl status nails\nnails - service for McAfee VirusScan Enterprise for Linux\n>  Loaded: loaded\n/opt/NAI/package/McAfeeVSEForLinux/McAfeeVSEForLinux-2.0.2.<build_number>;\nenabled)\n>  Active: active (running) since Mon 2015-09-27 04:11:22 UTC;21 min ago\n\nIf the \\\"nails\\\" service is not active, check for the presence of \\\"clamav\\\" on\nthe system with the following command:\n\n# systemctl status clamav-daemon.socket\nsystemctl status clamav-daemon.socket\n  clamav-daemon.socket - Socket for Clam AntiVirus userspace daemon\n     Loaded: loaded (/lib/systemd/system/clamav-daemon.socket; enabled)\n     Active: active (running) since Mon 2015-01-12 09:32:59 UTC; 7min ago\n\nIf \\\"McAfee VirusScan Enterprise for Linux\\\" is active on the system, check the\ndates of the virus definition files with the following command:\n\n# ls -al /opt/NAI/LinuxShield/engine/dat/*.dat\n<need output>\n\nIf the virus definition files have dates older than seven days from the current\ndate, this is a finding.\n\nIf \\\"clamav\\\" is active on the system, check the dates of the virus database\nwith the following commands:\n\n# grep -I databasedirectory /etc/clamav.conf\nDatabaseDirectory /var/lib/clamav\n\n# ls -al /var/lib/clamav/*.cvd\n-rwxr-xr-x  1 root root      149156 Mar  5  2011 daily.cvd\n\nIf the database file has a date older than seven days from the current date,\nthis is a finding.\"\n  desc \"fix\", \"Update the virus scan software and virus definition files.\"\n  tag \"fix_id\": \"F-78569r2_fix\"\n\n  sec_per_wk = 604800\n\n  describe.one do\n\t  describe systemd_service('nails') do\n\t    it { should be_running }\n\t  end\n\t  describe systemd_service('clamav-daemon.socket') do\n\t    it { should be_running }\n\t  end\n  end\n\n  if systemd_service('nails').running?\n\t  virus_defs = Dir[\"/opt/NAI/LinuxShield/engine/dat/*.dat\"]\n    virus_defs.each do |curr_def|\n\t    describe file(curr_def).mtime.to_i do\n\t\t    it { should >= Time.now.to_i - sec_per_wk }\n\t    end\n    end\n  end\n\n  if systemd_service('clamav-daemon.socket').running?\n\t  cvd_files = Dir[\"/var/lib/clamav/*.cvd\"]\n    cvd_files.each do |curr_file|\n      describe file(curr_file).mtime.to_i do\n\t      it { should >= Time.now.to_i - sec_per_wk }\n      end\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72215.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Service nails should be running",
              "run_time": 0.000365604,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected that `Service nails` is running",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Service clamav-daemon.socket should be running",
              "run_time": 0.000315351,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected that `Service clamav-daemon.socket` is running",
              "exception": "RSpec::Core::MultipleExceptionError"
            }
          ]
        },
        {
          "id": "V-72217",
          "title": "The operating system must limit the number of concurrent sessions to\n10 for all accounts and/or account types.",
          "desc": "Operating system management includes the ability to control the number of\nusers and user sessions that utilize an operating system. Limiting the number\nof allowed users and sessions per user is helpful in reducing the risks related\nto DoS attacks.\n\n    This requirement addresses concurrent sessions for information system\naccounts and does not address concurrent sessions by single users via multiple\nsystem accounts. The maximum number of concurrent sessions should be defined\nbased on mission needs and the operational environment for each system.",
          "descriptions": [
            {
              "label": "default",
              "data": "Operating system management includes the ability to control the number of\nusers and user sessions that utilize an operating system. Limiting the number\nof allowed users and sessions per user is helpful in reducing the risks related\nto DoS attacks.\n\n    This requirement addresses concurrent sessions for information system\naccounts and does not address concurrent sessions by single users via multiple\nsystem accounts. The maximum number of concurrent sessions should be defined\nbased on mission needs and the operational environment for each system."
            },
            {
              "label": "check",
              "data": "Verify the operating system limits the number of concurrent\nsessions to \"10\" for all accounts and/or account types by issuing the\nfollowing command:\n\n# grep \"maxlogins\" /etc/security/limits.conf\n* hard maxlogins 10\n\nThis can be set as a global domain (with the * wildcard) but may be set\ndifferently for multiple domains.\n\nIf the \"maxlogins\" item is missing or the value is not set to \"10\" or less\nfor all domains that have the \"maxlogins\" item assigned, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to limit the number of concurrent\nsessions to \"10\" for all accounts and/or account types.\n\nAdd the following line to the top of the /etc/security/limits.conf:\n\n* hard maxlogins 10"
            }
          ],
          "impact": 0.3,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000027-GPOS-00008",
            "gid": "V-72217",
            "rid": "SV-86841r1_rule",
            "stig_id": "RHEL-07-040000",
            "cci": [
              "CCI-000054"
            ],
            "documentable": false,
            "nist": [
              "AC-10",
              "Rev_4"
            ],
            "subsystems": [
              "session"
            ],
            "fix_id": "F-78571r1_fix"
          },
          "code": "control \"V-72217\" do\n  title \"The operating system must limit the number of concurrent sessions to\n10 for all accounts and/or account types.\"\n  desc  \"\n    Operating system management includes the ability to control the number of\nusers and user sessions that utilize an operating system. Limiting the number\nof allowed users and sessions per user is helpful in reducing the risks related\nto DoS attacks.\n\n    This requirement addresses concurrent sessions for information system\naccounts and does not address concurrent sessions by single users via multiple\nsystem accounts. The maximum number of concurrent sessions should be defined\nbased on mission needs and the operational environment for each system.\n  \"\n  impact 0.3\n  tag \"gtitle\": \"SRG-OS-000027-GPOS-00008\"\n  tag \"gid\": \"V-72217\"\n  tag \"rid\": \"SV-86841r1_rule\"\n  tag \"stig_id\": \"RHEL-07-040000\"\n  tag \"cci\": [\"CCI-000054\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-10\", \"Rev_4\"]\n  tag \"subsystems\": ['session']\n  desc \"check\", \"Verify the operating system limits the number of concurrent\nsessions to \\\"10\\\" for all accounts and/or account types by issuing the\nfollowing command:\n\n# grep \\\"maxlogins\\\" /etc/security/limits.conf\n* hard maxlogins 10\n\nThis can be set as a global domain (with the * wildcard) but may be set\ndifferently for multiple domains.\n\nIf the \\\"maxlogins\\\" item is missing or the value is not set to \\\"10\\\" or less\nfor all domains that have the \\\"maxlogins\\\" item assigned, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to limit the number of concurrent\nsessions to \\\"10\\\" for all accounts and/or account types.\n\nAdd the following line to the top of the /etc/security/limits.conf:\n\n* hard maxlogins 10\"\n  tag \"fix_id\": \"F-78571r1_fix\"\n\n  # TODO - update to handle other users and values 0-10\n  # TODO - refactor the `limits_conf` use FilterTables like `etc_hosts` and `etc_fstab`\n  # TODO - this will allow us to implament this control such as\n  # describe limits_conf.where { domain: '*' } do\n  #   its(['hard','maxlogins']) { should be 1..10 }\n  # end\n  #\n  # describe limits_conf.domains.where { item: 'maxlogins' } do\n  #   its('type') { should cmp 'hard' }\n  #   its('value') { should be 1..10 }\n  # end\n  #\n  # describe limits_conf.domans.items do\n  #   it { should include 'maxlogins' }\n  # end\n\n  describe limits_conf do\n    its('*') { should include [\"hard\", \"maxlogins\", \"10\"] }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72217.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "limits.conf * should include [\"hard\", \"maxlogins\", \"10\"]",
              "run_time": 0.000774397,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected nil to include [\"hard\", \"maxlogins\", \"10\"], but it does not respond to `include?`"
            }
          ]
        },
        {
          "id": "V-72219",
          "title": "The host must be configured to prohibit or restrict the use of\nfunctions, ports, protocols, and/or services, as defined in the Ports,\nProtocols, and Services Management Component Local Service Assessment (PPSM\nCLSA) and vulnerability assessments.",
          "desc": "In order to prevent unauthorized connection of devices, unauthorized\ntransfer of information, or unauthorized tunneling (i.e., embedding of data\ntypes within data types), organizations must disable or restrict unused or\nunnecessary physical and logical ports/protocols on information systems.\n\n    Operating systems are capable of providing a wide variety of functions and\nservices. Some of the functions and services provided by default may not be\nnecessary to support essential organizational operations. Additionally, it is\nsometimes convenient to provide multiple services from a single component\n(e.g., VPN and IPS); however, doing so increases risk over limiting the\nservices provided by any one component.\n\n    To support the requirements and principles of least functionality, the\noperating system must support the organizational requirements, providing only\nessential capabilities and limiting the use of ports, protocols, and/or\nservices to only those required, authorized, and approved to conduct official\nbusiness or to address authorized quality of life issues.",
          "descriptions": [
            {
              "label": "default",
              "data": "In order to prevent unauthorized connection of devices, unauthorized\ntransfer of information, or unauthorized tunneling (i.e., embedding of data\ntypes within data types), organizations must disable or restrict unused or\nunnecessary physical and logical ports/protocols on information systems.\n\n    Operating systems are capable of providing a wide variety of functions and\nservices. Some of the functions and services provided by default may not be\nnecessary to support essential organizational operations. Additionally, it is\nsometimes convenient to provide multiple services from a single component\n(e.g., VPN and IPS); however, doing so increases risk over limiting the\nservices provided by any one component.\n\n    To support the requirements and principles of least functionality, the\noperating system must support the organizational requirements, providing only\nessential capabilities and limiting the use of ports, protocols, and/or\nservices to only those required, authorized, and approved to conduct official\nbusiness or to address authorized quality of life issues."
            },
            {
              "label": "check",
              "data": "Inspect the firewall configuration and running services to\nverify that it is configured to prohibit or restrict the use of functions,\nports, protocols, and/or services that are unnecessary or prohibited.\n\nCheck which services are currently active with the following command:\n\n# firewall-cmd --list-all\npublic (default, active)\n  interfaces: enp0s3\n  sources:\n  services: dhcpv6-client dns http https ldaps rpc-bind ssh\n  ports:\n  masquerade: no\n  forward-ports:\n  icmp-blocks:\n  rich rules:\n\nAsk the System Administrator for the site or program PPSM CLSA. Verify the\nservices allowed by the firewall match the PPSM CLSA.\n\nIf there are additional ports, protocols, or services that are not in the PPSM\nCLSA, or there are ports, protocols, or services that are prohibited by the\nPPSM Category Assurance List (CAL), this is a finding."
            },
            {
              "label": "fix",
              "data": "Update the host's firewall settings and/or running services to\ncomply with the PPSM CLSA for the site or program and the PPSM CAL."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000096-GPOS-00050",
            "satisfies": [
              "SRG-OS-000096-GPOS-00050",
              "SRG-OS-000297-GPOS-00115"
            ],
            "gid": "V-72219",
            "rid": "SV-86843r1_rule",
            "stig_id": "RHEL-07-040100",
            "cci": [
              "CCI-000382",
              "CCI-002314"
            ],
            "documentable": false,
            "nist": [
              "CM-7 b",
              "AC-17 (1)",
              "Rev_4"
            ],
            "subsystems": [
              "firewall",
              "manual"
            ],
            "fix_id": "F-78573r1_fix"
          },
          "code": "control \"V-72219\" do\n  title \"The host must be configured to prohibit or restrict the use of\nfunctions, ports, protocols, and/or services, as defined in the Ports,\nProtocols, and Services Management Component Local Service Assessment (PPSM\nCLSA) and vulnerability assessments.\"\n  desc  \"\n    In order to prevent unauthorized connection of devices, unauthorized\ntransfer of information, or unauthorized tunneling (i.e., embedding of data\ntypes within data types), organizations must disable or restrict unused or\nunnecessary physical and logical ports/protocols on information systems.\n\n    Operating systems are capable of providing a wide variety of functions and\nservices. Some of the functions and services provided by default may not be\nnecessary to support essential organizational operations. Additionally, it is\nsometimes convenient to provide multiple services from a single component\n(e.g., VPN and IPS); however, doing so increases risk over limiting the\nservices provided by any one component.\n\n    To support the requirements and principles of least functionality, the\noperating system must support the organizational requirements, providing only\nessential capabilities and limiting the use of ports, protocols, and/or\nservices to only those required, authorized, and approved to conduct official\nbusiness or to address authorized quality of life issues.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000096-GPOS-00050\"\n  tag \"satisfies\": [\"SRG-OS-000096-GPOS-00050\", \"SRG-OS-000297-GPOS-00115\"]\n  tag \"gid\": \"V-72219\"\n  tag \"rid\": \"SV-86843r1_rule\"\n  tag \"stig_id\": \"RHEL-07-040100\"\n  tag \"cci\": [\"CCI-000382\", \"CCI-002314\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-7 b\", \"AC-17 (1)\", \"Rev_4\"]\n  tag \"subsystems\": ['firewall', 'manual']\n  desc \"check\", \"Inspect the firewall configuration and running services to\nverify that it is configured to prohibit or restrict the use of functions,\nports, protocols, and/or services that are unnecessary or prohibited.\n\nCheck which services are currently active with the following command:\n\n# firewall-cmd --list-all\npublic (default, active)\n  interfaces: enp0s3\n  sources:\n  services: dhcpv6-client dns http https ldaps rpc-bind ssh\n  ports:\n  masquerade: no\n  forward-ports:\n  icmp-blocks:\n  rich rules:\n\nAsk the System Administrator for the site or program PPSM CLSA. Verify the\nservices allowed by the firewall match the PPSM CLSA.\n\nIf there are additional ports, protocols, or services that are not in the PPSM\nCLSA, or there are ports, protocols, or services that are prohibited by the\nPPSM Category Assurance List (CAL), this is a finding.\"\n  desc \"fix\", \"Update the host's firewall settings and/or running services to\ncomply with the PPSM CLSA for the site or program and the PPSM CAL.\"\n  tag \"fix_id\": \"F-78573r1_fix\"\n\n  describe \"This test currently has no automated tests, you must check manually\" do\n    skip \"This check must be preformed manually\"\n  end\nend\n",
          "source_location": {
            "line": 6,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72219.rb"
          },
          "results": [
            {
              "status": "skipped",
              "code_desc": "This test currently has no automated tests, you must check manually",
              "run_time": 6.461e-06,
              "start_time": "2019-11-04T16:17:15-05:00",
              "resource": "",
              "skip_message": "This check must be preformed manually"
            }
          ]
        },
        {
          "id": "V-72221",
          "title": "A FIPS 140-2 approved cryptographic algorithm must be used for SSH\ncommunications.",
          "desc": "Unapproved mechanisms that are used for authentication to the cryptographic\nmodule are not verified and therefore cannot be relied upon to provide\nconfidentiality or integrity, and DoD data may be compromised.\n\n    Operating systems utilizing encryption are required to use FIPS-compliant\nmechanisms for authenticating to cryptographic modules.\n\n    FIPS 140-2 is the current standard for validating that mechanisms used to\naccess cryptographic modules utilize authentication that meets DoD\nrequirements. This allows for Security Levels 1, 2, 3, or 4 for use on a\ngeneral purpose computing system.",
          "descriptions": [
            {
              "label": "default",
              "data": "Unapproved mechanisms that are used for authentication to the cryptographic\nmodule are not verified and therefore cannot be relied upon to provide\nconfidentiality or integrity, and DoD data may be compromised.\n\n    Operating systems utilizing encryption are required to use FIPS-compliant\nmechanisms for authenticating to cryptographic modules.\n\n    FIPS 140-2 is the current standard for validating that mechanisms used to\naccess cryptographic modules utilize authentication that meets DoD\nrequirements. This allows for Security Levels 1, 2, 3, or 4 for use on a\ngeneral purpose computing system."
            },
            {
              "label": "check",
              "data": "Verify the operating system uses mechanisms meeting the\nrequirements of applicable federal laws, Executive orders, directives,\npolicies, regulations, standards, and guidance for authentication to a\ncryptographic module.\n\nNote: If RHEL-07-021350 is a finding, this is automatically a finding as the\nsystem cannot implement FIPS 140-2-approved cryptographic algorithms and hashes.\n\nThe location of the \"sshd_config\" file may vary if a different daemon is in\nuse.\n\nInspect the \"Ciphers\" configuration with the following command:\n\n# grep -i ciphers /etc/ssh/sshd_config\nCiphers aes128-ctr,aes192-ctr,aes256-ctr\n\nIf any ciphers other than \"aes128-ctr\", \"aes192-ctr\", or \"aes256-ctr\" are\nlisted, the \"Ciphers\" keyword is missing, or the retuned line is commented\nout, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure SSH to use FIPS 140-2 approved cryptographic algorithms.\n\nAdd the following line (or modify the line to have the required value) to the\n\"/etc/ssh/sshd_config\" file (this file may be named differently or be in a\ndifferent location if using a version of SSH that is provided by a third-party\nvendor).\n\nCiphers aes128-ctr,aes192-ctr,aes256-ctr\n\nThe SSH service must be restarted for changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000033-GPOS-00014",
            "satisfies": [
              "SRG-OS-000033-GPOS-00014",
              "SRG-OS-000120-GPOS-00061",
              "SRG-OS-000125-GPOS-00065",
              "SRG-OS-000250-GPOS-00093",
              "SRG-OS-000393-GPOS-00173"
            ],
            "gid": "V-72221",
            "rid": "SV-86845r2_rule",
            "stig_id": "RHEL-07-040110",
            "cci": [
              "CCI-000068",
              "CCI-000366",
              "CCI-000803"
            ],
            "documentable": false,
            "nist": [
              "AC-17 (2)",
              "CM-6 b",
              "IA-7",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78575r3_fix"
          },
          "code": "control \"V-72221\" do\n  title \"A FIPS 140-2 approved cryptographic algorithm must be used for SSH\ncommunications.\"\n  desc  \"\n    Unapproved mechanisms that are used for authentication to the cryptographic\nmodule are not verified and therefore cannot be relied upon to provide\nconfidentiality or integrity, and DoD data may be compromised.\n\n    Operating systems utilizing encryption are required to use FIPS-compliant\nmechanisms for authenticating to cryptographic modules.\n\n    FIPS 140-2 is the current standard for validating that mechanisms used to\naccess cryptographic modules utilize authentication that meets DoD\nrequirements. This allows for Security Levels 1, 2, 3, or 4 for use on a\ngeneral purpose computing system.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000033-GPOS-00014\"\n  tag \"satisfies\": [\"SRG-OS-000033-GPOS-00014\", \"SRG-OS-000120-GPOS-00061\",\n\"SRG-OS-000125-GPOS-00065\", \"SRG-OS-000250-GPOS-00093\",\n\"SRG-OS-000393-GPOS-00173\"]\n  tag \"gid\": \"V-72221\"\n  tag \"rid\": \"SV-86845r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040110\"\n  tag \"cci\": [\"CCI-000068\", \"CCI-000366\", \"CCI-000803\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-17 (2)\", \"CM-6 b\", \"IA-7\", \"Rev_4\"]\n  tag \"subsystems\": [\"ssh\"]\n  desc \"check\", \"Verify the operating system uses mechanisms meeting the\nrequirements of applicable federal laws, Executive orders, directives,\npolicies, regulations, standards, and guidance for authentication to a\ncryptographic module.\n\nNote: If RHEL-07-021350 is a finding, this is automatically a finding as the\nsystem cannot implement FIPS 140-2-approved cryptographic algorithms and hashes.\n\nThe location of the \\\"sshd_config\\\" file may vary if a different daemon is in\nuse.\n\nInspect the \\\"Ciphers\\\" configuration with the following command:\n\n# grep -i ciphers /etc/ssh/sshd_config\nCiphers aes128-ctr,aes192-ctr,aes256-ctr\n\nIf any ciphers other than \\\"aes128-ctr\\\", \\\"aes192-ctr\\\", or \\\"aes256-ctr\\\" are\nlisted, the \\\"Ciphers\\\" keyword is missing, or the retuned line is commented\nout, this is a finding.\"\n  desc \"fix\", \"Configure SSH to use FIPS 140-2 approved cryptographic algorithms.\n\nAdd the following line (or modify the line to have the required value) to the\n\\\"/etc/ssh/sshd_config\\\" file (this file may be named differently or be in a\ndifferent location if using a version of SSH that is provided by a third-party\nvendor).\n\nCiphers aes128-ctr,aes192-ctr,aes256-ctr\n\nThe SSH service must be restarted for changes to take effect.\"\n  tag \"fix_id\": \"F-78575r3_fix\"\n\n  @ciphers_array = inspec.sshd_config.params['ciphers']\n\n  unless @ciphers_array.nil?\n    @ciphers_array = @ciphers_array.first.split(\",\")\n  end\n\n  describe @ciphers_array do\n    it { should be_in ['aes128-ctr', 'aes192-ctr', 'aes256-ctr'] }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72221.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "should be in \"aes128-ctr\", \"aes192-ctr\", and \"aes256-ctr\"",
              "run_time": 0.000168688,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected `` to be in the list: `[\"aes128-ctr\", \"aes192-ctr\", \"aes256-ctr\"]`"
            }
          ]
        },
        {
          "id": "V-72223",
          "title": "All network connections associated with a communication session must\nbe terminated at the end of the session or after 10 minutes of inactivity from\nthe user at a command prompt, except to fulfill documented and validated\nmission requirements.",
          "desc": "Terminating an idle session within a short time period reduces the window\nof opportunity for unauthorized personnel to take control of a management\nsession enabled on the console or console port that has been left unattended.\nIn addition, quickly terminating an idle session will also free up resources\ncommitted by the managed network element.\n\n    Terminating network connections associated with communications sessions\nincludes, for example, de-allocating associated TCP/IP address/port pairs at\nthe operating system level and de-allocating networking assignments at the\napplication level if multiple application sessions are using a single operating\nsystem-level network connection. This does not mean that the operating system\nterminates all sessions or network access; it only ends the inactive session\nand releases the resources associated with that session.",
          "descriptions": [
            {
              "label": "default",
              "data": "Terminating an idle session within a short time period reduces the window\nof opportunity for unauthorized personnel to take control of a management\nsession enabled on the console or console port that has been left unattended.\nIn addition, quickly terminating an idle session will also free up resources\ncommitted by the managed network element.\n\n    Terminating network connections associated with communications sessions\nincludes, for example, de-allocating associated TCP/IP address/port pairs at\nthe operating system level and de-allocating networking assignments at the\napplication level if multiple application sessions are using a single operating\nsystem-level network connection. This does not mean that the operating system\nterminates all sessions or network access; it only ends the inactive session\nand releases the resources associated with that session."
            },
            {
              "label": "check",
              "data": "Verify the operating system terminates all network connections\nassociated with a communications session at the end of the session or based on\ninactivity.\n\nCheck the value of the system inactivity timeout with the following command:\n\n# grep -i tmout /etc/bashrc /etc/profile.d/*\n\nTMOUT=600\n\nIf \"TMOUT\" is not set to \"600\" or less in \"/etc/bashrc\" or in a script\ncreated to enforce session termination after inactivity, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to terminate all network\nconnections associated with a communications session at the end of the session\nor after a period of inactivity.\n\nAdd or update the following lines in \"/etc/profile\".\n\nTMOUT=600\nreadonly TMOUT\nexport TMOUT\n\nOr create a script to enforce the inactivity timeout (for example\n/etc/profile.d/tmout.sh) such as:\n\n#!/bin/bash\n\nTMOUT=600\nreadonly TMOUT\nexport TMOUT"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000163-GPOS-00072",
            "gid": "V-72223",
            "rid": "SV-86847r3_rule",
            "stig_id": "RHEL-07-040160",
            "cci": [
              "CCI-001133",
              "CCI-002361"
            ],
            "documentable": false,
            "nist": [
              "SC-10",
              "AC-12",
              "Rev_4"
            ],
            "subsystems": [
              "user_profile"
            ],
            "fix_id": "F-78577r4_fix"
          },
          "code": "control \"V-72223\" do\n  title \"All network connections associated with a communication session must\nbe terminated at the end of the session or after 10 minutes of inactivity from\nthe user at a command prompt, except to fulfill documented and validated\nmission requirements.\"\n  desc  \"\n    Terminating an idle session within a short time period reduces the window\nof opportunity for unauthorized personnel to take control of a management\nsession enabled on the console or console port that has been left unattended.\nIn addition, quickly terminating an idle session will also free up resources\ncommitted by the managed network element.\n\n    Terminating network connections associated with communications sessions\nincludes, for example, de-allocating associated TCP/IP address/port pairs at\nthe operating system level and de-allocating networking assignments at the\napplication level if multiple application sessions are using a single operating\nsystem-level network connection. This does not mean that the operating system\nterminates all sessions or network access; it only ends the inactive session\nand releases the resources associated with that session.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000163-GPOS-00072\"\n  tag \"gid\": \"V-72223\"\n  tag \"rid\": \"SV-86847r3_rule\"\n  tag \"stig_id\": \"RHEL-07-040160\"\n  tag \"cci\": [\"CCI-001133\", \"CCI-002361\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"SC-10\", \"AC-12\", \"Rev_4\"]\n  tag \"subsystems\": ['user_profile']\n  desc \"check\", \"Verify the operating system terminates all network connections\nassociated with a communications session at the end of the session or based on\ninactivity.\n\nCheck the value of the system inactivity timeout with the following command:\n\n# grep -i tmout /etc/bashrc /etc/profile.d/*\n\nTMOUT=600\n\nIf \\\"TMOUT\\\" is not set to \\\"600\\\" or less in \\\"/etc/bashrc\\\" or in a script\ncreated to enforce session termination after inactivity, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to terminate all network\nconnections associated with a communications session at the end of the session\nor after a period of inactivity.\n\nAdd or update the following lines in \\\"/etc/profile\\\".\n\nTMOUT=600\nreadonly TMOUT\nexport TMOUT\n\nOr create a script to enforce the inactivity timeout (for example\n/etc/profile.d/tmout.sh) such as:\n\n#!/bin/bash\n\nTMOUT=600\nreadonly TMOUT\nexport TMOUT\"\n  tag \"fix_id\": \"F-78577r4_fix\"\n\n  bashrc_file = parse_config_file('/etc/bashrc')\n\n  describe.one do\n    describe bashrc_file do\n      its('TMOUT') { should cmp <= system_activity_timeout }\n    end\n\n    profiled_files = command(\"find /etc/profile.d/*\").stdout.split(\"\\n\")\n    profiled_files.each do |file|\n      profile_file = parse_config_file(file)\n      describe profile_file do\n        its('TMOUT') { should cmp <= system_activity_timeout }\n      end\n    end\n  end\nend\n",
          "source_location": {
            "line": 10,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72223.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/bashrc TMOUT should cmp <= 600",
              "run_time": 0.000231378,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it to be <= 600\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/profile.d/256term.csh TMOUT should cmp <= 600",
              "run_time": 0.00015545,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it to be <= 600\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/profile.d/256term.sh TMOUT should cmp <= 600",
              "run_time": 0.000387218,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it to be <= 600\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/profile.d/abrt-console-notification.sh TMOUT should cmp <= 600",
              "run_time": 0.000369527,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it to be <= 600\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/profile.d/bash_completion.sh TMOUT should cmp <= 600",
              "run_time": 0.000431845,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it to be <= 600\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/profile.d/colorgrep.csh TMOUT should cmp <= 600",
              "run_time": 0.000209924,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it to be <= 600\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/profile.d/colorgrep.sh TMOUT should cmp <= 600",
              "run_time": 0.000346348,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it to be <= 600\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/profile.d/colorls.csh TMOUT should cmp <= 600",
              "run_time": 0.000433338,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it to be <= 600\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/profile.d/colorls.sh TMOUT should cmp <= 600",
              "run_time": 0.000372825,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it to be <= 600\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/profile.d/csh.local TMOUT should cmp <= 600",
              "run_time": 0.000402545,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it to be <= 600\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/profile.d/flatpak.sh TMOUT should cmp <= 600",
              "run_time": 0.000287044,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it to be <= 600\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/profile.d/lang.csh TMOUT should cmp <= 600",
              "run_time": 0.000581827,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it to be <= 600\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/profile.d/lang.sh TMOUT should cmp <= 600",
              "run_time": 0.000176351,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it to be <= 600\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/profile.d/less.csh TMOUT should cmp <= 600",
              "run_time": 0.000339192,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it to be <= 600\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/profile.d/less.sh TMOUT should cmp <= 600",
              "run_time": 0.00017674,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it to be <= 600\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/profile.d/PackageKit.sh TMOUT should cmp <= 600",
              "run_time": 0.000467222,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it to be <= 600\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/profile.d/sh.local TMOUT should cmp <= 600",
              "run_time": 0.000296463,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it to be <= 600\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/profile.d/vim.csh TMOUT should cmp <= 600",
              "run_time": 0.000270319,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it to be <= 600\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/profile.d/vim.sh TMOUT should cmp <= 600",
              "run_time": 0.000311823,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it to be <= 600\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/profile.d/vte.sh TMOUT should cmp <= 600",
              "run_time": 0.000173907,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it to be <= 600\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/profile.d/which2.csh TMOUT should cmp <= 600",
              "run_time": 0.000147363,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it to be <= 600\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Parse Config File /etc/profile.d/which2.sh TMOUT should cmp <= 600",
              "run_time": 0.000144879,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it to be <= 600\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            }
          ]
        },
        {
          "id": "V-72225",
          "title": "The Standard Mandatory DoD Notice and Consent Banner must be displayed\nimmediately prior to, or as part of, remote access logon prompts.",
          "desc": "Display of a standardized and approved use notification before granting\naccess to the publicly accessible operating system ensures privacy and security\nnotification verbiage used is consistent with applicable federal laws,\nExecutive Orders, directives, policies, regulations, standards, and guidance.\n\n    System use notifications are required only for access via logon interfaces\nwith human users and are not required when such human interfaces do not exist.\n\n    The banner must be formatted in accordance with applicable DoD policy. Use\nthe following verbiage for operating systems that can accommodate banners of\n1300 characters:\n\n    \"You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only.\n\n    By using this IS (which includes any device attached to this IS), you\nconsent to the following conditions:\n\n    -The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n    -At any time, the USG may inspect and seize data stored on this IS.\n\n    -Communications using, or data stored on, this IS are not private, are\nsubject to routine monitoring, interception, and search, and may be disclosed\nor used for any USG-authorized purpose.\n\n    -This IS includes security measures (e.g., authentication and access\ncontrols) to protect USG interests--not for your personal benefit or privacy.\n\n    -Notwithstanding the above, using this IS does not constitute consent to\nPM, LE or CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details.\"",
          "descriptions": [
            {
              "label": "default",
              "data": "Display of a standardized and approved use notification before granting\naccess to the publicly accessible operating system ensures privacy and security\nnotification verbiage used is consistent with applicable federal laws,\nExecutive Orders, directives, policies, regulations, standards, and guidance.\n\n    System use notifications are required only for access via logon interfaces\nwith human users and are not required when such human interfaces do not exist.\n\n    The banner must be formatted in accordance with applicable DoD policy. Use\nthe following verbiage for operating systems that can accommodate banners of\n1300 characters:\n\n    \"You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only.\n\n    By using this IS (which includes any device attached to this IS), you\nconsent to the following conditions:\n\n    -The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n    -At any time, the USG may inspect and seize data stored on this IS.\n\n    -Communications using, or data stored on, this IS are not private, are\nsubject to routine monitoring, interception, and search, and may be disclosed\nor used for any USG-authorized purpose.\n\n    -This IS includes security measures (e.g., authentication and access\ncontrols) to protect USG interests--not for your personal benefit or privacy.\n\n    -Notwithstanding the above, using this IS does not constitute consent to\nPM, LE or CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details.\""
            },
            {
              "label": "check",
              "data": "Verify any publicly accessible connection to the operating\nsystem displays the Standard Mandatory DoD Notice and Consent Banner before\ngranting access to the system.\n\nCheck for the location of the banner file being used with the following command:\n\n# grep -i banner /etc/ssh/sshd_config\n\nbanner /etc/issue\n\nThis command will return the banner keyword and the name of the file that\ncontains the ssh banner (in this case \"/etc/issue\").\n\nIf the line is commented out, this is a finding.\n\nView the file specified by the banner keyword to check that it matches the text\nof the Standard Mandatory DoD Notice and Consent Banner:\n\n\"You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only. By using this IS (which includes any\ndevice attached to this IS), you consent to the following conditions:\n\n-The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n-At any time, the USG may inspect and seize data stored on this IS.\n\n-Communications using, or data stored on, this IS are not private, are subject\nto routine monitoring, interception, and search, and may be disclosed or used\nfor any USG-authorized purpose.\n\n-This IS includes security measures (e.g., authentication and access controls)\nto protect USG interests--not for your personal benefit or privacy.\n\n-Notwithstanding the above, using this IS does not constitute consent to PM, LE\nor CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details.\"\n\nIf the system does not display a graphical logon banner or the banner does not\nmatch the Standard Mandatory DoD Notice and Consent Banner, this is a finding.\n\nIf the text in the file does not match the Standard Mandatory DoD Notice and\nConsent Banner, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to display the Standard Mandatory\nDoD Notice and Consent Banner before granting access to the system via the ssh.\n\nEdit the \"/etc/ssh/sshd_config\" file to uncomment the banner keyword and\nconfigure it to point to a file that will contain the logon banner (this file\nmay be named differently or be in a different location if using a version of\nSSH that is provided by a third-party vendor). An example configuration line is:\n\nbanner /etc/issue\n\nEither create the file containing the banner or replace the text in the file\nwith the Standard Mandatory DoD Notice and Consent Banner. The DoD required\ntext is:\n\n\"You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only. By using this IS (which includes any\ndevice attached to this IS), you consent to the following conditions:\n\n-The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n-At any time, the USG may inspect and seize data stored on this IS.\n\n-Communications using, or data stored on, this IS are not private, are subject\nto routine monitoring, interception, and search, and may be disclosed or used\nfor any USG-authorized purpose.\n\n-This IS includes security measures (e.g., authentication and access controls)\nto protect USG interests--not for your personal benefit or privacy.\n\n-Notwithstanding the above, using this IS does not constitute consent to PM, LE\nor CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details.\"\n\nThe SSH service must be restarted for changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000023-GPOS-00006",
            "satisfies": [
              "SRG-OS-000023-GPOS-00006",
              "SRG-OS-000024-GPOS-00007",
              "SRG-OS-000228-GPOS-00088"
            ],
            "gid": "V-72225",
            "rid": "SV-86849r3_rule",
            "stig_id": "RHEL-07-040170",
            "cci": [
              "CCI-000048",
              "CCI-000050",
              "CCI-001384",
              "CCI-001385",
              "CCI-001386",
              "CCI-001387",
              "CCI-001388"
            ],
            "documentable": false,
            "nist": [
              "AC-8 a",
              "AC-8 b",
              "AC-8 c 1",
              "AC-8 c 2",
              "AC-8 c 2",
              "AC-8 c\n2",
              "AC-8 c 3",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78579r4_fix"
          },
          "code": "control \"V-72225\" do\n  title \"The Standard Mandatory DoD Notice and Consent Banner must be displayed\nimmediately prior to, or as part of, remote access logon prompts.\"\n  desc  \"\n    Display of a standardized and approved use notification before granting\naccess to the publicly accessible operating system ensures privacy and security\nnotification verbiage used is consistent with applicable federal laws,\nExecutive Orders, directives, policies, regulations, standards, and guidance.\n\n    System use notifications are required only for access via logon interfaces\nwith human users and are not required when such human interfaces do not exist.\n\n    The banner must be formatted in accordance with applicable DoD policy. Use\nthe following verbiage for operating systems that can accommodate banners of\n1300 characters:\n\n    \\\"You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only.\n\n    By using this IS (which includes any device attached to this IS), you\nconsent to the following conditions:\n\n    -The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n    -At any time, the USG may inspect and seize data stored on this IS.\n\n    -Communications using, or data stored on, this IS are not private, are\nsubject to routine monitoring, interception, and search, and may be disclosed\nor used for any USG-authorized purpose.\n\n    -This IS includes security measures (e.g., authentication and access\ncontrols) to protect USG interests--not for your personal benefit or privacy.\n\n    -Notwithstanding the above, using this IS does not constitute consent to\nPM, LE or CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details.\\\"\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000023-GPOS-00006\"\n  tag \"satisfies\": [\"SRG-OS-000023-GPOS-00006\", \"SRG-OS-000024-GPOS-00007\",\n\"SRG-OS-000228-GPOS-00088\"]\n  tag \"gid\": \"V-72225\"\n  tag \"rid\": \"SV-86849r3_rule\"\n  tag \"stig_id\": \"RHEL-07-040170\"\n  tag \"cci\": [\"CCI-000048\", \"CCI-000050\", \"CCI-001384\", \"CCI-001385\",\n\"CCI-001386\", \"CCI-001387\", \"CCI-001388\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-8 a\", \"AC-8 b\", \"AC-8 c 1\", \"AC-8 c 2\", \"AC-8 c 2\", \"AC-8 c\n2\", \"AC-8 c 3\", \"Rev_4\"]\n  tag \"subsystems\": [\"ssh\"]\n  desc \"check\", \"Verify any publicly accessible connection to the operating\nsystem displays the Standard Mandatory DoD Notice and Consent Banner before\ngranting access to the system.\n\nCheck for the location of the banner file being used with the following command:\n\n# grep -i banner /etc/ssh/sshd_config\n\nbanner /etc/issue\n\nThis command will return the banner keyword and the name of the file that\ncontains the ssh banner (in this case \\\"/etc/issue\\\").\n\nIf the line is commented out, this is a finding.\n\nView the file specified by the banner keyword to check that it matches the text\nof the Standard Mandatory DoD Notice and Consent Banner:\n\n\\\"You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only. By using this IS (which includes any\ndevice attached to this IS), you consent to the following conditions:\n\n-The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n-At any time, the USG may inspect and seize data stored on this IS.\n\n-Communications using, or data stored on, this IS are not private, are subject\nto routine monitoring, interception, and search, and may be disclosed or used\nfor any USG-authorized purpose.\n\n-This IS includes security measures (e.g., authentication and access controls)\nto protect USG interests--not for your personal benefit or privacy.\n\n-Notwithstanding the above, using this IS does not constitute consent to PM, LE\nor CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details.\\\"\n\nIf the system does not display a graphical logon banner or the banner does not\nmatch the Standard Mandatory DoD Notice and Consent Banner, this is a finding.\n\nIf the text in the file does not match the Standard Mandatory DoD Notice and\nConsent Banner, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to display the Standard Mandatory\nDoD Notice and Consent Banner before granting access to the system via the ssh.\n\nEdit the \\\"/etc/ssh/sshd_config\\\" file to uncomment the banner keyword and\nconfigure it to point to a file that will contain the logon banner (this file\nmay be named differently or be in a different location if using a version of\nSSH that is provided by a third-party vendor). An example configuration line is:\n\nbanner /etc/issue\n\nEither create the file containing the banner or replace the text in the file\nwith the Standard Mandatory DoD Notice and Consent Banner. The DoD required\ntext is:\n\n\\\"You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only. By using this IS (which includes any\ndevice attached to this IS), you consent to the following conditions:\n\n-The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n-At any time, the USG may inspect and seize data stored on this IS.\n\n-Communications using, or data stored on, this IS are not private, are subject\nto routine monitoring, interception, and search, and may be disclosed or used\nfor any USG-authorized purpose.\n\n-This IS includes security measures (e.g., authentication and access controls)\nto protect USG interests--not for your personal benefit or privacy.\n\n-Notwithstanding the above, using this IS does not constitute consent to PM, LE\nor CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details.\\\"\n\nThe SSH service must be restarted for changes to take effect.\"\n  tag \"fix_id\": \"F-78579r4_fix\"\n\n  #When Banner is commented, not found, disabled, or the specified file does not exist, this is a finding.\n  banner_files = [sshd_config.banner].flatten\n\n  banner_files.each do |banner_file|\n\n    #Banner property is commented out.\n    describe \"The SSHD Banner is not set\" do\n      subject { banner_file.nil? }\n      it { should be false }\n    end if banner_file.nil?\n\n    #Banner property is set to \"none\"\n    describe \"The SSHD Banner is disabled\" do\n      subject { banner_file.match(/none/i).nil? }\n      it { should be true }\n    end if !banner_file.nil? && !banner_file.match(/none/i).nil?\n\n    #Banner property provides a path to a file, however, it does not exist.\n    describe \"The SSHD Banner is set, but, the file does not exist\" do\n      subject { file(banner_file).exist? }\n      it { should be true }\n    end if !banner_file.nil? && banner_file.match(/none/i).nil? && !file(banner_file).exist?\n\n    #Banner property provides a path to a file and it exists.\n    describe.one do\n      banner = file(banner_file).content.gsub(%r{[\\r\\n\\s]}, '')\n      clean_banner = banner_message_text_ral.gsub(%r{[\\r\\n\\s]}, '')\n      clean_banner_limited = banner_message_text_ral_limited.gsub(%r{[\\r\\n\\s]}, '')\n\n      describe \"The SSHD Banner is set to the standard banner and has the correct text\" do\n        subject { banner }\n        it { should cmp clean_banner }\n      end\n\n      describe \"The SSHD Banner is set to the standard limited banner and has the correct text\" do\n        subject { banner }\n        it { should cmp clean_banner_limited }\n      end\n    end if !banner_file.nil? && banner_file.match(/none/i).nil? && file(banner_file).exist?\n  end\nend\n",
          "source_location": {
            "line": 30,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72225.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "The SSHD Banner is not set should equal false",
              "run_time": 0.000193044,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected false\n     got true\n"
            }
          ]
        },
        {
          "id": "V-72227",
          "title": "The operating system must implement cryptography to protect the\nintegrity of Lightweight Directory Access Protocol (LDAP) authentication\ncommunications.",
          "desc": "Without cryptographic integrity protections, information can be altered by\nunauthorized users without detection.\n\n    Cryptographic mechanisms used for protecting the integrity of information\ninclude, for example, signed hash functions using asymmetric cryptography\nenabling distribution of the public key to verify the hash information while\nmaintaining the confidentiality of the key used to generate the hash.",
          "descriptions": [
            {
              "label": "default",
              "data": "Without cryptographic integrity protections, information can be altered by\nunauthorized users without detection.\n\n    Cryptographic mechanisms used for protecting the integrity of information\ninclude, for example, signed hash functions using asymmetric cryptography\nenabling distribution of the public key to verify the hash information while\nmaintaining the confidentiality of the key used to generate the hash."
            },
            {
              "label": "check",
              "data": "Verify the operating system implements cryptography to protect\nthe integrity of remote LDAP authentication sessions.\n\nTo determine if LDAP is being used for authentication, use the following\ncommand:\n\n# grep -i useldapauth /etc/sysconfig/authconfig\nUSELDAPAUTH=yes\n\nIf USELDAPAUTH=yes, then LDAP is being used. To see if LDAP is configured to\nuse TLS, use the following command:\n\n# grep -i ssl /etc/pam_ldap.conf\nssl start_tls\n\nIf the \"ssl\" option is not \"start_tls\", this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to implement cryptography to\nprotect the integrity of LDAP authentication sessions.\n\nSet the USELDAPAUTH=yes in \"/etc/sysconfig/authconfig\".\n\nSet \"ssl start_tls\" in \"/etc/pam_ldap.conf\"."
            }
          ],
          "impact": 0,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000250-GPOS-00093",
            "gid": "V-72227",
            "rid": "SV-86851r2_rule",
            "stig_id": "RHEL-07-040180",
            "cci": [
              "CCI-001453"
            ],
            "documentable": false,
            "nist": [
              "AC-17 (2)",
              "Rev_4"
            ],
            "subsystems": [
              "sssd",
              "ldap"
            ],
            "fix_id": "F-78581r1_fix"
          },
          "code": "control \"V-72227\" do\n  title \"The operating system must implement cryptography to protect the\nintegrity of Lightweight Directory Access Protocol (LDAP) authentication\ncommunications.\"\n  desc  \"\n    Without cryptographic integrity protections, information can be altered by\nunauthorized users without detection.\n\n    Cryptographic mechanisms used for protecting the integrity of information\ninclude, for example, signed hash functions using asymmetric cryptography\nenabling distribution of the public key to verify the hash information while\nmaintaining the confidentiality of the key used to generate the hash.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000250-GPOS-00093\"\n  tag \"gid\": \"V-72227\"\n  tag \"rid\": \"SV-86851r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040180\"\n  tag \"cci\": [\"CCI-001453\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-17 (2)\", \"Rev_4\"]\n  tag \"subsystems\": ['sssd', 'ldap']\n  desc \"check\", \"Verify the operating system implements cryptography to protect\nthe integrity of remote LDAP authentication sessions.\n\nTo determine if LDAP is being used for authentication, use the following\ncommand:\n\n# grep -i useldapauth /etc/sysconfig/authconfig\nUSELDAPAUTH=yes\n\nIf USELDAPAUTH=yes, then LDAP is being used. To see if LDAP is configured to\nuse TLS, use the following command:\n\n# grep -i ssl /etc/pam_ldap.conf\nssl start_tls\n\nIf the \\\"ssl\\\" option is not \\\"start_tls\\\", this is a finding.\"\n  desc \"fix\", \"Configure the operating system to implement cryptography to\nprotect the integrity of LDAP authentication sessions.\n\nSet the USELDAPAUTH=yes in \\\"/etc/sysconfig/authconfig\\\".\n\nSet \\\"ssl start_tls\\\" in \\\"/etc/pam_ldap.conf\\\".\"\n  tag \"fix_id\": \"F-78581r1_fix\"\n\n  sssd_id_ldap_enabled = (package('sssd').installed? and\n    !command('grep \"^\\s*id_provider\\s*=\\s*ldap\" /etc/sssd/sssd.conf').stdout.strip.empty?)\n\n  pam_ldap_enabled = (!command('grep \"^[^#]*pam_ldap\\.so\" /etc/pam.d/*').stdout.strip.empty?)\n\n  if !(sssd_id_ldap_enabled or pam_ldap_enabled)\n    impact 0.0\n    describe \"LDAP not enabled\" do\n      skip \"LDAP not enabled using any known mechanisms, this control is Not Applicable.\"\n    end\n  end\n\n  if sssd_id_ldap_enabled\n    ldap_id_use_start_tls = command('grep ldap_id_use_start_tls /etc/sssd/sssd.conf')\n    describe ldap_id_use_start_tls do\n      its('stdout.strip') { should match %r{^ldap_id_use_start_tls\\s*=\\s*true$}}\n    end\n\n    ldap_id_use_start_tls.stdout.strip.each_line do |line|\n      describe line do\n        it { should match %r{^ldap_id_use_start_tls\\s*=\\s*true$}}\n      end\n    end\n  end\n\n  if pam_ldap_enabled\n    describe command('grep -i ssl /etc/pam_ldap.conf') do\n      its('stdout.strip') { should match %r{^ssl start_tls$}}\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72227.rb"
          },
          "results": [
            {
              "status": "skipped",
              "code_desc": "LDAP not enabled",
              "run_time": 6.202e-06,
              "start_time": "2019-11-04T16:17:15-05:00",
              "resource": "",
              "skip_message": "LDAP not enabled using any known mechanisms, this control is Not Applicable."
            }
          ]
        },
        {
          "id": "V-72229",
          "title": "The operating system must implement cryptography to protect the\nintegrity of Lightweight Directory Access Protocol (LDAP) communications.",
          "desc": "Without cryptographic integrity protections, information can be altered by\nunauthorized users without detection.\n\n    Cryptographic mechanisms used for protecting the integrity of information\ninclude, for example, signed hash functions using asymmetric cryptography\nenabling distribution of the public key to verify the hash information while\nmaintaining the confidentiality of the key used to generate the hash.",
          "descriptions": [
            {
              "label": "default",
              "data": "Without cryptographic integrity protections, information can be altered by\nunauthorized users without detection.\n\n    Cryptographic mechanisms used for protecting the integrity of information\ninclude, for example, signed hash functions using asymmetric cryptography\nenabling distribution of the public key to verify the hash information while\nmaintaining the confidentiality of the key used to generate the hash."
            },
            {
              "label": "check",
              "data": "Verify the operating system implements cryptography to protect\nthe integrity of remote LDAP access sessions.\n\nTo determine if LDAP is being used for authentication, use the following\ncommand:\n\n# grep -i useldapauth /etc/sysconfig/authconfig\nUSELDAPAUTH=yes\n\nIf USELDAPAUTH=yes, then LDAP is being used.\n\nCheck for the directory containing X.509 certificates for peer authentication\nwith the following command:\n\n# grep -i cacertdir /etc/pam_ldap.conf\ntls_cacertdir /etc/openldap/certs\n\nVerify the directory set with the \"tls_cacertdir\" option exists.\n\nIf the directory does not exist or the option is commented out, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to implement cryptography to\nprotect the integrity of LDAP remote access sessions.\n\nSet the \"tls_cacertdir\" option in \"/etc/pam_ldap.conf\" to point to the\ndirectory that will contain the X.509 certificates for peer authentication.\n\nSet the \"tls_cacertfile\" option in \"/etc/pam_ldap.conf\" to point to the\npath for the X.509 certificates used for peer authentication."
            }
          ],
          "impact": 0,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000250-GPOS-00093",
            "gid": "V-72229",
            "rid": "SV-86853r2_rule",
            "stig_id": "RHEL-07-040190",
            "cci": [
              "CCI-001453"
            ],
            "documentable": false,
            "nist": [
              "AC-17 (2)",
              "Rev_4"
            ],
            "subsystems": [
              "sssd",
              "ldap"
            ],
            "fix_id": "F-78583r1_fix"
          },
          "code": "control \"V-72229\" do\n  title \"The operating system must implement cryptography to protect the\nintegrity of Lightweight Directory Access Protocol (LDAP) communications.\"\n  desc  \"\n    Without cryptographic integrity protections, information can be altered by\nunauthorized users without detection.\n\n    Cryptographic mechanisms used for protecting the integrity of information\ninclude, for example, signed hash functions using asymmetric cryptography\nenabling distribution of the public key to verify the hash information while\nmaintaining the confidentiality of the key used to generate the hash.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000250-GPOS-00093\"\n  tag \"gid\": \"V-72229\"\n  tag \"rid\": \"SV-86853r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040190\"\n  tag \"cci\": [\"CCI-001453\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-17 (2)\", \"Rev_4\"]\n  tag \"subsystems\": ['sssd', 'ldap']\n  desc \"check\", \"Verify the operating system implements cryptography to protect\nthe integrity of remote LDAP access sessions.\n\nTo determine if LDAP is being used for authentication, use the following\ncommand:\n\n# grep -i useldapauth /etc/sysconfig/authconfig\nUSELDAPAUTH=yes\n\nIf USELDAPAUTH=yes, then LDAP is being used.\n\nCheck for the directory containing X.509 certificates for peer authentication\nwith the following command:\n\n# grep -i cacertdir /etc/pam_ldap.conf\ntls_cacertdir /etc/openldap/certs\n\nVerify the directory set with the \\\"tls_cacertdir\\\" option exists.\n\nIf the directory does not exist or the option is commented out, this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to implement cryptography to\nprotect the integrity of LDAP remote access sessions.\n\nSet the \\\"tls_cacertdir\\\" option in \\\"/etc/pam_ldap.conf\\\" to point to the\ndirectory that will contain the X.509 certificates for peer authentication.\n\nSet the \\\"tls_cacertfile\\\" option in \\\"/etc/pam_ldap.conf\\\" to point to the\npath for the X.509 certificates used for peer authentication.\"\n  tag \"fix_id\": \"F-78583r1_fix\"\n\n  sssd_id_ldap_enabled = (package('sssd').installed? and\n    !command('grep \"^\\s*id_provider\\s*=\\s*ldap\" /etc/sssd/sssd.conf').stdout.strip.empty?)\n\n  sssd_ldap_enabled = (package('sssd').installed? and\n    !command('grep \"^\\s*[a-z]*_provider\\s*=\\s*ldap\" /etc/sssd/sssd.conf').stdout.strip.empty?)\n\n  pam_ldap_enabled = (!command('grep \"^[^#]*pam_ldap\\.so\" /etc/pam.d/*').stdout.strip.empty?)\n\n  if !(sssd_id_ldap_enabled or sssd_ldap_enabled or pam_ldap_enabled)\n    impact 0.0\n    describe \"LDAP not enabled\" do\n      skip \"LDAP not enabled using any known mechanisms, this control is Not Applicable.\"\n    end\n  end\n\n  if sssd_id_ldap_enabled\n    ldap_id_use_start_tls = command('grep ldap_id_use_start_tls /etc/sssd/sssd.conf')\n    describe ldap_id_use_start_tls do\n      its('stdout.strip') { should match %r{^ldap_id_use_start_tls\\s*=\\s*true$}}\n    end\n\n    ldap_id_use_start_tls.stdout.strip.each_line do |line|\n      describe line do\n        it { should match %r{^ldap_id_use_start_tls\\s*=\\s*true$}}\n      end\n    end\n  end\n\n  if sssd_ldap_enabled\n    ldap_tls_cacertdir = command('grep -i ldap_tls_cacertdir /etc/sssd/sssd.conf').\n      stdout.strip.scan(%r{^ldap_tls_cacertdir\\s*=\\s*(.*)}).last\n\n    describe \"ldap_tls_cacertdir\" do\n      subject { ldap_tls_cacertdir }\n      it { should_not eq nil }\n    end\n\n    describe file(ldap_tls_cacertdir.last) do\n      it { should exist }\n      it { should be_directory }\n    end if !ldap_tls_cacertdir.nil?\n  end\n\n  if pam_ldap_enabled\n    tls_cacertdir = command('grep -i tls_cacertdir /etc/pam_ldap.conf').\n      stdout.strip.scan(%r{^tls_cacertdir\\s+(.*)}).last\n\n    describe \"tls_cacertdir\" do\n      subject { tls_cacertdir }\n      it { should_not eq nil }\n    end\n\n    describe file(tls_cacertdir.last) do\n      it { should exist }\n      it { should be_directory }\n    end if !tls_cacertdir.nil?\n  end\nend\n",
          "source_location": {
            "line": 4,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72229.rb"
          },
          "results": [
            {
              "status": "skipped",
              "code_desc": "LDAP not enabled",
              "run_time": 4.256e-06,
              "start_time": "2019-11-04T16:17:15-05:00",
              "resource": "",
              "skip_message": "LDAP not enabled using any known mechanisms, this control is Not Applicable."
            }
          ]
        },
        {
          "id": "V-72231",
          "title": "The operating system must implement cryptography to protect the\nintegrity of Lightweight Directory Access Protocol (LDAP) communications.",
          "desc": "Without cryptographic integrity protections, information can be altered by\nunauthorized users without detection.\n\n    Cryptographic mechanisms used for protecting the integrity of information\ninclude, for example, signed hash functions using asymmetric cryptography\nenabling distribution of the public key to verify the hash information while\nmaintaining the confidentiality of the key used to generate the hash.",
          "descriptions": [
            {
              "label": "default",
              "data": "Without cryptographic integrity protections, information can be altered by\nunauthorized users without detection.\n\n    Cryptographic mechanisms used for protecting the integrity of information\ninclude, for example, signed hash functions using asymmetric cryptography\nenabling distribution of the public key to verify the hash information while\nmaintaining the confidentiality of the key used to generate the hash."
            },
            {
              "label": "check",
              "data": "Verify the operating system implements cryptography to protect\nthe integrity of remote ldap access sessions.\n\nTo determine if LDAP is being used for authentication, use the following\ncommand:\n\n# grep -i useldapauth /etc/sysconfig/authconfig\nUSELDAPAUTH=yes\n\nIf USELDAPAUTH=yes, then LDAP is being used.\n\nCheck that the path to the X.509 certificate for peer authentication with the\nfollowing command:\n\n# grep -i cacertfile /etc/pam_ldap.conf\ntls_cacertfile /etc/openldap/ldap-cacert.pem\n\nVerify the \"tls_cacertfile\" option points to a file that contains the trusted\nCA certificate.\n\nIf this file does not exist, or the option is commented out or missing, this is\na finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to implement cryptography to\nprotect the integrity of LDAP remote access sessions.\n\nSet the \"tls_cacertfile\" option in \"/etc/pam_ldap.conf\" to point to the\npath for the X.509 certificates used for peer authentication."
            }
          ],
          "impact": 0,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000250-GPOS-00093",
            "gid": "V-72231",
            "rid": "SV-86855r2_rule",
            "stig_id": "RHEL-07-040200",
            "cci": [
              "CCI-001453"
            ],
            "documentable": false,
            "nist": [
              "AC-17 (2)",
              "Rev_4"
            ],
            "subsystems": [
              "sssd",
              "ldap"
            ],
            "fix_id": "F-78585r1_fix"
          },
          "code": "control \"V-72231\" do\n  title \"The operating system must implement cryptography to protect the\nintegrity of Lightweight Directory Access Protocol (LDAP) communications.\"\n  desc  \"\n    Without cryptographic integrity protections, information can be altered by\nunauthorized users without detection.\n\n    Cryptographic mechanisms used for protecting the integrity of information\ninclude, for example, signed hash functions using asymmetric cryptography\nenabling distribution of the public key to verify the hash information while\nmaintaining the confidentiality of the key used to generate the hash.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000250-GPOS-00093\"\n  tag \"gid\": \"V-72231\"\n  tag \"rid\": \"SV-86855r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040200\"\n  tag \"cci\": [\"CCI-001453\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-17 (2)\", \"Rev_4\"]\n  tag \"subsystems\": ['sssd', 'ldap']\n  desc \"check\", \"Verify the operating system implements cryptography to protect\nthe integrity of remote ldap access sessions.\n\nTo determine if LDAP is being used for authentication, use the following\ncommand:\n\n# grep -i useldapauth /etc/sysconfig/authconfig\nUSELDAPAUTH=yes\n\nIf USELDAPAUTH=yes, then LDAP is being used.\n\nCheck that the path to the X.509 certificate for peer authentication with the\nfollowing command:\n\n# grep -i cacertfile /etc/pam_ldap.conf\ntls_cacertfile /etc/openldap/ldap-cacert.pem\n\nVerify the \\\"tls_cacertfile\\\" option points to a file that contains the trusted\nCA certificate.\n\nIf this file does not exist, or the option is commented out or missing, this is\na finding.\"\n  desc \"fix\", \"Configure the operating system to implement cryptography to\nprotect the integrity of LDAP remote access sessions.\n\nSet the \\\"tls_cacertfile\\\" option in \\\"/etc/pam_ldap.conf\\\" to point to the\npath for the X.509 certificates used for peer authentication.\"\n  tag \"fix_id\": \"F-78585r1_fix\"\n\n  sssd_id_ldap_enabled = (package('sssd').installed? and\n    !command('grep \"^\\s*id_provider\\s*=\\s*ldap\" /etc/sssd/sssd.conf').stdout.strip.empty?)\n\n  sssd_ldap_enabled = (package('sssd').installed? and\n    !command('grep \"^\\s*[a-z]*_provider\\s*=\\s*ldap\" /etc/sssd/sssd.conf').stdout.strip.empty?)\n\n  pam_ldap_enabled = (!command('grep \"^[^#]*pam_ldap\\.so\" /etc/pam.d/*').stdout.strip.empty?)\n\n  if !(sssd_id_ldap_enabled or sssd_ldap_enabled or pam_ldap_enabled)\n    impact 0.0\n    describe \"LDAP not enabled\" do\n      skip \"LDAP not enabled using any known mechanisms, this control is Not Applicable.\"\n    end\n  end\n\n  if sssd_id_ldap_enabled\n    ldap_id_use_start_tls = command('grep ldap_id_use_start_tls /etc/sssd/sssd.conf')\n    describe ldap_id_use_start_tls do\n      its('stdout.strip') { should match %r{^ldap_id_use_start_tls\\s*=\\s*true$}}\n    end\n\n    ldap_id_use_start_tls.stdout.strip.each_line do |line|\n      describe line do\n        it { should match %r{^ldap_id_use_start_tls\\s*=\\s*true$}}\n      end\n    end\n  end\n\n  if sssd_ldap_enabled\n    ldap_tls_cacert = command('grep -i ldap_tls_cacert /etc/sssd/sssd.conf').\n      stdout.strip.scan(%r{^ldap_tls_cacert\\s*=\\s*(.*)}).last\n\n    describe \"ldap_tls_cacert\" do\n      subject { ldap_tls_cacert }\n      it { should_not eq nil }\n    end\n\n    describe file(ldap_tls_cacert.last) do\n      it { should exist }\n      it { should be_file }\n    end if !ldap_tls_cacert.nil?\n  end\n\n  if pam_ldap_enabled\n    tls_cacertfile = command('grep -i tls_cacertfile /etc/pam_ldap.conf').\n      stdout.strip.scan(%r{^tls_cacertfile\\s+(.*)}).last\n\n    describe \"tls_cacertfile\" do\n      subject { tls_cacertfile }\n      it { should_not eq nil }\n    end\n\n    describe file(tls_cacertfile.last) do\n      it { should exist }\n      it { should be_file }\n    end if !tls_cacertfile.nil?\n  end\nend\n",
          "source_location": {
            "line": 4,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72231.rb"
          },
          "results": [
            {
              "status": "skipped",
              "code_desc": "LDAP not enabled",
              "run_time": 4.243e-06,
              "start_time": "2019-11-04T16:17:15-05:00",
              "resource": "",
              "skip_message": "LDAP not enabled using any known mechanisms, this control is Not Applicable."
            }
          ]
        },
        {
          "id": "V-72233",
          "title": "All networked systems must have SSH installed.",
          "desc": "Without protection of the transmitted information, confidentiality and\nintegrity may be compromised because unprotected communications can be\nintercepted and either read or altered.\n\n    This requirement applies to both internal and external networks and all\ntypes of information system components from which information can be\ntransmitted (e.g., servers, mobile devices, notebook computers, printers,\ncopiers, scanners, and facsimile machines). Communication paths outside the\nphysical protection of a controlled boundary are exposed to the possibility of\ninterception and modification.\n\n    Protecting the confidentiality and integrity of organizational information\ncan be accomplished by physical means (e.g., employing physical distribution\nsystems) or by logical means (e.g., employing cryptographic techniques). If\nphysical means of protection are employed, logical means (cryptography) do not\nhave to be employed, and vice versa.",
          "descriptions": [
            {
              "label": "default",
              "data": "Without protection of the transmitted information, confidentiality and\nintegrity may be compromised because unprotected communications can be\nintercepted and either read or altered.\n\n    This requirement applies to both internal and external networks and all\ntypes of information system components from which information can be\ntransmitted (e.g., servers, mobile devices, notebook computers, printers,\ncopiers, scanners, and facsimile machines). Communication paths outside the\nphysical protection of a controlled boundary are exposed to the possibility of\ninterception and modification.\n\n    Protecting the confidentiality and integrity of organizational information\ncan be accomplished by physical means (e.g., employing physical distribution\nsystems) or by logical means (e.g., employing cryptographic techniques). If\nphysical means of protection are employed, logical means (cryptography) do not\nhave to be employed, and vice versa."
            },
            {
              "label": "check",
              "data": "Check to see if sshd is installed with the following command:\n\n# yum list installed | grep  ssh\nlibssh2.x86_64                           1.4.3-8.el7               @anaconda/7.1\nopenssh.x86_64                           6.6.1p1-11.el7            @anaconda/7.1\nopenssh-clients.x86_64                   6.6.1p1-11.el7            @anaconda/7.1\nopenssh-server.x86_64                    6.6.1p1-11.el7            @anaconda/7.1\n\nIf the \"SSH server\" package is not installed, this is a finding.\n\nIf the \"SSH client\" package is not installed, this is a finding."
            },
            {
              "label": "fix",
              "data": "Install SSH packages onto the host with the following commands:\n\n# yum install openssh-clients.x86_64\n# yum install openssh-server.x86_64"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000423-GPOS-00187",
            "satisfies": [
              "SRG-OS-000423-GPOS-00187",
              "SRG-OS-000424-GPOS-00188",
              "SRG-OS-000425-GPOS-00189",
              "SRG-OS-000426-GPOS-00190"
            ],
            "gid": "V-72233",
            "rid": "SV-86857r2_rule",
            "stig_id": "RHEL-07-040300",
            "cci": [
              "CCI-002418",
              "CCI-002420",
              "CCI-002421",
              "CCI-002422"
            ],
            "documentable": false,
            "nist": [
              "SC-8",
              "SC-8 (2)",
              "SC-8 (1)",
              "SC-8 (2)",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78587r2_fix"
          },
          "code": "control \"V-72233\" do\n  title \"All networked systems must have SSH installed.\"\n  desc  \"\n    Without protection of the transmitted information, confidentiality and\nintegrity may be compromised because unprotected communications can be\nintercepted and either read or altered.\n\n    This requirement applies to both internal and external networks and all\ntypes of information system components from which information can be\ntransmitted (e.g., servers, mobile devices, notebook computers, printers,\ncopiers, scanners, and facsimile machines). Communication paths outside the\nphysical protection of a controlled boundary are exposed to the possibility of\ninterception and modification.\n\n    Protecting the confidentiality and integrity of organizational information\ncan be accomplished by physical means (e.g., employing physical distribution\nsystems) or by logical means (e.g., employing cryptographic techniques). If\nphysical means of protection are employed, logical means (cryptography) do not\nhave to be employed, and vice versa.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000423-GPOS-00187\"\n  tag \"satisfies\": [\"SRG-OS-000423-GPOS-00187\", \"SRG-OS-000424-GPOS-00188\",\n\"SRG-OS-000425-GPOS-00189\", \"SRG-OS-000426-GPOS-00190\"]\n  tag \"gid\": \"V-72233\"\n  tag \"rid\": \"SV-86857r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040300\"\n  tag \"cci\": [\"CCI-002418\", \"CCI-002420\", \"CCI-002421\", \"CCI-002422\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"SC-8\", \"SC-8 (2)\", \"SC-8 (1)\", \"SC-8 (2)\", \"Rev_4\"]\n  tag \"subsystems\": [\"ssh\"]\n  desc \"check\", \"Check to see if sshd is installed with the following command:\n\n# yum list installed | grep  ssh\nlibssh2.x86_64                           1.4.3-8.el7               @anaconda/7.1\nopenssh.x86_64                           6.6.1p1-11.el7            @anaconda/7.1\nopenssh-clients.x86_64                   6.6.1p1-11.el7            @anaconda/7.1\nopenssh-server.x86_64                    6.6.1p1-11.el7            @anaconda/7.1\n\nIf the \\\"SSH server\\\" package is not installed, this is a finding.\n\nIf the \\\"SSH client\\\" package is not installed, this is a finding.\"\n  desc \"fix\", \"Install SSH packages onto the host with the following commands:\n\n# yum install openssh-clients.x86_64\n# yum install openssh-server.x86_64\n\"\n  tag \"fix_id\": \"F-78587r2_fix\"\n\n  describe package('openssh-server') do\n    it { should be_installed }\n  end\n  describe package('openssh-clients') do\n    it { should be_installed }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72233.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "System Package openssh-server should be installed",
              "run_time": 0.054321325,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "System Package openssh-clients should be installed",
              "run_time": 0.046042065,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72235",
          "title": "All networked systems must use SSH for confidentiality and integrity\nof transmitted and received information as well as information during\npreparation for transmission.",
          "desc": "Without protection of the transmitted information, confidentiality and\nintegrity may be compromised because unprotected communications can be\nintercepted and either read or altered.\n\n    This requirement applies to both internal and external networks and all\ntypes of information system components from which information can be\ntransmitted (e.g., servers, mobile devices, notebook computers, printers,\ncopiers, scanners, and facsimile machines). Communication paths outside the\nphysical protection of a controlled boundary are exposed to the possibility of\ninterception and modification.\n\n    Protecting the confidentiality and integrity of organizational information\ncan be accomplished by physical means (e.g., employing physical distribution\nsystems) or by logical means (e.g., employing cryptographic techniques). If\nphysical means of protection are employed, then logical means (cryptography) do\nnot have to be employed, and vice versa.",
          "descriptions": [
            {
              "label": "default",
              "data": "Without protection of the transmitted information, confidentiality and\nintegrity may be compromised because unprotected communications can be\nintercepted and either read or altered.\n\n    This requirement applies to both internal and external networks and all\ntypes of information system components from which information can be\ntransmitted (e.g., servers, mobile devices, notebook computers, printers,\ncopiers, scanners, and facsimile machines). Communication paths outside the\nphysical protection of a controlled boundary are exposed to the possibility of\ninterception and modification.\n\n    Protecting the confidentiality and integrity of organizational information\ncan be accomplished by physical means (e.g., employing physical distribution\nsystems) or by logical means (e.g., employing cryptographic techniques). If\nphysical means of protection are employed, then logical means (cryptography) do\nnot have to be employed, and vice versa."
            },
            {
              "label": "check",
              "data": "Verify SSH is loaded and active with the following command:\n\n# systemctl status sshd\n sshd.service - OpenSSH server daemon\n   Loaded: loaded (/usr/lib/systemd/system/sshd.service; enabled)\n   Active: active (running) since Tue 2015-11-17 15:17:22 EST; 4 weeks 0 days\nago\n Main PID: 1348 (sshd)\n   CGroup: /system.slice/sshd.service\n           ??1348 /usr/sbin/sshd -D\n\nIf \"sshd\" does not show a status of \"active\" and \"running\", this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the SSH service to automatically start after reboot\nwith the following command:\n\n# systemctl enable sshd ln -s '/usr/lib/systemd/system/sshd.service'\n'/etc/systemd/system/multi-user.target.wants/sshd.service'"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000423-GPOS-00187",
            "satisfies": [
              "SRG-OS-000423-GPOS-00187",
              "SRG-OS-000423-GPOS-00188",
              "SRG-OS-000423-GPOS-00189",
              "SRG-OS-000423-GPOS-00190"
            ],
            "gid": "V-72235",
            "rid": "SV-86859r2_rule",
            "stig_id": "RHEL-07-040310",
            "cci": [
              "CCI-002418",
              "CCI-002420",
              "CCI-002421",
              "CCI-002422"
            ],
            "documentable": false,
            "nist": [
              "SC-8",
              "SC-8 (2)",
              "SC-8 (1)",
              "SC-8 (2)",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78589r1_fix"
          },
          "code": "control \"V-72235\" do\n  title \"All networked systems must use SSH for confidentiality and integrity\nof transmitted and received information as well as information during\npreparation for transmission.\"\n  desc  \"\n    Without protection of the transmitted information, confidentiality and\nintegrity may be compromised because unprotected communications can be\nintercepted and either read or altered.\n\n    This requirement applies to both internal and external networks and all\ntypes of information system components from which information can be\ntransmitted (e.g., servers, mobile devices, notebook computers, printers,\ncopiers, scanners, and facsimile machines). Communication paths outside the\nphysical protection of a controlled boundary are exposed to the possibility of\ninterception and modification.\n\n    Protecting the confidentiality and integrity of organizational information\ncan be accomplished by physical means (e.g., employing physical distribution\nsystems) or by logical means (e.g., employing cryptographic techniques). If\nphysical means of protection are employed, then logical means (cryptography) do\nnot have to be employed, and vice versa.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000423-GPOS-00187\"\n  tag \"satisfies\": [\"SRG-OS-000423-GPOS-00187\", \"SRG-OS-000423-GPOS-00188\",\n\"SRG-OS-000423-GPOS-00189\", \"SRG-OS-000423-GPOS-00190\"]\n  tag \"gid\": \"V-72235\"\n  tag \"rid\": \"SV-86859r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040310\"\n  tag \"cci\": [\"CCI-002418\", \"CCI-002420\", \"CCI-002421\", \"CCI-002422\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"SC-8\", \"SC-8 (2)\", \"SC-8 (1)\", \"SC-8 (2)\", \"Rev_4\"]\n  tag \"subsystems\": [\"ssh\"]\n  desc \"check\", \"Verify SSH is loaded and active with the following command:\n\n# systemctl status sshd\n sshd.service - OpenSSH server daemon\n   Loaded: loaded (/usr/lib/systemd/system/sshd.service; enabled)\n   Active: active (running) since Tue 2015-11-17 15:17:22 EST; 4 weeks 0 days\nago\n Main PID: 1348 (sshd)\n   CGroup: /system.slice/sshd.service\n           ??1348 /usr/sbin/sshd -D\n\nIf \\\"sshd\\\" does not show a status of \\\"active\\\" and \\\"running\\\", this is a\nfinding.\"\n  desc \"fix\", \"Configure the SSH service to automatically start after reboot\nwith the following command:\n\n# systemctl enable sshd ln -s '/usr/lib/systemd/system/sshd.service'\n'/etc/systemd/system/multi-user.target.wants/sshd.service'\"\n  tag \"fix_id\": \"F-78589r1_fix\"\n\n  describe systemd_service('sshd.service') do\n    it { should be_running }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72235.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Service sshd.service should be running",
              "run_time": 0.050958596,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72237",
          "title": "All network connections associated with SSH traffic must terminate at\nthe end of the session or after 10 minutes of inactivity, except to fulfill\ndocumented and validated mission requirements.",
          "desc": "Terminating an idle SSH session within a short time period reduces the\nwindow of opportunity for unauthorized personnel to take control of a\nmanagement session enabled on the console or console port that has been left\nunattended. In addition, quickly terminating an idle SSH session will also free\nup resources committed by the managed network element.\n\n    Terminating network connections associated with communications sessions\nincludes, for example, de-allocating associated TCP/IP address/port pairs at\nthe operating system level and de-allocating networking assignments at the\napplication level if multiple application sessions are using a single operating\nsystem-level network connection. This does not mean that the operating system\nterminates all sessions or network access; it only ends the inactive session\nand releases the resources associated with that session.",
          "descriptions": [
            {
              "label": "default",
              "data": "Terminating an idle SSH session within a short time period reduces the\nwindow of opportunity for unauthorized personnel to take control of a\nmanagement session enabled on the console or console port that has been left\nunattended. In addition, quickly terminating an idle SSH session will also free\nup resources committed by the managed network element.\n\n    Terminating network connections associated with communications sessions\nincludes, for example, de-allocating associated TCP/IP address/port pairs at\nthe operating system level and de-allocating networking assignments at the\napplication level if multiple application sessions are using a single operating\nsystem-level network connection. This does not mean that the operating system\nterminates all sessions or network access; it only ends the inactive session\nand releases the resources associated with that session."
            },
            {
              "label": "check",
              "data": "Verify the operating system automatically terminates a user\nsession after inactivity time-outs have expired.\n\nCheck for the value of the \"ClientAliveInterval\" keyword with the following\ncommand:\n\n# grep -iw clientaliveinterval /etc/ssh/sshd_config\n\nClientAliveInterval 600\n\nIf \"ClientAliveInterval\" is not configured, commented out, or has a value of\n\"0\", this is a finding.\n\nIf \"ClientAliveInterval\" has a value that is greater than \"600\" and is not\ndocumented with the Information System Security Officer (ISSO) as an\noperational requirement, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to automatically terminate a user\nsession after inactivity time-outs have expired or at shutdown.\n\nAdd the following line (or modify the line to have the required value) to the\n\"/etc/ssh/sshd_config\" file (this file may be named differently or be in a\ndifferent location if using a version of SSH that is provided by a third-party\nvendor):\n\nClientAliveInterval 600\n\nThe SSH service must be restarted for changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000163-GPOS-00072",
            "satisfies": [
              "SRG-OS-000163-GPOS-00072",
              "SRG-OS-000279-GPOS-00109"
            ],
            "gid": "V-72237",
            "rid": "SV-86861r3_rule",
            "stig_id": "RHEL-07-040320",
            "cci": [
              "CCI-001133",
              "CCI-002361"
            ],
            "documentable": false,
            "nist": [
              "SC-10",
              "AC-12",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78591r2_fix"
          },
          "code": "control \"V-72237\" do\n  title \"All network connections associated with SSH traffic must terminate at\nthe end of the session or after 10 minutes of inactivity, except to fulfill\ndocumented and validated mission requirements.\"\n  desc  \"\n    Terminating an idle SSH session within a short time period reduces the\nwindow of opportunity for unauthorized personnel to take control of a\nmanagement session enabled on the console or console port that has been left\nunattended. In addition, quickly terminating an idle SSH session will also free\nup resources committed by the managed network element.\n\n    Terminating network connections associated with communications sessions\nincludes, for example, de-allocating associated TCP/IP address/port pairs at\nthe operating system level and de-allocating networking assignments at the\napplication level if multiple application sessions are using a single operating\nsystem-level network connection. This does not mean that the operating system\nterminates all sessions or network access; it only ends the inactive session\nand releases the resources associated with that session.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000163-GPOS-00072\"\n  tag \"satisfies\": [\"SRG-OS-000163-GPOS-00072\", \"SRG-OS-000279-GPOS-00109\"]\n  tag \"gid\": \"V-72237\"\n  tag \"rid\": \"SV-86861r3_rule\"\n  tag \"stig_id\": \"RHEL-07-040320\"\n  tag \"cci\": [\"CCI-001133\", \"CCI-002361\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"SC-10\", \"AC-12\", \"Rev_4\"]\n  tag \"subsystems\": [\"ssh\"]\n  desc \"check\", \"Verify the operating system automatically terminates a user\nsession after inactivity time-outs have expired.\n\nCheck for the value of the \\\"ClientAliveInterval\\\" keyword with the following\ncommand:\n\n# grep -iw clientaliveinterval /etc/ssh/sshd_config\n\nClientAliveInterval 600\n\nIf \\\"ClientAliveInterval\\\" is not configured, commented out, or has a value of\n\\\"0\\\", this is a finding.\n\nIf \\\"ClientAliveInterval\\\" has a value that is greater than \\\"600\\\" and is not\ndocumented with the Information System Security Officer (ISSO) as an\noperational requirement, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to automatically terminate a user\nsession after inactivity time-outs have expired or at shutdown.\n\nAdd the following line (or modify the line to have the required value) to the\n\\\"/etc/ssh/sshd_config\\\" file (this file may be named differently or be in a\ndifferent location if using a version of SSH that is provided by a third-party\nvendor):\n\nClientAliveInterval 600\n\nThe SSH service must be restarted for changes to take effect.\"\n  tag \"fix_id\": \"F-78591r2_fix\"\n\n  #This may show slightly confusing results when a ClientAliveInterValue is not\n  #specified. Specifically, because the value will be nil and when you try to\n  #convert it to an integer using to_i it will convert it to 0 and pass the\n  #<= client_alive_interval check. However, the control as a whole will still fail.\n  describe sshd_config do\n    its(\"ClientAliveInterval.to_i\"){should cmp >= 1}\n    its(\"ClientAliveInterval.to_i\"){should cmp <= client_alive_interval}\n    its(\"ClientAliveInterval\"){should_not eq nil}\n  end\nend\n",
          "source_location": {
            "line": 7,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72237.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "SSHD Configuration ClientAliveInterval.to_i should cmp >= 1",
              "run_time": 0.000599409,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected it to be >= 1\n     got: 0\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "SSHD Configuration ClientAliveInterval.to_i should cmp <= 600",
              "run_time": 0.000126756,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "SSHD Configuration ClientAliveInterval should not eq nil",
              "run_time": 0.000150053,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: value != nil\n     got: nil\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72239",
          "title": "The SSH daemon must not allow authentication using RSA rhosts\nauthentication.",
          "desc": "Configuring this setting for the SSH daemon provides additional\nassurance that remote logon via SSH will require a password, even in the event\nof misconfiguration elsewhere.",
          "descriptions": [
            {
              "label": "default",
              "data": "Configuring this setting for the SSH daemon provides additional\nassurance that remote logon via SSH will require a password, even in the event\nof misconfiguration elsewhere."
            },
            {
              "label": "check",
              "data": "Verify the SSH daemon does not allow authentication using RSA\nrhosts authentication.\n\nTo determine how the SSH daemon's \"RhostsRSAAuthentication\" option is set,\nrun the following command:\n\n# grep RhostsRSAAuthentication /etc/ssh/sshd_config\nRhostsRSAAuthentication no\n\nIf the value is returned as \"yes\", the returned line is commented out, or no\noutput is returned, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the SSH daemon to not allow authentication using RSA\nrhosts authentication.\n\nAdd the following line in \"/etc/ssh/sshd_config\", or uncomment the line and\nset the value to \"no\":\n\nRhostsRSAAuthentication no\n\nThe SSH service must be restarted for changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72239",
            "rid": "SV-86863r3_rule",
            "stig_id": "RHEL-07-040330",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78593r4_fix"
          },
          "code": "control \"V-72239\" do\n  title \"The SSH daemon must not allow authentication using RSA rhosts\nauthentication.\"\n  desc  \"Configuring this setting for the SSH daemon provides additional\nassurance that remote logon via SSH will require a password, even in the event\nof misconfiguration elsewhere.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72239\"\n  tag \"rid\": \"SV-86863r3_rule\"\n  tag \"stig_id\": \"RHEL-07-040330\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": [\"ssh\"]\n  desc \"check\", \"Verify the SSH daemon does not allow authentication using RSA\nrhosts authentication.\n\nTo determine how the SSH daemon's \\\"RhostsRSAAuthentication\\\" option is set,\nrun the following command:\n\n# grep RhostsRSAAuthentication /etc/ssh/sshd_config\nRhostsRSAAuthentication no\n\nIf the value is returned as \\\"yes\\\", the returned line is commented out, or no\noutput is returned, this is a finding.\"\n  desc \"fix\", \"Configure the SSH daemon to not allow authentication using RSA\nrhosts authentication.\n\nAdd the following line in \\\"/etc/ssh/sshd_config\\\", or uncomment the line and\nset the value to \\\"no\\\":\n\nRhostsRSAAuthentication no\n\nThe SSH service must be restarted for changes to take effect.\"\n  tag \"fix_id\": \"F-78593r4_fix\"\n\n  describe sshd_config do\n    its('RhostsRSAAuthentication') { should cmp 'no' }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72239.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "SSHD Configuration RhostsRSAAuthentication should cmp == \"no\"",
              "run_time": 0.000444186,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: \"no\"\n     got: nil\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-72241",
          "title": "All network connections associated with SSH traffic must terminate\nafter a period of inactivity.",
          "desc": "Terminating an idle SSH session within a short time period reduces the\nwindow of opportunity for unauthorized personnel to take control of a\nmanagement session enabled on the console or console port that has been left\nunattended. In addition, quickly terminating an idle SSH session will also free\nup resources committed by the managed network element.\n\n    Terminating network connections associated with communications sessions\nincludes, for example, de-allocating associated TCP/IP address/port pairs at\nthe operating system level and de-allocating networking assignments at the\napplication level if multiple application sessions are using a single operating\nsystem-level network connection. This does not mean that the operating system\nterminates all sessions or network access; it only ends the inactive session\nand releases the resources associated with that session.",
          "descriptions": [
            {
              "label": "default",
              "data": "Terminating an idle SSH session within a short time period reduces the\nwindow of opportunity for unauthorized personnel to take control of a\nmanagement session enabled on the console or console port that has been left\nunattended. In addition, quickly terminating an idle SSH session will also free\nup resources committed by the managed network element.\n\n    Terminating network connections associated with communications sessions\nincludes, for example, de-allocating associated TCP/IP address/port pairs at\nthe operating system level and de-allocating networking assignments at the\napplication level if multiple application sessions are using a single operating\nsystem-level network connection. This does not mean that the operating system\nterminates all sessions or network access; it only ends the inactive session\nand releases the resources associated with that session."
            },
            {
              "label": "check",
              "data": "Check the version of the operating system with the following\ncommand:\n\n# cat /etc/redhat-release\n\nIf the release is 7.4 or newer this requirement is Not Applicable.\n\nVerify the operating system automatically terminates a user session after\ninactivity time-outs have expired.\n\nCheck for the value of the \"ClientAliveCountMax\" keyword with the following\ncommand:\n\n# grep -i clientalivecount /etc/ssh/sshd_config\nClientAliveCountMax 0\n\nIf \"ClientAliveCountMax\" is not set to \"0\" in \"/etc/ ssh/sshd_config\",\nthis is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to automatically terminate a user\nsession after inactivity time-outs have expired or at shutdown.\n\nAdd the following line (or modify the line to have the required value) to the\n\"/etc/ssh/sshd_config\" file (this file may be named differently or be in a\ndifferent location if using a version of SSH that is provided by a third-party\nvendor):\n\nClientAliveCountMax 0\n\nThe SSH service must be restarted for changes to take effect."
            }
          ],
          "impact": 0,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000163-GPOS-00072",
            "satisfies": [
              "SRG-OS-000163-GPOS-00072",
              "SRG-OS-000279-GPOS-00109"
            ],
            "gid": "V-72241",
            "rid": "SV-86865r3_rule",
            "stig_id": "RHEL-07-040340",
            "cci": [
              "CCI-001133",
              "CCI-002361"
            ],
            "documentable": false,
            "nist": [
              "SC-10",
              "AC-12",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78595r3_fix"
          },
          "code": "control \"V-72241\" do\n  title \"All network connections associated with SSH traffic must terminate\nafter a period of inactivity.\"\n  desc  \"\n    Terminating an idle SSH session within a short time period reduces the\nwindow of opportunity for unauthorized personnel to take control of a\nmanagement session enabled on the console or console port that has been left\nunattended. In addition, quickly terminating an idle SSH session will also free\nup resources committed by the managed network element.\n\n    Terminating network connections associated with communications sessions\nincludes, for example, de-allocating associated TCP/IP address/port pairs at\nthe operating system level and de-allocating networking assignments at the\napplication level if multiple application sessions are using a single operating\nsystem-level network connection. This does not mean that the operating system\nterminates all sessions or network access; it only ends the inactive session\nand releases the resources associated with that session.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000163-GPOS-00072\"\n  tag \"satisfies\": [\"SRG-OS-000163-GPOS-00072\", \"SRG-OS-000279-GPOS-00109\"]\n  tag \"gid\": \"V-72241\"\n  tag \"rid\": \"SV-86865r3_rule\"\n  tag \"stig_id\": \"RHEL-07-040340\"\n  tag \"cci\": [\"CCI-001133\", \"CCI-002361\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"SC-10\", \"AC-12\", \"Rev_4\"]\n  tag \"subsystems\": [\"ssh\"]\n  desc \"check\", \"Check the version of the operating system with the following\ncommand:\n\n# cat /etc/redhat-release\n\nIf the release is 7.4 or newer this requirement is Not Applicable.\n\nVerify the operating system automatically terminates a user session after\ninactivity time-outs have expired.\n\nCheck for the value of the \\\"ClientAliveCountMax\\\" keyword with the following\ncommand:\n\n# grep -i clientalivecount /etc/ssh/sshd_config\nClientAliveCountMax 0\n\nIf \\\"ClientAliveCountMax\\\" is not set to \\\"0\\\" in \\\"/etc/ ssh/sshd_config\\\",\nthis is a finding.\"\n  desc \"fix\", \"Configure the operating system to automatically terminate a user\nsession after inactivity time-outs have expired or at shutdown.\n\nAdd the following line (or modify the line to have the required value) to the\n\\\"/etc/ssh/sshd_config\\\" file (this file may be named differently or be in a\ndifferent location if using a version of SSH that is provided by a third-party\nvendor):\n\nClientAliveCountMax 0\n\nThe SSH service must be restarted for changes to take effect.\"\n  tag \"fix_id\": \"F-78595r3_fix\"\n\n  if os.release.to_f >= 7.4\n    impact 0.0\n    describe \"The release is #{os.release}\" do\n      skip \"The release is newer than 7.4; this control is Not Applicable.\"\n    end\n  else\n    describe sshd_config do\n      its('ClientAliveCountMax') { should cmp '0' }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72241.rb"
          },
          "results": [
            {
              "status": "skipped",
              "code_desc": "The release is 7.6.1810",
              "run_time": 6.698e-06,
              "start_time": "2019-11-04T16:17:15-05:00",
              "resource": "",
              "skip_message": "The release is newer than 7.4; this control is Not Applicable."
            }
          ]
        },
        {
          "id": "V-72243",
          "title": "The SSH daemon must not allow authentication using rhosts\nauthentication.",
          "desc": "Configuring this setting for the SSH daemon provides additional\nassurance that remote logon via SSH will require a password, even in the event\nof misconfiguration elsewhere.",
          "descriptions": [
            {
              "label": "default",
              "data": "Configuring this setting for the SSH daemon provides additional\nassurance that remote logon via SSH will require a password, even in the event\nof misconfiguration elsewhere."
            },
            {
              "label": "check",
              "data": "Verify the SSH daemon does not allow authentication using known\nhosts authentication.\n\nTo determine how the SSH daemon's \"IgnoreRhosts\" option is set, run the\nfollowing command:\n\n# grep -i IgnoreRhosts /etc/ssh/sshd_config\n\nIgnoreRhosts yes\n\nIf the value is returned as \"no\", the returned line is commented out, or no\noutput is returned, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the SSH daemon to not allow authentication using known\nhosts authentication.\n\nAdd the following line in \"/etc/ssh/sshd_config\", or uncomment the line and\nset the value to \"yes\":\n\nIgnoreRhosts yes"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72243",
            "rid": "SV-86867r2_rule",
            "stig_id": "RHEL-07-040350",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78597r2_fix"
          },
          "code": "control \"V-72243\" do\n  title \"The SSH daemon must not allow authentication using rhosts\nauthentication.\"\n  desc  \"Configuring this setting for the SSH daemon provides additional\nassurance that remote logon via SSH will require a password, even in the event\nof misconfiguration elsewhere.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72243\"\n  tag \"rid\": \"SV-86867r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040350\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": [\"ssh\"]\n  desc \"check\", \"Verify the SSH daemon does not allow authentication using known\nhosts authentication.\n\nTo determine how the SSH daemon's \\\"IgnoreRhosts\\\" option is set, run the\nfollowing command:\n\n# grep -i IgnoreRhosts /etc/ssh/sshd_config\n\nIgnoreRhosts yes\n\nIf the value is returned as \\\"no\\\", the returned line is commented out, or no\noutput is returned, this is a finding.\"\n  desc \"fix\", \"Configure the SSH daemon to not allow authentication using known\nhosts authentication.\n\nAdd the following line in \\\"/etc/ssh/sshd_config\\\", or uncomment the line and\nset the value to \\\"yes\\\":\n\nIgnoreRhosts yes\"\n  tag \"fix_id\": \"F-78597r2_fix\"\n\n  describe sshd_config do\n    its('IgnoreRhosts') { should cmp 'yes' }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72243.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "SSHD Configuration IgnoreRhosts should cmp == \"yes\"",
              "run_time": 0.000422567,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: \"yes\"\n     got: nil\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-72245",
          "title": "The system must display the date and time of the last successful\naccount logon upon an SSH logon.",
          "desc": "Providing users with feedback on when account accesses via SSH last\noccurred facilitates user recognition and reporting of unauthorized account\nuse.",
          "descriptions": [
            {
              "label": "default",
              "data": "Providing users with feedback on when account accesses via SSH last\noccurred facilitates user recognition and reporting of unauthorized account\nuse."
            },
            {
              "label": "check",
              "data": "Verify SSH provides users with feedback on when account\naccesses last occurred.\n\nCheck that \"PrintLastLog\" keyword in the sshd daemon configuration file is\nused and set to \"yes\" with the following command:\n\n# grep -i printlastlog /etc/ssh/sshd_config\nPrintLastLog yes\n\nIf the \"PrintLastLog\" keyword is set to \"no\", is missing, or is commented\nout, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure SSH to provide users with feedback on when account\naccesses last occurred by setting the required configuration options in\n\"/etc/pam.d/sshd\" or in the \"sshd_config\" file used by the system\n(\"/etc/ssh/sshd_config\" will be used in the example) (this file may be named\ndifferently or be in a different location if using a version of SSH that is\nprovided by a third-party vendor).\n\nAdd the following line to the top of \"/etc/pam.d/sshd\":\n\nsession     required      pam_lastlog.so showfailed\n\nOr modify the \"PrintLastLog\" line in \"/etc/ssh/sshd_config\" to match the\nfollowing:\n\nPrintLastLog yes\n\nThe SSH service must be restarted for changes to \"sshd_config\" to take\neffect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72245",
            "rid": "SV-86869r2_rule",
            "stig_id": "RHEL-07-040360",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "pam",
              "ssh",
              "lastlog"
            ],
            "fix_id": "F-78599r2_fix"
          },
          "code": "control \"V-72245\" do\n  title \"The system must display the date and time of the last successful\naccount logon upon an SSH logon.\"\n  desc  \"Providing users with feedback on when account accesses via SSH last\noccurred facilitates user recognition and reporting of unauthorized account\nuse.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72245\"\n  tag \"rid\": \"SV-86869r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040360\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['pam', 'ssh', 'lastlog']\n  desc \"check\", \"Verify SSH provides users with feedback on when account\naccesses last occurred.\n\nCheck that \\\"PrintLastLog\\\" keyword in the sshd daemon configuration file is\nused and set to \\\"yes\\\" with the following command:\n\n# grep -i printlastlog /etc/ssh/sshd_config\nPrintLastLog yes\n\nIf the \\\"PrintLastLog\\\" keyword is set to \\\"no\\\", is missing, or is commented\nout, this is a finding.\"\n  desc \"fix\", \"Configure SSH to provide users with feedback on when account\naccesses last occurred by setting the required configuration options in\n\\\"/etc/pam.d/sshd\\\" or in the \\\"sshd_config\\\" file used by the system\n(\\\"/etc/ssh/sshd_config\\\" will be used in the example) (this file may be named\ndifferently or be in a different location if using a version of SSH that is\nprovided by a third-party vendor).\n\nAdd the following line to the top of \\\"/etc/pam.d/sshd\\\":\n\nsession     required      pam_lastlog.so showfailed\n\nOr modify the \\\"PrintLastLog\\\" line in \\\"/etc/ssh/sshd_config\\\" to match the\nfollowing:\n\nPrintLastLog yes\n\nThe SSH service must be restarted for changes to \\\"sshd_config\\\" to take\neffect.\"\n  tag \"fix_id\": \"F-78599r2_fix\"\n\n  if sshd_config.params['printlastlog'] == ['yes']\n    describe sshd_config do\n      its('PrintLastLog') { should cmp 'yes' }\n    end\n  else\n    describe pam('/etc/pam.d/sshd') do\n      its('lines') { should match_pam_rule('session required pam_lastlog.so showfailed') }\n      its('lines') { should match_pam_rule('session required pam_lastlog.so showfailed').all_without_args('silent') }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72245.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "PAM Config[/etc/pam.d/sshd] lines should include session required pam_lastlog.so showfailed",
              "run_time": 0.001542344,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected \"account required pam_unix.so\\naccount sufficient pam_localuser.so\\naccount sufficient pam_succeed_if...on optional pam_lastlog.so silent noupdate showfailed\\n-session optional pam_reauthorize.so prepare\" to include session required pam_lastlog.so showfailed\nDiff:\n@@ -1,2 +1,84 @@\n-session required pam_lastlog.so showfailed\n+account required pam_unix.so\n+account sufficient pam_localuser.so\n+account sufficient pam_succeed_if.so uid < 1000 quiet\n+account required pam_permit.so\n+account required pam_nologin.so\n+account required pam_unix.so\n+account sufficient pam_localuser.so\n+account sufficient pam_succeed_if.so uid < 1000 quiet\n+account required pam_permit.so\n+account required pam_unix.so\n+account sufficient pam_localuser.so\n+account sufficient pam_succeed_if.so uid < 1000 quiet\n+account required pam_permit.so\n+account required pam_unix.so\n+account sufficient pam_localuser.so\n+account sufficient pam_succeed_if.so uid < 1000 quiet\n+account required pam_permit.so\n+auth required pam_sepermit.so\n+auth required pam_env.so\n+auth required pam_faildelay.so delay=2000000\n+auth sufficient pam_unix.so nullok try_first_pass\n+auth requisite pam_succeed_if.so uid >= 1000 quiet_success\n+auth required pam_deny.so\n+-auth optional pam_reauthorize.so prepare\n+auth required pam_env.so\n+auth required pam_faildelay.so delay=2000000\n+auth sufficient pam_unix.so nullok try_first_pass\n+auth requisite pam_succeed_if.so uid >= 1000 quiet_success\n+auth required pam_deny.so\n+auth required pam_env.so\n+auth required pam_faildelay.so delay=2000000\n+auth sufficient pam_unix.so nullok try_first_pass\n+auth requisite pam_succeed_if.so uid >= 1000 quiet_success\n+auth required pam_deny.so\n+auth required pam_env.so\n+auth required pam_faildelay.so delay=2000000\n+auth sufficient pam_unix.so nullok try_first_pass\n+auth requisite pam_succeed_if.so uid >= 1000 quiet_success\n+auth required pam_deny.so\n+password requisite pam_pwquality.so try_first_pass local_users_only retry=3 authtok_type=\n+password sufficient pam_unix.so sha512 shadow nullok try_first_pass use_authtok\n+password required pam_deny.so\n+password requisite pam_pwquality.so try_first_pass local_users_only retry=3 authtok_type=\n+password sufficient pam_unix.so sha512 shadow nullok try_first_pass use_authtok\n+password required pam_deny.so\n+password requisite pam_pwquality.so try_first_pass local_users_only retry=3 authtok_type=\n+password sufficient pam_unix.so sha512 shadow nullok try_first_pass use_authtok\n+password required pam_deny.so\n+password requisite pam_pwquality.so try_first_pass local_users_only retry=3 authtok_type=\n+password sufficient pam_unix.so sha512 shadow nullok try_first_pass use_authtok\n+password required pam_deny.so\n+session optional pam_keyinit.so revoke\n+session required pam_limits.so\n+-session optional pam_systemd.so\n+session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid\n+session required pam_unix.so\n+session [success=1 default=ignore] pam_succeed_if.so service !~ gdm* service !~ su* quiet\n+session [default=1] pam_lastlog.so nowtmp showfailed\n+session optional pam_lastlog.so silent noupdate showfailed\n+session optional pam_keyinit.so revoke\n+session required pam_limits.so\n+-session optional pam_systemd.so\n+session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid\n+session required pam_unix.so\n+session optional pam_keyinit.so revoke\n+session required pam_limits.so\n+-session optional pam_systemd.so\n+session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid\n+session required pam_unix.so\n+session required pam_selinux.so close\n+session required pam_loginuid.so\n+session required pam_selinux.so open env_params\n+session required pam_namespace.so\n+session optional pam_keyinit.so force revoke\n+session optional pam_keyinit.so revoke\n+session required pam_limits.so\n+-session optional pam_systemd.so\n+session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid\n+session required pam_unix.so\n+session [success=1 default=ignore] pam_succeed_if.so service !~ gdm* service !~ su* quiet\n+session [default=1] pam_lastlog.so nowtmp showfailed\n+session optional pam_lastlog.so silent noupdate showfailed\n+-session optional pam_reauthorize.so prepare\n"
            },
            {
              "status": "passed",
              "code_desc": "PAM Config[/etc/pam.d/sshd] lines should include session required pam_lastlog.so showfailed, all without args silent",
              "run_time": 0.001274036,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72247",
          "title": "The system must not permit direct logons to the root account using\nremote access via SSH.",
          "desc": "Even though the communications channel may be encrypted, an additional\nlayer of security is gained by extending the policy of not logging on directly\nas root. In addition, logging on with a user-specific account provides\nindividual accountability of actions performed on the system.",
          "descriptions": [
            {
              "label": "default",
              "data": "Even though the communications channel may be encrypted, an additional\nlayer of security is gained by extending the policy of not logging on directly\nas root. In addition, logging on with a user-specific account provides\nindividual accountability of actions performed on the system."
            },
            {
              "label": "check",
              "data": "Verify remote access using SSH prevents users from logging on\ndirectly as root.\n\nCheck that SSH prevents users from logging on directly as root with the\nfollowing command:\n\n# grep -i permitrootlogin /etc/ssh/sshd_config\nPermitRootLogin no\n\nIf the \"PermitRootLogin\" keyword is set to \"yes\", is missing, or is\ncommented out, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure SSH to stop users from logging on remotely as the root\nuser.\n\nEdit the appropriate  \"/etc/ssh/sshd_config\" file to uncomment or add the\nline for the \"PermitRootLogin\" keyword and set its value to \"no\" (this file\nmay be named differently or be in a different location if using a version of\nSSH that is provided by a third-party vendor):\n\nPermitRootLogin no\n\nThe SSH service must be restarted for changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72247",
            "rid": "SV-86871r2_rule",
            "stig_id": "RHEL-07-040370",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78601r2_fix"
          },
          "code": "control \"V-72247\" do\n  title \"The system must not permit direct logons to the root account using\nremote access via SSH.\"\n  desc  \"Even though the communications channel may be encrypted, an additional\nlayer of security is gained by extending the policy of not logging on directly\nas root. In addition, logging on with a user-specific account provides\nindividual accountability of actions performed on the system.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72247\"\n  tag \"rid\": \"SV-86871r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040370\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": [\"ssh\"]\n  desc \"check\", \"Verify remote access using SSH prevents users from logging on\ndirectly as root.\n\nCheck that SSH prevents users from logging on directly as root with the\nfollowing command:\n\n# grep -i permitrootlogin /etc/ssh/sshd_config\nPermitRootLogin no\n\nIf the \\\"PermitRootLogin\\\" keyword is set to \\\"yes\\\", is missing, or is\ncommented out, this is a finding.\"\n  desc \"fix\", \"Configure SSH to stop users from logging on remotely as the root\nuser.\n\nEdit the appropriate  \\\"/etc/ssh/sshd_config\\\" file to uncomment or add the\nline for the \\\"PermitRootLogin\\\" keyword and set its value to \\\"no\\\" (this file\nmay be named differently or be in a different location if using a version of\nSSH that is provided by a third-party vendor):\n\nPermitRootLogin no\n\nThe SSH service must be restarted for changes to take effect.\"\n  tag \"fix_id\": \"F-78601r2_fix\"\n\n  describe sshd_config do\n    its('PermitRootLogin') { should cmp 'no' }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72247.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "SSHD Configuration PermitRootLogin should cmp == \"no\"",
              "run_time": 0.000652061,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: \"no\"\n     got: nil\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-72249",
          "title": "The SSH daemon must not allow authentication using known hosts\nauthentication.",
          "desc": "Configuring this setting for the SSH daemon provides additional\nassurance that remote logon via SSH will require a password, even in the event\nof misconfiguration elsewhere.",
          "descriptions": [
            {
              "label": "default",
              "data": "Configuring this setting for the SSH daemon provides additional\nassurance that remote logon via SSH will require a password, even in the event\nof misconfiguration elsewhere."
            },
            {
              "label": "check",
              "data": "Verify the SSH daemon does not allow authentication using known\nhosts authentication.\n\nTo determine how the SSH daemon's \"IgnoreUserKnownHosts\" option is set, run\nthe following command:\n\n# grep -i IgnoreUserKnownHosts /etc/ssh/sshd_config\n\nIgnoreUserKnownHosts yes\n\nIf the value is returned as \"no\", the returned line is commented out, or no\noutput is returned, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the SSH daemon to not allow authentication using known\nhosts authentication.\n\nAdd the following line in \"/etc/ssh/sshd_config\", or uncomment the line and\nset the value to \"yes\":\n\nIgnoreUserKnownHosts yes\n\nThe SSH service must be restarted for changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72249",
            "rid": "SV-86873r2_rule",
            "stig_id": "RHEL-07-040380",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78603r2_fix"
          },
          "code": "control \"V-72249\" do\n  title \"The SSH daemon must not allow authentication using known hosts\nauthentication.\"\n  desc  \"Configuring this setting for the SSH daemon provides additional\nassurance that remote logon via SSH will require a password, even in the event\nof misconfiguration elsewhere.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72249\"\n  tag \"rid\": \"SV-86873r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040380\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": [\"ssh\"]\n  desc \"check\", \"Verify the SSH daemon does not allow authentication using known\nhosts authentication.\n\nTo determine how the SSH daemon's \\\"IgnoreUserKnownHosts\\\" option is set, run\nthe following command:\n\n# grep -i IgnoreUserKnownHosts /etc/ssh/sshd_config\n\nIgnoreUserKnownHosts yes\n\nIf the value is returned as \\\"no\\\", the returned line is commented out, or no\noutput is returned, this is a finding.\"\n  desc \"fix\", \"Configure the SSH daemon to not allow authentication using known\nhosts authentication.\n\nAdd the following line in \\\"/etc/ssh/sshd_config\\\", or uncomment the line and\nset the value to \\\"yes\\\":\n\nIgnoreUserKnownHosts yes\n\nThe SSH service must be restarted for changes to take effect.\"\n  tag \"fix_id\": \"F-78603r2_fix\"\n\n  describe sshd_config do\n    its('IgnoreUserKnownHosts') { should cmp 'yes' }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72249.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "SSHD Configuration IgnoreUserKnownHosts should cmp == \"yes\"",
              "run_time": 0.000664721,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: \"yes\"\n     got: nil\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-72251",
          "title": "The SSH daemon must be configured to only use the SSHv2 protocol.",
          "desc": "SSHv1 is an insecure implementation of the SSH protocol and has many\nwell-known vulnerability exploits. Exploits of the SSH daemon could provide\nimmediate root access to the system.",
          "descriptions": [
            {
              "label": "default",
              "data": "SSHv1 is an insecure implementation of the SSH protocol and has many\nwell-known vulnerability exploits. Exploits of the SSH daemon could provide\nimmediate root access to the system."
            },
            {
              "label": "check",
              "data": "Check the version of the operating system with the following\ncommand:\n\n# cat /etc/redhat-release\n\nIf the release is 7.4 or newer this requirement is Not Applicable.\n\nVerify the SSH daemon is configured to only use the SSHv2 protocol.\n\nCheck that the SSH daemon is configured to only use the SSHv2 protocol with the\nfollowing command:\n\n# grep -i protocol /etc/ssh/sshd_config\nProtocol 2\n#Protocol 1,2\n\nIf any protocol line other than \"Protocol 2\" is uncommented, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Remove all Protocol lines that reference version \"1\" in\n\"/etc/ssh/sshd_config\" (this file may be named differently or be in a\ndifferent location if using a version of SSH that is provided by a third-party\nvendor). The \"Protocol\" line must be as follows:\n\nProtocol 2\n\nThe SSH service must be restarted for changes to take effect."
            }
          ],
          "impact": 0,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000074-GPOS-00042",
            "satisfies": [
              "SRG-OS-000074-GPOS-00042",
              "SRG-OS-000480-GPOS-00227"
            ],
            "gid": "V-72251",
            "rid": "SV-86875r3_rule",
            "stig_id": "RHEL-07-040390",
            "cci": [
              "CCI-000197",
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "IA-5 (1) (c)",
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78605r2_fix"
          },
          "code": "control \"V-72251\" do\n  title \"The SSH daemon must be configured to only use the SSHv2 protocol.\"\n  desc  \"SSHv1 is an insecure implementation of the SSH protocol and has many\nwell-known vulnerability exploits. Exploits of the SSH daemon could provide\nimmediate root access to the system.\"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000074-GPOS-00042\"\n  tag \"satisfies\": [\"SRG-OS-000074-GPOS-00042\", \"SRG-OS-000480-GPOS-00227\"]\n  tag \"gid\": \"V-72251\"\n  tag \"rid\": \"SV-86875r3_rule\"\n  tag \"stig_id\": \"RHEL-07-040390\"\n  tag \"cci\": [\"CCI-000197\", \"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-5 (1) (c)\", \"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": [\"ssh\"]\n  desc \"check\", \"Check the version of the operating system with the following\ncommand:\n\n# cat /etc/redhat-release\n\nIf the release is 7.4 or newer this requirement is Not Applicable.\n\nVerify the SSH daemon is configured to only use the SSHv2 protocol.\n\nCheck that the SSH daemon is configured to only use the SSHv2 protocol with the\nfollowing command:\n\n# grep -i protocol /etc/ssh/sshd_config\nProtocol 2\n#Protocol 1,2\n\nIf any protocol line other than \\\"Protocol 2\\\" is uncommented, this is a\nfinding.\"\n  desc \"fix\", \"Remove all Protocol lines that reference version \\\"1\\\" in\n\\\"/etc/ssh/sshd_config\\\" (this file may be named differently or be in a\ndifferent location if using a version of SSH that is provided by a third-party\nvendor). The \\\"Protocol\\\" line must be as follows:\n\nProtocol 2\n\nThe SSH service must be restarted for changes to take effect.\"\n  tag \"fix_id\": \"F-78605r2_fix\"\n\n  if os.release.to_f >= 7.4\n    impact 0.0\n    describe \"The release is #{os.release}\" do\n      skip \"The release is newer than 7.4; this control is Not Applicable.\"\n    end\n  else\n    describe sshd_config do\n      its('Protocol') { should cmp '2' }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72251.rb"
          },
          "results": [
            {
              "status": "skipped",
              "code_desc": "The release is 7.6.1810",
              "run_time": 7.273e-06,
              "start_time": "2019-11-04T16:17:15-05:00",
              "resource": "",
              "skip_message": "The release is newer than 7.4; this control is Not Applicable."
            }
          ]
        },
        {
          "id": "V-72253",
          "title": "The SSH daemon must be configured to only use Message Authentication\nCodes (MACs) employing FIPS 140-2 approved cryptographic hash algorithms.",
          "desc": "DoD information systems are required to use FIPS 140-2 approved\ncryptographic hash functions. The only SSHv2 hash algorithm meeting this\nrequirement is SHA.",
          "descriptions": [
            {
              "label": "default",
              "data": "DoD information systems are required to use FIPS 140-2 approved\ncryptographic hash functions. The only SSHv2 hash algorithm meeting this\nrequirement is SHA."
            },
            {
              "label": "check",
              "data": "Verify the SSH daemon is configured to only use MACs employing\nFIPS 140-2-approved ciphers.\n\nNote: If RHEL-07-021350 is a finding, this is automatically a finding as the\nsystem cannot implement FIPS 140-2-approved cryptographic algorithms and hashes.\n\nCheck that the SSH daemon is configured to only use MACs employing FIPS\n140-2-approved ciphers with the following command:\n\n# grep -i macs /etc/ssh/sshd_config\nMACs hmac-sha2-256,hmac-sha2-512\n\nIf any ciphers other than \"hmac-sha2-256\" or \"hmac-sha2-512\" are listed or\nthe retuned line is commented out, this is a finding."
            },
            {
              "label": "fix",
              "data": "Edit the \"/etc/ssh/sshd_config\" file to uncomment or add the\nline for the \"MACs\" keyword and set its value to \"hmac-sha2-256\" and/or\n\"hmac-sha2-512\" (this file may be named differently or be in a different\nlocation if using a version of SSH that is provided by a third-party vendor):\n\nMACs hmac-sha2-256,hmac-sha2-512\n\nThe SSH service must be restarted for changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000250-GPOS-00093",
            "gid": "V-72253",
            "rid": "SV-86877r2_rule",
            "stig_id": "RHEL-07-040400",
            "cci": [
              "CCI-001453"
            ],
            "documentable": false,
            "nist": [
              "AC-17 (2)",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78607r2_fix"
          },
          "code": "control \"V-72253\" do\n  title \"The SSH daemon must be configured to only use Message Authentication\nCodes (MACs) employing FIPS 140-2 approved cryptographic hash algorithms.\"\n  desc  \"DoD information systems are required to use FIPS 140-2 approved\ncryptographic hash functions. The only SSHv2 hash algorithm meeting this\nrequirement is SHA.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000250-GPOS-00093\"\n  tag \"gid\": \"V-72253\"\n  tag \"rid\": \"SV-86877r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040400\"\n  tag \"cci\": [\"CCI-001453\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-17 (2)\", \"Rev_4\"]\n  tag \"subsystems\": [\"ssh\"]\n  tag \"fix_id\": \"F-78607r2_fix\"\n  desc \"check\", \"Verify the SSH daemon is configured to only use MACs employing\nFIPS 140-2-approved ciphers.\n\nNote: If RHEL-07-021350 is a finding, this is automatically a finding as the\nsystem cannot implement FIPS 140-2-approved cryptographic algorithms and hashes.\n\nCheck that the SSH daemon is configured to only use MACs employing FIPS\n140-2-approved ciphers with the following command:\n\n# grep -i macs /etc/ssh/sshd_config\nMACs hmac-sha2-256,hmac-sha2-512\n\nIf any ciphers other than \\\"hmac-sha2-256\\\" or \\\"hmac-sha2-512\\\" are listed or\nthe retuned line is commented out, this is a finding.\"\n  desc \"fix\", \"Edit the \\\"/etc/ssh/sshd_config\\\" file to uncomment or add the\nline for the \\\"MACs\\\" keyword and set its value to \\\"hmac-sha2-256\\\" and/or\n\\\"hmac-sha2-512\\\" (this file may be named differently or be in a different\nlocation if using a version of SSH that is provided by a third-party vendor):\n\nMACs hmac-sha2-256,hmac-sha2-512\n\nThe SSH service must be restarted for changes to take effect.\"\n\n  @macs = inspec.sshd_config.params(\"macs\")\n  if @macs.nil?\n    # fail fast\n    describe 'The `sshd_config` setting for `MACs`' do\n    subject { @macs }\n      it 'should be explicitly set and not commented out' do\n        expect(subject).not_to be_nil\n      end\n    end\n  else  \n    @macs.first.split(\",\").each do |mac|\n      describe mac do\n        it { should be_in ['hmac-sha2-256', 'hmac-sha2-512'] }\n      end\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72253.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "The `sshd_config` setting for `MACs` should be explicitly set and not commented out",
              "run_time": 0.000119149,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected: not nil\n     got: nil"
            }
          ]
        },
        {
          "id": "V-72255",
          "title": "The SSH public host key files must have mode 0644 or less permissive.",
          "desc": "If a public host key file is modified by an unauthorized user, the SSH\nservice may be compromised.",
          "descriptions": [
            {
              "label": "default",
              "data": "If a public host key file is modified by an unauthorized user, the SSH\nservice may be compromised."
            },
            {
              "label": "check",
              "data": "Verify the SSH public host key files have mode \"0644\" or less\npermissive.\n\nNote: SSH public key files may be found in other directories on the system\ndepending on the installation.\n\nThe following command will find all SSH public key files on the system:\n\n# find /etc/ssh -name '*.pub' -exec ls -lL {} \\;\n\n-rw-r--r--  1 root  wheel  618 Nov 28 06:43 ssh_host_dsa_key.pub\n-rw-r--r--  1 root  wheel  347 Nov 28 06:43 ssh_host_key.pub\n-rw-r--r--  1 root  wheel  238 Nov 28 06:43 ssh_host_rsa_key.pub\n\nIf any file has a mode more permissive than \"0644\", this is a finding."
            },
            {
              "label": "fix",
              "data": "Note: SSH public key files may be found in other directories on\nthe system depending on the installation.\n\nChange the mode of public host key files under \"/etc/ssh\" to \"0644\" with\nthe following command:\n\n# chmod 0644 /etc/ssh/*.key.pub"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72255",
            "rid": "SV-86879r1_rule",
            "stig_id": "RHEL-07-040410",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78609r1_fix"
          },
          "code": "control \"V-72255\" do\n  title \"The SSH public host key files must have mode 0644 or less permissive.\"\n  desc  \"If a public host key file is modified by an unauthorized user, the SSH\nservice may be compromised.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72255\"\n  tag \"rid\": \"SV-86879r1_rule\"\n  tag \"stig_id\": \"RHEL-07-040410\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": [\"ssh\"]\n  desc \"check\", \"Verify the SSH public host key files have mode \\\"0644\\\" or less\npermissive.\n\nNote: SSH public key files may be found in other directories on the system\ndepending on the installation.\n\nThe following command will find all SSH public key files on the system:\n\n# find /etc/ssh -name '*.pub' -exec ls -lL {} \\\\;\n\n-rw-r--r--  1 root  wheel  618 Nov 28 06:43 ssh_host_dsa_key.pub\n-rw-r--r--  1 root  wheel  347 Nov 28 06:43 ssh_host_key.pub\n-rw-r--r--  1 root  wheel  238 Nov 28 06:43 ssh_host_rsa_key.pub\n\nIf any file has a mode more permissive than \\\"0644\\\", this is a finding.\"\n  desc \"fix\", \"Note: SSH public key files may be found in other directories on\nthe system depending on the installation.\n\nChange the mode of public host key files under \\\"/etc/ssh\\\" to \\\"0644\\\" with\nthe following command:\n\n# chmod 0644 /etc/ssh/*.key.pub\"\n  tag \"fix_id\": \"F-78609r1_fix\"\n\n  pub_files = command(\"find /etc/ssh -xdev -name '*.pub' -perm /133\").stdout.split(\"\\n\")\n  if !pub_files.nil? and !pub_files.empty?\n    pub_files.each do |pubfile|\n      describe file(pubfile) do\n        it { should_not be_executable.by('owner') }\n        it { should_not be_executable.by('group') }\n        it { should_not be_writable.by('group') }\n        it { should_not be_executable.by('others') }\n        it { should_not be_writable.by('others') }\n      end\n    end\n  else\n     describe \"No files have a more permissive mode.\" do\n      subject { pub_files.nil? or pub_files.empty? }\n      it { should eq true }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72255.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "No files have a more permissive mode. should eq true",
              "run_time": 9.574e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72257",
          "title": "The SSH private host key files must have mode 0600 or less permissive.",
          "desc": "If an unauthorized user obtains the private SSH host key file, the\nhost could be impersonated.",
          "descriptions": [
            {
              "label": "default",
              "data": "If an unauthorized user obtains the private SSH host key file, the\nhost could be impersonated."
            },
            {
              "label": "check",
              "data": "Verify the SSH private host key files have mode \"0600\" or\nless permissive.\n\nThe following command will find all SSH private key files on the system:\n\n# find / -name '*ssh_host*key'\n\nCheck the mode of the private host key files under \"/etc/ssh\" file with the\nfollowing command:\n\n# ls -lL /etc/ssh/*key\n-rw-------  1 root  wheel  668 Nov 28 06:43 ssh_host_dsa_key\n-rw-------  1 root  wheel  582 Nov 28 06:43 ssh_host_key\n-rw-------  1 root  wheel  887 Nov 28 06:43 ssh_host_rsa_key\n\nIf any file has a mode more permissive than \"0600\", this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the mode of SSH private host key files under\n\"/etc/ssh\" to \"0600\" with the following command:\n\n# chmod 0600 /etc/ssh/ssh_host*key"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72257",
            "rid": "SV-86881r1_rule",
            "stig_id": "RHEL-07-040420",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78611r3_fix"
          },
          "code": "control \"V-72257\" do\n  title \"The SSH private host key files must have mode 0600 or less permissive.\"\n  desc  \"If an unauthorized user obtains the private SSH host key file, the\nhost could be impersonated.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72257\"\n  tag \"rid\": \"SV-86881r1_rule\"\n  tag \"stig_id\": \"RHEL-07-040420\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": [\"ssh\"]\n  desc \"check\", \"Verify the SSH private host key files have mode \\\"0600\\\" or\nless permissive.\n\nThe following command will find all SSH private key files on the system:\n\n# find / -name '*ssh_host*key'\n\nCheck the mode of the private host key files under \\\"/etc/ssh\\\" file with the\nfollowing command:\n\n# ls -lL /etc/ssh/*key\n-rw-------  1 root  wheel  668 Nov 28 06:43 ssh_host_dsa_key\n-rw-------  1 root  wheel  582 Nov 28 06:43 ssh_host_key\n-rw-------  1 root  wheel  887 Nov 28 06:43 ssh_host_rsa_key\n\nIf any file has a mode more permissive than \\\"0600\\\", this is a finding.\"\n  desc \"fix\", \"Configure the mode of SSH private host key files under\n\\\"/etc/ssh\\\" to \\\"0600\\\" with the following command:\n\n# chmod 0600 /etc/ssh/ssh_host*key\"\n  tag \"fix_id\": \"F-78611r3_fix\"\n\n  key_files = command(\"find /etc/ssh -xdev -name '*ssh_host*key' -perm /177\").stdout.split(\"\\n\")\n  if !key_files.nil? and !key_files.empty?\n    key_files.each do |keyfile|\n      describe file(keyfile) do\n        it { should_not be_executable.by('owner') }\n        it { should_not be_readable.by('group') }\n        it { should_not be_writable.by('group') }\n        it { should_not be_executable.by('group') }\n        it { should_not be_readable.by('others') }\n        it { should_not be_writable.by('others') }\n        it { should_not be_executable.by('others') }\n      end\n    end\n  else\n    describe \"No files have a more permissive mode.\" do\n      subject { key_files.nil? or key_files.empty? }\n      it { should eq true }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72257.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "File /etc/ssh/ssh_host_rsa_key should not be executable by owner",
              "run_time": 0.017312555,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "File /etc/ssh/ssh_host_rsa_key should not be readable by group",
              "run_time": 0.000292867,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected File /etc/ssh/ssh_host_rsa_key not to be readable by group"
            },
            {
              "status": "passed",
              "code_desc": "File /etc/ssh/ssh_host_rsa_key should not be writable by group",
              "run_time": 0.000203271,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /etc/ssh/ssh_host_rsa_key should not be executable by group",
              "run_time": 9.1289e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /etc/ssh/ssh_host_rsa_key should not be readable by others",
              "run_time": 8.2061e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /etc/ssh/ssh_host_rsa_key should not be writable by others",
              "run_time": 8.1525e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /etc/ssh/ssh_host_rsa_key should not be executable by others",
              "run_time": 8.0982e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /etc/ssh/ssh_host_ecdsa_key should not be executable by owner",
              "run_time": 0.015725523,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "File /etc/ssh/ssh_host_ecdsa_key should not be readable by group",
              "run_time": 0.000277524,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected File /etc/ssh/ssh_host_ecdsa_key not to be readable by group"
            },
            {
              "status": "passed",
              "code_desc": "File /etc/ssh/ssh_host_ecdsa_key should not be writable by group",
              "run_time": 9.925e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /etc/ssh/ssh_host_ecdsa_key should not be executable by group",
              "run_time": 8.7982e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /etc/ssh/ssh_host_ecdsa_key should not be readable by others",
              "run_time": 7.6695e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /etc/ssh/ssh_host_ecdsa_key should not be writable by others",
              "run_time": 8.0655e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /etc/ssh/ssh_host_ecdsa_key should not be executable by others",
              "run_time": 7.7604e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /etc/ssh/ssh_host_ed25519_key should not be executable by owner",
              "run_time": 0.016119804,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "File /etc/ssh/ssh_host_ed25519_key should not be readable by group",
              "run_time": 0.000288628,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected File /etc/ssh/ssh_host_ed25519_key not to be readable by group"
            },
            {
              "status": "passed",
              "code_desc": "File /etc/ssh/ssh_host_ed25519_key should not be writable by group",
              "run_time": 0.000104368,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /etc/ssh/ssh_host_ed25519_key should not be executable by group",
              "run_time": 9.0792e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /etc/ssh/ssh_host_ed25519_key should not be readable by others",
              "run_time": 8.2362e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /etc/ssh/ssh_host_ed25519_key should not be writable by others",
              "run_time": 7.5973e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "File /etc/ssh/ssh_host_ed25519_key should not be executable by others",
              "run_time": 7.9997e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72259",
          "title": "The SSH daemon must not permit Generic Security Service Application\nProgram Interface (GSSAPI) authentication unless needed.",
          "desc": "GSSAPI authentication is used to provide additional authentication\nmechanisms to applications. Allowing GSSAPI authentication through SSH exposes\nthe system’s GSSAPI to remote hosts, increasing the attack surface of the\nsystem. GSSAPI authentication must be disabled unless needed.",
          "descriptions": [
            {
              "label": "default",
              "data": "GSSAPI authentication is used to provide additional authentication\nmechanisms to applications. Allowing GSSAPI authentication through SSH exposes\nthe system’s GSSAPI to remote hosts, increasing the attack surface of the\nsystem. GSSAPI authentication must be disabled unless needed."
            },
            {
              "label": "check",
              "data": "Verify the SSH daemon does not permit GSSAPI authentication\nunless approved.\n\nCheck that the SSH daemon does not permit GSSAPI authentication with the\nfollowing command:\n\n# grep -i gssapiauth /etc/ssh/sshd_config\nGSSAPIAuthentication no\n\nIf the \"GSSAPIAuthentication\" keyword is missing, is set to \"yes\" and is\nnot documented with the Information System Security Officer (ISSO), or the\nreturned line is commented out, this is a finding."
            },
            {
              "label": "fix",
              "data": "Uncomment the \"GSSAPIAuthentication\" keyword in\n\"/etc/ssh/sshd_config\" (this file may be named differently or be in a\ndifferent location if using a version of SSH that is provided by a third-party\nvendor) and set the value to \"no\":\n\nGSSAPIAuthentication no\n\nThe SSH service must be restarted for changes to take effect.\n\nIf GSSAPI authentication is required, it must be documented, to include the\nlocation of the configuration file, with the ISSO."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000364-GPOS-00151",
            "gid": "V-72259",
            "rid": "SV-86883r2_rule",
            "stig_id": "RHEL-07-040430",
            "cci": [
              "CCI-000318",
              "CCI-000368",
              "CCI-001812",
              "CCI-001813",
              "CCI-001814"
            ],
            "documentable": false,
            "nist": [
              "CM-3 f",
              "CM-6 c",
              "CM-11 (2)",
              "CM-5 (1)",
              "CM-5 (1)",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78613r2_fix"
          },
          "code": "control \"V-72259\" do\n  title \"The SSH daemon must not permit Generic Security Service Application\nProgram Interface (GSSAPI) authentication unless needed.\"\n  desc  \"GSSAPI authentication is used to provide additional authentication\nmechanisms to applications. Allowing GSSAPI authentication through SSH exposes\nthe system’s GSSAPI to remote hosts, increasing the attack surface of the\nsystem. GSSAPI authentication must be disabled unless needed.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000364-GPOS-00151\"\n  tag \"gid\": \"V-72259\"\n  tag \"rid\": \"SV-86883r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040430\"\n  tag \"cci\": [\"CCI-000318\", \"CCI-000368\", \"CCI-001812\", \"CCI-001813\",\n\"CCI-001814\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-3 f\", \"CM-6 c\", \"CM-11 (2)\", \"CM-5 (1)\", \"CM-5 (1)\", \"Rev_4\"]\n  tag \"subsystems\": [\"ssh\"]\n  desc \"check\", \"Verify the SSH daemon does not permit GSSAPI authentication\nunless approved.\n\nCheck that the SSH daemon does not permit GSSAPI authentication with the\nfollowing command:\n\n# grep -i gssapiauth /etc/ssh/sshd_config\nGSSAPIAuthentication no\n\nIf the \\\"GSSAPIAuthentication\\\" keyword is missing, is set to \\\"yes\\\" and is\nnot documented with the Information System Security Officer (ISSO), or the\nreturned line is commented out, this is a finding.\"\n  desc \"fix\", \"Uncomment the \\\"GSSAPIAuthentication\\\" keyword in\n\\\"/etc/ssh/sshd_config\\\" (this file may be named differently or be in a\ndifferent location if using a version of SSH that is provided by a third-party\nvendor) and set the value to \\\"no\\\":\n\nGSSAPIAuthentication no\n\nThe SSH service must be restarted for changes to take effect.\n\nIf GSSAPI authentication is required, it must be documented, to include the\nlocation of the configuration file, with the ISSO.\"\n  tag \"fix_id\": \"F-78613r2_fix\"\n\n  describe sshd_config do\n    its('GSSAPIAuthentication') { should cmp 'no' }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72259.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "SSHD Configuration GSSAPIAuthentication should cmp == \"no\"",
              "run_time": 0.000524605,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: \"no\"\n     got: \"yes\"\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-72261",
          "title": "The SSH daemon must not permit Kerberos authentication unless needed.",
          "desc": "Kerberos authentication for SSH is often implemented using Generic\nSecurity Service Application Program Interface (GSSAPI). If Kerberos is enabled\nthrough SSH, the SSH daemon provides a means of access to the system's Kerberos\nimplementation. Vulnerabilities in the system's Kerberos implementation may\nthen be subject to exploitation. To reduce the attack surface of the system,\nthe Kerberos authentication mechanism within SSH must be disabled for systems\nnot using this capability.",
          "descriptions": [
            {
              "label": "default",
              "data": "Kerberos authentication for SSH is often implemented using Generic\nSecurity Service Application Program Interface (GSSAPI). If Kerberos is enabled\nthrough SSH, the SSH daemon provides a means of access to the system's Kerberos\nimplementation. Vulnerabilities in the system's Kerberos implementation may\nthen be subject to exploitation. To reduce the attack surface of the system,\nthe Kerberos authentication mechanism within SSH must be disabled for systems\nnot using this capability."
            },
            {
              "label": "check",
              "data": "Verify the SSH daemon does not permit Kerberos to authenticate\npasswords unless approved.\n\nCheck that the SSH daemon does not permit Kerberos to authenticate passwords\nwith the following command:\n\n# grep -i kerberosauth /etc/ssh/sshd_config\nKerberosAuthentication no\n\nIf the \"KerberosAuthentication\" keyword is missing, or is set to \"yes\" and\nis not documented with the Information System Security Officer (ISSO), or the\nreturned line is commented out, this is a finding."
            },
            {
              "label": "fix",
              "data": "Uncomment the \"KerberosAuthentication\" keyword in\n\"/etc/ssh/sshd_config\" (this file may be named differently or be in a\ndifferent location if using a version of SSH that is provided by a third-party\nvendor) and set the value to \"no\":\n\nKerberosAuthentication no\n\nThe SSH service must be restarted for changes to take effect.\n\nIf Kerberos authentication is required, it must be documented, to include the\nlocation of the configuration file, with the ISSO."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000364-GPOS-00151",
            "gid": "V-72261",
            "rid": "SV-86885r2_rule",
            "stig_id": "RHEL-07-040440",
            "cci": [
              "CCI-000318",
              "CCI-000368",
              "CCI-001812",
              "CCI-001813",
              "CCI-001814"
            ],
            "documentable": false,
            "nist": [
              "CM-3 f",
              "CM-6 c",
              "CM-11 (2)",
              "CM-5 (1)",
              "CM-5 (1)",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78615r2_fix"
          },
          "code": "control \"V-72261\" do\n  title \"The SSH daemon must not permit Kerberos authentication unless needed.\"\n  desc  \"Kerberos authentication for SSH is often implemented using Generic\nSecurity Service Application Program Interface (GSSAPI). If Kerberos is enabled\nthrough SSH, the SSH daemon provides a means of access to the system's Kerberos\nimplementation. Vulnerabilities in the system's Kerberos implementation may\nthen be subject to exploitation. To reduce the attack surface of the system,\nthe Kerberos authentication mechanism within SSH must be disabled for systems\nnot using this capability.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000364-GPOS-00151\"\n  tag \"gid\": \"V-72261\"\n  tag \"rid\": \"SV-86885r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040440\"\n  tag \"cci\": [\"CCI-000318\", \"CCI-000368\", \"CCI-001812\", \"CCI-001813\",\n\"CCI-001814\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-3 f\", \"CM-6 c\", \"CM-11 (2)\", \"CM-5 (1)\", \"CM-5 (1)\", \"Rev_4\"]\n  tag \"subsystems\": [\"ssh\"]\n  desc \"check\", \"Verify the SSH daemon does not permit Kerberos to authenticate\npasswords unless approved.\n\nCheck that the SSH daemon does not permit Kerberos to authenticate passwords\nwith the following command:\n\n# grep -i kerberosauth /etc/ssh/sshd_config\nKerberosAuthentication no\n\nIf the \\\"KerberosAuthentication\\\" keyword is missing, or is set to \\\"yes\\\" and\nis not documented with the Information System Security Officer (ISSO), or the\nreturned line is commented out, this is a finding.\"\n  desc \"fix\", \"Uncomment the \\\"KerberosAuthentication\\\" keyword in\n\\\"/etc/ssh/sshd_config\\\" (this file may be named differently or be in a\ndifferent location if using a version of SSH that is provided by a third-party\nvendor) and set the value to \\\"no\\\":\n\nKerberosAuthentication no\n\nThe SSH service must be restarted for changes to take effect.\n\nIf Kerberos authentication is required, it must be documented, to include the\nlocation of the configuration file, with the ISSO.\"\n  tag \"fix_id\": \"F-78615r2_fix\"\n\n  describe sshd_config do\n    its('KerberosAuthentication') { should cmp 'no' }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72261.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "SSHD Configuration KerberosAuthentication should cmp == \"no\"",
              "run_time": 0.000570244,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: \"no\"\n     got: nil\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-72263",
          "title": "The SSH daemon must perform strict mode checking of home directory\nconfiguration files.",
          "desc": "If other users have access to modify user-specific SSH configuration\nfiles, they may be able to log on to the system as another user.",
          "descriptions": [
            {
              "label": "default",
              "data": "If other users have access to modify user-specific SSH configuration\nfiles, they may be able to log on to the system as another user."
            },
            {
              "label": "check",
              "data": "Verify the SSH daemon performs strict mode checking of home\ndirectory configuration files.\n\nThe location of the \"sshd_config\" file may vary if a different daemon is in\nuse.\n\nInspect the \"sshd_config\" file with the following command:\n\n# grep -i strictmodes /etc/ssh/sshd_config\n\nStrictModes yes\n\nIf \"StrictModes\" is set to \"no\", is missing, or the returned line is\ncommented out, this is a finding."
            },
            {
              "label": "fix",
              "data": "Uncomment the \"StrictModes\" keyword in \"/etc/ssh/sshd_config\"\n(this file may be named differently or be in a different location if using a\nversion of SSH that is provided by a third-party vendor) and set the value to\n\"yes\":\n\nStrictModes yes\n\nThe SSH service must be restarted for changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72263",
            "rid": "SV-86887r2_rule",
            "stig_id": "RHEL-07-040450",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78617r4_fix"
          },
          "code": "control \"V-72263\" do\n  title \"The SSH daemon must perform strict mode checking of home directory\nconfiguration files.\"\n  desc  \"If other users have access to modify user-specific SSH configuration\nfiles, they may be able to log on to the system as another user.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72263\"\n  tag \"rid\": \"SV-86887r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040450\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": [\"ssh\"]\n  desc \"check\", \"Verify the SSH daemon performs strict mode checking of home\ndirectory configuration files.\n\nThe location of the \\\"sshd_config\\\" file may vary if a different daemon is in\nuse.\n\nInspect the \\\"sshd_config\\\" file with the following command:\n\n# grep -i strictmodes /etc/ssh/sshd_config\n\nStrictModes yes\n\nIf \\\"StrictModes\\\" is set to \\\"no\\\", is missing, or the returned line is\ncommented out, this is a finding.\"\n  desc \"fix\", \"Uncomment the \\\"StrictModes\\\" keyword in \\\"/etc/ssh/sshd_config\\\"\n(this file may be named differently or be in a different location if using a\nversion of SSH that is provided by a third-party vendor) and set the value to\n\\\"yes\\\":\n\nStrictModes yes\n\nThe SSH service must be restarted for changes to take effect.\"\n  tag \"fix_id\": \"F-78617r4_fix\"\n\n  describe sshd_config do\n    its('StrictModes') { should cmp 'yes' }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72263.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "SSHD Configuration StrictModes should cmp == \"yes\"",
              "run_time": 0.000584965,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: \"yes\"\n     got: nil\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-72265",
          "title": "The SSH daemon must use privilege separation.",
          "desc": "SSH daemon privilege separation causes the SSH process to drop root\nprivileges when not needed, which would decrease the impact of software\nvulnerabilities in the unprivileged section.",
          "descriptions": [
            {
              "label": "default",
              "data": "SSH daemon privilege separation causes the SSH process to drop root\nprivileges when not needed, which would decrease the impact of software\nvulnerabilities in the unprivileged section."
            },
            {
              "label": "check",
              "data": "Verify the SSH daemon performs privilege separation.\n\nCheck that the SSH daemon performs privilege separation with the following\ncommand:\n\n# grep -i usepriv /etc/ssh/sshd_config\n\nUsePrivilegeSeparation sandbox\n\nIf the \"UsePrivilegeSeparation\" keyword is set to \"no\", is missing, or the\nretuned line is commented out, this is a finding."
            },
            {
              "label": "fix",
              "data": "Uncomment the \"UsePrivilegeSeparation\" keyword in\n\"/etc/ssh/sshd_config\" (this file may be named differently or be in a\ndifferent location if using a version of SSH that is provided by a third-party\nvendor) and set the value to \"sandbox\" or \"yes\":\n\nUsePrivilegeSeparation sandbox\n\nThe SSH service must be restarted for changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72265",
            "rid": "SV-86889r2_rule",
            "stig_id": "RHEL-07-040460",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78619r2_fix"
          },
          "code": "control \"V-72265\" do\n  title \"The SSH daemon must use privilege separation.\"\n  desc  \"SSH daemon privilege separation causes the SSH process to drop root\nprivileges when not needed, which would decrease the impact of software\nvulnerabilities in the unprivileged section.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72265\"\n  tag \"rid\": \"SV-86889r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040460\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": [\"ssh\"]\n  desc \"check\", \"Verify the SSH daemon performs privilege separation.\n\nCheck that the SSH daemon performs privilege separation with the following\ncommand:\n\n# grep -i usepriv /etc/ssh/sshd_config\n\nUsePrivilegeSeparation sandbox\n\nIf the \\\"UsePrivilegeSeparation\\\" keyword is set to \\\"no\\\", is missing, or the\nretuned line is commented out, this is a finding.\"\n  desc \"fix\", \"Uncomment the \\\"UsePrivilegeSeparation\\\" keyword in\n\\\"/etc/ssh/sshd_config\\\" (this file may be named differently or be in a\ndifferent location if using a version of SSH that is provided by a third-party\nvendor) and set the value to \\\"sandbox\\\" or \\\"yes\\\":\n\nUsePrivilegeSeparation sandbox\n\nThe SSH service must be restarted for changes to take effect.\"\n  tag \"fix_id\": \"F-78619r2_fix\"\n\n  describe.one do\n    describe sshd_config do\n      its('UsePrivilegeSeparation') { should cmp 'sandbox' }\n    end\n    describe sshd_config do\n      its('UsePrivilegeSeparation') { should cmp 'yes' }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72265.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "SSHD Configuration UsePrivilegeSeparation should cmp == \"sandbox\"",
              "run_time": 0.000215023,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: \"sandbox\"\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "SSHD Configuration UsePrivilegeSeparation should cmp == \"yes\"",
              "run_time": 0.000128831,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: \"yes\"\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            }
          ]
        },
        {
          "id": "V-72267",
          "title": "The SSH daemon must not allow compression or must only allow\ncompression after successful authentication.",
          "desc": "If compression is allowed in an SSH connection prior to\nauthentication, vulnerabilities in the compression software could result in\ncompromise of the system from an unauthenticated connection, potentially with\nroot privileges.",
          "descriptions": [
            {
              "label": "default",
              "data": "If compression is allowed in an SSH connection prior to\nauthentication, vulnerabilities in the compression software could result in\ncompromise of the system from an unauthenticated connection, potentially with\nroot privileges."
            },
            {
              "label": "check",
              "data": "Verify the SSH daemon performs compression after a user\nsuccessfully authenticates.\n\nCheck that the SSH daemon performs compression after a user successfully\nauthenticates with the following command:\n\n# grep -i compression /etc/ssh/sshd_config\nCompression delayed\n\nIf the \"Compression\" keyword is set to \"yes\", is missing, or the retuned\nline is commented out, this is a finding."
            },
            {
              "label": "fix",
              "data": "Uncomment the \"Compression\" keyword in \"/etc/ssh/sshd_config\"\n(this file may be named differently or be in a different location if using a\nversion of SSH that is provided by a third-party vendor) on the system and set\nthe value to \"delayed\" or \"no\":\n\nCompression no\n\nThe SSH service must be restarted for changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72267",
            "rid": "SV-86891r2_rule",
            "stig_id": "RHEL-07-040470",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78621r2_fix"
          },
          "code": "control \"V-72267\" do\n  title \"The SSH daemon must not allow compression or must only allow\ncompression after successful authentication.\"\n  desc  \"If compression is allowed in an SSH connection prior to\nauthentication, vulnerabilities in the compression software could result in\ncompromise of the system from an unauthenticated connection, potentially with\nroot privileges.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72267\"\n  tag \"rid\": \"SV-86891r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040470\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": [\"ssh\"]\n  desc \"check\", \"Verify the SSH daemon performs compression after a user\nsuccessfully authenticates.\n\nCheck that the SSH daemon performs compression after a user successfully\nauthenticates with the following command:\n\n# grep -i compression /etc/ssh/sshd_config\nCompression delayed\n\nIf the \\\"Compression\\\" keyword is set to \\\"yes\\\", is missing, or the retuned\nline is commented out, this is a finding.\"\n  desc \"fix\", \"Uncomment the \\\"Compression\\\" keyword in \\\"/etc/ssh/sshd_config\\\"\n(this file may be named differently or be in a different location if using a\nversion of SSH that is provided by a third-party vendor) on the system and set\nthe value to \\\"delayed\\\" or \\\"no\\\":\n\nCompression no\n\nThe SSH service must be restarted for changes to take effect.\"\n  tag \"fix_id\": \"F-78621r2_fix\"\n\n  describe.one do\n    describe sshd_config do\n      its('Compression') { should cmp 'delayed' }\n    end\n    describe sshd_config do\n      its('Compression') { should cmp 'no' }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72267.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "SSHD Configuration Compression should cmp == \"delayed\"",
              "run_time": 0.000128616,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: \"delayed\"\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "SSHD Configuration Compression should cmp == \"no\"",
              "run_time": 0.000123594,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: \"no\"\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            }
          ]
        },
        {
          "id": "V-72269",
          "title": "The operating system must, for networked systems, synchronize clocks\nwith a server that is synchronized to one of the redundant United States Naval\nObservatory (USNO) time servers, a time server designated for the appropriate\nDoD network (NIPRNet/SIPRNet), and/or the Global Positioning System (GPS).",
          "desc": "Inaccurate time stamps make it more difficult to correlate events and can\nlead to an inaccurate analysis. Determining the correct time a particular event\noccurred on a system is critical when conducting forensic analysis and\ninvestigating system events. Sources outside the configured acceptable\nallowance (drift) may be inaccurate.\n\n    Synchronizing internal information system clocks provides uniformity of\ntime stamps for information systems with multiple system clocks and systems\nconnected over a network.\n\n    Organizations should consider endpoints that may not have regular access to\nthe authoritative time server (e.g., mobile, teleworking, and tactical\nendpoints).",
          "descriptions": [
            {
              "label": "default",
              "data": "Inaccurate time stamps make it more difficult to correlate events and can\nlead to an inaccurate analysis. Determining the correct time a particular event\noccurred on a system is critical when conducting forensic analysis and\ninvestigating system events. Sources outside the configured acceptable\nallowance (drift) may be inaccurate.\n\n    Synchronizing internal information system clocks provides uniformity of\ntime stamps for information systems with multiple system clocks and systems\nconnected over a network.\n\n    Organizations should consider endpoints that may not have regular access to\nthe authoritative time server (e.g., mobile, teleworking, and tactical\nendpoints)."
            },
            {
              "label": "check",
              "data": "Check to see if NTP is running in continuous mode.\n\n  # ps -ef | grep ntp\n\n  If NTP is not running, this is a finding.\n\n  If the process is found, then check the \"ntp.conf\" file for the \"maxpoll\"\n  option setting:\n\n  # grep maxpoll /etc/ntp.conf\n\n  maxpoll 17\n\n  If the option is set to \"17\" or is not set, this is a finding.\n\n  If the file does not exist, check the \"/etc/cron.daily\" subdirectory for a\n  crontab file controlling the execution of the \"ntpdate\" command.\n\n  # grep –l ntpdate /etc/cron.daily\n\n  # ls -al /etc/cron.* | grep ntp\n  ntp\n\n  If a crontab file does not exist in the \"/etc/cron.daily\" that executes the\n  \"ntpdate\" file, this is a finding."
            },
            {
              "label": "fix",
              "data": "Edit the \"/etc/ntp.conf\" file and add or update an entry to\n  define \"maxpoll\" to \"10\" as follows:\n\n  maxpoll 10\n\n  If NTP was running and \"maxpoll\" was updated, the NTP service must be\n  restarted:\n\n  # systemctl restart ntpd\n\n  If NTP was not running, it must be started:\n\n  # systemctl start ntpd"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000355-GPOS-00143",
            "satisfies": [
              "SRG-OS-000355-GPOS-00143",
              "SRG-OS-000356-GPOS-00144"
            ],
            "gid": "V-72269",
            "rid": "SV-86893r2_rule",
            "stig_id": "RHEL-07-040500",
            "cci": [
              "CCI-001891",
              "CCI-002046"
            ],
            "documentable": false,
            "subsystems": [
              "ntp"
            ],
            "nist": [
              "AU-8 (1) (a)",
              "AU-8 (1) (b)",
              "Rev_4"
            ],
            "fix_id": "F-78623r3_fix"
          },
          "code": "control \"V-72269\" do\n  title \"The operating system must, for networked systems, synchronize clocks\nwith a server that is synchronized to one of the redundant United States Naval\nObservatory (USNO) time servers, a time server designated for the appropriate\nDoD network (NIPRNet/SIPRNet), and/or the Global Positioning System (GPS).\"\n  desc  \"\n    Inaccurate time stamps make it more difficult to correlate events and can\nlead to an inaccurate analysis. Determining the correct time a particular event\noccurred on a system is critical when conducting forensic analysis and\ninvestigating system events. Sources outside the configured acceptable\nallowance (drift) may be inaccurate.\n\n    Synchronizing internal information system clocks provides uniformity of\ntime stamps for information systems with multiple system clocks and systems\nconnected over a network.\n\n    Organizations should consider endpoints that may not have regular access to\nthe authoritative time server (e.g., mobile, teleworking, and tactical\nendpoints).\n  \"\n  impact 0.5\n  \n  tag \"gtitle\": \"SRG-OS-000355-GPOS-00143\"\n  tag \"satisfies\": [\"SRG-OS-000355-GPOS-00143\", \"SRG-OS-000356-GPOS-00144\"]\n  tag \"gid\": \"V-72269\"\n  tag \"rid\": \"SV-86893r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040500\"\n  tag \"cci\": [\"CCI-001891\", \"CCI-002046\"]\n  tag \"documentable\": false\n  tag \"subsystems\": ['ntp']  \n  tag \"nist\": [\"AU-8 (1) (a)\", \"AU-8 (1) (b)\", \"Rev_4\"]\n  tag \"fix_id\": \"F-78623r3_fix\"\n\n  desc \"check\", \"Check to see if NTP is running in continuous mode.\n\n  # ps -ef | grep ntp\n\n  If NTP is not running, this is a finding.\n\n  If the process is found, then check the \\\"ntp.conf\\\" file for the \\\"maxpoll\\\"\n  option setting:\n\n  # grep maxpoll /etc/ntp.conf\n\n  maxpoll 17\n\n  If the option is set to \\\"17\\\" or is not set, this is a finding.\n\n  If the file does not exist, check the \\\"/etc/cron.daily\\\" subdirectory for a\n  crontab file controlling the execution of the \\\"ntpdate\\\" command.\n\n  # grep –l ntpdate /etc/cron.daily\n\n  # ls -al /etc/cron.* | grep ntp\n  ntp\n\n  If a crontab file does not exist in the \\\"/etc/cron.daily\\\" that executes the\n  \\\"ntpdate\\\" file, this is a finding.\"\n  \n  desc \"fix\", \"Edit the \\\"/etc/ntp.conf\\\" file and add or update an entry to\n  define \\\"maxpoll\\\" to \\\"10\\\" as follows:\n\n  maxpoll 10\n\n  If NTP was running and \\\"maxpoll\\\" was updated, the NTP service must be\n  restarted:\n\n  # systemctl restart ntpd\n\n  If NTP was not running, it must be started:\n\n  # systemctl start ntpd\"\n\n  describe service('ntpd') do\n    it { should be_running }\n  end\n\n  describe.one do\n    describe command('ntpd --saveconfigquit=/dev/stdout | grep -E \"^server\\s\"') do\n      its('stdout.strip') { should_not be_empty }\n      its('stdout.strip.lines') { should all(match %r{\\smaxpoll\\s+([1-9]|1[0-6])\\b}) }\n    end\n    # Case where maxpoll empty\n    describe file('/etc/cron.daily/ntpdate') do\n      it { should exist }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72269.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Service ntpd should be running",
              "run_time": 0.050316455,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected that `Service ntpd` is running"
            },
            {
              "status": "passed",
              "code_desc": "Command: `ntpd --saveconfigquit=/dev/stdout | grep -E \"^server\\s\"` stdout.strip should not be empty",
              "run_time": 0.000169922,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "Command: `ntpd --saveconfigquit=/dev/stdout | grep -E \"^server\\s\"` stdout.strip.lines should all match /\\smaxpoll\\s+([1-9]|1[0-6])\\b/",
              "run_time": 0.000450362,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected [\"server 0.centos.pool.ntp.org iburst\\n\", \"server 1.centos.pool.ntp.org iburst\\n\", \"server 2.centos.pool.ntp.org iburst\\n\", \"server 3.centos.pool.ntp.org iburst\"] to all match /\\smaxpoll\\s+([1-9]|1[0-6])\\b/\n\n   object at index 0 failed to match:\n      expected \"server 0.centos.pool.ntp.org iburst\\n\" to match /\\smaxpoll\\s+([1-9]|1[0-6])\\b/\n\n   object at index 1 failed to match:\n      expected \"server 1.centos.pool.ntp.org iburst\\n\" to match /\\smaxpoll\\s+([1-9]|1[0-6])\\b/\n\n   object at index 2 failed to match:\n      expected \"server 2.centos.pool.ntp.org iburst\\n\" to match /\\smaxpoll\\s+([1-9]|1[0-6])\\b/\n\n   object at index 3 failed to match:\n      expected \"server 3.centos.pool.ntp.org iburst\" to match /\\smaxpoll\\s+([1-9]|1[0-6])\\b/",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "File /etc/cron.daily/ntpdate should exist",
              "run_time": 0.000173561,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected File /etc/cron.daily/ntpdate to exist",
              "exception": "RSpec::Core::MultipleExceptionError"
            }
          ]
        },
        {
          "id": "V-72271",
          "title": "The operating system must protect against or limit the effects of\nDenial of Service (DoS) attacks by validating the operating system is\nimplementing rate-limiting measures on impacted network interfaces.",
          "desc": "DoS is a condition when a resource is not available for legitimate users.\nWhen this occurs, the organization either cannot accomplish its mission or must\noperate at degraded capacity.\n\n    This requirement addresses the configuration of the operating system to\nmitigate the impact of DoS attacks that have occurred or are ongoing on system\navailability. For each system, known and potential DoS attacks must be\nidentified and solutions for each type implemented. A variety of technologies\nexist to limit or, in some cases, eliminate the effects of DoS attacks (e.g.,\nlimiting processes or establishing memory partitions). Employing increased\ncapacity and bandwidth, combined with service redundancy, may reduce the\nsusceptibility to some DoS attacks.",
          "descriptions": [
            {
              "label": "default",
              "data": "DoS is a condition when a resource is not available for legitimate users.\nWhen this occurs, the organization either cannot accomplish its mission or must\noperate at degraded capacity.\n\n    This requirement addresses the configuration of the operating system to\nmitigate the impact of DoS attacks that have occurred or are ongoing on system\navailability. For each system, known and potential DoS attacks must be\nidentified and solutions for each type implemented. A variety of technologies\nexist to limit or, in some cases, eliminate the effects of DoS attacks (e.g.,\nlimiting processes or establishing memory partitions). Employing increased\ncapacity and bandwidth, combined with service redundancy, may reduce the\nsusceptibility to some DoS attacks."
            },
            {
              "label": "check",
              "data": "Verify the operating system protects against or limits the\neffects of DoS attacks by ensuring the operating system is implementing\nrate-limiting measures on impacted network interfaces.\n\nCheck the firewall configuration with the following command:\n\nNote: The command is to query rules for the public zone.\n\n# firewall-cmd --direct --get-rule ipv4 filter IN_public_allow\nrule ipv4 filter IN_public_allow 0 -p tcp -m limit --limit 25/minute --limit-burst 100  -j ACCEPT\n\nIf a rule with both the limit and limit-burst arguments parameters does not\nexist, this is a finding."
            },
            {
              "label": "fix",
              "data": "Create a direct firewall rule to protect against DoS attacks with\nthe following command:\n\nNote: The command is to add a rule to the public zone.\n\n# firewall-cmd --direct --permanent --add-rule ipv4 filter IN_public_allow 0 -m tcp -p tcp -m limit --limit 25/minute --limit-burst 100 -j ACCEPT\n\nThe firewalld service will need to be restarted for this to take effect:\n\n# systemctl restart firewalld"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000420-GPOS-00186",
            "gid": "V-72271",
            "rid": "SV-86895r2_rule",
            "stig_id": "RHEL-07-040510",
            "cci": [
              "CCI-002385"
            ],
            "documentable": false,
            "nist": [
              "SC-5",
              "Rev_4"
            ],
            "subsystems": [
              "firewalld",
              "iptables"
            ],
            "fix_id": "F-78625r2_fix"
          },
          "code": "control \"V-72271\" do\n  title \"The operating system must protect against or limit the effects of\nDenial of Service (DoS) attacks by validating the operating system is\nimplementing rate-limiting measures on impacted network interfaces.\"\n  desc  \"\n    DoS is a condition when a resource is not available for legitimate users.\nWhen this occurs, the organization either cannot accomplish its mission or must\noperate at degraded capacity.\n\n    This requirement addresses the configuration of the operating system to\nmitigate the impact of DoS attacks that have occurred or are ongoing on system\navailability. For each system, known and potential DoS attacks must be\nidentified and solutions for each type implemented. A variety of technologies\nexist to limit or, in some cases, eliminate the effects of DoS attacks (e.g.,\nlimiting processes or establishing memory partitions). Employing increased\ncapacity and bandwidth, combined with service redundancy, may reduce the\nsusceptibility to some DoS attacks.\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000420-GPOS-00186\"\n  tag \"gid\": \"V-72271\"\n  tag \"rid\": \"SV-86895r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040510\"\n  tag \"cci\": [\"CCI-002385\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"SC-5\", \"Rev_4\"]\n  tag \"subsystems\": ['firewalld', 'iptables']\n  desc \"check\", \"Verify the operating system protects against or limits the\neffects of DoS attacks by ensuring the operating system is implementing\nrate-limiting measures on impacted network interfaces.\n\nCheck the firewall configuration with the following command:\n\nNote: The command is to query rules for the public zone.\n\n# firewall-cmd --direct --get-rule ipv4 filter IN_public_allow\nrule ipv4 filter IN_public_allow 0 -p tcp -m limit --limit 25/minute --limit-burst 100  -j ACCEPT\n\nIf a rule with both the limit and limit-burst arguments parameters does not\nexist, this is a finding.\"\n  desc \"fix\", \"Create a direct firewall rule to protect against DoS attacks with\nthe following command:\n\nNote: The command is to add a rule to the public zone.\n\n# firewall-cmd --direct --permanent --add-rule ipv4 filter IN_public_allow 0 -m tcp -p tcp -m limit --limit 25/minute --limit-burst 100 -j ACCEPT\n\nThe firewalld service will need to be restarted for this to take effect:\n\n# systemctl restart firewalld\"\n  tag \"fix_id\": \"F-78625r2_fix\"\n\n  # @todo - firewall resource?\n  describe.one do\n    describe command('firewall-cmd --direct --get-rule ipv4 filter IN_public_allow') do\n       its('stdout') { should match %r{--limit .+} }\n       its('stdout') { should match %r{--limit-burst .+} }\n    end\n    describe command('iptables -L') do\n       its('stdout') { should match %r{limit.+} }\n       its('stdout') { should match %r{burst.+} }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72271.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Command: `firewall-cmd --direct --get-rule ipv4 filter IN_public_allow` stdout should match /--limit .+/",
              "run_time": 0.000320503,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected \"\" to match /--limit .+/\nDiff:\n@@ -1,2 +1,2 @@\n-/--limit .+/\n+\"\"\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Command: `firewall-cmd --direct --get-rule ipv4 filter IN_public_allow` stdout should match /--limit-burst .+/",
              "run_time": 0.000292607,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected \"\" to match /--limit-burst .+/\nDiff:\n@@ -1,2 +1,2 @@\n-/--limit-burst .+/\n+\"\"\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Command: `iptables -L` stdout should match /limit.+/",
              "run_time": 0.000870835,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected \"Chain INPUT (policy ACCEPT)\\ntarget     prot opt source               destination         \\nACCEPT  ...Chain OUTPUT_direct (1 references)\\ntarget     prot opt source               destination         \\n\" to match /limit.+/\nDiff:\n@@ -1,2 +1,117 @@\n-/limit.+/\n+Chain INPUT (policy ACCEPT)\n+target     prot opt source               destination         \n+ACCEPT     udp  --  anywhere             anywhere             udp dpt:domain\n+ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:domain\n+ACCEPT     udp  --  anywhere             anywhere             udp dpt:bootps\n+ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:bootps\n+ACCEPT     all  --  anywhere             anywhere             ctstate RELATED,ESTABLISHED\n+ACCEPT     all  --  anywhere             anywhere            \n+INPUT_direct  all  --  anywhere             anywhere            \n+INPUT_ZONES_SOURCE  all  --  anywhere             anywhere            \n+INPUT_ZONES  all  --  anywhere             anywhere            \n+DROP       all  --  anywhere             anywhere             ctstate INVALID\n+REJECT     all  --  anywhere             anywhere             reject-with icmp-host-prohibited\n+\n+Chain FORWARD (policy ACCEPT)\n+target     prot opt source               destination         \n+ACCEPT     all  --  anywhere             192.168.122.0/24     ctstate RELATED,ESTABLISHED\n+ACCEPT     all  --  192.168.122.0/24     anywhere            \n+ACCEPT     all  --  anywhere             anywhere            \n+REJECT     all  --  anywhere             anywhere             reject-with icmp-port-unreachable\n+REJECT     all  --  anywhere             anywhere             reject-with icmp-port-unreachable\n+ACCEPT     all  --  anywhere             anywhere             ctstate RELATED,ESTABLISHED\n+ACCEPT     all  --  anywhere             anywhere            \n+FORWARD_direct  all  --  anywhere             anywhere            \n+FORWARD_IN_ZONES_SOURCE  all  --  anywhere             anywhere            \n+FORWARD_IN_ZONES  all  --  anywhere             anywhere            \n+FORWARD_OUT_ZONES_SOURCE  all  --  anywhere             anywhere            \n+FORWARD_OUT_ZONES  all  --  anywhere             anywhere            \n+DROP       all  --  anywhere             anywhere             ctstate INVALID\n+REJECT     all  --  anywhere             anywhere             reject-with icmp-host-prohibited\n+\n+Chain OUTPUT (policy ACCEPT)\n+target     prot opt source               destination         \n+ACCEPT     udp  --  anywhere             anywhere             udp dpt:bootpc\n+OUTPUT_direct  all  --  anywhere             anywhere            \n+\n+Chain FORWARD_IN_ZONES (1 references)\n+target     prot opt source               destination         \n+FWDI_public  all  --  anywhere             anywhere            [goto] \n+FWDI_public  all  --  anywhere             anywhere            [goto] \n+\n+Chain FORWARD_IN_ZONES_SOURCE (1 references)\n+target     prot opt source               destination         \n+\n+Chain FORWARD_OUT_ZONES (1 references)\n+target     prot opt source               destination         \n+FWDO_public  all  --  anywhere             anywhere            [goto] \n+FWDO_public  all  --  anywhere             anywhere            [goto] \n+\n+Chain FORWARD_OUT_ZONES_SOURCE (1 references)\n+target     prot opt source               destination         \n+\n+Chain FORWARD_direct (1 references)\n+target     prot opt source               destination         \n+\n+Chain FWDI_public (2 references)\n+target     prot opt source               destination         \n+FWDI_public_log  all  --  anywhere             anywhere            \n+FWDI_public_deny  all  --  anywhere             anywhere            \n+FWDI_public_allow  all  --  anywhere             anywhere            \n+ACCEPT     icmp --  anywhere             anywhere            \n+\n+Chain FWDI_public_allow (1 references)\n+target     prot opt source               destination         \n+\n+Chain FWDI_public_deny (1 references)\n+target     prot opt source               destination         \n+\n+Chain FWDI_public_log (1 references)\n+target     prot opt source               destination         \n+\n+Chain FWDO_public (2 references)\n+target     prot opt source               destination         \n+FWDO_public_log  all  --  anywhere             anywhere            \n+FWDO_public_deny  all  --  anywhere             anywhere            \n+FWDO_public_allow  all  --  anywhere             anywhere            \n+\n+Chain FWDO_public_allow (1 references)\n+target     prot opt source               destination         \n+\n+Chain FWDO_public_deny (1 references)\n+target     prot opt source               destination         \n+\n+Chain FWDO_public_log (1 references)\n+target     prot opt source               destination         \n+\n+Chain INPUT_ZONES (1 references)\n+target     prot opt source               destination         \n+IN_public  all  --  anywhere             anywhere            [goto] \n+IN_public  all  --  anywhere             anywhere            [goto] \n+\n+Chain INPUT_ZONES_SOURCE (1 references)\n+target     prot opt source               destination         \n+\n+Chain INPUT_direct (1 references)\n+target     prot opt source               destination         \n+\n+Chain IN_public (2 references)\n+target     prot opt source               destination         \n+IN_public_log  all  --  anywhere             anywhere            \n+IN_public_deny  all  --  anywhere             anywhere            \n+IN_public_allow  all  --  anywhere             anywhere            \n+ACCEPT     icmp --  anywhere             anywhere            \n+\n+Chain IN_public_allow (1 references)\n+target     prot opt source               destination         \n+ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:ssh ctstate NEW\n+\n+Chain IN_public_deny (1 references)\n+target     prot opt source               destination         \n+\n+Chain IN_public_log (1 references)\n+target     prot opt source               destination         \n+\n+Chain OUTPUT_direct (1 references)\n+target     prot opt source               destination         \n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Command: `iptables -L` stdout should match /burst.+/",
              "run_time": 0.000917798,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected \"Chain INPUT (policy ACCEPT)\\ntarget     prot opt source               destination         \\nACCEPT  ...Chain OUTPUT_direct (1 references)\\ntarget     prot opt source               destination         \\n\" to match /burst.+/\nDiff:\n@@ -1,2 +1,117 @@\n-/burst.+/\n+Chain INPUT (policy ACCEPT)\n+target     prot opt source               destination         \n+ACCEPT     udp  --  anywhere             anywhere             udp dpt:domain\n+ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:domain\n+ACCEPT     udp  --  anywhere             anywhere             udp dpt:bootps\n+ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:bootps\n+ACCEPT     all  --  anywhere             anywhere             ctstate RELATED,ESTABLISHED\n+ACCEPT     all  --  anywhere             anywhere            \n+INPUT_direct  all  --  anywhere             anywhere            \n+INPUT_ZONES_SOURCE  all  --  anywhere             anywhere            \n+INPUT_ZONES  all  --  anywhere             anywhere            \n+DROP       all  --  anywhere             anywhere             ctstate INVALID\n+REJECT     all  --  anywhere             anywhere             reject-with icmp-host-prohibited\n+\n+Chain FORWARD (policy ACCEPT)\n+target     prot opt source               destination         \n+ACCEPT     all  --  anywhere             192.168.122.0/24     ctstate RELATED,ESTABLISHED\n+ACCEPT     all  --  192.168.122.0/24     anywhere            \n+ACCEPT     all  --  anywhere             anywhere            \n+REJECT     all  --  anywhere             anywhere             reject-with icmp-port-unreachable\n+REJECT     all  --  anywhere             anywhere             reject-with icmp-port-unreachable\n+ACCEPT     all  --  anywhere             anywhere             ctstate RELATED,ESTABLISHED\n+ACCEPT     all  --  anywhere             anywhere            \n+FORWARD_direct  all  --  anywhere             anywhere            \n+FORWARD_IN_ZONES_SOURCE  all  --  anywhere             anywhere            \n+FORWARD_IN_ZONES  all  --  anywhere             anywhere            \n+FORWARD_OUT_ZONES_SOURCE  all  --  anywhere             anywhere            \n+FORWARD_OUT_ZONES  all  --  anywhere             anywhere            \n+DROP       all  --  anywhere             anywhere             ctstate INVALID\n+REJECT     all  --  anywhere             anywhere             reject-with icmp-host-prohibited\n+\n+Chain OUTPUT (policy ACCEPT)\n+target     prot opt source               destination         \n+ACCEPT     udp  --  anywhere             anywhere             udp dpt:bootpc\n+OUTPUT_direct  all  --  anywhere             anywhere            \n+\n+Chain FORWARD_IN_ZONES (1 references)\n+target     prot opt source               destination         \n+FWDI_public  all  --  anywhere             anywhere            [goto] \n+FWDI_public  all  --  anywhere             anywhere            [goto] \n+\n+Chain FORWARD_IN_ZONES_SOURCE (1 references)\n+target     prot opt source               destination         \n+\n+Chain FORWARD_OUT_ZONES (1 references)\n+target     prot opt source               destination         \n+FWDO_public  all  --  anywhere             anywhere            [goto] \n+FWDO_public  all  --  anywhere             anywhere            [goto] \n+\n+Chain FORWARD_OUT_ZONES_SOURCE (1 references)\n+target     prot opt source               destination         \n+\n+Chain FORWARD_direct (1 references)\n+target     prot opt source               destination         \n+\n+Chain FWDI_public (2 references)\n+target     prot opt source               destination         \n+FWDI_public_log  all  --  anywhere             anywhere            \n+FWDI_public_deny  all  --  anywhere             anywhere            \n+FWDI_public_allow  all  --  anywhere             anywhere            \n+ACCEPT     icmp --  anywhere             anywhere            \n+\n+Chain FWDI_public_allow (1 references)\n+target     prot opt source               destination         \n+\n+Chain FWDI_public_deny (1 references)\n+target     prot opt source               destination         \n+\n+Chain FWDI_public_log (1 references)\n+target     prot opt source               destination         \n+\n+Chain FWDO_public (2 references)\n+target     prot opt source               destination         \n+FWDO_public_log  all  --  anywhere             anywhere            \n+FWDO_public_deny  all  --  anywhere             anywhere            \n+FWDO_public_allow  all  --  anywhere             anywhere            \n+\n+Chain FWDO_public_allow (1 references)\n+target     prot opt source               destination         \n+\n+Chain FWDO_public_deny (1 references)\n+target     prot opt source               destination         \n+\n+Chain FWDO_public_log (1 references)\n+target     prot opt source               destination         \n+\n+Chain INPUT_ZONES (1 references)\n+target     prot opt source               destination         \n+IN_public  all  --  anywhere             anywhere            [goto] \n+IN_public  all  --  anywhere             anywhere            [goto] \n+\n+Chain INPUT_ZONES_SOURCE (1 references)\n+target     prot opt source               destination         \n+\n+Chain INPUT_direct (1 references)\n+target     prot opt source               destination         \n+\n+Chain IN_public (2 references)\n+target     prot opt source               destination         \n+IN_public_log  all  --  anywhere             anywhere            \n+IN_public_deny  all  --  anywhere             anywhere            \n+IN_public_allow  all  --  anywhere             anywhere            \n+ACCEPT     icmp --  anywhere             anywhere            \n+\n+Chain IN_public_allow (1 references)\n+target     prot opt source               destination         \n+ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:ssh ctstate NEW\n+\n+Chain IN_public_deny (1 references)\n+target     prot opt source               destination         \n+\n+Chain IN_public_log (1 references)\n+target     prot opt source               destination         \n+\n+Chain OUTPUT_direct (1 references)\n+target     prot opt source               destination         \n",
              "exception": "RSpec::Core::MultipleExceptionError"
            }
          ]
        },
        {
          "id": "V-72273",
          "title": "The operating system must enable an application firewall, if\navailable.",
          "desc": "Firewalls protect computers from network attacks by blocking or\nlimiting access to open network ports. Application firewalls limit which\napplications are allowed to communicate over the network.",
          "descriptions": [
            {
              "label": "default",
              "data": "Firewalls protect computers from network attacks by blocking or\nlimiting access to open network ports. Application firewalls limit which\napplications are allowed to communicate over the network."
            },
            {
              "label": "check",
              "data": "Verify the operating system enabled an application firewall.\n\nCheck to see if \"firewalld\" is installed with the following command:\n\n# yum list installed firewalld\nfirewalld-0.3.9-11.el7.noarch.rpm\n\nIf the \"firewalld\" package is not installed, ask the System Administrator if\nanother firewall application (such as iptables) is installed.\n\nIf an application firewall is not installed, this is a finding.\n\nCheck to see if the firewall is loaded and active with the following command:\n\n# systemctl status firewalld\nfirewalld.service - firewalld - dynamic firewall daemon\n\n   Loaded: loaded (/usr/lib/systemd/system/firewalld.service; enabled)\n   Active: active (running) since Tue 2014-06-17 11:14:49 CEST; 5 days ago\n\nIf \"firewalld\" does not show a status of \"loaded\" and \"active\", this is a\nfinding.\n\nCheck the state of the firewall:\n\n# firewall-cmd --state\nrunning\n\nIf \"firewalld\" does not show a state of \"running\", this is a finding."
            },
            {
              "label": "fix",
              "data": "Ensure the operating system's application firewall is enabled.\n\nInstall the \"firewalld\" package, if it is not on the system, with the\nfollowing command:\n\n# yum install firewalld\n\nStart the firewall via \"systemctl\" with the following command:\n\n# systemctl start firewalld"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "satisfies": [
              "SRG-OS-000480-GPOS-00227",
              "SRG-OS-000480-GPOS-00231",
              "SRG-OS-000480-GPOS-00232"
            ],
            "gid": "V-72273",
            "rid": "SV-86897r1_rule",
            "stig_id": "RHEL-07-040520",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "firewalld",
              "iptables"
            ],
            "fix_id": "F-78627r1_fix"
          },
          "code": "control \"V-72273\" do\n  title \"The operating system must enable an application firewall, if\navailable.\"\n  desc  \"Firewalls protect computers from network attacks by blocking or\nlimiting access to open network ports. Application firewalls limit which\napplications are allowed to communicate over the network.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"satisfies\": [\"SRG-OS-000480-GPOS-00227\", \"SRG-OS-000480-GPOS-00231\",\n\"SRG-OS-000480-GPOS-00232\"]\n  tag \"gid\": \"V-72273\"\n  tag \"rid\": \"SV-86897r1_rule\"\n  tag \"stig_id\": \"RHEL-07-040520\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['firewalld', 'iptables']\n  desc \"check\", \"Verify the operating system enabled an application firewall.\n\nCheck to see if \\\"firewalld\\\" is installed with the following command:\n\n# yum list installed firewalld\nfirewalld-0.3.9-11.el7.noarch.rpm\n\nIf the \\\"firewalld\\\" package is not installed, ask the System Administrator if\nanother firewall application (such as iptables) is installed.\n\nIf an application firewall is not installed, this is a finding.\n\nCheck to see if the firewall is loaded and active with the following command:\n\n# systemctl status firewalld\nfirewalld.service - firewalld - dynamic firewall daemon\n\n   Loaded: loaded (/usr/lib/systemd/system/firewalld.service; enabled)\n   Active: active (running) since Tue 2014-06-17 11:14:49 CEST; 5 days ago\n\nIf \\\"firewalld\\\" does not show a status of \\\"loaded\\\" and \\\"active\\\", this is a\nfinding.\n\nCheck the state of the firewall:\n\n# firewall-cmd --state\nrunning\n\nIf \\\"firewalld\\\" does not show a state of \\\"running\\\", this is a finding.\"\n  desc \"fix\", \"Ensure the operating system's application firewall is enabled.\n\nInstall the \\\"firewalld\\\" package, if it is not on the system, with the\nfollowing command:\n\n# yum install firewalld\n\nStart the firewall via \\\"systemctl\\\" with the following command:\n\n# systemctl start firewalld\"\n  tag \"fix_id\": \"F-78627r1_fix\"\n\n  describe.one do\n    describe package('firewalld') do\n      it { should be_installed }\n    end\n    describe package('iptables') do\n      it { should be_installed }\n    end\n  end\n  describe.one do\n    describe systemd_service('firewalld.service') do\n      it { should be_running }\n    end\n\tdescribe systemd_service('iptables.service') do\n      it { should be_running }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72273.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "System Package firewalld should be installed",
              "run_time": 0.000256476,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "System Package iptables should be installed",
              "run_time": 0.000191651,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "passed",
              "code_desc": "Service firewalld.service should be running",
              "run_time": 7.6274e-05,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72275",
          "title": "The system must display the date and time of the last successful\naccount logon upon logon.",
          "desc": "Providing users with feedback on when account accesses last occurred\nfacilitates user recognition and reporting of unauthorized account use.",
          "descriptions": [
            {
              "label": "default",
              "data": "Providing users with feedback on when account accesses last occurred\nfacilitates user recognition and reporting of unauthorized account use."
            },
            {
              "label": "check",
              "data": "Verify users are provided with feedback on when account\naccesses last occurred.\n\nCheck that \"pam_lastlog\" is used and not silent with the following command:\n\n# grep pam_lastlog /etc/pam.d/postlogin-ac\nsession required pam_lastlog.so showfailed\n\nIf the \"silent\" option is present with \"pam_lastlog\" check the sshd\nconfiguration file.\n\n# grep -i printlastlog /etc/ssh/sshd_config\nPrintLastLog yes\n\nIf \"pam_lastlog\" is missing from \"/etc/pam.d/postlogin-ac\" file, or the\nsilent option is present and PrintLastLog is missing from or set to \"no\" in\nthe \"/etc/ssh/sshd_config\" file this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to provide users with feedback on\nwhen account accesses last occurred by setting the required configuration\noptions in \"/etc/pam.d/postlogin-ac\".\n\nAdd the following line to the top of \"/etc/pam.d/postlogin-ac\":\n\nsession     required      pam_lastlog.so showfailed"
            }
          ],
          "impact": 0.3,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72275",
            "rid": "SV-86899r2_rule",
            "stig_id": "RHEL-07-040530",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "pam",
              "lastlog",
              "ssh"
            ],
            "fix_id": "F-78629r1_fix"
          },
          "code": "control \"V-72275\" do\n  title \"The system must display the date and time of the last successful\naccount logon upon logon.\"\n  desc  \"Providing users with feedback on when account accesses last occurred\nfacilitates user recognition and reporting of unauthorized account use.\"\n  impact 0.3\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72275\"\n  tag \"rid\": \"SV-86899r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040530\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['pam', 'lastlog', 'ssh']\n  desc \"check\", \"Verify users are provided with feedback on when account\naccesses last occurred.\n\nCheck that \\\"pam_lastlog\\\" is used and not silent with the following command:\n\n# grep pam_lastlog /etc/pam.d/postlogin-ac\nsession required pam_lastlog.so showfailed\n\nIf the \\\"silent\\\" option is present with \\\"pam_lastlog\\\" check the sshd\nconfiguration file.\n\n# grep -i printlastlog /etc/ssh/sshd_config\nPrintLastLog yes\n\nIf \\\"pam_lastlog\\\" is missing from \\\"/etc/pam.d/postlogin-ac\\\" file, or the\nsilent option is present and PrintLastLog is missing from or set to \\\"no\\\" in\nthe \\\"/etc/ssh/sshd_config\\\" file this is a finding.\"\n  desc \"fix\", \"Configure the operating system to provide users with feedback on\nwhen account accesses last occurred by setting the required configuration\noptions in \\\"/etc/pam.d/postlogin-ac\\\".\n\nAdd the following line to the top of \\\"/etc/pam.d/postlogin-ac\\\":\n\nsession     required      pam_lastlog.so showfailed\"\n  tag \"fix_id\": \"F-78629r1_fix\"\n\n  describe pam('/etc/pam.d/postlogin') do\n    its('lines') { should match_pam_rule('session .* pam_lastlog.so showfailed') }\n  end\n\n  describe.one do\n    describe sshd_config do\n      its('PrintLastLog') { should cmp 'yes' }\n    end\n\n    describe pam('/etc/pam.d/postlogin') do\n      its('lines') { should match_pam_rule('session .* pam_lastlog.so showfailed').all_without_args('silent') }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72275.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "PAM Config[/etc/pam.d/postlogin] lines should include session .* pam_lastlog.so showfailed",
              "run_time": 0.000236823,
              "start_time": "2019-11-04T16:17:15-05:00"
            },
            {
              "status": "failed",
              "code_desc": "SSHD Configuration PrintLastLog should cmp == \"yes\"",
              "run_time": 0.000160045,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "\nexpected: \"yes\"\n     got: nil\n\n(compared using `cmp` matcher)\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "PAM Config[/etc/pam.d/postlogin] lines should include session .* pam_lastlog.so showfailed, all without args silent",
              "run_time": 0.000447477,
              "start_time": "2019-11-04T16:17:15-05:00",
              "message": "expected \"session [default=1] pam_lastlog.so nowtmp showfailed\\nsession optional pam_lastlog.so silent noupdate showfailed\" to include session .* pam_lastlog.so showfailed, all without args silent\nDiff:\n@@ -1,2 +1,3 @@\n-session .* pam_lastlog.so showfailed\n+session [default=1] pam_lastlog.so nowtmp showfailed\n+session optional pam_lastlog.so silent noupdate showfailed\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            }
          ]
        },
        {
          "id": "V-72277",
          "title": "There must be no .shosts files on the system.",
          "desc": "The .shosts files are used to configure host-based authentication for\nindividual users or the system via SSH. Host-based authentication is not\nsufficient for preventing unauthorized access to the system, as it does not\nrequire interactive identification and authentication of a connection request,\nor for the use of two-factor authentication.",
          "descriptions": [
            {
              "label": "default",
              "data": "The .shosts files are used to configure host-based authentication for\nindividual users or the system via SSH. Host-based authentication is not\nsufficient for preventing unauthorized access to the system, as it does not\nrequire interactive identification and authentication of a connection request,\nor for the use of two-factor authentication."
            },
            {
              "label": "check",
              "data": "Verify there are no \".shosts\" files on the system.\n\nCheck the system for the existence of these files with the following command:\n\n# find / -name '*.shosts'\n\nIf any \".shosts\" files are found on the system, this is a finding."
            },
            {
              "label": "fix",
              "data": "Remove any found \".shosts\" files from the system.\n\n# rm /[path]/[to]/[file]/.shosts"
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72277",
            "rid": "SV-86901r1_rule",
            "stig_id": "RHEL-07-040540",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78631r1_fix",
            "dangerous": {
              "reason": "Uses global find command"
            }
          },
          "code": "control \"V-72277\" do\n  title \"There must be no .shosts files on the system.\"\n  desc  \"The .shosts files are used to configure host-based authentication for\nindividual users or the system via SSH. Host-based authentication is not\nsufficient for preventing unauthorized access to the system, as it does not\nrequire interactive identification and authentication of a connection request,\nor for the use of two-factor authentication.\"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72277\"\n  tag \"rid\": \"SV-86901r1_rule\"\n  tag \"stig_id\": \"RHEL-07-040540\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['ssh']\n  desc \"check\", \"Verify there are no \\\".shosts\\\" files on the system.\n\nCheck the system for the existence of these files with the following command:\n\n# find / -name '*.shosts'\n\nIf any \\\".shosts\\\" files are found on the system, this is a finding.\"\n  desc \"fix\", \"Remove any found \\\".shosts\\\" files from the system.\n\n# rm /[path]/[to]/[file]/.shosts\"\n  tag \"fix_id\": \"F-78631r1_fix\"\n  tag \"dangerous\": { :reason => \"Uses global find command\" }\n\n  describe command(\"find / -xautofs -name '*.shosts'\") do\n    its('stdout.strip') { should be_empty }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72277.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Command: `find / -xautofs -name '*.shosts'` stdout.strip should be empty",
              "run_time": 0.581566297,
              "start_time": "2019-11-04T16:17:15-05:00"
            }
          ]
        },
        {
          "id": "V-72279",
          "title": "There must be no shosts.equiv files on the system.",
          "desc": "The shosts.equiv files are used to configure host-based authentication\nfor the system via SSH. Host-based authentication is not sufficient for\npreventing unauthorized access to the system, as it does not require\ninteractive identification and authentication of a connection request, or for\nthe use of two-factor authentication.",
          "descriptions": [
            {
              "label": "default",
              "data": "The shosts.equiv files are used to configure host-based authentication\nfor the system via SSH. Host-based authentication is not sufficient for\npreventing unauthorized access to the system, as it does not require\ninteractive identification and authentication of a connection request, or for\nthe use of two-factor authentication."
            },
            {
              "label": "check",
              "data": "Verify there are no \"shosts.equiv\" files on the system.\n\nCheck the system for the existence of these files with the following command:\n\n# find / -name shosts.equiv\n\nIf any \"shosts.equiv\" files are found on the system, this is a finding."
            },
            {
              "label": "fix",
              "data": "Remove any found \"shosts.equiv\" files from the system.\n\n# rm /[path]/[to]/[file]/shosts.equiv"
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72279",
            "rid": "SV-86903r1_rule",
            "stig_id": "RHEL-07-040550",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78633r1_fix",
            "dangerous": {
              "reason": "Uses global find command"
            }
          },
          "code": "control \"V-72279\" do\n  title \"There must be no shosts.equiv files on the system.\"\n  desc  \"The shosts.equiv files are used to configure host-based authentication\nfor the system via SSH. Host-based authentication is not sufficient for\npreventing unauthorized access to the system, as it does not require\ninteractive identification and authentication of a connection request, or for\nthe use of two-factor authentication.\"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72279\"\n  tag \"rid\": \"SV-86903r1_rule\"\n  tag \"stig_id\": \"RHEL-07-040550\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['ssh']\n  desc \"check\", \"Verify there are no \\\"shosts.equiv\\\" files on the system.\n\nCheck the system for the existence of these files with the following command:\n\n# find / -name shosts.equiv\n\nIf any \\\"shosts.equiv\\\" files are found on the system, this is a finding.\"\n  desc \"fix\", \"Remove any found \\\"shosts.equiv\\\" files from the system.\n\n# rm /[path]/[to]/[file]/shosts.equiv\"\n  tag \"fix_id\": \"F-78633r1_fix\"\n  tag \"dangerous\": { :reason => \"Uses global find command\" }\n\n  describe command('find / -xautofs -name shosts.equiv') do\n    its('stdout.strip') { should be_empty }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72279.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Command: `find / -xautofs -name shosts.equiv` stdout.strip should be empty",
              "run_time": 0.537816645,
              "start_time": "2019-11-04T16:17:16-05:00"
            }
          ]
        },
        {
          "id": "V-72281",
          "title": "For systems using DNS resolution, at least two name servers must be\nconfigured.",
          "desc": "To provide availability for name resolution services, multiple\nredundant name servers are mandated. A failure in name resolution could lead to\nthe failure of security functions requiring name resolution, which may include\ntime synchronization, centralized authentication, and remote system logging.",
          "descriptions": [
            {
              "label": "default",
              "data": "To provide availability for name resolution services, multiple\nredundant name servers are mandated. A failure in name resolution could lead to\nthe failure of security functions requiring name resolution, which may include\ntime synchronization, centralized authentication, and remote system logging."
            },
            {
              "label": "check",
              "data": "Determine whether the system is using local or DNS name\nresolution with the following command:\n\n# grep hosts /etc/nsswitch.conf\nhosts:   files dns\n\nIf the DNS entry is missing from the host’s line in the \"/etc/nsswitch.conf\"\nfile, the \"/etc/resolv.conf\" file must be empty.\n\nVerify the \"/etc/resolv.conf\" file is empty with the following command:\n\n# ls -al /etc/resolv.conf\n-rw-r--r--  1 root root        0 Aug 19 08:31 resolv.conf\n\nIf local host authentication is being used and the \"/etc/resolv.conf\" file is\nnot empty, this is a finding.\n\nIf the DNS entry is found on the host’s line of the \"/etc/nsswitch.conf\"\nfile, verify the operating system is configured to use two or more name servers\nfor DNS resolution.\n\nDetermine the name servers used by the system with the following command:\n\n# grep nameserver /etc/resolv.conf\nnameserver 192.168.1.2\nnameserver 192.168.1.3\n\nIf less than two lines are returned that are not commented out, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to use two or more name servers\nfor DNS resolution.\n\nEdit the \"/etc/resolv.conf\" file to uncomment or add the two or more\n\"nameserver\" option lines with the IP address of local authoritative name\nservers. If local host resolution is being performed, the \"/etc/resolv.conf\"\nfile must be empty. An empty \"/etc/resolv.conf\" file can be created as\nfollows:\n\n# echo -n > /etc/resolv.conf\n\nAnd then make the file immutable with the following command:\n\n# chattr +i /etc/resolv.conf\n\nIf the \"/etc/resolv.conf\" file must be mutable, the required configuration\nmust be documented with the Information System Security Officer (ISSO) and the\nfile must be verified by the system file integrity tool."
            }
          ],
          "impact": 0.3,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72281",
            "rid": "SV-86905r1_rule",
            "stig_id": "RHEL-07-040600",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "dns",
              "resolv"
            ],
            "fix_id": "F-78635r1_fix"
          },
          "code": "control \"V-72281\" do\n  title \"For systems using DNS resolution, at least two name servers must be\nconfigured.\"\n  desc  \"To provide availability for name resolution services, multiple\nredundant name servers are mandated. A failure in name resolution could lead to\nthe failure of security functions requiring name resolution, which may include\ntime synchronization, centralized authentication, and remote system logging.\"\n  impact 0.3\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72281\"\n  tag \"rid\": \"SV-86905r1_rule\"\n  tag \"stig_id\": \"RHEL-07-040600\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['dns', 'resolv']\n  desc \"check\", \"Determine whether the system is using local or DNS name\nresolution with the following command:\n\n# grep hosts /etc/nsswitch.conf\nhosts:   files dns\n\nIf the DNS entry is missing from the host’s line in the \\\"/etc/nsswitch.conf\\\"\nfile, the \\\"/etc/resolv.conf\\\" file must be empty.\n\nVerify the \\\"/etc/resolv.conf\\\" file is empty with the following command:\n\n# ls -al /etc/resolv.conf\n-rw-r--r--  1 root root        0 Aug 19 08:31 resolv.conf\n\nIf local host authentication is being used and the \\\"/etc/resolv.conf\\\" file is\nnot empty, this is a finding.\n\nIf the DNS entry is found on the host’s line of the \\\"/etc/nsswitch.conf\\\"\nfile, verify the operating system is configured to use two or more name servers\nfor DNS resolution.\n\nDetermine the name servers used by the system with the following command:\n\n# grep nameserver /etc/resolv.conf\nnameserver 192.168.1.2\nnameserver 192.168.1.3\n\nIf less than two lines are returned that are not commented out, this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to use two or more name servers\nfor DNS resolution.\n\nEdit the \\\"/etc/resolv.conf\\\" file to uncomment or add the two or more\n\\\"nameserver\\\" option lines with the IP address of local authoritative name\nservers. If local host resolution is being performed, the \\\"/etc/resolv.conf\\\"\nfile must be empty. An empty \\\"/etc/resolv.conf\\\" file can be created as\nfollows:\n\n# echo -n > /etc/resolv.conf\n\nAnd then make the file immutable with the following command:\n\n# chattr +i /etc/resolv.conf\n\nIf the \\\"/etc/resolv.conf\\\" file must be mutable, the required configuration\nmust be documented with the Information System Security Officer (ISSO) and the\nfile must be verified by the system file integrity tool.\"\n  tag \"fix_id\": \"F-78635r1_fix\"\n\n  dns_in_host_line = parse_config_file(\"/etc/nsswitch.conf\",\n    {\n      comment_char: '#',\n      assignment_regex: /^\\s*([^:]*?)\\s*:\\s*(.*?)\\s*$/,\n    }\n  ).params['hosts'].include?('dns')\n\n  describe \"If `local` resolution is being used, a `hosts` entry in /etc/nsswitch.conf having `dns`\" do\n    subject { dns_in_host_line }\n    it { should be false }\n  end if !dns_in_host_line\n\n  describe \"If `local` resoultion is being used, the /etc/resolv.conf file should\" do\n    subject { parse_config_file(\"/etc/resolv.conf\", { comment_char: '#'}).params }\n    it { should be_empty }\n  end if !dns_in_host_line\n\n  nameservers = parse_config_file(\"/etc/resolv.conf\",\n    { comment_char: '#'}\n  ).params.keys.grep(/nameserver/)\n\n  describe \"The system's nameservers: #{nameservers}\" do\n  subject { nameservers }\n    it { should_not be nil }\n  end if dns_in_host_line\n\n  describe \"The number of nameservers\" do\n  subject { nameservers.count }\n    it { should cmp >= 2 }\n  end if dns_in_host_line\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72281.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "The system's nameservers: [\"nameserver 10.20.100.53\", \"nameserver 10.20.200.53\"] should not equal nil",
              "run_time": 0.000234991,
              "start_time": "2019-11-04T16:17:17-05:00"
            },
            {
              "status": "passed",
              "code_desc": "The number of nameservers should cmp >= 2",
              "run_time": 0.000183086,
              "start_time": "2019-11-04T16:17:17-05:00"
            }
          ]
        },
        {
          "id": "V-72283",
          "title": "The system must not forward Internet Protocol version 4 (IPv4)\nsource-routed packets.",
          "desc": "Source-routed packets allow the source of the packet to suggest that\nrouters forward the packet along a different path than configured on the\nrouter, which can be used to bypass network security measures. This requirement\napplies only to the forwarding of source-routed traffic, such as when IPv4\nforwarding is enabled and the system is functioning as a router.",
          "descriptions": [
            {
              "label": "default",
              "data": "Source-routed packets allow the source of the packet to suggest that\nrouters forward the packet along a different path than configured on the\nrouter, which can be used to bypass network security measures. This requirement\napplies only to the forwarding of source-routed traffic, such as when IPv4\nforwarding is enabled and the system is functioning as a router."
            },
            {
              "label": "check",
              "data": "Verify the system does not accept IPv4 source-routed packets.\n\nCheck the value of the accept source route variable with the following command:\n\n# /sbin/sysctl -a | grep  net.ipv4.conf.all.accept_source_route\nnet.ipv4.conf.all.accept_source_route=0\n\nIf the returned line does not have a value of \"0\", a line is not returned, or\nthe returned line is commented out, this is a finding."
            },
            {
              "label": "fix",
              "data": "Set the system to the required kernel parameter by adding the\nfollowing line to \"/etc/sysctl.conf\" (or modify the line to have the required\nvalue):\n\nnet.ipv4.conf.all.accept_source_route = 0"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72283",
            "rid": "SV-86907r1_rule",
            "stig_id": "RHEL-07-040610",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "kernel_parameter"
            ],
            "fix_id": "F-78637r1_fix"
          },
          "code": "control \"V-72283\" do\n  title \"The system must not forward Internet Protocol version 4 (IPv4)\nsource-routed packets.\"\n  desc  \"Source-routed packets allow the source of the packet to suggest that\nrouters forward the packet along a different path than configured on the\nrouter, which can be used to bypass network security measures. This requirement\napplies only to the forwarding of source-routed traffic, such as when IPv4\nforwarding is enabled and the system is functioning as a router.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72283\"\n  tag \"rid\": \"SV-86907r1_rule\"\n  tag \"stig_id\": \"RHEL-07-040610\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['kernel_parameter']\n  desc \"check\", \"Verify the system does not accept IPv4 source-routed packets.\n\nCheck the value of the accept source route variable with the following command:\n\n# /sbin/sysctl -a | grep  net.ipv4.conf.all.accept_source_route\nnet.ipv4.conf.all.accept_source_route=0\n\nIf the returned line does not have a value of \\\"0\\\", a line is not returned, or\nthe returned line is commented out, this is a finding.\"\n  desc \"fix\", \"Set the system to the required kernel parameter by adding the\nfollowing line to \\\"/etc/sysctl.conf\\\" (or modify the line to have the required\nvalue):\n\nnet.ipv4.conf.all.accept_source_route = 0\"\n  tag \"fix_id\": \"F-78637r1_fix\"\n\n  describe kernel_parameter('net.ipv4.conf.all.accept_source_route') do\n    its('value') { should eq 0 }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72283.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Kernel Parameter net.ipv4.conf.all.accept_source_route value should eq 0",
              "run_time": 0.015731554,
              "start_time": "2019-11-04T16:17:17-05:00"
            }
          ]
        },
        {
          "id": "V-72285",
          "title": "The system must not forward Internet Protocol version 4 (IPv4)\nsource-routed packets by default.",
          "desc": "Source-routed packets allow the source of the packet to suggest that\nrouters forward the packet along a different path than configured on the\nrouter, which can be used to bypass network security measures. This requirement\napplies only to the forwarding of source-routed traffic, such as when IPv4\nforwarding is enabled and the system is functioning as a router.",
          "descriptions": [
            {
              "label": "default",
              "data": "Source-routed packets allow the source of the packet to suggest that\nrouters forward the packet along a different path than configured on the\nrouter, which can be used to bypass network security measures. This requirement\napplies only to the forwarding of source-routed traffic, such as when IPv4\nforwarding is enabled and the system is functioning as a router."
            },
            {
              "label": "check",
              "data": "Verify the system does not accept IPv4 source-routed packets by\ndefault.\n\nCheck the value of the accept source route variable with the following command:\n\n# /sbin/sysctl -a | grep  net.ipv4.conf.default.accept_source_route\nnet.ipv4.conf.default.accept_source_route=0\n\nIf the returned line does not have a value of \"0\", a line is not returned, or\nthe returned line is commented out, this is a finding."
            },
            {
              "label": "fix",
              "data": "Set the system to the required kernel parameter by adding the\nfollowing line to \"/etc/sysctl.conf\" (or modify the line to have the required\nvalue):\n\nnet.ipv4.conf.default.accept_source_route = 0"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72285",
            "rid": "SV-86909r1_rule",
            "stig_id": "RHEL-07-040620",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "kernel_parameter"
            ],
            "fix_id": "F-78639r1_fix"
          },
          "code": "control \"V-72285\" do\n  title \"The system must not forward Internet Protocol version 4 (IPv4)\nsource-routed packets by default.\"\n  desc  \"Source-routed packets allow the source of the packet to suggest that\nrouters forward the packet along a different path than configured on the\nrouter, which can be used to bypass network security measures. This requirement\napplies only to the forwarding of source-routed traffic, such as when IPv4\nforwarding is enabled and the system is functioning as a router.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72285\"\n  tag \"rid\": \"SV-86909r1_rule\"\n  tag \"stig_id\": \"RHEL-07-040620\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['kernel_parameter']\n  desc \"check\", \"Verify the system does not accept IPv4 source-routed packets by\ndefault.\n\nCheck the value of the accept source route variable with the following command:\n\n# /sbin/sysctl -a | grep  net.ipv4.conf.default.accept_source_route\nnet.ipv4.conf.default.accept_source_route=0\n\nIf the returned line does not have a value of \\\"0\\\", a line is not returned, or\nthe returned line is commented out, this is a finding.\"\n  desc \"fix\", \"Set the system to the required kernel parameter by adding the\nfollowing line to \\\"/etc/sysctl.conf\\\" (or modify the line to have the required\nvalue):\n\nnet.ipv4.conf.default.accept_source_route = 0\"\n  tag \"fix_id\": \"F-78639r1_fix\"\n\n  describe kernel_parameter('net.ipv4.conf.default.accept_source_route') do\n    its('value') { should eq 0 }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72285.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Kernel Parameter net.ipv4.conf.default.accept_source_route value should eq 0",
              "run_time": 0.01573367,
              "start_time": "2019-11-04T16:17:17-05:00"
            }
          ]
        },
        {
          "id": "V-72287",
          "title": "The system must not respond to Internet Protocol version 4 (IPv4)\nInternet Control Message Protocol (ICMP) echoes sent to a broadcast address.",
          "desc": "Responding to broadcast (ICMP) echoes facilitates network mapping and\nprovides a vector for amplification attacks.",
          "descriptions": [
            {
              "label": "default",
              "data": "Responding to broadcast (ICMP) echoes facilitates network mapping and\nprovides a vector for amplification attacks."
            },
            {
              "label": "check",
              "data": "Verify the system does not respond to IPv4 ICMP echoes sent to\na broadcast address.\n\nCheck the value of the \"icmp_echo_ignore_broadcasts\" variable with the\nfollowing command:\n\n# /sbin/sysctl -a | grep  net.ipv4.icmp_echo_ignore_broadcasts\nnet.ipv4.icmp_echo_ignore_broadcasts=1\n\nIf the returned line does not have a value of \"1\", a line is not returned, or\nthe retuned line is commented out, this is a finding."
            },
            {
              "label": "fix",
              "data": "Set the system to the required kernel parameter by adding the\nfollowing line to \"/etc/sysctl.conf\" (or modify the line to have the required\nvalue):\n\nnet.ipv4.icmp_echo_ignore_broadcasts=1"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72287",
            "rid": "SV-86911r1_rule",
            "stig_id": "RHEL-07-040630",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "kernel_parameter"
            ],
            "fix_id": "F-78641r1_fix"
          },
          "code": "control \"V-72287\" do\n  title \"The system must not respond to Internet Protocol version 4 (IPv4)\nInternet Control Message Protocol (ICMP) echoes sent to a broadcast address.\"\n  desc  \"Responding to broadcast (ICMP) echoes facilitates network mapping and\nprovides a vector for amplification attacks.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72287\"\n  tag \"rid\": \"SV-86911r1_rule\"\n  tag \"stig_id\": \"RHEL-07-040630\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['kernel_parameter']\n  desc \"check\", \"Verify the system does not respond to IPv4 ICMP echoes sent to\na broadcast address.\n\nCheck the value of the \\\"icmp_echo_ignore_broadcasts\\\" variable with the\nfollowing command:\n\n# /sbin/sysctl -a | grep  net.ipv4.icmp_echo_ignore_broadcasts\nnet.ipv4.icmp_echo_ignore_broadcasts=1\n\nIf the returned line does not have a value of \\\"1\\\", a line is not returned, or\nthe retuned line is commented out, this is a finding.\"\n  desc \"fix\", \"Set the system to the required kernel parameter by adding the\nfollowing line to \\\"/etc/sysctl.conf\\\" (or modify the line to have the required\nvalue):\n\nnet.ipv4.icmp_echo_ignore_broadcasts=1\"\n  tag \"fix_id\": \"F-78641r1_fix\"\n\n  describe kernel_parameter('net.ipv4.icmp_echo_ignore_broadcasts') do\n    its('value') { should eq 1 }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72287.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Kernel Parameter net.ipv4.icmp_echo_ignore_broadcasts value should eq 1",
              "run_time": 0.015138998,
              "start_time": "2019-11-04T16:17:17-05:00"
            }
          ]
        },
        {
          "id": "V-72289",
          "title": "The system must prevent Internet Protocol version 4 (IPv4) Internet\nControl Message Protocol (ICMP) redirect messages from being accepted.",
          "desc": "ICMP redirect messages are used by routers to inform hosts that a more\ndirect route exists for a particular destination. These messages modify the\nhost's route table and are unauthenticated. An illicit ICMP redirect message\ncould result in a man-in-the-middle attack.",
          "descriptions": [
            {
              "label": "default",
              "data": "ICMP redirect messages are used by routers to inform hosts that a more\ndirect route exists for a particular destination. These messages modify the\nhost's route table and are unauthenticated. An illicit ICMP redirect message\ncould result in a man-in-the-middle attack."
            },
            {
              "label": "check",
              "data": "Verify the system will not accept IPv4 ICMP redirect messages.\n\nCheck the value of the default \"accept_redirects\" variables with the\nfollowing command:\n\n# /sbin/sysctl -a | grep  'net.ipv4.conf.default.accept_redirects'\nnet.ipv4.conf.default.accept_redirects=0\n\nIf the returned line does not have a value of \"0\", or a line is not returned,\nthis is a finding."
            },
            {
              "label": "fix",
              "data": "Set the system to not accept IPv4 ICMP redirect messages by\nadding the following line to \"/etc/sysctl.conf\" (or modify the line to have\nthe required value):\n\nnet.ipv4.conf.default.accept_redirects = 0"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72289",
            "rid": "SV-86913r2_rule",
            "stig_id": "RHEL-07-040640",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "kernel_parameter"
            ],
            "fix_id": "F-78643r2_fix"
          },
          "code": "control \"V-72289\" do\n  title \"The system must prevent Internet Protocol version 4 (IPv4) Internet\nControl Message Protocol (ICMP) redirect messages from being accepted.\"\n  desc  \"ICMP redirect messages are used by routers to inform hosts that a more\ndirect route exists for a particular destination. These messages modify the\nhost's route table and are unauthenticated. An illicit ICMP redirect message\ncould result in a man-in-the-middle attack.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72289\"\n  tag \"rid\": \"SV-86913r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040640\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['kernel_parameter']\n  desc \"check\", \"Verify the system will not accept IPv4 ICMP redirect messages.\n\nCheck the value of the default \\\"accept_redirects\\\" variables with the\nfollowing command:\n\n# /sbin/sysctl -a | grep  'net.ipv4.conf.default.accept_redirects'\nnet.ipv4.conf.default.accept_redirects=0\n\nIf the returned line does not have a value of \\\"0\\\", or a line is not returned,\nthis is a finding.\"\n  desc \"fix\", \"Set the system to not accept IPv4 ICMP redirect messages by\nadding the following line to \\\"/etc/sysctl.conf\\\" (or modify the line to have\nthe required value):\n\nnet.ipv4.conf.default.accept_redirects = 0\"\n  tag \"fix_id\": \"F-78643r2_fix\"\n\n  describe kernel_parameter('net.ipv4.conf.default.accept_redirects') do\n    its('value') { should eq 0 }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72289.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Kernel Parameter net.ipv4.conf.default.accept_redirects value should eq 0",
              "run_time": 0.015175889,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "\nexpected: 0\n     got: 1\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72291",
          "title": "The system must not allow interfaces to perform Internet Protocol\nversion 4 (IPv4) Internet Control Message Protocol (ICMP) redirects by default.",
          "desc": "ICMP redirect messages are used by routers to inform hosts that a more\ndirect route exists for a particular destination. These messages contain\ninformation from the system's route table, possibly revealing portions of the\nnetwork topology.",
          "descriptions": [
            {
              "label": "default",
              "data": "ICMP redirect messages are used by routers to inform hosts that a more\ndirect route exists for a particular destination. These messages contain\ninformation from the system's route table, possibly revealing portions of the\nnetwork topology."
            },
            {
              "label": "check",
              "data": "Verify the system does not allow interfaces to perform IPv4\nICMP redirects by default.\n\nCheck the value of the \"default send_redirects\" variables with the following\ncommand:\n\n# /sbin/sysctl -a | grep 'net.ipv4.conf.default.send_redirects'\n\nnet.ipv4.conf.default.send_redirects = 0\n\nIf the returned line does not have a value of \"0\", or a line is not returned,\nthis is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the system to not allow interfaces to perform IPv4 ICMP\nredirects by default.\n\nSet the system to the required kernel parameter by adding the following line to\n\"/etc/sysctl.conf\" (or modify the line to have the required value):\n\nnet.ipv4.conf.default.send_redirects=0\n\nIssue the following command to make the changes take effect:\n\n# sysctl -p /etc/sysctl.conf"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72291",
            "rid": "SV-86915r3_rule",
            "stig_id": "RHEL-07-040650",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "kernel_parameter"
            ],
            "fix_id": "F-78645r3_fix"
          },
          "code": "control \"V-72291\" do\n  title \"The system must not allow interfaces to perform Internet Protocol\nversion 4 (IPv4) Internet Control Message Protocol (ICMP) redirects by default.\"\n  desc  \"ICMP redirect messages are used by routers to inform hosts that a more\ndirect route exists for a particular destination. These messages contain\ninformation from the system's route table, possibly revealing portions of the\nnetwork topology.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72291\"\n  tag \"rid\": \"SV-86915r3_rule\"\n  tag \"stig_id\": \"RHEL-07-040650\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['kernel_parameter']\n  desc \"check\", \"Verify the system does not allow interfaces to perform IPv4\nICMP redirects by default.\n\nCheck the value of the \\\"default send_redirects\\\" variables with the following\ncommand:\n\n# /sbin/sysctl -a | grep 'net.ipv4.conf.default.send_redirects'\n\nnet.ipv4.conf.default.send_redirects = 0\n\nIf the returned line does not have a value of \\\"0\\\", or a line is not returned,\nthis is a finding.\"\n  desc \"fix\", \"Configure the system to not allow interfaces to perform IPv4 ICMP\nredirects by default.\n\nSet the system to the required kernel parameter by adding the following line to\n\\\"/etc/sysctl.conf\\\" (or modify the line to have the required value):\n\nnet.ipv4.conf.default.send_redirects=0\n\nIssue the following command to make the changes take effect:\n\n# sysctl -p /etc/sysctl.conf\"\n  tag \"fix_id\": \"F-78645r3_fix\"\n\n  describe kernel_parameter('net.ipv4.conf.default.send_redirects') do\n    its('value') { should eq 0 }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72291.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Kernel Parameter net.ipv4.conf.default.send_redirects value should eq 0",
              "run_time": 0.01801669,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "\nexpected: 0\n     got: 1\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72293",
          "title": "The system must not send Internet Protocol version 4 (IPv4) Internet\nControl Message Protocol (ICMP) redirects.",
          "desc": "ICMP redirect messages are used by routers to inform hosts that a more\ndirect route exists for a particular destination. These messages contain\ninformation from the system's route table, possibly revealing portions of the\nnetwork topology.",
          "descriptions": [
            {
              "label": "default",
              "data": "ICMP redirect messages are used by routers to inform hosts that a more\ndirect route exists for a particular destination. These messages contain\ninformation from the system's route table, possibly revealing portions of the\nnetwork topology."
            },
            {
              "label": "check",
              "data": "Verify the system does not send IPv4 ICMP redirect messages.\n\nCheck the value of the \"all send_redirects\" variables with the following\ncommand:\n\n# grep  'net.ipv4.conf.all.send_redirects' /etc/sysctl.conf\n\nnet.ipv4.conf.all.send_redirects=0\n\nIf the returned line does not have a value of \"0\", or a line is not returned,\nthis is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the system to not allow interfaces to perform IPv4 ICMP\nredirects.\n\nSet the system to the required kernel parameter by adding the following line to\n\"/etc/sysctl.conf\" (or modify the line to have the required value):\n\nnet.ipv4.conf.all.send_redirects=0"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72293",
            "rid": "SV-86917r2_rule",
            "stig_id": "RHEL-07-040660",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "kernel_parameter"
            ],
            "fix_id": "F-78647r2_fix"
          },
          "code": "control \"V-72293\" do\n  title \"The system must not send Internet Protocol version 4 (IPv4) Internet\nControl Message Protocol (ICMP) redirects.\"\n  desc  \"ICMP redirect messages are used by routers to inform hosts that a more\ndirect route exists for a particular destination. These messages contain\ninformation from the system's route table, possibly revealing portions of the\nnetwork topology.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72293\"\n  tag \"rid\": \"SV-86917r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040660\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['kernel_parameter']\n  desc \"check\", \"Verify the system does not send IPv4 ICMP redirect messages.\n\nCheck the value of the \\\"all send_redirects\\\" variables with the following\ncommand:\n\n# grep  'net.ipv4.conf.all.send_redirects' /etc/sysctl.conf\n\nnet.ipv4.conf.all.send_redirects=0\n\nIf the returned line does not have a value of \\\"0\\\", or a line is not returned,\nthis is a finding.\"\n  desc \"fix\", \"Configure the system to not allow interfaces to perform IPv4 ICMP\nredirects.\n\nSet the system to the required kernel parameter by adding the following line to\n\\\"/etc/sysctl.conf\\\" (or modify the line to have the required value):\n\nnet.ipv4.conf.all.send_redirects=0\"\n  tag \"fix_id\": \"F-78647r2_fix\"\n\n  describe kernel_parameter('net.ipv4.conf.all.send_redirects') do\n    its('value') { should eq 0 }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72293.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Kernel Parameter net.ipv4.conf.all.send_redirects value should eq 0",
              "run_time": 0.015774644,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "\nexpected: 0\n     got: 1\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72295",
          "title": "Network interfaces must not be in promiscuous mode.",
          "desc": "Network interfaces in promiscuous mode allow for the capture of all network\ntraffic visible to the system. If unauthorized individuals can access these\napplications, it may allow then to collect information such as logon IDs,\npasswords, and key exchanges between systems.\n\n    If the system is being used to perform a network troubleshooting function,\nthe use of these tools must be documented with the Information System Security\nOfficer (ISSO) and restricted to only authorized personnel.",
          "descriptions": [
            {
              "label": "default",
              "data": "Network interfaces in promiscuous mode allow for the capture of all network\ntraffic visible to the system. If unauthorized individuals can access these\napplications, it may allow then to collect information such as logon IDs,\npasswords, and key exchanges between systems.\n\n    If the system is being used to perform a network troubleshooting function,\nthe use of these tools must be documented with the Information System Security\nOfficer (ISSO) and restricted to only authorized personnel."
            },
            {
              "label": "check",
              "data": "Verify network interfaces are not in promiscuous mode unless\n  approved by the ISSO and documented.\n\n  Check for the status with the following command:\n\n  # ip link | grep -i promisc\n\n  If network interfaces are found on the system in promiscuous mode and their use\n  has not been approved by the ISSO and documented, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure network interfaces to turn off promiscuous mode unless\n  approved by the ISSO and documented.\n\n  Set the promiscuous mode of an interface to off with the following command:\n\n  #ip link set dev <devicename> multicast off promisc off"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72295",
            "rid": "SV-86919r1_rule",
            "stig_id": "RHEL-07-040670",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "network",
              "ip_link"
            ],
            "fix_id": "F-78649r1_fix"
          },
          "code": "control \"V-72295\" do\n  title \"Network interfaces must not be in promiscuous mode.\"\n  desc  \"\n    Network interfaces in promiscuous mode allow for the capture of all network\ntraffic visible to the system. If unauthorized individuals can access these\napplications, it may allow then to collect information such as logon IDs,\npasswords, and key exchanges between systems.\n\n    If the system is being used to perform a network troubleshooting function,\nthe use of these tools must be documented with the Information System Security\nOfficer (ISSO) and restricted to only authorized personnel.\n  \"\n  impact 0.5\n\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72295\"\n  tag \"rid\": \"SV-86919r1_rule\"\n  tag \"stig_id\": \"RHEL-07-040670\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['network', 'ip_link']\n  tag \"fix_id\": \"F-78649r1_fix\"\n\n  desc \"check\", \"Verify network interfaces are not in promiscuous mode unless\n  approved by the ISSO and documented.\n\n  Check for the status with the following command:\n\n  # ip link | grep -i promisc\n\n  If network interfaces are found on the system in promiscuous mode and their use\n  has not been approved by the ISSO and documented, this is a finding.\"\n  \n  desc \"fix\", \"Configure network interfaces to turn off promiscuous mode unless\n  approved by the ISSO and documented.\n\n  Set the promiscuous mode of an interface to off with the following command:\n\n  #ip link set dev <devicename> multicast off promisc off\"\n\n  # @todo - test against list of approved interfaces\n  describe command(\"ip link | grep -i promisc\") do\n    its('stdout.strip') { should match %r{^$} }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72295.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Command: `ip link | grep -i promisc` stdout.strip should match /^$/",
              "run_time": 0.018898607,
              "start_time": "2019-11-04T16:17:17-05:00"
            }
          ]
        },
        {
          "id": "V-72297",
          "title": "The system must be configured to prevent unrestricted mail relaying.",
          "desc": "If unrestricted mail relaying is permitted, unauthorized senders could\nuse this host as a mail relay for the purpose of sending spam or other\nunauthorized activity.",
          "descriptions": [
            {
              "label": "default",
              "data": "If unrestricted mail relaying is permitted, unauthorized senders could\nuse this host as a mail relay for the purpose of sending spam or other\nunauthorized activity."
            },
            {
              "label": "check",
              "data": "Verify the system is configured to prevent unrestricted mail\nrelaying.\n\nDetermine if \"postfix\" is installed with the following commands:\n\n# yum list installed postfix\npostfix-2.6.6-6.el7.x86_64.rpm\n\nIf postfix is not installed, this is Not Applicable.\n\nIf postfix is installed, determine if it is configured to reject connections\nfrom unknown or untrusted networks with the following command:\n\n# postconf -n smtpd_client_restrictions\nsmtpd_client_restrictions = permit_mynetworks, reject\n\nIf the \"smtpd_client_restrictions\" parameter contains any entries other than\n\"permit_mynetworks\" and \"reject\", this is a finding."
            },
            {
              "label": "fix",
              "data": "If \"postfix\" is installed, modify the \"/etc/postfix/main.cf\"\nfile to restrict client connections to the local network with the following\ncommand:\n\n# postconf -e 'smtpd_client_restrictions = permit_mynetworks,reject'"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72297",
            "rid": "SV-86921r2_rule",
            "stig_id": "RHEL-07-040680",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "postfix"
            ],
            "fix_id": "F-78651r2_fix"
          },
          "code": "control \"V-72297\" do\n  title \"The system must be configured to prevent unrestricted mail relaying.\"\n  desc  \"If unrestricted mail relaying is permitted, unauthorized senders could\nuse this host as a mail relay for the purpose of sending spam or other\nunauthorized activity.\"\nif package('postfix').installed?\n  impact 0.5\nelse\n  impact 0.0\nend\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72297\"\n  tag \"rid\": \"SV-86921r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040680\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['postfix']\n  desc \"check\", \"Verify the system is configured to prevent unrestricted mail\nrelaying.\n\nDetermine if \\\"postfix\\\" is installed with the following commands:\n\n# yum list installed postfix\npostfix-2.6.6-6.el7.x86_64.rpm\n\nIf postfix is not installed, this is Not Applicable.\n\nIf postfix is installed, determine if it is configured to reject connections\nfrom unknown or untrusted networks with the following command:\n\n# postconf -n smtpd_client_restrictions\nsmtpd_client_restrictions = permit_mynetworks, reject\n\nIf the \\\"smtpd_client_restrictions\\\" parameter contains any entries other than\n\\\"permit_mynetworks\\\" and \\\"reject\\\", this is a finding.\"\n  desc \"fix\", \"If \\\"postfix\\\" is installed, modify the \\\"/etc/postfix/main.cf\\\"\nfile to restrict client connections to the local network with the following\ncommand:\n\n# postconf -e 'smtpd_client_restrictions = permit_mynetworks,reject'\"\n  tag \"fix_id\": \"F-78651r2_fix\"\n\n  # Only permit_mynetworks and reject should be allowed\n  describe.one do\n    describe command('postconf -n smtpd_client_restrictions') do\n      its('stdout.strip') { should match %r{^smtpd_client_restrictions\\s+=\\s+permit_mynetworks,\\s*reject\\s*$} }\n    end\n    describe command('postconf -n smtpd_client_restrictions') do\n      its('stdout.strip') { should match %r{^smtpd_client_restrictions\\s+=\\s+permit_mynetworks\\s*$} }\n    end\n    describe command('postconf -n smtpd_client_restrictions') do\n      its('stdout.strip') { should match %r{^smtpd_client_restrictions\\s+=\\s+reject\\s*$} }\n    end\n    describe command('postconf -n smtpd_client_restrictions') do\n      its('stdout.strip') { should match %r{^smtpd_client_restrictions\\s+=\\s+reject,\\s*permit_mynetworks\\s*$} }\n    end\n  end if package('postfix').installed?\n\n  describe \"The `postfix` package is not installed\" do\n    skip \"The `postfix` package is not installed, this control is Not Applicable\"\n  end if !package('postfix').installed?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72297.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Command: `postconf -n smtpd_client_restrictions` stdout.strip should match /^smtpd_client_restrictions\\s+=\\s+permit_mynetworks,\\s*reject\\s*$/",
              "run_time": 0.000424615,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "expected \"\" to match /^smtpd_client_restrictions\\s+=\\s+permit_mynetworks,\\s*reject\\s*$/\nDiff:\n@@ -1,2 +1,2 @@\n-/^smtpd_client_restrictions\\s+=\\s+permit_mynetworks,\\s*reject\\s*$/\n+\"\"\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Command: `postconf -n smtpd_client_restrictions` stdout.strip should match /^smtpd_client_restrictions\\s+=\\s+permit_mynetworks\\s*$/",
              "run_time": 0.000233278,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "expected \"\" to match /^smtpd_client_restrictions\\s+=\\s+permit_mynetworks\\s*$/\nDiff:\n@@ -1,2 +1,2 @@\n-/^smtpd_client_restrictions\\s+=\\s+permit_mynetworks\\s*$/\n+\"\"\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Command: `postconf -n smtpd_client_restrictions` stdout.strip should match /^smtpd_client_restrictions\\s+=\\s+reject\\s*$/",
              "run_time": 0.000298146,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "expected \"\" to match /^smtpd_client_restrictions\\s+=\\s+reject\\s*$/\nDiff:\n@@ -1,2 +1,2 @@\n-/^smtpd_client_restrictions\\s+=\\s+reject\\s*$/\n+\"\"\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            },
            {
              "status": "failed",
              "code_desc": "Command: `postconf -n smtpd_client_restrictions` stdout.strip should match /^smtpd_client_restrictions\\s+=\\s+reject,\\s*permit_mynetworks\\s*$/",
              "run_time": 0.000200265,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "expected \"\" to match /^smtpd_client_restrictions\\s+=\\s+reject,\\s*permit_mynetworks\\s*$/\nDiff:\n@@ -1,2 +1,2 @@\n-/^smtpd_client_restrictions\\s+=\\s+reject,\\s*permit_mynetworks\\s*$/\n+\"\"\n",
              "exception": "RSpec::Core::MultipleExceptionError"
            }
          ]
        },
        {
          "id": "V-72299",
          "title": "A File Transfer Protocol (FTP) server package must not be installed\nunless needed.",
          "desc": "The FTP service provides an unencrypted remote access that does not\nprovide for the confidentiality and integrity of user passwords or the remote\nsession. If a privileged user were to log on using this service, the privileged\nuser password could be compromised. SSH or other encrypted file transfer\nmethods must be used in place of this service.",
          "descriptions": [
            {
              "label": "default",
              "data": "The FTP service provides an unencrypted remote access that does not\nprovide for the confidentiality and integrity of user passwords or the remote\nsession. If a privileged user were to log on using this service, the privileged\nuser password could be compromised. SSH or other encrypted file transfer\nmethods must be used in place of this service."
            },
            {
              "label": "check",
              "data": "Verify an FTP server has not been installed on the system.\n\nCheck to see if an FTP server has been installed with the following commands:\n\n# yum list installed vsftpd\n\n vsftpd-3.0.2.el7.x86_64.rpm\n\nIf \"vsftpd\" is installed and is not documented with the Information System\nSecurity Officer (ISSO) as an operational requirement, this is a finding."
            },
            {
              "label": "fix",
              "data": "Document the \"vsftpd\" package with the ISSO as an operational\nrequirement or remove it from the system with the following command:\n\n# yum remove vsftpd"
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72299",
            "rid": "SV-86923r2_rule",
            "stig_id": "RHEL-07-040690",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "vsftpd"
            ],
            "fix_id": "F-78653r2_fix"
          },
          "code": "control \"V-72299\" do\n  title \"A File Transfer Protocol (FTP) server package must not be installed\nunless needed.\"\n  desc  \"The FTP service provides an unencrypted remote access that does not\nprovide for the confidentiality and integrity of user passwords or the remote\nsession. If a privileged user were to log on using this service, the privileged\nuser password could be compromised. SSH or other encrypted file transfer\nmethods must be used in place of this service.\"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72299\"\n  tag \"rid\": \"SV-86923r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040690\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['vsftpd']\n  desc \"check\", \"Verify an FTP server has not been installed on the system.\n\nCheck to see if an FTP server has been installed with the following commands:\n\n# yum list installed vsftpd\n\n vsftpd-3.0.2.el7.x86_64.rpm\n\nIf \\\"vsftpd\\\" is installed and is not documented with the Information System\nSecurity Officer (ISSO) as an operational requirement, this is a finding.\n\"\n  desc \"fix\", \"Document the \\\"vsftpd\\\" package with the ISSO as an operational\nrequirement or remove it from the system with the following command:\n\n# yum remove vsftpd\n\"\n  tag \"fix_id\": \"F-78653r2_fix\"\n\n  describe.one do\n    describe package('vsftpd') do\n      it { should_not be_installed }\n    end\n    describe parse_config_file('/etc/vsftpd/vsftpd.conf') do\n      its('ssl_enable') { should cmp 'YES' }\n      its('force_anon_data_ssl') { should cmp 'YES' }\n      its('force_anon_logins_ssl') { should cmp 'YES' }\n      its('force_local_data_ssl') { should cmp 'YES' }\n      its('force_local_logins_ssl') { should cmp 'YES' }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72299.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "System Package vsftpd should not be installed",
              "run_time": 0.000167552,
              "start_time": "2019-11-04T16:17:17-05:00"
            }
          ]
        },
        {
          "id": "V-72301",
          "title": "The Trivial File Transfer Protocol (TFTP) server package must not be\ninstalled if not required for operational support.",
          "desc": "If TFTP is required for operational support (such as the transmission\nof router configurations) its use must be documented with the Information\nSystem Security Officer (ISSO), restricted to only authorized personnel, and\nhave access control rules established.",
          "descriptions": [
            {
              "label": "default",
              "data": "If TFTP is required for operational support (such as the transmission\nof router configurations) its use must be documented with the Information\nSystem Security Officer (ISSO), restricted to only authorized personnel, and\nhave access control rules established."
            },
            {
              "label": "check",
              "data": "Verify a TFTP server has not been installed on the system.\n\nCheck to see if a TFTP server has been installed with the following command:\n\n# yum list installed tftp-server\ntftp-server-0.49-9.el7.x86_64.rpm\n\nIf TFTP is installed and the requirement for TFTP is not documented with the\nISSO, this is a finding."
            },
            {
              "label": "fix",
              "data": "Remove the TFTP package from the system with the following\ncommand:\n\n# yum remove tftp"
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72301",
            "rid": "SV-86925r1_rule",
            "stig_id": "RHEL-07-040700",
            "cci": [
              "CCI-000318",
              "CCI-000368",
              "CCI-001812",
              "CCI-001813",
              "CCI-001814"
            ],
            "documentable": false,
            "nist": [
              "CM-3 f",
              "CM-6 c",
              "CM-11 (2)",
              "CM-5 (1)",
              "CM-5 (1)",
              "Rev_4"
            ],
            "subsystems": [
              "tftp"
            ],
            "fix_id": "F-78655r1_fix"
          },
          "code": "control \"V-72301\" do\n  title \"The Trivial File Transfer Protocol (TFTP) server package must not be\ninstalled if not required for operational support.\"\n  desc  \"If TFTP is required for operational support (such as the transmission\nof router configurations) its use must be documented with the Information\nSystem Security Officer (ISSO), restricted to only authorized personnel, and\nhave access control rules established.\"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72301\"\n  tag \"rid\": \"SV-86925r1_rule\"\n  tag \"stig_id\": \"RHEL-07-040700\"\n  tag \"cci\": [\"CCI-000318\", \"CCI-000368\", \"CCI-001812\", \"CCI-001813\",\n\"CCI-001814\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-3 f\", \"CM-6 c\", \"CM-11 (2)\", \"CM-5 (1)\", \"CM-5 (1)\", \"Rev_4\"]\n  tag \"subsystems\": ['tftp']\n  desc \"check\", \"Verify a TFTP server has not been installed on the system.\n\nCheck to see if a TFTP server has been installed with the following command:\n\n# yum list installed tftp-server\ntftp-server-0.49-9.el7.x86_64.rpm\n\nIf TFTP is installed and the requirement for TFTP is not documented with the\nISSO, this is a finding.\"\n  desc \"fix\", \"Remove the TFTP package from the system with the following\ncommand:\n\n# yum remove tftp\"\n  tag \"fix_id\": \"F-78655r1_fix\"\n\n  describe package('tftp-server') do\n    it { should_not be_installed }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72301.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "System Package tftp-server should not be installed",
              "run_time": 0.000118455,
              "start_time": "2019-11-04T16:17:17-05:00"
            }
          ]
        },
        {
          "id": "V-72303",
          "title": "Remote X connections for interactive users must be encrypted.",
          "desc": "Open X displays allow an attacker to capture keystrokes and execute\ncommands remotely.",
          "descriptions": [
            {
              "label": "default",
              "data": "Open X displays allow an attacker to capture keystrokes and execute\ncommands remotely."
            },
            {
              "label": "check",
              "data": "Verify remote X connections for interactive users are encrypted.\n\nCheck that remote X connections are encrypted with the following command:\n\n# grep -i x11forwarding /etc/ssh/sshd_config\n\nX11Forwarding yes\n\nIf the \"X11Forwarding\" keyword is set to \"no\", is missing, or is commented\nout, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure SSH to encrypt connections for interactive users.\n\nEdit the \"/etc/ssh/sshd_config\" file to uncomment or add the line for the\n\"X11Forwarding\" keyword and set its value to \"yes\" (this file may be named\ndifferently or be in a different location if using a version of SSH that is\nprovided by a third-party vendor):\n\nX11Forwarding yes\n\nThe SSH service must be restarted for changes to take effect."
            }
          ],
          "impact": 0.7,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72303",
            "rid": "SV-86927r3_rule",
            "stig_id": "RHEL-07-040710",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "ssh"
            ],
            "fix_id": "F-78657r5_fix"
          },
          "code": "control \"V-72303\" do\n  title \"Remote X connections for interactive users must be encrypted.\"\n  desc  \"Open X displays allow an attacker to capture keystrokes and execute\ncommands remotely.\"\n  impact 0.7\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72303\"\n  tag \"rid\": \"SV-86927r3_rule\"\n  tag \"stig_id\": \"RHEL-07-040710\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": [\"ssh\"]\n  desc \"check\", \"Verify remote X connections for interactive users are encrypted.\n\nCheck that remote X connections are encrypted with the following command:\n\n# grep -i x11forwarding /etc/ssh/sshd_config\n\nX11Forwarding yes\n\nIf the \\\"X11Forwarding\\\" keyword is set to \\\"no\\\", is missing, or is commented\nout, this is a finding.\"\n  desc \"fix\", \"Configure SSH to encrypt connections for interactive users.\n\nEdit the \\\"/etc/ssh/sshd_config\\\" file to uncomment or add the line for the\n\\\"X11Forwarding\\\" keyword and set its value to \\\"yes\\\" (this file may be named\ndifferently or be in a different location if using a version of SSH that is\nprovided by a third-party vendor):\n\nX11Forwarding yes\n\nThe SSH service must be restarted for changes to take effect.\"\n  tag \"fix_id\": \"F-78657r5_fix\"\n\n  describe sshd_config do\n    its('X11Forwarding') { should cmp 'yes' }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72303.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "SSHD Configuration X11Forwarding should cmp == \"yes\"",
              "run_time": 0.000526254,
              "start_time": "2019-11-04T16:17:17-05:00"
            }
          ]
        },
        {
          "id": "V-72305",
          "title": "If the Trivial File Transfer Protocol (TFTP) server is required, the\nTFTP daemon must be configured to operate in secure mode.",
          "desc": "Restricting TFTP to a specific directory prevents remote users from\ncopying, transferring, or overwriting system files.",
          "descriptions": [
            {
              "label": "default",
              "data": "Restricting TFTP to a specific directory prevents remote users from\ncopying, transferring, or overwriting system files."
            },
            {
              "label": "check",
              "data": "Verify the TFTP daemon is configured to operate in secure mode.\n\nCheck to see if a TFTP server has been installed with the following commands:\n\n# yum list installed | grep tftp-server\ntftp-server.x86_64    x.x-x.el7    rhel-7-server-rpms\n\nIf a TFTP server is not installed, this is Not Applicable.\n\nIf a TFTP server is installed, check for the server arguments with the\nfollowing command:\n\n# grep server_args /etc/xinetd.d/tftp\nserver_args = -s /var/lib/tftpboot\n\nIf the \"server_args\" line does not have a \"-s\" option and a subdirectory is\nnot assigned, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the TFTP daemon to operate in secure mode by adding the\nfollowing line to \"/etc/xinetd.d/tftp\" (or modify the line to have the\nrequired value):\n\nserver_args = -s /var/lib/tftpboot"
            }
          ],
          "impact": 0,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72305",
            "rid": "SV-86929r2_rule",
            "stig_id": "RHEL-07-040720",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "tftp"
            ],
            "fix_id": "F-78659r1_fix"
          },
          "code": "control \"V-72305\" do\n  title \"If the Trivial File Transfer Protocol (TFTP) server is required, the\nTFTP daemon must be configured to operate in secure mode.\"\n  desc  \"Restricting TFTP to a specific directory prevents remote users from\ncopying, transferring, or overwriting system files.\"\n  if package('tftp-server').installed?\n    impact 0.5\n  else\n    impact 0.0\n  end\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72305\"\n  tag \"rid\": \"SV-86929r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040720\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['tftp']\n  desc \"check\", \"Verify the TFTP daemon is configured to operate in secure mode.\n\nCheck to see if a TFTP server has been installed with the following commands:\n\n# yum list installed | grep tftp-server\ntftp-server.x86_64    x.x-x.el7    rhel-7-server-rpms\n\nIf a TFTP server is not installed, this is Not Applicable.\n\nIf a TFTP server is installed, check for the server arguments with the\nfollowing command:\n\n# grep server_args /etc/xinetd.d/tftp\nserver_args = -s /var/lib/tftpboot\n\nIf the \\\"server_args\\\" line does not have a \\\"-s\\\" option and a subdirectory is\nnot assigned, this is a finding.\"\n  desc \"fix\", \"Configure the TFTP daemon to operate in secure mode by adding the\nfollowing line to \\\"/etc/xinetd.d/tftp\\\" (or modify the line to have the\nrequired value):\n\nserver_args = -s /var/lib/tftpboot\"\n  tag \"fix_id\": \"F-78659r1_fix\"\n\n  if package('tftp-server').installed?\n    describe command('grep server_args /etc/xinetd.d/tftp') do\n      its('stdout.strip') { should match %r{^\\s*server_args\\s+=\\s+(-s|--secure)\\s(\\/\\S+)$} }\n    end\n  else\n    describe \"The TFTP package is not installed\" do\n      skip \"If a TFTP server is not installed, this is Not Applicable.\"\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72305.rb"
          },
          "results": [
            {
              "status": "skipped",
              "code_desc": "The TFTP package is not installed",
              "run_time": 5.677e-06,
              "start_time": "2019-11-04T16:17:17-05:00",
              "resource": "",
              "skip_message": "If a TFTP server is not installed, this is Not Applicable."
            }
          ]
        },
        {
          "id": "V-72307",
          "title": "An X Windows display manager must not be installed unless approved.",
          "desc": "Internet services that are not required for system or application\nprocesses must not be active to decrease the attack surface of the system. X\nWindows has a long history of security vulnerabilities and will not be used\nunless approved and documented.",
          "descriptions": [
            {
              "label": "default",
              "data": "Internet services that are not required for system or application\nprocesses must not be active to decrease the attack surface of the system. X\nWindows has a long history of security vulnerabilities and will not be used\nunless approved and documented."
            },
            {
              "label": "check",
              "data": "Verify that if the system has X Windows System installed, it is\nauthorized.\n\nCheck for the X11 package with the following command:\n\n# rpm -qa | grep xorg | grep server\n\nAsk the System Administrator if use of the X Windows System is an operational\nrequirement.\n\nIf the use of X Windows on the system is not documented with the Information\nSystem Security Officer (ISSO), this is a finding."
            },
            {
              "label": "fix",
              "data": "Document the requirement for an X Windows server with the ISSO or\nremove the related packages with the following commands:\n\n# rpm -e xorg-x11-server-common"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72307",
            "rid": "SV-86931r3_rule",
            "stig_id": "RHEL-07-040730",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "packages"
            ],
            "fix_id": "F-78661r2_fix"
          },
          "code": "control \"V-72307\" do\n  title \"An X Windows display manager must not be installed unless approved.\"\n  desc  \"Internet services that are not required for system or application\nprocesses must not be active to decrease the attack surface of the system. X\nWindows has a long history of security vulnerabilities and will not be used\nunless approved and documented.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72307\"\n  tag \"rid\": \"SV-86931r3_rule\"\n  tag \"stig_id\": \"RHEL-07-040730\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['packages']\n  desc \"check\", \"Verify that if the system has X Windows System installed, it is\nauthorized.\n\nCheck for the X11 package with the following command:\n\n# rpm -qa | grep xorg | grep server\n\nAsk the System Administrator if use of the X Windows System is an operational\nrequirement.\n\nIf the use of X Windows on the system is not documented with the Information\nSystem Security Officer (ISSO), this is a finding.\"\n  desc \"fix\", \"Document the requirement for an X Windows server with the ISSO or\nremove the related packages with the following commands:\n\n# rpm -e xorg-x11-server-common\"\n  tag \"fix_id\": \"F-78661r2_fix\"\n\n  describe package('xorg-x11-server-common') do\n    it { should_not be_installed }\n  end if !x11_enabled\n\n  describe package('xorg-x11-server-common') do\n    it { should be_installed }\n  end if x11_enabled\nend\n",
          "source_location": {
            "line": 12,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72307.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "System Package xorg-x11-server-common should not be installed",
              "run_time": 0.04060468,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "expected System Package xorg-x11-server-common not to be installed"
            }
          ]
        },
        {
          "id": "V-72309",
          "title": "The system must not be performing packet forwarding unless the system\nis a router.",
          "desc": "Routing protocol daemons are typically used on routers to exchange\nnetwork topology information with other routers. If this software is used when\nnot required, system network information may be unnecessarily transmitted\nacross the network.",
          "descriptions": [
            {
              "label": "default",
              "data": "Routing protocol daemons are typically used on routers to exchange\nnetwork topology information with other routers. If this software is used when\nnot required, system network information may be unnecessarily transmitted\nacross the network."
            },
            {
              "label": "check",
              "data": "Verify the system is not performing packet forwarding, unless\nthe system is a router.\n\nCheck to see if IP forwarding is enabled using the following command:\n\n# /sbin/sysctl -a | grep  net.ipv4.ip_forward\nnet.ipv4.ip_forward=0\n\nIf IP forwarding value is \"1\" and the system is hosting any application,\ndatabase, or web servers, this is a finding."
            },
            {
              "label": "fix",
              "data": "Set the system to the required kernel parameter by adding the\nfollowing line to \"/etc/sysctl.conf\" (or modify the line to have the required\nvalue):\n\nnet.ipv4.ip_forward = 0"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72309",
            "rid": "SV-86933r1_rule",
            "stig_id": "RHEL-07-040740",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "kernel_parameter"
            ],
            "fix_id": "F-78663r1_fix"
          },
          "code": "control \"V-72309\" do\n  title \"The system must not be performing packet forwarding unless the system\nis a router.\"\n  desc  \"Routing protocol daemons are typically used on routers to exchange\nnetwork topology information with other routers. If this software is used when\nnot required, system network information may be unnecessarily transmitted\nacross the network.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72309\"\n  tag \"rid\": \"SV-86933r1_rule\"\n  tag \"stig_id\": \"RHEL-07-040740\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['kernel_parameter']\n  desc \"check\", \"Verify the system is not performing packet forwarding, unless\nthe system is a router.\n\nCheck to see if IP forwarding is enabled using the following command:\n\n# /sbin/sysctl -a | grep  net.ipv4.ip_forward\nnet.ipv4.ip_forward=0\n\nIf IP forwarding value is \\\"1\\\" and the system is hosting any application,\ndatabase, or web servers, this is a finding.\"\n  desc \"fix\", \"Set the system to the required kernel parameter by adding the\nfollowing line to \\\"/etc/sysctl.conf\\\" (or modify the line to have the required\nvalue):\n\nnet.ipv4.ip_forward = 0\"\n  tag \"fix_id\": \"F-78663r1_fix\"\n\n  describe kernel_parameter('net.ipv4.ip_forward') do\n    its('value') { should eq 0 }\n  end\n\nend\n",
          "source_location": {
            "line": 6,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72309.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Kernel Parameter net.ipv4.ip_forward value should eq 0",
              "run_time": 0.015272065,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "\nexpected: 0\n     got: 1\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-72311",
          "title": "The Network File System (NFS) must be configured to use RPCSEC_GSS.",
          "desc": "When an NFS server is configured to use RPCSEC_SYS, a selected userid\nand groupid are used to handle requests from the remote user. The userid and\ngroupid could mistakenly or maliciously be set incorrectly. The RPCSEC_GSS\nmethod of authentication uses certificates on the server and client systems to\nmore securely authenticate the remote mount request.",
          "descriptions": [
            {
              "label": "default",
              "data": "When an NFS server is configured to use RPCSEC_SYS, a selected userid\nand groupid are used to handle requests from the remote user. The userid and\ngroupid could mistakenly or maliciously be set incorrectly. The RPCSEC_GSS\nmethod of authentication uses certificates on the server and client systems to\nmore securely authenticate the remote mount request."
            },
            {
              "label": "check",
              "data": "Verify \"AUTH_GSS\" is being used to authenticate NFS mounts.\n\nTo check if the system is importing an NFS file system, look for any entries in\nthe \"/etc/fstab\" file that have a file system type of \"nfs\" with the\nfollowing command:\n\n# cat /etc/fstab | grep nfs\n192.168.21.5:/mnt/export /data1 nfs4 rw,sync ,soft,sec=krb5:krb5i:krb5p\n\nIf the system is mounting file systems via NFS and has the sec option without\nthe \"krb5:krb5i:krb5p\" settings, the \"sec\" option has the \"sys\" setting,\nor the \"sec\" option is missing, this is a finding."
            },
            {
              "label": "fix",
              "data": "Update the \"/etc/fstab\" file so the option \"sec\" is defined\nfor each NFS mounted file system and the \"sec\" option does not have the\n\"sys\" setting.\n\nEnsure the \"sec\" option is defined as \"krb5:krb5i:krb5p\"."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72311",
            "rid": "SV-86935r3_rule",
            "stig_id": "RHEL-07-040750",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "nfs"
            ],
            "fix_id": "F-78665r2_fix"
          },
          "code": "control \"V-72311\" do\n  title \"The Network File System (NFS) must be configured to use RPCSEC_GSS.\"\n  desc  \"When an NFS server is configured to use RPCSEC_SYS, a selected userid\nand groupid are used to handle requests from the remote user. The userid and\ngroupid could mistakenly or maliciously be set incorrectly. The RPCSEC_GSS\nmethod of authentication uses certificates on the server and client systems to\nmore securely authenticate the remote mount request.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72311\"\n  tag \"rid\": \"SV-86935r3_rule\"\n  tag \"stig_id\": \"RHEL-07-040750\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['nfs']\n  desc \"check\", \"Verify \\\"AUTH_GSS\\\" is being used to authenticate NFS mounts.\n\nTo check if the system is importing an NFS file system, look for any entries in\nthe \\\"/etc/fstab\\\" file that have a file system type of \\\"nfs\\\" with the\nfollowing command:\n\n# cat /etc/fstab | grep nfs\n192.168.21.5:/mnt/export /data1 nfs4 rw,sync ,soft,sec=krb5:krb5i:krb5p\n\nIf the system is mounting file systems via NFS and has the sec option without\nthe \\\"krb5:krb5i:krb5p\\\" settings, the \\\"sec\\\" option has the \\\"sys\\\" setting,\nor the \\\"sec\\\" option is missing, this is a finding.\"\n  desc \"fix\", \"Update the \\\"/etc/fstab\\\" file so the option \\\"sec\\\" is defined\nfor each NFS mounted file system and the \\\"sec\\\" option does not have the\n\\\"sys\\\" setting.\n\nEnsure the \\\"sec\\\" option is defined as \\\"krb5:krb5i:krb5p\\\".\"\n  tag \"fix_id\": \"F-78665r2_fix\"\n\n  nfs_systems = etc_fstab.nfs_file_systems.entries\n  if !nfs_systems.nil? and !nfs_systems.empty?\n    nfs_systems.each do |file_system|\n      describe file_system do\n        its ('mount_options') { should include 'sec=krb5:krb5i:krb5p' }\n      end\n    end\n  else\n    describe \"No NFS file systems were found.\" do\n      subject { nfs_systems.nil? or nfs_systems.empty? }\n      it { should eq true }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72311.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "No NFS file systems were found. should eq true",
              "run_time": 0.000131476,
              "start_time": "2019-11-04T16:17:17-05:00"
            }
          ]
        },
        {
          "id": "V-72313",
          "title": "SNMP community strings must be changed from the default.",
          "desc": "Whether active or not, default Simple Network Management Protocol\n(SNMP) community strings must be changed to maintain security. If the service\nis running with the default authenticators, anyone can gather data about the\nsystem and the network and use the information to potentially compromise the\nintegrity of the system or network(s). It is highly recommended that SNMP\nversion 3 user authentication and message encryption be used in place of the\nversion 2 community strings.",
          "descriptions": [
            {
              "label": "default",
              "data": "Whether active or not, default Simple Network Management Protocol\n(SNMP) community strings must be changed to maintain security. If the service\nis running with the default authenticators, anyone can gather data about the\nsystem and the network and use the information to potentially compromise the\nintegrity of the system or network(s). It is highly recommended that SNMP\nversion 3 user authentication and message encryption be used in place of the\nversion 2 community strings."
            },
            {
              "label": "check",
              "data": "Verify that a system using SNMP is not using default community\nstrings.\n\nCheck to see if the \"/etc/snmp/snmpd.conf\" file exists with the following\ncommand:\n\n# ls -al /etc/snmp/snmpd.conf\n -rw-------   1 root root      52640 Mar 12 11:08 snmpd.conf\n\nIf the file does not exist, this is Not Applicable.\n\nIf the file does exist, check for the default community strings with the\nfollowing commands:\n\n# grep public /etc/snmp/snmpd.conf\n# grep private /etc/snmp/snmpd.conf\n\nIf either of these commands returns any output, this is a finding."
            },
            {
              "label": "fix",
              "data": "If the \"/etc/snmp/snmpd.conf\" file exists, modify any lines\nthat contain a community string value of \"public\" or \"private\" to another\nstring value."
            }
          ],
          "impact": 0,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72313",
            "rid": "SV-86937r1_rule",
            "stig_id": "RHEL-07-040800",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "snmp"
            ],
            "fix_id": "F-78667r1_fix"
          },
          "code": "control \"V-72313\" do\n  title \"SNMP community strings must be changed from the default.\"\n  desc  \"Whether active or not, default Simple Network Management Protocol\n(SNMP) community strings must be changed to maintain security. If the service\nis running with the default authenticators, anyone can gather data about the\nsystem and the network and use the information to potentially compromise the\nintegrity of the system or network(s). It is highly recommended that SNMP\nversion 3 user authentication and message encryption be used in place of the\nversion 2 community strings.\"\n  if file('/etc/snmp/snmpd.conf').exist?\n    impact 0.7\n  else\n    impact 0.0\n  end\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72313\"\n  tag \"rid\": \"SV-86937r1_rule\"\n  tag \"stig_id\": \"RHEL-07-040800\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['snmp']\n  desc \"check\", \"Verify that a system using SNMP is not using default community\nstrings.\n\nCheck to see if the \\\"/etc/snmp/snmpd.conf\\\" file exists with the following\ncommand:\n\n# ls -al /etc/snmp/snmpd.conf\n -rw-------   1 root root      52640 Mar 12 11:08 snmpd.conf\n\nIf the file does not exist, this is Not Applicable.\n\nIf the file does exist, check for the default community strings with the\nfollowing commands:\n\n# grep public /etc/snmp/snmpd.conf\n# grep private /etc/snmp/snmpd.conf\n\nIf either of these commands returns any output, this is a finding.\"\n  desc \"fix\", \"If the \\\"/etc/snmp/snmpd.conf\\\" file exists, modify any lines\nthat contain a community string value of \\\"public\\\" or \\\"private\\\" to another\nstring value.\"\n  tag \"fix_id\": \"F-78667r1_fix\"\n\n  if file('/etc/snmp/snmpd.conf').exist?\n    processed = []\n    to_process = ['/etc/snmp/snmpd.conf']\n\n    while !to_process.empty?\n      in_process = to_process.pop\n      next if processed.include? in_process\n      processed.push in_process\n\n      if file(in_process).directory?\n        to_process.concat(\n          command(\"find #{in_process} -maxdepth 1 -mindepth 1 -name '*.conf'\").\n            stdout.strip.split(\"\\n\").\n            select { |f| file(f).file? }\n        )\n      elsif file(in_process).file?\n        to_process.concat(\n          command(\"grep -E '^\\\\s*includeFile\\\\s+' #{in_process} | sed 's/^[[:space:]]*includeFile[[:space:]]*//g'\").\n            stdout.strip.split(%r{\\n+}).\n            map { |f| f.start_with?('/') ? f : File.join(File.dirname(in_process), f) }.\n            select { |f| file(f).file? }\n        )\n        to_process.concat(\n          command(\"grep -E '^\\\\s*includeDir\\\\s+' #{in_process} | sed 's/^[[:space:]]*includeDir[[:space:]]*//g'\").\n            stdout.strip.split(%r{\\n+}).\n            map { |f| f.start_with?('/') ? f : File.join('/', f) }. # relative dirs are treated as absolute\n            select { |f| file(f).directory? }\n        )\n      end\n    end\n\n    config_files = processed.select { |f| file(f).file? }\n\n    config_files.each do |config|\n      describe file(config) do\n        its('content') { should_not match %r{^[^#]*(public|private)} }\n      end\n    end\n  else\n    describe \"The `snmpd.conf` does not exist\" do\n      skip \"The snmpd.conf file does not exist, this control is Not Applicable\"\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72313.rb"
          },
          "results": [
            {
              "status": "skipped",
              "code_desc": "The `snmpd.conf` does not exist",
              "run_time": 3.1842e-05,
              "start_time": "2019-11-04T16:17:17-05:00",
              "resource": "",
              "skip_message": "The snmpd.conf file does not exist, this control is Not Applicable"
            }
          ]
        },
        {
          "id": "V-72315",
          "title": "The system access control program must be configured to grant or deny\nsystem access to specific hosts and services.",
          "desc": "If the systems access control program is not configured with\nappropriate rules for allowing and denying access to system network resources,\nservices may be accessible to unauthorized hosts.",
          "descriptions": [
            {
              "label": "default",
              "data": "If the systems access control program is not configured with\nappropriate rules for allowing and denying access to system network resources,\nservices may be accessible to unauthorized hosts."
            },
            {
              "label": "check",
              "data": "If the \"firewalld\" package is not installed, ask the System\nAdministrator (SA) if another firewall application (such as iptables) is\ninstalled. If an application firewall is not installed, this is a finding.\n\nVerify the system's access control program is configured to grant or deny\nsystem access to specific hosts.\n\nCheck to see if \"firewalld\" is active with the following command:\n\n# systemctl status firewalld\nfirewalld.service - firewalld - dynamic firewall daemon\n   Loaded: loaded (/usr/lib/systemd/system/firewalld.service; enabled)\n   Active: active (running) since Sun 2014-04-20 14:06:46 BST; 30s ago\n\nIf \"firewalld\" is active, check to see if it is configured to grant or deny\naccess to specific hosts or services with the following commands:\n\n# firewall-cmd --get-default-zone\npublic\n\n# firewall-cmd --list-all --zone=public\npublic (default, active)\n  interfaces: eth0\n  sources:\n  services: mdns ssh\n  ports:\n  masquerade: no\n  forward-ports:\n  icmp-blocks:\n  rich rules:\n rule family=\"ipv4\" source address=\"92.188.21.1/24\" accept\n rule family=\"ipv4\" source address=\"211.17.142.46/32\" accept\n\nIf \"firewalld\" is not active, determine whether \"tcpwrappers\" is being used\nby checking whether the \"hosts.allow\" and \"hosts.deny\" files are empty with\nthe following commands:\n\n# ls -al /etc/hosts.allow\nrw-r----- 1 root root 9 Aug  2 23:13 /etc/hosts.allow\n\n# ls -al /etc/hosts.deny\n-rw-r----- 1 root root  9 Apr  9  2007 /etc/hosts.deny\n\nIf \"firewalld\" and \"tcpwrappers\" are not installed, configured, and active,\nask the SA if another access control program (such as iptables) is installed\nand active. Ask the SA to show that the running configuration grants or denies\naccess to specific hosts or services.\n\nIf \"firewalld\" is active and is not configured to grant access to specific\nhosts or \"tcpwrappers\" is not configured to grant or deny access to specific\nhosts, this is a finding."
            },
            {
              "label": "fix",
              "data": "If \"firewalld\" is installed and active on the system, configure\nrules for allowing specific services and hosts.\n\nIf \"firewalld\" is not \"active\", enable \"tcpwrappers\" by configuring\n\"/etc/hosts.allow\" and \"/etc/hosts.deny\" to allow or deny access to\nspecific hosts."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72315",
            "rid": "SV-86939r2_rule",
            "stig_id": "RHEL-07-040810",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "iptables",
              "firewall"
            ],
            "fix_id": "F-78669r2_fix"
          },
          "code": "control \"V-72315\" do\n  title \"The system access control program must be configured to grant or deny\nsystem access to specific hosts and services.\"\n  desc  \"If the systems access control program is not configured with\nappropriate rules for allowing and denying access to system network resources,\nservices may be accessible to unauthorized hosts.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72315\"\n  tag \"rid\": \"SV-86939r2_rule\"\n  tag \"stig_id\": \"RHEL-07-040810\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": [\"iptables\", 'firewall']\n  desc \"check\", \"If the \\\"firewalld\\\" package is not installed, ask the System\nAdministrator (SA) if another firewall application (such as iptables) is\ninstalled. If an application firewall is not installed, this is a finding.\n\nVerify the system's access control program is configured to grant or deny\nsystem access to specific hosts.\n\nCheck to see if \\\"firewalld\\\" is active with the following command:\n\n# systemctl status firewalld\nfirewalld.service - firewalld - dynamic firewall daemon\n   Loaded: loaded (/usr/lib/systemd/system/firewalld.service; enabled)\n   Active: active (running) since Sun 2014-04-20 14:06:46 BST; 30s ago\n\nIf \\\"firewalld\\\" is active, check to see if it is configured to grant or deny\naccess to specific hosts or services with the following commands:\n\n# firewall-cmd --get-default-zone\npublic\n\n# firewall-cmd --list-all --zone=public\npublic (default, active)\n  interfaces: eth0\n  sources:\n  services: mdns ssh\n  ports:\n  masquerade: no\n  forward-ports:\n  icmp-blocks:\n  rich rules:\n rule family=\\\"ipv4\\\" source address=\\\"92.188.21.1/24\\\" accept\n rule family=\\\"ipv4\\\" source address=\\\"211.17.142.46/32\\\" accept\n\nIf \\\"firewalld\\\" is not active, determine whether \\\"tcpwrappers\\\" is being used\nby checking whether the \\\"hosts.allow\\\" and \\\"hosts.deny\\\" files are empty with\nthe following commands:\n\n# ls -al /etc/hosts.allow\nrw-r----- 1 root root 9 Aug  2 23:13 /etc/hosts.allow\n\n# ls -al /etc/hosts.deny\n-rw-r----- 1 root root  9 Apr  9  2007 /etc/hosts.deny\n\nIf \\\"firewalld\\\" and \\\"tcpwrappers\\\" are not installed, configured, and active,\nask the SA if another access control program (such as iptables) is installed\nand active. Ask the SA to show that the running configuration grants or denies\naccess to specific hosts or services.\n\nIf \\\"firewalld\\\" is active and is not configured to grant access to specific\nhosts or \\\"tcpwrappers\\\" is not configured to grant or deny access to specific\nhosts, this is a finding.\"\n  desc \"fix\", \"If \\\"firewalld\\\" is installed and active on the system, configure\nrules for allowing specific services and hosts.\n\nIf \\\"firewalld\\\" is not \\\"active\\\", enable \\\"tcpwrappers\\\" by configuring\n\\\"/etc/hosts.allow\\\" and \\\"/etc/hosts.deny\\\" to allow or deny access to\nspecific hosts.   \"\n  tag \"fix_id\": \"F-78669r2_fix\"\n\n  describe \"This control must be reviewed manually\" do\n    skip \"You must review this control manually.\"\n  end\nend\n",
          "source_location": {
            "line": 6,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72315.rb"
          },
          "results": [
            {
              "status": "skipped",
              "code_desc": "This control must be reviewed manually",
              "run_time": 5.314e-06,
              "start_time": "2019-11-04T16:17:17-05:00",
              "resource": "",
              "skip_message": "You must review this control manually."
            }
          ]
        },
        {
          "id": "V-72317",
          "title": "The system must not have unauthorized IP tunnels configured.",
          "desc": "IP tunneling mechanisms can be used to bypass network filtering. If\ntunneling is required, it must be documented with the Information System\nSecurity Officer (ISSO).",
          "descriptions": [
            {
              "label": "default",
              "data": "IP tunneling mechanisms can be used to bypass network filtering. If\ntunneling is required, it must be documented with the Information System\nSecurity Officer (ISSO)."
            },
            {
              "label": "check",
              "data": "Verify the system does not have unauthorized IP tunnels\nconfigured.\n\nCheck to see if \"libreswan\" is installed with the following command:\n\n# yum list installed libreswan\nopenswan-2.6.32-27.el6.x86_64\n\nIf \"libreswan\" is installed, check to see if the \"IPsec\" service is active\nwith the following command:\n\n# systemctl status ipsec\nipsec.service - Internet Key Exchange (IKE) Protocol Daemon for IPsec\n   Loaded: loaded (/usr/lib/systemd/system/ipsec.service; disabled)\n   Active: inactive (dead)\n\nIf the \"IPsec\" service is active, check to see if any tunnels are configured\nin \"/etc/ipsec.conf\" and \"/etc/ipsec.d/\" with the following commands:\n\n# grep -i conn /etc/ipsec.conf\nconn mytunnel\n\n# grep -i conn /etc/ipsec.d/*.conf\nconn mytunnel\n\nIf there are indications that a \"conn\" parameter is configured for a tunnel,\nask the System Administrator if the tunnel is documented with the ISSO. If\n\"libreswan\" is installed, \"IPsec\" is active, and an undocumented tunnel is\nactive, this is a finding."
            },
            {
              "label": "fix",
              "data": "Remove all unapproved tunnels from the system, or document them\nwith the ISSO."
            }
          ],
          "impact": 0,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72317",
            "rid": "SV-86941r1_rule",
            "stig_id": "RHEL-07-040820",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "libreswan",
              "ipsec"
            ],
            "fix_id": "F-78671r1_fix"
          },
          "code": "control \"V-72317\" do\n  title \"The system must not have unauthorized IP tunnels configured.\"\n  desc  \"IP tunneling mechanisms can be used to bypass network filtering. If\ntunneling is required, it must be documented with the Information System\nSecurity Officer (ISSO).\"\nif !package('libreswan').installed? || !service('ipsec.service').running?\n  impact 0.0\nelse\n  impact 0.5\nend\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72317\"\n  tag \"rid\": \"SV-86941r1_rule\"\n  tag \"stig_id\": \"RHEL-07-040820\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['libreswan', 'ipsec']\n  desc \"check\", \"Verify the system does not have unauthorized IP tunnels\nconfigured.\n\nCheck to see if \\\"libreswan\\\" is installed with the following command:\n\n# yum list installed libreswan\nopenswan-2.6.32-27.el6.x86_64\n\nIf \\\"libreswan\\\" is installed, check to see if the \\\"IPsec\\\" service is active\nwith the following command:\n\n# systemctl status ipsec\nipsec.service - Internet Key Exchange (IKE) Protocol Daemon for IPsec\n   Loaded: loaded (/usr/lib/systemd/system/ipsec.service; disabled)\n   Active: inactive (dead)\n\nIf the \\\"IPsec\\\" service is active, check to see if any tunnels are configured\nin \\\"/etc/ipsec.conf\\\" and \\\"/etc/ipsec.d/\\\" with the following commands:\n\n# grep -i conn /etc/ipsec.conf\nconn mytunnel\n\n# grep -i conn /etc/ipsec.d/*.conf\nconn mytunnel\n\nIf there are indications that a \\\"conn\\\" parameter is configured for a tunnel,\nask the System Administrator if the tunnel is documented with the ISSO. If\n\\\"libreswan\\\" is installed, \\\"IPsec\\\" is active, and an undocumented tunnel is\nactive, this is a finding.\"\n  desc \"fix\", \"Remove all unapproved tunnels from the system, or document them\nwith the ISSO.\"\n  tag \"fix_id\": \"F-78671r1_fix\"\n\n  if package('libreswan').installed? && service('ipsec.service').running?\n    processed = []\n    to_process = ['/etc/ipsec.conf']\n\n    while !to_process.empty?\n      in_process = to_process.pop\n      next if processed.include? in_process\n      processed.push in_process\n\n      to_process.concat(\n        command(\"grep -E '^\\\\s*include\\\\s+' #{in_process} | sed 's/^[[:space:]]*include[[:space:]]*//g'\").\n          stdout.strip.split(%r{\\s*\\n+\\s*}).\n          map { |f| f.start_with?('/') ? f : File.join(File.dirname(in_process), f) }.\n          map { |f|\n            dir = f.sub(%r{[^/]*[\\*\\?\\[].*$}, '') # gets the longest ancestor path which doesn't contain wildcards\n            command(\"find #{dir} -wholename '#{f}'\").stdout.strip.split(\"\\n\")\n          }.\n          flatten.\n          select { |f| file(f).file? }\n      )\n    end\n\n    conn_grep = processed.map do |conf|\n      command(\"grep -E '^\\\\s*conn\\\\s+' #{conf}\").\n        stdout.strip.split(%r{\\s*\\n\\s*})\n    end.flatten\n\n    describe conn_grep do\n      it { should all(be_in approved_tunnels) }\n    end\n  else\n    describe \"The system does not have libreswan installed or the ipsec.service isn't running\" do\n      skip \"The system does not have libreswan installed or the ipsec.service isn't running, this requirement is Not Applicable.\"\n    end\n  end\nend\n",
          "source_location": {
            "line": 13,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72317.rb"
          },
          "results": [
            {
              "status": "skipped",
              "code_desc": "The system does not have libreswan installed or the ipsec.service isn't running",
              "run_time": 9.2584e-05,
              "start_time": "2019-11-04T16:17:17-05:00",
              "resource": "",
              "skip_message": "The system does not have libreswan installed or the ipsec.service isn't running, this requirement is Not Applicable."
            }
          ]
        },
        {
          "id": "V-72319",
          "title": "The system must not forward IPv6 source-routed packets.",
          "desc": "Source-routed packets allow the source of the packet to suggest that\nrouters forward the packet along a different path than configured on the\nrouter, which can be used to bypass network security measures. This requirement\napplies only to the forwarding of source-routed traffic, such as when IPv6\nforwarding is enabled and the system is functioning as a router.",
          "descriptions": [
            {
              "label": "default",
              "data": "Source-routed packets allow the source of the packet to suggest that\nrouters forward the packet along a different path than configured on the\nrouter, which can be used to bypass network security measures. This requirement\napplies only to the forwarding of source-routed traffic, such as when IPv6\nforwarding is enabled and the system is functioning as a router."
            },
            {
              "label": "check",
              "data": "Verify the system does not accept IPv6 source-routed packets.\n\nNote: If IPv6 is not enabled, the key will not exist, and this is not a finding.\n\nCheck the value of the accept source route variable with the following command:\n\n# /sbin/sysctl -a | grep  net.ipv6.conf.all.accept_source_route\nnet.ipv6.conf.all.accept_source_route=0\n\nIf the returned lines do not have a value of \"0\", or a line is not returned,\nthis is a finding."
            },
            {
              "label": "fix",
              "data": "Set the system to the required kernel parameter, if IPv6 is\nenabled, by adding the following line to \"/etc/sysctl.conf\" (or modify the\nline to have the required value):\n\nnet.ipv6.conf.all.accept_source_route = 0"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-72319",
            "rid": "SV-86943r1_rule",
            "stig_id": "RHEL-07-040830",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "networking": null,
            "kernel": null,
            "subsystems": [
              "kernel_parameter"
            ],
            "fix_id": "F-78673r1_fix"
          },
          "code": "control \"V-72319\" do\n  title \"The system must not forward IPv6 source-routed packets.\"\n  desc  \"Source-routed packets allow the source of the packet to suggest that\nrouters forward the packet along a different path than configured on the\nrouter, which can be used to bypass network security measures. This requirement\napplies only to the forwarding of source-routed traffic, such as when IPv6\nforwarding is enabled and the system is functioning as a router.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-72319\"\n  tag \"rid\": \"SV-86943r1_rule\"\n  tag \"stig_id\": \"RHEL-07-040830\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"networking\",\"kernel\"\n  tag \"subsystems\": ['kernel_parameter']\n  desc \"check\", \"Verify the system does not accept IPv6 source-routed packets.\n\nNote: If IPv6 is not enabled, the key will not exist, and this is not a finding.\n\nCheck the value of the accept source route variable with the following command:\n\n# /sbin/sysctl -a | grep  net.ipv6.conf.all.accept_source_route\nnet.ipv6.conf.all.accept_source_route=0\n\nIf the returned lines do not have a value of \\\"0\\\", or a line is not returned,\nthis is a finding.\"\n  desc \"fix\", \"Set the system to the required kernel parameter, if IPv6 is\nenabled, by adding the following line to \\\"/etc/sysctl.conf\\\" (or modify the\nline to have the required value):\n\nnet.ipv6.conf.all.accept_source_route = 0\"\n  tag \"fix_id\": \"F-78673r1_fix\"\n\n  describe.one do\n    describe kernel_parameter('net.ipv6.conf.all.accept_source_route') do\n      its('value') { should eq 0 }\n    end\n\t# If IPv6 is disabled in the kernel it will return NIL\n    describe kernel_parameter('net.ipv6.conf.all.accept_source_route') do\n      its('value') { should eq nil }\n    end\n  end\nend\n",
          "source_location": {
            "line": 6,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72319.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Kernel Parameter net.ipv6.conf.all.accept_source_route value should eq 0",
              "run_time": 0.000947428,
              "start_time": "2019-11-04T16:17:17-05:00"
            }
          ]
        },
        {
          "id": "V-72417",
          "title": "The operating system must have the required packages for multifactor\nauthentication installed.",
          "desc": "Using an authentication device, such as a CAC or token that is separate\nfrom the information system, ensures that even if the information system is\ncompromised, that compromise will not affect credentials stored on the\nauthentication device.\n\n    Multifactor solutions that require devices separate from information\nsystems gaining access include, for example, hardware tokens providing\ntime-based or challenge-response authenticators and smart cards such as the\nU.S. Government Personal Identity Verification card and the DoD Common Access\nCard.\n\n    A privileged account is defined as an information system account with\nauthorizations of a privileged user.\n\n    Remote access is access to DoD nonpublic information systems by an\nauthorized user (or an information system) communicating through an external,\nnon-organization-controlled network. Remote access methods include, for\nexample, dial-up, broadband, and wireless.\n\n    This requirement only applies to components where this is specific to the\nfunction of the device or has the concept of an organizational user (e.g., VPN,\nproxy capability). This does not apply to authentication for the purpose of\nconfiguring the device itself (management).\n\n    Requires further clarification from NIST.",
          "descriptions": [
            {
              "label": "default",
              "data": "Using an authentication device, such as a CAC or token that is separate\nfrom the information system, ensures that even if the information system is\ncompromised, that compromise will not affect credentials stored on the\nauthentication device.\n\n    Multifactor solutions that require devices separate from information\nsystems gaining access include, for example, hardware tokens providing\ntime-based or challenge-response authenticators and smart cards such as the\nU.S. Government Personal Identity Verification card and the DoD Common Access\nCard.\n\n    A privileged account is defined as an information system account with\nauthorizations of a privileged user.\n\n    Remote access is access to DoD nonpublic information systems by an\nauthorized user (or an information system) communicating through an external,\nnon-organization-controlled network. Remote access methods include, for\nexample, dial-up, broadband, and wireless.\n\n    This requirement only applies to components where this is specific to the\nfunction of the device or has the concept of an organizational user (e.g., VPN,\nproxy capability). This does not apply to authentication for the purpose of\nconfiguring the device itself (management).\n\n    Requires further clarification from NIST."
            },
            {
              "label": "check",
              "data": "Verify the operating system has the packages required for\nmultifactor authentication installed.\n\nCheck for the presence of the packages required to support multifactor\nauthentication with the following commands:\n\n# yum list installed esc\nesc-1.1.0-26.el7.noarch.rpm\n\n# yum list installed pam_pkcs11\npam_pkcs11-0.6.2-14.el7.noarch.rpm\n\n# yum list installed authconfig-gtk\nauthconfig-gtk-6.1.12-19.el7.noarch.rpm\n\nIf the \"esc\", \"pam_pkcs11\", and \"authconfig-gtk\" packages are not\ninstalled, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to implement multifactor\nauthentication by installing the required packages.\n\nInstall the \"esc\", \"pam_pkcs11\", \"authconfig\", and \"authconfig-gtk\"\npackages on the system with the following command:\n\n# yum install esc pam_pkcs11 authconfig-gtk"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000375-GPOS-00160",
            "satisfies": [
              "SRG-OS-000375-GPOS-00160",
              "SRG-OS-000375-GPOS-00161",
              "SRG-OS-000375-GPOS-00162"
            ],
            "gid": "V-72417",
            "rid": "SV-87041r2_rule",
            "stig_id": "RHEL-07-041001",
            "cci": [
              "CCI-001948",
              "CCI-001953",
              "CCI-001954"
            ],
            "documentable": false,
            "nist": [
              "IA-2 (11)",
              "IA-2 (12)",
              "IA-2 (12)",
              "Rev_4"
            ],
            "subsystems": [
              "pki",
              "pam",
              "MFA",
              "pkcs11",
              "smartcard"
            ],
            "pki": null,
            "MFA": null,
            "pam": null,
            "pkcs11": null,
            "networking": null,
            "fix_id": "F-78769r3_fix"
          },
          "code": "control \"V-72417\" do\n  title \"The operating system must have the required packages for multifactor\nauthentication installed.\"\n  desc  \"\n    Using an authentication device, such as a CAC or token that is separate\nfrom the information system, ensures that even if the information system is\ncompromised, that compromise will not affect credentials stored on the\nauthentication device.\n\n    Multifactor solutions that require devices separate from information\nsystems gaining access include, for example, hardware tokens providing\ntime-based or challenge-response authenticators and smart cards such as the\nU.S. Government Personal Identity Verification card and the DoD Common Access\nCard.\n\n    A privileged account is defined as an information system account with\nauthorizations of a privileged user.\n\n    Remote access is access to DoD nonpublic information systems by an\nauthorized user (or an information system) communicating through an external,\nnon-organization-controlled network. Remote access methods include, for\nexample, dial-up, broadband, and wireless.\n\n    This requirement only applies to components where this is specific to the\nfunction of the device or has the concept of an organizational user (e.g., VPN,\nproxy capability). This does not apply to authentication for the purpose of\nconfiguring the device itself (management).\n\n    Requires further clarification from NIST.\n  \"\n  if smart_card_status.eql?('enabled')\n  impact 0.5\n  else\n    impact 0.0\n  end\n  tag \"gtitle\": \"SRG-OS-000375-GPOS-00160\"\n  tag \"satisfies\": [\"SRG-OS-000375-GPOS-00160\", \"SRG-OS-000375-GPOS-00161\",\n\"SRG-OS-000375-GPOS-00162\"]\n  tag \"gid\": \"V-72417\"\n  tag \"rid\": \"SV-87041r2_rule\"\n  tag \"stig_id\": \"RHEL-07-041001\"\n  tag \"cci\": [\"CCI-001948\", \"CCI-001953\", \"CCI-001954\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-2 (11)\", \"IA-2 (12)\", \"IA-2 (12)\", \"Rev_4\"]\n  tag \"subsystems\": ['pki', 'pam', 'MFA', 'pkcs11', 'smartcard']\n  tag \"pki\",\"MFA\",\"pam\",\"pkcs11\",\"networking\"\n  desc \"check\", \"Verify the operating system has the packages required for\nmultifactor authentication installed.\n\nCheck for the presence of the packages required to support multifactor\nauthentication with the following commands:\n\n# yum list installed esc\nesc-1.1.0-26.el7.noarch.rpm\n\n# yum list installed pam_pkcs11\npam_pkcs11-0.6.2-14.el7.noarch.rpm\n\n# yum list installed authconfig-gtk\nauthconfig-gtk-6.1.12-19.el7.noarch.rpm\n\nIf the \\\"esc\\\", \\\"pam_pkcs11\\\", and \\\"authconfig-gtk\\\" packages are not\ninstalled, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to implement multifactor\nauthentication by installing the required packages.\n\nInstall the \\\"esc\\\", \\\"pam_pkcs11\\\", \\\"authconfig\\\", and \\\"authconfig-gtk\\\"\npackages on the system with the following command:\n\n# yum install esc pam_pkcs11 authconfig-gtk\"\n  tag \"fix_id\": \"F-78769r3_fix\"\n\n  mfa_pkg_list.each do |pkg|\n    describe package(\"#{pkg}\") do\n      it { should be_installed }\n    end\n  end if smart_card_status.eql?('enabled')\n\n  describe \"The system is not smartcard enabled\" do\n    skip \"The system is not using Smartcards / PIVs to fulfil the MFA requirement, this control is Not Applicable.\"\n  end if !smart_card_status.eql?('enabled')\nend\n",
          "source_location": {
            "line": 19,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72417.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "System Package esc should be installed",
              "run_time": 0.001749344,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "expected that `System Package esc` is installed"
            },
            {
              "status": "failed",
              "code_desc": "System Package pam_pkcs11 should be installed",
              "run_time": 0.072730812,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "expected that `System Package pam_pkcs11` is installed"
            },
            {
              "status": "failed",
              "code_desc": "System Package authconfig-gtk should be installed",
              "run_time": 0.038294292,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "expected that `System Package authconfig-gtk` is installed"
            }
          ]
        },
        {
          "id": "V-72427",
          "title": "The operating system must implement multifactor authentication for\naccess to privileged accounts via pluggable authentication modules (PAM).",
          "desc": "Using an authentication device, such as a CAC or token that is separate\nfrom the information system, ensures that even if the information system is\ncompromised, that compromise will not affect credentials stored on the\nauthentication device.\n\n    Multifactor solutions that require devices separate from information\nsystems gaining access include, for example, hardware tokens providing\ntime-based or challenge-response authenticators and smart cards such as the\nU.S. Government Personal Identity Verification card and the DoD Common Access\nCard.\n\n    A privileged account is defined as an information system account with\nauthorizations of a privileged user.\n\n    Remote access is access to DoD nonpublic information systems by an\nauthorized user (or an information system) communicating through an external,\nnon-organization-controlled network. Remote access methods include, for\nexample, dial-up, broadband, and wireless.\n\n    This requirement only applies to components where this is specific to the\nfunction of the device or has the concept of an organizational user (e.g., VPN,\nproxy capability). This does not apply to authentication for the purpose of\nconfiguring the device itself (management).\n\n    Requires further clarification from NIST.",
          "descriptions": [
            {
              "label": "default",
              "data": "Using an authentication device, such as a CAC or token that is separate\nfrom the information system, ensures that even if the information system is\ncompromised, that compromise will not affect credentials stored on the\nauthentication device.\n\n    Multifactor solutions that require devices separate from information\nsystems gaining access include, for example, hardware tokens providing\ntime-based or challenge-response authenticators and smart cards such as the\nU.S. Government Personal Identity Verification card and the DoD Common Access\nCard.\n\n    A privileged account is defined as an information system account with\nauthorizations of a privileged user.\n\n    Remote access is access to DoD nonpublic information systems by an\nauthorized user (or an information system) communicating through an external,\nnon-organization-controlled network. Remote access methods include, for\nexample, dial-up, broadband, and wireless.\n\n    This requirement only applies to components where this is specific to the\nfunction of the device or has the concept of an organizational user (e.g., VPN,\nproxy capability). This does not apply to authentication for the purpose of\nconfiguring the device itself (management).\n\n    Requires further clarification from NIST."
            },
            {
              "label": "check",
              "data": "Verify the operating system implements multifactor\nauthentication for remote access to privileged accounts via pluggable\nauthentication modules (PAM).\n\nCheck the \"/etc/sssd/sssd.conf\" file for the authentication services that are\nbeing used with the following command:\n\n# grep services /etc/sssd/sssd.conf /etc/sssd/conf.d/*.conf\n\nservices = nss, pam\n\nIf the \"pam\" service is not present, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to implement multifactor\nauthentication for remote access to privileged accounts via pluggable\nauthentication modules (PAM).\n\nModify all of the services lines in \"/etc/sssd/sssd.conf\" or in configuration\nfiles found under \"/etc/sssd/conf.d\" to include pam."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000375-GPOS-00160",
            "satisfies": [
              "SRG-OS-000375-GPOS-00160",
              "SRG-OS-000375-GPOS-00161",
              "SRG-OS-000375-GPOS-00162"
            ],
            "gid": "V-72427",
            "rid": "SV-87051r3_rule",
            "stig_id": "RHEL-07-041002",
            "cci": [
              "CCI-001948",
              "CCI-001953",
              "CCI-001954"
            ],
            "documentable": false,
            "nist": [
              "IA-2 (11)",
              "IA-2 (12)",
              "IA-2 (12)",
              "Rev_4"
            ],
            "subsystems": [
              "pam",
              "nss",
              "MFA",
              "pki",
              "sssd"
            ],
            "pam": null,
            "nss": null,
            "MFA": null,
            "pki": null,
            "fix_id": "F-78779r3_fix"
          },
          "code": "control \"V-72427\" do\n  title \"The operating system must implement multifactor authentication for\naccess to privileged accounts via pluggable authentication modules (PAM).\"\n  desc  \"\n    Using an authentication device, such as a CAC or token that is separate\nfrom the information system, ensures that even if the information system is\ncompromised, that compromise will not affect credentials stored on the\nauthentication device.\n\n    Multifactor solutions that require devices separate from information\nsystems gaining access include, for example, hardware tokens providing\ntime-based or challenge-response authenticators and smart cards such as the\nU.S. Government Personal Identity Verification card and the DoD Common Access\nCard.\n\n    A privileged account is defined as an information system account with\nauthorizations of a privileged user.\n\n    Remote access is access to DoD nonpublic information systems by an\nauthorized user (or an information system) communicating through an external,\nnon-organization-controlled network. Remote access methods include, for\nexample, dial-up, broadband, and wireless.\n\n    This requirement only applies to components where this is specific to the\nfunction of the device or has the concept of an organizational user (e.g., VPN,\nproxy capability). This does not apply to authentication for the purpose of\nconfiguring the device itself (management).\n\n    Requires further clarification from NIST.\n  \"\n  if package('sssd').installed?\n    impact 0.5\n  else\n    impact 0.0\n  end\n  tag \"gtitle\": \"SRG-OS-000375-GPOS-00160\"\n  tag \"satisfies\": [\"SRG-OS-000375-GPOS-00160\", \"SRG-OS-000375-GPOS-00161\",\n                    \"SRG-OS-000375-GPOS-00162\"]\n  tag \"gid\": \"V-72427\"\n  tag \"rid\": \"SV-87051r3_rule\"\n  tag \"stig_id\": \"RHEL-07-041002\"\n  tag \"cci\": [\"CCI-001948\", \"CCI-001953\", \"CCI-001954\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-2 (11)\", \"IA-2 (12)\", \"IA-2 (12)\", \"Rev_4\"]\n  tag \"subsystems\": ['pam', 'nss', 'MFA', 'pki', 'sssd']\n  tag \"pam\",\"nss\",\"MFA\",\"pki\"\n  desc \"check\", \"Verify the operating system implements multifactor\nauthentication for remote access to privileged accounts via pluggable\nauthentication modules (PAM).\n\nCheck the \\\"/etc/sssd/sssd.conf\\\" file for the authentication services that are\nbeing used with the following command:\n\n# grep services /etc/sssd/sssd.conf /etc/sssd/conf.d/*.conf\n\nservices = nss, pam\n\nIf the \\\"pam\\\" service is not present, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to implement multifactor\nauthentication for remote access to privileged accounts via pluggable\nauthentication modules (PAM).\n\nModify all of the services lines in \\\"/etc/sssd/sssd.conf\\\" or in configuration\nfiles found under \\\"/etc/sssd/conf.d\\\" to include pam.\"\n  tag \"fix_id\": \"F-78779r3_fix\"\n\n  # its('services\") doesn't appear to be working properly\n  # added a test with grep to make sure one will pass if pam exists.\n  if (!(sssd_files = command(\"find /etc/sssd -name *.conf\").stdout.split(\"\\n\")).empty?)\n    sssd_files.each do |file|\n      describe.one do\n        describe parse_config_file(file) do\n          its('services') { should include 'pam' }\n        end if package('sssd').installed?\n        describe command(\"grep -i -E 'services(\\s)*=(\\s)*(.+*)pam' #{file}\") do\n          its('stdout.strip') { should include 'pam' }\n        end if package('sssd').installed?\n      end if package('sssd').installed?\n    end\n  else\n    describe \"The set of SSSD configuration files\" do\n        subject { sssd_files.to_a }\n        it { should_not be_empty }\n    end\n  end\n  describe \"The SSSD Package is not installed on the system\" do\n    skip \"This control is Not Appliciable without the SSSD Package installed.\"\n  end if !package('sssd').installed?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72427.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "The set of SSSD configuration files should not be empty",
              "run_time": 0.000259004,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "expected `[].empty?` to return false, got true"
            }
          ]
        },
        {
          "id": "V-72433",
          "title": "The operating system must implement certificate status checking for\nPKI authentication.",
          "desc": "Using an authentication device, such as a CAC or token that is separate\nfrom the information system, ensures that even if the information system is\ncompromised, that compromise will not affect credentials stored on the\nauthentication device.\n\n    Multifactor solutions that require devices separate from information\nsystems gaining access include, for example, hardware tokens providing\ntime-based or challenge-response authenticators and smart cards such as the\nU.S. Government Personal Identity Verification card and the DoD Common Access\nCard.\n\n    A privileged account is defined as an information system account with\nauthorizations of a privileged user.\n\n    Remote access is access to DoD nonpublic information systems by an\nauthorized user (or an information system) communicating through an external,\nnon-organization-controlled network. Remote access methods include, for\nexample, dial-up, broadband, and wireless.\n\n    This requirement only applies to components where this is specific to the\nfunction of the device or has the concept of an organizational user (e.g., VPN,\nproxy capability). This does not apply to authentication for the purpose of\nconfiguring the device itself (management).\n\n    Requires further clarification from NIST.",
          "descriptions": [
            {
              "label": "default",
              "data": "Using an authentication device, such as a CAC or token that is separate\nfrom the information system, ensures that even if the information system is\ncompromised, that compromise will not affect credentials stored on the\nauthentication device.\n\n    Multifactor solutions that require devices separate from information\nsystems gaining access include, for example, hardware tokens providing\ntime-based or challenge-response authenticators and smart cards such as the\nU.S. Government Personal Identity Verification card and the DoD Common Access\nCard.\n\n    A privileged account is defined as an information system account with\nauthorizations of a privileged user.\n\n    Remote access is access to DoD nonpublic information systems by an\nauthorized user (or an information system) communicating through an external,\nnon-organization-controlled network. Remote access methods include, for\nexample, dial-up, broadband, and wireless.\n\n    This requirement only applies to components where this is specific to the\nfunction of the device or has the concept of an organizational user (e.g., VPN,\nproxy capability). This does not apply to authentication for the purpose of\nconfiguring the device itself (management).\n\n    Requires further clarification from NIST."
            },
            {
              "label": "check",
              "data": "Verify the operating system implements certificate status\nchecking for PKI authentication.\n\nCheck to see if Online Certificate Status Protocol (OCSP) is enabled on the\nsystem with the following command:\n\n# grep cert_policy /etc/pam_pkcs11/pam_pkcs11.conf\n\ncert_policy = ca, ocsp_on, signature;\ncert_policy = ca, ocsp_on, signature;\ncert_policy = ca, ocsp_on, signature;\n\n\nThere should be at least three lines returned.\n\nIf \"oscp_on\" is not present in all \"cert_policy\" lines in\n\"/etc/pam_pkcs11/pam_pkcs11.conf\", this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to do certificate status checking\nfor PKI authentication.\n\nModify all of the \"cert_policy\" lines in \"/etc/pam_pkcs11/pam_pkcs11.conf\"\nto include \"ocsp_on\"."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000375-GPOS-00160",
            "satisfies": [
              "SRG-OS-000375-GPOS-00160",
              "SRG-OS-000375-GPOS-00161",
              "SRG-OS-000375-GPOS-00162"
            ],
            "gid": "V-72433",
            "rid": "SV-87057r4_rule",
            "stig_id": "RHEL-07-041003",
            "cci": [
              "CCI-001948",
              "CCI-001953",
              "CCI-001954"
            ],
            "documentable": false,
            "nist": [
              "IA-2 (11)",
              "IA-2 (12)",
              "IA-2 (12)",
              "Rev_4"
            ],
            "subsystems": [
              "pam_pkcs11",
              "pam",
              "pkcs11"
            ],
            "fix_id": "F-78785r3_fix"
          },
          "code": "control \"V-72433\" do\n  title \"The operating system must implement certificate status checking for\nPKI authentication.\"\n  desc  \"\n    Using an authentication device, such as a CAC or token that is separate\nfrom the information system, ensures that even if the information system is\ncompromised, that compromise will not affect credentials stored on the\nauthentication device.\n\n    Multifactor solutions that require devices separate from information\nsystems gaining access include, for example, hardware tokens providing\ntime-based or challenge-response authenticators and smart cards such as the\nU.S. Government Personal Identity Verification card and the DoD Common Access\nCard.\n\n    A privileged account is defined as an information system account with\nauthorizations of a privileged user.\n\n    Remote access is access to DoD nonpublic information systems by an\nauthorized user (or an information system) communicating through an external,\nnon-organization-controlled network. Remote access methods include, for\nexample, dial-up, broadband, and wireless.\n\n    This requirement only applies to components where this is specific to the\nfunction of the device or has the concept of an organizational user (e.g., VPN,\nproxy capability). This does not apply to authentication for the purpose of\nconfiguring the device itself (management).\n\n    Requires further clarification from NIST.\n  \"\nif smart_card_status.eql?('enabled')\n  impact 0.5\nelse\n  impact 0.0\nend\n  tag \"gtitle\": \"SRG-OS-000375-GPOS-00160\"\n  tag \"satisfies\": [\"SRG-OS-000375-GPOS-00160\", \"SRG-OS-000375-GPOS-00161\",\n\"SRG-OS-000375-GPOS-00162\"]\n  tag \"gid\": \"V-72433\"\n  tag \"rid\": \"SV-87057r4_rule\"\n  tag \"stig_id\": \"RHEL-07-041003\"\n  tag \"cci\": [\"CCI-001948\", \"CCI-001953\", \"CCI-001954\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-2 (11)\", \"IA-2 (12)\", \"IA-2 (12)\", \"Rev_4\"]\n  tag \"subsystems\": ['pam_pkcs11', 'pam' , 'pkcs11']\n  desc \"check\", \"Verify the operating system implements certificate status\nchecking for PKI authentication.\n\nCheck to see if Online Certificate Status Protocol (OCSP) is enabled on the\nsystem with the following command:\n\n# grep cert_policy /etc/pam_pkcs11/pam_pkcs11.conf\n\ncert_policy = ca, ocsp_on, signature;\ncert_policy = ca, ocsp_on, signature;\ncert_policy = ca, ocsp_on, signature;\n\n\nThere should be at least three lines returned.\n\nIf \\\"oscp_on\\\" is not present in all \\\"cert_policy\\\" lines in\n\\\"/etc/pam_pkcs11/pam_pkcs11.conf\\\", this is a finding.\n\"\n  desc \"fix\", \"Configure the operating system to do certificate status checking\nfor PKI authentication.\n\nModify all of the \\\"cert_policy\\\" lines in \\\"/etc/pam_pkcs11/pam_pkcs11.conf\\\"\nto include \\\"ocsp_on\\\".\"\n  tag \"fix_id\": \"F-78785r3_fix\"\n\n  if smart_card_status.eql?('enabled')\n    if ((pam_file = file('/etc/pam_pkcs11/pam_pkcs11.conf')).exist?)\n      cert_policy_lines = (pam_file.content.nil?)?[]:\n        pam_file.content.lines.grep(%r{^(?!.+#).*cert_policy}i)\n      if (cert_policy_lines.length < 3)\n        describe \"should contain at least 3 cert policy lines\" do\n          subject { cert_policy_lines.length }\n          it { should >= 3 }\n        end\n      else\n        describe \"each cert policy line should include oscp_on\" do\n          cert_policy_lines.each do |line|                                    \n            line.should match %r{=[^;]*ocsp_on}i                                        \n          end \n        end                                                                                              \n      end\n    else \n      describe pam_file do\n        it { should exist }\n      end\n    end\n  else\n    describe \"The system is not smartcard enabled\" do\n      skip \"The system is not using Smartcards / PIVs to fulfil the MFA requirement, this control is Not Applicable.\"\n    end\n  end\nend\n",
          "source_location": {
            "line": 10,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72433.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "should contain at least 3 cert policy lines should >= 3",
              "run_time": 0.000135703,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "expected: >= 3\n     got:    0"
            }
          ]
        },
        {
          "id": "V-72435",
          "title": "The operating system must implement smart card logons for multifactor\nauthentication for access to privileged accounts.",
          "desc": "Using an authentication device, such as a CAC or token that is separate from the\ninformation system, ensures that even if the information system is compromised, that\ncompromise will not affect credentials stored on the authentication device.\n\n    Multifactor solutions that require devices separate from information systems\ngaining access include, for example, hardware tokens providing time-based or\nchallenge-response authenticators and smart cards such as the U.S. Government\nPersonal Identity Verification card and the DoD Common Access Card.\n\n    A privileged account is defined as an information system account with\nauthorizations of a privileged user.\n\n    Remote access is access to DoD nonpublic information systems by an authorized\nuser (or an information system) communicating through an external,\nnon-organization-controlled network. Remote access methods include, for example,\ndial-up, broadband, and wireless.\n\n    This requirement only applies to components where this is specific to the\nfunction of the device or has the concept of an organizational user (e.g., VPN,\nproxy capability). This does not apply to authentication for the purpose of\nconfiguring the device itself (management).\n\n    Requires further clarification from NIST.\n\n    Satisfies: SRG-OS-000375-GPOS-00160, SRG-OS-000375-GPOS-00161,\nSRG-OS-000375-GPOS-0016.",
          "descriptions": [
            {
              "label": "default",
              "data": "Using an authentication device, such as a CAC or token that is separate from the\ninformation system, ensures that even if the information system is compromised, that\ncompromise will not affect credentials stored on the authentication device.\n\n    Multifactor solutions that require devices separate from information systems\ngaining access include, for example, hardware tokens providing time-based or\nchallenge-response authenticators and smart cards such as the U.S. Government\nPersonal Identity Verification card and the DoD Common Access Card.\n\n    A privileged account is defined as an information system account with\nauthorizations of a privileged user.\n\n    Remote access is access to DoD nonpublic information systems by an authorized\nuser (or an information system) communicating through an external,\nnon-organization-controlled network. Remote access methods include, for example,\ndial-up, broadband, and wireless.\n\n    This requirement only applies to components where this is specific to the\nfunction of the device or has the concept of an organizational user (e.g., VPN,\nproxy capability). This does not apply to authentication for the purpose of\nconfiguring the device itself (management).\n\n    Requires further clarification from NIST.\n\n    Satisfies: SRG-OS-000375-GPOS-00160, SRG-OS-000375-GPOS-00161,\nSRG-OS-000375-GPOS-0016."
            },
            {
              "label": "check",
              "data": "Verify the operating system requires smart card logons for\nmultifactor authentication to uniquely identify privileged users.\n\nCheck to see if smartcard authentication is enforced on the system with the\nfollowing command:\n\n# authconfig --test | grep -i smartcard\n\nThe entry for use only smartcard for logon may be enabled, and the smartcard module\nand smartcard removal actions must not be blank.\n\nIf smartcard authentication is disabled or the smartcard and smartcard removal\nactions are blank, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to implement smart card logon for\nmultifactor authentication to uniquely identify privileged users.\n\nEnable smart card logons with the following commands:\n\n# authconfig --enablesmartcard --smartcardaction=1 --update\n# authconfig --enablerequiresmartcard --update"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "severity": "medium",
            "gtitle": "SRG-OS-000375-GPOS-00160",
            "gid": "V-72435",
            "rid": "SV-87059r2_rule",
            "stig_id": "RHEL-07-041004",
            "cci": [
              "CCI-001954"
            ],
            "nist": [
              "IA-2 (12)",
              "Rev_4"
            ],
            "subsystems": [
              "smartcard",
              "MFA"
            ]
          },
          "code": "control \"V-72435\" do\n  title \"The operating system must implement smart card logons for multifactor\nauthentication for access to privileged accounts.\"\n  desc  \"\n    Using an authentication device, such as a CAC or token that is separate from the\ninformation system, ensures that even if the information system is compromised, that\ncompromise will not affect credentials stored on the authentication device.\n\n    Multifactor solutions that require devices separate from information systems\ngaining access include, for example, hardware tokens providing time-based or\nchallenge-response authenticators and smart cards such as the U.S. Government\nPersonal Identity Verification card and the DoD Common Access Card.\n\n    A privileged account is defined as an information system account with\nauthorizations of a privileged user.\n\n    Remote access is access to DoD nonpublic information systems by an authorized\nuser (or an information system) communicating through an external,\nnon-organization-controlled network. Remote access methods include, for example,\ndial-up, broadband, and wireless.\n\n    This requirement only applies to components where this is specific to the\nfunction of the device or has the concept of an organizational user (e.g., VPN,\nproxy capability). This does not apply to authentication for the purpose of\nconfiguring the device itself (management).\n\n    Requires further clarification from NIST.\n\n    Satisfies: SRG-OS-000375-GPOS-00160, SRG-OS-000375-GPOS-00161,\nSRG-OS-000375-GPOS-0016.\n  \"\n  impact 0.5\n  tag \"severity\": \"medium\"\n  tag \"gtitle\": \"SRG-OS-000375-GPOS-00160\"\n  tag \"gid\": \"V-72435\"\n  tag \"rid\": \"SV-87059r2_rule\"\n  tag \"stig_id\": \"RHEL-07-041004\"\n  tag \"cci\": \"CCI-001948\"\n  tag \"nist\": [\"IA-2 (11)\", \"Rev_4\"]\n  tag \"cci\": \"CCI-001953\"\n  tag \"nist\": [\"IA-2 (12)\", \"Rev_4\"]\n  tag \"cci\": \"CCI-001954\"\n  tag \"nist\": [\"IA-2 (12)\", \"Rev_4\"]\n  tag \"subsystems\": ['smartcard', 'MFA']\n  desc \"check\", \"Verify the operating system requires smart card logons for\nmultifactor authentication to uniquely identify privileged users.\n\nCheck to see if smartcard authentication is enforced on the system with the\nfollowing command:\n\n# authconfig --test | grep -i smartcard\n\nThe entry for use only smartcard for logon may be enabled, and the smartcard module\nand smartcard removal actions must not be blank.\n\nIf smartcard authentication is disabled or the smartcard and smartcard removal\nactions are blank, this is a finding.\"\n\n  desc \"fix\", \"Configure the operating system to implement smart card logon for\nmultifactor authentication to uniquely identify privileged users.\n\nEnable smart card logons with the following commands:\n\n# authconfig --enablesmartcard --smartcardaction=1 --update\n# authconfig --enablerequiresmartcard --update\"\n\n\n  describe command(\"authconfig --test | grep -i \\\"smartcard for login is\\\" | awk '{ print $NF }'\") do\n    its('stdout.strip') { should eq 'enabled' }\n  end\n\n  describe command('authconfig --test | grep -i \"smartcard removal action\" | awk \\'{ print $NF }\\'') do\n    its('stdout.strip') { should_not be nil }\n  end\n\nend\n",
          "source_location": {
            "line": 23,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-72435.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Command: `authconfig --test | grep -i \"smartcard for login is\" | awk '{ print $NF }'` stdout.strip should eq \"enabled\"",
              "run_time": 0.159441549,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "\nexpected: \"enabled\"\n     got: \"disabled\"\n\n(compared using ==)\n"
            },
            {
              "status": "passed",
              "code_desc": "Command: `authconfig --test | grep -i \"smartcard removal action\" | awk '{ print $NF }'` stdout.strip should not equal nil",
              "run_time": 0.105034662,
              "start_time": "2019-11-04T16:17:17-05:00"
            }
          ]
        },
        {
          "id": "V-73155",
          "title": "The operating system must prevent a user from overriding the\nscreensaver lock-delay setting for the graphical user interface.",
          "desc": "A session time-out lock is a temporary action taken when a user stops work\nand moves away from the immediate physical vicinity of the information system\nbut does not log out because of the temporary nature of the absence. Rather\nthan relying on the user to manually lock their operating system session prior\nto vacating the vicinity, operating systems need to be able to identify when a\nuser's session has idled and take action to initiate the session lock.\n\n    The session lock is implemented at the point where session activity can be\ndetermined and/or controlled.",
          "descriptions": [
            {
              "label": "default",
              "data": "A session time-out lock is a temporary action taken when a user stops work\nand moves away from the immediate physical vicinity of the information system\nbut does not log out because of the temporary nature of the absence. Rather\nthan relying on the user to manually lock their operating system session prior\nto vacating the vicinity, operating systems need to be able to identify when a\nuser's session has idled and take action to initiate the session lock.\n\n    The session lock is implemented at the point where session activity can be\ndetermined and/or controlled."
            },
            {
              "label": "check",
              "data": "Verify the operating system prevents a user from overriding a\nscreensaver lock after a 15-minute period of inactivity for graphical user\ninterfaces.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable. The screen program must be installed to lock sessions on the\nconsole.\n\nDetermine which profile the system database is using with the following command:\n# grep system-db /etc/dconf/profile/user\n\nsystem-db:local\n\nCheck for the lock delay setting with the following command:\n\nNote: The example below is using the database \"local\" for the system, so the\npath is \"/etc/dconf/db/local.d\". This path must be modified if a database\nother than \"local\" is being used.\n\n# grep -i lock-delay /etc/dconf/db/local.d/locks/*\n\n/org/gnome/desktop/screensaver/lock-delay\n\nIf the command does not return a result, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to prevent a user from overriding\na screensaver lock after a 15-minute period of inactivity for graphical user\ninterfaces.\n\nCreate a database to contain the system-wide screensaver settings (if it does\nnot already exist) with the following command:\n\nNote: The example below is using the database \"local\" for the system, so if\nthe system is using another database in \"/etc/dconf/profile/user\", the file\nshould be created under the appropriate subdirectory.\n\n# touch /etc/dconf/db/local.d/locks/session\n\nAdd the setting to lock the screensaver lock delay:\n\n/org/gnome/desktop/screensaver/lock-delay"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000029-GPOS-00010",
            "gid": "V-73155",
            "rid": "SV-87807r3_rule",
            "stig_id": "RHEL-07-010081",
            "cci": [
              "CCI-000057"
            ],
            "documentable": false,
            "nist": [
              "AC-11 a",
              "Rev_4"
            ],
            "subsystems": [
              "gnome3"
            ],
            "fix_id": "F-79601r2_fix"
          },
          "code": "control \"V-73155\" do\n  title \"The operating system must prevent a user from overriding the\nscreensaver lock-delay setting for the graphical user interface.\"\n  desc  \"\n    A session time-out lock is a temporary action taken when a user stops work\nand moves away from the immediate physical vicinity of the information system\nbut does not log out because of the temporary nature of the absence. Rather\nthan relying on the user to manually lock their operating system session prior\nto vacating the vicinity, operating systems need to be able to identify when a\nuser's session has idled and take action to initiate the session lock.\n\n    The session lock is implemented at the point where session activity can be\ndetermined and/or controlled.\n  \"\n  if package('gnome-desktop3').installed?\n    impact 0.5\n  else\n    impact 0.0\n  end\n  tag \"gtitle\": \"SRG-OS-000029-GPOS-00010\"\n  tag \"gid\": \"V-73155\"\n  tag \"rid\": \"SV-87807r3_rule\"\n  tag \"stig_id\": \"RHEL-07-010081\"\n  tag \"cci\": [\"CCI-000057\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-11 a\", \"Rev_4\"]\n  tag \"subsystems\": [\"gnome3\"]\n  desc \"check\", \"Verify the operating system prevents a user from overriding a\nscreensaver lock after a 15-minute period of inactivity for graphical user\ninterfaces.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable. The screen program must be installed to lock sessions on the\nconsole.\n\nDetermine which profile the system database is using with the following command:\n# grep system-db /etc/dconf/profile/user\n\nsystem-db:local\n\nCheck for the lock delay setting with the following command:\n\nNote: The example below is using the database \\\"local\\\" for the system, so the\npath is \\\"/etc/dconf/db/local.d\\\". This path must be modified if a database\nother than \\\"local\\\" is being used.\n\n# grep -i lock-delay /etc/dconf/db/local.d/locks/*\n\n/org/gnome/desktop/screensaver/lock-delay\n\nIf the command does not return a result, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to prevent a user from overriding\na screensaver lock after a 15-minute period of inactivity for graphical user\ninterfaces.\n\nCreate a database to contain the system-wide screensaver settings (if it does\nnot already exist) with the following command:\n\nNote: The example below is using the database \\\"local\\\" for the system, so if\nthe system is using another database in \\\"/etc/dconf/profile/user\\\", the file\nshould be created under the appropriate subdirectory.\n\n# touch /etc/dconf/db/local.d/locks/session\n\nAdd the setting to lock the screensaver lock delay:\n\n/org/gnome/desktop/screensaver/lock-delay\"\n  tag \"fix_id\": \"F-79601r2_fix\"\n\n  describe command(\"gsettings writable org.gnome.desktop.screensaver lock-delay\") do\n    its('stdout.strip') { should cmp 'false' }\n  end if package('gnome-desktop3').installed?\n\n  describe \"The GNOME desktop is not installed\" do\n    skip \"The GNOME desktop is not installed, this control is Not Applicable.\"\n  end if !package('gnome-desktop3').installed?\nend\n",
          "source_location": {
            "line": 4,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-73155.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Command: `gsettings writable org.gnome.desktop.screensaver lock-delay` stdout.strip should cmp == \"false\"",
              "run_time": 0.017389322,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "\nexpected: \"false\"\n     got: \"true\"\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-73157",
          "title": "The operating system must prevent a user from overriding the session\nidle-delay setting for the graphical user interface.",
          "desc": "A session time-out lock is a temporary action taken when a user stops work\nand moves away from the immediate physical vicinity of the information system\nbut does not log out because of the temporary nature of the absence. Rather\nthan relying on the user to manually lock their operating system session prior\nto vacating the vicinity, operating systems need to be able to identify when a\nuser's session has idled and take action to initiate the session lock.\n\n    The session lock is implemented at the point where session activity can be\ndetermined and/or controlled.",
          "descriptions": [
            {
              "label": "default",
              "data": "A session time-out lock is a temporary action taken when a user stops work\nand moves away from the immediate physical vicinity of the information system\nbut does not log out because of the temporary nature of the absence. Rather\nthan relying on the user to manually lock their operating system session prior\nto vacating the vicinity, operating systems need to be able to identify when a\nuser's session has idled and take action to initiate the session lock.\n\n    The session lock is implemented at the point where session activity can be\ndetermined and/or controlled."
            },
            {
              "label": "check",
              "data": "Verify the operating system prevents a user from overriding\nsession idle delay after a 15-minute period of inactivity for graphical user\ninterfaces.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable. The screen program must be installed to lock sessions on the\nconsole.\n\nDetermine which profile the system database is using with the following command:\n# grep system-db /etc/dconf/profile/user\n\nsystem-db:local\n\nCheck for the session idle delay setting with the following command:\n\nNote: The example below is using the database \"local\" for the system, so the\npath is \"/etc/dconf/db/local.d\". This path must be modified if a database\nother than \"local\" is being used.\n\n# grep -i idle-delay /etc/dconf/db/local.d/locks/*\n\n/org/gnome/desktop/session/idle-delay\n\nIf the command does not return a result, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to prevent a user from overriding\na session lock after a 15-minute period of inactivity for graphical user\ninterfaces.\n\nCreate a database to contain the system-wide screensaver settings (if it does\nnot already exist) with the following command:\n\nNote: The example below is using the database \"local\" for the system, so if\nthe system is using another database in /etc/dconf/profile/user, the file\nshould be created under the appropriate subdirectory.\n\n# touch /etc/dconf/db/local.d/locks/session\n\nAdd the setting to lock the session idle delay:\n\n/org/gnome/desktop/session/idle-delay"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000029-GPOS-00010",
            "gid": "V-73157",
            "rid": "SV-87809r3_rule",
            "stig_id": "RHEL-07-010082",
            "cci": [
              "CCI-000057"
            ],
            "documentable": false,
            "nist": [
              "AC-11 a",
              "Rev_4"
            ],
            "subsystems": [
              "gnome3"
            ],
            "fix_id": "F-79603r1_fix"
          },
          "code": "control \"V-73157\" do\n  title \"The operating system must prevent a user from overriding the session\nidle-delay setting for the graphical user interface.\"\n  desc  \"\n    A session time-out lock is a temporary action taken when a user stops work\nand moves away from the immediate physical vicinity of the information system\nbut does not log out because of the temporary nature of the absence. Rather\nthan relying on the user to manually lock their operating system session prior\nto vacating the vicinity, operating systems need to be able to identify when a\nuser's session has idled and take action to initiate the session lock.\n\n    The session lock is implemented at the point where session activity can be\ndetermined and/or controlled.\n  \"\n  if package('gnome-desktop3').installed?\n    impact 0.5\n  else\n    impact 0.0\n  end\n  tag \"gtitle\": \"SRG-OS-000029-GPOS-00010\"\n  tag \"gid\": \"V-73157\"\n  tag \"rid\": \"SV-87809r3_rule\"\n  tag \"stig_id\": \"RHEL-07-010082\"\n  tag \"cci\": [\"CCI-000057\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-11 a\", \"Rev_4\"]\n  tag \"subsystems\": ['gnome3']\n  desc \"check\", \"Verify the operating system prevents a user from overriding\nsession idle delay after a 15-minute period of inactivity for graphical user\ninterfaces.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable. The screen program must be installed to lock sessions on the\nconsole.\n\nDetermine which profile the system database is using with the following command:\n# grep system-db /etc/dconf/profile/user\n\nsystem-db:local\n\nCheck for the session idle delay setting with the following command:\n\nNote: The example below is using the database \\\"local\\\" for the system, so the\npath is \\\"/etc/dconf/db/local.d\\\". This path must be modified if a database\nother than \\\"local\\\" is being used.\n\n# grep -i idle-delay /etc/dconf/db/local.d/locks/*\n\n/org/gnome/desktop/session/idle-delay\n\nIf the command does not return a result, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to prevent a user from overriding\na session lock after a 15-minute period of inactivity for graphical user\ninterfaces.\n\nCreate a database to contain the system-wide screensaver settings (if it does\nnot already exist) with the following command:\n\nNote: The example below is using the database \\\"local\\\" for the system, so if\nthe system is using another database in /etc/dconf/profile/user, the file\nshould be created under the appropriate subdirectory.\n\n# touch /etc/dconf/db/local.d/locks/session\n\nAdd the setting to lock the session idle delay:\n\n/org/gnome/desktop/session/idle-delay\"\n  tag \"fix_id\": \"F-79603r1_fix\"\n\n  describe command(\"gsettings writable org.gnome.desktop.session idle-delay\") do\n    its('stdout.strip') { should cmp 'false' }\n  end if package('gnome-desktop3').installed?\n\n  describe \"The GNOME desktop is not installed\" do\n    skip \"The GNOME desktop is not installed, this control is Not Applicable.\"\n  end if !package('gnome-desktop3').installed?\nend\n",
          "source_location": {
            "line": 4,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-73157.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Command: `gsettings writable org.gnome.desktop.session idle-delay` stdout.strip should cmp == \"false\"",
              "run_time": 0.015937787,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "\nexpected: \"false\"\n     got: \"true\"\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-73159",
          "title": "When passwords are changed or new passwords are established, pwquality\nmust be used.",
          "desc": "Use of a complex password helps to increase the time and resources\nrequired to compromise the password. Password complexity, or strength, is a\nmeasure of the effectiveness of a password in resisting attempts at guessing\nand brute-force attacks. \"pwquality\" enforces complex password construction\nconfiguration and has the ability to limit brute-force attacks on the system.",
          "descriptions": [
            {
              "label": "default",
              "data": "Use of a complex password helps to increase the time and resources\nrequired to compromise the password. Password complexity, or strength, is a\nmeasure of the effectiveness of a password in resisting attempts at guessing\nand brute-force attacks. \"pwquality\" enforces complex password construction\nconfiguration and has the ability to limit brute-force attacks on the system."
            },
            {
              "label": "check",
              "data": "Verify the operating system uses \"pwquality\" to enforce the\npassword complexity rules.\n\nCheck for the use of \"pwquality\" with the following command:\n\n#  cat /etc/pam.d/passwd | grep pam_pwquality\n\npassword required pam_pwquality.so retry=3\n\nIf the command does not return a line containing the value\n\"pam_pwquality.so\", this is a finding.\n\nIf the value of \"retry\" is set to \"0\" or greater than \"3\", this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to use \"pwquality\" to enforce\npassword complexity rules.\n\nAdd the following line to \"/etc/pam.d/passwd\" (or modify the line to have the\nrequired value):\n\npassword    required    pam_pwquality.so retry=3\n\nNote: The value of \"retry\" should be between \"1\" and \"3\"."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000069-GPOS-00037",
            "gid": "V-73159",
            "rid": "SV-87811r3_rule",
            "stig_id": "RHEL-07-010119",
            "cci": [
              "CCI-000192"
            ],
            "documentable": false,
            "nist": [
              "IA-5 (1) (a)",
              "Rev_4"
            ],
            "subsystems": [
              "pam",
              "pwquality",
              "password"
            ],
            "fix_id": "F-79605r2_fix"
          },
          "code": "control \"V-73159\" do\n  title \"When passwords are changed or new passwords are established, pwquality\nmust be used.\"\n  desc  \"Use of a complex password helps to increase the time and resources\nrequired to compromise the password. Password complexity, or strength, is a\nmeasure of the effectiveness of a password in resisting attempts at guessing\nand brute-force attacks. \\\"pwquality\\\" enforces complex password construction\nconfiguration and has the ability to limit brute-force attacks on the system.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000069-GPOS-00037\"\n  tag \"gid\": \"V-73159\"\n  tag \"rid\": \"SV-87811r3_rule\"\n  tag \"stig_id\": \"RHEL-07-010119\"\n  tag \"cci\": [\"CCI-000192\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-5 (1) (a)\", \"Rev_4\"]\n  tag \"subsystems\": ['pam', 'pwquality', 'password']\n  desc \"check\", \"Verify the operating system uses \\\"pwquality\\\" to enforce the\npassword complexity rules.\n\nCheck for the use of \\\"pwquality\\\" with the following command:\n\n#  cat /etc/pam.d/passwd | grep pam_pwquality\n\npassword required pam_pwquality.so retry=3\n\nIf the command does not return a line containing the value\n\\\"pam_pwquality.so\\\", this is a finding.\n\nIf the value of \\\"retry\\\" is set to \\\"0\\\" or greater than \\\"3\\\", this is a finding.\"\n  desc \"fix\", \"Configure the operating system to use \\\"pwquality\\\" to enforce\npassword complexity rules.\n\nAdd the following line to \\\"/etc/pam.d/passwd\\\" (or modify the line to have the\nrequired value):\n\npassword    required    pam_pwquality.so retry=3\n\nNote: The value of \\\"retry\\\" should be between \\\"1\\\" and \\\"3\\\".\"\n  tag \"fix_id\": \"F-79605r2_fix\"\n\n  describe pam('/etc/pam.d/passwd') do\n    its('lines') { should match_pam_rule('password (required|requisite) pam_pwquality.so') }\n    its('lines') { should match_pam_rule('password (required|requisite) pam_pwquality.so').all_with_integer_arg('retry', '>=', 1) }\n    its('lines') { should match_pam_rule('password (required|requisite) pam_pwquality.so').all_with_integer_arg('retry', '<=', max_retry) }\n  end\nend\n",
          "source_location": {
            "line": 7,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-73159.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "PAM Config[/etc/pam.d/passwd] lines should include password (required|requisite) pam_pwquality.so",
              "run_time": 0.000352374,
              "start_time": "2019-11-04T16:17:17-05:00"
            },
            {
              "status": "passed",
              "code_desc": "PAM Config[/etc/pam.d/passwd] lines should include password (required|requisite) pam_pwquality.so, all with arg retry >= 1",
              "run_time": 0.000581986,
              "start_time": "2019-11-04T16:17:17-05:00"
            },
            {
              "status": "passed",
              "code_desc": "PAM Config[/etc/pam.d/passwd] lines should include password (required|requisite) pam_pwquality.so, all with arg retry <= 3",
              "run_time": 0.000488188,
              "start_time": "2019-11-04T16:17:17-05:00"
            }
          ]
        },
        {
          "id": "V-73161",
          "title": "File systems that are being imported via Network File System (NFS)\nmust be mounted to prevent binary files from being executed.",
          "desc": "The \"noexec\" mount option causes the system to not execute binary\nfiles. This option must be used for mounting any file system not containing\napproved binary files as they may be incompatible. Executing files from\nuntrusted file systems increases the opportunity for unprivileged users to\nattain unauthorized administrative access.",
          "descriptions": [
            {
              "label": "default",
              "data": "The \"noexec\" mount option causes the system to not execute binary\nfiles. This option must be used for mounting any file system not containing\napproved binary files as they may be incompatible. Executing files from\nuntrusted file systems increases the opportunity for unprivileged users to\nattain unauthorized administrative access."
            },
            {
              "label": "check",
              "data": "Verify file systems that are being NFS exported are mounted\nwith the \"noexec\" option.\n\nFind the file system(s) that contain the directories being exported with the\nfollowing command:\n\n# more /etc/fstab | grep nfs\n\nUUID=e06097bb-cfcd-437b-9e4d-a691f5662a7d /store nfs rw,noexec 0 0\n\nIf a file system found in \"/etc/fstab\" refers to NFS and it does not have the\n\"noexec\" option set, and use of NFS exported binaries is not documented with\nthe Information System Security Officer (ISSO) as an operational requirement,\nthis is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the \"/etc/fstab\" to use the \"noexec\" option on file\nsystems that are being exported via NFS."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-73161",
            "rid": "SV-87813r1_rule",
            "stig_id": "RHEL-07-021021",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "nfs"
            ],
            "fix_id": "F-79607r1_fix"
          },
          "code": "control \"V-73161\" do\n  title \"File systems that are being imported via Network File System (NFS)\nmust be mounted to prevent binary files from being executed.\"\n  desc  \"The \\\"noexec\\\" mount option causes the system to not execute binary\nfiles. This option must be used for mounting any file system not containing\napproved binary files as they may be incompatible. Executing files from\nuntrusted file systems increases the opportunity for unprivileged users to\nattain unauthorized administrative access.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-73161\"\n  tag \"rid\": \"SV-87813r1_rule\"\n  tag \"stig_id\": \"RHEL-07-021021\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['nfs']\n  desc \"check\", \"Verify file systems that are being NFS exported are mounted\nwith the \\\"noexec\\\" option.\n\nFind the file system(s) that contain the directories being exported with the\nfollowing command:\n\n# more /etc/fstab | grep nfs\n\nUUID=e06097bb-cfcd-437b-9e4d-a691f5662a7d /store nfs rw,noexec 0 0\n\nIf a file system found in \\\"/etc/fstab\\\" refers to NFS and it does not have the\n\\\"noexec\\\" option set, and use of NFS exported binaries is not documented with\nthe Information System Security Officer (ISSO) as an operational requirement,\nthis is a finding.\"\n  desc \"fix\", \"Configure the \\\"/etc/fstab\\\" to use the \\\"noexec\\\" option on file\nsystems that are being exported via NFS.\"\n  tag \"fix_id\": \"F-79607r1_fix\"\n\n  nfs_systems = etc_fstab.nfs_file_systems.entries\n  if !nfs_systems.nil? and !nfs_systems.empty?\n    nfs_systems.each do |file_system|\n      describe file_system do\n        its ('mount_options') { should include 'noexec' }\n      end\n    end\n  else\n    describe \"No NFS file systems were found.\" do\n      subject { nfs_systems.nil? or nfs_systems.empty? }\n      it { should eq true }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-73161.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "No NFS file systems were found. should eq true",
              "run_time": 8.9214e-05,
              "start_time": "2019-11-04T16:17:17-05:00"
            }
          ]
        },
        {
          "id": "V-73163",
          "title": "The audit system must take appropriate action when there is an error\nsending audit records to a remote system.",
          "desc": "Taking appropriate action when there is an error sending audit records\nto a remote system will minimize the possibility of losing audit records.",
          "descriptions": [
            {
              "label": "default",
              "data": "Taking appropriate action when there is an error sending audit records\nto a remote system will minimize the possibility of losing audit records."
            },
            {
              "label": "check",
              "data": "Verify the action the operating system takes if there is an\nerror sending audit records to a remote system.\n\nCheck the action that takes place if there is an error sending audit records to\na remote system with the following command:\n\n# grep -i network_failure_action /etc/audisp/audisp-remote.conf\nnetwork_failure_action = stop\n\nIf the value of the \"network_failure_action\" option is not \"syslog\",\n\"single\", or \"halt\", or the line is commented out, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the action the operating system takes if there is an\nerror sending audit records to a remote system.\n\nUncomment the \"network_failure_action\" option in\n\"/etc/audisp/audisp-remote.conf\" and set it to \"syslog\", \"single\", or\n\"halt\".\n\nnetwork_failure_action = single"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000342-GPOS-00133",
            "gid": "V-73163",
            "rid": "SV-87815r2_rule",
            "stig_id": "RHEL-07-030321",
            "cci": [
              "CCI-001851"
            ],
            "documentable": false,
            "nist": [
              "AU-4 (1)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audisp"
            ],
            "fix_id": "F-79609r1_fix"
          },
          "code": "control \"V-73163\" do\n  title \"The audit system must take appropriate action when there is an error\nsending audit records to a remote system.\"\n  desc  \"Taking appropriate action when there is an error sending audit records\nto a remote system will minimize the possibility of losing audit records.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000342-GPOS-00133\"\n  tag \"gid\": \"V-73163\"\n  tag \"rid\": \"SV-87815r2_rule\"\n  tag \"stig_id\": \"RHEL-07-030321\"\n  tag \"cci\": [\"CCI-001851\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-4 (1)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audisp']\n  desc \"check\", \"Verify the action the operating system takes if there is an\nerror sending audit records to a remote system.\n\nCheck the action that takes place if there is an error sending audit records to\na remote system with the following command:\n\n# grep -i network_failure_action /etc/audisp/audisp-remote.conf\nnetwork_failure_action = stop\n\nIf the value of the \\\"network_failure_action\\\" option is not \\\"syslog\\\",\n\\\"single\\\", or \\\"halt\\\", or the line is commented out, this is a finding.\"\n  desc \"fix\", \"Configure the action the operating system takes if there is an\nerror sending audit records to a remote system.\n\nUncomment the \\\"network_failure_action\\\" option in\n\\\"/etc/audisp/audisp-remote.conf\\\" and set it to \\\"syslog\\\", \\\"single\\\", or\n\\\"halt\\\".\n\nnetwork_failure_action = single\"\n  tag \"fix_id\": \"F-79609r1_fix\"\n\n#Test matches the test for ./inspec-profiles/controls/V-72087.rb\n  describe parse_config_file('/etc/audisp/audisp-remote.conf') do\n    its('network_failure_action.strip') { should match %r{^(syslog|single|halt)$} }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-73163.rb"
          },
          "results": [
            {
              "status": "skipped",
              "code_desc": "Parse Config File /etc/audisp/audisp-remote.conf",
              "run_time": 7.017e-06,
              "start_time": "2019-11-04T16:17:17-05:00",
              "resource": "Parse Config File /etc/audisp/audisp-remote.conf",
              "skip_message": "Can't find file: /etc/audisp/audisp-remote.conf"
            }
          ]
        },
        {
          "id": "V-73165",
          "title": "The operating system must generate audit records for all account\ncreations, modifications, disabling, and termination events that affect\n/etc/group.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system must generate audit records for all\naccount creations, modifications, disabling, and termination events that affect\n\"/etc/group\".\n\nCheck the auditing rules in \"/etc/audit/audit.rules\" with the following\ncommand:\n\n# grep /etc/group /etc/audit/audit.rules\n\n-w /etc/group -p wa -k audit_rules_usergroup_modification\n\nIf the command does not return a line, or the line is commented out, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records for all\naccount creations, modifications, disabling, and termination events that affect\n\"/etc/group\".\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-w /etc/group -p wa -k identity\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000004-GPOS-00004",
            "gid": "V-73165",
            "rid": "SV-87817r2_rule",
            "stig_id": "RHEL-07-030871",
            "cci": [
              "CCI-000018",
              "CCI-000172",
              "CCI-001403",
              "CCI-002130"
            ],
            "documentable": false,
            "nist": [
              "AC-2 (4)",
              "AU-12 c",
              "AC-2 (4)",
              "AC-2 (4)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-79611r3_fix"
          },
          "code": "control \"V-73165\" do\n  title \"The operating system must generate audit records for all account\ncreations, modifications, disabling, and termination events that affect\n/etc/group.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  tag \"gtitle\": \"SRG-OS-000004-GPOS-00004\"\n  tag \"gid\": \"V-73165\"\n  tag \"rid\": \"SV-87817r2_rule\"\n  tag \"stig_id\": \"RHEL-07-030871\"\n  tag \"cci\": [\"CCI-000018\", \"CCI-000172\", \"CCI-001403\", \"CCI-002130\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-2 (4)\", \"AU-12 c\", \"AC-2 (4)\", \"AC-2 (4)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system must generate audit records for all\naccount creations, modifications, disabling, and termination events that affect\n\\\"/etc/group\\\".\n\nCheck the auditing rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\n# grep /etc/group /etc/audit/audit.rules\n\n-w /etc/group -p wa -k audit_rules_usergroup_modification\n\nIf the command does not return a line, or the line is commented out, this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records for all\naccount creations, modifications, disabling, and termination events that affect\n\\\"/etc/group\\\".\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-w /etc/group -p wa -k identity\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-79611r3_fix\"\n\n  audit_file = '/etc/group'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'w' }\n      it { should include 'a' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\n\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-73165.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/etc/group\" permissions should not cmp == []",
              "run_time": 0.000148383,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/etc/group\" action should not include \"never\"",
              "run_time": 0.000101415,
              "start_time": "2019-11-04T16:17:17-05:00"
            }
          ]
        },
        {
          "id": "V-73167",
          "title": "The operating system must generate audit records for all account\ncreations, modifications, disabling, and termination events that affect\n/etc/gshadow.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system must generate audit records for all\naccount creations, modifications, disabling, and termination events that affect\n\"/etc/gshadow\".\n\nCheck the auditing rules in \"/etc/audit/audit.rules\" with the following\ncommand:\n\n# grep /etc/gshadow /etc/audit/audit.rules\n\n-w /etc/gshadow -p wa -k identity\n\nIf the command does not return a line, or the line is commented out, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records for all\naccount creations, modifications, disabling, and termination events that affect\n\"/etc/gshadow\".\n\nAdd or update the following rule in \"/etc/audit/rules.d/audit.rules\":\n\n-w /etc/gshadow -p wa -k identity\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000004-GPOS-00004",
            "gid": "V-73167",
            "rid": "SV-87819r3_rule",
            "stig_id": "RHEL-07-030872",
            "cci": [
              "CCI-000018",
              "CCI-000172",
              "CCI-001403",
              "CCI-002130"
            ],
            "documentable": false,
            "nist": [
              "AC-2 (4)",
              "AU-12 c",
              "AC-2 (4)",
              "AC-2 (4)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule",
              "gshadow"
            ],
            "fix_id": "F-79613r3_fix"
          },
          "code": "control \"V-73167\" do\n  title \"The operating system must generate audit records for all account\ncreations, modifications, disabling, and termination events that affect\n/etc/gshadow.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  tag \"gtitle\": \"SRG-OS-000004-GPOS-00004\"\n  tag \"gid\": \"V-73167\"\n  tag \"rid\": \"SV-87819r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030872\"\n  tag \"cci\": [\"CCI-000018\", \"CCI-000172\", \"CCI-001403\", \"CCI-002130\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-2 (4)\", \"AU-12 c\", \"AC-2 (4)\", \"AC-2 (4)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule', 'gshadow']\n  desc \"check\", \"Verify the operating system must generate audit records for all\naccount creations, modifications, disabling, and termination events that affect\n\\\"/etc/gshadow\\\".\n\nCheck the auditing rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\n# grep /etc/gshadow /etc/audit/audit.rules\n\n-w /etc/gshadow -p wa -k identity\n\nIf the command does not return a line, or the line is commented out, this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records for all\naccount creations, modifications, disabling, and termination events that affect\n\\\"/etc/gshadow\\\".\n\nAdd or update the following rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-w /etc/gshadow -p wa -k identity\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-79613r3_fix\"\n\n  audit_file = '/etc/gshadow'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'w' }\n      it { should include 'a' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\n\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-73167.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/etc/gshadow\" permissions should not cmp == []",
              "run_time": 0.000115346,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/etc/gshadow\" action should not include \"never\"",
              "run_time": 7.7666e-05,
              "start_time": "2019-11-04T16:17:17-05:00"
            }
          ]
        },
        {
          "id": "V-73171",
          "title": "The operating system must generate audit records for all account\ncreations, modifications, disabling, and termination events that affect\n/etc/shadow.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system must generate audit records for all\naccount creations, modifications, disabling, and termination events that affect\n/etc/shadow.\n\nCheck the auditing rules in \"/etc/audit/audit.rules\" with the following\ncommand:\n\n# grep /etc/shadow /etc/audit/audit.rules\n\n-w /etc/shadow -p wa -k identity\n\nIf the command does not return a line, or the line is commented out, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records for all\naccount creations, modifications, disabling, and termination events that affect\n/etc/shadow.\n\nAdd or update the following file system rule in \"/etc/audit/rules.d/audit.rules\":\n\n-w /etc/shadow -p wa -k identity\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000004-GPOS-00004",
            "gid": "V-73171",
            "rid": "SV-87823r3_rule",
            "stig_id": "RHEL-07-030873",
            "cci": [
              "CCI-000018",
              "CCI-000172",
              "CCI-001403",
              "CCI-002130"
            ],
            "documentable": false,
            "nist": [
              "AC-2 (4)",
              "AU-12 c",
              "AC-2 (4)",
              "AC-2 (4)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule"
            ],
            "fix_id": "F-79617r4_fix"
          },
          "code": "control \"V-73171\" do\n  title \"The operating system must generate audit records for all account\ncreations, modifications, disabling, and termination events that affect\n/etc/shadow.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  tag \"gtitle\": \"SRG-OS-000004-GPOS-00004\"\n  tag \"gid\": \"V-73171\"\n  tag \"rid\": \"SV-87823r3_rule\"\n  tag \"stig_id\": \"RHEL-07-030873\"\n  tag \"cci\": [\"CCI-000018\", \"CCI-000172\", \"CCI-001403\", \"CCI-002130\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-2 (4)\", \"AU-12 c\", \"AC-2 (4)\", \"AC-2 (4)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule']\n  desc \"check\", \"Verify the operating system must generate audit records for all\naccount creations, modifications, disabling, and termination events that affect\n/etc/shadow.\n\nCheck the auditing rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\n# grep /etc/shadow /etc/audit/audit.rules\n\n-w /etc/shadow -p wa -k identity\n\nIf the command does not return a line, or the line is commented out, this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records for all\naccount creations, modifications, disabling, and termination events that affect\n/etc/shadow.\n\nAdd or update the following file system rule in \\\"/etc/audit/rules.d/audit.rules\\\":\n\n-w /etc/shadow -p wa -k identity\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-79617r4_fix\"\n\n  audit_file = '/etc/shadow'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'w' }\n      it { should include 'a' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\n\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-73171.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/etc/shadow\" permissions should not cmp == []",
              "run_time": 0.000113944,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/etc/shadow\" action should not include \"never\"",
              "run_time": 0.000123803,
              "start_time": "2019-11-04T16:17:17-05:00"
            }
          ]
        },
        {
          "id": "V-73173",
          "title": "The operating system must generate audit records for all account\ncreations, modifications, disabling, and termination events that affect\n/etc/opasswd.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system must generate audit records for all\naccount creations, modifications, disabling, and termination events that affect\n/etc/security/opasswd.\n\nCheck the auditing rules in \"/etc/audit/rules.d/audit.rules\" with the\nfollowing command:\n\n# grep /etc/security/opasswd /etc/audit/rules.d/audit.rules\n\n-w /etc/security/opasswd -p wa -k identity\n\nIf the command does not return a line, or the line is commented out, this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records for all\naccount creations, modifications, disabling, and termination events that affect\n/etc/security/opasswd.\n\nAdd or update the following file system rule in\n\"/etc/audit/rules.d/audit.rules\":\n\n-w /etc/security/opasswd -p wa -k identity\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000004-GPOS-00004",
            "gid": "V-73173",
            "rid": "SV-87825r4_rule",
            "stig_id": "RHEL-07-030874",
            "cci": [
              "CCI-000018",
              "CCI-000172",
              "CCI-001403",
              "CCI-002130"
            ],
            "documentable": false,
            "nist": [
              "AC-2 (4)",
              "AU-12 c",
              "AC-2 (4)",
              "AC-2 (4)",
              "Rev_4"
            ],
            "subsystems": [
              "audit",
              "auditd",
              "audit_rule",
              "opasswd"
            ],
            "fix_id": "F-79619r5_fix"
          },
          "code": "control \"V-73173\" do\n  title \"The operating system must generate audit records for all account\ncreations, modifications, disabling, and termination events that affect\n/etc/opasswd.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  tag \"gtitle\": \"SRG-OS-000004-GPOS-00004\"\n  tag \"gid\": \"V-73173\"\n  tag \"rid\": \"SV-87825r4_rule\"\n  tag \"stig_id\": \"RHEL-07-030874\"\n  tag \"cci\": [\"CCI-000018\", \"CCI-000172\", \"CCI-001403\", \"CCI-002130\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-2 (4)\", \"AU-12 c\", \"AC-2 (4)\", \"AC-2 (4)\", \"Rev_4\"]\n  tag \"subsystems\": ['audit', 'auditd', 'audit_rule', 'opasswd']\n  desc \"check\", \"Verify the operating system must generate audit records for all\naccount creations, modifications, disabling, and termination events that affect\n/etc/security/opasswd.\n\nCheck the auditing rules in \\\"/etc/audit/rules.d/audit.rules\\\" with the\nfollowing command:\n\n# grep /etc/security/opasswd /etc/audit/rules.d/audit.rules\n\n-w /etc/security/opasswd -p wa -k identity\n\nIf the command does not return a line, or the line is commented out, this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records for all\naccount creations, modifications, disabling, and termination events that affect\n/etc/security/opasswd.\n\nAdd or update the following file system rule in\n\\\"/etc/audit/rules.d/audit.rules\\\":\n\n-w /etc/security/opasswd -p wa -k identity\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-79619r5_fix\"\n\n  audit_file = '/etc/security/opasswd'\n\n  if file(audit_file).exist?\n    impact 0.5\n  else\n    impact 0.0\n  end\n\n  describe auditd.file(audit_file) do\n    its('permissions') { should_not cmp [] }\n    its('action') { should_not include 'never' }\n  end if file(audit_file).exist?\n\n  # Resource creates data structure including all usages of file\n  perms = auditd.file(audit_file).permissions\n\n  perms.each do |perm|\n    describe perm do\n      it { should include 'w' }\n      it { should include 'a' }\n    end\n  end if file(audit_file).exist?\n\n  describe \"The #{audit_file} file does not exist\" do\n    skip \"The #{audit_file} file does not exist, this requirement is Not Applicable.\"\n  end if !file(audit_file).exist?\n\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-73173.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with file == \"/etc/security/opasswd\" permissions should not cmp == []",
              "run_time": 0.000113866,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "\nexpected it not to be == []\n     got: []\n\n(compared using `cmp` matcher)\n"
            },
            {
              "status": "passed",
              "code_desc": "Auditd Rules with file == \"/etc/security/opasswd\" action should not include \"never\"",
              "run_time": 7.7518e-05,
              "start_time": "2019-11-04T16:17:17-05:00"
            }
          ]
        },
        {
          "id": "V-73175",
          "title": "The system must ignore Internet Protocol version 4 (IPv4) Internet\nControl Message Protocol (ICMP) redirect messages.",
          "desc": "ICMP redirect messages are used by routers to inform hosts that a more\ndirect route exists for a particular destination. These messages modify the\nhost's route table and are unauthenticated. An illicit ICMP redirect message\ncould result in a man-in-the-middle attack.",
          "descriptions": [
            {
              "label": "default",
              "data": "ICMP redirect messages are used by routers to inform hosts that a more\ndirect route exists for a particular destination. These messages modify the\nhost's route table and are unauthenticated. An illicit ICMP redirect message\ncould result in a man-in-the-middle attack."
            },
            {
              "label": "check",
              "data": "Verify the system ignores IPv4 ICMP redirect messages.\n\nCheck the value of the \"accept_redirects\" variables with the following\ncommand:\n\n# /sbin/sysctl -a | grep  'net.ipv4.conf.all.accept_redirects'\n\nnet.ipv4.conf.all.accept_redirects=0\n\nIf the returned line does not have a value of \"0\", or a line is not returned,\nthis is a finding."
            },
            {
              "label": "fix",
              "data": "Set the system to ignore IPv4 ICMP redirect messages by adding\nthe following line to \"/etc/sysctl.conf\" (or modify the line to have the\nrequired value):\n\nnet.ipv4.conf.all.accept_redirects = 0"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-73175",
            "rid": "SV-87827r3_rule",
            "stig_id": "RHEL-07-040641",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "networking": null,
            "kernel": null,
            "subsystems": [
              "kernel_parameter"
            ],
            "fix_id": "F-79621r2_fix"
          },
          "code": "control \"V-73175\" do\n  title \"The system must ignore Internet Protocol version 4 (IPv4) Internet\nControl Message Protocol (ICMP) redirect messages.\"\n  desc  \"ICMP redirect messages are used by routers to inform hosts that a more\ndirect route exists for a particular destination. These messages modify the\nhost's route table and are unauthenticated. An illicit ICMP redirect message\ncould result in a man-in-the-middle attack.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-73175\"\n  tag \"rid\": \"SV-87827r3_rule\"\n  tag \"stig_id\": \"RHEL-07-040641\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"networking\",\"kernel\"\n  tag \"subsystems\": ['kernel_parameter']\n  desc \"check\", \"Verify the system ignores IPv4 ICMP redirect messages.\n\nCheck the value of the \\\"accept_redirects\\\" variables with the following\ncommand:\n\n# /sbin/sysctl -a | grep  'net.ipv4.conf.all.accept_redirects'\n\nnet.ipv4.conf.all.accept_redirects=0\n\nIf the returned line does not have a value of \\\"0\\\", or a line is not returned,\nthis is a finding.\"\n  desc \"fix\", \"Set the system to ignore IPv4 ICMP redirect messages by adding\nthe following line to \\\"/etc/sysctl.conf\\\" (or modify the line to have the\nrequired value):\n\nnet.ipv4.conf.all.accept_redirects = 0\"\n  tag \"fix_id\": \"F-79621r2_fix\"\n\n  describe kernel_parameter('net.ipv4.conf.all.accept_redirects') do\n    its('value') { should eq 0 }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-73175.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Kernel Parameter net.ipv4.conf.all.accept_redirects value should eq 0",
              "run_time": 0.015086615,
              "start_time": "2019-11-04T16:17:17-05:00"
            }
          ]
        },
        {
          "id": "V-73177",
          "title": "Wireless network adapters must be disabled.",
          "desc": "The use of wireless networking can introduce many different attack\nvectors into the organization's network. Common attack vectors such as\nmalicious association and ad hoc networks will allow an attacker to spoof a\nwireless access point (AP), allowing validated systems to connect to the\nmalicious AP and enabling the attacker to monitor and record network traffic.\nThese malicious APs can also serve to create a man-in-the-middle attack or be\nused to create a denial of service to valid network resources.",
          "descriptions": [
            {
              "label": "default",
              "data": "The use of wireless networking can introduce many different attack\nvectors into the organization's network. Common attack vectors such as\nmalicious association and ad hoc networks will allow an attacker to spoof a\nwireless access point (AP), allowing validated systems to connect to the\nmalicious AP and enabling the attacker to monitor and record network traffic.\nThese malicious APs can also serve to create a man-in-the-middle attack or be\nused to create a denial of service to valid network resources."
            },
            {
              "label": "check",
              "data": "Verify that there are no wireless interfaces configured on the\n  system.\n\n  This is N/A for systems that do not have wireless network adapters.\n\n  Check for the presence of active wireless interfaces with the following command:\n\n  # nmcli device\n  DEVICE TYPE STATE\n  eth0 ethernet connected\n  wlp3s0 wifi disconnected\n  lo loopback unmanaged\n\n  If a wireless interface is configured and its use on the system is not\n  documented with the Information System Security Officer (ISSO), this is a\n  finding."
            },
            {
              "label": "fix",
              "data": "Configure the system to disable all wireless network interfaces\n  with the following command:\n\n  # nmcli radio wifi off"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000424-GPOS-00188",
            "gid": "V-73177",
            "rid": "SV-87829r1_rule",
            "stig_id": "RHEL-07-041010",
            "cci": [
              "CCI-001443",
              "CCI-001444",
              "CCI-002418"
            ],
            "documentable": false,
            "nist": [
              "AC-18 (1)",
              "AC-18 (1)",
              "SC-8",
              "Rev_4"
            ],
            "subsystems": [
              "network",
              "wifi",
              "nmcli"
            ],
            "fix_id": "F-79623r1_fix",
            "networking": null,
            "wifi": null
          },
          "code": "control \"V-73177\" do\n  title \"Wireless network adapters must be disabled.\"\n  desc  \"The use of wireless networking can introduce many different attack\nvectors into the organization's network. Common attack vectors such as\nmalicious association and ad hoc networks will allow an attacker to spoof a\nwireless access point (AP), allowing validated systems to connect to the\nmalicious AP and enabling the attacker to monitor and record network traffic.\nThese malicious APs can also serve to create a man-in-the-middle attack or be\nused to create a denial of service to valid network resources.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000424-GPOS-00188\"\n  tag \"gid\": \"V-73177\"\n  tag \"rid\": \"SV-87829r1_rule\"\n  tag \"stig_id\": \"RHEL-07-041010\"\n  tag \"cci\": [\"CCI-001443\", \"CCI-001444\", \"CCI-002418\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-18 (1)\", \"AC-18 (1)\", \"SC-8\", \"Rev_4\"]\n  tag \"subsystems\": ['network', 'wifi', 'nmcli']\n  tag \"fix_id\": \"F-79623r1_fix\"\n  tag \"networking\",\"wifi\"\n\n  desc \"check\", \"Verify that there are no wireless interfaces configured on the\n  system.\n\n  This is N/A for systems that do not have wireless network adapters.\n\n  Check for the presence of active wireless interfaces with the following command:\n\n  # nmcli device\n  DEVICE TYPE STATE\n  eth0 ethernet connected\n  wlp3s0 wifi disconnected\n  lo loopback unmanaged\n\n  If a wireless interface is configured and its use on the system is not\n  documented with the Information System Security Officer (ISSO), this is a\n  finding.\"\n\n  desc \"fix\", \"Configure the system to disable all wireless network interfaces\n  with the following command:\n\n  # nmcli radio wifi off\"\n\n    describe command('nmcli device') do\n      its('stdout.strip') { should_not match %r{wifi connected} }\n    end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-73177.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Command: `nmcli device` stdout.strip should not match /wifi connected/",
              "run_time": 0.031322938,
              "start_time": "2019-11-04T16:17:17-05:00"
            }
          ]
        },
        {
          "id": "V-77819",
          "title": "The operating system must uniquely identify and must authenticate\nusers using multifactor authentication via a graphical user logon.",
          "desc": "To assure accountability and prevent unauthenticated access, users must be\nidentified and authenticated to prevent potential misuse and compromise of the\nsystem.\n\n    Multifactor solutions that require devices separate from information\nsystems gaining access include, for example, hardware tokens providing\ntime-based or challenge-response authenticators and smart cards such as the\nU.S. Government Personal Identity Verification card and the DoD Common Access\nCard.",
          "descriptions": [
            {
              "label": "default",
              "data": "To assure accountability and prevent unauthenticated access, users must be\nidentified and authenticated to prevent potential misuse and compromise of the\nsystem.\n\n    Multifactor solutions that require devices separate from information\nsystems gaining access include, for example, hardware tokens providing\ntime-based or challenge-response authenticators and smart cards such as the\nU.S. Government Personal Identity Verification card and the DoD Common Access\nCard."
            },
            {
              "label": "check",
              "data": "Verify the operating system uniquely identifies and\nauthenticates users using multifactor authentication via a graphical user logon.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nDetermine which profile the system database is using with the following command:\n\n# grep system-db /etc/dconf/profile/user\n\nsystem-db:local\n\nNote: The example is using the database local for the system, so the path is\n\"/etc/dconf/db/local.d\". This path must be modified if a database other than\nlocal is being used.\n\n# grep enable-smartcard-authentication /etc/dconf/db/local.d/*\n\nenable-smartcard-authentication=true\n\nIf \"enable-smartcard-authentication\" is set to \"false\" or the keyword is\nmissing, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to uniquely identify and\nauthenticate users using multifactor authentication via a graphical user logon.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nCreate a database to contain the system-wide screensaver settings (if it does\nnot already exist) with the following command:\n\nNote: The example is using the database local for the system, so if the system\nis using another database in \"/etc/dconf/profile/user\", the file should be\ncreated under the appropriate subdirectory.\n\n# touch /etc/dconf/db/local.d/00-defaults\n\nAdd the setting to enable smartcard login:\nenable-smartcard-authentication=true"
            }
          ],
          "impact": 0,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000375-GPOS-00160",
            "satisfies": [
              "SRG-OS-000375-GPOS-00161",
              "SRG-OS-000375-GPOS-00162"
            ],
            "gid": "V-77819",
            "rid": "SV-92515r1_rule",
            "stig_id": "RHEL-07-010061",
            "cci": [
              "CCI-001948",
              "CCI-001953",
              "CCI-001954"
            ],
            "documentable": false,
            "nist": [
              "IA-2 (11)",
              "IA-2 (12)",
              "IA-2 (12)",
              "Rev_4"
            ],
            "subsystems": [
              "gnome3"
            ],
            "fix_id": "F-84519r2_fix"
          },
          "code": "control \"V-77819\" do\n  title \"The operating system must uniquely identify and must authenticate\nusers using multifactor authentication via a graphical user logon.\"\n  desc  \"\n    To assure accountability and prevent unauthenticated access, users must be\nidentified and authenticated to prevent potential misuse and compromise of the\nsystem.\n\n    Multifactor solutions that require devices separate from information\nsystems gaining access include, for example, hardware tokens providing\ntime-based or challenge-response authenticators and smart cards such as the\nU.S. Government Personal Identity Verification card and the DoD Common Access\nCard.\n  \"\n  if package('gnome-desktop3').installed? and (package('pcsc-lite').installed? or package('esc').installed?)\n    impact 0.5\n  else\n    impact 0.0\n  end\n  tag \"gtitle\": \"SRG-OS-000375-GPOS-00160\"\n  tag \"satisfies\": [\"SRG-OS-000375-GPOS-00161\", \"SRG-OS-000375-GPOS-00162\"]\n  tag \"gid\": \"V-77819\"\n  tag \"rid\": \"SV-92515r1_rule\"\n  tag \"stig_id\": \"RHEL-07-010061\"\n  tag \"cci\": [\"CCI-001948\", \"CCI-001953\", \"CCI-001954\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-2 (11)\", \"IA-2 (12)\", \"IA-2 (12)\", \"Rev_4\"]\n  tag \"subsystems\": [\"gnome3\"]\n  desc \"check\", \"Verify the operating system uniquely identifies and\nauthenticates users using multifactor authentication via a graphical user logon.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nDetermine which profile the system database is using with the following command:\n\n# grep system-db /etc/dconf/profile/user\n\nsystem-db:local\n\nNote: The example is using the database local for the system, so the path is\n\\\"/etc/dconf/db/local.d\\\". This path must be modified if a database other than\nlocal is being used.\n\n# grep enable-smartcard-authentication /etc/dconf/db/local.d/*\n\nenable-smartcard-authentication=true\n\nIf \\\"enable-smartcard-authentication\\\" is set to \\\"false\\\" or the keyword is\nmissing, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to uniquely identify and\nauthenticate users using multifactor authentication via a graphical user logon.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable.\n\nCreate a database to contain the system-wide screensaver settings (if it does\nnot already exist) with the following command:\n\nNote: The example is using the database local for the system, so if the system\nis using another database in \\\"/etc/dconf/profile/user\\\", the file should be\ncreated under the appropriate subdirectory.\n\n# touch /etc/dconf/db/local.d/00-defaults\n\nAdd the setting to enable smartcard login:\nenable-smartcard-authentication=true\"\n  tag \"fix_id\": \"F-84519r2_fix\"\n\n  # @todo - dynamically gather system_db_path?\n  if package('gnome-desktop3').installed? and (package('pcsc-lite').installed? or package('esc').installed?)\n    if !dconf_user.empty? and command('whoami').stdout.strip == 'root'\n      describe command(\"sudo -u #{dconf_user} dconf read /org/gnome/login-screen/enable-smartcard-authentication\") do\n        its('stdout.strip') { should eq multifactor_enabled.to_s }\n      end\n    else\n      describe command(\"dconf read /org/gnome/login-screen/enable-smartcard-authentication\") do\n        its('stdout.strip') { should eq multifactor_enabled.to_s }\n      end\n    end\n  else\n    describe \"The GNOME desktop is not installed\" do\n      skip \"The GNOME desktop is not installed, this control is Not Applicable.\"\n    end\n  end\nend\n",
          "source_location": {
            "line": 16,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-77819.rb"
          },
          "results": [
            {
              "status": "skipped",
              "code_desc": "The GNOME desktop is not installed",
              "run_time": 8.827e-06,
              "start_time": "2019-11-04T16:17:17-05:00",
              "resource": "",
              "skip_message": "The GNOME desktop is not installed, this control is Not Applicable."
            }
          ]
        },
        {
          "id": "V-77821",
          "title": "The Datagram Congestion Control Protocol (DCCP) kernel module must be\ndisabled unless required.",
          "desc": "Disabling DCCP protects the system against exploitation of any flaws\nin the protocol implementation.",
          "descriptions": [
            {
              "label": "default",
              "data": "Disabling DCCP protects the system against exploitation of any flaws\nin the protocol implementation."
            },
            {
              "label": "check",
              "data": "Verify the operating system disables the ability to load the\nDCCP kernel module.\n\nCheck to see if the DCCP kernel module is disabled with the following command:\n\n# grep -r dccp /etc/modprobe.d/* | grep -i \"/bin/true\" | grep -v \"^#\"\n\ninstall dccp /bin/true\n\nIf the command does not return any output, or the line is commented out, and\nuse of DCCP is not documented with the Information System Security Officer\n(ISSO) as an operational requirement, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to disable the ability to use the\nDCCP kernel module.\n\nCreate a file under \"/etc/modprobe.d\" with the following command:\n\n# touch /etc/modprobe.d/nodccp.conf\n\nAdd the following line to the created file:\n\ninstall dccp /bin/true"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000378-GPOS-00163",
            "gid": "V-77821",
            "rid": "SV-92517r1_rule",
            "stig_id": "RHEL-07-020101",
            "cci": [
              "CCI-001958"
            ],
            "documentable": false,
            "nist": [
              "IA-3",
              "Rev_4"
            ],
            "subsystems": [
              "dccp",
              "kernel_module"
            ],
            "fix_id": "F-84521r2_fix"
          },
          "code": "control \"V-77821\" do\n  title \"The Datagram Congestion Control Protocol (DCCP) kernel module must be\ndisabled unless required.\"\n  desc  \"Disabling DCCP protects the system against exploitation of any flaws\nin the protocol implementation.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000378-GPOS-00163\"\n  tag \"gid\": \"V-77821\"\n  tag \"rid\": \"SV-92517r1_rule\"\n  tag \"stig_id\": \"RHEL-07-020101\"\n  tag \"cci\": [\"CCI-001958\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"IA-3\", \"Rev_4\"]\n  tag \"subsystems\": ['dccp', 'kernel_module']\n  desc \"check\", \"Verify the operating system disables the ability to load the\nDCCP kernel module.\n\nCheck to see if the DCCP kernel module is disabled with the following command:\n\n# grep -r dccp /etc/modprobe.d/* | grep -i \\\"/bin/true\\\" | grep -v \\\"^#\\\"\n\ninstall dccp /bin/true\n\nIf the command does not return any output, or the line is commented out, and\nuse of DCCP is not documented with the Information System Security Officer\n(ISSO) as an operational requirement, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to disable the ability to use the\nDCCP kernel module.\n\nCreate a file under \\\"/etc/modprobe.d\\\" with the following command:\n\n# touch /etc/modprobe.d/nodccp.conf\n\nAdd the following line to the created file:\n\ninstall dccp /bin/true\"\n  tag \"fix_id\": \"F-84521r2_fix\"\n\n  describe kernel_module('dccp') do\n    it { should_not be_loaded }\n    it { should be_blacklisted }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-77821.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Kernel Module dccp should not be loaded",
              "run_time": 0.000242273,
              "start_time": "2019-11-04T16:17:17-05:00"
            },
            {
              "status": "passed",
              "code_desc": "Kernel Module dccp should be blacklisted",
              "run_time": 0.000112901,
              "start_time": "2019-11-04T16:17:17-05:00"
            }
          ]
        },
        {
          "id": "V-77823",
          "title": "The operating system must require authentication upon booting into\n  single-user and maintenance modes.",
          "desc": "If the system does not require valid root authentication before it\n  boots into single-user or maintenance mode, anyone who invokes single-user or\n  maintenance mode is granted privileged access to all files on the system.",
          "descriptions": [
            {
              "label": "default",
              "data": "If the system does not require valid root authentication before it\n  boots into single-user or maintenance mode, anyone who invokes single-user or\n  maintenance mode is granted privileged access to all files on the system."
            },
            {
              "label": "check",
              "data": "Verify the operating system must require authentication upon\n  booting into single-user and maintenance modes.\n\n  Check that the operating system requires authentication upon booting into\n  single-user mode with the following command:\n\n  # grep -i execstart /usr/lib/systemd/system/rescue.service\n\n  ExecStart=-/bin/sh -c \"/usr/sbin/sulogin; /usr/bin/systemctl --fail --no-block\n  default\"\n\n  If \"ExecStart\" does not have \"/usr/sbin/sulogin\" as an option, this is a\n  finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to require authentication upon\n  booting into single-user and maintenance modes.\n\n  Add or modify the \"ExecStart\" line in\n  \"/usr/lib/systemd/system/rescue.service\" to include \"/usr/sbin/sulogin\":\n\n  ExecStart=-/bin/sh -c \"/usr/sbin/sulogin; /usr/bin/systemctl --fail --no-block\n  default\""
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000080-GPOS-00048",
            "gid": "V-77823",
            "rid": "SV-92519r1_rule",
            "stig_id": "RHEL-07-010481",
            "cci": [
              "CCI-000213"
            ],
            "documentable": false,
            "nist": [
              "AC-3",
              "Rev_4"
            ],
            "subsystems": [
              "root",
              "sulogin"
            ],
            "fix_id": "F-84523r1_fix"
          },
          "code": "control \"V-77823\" do\n  title \"The operating system must require authentication upon booting into\n  single-user and maintenance modes.\"\n  desc  \"If the system does not require valid root authentication before it\n  boots into single-user or maintenance mode, anyone who invokes single-user or\n  maintenance mode is granted privileged access to all files on the system.\"\n  impact 0.5\n  \n  tag \"gtitle\": \"SRG-OS-000080-GPOS-00048\"\n  tag \"gid\": \"V-77823\"\n  tag \"rid\": \"SV-92519r1_rule\"\n  tag \"stig_id\": \"RHEL-07-010481\"\n  tag \"cci\": [\"CCI-000213\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-3\", \"Rev_4\"]\n  tag \"subsystems\": ['root', 'sulogin']\n  tag \"fix_id\": \"F-84523r1_fix\"\n\n  desc \"check\", \"Verify the operating system must require authentication upon\n  booting into single-user and maintenance modes.\n\n  Check that the operating system requires authentication upon booting into\n  single-user mode with the following command:\n\n  # grep -i execstart /usr/lib/systemd/system/rescue.service\n\n  ExecStart=-/bin/sh -c \\\"/usr/sbin/sulogin; /usr/bin/systemctl --fail --no-block\n  default\\\"\n\n  If \\\"ExecStart\\\" does not have \\\"/usr/sbin/sulogin\\\" as an option, this is a\n  finding.\n  \"\n  desc \"fix\", \"Configure the operating system to require authentication upon\n  booting into single-user and maintenance modes.\n\n  Add or modify the \\\"ExecStart\\\" line in\n  \\\"/usr/lib/systemd/system/rescue.service\\\" to include \\\"/usr/sbin/sulogin\\\":\n\n  ExecStart=-/bin/sh -c \\\"/usr/sbin/sulogin; /usr/bin/systemctl --fail --no-block\n  default\\\"\n  \"\n\n  describe command(\"grep -i execstart /usr/lib/systemd/system/rescue.service\") do\n    its('stdout.strip') { should match %r{/usr/sbin/sulogin} }\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-77823.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Command: `grep -i execstart /usr/lib/systemd/system/rescue.service` stdout.strip should match /\\/usr\\/sbin\\/sulogin/",
              "run_time": 0.013939013,
              "start_time": "2019-11-04T16:17:17-05:00"
            }
          ]
        },
        {
          "id": "V-77825",
          "title": "The operating system must implement virtual address space\nrandomization.",
          "desc": "Address space layout randomization (ASLR) makes it more difficult for\nan attacker to predict the location of attack code he or she has introduced\ninto a process's address space during an attempt at exploitation. Additionally,\nASLR also makes it more difficult for an attacker to know the location of\nexisting code in order to repurpose it using return-oriented programming (ROP)\ntechniques.",
          "descriptions": [
            {
              "label": "default",
              "data": "Address space layout randomization (ASLR) makes it more difficult for\nan attacker to predict the location of attack code he or she has introduced\ninto a process's address space during an attempt at exploitation. Additionally,\nASLR also makes it more difficult for an attacker to know the location of\nexisting code in order to repurpose it using return-oriented programming (ROP)\ntechniques."
            },
            {
              "label": "check",
              "data": "Verify the operating system implements virtual address space\nrandomization.\n\nCheck that the operating system implements virtual address space randomization\nwith the following command:\n\n# grep kernel.randomize_va_space /etc/sysctl.conf\n\nkernel.randomize_va_space=2\n\nIf \"kernel.randomize_va_space\" does not have a value of \"2\", this is a\nfinding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system implement virtual address space\nrandomization.\n\nSet the system to the required kernel parameter by adding the following line to\n\"/etc/sysctl.conf\" (or modify the line to have the required value):\n\nkernel.randomize_va_space=2"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000480-GPOS-00227",
            "gid": "V-77825",
            "rid": "SV-92521r1_rule",
            "stig_id": "RHEL-07-040201",
            "cci": [
              "CCI-000366"
            ],
            "documentable": false,
            "nist": [
              "CM-6 b",
              "Rev_4"
            ],
            "subsystems": [
              "ASLR",
              "kernel_parameter"
            ],
            "fix_id": "F-84531r1_fix"
          },
          "code": "control \"V-77825\" do\n  title \"The operating system must implement virtual address space\nrandomization.\"\n  desc  \"Address space layout randomization (ASLR) makes it more difficult for\nan attacker to predict the location of attack code he or she has introduced\ninto a process's address space during an attempt at exploitation. Additionally,\nASLR also makes it more difficult for an attacker to know the location of\nexisting code in order to repurpose it using return-oriented programming (ROP)\ntechniques.\"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000480-GPOS-00227\"\n  tag \"gid\": \"V-77825\"\n  tag \"rid\": \"SV-92521r1_rule\"\n  tag \"stig_id\": \"RHEL-07-040201\"\n  tag \"cci\": [\"CCI-000366\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"CM-6 b\", \"Rev_4\"]\n  tag \"subsystems\": ['ASLR', 'kernel_parameter']\n  desc \"check\", \"Verify the operating system implements virtual address space\nrandomization.\n\nCheck that the operating system implements virtual address space randomization\nwith the following command:\n\n# grep kernel.randomize_va_space /etc/sysctl.conf\n\nkernel.randomize_va_space=2\n\nIf \\\"kernel.randomize_va_space\\\" does not have a value of \\\"2\\\", this is a\nfinding.\"\n  desc \"fix\", \"Configure the operating system implement virtual address space\nrandomization.\n\nSet the system to the required kernel parameter by adding the following line to\n\\\"/etc/sysctl.conf\\\" (or modify the line to have the required value):\n\nkernel.randomize_va_space=2\"\n  tag \"fix_id\": \"F-84531r1_fix\"\n\ndescribe kernel_parameter('kernel.randomize_va_space') do\n  its('value') { should eq randomize_va_space }\nend\n\nend\n",
          "source_location": {
            "line": 7,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-77825.rb"
          },
          "results": [
            {
              "status": "passed",
              "code_desc": "Kernel Parameter kernel.randomize_va_space value should eq 2",
              "run_time": 0.015331197,
              "start_time": "2019-11-04T16:17:17-05:00"
            }
          ]
        },
        {
          "id": "V-78995",
          "title": "The operating system must prevent a user from overriding the\nscreensaver lock-enabled setting for the graphical user interface.",
          "desc": "A session lock is a temporary action taken when a user stops work and moves\naway from the immediate physical vicinity of the information system but does\nnot want to log out because of the temporary nature of the absence.\n\n    The session lock is implemented at the point where session activity can be\ndetermined.\n\n    The ability to enable/disable a session lock is given to the user by\ndefault. Disabling the user’s ability to disengage the graphical user interface\nsession lock provides the assurance that all sessions will lock after the\nspecified period of time.",
          "descriptions": [
            {
              "label": "default",
              "data": "A session lock is a temporary action taken when a user stops work and moves\naway from the immediate physical vicinity of the information system but does\nnot want to log out because of the temporary nature of the absence.\n\n    The session lock is implemented at the point where session activity can be\ndetermined.\n\n    The ability to enable/disable a session lock is given to the user by\ndefault. Disabling the user’s ability to disengage the graphical user interface\nsession lock provides the assurance that all sessions will lock after the\nspecified period of time."
            },
            {
              "label": "check",
              "data": "Verify the operating system prevents a user from overriding the\nscreensaver lock-enabled setting for the graphical user interface.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable. The screen program must be installed to lock sessions on the\nconsole.\n\nDetermine which profile the system database is using with the following command:\n# grep system-db /etc/dconf/profile/user\n\nsystem-db:local\n\nCheck for the lock-enabled setting with the following command:\n\nNote: The example below is using the database \"local\" for the system, so the\npath is \"/etc/dconf/db/local.d\". This path must be modified if a database\nother than \"local\" is being used.\n\n# grep -i lock-enabled /etc/dconf/db/local.d/locks/*\n\n/org/gnome/desktop/screensaver/lock-enabled\n\nIf the command does not return a result, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to prevent a user from overriding\na screensaver lock after a 15-minute period of inactivity for graphical user\ninterfaces.\n\nCreate a database to contain the system-wide screensaver settings (if it does\nnot already exist) with the following command:\n\nNote: The example below is using the database \"local\" for the system, so if\nthe system is using another database in \"/etc/dconf/profile/user\", the file\nshould be created under the appropriate subdirectory.\n\n# touch /etc/dconf/db/local.d/locks/session\n\nAdd the setting to lock the screensaver lock-enabled setting:\n\n/org/gnome/desktop/screensaver/lock-enabled"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000029-GPOS-00010",
            "gid": "V-78995",
            "rid": "SV-93701r1_rule",
            "stig_id": "RHEL-07-010062",
            "cci": [
              "CCI-000057"
            ],
            "documentable": false,
            "nist": [
              "AC-11 a",
              "Rev_4"
            ],
            "subsystems": [
              "gnome",
              "gnome3"
            ],
            "fix_id": "F-85745r1_fix"
          },
          "code": "control \"V-78995\" do\n  title \"The operating system must prevent a user from overriding the\nscreensaver lock-enabled setting for the graphical user interface.\"\n  desc  \"\n    A session lock is a temporary action taken when a user stops work and moves\naway from the immediate physical vicinity of the information system but does\nnot want to log out because of the temporary nature of the absence.\n\n    The session lock is implemented at the point where session activity can be\ndetermined.\n\n    The ability to enable/disable a session lock is given to the user by\ndefault. Disabling the user’s ability to disengage the graphical user interface\nsession lock provides the assurance that all sessions will lock after the\nspecified period of time.\n  \"\n  if package('gnome-desktop3').installed?\n    impact 0.5\n  else\n    impact 0.0\n  end\n  tag \"gtitle\": \"SRG-OS-000029-GPOS-00010\"\n  tag \"gid\": \"V-78995\"\n  tag \"rid\": \"SV-93701r1_rule\"\n  tag \"stig_id\": \"RHEL-07-010062\"\n  tag \"cci\": [\"CCI-000057\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-11 a\", \"Rev_4\"]\n  tag \"subsystems\": ['gnome', 'gnome3']\n  desc \"check\", \"Verify the operating system prevents a user from overriding the\nscreensaver lock-enabled setting for the graphical user interface.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable. The screen program must be installed to lock sessions on the\nconsole.\n\nDetermine which profile the system database is using with the following command:\n# grep system-db /etc/dconf/profile/user\n\nsystem-db:local\n\nCheck for the lock-enabled setting with the following command:\n\nNote: The example below is using the database \\\"local\\\" for the system, so the\npath is \\\"/etc/dconf/db/local.d\\\". This path must be modified if a database\nother than \\\"local\\\" is being used.\n\n# grep -i lock-enabled /etc/dconf/db/local.d/locks/*\n\n/org/gnome/desktop/screensaver/lock-enabled\n\nIf the command does not return a result, this is a finding.\n\"\n  desc \"fix\", \"Configure the operating system to prevent a user from overriding\na screensaver lock after a 15-minute period of inactivity for graphical user\ninterfaces.\n\nCreate a database to contain the system-wide screensaver settings (if it does\nnot already exist) with the following command:\n\nNote: The example below is using the database \\\"local\\\" for the system, so if\nthe system is using another database in \\\"/etc/dconf/profile/user\\\", the file\nshould be created under the appropriate subdirectory.\n\n# touch /etc/dconf/db/local.d/locks/session\n\nAdd the setting to lock the screensaver lock-enabled setting:\n\n/org/gnome/desktop/screensaver/lock-enabled\n\"\n  tag \"fix_id\": \"F-85745r1_fix\"\n\n  describe command(\"gsettings writable org.gnome.desktop.screensaver lock-enabled\") do\n    its('stdout.strip') { should cmp 'false' }\n  end if package('gnome-desktop3').installed?\n\n  describe \"The GNOME desktop is not installed\" do\n    skip \"The GNOME desktop is not installed, this control is Not Applicable.\"\n  end if !package('gnome-desktop3').installed?\nend\n",
          "source_location": {
            "line": 4,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-78995.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Command: `gsettings writable org.gnome.desktop.screensaver lock-enabled` stdout.strip should cmp == \"false\"",
              "run_time": 0.016435936,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "\nexpected: \"false\"\n     got: \"true\"\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-78997",
          "title": "The operating system must prevent a user from overriding the\nscreensaver idle-activation-enabled setting for the graphical user interface.",
          "desc": "A session lock is a temporary action taken when a user stops work and moves\naway from the immediate physical vicinity of the information system but does\nnot want to log out because of the temporary nature of the absence.\n\n    The session lock is implemented at the point where session activity can be\ndetermined.\n\n    The ability to enable/disable a session lock is given to the user by\ndefault. Disabling the user’s ability to disengage the graphical user interface\nsession lock provides the assurance that all sessions will lock after the\nspecified period of time.",
          "descriptions": [
            {
              "label": "default",
              "data": "A session lock is a temporary action taken when a user stops work and moves\naway from the immediate physical vicinity of the information system but does\nnot want to log out because of the temporary nature of the absence.\n\n    The session lock is implemented at the point where session activity can be\ndetermined.\n\n    The ability to enable/disable a session lock is given to the user by\ndefault. Disabling the user’s ability to disengage the graphical user interface\nsession lock provides the assurance that all sessions will lock after the\nspecified period of time."
            },
            {
              "label": "check",
              "data": "Verify the operating system prevents a user from overriding the\nscreensaver idle-activation-enabled setting for the graphical user interface.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable. The screen program must be installed to lock sessions on the\nconsole.\n\nDetermine which profile the system database is using with the following command:\n# grep system-db /etc/dconf/profile/user\n\nsystem-db:local\n\nCheck for the idle-activation-enabled setting with the following command:\n\nNote: The example below is using the database \"local\" for the system, so the\npath is \"/etc/dconf/db/local.d\". This path must be modified if a database\nother than \"local\" is being used.\n\n# grep -i idle-activation-enabled /etc/dconf/db/local.d/locks/*\n\n/org/gnome/desktop/screensaver/idle-activation-enabled\n\nIf the command does not return a result, this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to prevent a user from overriding\na screensaver lock after a 15-minute period of inactivity for graphical user\ninterfaces.\n\nCreate a database to contain the system-wide screensaver settings (if it does\nnot already exist) with the following command:\n\nNote: The example below is using the database \"local\" for the system, so if\nthe system is using another database in \"/etc/dconf/profile/user\", the file\nshould be created under the appropriate subdirectory.\n\n# touch /etc/dconf/db/local.d/locks/session\n\nAdd the setting to lock the screensaver idle-activation-enabled setting:\n\n/org/gnome/desktop/screensaver/idle-activation-enabled"
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000029-GPOS-00010",
            "gid": "V-78997",
            "rid": "SV-93703r1_rule",
            "stig_id": "RHEL-07-010101",
            "cci": [
              "CCI-000057"
            ],
            "documentable": false,
            "nist": [
              "AC-11 a",
              "Rev_4"
            ],
            "subsystems": [
              "gnome3"
            ],
            "fix_id": "F-85747r1_fix"
          },
          "code": "control \"V-78997\" do\n  title \"The operating system must prevent a user from overriding the\nscreensaver idle-activation-enabled setting for the graphical user interface.\"\n  desc  \"\n    A session lock is a temporary action taken when a user stops work and moves\naway from the immediate physical vicinity of the information system but does\nnot want to log out because of the temporary nature of the absence.\n\n    The session lock is implemented at the point where session activity can be\ndetermined.\n\n    The ability to enable/disable a session lock is given to the user by\ndefault. Disabling the user’s ability to disengage the graphical user interface\nsession lock provides the assurance that all sessions will lock after the\nspecified period of time.\n  \"\n  if package('gnome-desktop3').installed?\n    impact 0.5\n  else\n    impact 0.0\n  end\n  tag \"gtitle\": \"SRG-OS-000029-GPOS-00010\"\n  tag \"gid\": \"V-78997\"\n  tag \"rid\": \"SV-93703r1_rule\"\n  tag \"stig_id\": \"RHEL-07-010101\"\n  tag \"cci\": [\"CCI-000057\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AC-11 a\", \"Rev_4\"]\n  tag \"subsystems\": [\"gnome3\"]\n  desc \"check\", \"Verify the operating system prevents a user from overriding the\nscreensaver idle-activation-enabled setting for the graphical user interface.\n\nNote: If the system does not have GNOME installed, this requirement is Not\nApplicable. The screen program must be installed to lock sessions on the\nconsole.\n\nDetermine which profile the system database is using with the following command:\n# grep system-db /etc/dconf/profile/user\n\nsystem-db:local\n\nCheck for the idle-activation-enabled setting with the following command:\n\nNote: The example below is using the database \\\"local\\\" for the system, so the\npath is \\\"/etc/dconf/db/local.d\\\". This path must be modified if a database\nother than \\\"local\\\" is being used.\n\n# grep -i idle-activation-enabled /etc/dconf/db/local.d/locks/*\n\n/org/gnome/desktop/screensaver/idle-activation-enabled\n\nIf the command does not return a result, this is a finding.\"\n  desc \"fix\", \"Configure the operating system to prevent a user from overriding\na screensaver lock after a 15-minute period of inactivity for graphical user\ninterfaces.\n\nCreate a database to contain the system-wide screensaver settings (if it does\nnot already exist) with the following command:\n\nNote: The example below is using the database \\\"local\\\" for the system, so if\nthe system is using another database in \\\"/etc/dconf/profile/user\\\", the file\nshould be created under the appropriate subdirectory.\n\n# touch /etc/dconf/db/local.d/locks/session\n\nAdd the setting to lock the screensaver idle-activation-enabled setting:\n\n/org/gnome/desktop/screensaver/idle-activation-enabled\"\n  tag \"fix_id\": \"F-85747r1_fix\"\n\n  describe command(\"gsettings writable org.gnome.desktop.screensaver idle-activation-enabled\") do\n    its('stdout.strip') { should cmp 'false' }\n  end if package('gnome-desktop3').installed?\n\n  describe \"The GNOME desktop is not installed\" do\n    skip \"The GNOME desktop is not installed, this control is Not Applicable.\"\n  end if !package('gnome-desktop3').installed?\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-78997.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Command: `gsettings writable org.gnome.desktop.screensaver idle-activation-enabled` stdout.strip should cmp == \"false\"",
              "run_time": 0.016275313,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "\nexpected: \"false\"\n     got: \"true\"\n\n(compared using `cmp` matcher)\n"
            }
          ]
        },
        {
          "id": "V-78999",
          "title": "All uses of the create_module command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"create_module\" command occur.\n\nCheck the auditing rules in \"/etc/audit/audit.rules\" with the following\ncommand:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the line appropriate for the system architecture\nmust be present.\n\n# grep -iw create_module /etc/audit/audit.rules\n\nIf the command does not return the following output (appropriate to the\narchitecture), this is a finding.\n\n-a always,exit -F arch=b32 -S create_module -k module-change\n\n-a always,exit -F arch=b64 -S create_module -k module-change\n\nIf there are no audit rules defined for \"create_module\", this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"create_module\" command occur.\n\nAdd or update the following rules in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S create_module -k module-change\n\n-a always,exit -F arch=b64 -S create_module -k module-change\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000471-GPOS-00216",
            "satisfies": [
              "SRG-OS-000471-GPOS-00216",
              "SRG-OS-000477-GPOS-00222"
            ],
            "gid": "V-78999",
            "rid": "SV-93705r1_rule",
            "stig_id": "RHEL-07-030819",
            "cci": [
              "CCI-000172"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "Rev_4"
            ],
            "subsystems": [
              "audit"
            ],
            "fix_id": "F-85749r1_fix"
          },
          "code": "control \"V-78999\" do\n  title \"All uses of the create_module command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000471-GPOS-00216\"\n  tag \"satisfies\": [\"SRG-OS-000471-GPOS-00216\", \"SRG-OS-000477-GPOS-00222\"]\n  tag \"gid\": \"V-78999\"\n  tag \"rid\": \"SV-93705r1_rule\"\n  tag \"stig_id\": \"RHEL-07-030819\"\n  tag \"cci\": [\"CCI-000172\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"Rev_4\"]\n  tag \"subsystems\": [\"audit\"]\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"create_module\\\" command occur.\n\nCheck the auditing rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the line appropriate for the system architecture\nmust be present.\n\n# grep -iw create_module /etc/audit/audit.rules\n\nIf the command does not return the following output (appropriate to the\narchitecture), this is a finding.\n\n-a always,exit -F arch=b32 -S create_module -k module-change\n\n-a always,exit -F arch=b64 -S create_module -k module-change\n\nIf there are no audit rules defined for \\\"create_module\\\", this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"create_module\\\" command occur.\n\nAdd or update the following rules in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n\n-a always,exit -F arch=b32 -S create_module -k module-change\n\n-a always,exit -F arch=b64 -S create_module -k module-change\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-85749r1_fix\"\n\n  describe auditd.syscall(\"create_module\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"create_module\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n  end\n\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-78999.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"create_module\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000194481,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"create_module\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.00010726,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"create_module\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000106841,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"create_module\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000100611,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            }
          ]
        },
        {
          "id": "V-79001",
          "title": "All uses of the finit_module command must be audited.",
          "desc": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).",
          "descriptions": [
            {
              "label": "default",
              "data": "Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter)."
            },
            {
              "label": "check",
              "data": "Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \"finit_module\" command occur.\n\nCheck the auditing rules in \"/etc/audit/audit.rules\" with the following\ncommand:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the line appropriate for the system architecture\nmust be present.\n\n# grep -iw finit_module /etc/audit/audit.rules\n\nIf the command does not return the following output (appropriate to the\narchitecture), this is a finding.\n\n-a always,exit -F arch=b32 -S finit_module -k module-change\n\n-a always,exit -F arch=b64 -S finit_module -k module-change\n\nIf there are no audit rules defined for \"finit_module\", this is a finding."
            },
            {
              "label": "fix",
              "data": "Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \"finit_module\" command occur.\n\nAdd or update the following rules in \"/etc/audit/rules.d/audit.rules\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n-a always,exit -F arch=b32 -S finit_module -k module-change\n\n-a always,exit -F arch=b64 -S finit_module -k module-change\n\nThe audit daemon must be restarted for the changes to take effect."
            }
          ],
          "impact": 0.5,
          "refs": [],
          "tags": {
            "gtitle": "SRG-OS-000471-GPOS-00216",
            "satisfies": [
              "SRG-OS-000471-GPOS-00216",
              "SRG-OS-000477-GPOS-00222"
            ],
            "gid": "V-79001",
            "rid": "SV-93707r1_rule",
            "stig_id": "RHEL-07-030821",
            "cci": [
              "CCI-000172"
            ],
            "documentable": false,
            "nist": [
              "AU-12 c",
              "Rev_4"
            ],
            "subsystems": [
              "audit"
            ],
            "fix_id": "F-85751r1_fix"
          },
          "code": "control \"V-79001\" do\n  title \"All uses of the finit_module command must be audited.\"\n  desc  \"\n    Without generating audit records that are specific to the security and\nmission needs of the organization, it would be difficult to establish,\ncorrelate, and investigate the events relating to an incident or identify those\nresponsible for one.\n\n    Audit records can be generated from various components within the\ninformation system (e.g., module or policy filter).\n  \"\n  impact 0.5\n  tag \"gtitle\": \"SRG-OS-000471-GPOS-00216\"\n  tag \"satisfies\": [\"SRG-OS-000471-GPOS-00216\", \"SRG-OS-000477-GPOS-00222\"]\n  tag \"gid\": \"V-79001\"\n  tag \"rid\": \"SV-93707r1_rule\"\n  tag \"stig_id\": \"RHEL-07-030821\"\n  tag \"cci\": [\"CCI-000172\"]\n  tag \"documentable\": false\n  tag \"nist\": [\"AU-12 c\", \"Rev_4\"]\n  tag \"subsystems\": [\"audit\"]\n  desc \"check\", \"Verify the operating system generates audit records when\nsuccessful/unsuccessful attempts to use the \\\"finit_module\\\" command occur.\n\nCheck the auditing rules in \\\"/etc/audit/audit.rules\\\" with the following\ncommand:\n\nNote: The output lines of the command are duplicated to cover both 32-bit and\n64-bit architectures. Only the line appropriate for the system architecture\nmust be present.\n\n# grep -iw finit_module /etc/audit/audit.rules\n\nIf the command does not return the following output (appropriate to the\narchitecture), this is a finding.\n\n-a always,exit -F arch=b32 -S finit_module -k module-change\n\n-a always,exit -F arch=b64 -S finit_module -k module-change\n\nIf there are no audit rules defined for \\\"finit_module\\\", this is a finding.\"\n  desc \"fix\", \"Configure the operating system to generate audit records when\nsuccessful/unsuccessful attempts to use the \\\"finit_module\\\" command occur.\n\nAdd or update the following rules in \\\"/etc/audit/rules.d/audit.rules\\\":\n\nNote: The rules are duplicated to cover both 32-bit and 64-bit architectures.\nOnly the lines appropriate for the system architecture must be configured.\n-a always,exit -F arch=b32 -S finit_module -k module-change\n\n-a always,exit -F arch=b64 -S finit_module -k module-change\n\nThe audit daemon must be restarted for the changes to take effect.\"\n  tag \"fix_id\": \"F-85751r1_fix\"\n\n   describe auditd.syscall(\"finit_module\").where {arch == \"b32\"} do\n    its('action.uniq') { should eq ['always'] }\n    its('list.uniq') { should eq ['exit'] }\n  end\n  if os.arch == 'x86_64'\n    describe auditd.syscall(\"finit_module\").where {arch == \"b64\"} do\n      its('action.uniq') { should eq ['always'] }\n      its('list.uniq') { should eq ['exit'] }\n    end\n  end\nend\n",
          "source_location": {
            "line": 3,
            "ref": "inspec-profile-disa_stig-el7-master/controls/V-79001.rb"
          },
          "results": [
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"finit_module\" arch == \"b32\" action.uniq should eq [\"always\"]",
              "run_time": 0.000110984,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"finit_module\" arch == \"b32\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000275511,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"finit_module\" arch == \"b64\" action.uniq should eq [\"always\"]",
              "run_time": 0.000151224,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "\nexpected: [\"always\"]\n     got: []\n\n(compared using ==)\n"
            },
            {
              "status": "failed",
              "code_desc": "Auditd Rules with syscall == \"finit_module\" arch == \"b64\" list.uniq should eq [\"exit\"]",
              "run_time": 0.000186537,
              "start_time": "2019-11-04T16:17:17-05:00",
              "message": "\nexpected: [\"exit\"]\n     got: []\n\n(compared using ==)\n"
            }
          ]
        }
      ],
      "status": "loaded"
    }
  ],
  "statistics": {
    "duration": 10.681128104
  },
  "version": "4.16.0"
}
